<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>VerificateAI on GitHub Actions Marketplace News</title><link>https://devops-actions.github.io/github-actions-marketplace-news/tags/verificateai/</link><description>Recent content in VerificateAI on GitHub Actions Marketplace News</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Thu, 20 Aug 2026 06:16:59 +0000</lastBuildDate><atom:link href="https://devops-actions.github.io/github-actions-marketplace-news/tags/verificateai/index.xml" rel="self" type="application/rss+xml"/><item><title>forsakringskassan/eslint-config</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/forsakringskassan/eslint-config/</link><pubDate>Sat, 29 Aug 2026 22:16:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/forsakringskassan/eslint-config/</guid><description>Version updated for https://github.com/Forsakringskassan/eslint-config to version v15.8.15.
This action is used across all versions by 25 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The eslint-config-fk action is an ESLint configuration for Försäkringskassan projects. It provides a custom base configuration tailored to FK’s development guidelines, with rules set as warnings and disabled during local builds but enabled in CI/CD pipelines. The action simplifies the setup of ESLint configurations by providing pre-defined configurations for different project types such as Vue, TypeScript, and Cypress. It also supports overriding specific rules and global variables for certain files or directories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Forsakringskassan/eslint-config">https://github.com/Forsakringskassan/eslint-config</a></strong> to version <strong>v15.8.15</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>25</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/forsakringskassan-eslint-config">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>eslint-config-fk</code> action is an ESLint configuration for Försäkringskassan projects. It provides a custom base configuration tailored to FK&rsquo;s development guidelines, with rules set as warnings and disabled during local builds but enabled in CI/CD pipelines. The action simplifies the setup of ESLint configurations by providing pre-defined configurations for different project types such as Vue, TypeScript, and Cypress. It also supports overriding specific rules and global variables for certain files or directories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="15815-2026-08-29">15.8.15 (2026-08-29)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update dependency eslint-plugin-jest to v29.16.2 22700f4</li>
</ul>
]]></content:encoded></item><item><title>yaml reader</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/yaml-reader/</link><pubDate>Sat, 29 Aug 2026 22:15:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/yaml-reader/</guid><description>Version updated for https://github.com/gertd/yaml-reader-action to version v1.0.3.
This action is used across all versions by 28 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The YAML Reader GitHub Action reads a specified YAML file from a repository and outputs its contents as JSON. This action automates the parsing of YAML files, enabling developers to easily convert YAML configurations into JSON format for further processing or integration with other tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gertd/yaml-reader-action">https://github.com/gertd/yaml-reader-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>28</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yaml-reader">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The YAML Reader GitHub Action reads a specified YAML file from a repository and outputs its contents as JSON. This action automates the parsing of YAML files, enabling developers to easily convert YAML configurations into JSON format for further processing or integration with other tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>use 1.0.* yaml reader (cfdc6f4)</li>
<li>upd (01aace6)</li>
<li>add &ndash;json (701c72b)</li>
<li>test (5277b61)</li>
<li>init (9620163)</li>
<li>Initial commit (9b2f349)</li>
</ul>
]]></content:encoded></item><item><title>gocov coverage upload</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/gocov-coverage-upload/</link><pubDate>Sat, 29 Aug 2026 22:15:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/gocov-coverage-upload/</guid><description>Version updated for https://github.com/gocov/gocov-action to version v1.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uploads test coverage data to gocov from GitHub Actions, handling various programming languages and formats like Go (LCOV), JavaScript/TypeScript (LCOV), Java (JaCoCo), and Python (Cobertura). It supports splitting coverage across different jobs in a matrix build for better visibility and reporting. The action is designed to automatically generate badges and PR comments on the hosted service or your own server, ensuring comprehensive test coverage reporting for your projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gocov/gocov-action">https://github.com/gocov/gocov-action</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gocov-coverage-upload">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uploads test coverage data to <a href="https://app.gocov.dev">gocov</a> from GitHub Actions, handling various programming languages and formats like Go (LCOV), JavaScript/TypeScript (LCOV), Java (JaCoCo), and Python (Cobertura). It supports splitting coverage across different jobs in a matrix build for better visibility and reporting. The action is designed to automatically generate badges and PR comments on the hosted service or your own server, ensuring comprehensive test coverage reporting for your projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fork PRs upload tokenless through the GitHub App by @bykclk in <a href="https://github.com/gocov/gocov-action/pull/8">https://github.com/gocov/gocov-action/pull/8</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/gocov/gocov-action/compare/v1.6.0...v1.7.0">https://github.com/gocov/gocov-action/compare/v1.6.0...v1.7.0</a></p>
]]></content:encoded></item><item><title>guard-my-design-system</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/guard-my-design-system/</link><pubDate>Sat, 29 Aug 2026 22:14:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/guard-my-design-system/</guid><description>Version updated for https://github.com/gregkozakiewicz/guard-my-design-system to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action monitors pull requests to detect and warn about design system violations in your codebase. It checks only added lines, compares them to the learned values from roast-my-design-system, and provides specific comments indicating any issues found, helping maintain a clean and consistent design system.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gregkozakiewicz/guard-my-design-system">https://github.com/gregkozakiewicz/guard-my-design-system</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/guard-my-design-system">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action monitors pull requests to detect and warn about design system violations in your codebase. It checks only added lines, compares them to the learned values from <code>roast-my-design-system</code>, and provides specific comments indicating any issues found, helping maintain a clean and consistent design system.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Your design system dies one pull request at a time. This makes sure it doesn&rsquo;t.</p>
<p>The guard judges only the lines a pull request adds, against the design system
the repo already has. It catches stray colours (and names the nearest token),
spacing values new to the codebase (and names the nearest step), undeclared
typefaces, !important, and arbitrary Tailwind values. One sticky comment per
pull request, updated in place; strict mode fails the check instead.</p>
<p>Field-tested against vercel/ai-chatbot, excalidraw and shadcn-ui, plus
master-only repos, repos with no remote, and detached-HEAD CI. Exclusions
scope the judging as well as the learning, and on a fork&rsquo;s pull request the
verdict lands in the workflow log with a line saying why it could not be
posted. Honest limits are documented in the README.</p>
<p>Full history in CHANGELOG.md.</p>
]]></content:encoded></item><item><title>Setup MySQL with Python 2.7</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/setup-mysql-with-python-2.7/</link><pubDate>Sat, 29 Aug 2026 22:12:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/setup-mysql-with-python-2.7/</guid><description>Version updated for https://github.com/griffinkelly/mysql-python to version 0.9.4.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up a MySQL database in Docker using various options to configure and execute MySQL. It solves problems related to configuring and running MySQL databases within GitHub Actions environments, which are limited by Linux. The action supports multiple MySQL versions and can be used to manage different configurations for the database.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/griffinkelly/mysql-python">https://github.com/griffinkelly/mysql-python</a></strong> to version <strong>0.9.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-mysql-with-python-2-7">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up a MySQL database in Docker using various options to configure and execute MySQL. It solves problems related to configuring and running MySQL databases within GitHub Actions environments, which are limited by Linux. The action supports multiple MySQL versions and can be used to manage different configurations for the database.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update Dockerfile (88923f6)</li>
<li>Update Dockerfile (958fe5b)</li>
<li>Update Dockerfile (76bb5fc)</li>
<li>Update action.yml (2f7c2ae)</li>
<li>Update entrypoint.sh (149624a)</li>
<li>Update action.yml (76f218b)</li>
<li>Update Dockerfile (94ea8c5)</li>
<li>Improve documentations (700bd56)</li>
<li>Add restart option (c2f734e)</li>
<li>Add test code (82ee48a)</li>
</ul>
]]></content:encoded></item><item><title>offsec-ai Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/offsec-ai-security-scanner/</link><pubDate>Sat, 29 Aug 2026 22:11:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/offsec-ai-security-scanner/</guid><description>Version updated for https://github.com/Htunn/offsec-ai to version v2.7.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary offsec-ai is an offensive-security toolkit that combines classic network reconnaissance with modern AI/LLM security testing. It automates tasks such as scanning live AI/LLM endpoints, probing Model Context Protocol (MCP) servers, and performing full-stack infrastructure security assessments. The tool can also detect and report on secrets in responses from Postman collections.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Htunn/offsec-ai">https://github.com/Htunn/offsec-ai</a></strong> to version <strong>v2.7.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/offsec-ai-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>offsec-ai</code> is an offensive-security toolkit that combines classic network reconnaissance with modern AI/LLM security testing. It automates tasks such as scanning live AI/LLM endpoints, probing Model Context Protocol (MCP) servers, and performing full-stack infrastructure security assessments. The tool can also detect and report on secrets in responses from Postman collections.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: bound pending task count in batch_check for hybrid identity and security headers (2041948)</li>
<li>feat: add Postman Collection v2.x security scanner and attacker (v2.7.0) (e4668e8)</li>
<li>ci: publish container to GitHub Container Registry (ghcr.io) (46d755c)</li>
<li>fix: remove undefined OwaspScanResult string annotation in test_cli.py (F821) (8e750e3)</li>
<li>feat: add A2A protocol security support (v2.6.0) (1b99a1b)</li>
<li>fix: define OUTPUT_ARGS before use; -o was silently dropped (v2.5.9) (889e688)</li>
<li>chore: replace all example.com targets with simpleportchecker.com (676106d)</li>
<li>fix: &ndash;format not -f for ai-owasp-scan; use simpleportchecker target (v2.5.8) (504b6e8)</li>
<li>fix: skip &ndash;timeout for ai-owasp-scan which does not support it (v2.5.7) (67a28cd)</li>
<li>chore: use Gemini public endpoint in ai-owasp-scan job (6a13857)</li>
</ul>
]]></content:encoded></item><item><title>Agent-Argus Code Audit &amp; Release Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/agent-argus-code-audit-release-gate/</link><pubDate>Sat, 29 Aug 2026 22:10:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/agent-argus-code-audit-release-gate/</guid><description>Version updated for https://github.com/Inan15/Agent-Argus to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent-Argus (argus-agent) automates security audits of code repositories by identifying and blocking test cases that assert nothing or do not call functions. It helps prevent incorrect assumptions in tests and ensures that code is thoroughly tested before deployment, preventing potential issues and vulnerabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Inan15/Agent-Argus">https://github.com/Inan15/Agent-Argus</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-argus-code-audit-release-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent-Argus (<code>argus-agent</code>) automates security audits of code repositories by identifying and blocking test cases that assert nothing or do not call functions. It helps prevent incorrect assumptions in tests and ensures that code is thoroughly tested before deployment, preventing potential issues and vulnerabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Source distribution and wheel for <code>argus-agent</code> v1.0.0.</p>
<p>Install directly from this repository at this tag:</p>
<pre><code>pip install &quot;argus-agent @ git+https://github.com/Inan15/Agent-Argus.git@v1.0.0&quot;
</code></pre>
<p>Repository visibility, MEASURED 2026-08-29 by <code>gh repo view Inan15/Agent-Argus --json visibility,isPrivate</code> -&gt; <code>PUBLIC</code> / <code>isPrivate: false</code>. What that buys a consumer, stated plainly: the pinned install resolves for anybody with no credential, and the GitHub Release and its attached packages are publicly downloadable. This SUPERSEDES the 2026-08-15 measurement, which read <code>PRIVATE</code> / <code>isPrivate: true</code> and said the pinned install cannot resolve for anybody — tag or no tag — without a read credential carried in the URL (<code>git+https://&lt;credential&gt;@github.com/...</code>) — accurate on its date, never re-run for fourteen days, and false for an unknown part of them. That is the whole hazard of this sentence: it is a dated measurement, not a standing claim, and re-running the command above before relying on it is the only thing that keeps it true.</p>
<p>The exit-code wire contract is UNCHANGED by this release: 0=RELEASE_READY, 1=no verdict produced, 2=NOT_READY_FOR_RELEASE, 3=INSUFFICIENT_COVERAGE. Exit 1 is reserved and is never a verdict — a run that produced no verdict made no statement about your code. See CHANGELOG.md for the full consumer contract.</p>
<p>CI evidence: run 33235322979 (ac1265e6ffabe0a6cb3b7633dc3107bd3556b274, 3/3 legs green) on <code>audit-ci.yml</code> covers the commit being released. Observed 2026-08-29 through the GitHub API.</p>
<p>SCOPE of that run, because a green run is evidence for what it EXECUTED and this one did not execute everything it carries. Each leg reported <code>1777 passed, 4 skipped</code>. The run recorded the following as NOT EVALUATED rather than as passing, so the citation above does not reach them: (1) <code>tests/test_installed_artifact.py</code> (<code>TC-ArgusAgent-RELEASE-001-25</code>..<code>-28</code>) — the fresh-environment installed-artifact proof: every <code>[project.scripts]</code> console script, <code>argus --help</code>, a fixture audit run to a real verdict, and an MCP JSON-RPC exchange over stdio through the installed <code>argus-mcp</code> shim. All four SKIPPED on all three legs, each reporting the named E6 outcome <em>NOT EVALUATED — uv is not on PATH, so the wheel could NOT be installed into a fresh environment and nothing about the INSTALLED distribution was checked</em>. So the front-door claim of this release is held by LOCAL runs only, and this citation does not cover it. Provisioning <code>uv</code> on the CI runner is a tooling decision that has not been taken; it is filed OPEN and unscheduled as <code>DF-12-9-B</code>, owned by the Engineering Lead. Reading the citation as covering these would be the same class of overstatement as quoting a run id without the sha it covers.</p>
<p>This release makes no assurance claim about Argus itself. Argus&rsquo;s dogfood run is a self-audit and is not independent corroboration.</p>
<p>Beta: Argus&rsquo;s finding precision has not been independently validated. Its findings rest on the Argus dogfood corpus, a self-audit of this repository. Treat findings as a prompt to look, not a verdict. This notice is removed only when the &gt;=80% precision gate is met; nothing else removes it.</p>
]]></content:encoded></item><item><title>mdsmith Markdown linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/mdsmith-markdown-linter/</link><pubDate>Sat, 29 Aug 2026 22:09:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/mdsmith-markdown-linter/</guid><description>Version updated for https://github.com/jeduden/mdsmith to version v0.55.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The mdsmith GitHub Action is designed to automate the process of linting and formatting Markdown files in a repository. It focuses on improving readability and consistency across multiple files and pipelines by checking style, structure, and cross-file integrity. The action provides auto-fix capabilities that automatically rewrite errors found during linting, ensuring that Markdown content remains clean and consistent.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jeduden/mdsmith">https://github.com/jeduden/mdsmith</a></strong> to version <strong>v0.55.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mdsmith-markdown-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The mdsmith GitHub Action is designed to automate the process of linting and formatting Markdown files in a repository. It focuses on improving readability and consistency across multiple files and pipelines by checking style, structure, and cross-file integrity. The action provides auto-fix capabilities that automatically rewrite errors found during linting, ensuring that Markdown content remains clean and consistent.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>perf: audit against high-performance-go.md, fix 5 measured hot paths by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/770">https://github.com/jeduden/mdsmith/pull/770</a></li>
<li>perf: audit against high-performance-go.md, fix 5 measured hot paths by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/774">https://github.com/jeduden/mdsmith/pull/774</a></li>
<li>perf: audit against high-performance-go.md, fix top 5 hot-path violations by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/775">https://github.com/jeduden/mdsmith/pull/775</a></li>
<li>perf: fix top 5 hot-path issues from a high-performance-go.md audit by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/780">https://github.com/jeduden/mdsmith/pull/780</a></li>
<li>perf: fix top 5 high-performance-go.md violations found by codebase audit by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/782">https://github.com/jeduden/mdsmith/pull/782</a></li>
<li>perf: audit against high-performance-go.md, fix 5 confirmed hot paths by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/785">https://github.com/jeduden/mdsmith/pull/785</a></li>
<li>perf: fix top 5 high-performance-go.md violations by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/786">https://github.com/jeduden/mdsmith/pull/786</a></li>
<li>perf: fix top 5 high-performance-go.md violations from a 3-agent audit by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/783">https://github.com/jeduden/mdsmith/pull/783</a></li>
<li>perf: audit against high-performance-go.md, fix top 5 new hot-path issues by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/788">https://github.com/jeduden/mdsmith/pull/788</a></li>
<li>perf: fix 4 high-performance-go.md violations found by codebase audit by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/794">https://github.com/jeduden/mdsmith/pull/794</a></li>
<li>perf: consolidate #776, #779, #790, #793 with manual conflict resolution by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/800">https://github.com/jeduden/mdsmith/pull/800</a></li>
<li>chore(deps): bump markdownlint-cli2 from 0.23.1 to 0.23.2 in /docs/research/benchmarks/npm by @dependabot[bot] in <a href="https://github.com/jeduden/mdsmith/pull/778">https://github.com/jeduden/mdsmith/pull/778</a></li>
<li>fix(foreignregion): resolve MDS073 rule-ID collision with slidevstructure by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/791">https://github.com/jeduden/mdsmith/pull/791</a></li>
<li>docs(security): scope zero-egress claim and add MDS072 SSRF caveat by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/771">https://github.com/jeduden/mdsmith/pull/771</a></li>
<li>feat(init): APM coexistence — <code>--apm</code> flag, kind pack, and guide by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/772">https://github.com/jeduden/mdsmith/pull/772</a></li>
<li>chore(deps-dev): bump the npm_and_yarn group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/jeduden/mdsmith/pull/787">https://github.com/jeduden/mdsmith/pull/787</a></li>
<li>docs(security): 2026-08-14 post-audit diff review — clean window by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/795">https://github.com/jeduden/mdsmith/pull/795</a></li>
<li>docs(security): 2026-07-31 post-audit diff review — no new findings by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/781">https://github.com/jeduden/mdsmith/pull/781</a></li>
<li>docs(security): 2026-08-07 post-audit diff review — zero new findings by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/789">https://github.com/jeduden/mdsmith/pull/789</a></li>
<li>docs(security): consolidate the 2026-07-31, 08-07 and 08-14 post-audit reviews by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/801">https://github.com/jeduden/mdsmith/pull/801</a></li>
<li>feat(mds072): SSRF guard and per-run egress ceiling by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/769">https://github.com/jeduden/mdsmith/pull/769</a></li>
<li>test(cmd/mdsmith): add dedicated unit tests for runCheck/runFix by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/784">https://github.com/jeduden/mdsmith/pull/784</a></li>
<li>perf: fix 5 highest-impact violations of the high-performance-go guideline by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/802">https://github.com/jeduden/mdsmith/pull/802</a></li>
<li>plan: vendor go-runewidth as a patched fork, bump tinygo to 0.41.1 by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/804">https://github.com/jeduden/mdsmith/pull/804</a></li>
<li>feat(runewidth): vendor go-runewidth as a patched fork, remove eager LUT by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/807">https://github.com/jeduden/mdsmith/pull/807</a></li>
<li>ci(tinygo): bump pinned tinygo 0.39.0 → 0.41.1 by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/808">https://github.com/jeduden/mdsmith/pull/808</a></li>
<li>perf: fix top 5 high-performance-go.md violations by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/811">https://github.com/jeduden/mdsmith/pull/811</a></li>
<li>build(deps): bump golang.org/x/net from 0.57.0 to 0.58.0 by @dependabot[bot] in <a href="https://github.com/jeduden/mdsmith/pull/812">https://github.com/jeduden/mdsmith/pull/812</a></li>
<li>refactor(githooks): split by responsibility; record 2026-08-23 arch audit by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/815">https://github.com/jeduden/mdsmith/pull/815</a></li>
<li>test(pkg/mdsmith): add dedicated unit test for readBoundedFrontMatterSource by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/805">https://github.com/jeduden/mdsmith/pull/805</a></li>
<li>feat(metrics,rules): add MET007 word-frequency metric and MDS074 over-repetition rule by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/806">https://github.com/jeduden/mdsmith/pull/806</a></li>
<li>refactor(cmd/mdsmith): move list-query subcommand logic into query.go by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/809">https://github.com/jeduden/mdsmith/pull/809</a></li>
<li>test(rules): add dedicated unit tests for occurrence and slidevstructure private helpers by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/810">https://github.com/jeduden/mdsmith/pull/810</a></li>
<li>docs(security): 2026-08-28 post-audit diff review by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/816">https://github.com/jeduden/mdsmith/pull/816</a></li>
<li>feat(schema): let <code>filename:</code> accept a list of globs (OR match) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/818">https://github.com/jeduden/mdsmith/pull/818</a></li>
<li>perf: cut check allocations 21% and CPU 6% across five hot-path fixes by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/813">https://github.com/jeduden/mdsmith/pull/813</a></li>
<li>fix(security): remove proxy blind spot from MDS072 guarded HTTP client by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/819">https://github.com/jeduden/mdsmith/pull/819</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jeduden/mdsmith/compare/v0.54.0...v0.55.0">https://github.com/jeduden/mdsmith/compare/v0.54.0...v0.55.0</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/neurolink-ai/</link><pubDate>Sat, 29 Aug 2026 22:08:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v12.7.2.
This action is used across all versions by 11 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that unifies multiple AI providers and models into a single API using TypeScript-first development. It provides features like switching providers with a simple parameter change, leveraging built-in tools and integrating with any MCP-compliant tool server. NeuroLink also includes enterprise-level features such as Redis memory and multi-provider failover to optimize costs automatically.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v12.7.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>NeuroLink is a universal AI integration platform that unifies multiple AI providers and models into a single API using TypeScript-first development. It provides features like switching providers with a simple parameter change, leveraging built-in tools and integrating with any MCP-compliant tool server. NeuroLink also includes enterprise-level features such as Redis memory and multi-provider failover to optimize costs automatically.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1272-2026-08-29"><a href="https://github.com/juspay/neurolink/compare/v12.7.1...v12.7.2">12.7.2</a> (2026-08-29)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(localUsage):</strong>  pin window monotonicity, and stop two tests lying about failure (<a href="https://github.com/juspay/neurolink/commit/f07f1454e457f73c3d9b162faa09f1cd624f9e27">f07f145</a>)</li>
</ul>
]]></content:encoded></item><item><title>AIsbom Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/aisbom-security-scanner/</link><pubDate>Sat, 29 Aug 2026 22:06:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/aisbom-security-scanner/</guid><description>Version updated for https://github.com/Lab700xOrg/aisbom to version v1.3.3.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AIsbom is a security scanner for AI models that performs static analysis to detect malware, license risks, and code execution vulnerabilities within ML model files. It scans various formats like PyTorch Pickle bytecode, Keras configurations, GGUF chat templates, ONNX graphs, and SafeTensors. The action can be used as a GitHub Action to post an idempotent PR comment on every commit, helping developers identify potential security issues before model deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lab700xOrg/aisbom">https://github.com/Lab700xOrg/aisbom</a></strong> to version <strong>v1.3.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aisbom-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AIsbom is a security scanner for AI models that performs static analysis to detect malware, license risks, and code execution vulnerabilities within ML model files. It scans various formats like PyTorch Pickle bytecode, Keras configurations, GGUF chat templates, ONNX graphs, and SafeTensors. The action can be used as a GitHub Action to post an idempotent PR comment on every commit, helping developers identify potential security issues before model deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="correction-to-the-v132-notes">Correction to the v1.3.2 notes</h3>
<p>v1.3.2 introduced content-based discovery for files no extension claims, and documented one known limit: that a payload could only hide behind a literal larger than the whole 16MB sniff budget.</p>
<p><strong>That figure was wrong.</strong> The real threshold was roughly <strong>64KB</strong> — about 254× easier to reach than published. This release fixes the underlying gap and makes the documented ceiling the true one.</p>
<h3 id="what-was-wrong">What was wrong</h3>
<p>Discovery reads a 64KB head and re-reads with a larger budget only when that head looks like an <em>unfinished</em> pickle. The signal for &ldquo;unfinished&rdquo; was <strong>at least one opcode parsed</strong>.</p>
<p>A pickle that opens with a single literal bigger than that first read completes <strong>zero</strong> opcodes — so the larger read never happened, and the file was never discovered at all. Measured on the released v1.3.2:</p>
<pre tabindex="0"><code>first-literal    65,000 B: CRITICAL (RCE Detected: os.system)
first-literal    70,000 B: NOT DISCOVERED
first-literal 1,000,000 B: NOT DISCOVERED
</code></pre><p>Scope: <strong>discovery only</strong>, and only for files whose extension nothing claims. The same padded payloads under a recognized extension such as <code>.pkl</code> were always caught, as was a payload <em>followed</em> by a large literal. If you scan <code>.pt</code>, <code>.pkl</code>, <code>.safetensors</code>, <code>.gguf</code> or any other recognized format, this never applied to you.</p>
<h3 id="the-fix">The fix</h3>
<p>Discovery now also re-reads when the first opcode declares an argument that runs past the buffer — the one way a genuine pickle yields no opcodes at all.</p>
<ul>
<li><strong>Length-prefixed arguments</strong> (<code>BINBYTES</code>, <code>BINUNICODE</code>, <code>BINBYTES8</code>, …) are read exactly from their size prefix.</li>
<li><strong>Newline-terminated arguments</strong> cannot be measured without the terminator, so they are admitted only for the handful of opcodes that can really begin a pickle (<code>STRING</code>, <code>UNICODE</code>, <code>INT</code>, <code>LONG</code>, <code>FLOAT</code>), only when no newline is already in view, and only when the next byte matches what that opcode&rsquo;s argument must start with.</li>
</ul>
<p>That last guard is what keeps the walk cheap. A parquet file opens <code>PAR1</code>, and <code>P</code> <em>is</em> the PERSID opcode — but no real pickle begins with a persistent id, so parquet still settles on its first 64KB instead of being re-read to the cap. There is a test asserting exactly that.</p>
<h3 id="verification">Verification</h3>
<ul>
<li>Every previously-evading pad is now caught — 70,000 B, 250,000 B, 1,000,000 B and 2,000,000 B, in both the protocol-0 quoted-string and binary length-prefixed shapes.</li>
<li><strong>The ceiling is now real</strong>: caught at 16,773,120 bytes, not discovered at 16,781,312.</li>
<li>Cost unchanged — a 5,101-file <code>node_modules</code> walk still yields 0 artifacts in 0.83s.</li>
<li><code>poetry run pytest</code>: <strong>831 passed, 91.38% coverage</strong>.</li>
<li><code>aisbom bypass-scorecard --check</code>: gate green, <strong>9/11</strong> unchanged.</li>
</ul>
<h3 id="whats-not-changing">What&rsquo;s not changing</h3>
<p>Exit codes, output formats and the CycloneDX/SPDX schemas are identical to v1.3.2. No new dependencies. The bypass scorecard is unmoved at 9/11 — this gap was never one of the eleven published corpus cases, which is its own lesson about what a corpus does and does not cover.</p>
]]></content:encoded></item><item><title>AI Compliance Gates</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/ai-compliance-gates/</link><pubDate>Sat, 29 Aug 2026 22:05:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/ai-compliance-gates/</guid><description>Version updated for https://github.com/mmubarak-io/ai-compliance-gates to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates compliance checks for AI models and pipelines, ensuring adherence to UAE PDPL, GDPR, and EU AI Act regulations. It enforces data protection, model documentation completeness, Terraform policy compliance, and auditor-facing artifacts in CI/CD pipelines. The action supports multiple entry points for different use cases and runs on GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmubarak-io/ai-compliance-gates">https://github.com/mmubarak-io/ai-compliance-gates</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-compliance-gates">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates compliance checks for AI models and pipelines, ensuring adherence to UAE PDPL, GDPR, and EU AI Act regulations. It enforces data protection, model documentation completeness, Terraform policy compliance, and auditor-facing artifacts in CI/CD pipelines. The action supports multiple entry points for different use cases and runs on GitHub Actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Reusable GitHub Actions that turn UAE PDPL, GDPR and EU AI Act requirements into blocking CI checks. Every policy is an executable check that fails the build, not a paragraph in a document nobody reads.</p>
<h2 id="adopt-in-one-step">Adopt in one step</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">mmubarak-io/ai-compliance-gates@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">data-path</span>: <span style="color:#ae81ff">./data</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">model-cards-path</span>: <span style="color:#ae81ff">./model_cards</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">terraform-paths</span>: <span style="color:#e6db74">&#34;infra/*.tf&#34;</span>
</span></span></code></pre></div><h2 id="the-gates">The gates</h2>
<table>
  <thead>
      <tr>
          <th>Gate</th>
          <th>Enforces</th>
          <th>Regulation</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>PII scan</td>
          <td>Datasets free of PII, including Emirates ID, +971 phones and AE IBANs that generic scanners miss. Reads CSV, TSV, JSON, JSON Lines and Parquet, compressed or not</td>
          <td>UAE PDPL Art. 20, GDPR Art. 32</td>
      </tr>
      <tr>
          <td>Model card check</td>
          <td>AI documentation complete, every missing field citing the article it fails</td>
          <td>EU AI Act Annex IV, Art. 9/13/14</td>
      </tr>
      <tr>
          <td>Policy check</td>
          <td>Terraform satisfies the register via OPA/Conftest: TLS 1.2, no public access, data residency, RBAC, audit logging, retention</td>
          <td>UAE PDPL Art. 9, 20, 22-23; GDPR Art. 5, 30, 32</td>
      </tr>
      <tr>
          <td>Evidence pack</td>
          <td>Auditor-facing artifact per run: what was checked, against which regulation, at which commit, with a sha256 of its own content</td>
          <td>GDPR Art. 5(2), EU AI Act Art. 12</td>
      </tr>
  </tbody>
</table>
<h2 id="how-it-fails">How it fails</h2>
<p>A gate must never report success for a check it did not perform.</p>
<table>
  <thead>
      <tr>
          <th>Exit code</th>
          <th>Meaning</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>0</code></td>
          <td>Checked something, found nothing wrong</td>
      </tr>
      <tr>
          <td><code>1</code></td>
          <td>Policy violation, the build blocks</td>
      </tr>
      <tr>
          <td><code>2</code></td>
          <td>Misconfigured, could not check what it was pointed at</td>
      </tr>
  </tbody>
</table>
<p>Code <code>2</code> is the load-bearing one. A path matching zero files, unreadable input, a format with no reader, invalid config and a run given no gate at all all exit <code>2</code> rather than passing. Partial coverage blocks too: a directory of Parquet shards next to one CSV does not pass on the strength of the CSV. Opt out only deliberately with <code>allow-empty</code> or <code>allow-unscanned</code>, and the gap stays recorded in the evidence pack as <code>PARTIAL</code>, never <code>PASS</code>.</p>
<p>Each gate is also available on its own under <code>.github/actions/</code>, and the whole pipeline as a reusable workflow at <code>.github/workflows/gates.yml</code>.</p>
<p>Full changelog: <a href="https://github.com/mmubarak-io/ai-compliance-gates/blob/main/CHANGELOG.md">https://github.com/mmubarak-io/ai-compliance-gates/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Go - Test Suites</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/go-test-suites/</link><pubDate>Sat, 29 Aug 2026 22:04:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/go-test-suites/</guid><description>Version updated for https://github.com/mvrahden/go-test to version v1.28.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the creation and execution of test suites in Go, providing features such as isolation and parallelism, along with a specification-driven approach to testing through BDD vocabulary. It supports generating test outputs that are both readable and in sync with the underlying code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mvrahden/go-test">https://github.com/mvrahden/go-test</a></strong> to version <strong>v1.28.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-test-suites">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action automates the creation and execution of test suites in Go, providing features such as isolation and parallelism, along with a specification-driven approach to testing through BDD vocabulary. It supports generating test outputs that are both readable and in sync with the underlying code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(docs): point the gopher image at its new site/static home by @mvrahden in <a href="https://github.com/mvrahden/go-test/commit/8a3845b9b313acaa66a0dc2257f6df496560b094">https://github.com/mvrahden/go-test/commit/8a3845b9b313acaa66a0dc2257f6df496560b094</a></li>
<li>chore: Go 1.25 is the supported floor, 1.27 the newest version tested by @mvrahden in <a href="https://github.com/mvrahden/go-test/commit/33d0762a5b3795df5073bd8cced931560af5d765">https://github.com/mvrahden/go-test/commit/33d0762a5b3795df5073bd8cced931560af5d765</a></li>
<li>feat(cli): every JSON surface emits one compact line, halving the payload by @mvrahden in <a href="https://github.com/mvrahden/go-test/commit/36150839f75acb910ab486590720ff90e7ef6e6d">https://github.com/mvrahden/go-test/commit/36150839f75acb910ab486590720ff90e7ef6e6d</a></li>
<li>fix(vscode): discovery streams the CLI&rsquo;s output instead of losing it past 1 MiB by @mvrahden in <a href="https://github.com/mvrahden/go-test/commit/cc46b4940444744dc8261c12eeab400b938ea158">https://github.com/mvrahden/go-test/commit/cc46b4940444744dc8261c12eeab400b938ea158</a></li>
<li>Restore compatibility with Go 1.27 and test main after merge by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/113">https://github.com/mvrahden/go-test/pull/113</a></li>
<li>Update every dependency and raise the extension floor to VS Code 1.123 by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/121">https://github.com/mvrahden/go-test/pull/121</a></li>
<li>fix(ci): the publish jobs receive their tokens again, and refuse to run without them by @mvrahden in <a href="https://github.com/mvrahden/go-test/commit/9ccfa36d">https://github.com/mvrahden/go-test/commit/9ccfa36d</a></li>
<li>fix(ci): the tokens travel under names no environment secret can shadow, and the guards run from the workspace root by @mvrahden in <a href="https://github.com/mvrahden/go-test/commit/f4aa6289">https://github.com/mvrahden/go-test/commit/f4aa6289</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mvrahden/go-test/compare/v1.27.0...v1.28.0">https://github.com/mvrahden/go-test/compare/v1.27.0...v1.28.0</a></p>
]]></content:encoded></item><item><title>Sigil Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/sigil-security-scan/</link><pubDate>Sat, 29 Aug 2026 22:02:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/sigil-security-scan/</guid><description>Version updated for https://github.com/NOMARJ/sigil to version v1.3.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sigil is an automated security auditing action that scans AI agent code to detect malicious patterns before they reach working environments. It uses a quarantine-first approach and provides eight analysis phases, including Install Hooks, Code Patterns, Network/Exfil, Credentials, Obfuscation, Provenance, Prompt Injection, Skill Security, and LLM Analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NOMARJ/sigil">https://github.com/NOMARJ/sigil</a></strong> to version <strong>v1.3.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sigil-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sigil is an automated security auditing action that scans AI agent code to detect malicious patterns before they reach working environments. It uses a quarantine-first approach and provides eight analysis phases, including Install Hooks, Code Patterns, Network/Exfil, Credentials, Obfuscation, Provenance, Prompt Injection, Skill Security, and LLM Analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="sigil-v133">Sigil v1.3.3</h2>
<h3 id="quick-install">Quick Install</h3>
<p><strong>Homebrew (macOS/Linux):</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap nomarj/tap
</span></span><span style="display:flex;"><span>brew install sigil
</span></span></code></pre></div><p><strong>npm (macOS/Linux):</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install -g @nomarj/sigil
</span></span></code></pre></div><p><strong>Cargo (Rust):</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>cargo install sigil-cli
</span></span></code></pre></div><p><strong>Installer script:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -fsSLO https://www.sigilsec.ai/install.sh
</span></span><span style="display:flex;"><span>sh install.sh
</span></span></code></pre></div><h3 id="manual-installation">Manual Installation</h3>
<p><strong>macOS (Apple Silicon):</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -fsSLO https://github.com/NOMARJ/sigil/releases/download/v1.3.3/sigil-macos-arm64.tar.gz
</span></span><span style="display:flex;"><span>curl -fsSLO https://github.com/NOMARJ/sigil/releases/download/v1.3.3/SHA256SUMS.txt
</span></span><span style="display:flex;"><span>sha256sum -c --ignore-missing SHA256SUMS.txt
</span></span><span style="display:flex;"><span>tar -xzf sigil-macos-arm64.tar.gz
</span></span><span style="display:flex;"><span>sudo mv sigil /usr/local/bin/
</span></span></code></pre></div><p><strong>macOS (Intel):</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -fsSLO https://github.com/NOMARJ/sigil/releases/download/v1.3.3/sigil-macos-x64.tar.gz
</span></span><span style="display:flex;"><span>curl -fsSLO https://github.com/NOMARJ/sigil/releases/download/v1.3.3/SHA256SUMS.txt
</span></span><span style="display:flex;"><span>sha256sum -c --ignore-missing SHA256SUMS.txt
</span></span><span style="display:flex;"><span>tar -xzf sigil-macos-x64.tar.gz
</span></span><span style="display:flex;"><span>sudo mv sigil /usr/local/bin/
</span></span></code></pre></div><p><strong>Linux (x64):</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -fsSLO https://github.com/NOMARJ/sigil/releases/download/v1.3.3/sigil-linux-x64.tar.gz
</span></span><span style="display:flex;"><span>curl -fsSLO https://github.com/NOMARJ/sigil/releases/download/v1.3.3/SHA256SUMS.txt
</span></span><span style="display:flex;"><span>sha256sum -c --ignore-missing SHA256SUMS.txt
</span></span><span style="display:flex;"><span>tar -xzf sigil-linux-x64.tar.gz
</span></span><span style="display:flex;"><span>sudo mv sigil /usr/local/bin/
</span></span></code></pre></div><p><strong>Linux (ARM64):</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -fsSLO https://github.com/NOMARJ/sigil/releases/download/v1.3.3/sigil-linux-arm64.tar.gz
</span></span><span style="display:flex;"><span>curl -fsSLO https://github.com/NOMARJ/sigil/releases/download/v1.3.3/SHA256SUMS.txt
</span></span><span style="display:flex;"><span>sha256sum -c --ignore-missing SHA256SUMS.txt
</span></span><span style="display:flex;"><span>tar -xzf sigil-linux-arm64.tar.gz
</span></span><span style="display:flex;"><span>sudo mv sigil /usr/local/bin/
</span></span></code></pre></div><p><strong>Windows (x64):</strong>
Download <code>sigil-windows-x64.zip</code>, extract, and add to your PATH.</p>
<h3 id="verify-checksums">Verify checksums</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>sha256sum -c SHA256SUMS.txt
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(release): move embedded packs into the crate for cargo publish; bump 1.3.3 by @nomark-dev in <a href="https://github.com/NOMARJ/sigil/pull/145">https://github.com/NOMARJ/sigil/pull/145</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NOMARJ/sigil/compare/v1.3.2...v1.3.3">https://github.com/NOMARJ/sigil/compare/v1.3.2...v1.3.3</a></p>
]]></content:encoded></item><item><title>Full-site SEO Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/full-site-seo-audit/</link><pubDate>Sat, 29 Aug 2026 22:01:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/full-site-seo-audit/</guid><description>Version updated for https://github.com/nurkamol/seo-audit to version v1.38.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action seo-audit is designed to crawl an entire website’s sitemap and check all pages for SEO, metadata, and structured data issues that single-page graders often overlook. It automates the process of identifying problems such as duplicate content, long page titles, and missing language switcher links on translated pages. The action can be run in CI environments or directly from the command line with minimal setup, ensuring comprehensive SEO audits across a site’s entire structure without requiring manual checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nurkamol/seo-audit">https://github.com/nurkamol/seo-audit</a></strong> to version <strong>v1.38.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/full-site-seo-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>seo-audit</code> is designed to crawl an entire website&rsquo;s sitemap and check all pages for SEO, metadata, and structured data issues that single-page graders often overlook. It automates the process of identifying problems such as duplicate content, long page titles, and missing language switcher links on translated pages. The action can be run in CI environments or directly from the command line with minimal setup, ensuring comprehensive SEO audits across a site&rsquo;s entire structure without requiring manual checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<blockquote>
<h3 id="updating-from-1380-or-earlier-on-macos-needs-one-command">Updating from 1.38.0 or earlier on macOS needs one command</h3>
<p>This release fixes an updater that could not install its own fix. On 1.38.0
and earlier, <strong>Update</strong> offers this version and then does nothing: the banner
reads GitHub&rsquo;s releases while <code>brew upgrade</code> reads Homebrew&rsquo;s own copy of the
tap, which is refreshed at most once a day, so for a while after any release
the two disagree and Homebrew answers <em>&ldquo;the latest version is already
installed&rdquo;</em>.</p>
<p>Once, in a terminal:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew update <span style="color:#f92672">&amp;&amp;</span> brew upgrade --cask seo-audit
</span></span></code></pre></div><p>From 1.38.1 onward the button does both steps itself, and this is the last
time it is needed.</p>
</blockquote>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>Update said a new version had appeared and then did nothing.</strong> The banner
reads GitHub&rsquo;s releases; <code>brew upgrade</code> reads Homebrew&rsquo;s own clone of the tap,
and that clone is refreshed by an auto-update which runs at most once a day.
So for up to twenty-four hours after a release the two disagree: the window
offers 1.38.0, Homebrew answers <em>&ldquo;Not upgrading seo-audit, the latest version
is already installed&rdquo;</em>, and the process exits 0 — so nothing reported a
failure and nothing moved.</p>
<p><code>brew update</code> now runs first, as a step rather than a hope, and the command
shown on screen says both so that running it by hand does the same thing.
Found by pressing Update on a real 1.36.0 with 1.38.0 published, watching it
do nothing, and going after the reason.</p>
</li>
<li>
<p><strong>Linux was told to run a command that could not work.</strong> An apt-installed
copy was offered <code>sudo apt-get install --only-upgrade seo-audit</code>, and no apt
repository anywhere carries this package — the <code>.deb</code> is downloaded from a
release and installed by hand. apt would answer that it cannot locate it. The
same failure as above in a different package manager: an instruction that
reads like an answer and is not one. That copy now goes to the release page,
where the next <code>.deb</code> actually is.</p>
<p>With nothing left that could produce it, the &ldquo;Show me&rdquo; path and its dialog are
gone. An option nothing can reach is an option that does not exist.</p>
</li>
<li>
<p><strong>The winget path could never have worked, token or no token.</strong> Detection ran
<code>winget list --id Nurkamol.SeoAudit --exact</code> and then asked whether the output
contained <code>seo-audit</code>. It never does: winget prints an Id column reading
<code>Nurkamol.SeoAudit</code>, the Name is <code>SEO Audit</code>, and the lowercase hyphenated
spelling appears nowhere. So the check was false for every winget install
there could ever be — and would have stayed false after a manifest shipped,
with the branch dead for a reason nobody was looking at any more. It matches
on the identifier now, case-insensitively, which is what winget is.</p>
<p>The identifier is one constant rather than three copies, and the guard that
keeps it in step with the workflow reads that constant and also fails if
anybody writes it out by hand again.</p>
</li>
<li>
<p><strong>The bundle declared no publisher, licence or description</strong>, all of which a
winget manifest requires and all of which Windows shows in Add/Remove
Programs. Set, so the first submission has something true to carry.</p>
</li>
</ul>
<hr>
<h3 id="installing-on-macos">Installing on macOS</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap nurkamol/seo-audit https://github.com/nurkamol/seo-audit
</span></span><span style="display:flex;"><span>brew trust nurkamol/seo-audit
</span></span><span style="display:flex;"><span>brew install --cask seo-audit
</span></span></code></pre></div><p>Homebrew verifies the download against the checksum below and clears the
quarantine flag for you, so the app opens the first time.</p>
<p><strong>Downloading the zip instead?</strong> macOS may say <em>&ldquo;SEO Audit is damaged and
can&rsquo;t be opened.&rdquo;</em> It is not damaged. The app is ad-hoc signed rather than
notarised — notarising needs a paid Apple Developer account this project
does not have — and macOS refuses quarantined apps without a notarisation
ticket. Check what you downloaded first:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>shasum -a <span style="color:#ae81ff">256</span> seo-audit-1.38.1-macos.zip
</span></span><span style="display:flex;"><span><span style="color:#75715e"># f1ce47dace1edecef143143f27e50f94dcd068b621e86affdc0ed39d4457eeb1</span>
</span></span></code></pre></div><p>Then, once it matches, clear the flag — no <code>sudo</code> needed:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>xattr -dr com.apple.quarantine <span style="color:#e6db74">&#34;/Applications/SEO Audit.app&#34;</span>
</span></span></code></pre></div><p>That is what right-click → <strong>Open</strong> does in the Finder, without the dialog.
Apple Silicon, macOS Tahoe or newer.</p>
<h3 id="windows-and-linux">Windows and Linux</h3>
<p>The <code>setup.exe</code>, <code>.deb</code> and <code>.AppImage</code> below are attached by a separate
job and may appear a few minutes after this release does.</p>
<p>The Windows installer is unsigned, so SmartScreen shows <em>&ldquo;Windows protected
your PC&rdquo;</em> — <strong>More info → Run anyway</strong>. Same reason as macOS: a code-signing
certificate is a paid, per-year thing this project does not have. The
<code>.AppImage</code> needs <code>chmod +x</code> before it will run.</p>
<p>Check any of them first. A <code>SHA256SUMS.txt</code> covering every file here is
attached alongside them, and the same checksums are listed at the end of
these notes:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>shasum -a <span style="color:#ae81ff">256</span> --ignore-missing -c SHA256SUMS.txt
</span></span></code></pre></div><h3 id="checksums">Checksums</h3>
<p>Verify a download before you wave a warning away. With <code>SHA256SUMS.txt</code>
saved beside the file, in the same folder:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>shasum -a <span style="color:#ae81ff">256</span> --ignore-missing -c SHA256SUMS.txt
</span></span></code></pre></div><pre tabindex="0"><code>1328e19d7b4e3de68706ac978376b6b5f02a03182c2434e60a809b2671bdea17  SEO.Audit_1.38.1_amd64.AppImage
c147fe6865200efeff9454df5c792a4bc087f0a201ebc7d807a4309323ada651  SEO.Audit_1.38.1_amd64.deb
30fe3d86dee9b056638fa986387e9a1a0a20224a90764366a79aebde4c67d1af  SEO.Audit_1.38.1_x64-setup.exe
f1ce47dace1edecef143143f27e50f94dcd068b621e86affdc0ed39d4457eeb1  seo-audit-1.38.1-macos.zip
</code></pre><p>The macOS line appears twice in these notes on purpose: once above, computed
when the app was built, and once here, computed from what is actually attached.
They should agree.</p>
]]></content:encoded></item><item><title>Chock Governance Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/chock-governance-check/</link><pubDate>Sat, 29 Aug 2026 22:00:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/chock-governance-check/</guid><description>Version updated for https://github.com/open-coder-ai/chock to version v0.6.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Chock is a governance-as-code tool that automates AI coding agents by compiling rules into deterministic guardrails. It ensures that all AI coding agents within a team or open-source project follow specific policies, such as disallowing force pushes to the main branch, and provides coverage reports on rule adherence across different agents.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/open-coder-ai/chock">https://github.com/open-coder-ai/chock</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/chock-governance-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Chock is a governance-as-code tool that automates AI coding agents by compiling rules into deterministic guardrails. It ensures that all AI coding agents within a team or open-source project follow specific policies, such as disallowing force pushes to the main branch, and provides coverage reports on rule adherence across different agents.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="agent-hooks-py-launcher-fallback-and-int-3-verb-list">Agent-hooks <code>py</code> launcher fallback and INT-3 verb list</h2>
<p>MINOR: the agent-hooks emitter output changes, so an adopter&rsquo;s next <code>chock sync</code> /
<code>chock plugin build</code> rewrites <code>.github/hooks/*.json</code>. No credited enforcement surface
changes — the guard runs the same, just with one more way to find an interpreter.</p>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Agent-hooks Bash resolver adds the <code>py</code> launcher fallback.</strong> The Bash branch resolved
<code>command -v python3 || command -v python</code>; the PowerShell branch already tried <code>py</code>. On a
Windows checkout where only the <code>py</code> launcher is on PATH, the Bash hook exited
&ldquo;no python interpreter found&rdquo; and <strong>the guard failed open</strong>. It now also tries <code>py</code>,
matching the PowerShell branch, so the two agree about where enforcement holds. (#71)</li>
<li><strong>INT-3 recognises <code>pin</code> as a verb.</strong> Policy ids like <code>pin-github-actions</code> no longer draw
a spurious &ldquo;does not start with a verb&rdquo; warning. (#71)</li>
<li><strong>Docs</strong>: dropped a stale hardcoded published-version snapshot from the compatibility
page; the GitHub Action example now pins v0.6.0. (#72)</li>
</ul>
<h3 id="release-verification">Release verification</h3>
<p>The full pre-tag routine ran at zero failures on the tagged lineage: 844 tests green,
83% statement coverage, docs-accuracy and emitter-golden checks pass, catalog truth-check
251/251 eval cases (block and allow), and a byte-identical rebuild of the published
distribution trees. Post-tag verification (PyPI publish attestation, cold install, and
distribution republish from this tag) runs next and the distribution repos will republish
against v0.6.0.</p>
]]></content:encoded></item><item><title>Web App Security Skill</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/web-app-security-skill/</link><pubDate>Sat, 29 Aug 2026 21:59:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/web-app-security-skill/</guid><description>Version updated for https://github.com/parousia8888/web-app-security-skill to version v0.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates web application security audits using AI coding agents. It provides actionable security reports with realistic consequences, reviewable changes, and evidence-based decisions. The action supports JavaScript/TypeScript frameworks and generates route-security.json and route-security.md files. It can be used to audit a local project without contacting a deployment or modifying code, focusing on actionable results and providing clear explanations of what needs human confirmation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/parousia8888/web-app-security-skill">https://github.com/parousia8888/web-app-security-skill</a></strong> to version <strong>v0.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/web-app-security-skill">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates web application security audits using AI coding agents. It provides actionable security reports with realistic consequences, reviewable changes, and evidence-based decisions. The action supports JavaScript/TypeScript frameworks and generates route-security.json and route-security.md files. It can be used to audit a local project without contacting a deployment or modifying code, focusing on actionable results and providing clear explanations of what needs human confirmation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v080-release-evidence">v0.8.0 release evidence</h1>
<p>Status: complete. Immutable release, npm package, verified installer and signed <code>v1</code> are published.
The immutable and moving-alias consumers passed, and the byte-matched durable live-verification
record is available as both a workflow artifact and GitHub Release asset.</p>
<p>Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.</p>
<h2 id="outcome">Outcome</h2>
<p>v0.8.0 deepens the existing JavaScript/TypeScript route review without adding a framework, ORM,
general SAST or automatic-repair claim.</p>
<ul>
<li>Route-security v3 follows exact route, query, direct JSON-body and Server Action object selectors
through at most four exact project-local call edges.</li>
<li>Object, principal and tenant facts remain separate. Supported Prisma/Drizzle operations record
visible query predicates, supported post-load comparisons, absent supported constraints or
incomplete evidence as different outcomes.</li>
<li>Express, NestJS, Next.js App Router and Next.js Server Actions share one bounded project graph,
while framework inventory and access-path coverage remain independent.</li>
<li>Compatible v3 baselines can expose lost authorization evidence or incomplete current paths.
Route-security v1/v2 baselines are <code>not_comparable / route_schema_changed</code> under v3.</li>
<li>Each rendered review lead includes the professional term, plain-language meaning, conditional
consequence, evidence limit, review proposal, change risk and owner/non-owner/normal-flow checks.</li>
</ul>
<p><code>completed</code> means the bounded static model reached a supported operation. It does not prove runtime
reachability, correct authorization, control-flow dominance, exploitability or absence of an
unsupported path. Clerk, Better Auth and Supabase remain experimental; Supabase always requires
deployed RLS-policy evidence.</p>
<h2 id="fixed-commit-effectiveness-evidence">Fixed-commit effectiveness evidence</h2>
<p>The denominator was frozen before implementation at 14 eligible paths across four exact public
commits, with a target of 10 and a six-path grounded floor. It was not reduced after misses.</p>
<ul>
<li>13 of 14 frozen paths completed: Drizzle 6/6 and Prisma 7/8.</li>
<li>The sole miss, Formbricks <code>ACTION getMembershipRole</code>, remains partial with
<code>argument_mapping_ambiguous</code> and <code>call_target_unresolved</code>.</li>
<li>The review contains 63 distinct completed operation chains and 50 additional completed review
paths outside the frozen score; additional paths were not added to the denominator.</li>
<li>Four completed paths retain supporting limitations. Completion does not erase them.</li>
<li>Same-machine median runtime ratios were 1.10x to 1.41x against the v0.7.3 baseline, below the 2x
stop threshold for all four fixed targets.</li>
</ul>
<p>The <a href="../reviews/v0.8.0-access-control-review.md">review</a>,
<a href="../reviews/v0.8.0-access-control-review-provenance.md">provenance record</a> and
<a href="../regressions/v0.8.0-access-control-real-world-regression.md">minimized regression</a> bind these
facts. This author-selected fixed corpus is bounded effectiveness evidence, not production
precision/recall, framework-wide coverage or a vulnerability benchmark.</p>
<h2 id="candidate-verification">Candidate verification</h2>
<p>The local P13 gate completed with the failure history retained rather than rewritten. The single
<code>npm run check</code> invocation stopped first on a stale curated v2 fixture; its explicit continuation
then found one duplicate-ID renderer fixture and the v0.7.3-bound active journey catalog. The
schemas and duplicate-ID validator were not relaxed. After the focused corrections, non-overlapping
runner records cover all 82 intended test files: 81 passed, zero failed, one opt-in real-adapter file
skipped and zero not run. Prerequisite surfaces record three passed and one explicit skip. The shell
smoke suite and every remaining lint/contract command passed; no second monolithic check was run.</p>
<p>Final local artifacts:</p>
<ul>
<li>npm dry-run package: v0.8.0, 215 files, 645,212 packed bytes, SHA-1
<code>1b45330758998f04eeacf71166ab20310fd1c1e7</code>;</li>
<li>SPDX 2.3 SBOM: two packages, SHA-256
<code>e3a0cd020e846d6f8af3751a9ff31bf108b4e1813c958b7cc337d2a6846e295f</code>;</li>
<li>parser bundle: SHA-256 <code>f8d700c78a6d0a50513a672b419074a87597093733d2d69ecee92675d8139698</code>;</li>
<li>active five-project v0.8.0 catalog: exact tool source <code>80d21afbbca2075a66e761b085e7bd4752fdac7f</code>,
all five fixed checkouts clean, two complete and three explicitly incomplete audit exits;</li>
<li>secret scan: two intentional planted test-fixture files, zero production credential values after
redacted manual classification;</li>
<li>Skill validation, package isolation, document/product/release/distribution contracts and
<code>git diff --check</code>: passed.</li>
</ul>
<p>Hosted candidate verification passed before immutable publication on the final release source:</p>
<ul>
<li>source commit: <code>119cbcc7f8d327482df8abfa50a4af0b69fcceee</code>;</li>
<li><a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/33263683220">CI run 33263683220</a>:
<code>success</code> on macOS/Ubuntu with Node 22/24, including pinned real-adapter fixtures on Ubuntu Node 22;</li>
<li><a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/33263683203">CodeQL run 33263683203</a>:
<code>success</code> on the same commit;</li>
<li><code>main</code> was observed at that commit, but the branch-protection API reports that <code>main</code> is not
protected. The hosted checks passed; their enforcement by branch protection is not claimed.</li>
</ul>
<h2 id="immutable-publication-evidence">Immutable publication evidence</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>git -c gpg.ssh.allowedSignersFile<span style="color:#f92672">=</span>.github/release-signers verify-tag v0.8.0
</span></span></code></pre></div><p>The SSH-signed annotated tag object is
<code>e826ede4b3ee1eab9237b5ea49ba8e340da26bd5</code> and peels to release source
<code>119cbcc7f8d327482df8abfa50a4af0b69fcceee</code>. Repository-local SSH verification passes, and GitHub
reports <code>verified: true</code> with reason <code>valid</code> for that exact tag object.</p>
<p><a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/33263798089">Release workflow 33263798089</a>
completed successfully and published four immutable assets:</p>
<ul>
<li><code>SHA256SUMS</code>: SHA-256
<code>e606db959a83171a6d19a76ff29979e9c5155594fa993be376fb36a10c75899e</code>;</li>
<li>release manifest: SHA-256
<code>3bee5679b353c3071eac1452cf52b2439979b30ded03686afbb734eec63b846a</code>;</li>
<li>SPDX 2.3 SBOM: SHA-256
<code>cce92a9bfdd96617c59d0c49c2f59f0ce07e9ea2b529de2f0dad16f57296a137</code>;</li>
<li>source archive: SHA-256
<code>d6136bdc82975274cc0059ad0bf36e602b447dbfb9cbcca8a7a058b60bb8d888</code>.</li>
</ul>
<p>The downloaded asset set passed checksum, manifest, archive lifecycle and GitHub attestation
verification. The manifest and tag identify the same release source. The archive contains 547
entries and its SBOM declares SPDX 2.3 with two packages.</p>
<p><a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/33263916671">npm trusted-publishing run 33263916671</a>
published <code>web-app-security-skill@0.8.0</code> from the same source. npm records shasum
<code>1b45330758998f04eeacf71166ab20310fd1c1e7</code>, integrity
<code>sha512-zbnRkSZ4bdMgRtXprWSp8uvgMswAGjdZstXbcObLJlOIvjnpbmmSHQzdzWPTTlID3giNFfsDH8hchnomYQfUNQ==</code>
and SLSA provenance for that workflow/source. All 215 npm package files match the signed release
source archive byte-for-byte. A fresh-cache exact-version consumer returned
<code>Web App Security Skill 0.8.0</code>.</p>
<p>Verifier commit <code>f55c80e7c5014ff6d39d61ca8cbb4fec2ec1fbac</code> records the public v0.8.0 asset
digests and has SHA-256 <code>0e3e27ae7f00314668337b9d0a2d8a350ac01b908ab65aa0b2856c614278d5a7</code>.
Bootstrap commit <code>12cb085d7f3a21c2b6ffb6cb2758ee4247e2af9f</code> fixes that verifier identity and has
SHA-256 <code>137b5d8fdf6f616be3aa2631e0134b354fd9142ce19419bad6c37e5b0409480f</code>.
Focused trust-chain tests pass locally. Public raw bootstrap retrieval, an isolated clean install
and the immutable full-SHA Action consumer have now passed. The public bootstrap matched SHA-256
<code>137b5d8fdf6f616be3aa2631e0134b354fd9142ce19419bad6c37e5b0409480f</code> before execution. It installed
all three supported targets under an isolated HOME with <code>--attestation required</code>; GitHub CLI
attestation verified successfully, and no existing user installation was touched.</p>
<p><a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/33264836987">Immutable consumer run 33264836987</a>
completed successfully against the full release source SHA. The owned Express/Prisma fixture
produced route-security v3 with completed bounded-path coverage and an observed owner constraint,
without converting the review evidence into a confirmed-vulnerability claim. The moving-<code>v1</code>
consumer and live-verification jobs were intentionally skipped until P16.</p>
<h2 id="final-promotion-and-live-verification">Final promotion and live verification</h2>
<p>Signed annotated <code>v1</code> was moved with an exact guarded lease from tag object
<code>7bd05668153d21c1ac55ac35e8707703e2a6eb0f</code> to
<code>3e44c123d45f5fc06fa437fe1fbd58a71c5aaaa8</code>. It peels to immutable release source
<code>119cbcc7f8d327482df8abfa50a4af0b69fcceee</code>. Repository-local signer-policy verification passes,
and GitHub reports <code>verified: true</code> with reason <code>valid</code> for the new tag object.</p>
<p><a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/33265256940">Final public verification run 33265256940</a>
completed successfully on coordination commit <code>43dbc9bdbe31e994560212d56131f60f956805b7</code>. It verified:</p>
<ul>
<li>the immutable full-SHA Express/Prisma route-security v3 consumer;</li>
<li>the signed <code>v1</code> passive crawl consumer and its authorization-refusal behavior;</li>
<li>GitHub Release checksums, manifest, signed tag and build provenance;</li>
<li>npm package bytes and provenance;</li>
<li>an isolated all-target installer run with GitHub attestation required;</li>
<li>the published moving-alias state.</li>
</ul>
<p>The workflow produced
<a href="https://github.com/parousia8888/web-app-security-skill/releases/download/v0.8.0/web-app-security-skill-0.8.0.live-verification.json"><code>web-app-security-skill-0.8.0.live-verification.json</code></a>
as both a 90-day workflow artifact and durable Release asset. The two downloaded records matched
byte-for-byte with SHA-256
<code>5ff2d022a192ae2d95a805e26464d8e392d3e68d0c91f43fe4ea72887525bead</code>; the record reports
<code>live_verified</code> and all eight public gates as <code>verified</code>.</p>
<p>The expected authorization-refusal probe is visible in the workflow UI as an exit-2 annotation.
The step used <code>continue-on-error</code>, the following assertion required that failure, and the consumer
job concluded successfully. It is negative-test evidence, not an unhandled workflow failure.</p>
<h2 id="public-release-facts">Public release facts</h2>
<ul>
<li>GitHub Release: <a href="https://github.com/parousia8888/web-app-security-skill/releases/tag/v0.8.0">https://github.com/parousia8888/web-app-security-skill/releases/tag/v0.8.0</a></li>
<li>npm: <a href="https://www.npmjs.com/package/web-app-security-skill/v/0.8.0">https://www.npmjs.com/package/web-app-security-skill/v/0.8.0</a></li>
<li>Immutable Action source: <code>119cbcc7f8d327482df8abfa50a4af0b69fcceee</code></li>
<li>Signed <code>v1</code> tag object: <code>3e44c123d45f5fc06fa437fe1fbd58a71c5aaaa8</code></li>
<li>Signed <code>v1</code> source: <code>119cbcc7f8d327482df8abfa50a4af0b69fcceee</code></li>
<li>GitHub signature state: <code>verified: true</code>, reason <code>valid</code></li>
<li>Final combined consumer: <a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/33265256940">https://github.com/parousia8888/web-app-security-skill/actions/runs/33265256940</a></li>
<li>Durable live-verification record: <a href="https://github.com/parousia8888/web-app-security-skill/releases/download/v0.8.0/web-app-security-skill-0.8.0.live-verification.json">https://github.com/parousia8888/web-app-security-skill/releases/download/v0.8.0/web-app-security-skill-0.8.0.live-verification.json</a></li>
</ul>
]]></content:encoded></item><item><title>SkillSeal Agent Skill Linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/skillseal-agent-skill-linter/</link><pubDate>Sat, 29 Aug 2026 21:58:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/skillseal-agent-skill-linter/</guid><description>Version updated for https://github.com/pespinel/SkillSeal to version v0.27.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SkillSeal is a local-first, offline-first CLI tool that lints, scores, and routing-tests SKILL.md files. It catches invalid frontmatter, vague descriptions, oversized files, dangling file references, rm -rf/curl | sh in code blocks, hardcoded paths, OS-specific commands, and more. The action helps identify issues before agents use the skills, ensuring quality and reliability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pespinel/SkillSeal">https://github.com/pespinel/SkillSeal</a></strong> to version <strong>v0.27.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skillseal-agent-skill-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SkillSeal is a local-first, offline-first CLI tool that lints, scores, and routing-tests SKILL.md files. It catches invalid frontmatter, vague descriptions, oversized files, dangling file references, <code>rm -rf</code>/<code>curl | sh</code> in code blocks, hardcoded paths, OS-specific commands, and more. The action helps identify issues before agents use the skills, ensuring quality and reliability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add &ndash;explain-score breakdown of the QUALITY category</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pespinel/SkillSeal/compare/v0.26.2...v0.27.0">https://github.com/pespinel/SkillSeal/compare/v0.26.2...v0.27.0</a></p>
]]></content:encoded></item><item><title>Plori persistent agent review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/plori-persistent-agent-review/</link><pubDate>Sat, 29 Aug 2026 21:57:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/plori-persistent-agent-review/</guid><description>Version updated for https://github.com/plori-ai/agent-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Plori agent action creates a persistent workspace for each repository to analyze pull request commits, inspecting surrounding code and running targeted tests instead of judging a diff in isolation. It automates the process of reviewing code changes without duplicating work across PRs. The action maintains a signed claim link for private repositories or exhausted free quotas, allowing owners to continue reviews after claiming the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plori-ai/agent-action">https://github.com/plori-ai/agent-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/plori-persistent-agent-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Plori agent action creates a persistent workspace for each repository to analyze pull request commits, inspecting surrounding code and running targeted tests instead of judging a diff in isolation. It automates the process of reviewing code changes without duplicating work across PRs. The action maintains a signed claim link for private repositories or exhausted free quotas, allowing owners to continue reviews after claiming the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Persistent remote pull-request review with GitHub Actions OIDC and isolated comment permissions.</p>
]]></content:encoded></item><item><title>Z-AI GLM Code Review Bot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/z-ai-glm-code-review-bot/</link><pubDate>Sat, 29 Aug 2026 21:56:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/z-ai-glm-code-review-bot/</guid><description>Version updated for https://github.com/secondsky/z.ai-code-review-bot to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Z-AI GLM Code Review Bot automates code reviews using AI-driven models, providing inline line-level review comments, deterministic scanners, structured findings with noise caps and severity rankings, and interactive /zai commands. It also offers commit-status feedback and per-path review instructions without editing the workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/secondsky/z.ai-code-review-bot">https://github.com/secondsky/z.ai-code-review-bot</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/z-ai-glm-code-review-bot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Z-AI GLM Code Review Bot automates code reviews using AI-driven models, providing inline line-level review comments, deterministic scanners, structured findings with noise caps and severity rankings, and interactive <code>/zai</code> commands. It also offers commit-status feedback and per-path review instructions without editing the workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Z-AI GLM Code Review Bot v2.0.0 — the Marketplace release of the v2 line, now running on the <strong>Node 24</strong> runtime.</p>
<p>This tag supersedes the original v2.0.0 cut: it moves the tag to current main so <code>@v2.0.0</code>, <code>@v2</code>, and the Marketplace listing all serve the latest audited build — <strong>build <code>31b626c</code> (2026-08-29)</strong>. A floating <code>v2</code> major tag tracks this release.</p>
<h2 id="since-the-original-v200-cut">Since the original v2.0.0 cut</h2>
<h3 id="runtime--tooling">Runtime &amp; tooling</h3>
<ul>
<li><strong>node20 → node24</strong> (<code>runs.using</code>) — Node 20 reached EOL in April 2026 and GitHub Actions forces Node 24 execution. CI now tests Node 22/24.</li>
<li><code>@actions/core</code> pinned to 2.0.3 (core@3 breaks native ESM bundling), actions/checkout &amp; setup-node bumped to v7.</li>
</ul>
<h3 id="review-defaults-2026-08-29-21">Review defaults (2026-08-29, #21)</h3>
<ul>
<li><strong>Default model is now <code>glm-5.3</code></strong> (<code>ZAI_MODEL</code>). <code>glm-5.3-flash</code> works out of the box as the faster/cheaper option — no allowlist, any model name passes through.</li>
<li><strong><code>ZAI_MAX_FINDINGS</code> default raised 8 → 25</strong> (clamp unchanged at [1, 50]; <code>.zai.yml</code> can still only lower the cap).</li>
</ul>
<h3 id="supply-chain--dependency-refresh-2026-08-29-2229">Supply-chain &amp; dependency refresh (2026-08-29, #22–#29)</h3>
<ul>
<li><strong>Workflow hardening (#22, #23):</strong> every CI action SHA-pinned, <code>persist-credentials: false</code>, job timeouts, <code>ubuntu-24.04</code>, concurrency guards, and new <strong>actionlint / zizmor / CodeQL / OSSF Scorecard / Socket</strong> gates — plus a <code>workflow-security</code> policy test that enforces the invariants.</li>
<li><strong>Dependabot 7-day supply-chain cooldown</strong> on npm and GitHub Actions ecosystems (new releases age 7 days before Dependabot proposes them).</li>
<li><strong>Dependency bumps:</strong> <code>actions/upload-artifact</code> v7.0.1, <code>github/codeql-action</code> v4.37.8, vitest family 4.1.11; <code>picomatch</code> and others follow via the cooldown. <code>@actions/core</code> stays deliberately on 2.x.</li>
<li>README quickstart pinned to the audited build SHA (#29).</li>
</ul>
<h3 id="security--correctness-audited-across-14-adversarial-waves-all-fixed-via-tdd">Security &amp; correctness (audited across 14 adversarial waves, all fixed via TDD)</h3>
<ul>
<li><strong>Adversarial audit waves W1–W21</strong> (#8, #12): 170+ bugs fixed across prompt-injection defenses, markdown rendering (CommonMark code spans, nested blockquotes, surrogate pairs), <code>.zai.yml</code> config wiring, scheduling/push parity, and secret redaction.</li>
<li><strong>CodeRabbit follow-up</strong> (#10): 4 findings fixed, including a prompt-injection bypass and an unbounded <code>scheduleMaxPrs</code>.</li>
<li><strong>Feature-tracker audit</strong> (#9): 66 user stories walked, 5 logistical bugs fixed.</li>
<li><strong>Simplification audit</strong> (#13): 20 fixes — 9 drifting duplicate helpers deduped, 2 hardening fixes, plus a real <code>.zai.yml</code> glued-quote parsing bug.</li>
<li><strong>Deferred follow-ups</strong> (#15): key-parity &amp; <code>action.yml</code> drift guards, early-exit pagination, worker pool, status-policy parity.</li>
</ul>
<h3 id="housekeeping">Housekeeping</h3>
<ul>
<li>Version pinned to v2 everywhere (<code>package.json</code> 2.0.0, <code>@v2</code> usage ref), README gains a Marketplace badge and refreshed docs, MIT license field added.</li>
<li>Action renamed to <strong>Z-AI GLM Code Review Bot</strong> — the name &ldquo;Z.ai Code Review&rdquo; was already taken on the Marketplace by the upstream repo.</li>
</ul>
<p><strong>Test suite: 2349 passing. Zero npm audit vulnerabilities.</strong></p>
<hr>
<h3 id="upgrading-from-v1">Upgrading from v1</h3>
<p>See the README for the v2 input table — v2 adds structured findings, inline review comments, deterministic scanners (gitleaks + ast-grep), a walkthrough summary, <code>.zai.yml</code> repo config, and incremental review. All v1 users should carry <code>ZAI_API_KEY</code> unchanged; everything else has sensible defaults.</p>
]]></content:encoded></item><item><title>Next Secure Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/next-secure-check/</link><pubDate>Sat, 29 Aug 2026 21:55:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/next-secure-check/</guid><description>Version updated for https://github.com/SetraTheXX/next-secure-check to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary next-secure-check is a Next.js-focused security checker that provides deterministic findings for common vulnerabilities before deployment. It uses rule-based pattern matching and AST analysis to scan local projects, offering insights into potential security risks without executing repository code or using AI at runtime. This tool helps developers identify and address security issues early in the development process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SetraTheXX/next-secure-check">https://github.com/SetraTheXX/next-secure-check</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/next-secure-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>next-secure-check is a Next.js-focused security checker that provides deterministic findings for common vulnerabilities before deployment. It uses rule-based pattern matching and AST analysis to scan local projects, offering insights into potential security risks without executing repository code or using AI at runtime. This tool helps developers identify and address security issues early in the development process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s changed</h2>
<ul>
<li>The reusable composite Action now invokes the published <a href="mailto:next-secure-check@0.5.0">next-secure-check@0.5.0</a> CLI.</li>
<li>Existing inputs, outputs, summary behavior, SARIF handling, and the @v1 consumer reference remain compatible.</li>
<li>The release follows the v0.5.0 npm publication and the successful security-check workflow.</li>
</ul>
<h2 id="validation">Validation</h2>
<ul>
<li>GitHub Security Check run 33261300291 passed build, typecheck, lint, tests, release gate, security check, and reusable Action smoke.</li>
<li>The four npm packages report version 0.5.0, with next-secure-check latest at 0.5.0.</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/wails3-build-action/</link><pubDate>Sat, 29 Aug 2026 21:54:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the build process for Wails.io v3 projects. It installs GoLang and NodeJS, builds the application, and optionally uploads the results to GitHub or publishes them on a tagged release. The action supports various build options such as obfuscation, platform selection, caching, and package uploading.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the build process for Wails.io v3 projects. It installs GoLang and NodeJS, builds the application, and optionally uploads the results to GitHub or publishes them on a tagged release. The action supports various build options such as obfuscation, platform selection, caching, and package uploading.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>UnityInFlow Spec Compliance</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/unityinflow-spec-compliance/</link><pubDate>Sat, 29 Aug 2026 21:53:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/unityinflow-spec-compliance/</guid><description>Version updated for https://github.com/UnityInFlow/spec-ci-plugin to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The spec-ci-plugin GitHub Action ensures that pull requests adhere to specified guidelines, automating tasks like validating specs, checking for security vulnerabilities, ensuring scope compliance, and verifying acceptance criteria. It posts a structured report as a PR comment when the checks are passed or fails them if there are issues. The action requires a GitHub token and specifies input parameters such as the spec file path and how to handle errors.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/UnityInFlow/spec-ci-plugin">https://github.com/UnityInFlow/spec-ci-plugin</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/unityinflow-spec-compliance">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The spec-ci-plugin GitHub Action ensures that pull requests adhere to specified guidelines, automating tasks like validating specs, checking for security vulnerabilities, ensuring scope compliance, and verifying acceptance criteria. It posts a structured report as a PR comment when the checks are passed or fails them if there are issues. The action requires a GitHub token and specifies input parameters such as the spec file path and how to handle errors.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release whose purpose is to <strong>move the <code>v1</code> tag</strong> onto the injection-scanner <code>v0.1.0</code> default.</p>
<h2 id="what-changed">What changed</h2>
<p>Only the default value of the <code>injection-scanner-version</code> input: <code>v0.0.3</code> → <code>v0.1.0</code>. No input,
output, or behaviour of this Action changed.</p>
<h2 id="why-it-matters">Why it matters</h2>
<p>The scanner this Action runs got substantially better, and <code>@v1</code> consumers were not getting it.</p>
<table>
  <thead>
      <tr>
          <th></th>
          <th>injection-scanner v0.0.3</th>
          <th>injection-scanner v0.1.0</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Measured detection recall</td>
          <td><strong>10/60</strong></td>
          <td><strong>56/60</strong></td>
      </tr>
  </tbody>
</table>
<p>Four of the five attack categories were rewritten from lists of literal phrases into
verb × modifier × object matrices. Before, a paraphrased payload walked straight past — which made
this Action&rsquo;s PR gate substantially weaker than it looked. Recall is measured against a corpus
written from the threat model rather than derived from the scanner&rsquo;s own patterns, and is pinned
by tests upstream.</p>
<h2 id="upgrading">Upgrading</h2>
<p>Nothing to do if you pin <code>@v1</code> — this release moves that tag for you.</p>
<p>If you pin an immutable tag, move to <code>@v1.1.1</code>. If you pin <code>injection-scanner-version</code> explicitly,
set it to <code>v0.1.0</code> to pick up the detection work.</p>
<p>See <a href="https://github.com/UnityInFlow/injection-scanner/releases/tag/v0.1.0">injection-scanner v0.1.0</a>.</p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/vibgrate-scan/</link><pubDate>Sat, 29 Aug 2026 21:52:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.829.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of VIBGrate CLI command documentation, generating markdown files based on a template and JSON data. It simplifies the process of documenting command options, descriptions, and examples by rendering them directly from a JSON file structure. This is particularly useful for developers who need to maintain comprehensive documentation without manual intervention.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.829.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of VIBGrate CLI command documentation, generating markdown files based on a template and JSON data. It simplifies the process of documenting command options, descriptions, and examples by rendering them directly from a JSON file structure. This is particularly useful for developers who need to maintain comprehensive documentation without manual intervention.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268291">Vibgrate CLI 2026.829.1</h1>
<p><em>Released 2026-08-29</em></p>
<p>This release of the Vibgrate CLI includes important fixes and a new feature for improved architecture classification reporting. Users can expect enhanced accuracy in handling existing imports and better insights into unclassified files.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li><code>vg scan</code> now reports architecture classification coverage, detailing the share of source files with layers and identifying directories containing unclassified files.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>vg review</code> now correctly treats an existing import as occupancy, preventing failures due to typos in handlers that have already called a repository.</li>
<li>VG Code on a local Spark model no longer stalls on <code>search_symbols</code>, and project AGENTS.md MCP names now run as <code>search_code</code> / graph tools.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.826.1, interleaved on one runner against the pinned corpus (187 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>22212 count</td>
          <td>22212 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>12188 count</td>
          <td>12188 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.94 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>745.30 ms</td>
          <td>756.90 ms</td>
      </tr>
  </tbody>
</table>
<p>2 regression(s) — published, not omitted:</p>
<ul>
<li>Token reduction vs baseline agent (equal success): 0.22 → 0.20 (-9.2%)</li>
<li>Agent tokens with vg (comparable tasks, total): 562247 → 620882 (10.4%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.829.1">https://vibgrate.com/changelog/cli/2026.829.1</a></p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/rustscript-action/</link><pubDate>Sat, 29 Aug 2026 21:50:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.6.16.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that allows users to write helper scripts in Rust and run them as shell scripts, with no compile step. It interprets a practical subset of the language and validates files with real rustc. The action supports features like functions, closures, structs, enums, patterns, loops, iterators, collections, and more. It also bridges the std library and some external crates for additional functionality.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.6.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a tool that allows users to write helper scripts in Rust and run them as shell scripts, with no compile step. It interprets a practical subset of the language and validates files with real <code>rustc</code>. The action supports features like functions, closures, structs, enums, patterns, loops, iterators, collections, and more. It also bridges the std library and some external crates for additional functionality.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.6.15...v0.6.16">https://github.com/VladasZ/rustscript/compare/v0.6.15...v0.6.16</a></p>
]]></content:encoded></item><item><title>Apex Test List</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/apex-test-list/</link><pubDate>Sat, 29 Aug 2026 21:49:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/apex-test-list/</guid><description>Version updated for https://github.com/wisefoxme/apex-test-list to version v1.14.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Apex Test List GitHub Action generates a list of tests that should be run, enabling users to automate and save time by skipping tests not relevant to their automated processes. It supports identifying tests using Apex annotations or a centralized metadata filter, simplifying the process of managing test dependencies in Salesforce environments. The action is available as both a Salesforce CLI plugin and a native GitHub Action for GitHub Actions users.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wisefoxme/apex-test-list">https://github.com/wisefoxme/apex-test-list</a></strong> to version <strong>v1.14.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/apex-test-list">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Apex Test List GitHub Action generates a list of tests that should be run, enabling users to automate and save time by skipping tests not relevant to their automated processes. It supports identifying tests using Apex annotations or a centralized metadata filter, simplifying the process of managing test dependencies in Salesforce environments. The action is available as both a Salesforce CLI plugin and a native GitHub Action for GitHub Actions users.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1142-2026-08-29"><a href="https://github.com/wisefoxme/apex-test-list/compare/v1.14.1...v1.14.2">1.14.2</a> (2026-08-29)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> bump the salesforce group with 2 updates (<a href="https://github.com/wisefoxme/apex-test-list/issues/404">#404</a>) (<a href="https://github.com/wisefoxme/apex-test-list/commit/acf6e106b125b4bb5250f42b0fc31011b4ed6052">acf6e10</a>)</li>
</ul>
]]></content:encoded></item><item><title>Sigil Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/sigil-security-scan/</link><pubDate>Sat, 29 Aug 2026 14:10:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/sigil-security-scan/</guid><description>Version updated for https://github.com/NOMARJ/sigil to version v1.3.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sigil automates the security auditing of AI agent code before it reaches working environments. It scans repositories, packages, and tools for malicious patterns, including intentional malicious code. The action fills a gap by implementing a quarantine-first approach to protect developers from inadvertently deploying potentially harmful code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NOMARJ/sigil">https://github.com/NOMARJ/sigil</a></strong> to version <strong>v1.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sigil-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sigil automates the security auditing of AI agent code before it reaches working environments. It scans repositories, packages, and tools for malicious patterns, including intentional malicious code. The action fills a gap by implementing a quarantine-first approach to protect developers from inadvertently deploying potentially harmful code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix(release): build linux-arm64 natively on the arm runner; bump 1.3.2 (#144) (d518086)</li>
<li>fix(release): vendor OpenSSL for aarch64-linux cross build; bump 1.3.1 (#143) (3c39f10)</li>
<li>fix(api): add sentry-sdk to requirements.lock so the image actually has it (#142) (3058497)</li>
<li>fix(deploy): roll container apps directly after image push (#141) (64e44b6)</li>
<li>chore(NOM-616): mark brief complete, record DONE in progress.md (#129) (b504325)</li>
<li>fix(deps): patch HIGH OSV advisories in dashboard and plugin lockfiles (#140) (dc7e683)</li>
<li>fix(launch): remove Stripe IDs, true-up privacy claims, honest FP framing (#139) (61306ae)</li>
<li>feat(docs): complete deployment and rollback runbooks (LAUNCH-005) (#134) (0f73627)</li>
<li>fix(NOM-615): drain stale cursor before rollback in _MssqlStore.upsert (#135) (29557f9)</li>
<li>feat(billing): test-mode Stripe webhook support (NOM-884 US-003) (#136) (6afd0e8)</li>
</ul>
]]></content:encoded></item><item><title>Nox Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/nox-security-scanner/</link><pubDate>Sat, 29 Aug 2026 14:09:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/nox-security-scanner/</guid><description>Version updated for https://github.com/Nox-HQ/nox to version v1.31.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Nox is an open-source static analysis tool designed to identify and prevent security vulnerabilities in AI applications. It analyzes code offline and does not rely on APIs or external services, ensuring determinism and privacy. Nox can detect issues such as prompt injection, embedding leakage, agent over-privilege, and more, covering OWASP Top 10, MCP Top 10, and other security aspects related to AI applications. It provides a comprehensive inventory of all model invocations, auth environment variables, and endpoints for multi-language projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nox-HQ/nox">https://github.com/Nox-HQ/nox</a></strong> to version <strong>v1.31.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nox-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Nox is an open-source static analysis tool designed to identify and prevent security vulnerabilities in AI applications. It analyzes code offline and does not rely on APIs or external services, ensuring determinism and privacy. Nox can detect issues such as prompt injection, embedding leakage, agent over-privilege, and more, covering OWASP Top 10, MCP Top 10, and other security aspects related to AI applications. It provides a comprehensive inventory of all model invocations, auth environment variables, and endpoints for multi-language projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="nox-v1310-2026-08-29t105916z">Nox v1.31.0 (2026-08-29T10:59:16Z)</h2>
<p>Language-agnostic security scanner with first-class AI application security.</p>
<h3 id="installation">Installation</h3>
<h4 id="macoslinux-homebrew">macOS/Linux (Homebrew)</h4>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap felixgeelhaar/tap
</span></span><span style="display:flex;"><span>brew install nox
</span></span></code></pre></div><h4 id="direct-download">Direct Download</h4>
<p>Download the appropriate archive for your platform from the assets below.</p>
<h3 id="whats-changed-1">What&rsquo;s Changed</h3>
<h2 id="changelog">Changelog</h2>
<h3 id="features">Features</h3>
<ul>
<li>7172305a11f8f00e0f8eb53cb46a50fd6ff80169 feat(intel): enrol an operator&rsquo;s second factor from the CLI (#490)</li>
<li>703b105ec9841a067c16f49fd7bf46ab3615748c feat(vulnsource): superset model with verifiable non-suppression (#478)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>cc304dfef2de32c10369e080325a667cd8faa579 fix(cli): scan &ndash;help shows the flags that make it emit an SBOM (#492)</li>
</ul>
<h3 id="refactoring">Refactoring</h3>
<ul>
<li>80d0f4a7526f57c7a18856c7438ac1e698ba8f83 refactor: move the shared kernel out to nox-core (#485)</li>
</ul>
<h3 id="others">Others</h3>
<ul>
<li>f8dc9ac9adf3e09e56645e3ad0046f6d4195c770 build: warden gate for nox (#486)</li>
<li>8b00e6c4a3dcbb3ef9fcda5e32ad1812bf8f9d76 docs(changelog): 1.31.0, and let nox run its own secret check (#487)</li>
<li>34b37a31efe5eb37aeed015ec1ec3d394b8fe255 docs(changelog): the two help fixes that shipped in 1.31.0 (#495)</li>
<li>8e24156a6d9ef3f22fcd9a384342624f14bb3b1d docs(vex): describe &ndash;product as what OpenVEX actually takes (#491)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nox-hq/nox/compare/v1.30.1...v1.31.0">https://github.com/nox-hq/nox/compare/v1.30.1...v1.31.0</a></p>
]]></content:encoded></item><item><title>Full-site SEO Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/full-site-seo-audit/</link><pubDate>Sat, 29 Aug 2026 14:08:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/full-site-seo-audit/</guid><description>Version updated for https://github.com/nurkamol/seo-audit to version v1.37.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action nurkamol/seo-audit automates the SEO audit of a website by crawling its sitemap and checking every page for metadata, structured data, and other SEO issues that single-page graders might miss. It provides zero dependencies, is one command to use, and works in CI environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nurkamol/seo-audit">https://github.com/nurkamol/seo-audit</a></strong> to version <strong>v1.37.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/full-site-seo-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>nurkamol/seo-audit</code> automates the SEO audit of a website by crawling its sitemap and checking every page for metadata, structured data, and other SEO issues that single-page graders might miss. It provides zero dependencies, is one command to use, and works in CI environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>The Raycast extension can ask Search Console.</strong> The engine has had
<code>--search-console</code> since 1.21.0 and the extension never exposed it — a
launcher showing every finding except the one number that is not a proxy for
attention. A checkbox switches it on and a field names the property, the same
shape the flag has: bare means the site being crawled, a value names a
property.</p>
<p>It does not ask for credentials. Getting them opens a browser and writes a
file, which is a terminal errand rather than a control in a window — the same
answer the macOS app gives. Without them the engine reports
<code>search-console-unconfigured</code> and names what is missing, so this fails in the
report rather than going quiet.</p>
<p>Checked in both directions, because both failures are silent: a preference
the code reads and the manifest never declares is a control nobody can reach,
and one declared but never read is a control that does nothing.</p>
</li>
<li>
<p><strong><code>--reports</code> lists the runs kept on this machine</strong>, and <code>--reports 2026-08-01</code> lists what was kept since. The library was reachable from the
macOS window and the served list and from nowhere on the command line, which
is the one place the rest of this tool lives. <code>/reports</code> gains the same filter
as a date control, and both call one function so the browser and the terminal
cannot disagree about what &ldquo;since&rdquo; means.</p>
<p>That function is not in <code>src/library.mjs</code>. That module opens files, so it
imports <code>node:fs</code>, and the Worker showing the same list has no filesystem and
would not have survived the import — <code>src/kept.mjs</code> is the pure half both
sides need.</p>
<p>A date it cannot read is refused rather than ignored, because listing every
run when somebody asked for one week looks like an answer. A date that hides
everything says how many it hid, since an empty list and an empty library read
identically and only one of them means &ldquo;widen the date&rdquo;.</p>
</li>
<li>
<p><strong>A check that fires on every page is one thing to change, not one per
section.</strong> Grouping by URL prefix is right when a check hits part of a site —
that is the Shopify <code>/products/</code> insight this project&rsquo;s grouping was built on
— and wrong when it hits all of it. gohugo.io produced <strong>200 things to change
and 104 of them were four checks that each applied to all 150 pages</strong>;
<code>canonical-missing</code> alone arrived as twenty-six separate pieces of work, one
per prefix, making the reader do the arithmetic that tells them it was
site-wide. The same report is now 100 things to change, and those four read
<code>every page crawled (150), 1,695 links in</code>.</p>
<p>Exactly every page, never nearly. On 149 of 150 &ldquo;every page&rdquo; is a false
sentence, and a report is only worth reading because its sentences are true.
It costs no extra requests — the grouping was already computed.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>&ldquo;1 image(s) without width/height&rdquo;</strong> was the most repeated finding title in a
real report and read like a form nobody finished. Fifty of these across seven
files now pick the right word. Zero is plural, which is the case that gets
written wrong by reaching for <code>n &gt; 1</code>.</p>
</li>
<li>
<p><strong>&ldquo;1 links in&rdquo;</strong> — the same defect one line further on, hardcoded rather than
spelled <code>(s)</code>, so no search for the first would have found it. It had been
shipping for as long as reach has been reported, and no fixture ever had
exactly one inbound link. Found by running the tool against a real site and
reading the output, which is the only way anything here has ever been found.</p>
</li>
<li>
<p><strong>A PDF&rsquo;s section headings could be left alone at the foot of a page</strong>, with
the findings they introduce overleaf. A cause block listing every affected
page can be most of a page tall, so a heading placed just before one had
nowhere to go — the packer was greedy and had no keep-with-next rule. Three
of the 53 pages in a gohugo.io export ended that way: <code>Content 79</code>,
<code>Indexability 26</code>, <code>Images 52</code>.</p>
<p>A heading now travels with the block it introduces. <code>PDF.paginate</code> came out
of <code>write</code> to make it testable without a renderer, because the bug is
arithmetic rather than drawing — including the cases that must <em>not</em> move a
heading, and the one where a page holds nothing but headings and must not be
emitted blank.</p>
<p>It does not make the document shorter, and the page count is unchanged at 53.
The white space above a page break comes from cause blocks being atomic and
nearly page-tall; only splitting them would reclaim it, and a finding split
across a page break is worse than a short page.</p>
</li>
</ul>
<hr>
<h3 id="installing-on-macos">Installing on macOS</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap nurkamol/seo-audit https://github.com/nurkamol/seo-audit
</span></span><span style="display:flex;"><span>brew trust nurkamol/seo-audit
</span></span><span style="display:flex;"><span>brew install --cask seo-audit
</span></span></code></pre></div><p>Homebrew verifies the download against the checksum below and clears the
quarantine flag for you, so the app opens the first time.</p>
<p><strong>Downloading the zip instead?</strong> macOS may say <em>&ldquo;SEO Audit is damaged and
can&rsquo;t be opened.&rdquo;</em> It is not damaged. The app is ad-hoc signed rather than
notarised — notarising needs a paid Apple Developer account this project
does not have — and macOS refuses quarantined apps without a notarisation
ticket. Check what you downloaded first:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>shasum -a <span style="color:#ae81ff">256</span> seo-audit-1.37.0-macos.zip
</span></span><span style="display:flex;"><span><span style="color:#75715e"># a350802df8f5f4bdf808909aab22a88d5313d1b3ffd50c543f41e8d8545fc2bb</span>
</span></span></code></pre></div><p>Then, once it matches, clear the flag — no <code>sudo</code> needed:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>xattr -dr com.apple.quarantine <span style="color:#e6db74">&#34;/Applications/SEO Audit.app&#34;</span>
</span></span></code></pre></div><p>That is what right-click → <strong>Open</strong> does in the Finder, without the dialog.
Apple Silicon, macOS Tahoe or newer.</p>
<h3 id="windows-and-linux">Windows and Linux</h3>
<p>The <code>setup.exe</code>, <code>.deb</code> and <code>.AppImage</code> below are attached by a separate
job and may appear a few minutes after this release does.</p>
<p>The Windows installer is unsigned, so SmartScreen shows <em>&ldquo;Windows protected
your PC&rdquo;</em> — <strong>More info → Run anyway</strong>. Same reason as macOS: a code-signing
certificate is a paid, per-year thing this project does not have. The
<code>.AppImage</code> needs <code>chmod +x</code> before it will run.</p>
<p>Check any of them first. A <code>SHA256SUMS.txt</code> covering every file here is
attached alongside them, and the same checksums are listed at the end of
these notes:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>shasum -a <span style="color:#ae81ff">256</span> --ignore-missing -c SHA256SUMS.txt
</span></span></code></pre></div><h3 id="checksums">Checksums</h3>
<p>Verify a download before you wave a warning away. With <code>SHA256SUMS.txt</code>
saved beside the file, in the same folder:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>shasum -a <span style="color:#ae81ff">256</span> --ignore-missing -c SHA256SUMS.txt
</span></span></code></pre></div><pre tabindex="0"><code>8e4e289a09f72481a476afcd194af08395b22966f801510db8a75fd5f70e3fd2  SEO.Audit_1.37.0_amd64.AppImage
649b24e6c2434637061bc6e103f4c85c8f067da3bdad33f94baa29f12cbb1bcd  SEO.Audit_1.37.0_amd64.deb
a8b061f31ffd6f39a4492de1ab6d4a0dcbd882491eb44044a50836ab8691a8e4  SEO.Audit_1.37.0_x64-setup.exe
a350802df8f5f4bdf808909aab22a88d5313d1b3ffd50c543f41e8d8545fc2bb  seo-audit-1.37.0-macos.zip
</code></pre><p>The macOS line appears twice in these notes on purpose: once above, computed
when the app was built, and once here, computed from what is actually attached.
They should agree.</p>
]]></content:encoded></item><item><title>Changelog Bot Runner Nyaomaru</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/changelog-bot-runner-nyaomaru/</link><pubDate>Sat, 29 Aug 2026 14:07:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/changelog-bot-runner-nyaomaru/</guid><description>Version updated for https://github.com/nyaomaru/changelog-bot to version v0.6.12.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, @nyaomaru/changelog-bot, automates the creation of polished changelog entries based on commit history, pull request titles, and release notes. It can also use AI models to enhance the tone and clarity of the changelog. The action supports various options for customization, including LLM integration and PR readiness.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nyaomaru/changelog-bot">https://github.com/nyaomaru/changelog-bot</a></strong> to version <strong>v0.6.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/changelog-bot-runner-nyaomaru">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>@nyaomaru/changelog-bot</code>, automates the creation of polished changelog entries based on commit history, pull request titles, and release notes. It can also use AI models to enhance the tone and clarity of the changelog. The action supports various options for customization, including LLM integration and PR readiness.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: upgrade TypeScript 7 and dependencies by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/184">https://github.com/nyaomaru/changelog-bot/pull/184</a></li>
<li>docs(changelog): 0.6.11 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/183">https://github.com/nyaomaru/changelog-bot/pull/183</a></li>
<li>refactor: separate changelog run phase by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/185">https://github.com/nyaomaru/changelog-bot/pull/185</a></li>
<li>chore: update dependencies by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/186">https://github.com/nyaomaru/changelog-bot/pull/186</a></li>
<li>Release: 0.6.12 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/187">https://github.com/nyaomaru/changelog-bot/pull/187</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nyaomaru/changelog-bot/compare/v0.6.11...v0.6.12">https://github.com/nyaomaru/changelog-bot/compare/v0.6.11...v0.6.12</a></p>
]]></content:encoded></item><item><title>Setup Slipshow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/setup-slipshow/</link><pubDate>Sat, 29 Aug 2026 14:06:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/setup-slipshow/</guid><description>Version updated for https://github.com/panglesd/setup-slipshow to version 1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-slipshow GitHub Action installs the slipshow presentation tool in the action environment, supporting macOS and Linux runners. It allows users to automate the installation of specific versions of slipshow using the version input parameter, defaulting to the latest version if omitted. The action is useful for CI/CD pipelines where slipshow presentations need to be compiled and published to GitHub Pages.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/panglesd/setup-slipshow">https://github.com/panglesd/setup-slipshow</a></strong> to version <strong>1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-slipshow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>setup-slipshow</code> GitHub Action installs the slipshow presentation tool in the action environment, supporting macOS and Linux runners. It allows users to automate the installation of specific versions of slipshow using the <code>version</code> input parameter, defaulting to the latest version if omitted. The action is useful for CI/CD pipelines where slipshow presentations need to be compiled and published to GitHub Pages.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release.</p>
]]></content:encoded></item><item><title>SkillSeal Agent Skill Linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/skillseal-agent-skill-linter/</link><pubDate>Sat, 29 Aug 2026 14:05:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/skillseal-agent-skill-linter/</guid><description>Version updated for https://github.com/pespinel/SkillSeal to version v0.23.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SkillSeal is a CLI tool that lints, scores, and routing-tests SKILL.md files for best practices. It catches issues such as invalid frontmatter, vague descriptions, oversized files, dangling file references, hardcoded paths, OS-specific commands, and more before an agent can execute the skill.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pespinel/SkillSeal">https://github.com/pespinel/SkillSeal</a></strong> to version <strong>v0.23.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skillseal-agent-skill-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SkillSeal is a CLI tool that lints, scores, and routing-tests <code>SKILL.md</code> files for best practices. It catches issues such as invalid frontmatter, vague descriptions, oversized files, dangling file references, hardcoded paths, OS-specific commands, and more before an agent can execute the skill.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix(quality): don&rsquo;t flag markdown links inside code spans as dangling</li>
<li>fix(metadata): recognize Claude Code&rsquo;s documented frontmatter extensions</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pespinel/SkillSeal/compare/v0.22.0...v0.23.0">https://github.com/pespinel/SkillSeal/compare/v0.22.0...v0.23.0</a></p>
]]></content:encoded></item><item><title>Agent Spec Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/agent-spec-guard/</link><pubDate>Sat, 29 Aug 2026 14:05:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/agent-spec-guard/</guid><description>Version updated for https://github.com/pmcostadev/spec-forge-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks that key development context files exist, are more than a placeholder, and fit within the targeted context window. It fails builds when specs do not meet these criteria, ensuring that coding agents have comprehensive context for their tasks. The action supports customizing spec files, paths, and other settings to suit different development workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pmcostadev/spec-forge-action">https://github.com/pmcostadev/spec-forge-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-spec-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks that key development context files exist, are more than a placeholder, and fit within the targeted context window. It fails builds when specs do not meet these criteria, ensuring that coding agents have comprehensive context for their tasks. The action supports customizing spec files, paths, and other settings to suit different development workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release.</p>
<p>Checks that your AI-agent spec files exist, are more than a stub, and fit
inside the context window you are targeting.</p>
<ul>
<li>Verifies PRD.md, ARCHITECTURE.md and DESIGN.md by default, or any file list you pass</li>
<li>Flags specs below a word-count threshold as stubs</li>
<li>Estimates the combined token count and warns when you go over budget</li>
<li>Writes a report to the job summary, and optionally comments on the pull request</li>
<li>Fails the build on a missing or hollow spec, or set fail-on-missing to false to report only</li>
</ul>
<p>Composite action, no Node build step.</p>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-api-onboarding/</link><pubDate>Sat, 29 Aug 2026 14:04:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v3.5.9.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the onboarding of a new API repository by generating and executing test cases, enforcing contracts, and linking insights. It streamlines the process by creating a service account token and team ID using Postman Onboarding: Service Token, then feeding these outputs into this composite action. The action supports workspace creation, OpenAPI upload, collection generation, repository artifact sync, built-in smoke and contract runs, and optional Postman Insights linking.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v3.5.9</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the onboarding of a new API repository by generating and executing test cases, enforcing contracts, and linking insights. It streamlines the process by creating a service account token and team ID using Postman Onboarding: Service Token, then feeding these outputs into this composite action. The action supports workspace creation, OpenAPI upload, collection generation, repository artifact sync, built-in smoke and contract runs, and optional Postman Insights linking.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/91">https://github.com/postman-cs/postman-api-onboarding-action/pull/91</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/92">https://github.com/postman-cs/postman-api-onboarding-action/pull/92</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/93">https://github.com/postman-cs/postman-api-onboarding-action/pull/93</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/94">https://github.com/postman-cs/postman-api-onboarding-action/pull/94</a></li>
<li>chore(deps): pin Insights onboarding v2.2.1 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/95">https://github.com/postman-cs/postman-api-onboarding-action/pull/95</a></li>
<li>fix: consume Insights human-session normalization by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/96">https://github.com/postman-cs/postman-api-onboarding-action/pull/96</a></li>
<li>fix: consume repo-sync v2.2.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/97">https://github.com/postman-cs/postman-api-onboarding-action/pull/97</a></li>
<li>fix: expose mock environment and refresh Azure pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/98">https://github.com/postman-cs/postman-api-onboarding-action/pull/98</a></li>
<li>feat: pass mock visibility policy through to repo-sync by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/99">https://github.com/postman-cs/postman-api-onboarding-action/pull/99</a></li>
<li>chore: pin repo-sync v2.4.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/100">https://github.com/postman-cs/postman-api-onboarding-action/pull/100</a></li>
<li>fix: document private mock credential paths for consumers by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/101">https://github.com/postman-cs/postman-api-onboarding-action/pull/101</a></li>
<li>fix(deps): advance the bootstrap pin to v2.13.2 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/102">https://github.com/postman-cs/postman-api-onboarding-action/pull/102</a></li>
<li>fix(deps): advance bootstrap and repo-sync pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/103">https://github.com/postman-cs/postman-api-onboarding-action/pull/103</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/104">https://github.com/postman-cs/postman-api-onboarding-action/pull/104</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.8 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/105">https://github.com/postman-cs/postman-api-onboarding-action/pull/105</a></li>
<li>fix(deps): advance bootstrap pin to v2.13.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/106">https://github.com/postman-cs/postman-api-onboarding-action/pull/106</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>fix(ci): validate sibling pins without local checkouts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/111">https://github.com/postman-cs/postman-api-onboarding-action/pull/111</a></li>
<li>feat(azure-devops): forward an explicit workspace squad id from the Windows template by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/112">https://github.com/postman-cs/postman-api-onboarding-action/pull/112</a></li>
<li>fix(release): harden composite pin and E2E releases by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/113">https://github.com/postman-cs/postman-api-onboarding-action/pull/113</a></li>
<li>fix(release): supersede stale aliases with pending cuts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/114">https://github.com/postman-cs/postman-api-onboarding-action/pull/114</a></li>
<li>fix(release): wait for correlated E2E run names by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/115">https://github.com/postman-cs/postman-api-onboarding-action/pull/115</a></li>
<li>fix(release): keep pin ratchet synchronized by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/116">https://github.com/postman-cs/postman-api-onboarding-action/pull/116</a></li>
<li>fix(ci): preserve pin updater test fixtures by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/117">https://github.com/postman-cs/postman-api-onboarding-action/pull/117</a></li>
<li>fix(release): reconcile failed release completions by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/118">https://github.com/postman-cs/postman-api-onboarding-action/pull/118</a></li>
<li>fix(release): emit automated completion events by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/119">https://github.com/postman-cs/postman-api-onboarding-action/pull/119</a></li>
<li>fix(release): bound failed release recovery by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/120">https://github.com/postman-cs/postman-api-onboarding-action/pull/120</a></li>
<li>fix(release): hold auto release through E2E completion by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/121">https://github.com/postman-cs/postman-api-onboarding-action/pull/121</a></li>
<li>feat: expose spec-only onboarding scope by @sean-riney in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/123">https://github.com/postman-cs/postman-api-onboarding-action/pull/123</a></li>
<li>docs: add service-account workspace permission preflight by @andrewpostymt in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/122">https://github.com/postman-cs/postman-api-onboarding-action/pull/122</a></li>
<li>chore(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/108">https://github.com/postman-cs/postman-api-onboarding-action/pull/108</a></li>
<li>fix(ci): make cache pin assertion semantic by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/124">https://github.com/postman-cs/postman-api-onboarding-action/pull/124</a></li>
<li>chore(deps): bump actions/cache from 4.2.0 to 6.1.0 in the actions group across 1 directory by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/109">https://github.com/postman-cs/postman-api-onboarding-action/pull/109</a></li>
<li>feat: publish as @postman/onboarding-api with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/127">https://github.com/postman-cs/postman-api-onboarding-action/pull/127</a></li>
<li>fix(release): gate alias advance on npm publish output, not job result by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/128">https://github.com/postman-cs/postman-api-onboarding-action/pull/128</a></li>
<li>fix(release): keep alias gates on publish job result by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/129">https://github.com/postman-cs/postman-api-onboarding-action/pull/129</a></li>
<li>feat: add monorepo working-directory by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/130">https://github.com/postman-cs/postman-api-onboarding-action/pull/130</a></li>
<li>fix(release): require pull requests for pin advances by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/131">https://github.com/postman-cs/postman-api-onboarding-action/pull/131</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @postman-suite-pin-bot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/134">https://github.com/postman-cs/postman-api-onboarding-action/pull/134</a></li>
<li>chore: ignore local plans by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/139">https://github.com/postman-cs/postman-api-onboarding-action/pull/139</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @postman-suite-pin-bot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/142">https://github.com/postman-cs/postman-api-onboarding-action/pull/142</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @postman-suite-pin-bot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/143">https://github.com/postman-cs/postman-api-onboarding-action/pull/143</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @postman-suite-pin-bot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/144">https://github.com/postman-cs/postman-api-onboarding-action/pull/144</a></li>
<li>fix(security): harden workflow trust boundaries by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/145">https://github.com/postman-cs/postman-api-onboarding-action/pull/145</a></li>
<li>fix(security): harden onboarding and release boundaries by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/149">https://github.com/postman-cs/postman-api-onboarding-action/pull/149</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@github-actions[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>@andrewpostymt made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/122">https://github.com/postman-cs/postman-api-onboarding-action/pull/122</a></li>
<li>@postman-suite-pin-bot[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/134">https://github.com/postman-cs/postman-api-onboarding-action/pull/134</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.5.9">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.5.9</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Azure Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-azure-spec-discovery/</link><pubDate>Sat, 29 Aug 2026 14:03:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-azure-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-azure-spec-discovery-action to version v1.5.5.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Azure Spec Discovery GitHub Action automates the discovery and export of API specifications from Azure services using only existing Azure credentials. It solves the problem of integrating Azure APIs into Postman onboarding by automatically discovering, ranking, and exporting OpenAPI or AsyncAPI specifications based on the provider’s access levels, environment variables, or committed .postman bindings. The action supports a variety of Azure providers and provides a six-tier narrowing pipeline to resolve API specs efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-azure-spec-discovery-action">https://github.com/postman-cs/postman-azure-spec-discovery-action</a></strong> to version <strong>v1.5.5</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-azure-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Azure Spec Discovery GitHub Action automates the discovery and export of API specifications from Azure services using only existing Azure credentials. It solves the problem of integrating Azure APIs into Postman onboarding by automatically discovering, ranking, and exporting OpenAPI or AsyncAPI specifications based on the provider&rsquo;s access levels, environment variables, or committed <code>.postman</code> bindings. The action supports a variety of Azure providers and provides a six-tier narrowing pipeline to resolve API specs efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/15">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/15</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/18">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/18</a></li>
<li>fix(test): assert the packaged version against package.json by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/19">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/19</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/20">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/20</a></li>
<li>fix(release): fetch the tag parent before ancestry checks by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/21">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/21</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/22">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/22</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/23">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/23</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/24">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/24</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/26">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/26</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/28">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/28</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/29">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/29</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/30">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/30</a></li>
<li>fix(ci): address Codex writeback feedback by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/31">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/31</a></li>
<li>fix(ci): use ESM execSync and update permission test by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/32">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/32</a></li>
<li>test(windows): preserve gate timing under contention by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/34">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/34</a></li>
<li>feat: publish as @postman/onboarding-azure-spec-discovery with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/38">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/38</a></li>
<li>fix(release): gate aliases on npm publish output and retry registry r… by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/39">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/39</a></li>
<li>fix(release): size registry read-back window to measured propagation delay by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/40">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/40</a></li>
<li>fix(release): keep alias gates on publish job result by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/41">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/41</a></li>
<li>fix(deps): migrate automation core scope by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/42">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/42</a></li>
<li>chore: ignore local plans by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/44">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/44</a></li>
<li>fix(security): harden spec processing boundaries by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/45">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/45</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@pavan-nelakuditi made their first contribution in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/39">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/39</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/compare/v1.3.5...v1.5.5">https://github.com/postman-cs/postman-azure-spec-discovery-action/compare/v1.3.5...v1.5.5</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-workspace-bootstrap/</link><pubDate>Sat, 29 Aug 2026 14:03:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.21.10.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of a Postman workspace from an OpenAPI specification. It generates baseline, smoke, and contract collections with executable contract tests, covering various protocols like gRPC, SOAP, GraphQL, AsyncAPI, and MCP. The action is part of the Postman API Onboarding suite and uses credentials to access and interact with Postman’s services.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.21.10</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of a Postman workspace from an OpenAPI specification. It generates baseline, smoke, and contract collections with executable contract tests, covering various protocols like gRPC, SOAP, GraphQL, AsyncAPI, and MCP. The action is part of the Postman API Onboarding suite and uses credentials to access and interact with Postman&rsquo;s services.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: normalize multifile receipt after v2.21.2 by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/218">https://github.com/postman-cs/postman-bootstrap-action/pull/218</a></li>
<li>chore: ignore local plans by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/220">https://github.com/postman-cs/postman-bootstrap-action/pull/220</a></li>
<li>chore: rebind multifile receipt to source by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/221">https://github.com/postman-cs/postman-bootstrap-action/pull/221</a></li>
<li>fix(security): harden untrusted input boundaries by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/222">https://github.com/postman-cs/postman-bootstrap-action/pull/222</a></li>
<li>fix(preview): stabilize concurrent collection markers by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/224">https://github.com/postman-cs/postman-bootstrap-action/pull/224</a></li>
<li>fix(release): refresh E2E registry revision by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/225">https://github.com/postman-cs/postman-bootstrap-action/pull/225</a></li>
<li>fix(import): eliminate rename finalization writes by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/226">https://github.com/postman-cs/postman-bootstrap-action/pull/226</a></li>
<li>fix(collections): converge concurrent imports safely by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/227">https://github.com/postman-cs/postman-bootstrap-action/pull/227</a></li>
<li>fix: prove atomic collection writes via sync receipts by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/228">https://github.com/postman-cs/postman-bootstrap-action/pull/228</a></li>
<li>fix(collections): replace export preflight with sync snapshots by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/229">https://github.com/postman-cs/postman-bootstrap-action/pull/229</a></li>
<li>fix(release): pin repo-sync populated snapshots by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/230">https://github.com/postman-cs/postman-bootstrap-action/pull/230</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2.21.2...v2.21.10">https://github.com/postman-cs/postman-bootstrap-action/compare/v2.21.2...v2.21.10</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-repo-sync/</link><pubDate>Sat, 29 Aug 2026 14:02:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.10.9.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of exporting Postman collections, environments, and monitoring configurations into a repository. It helps streamline API development by integrating CI/CD pipelines, mocks, and monitors directly from Postman into the codebase. The action supports both monorepos and individual projects, and it can handle various synchronization modes to ensure that changes are managed efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.10.9</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of exporting Postman collections, environments, and monitoring configurations into a repository. It helps streamline API development by integrating CI/CD pipelines, mocks, and monitors directly from Postman into the codebase. The action supports both monorepos and individual projects, and it can handle various synchronization modes to ensure that changes are managed efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/134">https://github.com/postman-cs/postman-repo-sync-action/pull/134</a></li>
<li>feat: publish as @postman/onboarding-repo-sync with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/140">https://github.com/postman-cs/postman-repo-sync-action/pull/140</a></li>
<li>ci: install restricted dependencies without npm token by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/141">https://github.com/postman-cs/postman-repo-sync-action/pull/141</a></li>
<li>fix(deps): move private @postman platform packages to devDependencies by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/144">https://github.com/postman-cs/postman-repo-sync-action/pull/144</a></li>
<li>feat: support monorepo working directories by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/145">https://github.com/postman-cs/postman-repo-sync-action/pull/145</a></li>
<li>fix(release): repair stale rolling alias by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/146">https://github.com/postman-cs/postman-repo-sync-action/pull/146</a></li>
<li>fix(release): use workflow-capable tag token by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/147">https://github.com/postman-cs/postman-repo-sync-action/pull/147</a></li>
<li>fix(release): use writable workflow token by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/148">https://github.com/postman-cs/postman-repo-sync-action/pull/148</a></li>
<li>fix(release): scope workflow token to repository by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/149">https://github.com/postman-cs/postman-repo-sync-action/pull/149</a></li>
<li>fix: fail when artifact commit is rejected by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/150">https://github.com/postman-cs/postman-repo-sync-action/pull/150</a></li>
<li>fix(deps): migrate automation core scope by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/151">https://github.com/postman-cs/postman-repo-sync-action/pull/151</a></li>
<li>chore: ignore local plans by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/153">https://github.com/postman-cs/postman-repo-sync-action/pull/153</a></li>
<li>fix(security): harden secret persistence checks by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/154">https://github.com/postman-cs/postman-repo-sync-action/pull/154</a></li>
<li>fix(security): harden repository and asset trust boundaries by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/155">https://github.com/postman-cs/postman-repo-sync-action/pull/155</a></li>
<li>fix(gc): reconcile nameless preview collections by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/156">https://github.com/postman-cs/postman-repo-sync-action/pull/156</a></li>
<li>fix(gc): replace export scans with inventory snapshot by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/157">https://github.com/postman-cs/postman-repo-sync-action/pull/157</a></li>
<li>fix(release): pin authenticated E2E provider by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/158">https://github.com/postman-cs/postman-repo-sync-action/pull/158</a></li>
<li>fix(release): let new cuts supersede stale evidence by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/159">https://github.com/postman-cs/postman-repo-sync-action/pull/159</a></li>
<li>fix: avoid fresh collection export after mock creation by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/160">https://github.com/postman-cs/postman-repo-sync-action/pull/160</a></li>
<li>fix(collections): use populated Sync snapshots by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/161">https://github.com/postman-cs/postman-repo-sync-action/pull/161</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.10.9">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.10.9</a></p>
]]></content:encoded></item><item><title>Python Semantic Release - Publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/python-semantic-release-publish/</link><pubDate>Sat, 29 Aug 2026 14:01:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/python-semantic-release-publish/</guid><description>Version updated for https://github.com/python-semantic-release/publish-action to version v10.6.2.
This action is used across all versions by 704 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the publishing process for Python projects using python-semantic-release. It uses semantic release, which helps manage project releases and changelogs automatically. This action integrates seamlessly with Python Semantic Release configurations to handle versioning and automated releases through a GitHub workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/python-semantic-release/publish-action">https://github.com/python-semantic-release/publish-action</a></strong> to version <strong>v10.6.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>704</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/python-semantic-release-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the publishing process for Python projects using <code>python-semantic-release</code>. It uses semantic release, which helps manage project releases and changelogs automatically. This action integrates seamlessly with Python Semantic Release configurations to handle versioning and automated releases through a GitHub workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v1062-2026-08-29">v10.6.2 (2026-08-29)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps</strong>: Bump <code>python-semantic-release</code> from <code>v10.6.1</code> to <code>v10.6.2</code> (<a href="https://github.com/python-semantic-release/publish-action/pull/108">#108</a>, <a href="https://github.com/python-semantic-release/publish-action/commit/6d89e2de8d40ecb3717316ecbbf15a6fa8ea9039"><code>6d89e2d</code></a>)</li>
</ul>
<hr>
<p><strong>Detailed Changes</strong>: <a href="https://github.com/python-semantic-release/publish-action/compare/v10.6.1...v10.6.2">v10.6.1&hellip;v10.6.2</a></p>
]]></content:encoded></item><item><title>GitHub Project Trello Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/github-project-trello-sync/</link><pubDate>Sat, 29 Aug 2026 14:01:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/github-project-trello-sync/</guid><description>Version updated for https://github.com/rajipkanxo01/Trello-Github-Sync to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “GitHub Project → Trello Sync” automates the process of keeping a Trello board up-to-date with issues from a specified GitHub Project. It creates one card per issue, updating its title, description, labels, and assignees based on the issue’s status within the project. The action supports different statuses in the GitHub Project to map to specific Trello lists (Todo, In Progress, Done).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rajipkanxo01/Trello-Github-Sync">https://github.com/rajipkanxo01/Trello-Github-Sync</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-project-trello-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;GitHub Project → Trello Sync&rdquo; automates the process of keeping a Trello board up-to-date with issues from a specified GitHub Project. It creates one card per issue, updating its title, description, labels, and assignees based on the issue&rsquo;s status within the project. The action supports different statuses in the GitHub Project to map to specific Trello lists (Todo, In Progress, Done).</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="github-project-trello-sync-v100">GitHub Project Trello Sync v1.0.0</h2>
<p>First stable release.</p>
<h3 id="features">Features</h3>
<ul>
<li>Creates and updates Trello cards from GitHub Project Issues</li>
<li>Synchronizes Todo, In Progress, In Review and Done statuses</li>
<li>Synchronizes issue titles, descriptions, labels and mapped assignees</li>
<li>Supports personal and organization-owned GitHub Projects</li>
<li>Supports immediate Issue-event synchronization</li>
<li>Supports scheduled reconciliation for Project status changes</li>
<li>Requires no hosted server or third-party automation service</li>
</ul>
<p>See the README for complete installation and configuration instructions.</p>
]]></content:encoded></item><item><title>SBOMlyze Diff</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/sbomlyze-diff/</link><pubDate>Sat, 29 Aug 2026 14:00:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/sbomlyze-diff/</guid><description>Version updated for https://github.com/rezmoss/sbomlyze to version v0.5.3.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary sbomlyze is a GitHub Action that compares two Software Bills of Materials (SBOMs) to detect changes and security issues. It helps identify tampered components and ensures compliance by scoring SBOMs based on NTIA, CISA, and BSI standards. The action provides an immutable SHA for comparison, enabling reliable drift detection without temporary files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rezmoss/sbomlyze">https://github.com/rezmoss/sbomlyze</a></strong> to version <strong>v0.5.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sbomlyze-diff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>sbomlyze is a GitHub Action that compares two Software Bills of Materials (SBOMs) to detect changes and security issues. It helps identify tampered components and ensures compliance by scoring SBOMs based on NTIA, CISA, and BSI standards. The action provides an immutable SHA for comparison, enabling reliable drift detection without temporary files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>db9182a06acbc58a66143978765f096a576f1f9c chore(main): release 0.5.3 (#52)</li>
<li>9662e6b13f556ac0efe50e472b5af32dcfe00f9a fix: sync action version metadata to v0.5.2 (#51)</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/kaniko-build-action/</link><pubDate>Sat, 29 Aug 2026 13:59:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or “Hello” + a specified name to the log, automating the greeting process. It allows users to specify who they want to greet and displays the current time when greeted.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or &ldquo;Hello&rdquo; + a specified name to the log, automating the greeting process. It allows users to specify who they want to greet and displays the current time when greeted.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/custom-amazon-bedrock-agent-action/</link><pubDate>Sat, 29 Aug 2026 13:59:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide feedback tailored to specific requirements. It enables integration with Amazon Bedrock Knowledge Bases for context-aware insights, enhancing the analysis capabilities beyond code review.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide feedback tailored to specific requirements. It enables integration with Amazon Bedrock Knowledge Bases for context-aware insights, enhancing the analysis capabilities beyond code review.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/sherpa.sh/</link><pubDate>Sat, 29 Aug 2026 13:58:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI tool designed to automate the deployment process by translating developer intentions into optimized infrastructure configurations. It simplifies the setup of various cloud providers and services, reducing the need for manual configuration files and freeing up developers to focus on code instead of infrastructure management. With Sherpa, developers can write plain English prompts to deploy their applications across multiple clouds seamlessly, providing a transparent and cost-effective way to build and deploy applications globally.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI tool designed to automate the deployment process by translating developer intentions into optimized infrastructure configurations. It simplifies the setup of various cloud providers and services, reducing the need for manual configuration files and freeing up developers to focus on code instead of infrastructure management. With Sherpa, developers can write plain English prompts to deploy their applications across multiple clouds seamlessly, providing a transparent and cost-effective way to build and deploy applications globally.</p>
]]></content:encoded></item><item><title>Skill Provenance Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/skill-provenance-validate/</link><pubDate>Sat, 29 Aug 2026 13:57:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/skill-provenance-validate/</guid><description>Version updated for https://github.com/snapsynapse/skill-provenance to version v6.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation of Agent Skill bundles to ensure they are portable, have accurate versions and integrity, and detect any drift between the manifest and actual bundle contents. It helps teams track the version history and integrity of their skills across different platforms and sessions. The action ensures that a downloaded or shared bundle matches its recorded state before installing it, using SHA-256 hashes to catch tampering and accidental drift.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snapsynapse/skill-provenance">https://github.com/snapsynapse/skill-provenance</a></strong> to version <strong>v6.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skill-provenance-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation of Agent Skill bundles to ensure they are portable, have accurate versions and integrity, and detect any drift between the manifest and actual bundle contents. It helps teams track the version history and integrity of their skills across different platforms and sessions. The action ensures that a downloaded or shared bundle matches its recorded state before installing it, using SHA-256 hashes to catch tampering and accidental drift.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="skill-provenance-620">Skill Provenance 6.2.0</h1>
<p>This release adds portable, no-plugin verification and makes bundle identity easier to verify across GitHub, GitHub Pages, and agent-facing surfaces.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Added <code>verify.sh</code>, a zero-install bootstrap that pins and authenticates the canonical validator before execution.</li>
<li>Added regression coverage for local and downloaded validator pins, tamper rejection, exit-code propagation, paths with spaces, and temporary-file cleanup.</li>
<li>Expanded the evaluation suite to 41 core and 18 supplemental scenarios, 59 total.</li>
<li>Separated immutable bundle tags (<code>vX.Y.Z</code>) from GuideCheck sidecar tags (<code>guidecheck-X.Y.Z</code>) throughout docs and release checks.</li>
<li>Updated GitHub Pages, <code>llms.txt</code>, the assistant guide, agentic-surface inventory, roadmap, and project context for v6.2.0.</li>
<li>Added a dated 2026 skill-versioning ecosystem observation with explicit reproduction boundaries.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li>Canonical manifest validation passed for all 11 bundle files.</li>
<li>Release-surface checks passed, including ZIP/source agreement and exact tag-family references.</li>
<li>Validate bundle, CodeQL, and GitHub Pages workflows passed on commit <code>2a752319377327b5fd905c0b72f222ad4fb0cb26</code>.</li>
<li><code>skill-provenance.skill</code> SHA-256: <code>e0ebef495463492641a39b9fedb8b949c05f93b0b20265eef5e46433747622dc</code></li>
</ul>
<p>Full details are in <a href="https://github.com/snapsynapse/skill-provenance/blob/v6.2.0/CHANGELOG.md">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>ZIRAN Agent Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/ziran-agent-security-scan/</link><pubDate>Sat, 29 Aug 2026 13:56:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/ziran-agent-security-scan/</guid><description>Version updated for https://github.com/taoq-ai/ziran to version v0.38.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ZIRAN is an AI-driven security tool designed to identify vulnerabilities in AI agents, including their capabilities and potential attack chains. It models agents as graph structures and conducts multi-phase campaigns to detect dangerous tool chains, execution-level side effects, and multi-phase exploits that conventional scanners might overlook. The tool uses machine learning to analyze the interactions between agent functions and tools, providing a comprehensive understanding of the agent’s behavior and vulnerabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/taoq-ai/ziran">https://github.com/taoq-ai/ziran</a></strong> to version <strong>v0.38.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ziran-agent-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ZIRAN is an AI-driven security tool designed to identify vulnerabilities in AI agents, including their capabilities and potential attack chains. It models agents as graph structures and conducts multi-phase campaigns to detect dangerous tool chains, execution-level side effects, and multi-phase exploits that conventional scanners might overlook. The tool uses machine learning to analyze the interactions between agent functions and tools, providing a comprehensive understanding of the agent&rsquo;s behavior and vulnerabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0380-2026-08-29"><a href="https://github.com/taoq-ai/ziran/compare/v0.37.1...v0.38.0">0.38.0</a> (2026-08-29)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>observability:</strong> add &ndash;log-format flag and bind campaign/phase/vector log context (<a href="https://github.com/taoq-ai/ziran/commit/de1aceed6af21d17cec0fd6675886e4583acb0a7">de1acee</a>)</li>
<li><strong>observability:</strong> configure structlog with json/text renderers and context helpers (<a href="https://github.com/taoq-ai/ziran/commit/8aef7f16d1d3744c9637d5b29b30dd73b3d3552f">8aef7f1</a>)</li>
<li><strong>observability:</strong> metrics CLI flags, Prometheus scrape test, Grafana dashboard, docs (<a href="https://github.com/taoq-ai/ziran/commit/4d7294f28306288b615c5440d3ff5962b081b69c">4d7294f</a>)</li>
<li><strong>observability:</strong> OTel metrics export (Prometheus-compatible) (<a href="https://github.com/taoq-ai/ziran/commit/f71e23871bf01726292617b26a564b0be4470adb">f71e238</a>)</li>
<li><strong>observability:</strong> OTel metrics module + campaign/phase/attack instrumentation (<a href="https://github.com/taoq-ai/ziran/commit/cbe49a300f7bf5549b5d215ccb8d318dca384ab1">cbe49a3</a>)</li>
<li><strong>observability:</strong> structured JSON logging via structlog (<a href="https://github.com/taoq-ai/ziran/commit/4981da29e97637467e56fb1f291783092d24014f">4981da2</a>)</li>
<li><strong>runtime:</strong> add FlushThrottle for incremental checkpoint writes (<a href="https://github.com/taoq-ai/ziran/commit/959629191b7acb5160136a7d6f74c5555b5a83ad">9596291</a>)</li>
<li><strong>runtime:</strong> add on_vector_complete hook to PhaseExecutor (<a href="https://github.com/taoq-ai/ziran/commit/14c2752af079be1ced7e8bc94200c56ad558305d">14c2752</a>)</li>
<li><strong>runtime:</strong> incremental mid-phase checkpoint flush with &ndash;checkpoint-flush-interval (<a href="https://github.com/taoq-ai/ziran/commit/9fe794012b6c6024eb9394320008a682366811a8">9fe7940</a>)</li>
<li><strong>runtime:</strong> partial-phase checkpoint resume (<a href="https://github.com/taoq-ai/ziran/commit/6652f7f54af77852e7e4ab1549d4906200174d74">6652f7f</a>)</li>
<li><strong>runtime:</strong> rate-limiting and retry with exponential backoff for LLM provider calls (<a href="https://github.com/taoq-ai/ziran/commit/17def683816dc16793e8469ae9fe07d73b7923d0">17def68</a>)</li>
<li><strong>runtime:</strong> token-bucket limiter and retry-with-backoff for LLM calls (<a href="https://github.com/taoq-ai/ziran/issues/281">#281</a>) (<a href="https://github.com/taoq-ai/ziran/commit/06d6ee3c949a9feec6e23dea27cc8e89ff0f74d0">06d6ee3</a>)</li>
<li><strong>runtime:</strong> wire rate-limited LLM client into factory and CLI (<a href="https://github.com/taoq-ai/ziran/issues/281">#281</a>) (<a href="https://github.com/taoq-ai/ziran/commit/e8bfc609e8d5986ab3bc5ef601d6d8d852c9d856">e8bfc60</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>alerting:</strong> never create a GitHub issue when dedup cannot be confirmed (<a href="https://github.com/taoq-ai/ziran/commit/5cda14df4d8c2c959f472a0a69ff36b05d99584e">5cda14d</a>)</li>
<li><strong>alerting:</strong> never create a GitHub issue when dedup cannot be confirmed (<a href="https://github.com/taoq-ai/ziran/commit/0c6e89aff5ed43f09d92a836fe2180309659ac3a">0c6e89a</a>)</li>
<li><strong>anthropic:</strong> detect AsyncAnthropic clients under anthropic 1.x (<a href="https://github.com/taoq-ai/ziran/commit/e33dd7cf273bcb7b69030d8e37ed08b1dcf536fa">e33dd7c</a>)</li>
<li><strong>observability:</strong> guard provider label read and ignore prometheus_client imports (<a href="https://github.com/taoq-ai/ziran/commit/55c96eae09bedc4784c219b3e0ae084bfdf6238d">55c96ea</a>)</li>
<li><strong>security:</strong> bump mcp and json-repair to clear the audit gate (<a href="https://github.com/taoq-ai/ziran/commit/f26468974c34e27f27baa637da18672a2a78a8fd">f264689</a>)</li>
<li><strong>security:</strong> bump mcp and json-repair to clear the audit gate (<a href="https://github.com/taoq-ai/ziran/issues/370">#370</a> tier 2) (<a href="https://github.com/taoq-ai/ziran/commit/01c5fd79c26c8a872029552ab814a40ba8f3267a">01c5fd7</a>)</li>
<li><strong>security:</strong> bump pillow, pyasn1, bedrock-agentcore and websockets (<a href="https://github.com/taoq-ai/ziran/commit/56cc289da5d5e16ec8a03b114189030c71f20155">56cc289</a>)</li>
<li><strong>security:</strong> bump pillow, pyasn1, bedrock-agentcore and websockets (<a href="https://github.com/taoq-ai/ziran/issues/370">#370</a> tier 1) (<a href="https://github.com/taoq-ai/ziran/commit/665c7a114df62c415bc68b91bb4ad7503598f547">665c7a1</a>)</li>
<li><strong>security:</strong> clear new pip-audit advisories (aiohttp, cryptography, chromadb) (<a href="https://github.com/taoq-ai/ziran/commit/bae66908da0d277d37121fd9dded47f2b61dd7b7">bae6690</a>)</li>
<li><strong>security:</strong> clear remaining npm audit high-severity advisories in ui (<a href="https://github.com/taoq-ai/ziran/commit/f0b37681986d5aac025196416add67363a43a83e">f0b3768</a>)</li>
<li><strong>security:</strong> clear remaining npm audit high-severity advisories in ui (<a href="https://github.com/taoq-ai/ziran/commit/e99c675e22c2a082af51d98599332c38cfca2def">e99c675</a>), closes <a href="https://github.com/taoq-ai/ziran/issues/373">#373</a></li>
<li><strong>typing:</strong> ignore missing anthropic stubs when extra not installed (<a href="https://github.com/taoq-ai/ziran/commit/7e1249ecebcaa8b774fa2f439f24b0f0dde37bda">7e1249e</a>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: bump the python-dependencies group across 1 directory with 4 updates by @dependabot[bot] in <a href="https://github.com/taoq-ai/ziran/pull/355">https://github.com/taoq-ai/ziran/pull/355</a></li>
<li>fix(security): bump pillow, pyasn1, bedrock-agentcore and websockets (#370 tier 1) by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/371">https://github.com/taoq-ai/ziran/pull/371</a></li>
<li>fix(security): bump mcp and json-repair to clear the audit gate (#370 tier 2) by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/372">https://github.com/taoq-ai/ziran/pull/372</a></li>
<li>chore: bump postcss from 8.5.15 to 8.5.23 in /ui by @dependabot[bot] in <a href="https://github.com/taoq-ai/ziran/pull/374">https://github.com/taoq-ai/ziran/pull/374</a></li>
<li>chore: bump brace-expansion from 5.0.6 to 5.0.8 in /ui by @dependabot[bot] in <a href="https://github.com/taoq-ai/ziran/pull/375">https://github.com/taoq-ai/ziran/pull/375</a></li>
<li>fix(security): clear remaining npm audit high-severity advisories in ui by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/388">https://github.com/taoq-ai/ziran/pull/388</a></li>
<li>feat(runtime): rate-limiting and retry with exponential backoff for LLM provider calls by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/391">https://github.com/taoq-ai/ziran/pull/391</a></li>
<li>chore(ui): apply frontend dependency group bumps with peer-conflict fixes by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/390">https://github.com/taoq-ai/ziran/pull/390</a></li>
<li>feat(runtime): partial-phase checkpoint resume by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/402">https://github.com/taoq-ai/ziran/pull/402</a></li>
<li>feat(observability): structured JSON logging via structlog by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/403">https://github.com/taoq-ai/ziran/pull/403</a></li>
<li>ci: bump the actions group across 1 directory with 3 updates by @dependabot[bot] in <a href="https://github.com/taoq-ai/ziran/pull/385">https://github.com/taoq-ai/ziran/pull/385</a></li>
<li>chore(deps): allow anthropic 1.x and websockets 17.x with adapter compatibility fix by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/401">https://github.com/taoq-ai/ziran/pull/401</a></li>
<li>chore: update structlog requirement from &lt;26,&gt;=24.1 to &gt;=24.1,&lt;27 in the python-dependencies group across 1 directory by @dependabot[bot] in <a href="https://github.com/taoq-ai/ziran/pull/407">https://github.com/taoq-ai/ziran/pull/407</a></li>
<li>fix(alerting): never create a GitHub issue when dedup cannot be confirmed by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/377">https://github.com/taoq-ai/ziran/pull/377</a></li>
<li>docs(specs): archive six delivered specs and correct their lifecycle status by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/369">https://github.com/taoq-ai/ziran/pull/369</a></li>
<li>feat(observability): OTel metrics export (Prometheus-compatible) by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/406">https://github.com/taoq-ai/ziran/pull/406</a></li>
<li>release: v0.38.0 — Production Scale by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/408">https://github.com/taoq-ai/ziran/pull/408</a></li>
<li>chore(main): release 0.38.0 by @leoneperdigao in <a href="https://github.com/taoq-ai/ziran/pull/409">https://github.com/taoq-ai/ziran/pull/409</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/taoq-ai/ziran/compare/v0.37.1...v0.38.0">https://github.com/taoq-ai/ziran/compare/v0.37.1...v0.38.0</a></p>
]]></content:encoded></item><item><title>wp-env for GitHub Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/wp-env-for-github-actions/</link><pubDate>Sat, 29 Aug 2026 13:55:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/wp-env-for-github-actions/</guid><description>Version updated for https://github.com/tbdsux/gh-setup-wpenv to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action gh-setup-wpenv automates setting up the @wordpress/env package for WordPress development in CI environments, enabling developers to build and test plugins and themes with Dockerized WordPress environments using Node.js. It provides a simple setup process by installing Node.js, global wp-env, and optionally starting the environment, making it easier to automate WordPress development tasks on GitHub Actions runners.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tbdsux/gh-setup-wpenv">https://github.com/tbdsux/gh-setup-wpenv</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wp-env-for-github-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>gh-setup-wpenv</code> automates setting up the <code>@wordpress/env</code> package for WordPress development in CI environments, enabling developers to build and test plugins and themes with Dockerized WordPress environments using Node.js. It provides a simple setup process by installing Node.js, global <code>wp-env</code>, and optionally starting the environment, making it easier to automate WordPress development tasks on GitHub Actions runners.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release</p>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/delivery-autopilot-runner/</link><pubDate>Sat, 29 Aug 2026 13:55:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.79.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Delivery Autopilot Runner GitHub Action automates the process of using an AI pipeline to plan, build, check, and self-heal code changes from a ticket. It requires an active subscription with Delivery Autopilot, which triggers the action to run based on signed instructions. The action checks out the repository only on GitHub’s runners and does not send any source code to Tekunda’s servers. Users can set up the action using a GitHub App or by manually configuring it in their workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.79</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Delivery Autopilot Runner GitHub Action automates the process of using an AI pipeline to plan, build, check, and self-heal code changes from a ticket. It requires an active subscription with Delivery Autopilot, which triggers the action to run based on signed instructions. The action checks out the repository only on GitHub&rsquo;s runners and does not send any source code to Tekunda&rsquo;s servers. Users can set up the action using a GitHub App or by manually configuring it in their workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runner-dist synced from AutoPilot 3969f92a66fd. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/wails3-build-action/</link><pubDate>Sat, 29 Aug 2026 13:54:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the build process for Wails.io v3 projects. It installs GoLang and NodeJS, runs a build, and optionally uploads the results to GitHub and releases on tagged builds. The action supports various configurations such as platform selection, obfuscation, caching, and package upload options.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the build process for Wails.io v3 projects. It installs GoLang and NodeJS, runs a build, and optionally uploads the results to GitHub and releases on tagged builds. The action supports various configurations such as platform selection, obfuscation, caching, and package upload options.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Sentral CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/sentral-ci/</link><pubDate>Sat, 29 Aug 2026 13:53:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/sentral-ci/</guid><description>Version updated for https://github.com/Troaxx/sentral to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, troaxx/sentral, helps diagnose and understand why a CI job failed by comparing the CI environment with your local one. It provides an honest confidence score and highlights any discrepancies between the two environments. The tool is particularly useful for Node.js and Python projects running on Ubuntu runners but does not yet support other platforms or configurations. To use it, add it to your workflow when a previous step fails, and optionally run it locally to generate a baseline for future comparisons.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Troaxx/sentral">https://github.com/Troaxx/sentral</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sentral-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>troaxx/sentral</code>, helps diagnose and understand why a CI job failed by comparing the CI environment with your local one. It provides an honest confidence score and highlights any discrepancies between the two environments. The tool is particularly useful for Node.js and Python projects running on Ubuntu runners but does not yet support other platforms or configurations. To use it, add it to your workflow when a previous step fails, and optionally run it locally to generate a baseline for future comparisons.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Troaxx/sentral/commits/v1">https://github.com/Troaxx/sentral/commits/v1</a></p>
]]></content:encoded></item><item><title>YAMLResume</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/yamlresume/</link><pubDate>Sat, 29 Aug 2026 13:52:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/yamlresume/</guid><description>Version updated for https://github.com/yamlresume/action to version v0.16.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of building professional resumes using YAML files with the YAMLResume CLI. It allows users to build multiple resumes in a single step, customize build options such as skipping validation and PDF generation, outputs generated file paths, and seamlessly integrates with actions/upload-artifact. The action supports various workflows and provides detailed outputs for further processing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yamlresume/action">https://github.com/yamlresume/action</a></strong> to version <strong>v0.16.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yamlresume">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of building professional resumes using YAML files with the YAMLResume CLI. It allows users to build multiple resumes in a single step, customize build options such as skipping validation and PDF generation, outputs generated file paths, and seamlessly integrates with <code>actions/upload-artifact</code>. The action supports various workflows and provides detailed outputs for further processing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="features">Features</h3>
<ul>
<li>bump yamlresume from v0.15.3 to v0.16.0 (<a href="https://github.com/yamlresume/action/commit/01b18101aac5439619e821dd8434f126cfc610f7">01b1810</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yamlresume/action/compare/v0.15.3...v0.16.0">https://github.com/yamlresume/action/compare/v0.15.3...v0.16.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/b.ia-accessibility-checker/</link><pubDate>Sat, 29 Aug 2026 13:52:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in your CI/CD pipeline. It enables companies to define an audience and percentage of WCAG guidelines to be met, allowing them to ensure their products are accessible without the need for extensive learning or external solutions. The action uses AI analysis to measure guidelines more abstractly and provides feedback to developers if their code does not meet accessibility requirements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in your CI/CD pipeline. It enables companies to define an audience and percentage of WCAG guidelines to be met, allowing them to ensure their products are accessible without the need for extensive learning or external solutions. The action uses AI analysis to measure guidelines more abstractly and provides feedback to developers if their code does not meet accessibility requirements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>ttyd server</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/ttyd-server/</link><pubDate>Sat, 29 Aug 2026 13:51:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/ttyd-server/</guid><description>Version updated for https://github.com/zongou/run-ttyd-server to version 0.0.8.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The zongou/run-ttyd-server GitHub Action starts a ttyd server, which allows users to connect to their terminal sessions over the internet using web browsers or SSH clients. This action helps automate the setup and management of a remote terminal service that can be accessed securely from any device with internet access.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zongou/run-ttyd-server">https://github.com/zongou/run-ttyd-server</a></strong> to version <strong>0.0.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ttyd-server">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>zongou/run-ttyd-server</code> GitHub Action starts a ttyd server, which allows users to connect to their terminal sessions over the internet using web browsers or SSH clients. This action helps automate the setup and management of a remote terminal service that can be accessed securely from any device with internet access.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/zongou/run-ttyd-server/commits/0.0.8">https://github.com/zongou/run-ttyd-server/commits/0.0.8</a></p>
]]></content:encoded></item><item><title>Aether Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/aether-deploy/</link><pubDate>Sat, 29 Aug 2026 02:04:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/aether-deploy/</guid><description>Version updated for https://github.com/Monoradioactivo/aetherpush-deploy-action to version v0.4.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates React Native over-the-air updates using the Aether push SDK. It simplifies CI/CD processes by releasing updates to apps on iOS and Android platforms, providing options like customizing deployment channels, rollouts, and metadata. The action supports both release and release-react commands and handles various configuration inputs to streamline the update release process in a CI pipeline.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Monoradioactivo/aetherpush-deploy-action">https://github.com/Monoradioactivo/aetherpush-deploy-action</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aether-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates React Native over-the-air updates using the Aether push SDK. It simplifies CI/CD processes by releasing updates to apps on iOS and Android platforms, providing options like customizing deployment channels, rollouts, and metadata. The action supports both <code>release</code> and <code>release-react</code> commands and handles various configuration inputs to streamline the update release process in a CI pipeline.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="041-2026-08-28"><a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/compare/v0.4.0...v0.4.1">0.4.1</a> (2026-08-28)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>action:</strong> treat a skipped duplicate as success (<a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/issues/30">#30</a>) (<a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/commit/657d269d810e17add1d7e5a1fc02c12de2b621e7">657d269</a>)</li>
</ul>
]]></content:encoded></item><item><title>Planizer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/planizer/</link><pubDate>Sat, 29 Aug 2026 02:03:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/planizer/</guid><description>Version updated for https://github.com/mustafaabasaran/planizer to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Planizer is a deterministic static-analysis linter for SQL Server migrations that analyzes DDL, DML, and migration scripts to ensure they are safe, reversible, and perform within expected limits. It provides detailed findings with rules covering locking/blocking, rewrite vs metadata-only operations, reversibility, failure risk, and transaction hygiene, generating exit codes and SARIF reports for CI integration and GitHub code scanning.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mustafaabasaran/planizer">https://github.com/mustafaabasaran/planizer</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/planizer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Planizer is a deterministic static-analysis linter for SQL Server migrations that analyzes DDL, DML, and migration scripts to ensure they are safe, reversible, and perform within expected limits. It provides detailed findings with rules covering locking/blocking, rewrite vs metadata-only operations, reversibility, failure risk, and transaction hygiene, generating exit codes and SARIF reports for CI integration and GitHub code scanning.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Planizer is a deterministic static-analysis linter for <strong>SQL Server (MSSQL) / T-SQL migrations</strong>. It reads plain <code>.sql</code> files ‚Äî no database connection required ‚Äî and answers the questions every migration review asks before a change reaches production:</p>
<blockquote>
<p>Does it lock the table, and for how long? Does it rewrite the data or only metadata? Can it be rolled back? Will it fail on a re-run, or on our version and edition?</p>
</blockquote>
<p>Every finding carries a rule id, a severity, a <code>line:column</code>, a one-sentence reason, a suggested fix (as SQL where possible), and the <strong>version/edition assumption it was produced under</strong>.</p>
<h2 id="whats-in-010">What&rsquo;s in 0.1.0</h2>
<p><strong>53 rules</strong> in six families:</p>
<table>
  <thead>
      <tr>
          <th>Family</th>
          <th>Covers</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>LOCK</code> (10)</td>
          <td>Sch-M windows, offline vs <code>ONLINE = ON</code>, <code>RESUMABLE</code>, <code>WAIT_AT_LOW_PRIORITY</code>, multi-statement transactions, lock escalation</td>
      </tr>
      <tr>
          <td><code>RW</code> (16)</td>
          <td>Rewrite vs metadata-only: <code>ADD</code>/<code>ALTER</code>/<code>DROP COLUMN</code> variants, constraints, clustered indexes, compression, row width</td>
      </tr>
      <tr>
          <td><code>REV</code> (5)</td>
          <td>Irreversible data loss, <code>sp_rename</code> fallout, <code>TRUNCATE</code>, opt-in rollback-script generation (<code>--rollback</code>)</td>
      </tr>
      <tr>
          <td><code>IDEM</code> / <code>BATCH</code> / <code>LIT</code> / <code>LIM</code> / <code>VER</code> (9)</td>
          <td>Will the script <em>fail</em>: existence guards, same-batch column use, <code>GO</code> boundaries, non-Unicode literals, index-key and identifier limits, features missing on the target version</td>
      </tr>
      <tr>
          <td><code>TRAN</code> / <code>SET</code> / <code>ENV</code> (11)</td>
          <td><code>XACT_ABORT</code>, <code>BEGIN</code>/<code>COMMIT</code> balance, <code>TRY</code>/<code>CATCH</code>, <code>QUOTED_IDENTIFIER</code>, <code>USE</code> and cross-database coupling</td>
      </tr>
      <tr>
          <td><code>PARSE</code> / <code>DYN</code> (2)</td>
          <td>Parse failures, dynamic SQL marked as unanalyzable rather than silently skipped</td>
      </tr>
  </tbody>
</table>
<p><strong>Also in this release</strong></p>
<ul>
<li>Statements nested in <code>IF</code> / <code>BEGIN‚Ä¶END</code> / <code>WHILE</code> / <code>TRY‚Ä¶CATCH</code> are analyzed like top-level ones, with their batch and control-flow context.</li>
<li>Four outputs: <code>text</code>, <code>json</code>, <code>markdown</code> (PR comments), <code>sarif</code> (GitHub code scanning) ‚Äî plus <code>--sarif-file</code> to write SARIF alongside any other output.</li>
<li>A composite <strong>GitHub Action</strong>: <code>uses: mustafaabasaran/planizer@v0.1.0</code>.</li>
<li>Suppressions (<code>-- planizer:ignore RULE_ID reason</code>) and per-directory <code>.planizer.json</code> config.</li>
<li>Worst-case defaults: SQL Server 2019 <strong>Standard</strong> ‚Äî the edition where the expensive surprises live.</li>
</ul>
<h2 id="why-you-can-trust-the-rules">Why you can trust the rules</h2>
<p>The behavior catalog behind the rules (<code>operation √ó version √ó edition ‚Üí lock, data movement, reversibility</code>) is not documentation-derived guesswork: a <a href="https://github.com/mustafaabasaran/planizer/actions/workflows/catalog-verification.yml">CI job</a> measures <strong>every row against real SQL Server containers</strong> ‚Äî Developer <em>and</em> Express ‚Äî using transaction-log deltas, two-session blocking profiles and expected error numbers. The current state is 30/30 rows verified on Developer, 26/26 applicable rows on Express, zero contradictions. That harness has already corrected two claims this project got wrong.</p>
<p>The rules were also validated against a private corpus of 24 production repositories (8,507 migration files, 1.5M statements) over several false-positive rounds.</p>
<h2 id="install">Install</h2>
<p><strong>As a GitHub Action</strong> (no install):</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">mustafaabasaran/planizer@v0.1.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">path</span>: <span style="color:#ae81ff">migrations</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">target-version</span>: <span style="color:#e6db74">&#39;2019&#39;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">edition</span>: <span style="color:#ae81ff">standard</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">critical</span>
</span></span></code></pre></div><p><strong>As a .NET tool</strong>, from the package attached below (requires .NET 10; the tool rolls forward to newer majors):</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>dotnet tool install --global --add-source &lt;folder-with-the-downloaded-nupkg&gt; Planizer
</span></span><span style="display:flex;"><span>planizer analyze migrations/ --output text
</span></span></code></pre></div><p><strong>From source:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>git clone https://github.com/mustafaabasaran/planizer <span style="color:#f92672">&amp;&amp;</span> cd planizer
</span></span><span style="display:flex;"><span>dotnet pack src/Planizer.Cli -c Release
</span></span><span style="display:flex;"><span>dotnet tool install --global --add-source src/Planizer.Cli/nupkg Planizer
</span></span></code></pre></div><h2 id="scope-and-limitations">Scope and limitations</h2>
<ul>
<li><strong>SQL Server only</strong> for now; PostgreSQL is planned via a Squawk adapter.</li>
<li><strong>Offline analysis only.</strong> Rules that need schema or statistics report <code>inconclusive</code> rather than staying silent; snapshot and live modes are the next phase (&ldquo;this migration takes an estimated X seconds and Y MB of log&rdquo;).</li>
<li><strong>No LLM anywhere in the pipeline</strong> ‚Äî parser plus a verified behavior catalog, so the same input always produces the same report.</li>
<li>Not yet on NuGet.org.</li>
</ul>
<h2 id="docs">Docs</h2>
<p><a href="https://github.com/mustafaabasaran/planizer#readme">README</a> ¬∑ <a href="https://github.com/mustafaabasaran/planizer/tree/main/docs/rules">Rule pages</a> ¬∑ <a href="https://github.com/mustafaabasaran/planizer/blob/main/docs/ROADMAP.md">Roadmap</a> ¬∑ <a href="https://github.com/mustafaabasaran/planizer/tree/main/docs/adr">Design decisions</a></p>
<p>This is an early release ‚Äî issues and rule suggestions are very welcome, especially false positives from real migrations.</p>
]]></content:encoded></item><item><title>GitHub backport</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/github-backport/</link><pubDate>Sat, 29 Aug 2026 02:02:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/github-backport/</guid><description>Version updated for https://github.com/nicklegan/backport to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action cherry-picks pull requests onto long-running backport branches and gates the original pull request and its backports with bidirectional checks. It allows users to specify allowed backport branches and gate check names, and provides options for cherry-picking behavior and label management. The action is useful for maintaining multiple stable release branches while ensuring that changes are backported correctly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicklegan/backport">https://github.com/nicklegan/backport</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-backport">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action cherry-picks pull requests onto long-running backport branches and gates the original pull request and its backports with bidirectional checks. It allows users to specify allowed backport branches and gate check names, and provides options for cherry-picking behavior and label management. The action is useful for maintaining multiple stable release branches while ensuring that changes are backported correctly.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Host-aware support for github.com, ghe.com (data residency), and GitHub Enterprise Server. Host URLs are sourced from the runner env vars (<code>GITHUB_API_URL</code>, <code>GITHUB_GRAPHQL_URL</code>, <code>GITHUB_SERVER_URL</code>) instead of hardcoding github.com.</p>
]]></content:encoded></item><item><title>Full-site SEO Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/full-site-seo-audit/</link><pubDate>Sat, 29 Aug 2026 02:00:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/full-site-seo-audit/</guid><description>Version updated for https://github.com/nurkamol/seo-audit to version v1.34.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action nurkamol/seo-audit crawls a website’s sitemap and checks each page for SEO, metadata, and structured data problems, offering zero dependencies and automatic execution within CI. It automates tasks that single-page graders typically miss, ensuring comprehensive site audits without manual intervention.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nurkamol/seo-audit">https://github.com/nurkamol/seo-audit</a></strong> to version <strong>v1.34.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/full-site-seo-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>nurkamol/seo-audit</code> crawls a website&rsquo;s sitemap and checks each page for SEO, metadata, and structured data problems, offering zero dependencies and automatic execution within CI. It automates tasks that single-page graders typically miss, ensuring comprehensive site audits without manual intervention.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>A score out of 100, and the checks that passed to earn it.</strong> Every report
now opens with a number, a grade and a ring: <code>81/100 (B)</code>, followed by the
arithmetic that produced it. A run starts at 100 and pays for what is wrong
with it — an error-level check costs 12 points, a warning 4, spread across
the pages it is on — so what a check costs is exactly what fixing it is
worth, and every piece of work in <em>Start here</em> now carries the points it
returns.</p>
<p>This project has refused a score everywhere else and the refusal still
stands for the thing people usually mean by one: nothing here predicts a
ranking, estimates traffic, or grades a site against its competitors. The
weights are not a new judgement either — every check already carries a level,
argued over check by check when it was written, and <code>scripts/check-levels.mjs</code>
reads those levels back out of the source so a check promoted from warning to
error cannot keep its old weight. A test asserts it on the machine of whoever
changes one.</p>
</li>
<li>
<p><strong>What passed, and what was never checked.</strong> A report that only lists faults
gives no way to tell a check that passed from one that never ran, and a
missing finding reads exactly like a passing one. Both are now named: a
<strong>Passing</strong> section listing every check the site cleared, in its own words
(<em>&ldquo;Every page has an og:image&rdquo;</em>, not <code>og-image-missing</code>), and a <strong>Not checked</strong>
section saying why the rest did not apply — no page carries an image, no
redirect map was given, PageSpeed was not asked.</p>
<p>A check that could not run is left out of the score entirely rather than
counted as passed. A site with no images has not passed the alt-text check,
and scoring it as though it had would hand out points for doing less.</p>
</li>
<li>
<p><strong>Errors and warnings first, notes after them.</strong> Findings used to arrive
interleaved, and a note is <em>&ldquo;worth knowing, may be deliberate&rdquo;</em> — reading
forty of them mixed into the faults is how a reader loses track of which is
which. The terminal, the Markdown and the HTML now put what is wrong first
and everything only worth knowing under its own heading, which says out loud
that none of it costs the score anything.</p>
</li>
<li>
<p><strong><code>--write-schema &lt;file&gt;</code></strong> — the JSON-LD this site could add: <code>WebSite</code>,
<code>Organization</code> and <code>BreadcrumbList</code>. Every schema generator on the internet
asks you to type the answers in; this one refuses to ask, because the moment
it asks it is no longer describing the site — and structured data that
describes a site inaccurately is worse than none. It is a machine-readable
claim the page does not support, which is a manual-action category at Google.</p>
<p>So the rule is narrower than the rest of this project&rsquo;s and it is absolute:
every value emitted is a string this crawl read off this site. An
organisation is named only when the site names itself in <code>og:site_name</code>,
because the home page&rsquo;s title with its tagline still attached is a claim
about a company&rsquo;s name.</p>
<p>The first live run made the point better than any test: a breadcrumb built
from <code>&lt;title&gt;</code> produced <em>&ldquo;Assets | Jekyll • Simple, blog-aware, static
sites&rdquo;</em> as a step. A title is not a breadcrumb name. Now a step is named by
the page&rsquo;s <code>&lt;h1&gt;</code> when it has exactly one, or by what the site&rsquo;s own
navigation calls it when the links agree and the words are not &ldquo;read more&rdquo; —
and by nothing else. <code>Jekyll › Docs › Assets</code>. On that site 142 pages were
skipped rather than given a name invented from a slug.</p>
<p>The refusal can be the good answer here, so it says which it is: a site that
already declares everything this could write gets told exactly that, with the
counts, rather than the same sentence a site with no evidence gets.</p>
</li>
<li>
<p><strong><code>--write-llms &lt;file&gt;</code></strong> — the <code>llms.txt</code> this site should have had.
Sibling to <code>--write-sitemap</code>, on the same premise: the crawl has already read
every page&rsquo;s title, description, section and indexing directives, which is
exactly what the file is made of. Every line is a string the site already
serves — a page that gave us no description gets a line without one rather
than a sentence somebody made up about it, and the H1 is the site&rsquo;s own name
for itself rather than a guess.</p>
<p>It refuses for the same reasons the sitemap does, and the refusals matter
more than the file: this is a document handed to an assistant as the
authoritative summary of a site, and one built from a third of the site is
worse than none because it looks complete. A truncated crawl writes nothing
and names the run that would work.</p>
<p>Reachable everywhere: the flag, <code>llms-out=1</code> on the Worker, the macOS Export
menu (which says <em>why</em> when the engine refused), the Raycast extension, and
a <code>write-llms</code> input on the Action. <code>--write-sitemap</code> gained the Action input
it should always have had while the wiring was open.</p>
</li>
<li>
<p><strong>Search Console now answers where you rank, and what for.</strong> The same
connection, asked one more question — no second account, no scrape, no
keyword provider, and no number that anybody here worked out.</p>
<p>Every response Google has ever sent carried <code>position</code>, and it was being
thrown away. It now travels with each finding, so a template on page two can
be ordered ahead of one nobody has been shown, and the scope line says <em>&ldquo;12
pages, 4,300 impressions, best at position 6.4&rdquo;</em>.</p>
<p><strong><code>search-console-striking</code></strong> names the crawled pages at positions 11 to 20 —
page two, where the click-through rate is roughly nothing and the ranking is
already earned — with the query each is closest on, most-shown first. It is
the only list in this tool that is an opportunity rather than a fault, and
moving one of them up two places is usually less work than a new page.</p>
<p>A live property found the part no test would have: Google returns HTTP 200
and <strong>zero</strong> query rows for a site under its anonymity threshold — 99
impressions over 28 days was well under. Silence there reads exactly like
&ldquo;this site is found for nothing&rdquo;, so the report says which it is. The query
call is best-effort besides: if it fails, the positions still stand.</p>
</li>
<li>
<p><strong>Which AI crawlers a site lets in.</strong> GPTBot, OAI-SearchBot, ClaudeBot,
Claude-SearchBot, PerplexityBot, Google-Extended, Applebot-Extended, CCBot
and five more, asked of <code>robots.txt</code> through the same <code>robotsVerdict()</code> every
other robots question in this project goes through — so a rule this reads and
a rule Google reads are the same rule, longer-<code>Allow</code>-wins included. Nothing
is fetched that was not already being fetched and nothing is estimated: a
site&rsquo;s position on being read by the answer engines is already written down
in a file it already serves.</p>
<p>It is a <strong>note</strong>, and stays one. A publisher who does not want their work in a
training set and says so has done the correct thing correctly, and a check
that cries wolf gets the whole report ignored. What the finding adds is the
distinction everybody gets wrong — an <em>answering</em> crawler fetches a page
because somebody asked a question just now, so blocking it removes the site
from that answer today; a <em>training</em> crawler does not, and blocking it changes
nothing about being cited. And it says whether anybody actually decided: a
block that arrives through <code>User-agent: *</code> rather than the agent&rsquo;s own name is
usually a CDN or plugin default nobody has seen.</p>
<p>The one thing here that is a fault gets a warning: <code>ai-crawler-conflict</code>, a
site serving <code>llms.txt</code> — a file whose only purpose is to tell an assistant
what to read — while <code>robots.txt</code> turns that assistant away. The invitation
never gets read, and unlike the block itself, nobody chose it.</p>
<p>New area, <strong>AI &amp; answer engines</strong>, which <code>llms-missing</code> moves into: it is
addressed to assistants rather than to crawlers and belongs beside the agents
that read it.</p>
</li>
<li>
<p><strong><code>/checks</code></strong>, served beside <code>/options</code>: every scored check with its weight,
its area and what it says when it passes. &ldquo;What does this thing actually
check&rdquo; is now a question with a fetchable answer rather than one that needs a
source file read.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><strong>The CSV is the whole checklist, not only the faults.</strong> A <code>points</code> column
carries what each failing check is taking off the score, so a spreadsheet
sorts by what fixing something is worth rather than only by how often it
occurs. Checks that passed arrive as rows at level <code>pass</code>, and ones that did
not apply as <code>not-checked</code> with the reason in <code>detail</code>.</p>
<p>Additive on purpose: <code>points</code> is appended after <code>detail</code> rather than put
beside <code>indexable</code> where it reads better, so every column keeps the index it
has had since the file shipped. Anything filtering on <code>error</code>, <code>warn</code> or
<code>info</code> is untouched.</p>
</li>
<li>
<p><strong>The portfolio table has a score column</strong>, and orders by it where every run
has one. &ldquo;Which of my twenty sites is worst&rdquo; is the only question a portfolio
exists to answer, and counting errors weighs a site-wide failure the same as a
warning on one page of four hundred. A run that never answered prints a dash,
never a zero.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong><code>&lt;title&gt;</code> and every heading arrived with their HTML entities undecoded.</strong>
<code>attr()</code> has decoded since it was written, so meta descriptions were always
fine — but a title and an <code>&lt;h1&gt;</code> are element text and went through none of
it. So <code>Widgets &amp;amp; Co</code> was the title in the terminal, in the CSV, in the
JSON, and in the length <code>title-long</code> measures against what Google shows,
where it was five characters too long. Hexadecimal numeric references were
not handled at all, and <code>&amp;#x2019;</code> is what a CMS emits for the apostrophe in
<em>Widget&rsquo;s</em>.</p>
<p>Found by generating an <code>llms.txt</code> for a real site and reading the first line
of it — not by the test suite, which is the usual way round here.</p>
</li>
<li>
<p><strong>Every export dropped the score except the two that were written first.</strong>
It reached the terminal and the HTML and stopped there: the CSV had no column
for it, the portfolio had no column for it, the Raycast extension&rsquo;s exports
did not pass it to the writers, and the PDF the macOS app draws itself did not
know about it.</p>
<p>Worst of the four: the window re-encoded the report from its own Swift models
on the way to <code>/render</code>, which silently dropped every field it had not been
taught about — so an HTML report exported from the window lost the score panel
the window itself was showing. The JSON export has written the engine&rsquo;s bytes
verbatim since it shipped, with a comment saying exactly why; the other three
formats now do the same. There is a test per writer.</p>
</li>
<li>
<p><strong><code>--against</code> never ignored hosts, though it said it did.</strong> Comparing a
rebuild against the site it replaces is the same question as comparing
yesterday against today — <em>did this change anything</em> — but <code>diff()</code> keys a
finding on its whole URL, and every URL on <code>new.example.com</code> differs from its
twin on <code>example.com</code> by the host. The flag has passed <code>{ ignoreHost: true }</code>
since it shipped and <code>diff()</code> has never read a third argument, so the answer
came back with every finding fixed and every finding added at once, which is
no answer at all.</p>
<p>Two runs of different origins are now matched by path — trailing slash
ignored, query kept, since <code>/search?q=a</code> and <code>/search?q=b</code> are two pages on
any host. It decides for itself when it is not told, so the hosted <code>/diff</code>
and the macOS window get it without either having to know the rule.</p>
</li>
<li>
<p><strong>The macOS window could only compare two runs of the same site.</strong> Its
Compare menu filtered the library by host, so a rebuild kept beside the site
it replaces greyed the button out — the exact comparison somebody keeps two
reports around to make. Runs of other sites are now offered under their own
heading, and the sheet says it matched by path when the hosts differ.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/odin-scan-smart-contract-security/</link><pubDate>Sat, 29 Aug 2026 01:59:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Odin Scan GitHub Action is an AI-powered tool that performs security analysis on CosmWasm, Solana, and EVM projects. It integrates with GitHub to detect vulnerabilities before they reach production through SARIF uploads and inline comments. The action supports automatic platform detection or explicit specification, offers configurable thresholds for severity levels, and allows comment-triggered scans.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Odin Scan GitHub Action is an AI-powered tool that performs security analysis on CosmWasm, Solana, and EVM projects. It integrates with GitHub to detect vulnerabilities before they reach production through SARIF uploads and inline comments. The action supports automatic platform detection or explicit specification, offers configurable thresholds for severity levels, and allows comment-triggered scans.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial Release</p>
<p>AI-powered smart contract security analysis, now integrated directly into your GitHub workflow.</p>
<p>✨ Features</p>
<p>Multi-Platform Support</p>
<ul>
<li>CosmWasm - Rust-based smart contracts for Cosmos SDK</li>
<li>Solana (SVM) - Anchor and native Solana programs</li>
<li>EVM - Solidity and Vyper contracts</li>
<li>Auto-detection - Automatically identifies platform from your repo</li>
</ul>
<p>GitHub Integration</p>
<ul>
<li>Code Scanning - SARIF upload for native security alerts in the Security tab</li>
<li>PR Comments - Severity summary and top findings posted directly on pull requests</li>
<li>Inline Annotations - Critical/high findings appear as errors, medium/low as warnings on diffs</li>
<li>Artifact Upload - Full JSON report available as workflow artifact</li>
</ul>
<p>Customization</p>
<ul>
<li>Severity Thresholds - Fail builds at critical, high, medium, or low severity</li>
<li>Platform Override - Force specific platform detection when auto-detect isn&rsquo;t enough</li>
<li>Timeout Control - Configurable analysis timeout (default: 30 minutes)</li>
<li>Flexible Triggers - Run on push, PR, schedule, or manual dispatch</li>
</ul>
<p>🚀 Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Security Scan</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&#39;on&#39;</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">main</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">security-events</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">api-key</span>: <span style="color:#e6db74">&#39;${{ secrets.ODIN_SCAN_API_KEY }}&#39;</span>
</span></span></code></pre></div><p>📋 Requirements</p>
<ul>
<li>Odin Scan Pro subscription - Required for API access</li>
<li>API Key - Generate at <a href="https://odinscan.ai/dashboard/settings">https://odinscan.ai/dashboard/settings</a></li>
<li>GitHub Permissions - contents: read, security-events: write (for SARIF), pull-requests: write (for
comments)</li>
</ul>
<p>🔧 Configuration</p>
<p>All Inputs</p>
<p>| ┌────────────────────┬─────────────────────┬──────────────────────────────────────────────┐ |
| │       Input        │       Default       │                 Description                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ api-key            │ Required            │ Your Odin Scan API key (odin_sk_*)           │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ platform           │ auto                │ Target platform: auto, cosmwasm, solana, evm │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ severity-threshold │ high                │ Fail at: critical, high, medium, low, none   │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ fail-on-findings   │ true                │ Whether to fail workflow on findings         │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ comment-on-pr      │ true                │ Post summary comment on PRs                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-sarif       │ true                │ Upload SARIF to Code Scanning                │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-artifact    │ true                │ Upload full report as artifact               │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ timeout            │ 1800                │ Max analysis wait time (seconds)             │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ github-token       │ ${{ github.token }} │ Token for PR comments and SARIF              │ |
| └────────────────────┴─────────────────────┴──────────────────────────────────────────────┘ |</p>
<p>All Outputs</p>
<ul>
<li>analysis-id - Unique analysis identifier</li>
<li>status - Analysis status (completed, failed)</li>
<li>total-findings - Total number of findings</li>
<li>critical-count, high-count, medium-count, low-count - Counts by severity</li>
<li>report-url - Link to full report on Odin Scan</li>
<li>sarif-file - Path to generated SARIF file</li>
</ul>
<p>📝 Example Workflows</p>
<p>Basic (Auto-detect)</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span></code></pre></div><p>EVM with Medium Threshold</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">platform</span>: <span style="color:#ae81ff">evm</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">severity-threshold</span>: <span style="color:#ae81ff">medium</span>
</span></span></code></pre></div><p>Only on Solidity Changes</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#39;**.sol&#39;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">foundry.toml</span>
</span></span></code></pre></div><p>🔒 Security &amp; Privacy</p>
<ul>
<li>All API communication over HTTPS (TLS 1.2+)</li>
<li>API keys automatically masked in logs</li>
<li>No data stored by the action (stateless)</li>
<li>See <a href="https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md">https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md</a> for details</li>
</ul>
<p>📖 Documentation</p>
<ul>
<li>Action README - <a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></li>
<li>Odin Scan Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
<li>Get API Key - <a href="https://app.odinscan.ai/settings">https://app.odinscan.ai/settings</a></li>
</ul>
<p>🐛 Known Limitations</p>
<ul>
<li>Private repos - Requires github-token with repo access</li>
<li>Large repos - May need increased timeout for complex codebases</li>
<li>Code Scanning - Requires GitHub Advanced Security on private repos</li>
</ul>
<p>🙏 Support</p>
<ul>
<li>Issues - <a href="https://github.com/Odin-Scan/odin-scan-action/issues">https://github.com/Odin-Scan/odin-scan-action/issues</a></li>
<li>Email - <a href="mailto:support@odinscan.ai">support@odinscan.ai</a></li>
<li>Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
</ul>
<hr>
<p>Full Changelog: <a href="https://github.com/Odin-Scan/odin-scan-action/commits/v1">https://github.com/Odin-Scan/odin-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>pipewell-confluence-publisher</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/pipewell-confluence-publisher/</link><pubDate>Sat, 29 Aug 2026 01:58:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/pipewell-confluence-publisher/</guid><description>Version updated for https://github.com/pipewell/confluence-publisher to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the synchronization of markdown files in a repository with Confluence pages, using a YAML manifest file to manage page IDs and handle auto-creation. It supports Markdown features like headings, lists, tables, and inline code. The action triggers on push events and performs a one-way sync, converting Markdown to Confluence Storage Format and managing page identity through the manifest. If conflicts occur with manual edits, it logs warnings or fails the build.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pipewell/confluence-publisher">https://github.com/pipewell/confluence-publisher</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipewell-confluence-publisher">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the synchronization of markdown files in a repository with Confluence pages, using a YAML manifest file to manage page IDs and handle auto-creation. It supports Markdown features like headings, lists, tables, and inline code. The action triggers on push events and performs a one-way sync, converting Markdown to Confluence Storage Format and managing page identity through the manifest. If conflicts occur with manual edits, it logs warnings or fails the build.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixes">Fixes</h2>
<ul>
<li><strong>Manifest write-back is now per-page, not per-batch.</strong> Previously, an unexpected error on one file in a batch (e.g. a non-UTF8 file) could crash the whole run before the manifest was saved, losing an earlier file&rsquo;s already-created <code>page_id</code> and causing a duplicate page on the next run. The manifest is now saved after every file.</li>
<li><strong><code>create_page</code> no longer retries on 5xx/429.</strong> A lost response after Confluence had already created the page could previously cause a retried request to create a second, duplicate page. Page creation now fails fast instead of silently duplicating.</li>
<li><strong><code>space_id</code> is validated at manifest load time.</strong> A page with no resolvable <code>space_id</code> (its own override or <code>defaults.space_id</code>) now fails clearly before any API calls, instead of a confusing error deep inside a network request.</li>
<li><strong>Ordered list <code>start=</code> is preserved.</strong> <code>3. foo</code> / <code>4. bar</code> no longer silently renders as <code>1, 2</code> in Confluence.</li>
<li><strong>Table column alignment is preserved.</strong> <code>:---</code>, <code>---:</code>, and <code>:---:</code> now carry through to Confluence instead of always rendering left-aligned.</li>
<li><strong>Raw HTML now actually raises a build error, as documented.</strong> ⚠️ Potentially build-affecting: <code>HtmlSpan</code>/<code>HtmlBlock</code> were never registered with the Markdown parser, so raw HTML previously fell through silently as escaped literal text instead of failing the build per the README&rsquo;s documented behaviour. If your docs contain raw HTML tags, this release will now correctly fail those builds &ndash; convert them to Markdown syntax.</li>
<li><strong>Manifest comments now survive automated write-back.</strong> <code>confluence-manifest.yaml</code> is written via a comment-preserving YAML round-trip (<code>ruamel.yaml</code>, new dependency) instead of plain PyYAML, which silently deleted all comments on every automated commit.</li>
</ul>
<h2 id="docs">Docs</h2>
<ul>
<li><code>docs/MANIFEST_SPEC.md</code> corrected: <code>space_id</code> is always a Confluence space key, never the numeric Cloud space ID.</li>
</ul>
<h2 id="also-in-this-release-since-v102">Also in this release (since v1.0.2)</h2>
<ul>
<li><code>confluence-publisher@v1</code> now resolves correctly (major tag moved forward).</li>
</ul>
]]></content:encoded></item><item><title>GSC Security Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/gsc-security-audit/</link><pubDate>Sat, 29 Aug 2026 01:57:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/gsc-security-audit/</guid><description>Version updated for https://github.com/poliakarmai/gsc to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GSC is a GitHub Action that performs SAST (Static Application Security Testing) and security audits on code repositories, providing features like PoC auto-generation, proof-of-fix, self-healing CI, and LLM-verification. It helps developers identify and fix vulnerabilities in their projects efficiently, and offers BYO-LLM support to customize the risk assessment process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/poliakarmai/gsc">https://github.com/poliakarmai/gsc</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gsc-security-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GSC is a GitHub Action that performs SAST (Static Application Security Testing) and security audits on code repositories, providing features like PoC auto-generation, proof-of-fix, self-healing CI, and LLM-verification. It helps developers identify and fix vulnerabilities in their projects efficiently, and offers BYO-LLM support to customize the risk assessment process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Self-learning code audit: 50 detectors, SQLi/XSS/NoSQL, PoC generation, BYO-LLM revalidation</p>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-api-onboarding/</link><pubDate>Sat, 29 Aug 2026 01:55:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v3.5.7.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the onboarding process for new API repositories, using Postman’s API to bootstrap a workspace, upload an OpenAPI specification, generate collections and tests, sync artifacts to a repository, and run built-in smoke and contract checks. It provides a comprehensive solution that includes automated testing and CI/CD integration, ensuring that the repository adheres to standards-grounded tests and contract assertions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v3.5.7</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the onboarding process for new API repositories, using Postman&rsquo;s API to bootstrap a workspace, upload an OpenAPI specification, generate collections and tests, sync artifacts to a repository, and run built-in smoke and contract checks. It provides a comprehensive solution that includes automated testing and CI/CD integration, ensuring that the repository adheres to standards-grounded tests and contract assertions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/91">https://github.com/postman-cs/postman-api-onboarding-action/pull/91</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/92">https://github.com/postman-cs/postman-api-onboarding-action/pull/92</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/93">https://github.com/postman-cs/postman-api-onboarding-action/pull/93</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/94">https://github.com/postman-cs/postman-api-onboarding-action/pull/94</a></li>
<li>chore(deps): pin Insights onboarding v2.2.1 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/95">https://github.com/postman-cs/postman-api-onboarding-action/pull/95</a></li>
<li>fix: consume Insights human-session normalization by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/96">https://github.com/postman-cs/postman-api-onboarding-action/pull/96</a></li>
<li>fix: consume repo-sync v2.2.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/97">https://github.com/postman-cs/postman-api-onboarding-action/pull/97</a></li>
<li>fix: expose mock environment and refresh Azure pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/98">https://github.com/postman-cs/postman-api-onboarding-action/pull/98</a></li>
<li>feat: pass mock visibility policy through to repo-sync by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/99">https://github.com/postman-cs/postman-api-onboarding-action/pull/99</a></li>
<li>chore: pin repo-sync v2.4.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/100">https://github.com/postman-cs/postman-api-onboarding-action/pull/100</a></li>
<li>fix: document private mock credential paths for consumers by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/101">https://github.com/postman-cs/postman-api-onboarding-action/pull/101</a></li>
<li>fix(deps): advance the bootstrap pin to v2.13.2 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/102">https://github.com/postman-cs/postman-api-onboarding-action/pull/102</a></li>
<li>fix(deps): advance bootstrap and repo-sync pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/103">https://github.com/postman-cs/postman-api-onboarding-action/pull/103</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/104">https://github.com/postman-cs/postman-api-onboarding-action/pull/104</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.8 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/105">https://github.com/postman-cs/postman-api-onboarding-action/pull/105</a></li>
<li>fix(deps): advance bootstrap pin to v2.13.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/106">https://github.com/postman-cs/postman-api-onboarding-action/pull/106</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>fix(ci): validate sibling pins without local checkouts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/111">https://github.com/postman-cs/postman-api-onboarding-action/pull/111</a></li>
<li>feat(azure-devops): forward an explicit workspace squad id from the Windows template by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/112">https://github.com/postman-cs/postman-api-onboarding-action/pull/112</a></li>
<li>fix(release): harden composite pin and E2E releases by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/113">https://github.com/postman-cs/postman-api-onboarding-action/pull/113</a></li>
<li>fix(release): supersede stale aliases with pending cuts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/114">https://github.com/postman-cs/postman-api-onboarding-action/pull/114</a></li>
<li>fix(release): wait for correlated E2E run names by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/115">https://github.com/postman-cs/postman-api-onboarding-action/pull/115</a></li>
<li>fix(release): keep pin ratchet synchronized by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/116">https://github.com/postman-cs/postman-api-onboarding-action/pull/116</a></li>
<li>fix(ci): preserve pin updater test fixtures by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/117">https://github.com/postman-cs/postman-api-onboarding-action/pull/117</a></li>
<li>fix(release): reconcile failed release completions by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/118">https://github.com/postman-cs/postman-api-onboarding-action/pull/118</a></li>
<li>fix(release): emit automated completion events by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/119">https://github.com/postman-cs/postman-api-onboarding-action/pull/119</a></li>
<li>fix(release): bound failed release recovery by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/120">https://github.com/postman-cs/postman-api-onboarding-action/pull/120</a></li>
<li>fix(release): hold auto release through E2E completion by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/121">https://github.com/postman-cs/postman-api-onboarding-action/pull/121</a></li>
<li>feat: expose spec-only onboarding scope by @sean-riney in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/123">https://github.com/postman-cs/postman-api-onboarding-action/pull/123</a></li>
<li>docs: add service-account workspace permission preflight by @andrewpostymt in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/122">https://github.com/postman-cs/postman-api-onboarding-action/pull/122</a></li>
<li>chore(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/108">https://github.com/postman-cs/postman-api-onboarding-action/pull/108</a></li>
<li>fix(ci): make cache pin assertion semantic by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/124">https://github.com/postman-cs/postman-api-onboarding-action/pull/124</a></li>
<li>chore(deps): bump actions/cache from 4.2.0 to 6.1.0 in the actions group across 1 directory by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/109">https://github.com/postman-cs/postman-api-onboarding-action/pull/109</a></li>
<li>feat: publish as @postman/onboarding-api with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/127">https://github.com/postman-cs/postman-api-onboarding-action/pull/127</a></li>
<li>fix(release): gate alias advance on npm publish output, not job result by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/128">https://github.com/postman-cs/postman-api-onboarding-action/pull/128</a></li>
<li>fix(release): keep alias gates on publish job result by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/129">https://github.com/postman-cs/postman-api-onboarding-action/pull/129</a></li>
<li>feat: add monorepo working-directory by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/130">https://github.com/postman-cs/postman-api-onboarding-action/pull/130</a></li>
<li>fix(release): require pull requests for pin advances by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/131">https://github.com/postman-cs/postman-api-onboarding-action/pull/131</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @postman-suite-pin-bot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/134">https://github.com/postman-cs/postman-api-onboarding-action/pull/134</a></li>
<li>chore: ignore local plans by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/139">https://github.com/postman-cs/postman-api-onboarding-action/pull/139</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @postman-suite-pin-bot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/142">https://github.com/postman-cs/postman-api-onboarding-action/pull/142</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @postman-suite-pin-bot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/143">https://github.com/postman-cs/postman-api-onboarding-action/pull/143</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @postman-suite-pin-bot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/144">https://github.com/postman-cs/postman-api-onboarding-action/pull/144</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@github-actions[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>@andrewpostymt made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/122">https://github.com/postman-cs/postman-api-onboarding-action/pull/122</a></li>
<li>@postman-suite-pin-bot[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/134">https://github.com/postman-cs/postman-api-onboarding-action/pull/134</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.5.7">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.5.7</a></p>
]]></content:encoded></item><item><title>Postman Onboarding AWS Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-aws-spec-discovery/</link><pubDate>Sat, 29 Aug 2026 01:54:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-aws-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v3.3.3.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: AWS Spec Discovery action automates the discovery and export of API specs from AWS services using your existing credentials. It solves problems by automatically resolving and exporting specs from AWS, reducing the need for manual configuration and providing a source-of-truth for Postman onboarding. The action is part of the Postman API Onboarding suite and supports various providers, ensuring seamless integration with other Postman actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-aws-spec-discovery-action">https://github.com/postman-cs/postman-aws-spec-discovery-action</a></strong> to version <strong>v3.3.3</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-aws-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: AWS Spec Discovery action automates the discovery and export of API specs from AWS services using your existing credentials. It solves problems by automatically resolving and exporting specs from AWS, reducing the need for manual configuration and providing a source-of-truth for Postman onboarding. The action is part of the Postman API Onboarding suite and supports various providers, ensuring seamless integration with other Postman actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/53">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/53</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/54">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/54</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/55">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/55</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/56">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/56</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/57">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/57</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/58">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/58</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/62">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/62</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/64">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/64</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/65">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/65</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/66">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/66</a></li>
<li>fix(ci): address Codex writeback feedback by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/67">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/67</a></li>
<li>fix(ci): use ESM execSync and update permission test by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/68">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/68</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/69">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/69</a></li>
<li>feat: publish as @postman/onboarding-aws-spec-discovery with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/73">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/73</a></li>
<li>fix(release): tolerate npm registry propagation by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/74">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/74</a></li>
<li>fix(deps): migrate automation core scope by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/75">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/75</a></li>
<li>chore: ignore local plans by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/77">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/77</a></li>
<li>fix(security): harden untrusted spec processing by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/78">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/78</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v3.1.4...v3.3.3">https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v3.1.4...v3.3.3</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-workspace-bootstrap/</link><pubDate>Sat, 29 Aug 2026 01:53:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.21.5.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Workspace Bootstrap GitHub Action automates the process of provisioning a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections with executable tests. This action simplifies the setup of testing environments by automating the import, linting, and testing of API specifications. It supports various protocols and provides comprehensive enforcement layers to ensure test accuracy and reliability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.21.5</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Workspace Bootstrap GitHub Action automates the process of provisioning a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections with executable tests. This action simplifies the setup of testing environments by automating the import, linting, and testing of API specifications. It supports various protocols and provides comprehensive enforcement layers to ensure test accuracy and reliability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: normalize multifile receipt after v2.21.2 by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/218">https://github.com/postman-cs/postman-bootstrap-action/pull/218</a></li>
<li>chore: ignore local plans by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/220">https://github.com/postman-cs/postman-bootstrap-action/pull/220</a></li>
<li>chore: rebind multifile receipt to source by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/221">https://github.com/postman-cs/postman-bootstrap-action/pull/221</a></li>
<li>fix(security): harden untrusted input boundaries by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/222">https://github.com/postman-cs/postman-bootstrap-action/pull/222</a></li>
<li>fix(preview): stabilize concurrent collection markers by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/224">https://github.com/postman-cs/postman-bootstrap-action/pull/224</a></li>
<li>fix(release): refresh E2E registry revision by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/225">https://github.com/postman-cs/postman-bootstrap-action/pull/225</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2.21.2...v2.21.5">https://github.com/postman-cs/postman-bootstrap-action/compare/v2.21.2...v2.21.5</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Insights Linking</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-insights-linking/</link><pubDate>Sat, 29 Aug 2026 01:52:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-insights-linking/</guid><description>Version updated for https://github.com/postman-cs/postman-insights-onboarding-action to version v2.5.2.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the linking of services discovered by Postman Insights to a user’s Postman workspace and environment, ensuring that every service lands in the catalog with a collection, repo link, and live telemetry. It supports linking to specific workspaces and environments and requires human-user credentials for authentication. The action does not deploy any resources but focuses on updating existing ones after deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-insights-onboarding-action">https://github.com/postman-cs/postman-insights-onboarding-action</a></strong> to version <strong>v2.5.2</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-insights-linking">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the linking of services discovered by Postman Insights to a user&rsquo;s Postman workspace and environment, ensuring that every service lands in the catalog with a collection, repo link, and live telemetry. It supports linking to specific workspaces and environments and requires human-user credentials for authentication. The action does not deploy any resources but focuses on updating existing ones after deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut from bootstrap by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/66">https://github.com/postman-cs/postman-insights-onboarding-action/pull/66</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/67">https://github.com/postman-cs/postman-insights-onboarding-action/pull/67</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/68">https://github.com/postman-cs/postman-insights-onboarding-action/pull/68</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/69">https://github.com/postman-cs/postman-insights-onboarding-action/pull/69</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/70">https://github.com/postman-cs/postman-insights-onboarding-action/pull/70</a></li>
<li>feat: ship self-contained SEA binary (no npm/Node) by @mmorales-post in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/64">https://github.com/postman-cs/postman-insights-onboarding-action/pull/64</a></li>
<li>fix: accept live human Insights sessions by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/71">https://github.com/postman-cs/postman-insights-onboarding-action/pull/71</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/76">https://github.com/postman-cs/postman-insights-onboarding-action/pull/76</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/78">https://github.com/postman-cs/postman-insights-onboarding-action/pull/78</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/79">https://github.com/postman-cs/postman-insights-onboarding-action/pull/79</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/80">https://github.com/postman-cs/postman-insights-onboarding-action/pull/80</a></li>
<li>fix(ci): address Codex writeback feedback by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/81">https://github.com/postman-cs/postman-insights-onboarding-action/pull/81</a></li>
<li>fix(ci): use ESM execSync and update permission test by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/82">https://github.com/postman-cs/postman-insights-onboarding-action/pull/82</a></li>
<li>fix(ci): keep gate logs outside the checkout by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/83">https://github.com/postman-cs/postman-insights-onboarding-action/pull/83</a></li>
<li>feat: publish as @postman/onboarding-insights with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/87">https://github.com/postman-cs/postman-insights-onboarding-action/pull/87</a></li>
<li>fix(release): tolerate npm registry propagation by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/88">https://github.com/postman-cs/postman-insights-onboarding-action/pull/88</a></li>
<li>fix(release): recover workflow-bearing aliases by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/89">https://github.com/postman-cs/postman-insights-onboarding-action/pull/89</a></li>
<li>fix(deps): migrate automation core scope by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/90">https://github.com/postman-cs/postman-insights-onboarding-action/pull/90</a></li>
<li>chore: ignore local plans by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/92">https://github.com/postman-cs/postman-insights-onboarding-action/pull/92</a></li>
<li>fix(security): bind trusted runtime and artifact inputs by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/93">https://github.com/postman-cs/postman-insights-onboarding-action/pull/93</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@mmorales-post made their first contribution in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/64">https://github.com/postman-cs/postman-insights-onboarding-action/pull/64</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2.1.8...v2.5.2">https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2.1.8...v2.5.2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-repo-sync/</link><pubDate>Sat, 29 Aug 2026 01:51:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.10.3.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Repo Sync GitHub Action exports Postman collections and environments into a repository and automates CI, mocking, and monitoring. It solves the problem of maintaining API documentation and infrastructure in sync with changes to Postman projects, providing a streamlined approach to integrating APIs into development workflows. The action supports various input configurations, including workspace-specific IDs, baseline collections, and runtime URLs, making it versatile for different use cases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.10.3</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Repo Sync GitHub Action exports Postman collections and environments into a repository and automates CI, mocking, and monitoring. It solves the problem of maintaining API documentation and infrastructure in sync with changes to Postman projects, providing a streamlined approach to integrating APIs into development workflows. The action supports various input configurations, including workspace-specific IDs, baseline collections, and runtime URLs, making it versatile for different use cases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/134">https://github.com/postman-cs/postman-repo-sync-action/pull/134</a></li>
<li>feat: publish as @postman/onboarding-repo-sync with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/140">https://github.com/postman-cs/postman-repo-sync-action/pull/140</a></li>
<li>ci: install restricted dependencies without npm token by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/141">https://github.com/postman-cs/postman-repo-sync-action/pull/141</a></li>
<li>fix(deps): move private @postman platform packages to devDependencies by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/144">https://github.com/postman-cs/postman-repo-sync-action/pull/144</a></li>
<li>feat: support monorepo working directories by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/145">https://github.com/postman-cs/postman-repo-sync-action/pull/145</a></li>
<li>fix(release): repair stale rolling alias by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/146">https://github.com/postman-cs/postman-repo-sync-action/pull/146</a></li>
<li>fix(release): use workflow-capable tag token by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/147">https://github.com/postman-cs/postman-repo-sync-action/pull/147</a></li>
<li>fix(release): use writable workflow token by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/148">https://github.com/postman-cs/postman-repo-sync-action/pull/148</a></li>
<li>fix(release): scope workflow token to repository by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/149">https://github.com/postman-cs/postman-repo-sync-action/pull/149</a></li>
<li>fix: fail when artifact commit is rejected by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/150">https://github.com/postman-cs/postman-repo-sync-action/pull/150</a></li>
<li>fix(deps): migrate automation core scope by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/151">https://github.com/postman-cs/postman-repo-sync-action/pull/151</a></li>
<li>chore: ignore local plans by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/153">https://github.com/postman-cs/postman-repo-sync-action/pull/153</a></li>
<li>fix(security): harden secret persistence checks by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/154">https://github.com/postman-cs/postman-repo-sync-action/pull/154</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.10.3">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.10.3</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Smoke Flow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-smoke-flow/</link><pubDate>Sat, 29 Aug 2026 01:50:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/postman-onboarding-smoke-flow/</guid><description>Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v3.7.4.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Smoke Flow action reshapes a generated Postman Smoke collection into an ordered journey, automatically determining the flow path using postman/flow.yaml or deriving it from an OpenAPI spec if it’s absent. It supports auto-curation of a manifest and runtime auth injection for OAuth2 and API keys. The composite action is part of the larger Postman API Onboarding suite and requires inputs such as project name, workspace ID, spec ID, Smoke collection ID, flow path, spec path, access token, and region.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-smoke-flow-action">https://github.com/postman-cs/postman-smoke-flow-action</a></strong> to version <strong>v3.7.4</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-smoke-flow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Smoke Flow action reshapes a generated Postman Smoke collection into an ordered journey, automatically determining the flow path using <code>postman/flow.yaml</code> or deriving it from an OpenAPI spec if it&rsquo;s absent. It supports auto-curation of a manifest and runtime auth injection for OAuth2 and API keys. The composite action is part of the larger Postman API Onboarding suite and requires inputs such as project name, workspace ID, spec ID, Smoke collection ID, flow path, spec path, access token, and region.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): cut immutable tags only after gates pass on main by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/57">https://github.com/postman-cs/postman-smoke-flow-action/pull/57</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/58">https://github.com/postman-cs/postman-smoke-flow-action/pull/58</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/59">https://github.com/postman-cs/postman-smoke-flow-action/pull/59</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/60">https://github.com/postman-cs/postman-smoke-flow-action/pull/60</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/61">https://github.com/postman-cs/postman-smoke-flow-action/pull/61</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/76">https://github.com/postman-cs/postman-smoke-flow-action/pull/76</a></li>
<li>feat: publish as @postman/onboarding-smoke-flow with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/80">https://github.com/postman-cs/postman-smoke-flow-action/pull/80</a></li>
<li>feat: support monorepo working directories by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/81">https://github.com/postman-cs/postman-smoke-flow-action/pull/81</a></li>
<li>fix(release): tolerate npm registry propagation by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/82">https://github.com/postman-cs/postman-smoke-flow-action/pull/82</a></li>
<li>fix: activate CLI working directory once by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/83">https://github.com/postman-cs/postman-smoke-flow-action/pull/83</a></li>
<li>fix(deps): migrate automation core scope by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/84">https://github.com/postman-cs/postman-smoke-flow-action/pull/84</a></li>
<li>chore: ignore local plans by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/86">https://github.com/postman-cs/postman-smoke-flow-action/pull/86</a></li>
<li>fix: harden untrusted flow inputs by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/87">https://github.com/postman-cs/postman-smoke-flow-action/pull/87</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.7...v3.7.4">https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.7...v3.7.4</a></p>
]]></content:encoded></item><item><title>action-semver</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/action-semver/</link><pubDate>Sat, 29 Aug 2026 01:49:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/action-semver/</guid><description>Version updated for https://github.com/quike/action-semantic-release to version v3.21.0.
This action is used across all versions by 5 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action action-semantic-release is a tool for automating the release process using semantic versioning. It simplifies the workflow by handling the generation of release notes, tagging, and publishing on various platforms like npm, PyPI, or Docker Hub. This action helps developers streamline their release process, ensuring that versions are correctly managed according to semver rules.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quike/action-semantic-release">https://github.com/quike/action-semantic-release</a></strong> to version <strong>v3.21.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-semver">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>action-semantic-release</code> is a tool for automating the release process using semantic versioning. It simplifies the workflow by handling the generation of release notes, tagging, and publishing on various platforms like npm, PyPI, or Docker Hub. This action helps developers streamline their release process, ensuring that versions are correctly managed according to semver rules.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="3210-2026-08-28"><a href="https://github.com/quike/action-semantic-release/compare/v3.20.1...v3.21.0">3.21.0</a> (2026-08-28)</h1>
]]></content:encoded></item><item><title>Xcode Packages Update</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/xcode-packages-update/</link><pubDate>Sat, 29 Aug 2026 01:48:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/xcode-packages-update/</guid><description>Version updated for https://github.com/quver/xcode-packages-update to version v4.0.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the management of Xcode Swift Package Manager (SPM) dependencies. It resolves all SPM packages, detects changes, and generates an HTML dependency report with version diffs, repo links, and type badges. Optionally, it outputs a CycloneDX SBOM for machine-readable bill of materials and classifies packages as App or Development automatically. The action is useful for maintaining consistent and secure dependencies across projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quver/xcode-packages-update">https://github.com/quver/xcode-packages-update</a></strong> to version <strong>v4.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xcode-packages-update">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the management of Xcode Swift Package Manager (SPM) dependencies. It resolves all SPM packages, detects changes, and generates an HTML dependency report with version diffs, repo links, and type badges. Optionally, it outputs a CycloneDX SBOM for machine-readable bill of materials and classifies packages as App or Development automatically. The action is useful for maintaining consistent and secure dependencies across projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #84 from quver/release/v4.0.3 (d209aee)</li>
<li>release: v4.0.3 (b2736c3)</li>
<li>Merge pull request #83 from quver/dependabot/npm_and_yarn/dev-dependencies-2534e80e37 (11f366b)</li>
<li>build(deps-dev): bump the dev-dependencies group with 5 updates (01a177a)</li>
<li>Merge pull request #82 from quver/dependabot/npm_and_yarn/dev-dependencies-dcfd69fc34 (493cc51)</li>
<li>build(deps-dev): bump globals in the dev-dependencies group (e1a7ae8)</li>
<li>Merge pull request #81 from quver/release/v4.0.2 (f0aa022)</li>
<li>release: v4.0.2 (3767881)</li>
<li>Merge pull request #80 from quver/dependabot/npm_and_yarn/dev-dependencies-e1dac8ee3a (82acb6b)</li>
<li>build(deps-dev): bump the dev-dependencies group across 1 directory with 4 updates (84c588e)</li>
</ul>
]]></content:encoded></item><item><title>SBOMlyze Diff</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/sbomlyze-diff/</link><pubDate>Sat, 29 Aug 2026 01:46:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/sbomlyze-diff/</guid><description>Version updated for https://github.com/rezmoss/sbomlyze to version v0.5.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary sbomlyze is an open-source GitHub Action that compares Software Bills of Materials (SBOMs) to detect changes between builds, versions, or releases. It uses component hashes instead of version strings, which helps in identifying package swaps without bumping the version number. This tool is particularly useful for security teams to ensure integrity and compliance in their software supply chain processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rezmoss/sbomlyze">https://github.com/rezmoss/sbomlyze</a></strong> to version <strong>v0.5.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sbomlyze-diff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>sbomlyze</code> is an open-source GitHub Action that compares Software Bills of Materials (SBOMs) to detect changes between builds, versions, or releases. It uses component hashes instead of version strings, which helps in identifying package swaps without bumping the version number. This tool is particularly useful for security teams to ensure integrity and compliance in their software supply chain processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>fdb5e2b99b7d7d162a0c269c7cd6c2da2f48b9c7 update pkgs (#50)</li>
</ul>
]]></content:encoded></item><item><title>AI Shipcheck</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/ai-shipcheck/</link><pubDate>Sat, 29 Aug 2026 01:45:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/ai-shipcheck/</guid><description>Version updated for https://github.com/sinceaihq/ai-shipcheck to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The AI Shipcheck action automates the security scanning of Node.js applications to identify potential vulnerabilities such as hardcoded secrets, insecure routes, and open redirects. It helps developers ensure their application is secure before deployment by running static code analysis locally.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sinceaihq/ai-shipcheck">https://github.com/sinceaihq/ai-shipcheck</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-shipcheck">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The AI Shipcheck action automates the security scanning of Node.js applications to identify potential vulnerabilities such as hardcoded secrets, insecure routes, and open redirects. It helps developers ensure their application is secure before deployment by running static code analysis locally.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI Shipcheck tells you whether a JavaScript or TypeScript project is ready to
deploy, with evidence for every finding. It runs locally: no signup, no API
key, and nothing from the scanned repository is executed or uploaded.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx ai-shipcheck .
</span></span></code></pre></div><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sinceaihq/ai-shipcheck@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">critical</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">min-score</span>: <span style="color:#ae81ff">80</span>
</span></span></code></pre></div><p>See the <a href="https://github.com/sinceaihq/ai-shipcheck/blob/main/CHANGELOG.md">changelog</a>
for everything in this release, and
<a href="https://github.com/sinceaihq/ai-shipcheck/blob/main/corpus/TRIAGE.md">corpus/TRIAGE.md</a>
for how the rules were validated against twenty real public repositories.</p>
<p>This is static analysis of source code. It is not a security certification, and
a clean report means the checks it knows how to make found nothing — not that
the code is correct. The
<a href="https://github.com/sinceaihq/ai-shipcheck/blob/main/docs/LIMITATIONS.md">limitations</a>
are documented.</p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/smyklot/</link><pubDate>Sat, 29 Aug 2026 01:44:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.50.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges based on the repository’s CODEOWNERS file. It supports multiple command formats, allows for explicit merge methods, provides reaction-based commands, and includes features for cleanup and approval deduplication. The action minimizes permissions and can be run as a GitHub Action or as a webhook service covering all repositories where it is installed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.50.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges based on the repository&rsquo;s CODEOWNERS file. It supports multiple command formats, allows for explicit merge methods, provides reaction-based commands, and includes features for cleanup and approval deduplication. The action minimizes permissions and can be run as a GitHub Action or as a webhook service covering all repositories where it is installed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1500-2026-08-28"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.49.1...v1.50.0">1.50.0</a> (2026-08-28)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>sync:</strong> configure preserve-first file formatting (<a href="https://github.com/smykla-skalski/smyklot/issues/333">#333</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/c88a4cc5cd33a492988809141defb4998679657f">c88a4cc</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update github.com/tailscale/hujson digest to b80ff77 (<a href="https://github.com/smykla-skalski/smyklot/issues/334">#334</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/f21349cb7c6b7a5d11b2886d33040cdb57c1a521">f21349c</a>)</li>
<li><strong>panel:</strong> stabilize frontend release validation (<a href="https://github.com/smykla-skalski/smyklot/issues/336">#336</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/bb2ab68332b7bd1118ce71524fa61464c373cffc">bb2ab68</a>)</li>
</ul>
<h2 id="smyklot-v1500">Smyklot v1.50.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.50.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>bb9b3b5115be814fa580487c07403b60413302cd chore(release): bump version to 1.50.0</li>
<li>bb2ab68332b7bd1118ce71524fa61464c373cffc fix(panel): stabilize frontend release validation (#336)</li>
<li>1e386a78a8a5776418cd64d17196d1898e10c627 chore(deps): update dependency @tanstack/svelte-query to v6.1.44 (#335)</li>
<li>f21349cb7c6b7a5d11b2886d33040cdb57c1a521 fix(deps): update github.com/tailscale/hujson digest to b80ff77 (#334)</li>
<li>c88a4cc5cd33a492988809141defb4998679657f feat(sync): configure preserve-first file formatting (#333)</li>
</ul>
]]></content:encoded></item><item><title>Graceful Boundaries Conformance Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/graceful-boundaries-conformance-check/</link><pubDate>Sat, 29 Aug 2026 01:43:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/graceful-boundaries-conformance-check/</guid><description>Version updated for https://github.com/snapsynapse/graceful-boundaries to version v1.5.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Graceful Boundaries is an open specification that grades API responses based on their conformance to a set of standards. It provides proactive discovery, structured refusal, and constructive guidance to help autonomous agents understand and act on operational limits efficiently. The action automates the process of checking response codes and providing actionable feedback for improving API reliability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snapsynapse/graceful-boundaries">https://github.com/snapsynapse/graceful-boundaries</a></strong> to version <strong>v1.5.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/graceful-boundaries-conformance-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Graceful Boundaries is an open specification that grades API responses based on their conformance to a set of standards. It provides proactive discovery, structured refusal, and constructive guidance to help autonomous agents understand and act on operational limits efficiently. The action automates the process of checking response codes and providing actionable feedback for improving API reliability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="graceful-boundaries-154">Graceful Boundaries 1.5.4</h1>
<p>Graceful Boundaries 1.5.4 is a maintenance and adoption-tooling release. It does not change the normative conformance levels, required fields, or response classes.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>The checker now reports the single smallest change that raises a service&rsquo;s confirmed conformance level, with matching human-readable and JSON output.</li>
<li>The README leads with the dependency-free <code>npx</code> check and CI integration, includes verified Level 4 output, and makes RFC 9457 compatibility visible at the first specification mention.</li>
<li>Adopter registration now starts with a URL-only issue. Validation remains evidence-led, and unanswered directory proposals remain gated on maintainer confirmation.</li>
<li>The RFC 9457 profile, comparative caller benchmark protocol, roadmap, conformance counts, and root-skill layout records are reconciled with current repository behavior.</li>
<li><code>SECURITY-AUDIT.md</code> adds concrete safer and unsafe examples for SC-2 through SC-6.</li>
<li>The published limits schema no longer reserves the roadmap-only <code>agentCapable</code> field.</li>
<li>ClawHub preparation now produces a deterministic three-file audit-only package from <code>build/clawhub-graceful-boundaries/</code>; repository-root packaging fails closed to <code>SKILL.md</code>, and the card reflects the repository&rsquo;s actual license split.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li>270 offline tests pass.</li>
<li>The offline search contract passes with zero defects.</li>
<li>The npm tarball installs in a clean consumer directory and its installed CLI confirms <a href="https://siteline.to/">https://siteline.to/</a> at Level 4.</li>
<li>The generated ClawHub bundle contains only <code>SKILL.md</code>, <code>MANIFEST.yaml</code>, and <code>skill-card.md</code>.</li>
</ul>
<p>Full details are in <code>CHANGELOG.md</code>.</p>
]]></content:encoded></item><item><title>Agent Vigil</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/agent-vigil/</link><pubDate>Sat, 29 Aug 2026 01:41:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/agent-vigil/</guid><description>Version updated for https://github.com/sulmusic2-star/agent-vigil to version v0.22.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Vigil is a tool that ensures the integrity and accuracy of code changes by verifying them against predefined rules. It checks if a proposed commit or pull request complies with expected behavior, including ensuring that all necessary tests are run and that no unintended changes have been made to other parts of the codebase. The action can be used to ensure that tasks are completed correctly before they are merged into a repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sulmusic2-star/agent-vigil">https://github.com/sulmusic2-star/agent-vigil</a></strong> to version <strong>v0.22.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-vigil">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Vigil is a tool that ensures the integrity and accuracy of code changes by verifying them against predefined rules. It checks if a proposed commit or pull request complies with expected behavior, including ensuring that all necessary tests are run and that no unintended changes have been made to other parts of the codebase. The action can be used to ensure that tasks are completed correctly before they are merged into a repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Agent Vigil v0.22.0 makes the first useful result visible in one command.</p>
<ul>
<li><code>vigil protect</code> now chooses an immutable reviewed Action commit when no SHA is supplied.</li>
<li>The first run reports <code>PREPARED — not active yet</code> instead of showing expected pre-commit doctor failures as if setup were broken.</li>
<li>A disposable differential rehearsal proves that a real regression test fails on old code and passes on proposed code, while a planted weak test that passes on both versions is blocked.</li>
<li><code>vigil check &lt;public-pr-url&gt;</code> uses the exact commit embedded in the release package; a conflicting <code>--tool-ref</code> is rejected.</li>
<li>Public distribution records now keep GitHub and npm publication states separate.</li>
</ul>
<p>Exact main validation: <a href="https://github.com/sulmusic2-star/agent-vigil/actions/runs/33213167172">https://github.com/sulmusic2-star/agent-vigil/actions/runs/33213167172</a></p>
<p>The attached package is built from commit <code>5925e8bcbaf97f08c8c840252f486e96bf3f9775</code>. Its SHA-256 is recorded in the attached checksum file. This GitHub release does not by itself prove npm or Marketplace publication, outside adoption, payment, or revenue.</p>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/delivery-autopilot-runner/</link><pubDate>Sat, 29 Aug 2026 01:40:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.66.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Delivery Autopilot to automate the development process by taking a ticket from your tracker all the way to a reviewed pull request. It automates code writing, quality checks, and PR management using an AI pipeline within your own GitHub Actions environment. The key capabilities include checking out repository content, running AI coding, performing quality checks, creating pull requests, reporting status, and verifying signed instructions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.66</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Delivery Autopilot to automate the development process by taking a ticket from your tracker all the way to a reviewed pull request. It automates code writing, quality checks, and PR management using an AI pipeline within your own GitHub Actions environment. The key capabilities include checking out repository content, running AI coding, performing quality checks, creating pull requests, reporting status, and verifying signed instructions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runner-dist synced from AutoPilot 6b136b6fb492. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>Tessl Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/tessl-code-review/</link><pubDate>Sat, 29 Aug 2026 01:39:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/tessl-code-review/</guid><description>Version updated for https://github.com/tesslio/code-review-action to version v1.5.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of running Tessl Code Review on pull requests in a repository and publishing the results as native comments in the Pull Request. It handles various tasks such as checking out the head of the pull request, setting up the Tessl CLI, running reviews, managing stale branches, ensuring idempotency, sending failure notices, and archiving result artifacts. The action provides flexibility to configure profiles and lenses for specific checks, and it supports posting reviews under a different identity if needed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tesslio/code-review-action">https://github.com/tesslio/code-review-action</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tessl-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of running Tessl Code Review on pull requests in a repository and publishing the results as native comments in the Pull Request. It handles various tasks such as checking out the head of the pull request, setting up the Tessl CLI, running reviews, managing stale branches, ensuring idempotency, sending failure notices, and archiving result artifacts. The action provides flexibility to configure profiles and lenses for specific checks, and it supports posting reviews under a different identity if needed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Pin the Action to this release&rsquo;s commit SHA:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">tesslio/code-review-action@68497531d3454174dfca5cd25627757b881f2b66</span> <span style="color:#75715e"># v1.5.0</span>
</span></span></code></pre></div><p>This revision installs the current Tessl CLI release. Set the
<code>cli-version</code> input to pin an exact one.</p>
<p>The major tag now points here, so a caller on that tag is on this
revision.</p>
]]></content:encoded></item><item><title>LoadBearing Architecture Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/loadbearing-architecture-gate/</link><pubDate>Sat, 29 Aug 2026 01:38:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/loadbearing-architecture-gate/</guid><description>Version updated for https://github.com/vishweshji/loadbearing to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The LoadBearing GitHub Action automates the detection of architectural decisions in pull requests by analyzing code changes and raising alerts if they introduce significant changes that deserve human attention before merging. It uses an AI coding agent to explain detected architectural impacts, ensuring teams are aware of potential risks or dependencies introduced by new features or changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vishweshji/loadbearing">https://github.com/vishweshji/loadbearing</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/loadbearing-architecture-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The LoadBearing GitHub Action automates the detection of architectural decisions in pull requests by analyzing code changes and raising alerts if they introduce significant changes that deserve human attention before merging. It uses an AI coding agent to explain detected architectural impacts, ensuring teams are aware of potential risks or dependencies introduced by new features or changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="what-is-loadbearing">What is LoadBearing?</h2>
<p>LoadBearing is a local-first, deterministic architecture gate for pull requests. It flags PRs
that introduce a consequential architectural decision - a new persistent schema, a new
deployable, a public contract change, a new external dependency, or a new infrastructure
resource - and can require an explicit human sign-off before merge, only when one of those
actually happens. No account, no hosted service, no telemetry, no LLM in the loop for 0.1.
Every finding is backed by evidence from your diff, not a black-box score.</p>
<h2 id="whats-in-this-release">What&rsquo;s in this release</h2>
<p>Five deterministic detectors, each with its own default severity and documented false
positives/negatives:</p>
<table>
  <thead>
      <tr>
          <th>ID</th>
          <th>Detects</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>LB001</td>
          <td>New external dependency (npm, pip/poetry, Go modules, Cargo)</td>
      </tr>
      <tr>
          <td>LB002</td>
          <td>New/changed persistent schema (SQL migrations, Prisma, Django, Alembic, Rails)</td>
      </tr>
      <tr>
          <td>LB003</td>
          <td>New deployable (Kubernetes workload, Compose service, Serverless function)</td>
      </tr>
      <tr>
          <td>LB004</td>
          <td>Public contract change (OpenAPI, Protobuf, GraphQL)</td>
      </tr>
      <tr>
          <td>LB005</td>
          <td>New infrastructure resource (Terraform, Kubernetes infra objects, CloudFormation/SAM)</td>
      </tr>
  </tbody>
</table>
<p>Three ways to run it, same engine underneath:</p>
<ul>
<li><strong>CLI</strong> (<code>@loadbearing/cli</code>) - <code>review</code>, <code>init</code>, <code>explain</code>, <code>version</code></li>
<li><strong>GitHub Action</strong> (this release) - a required check that fails on a HIGH-impact PR and clears
automatically once an authorized reviewer approves the current commit</li>
<li><strong>MCP server</strong> (<code>@loadbearing/mcp</code>) - native tools for Claude Code, Cursor, and other MCP
clients</li>
</ul>
<h2 id="quick-start">Quick start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">LoadBearing</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">types</span>: [<span style="color:#ae81ff">opened, synchronize, reopened, ready_for_review]</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request_review</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">types</span>: [<span style="color:#ae81ff">submitted, dismissed]</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">architecture</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v6</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">fetch-depth</span>: <span style="color:#ae81ff">0</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vishweshji/loadbearing@v0.1.0</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">github-token</span>: <span style="color:#ae81ff">${{ github.token }}</span>
</span></span></code></pre></div><p>Full setup for the CLI and MCP server is in the <a href="https://github.com/vishweshji/loadbearing#readme">README</a>.</p>
<h2 id="testing">Testing</h2>
<p>177 automated tests, plus manual verification against six real, unmodified public repositories
(Terraform, Kubernetes, Django, Go, Rust tooling) across both broad-history diffs and
60-150-commit stress tests per repo. Details in <a href="https://github.com/vishweshji/loadbearing/blob/main/CHANGELOG.md">CHANGELOG.md</a>.</p>
<h2 id="known-limitations">Known limitations</h2>
<ul>
<li>No AsyncAPI or standalone JSON Schema contract detection yet (LB004)</li>
<li>No team-based reviewers - a GitHub Actions token can&rsquo;t reliably resolve org team membership
without extra permissions this project deliberately doesn&rsquo;t request</li>
<li>First release: not yet exercised on external pull requests beyond this repository&rsquo;s own
history</li>
</ul>
<p>See <a href="https://github.com/vishweshji/loadbearing/blob/main/docs/roadmap.md">docs/roadmap.md</a> for
what&rsquo;s next and explicit non-goals.</p>
]]></content:encoded></item><item><title>Move Closed Issue to Top of Project Column</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/move-closed-issue-to-top-of-project-column/</link><pubDate>Sat, 29 Aug 2026 01:37:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/move-closed-issue-to-top-of-project-column/</guid><description>Version updated for https://github.com/wozaki/project-closed-issue-move-to-top-action to version v1.27.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically moves closed issues to the top of a specified project column in GitHub Project V2. It checks if an issue belongs to a specific project, updates its status to the specified column (default: “Done”), and moves it to the top of that column. This ensures visibility of recently closed issues on the project board.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wozaki/project-closed-issue-move-to-top-action">https://github.com/wozaki/project-closed-issue-move-to-top-action</a></strong> to version <strong>v1.27.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-closed-issue-to-top-of-project-column">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically moves closed issues to the top of a specified project column in GitHub Project V2. It checks if an issue belongs to a specific project, updates its status to the specified column (default: &ldquo;Done&rdquo;), and moves it to the top of that column. This ensures visibility of recently closed issues on the project board.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">wozaki/project-closed-issue-move-to-top-action@c6464c429f9e50da8434e06473ad2c5157ef8c40</span> <span style="color:#75715e"># v1.27.0</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update int128/release-typescript-action action to v1.81.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/190">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/190</a></li>
<li>chore(deps): update dependency @tsconfig/node24 to v24.0.5 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/191">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/191</a></li>
<li>chore(deps): update int128/update-generated-files-action action to v2.109.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/192">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/192</a></li>
<li>chore(deps): update int128/wait-for-workflows-action action to v1.94.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/193">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/193</a></li>
<li>chore(deps): update pnpm to v11.22.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/194">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/194</a></li>
<li>chore(deps): update dependency vitest to v4.1.11 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/195">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/195</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/196">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/196</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.26.0...v1.27.0">https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.26.0...v1.27.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/b.ia-accessibility-checker/</link><pubDate>Sat, 29 Aug 2026 01:36:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/29/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines by mapping and analyzing guidelines against target audiences. It helps companies ensure their code meets WCAG standards, reducing learning curve costs and improving product accessibility for a larger audience. The action uses AI to measure and report on guideline compliance, enabling developers to fix issues before pushes are accepted.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines by mapping and analyzing guidelines against target audiences. It helps companies ensure their code meets WCAG standards, reducing learning curve costs and improving product accessibility for a larger audience. The action uses AI to measure and report on guideline compliance, enabling developers to fix issues before pushes are accepted.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>Sutura Verified Self-Healing CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/sutura-verified-self-healing-ci/</link><pubDate>Fri, 28 Aug 2026 18:04:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/sutura-verified-self-healing-ci/</guid><description>Version updated for https://github.com/juan294/sutura to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically fixes CI failures by reproducing them in isolated sandboxes, races candidate repairs, and audits evidence. It uses AI agents for diagnosis and proposes patches before opening a PR for human review. Sutura ensures safety by rejecting unsafe shortcuts and provides an HTML case file for evidence. It is built for the Nebius x NVIDIA Global AI Hackathon and can be tried with a judge demo.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juan294/sutura">https://github.com/juan294/sutura</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sutura-verified-self-healing-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically fixes CI failures by reproducing them in isolated sandboxes, races candidate repairs, and audits evidence. It uses AI agents for diagnosis and proposes patches before opening a PR for human review. Sutura ensures safety by rejecting unsafe shortcuts and provides an HTML case file for evidence. It is built for the Nebius x NVIDIA Global AI Hackathon and can be tried with a judge demo.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Sutura v0.1.1 gives the GitHub Action a unique Marketplace name.</p>
<p>It repairs actionable failures from pull requests, pushes, schedules, and manual dispatches. Direct runs receive evidence on the failing commit.</p>
<p>Sutura rejects stale branch heads before repair. The installer publishes as <a href="mailto:sutura@0.1.1">sutura@0.1.1</a> through npm trusted publishing.</p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/neurolink-ai/</link><pubDate>Fri, 28 Aug 2026 18:03:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v12.3.0.
This action is used across all versions by 11 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that unifies 30+ AI providers and 100+ models under one consistent API, providing a practical, TypeScript-first way to integrate AI into any application. It supports extraction from production systems at Juspay, offering switchable providers with built-in tools and enterprise features like Redis memory and multi-provider failover.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v12.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is a universal AI integration platform that unifies 30+ AI providers and 100+ models under one consistent API, providing a practical, TypeScript-first way to integrate AI into any application. It supports extraction from production systems at Juspay, offering switchable providers with built-in tools and enterprise features like Redis memory and multi-provider failover.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1230-2026-08-28"><a href="https://github.com/juspay/neurolink/compare/v12.2.6...v12.3.0">12.3.0</a> (2026-08-28)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>(providers):</strong>  onboard SambaNova as the second post-gate catalog provider (<a href="https://github.com/juspay/neurolink/commit/4184700e5c4fa6c7001e97a8d06eacdbed834724">4184700</a>), closes <a href="https://github.com/juspay/neurolink/issues/33">#33</a> <a href="https://github.com/1583/neurolink/issues/1584">1583/#1584</a></li>
</ul>
]]></content:encoded></item><item><title>ctxloom PR review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/ctxloom-pr-review/</link><pubDate>Fri, 28 Aug 2026 18:02:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/ctxloom-pr-review/</guid><description>Version updated for https://github.com/kodiii/ctxloom-pr-bot to version v1.7.13.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, ctxloom PR review, automates security risk assessment and reviewer suggestions on pull requests. It uses a local dependency graph to identify high-risk modules and files in the diff, suggesting reviewers from past commits. This tool helps maintain code quality by flagging potential issues before they are merged into the main branch.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kodiii/ctxloom-pr-bot">https://github.com/kodiii/ctxloom-pr-bot</a></strong> to version <strong>v1.7.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ctxloom-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, ctxloom PR review, automates security risk assessment and reviewer suggestions on pull requests. It uses a local dependency graph to identify high-risk modules and files in the diff, suggesting reviewers from past commits. This tool helps maintain code quality by flagging potential issues before they are merged into the main branch.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Auto-generated release for ctxloom-pr-bot v1.7.13. Source: <a href="https://github.com/kodiii/ctxloom/releases/tag/v1.7.13">https://github.com/kodiii/ctxloom/releases/tag/v1.7.13</a></p>
]]></content:encoded></item><item><title>Setup poly</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/setup-poly/</link><pubDate>Fri, 28 Aug 2026 18:01:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/setup-poly/</guid><description>Version updated for https://github.com/linzeyan/vscode-syntax to version v0.4.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of managing and integrating various language syntax highlighting, linting, and formatting tools into a single binary. It simplifies the installation and management of multiple VSCode extensions by providing a unified solution that can be shared between development environments and CI pipelines. The action manages multiple languages, including custom grammars and external toolchains for linting and formatting, ensuring consistent results across different platforms and environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/linzeyan/vscode-syntax">https://github.com/linzeyan/vscode-syntax</a></strong> to version <strong>v0.4.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-poly">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of managing and integrating various language syntax highlighting, linting, and formatting tools into a single binary. It simplifies the installation and management of multiple VSCode extensions by providing a unified solution that can be shared between development environments and CI pipelines. The action manages multiple languages, including custom grammars and external toolchains for linting and formatting, ensuring consistent results across different platforms and environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/linzeyan/vscode-syntax/compare/v0.4.2...v0.4.3">https://github.com/linzeyan/vscode-syntax/compare/v0.4.2...v0.4.3</a></p>
]]></content:encoded></item><item><title>Git Velocity Analyser</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/git-velocity-analyser/</link><pubDate>Fri, 28 Aug 2026 17:59:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/git-velocity-analyser/</guid><description>Version updated for https://github.com/lukaszraczylo/git-velocity to version v1.0.22.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Git Velocity is a GitHub Action that analyzes your Git repository activities and generates a beautiful, gamified dashboard to track developer velocity. It automates tasks such as analyzing commit, pull request, code review, issue, and meaningful line counts, providing a comprehensive view of development performance through metrics and achievements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lukaszraczylo/git-velocity">https://github.com/lukaszraczylo/git-velocity</a></strong> to version <strong>v1.0.22</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/git-velocity-analyser">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Git Velocity is a GitHub Action that analyzes your Git repository activities and generates a beautiful, gamified dashboard to track developer velocity. It automates tasks such as analyzing commit, pull request, code review, issue, and meaningful line counts, providing a comprehensive view of development performance through metrics and achievements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
]]></content:encoded></item><item><title>Aether Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/aether-deploy/</link><pubDate>Fri, 28 Aug 2026 17:58:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/aether-deploy/</guid><description>Version updated for https://github.com/Monoradioactivo/aetherpush-deploy-action to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of releasing React Native over-the-air updates using Aether. It simplifies the deployment workflow by wrapping the @aetherpush/cli commands and exposing the necessary package metadata as outputs. The action supports various inputs such as API key, app name, release command, and platform, allowing for customization based on specific needs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Monoradioactivo/aetherpush-deploy-action">https://github.com/Monoradioactivo/aetherpush-deploy-action</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aether-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of releasing React Native over-the-air updates using Aether. It simplifies the deployment workflow by wrapping the <code>@aetherpush/cli</code> commands and exposing the necessary package metadata as outputs. The action supports various inputs such as API key, app name, release command, and platform, allowing for customization based on specific needs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="040-2026-08-28"><a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/compare/v0.3.3...v0.4.0">0.4.0</a> (2026-08-28)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li>the blob-url and manifest-blob-url outputs are removed, and there is no replacement output. The presigned URL is deliberately no longer published. Workflows that referenced either output need updating.</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li>stop publishing signed bundle URLs as step outputs (<a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/issues/27">#27</a>) (<a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/commit/7ca1e8e49cc24776ade21a8de2b59e34115385b9">7ca1e8e</a>)</li>
</ul>
]]></content:encoded></item><item><title>Setup-Oracle-Test-Pilot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/setup-oracle-test-pilot/</link><pubDate>Fri, 28 Aug 2026 17:56:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/setup-oracle-test-pilot/</guid><description>Version updated for https://github.com/oracle-actions/setup-testpilot to version v1.0.31.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 35 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action setup-testpilot by Oracle helps automate the setup and management of Oracle Test Pilot for Third-Party Software within GitHub workflows. It provides various actions to provision, delete, create a registration token, and skip testing based on changes in specific files or folders. The action supports Linux platforms and offers customizable inputs and outputs to streamline the integration process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oracle-actions/setup-testpilot">https://github.com/oracle-actions/setup-testpilot</a></strong> to version <strong>v1.0.31</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>35</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-oracle-test-pilot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>setup-testpilot</code> by Oracle helps automate the setup and management of Oracle Test Pilot for Third-Party Software within GitHub workflows. It provides various actions to provision, delete, create a registration token, and skip testing based on changes in specific files or folders. The action supports Linux platforms and offers customizable inputs and outputs to streamline the integration process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add input parameter to always send a fully qualified hostname and service name (useful for autonomous) by @loiclefevre in <a href="https://github.com/oracle-actions/setup-testpilot/pull/22">https://github.com/oracle-actions/setup-testpilot/pull/22</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/oracle-actions/setup-testpilot/compare/v1.0.30...v1.0.31">https://github.com/oracle-actions/setup-testpilot/compare/v1.0.30...v1.0.31</a></p>
]]></content:encoded></item><item><title>Orchestra Run Pipeline</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/orchestra-run-pipeline/</link><pubDate>Fri, 28 Aug 2026 17:55:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/orchestra-run-pipeline/</guid><description>Version updated for https://github.com/orchestra-hq/run-pipeline to version v.1.6.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution and monitoring of Orchestra pipelines. It supports running both backed by Orchestra or Git-backed pipelines, allowing users to choose specific branches and tasks to run. The action provides options for polling pipeline status at regular intervals and managing environments, making it useful for continuous integration workflows that integrate with Orchestra projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/orchestra-hq/run-pipeline">https://github.com/orchestra-hq/run-pipeline</a></strong> to version <strong>v.1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/orchestra-run-pipeline">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution and monitoring of Orchestra pipelines. It supports running both backed by Orchestra or Git-backed pipelines, allowing users to choose specific branches and tasks to run. The action provides options for polling pipeline status at regular intervals and managing environments, making it useful for continuous integration workflows that integrate with Orchestra projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix - Handle SKIPPED pipeline run status to stop infinite polling by @gthesheep-orchestra in <a href="https://github.com/orchestra-hq/run-pipeline/pull/17">https://github.com/orchestra-hq/run-pipeline/pull/17</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@gthesheep-orchestra made their first contribution in <a href="https://github.com/orchestra-hq/run-pipeline/pull/17">https://github.com/orchestra-hq/run-pipeline/pull/17</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/orchestra-hq/run-pipeline/compare/v1.5.0...v.1.6.0">https://github.com/orchestra-hq/run-pipeline/compare/v1.5.0...v.1.6.0</a></p>
]]></content:encoded></item><item><title>Otzaria Plugin Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/otzaria-plugin-validator/</link><pubDate>Fri, 28 Aug 2026 17:55:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/otzaria-plugin-validator/</guid><description>Version updated for https://github.com/Otzaria/otzaria-plugin-validator to version v1.16.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the validation, building, and publishing process for Otzaria plugins. It performs static checks using pack-plugin, builds the .otzplugin file, and automatically publishes new versions to otzaria.org upon push to the main branch. It requires OTZARIA_USER and OTZARIA_PASSWORD secrets for authentication. The action also supports pull request validation without publishing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Otzaria/otzaria-plugin-validator">https://github.com/Otzaria/otzaria-plugin-validator</a></strong> to version <strong>v1.16.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/otzaria-plugin-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the validation, building, and publishing process for Otzaria plugins. It performs static checks using <code>pack-plugin</code>, builds the <code>.otzplugin</code> file, and automatically publishes new versions to otzaria.org upon push to the main branch. It requires <code>OTZARIA_USER</code> and <code>OTZARIA_PASSWORD</code> secrets for authentication. The action also supports pull request validation without publishing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Otzaria/otzaria-plugin-validator/compare/v1.16.0...v1.16.1">https://github.com/Otzaria/otzaria-plugin-validator/compare/v1.16.0...v1.16.1</a></p>
]]></content:encoded></item><item><title>action-debian-build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/action-debian-build/</link><pubDate>Fri, 28 Aug 2026 17:53:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/action-debian-build/</guid><description>Version updated for https://github.com/pkghaus/action-debian-build to version v1.2.0.
This action is used across all versions by 1 repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of building a Debian package from an upstream git tag and a custom debian/ directory. It resolves build dependencies, runs dpkg-buildpackage, checks the result with lintian, and collects artifacts. The action can be used to build packages for different Debian suites and architectures and is reusable for validating packaging repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pkghaus/action-debian-build">https://github.com/pkghaus/action-debian-build</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<p>Go to the <a href="https://github.com/marketplace/actions/action-debian-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of building a Debian package from an upstream git tag and a custom <code>debian/</code> directory. It resolves build dependencies, runs <code>dpkg-buildpackage</code>, checks the result with <code>lintian</code>, and collects artifacts. The action can be used to build packages for different Debian suites and architectures and is reusable for validating packaging repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="120---2026-08-27">[1.2.0] - 2026-08-27</h2>
<h3 id="added">Added</h3>
<ul>
<li><code>DEP8_EXTRA_DEBS</code> in <code>package.conf</code>: packages from this archive that the DEP-8
testbed needs, fetched and handed to autopkgtest alongside the built package.
The testbed is Debian only, so a dependency Debian does not carry cannot
otherwise resolve. Space-separated; a value that is not a list of Debian
package names fails the build before anything is installed.</li>
</ul>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/prowler-security-scan/</link><pubDate>Fri, 28 Aug 2026 17:52:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.40.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Prowler automates the discovery and assessment of security risks in cloud environments by running predefined checks against various AWS services, helping organizations identify potential vulnerabilities and ensure compliance with industry standards.
What’s Changed ✨ New features to highlight in this version Enjoy them all now for free at https://cloud.prowler.com/</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.40.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Prowler</strong> automates the discovery and assessment of security risks in cloud environments by running predefined checks against various AWS services, helping organizations identify potential vulnerabilities and ensure compliance with industry standards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-new-features-to-highlight-in-this-version">✨ New features to highlight in this version</h2>
<p>Enjoy them all now for free at <a href="https://cloud.prowler.com/">https://cloud.prowler.com/</a></p>
<h2 id="-slack-integration--alert-channel-destinations">💬 Slack Integration — Alert Channel Destinations</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Alerts can now reach Slack. Connect a Slack workspace from the Integrations page, authorize one or several destination channels (the connection check confirms each channel with a one-time message and names any channel Slack refuses), and pick those channels in the alert modal&rsquo;s &ldquo;Destination channels&rdquo; selector, next to the &ldquo;Recipients&rdquo; selector for email. The alerts list summarizes both in a single &ldquo;Destinations&rdquo; column, showing a rule&rsquo;s email recipients and Slack channels at a glance. Disconnecting the workspace and recovering from revoked credentials are handled from the same page.</p>
<p><img src="https://raw.githubusercontent.com/prowler-cloud/prowler/master/docs/images/prowler-app/slack/connected-workspace.png" alt="Connected Slack workspace on the Integrations page"></p>
<p><img src="https://raw.githubusercontent.com/prowler-cloud/prowler/master/docs/images/prowler-app/alerts/create-alert-modal.png" alt="Alert rule with Slack channel destinations"></p>
<p>Read more in the <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-slack-integration">Slack integration documentation</a> and the <a href="https://docs.prowler.com/user-guide/tutorials/prowler-alerts">Alerts documentation</a>.</p>
<h2 id="-lighthouse-ai--answer-feedback">🤖 Lighthouse AI — Answer Feedback</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Every Lighthouse AI answer can now be rated with a 👍 or 👎, with an optional field to describe what worked or what did not. Feedback is collected per answer, directly in the chat, and tells the team where Lighthouse should improve next.</p>
<p>Read more in the <a href="https://docs.prowler.com/getting-started/products/prowler-cloud-lighthouse">Lighthouse AI documentation</a>.</p>
<h2 id="-providers--imported-findings-indicator">📥 Providers — Imported Findings Indicator</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Providers whose findings were imported with the Prowler CLI now show an &ldquo;Imported provider&rdquo; indicator next to their connection status in the providers table. In accounts that mix connected providers with Import Findings uploads, the table now tells them apart at a glance.</p>
<img width="1352" height="86" alt="Provider row with the Imported provider indicator and its tooltip" src="https://github.com/user-attachments/assets/68b130a1-fceb-4352-b6cf-aaa6c9870b1a" />
<p>Read more in the <a href="https://docs.prowler.com/user-guide/tutorials/prowler-import-findings">Import Findings documentation</a>.</p>
<h2 id="-compliance--ncsc-cyber-essentials-33">📚 Compliance — NCSC Cyber Essentials 3.3</h2>
<p>Cyber Essentials is the UK National Cyber Security Centre (NCSC) scheme certifying the baseline technical controls an organization must implement, and cloud services are explicitly in scope and cannot be excluded from an assessment. Prowler now includes NCSC Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026) as a universal framework, with its 28 requirements organized in the five control themes: Firewalls, Secure Configuration, Security Update Management, User Access Control, and Malware Protection.</p>
<p>Sixteen requirements map to Azure checks covering the controls the applicant organization owns under the shared responsibility model. The remaining twelve apply to end-user devices, on-premises network appliances, or organizational process, which cloud control-plane evidence cannot observe, so they are reported as Manual.</p>
<p>Contributed by @m-khan-97. Thank you!</p>
<p>Read more in the <a href="https://docs.prowler.com/user-guide/compliance/tutorials/compliance">Compliance documentation</a>.</p>
<h2 id="-checks">🔍 Checks</h2>
<p>Fifteen new checks land across seven providers in this release.</p>
<h3 id="aws">AWS</h3>
<ul>
<li><code>ecr_repository_image_no_secrets</code> scans the latest image of each ECR repository, both its configuration and its filesystem layers, for hardcoded secrets. Thanks to @esquaredsec!</li>
<li>Four new Amazon Bedrock checks, thanks to @tamg-aws!
<ul>
<li><code>bedrock_guardrail_contextual_grounding_filter_enabled</code> verifies that guardrails enable both contextual grounding filters, blocking responses that are not supported by the retrieved source or do not answer the question asked.</li>
<li><code>bedrock_custom_model_encrypted_with_cmk</code> verifies that custom models are encrypted at rest with a customer-managed KMS key instead of an AWS-owned key the organization cannot audit, rotate, or revoke.</li>
<li><code>bedrock_knowledge_base_encrypted_with_cmk</code> verifies that each knowledge-base data source encrypts with a customer-managed KMS key the transient storage used while documents are chunked and embedded.</li>
<li><code>bedrock_agent_role_not_shared_across_agents</code> verifies that every agent has a dedicated execution role, so no agent inherits another&rsquo;s permissions.</li>
</ul>
</li>
<li><code>rolesanywhere_profile_restricts_session_permissions</code> flags IAM Roles Anywhere profiles that reference an administrative role without scoping down the vended session with a session policy or managed policies.</li>
</ul>
<p>Explore all AWS checks at <a href="https://hub.prowler.com/check?provider=aws">Prowler Hub</a>.</p>
<h3 id="gcp">GCP</h3>
<ul>
<li><code>iam_workload_identity_pool_provider_attribute_condition</code> flags Workload Identity Federation providers that trust a multi-tenant issuer without an attribute condition restricting which external identities can impersonate federated principals.</li>
</ul>
<p>Explore all GCP checks at <a href="https://hub.prowler.com/check?provider=gcp">Prowler Hub</a>.</p>
<h3 id="github">GitHub</h3>
<p>Three new checks harden GitHub Actions defaults, all contributed by @Edneam. Thank you!</p>
<ul>
<li><code>organization_default_workflow_permissions_read_only</code> and <code>repository_default_workflow_permissions_read_only</code> verify that workflows get a read-only default <code>GITHUB_TOKEN</code> at the organization and repository level.</li>
<li><code>organization_actions_pull_request_approval_disabled</code> verifies that organizations prevent GitHub Actions from creating and approving pull requests.</li>
</ul>
<p>Explore all GitHub checks at <a href="https://hub.prowler.com/check?provider=github">Prowler Hub</a>.</p>
<h3 id="microsoft-365">Microsoft 365</h3>
<ul>
<li><code>defender_domain_dmarc_records_published</code> checks that every Exchange Online domain publishes a DMARC record with an enforcing policy (<code>p=quarantine</code> or <code>p=reject</code>). Thanks to @Rishi943!</li>
</ul>
<p>Explore all Microsoft 365 checks at <a href="https://hub.prowler.com/check?provider=m365">Prowler Hub</a>.</p>
<h3 id="alibaba-cloud">Alibaba Cloud</h3>
<ul>
<li><code>oss_bucket_versioning_enabled</code> verifies that OSS buckets keep versioning enabled, allowing recovery from accidental or malicious object overwrite and deletion. Thanks to @abidedavana!</li>
<li><code>oss_bucket_server_side_encryption_enabled</code> verifies that OSS buckets define a default server-side encryption rule, either AES256 or KMS. Thanks to @alexchen-sys!</li>
</ul>
<p>OSS bucket logging, versioning, default encryption, and ACL configurations are also now read correctly from the Alibaba Cloud SDK, so the checks reading them no longer report every bucket as unconfigured.</p>
<p>Explore all Alibaba Cloud checks at <a href="https://hub.prowler.com/check?provider=alibabacloud">Prowler Hub</a>.</p>
<h3 id="huawei-cloud">Huawei Cloud</h3>
<ul>
<li><code>vpc_security_group_open_egress</code> flags VPC security groups that allow open egress to the internet. Thanks to @tomitobio!</li>
</ul>
<p>Explore all Huawei Cloud checks at <a href="https://hub.prowler.com/check?provider=huaweicloud">Prowler Hub</a>.</p>
<h3 id="stackit">STACKIT</h3>
<ul>
<li><code>ske_cluster_no_public_endpoint</code> flags SKE clusters whose Kubernetes API endpoint is reachable from the whole internet, because the ACL extension is disabled or its allowed CIDR list contains <code>0.0.0.0/0</code> or <code>::/0</code>. Thanks to @johannes-engler-mw!</li>
</ul>
<p>Explore all STACKIT checks at <a href="https://hub.prowler.com/check?provider=stackit">Prowler Hub</a>.</p>
<h2 id="-security-updates">🔐 Security Updates</h2>
<ul>
<li>The API and SDK container images upgrade OpenSSL to 3.5.7-1~deb13u2, patching ten high CVEs; the UI image upgrades <code>libcrypto3</code> and <code>libssl3</code> to 3.5.8-r0, patching seven high CVEs; the MCP Server image patches CVE-2026-14456 (OpenSSL), CVE-2026-11822, and CVE-2026-11824 (SQLite).</li>
<li><code>sqlparse</code> upgraded to 0.6.0 in the API, patching CVE-2026-54284, CVE-2026-59893, and CVE-2026-71491.</li>
</ul>
<h2 id="-external-contributors">🙌 External Contributors</h2>
<p>Thank you to our community contributors for this release!</p>
<ul>
<li>@Edneam: GitHub <code>organization_default_workflow_permissions_read_only</code> (<a href="https://github.com/prowler-cloud/prowler/pull/12122">#12122</a>), <code>repository_default_workflow_permissions_read_only</code> (<a href="https://github.com/prowler-cloud/prowler/pull/12143">#12143</a>), and <code>organization_actions_pull_request_approval_disabled</code> (<a href="https://github.com/prowler-cloud/prowler/pull/12394">#12394</a>) checks</li>
<li>@tamg-aws: four AWS Bedrock checks covering guardrail grounding, CMK encryption, and agent role isolation (<a href="https://github.com/prowler-cloud/prowler/pull/12459">#12459</a>)</li>
<li>@esquaredsec: AWS <code>ecr_repository_image_no_secrets</code> check (<a href="https://github.com/prowler-cloud/prowler/pull/12123">#12123</a>)</li>
<li>@Rishi943: Microsoft 365 <code>defender_domain_dmarc_records_published</code> check (<a href="https://github.com/prowler-cloud/prowler/pull/11936">#11936</a>)</li>
<li>@abidedavana: Alibaba Cloud <code>oss_bucket_versioning_enabled</code> check (<a href="https://github.com/prowler-cloud/prowler/pull/11913">#11913</a>)</li>
<li>@alexchen-sys: Alibaba Cloud <code>oss_bucket_server_side_encryption_enabled</code> check (<a href="https://github.com/prowler-cloud/prowler/pull/11981">#11981</a>)</li>
<li>@tomitobio: Huawei Cloud <code>vpc_security_group_open_egress</code> check (<a href="https://github.com/prowler-cloud/prowler/pull/12209">#12209</a>)</li>
<li>@johannes-engler-mw: STACKIT <code>ske_cluster_no_public_endpoint</code> check (<a href="https://github.com/prowler-cloud/prowler/pull/11943">#11943</a>)</li>
<li>@gabrielfrdev: cluster name in Kubernetes compliance report outputs (<a href="https://github.com/prowler-cloud/prowler/pull/12506">#12506</a>)</li>
<li>@jfgmesquita: AWS FSBP compliance mapping fix for IAM.9 and EKS.1 (<a href="https://github.com/prowler-cloud/prowler/pull/12372">#12372</a>)</li>
<li>@hackertwinten: <code>ec2_securitygroup_not_used</code> no longer flags security groups held only by scaled-down AWS Batch compute environments (<a href="https://github.com/prowler-cloud/prowler/pull/12458">#12458</a>)</li>
<li>@0xTaoZ: ECS task-definition checks no longer report PASS when <code>DescribeTaskDefinition</code> fails, shipped early in v5.39.1 (<a href="https://github.com/prowler-cloud/prowler/pull/12217">#12217</a>)</li>
<li>@ye11oc4t: <code>ses_identity_not_publicly_accessible</code> now evaluates every identity authorization policy, shipped early in v5.39.1 (<a href="https://github.com/prowler-cloud/prowler/pull/12464">#12464</a>)</li>
<li>@Zuhef: IaC provider raises typed exceptions instead of <code>sys.exit</code> when cloning the scanned repository or running Trivy fails (<a href="https://github.com/prowler-cloud/prowler/pull/12227">#12227</a>), Kubernetes kubelet checks no longer disappear from the scan when a <code>kubelet-config</code> ConfigMap is broken (<a href="https://github.com/prowler-cloud/prowler/pull/12225">#12225</a>), and the CLI <code>--slack</code> summary is sent for scans with no findings instead of failing with <code>ZeroDivisionError</code> (<a href="https://github.com/prowler-cloud/prowler/pull/12229">#12229</a>)</li>
<li>@m-khan-97: NCSC Cyber Essentials 3.3 compliance framework with Azure provider coverage across the five Cyber Essentials themes (<a href="https://github.com/prowler-cloud/prowler/pull/11588">#11588</a>)</li>
</ul>
<hr>
<h2 id="ui">UI</h2>
<h3 id="-added">🚀 Added</h3>
<ul>
<li>NCSC Cyber Essentials 3.3 compliance support with its dedicated mapper, details panel, and icon <a href="https://github.com/prowler-cloud/prowler/pull/11588">(#11588)</a></li>
<li>Thumbs-up and thumbs-down feedback form for Lighthouse assistant answers with optional details <a href="https://github.com/prowler-cloud/prowler/pull/12419">(#12419)</a></li>
<li>Display the default one-scan free trial and trial expiration in the existing sidebar banner <a href="https://github.com/prowler-cloud/prowler/pull/12420">(#12420)</a></li>
<li>Slack integration: connect a Slack workspace from the Integrations page (Prowler Cloud only) <a href="https://github.com/prowler-cloud/prowler/pull/12435">(#12435)</a></li>
<li>Prowler Cloud indicator for providers created via Import Findings alongside every connection status <a href="https://github.com/prowler-cloud/prowler/pull/12447">(#12447)</a></li>
<li>Slack integration: authorize several destination channels at once — the connection check confirms each authorized channel with a one-time message and names the one Slack refuses <a href="https://github.com/prowler-cloud/prowler/pull/12491">(#12491)</a></li>
<li>Slack channels confirmed on the Slack integration as alert rule destinations, selectable in the alert modal alongside email recipients <a href="https://github.com/prowler-cloud/prowler/pull/12492">(#12492)</a></li>
<li>Cancelled-subscription variant in the sidebar trial banner (Prowler Cloud only) <a href="https://github.com/prowler-cloud/prowler/pull/12538">(#12538)</a></li>
</ul>
<h3 id="-changed">🔄 Changed</h3>
<ul>
<li>Alerts list Recipients column becomes Destinations, summarizing a rule&rsquo;s email recipients and Slack channels at a glance <a href="https://github.com/prowler-cloud/prowler/pull/12493">(#12493)</a></li>
</ul>
<h3 id="-fixed">🐞 Fixed</h3>
<ul>
<li>Scan auto-refresh no longer overlaps slow client refreshes and now signals when scan execution settles <a href="https://github.com/prowler-cloud/prowler/pull/12455">(#12455)</a></li>
<li>The compliance &ldquo;Across providers&rdquo; section builds its framework list from the API catalog instead of a hardcoded set of ids, so a universal framework registered by an installed package renders like a shipped one <a href="https://github.com/prowler-cloud/prowler/pull/12536">(#12536)</a></li>
<li>The compliance &ldquo;Across providers&rdquo; section reports a failed catalog request instead of rendering the &ldquo;no data yet&rdquo; empty state <a href="https://github.com/prowler-cloud/prowler/pull/12536">(#12536)</a></li>
<li>Returning from Slack after approving the install now reliably lands on the Slack integration page instead of getting stuck on the callback screen (Prowler Cloud only) <a href="https://github.com/prowler-cloud/prowler/pull/12572">(#12572)</a></li>
</ul>
<h3 id="-security">🔐 Security</h3>
<ul>
<li><code>libcrypto3</code> and <code>libssl3</code> upgraded to 3.5.8-r0 in the UI container image, patching seven high OpenSSL CVEs <a href="https://github.com/prowler-cloud/prowler/pull/12549">(#12549)</a></li>
</ul>
<h2 id="api">API</h2>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li><code>FINDINGS_TABLE_PARTITION_MAX_AGE_MONTHS</code> is now applied in months instead of days, and negative values are rejected <a href="https://github.com/prowler-cloud/prowler/pull/12580">(#12580)</a></li>
</ul>
<h3 id="-security-1">🔐 Security</h3>
<ul>
<li><code>sqlparse</code> upgraded to 0.6.0, patching CVE-2026-54284, CVE-2026-59893, and CVE-2026-71491 <a href="https://github.com/prowler-cloud/prowler/pull/12509">(#12509)</a></li>
<li><code>openssl</code>, <code>libssl3t64</code> and <code>openssl-provider-legacy</code> upgraded to 3.5.7-1~deb13u2 in the API container image, patching ten high OpenSSL CVEs <a href="https://github.com/prowler-cloud/prowler/pull/12549">(#12549)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-added-1">🚀 Added</h3>
<ul>
<li>NCSC Cyber Essentials 3.3 compliance framework with Azure provider coverage across the five Cyber Essentials themes <a href="https://github.com/prowler-cloud/prowler/pull/11588">(#11588)</a></li>
<li><code>oss_bucket_versioning_enabled</code> check for Alibaba Cloud provider, verifying that OSS buckets have versioning enabled to allow recovery from accidental or malicious object overwrite and deletion <a href="https://github.com/prowler-cloud/prowler/pull/11913">(#11913)</a></li>
<li><code>defender_domain_dmarc_records_published</code> checks that every Exchange Online domain publishes a DMARC record with an enforcing policy (<code>p=quarantine</code> or <code>p=reject</code>) <a href="https://github.com/prowler-cloud/prowler/pull/11936">(#11936)</a></li>
<li><code>ske_cluster_no_public_endpoint</code> check for STACKIT provider, flagging SKE clusters whose Kubernetes API endpoint is reachable from the whole internet because the ACL extension is disabled or its allowed CIDR list contains <code>0.0.0.0/0</code> or <code>::/0</code> <a href="https://github.com/prowler-cloud/prowler/pull/11943">(#11943)</a></li>
<li><code>oss_bucket_server_side_encryption_enabled</code> check for Alibaba Cloud provider, verifying that OSS buckets have a default server-side encryption rule (AES256 or KMS) <a href="https://github.com/prowler-cloud/prowler/pull/11981">(#11981)</a></li>
<li><code>organization_default_workflow_permissions_read_only</code> check for GitHub provider, verifying that organizations grant GitHub Actions workflows a read-only default <code>GITHUB_TOKEN</code> <a href="https://github.com/prowler-cloud/prowler/pull/12122">(#12122)</a></li>
<li><code>ecr_repository_image_no_secrets</code> check for AWS provider, scanning the latest ECR repository image&rsquo;s configuration and filesystem layers for hardcoded secrets <a href="https://github.com/prowler-cloud/prowler/pull/12123">(#12123)</a></li>
<li><code>repository_default_workflow_permissions_read_only</code> check for GitHub provider, verifying that repositories grant GitHub Actions workflows a read-only default <code>GITHUB_TOKEN</code> <a href="https://github.com/prowler-cloud/prowler/pull/12143">(#12143)</a></li>
<li><code>vpc_security_group_open_egress</code> check for Huawei Cloud provider: VPC security groups do not allow open egress to the internet <a href="https://github.com/prowler-cloud/prowler/pull/12209">(#12209)</a></li>
<li><code>organization_actions_pull_request_approval_disabled</code> check for GitHub provider, verifying that organizations prevent GitHub Actions from creating and approving pull requests <a href="https://github.com/prowler-cloud/prowler/pull/12394">(#12394)</a></li>
<li>Add the <code>iam_workload_identity_pool_provider_attribute_condition</code> check to flag GCP Workload Identity Federation providers that trust a multi-tenant issuer without an attribute condition restricting which external identities can impersonate federated principals <a href="https://github.com/prowler-cloud/prowler/pull/12416">(#12416)</a></li>
<li>Add the <code>rolesanywhere_profile_restricts_session_permissions</code> check to flag AWS IAM Roles Anywhere profiles that reference an administrative role without scoping down the vended session with a session policy or managed policies <a href="https://github.com/prowler-cloud/prowler/pull/12416">(#12416)</a></li>
<li><code>bedrock_guardrail_contextual_grounding_filter_enabled</code>, <code>bedrock_custom_model_encrypted_with_cmk</code>, <code>bedrock_knowledge_base_encrypted_with_cmk</code> and <code>bedrock_agent_role_not_shared_across_agents</code> are four new AWS Bedrock checks covering guardrail contextual grounding, custom model encryption, knowledge-base data-source encryption, and non-shared agent execution roles. <a href="https://github.com/prowler-cloud/prowler/pull/12459">(#12459)</a></li>
<li><code>Cluster</code> column in Kubernetes CIS, ISO27001, Prowler ThreatScore, and universal compliance outputs, populated with the resolved cluster name so multi-cluster scans can be told apart in the output <a href="https://github.com/prowler-cloud/prowler/pull/12506">(#12506)</a></li>
</ul>
<h3 id="-fixed-2">🐞 Fixed</h3>
<ul>
<li>Kubernetes <code>kubelet</code> checks no longer disappear from the scan with <code>TypeError: 'NoneType' object is not iterable</code> when a <code>kubelet-config</code> ConfigMap is broken: one with malformed YAML is logged and skipped while the valid ones are still evaluated, one without kubelet data is evaluated with an empty configuration instead of crashing the checks, and the <code>apiserver</code>, <code>controllermanager</code>, <code>etcd</code> and <code>scheduler</code> pod gatherers now always return a list <a href="https://github.com/prowler-cloud/prowler/pull/12225">(#12225)</a></li>
<li>IaC provider now raises typed <code>IacBaseException</code> errors (repository clone, Trivy missing, scan and output processing failures) instead of calling <code>sys.exit(1)</code>; the CLI still stops with the logged message, and API scans fail as regular task errors instead of a <code>SystemExit</code> escaping the worker <a href="https://github.com/prowler-cloud/prowler/pull/12227">(#12227)</a></li>
<li>CLI Slack integration (<code>--slack</code>) no longer fails when a scan produces no findings: the pass and fail percentages are guarded against a <code>findings_count</code> of 0, which previously raised <code>ZeroDivisionError</code> and sent <code>blocks=None</code> to Slack instead of the summary <a href="https://github.com/prowler-cloud/prowler/pull/12229">(#12229)</a></li>
<li>AWS FSBP compliance mapping for <code>IAM.9</code> and <code>EKS.1</code> referenced missing/renamed checks; both now point to their real, existing check IDs <a href="https://github.com/prowler-cloud/prowler/pull/12372">(#12372)</a></li>
<li><code>ec2_securitygroup_not_used</code> no longer reports a false positive for security groups attached only to an AWS Batch compute environment, which holds them in configuration without creating a network interface while scaled down to zero instances <a href="https://github.com/prowler-cloud/prowler/pull/12458">(#12458)</a></li>
<li>Bedrock Agent ARNs are now built from the audited partition instead of a hardcoded <code>arn:aws:</code>, so findings in GovCloud and China carry a resolvable ARN and <code>--resource-arn</code> scoping matches agents in those partitions. <a href="https://github.com/prowler-cloud/prowler/pull/12459">(#12459)</a></li>
<li><code>push-to-cloud</code> now validates Private Cloud TLS certificates with the operating system trust store without changing provider HTTP clients <a href="https://github.com/prowler-cloud/prowler/pull/12485">(#12485)</a></li>
<li><code>prowler.compliance.universal</code> entry point directories are resolved through a single shared helper and deduplicated by resolved path, so a directory reached through two entry points is parsed once and a package that fails to import no longer hides the rest <a href="https://github.com/prowler-cloud/prowler/pull/12536">(#12536)</a></li>
<li>OSS bucket logging, versioning, default encryption and ACL configurations are now read correctly from the Alibaba Cloud SDK, so <code>oss_bucket_logging_enabled</code>, <code>oss_bucket_versioning_enabled</code>, <code>oss_bucket_server_side_encryption_enabled</code> and <code>oss_bucket_not_publicly_accessible</code> no longer report every bucket as unconfigured <a href="https://github.com/prowler-cloud/prowler/pull/12546">(#12546)</a></li>
</ul>
<h3 id="-security-2">🔐 Security</h3>
<ul>
<li><code>openssl</code>, <code>libssl3t64</code> and <code>openssl-provider-legacy</code> upgraded to 3.5.7-1~deb13u2 in the SDK container image, patching ten high OpenSSL CVEs <a href="https://github.com/prowler-cloud/prowler/pull/12549">(#12549)</a></li>
</ul>
<h2 id="mcp">MCP</h2>
<h3 id="-added-2">🚀 Added</h3>
<ul>
<li>Failures shared by every tool - a rejected credential, a missing permission, a rate limit, an outage, an unreachable API, a bad argument - are now explained with a message that says what went wrong and what to do about it <a href="https://github.com/prowler-cloud/prowler/pull/12531">(#12531)</a></li>
</ul>
<h3 id="-fixed-3">🐞 Fixed</h3>
<ul>
<li><code>prowler_docs_search</code> returns results again: it calls the search endpoint docs.prowler.com moved to, since the one it used no longer exists, and each result now names the page&rsquo;s title, the section it matched and a URL anchored at that section <a href="https://github.com/prowler-cloud/prowler/pull/12578">(#12578)</a></li>
</ul>
<h3 id="-security-3">🔐 Security</h3>
<ul>
<li>Stop relaying upstream response bodies to agents: a failed request now reaches the caller as a sentence this server wrote, with the full body kept to the logs, so a gateway error page or a debug traceback can no longer be replayed into a model&rsquo;s context <a href="https://github.com/prowler-cloud/prowler/pull/12531">(#12531)</a></li>
<li><code>sqlite-libs</code> upgraded to 3.53.4-r0 in the container image, patching CVE-2026-11822 and CVE-2026-11824 <a href="https://github.com/prowler-cloud/prowler/pull/12537">(#12537)</a></li>
<li><code>libcrypto3</code> and <code>libssl3</code> upgraded to 3.5.8-r0 in the container image, patching CVE-2026-14456 <a href="https://github.com/prowler-cloud/prowler/pull/12547">(#12547)</a></li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/kaniko-build-action/</link><pubDate>Fri, 28 Aug 2026 17:50:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a simple tool that prints “Hello World” or a personalized greeting to the console. It takes an optional input parameter, who-to-greet, which allows users to specify the name they want to greet. The action also provides the current time when it runs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a simple tool that prints &ldquo;Hello World&rdquo; or a personalized greeting to the console. It takes an optional input parameter, <code>who-to-greet</code>, which allows users to specify the name they want to greet. The action also provides the current time when it runs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>DSH Plugin Migrate Bot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/dsh-plugin-migrate-bot/</link><pubDate>Fri, 28 Aug 2026 17:50:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/dsh-plugin-migrate-bot/</guid><description>Version updated for https://github.com/royenheart/dsh-migrate-bot to version v0.2.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the migration of a third-party plugin from one DeepSeek Harness version to another. It resolves the target harness version (dsh-v*), performs mechanical tests, runs two DSH review sessions (DeepSeek V4 Pro and dsh-anchored-standard), and then creates an Issue and PR if the plugin tree is dirty. The Action skips migration if the same version has already been processed successfully. It requires permissions to write to repository contents, open issues, and pull requests, with GitHub Actions permission enabled for creating pull requests. The action uses a cron schedule or manual workflow dispatch to trigger migrations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/royenheart/dsh-migrate-bot">https://github.com/royenheart/dsh-migrate-bot</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dsh-plugin-migrate-bot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the migration of a third-party plugin from one DeepSeek Harness version to another. It resolves the target harness version (<code>dsh-v*</code>), performs mechanical tests, runs two DSH review sessions (DeepSeek V4 Pro and dsh-anchored-standard), and then creates an Issue and PR if the plugin tree is dirty. The Action skips migration if the same version has already been processed successfully. It requires permissions to write to repository contents, open issues, and pull requests, with GitHub Actions permission enabled for creating pull requests. The action uses a cron schedule or manual workflow dispatch to trigger migrations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/royenheart/dsh-migrate-bot/compare/v0.2.0...v0.2.1">https://github.com/royenheart/dsh-migrate-bot/compare/v0.2.0...v0.2.1</a></p>
]]></content:encoded></item><item><title>IconKit Ribbon</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/iconkit-ribbon/</link><pubDate>Fri, 28 Aug 2026 17:49:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/iconkit-ribbon/</guid><description>Version updated for https://github.com/rozd/icon-kit to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary IconKit is a Swift library and CLI tool designed to work with Apple .icon bundles and Android adaptive icons. It enables the creation, inspection, modification, and validation of these icon formats using SF Symbols and provides features like adding environment ribbons to existing icons and generating adaptive icons in modern vector drawable and bitmap formats. The action supports full document models and is available as a command-line tool or embeddable library for Swift applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rozd/icon-kit">https://github.com/rozd/icon-kit</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/iconkit-ribbon">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>IconKit is a Swift library and CLI tool designed to work with Apple <code>.icon</code> bundles and Android adaptive icons. It enables the creation, inspection, modification, and validation of these icon formats using SF Symbols and provides features like adding environment ribbons to existing icons and generating adaptive icons in modern vector drawable and bitmap formats. The action supports full document models and is available as a command-line tool or embeddable library for Swift applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>resolve adaptive icon safe-zone positioning, legacy icon alpha masking, and vector gradients (<code>a893100</code>)</li>
<li>fallback to building from source when pre-built binary is not found (<code>6b97e0d</code>)</li>
</ul>
<h3 id="other-changes">Other Changes</h3>
<ul>
<li>Merge pull request #3 from rozd/feat/android-vector-drawables (<code>02c8c37</code>)</li>
<li>expand unit tests for gradients, safe-zone viewports, content bounds, and alpha masking (<code>6b37d5c</code>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/rozd/icon-kit/compare/v1.2.0...v1.2.1">https://github.com/rozd/icon-kit/compare/v1.2.0...v1.2.1</a></p>
]]></content:encoded></item><item><title>serverless-container-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/serverless-container-action/</link><pubDate>Fri, 28 Aug 2026 17:48:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/serverless-container-action/</guid><description>Version updated for https://github.com/scaleway/scw-serverless-container-action to version 0.0.8.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 1 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action scaleway/scaleway-containers-deploy automates the deployment and teardown of container services on Scaleway. It integrates seamlessly with Scaleway’s Container Registry, allowing users to deploy their applications efficiently using predefined configurations or custom settings. This action solves common deployment challenges by providing a simple interface for managing containers within CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scaleway/scw-serverless-container-action">https://github.com/scaleway/scw-serverless-container-action</a></strong> to version <strong>0.0.8</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>1</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/serverless-container-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>scaleway/scaleway-containers-deploy</code> automates the deployment and teardown of container services on Scaleway. It integrates seamlessly with Scaleway&rsquo;s Container Registry, allowing users to deploy their applications efficiently using predefined configurations or custom settings. This action solves common deployment challenges by providing a simple interface for managing containers within CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(container): await ready container before update by @philibea in <a href="https://github.com/scaleway/scw-serverless-container-action/pull/7">https://github.com/scaleway/scw-serverless-container-action/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scaleway/scw-serverless-container-action/compare/0.0.7...0.0.8">https://github.com/scaleway/scw-serverless-container-action/compare/0.0.7...0.0.8</a></p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/bernstein-multi-agent-orchestration/</link><pubDate>Fri, 28 Aug 2026 17:47:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.18.2.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is a deterministic multi-agent CLI orchestration tool that automates and orchestrates complex workflows, ensuring consistency across different environments. It simplifies the management of microservices, pipelines, and tasks by providing a comprehensive framework for defining and executing multi-step processes efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.18.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein is a deterministic multi-agent CLI orchestration tool that automates and orchestrates complex workflows, ensuring consistency across different environments. It simplifies the management of microservices, pipelines, and tasks by providing a comprehensive framework for defining and executing multi-step processes efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Sixty-four commits since the last patch, most of them the machine finding its own mistakes. That is the arrangement working, not failing.</p>
<h2 id="receipts-that-outlive-what-they-describe">Receipts that outlive what they describe</h2>
<p>A finished run&rsquo;s journal now maps onto a signed TRACE 0.2 Trust Record through the install Ed25519 identity, behind the optional <code>bernstein[trace]</code> extra (#4666). The record names its own signing key — the subject is a self-certifying <code>did:key</code> URI — states the runtime it was produced under, and binds a delegated execution to its parent by the hash of the parent&rsquo;s own signed record; three vectors minted from real runs verify offline (#4692). Sealed audit segments carry content-addressed hash tiles beside them (#4629). A refused read-set emits a receipt that verifies with no network and no repository (#4650). Journal verification is bound to plan rendering, so an approval binds to the rendering the reviewer actually saw (#4655). Task context packs are byte-deterministic, content-addressed containers (#4646), and sequential evaluation statistics gain time-uniform bounds computed in exact arithmetic (#4651).</p>
<h2 id="the-swarm-stops-stepping-on-itself">The swarm stops stepping on itself</h2>
<p>Migration checkpoints record chunk completion, so a restarted migration no longer re-spawns finished work and the reduce step can run at all (#4541). A re-run reuses a chunk whose task is still in flight instead of spawning a second owner for the same files (#4624). A run whose planning failed closes instead of idling to its wall-clock timeout (#4529). Fair scheduling caps the age boost, so an old task can no longer starve a fresh urgent one (#4675). Drain stops re-admitting a dead agent from a previous run&rsquo;s <code>agents.json</code> (#4479), and any unmerged agent branch is rescued to <code>refs/rescue/&lt;run-id&gt;/</code> before a forced delete (#4677). A spawn supervisor that exhausted its respawns records the failure on park, where a pruned store used to lose it (#4637). Issue-intake runs have no coordinator, so they now share a claim vocabulary two of them can read off each other&rsquo;s comments (#4521).</p>
<h2 id="bernstein-pr-says-what-happened"><code>bernstein pr</code> says what happened</h2>
<p>A description built from a git command that failed used to report that the branch changed nothing. It now reports the failure, and provenance is computed only from a diff that exists (#4669). The anchoring step no longer exits non-zero after the pull request is already open (#4686), and the description is composed against the base the request merges onto (#4693).</p>
<h2 id="adapters-plugins-volunteers">Adapters, plugins, volunteers</h2>
<p>The goose adapter passes through the model it was told to use — a role bound to a specific model had been running on whatever the CLI defaulted to — parses the stream, and reports usage like the other adapters (#3679). Aider writes a per-spawn analytics log (#3674). Declared third-party trigger and reporter entry points load at runtime, and a malformed entry is named in a warning rather than becoming a silent no-op (#4531). Volunteer runs gain a second independent reviewer (#4685) and issue comments filtered so the model receives what the reviewer read (#4652).</p>
<h2 id="housekeeping">Housekeeping</h2>
<p>Modules nothing reached are gone, with the documentation rows that advertised them (#4683, #4643). The team-hub page documented a loader that had been deleted as unreachable; it now documents the manifest parser that ships, and deleting a file the drift playbook names as a doc&rsquo;s source of truth fails on the pull request that deletes it rather than on the push afterwards (#4696). Committed coverage shards and scratch files are out of the tree, ignored by shape rather than by name (#4695). Context-file staleness on a pull request is attributed to that request&rsquo;s own commits (#4634), and CONTRIBUTING documents how milestones are targeted, which had been folklore (#4285). Three gates were failing for reasons no code change could fix: the lint gate called <code>ruff</code> outside <code>uv run</code> on a project that never activates its virtualenv (#4547); a required status check filtered its trigger on paths, so every pull request outside the filter waited forever on a run that never started (#4556); and a completion signal named its test by a path written when the task was planned rather than one that exists (#4554).</p>
<h2 id="contributors">Contributors</h2>
<ul>
<li><strong>Chirag Honnyal</strong> — branch rescue on drain (#4681), the priority age-boost cap (#4680), spawn-supervisor failure records (#4662), staleness attribution (#4664).</li>
<li><strong>Amir Fathi</strong> — swarm checkpoint completion (#4618), the drain liveness check (#4621), the reaper patch-target fix (#4688).</li>
<li><strong>Sujeito Operator</strong> — a producer for the parked-session store (#4636), in-flight chunk reuse (#4625).</li>
<li><strong>Jesus Esquer</strong> — agent timeout extension reaching the spawned process (#4608), reaper caller coverage (#4613).</li>
<li><strong>Abishek N</strong> — the deterministic TaskContextPack container (#4694), dead-module removal (#4696).</li>
<li><strong>Atirna</strong> — plugin entry-point registries (#4614).</li>
</ul>
<hr>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(release): publish the version&rsquo;s own release notes on the release page by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4606">https://github.com/sipyourdrink-ltd/bernstein/pull/4606</a></li>
<li>fix(ci): release the andon once main is green again by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4607">https://github.com/sipyourdrink-ltd/bernstein/pull/4607</a></li>
<li>chore(deps): update dependency @types/vscode to v1.134.0 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4604">https://github.com/sipyourdrink-ltd/bernstein/pull/4604</a></li>
<li>fix(#4571): agent timeout extension reaches the spawned process by @jm27 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4608">https://github.com/sipyourdrink-ltd/bernstein/pull/4608</a></li>
<li>docs: document _MAX_FLUSH_ATTEMPTS drop policy in metric_collector docstring by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4611">https://github.com/sipyourdrink-ltd/bernstein/pull/4611</a></li>
<li>fix(plugins): load the declared bernstein.triggers and bernstein.reporters entry-point groups by @atirna in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4614">https://github.com/sipyourdrink-ltd/bernstein/pull/4614</a></li>
<li>fix(#4541): wire swarm migration checkpoint completion and reduce by @AmirF194 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4618">https://github.com/sipyourdrink-ltd/bernstein/pull/4618</a></li>
<li>test(#4610): cover the reaper caller, not just the adapter contract by @jm27 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4613">https://github.com/sipyourdrink-ltd/bernstein/pull/4613</a></li>
<li>fix(security): restrict redirect destinations for third-party-derived URLs by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4619">https://github.com/sipyourdrink-ltd/bernstein/pull/4619</a></li>
<li>feat: add claim comment format constants and helpers for issue-intake runs by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4609">https://github.com/sipyourdrink-ltd/bernstein/pull/4609</a></li>
<li>fix(replay): ensure plan.graph.full nodes are sorted by task_id in board projection by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4622">https://github.com/sipyourdrink-ltd/bernstein/pull/4622</a></li>
<li>chore(deps): update dependency @vitejs/plugin-react to v6.1.0 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4620">https://github.com/sipyourdrink-ltd/bernstein/pull/4620</a></li>
<li>fix(#4479): stop drain from re-admitting a dead prior-run agent from agents.json by @AmirF194 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4621">https://github.com/sipyourdrink-ltd/bernstein/pull/4621</a></li>
<li>test: state the sandbox precondition instead of inferring it from the env by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4626">https://github.com/sipyourdrink-ltd/bernstein/pull/4626</a></li>
<li>feat(adapters): drive more of the goose CLI and parse its stream by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4616">https://github.com/sipyourdrink-ltd/bernstein/pull/4616</a></li>
<li>feat(quality): empirical confidence helper with a Hoeffding confidence sequence by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4612">https://github.com/sipyourdrink-ltd/bernstein/pull/4612</a></li>
<li>test(security): pin a computed capability delta across the recording seam by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4627">https://github.com/sipyourdrink-ltd/bernstein/pull/4627</a></li>
<li>fix(orchestrator): bound the planning window so a failed plan does not run to timeout by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4617">https://github.com/sipyourdrink-ltd/bernstein/pull/4617</a></li>
<li>fix(#4624): reuse in-flight swarm chunks instead of double-spawning owners by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4625">https://github.com/sipyourdrink-ltd/bernstein/pull/4625</a></li>
<li>feat(review): show the reviewer the conventions already filed for this repo by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4631">https://github.com/sipyourdrink-ltd/bernstein/pull/4631</a></li>
<li>feat(audit): write content-addressed hash tiles beside the sealed segments by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4629">https://github.com/sipyourdrink-ltd/bernstein/pull/4629</a></li>
<li>docs: refresh the curated context files against their subtrees by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4632">https://github.com/sipyourdrink-ltd/bernstein/pull/4632</a></li>
<li>fix: wire task resume checkpoint writer into orchestrator step-completion handling by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4615">https://github.com/sipyourdrink-ltd/bernstein/pull/4615</a></li>
<li>chore(deps): update dependency vite to v8.2.2 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4623">https://github.com/sipyourdrink-ltd/bernstein/pull/4623</a></li>
<li>feat: wire &ndash;analytics-log into aider spawn command by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4630">https://github.com/sipyourdrink-ltd/bernstein/pull/4630</a></li>
<li>fix(#3453): give the parked-session store a producer, and key the park on something that survives a retry by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4636">https://github.com/sipyourdrink-ltd/bernstein/pull/4636</a></li>
<li>feat: extend AutofixReceipt with thread resolution tracking by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4635">https://github.com/sipyourdrink-ltd/bernstein/pull/4635</a></li>
<li>feat: add CounterfactualAuditError and EquivalenceAttestation models by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4638">https://github.com/sipyourdrink-ltd/bernstein/pull/4638</a></li>
<li>fix(tasks): report an unreachable spawn supervisor instead of suppressing it by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4640">https://github.com/sipyourdrink-ltd/bernstein/pull/4640</a></li>
<li>fix(quality): handle exit 127 in import_cycle gate command path by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4639">https://github.com/sipyourdrink-ltd/bernstein/pull/4639</a></li>
<li>test: state the sandbox premise instead of inheriting it from the host by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4658">https://github.com/sipyourdrink-ltd/bernstein/pull/4658</a></li>
<li>docs: regenerate adapter last-green table from canary receipts by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4657">https://github.com/sipyourdrink-ltd/bernstein/pull/4657</a></li>
<li>fix(docs): attribute context-file staleness only to PR-contributed commits (#4634) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4664">https://github.com/sipyourdrink-ltd/bernstein/pull/4664</a></li>
<li>fix(core): persist spawn supervisor failure records on park for pruned store fallback (#4637) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4662">https://github.com/sipyourdrink-ltd/bernstein/pull/4662</a></li>
<li>feat: add exact-arithmetic time-uniform ConfidenceSequence primitive by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4651">https://github.com/sipyourdrink-ltd/bernstein/pull/4651</a></li>
<li>feat: wire comment filtering into volunteer runner (task 5959ed75355c) by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4652">https://github.com/sipyourdrink-ltd/bernstein/pull/4652</a></li>
<li>test: add SSRF protection tests for fetcher call sites by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4654">https://github.com/sipyourdrink-ltd/bernstein/pull/4654</a></li>
<li>feat: bind journal verification to plan rendering by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4655">https://github.com/sipyourdrink-ltd/bernstein/pull/4655</a></li>
<li>feat: add sample_evidence field to FailurePatternDraft by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4659">https://github.com/sipyourdrink-ltd/bernstein/pull/4659</a></li>
<li>fix: report git failures in PR descriptions instead of claiming no changes by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4670">https://github.com/sipyourdrink-ltd/bernstein/pull/4670</a></li>
<li>fix(lint): move Path import to TYPE_CHECKING block in context_policy.py by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4653">https://github.com/sipyourdrink-ltd/bernstein/pull/4653</a></li>
<li>fix(autoheal): remove orphan cost_guard module by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4679">https://github.com/sipyourdrink-ltd/bernstein/pull/4679</a></li>
<li>feat: add tool output digesters registry and ruleset models by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4656">https://github.com/sipyourdrink-ltd/bernstein/pull/4656</a></li>
<li>feat: add compute_observations_hash function by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4663">https://github.com/sipyourdrink-ltd/bernstein/pull/4663</a></li>
<li>fix(orchestration): cap priority age boost to prevent starvation of fresh P1 tasks (#4675) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4680">https://github.com/sipyourdrink-ltd/bernstein/pull/4680</a></li>
<li>feat: add milestone triage guidance to CONTRIBUTING.md by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4660">https://github.com/sipyourdrink-ltd/bernstein/pull/4660</a></li>
<li>feat: aider adapter parses prose while upstream already emits structured events: wire &ndash;analytics-log by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4661">https://github.com/sipyourdrink-ltd/bernstein/pull/4661</a></li>
<li>fix(orchestration): rescue unmerged agent branches before forced deletion on drain (#4677) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4681">https://github.com/sipyourdrink-ltd/bernstein/pull/4681</a></li>
<li>feat: add test for three-level chain revocation propagation (A ← B ← C) by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4682">https://github.com/sipyourdrink-ltd/bernstein/pull/4682</a></li>
<li>fix(pr): anchor the description without aborting the command by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4686">https://github.com/sipyourdrink-ltd/bernstein/pull/4686</a></li>
<li>feat: volunteer: independent review pass — a second donor reviews every submission by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4685">https://github.com/sipyourdrink-ltd/bernstein/pull/4685</a></li>
<li>fix(test): patch the correct _is_process_alive binding in test_ownership_released_on_reap by @AmirF194 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4688">https://github.com/sipyourdrink-ltd/bernstein/pull/4688</a></li>
<li>fix: audit cost and agents for unreachable modules: wire or delete, one verdict per module by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4683">https://github.com/sipyourdrink-ltd/bernstein/pull/4683</a></li>
<li>feat(protocols/volunteer): add shared document substrate (documents.py) by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4689">https://github.com/sipyourdrink-ltd/bernstein/pull/4689</a></li>
<li>feat: controller state sidecar persists adaptive parallelism and claim conflict cooldowns by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4687">https://github.com/sipyourdrink-ltd/bernstein/pull/4687</a></li>
<li>feat: add trust_record.py with TRACE 0.2 emitter API by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4684">https://github.com/sipyourdrink-ltd/bernstein/pull/4684</a></li>
<li>fix(pr): compose the description against the base the pull request merges onto by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4693">https://github.com/sipyourdrink-ltd/bernstein/pull/4693</a></li>
<li>feat: deterministic TaskContextPack container (#4646) by @AbishekCoder1 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4694">https://github.com/sipyourdrink-ltd/bernstein/pull/4694</a></li>
<li>chore: remove committed coverage shards and scratch files by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4695">https://github.com/sipyourdrink-ltd/bernstein/pull/4695</a></li>
<li>chore: remove dead code modules from plugins_core and routing (#4643) by @AbishekCoder1 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4696">https://github.com/sipyourdrink-ltd/bernstein/pull/4696</a></li>
<li>feat: add read-set refusal receipt with offline verification by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4650">https://github.com/sipyourdrink-ltd/bernstein/pull/4650</a></li>
<li>chore: move README translations to docs/i18n and clear run scratch from the root by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4702">https://github.com/sipyourdrink-ltd/bernstein/pull/4702</a></li>
<li>fix(docs): document the team-hub manifest that ships, gate deleted sources on the PR by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4703">https://github.com/sipyourdrink-ltd/bernstein/pull/4703</a></li>
<li>fix(observability): align trust record field surface with TRACE 0.2 draft by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4704">https://github.com/sipyourdrink-ltd/bernstein/pull/4704</a></li>
<li>feat: volunteer: hub HTTP surface — scoped endpoints over the lease store by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4700">https://github.com/sipyourdrink-ltd/bernstein/pull/4700</a></li>
<li>chore(release): v3.18.2 by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4707">https://github.com/sipyourdrink-ltd/bernstein/pull/4707</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sipyourdrink-ltd/bernstein/compare/v3.18.1...v3.18.2">https://github.com/sipyourdrink-ltd/bernstein/compare/v3.18.1...v3.18.2</a></p>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Fri, 28 Aug 2026 17:45:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the build process for a Docker Swarm service by running npm ci and npm run bundle, then commits the resulting distribution files to the repository. It helps streamline the development workflow by ensuring that the necessary dependencies are installed and the service is ready for deployment with just a push to the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the build process for a Docker Swarm service by running <code>npm ci</code> and <code>npm run bundle</code>, then commits the resulting distribution files to the repository. It helps streamline the development workflow by ensuring that the necessary dependencies are installed and the service is ready for deployment with just a push to the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/classroom-to-sheets-integration/</link><pubDate>Fri, 28 Aug 2026 17:45:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates Google Sheets with GitHub Classroom to automatically update assignment results. It requires setting up Google Cloud credentials and sharing access, then configuring a secret in your repository to use the integration. The action supports automated grading of tasks in GitHub Actions workflows and updates the corresponding columns in the specified Google Sheet.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates Google Sheets with GitHub Classroom to automatically update assignment results. It requires setting up Google Cloud credentials and sharing access, then configuring a secret in your repository to use the integration. The action supports automated grading of tasks in GitHub Actions workflows and updates the corresponding columns in the specified Google Sheet.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>setup-pawl</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/setup-pawl/</link><pubDate>Fri, 28 Aug 2026 17:44:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/setup-pawl/</guid><description>Version updated for https://github.com/tiangong-dev/pawl to version v0.8.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PAWL (Prowl) GitHub Action is designed to act as a quality gate by comparing metric measurements across codebase commits. It helps identify regressions in metrics such as coverage, test passes, lint findings, and file lengths, ensuring that changes do not make the repo worse than it already is. The action records the current baseline of each metric and compares them against future changes to ensure no metric regresses. This ensures that improvements are tracked and only genuine changes pass through CI, preventing the introduction of new mess while maintaining existing quality standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tiangong-dev/pawl">https://github.com/tiangong-dev/pawl</a></strong> to version <strong>v0.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-pawl">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The PAWL (Prowl) GitHub Action is designed to act as a quality gate by comparing metric measurements across codebase commits. It helps identify regressions in metrics such as coverage, test passes, lint findings, and file lengths, ensuring that changes do not make the repo worse than it already is. The action records the current baseline of each metric and compares them against future changes to ensure no metric regresses. This ensures that improvements are tracked and only genuine changes pass through CI, preventing the introduction of new mess while maintaining existing quality standards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changes-since-v080--npm-i--d-pawl-toolscli081">Changes since <code>v0.8.0</code> — <code>npm i -D @pawl-tools/cli@0.8.1</code></h2>
<p>Prebuilt binaries are attached below.</p>
<ul>
<li>chore: prepare v0.8.1 release (#44) (db848d2)</li>
<li>fix: run codeql on pull requests (#43) (77316e1)</li>
<li>chore: address repository security findings (#37) (8d54856)</li>
<li>feat: harden report freshness and baseline guards (#36) (9f69071)</li>
<li>docs: rewrite the doc set in pawl&rsquo;s own voice (#35) (9ce5f96)</li>
<li>docs: refresh OpenSSF Scorecard badge (041e8ba)</li>
<li>ci: publish OpenSSF Scorecard results (0a9f780)</li>
</ul>
]]></content:encoded></item><item><title>grype_me</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/grype_me/</link><pubDate>Fri, 28 Aug 2026 17:43:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/grype_me/</guid><description>Version updated for https://github.com/TomTonic/grype_me to version v1.3.21-release.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, grype_me, automates the scanning of dependencies to detect vulnerabilities using Anchore Grype. It provides a quick and efficient way to scan repositories, container images, or directories for known security issues by leveraging pre-downloaded vulnerability data within a Docker image. The action generates detailed reports and shields.io badges, which can be linked directly from Markdown text in the README. Users can configure various options such as scan mode, fail build behavior, and output format to suit their needs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TomTonic/grype_me">https://github.com/TomTonic/grype_me</a></strong> to version <strong>v1.3.21-release</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/grype_me">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>grype_me</code>, automates the scanning of dependencies to detect vulnerabilities using Anchore Grype. It provides a quick and efficient way to scan repositories, container images, or directories for known security issues by leveraging pre-downloaded vulnerability data within a Docker image. The action generates detailed reports and shields.io badges, which can be linked directly from Markdown text in the README. Users can configure various options such as scan mode, fail build behavior, and output format to suit their needs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v1321-release">v1.3.21-release</h1>
<h2 id="architectural-changes">Architectural Changes</h2>
<ul>
<li><strong>Migrated to Go 1.27</strong> (from 1.26.6). Building and testing <code>grype_me</code> now requires a Go 1.27+ toolchain.</li>
<li><strong>Adopted <code>encoding/json/v2</code></strong>, newly available in the standard library without <code>GOEXPERIMENT=jsonv2</code> as of Go 1.27, across <code>gist.go</code>, <code>scanner.go</code>, <code>types.go</code>, and their tests. Streaming JSON now goes through <code>json.UnmarshalRead</code>/<code>json.MarshalWrite</code> instead of <code>json.NewDecoder</code>/<code>json.NewEncoder</code>.</li>
<li><strong>Test suite migrated to Go 1.27&rsquo;s <code>httptest.NewTestServer</code></strong> in <code>gist_test.go</code>: the mock GitHub Gist API server is now bound to the test&rsquo;s lifecycle (in-memory fake network, auto-closed when the test ends) instead of manually created via <code>httptest.NewServer</code> + <code>defer server.Close()</code>.</li>
<li>Applied <code>go fix</code>-driven idiom cleanups: a C-style index loop in <code>git.go</code>&rsquo;s tag-version parser became <code>for i := range nums</code>; a manual <code>strings.Index</code>/slice split in <code>gist.go</code>&rsquo;s URL-stripping helper became <code>strings.Cut</code>.</li>
</ul>
<h2 id="changed-behavior">Changed Behavior</h2>
<ul>
<li>The <code>db.status</code> field in the internal <code>GrypeOutput</code> JSON struct dropped its <code>omitempty</code> tag as part of the <code>json/v2</code> migration. This has no observable effect on parsing — struct-typed fields were never treated as &ldquo;empty&rdquo; under either JSON implementation — but is a cleanup of a previously ineffective tag.</li>
</ul>
<h2 id="source-code-updates">Source Code Updates</h2>
<ul>
<li>Go toolchain <strong>1.26.6 → 1.27.0</strong> (major version). Go 1.27 is Go&rsquo;s regular six-month feature release, not itself billed as a security release; the fixes already backported into 1.26.6 in the previous release cycle (module sum-database/GOSUMDB tile-verification bypass, <code>encoding/xml</code> stack exhaustion, <code>net/http</code> header-timeout gap, <code>net/url</code> quadratic path resolution) are included as a baseline. I found no CVEs specific to the 1.27.0 release beyond those already covered.</li>
<li><code>github.com/skeema/knownhosts</code> (indirect, via <code>go-git</code>&rsquo;s SSH known-hosts handling) 1.3.2 → 1.3.3. I could not find published release notes for this version; treating it as a routine maintenance bump.</li>
</ul>
<h2 id="ci-updates">CI Updates</h2>
<ul>
<li>Docker build-stage base image bumped to <code>golang:1.27.0-bookworm</code> (with a follow-up digest-only refresh of the same tag).</li>
<li><code>github/codeql-action</code> v4.37.7 → v4.37.9.</li>
<li><code>docker/setup-buildx-action</code> v4.2.0 → v4.3.0.</li>
<li><code>step-security/harden-runner</code> v2.20.1 → v2.21.0.</li>
<li>Python tooling: <code>platformdirs</code> (yamllint CI dependency) 4.11.3 → 4.11.5.</li>
<li>Refreshed the self-referential <code>TomTonic/grype_me</code> action digest pin used in this repository&rsquo;s own dogfooding workflow.</li>
</ul>
<h2 id="new-features">New Features</h2>
<p>None — this release is an internal toolchain/idiom modernization; observable action behavior for consumers is unchanged.</p>
]]></content:encoded></item><item><title>TookEffect Verified Merge</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/tookeffect-verified-merge/</link><pubDate>Fri, 28 Aug 2026 17:42:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/tookeffect-verified-merge/</guid><description>Version updated for https://github.com/tookeffect/tookeffect-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary TookEffect Verified Merge is a GitHub Action that uses Tookeffect to verify if a pull request has been merged correctly into a branch. It provides an authoritative final verdict by executing the merge through TookEffect and ensuring that the change was applied as intended on the destination branch. The action binds a unique idempotency key to each exact PR head and base commit, retries only the identical request if needed, and returns success for a completed APPLIED verdict. It also provides detailed outputs about the Effect ID, verdict, reason, receipt URL, and keys, ensuring transparency in the verification process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tookeffect/tookeffect-action">https://github.com/tookeffect/tookeffect-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tookeffect-verified-merge">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>TookEffect Verified Merge</code> is a GitHub Action that uses <a href="https://tookeffect.com">Tookeffect</a> to verify if a pull request has been merged correctly into a branch. It provides an authoritative final verdict by executing the merge through TookEffect and ensuring that the change was applied as intended on the destination branch. The action binds a unique idempotency key to each exact PR head and base commit, retries only the identical request if needed, and returns success for a completed <code>APPLIED</code> verdict. It also provides detailed outputs about the Effect ID, verdict, reason, receipt URL, and keys, ensuring transparency in the verification process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of TookEffect Verified Merge.</p>
<p>Executes an exact GitHub pull request merge through TookEffect and independently verifies the authoritative GitHub state before returning APPLIED, NOT_APPLIED, or AMBIGUOUS.</p>
<p>Production end-to-end smoke verified with a real GitHub merge and TookEffect Effect receipt.</p>
]]></content:encoded></item><item><title>Win RDP Enabler</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/win-rdp-enabler/</link><pubDate>Fri, 28 Aug 2026 17:41:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/win-rdp-enabler/</guid><description>Version updated for https://github.com/Veniamin668/win-rdp-enabler to version v1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Win RDP Enabler GitHub Action automates the setup of Remote Desktop Protocol (RDP) access and network connectivity using Tailscale on Windows GitHub Actions runners. It simplifies configuring RDP by automatically setting up Tailscale, allowing users to connect to the runner via RDP without manual intervention. The action handles both default runneradmin credentials and custom admin or user accounts with optional passwords.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Veniamin668/win-rdp-enabler">https://github.com/Veniamin668/win-rdp-enabler</a></strong> to version <strong>v1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/win-rdp-enabler">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Win RDP Enabler GitHub Action automates the setup of Remote Desktop Protocol (RDP) access and network connectivity using Tailscale on Windows GitHub Actions runners. It simplifies configuring RDP by automatically setting up Tailscale, allowing users to connect to the runner via RDP without manual intervention. The action handles both default <code>runneradmin</code> credentials and custom admin or user accounts with optional passwords.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update action.yml (8a6a007)</li>
<li>Fix formatting of Win RDP Enabler workflow step (bcecee1)</li>
<li>Update README.md (036e52e)</li>
<li>Update action.yml (a495b61)</li>
<li>Update action.yml (b115754)</li>
<li>Update README.md (e15c9d3)</li>
<li>Create action.yml (76f4802)</li>
<li>Initial commit (af922ab)</li>
</ul>
]]></content:encoded></item><item><title>N-Plus-One Guardian</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/n-plus-one-guardian/</link><pubDate>Fri, 28 Aug 2026 17:40:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/n-plus-one-guardian/</guid><description>Version updated for https://github.com/whentony/n-plus-one-guardian to version 1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The N-Plus-One Guardian GitHub Action is designed to analyze and protect Pull Requests against the N+1 database performance issue by detecting and preventing incorrect use of lazy loading or index loss in loops. It supports multiple programming languages, including PHP, TypeScript, JavaScript, and Python, using Tree-sitter for parsing ASTs. The action automatically detects N+1 queries and index loss within loops and comments on PRs to prevent these issues.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/whentony/n-plus-one-guardian">https://github.com/whentony/n-plus-one-guardian</a></strong> to version <strong>1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/n-plus-one-guardian">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <strong>N-Plus-One Guardian</strong> GitHub Action is designed to analyze and protect Pull Requests against the N+1 database performance issue by detecting and preventing incorrect use of lazy loading or index loss in loops. It supports multiple programming languages, including PHP, TypeScript, JavaScript, and Python, using Tree-sitter for parsing ASTs. The action automatically detects N+1 queries and index loss within loops and comments on PRs to prevent these issues.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Inclusão da  identificação e alertar sobre o uso de conversões de tipo (casts) em consultas de banco de dados, que podem causar a invalidação de índices e resultar em problemas de performance (como full table scans).</p>
]]></content:encoded></item><item><title>Apex Test List</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/apex-test-list/</link><pubDate>Fri, 28 Aug 2026 17:39:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/apex-test-list/</guid><description>Version updated for https://github.com/wisefoxme/apex-test-list to version v1.14.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates a list of Apex tests that need to be run based on comments or specified metadata, automating the process of identifying and running necessary test classes. It supports both custom comment annotations (@Tests:) and using a centralized metadata filter file (.test-dependencies.yml), making it easier for developers to manage and execute test cases efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wisefoxme/apex-test-list">https://github.com/wisefoxme/apex-test-list</a></strong> to version <strong>v1.14.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/apex-test-list">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates a list of Apex tests that need to be run based on comments or specified metadata, automating the process of identifying and running necessary test classes. It supports both custom comment annotations (<code>@Tests:</code>) and using a centralized metadata filter file (<code>.test-dependencies.yml</code>), making it easier for developers to manage and execute test cases efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1141-2026-08-28"><a href="https://github.com/wisefoxme/apex-test-list/compare/v1.14.0...v1.14.1">1.14.1</a> (2026-08-28)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>handle YAML comments in yamlParser (regression from 1.14.0) (<a href="https://github.com/wisefoxme/apex-test-list/issues/402">#402</a>) (<a href="https://github.com/wisefoxme/apex-test-list/commit/05b91b1ca3749f9989fa9e1e7c6ebf36b9f5886c">05b91b1</a>)</li>
</ul>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/b.ia-accessibility-checker/</link><pubDate>Fri, 28 Aug 2026 17:38:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action B.IA automates accessibility checks in a CI/CD pipeline by mapping and analyzing guidelines to ensure code complies with WCAG standards. It provides flexibility in defining audiences and guideline percentages, allowing companies to focus on higher revenue audiences while improving product accessibility. The action uses AI for abstract guideline analysis and determines whether pull requests are accepted or blocked based on compliance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action B.IA automates accessibility checks in a CI/CD pipeline by mapping and analyzing guidelines to ensure code complies with WCAG standards. It provides flexibility in defining audiences and guideline percentages, allowing companies to focus on higher revenue audiences while improving product accessibility. The action uses AI for abstract guideline analysis and determines whether pull requests are accepted or blocked based on compliance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>ttyd server</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/ttyd-server/</link><pubDate>Fri, 28 Aug 2026 17:37:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/ttyd-server/</guid><description>Version updated for https://github.com/zongou/run-ttyd-server to version 0.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub action automates the setup and execution of a ttyd server on a GitHub Actions runner, providing an interactive terminal session for debugging or accessing system services remotely. It is designed to resolve issues with SSH access being blocked during GitHub actions by enabling remote terminal connections securely.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zongou/run-ttyd-server">https://github.com/zongou/run-ttyd-server</a></strong> to version <strong>0.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ttyd-server">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub action automates the setup and execution of a ttyd server on a GitHub Actions runner, providing an interactive terminal session for debugging or accessing system services remotely. It is designed to resolve issues with SSH access being blocked during GitHub actions by enabling remote terminal connections securely.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/zongou/run-ttyd-server/compare/0.0.1...0.0.2">https://github.com/zongou/run-ttyd-server/compare/0.0.1...0.0.2</a></p>
]]></content:encoded></item><item><title>Vizb Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/vizb-action/</link><pubDate>Fri, 28 Aug 2026 09:42:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/vizb-action/</guid><description>Version updated for https://github.com/goptics/vizb to version v0.20.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Vizb GitHub Action automates the creation of interactive HTML reports from CSV, JSON, and benchmark data. It simplifies the process by generating self-contained charts and statistical summaries without requiring a server or additional dependencies. This tool is useful for developers and data scientists who need to quickly visualize and analyze their datasets in a user-friendly format.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/goptics/vizb">https://github.com/goptics/vizb</a></strong> to version <strong>v0.20.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vizb-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Vizb GitHub Action automates the creation of interactive HTML reports from CSV, JSON, and benchmark data. It simplifies the process by generating self-contained charts and statistical summaries without requiring a server or additional dependencies. This tool is useful for developers and data scientists who need to quickly visualize and analyze their datasets in a user-friendly format.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(ui): trim dead-weight UI tests by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/379">https://github.com/goptics/vizb/pull/379</a></li>
<li>feat(action): add optional cmd retries by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/378">https://github.com/goptics/vizb/pull/378</a></li>
<li>fix(action): skip download when the resolved tag is cached by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/380">https://github.com/goptics/vizb/pull/380</a></li>
<li>refactor(ui): delete unused helpers and collapse duplicate chart/settings code by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/381">https://github.com/goptics/vizb/pull/381</a></li>
<li>fix(ui): align heatmap visual map with logo green by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/382">https://github.com/goptics/vizb/pull/382</a></li>
<li>feat(cli): split stdin spinner and report collected records by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/390">https://github.com/goptics/vizb/pull/390</a></li>
<li>ci: cache embed UI gen across workflows by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/391">https://github.com/goptics/vizb/pull/391</a></li>
<li>ci: rebuild embed UI on push by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/392">https://github.com/goptics/vizb/pull/392</a></li>
<li>ci: rebuild embed UI only when ui/ changes by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/393">https://github.com/goptics/vizb/pull/393</a></li>
<li>chore(deps): bump sharp from 0.34.5 to 0.35.3 in /docs by @dependabot[bot] in <a href="https://github.com/goptics/vizb/pull/283">https://github.com/goptics/vizb/pull/283</a></li>
<li>feat(ui): render bar background onto echarts series by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/396">https://github.com/goptics/vizb/pull/396</a></li>
<li>feat(cli): add bar &ndash;bg flag with chart object props by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/394">https://github.com/goptics/vizb/pull/394</a></li>
<li>feat(api): accept background on BarChartConfig by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/395">https://github.com/goptics/vizb/pull/395</a></li>
<li>docs: document bar &ndash;bg / chart bg object form by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/397">https://github.com/goptics/vizb/pull/397</a></li>
<li>feat(cli): show download progress on vizb update by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/411">https://github.com/goptics/vizb/pull/411</a></li>
<li>feat(ui): apply per-axis log scale and logBase by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/419">https://github.com/goptics/vizb/pull/419</a></li>
<li>feat(ui): add read-only log-scale info hover by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/422">https://github.com/goptics/vizb/pull/422</a></li>
<li>fix(ui): restrict line charts to slider-only dataZoom by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/425">https://github.com/goptics/vizb/pull/425</a></li>
<li>fix(ui): restore line canvas zoom and keep horizontal bar slider working by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/426">https://github.com/goptics/vizb/pull/426</a></li>
<li>feat(cli): parse &ndash;scale bag onto chart Scale by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/418">https://github.com/goptics/vizb/pull/418</a></li>
<li>feat(api): accept per-axis scale object on REST by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/421">https://github.com/goptics/vizb/pull/421</a></li>
<li>docs: document per-axis &ndash;scale bag and chart braces by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/420">https://github.com/goptics/vizb/pull/420</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/goptics/vizb/compare/v0.19.0...v0.20.0">https://github.com/goptics/vizb/compare/v0.19.0...v0.20.0</a></p>
]]></content:encoded></item><item><title>Setup MySQL with Python 2.7</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/setup-mysql-with-python-2.7/</link><pubDate>Fri, 28 Aug 2026 09:40:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/setup-mysql-with-python-2.7/</guid><description>Version updated for https://github.com/griffinkelly/mysql-python to version 0.9.4.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action sets up a MySQL database in Docker and provides various options to configure and execute MySQL. It supports specific MySQL options like character set, collation, version, and binds container port to host port. The action works on Linux environments and can be used to run complex MySQL setups while avoiding issues with the Default MySQL installed by GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/griffinkelly/mysql-python">https://github.com/griffinkelly/mysql-python</a></strong> to version <strong>0.9.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-mysql-with-python-2-7">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action sets up a MySQL database in Docker and provides various options to configure and execute MySQL. It supports specific MySQL options like character set, collation, version, and binds container port to host port. The action works on Linux environments and can be used to run complex MySQL setups while avoiding issues with the Default MySQL installed by GitHub Actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update Dockerfile (88923f6)</li>
<li>Update Dockerfile (958fe5b)</li>
<li>Update Dockerfile (76bb5fc)</li>
<li>Update action.yml (2f7c2ae)</li>
<li>Update entrypoint.sh (149624a)</li>
<li>Update action.yml (76f218b)</li>
<li>Update Dockerfile (94ea8c5)</li>
<li>Improve documentations (700bd56)</li>
<li>Add restart option (c2f734e)</li>
<li>Add test code (82ee48a)</li>
</ul>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/ai-plugin-scanner/</link><pubDate>Fri, 28 Aug 2026 09:39:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.548.
This action is used across all versions by 58 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security, publishability, runtime readiness, and trust signal analysis of AI plugins across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while aligning with the main scanner release train. The action supports different execution modes, output formats, and features such as live network probing and SARIF upload to GitHub code scanning for enhanced security monitoring.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.548</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>58</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the security, publishability, runtime readiness, and trust signal analysis of AI plugins across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while aligning with the main scanner release train. The action supports different execution modes, output formats, and features such as live network probing and SARIF upload to GitHub code scanning for enhanced security monitoring.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/6ecf11ff0aecb5af1b7b75bbcd273758a87ca0a0">https://github.com/hashgraph-online/hol-guard/tree/6ecf11ff0aecb5af1b7b75bbcd273758a87ca0a0</a> with plugin-scanner 3.0.11.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.547...v1.2.548">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.547...v1.2.548</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/hol-codex-plugin-scanner/</link><pubDate>Fri, 28 Aug 2026 09:38:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.548.
This action is used across all versions by 13 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security, publishability, runtime readiness, and trust signals scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while staying aligned to the main scanner release train. The action supports various execution modes, input parameters, and output formats, including text, JSON, markdown, and SARIF.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.548</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>13</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the security, publishability, runtime readiness, and trust signals scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while staying aligned to the main scanner release train. The action supports various execution modes, input parameters, and output formats, including text, JSON, markdown, and SARIF.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1.2.547...v1.2.548">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1.2.547...v1.2.548</a></p>
]]></content:encoded></item><item><title>Hayward model scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/hayward-model-scan/</link><pubDate>Fri, 28 Aug 2026 09:37:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/hayward-model-scan/</guid><description>Version updated for https://github.com/hedgerow-dev/hayward to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: Hayward is a security scanner designed to identify potentially unsafe model files by analyzing pickle files, which can execute arbitrary code. It helps teams detect malicious or risky models before loading them into their environments, ensuring compliance with security policies and preventing unauthorized execution of code on user machines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hedgerow-dev/hayward">https://github.com/hedgerow-dev/hayward</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hayward-model-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> Hayward is a security scanner designed to identify potentially unsafe model files by analyzing pickle files, which can execute arbitrary code. It helps teams detect malicious or risky models before loading them into their environments, ensuring compliance with security policies and preventing unauthorized execution of code on user machines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Shortens the GitHub Action&rsquo;s Marketplace description to under 125 characters (a Marketplace requirement). No scanner change: the code is identical to <a href="https://github.com/hedgerow-dev/hayward/releases/tag/v1.2.0">1.2.0</a>.</p>
]]></content:encoded></item><item><title>slack-build-notifier</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/slack-build-notifier/</link><pubDate>Fri, 28 Aug 2026 09:36:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/slack-build-notifier/</guid><description>Version updated for https://github.com/hennejg/slack-build-notifier to version v2.4.2.
This action is used across all versions by 25 repositories. Action Type This is a Node action using Node version 12.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This Slack Build Notifier automates the process of sending notifications to a Slack channel or DM upon the completion of a GitHub Actions job, with support for customizing various parameters such as status, text, author information, and notification methods. It also supports legacy webhook features for setting the author name and emoji icon, and provides more compact default templates while retaining all relevant information. Future directions include using Slack’s block formatting for improved presentation and supporting test failure analysis summaries in the message.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hennejg/slack-build-notifier">https://github.com/hennejg/slack-build-notifier</a></strong> to version <strong>v2.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>25</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>12</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/slack-build-notifier">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This Slack Build Notifier automates the process of sending notifications to a Slack channel or DM upon the completion of a GitHub Actions job, with support for customizing various parameters such as status, text, author information, and notification methods. It also supports legacy webhook features for setting the author name and emoji icon, and provides more compact default templates while retaining all relevant information. Future directions include using Slack&rsquo;s block formatting for improved presentation and supporting test failure analysis summaries in the message.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>[npm] run publish (2f5973e)</li>
<li>Merge branch &lsquo;master&rsquo; into v2 (830b880)</li>
<li>Merge pull request #13 from case/patch-1 (ad67a2b)</li>
<li>Fix a typo (e348b4b)</li>
<li>Merge pull request #10 from 8398a7/master (a3883bc)</li>
<li>Merge pull request #9 from smknstd/master (653db42)</li>
<li>fix legacy syntax in README (d833ff7)</li>
<li>[npm] run publish (a7f2c1c)</li>
<li>Merge branch &lsquo;master&rsquo; into v2 (2e18bc8)</li>
<li>Merge pull request #8 from 8398a7/feature/7 (b0f3156)</li>
</ul>
]]></content:encoded></item><item><title>Holon Solve</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/holon-solve/</link><pubDate>Fri, 28 Aug 2026 09:35:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/holon-solve/</guid><description>Version updated for https://github.com/holon-run/holon to version v0.33.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action provides a local workbench for agents to perform continuous work. It automates the process of setting up and managing an agent’s workspace, organizing tasks, and handling events in a structured manner. The key capabilities include maintaining state across sessions, using explicit task models, and maintaining clear context boundaries between different types of inputs or outputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/holon-run/holon">https://github.com/holon-run/holon</a></strong> to version <strong>v0.33.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/holon-solve">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action provides a local workbench for agents to perform continuous work. It automates the process of setting up and managing an agent&rsquo;s workspace, organizing tasks, and handling events in a structured manner. The key capabilities include maintaining state across sessions, using explicit task models, and maintaining clear context boundaries between different types of inputs or outputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="runtime-line">Runtime line</h2>
<p>Holon v0.33.0 is part of the Rust runtime line. The Rust runtime is now the main <code>holon</code> binary.</p>
<p>This release adds the observer-sync foundation for resilient browser clients, first-class Ollama support, richer provider model discovery and reasoning controls, and stronger runtime lifecycle and recovery guarantees.</p>
<p>Supported binary assets for this release are Linux amd64, macOS amd64, and macOS arm64. The Linux amd64 binary supports Ubuntu 22.04 or newer (glibc 2.35 or newer).</p>
<h2 id="changes">Changes</h2>
<ul>
<li>Add the observer-sync contract and canonical per-agent projection pipeline, including durable event ingestion, roster snapshots, recovery boundaries, browser-local read state, multi-tab merging, and unread state (<a href="https://github.com/holon-run/holon/pull/2617">#2617</a>, <a href="https://github.com/holon-run/holon/pull/2619">#2619</a>, <a href="https://github.com/holon-run/holon/pull/2623">#2623</a>, <a href="https://github.com/holon-run/holon/pull/2625">#2625</a>, <a href="https://github.com/holon-run/holon/pull/2626">#2626</a>, <a href="https://github.com/holon-run/holon/pull/2627">#2627</a>, <a href="https://github.com/holon-run/holon/pull/2628">#2628</a>, <a href="https://github.com/holon-run/holon/pull/2629">#2629</a>, <a href="https://github.com/holon-run/holon/pull/2630">#2630</a>, <a href="https://github.com/holon-run/holon/pull/2631">#2631</a>, <a href="https://github.com/holon-run/holon/pull/2634">#2634</a>).</li>
<li>Harden browser synchronization with persisted payload validation, bounded replay and roster lookups, v3 session event support, scoped observed heads, and deterministic real-daemon Chromium coverage (<a href="https://github.com/holon-run/holon/pull/2639">#2639</a>, <a href="https://github.com/holon-run/holon/pull/2652">#2652</a>, <a href="https://github.com/holon-run/holon/pull/2653">#2653</a>, <a href="https://github.com/holon-run/holon/pull/2658">#2658</a>, <a href="https://github.com/holon-run/holon/pull/2659">#2659</a>, <a href="https://github.com/holon-run/holon/pull/2661">#2661</a>, <a href="https://github.com/holon-run/holon/pull/2664">#2664</a>, <a href="https://github.com/holon-run/holon/pull/2665">#2665</a>, <a href="https://github.com/holon-run/holon/pull/2668">#2668</a>, <a href="https://github.com/holon-run/holon/pull/2669">#2669</a>, <a href="https://github.com/holon-run/holon/pull/2692">#2692</a>).</li>
<li>Add read-only runtime database auditing and strengthen retention, verification-proof reuse, and runtime search indexing boundaries (<a href="https://github.com/holon-run/holon/pull/2644">#2644</a>, <a href="https://github.com/holon-run/holon/pull/2650">#2650</a>, <a href="https://github.com/holon-run/holon/pull/2651">#2651</a>, <a href="https://github.com/holon-run/holon/pull/2656">#2656</a>).</li>
<li>Make task, turn, WorkItem, and scheduler recovery transitions more robust, including terminal settlement, pending web-read retries, legacy WorkItem completion, execution-source recovery routing, and quarantine for unmatched task results (<a href="https://github.com/holon-run/holon/pull/2624">#2624</a>, <a href="https://github.com/holon-run/holon/pull/2646">#2646</a>, <a href="https://github.com/holon-run/holon/pull/2682">#2682</a>, <a href="https://github.com/holon-run/holon/pull/2689">#2689</a>, <a href="https://github.com/holon-run/holon/pull/2691">#2691</a>, <a href="https://github.com/holon-run/holon/pull/2693">#2693</a>).</li>
<li>Complete timer lifecycle surfaces and improve timer rendering in the operator timeline (<a href="https://github.com/holon-run/holon/pull/2663">#2663</a>, <a href="https://github.com/holon-run/holon/pull/2683">#2683</a>).</li>
<li>Add first-class Ollama provider support with credential-free Web GUI discovery and automatic vision-model discovery for <code>ViewImage</code> (<a href="https://github.com/holon-run/holon/pull/2677">#2677</a>, <a href="https://github.com/holon-run/holon/pull/2679">#2679</a>, <a href="https://github.com/holon-run/holon/pull/2684">#2684</a>).</li>
<li>Expand provider interoperability with default model discovery for custom OpenAI-compatible routes, per-route reasoning effort, preserved provider server-tool blocks, and new GLM-5.3 and Qwen 3.8 catalog entries (<a href="https://github.com/holon-run/holon/pull/2640">#2640</a>, <a href="https://github.com/holon-run/holon/pull/2670">#2670</a>, <a href="https://github.com/holon-run/holon/pull/2673">#2673</a>, <a href="https://github.com/holon-run/holon/pull/2674">#2674</a>, <a href="https://github.com/holon-run/holon/pull/2696">#2696</a>, <a href="https://github.com/holon-run/holon/pull/2697">#2697</a>).</li>
</ul>
<h2 id="install">Install</h2>
<p>Homebrew:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap holon-run/tap
</span></span><span style="display:flex;"><span>brew install holon
</span></span></code></pre></div><p>Direct binary:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -L <span style="color:#e6db74">&#34;https://github.com/holon-run/holon/releases/download/v0.33.0/holon-linux-amd64.tar.gz&#34;</span> | tar -xz
</span></span><span style="display:flex;"><span>chmod +x holon
</span></span><span style="display:flex;"><span>./holon --help
</span></span></code></pre></div><p>Replace <code>holon-linux-amd64.tar.gz</code> with <code>holon-darwin-amd64.tar.gz</code> or <code>holon-darwin-arm64.tar.gz</code> on macOS.</p>
<p>Docker:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/holon-run/holon:0.33.0
</span></span></code></pre></div>]]></content:encoded></item><item><title>offsec-ai Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/offsec-ai-security-scanner/</link><pubDate>Fri, 28 Aug 2026 09:34:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/offsec-ai-security-scanner/</guid><description>Version updated for https://github.com/Htunn/offsec-ai to version v2.7.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary offsec-ai is an AI/ML-driven security toolkit that combines classic network reconnaissance with modern security testing. It performs full-stack infrastructure security assessments, actively attacks Model Context Protocol (MCP) servers for known CVEs, and integrates with Postman collections for comprehensive API vulnerability scanning and exploitation. The tool is designed to help authorized red teams identify and mitigate vulnerabilities in systems using LLM endpoints.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Htunn/offsec-ai">https://github.com/Htunn/offsec-ai</a></strong> to version <strong>v2.7.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/offsec-ai-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>offsec-ai</code> is an AI/ML-driven security toolkit that combines classic network reconnaissance with modern security testing. It performs full-stack infrastructure security assessments, actively attacks Model Context Protocol (MCP) servers for known CVEs, and integrates with Postman collections for comprehensive API vulnerability scanning and exploitation. The tool is designed to help authorized red teams identify and mitigate vulnerabilities in systems using LLM endpoints.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: bound pending task count in batch_check for hybrid identity and security headers (2041948)</li>
<li>feat: add Postman Collection v2.x security scanner and attacker (v2.7.0) (e4668e8)</li>
<li>ci: publish container to GitHub Container Registry (ghcr.io) (46d755c)</li>
<li>fix: remove undefined OwaspScanResult string annotation in test_cli.py (F821) (8e750e3)</li>
<li>feat: add A2A protocol security support (v2.6.0) (1b99a1b)</li>
<li>fix: define OUTPUT_ARGS before use; -o was silently dropped (v2.5.9) (889e688)</li>
<li>chore: replace all example.com targets with simpleportchecker.com (676106d)</li>
<li>fix: &ndash;format not -f for ai-owasp-scan; use simpleportchecker target (v2.5.8) (504b6e8)</li>
<li>fix: skip &ndash;timeout for ai-owasp-scan which does not support it (v2.5.7) (67a28cd)</li>
<li>chore: use Gemini public endpoint in ai-owasp-scan job (6a13857)</li>
</ul>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/neurolink-ai/</link><pubDate>Fri, 28 Aug 2026 09:33:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v12.2.6.
This action is used across all versions by 11 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that unifies 30+ AI providers and 100+ models under one consistent API, making it easy to integrate AI into any application with confidence. It supports switching providers with a single parameter change and offers built-in tools and enterprise features like Redis memory and multi-provider failover.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v12.2.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is a universal AI integration platform that unifies 30+ AI providers and 100+ models under one consistent API, making it easy to integrate AI into any application with confidence. It supports switching providers with a single parameter change and offers built-in tools and enterprise features like Redis memory and multi-provider failover.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1226-2026-08-27"><a href="https://github.com/juspay/neurolink/compare/v12.2.5...v12.2.6">12.2.6</a> (2026-08-27)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(localUsage):</strong>  a window longer than history means everything, not nothing (<a href="https://github.com/juspay/neurolink/commit/396553c073b31f07c30773221d45ed09a0965a10">396553c</a>)</li>
</ul>
]]></content:encoded></item><item><title>AIShield MCP/Agent Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/aishield-mcp/agent-security-scan/</link><pubDate>Fri, 28 Aug 2026 09:32:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/aishield-mcp/agent-security-scan/</guid><description>Version updated for https://github.com/lm203688/aishield to version v4.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI and Security: Agent Computer Security Plane
What’s Changed AIShield v4.3.0 — Closed-Loop Automation 新增能力 9-point version gate: sync_version.py 从 7→9 点，修复 server.py/openapi_spec.py 版本漂移 Local Ollama LLM backend: 本地 127.0.0.1/localhost 自动启用，无需 API key Differential scan: 对比两次扫描差异，区分新增/已修复/不变 Fuzzing engine: 编码逃逸/结构变异/语义混淆三种策略 arXiv→Rule pipeline: 安全论文自动转扫描规则 AIP agent-card: AIP-AC/v1 协议字段 自动化闭环 ci-state bus: ci.yml 写入 data/state/ci.json，下游 workflow 共享 feature-closed-loop: Python 3.11→3.13，修复崩溃 issue-labeler: 升级到 peter-evans/issue-labeler@v3 测试 590 tests passing / 0 failures 460 rules (227 MCP + 233 Skill) Zero third-party dependencies 已知问题 aishield.tools 线上站需 CF Dashboard Retry 重建 publish-npm / publish-mcp-registry 本 Release 触发</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lm203688/aishield">https://github.com/lm203688/aishield</a></strong> to version <strong>v4.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aishield-mcp-agent-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI and Security: Agent Computer Security Plane</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="aishield-v430--closed-loop-automation">AIShield v4.3.0 — Closed-Loop Automation</h2>
<h3 id="新增能力">新增能力</h3>
<ul>
<li><strong>9-point version gate</strong>: sync_version.py 从 7→9 点，修复 server.py/openapi_spec.py 版本漂移</li>
<li><strong>Local Ollama LLM backend</strong>: 本地 127.0.0.1/localhost 自动启用，无需 API key</li>
<li><strong>Differential scan</strong>: 对比两次扫描差异，区分新增/已修复/不变</li>
<li><strong>Fuzzing engine</strong>: 编码逃逸/结构变异/语义混淆三种策略</li>
<li><strong>arXiv→Rule pipeline</strong>: 安全论文自动转扫描规则</li>
<li><strong>AIP agent-card</strong>: AIP-AC/v1 协议字段</li>
</ul>
<h3 id="自动化闭环">自动化闭环</h3>
<ul>
<li><strong>ci-state bus</strong>: ci.yml 写入 data/state/ci.json，下游 workflow 共享</li>
<li><strong>feature-closed-loop</strong>: Python 3.11→3.13，修复崩溃</li>
<li><strong>issue-labeler</strong>: 升级到 peter-evans/issue-labeler@v3</li>
</ul>
<h3 id="测试">测试</h3>
<ul>
<li>590 tests passing / 0 failures</li>
<li>460 rules (227 MCP + 233 Skill)</li>
<li>Zero third-party dependencies</li>
</ul>
<h3 id="已知问题">已知问题</h3>
<ul>
<li>aishield.tools 线上站需 CF Dashboard Retry 重建</li>
<li>publish-npm / publish-mcp-registry 本 Release 触发</li>
</ul>
]]></content:encoded></item><item><title>Disensor Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/disensor-gate/</link><pubDate>Fri, 28 Aug 2026 09:27:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/disensor-gate/</guid><description>Version updated for https://github.com/NicolasRocchia/disensor to version v0.9.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates adversarial code review processes by integrating a controlled disagreement method. It helps in verifying and validating findings through CI gates and residue declarations. The action supports generating adversarial briefs, packages full reviews, and validates artifacts against a predefined schema. It also provides a guide for filling the artifact and rendering comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NicolasRocchia/disensor">https://github.com/NicolasRocchia/disensor</a></strong> to version <strong>v0.9.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/disensor-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates adversarial code review processes by integrating a controlled disagreement method. It helps in verifying and validating findings through CI gates and residue declarations. The action supports generating adversarial briefs, packages full reviews, and validates artifacts against a predefined schema. It also provides a guide for filling the artifact and rendering comments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Deja escrito cuándo sube el pin de la propia Action del gate: viaja en el próximo PR de trabajo real, salvo que la release corrija la seguridad del gate o cambie la versión del esquema. Y dice que eso es una convención, no un control: las reglas de protección de rama de GitHub no alcanzan a los administradores salvo que se deshabilite el bypass. Cierra #17.</p>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/odin-scan-smart-contract-security/</link><pubDate>Fri, 28 Aug 2026 09:26:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Odin Scan GitHub Action automates smart contract security analysis for CosmWasm, Solana, and EVM projects. It integrates with GitHub workflows to detect vulnerabilities before deployment, providing alerts in pull requests and inline comments on affected files. The action supports platform detection and customizable severity thresholds, allowing users to configure its behavior according to their needs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Odin Scan GitHub Action automates smart contract security analysis for CosmWasm, Solana, and EVM projects. It integrates with GitHub workflows to detect vulnerabilities before deployment, providing alerts in pull requests and inline comments on affected files. The action supports platform detection and customizable severity thresholds, allowing users to configure its behavior according to their needs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add comment-triggered PR scans (ac72e5f)</li>
<li>docs: expand findings-visibility section with threat model and annotation rationale (0404708)</li>
<li>feat: add findings-visibility input for graduated public disclosure control (f18df59)</li>
<li>fix: show findings detail in PR comment with fallback to medium (c2e43c8)</li>
<li>fix: new comment per run, show only critical/high findings, rebuild dist (e237b62)</li>
<li>feat: use GitHub App installation token for branded PR comments (3abce4e)</li>
<li>feat: enrich PR comment with emojis, descriptions, and fix report URL (27cc2f2)</li>
<li>fix: gzip SARIF before base64 encoding for Code Scanning upload (d9eed9f)</li>
<li>fix: include sourcemap-register.js in dist (bd265af)</li>
<li>docs: add privacy policy (b78db44)</li>
</ul>
]]></content:encoded></item><item><title>Plori persistent agent review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/plori-persistent-agent-review/</link><pubDate>Fri, 28 Aug 2026 09:25:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/plori-persistent-agent-review/</guid><description>Version updated for https://github.com/plori-ai/agent-action to version v1.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Plori agent review action creates and manages persistent review workspaces for GitHub repositories. It automates the process of checking out pull request commits, analyzing surrounding code, and running targeted tests to provide detailed feedback on code changes. The action ensures that each repository has a dedicated workspace for reviews, enhancing precision and reducing noise in automated feedback.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plori-ai/agent-action">https://github.com/plori-ai/agent-action</a></strong> to version <strong>v1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/plori-persistent-agent-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Plori agent review action creates and manages persistent review workspaces for GitHub repositories. It automates the process of checking out pull request commits, analyzing surrounding code, and running targeted tests to provide detailed feedback on code changes. The action ensures that each repository has a dedicated workspace for reviews, enhancing precision and reducing noise in automated feedback.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Persistent remote pull-request review with GitHub Actions OIDC and isolated comment permissions.</p>
]]></content:encoded></item><item><title>Healthchecks Ping Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/healthchecks-ping-action/</link><pubDate>Fri, 28 Aug 2026 09:24:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/healthchecks-ping-action/</guid><description>Version updated for https://github.com/reecetech/healthchecks-action to version v0.29.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates Healthchecks.io into workflows to monitor the health of scheduled jobs and workflows by sending pings at both the start and end of a job’s execution. It automatically sends pings to a specified URL, allowing for real-time monitoring and alerts. The action supports various inputs to customize ping behavior based on run status and workflow triggers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/reecetech/healthchecks-action">https://github.com/reecetech/healthchecks-action</a></strong> to version <strong>v0.29.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/healthchecks-ping-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates Healthchecks.io into workflows to monitor the health of scheduled jobs and workflows by sending pings at both the start and end of a job&rsquo;s execution. It automatically sends pings to a specified URL, allowing for real-time monitoring and alerts. The action supports various inputs to customize ping behavior based on run status and workflow triggers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #83 from reecetech/chore/dependabot-rollup-2026-08-27 (962e6b8)</li>
<li>Bump project dependencies (ce8aea9)</li>
<li>Merge pull request #66 from reecetech/dependabot/github_actions/EndBug/add-and-commit-10 (be7086c)</li>
<li>Merge branch &lsquo;main&rsquo; into dependabot/github_actions/EndBug/add-and-commit-10 (5fe9907)</li>
<li>Merge pull request #69 from reecetech/dependabot/npm_and_yarn/types/node-25.5.2 (7aad411)</li>
<li>Update README (2db2d12)</li>
<li>Merge branch &lsquo;main&rsquo; into dependabot/npm_and_yarn/types/node-25.5.2 (ac6f9ee)</li>
<li>Merge pull request #71 from reecetech/optional-skip-pings (def3b0f)</li>
<li>Update compiled action source (dist/*.js) (1e1edac)</li>
<li>Potential fix for pull request finding (c8ebb2d)</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/kaniko-build-action/</link><pubDate>Fri, 28 Aug 2026 09:23:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or “Hello” + a specified name to the log and also outputs the current time. It solves the problem of automating greetings with dynamic names and timestamps in CI/CD pipelines. The action is designed to be simple and reusable for various projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or &ldquo;Hello&rdquo; + a specified name to the log and also outputs the current time. It solves the problem of automating greetings with dynamic names and timestamps in CI/CD pipelines. The action is designed to be simple and reusable for various projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>serverless-container-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/serverless-container-action/</link><pubDate>Fri, 28 Aug 2026 09:23:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/serverless-container-action/</guid><description>Version updated for https://github.com/scaleway/scw-serverless-container-action to version 0.0.6.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 1 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Scaleway Serverless Containers GitHub Action simplifies deploying and managing containerized applications on Scaleway by integrating with their platform directly from a CI/CD pipeline. It automates the deployment of containers to a specified registry, namespace, and region, while also providing options for scaling and resource limits. The action supports both simple deploy and teardown workflows using input parameters for configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scaleway/scw-serverless-container-action">https://github.com/scaleway/scw-serverless-container-action</a></strong> to version <strong>0.0.6</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>1</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/serverless-container-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Scaleway Serverless Containers GitHub Action simplifies deploying and managing containerized applications on Scaleway by integrating with their platform directly from a CI/CD pipeline. It automates the deployment of containers to a specified registry, namespace, and region, while also providing options for scaling and resource limits. The action supports both simple deploy and teardown workflows using input parameters for configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(build): add workflow to check build by @philibea in <a href="https://github.com/scaleway/scw-serverless-container-action/pull/5">https://github.com/scaleway/scw-serverless-container-action/pull/5</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scaleway/scw-serverless-container-action/compare/0.0.5...0.0.6">https://github.com/scaleway/scw-serverless-container-action/compare/0.0.5...0.0.6</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/custom-amazon-bedrock-agent-action/</link><pubDate>Fri, 28 Aug 2026 09:22:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the analysis of PR files using Amazon Bedrock Agent, enhancing code quality and security assessments. It allows customization of prompts, integrates with Amazon Bedrock Knowledge Bases for context-aware insights, and seamlessly integrates into the PR process with comments posted in markdown format.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the analysis of PR files using Amazon Bedrock Agent, enhancing code quality and security assessments. It allows customization of prompts, integrates with Amazon Bedrock Knowledge Bases for context-aware insights, and seamlessly integrates into the PR process with comments posted in markdown format.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/sherpa.sh/</link><pubDate>Fri, 28 Aug 2026 09:21:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven deployment automation tool that simplifies infrastructure setup by translating human-readable descriptions into cloud-native configurations. It enables developers to define their deployment needs in natural language, and Sherpa automatically creates and configures the necessary resources (e.g., servers, DNS, SSL, CDN) to meet these requirements. The tool supports a wide range of cloud providers, frameworks, and deployment scenarios, making it suitable for various projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven deployment automation tool that simplifies infrastructure setup by translating human-readable descriptions into cloud-native configurations. It enables developers to define their deployment needs in natural language, and Sherpa automatically creates and configures the necessary resources (e.g., servers, DNS, SSL, CDN) to meet these requirements. The tool supports a wide range of cloud providers, frameworks, and deployment scenarios, making it suitable for various projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>greenbump</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/greenbump/</link><pubDate>Fri, 28 Aug 2026 09:20:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/greenbump/</guid><description>Version updated for https://github.com/shidesheng0218/greenbump to version v0.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary greenbump is a tool that automatically upgrades dependencies and fixes breaking code changes in your project. It uses AI to detect issues during the upgrade process and provides a loop to fix any errors, ensuring your build and tests pass successfully. The action supports multiple ecosystems and offers features like automatic code repair, multi-round verification, and customizable models for fixing issues.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shidesheng0218/greenbump">https://github.com/shidesheng0218/greenbump</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/greenbump">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>greenbump is a tool that automatically upgrades dependencies and fixes breaking code changes in your project. It uses AI to detect issues during the upgrade process and provides a loop to fix any errors, ensuring your build and tests pass successfully. The action supports multiple ecosystems and offers features like automatic code repair, multi-round verification, and customizable models for fixing issues.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Expanded codemod library</strong>: tier-1 free fixes grew from 6 to 24, covering the
highest-frequency breaking upgrades reported by users — Express 4→5 (<code>app.del</code>,
<code>res.send(status)</code>), Zod 3→4 (<code>error.errors</code>→<code>error.issues</code>, <code>.email()</code>/<code>.url()</code>/
<code>.uuid()</code> shorthand), Node 20→22 (<code>util.is*</code> removal), Lodash 4 (<code>_.pluck</code>,
<code>_.contains</code>), React Router 5→6 (<code>&lt;Switch&gt;</code>→<code>&lt;Routes&gt;</code>, <code>useHistory</code>→<code>useNavigate</code>),
Mongoose 6→8 (<code>doc.remove()</code>→<code>doc.deleteOne()</code>), plus <code>assert.deepEqual</code>.</li>
<li><strong>Guidance-only codemods</strong>: for breakages too risky to regex-rewrite (ESLint 9 flat
config, Axios 1.x, Webpack 5 polyfills, Jest 29+ jsdom split, TypeScript 5
<code>verbatimModuleSyntax</code>, Prettier 3 defaults, Socket.IO 4), tier 1 now matches the
failure and surfaces a migration note instead of guessing at a code change. These
never mark the tier as &ldquo;fixed&rdquo; — they escalate to tier 4 like a miss, but the
agent (and the user, via logs) starts with the right context.</li>
<li><strong>Codemod <code>creates</code></strong>: codemods can scaffold a companion file after a successful
transform (e.g. ESLint 9&rsquo;s <code>eslint.config.js</code> starter). Skipped if the file already
exists, so it never clobbers user config.</li>
<li><strong>Codemod <code>versionRange.toMajor</code></strong>: a codemod can now cover a span of majors
(e.g. Mongoose 6→7 and 6→8 both match <code>doc.remove()</code>), not just a single bump.</li>
<li><strong>Usage &amp; cost report</strong> (<code>greenbump --stats [days]</code>, default 30-day window):
every run appends a local record (<code>~/.greenbump/runs.jsonl</code>, override with
<code>GREENBUMP_STATS_DIR</code>) — dep, tier, tokens, cache hit, fixed/needsReview. <code>--stats</code>
aggregates them into fix-tier breakdown, LLM calls avoided, actual tokens/cost
spent, and an <em>estimated</em> dollar amount saved by tiers 1-3 (labeled as an estimate,
never presented as a bill). <code>--stats --json</code> prints the raw summary for scripting.
Fully local — no network calls, no telemetry.</li>
<li>New CLI flags: <code>--stats [days]</code>, <code>--json</code> (with <code>--stats</code>).</li>
<li>New modules:
<ul>
<li><code>src/engine/stats/recorder.ts</code> (append-only JSONL run log)</li>
<li><code>src/engine/stats/report.ts</code> (aggregation + terminal report + $/M-token pricing table)</li>
</ul>
</li>
<li>33 new tests (145 total): 13 new codemod cases (transform, guidance-only, <code>creates</code>,
multi-major <code>versionRange</code>), recorder round-trip/corrupt-line-tolerance, and report
aggregation (tier counts, window filtering, cost estimation, empty state).</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><code>tryBuiltinCodemods</code> no longer treats &ldquo;advice printed&rdquo; as &ldquo;applied&rdquo; — a
guidance-only codemod match now returns <code>applied: false</code> with an <code>advice[]</code> list,
so the fix loop correctly escalates to tier 4 instead of running a wasted
verification check. (Previously this case didn&rsquo;t exist; called out here since it&rsquo;s
the load-bearing invariant the new guidance codemods depend on.)</li>
<li><code>RunSummary</code>/batch group runs now record to the local stats log on every exit path
(clean upgrade, unverifiable, and fixed-or-not), not just the LLM fix path.</li>
</ul>
<h3 id="impact">Impact</h3>
<ul>
<li><strong>Higher tier-1 hit rate</strong>: 4x more codemods means more real-world upgrades resolve
at $0 without ever calling an LLM.</li>
<li><strong>Visible savings</strong>: <code>greenbump --stats</code> answers &ldquo;how much has this tool saved me&rdquo;
with real numbers instead of a single run&rsquo;s summary.</li>
<li>Verified end-to-end: Express 4→5 (<code>app.del</code>) and Zod 3→4 (<code>error.errors</code>) both fix
with 0 input / 0 output tokens; <code>--stats</code> correctly aggregates both runs.</li>
</ul>
]]></content:encoded></item><item><title>Claude Code Canary</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/claude-code-canary/</link><pubDate>Fri, 28 Aug 2026 09:18:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/claude-code-canary/</guid><description>Version updated for https://github.com/SLP-DEV1/claude-code-canary to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Canary is a GitHub Action that automates deterministic regression testing and compatibility intelligence for Claude Code. It helps users identify what broke in their codebase, which release first introduced the issue, and compares releases to detect regressions. Canary supports CI workflows and provides detailed reporting on tool/token/reported-cost/duration metrics and deterministic assertions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SLP-DEV1/claude-code-canary">https://github.com/SLP-DEV1/claude-code-canary</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/claude-code-canary">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Canary is a GitHub Action that automates deterministic regression testing and compatibility intelligence for Claude Code. It helps users identify what broke in their codebase, which release first introduced the issue, and compares releases to detect regressions. Canary supports CI workflows and provides detailed reporting on tool/token/reported-cost/duration metrics and deterministic assertions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci: add published consumer smoke coverage by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/46">https://github.com/SLP-DEV1/claude-code-canary/pull/46</a></li>
<li>ci: add stable required status gate by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/47">https://github.com/SLP-DEV1/claude-code-canary/pull/47</a></li>
<li>docs: sharpen install and distribution README by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/50">https://github.com/SLP-DEV1/claude-code-canary/pull/50</a></li>
<li>chore: harden community issue intake by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/51">https://github.com/SLP-DEV1/claude-code-canary/pull/51</a></li>
<li>docs: add community conduct and support standards by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/52">https://github.com/SLP-DEV1/claude-code-canary/pull/52</a></li>
<li>ci: validate local documentation links by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/54">https://github.com/SLP-DEV1/claude-code-canary/pull/54</a></li>
<li>chore: add CODEOWNERS routing by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/55">https://github.com/SLP-DEV1/claude-code-canary/pull/55</a></li>
<li>docs: synchronize public distribution status by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/56">https://github.com/SLP-DEV1/claude-code-canary/pull/56</a></li>
<li>docs: strengthen pull request checklist by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/57">https://github.com/SLP-DEV1/claude-code-canary/pull/57</a></li>
<li>docs: make roadmap release reference dynamic by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/58">https://github.com/SLP-DEV1/claude-code-canary/pull/58</a></li>
<li>docs: consolidate roadmap entry point by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/59">https://github.com/SLP-DEV1/claude-code-canary/pull/59</a></li>
<li>fix: shorten Marketplace action description by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/60">https://github.com/SLP-DEV1/claude-code-canary/pull/60</a></li>
<li>docs: mark Marketplace publication live by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/61">https://github.com/SLP-DEV1/claude-code-canary/pull/61</a></li>
<li>docs: replace roadmap with post-v1.2 product direction by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/62">https://github.com/SLP-DEV1/claude-code-canary/pull/62</a></li>
<li>feat: release Claude Code Canary v2 compatibility platform by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/63">https://github.com/SLP-DEV1/claude-code-canary/pull/63</a></li>
<li>fix: pin Claude version in live release E2E by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/64">https://github.com/SLP-DEV1/claude-code-canary/pull/64</a></li>
<li>chore: retrigger v2.0.0 release candidate by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/65">https://github.com/SLP-DEV1/claude-code-canary/pull/65</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SLP-DEV1/claude-code-canary/compare/v1.2.0...v2.0.0">https://github.com/SLP-DEV1/claude-code-canary/compare/v1.2.0...v2.0.0</a></p>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Fri, 28 Aug 2026 09:17:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service. It ensures that all necessary files are bundled and pushed to the repository before deploying, solving the need for manual steps in the CI/CD pipeline. The action simplifies the process by handling dependencies and bundling, allowing developers to focus on application deployment tasks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service. It ensures that all necessary files are bundled and pushed to the repository before deploying, solving the need for manual steps in the CI/CD pipeline. The action simplifies the process by handling dependencies and bundling, allowing developers to focus on application deployment tasks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/classroom-to-sheets-integration/</link><pubDate>Fri, 28 Aug 2026 09:17:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates GitHub Classroom results into Google Sheets. It automates the process of updating a specific Google Sheet with student names and task results as they are submitted through GitHub Classroom. The integration uses Google Sheets API credentials stored as secrets in your repository. Users can configure their workflow to automatically update the sheet whenever a new submission is made, making it easier to track and monitor student progress.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates GitHub Classroom results into Google Sheets. It automates the process of updating a specific Google Sheet with student names and task results as they are submitted through GitHub Classroom. The integration uses Google Sheets API credentials stored as secrets in your repository. Users can configure their workflow to automatically update the sheet whenever a new submission is made, making it easier to track and monitor student progress.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>Ccache for SushiKernel</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/ccache-for-sushikernel/</link><pubDate>Fri, 28 Aug 2026 09:16:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/ccache-for-sushikernel/</guid><description>Version updated for https://github.com/SushiKernel/ccache to version v1.2.23.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup of ccache/sccache for C/C++ projects in GitHub Actions, improving build speed by caching compiled binaries. It supports Linux, macOS, and Windows environments and provides options to cache specific jobs or targets separately, offering verbose logging for debugging purposes. The action installs ccache if necessary and sets it as the compiler launcher for C and C++ builds.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SushiKernel/ccache">https://github.com/SushiKernel/ccache</a></strong> to version <strong>v1.2.23</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ccache-for-sushikernel">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup of ccache/sccache for C/C++ projects in GitHub Actions, improving build speed by caching compiled binaries. It supports Linux, macOS, and Windows environments and provides options to cache specific jobs or targets separately, offering verbose logging for debugging purposes. The action installs ccache if necessary and sets it as the compiler launcher for C and C++ builds.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Support platforms without upstream ccache/sccache releases (#439) (d62db5f)</li>
<li>update code (05e1c04)</li>
<li>Bump brace-expansion (#438) (46cafa7)</li>
<li>Update ccache to 4.13.3 (#441) (1f2fc71)</li>
<li>Bump @types/node from 25.5.0 to 25.6.0 (#440) (a488765)</li>
<li>Bump handlebars from 4.7.8 to 4.7.9 (#436) (c97afba)</li>
<li>update code (3352247)</li>
<li>Bump fast-xml-parser from 5.4.1 to 5.5.7 (#434) (e44a23f)</li>
<li>Bump picomatch (#435) (bb3037d)</li>
<li>update code (1bbbcda)</li>
</ul>
]]></content:encoded></item><item><title>darnlink — self-healing Markdown links</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/darnlink-self-healing-markdown-links/</link><pubDate>Fri, 28 Aug 2026 09:15:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/darnlink-self-healing-markdown-links/</guid><description>Version updated for https://github.com/txemi/darnlink to version v0.26.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of fixing Markdown links in a documentation repository. It ensures that links remain valid even after changes are made, such as moving files or folders. The action uses UUIDs to anchor links and automatically updates them if necessary. It also provides an option to convert plain links into robust ones that self-heal in the future. The main purpose of this action is to maintain a reliable reference system for documentation content over time.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/txemi/darnlink">https://github.com/txemi/darnlink</a></strong> to version <strong>v0.26.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/darnlink-self-healing-markdown-links">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of fixing Markdown links in a documentation repository. It ensures that links remain valid even after changes are made, such as moving files or folders. The action uses UUIDs to anchor links and automatically updates them if necessary. It also provides an option to convert plain links into robust ones that self-heal in the future. The main purpose of this action is to maintain a reliable reference system for documentation content over time.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Everything since 0.24.0 — the 0.25.0 / 0.25.1 / 0.26.0 CHANGELOG sections were never tagged on their own; this is the first release that carries them. <strong>Consumers pin by SHA or tag: nothing changes for a repo until its <code>darnlink-gate.json</code> <code>ref</code> moves</strong> (and <code>recipe_sha256</code> with it, in the same commit).</p>
<blockquote>
<p>Consolidates everything since 0.24.0: the <code>0.25.0</code> / <code>0.25.1</code> / <code>0.26.0</code> sections that had been
written ahead of a tag were never released on their own; this is the first tag that carries them.</p>
</blockquote>
<h3 id="the-gate-recipe-verified-downloads-recipe_sha256-windows-cr">The gate recipe: verified downloads, <code>recipe_sha256</code>, Windows CR</h3>
<p><strong>The shipped CI templates downloaded the recipe and executed it without verifying a byte</strong> — both
of them, at every released version. <code>recipes/examples/github-actions-darnlink-gate.yml</code> and
<code>recipes/examples/Jenkinsfile-stage.groovy</code> now compare <code>recipe_sha256</code> <strong>before</strong> <code>chmod +x</code>, warn
loudly (instead of silently) when the key is absent, reject a value that is not a 64-hex digest with
a message about placeholders rather than crying tampering, and fall back to <code>shasum -a 256</code> where
<code>sha256sum</code> does not exist.</p>
<p><strong>New config key <code>recipe_sha256</code></strong> — and &ldquo;new&rdquo; understates it: consumers had been using the key for
months while it appeared nowhere in this repo, so every surface that verified had invented it
locally. It is now documented in the recipe&rsquo;s CONFIG header and in <code>recipes/README.md</code>, including
the rule that prevents the failure it is most likely to produce: <strong><code>ref</code> and <code>recipe_sha256</code> move in
the same commit.</strong> It is the one key the recipe never reads — whoever fetches the script consumes
it, because a downloaded script cannot vouch for its own download. It does <strong>not</strong> cover
<code>darnlink-gate.ps1</code>, which is a different file with a different digest.</p>
<h4 id="fixed">Fixed</h4>
<ul>
<li>
<p><code>recipes/darnlink-gate</code>: the three remaining Python heredocs (finding filter, README-offender
count and staged summary) now set <code>sys.stdout.reconfigure(newline=&quot;\n&quot;)</code>, as <code>read_cfg</code> and
<code>read_cfg_len</code> do since #97. On Windows the offender count came back as <code>&quot;N\r&quot;</code>, so the
<code>[ &quot;$cr&quot; -gt 0 ]</code> test failed with &ldquo;integer expression expected&rdquo; and the gate aborted; the
finding details carried a trailing CR. Behaviour on POSIX is byte-identical.</p>
</li>
<li>
<p><strong>A JSON <code>false</code> turned <code>include_mermaid</code> ON</strong>, and <code>default_branch: false</code> reached the tool as
<code>--default-branch False</code>, a branch that exists nowhere. <code>read_cfg</code> renders a JSON boolean as the
string <code>&quot;False&quot;</code>, and <code>[ -n &quot;$X&quot; ]</code> is true for any non-empty string. Five other keys were already
normalised; the two that were not sat directly above a <code>case</code> belonging to a key assigned thirteen
lines earlier, which is how both were missed. Normalisers now live beside their own assignment.</p>
</li>
<li>
<p><strong>A docstring in <code>frontmatter_index.py</code> claimed a leading BOM survives the read.</strong> <code>utf-8-sig</code>
consumes it. Documentation only — and the same reader&rsquo;s other docstring already said the opposite,
correctly.</p>
</li>
<li>
<p><strong><code>tools/check.sh</code> run as a git hook redirected the suite&rsquo;s git calls at this repository.</strong> git
exports <code>GIT_DIR</code> to hooks; tests that build their own repo in a temp dir were silently pointed
here, and one ordinary <code>git commit</code> produced a commit that deleted the entire tree. It also made
four tests fail <em>only</em> when the suite was acting as the gate.</p>
</li>
</ul>
<h3 id="an-inert-rung-now-says-so">An inert rung now says so</h3>
<p><strong>An inert rung now says so.</strong> When the pending-on-default-branch rung cannot identify the repo or
its default branch it disables itself — correct — but it did so SILENTLY, and a disabled rung looks
exactly like one that ran and found a real break: same <code>web_not_found</code>, same exit 4. Three
attempted fixes each looked like they had never arrived, when they had arrived and were switching
themselves off. One line on stderr turns that mystery into a datum.</p>
<p><strong>New <code>--default-branch NAME</code></strong>, which wins over both automatic sources. It is the only one that
cannot fail, and in CI it is often the only one that CAN answer: the checkout has no <code>origin/HEAD</code>
(only the PR ref is fetched) and the credentials for <code>ls-remote</code> are usually scoped to the checkout
step rather than to what it spawns.</p>
<h3 id="the-default-branch-read-was-inert-in-ci">The default-branch read was inert in CI</h3>
<p>The pending-on-default-branch rung was <strong>inert in CI</strong>, which is the only place it mattered. It read the default branch
from <code>origin/HEAD</code> — a LOCAL symref that a CI checkout does not create: a multibranch PR job fetches
only <code>+refs/pull/&lt;n&gt;/head:refs/remotes/origin/PR-&lt;n&gt;</code>, so there is no <code>refs/remotes/origin/master</code>
and <code>symbolic-ref</code> fails. Every ordinary clone HAS that symref, which is why it looked correct.</p>
<p>The local read stays first (free); the remote is asked with <code>ls-remote --symref</code> only when it
fails. Unknown default branch still means inert — guessing <code>main</code> would forgive links in every repo
whose default is something else.</p>
<h3 id="a-link-pending-on-the-default-branch-is-not-a-broken-link">A link pending on the default branch is not a broken link</h3>
<p>A <code>blob/&lt;default-branch&gt;/&lt;path&gt;</code> URL to a file that exists in the working tree but has not reached
the default branch yet was classified <code>web_not_found</code> -&gt; <code>exit 4</code>. In a blocking gate that is a
<strong>deadlock</strong>: the red blocks the merge that would make the link resolve. Measured in the field as
<code>not-found 6</code> on a branch that could not go green before merging and could not merge while red.</p>
<p>It now becomes <code>web_unverifiable</code> — the kind that already existed for &ldquo;cannot tell from here&rdquo; —
under <strong>five</strong> conditions, every one of which closes a way a permanently-dead link walked through
an earlier draft of this rung, green:</p>
<table>
  <thead>
      <tr>
          <th>condition</th>
          <th>what it stops forgiving</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>the ref IS the default branch</td>
          <td><code>blob/&lt;sha&gt;/…</code>, a tag, a deleted branch — none of which any merge resolves</td>
      </tr>
      <tr>
          <td>the slug is ASCII and matches <code>origin</code></td>
          <td>lookalike hosts; <code>casefold()</code> collapses U+212A to <code>k</code></td>
      </tr>
      <tr>
          <td>the path is confined to the tree</td>
          <td><code>blob/main//etc/hostname</code> escaped it entirely</td>
      </tr>
      <tr>
          <td>the destination is a FILE</td>
          <td>a directory is served under <code>/tree/</code>, so <code>/blob/&lt;dir&gt;</code> 404s forever</td>
      </tr>
      <tr>
          <td>the destination is TRACKED</td>
          <td>a gitignored artefact never reaches the default branch</td>
      </tr>
  </tbody>
</table>
<p>The base of the path join is <code>rev-parse --show-toplevel</code>, not the scanned directory: scanning a
subdirectory is supported, and there <code>&lt;path&gt;</code> (repo-relative) compared against the wrong tree.
Percent-encoded paths are decoded, so the rung is not silently inert on <code>%2B</code> and <code>%20</code>.</p>
<p>Unknown origin, non-GitHub remote or unknown default branch -&gt; the rung is <strong>inert</strong> and behaviour
is exactly as before. A rung that changed behaviour when it could not identify the repo would be
worse than no rung.</p>
<p>⚠️ <strong>Consumers pin by SHA</strong>, so merging this changes nothing for them until each <code>darnlink-gate.json</code>
<code>ref</code> is bumped.</p>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>Feature 017 — the read axis can see a diagram&rsquo;s <code>click</code> destinations</strong> (<code>--include-mermaid</code>,
recipe key <code>include_mermaid</code>). <strong>Off by default, per repository.</strong> A <code>mermaid</code> diagram carries
its links in <code>click</code> directives, which live inside a fenced block: feature 002 hides them from
every axis, including the read-only ones, so they die silently when a file moves and no gate ever
notices. Measured on a real tree, one folder reorganisation killed 14 of a diagram&rsquo;s destinations
at once while everything stayed green.</p>
<ul>
<li><strong>The write operations are unchanged.</strong> FR-015 is not amended: repair and robustify still
ignore every link inside every fence. This is the read axis only.</li>
<li><strong>These links are never anchored</strong> — they are report-only. The anchor is a trailing HTML
comment, and a diagram treats that as a node rather than a comment, so writing one would
corrupt the drawing. A diagram destination that stays plain forever is a normal state.</li>
<li><strong>No new dependency.</strong> The destination grammar was measured over 2,165 real directives and
reduces to three single-line shapes, so it is recognised by a pure textual function; the
fenced-region computation is reused rather than reimplemented.</li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/cowork-harness/</link><pubDate>Fri, 28 Aug 2026 09:14:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v2.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is an unofficial test harness designed to emulate Claude Cowork’s observable runtime contract. It allows developers to script and automate the testing of skills across various scenarios in a headless, CI-friendly environment. The action supports multiple fidelity levels (e.g., replay, full) to capture detailed information about what the agent did, not just its behavior. This helps ensure that skills work as expected within the constraints defined by Cowork’s runtime contract.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v2.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is an unofficial test harness designed to emulate Claude Cowork&rsquo;s observable runtime contract. It allows developers to script and automate the testing of skills across various scenarios in a headless, CI-friendly environment. The action supports multiple fidelity levels (e.g., replay, full) to capture detailed information about what the agent did, not just its behavior. This helps ensure that skills work as expected within the constraints defined by Cowork&rsquo;s runtime contract.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong><code>cowork-harness assertions --list</code> gains a &ldquo;Skill references (progressive disclosure)&rdquo; family</strong> for the
two new keys, so they are not appended to a flat dump nobody reads.</p>
</li>
<li>
<p><strong>A guard that a committed cassette&rsquo;s <code>tool_not_called</code> is actually violable by its own recording.</strong>
The tool surface at a tier is <strong>gate-conditional</strong>: at <code>container</code>, <code>mcp__workspace__web_fetch</code> is
offered only when <code>coworkWebFetchViaApi</code> is on (17 of 138 measured container runs), and with the gate
off <code>WebFetch</code> is offered instead. <code>examples/replays/example-pdf-skill.cassette.json</code> asserts
<code>tool_not_called: &quot;mcp__workspace__web_fetch&quot;</code> and passes today only because it was recorded gate-ON —
a re-record with the gate off would leave it naming a tool the run could never have called, so it would
keep passing while verifying nothing, and nothing in the suite would notice. <code>verify-cassettes</code>&rsquo;s
<code>replaced-builtin</code> note keys on the recorded <em>inventory</em>, never on the assertions, and only covers
built-ins being replaced, never the inverse.</p>
<p>The guard checks every committed cassette&rsquo;s <code>tool_called</code>/<code>tool_not_called</code> against that cassette&rsquo;s own
frozen init inventory, through the same glob engine the evaluator uses. It deliberately does <strong>not</strong>
cover <code>subagent_tool_absent</code> (judged against the per-dispatch <code>declaredTools</code>, a different inventory)
and cannot see alias-class vacuity (<code>tool_not_called: &quot;Task&quot;</code> names a tool that is in every inventory
yet never emitted — the agent binary canonicalizes <code>Task</code> to <code>Agent</code>); both are recorded as separate
work rather than left implied.</p>
</li>
<li>
<p><strong><code>referencesAccessed</code> — reference access through EVERY tool channel, not just the <code>Read</code> tool.</strong>
<code>referencesRead</code> counts one channel, and <code>critique</code>&rsquo;s headline invited a reader to conclude the agent
had opened no reference — a claim about <em>reading</em> that a one-channel count cannot support. An agent
that <code>cat</code>s, <code>grep</code>s or globs a reference has reached it just as much. The new <code>RunResult</code> field (and
its <code>subagents[]</code> twin) records each file with the channel(s) it was reached through: <code>read</code>
(<code>Read.file_path</code>), <code>grep</code> (its <code>path</code> input), and <code>bash</code> (a <code>Bash</code>/<code>mcp__workspace__bash</code>
command naming the path).</p>
<p>All four channels apply the <strong>same</strong> <code>skillReferenceReadPath()</code> predicate, so a token only counts when
it is rooted in the mounted plugin — the agent&rsquo;s own <code>node scripts/build.js</code> is not a skill-script
access, and a non-skill filename never reaches <code>result.json</code> under a field claiming it is skill
content. Redirection targets and every argument of a write verb (<code>rm</code>/<code>mv</code>/<code>mkdir</code>/<code>touch</code>/<code>chmod</code>/<code>tee</code>) is excluded, as is a verb that only inspects metadata (<code>ls</code>/<code>test</code>/<code>stat</code>/<code>echo</code>): those are files the command
wrote or destroyed.</p>
<p>It <strong>deliberately under-approximates</strong>. A <code>cd</code> into the skill dir followed by a bare
<code>cat references/x.md</code>, a heredoc body and a <code>$VAR</code>-built path are all invisible, and there are tests
pinning them as misses so a later widening is a visible change rather than a silent one.</p>
<p><strong>Presence is the cannot-verify channel</strong>, which is the one way it differs from <code>referencesRead</code>:
<code>[]</code> means the drive ran and observed nothing (a real negative); <strong>absent</strong> means there was no
observable drive, and must never be read as &ldquo;none&rdquo;. Present on live <em>and</em> replay — cassettes freeze
whole tool inputs, so the replay re-drive reconstructs every channel identically.</p>
<p><code>referencesRead</code> is unchanged in meaning and is now documented as this field&rsquo;s <code>read</code>-channel
projection, produced by the same capture so the two cannot disagree.</p>
<p>Scope is <strong>main agent ∪ sub-agents</strong>, via a single <code>unionReferenceAccesses()</code> derivation shared by the
assertion keys, the critique report and <code>--probe dispatch</code> — a dispatcher-shaped skill does all its
reading a level down, so judging the top-level list alone would report &ldquo;never reached&rdquo; on a run where a
sub-agent read the file cover to cover. A <strong>truncated cassette</strong> (one that could never be driven)
reports cannot-verify rather than an empty list, for the same reason.</p>
</li>
<li>
<p><strong><code>reference_read</code> / <code>no_observed_reference_access</code> assertion keys.</strong> Gate on whether a skill&rsquo;s
progressive disclosure actually works: a well-partitioned skill and one whose second half is dead look
identical from outside. Regex (unanchored, case-insensitive — the same shared helper every regex key
uses), main agent ∪ sub-agents, evaluated on replay as well as live.</p>
<p>The negative key is named <code>no_observed_reference_access</code>, not <code>no_reference_read</code>, because the
detector under-approximates by design: it proves nothing was <em>seen</em>, not that the file went unread.
Both keys <strong>fail evidence-unavailable</strong> when the run recorded no observable access list — including
the negative one, which is the direction that would otherwise pass vacuously off a missing field. The
scenario linter rejects asserting both with the same pattern.</p>
</li>
<li>
<p><strong><code>critique</code> names why the GRADED turn errored</strong> — <code>gradedErrorReason</code> in the JSON report and inline in
the text NOTE. <code>taskResult: &quot;error&quot;</code> is a legitimate <strong>gradeable</strong> outcome and the critique still runs,
but the report said only &ldquo;the task run ended in error&rdquo;, so an exhausted quota or a dropped connection
read as a defect in the skill under review.</p>
</li>
<li>
<p><strong><code>critique</code> reports which model produced the GRADED run</strong> — <code>gradedModels</code> in the JSON report and
<code>graded model(s):</code> in the text header, read back from the graded turn&rsquo;s own <code>result.json</code> and filtered
of the agent&rsquo;s locally-fabricated <code>&lt;synthetic&gt;</code> entries. The report named the <em>evaluator&rsquo;s</em> resolved
model and no other, so the model that produced the behaviour being graded appeared nowhere. It cannot
be inferred from context either: the turns are a subprocess that inherits no model from whatever
invoked <code>critique</code>, so an omitted <code>--model</code> silently grades whatever the spawned agent defaults to. A
run with nothing recorded now says <code>graded model(s): unknown</code> rather than staying silent. The ids are
<strong>observed, not requested</strong> — read from the model stamped on the graded turn&rsquo;s assistant messages, not
from the flag.</p>
</li>
<li>
<p><code>isLiveModelId</code> (<code>src/types.ts</code>) — the agent-marker filter every consumer of <code>RunResult.models</code> must
apply, now declared once beside the field it governs. It replaces <strong>three</strong> divergent copies, two of
which disagreed: <code>src/run/provenance.ts</code> (which renders <code>provenance.model</code> on every JSON envelope)
matched the angle-bracket <strong>shape</strong>, <code>scripts/eval-gate.ts</code> the <code>&lt;</code> <strong>prefix</strong> — so a malformed or
truncated marker such as <code>&quot;&lt;synthetic&quot;</code> was dropped by one and rendered as if it were a model id by the
other. The shared rule is the shape.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><strong>Skill and docs updated for the tier refusal.</strong> <code>SKILL.md</code> previously told authors a tier-mismatched
<code>tool_not_called</code> &ldquo;can silently void a web-fetch assertion&rdquo; when moving a scenario between tiers — the
harness now refuses it at load instead, so that guidance described behaviour that no longer exists. The
skill&rsquo;s critique reference gains the <code>referencesAccessed</code> field, its channels, and the
<code>[]</code>-vs-absent cannot-verify rule.</p>
</li>
<li>
<p><strong><code>subagent_declared_but_unused</code> documents that it fires only on a dispatch that declares a tool list.</strong>
It reads <code>subagents[].declaredTools</code>, populated from a <code>tools</code>/<code>allowedTools</code> key in the dispatch input.
The <code>Agent</code> tool carries neither, so that list is empty and the key passes on every such dispatch —
<strong>0 of 1091 real dispatches</strong> carry a non-empty list. The key is not wrong, but a green means &ldquo;not
applicable here&rdquo;, never &ldquo;no fabrication&rdquo;, and neither its description nor its docs said so.</p>
</li>
<li>
<p><strong>BEHAVIOUR CHANGE: <code>tool_not_called</code> and <code>subagent_tool_absent</code> naming a tool the tier does not serve
are now REFUSED at scenario load.</strong> <code>tool_not_called: &quot;Bash&quot;</code> at <code>hostloop</code> passed vacuously, always — that tier disallows the
built-in shell and aliases it to <code>mcp__workspace__bash</code>, so the run could never have called <code>Bash</code>
whatever the agent did. The assertion read as a guarantee and verified nothing. The inverse was equally
broken: <code>mcp__workspace__bash</code> at <code>container</code>, where the built-in is served instead.</p>
<p>The refusal is a <code>UsageError</code> at the point the tier resolves — after <code>fidelity: cowork</code> becomes a real
tier, and before any staging, image pull or spawn, so no model spend is wasted. The message names the
tool to assert instead, and names the sibling keys that behave differently (<code>tool_called</code> still fails
normally; <code>subagent_tool_absent</code> is judged against a per-dispatch inventory this check cannot
determine). <code>scenario.py lint</code> WARNs on the same set, before any run at all.</p>
<p><strong>The table is closed to tools the harness itself removes or registers</strong>, and never derived from the
launch plan. <code>--tools</code> gates the built-in set alone — the agent binary&rsquo;s own help says so — while every
sandbox tier separately passes <code>--mcp-config</code>. A launch-set-derived check would therefore have rejected
<code>tool_not_called: &quot;mcp__example-fs__write_file&quot;</code> for a session using the <code>mcp.config</code> this repo ships an
example of, while that tool was registered and callable. Globs are never refused, and the table
under-approximates on purpose: <code>REPL</code> at hostloop is vacuous too and is not caught, which is the correct
side to err on when the verdict is a hard refusal.</p>
<p>There is <strong>no opt-out</strong>, deliberately. The repo&rsquo;s <code>allow_*</code> modifiers all cover cases where the harness
might be wrong about a real signal; a fired reject here cannot be a false positive, so there is no
legitimate scenario to rescue. If one is ever found, the table is wrong and the table should change.</p>
<p><strong><code>subagent_tool_absent</code> is covered for the same reason <code>tool_not_called</code> is.</strong> It reads the tools
sub-agents actually USED, not a per-dispatch declared list, so a tool the tier never serves makes it
vacuous in exactly the same way — corroborated by the run population, where sub-agent <code>Bash</code> calls
appear 20 times, all at <code>container</code> and never at <code>hostloop</code>. Covering one key and not the other would
refuse an assertion at hostloop while silently greening the sub-agent form of the identical claim.</p>
<p><code>e2e/scenarios/canary-hostloop.yaml</code> carried exactly this defect and is fixed in the same change: its
<code>tool_not_called: Bash</code> never proved anything, and its <code>tool_called: mcp__workspace__*</code> already carries
the canary&rsquo;s stated purpose.</p>
</li>
<li>
<p><strong><code>critique</code>&rsquo;s &ldquo;no references were Read&rdquo; headline now says what it observed.</strong> It reads the wide
signal, names the channels it looked through, and states its own under-approximation in one short
clause instead of the load-bearing caveat that did all the work. Where the run recorded no observable
tool stream it makes <strong>no claim</strong> rather than rendering a clean negative. The evaluator&rsquo;s evidence
section moves with it (previously main-agent <code>Read</code>s only — a different population from the headline&rsquo;s,
so widening one without the other would have handed the evaluator a prompt contradicting the report),
and the grading prompt now tells the evaluator not to issue a finding whose only support is a path
missing from that list. <code>--probe dispatch</code> prints the wide list too.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong><code>tool_called: &quot;Task&quot;</code> could never pass and <code>tool_not_called: &quot;Task&quot;</code> always did.</strong> The agent binary
canonicalizes a set of legacy tool names — <code>Task</code>→<code>Agent</code>, <code>KillShell</code>/<code>KillBash</code>→<code>TaskStop</code>, and nine
more — while the spawn tool list still declares the <strong>legacy</strong> spelling. So the init inventory echoes
back <code>Task</code>, every actual dispatch is emitted as <code>Agent</code>, and a literal matcher could never connect the
two. Measured across 506 kept runs: <code>Task</code> offered <strong>506</strong> times and called <strong>0</strong>; <code>Agent</code> called <strong>188</strong>
times and offered <strong>0</strong>. The negative form was a permanent vacuous pass in the most common dispatch
assertion there is, at every tier.</p>
<p>All four tool keys (<code>tool_called</code>, <code>tool_not_called</code>, <code>subagent_tool_used</code>, <code>subagent_tool_absent</code>) now
match either spelling, through the one shared matcher. Globs see both too — the <strong>recorded name</strong> is
expanded rather than the author&rsquo;s pattern, so <code>tool_not_called: &quot;Ta*&quot;</code> and <code>&quot;*&quot;</code> are violated by a
recorded <code>Agent</code>, which rewriting the pattern would not have fixed.</p>
<p>Recorded data is unchanged: <code>toolCounts</code>, <code>context.tools</code> and every cassette keep exactly what the agent
reported, the same verbatim posture <code>RunResult.models</code> documents. Only matching is alias-aware, so
<code>tool_available: &quot;Task&quot;</code> still matches the inventory&rsquo;s literal <code>Task</code> and no committed cassette changes
meaning.</p>
<p><strong>Still vacuous, and now documented as such:</strong> <code>tool_not_called</code> on a tool the <em>tier</em> never offers —
<code>Bash</code> at <code>hostloop</code>, or <code>mcp__workspace__bash</code> at <code>container</code>. That is a separate class with a separate
fix; the key&rsquo;s docs and the skill reference now warn about it rather than leaving it implied.</p>
</li>
<li>
<p><strong><code>critique</code> diagnosed an unanswered gate as an infrastructure failure, and named the wrong turn while
doing it.</strong> A graded run that stopped at an <code>AskUserQuestion</code> gate with no scripted answer exits 2 with
a fully-formed <code>{ok:false, error:{category:&quot;unanswered&quot;, …}}</code> envelope, but the report read only
<code>results[0].outDir</code> and answered <em>&ldquo;task turn exited nonzero without a parseable result envelope — it
crashed before completing a gradeable task&rdquo;</em> — under a header hardcoded to
<code>INFRASTRUCTURE/PROTOCOL FAILURE (reflection turn)</code>, though it was the <strong>task</strong> turn that stopped and
no reflection turn had been attempted. Both halves pointed at the wrong subsystem: a reader following
the report would audit Docker and the staged agent over what is one scenario flag.</p>
<p>The report now prefers the failed turn&rsquo;s own diagnosis, on both turns, carrying its message <strong>and hint
verbatim</strong> (and only once — <code>UnansweredError</code>&rsquo;s message already contains its hint, so appending it
unconditionally printed the whole question, its options and its remedy tip twice). No remedy text is
synthesized on top: there are 36 <code>UnansweredError</code> sites and only one is &ldquo;the skill asked an unscripted
question&rdquo;, so advice keyed on the category is wrong for nearly all of them.</p>
<p>Two new fields carry the classification — <code>infraFailurePhase</code> (<code>task turn</code> | <code>reflection turn</code>) and
<code>infraFailureKind</code> (the harness <code>ErrCategory</code>). The header keys on <strong>which</strong> category, not on merely
having one: <code>unanswered</code> / <code>usage</code> / <code>boundary</code> render as <code>RUN FAILED (&lt;turn&gt;, &lt;kind&gt;)</code>; everything
else renders as <code>INFRASTRUCTURE/PROTOCOL FAILURE (&lt;turn&gt;)</code> and it <strong>fails closed</strong> — <code>internal</code> is the
CLI&rsquo;s catch-all for any unexpected throw (Docker down, container start failure, missing staged agent, a
harness bug), so an unrecognized category is treated as an instrument failure rather than assumed
ordinary.</p>
</li>
<li>
<p><strong>A turn that exited 1 was reported as a bare exit code, so an exhausted quota looked like a crash.</strong>
A turn that RAN and errored exits <code>1</code> with a full result envelope whose top-level <code>error</code> is <code>null</code> —
its cause lives in <code>results[0]</code>, not in an error object. Reading only the error object left the report
saying <code>reflection turn exited with code 1 (expected 0)</code> and nothing more, for a run whose actual cause
was an exhausted seven-day quota; it was findable only by opening <code>events.jsonl</code> by hand. The failed
turn&rsquo;s <code>resultErrorKind</code> / <code>errorSource</code> / <code>resultSubtype</code> are now read and rendered — <code>usage_limit</code>
as &ldquo;the account&rsquo;s quota is exhausted; retry after the reset. This is NOT a harness or skill defect&rdquo;,
<code>transport</code> as a retryable tail-end drop — matching how the run renderer has always shown them.
<code>usage_limit</code> and <code>transport</code> join the ordinary/actionable set; <code>agent</code> does not, because for
critique&rsquo;s own protocol turn an agent-level failure <em>is</em> the instrument breaking.</p>
</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 2.5.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/161">https://github.com/yaniv-golan/cowork-harness/pull/161</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v2.4.0...v2.5.0">https://github.com/yaniv-golan/cowork-harness/compare/v2.4.0...v2.5.0</a></p>
]]></content:encoded></item><item><title>Zenifra Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/zenifra-deploy/</link><pubDate>Fri, 28 Aug 2026 09:13:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/zenifra-deploy/</guid><description>Version updated for https://github.com/zenifra/action-zenifra-deploy to version v0.0.5.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action deploys images to Zenifra and can manage temporary preview environments for pull requests. It supports deploying a main project image, managing preview environments with stable keys, URLs, expirations, and idempotent deletion. The action is secure by using the API key only through GitHub secrets and respects different deployment actions such as auto-upsert or delete based on inputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zenifra/action-zenifra-deploy">https://github.com/zenifra/action-zenifra-deploy</a></strong> to version <strong>v0.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zenifra-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action deploys images to <a href="https://www.zenifra.com">Zenifra</a> and can manage temporary preview environments for pull requests. It supports deploying a main project image, managing preview environments with stable keys, URLs, expirations, and idempotent deletion. The action is secure by using the API key only through GitHub secrets and respects different deployment actions such as auto-upsert or delete based on inputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Feat/preview environments by @ramonpaolo in <a href="https://github.com/zenifra/action-zenifra-deploy/pull/7">https://github.com/zenifra/action-zenifra-deploy/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/zenifra/action-zenifra-deploy/compare/v0.0.4...v0.0.5">https://github.com/zenifra/action-zenifra-deploy/compare/v0.0.4...v0.0.5</a></p>
]]></content:encoded></item><item><title>Mount ISO</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/mount-iso/</link><pubDate>Fri, 28 Aug 2026 02:05:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/mount-iso/</guid><description>Version updated for https://github.com/linxDynW/mount-iso to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action linxDynW/mount-iso automates the process of mounting an ISO image to a specific drive letter and/or folder on Windows. It addresses common issues with identifying the correct volume after mounting, provides failure-proofing features such as atomicity, precondition checks, post checks, and race-free identity verification, and requires Admin privileges and PowerShell 7+ for execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/linxDynW/mount-iso">https://github.com/linxDynW/mount-iso</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mount-iso">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>linxDynW/mount-iso</code> automates the process of mounting an ISO image to a specific drive letter and/or folder on Windows. It addresses common issues with identifying the correct volume after mounting, provides failure-proofing features such as atomicity, precondition checks, post checks, and race-free identity verification, and requires Admin privileges and PowerShell 7+ for execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Failure-proof ISO mounting for Windows CI (drive letter and/or folder).</p>
<p>see README for details.</p>
<p>Usage: <code>uses: linxDynW/mount-iso@v1</code></p>
]]></content:encoded></item><item><title>Next.js Turbopack Bundle Size</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/next.js-turbopack-bundle-size/</link><pubDate>Fri, 28 Aug 2026 02:04:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/next.js-turbopack-bundle-size/</guid><description>Version updated for https://github.com/michalsanger/nextjs-turbopack-bundle-size to version v1.10.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action analyzes Next.js App Router bundle sizes across pull requests and posts a route-by-route size comparison comment on every PR. It tracks baseline stats for each branch, allowing users to identify changes in bundle sizes and determine if they exceed certain budget thresholds. The action is designed to help developers monitor the performance of their applications over time and ensure that size optimizations are effective.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/michalsanger/nextjs-turbopack-bundle-size">https://github.com/michalsanger/nextjs-turbopack-bundle-size</a></strong> to version <strong>v1.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/next-js-turbopack-bundle-size">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action analyzes Next.js App Router bundle sizes across pull requests and posts a route-by-route size comparison comment on every PR. It tracks baseline stats for each branch, allowing users to identify changes in bundle sizes and determine if they exceed certain budget thresholds. The action is designed to help developers monitor the performance of their applications over time and ensure that size optimizations are effective.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: resolve baseline by base-branch tip SHA instead of the stale branch-indexed run list by @michalsanger in <a href="https://github.com/michalsanger/nextjs-turbopack-bundle-size/pull/48">https://github.com/michalsanger/nextjs-turbopack-bundle-size/pull/48</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/michalsanger/nextjs-turbopack-bundle-size/compare/v1.9.0...v1.10.0">https://github.com/michalsanger/nextjs-turbopack-bundle-size/compare/v1.9.0...v1.10.0</a></p>
]]></content:encoded></item><item><title>postmortem supply-chain gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/postmortem-supply-chain-gate/</link><pubDate>Fri, 28 Aug 2026 02:03:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/postmortem-supply-chain-gate/</guid><description>Version updated for https://github.com/mlab-sh/postmortem to version v2.3.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary postmortem is an all-in-one supply-chain security scanner for modern software projects that inspects dependencies across multiple ecosystems and flags potential compromises like malicious install scripts, typosquats, and compromised maintainers. It provides reputation intelligence, audit your machine, and deep source inspection, all while ensuring no telemetry or network communication unless explicitly requested.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mlab-sh/postmortem">https://github.com/mlab-sh/postmortem</a></strong> to version <strong>v2.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postmortem-supply-chain-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>postmortem is an all-in-one supply-chain security scanner for modern software projects that inspects dependencies across multiple ecosystems and flags potential compromises like malicious install scripts, typosquats, and compromised maintainers. It provides reputation intelligence, audit your machine, and deep source inspection, all while ensuring no telemetry or network communication unless explicitly requested.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mlab-sh/postmortem/compare/v2.3.0...v2.3.1">https://github.com/mlab-sh/postmortem/compare/v2.3.0...v2.3.1</a></p>
]]></content:encoded></item><item><title>Disensor Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/disensor-gate/</link><pubDate>Fri, 28 Aug 2026 02:02:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/disensor-gate/</guid><description>Version updated for https://github.com/NicolasRocchia/disensor to version v0.9.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates adversarial plan and code review with residue declaration. It uses a controlled disagreement method to validate and close reviews automatically with CI gates, ensuring each finding is resolved, refuted with evidence, or escalated to human judgment. The action records how each event ends, including findings’ terminal states and residue, which aims at human reviewer scrutiny instead of quality seals.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NicolasRocchia/disensor">https://github.com/NicolasRocchia/disensor</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/disensor-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates adversarial plan and code review with residue declaration. It uses a controlled disagreement method to validate and close reviews automatically with CI gates, ensuring each finding is resolved, refuted with evidence, or escalated to human judgment. The action records how each event ends, including findings&rsquo; terminal states and residue, which aims at human reviewer scrutiny instead of quality seals.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>La ronda orquestada: disensor arma el paquete, corre al revisor, mide el árbol y ancla el resultado. El usuario no copia y pega nada entre modelos. Cualquier CLI puede ser el revisor; residue/v0.4 declara la independencia y hace declarable el modo degradado.</p>
]]></content:encoded></item><item><title>XAI Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/xai-review/</link><pubDate>Fri, 28 Aug 2026 02:01:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/xai-review/</guid><description>Version updated for https://github.com/Nikita-Filonov/ai-review to version v0.77.0.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Review automates code review using AI-powered tools, providing inline comments, summaries, and AI-generated replies directly into merge requests. It supports multiple LLM providers, VCS integrations, customizable prompts, agent mode, and flexible configuration options. This helps teams improve code quality, enforce consistency, and speed up the review process while maintaining human oversight.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nikita-Filonov/ai-review">https://github.com/Nikita-Filonov/ai-review</a></strong> to version <strong>v0.77.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xai-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Review automates code review using AI-powered tools, providing inline comments, summaries, and AI-generated replies directly into merge requests. It supports multiple LLM providers, VCS integrations, customizable prompts, agent mode, and flexible configuration options. This helps teams improve code quality, enforce consistency, and speed up the review process while maintaining human oversight.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>version (e3e19d6)</li>
<li>agent (a57145e)</li>
<li>agent (78c1d98)</li>
<li>Merge pull request #122 from dansan/fix/agent-loop-unparseable-action (8a59015)</li>
<li>docs (0e34b81)</li>
<li>Merge pull request #124 from AlpayY/readme-fix-gitlab-ci-descriptions (d3616aa)</li>
<li>Fixed GitLab CI/CD deployment descriptions in README (ab9e4da)</li>
<li>fix(agent): never promote an unparseable action to the final review (be80d10)</li>
<li>openai (81a1242)</li>
<li>json (c9fabe9)</li>
</ul>
]]></content:encoded></item><item><title>Foundry Toolbox Radar</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/foundry-toolbox-radar/</link><pubDate>Fri, 28 Aug 2026 01:59:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/foundry-toolbox-radar/</guid><description>Version updated for https://github.com/nithin42/Foundry-Toolbox-Radar-Lab to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The foundry-toolbox-radar-lab GitHub Action is a zero-latency static analyzer that audits Microsoft Foundry Toolboxes before they are deployed. It detects potential security and operational risks related to ungated mutating actions, static credential creep, indirect prompt injection, prompt &amp;amp; context leakage, and scope inflation. The action provides a comprehensive governance defense engine for enterprise AI practitioners deploying autonomous agents on Foundry.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nithin42/Foundry-Toolbox-Radar-Lab">https://github.com/nithin42/Foundry-Toolbox-Radar-Lab</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/foundry-toolbox-radar">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>foundry-toolbox-radar-lab</code> GitHub Action is a zero-latency static analyzer that audits Microsoft Foundry Toolboxes before they are deployed. It detects potential security and operational risks related to ungated mutating actions, static credential creep, indirect prompt injection, prompt &amp; context leakage, and scope inflation. The action provides a comprehensive governance defense engine for enterprise AI practitioners deploying autonomous agents on Foundry.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="foundry-toolbox-radar-v020">Foundry Toolbox Radar v0.2.0</h3>
<p>Pre-deployment governance, identity auditing, prompt injection detection, and data-leakage scanner for Microsoft Foundry Toolboxes and autonomous AI agents.</p>
<h4 id="highlights">Highlights:</h4>
<ul>
<li><strong>7-Rule Governance Matrix</strong>: Aligned with the OWASP Top 10 for Large Language Models (LLM01, LLM02, LLM06, LLM07).</li>
<li><strong>Indirect Prompt Injection Detection (<code>RULE-07</code>)</strong>: Flags instruction overrides, role-hijacks, and exfiltration directives in tool metadata.</li>
<li><strong>Zero-Dependency CLI (<code>radar</code>)</strong>: Instant, offline static analysis with clean ASCII reports and machine-readable JSON gates.</li>
<li><strong>Composite GitHub Action</strong>: Seamless integration into automated pull request workflows.</li>
<li><strong>Pre-Commit Hook Support</strong>: Prevents insecure toolbox definitions from entering git history.</li>
</ul>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/run-aer-tests/</link><pubDate>Fri, 28 Aug 2026 01:58:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.40.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running Apex unit tests locally on developers’ machines without the need for an org or deployment. It supports all Salesforce Apex features including SOQL, DML, triggers, validation rules, and flows, with comprehensive governor limits enforcement. The action is particularly useful for rapid development feedback cycles and debugging.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.40</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running Apex unit tests locally on developers&rsquo; machines without the need for an org or deployment. It supports all Salesforce Apex features including SOQL, DML, triggers, validation rules, and flows, with comprehensive governor limits enforcement. The action is particularly useful for rapid development feedback cycles and debugging.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.40</p>
<ul>
<li>
<p>Enforce MIXED_DML_OPERATION And Gate User Inserts On Manage Users</p>
</li>
<li>
<p>Run Platform Event Subscribers With Their Own Mixed-DML State</p>
</li>
<li>
<p>Run Async Jobs With Their Own Mixed-DML State</p>
</li>
<li>
<p>Lift Manage Users Restrictions For Code Declared Without Sharing</p>
</li>
</ul>
]]></content:encoded></item><item><title>Initialize GitHub Job</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/initialize-github-job/</link><pubDate>Fri, 28 Aug 2026 01:57:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/initialize-github-job/</guid><description>Version updated for https://github.com/PandasWhoCode/initialize-github-job to version v1.4.0.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Initialize GitHub Job composite action automates the setup steps for initializing a job in GitHub Actions, including security hardening, repository checkout, and multi-language support. It provides features like Node.js, Java, Python, Go, Rust, Swift, build tool setup (Gradle, Task, gomplate, jq, kubectl, Teleport), and automatic caching for dependencies and build artifacts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PandasWhoCode/initialize-github-job">https://github.com/PandasWhoCode/initialize-github-job</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/initialize-github-job">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Initialize GitHub Job composite action automates the setup steps for initializing a job in GitHub Actions, including security hardening, repository checkout, and multi-language support. It provides features like Node.js, Java, Python, Go, Rust, Swift, build tool setup (Gradle, Task, gomplate, jq, kubectl, Teleport), and automatic caching for dependencies and build artifacts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): Bump step-security/harden-runner from 2.20.0 to 2.20.1 by @dependabot[bot] in <a href="https://github.com/PandasWhoCode/initialize-github-job/pull/98">https://github.com/PandasWhoCode/initialize-github-job/pull/98</a></li>
<li>chore(deps): Bump go-task/setup-task from 2.1.0 to 2.2.0 by @dependabot[bot] in <a href="https://github.com/PandasWhoCode/initialize-github-job/pull/99">https://github.com/PandasWhoCode/initialize-github-job/pull/99</a></li>
<li>chore(deps): Bump testlens-app/setup-testlens from 1.9.3 to 1.9.4 by @dependabot[bot] in <a href="https://github.com/PandasWhoCode/initialize-github-job/pull/100">https://github.com/PandasWhoCode/initialize-github-job/pull/100</a></li>
<li>chore(deps): Bump gradle/actions/setup-gradle from 6.2.0 to 6.3.0 by @dependabot[bot] in <a href="https://github.com/PandasWhoCode/initialize-github-job/pull/101">https://github.com/PandasWhoCode/initialize-github-job/pull/101</a></li>
<li>chore(deps): Bump actions/setup-java from 5.6.0 to 5.7.0 by @dependabot[bot] in <a href="https://github.com/PandasWhoCode/initialize-github-job/pull/102">https://github.com/PandasWhoCode/initialize-github-job/pull/102</a></li>
<li>feat: add kubectl support by @andrewb1269 in <a href="https://github.com/PandasWhoCode/initialize-github-job/pull/105">https://github.com/PandasWhoCode/initialize-github-job/pull/105</a></li>
<li>feat: add teleport client support by @andrewb1269 in <a href="https://github.com/PandasWhoCode/initialize-github-job/pull/106">https://github.com/PandasWhoCode/initialize-github-job/pull/106</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/PandasWhoCode/initialize-github-job/compare/v1.3.1...v1.4.0">https://github.com/PandasWhoCode/initialize-github-job/compare/v1.3.1...v1.4.0</a></p>
]]></content:encoded></item><item><title>MegaLinter Custom Flavor PracticalliZensical</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/megalinter-custom-flavor-practicallizensical/</link><pubDate>Fri, 28 Aug 2026 01:56:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/megalinter-custom-flavor-practicallizensical/</guid><description>Version updated for https://github.com/practicalli/megalinter-custom-flavor-zensical to version v10.0.0-beta.
This action is used across all versions by 12 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action customizes the official MegaLinter image to include only specific linters and reduces its Docker image size. It automates the process of checking for new MegaLinter releases, building a customized Docker image with selected linters, and optionally publishing it to both GitHub Container Registry and Docker Hub.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/practicalli/megalinter-custom-flavor-zensical">https://github.com/practicalli/megalinter-custom-flavor-zensical</a></strong> to version <strong>v10.0.0-beta</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>12</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/megalinter-custom-flavor-practicallizensical">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action customizes the official MegaLinter image to include only specific linters and reduces its Docker image size. It automates the process of checking for new MegaLinter releases, building a customized Docker image with selected linters, and optionally publishing it to both GitHub Container Registry and Docker Hub.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>build(make): 🔧 common practicalli tasks for projects (fb97086)</li>
<li>ci(github): 🔧 update actions to latest versions using <code>make dependencies-update</code> (b3a34b2)</li>
<li>style: delete blank spaces in GitHub workflow config (332a09d)</li>
<li>ci(megalinter): schedule version check on 1st day of month (34e97d8)</li>
<li>release(action): latest release of zensical megalinter custom flavor (f3c789b)</li>
<li>dev: install custom flavor of megalinter for zensical projects (e4fe720)</li>
<li>Initial commit (a92cd50)</li>
</ul>
]]></content:encoded></item><item><title>PyGo CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/pygo-cli/</link><pubDate>Fri, 28 Aug 2026 01:55:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/pygo-cli/</guid><description>Version updated for https://github.com/PyGo-Labs/pygo-framework to version v2.2.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a framework for building web applications using Go for the backend and Python for the domain layer. It uses UDS+MessagePack for communication between components, with support for Hot Reload in development mode. The action provides a modular structure, includes various modules like authentication, internationalization, admin panel, and notifications, and supports automated updates via GitHub Releases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PyGo-Labs/pygo-framework">https://github.com/PyGo-Labs/pygo-framework</a></strong> to version <strong>v2.2.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pygo-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a framework for building web applications using Go for the backend and Python for the domain layer. It uses UDS+MessagePack for communication between components, with support for Hot Reload in development mode. The action provides a modular structure, includes various modules like authentication, internationalization, admin panel, and notifications, and supports automated updates via GitHub Releases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore: version interna 2.2.4 (coherente con tag) despues de fix de checksum (5a178e4)</li>
<li>ci: checksums.txt con nombres sin prefijo dist/ para verificacion portatil (5061dfa)</li>
<li>ci: release en un solo job - builda 5 binarios + checksums.txt y sube todo junto (8f06be0)</li>
<li>ci: release workflow con Go 1.26.6 + checksums.txt (cce5aed)</li>
<li>fix(cli): instalacion/upgrade robusta - binario crudo + checksum (cd65d6e)</li>
<li>docs: actualizar a v2.2.1 - eliminar rastros v1/DSL y corregir roadmap (c9082ba)</li>
<li>fix: reparar build roto y tests - unificar module path a &lsquo;pygo-framework&rsquo; (f1b4a56)</li>
<li>v2.2.0: transport layer abstraction - UDS+MessagePack default, gRPC opt-in (cedcece)</li>
<li>docs: update README.md to v2.1.0 modular architecture and full CLI (274d92a)</li>
<li>fix(cli): bump version strings to v2.1.0-native in version, info, main (cd27067)</li>
</ul>
]]></content:encoded></item><item><title>Kubernetes in Docker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/kubernetes-in-docker/</link><pubDate>Fri, 28 Aug 2026 01:54:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/kubernetes-in-docker/</guid><description>Version updated for https://github.com/reconcilerio/kind to version v1.0.8.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action starts a secure, trusted OCI registry for a GitHub Actions workflow. It automates the setup of a Kubernetes cluster using Kind, ensuring no need to manually manage certificates or insecure configurations. The action provides various options to customize the cluster and registry settings, making it easy to integrate into CI/CD pipelines securely.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/reconcilerio/kind">https://github.com/reconcilerio/kind</a></strong> to version <strong>v1.0.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kubernetes-in-docker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action starts a secure, trusted OCI registry for a GitHub Actions workflow. It automates the setup of a Kubernetes cluster using Kind, ensuring no need to manually manage certificates or insecure configurations. The action provides various options to customize the cluster and registry settings, making it easy to integrate into CI/CD pipelines securely.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Default versions:</p>
<ul>
<li>kubernetes: v1.37.0</li>
<li>kind: v0.33.0</li>
<li>cloud-provider-kind: v0.11.1</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Track Kubernetes 1.38 development by @scothis in <a href="https://github.com/reconcilerio/kind/pull/59">https://github.com/reconcilerio/kind/pull/59</a></li>
<li>Bump k8s.io/kubectl from 0.37.0-beta.0 to 0.37.0-rc.0 in /versions/kubernetes/v1.37 by @dependabot[bot] in <a href="https://github.com/reconcilerio/kind/pull/60">https://github.com/reconcilerio/kind/pull/60</a></li>
<li>Bump k8s.io/kubectl from 0.36.3 to 0.36.4 in /versions/kubernetes/v1.36 by @dependabot[bot] in <a href="https://github.com/reconcilerio/kind/pull/63">https://github.com/reconcilerio/kind/pull/63</a></li>
<li>Bump k8s.io/kubectl from 0.37.0-rc.0 to 0.37.0-rc.1 in /versions/kubernetes/v1.37 by @dependabot[bot] in <a href="https://github.com/reconcilerio/kind/pull/61">https://github.com/reconcilerio/kind/pull/61</a></li>
<li>Bump k8s.io/kubectl from 0.36.3 to 0.36.4 in /versions/kubernetes/default by @dependabot[bot] in <a href="https://github.com/reconcilerio/kind/pull/62">https://github.com/reconcilerio/kind/pull/62</a></li>
<li>Bump k8s.io/kubectl from 0.35.7 to 0.35.8 in /versions/kubernetes/v1.35 by @dependabot[bot] in <a href="https://github.com/reconcilerio/kind/pull/65">https://github.com/reconcilerio/kind/pull/65</a></li>
<li>Bump k8s.io/kubectl from 0.34.10 to 0.34.11 in /versions/kubernetes/v1.34 by @dependabot[bot] in <a href="https://github.com/reconcilerio/kind/pull/64">https://github.com/reconcilerio/kind/pull/64</a></li>
<li>Bump k8s.io/kubectl from 0.37.0-rc.1 to 0.37.0 in /versions/kubernetes/v1.37 by @dependabot[bot] in <a href="https://github.com/reconcilerio/kind/pull/66">https://github.com/reconcilerio/kind/pull/66</a></li>
<li>Bump k8s.io/kubectl from 0.36.4 to 0.37.0 in /versions/kubernetes/default by @dependabot[bot] in <a href="https://github.com/reconcilerio/kind/pull/67">https://github.com/reconcilerio/kind/pull/67</a></li>
<li>Bump sigs.k8s.io/kind from 0.32.0 to 0.33.0 in /versions/kind by @dependabot[bot] in <a href="https://github.com/reconcilerio/kind/pull/68">https://github.com/reconcilerio/kind/pull/68</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/reconcilerio/kind/compare/v1.0.7...v1.0.8">https://github.com/reconcilerio/kind/compare/v1.0.7...v1.0.8</a></p>
]]></content:encoded></item><item><title>setup-maestro-cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/setup-maestro-cli/</link><pubDate>Fri, 28 Aug 2026 01:53:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/setup-maestro-cli/</guid><description>Version updated for https://github.com/remarkablemark/setup-maestro-cli to version v1.0.21.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-maestro-cli GitHub Action automates the installation and configuration of Maestro, a mobile testing tool for Android. It provides a quick start guide and usage instructions to set up GitHub Actions with Maestro CLI, allowing users to run Maestro commands in their workflows. The action allows specifying a version of Maestro, defaulting to 2.9.0 if not provided.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablemark/setup-maestro-cli">https://github.com/remarkablemark/setup-maestro-cli</a></strong> to version <strong>v1.0.21</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-maestro-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The setup-maestro-cli GitHub Action automates the installation and configuration of Maestro, a mobile testing tool for Android. It provides a quick start guide and usage instructions to set up GitHub Actions with Maestro CLI, allowing users to run Maestro commands in their workflows. The action allows specifying a version of Maestro, defaulting to 2.9.0 if not provided.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1021-2026-08-27"><a href="https://github.com/remarkablemark/setup-maestro-cli/compare/v1.0.20...v1.0.21">1.0.21</a> (2026-08-27)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump maestro from 2.8.0 to 2.9.0 (<a href="https://github.com/remarkablemark/setup-maestro-cli/issues/286">#286</a>) (<a href="https://github.com/remarkablemark/setup-maestro-cli/commit/0205438366779883347cc34e707c8d95ea8a07b1">0205438</a>)</li>
</ul>
]]></content:encoded></item><item><title>setup-openapi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/setup-openapi/</link><pubDate>Fri, 28 Aug 2026 01:52:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/setup-openapi/</guid><description>Version updated for https://github.com/remarkablemark/setup-openapi to version v1.1.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs the OpenAPI Generator CLI tool and caches it by version, making it easy to automate API client generation tasks in GitHub Actions workflows. It supports generating clients for various languages such as Ruby, Python, Java, etc., and provides options to specify the version and binary name of the tool.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablemark/setup-openapi">https://github.com/remarkablemark/setup-openapi</a></strong> to version <strong>v1.1.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-openapi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs the OpenAPI Generator CLI tool and caches it by version, making it easy to automate API client generation tasks in GitHub Actions workflows. It supports generating clients for various languages such as Ruby, Python, Java, etc., and provides options to specify the version and binary name of the tool.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1114-2026-08-27"><a href="https://github.com/remarkablemark/setup-openapi/compare/v1.1.13...v1.1.14">1.1.14</a> (2026-08-27)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump actions/setup-java from 5.7.0 to 6.0.0 (<a href="https://github.com/remarkablemark/setup-openapi/issues/38">#38</a>) (<a href="https://github.com/remarkablemark/setup-openapi/commit/75bf509c0f544c9506c111eaba1be89dd011bd31">75bf509</a>)</li>
</ul>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/custom-amazon-bedrock-agent-action/</link><pubDate>Fri, 28 Aug 2026 01:51:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR), providing customized feedback tailored to your specific requirements. It leverages Amazon Bedrock Knowledge Bases for enhanced context and provides customizable prompts, file ignoring patterns, and language-agnostic analysis capabilities. The integration with AWS enhances the action’s capability by offering more accurate insights and context-aware responses.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR), providing customized feedback tailored to your specific requirements. It leverages Amazon Bedrock Knowledge Bases for enhanced context and provides customizable prompts, file ignoring patterns, and language-agnostic analysis capabilities. The integration with AWS enhances the action&rsquo;s capability by offering more accurate insights and context-aware responses.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/sherpa.sh/</link><pubDate>Fri, 28 Aug 2026 01:50:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh automates the deployment of applications by translating human-readable descriptions into cloud infrastructure configurations. It simplifies the process for developers by enabling them to focus on their code without needing to manage complex YAML files or learn DevOps tools. With Sherpa, users can deploy their applications across various clouds like AWS, Google Cloud, and more, while maintaining full control over the infrastructure setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh automates the deployment of applications by translating human-readable descriptions into cloud infrastructure configurations. It simplifies the process for developers by enabling them to focus on their code without needing to manage complex YAML files or learn DevOps tools. With Sherpa, users can deploy their applications across various clouds like AWS, Google Cloud, and more, while maintaining full control over the infrastructure setup.</p>
]]></content:encoded></item><item><title>Claude Canary</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/claude-canary/</link><pubDate>Fri, 28 Aug 2026 01:49:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/claude-canary/</guid><description>Version updated for https://github.com/SLP-DEV1/claude-code-canary to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Claude Code Canary is a deterministic regression testing and compatibility intelligence tool designed to help developers determine the source of breaking changes in their Claude Code projects. It captures and analyzes metrics, checks deterministic assertions, compares releases, and performs bisection to identify first-bad releases efficiently. Canary supports scenario suites with tags, concurrency, and run budgets, as well as scheduled release watch for regression detection and automatic bisection.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SLP-DEV1/claude-code-canary">https://github.com/SLP-DEV1/claude-code-canary</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/claude-canary">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Claude Code Canary is a deterministic regression testing and compatibility intelligence tool designed to help developers determine the source of breaking changes in their Claude Code projects. It captures and analyzes metrics, checks deterministic assertions, compares releases, and performs bisection to identify first-bad releases efficiently. Canary supports scenario suites with tags, concurrency, and run budgets, as well as scheduled release watch for regression detection and automatic bisection.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: detect efficiency and lifecycle regressions by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/39">https://github.com/SLP-DEV1/claude-code-canary/pull/39</a></li>
<li>feat: add PR regression checks and committed baselines by @SLP-DEV1 in <a href="https://github.com/SLP-DEV1/claude-code-canary/pull/40">https://github.com/SLP-DEV1/claude-code-canary/pull/40</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SLP-DEV1/claude-code-canary/compare/v1.0.1...v1.1.0">https://github.com/SLP-DEV1/claude-code-canary/compare/v1.0.1...v1.1.0</a></p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/ssg-static-site-generator/</link><pubDate>Fri, 28 Aug 2026 01:48:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.52.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go, which converts Markdown with YAML frontmatter into a complete website. It automates tasks such as building the site, serving it locally, and deploying it to various platforms like GitHub Pages, Netlify, Vercel, etc. The action provides features for generating sitemaps, feeds, search indexes, and SEO metadata, among others, making it suitable for creating blogs, portfolios, and other types of websites.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.52</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go, which converts Markdown with YAML frontmatter into a complete website. It automates tasks such as building the site, serving it locally, and deploying it to various platforms like GitHub Pages, Netlify, Vercel, etc. The action provides features for generating sitemaps, feeds, search indexes, and SEO metadata, among others, making it suitable for creating blogs, portfolios, and other types of websites.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.52 — media the site actually serves, and one front page in the sitemap by @spagu in <a href="https://github.com/spagu/ssg/pull/221">https://github.com/spagu/ssg/pull/221</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.51...v1.8.52">https://github.com/spagu/ssg/compare/v1.8.51...v1.8.52</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/classroom-to-sheets-integration/</link><pubDate>Fri, 28 Aug 2026 01:47:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates GitHub Classroom with Google Sheets, allowing instructors to automatically update grades and submission status directly into a Google Sheet. The action uses Google Sheets API credentials to authenticate and interact with the spreadsheet, updating specified columns based on task results from GitHub Actions workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates GitHub Classroom with Google Sheets, allowing instructors to automatically update grades and submission status directly into a Google Sheet. The action uses Google Sheets API credentials to authenticate and interact with the spreadsheet, updating specified columns based on task results from GitHub Actions workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/runward-gate/</link><pubDate>Fri, 28 Aug 2026 01:46:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.37.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is an open-source delivery methodology that verifies engineering decisions behind AI-generated code. It ensures deterministic verification of architectural, security, and operational aspects during the software delivery lifecycle using plain code. Runward helps developers understand and ensure the correctness of their engineered systems after deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.37.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Runward is an open-source delivery methodology that verifies engineering decisions behind AI-generated code. It ensures deterministic verification of architectural, security, and operational aspects during the software delivery lifecycle using plain code. Runward helps developers understand and ensure the correctness of their engineered systems after deployment.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="every-defect-says-what-found-it">Every defect says what found it</h3>
<p>Each of the register&rsquo;s entries now carries a <code>found-by</code> field from a closed vocabulary, guarded by
test and back-filled from headings and first-hand knowledge; two entries say <code>not-recorded</code> because
nobody wrote it down and guessing would be the fabrication the register exists to refuse. Read
across all 87 the mix is 59 adversarial-audit, 14 mutation-instruction, 4 while-reproducing,
3 declared, 2 existing-guard, 2 not-recorded, 1 ci-os-leg, 1 conformance-corpus, 1 measurement —
and the derivation, with three worked examples and the answer to &ldquo;we already do code review&rdquo;, is
<a href="docs/compliance/what-found-them.md">what-found-them.md</a>. The header mix is recomputed from the
rows, never edited by hand.</p>
<p>The author now submits to the constraint the tool sells: the repository&rsquo;s own Stop hook runs
<code>node dist/cli.js check --strict</code> from the tree&rsquo;s build, and the only bypass appends to a
committed log.</p>
<h3 id="compliance-instructed-300-verdicts-re-measured-to-289"><code>compliance</code> instructed: 300 verdicts, re-measured to 289</h3>
<p>The module entered the mutation perimeter with 300 surviving mutants and a ratchet that REFUSED
(&ldquo;never instructed&rdquo;). A seven-agent fleet filed every one — each hole with a mission recipe that
was RUN, each equivalence with a sensitivity control, zero contention — and the whole net replayed
all 300: seven died against a leg (six smoke, one audit-corpus), six of which the instruction had
already filed defence-in-depth with the right leg named. One verdict was reclassed, which is the
argument for running the net rather than reasoning about it (ADR-0046 decision 3).</p>
<p>What the concentration taught: the module&rsquo;s only byte-for-byte guard renders <code>eu-ai-act</code>, pins the
OSCAL JSON and never the markdown, on a fresh mission whose gate is red — so nothing walked
<code>clean</code>, <code>implemented</code>, the prose depth, or a single byte of the three readiness drafts. The
instruction found the one-mutant reintroductions of RWD-2026-0058 (prose <code>implemented</code>) and
RWD-2026-0061 (two vocabularies for one fact) before any of them could ship.</p>
<p>After the fixes below changed three source lines, the tree was re-measured (8 CI chunks), the
predicted MISMATCH read exactly 1 new survivor and 12 orphan keys — three of them filed holes
retired by the new guards themselves — and the register is fresh again: 289 survivors, every one
filed, 557 across both modules.</p>
<h3 id="fixed--two-shipped-defects-the-instruction-surfaced">Fixed — two shipped defects the instruction surfaced</h3>
<ul>
<li><strong>A Windows checkout reported zero agentic-risk coverage</strong> (RWD-2026-0083). <code>compliance.ts</code> kept
the pre-RWD-2026-0016 frontmatter delimiter while <code>rules.ts</code> and <code>conformance.ts</code> were fixed, and
the constant is named <code>FRONTMATTER</code> in all three. Measured on a CRLF-rewritten corpus: <code>runward rules --json</code> reads 10/10 ASI categories, the pack writes 0/10 — same tree, same pass, exit 0.
Invisible here because this repository&rsquo;s own <code>.gitattributes</code> pins every checkout to LF: the fix
that made the project&rsquo;s measurements honest is what hid the defect from them. The guard compiles
and runs every <code>FRONTMATTER</code> delimiter found in <code>src/lib</code> against a CRLF document, so a copy of
the old pattern under a new name still fails.</li>
<li><strong>One ADR status line, four readers, four spellings</strong> (RWD-2026-0084). On <code>**Status** : accepted</code>
— the space French typography requires — the pack printed <code>accepted</code> while the same run counted
the decision not ratified, the ADR-0033 reopening watch skipped it, and a draft rejected with
that spelling would have been resurrected against ADR-0038. All four readers now go through one
exported <code>adrStatusLine</code> in <code>mission.ts</code>, and a recurrence guard asserts no other module in
<code>src/lib</code> spells the pattern at all.</li>
</ul>
<h3 id="the-trust-apparatus-records-its-own-defects">The trust apparatus records its own defects</h3>
<p>Three defects in the measurement layer itself, found the day the second module landed, filed per
the RWD-2026-0060 precedent (RWD-2026-0085..0087): the register generator hard-coded
<code>## Module: evidence</code> and filed 300 compliance survivors under the wrong module — the module is now
read off each verdict&rsquo;s stable key, one section per module; the key-shape guard split on the wrong
separator character, compared 1 to 1 and could not fail — pointed at the real <code>SEP</code> it failed at
once, for the second reason that its statement was also wrong; and the register test&rsquo;s heading
regex could not parse <code>(top level)</code>, so top-level rows were appended to the previous function.
None of the three ever put a false byte in a committed artifact, and the register now says so
with the same evidence discipline it applies to the product.</p>
<h3 id="the-runtime-answer-stated-as-product">The runtime answer, stated as product</h3>
<p><code>docs/positioning.md</code> gains the sibling of its release-stage section: runward&rsquo;s runtime product is
<strong>a verification contract, not a process</strong> — the attestation at delivery (ADR-0055 layers 1–5),
any policy engine verifying it at admission (the Kyverno reference, layer 6), the operator-wired
harness hooks in session (ADR-0039) — and the five ADR-0054 boundary crossings stated as a
buyer-facing guarantee rather than a roadmap gap. Nothing new is decided; the page that has the
charge assembles three ratified decisions into one answer.</p>
<h3 id="the-register-describes-the-tree-again--and-the-instruction-found-three-more-things">The register describes the tree again — and the instruction found three more things</h3>
<p>The 2026-08-26 fixes added 148 lines to <code>evidence.ts</code>, and the CI ratchet came back MISMATCH with
<strong>75 survivors the register did not carry</strong>. A three-agent fleet instructed all of them in isolated
worktrees: <strong>32 holes, 35 equivalents, 7 defence-in-depth, 1 display-only</strong>, each hole carrying a
mission recipe that was RUN, each equivalence carrying a sensitivity control. The register is
regenerated at 268 survivors across 22 functions (164 hole, 69 equivalent, 26 display-only,
9 defence-in-depth) and the ratchet is green.</p>
<p>The brief carried a new rule, and it held: these survivors were measured on an idle CI runner, so a
local &ldquo;killed&rdquo; contradicting that is CONTENTION, not a finding. No agent reported one.</p>
<p>Three things the instruction found that the classification was not looking for:</p>
<ul>
<li><strong>RWD-2026-0082</strong> — an ESCAPED parenthesis (<code>sand\(box</code>) was refused as a catastrophic group by
yesterday&rsquo;s own fix. A false red on correct work, quiet because a balanced pair happens to reduce.</li>
<li><strong>The two nets added this week were in NEITHER pass of the mutation harness</strong>, so every mutant they
catch was reported as surviving. <code>test/spelling-conformance.js</code> and <code>test/sarif-shape.js</code> join the
whole net.</li>
<li><strong>runward had no macOS leg</strong>, so the two Unicode-folding cases of the ADR-0061 corpus — the ones
covering RWD-2026-0031 and RWD-2026-0035 — were skipped on every runner the project used. ext4 is
case-sensitive and NTFS does not fold the sharp s. A <code>macos-latest</code> leg now runs the corpus and the
self-gate. The corpus surfaced this by NAMING its skips, which is what it was built to do.</li>
</ul>
<p>And one worth recording without an entry: <strong>RWD-2026-0070, the symlink seal, shipped with no test of
its own</strong> — which is why eleven of its mutants survive, and why an agent could name the gap in a
sentence.</p>
<h3 id="the-sarif-is-held-to-the-official-schema-adr-0062">The SARIF is held to the official schema (ADR-0062)</h3>
<p><code>test/fixtures/sarif_schema.v2.1.0.json</code> — the OASIS SARIF 2.1.0 schema, vendored offline with its
provenance and sha256 like the OSCAL and in-toto ones — now validates all four mission states.</p>
<p>It needed <code>ajv-draft-04</code> (the schema is draft-04; ajv 8 dropped it), which was left as an operator
decision on 2026-08-26 rather than taken silently. Taken now, and the reason is checkable: the
package comes from the same <code>ajv-validator</code> organisation as <code>ajv</code> and <code>ajv-formats</code>, <strong>both already
dev dependencies here</strong>, is dev-only, and was verified to DETECT before being adopted — a wrong
<code>version</code>, a missing <code>runs</code> and a <code>level</code> outside the enumeration are each refused. The structural
checks stay: a schema cannot say that a uri resolves in the checkout, and every uri of
RWD-2026-0041 was schema-valid.</p>
<h3 id="the-spelling-brick-gets-a-specification-adr-0061">The spelling brick gets a specification (ADR-0061)</h3>
<p><code>test/fixtures/spelling-corpus.json</code> + <code>test/spelling-conformance.js</code>: twelve cases, each a triple of
pointer-as-written / layout-on-disk / expected verdict, each citing the defect it was learned from
(fourteen of them belong to this one brick). The harness probes the host filesystem, runs what
applies, and <strong>names what it skipped and why</strong> — ADR-0046&rsquo;s amendment was paid for by a measurement
that was a property of code AND filesystem while claiming to be a property of code.</p>
<p>The harness itself failed its first <code>windows-latest</code> run — a dynamic <code>import()</code> of a bare <code>C:\...</code>
path is read as the URL scheme <code>c:</code> — which is the right place for a corpus that claims to be the
portable artifact to be corrected.</p>
<ul>
<li><strong>RWD-2026-0081</strong> — found on the corpus&rsquo;s FIRST run: the walk bound added the previous day was
passed in the canonical namespace while the walked path is logical, so on macOS (<code>/var</code> →
<code>/private/var</code>) it never engaged and the false red it closed was alive again. The verification that
had accepted that fix used a path where the two namespaces coincide, so it could not have shown it.</li>
</ul>
<h3 id="a-vacuous-green-is-disclosed-not-refused-adr-0060">A vacuous green is disclosed, not refused (ADR-0060)</h3>
<ul>
<li><strong>RWD-2026-0079</strong> — a mission with no code returned exit 0, <code>clean</code>, and <code>100%</code> coverage while the
honest example reads 87%. It stays green (ADR-0054 makes this a documentary gate) and the run now
SAYS it: <code>evidenceFiles: {total, external}</code> is counted, disclosed in the pass, and carried in the
ADR-0030 contract. The precedent followed is ISA 705&rsquo;s disclaimer of opinion, not pytest&rsquo;s exit 5.</li>
<li><strong>RWD-2026-0080</strong> — <code>verify</code> compared predicates through <code>JSON.stringify</code>, making key order
load-bearing: an honest attestation with identical contents reported <code>differing: [&quot;evidence&quot;]</code>.
Object keys are canonicalised now; arrays keep their order, where order is meaning.</li>
</ul>
<h3 id="the-boundarys-own-paperwork-2026-08-26-audit-tier-5">The boundary&rsquo;s own paperwork (2026-08-26 audit, tier 5)</h3>
<ul>
<li><strong>RWD-2026-0075</strong> — &ldquo;same working tree, same verdict&rdquo; omitted the installed runward version, which
is a real second input by design. Measured: one rule added to the installed corpus flips an
untouched mission from exit 0 to exit 1. Four documents now say the tree AND the version.</li>
<li><strong>RWD-2026-0076</strong> — two of ADR-0054&rsquo;s five crossings had no test, and one test proved crossing 5
under crossing 3&rsquo;s name. Both gaps are closed, each guard with its own positive control.</li>
<li><strong>RWD-2026-0077</strong> — the boundary test called <code>--hooks</code> &ldquo;outside computeVerdict&rdquo;; <code>hookFailed</code> is an
argument to it. The real mitigations are written down instead of implied, along with the closure&rsquo;s
package-boundary limit.</li>
<li><strong>RWD-2026-0078</strong> — <code>--corpus @acme/rules@1.2.3</code> fell to a generic &ldquo;path not found&rdquo; because the
guard&rsquo;s shape stopped at the second <code>@</code>, so the sentence explaining the boundary reached only
someone who had already dropped the version.</li>
</ul>
<h3 id="the-runtime-boundary-and-the-instrument-that-guarded-it-2026-08-26-audit-tier-5">The runtime boundary, and the instrument that guarded it (2026-08-26 audit, tier 5)</h3>
<ul>
<li><strong>RWD-2026-0073</strong> — the ADR-0054 boundary test was blind on the path that owns the exit code. Four
of five planted mutations left all four tests green, including a dynamic import — verbatim the
reevaluation trigger ADR-0054 wrote for itself, already met when it was written. The boundary did
not move; the instrument now walks a second, wider ring from <code>check.js</code> with exactly one
enumerated crossing allowed. ADR-0054 carries the amendment and the measurement table.</li>
<li><strong>RWD-2026-0074</strong> — <code>chmod 0111</code> on the project&rsquo;s PARENT turned an unchanged tree from exit 0 into
exit 1 with 21 pointers refused, each pointing the operator at a path outside their project. The
case walk is now bounded to the project root.</li>
</ul>
<p>Two more findings from the same report were <strong>closed as side effects</strong> of the morning&rsquo;s containment
work and verified: an empty <code>.git</code> above the project no longer greens out-of-tree evidence, and the
in-toto mission digest no longer changes when a file outside the project does.</p>
<h3 id="the-machine-surfaces-2026-08-26-audit-tier-5">The machine surfaces (2026-08-26 audit, tier 5)</h3>
<ul>
<li><strong>RWD-2026-0067</strong> — <code>--json --sarif</code> emitted one document and silently dropped the other, by an
undocumented precedence chain. Combined emission flags are now refused; a document-typed request
with no mission writes nothing to stdout instead of a JSON that is not the document asked for.</li>
<li><strong>RWD-2026-0068</strong> — <code>--freeze --json</code> reported <code>seal: present false</code> on the pass that sealed.</li>
<li><strong>RWD-2026-0069</strong> — <code>SOURCE_DATE_EPOCH</code> reached only the VSA. It now reaches every clock runward
writes; <code>interop.md</code> named the wrong set and the wrong variable, and now names both correctly.</li>
<li><strong>RWD-2026-0070</strong> — a cited symlink put its target in the seal and never itself, so re-pointing
the link left <code>✓ seal intact</code> at exit 0. Link and target are both sealed now.</li>
<li><strong>RWD-2026-0071</strong> — <code>runward bundle ../outside.txt</code> bound a file outside the project into a
document about that project. ADR-0019&rsquo;s containment now holds one envelope out.</li>
<li><strong>RWD-2026-0072</strong> — nothing checked the emitted SARIF. <code>test/sarif-shape.js</code> runs four mission
states through every structural invariant a consumer relies on. It is <strong>not</strong> OASIS-schema
validation and says so: that needs <code>ajv-draft-04</code>, a dependency decision left to the operator.</li>
</ul>
<p>Two findings from the same report were <strong>closed as side effects</strong> and verified: <code>--through</code> +
<code>--sarif</code> no longer annotates deferred deliverables with an error level, and an empty <code>.git</code>
directory above the project no longer greens out-of-tree evidence (it now refuses with
<em>&ldquo;resolves outside the project this mission audits&rdquo;</em>).</p>
<h3 id="the-caveat-reaches-the-envelopes-that-leave-the-building-2026-08-26-audit-tier-4">The caveat reaches the envelopes that leave the building (2026-08-26 audit, tier 4)</h3>
<ul>
<li><strong>RWD-2026-0065</strong> — the SLSA VSA and the bundle predicate were the only two emission surfaces
without <code>GATE_NON_SCOPE</code>, and they are the two a policy engine ingests with no human in the loop.
The VSA carries it in <code>policy.annotations</code>, inside the spec shape.</li>
<li><strong>RWD-2026-0066</strong> — the OSCAL mapping spec offered three implementation states, one of which
cannot occur on a mission using the shipped corpus: all ten ASI categories are mapped, so
<code>planned</code> never fires. The spec says so, and names when it would.</li>
</ul>
<h3 id="the-run-says-what-actually-failed-2026-08-26-audit-tier-4">The run says what actually failed (2026-08-26 audit, tier 4)</h3>
<ul>
<li><strong>RWD-2026-0063</strong> — a broken seal printed <code>1 floor rule-conformance gap(s)</code> and <code>Fill the deliverable(s) named above</code>, with none named and every one filled. The verdict now carries
<code>strictBreakdown</code>; the summary names the class and the <code>Next</code> gesture matches it.</li>
<li><strong>RWD-2026-0064</strong> — the corpus-drift remedy prescribed <code>runward update</code> for all three cases.
Measured: it clears <em>missing</em>, is a no-op for <em>edited</em> (only <code>--force</code> works), and clears
<em>extra</em> not at all. Each line now carries the gesture measured to clear it.</li>
</ul>
<h3 id="two-surfaces-that-disagreed-with-themselves-2026-08-26-audit-tier-4">Two surfaces that disagreed with themselves (2026-08-26 audit, tier 4)</h3>
<ul>
<li><strong>RWD-2026-0061</strong> — <code>compliance</code> called a governance file <em>present</em> in the same pass where <code>check</code>
called it a <em>raw template</em>. One used <code>existsSync</code>, the other <code>artifactState</code>. Same function now,
and the same words.</li>
<li><strong>RWD-2026-0062</strong> — the README said <em>six phases, gated</em>; five are gated. Phase 4 carries no gate
by decision (ADR-0033), and the README now carries the reason.</li>
</ul>
<h3 id="the-documents-catch-up-with-the-code-2026-08-26-audit-tier-4">The documents catch up with the code (2026-08-26 audit, tier 4)</h3>
<ul>
<li><strong>RWD-2026-0058</strong> — the OSCAL pack called a control <code>implemented</code> when its only evidence was a
sentence, and the readiness document never used the word <em>prose</em>. Now <code>partial</code>, with a
<code>runward-evidence-depth</code> prop naming which rules rest on a sentence.</li>
<li><strong>RWD-2026-0059</strong> — README and runward&rsquo;s own port contract claimed it <em>runs nothing of yours</em>, in
a build where <code>check --hooks</code> runs your shell commands outside the audited repository. The code was
precise the whole time; only the prose overstated. Guarded from the code, not from a list.</li>
<li><strong>RWD-2026-0060</strong> — the defect register had two duplicate identifiers and a header twelve days and
three releases stale. Renumbered by first-assignment, with a redirect note, and guarded.</li>
</ul>
<h3 id="spec-check-reads-the-spec-people-write-2026-08-26-audit-tier-3"><code>spec-check</code> reads the spec people write (2026-08-26 audit, tier 3)</h3>
<ul>
<li><strong>RWD-2026-0054</strong> — <code>spec-check</code> said <em>every criterion is linked</em> on six ordinary shapes: two
acceptance sections, a <code>###</code> sub-heading inside one, criteria as a table, criteria as prose, an
empty section, and a decoy heading above the real one. The pointer layer was repaired; the section
walk was not, while the manifest parser beside it documents these exact shapes as fixed bugs.</li>
<li><strong>RWD-2026-0055</strong> — a pointer inside backticks, the way markdown is written, was refused with
*symbol &ldquo;login<code>&quot; not found*. </code>clean()` now strips a trailing backtick.</li>
</ul>
<h3 id="test-now-means-a-test-2026-08-26-audit-tier-2"><code>test:</code> now means a test (2026-08-26 audit, tier 2)</h3>
<ul>
<li><strong>RWD-2026-0053</strong> — a prose deliverable declared as <code>test:…::of</code> returned exit 0 on an unsigned
rule. A document is not a test. Checked on the extension only, because a name convention would
refuse Rust <code>#[cfg(test)]</code> and Go table tests that live in source files.</li>
</ul>
<p>Two low findings from the same audit closed as a side effect and verified: the coverage counter no
longer reaches 100% on self-citing <code>#of</code> pointers (it now reads 0 typed / 23 prose on that mission),
because the counter consults the same circularity rule the verdict does.</p>
<h3 id="four-missing-nets-2026-08-26-audit-tier-2">Four missing nets (2026-08-26 audit, tier 2)</h3>
<p>Detectors that could not see the one shape where the abuse is free. Each reproduced first, each
fixed with the opposite direction asserted, and each new test measured RED against the unfixed build.</p>
<ul>
<li><strong>RWD-2026-0049</strong> — the seal covered no <code>adr:</code> target: 0 of 18 lock keys under <code>adr/</code>, so every
ADR body could be replaced with filler under <code>✓ seal intact</code>.</li>
<li><strong>RWD-2026-0050</strong> — the duplicate-cell census read <code>applied</code> rows only, skipping the two columns
where copying a cell costs nothing. <code>duplicated[].rules[]</code> now carries <code>status</code> (additive).</li>
<li><strong>RWD-2026-0051</strong> — the ReDoS screen accepted anything past 21 nesting levels, and was blind to
<code>a*a*</code>: eight adjacent repetitions of one atom exceed 20 s on a 40-character subject. An exhausted
screen now refuses instead of approving.</li>
<li><strong>RWD-2026-0052</strong> — the <code>n/a</code> reason floor counted keystrokes, so <code>xxxxxxxx</code> cleared it. Now a
degeneracy floor, and <strong>recorded as a limitation rather than closed</strong>: the gate does not read prose.</li>
</ul>
<h3 id="the-gates-own-false-greens-2026-08-26-audit-tier-2">The gate&rsquo;s own false greens (2026-08-26 audit, tier 2)</h3>
<p>Three ways a green line rested on nothing, all reproduced on the shipped 0.36.2 binary and on this
tree before being closed, each with a sensitivity control proving the fix is not a blanket refusal.</p>
<ul>
<li><strong>RWD-2026-0046</strong> — circularity was tested on the pointer, not the target: dropping <code>file:</code> moved
the rule&rsquo;s own file into a loop that banked it unexamined. Four states of one cell on a CRITICAL
signed rule: prose → 1, unrelated file → 1, typed self-pointer → 1, <strong>bare self-path → 0</strong>.</li>
<li><strong>RWD-2026-0047</strong> — the signature was tested against the whole file, table included, so the row
declaring a rule satisfied it. 7 of the 9 signed rules ship a signature their own slug matches,
three CRITICAL. The signature now reads the text outside the manifest.</li>
<li><strong>RWD-2026-0048</strong> — <code>isRealAdr</code> was a filename test, so a zero-byte ADR read <code>✓ Decision journal</code>,
<code>all gates passed</code>, <code>1 decision(s) traced</code> and <code>1 ratified ADR(s)</code>. Three definitions of &ldquo;an ADR&rdquo;
existed across three layers; they now share one predicate and one threshold, and the compliance
pack counts as <em>ratified</em> only what carries a ratified status.</li>
</ul>
<p><code>test/audit-corpus.js</code> gains the bare-path vector and reads 15/15 — it read 14/14 while that hole was
live, because it carried only the <code>file:</code> spelling of the same attack. A second candidate vector was
written and then REMOVED rather than shipped: it was refused by the unfixed build for an unrelated
reason, so it would have printed <code>ok</code> without testing what it names. Its proven detector is
<code>test/unit/gate-false-greens.test.js</code>, measured red on the unfixed build and green on the fixed one.</p>
<p><strong>The version string is part of the fix, not bookkeeping.</strong> <code>runward verify</code> derives version skew from
<code>predicate.runward !== VERSION</code>, and this tree carries fifteen false-green fixes over the published
0.36.2 while stamping the same string — so no skew could ever be named between a build that has the
defects and one that fixes them, and a compliance pack stamped <code>0.36.2</code> may have been produced by
either. That was itself an audit finding.</p>
<h3 id="fixed--the-adoption-path-update---corpus">Fixed — the adoption path (<code>update --corpus</code>)</h3>
<ul>
<li><strong>RWD-2026-0038</strong> — vendoring an org corpus erased the lock record of every rule runward wrote,
turning a green mission red on 31 rules it had scaffolded seconds earlier while reporting success.</li>
<li><strong>RWD-2026-0039</strong> — replacing a shipped rule from an org corpus was labelled with the word runward
uses for its own refreshes, so a fork with one <code>signature:</code> line deleted flipped a red gate green
in silence. It is now named <code>replaced</code> and counted as a warning.</li>
</ul>
<h3 id="fixed--the-artifacts-the-gate-hands-to-a-machine">Fixed — the artifacts the gate hands to a machine</h3>
<ul>
<li><strong>RWD-2026-0040</strong> — a red gate emitted a SARIF byte-identical to a green one whenever the gap was
the evidence seal, the rule corpus, an unratified decision or a failed hook.</li>
<li><strong>RWD-2026-0041</strong> — half of every SARIF used a mission-relative uri, so those annotations pointed
at paths no checkout holds.</li>
<li><strong>RWD-2026-0042</strong> — <code>runward verify</code> re-derived two predicate fields of fifteen; everything a
regulator would read was unbound free text.</li>
<li><strong>RWD-2026-0043</strong> — <code>verify</code> took its strictness from the untrusted predicate and never reported
which gate it had re-derived.</li>
<li><strong>RWD-2026-0044</strong> — <code>--vsa</code> named <code>RUNWARD_GATE_STRICT</code> on a <code>FAILED</code> verification, in the one
field the interop page tells a policy engine to branch on.</li>
<li><strong>RWD-2026-0045</strong> — the OSCAL pack was byte-identical between a green gate and one red on eighteen
unresolvable pointers, and declared controls <code>implemented</code> from the manifest status column alone.</li>
</ul>
<h3 id="still-open-recorded-rather-than-fixed">Still open, recorded rather than fixed</h3>
<p>The third adversarial audit produced 56 measured findings across five dimensions. Nine of the fifteen
high-severity ones are fixed here; the remainder are filed in
<a href="docs/compliance/known-defects.md">known-defects.md</a> with their reproductions, and are not closed.</p>
]]></content:encoded></item><item><title>Agent Vigil</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/agent-vigil/</link><pubDate>Fri, 28 Aug 2026 01:45:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/agent-vigil/</guid><description>Version updated for https://github.com/sulmusic2-star/agent-vigil to version v0.20.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Vigil checks an agent-written pull request against rules recorded when the task started, providing PASS, FAIL, or INCONCLUSIVE results. It can also generate a lifecycle receipt without opening a pull request, verifying evidence, and handling public PR receipts securely.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sulmusic2-star/agent-vigil">https://github.com/sulmusic2-star/agent-vigil</a></strong> to version <strong>v0.20.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-vigil">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Vigil checks an agent-written pull request against rules recorded when the task started, providing <code>PASS</code>, <code>FAIL</code>, or <code>INCONCLUSIVE</code> results. It can also generate a lifecycle receipt without opening a pull request, verifying evidence, and handling public PR receipts securely.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Agent Vigil v0.20.0 adds the complete execution-gate package:</p>
<ul>
<li>safe Claude Code and Codex process-conformance checks with explicit <code>ALLOW</code>, <code>DENY</code>, <code>DEFER</code>, <code>ERROR</code>, and <code>UNKNOWN</code> results;</li>
<li>live-host routing drills using harmless allow and deny canaries in disposable profiles;</li>
<li>sticky continuity revocation and independent signed repair;</li>
<li>the five-minute GitHub marker installation;</li>
<li>the signed TypeScript continuity-staple verifier and shared vectors;</li>
<li>a Terraform saved-plan gate that rechecks wall-clock freshness after plan inspection;</li>
<li>a disposable Kubernetes admission lab;</li>
<li>Outcome Mandates, Outcome Receipts, and a retained, unified result view.</li>
</ul>
<p>Release validation at merge commit <code>8b3c8da7210871fec1dd60d36cb382297786c122</code>:</p>
<ul>
<li>609 tests: 604 passed, 5 optional Docker tests skipped, 0 failed;</li>
<li>80.46% branch coverage with the 80% requirement unchanged;</li>
<li>typecheck, build, smoke, public-surface review, package rehearsal, and runtime audit passed;</li>
<li>package rehearsal covered 11 repository shapes and 33 setup flows;</li>
<li>fresh Claude Code 2.1.245 and Codex 0.149.1 live routes passed on the identical validated source tree;</li>
<li>guarded continuity reached <code>CURRENT → REVOKED → REVOKED → CURRENT</code>.</li>
</ul>
<p>The route drills and Kubernetes environment are bounded tests. This release does not claim a production deployment, unrelated installation, real protected-action stop, payment, or revenue.</p>
]]></content:encoded></item><item><title>Effectprint behavioral contract audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/effectprint-behavioral-contract-audit/</link><pubDate>Fri, 28 Aug 2026 01:43:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/effectprint-behavioral-contract-audit/</guid><description>Version updated for https://github.com/TommyTranX/effectprint to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Effectprint is an open-source behavioral contract auditor for imperative WebMCP tools. It checks whether audited invocations of a tool stay within its declared effect boundary, catching attempts to perform unintended actions or mutations on the page. The action helps identify and prevent potential issues related to trust gaps in the WebMCP ecosystem by comparing actual effects with expected behavior.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TommyTranX/effectprint">https://github.com/TommyTranX/effectprint</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/effectprint-behavioral-contract-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Effectprint is an open-source behavioral contract auditor for imperative WebMCP tools. It checks whether audited invocations of a tool stay within its declared effect boundary, catching attempts to perform unintended actions or mutations on the page. The action helps identify and prevent potential issues related to trust gaps in the WebMCP ecosystem by comparing actual effects with expected behavior.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="effectprint-v020">Effectprint v0.2.0</h2>
<p>Deterministic behavioral contract audits for imperative WebMCP tools. Effectprint observes what one audited invocation attempts to change and compares those effects with read-only annotations and explicit contracts.</p>
<h3 id="highlights">Highlights</h3>
<ul>
<li>Fresh guarded Chromium context for discovery and every audited tool</li>
<li>HTTP, WebSocket, navigation, cookies, storage, DOM, clipboard, popup, and download evidence</li>
<li>Safe-mode mutation blocking that preserves attempted effects as evidence</li>
<li>Terminal, JSON, Markdown, HTML, JUnit, SARIF, and SVG badge reports</li>
<li>Deterministic poisoned-shop demo with no model key required</li>
<li>Inputs, outputs, query values, and previews redacted by default</li>
</ul>
<h3 id="rename">Rename</h3>
<p>This release supersedes ToolTruth v0.1.0. The project was renamed before adoption to avoid an existing AI-tooling namespace collision. The canonical CLI is now <code>effectprint</code>, and the default contract file is <code>.effectprint.json</code>.</p>
<h3 id="try-it">Try it</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx --yes github:TommyTranX/effectprint#v0.2.0 demo
</span></span></code></pre></div>]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/wails3-build-action/</link><pubDate>Fri, 28 Aug 2026 01:42:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building process for Wails.io applications, allowing developers to streamline their development workflow. It installs necessary dependencies like Go and Node.js, runs a build of the application, and optionally uploads artifacts to GitHub or releases on tagged builds. Users can specify various options such as build name, platform, and obfuscation settings. The action supports multiple platforms and versions for building Wails projects efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building process for Wails.io applications, allowing developers to streamline their development workflow. It installs necessary dependencies like Go and Node.js, runs a build of the application, and optionally uploads artifacts to GitHub or releases on tagged builds. Users can specify various options such as build name, platform, and obfuscation settings. The action supports multiple platforms and versions for building Wails projects efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/rustscript-action/</link><pubDate>Fri, 28 Aug 2026 01:41:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.6.15.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that allows developers to write scripts in Rust and run them as if they were shell scripts, without the need for compilation. It provides a practical subset of Rust syntax and includes support for many standard library features and bridged crates, such as anyhow, serde, and reqwest. RustScript also supports async programming with tokio and real sharing through Rc, Arc, RefCell, Cell, and Mutex. The tool is cross-platform, supporting Linux, macOS, and Windows, and provides built-in commands for validating scripts, compiling them into native binaries, listing supported features, and cleaning caches.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.6.15</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a tool that allows developers to write scripts in Rust and run them as if they were shell scripts, without the need for compilation. It provides a practical subset of Rust syntax and includes support for many standard library features and bridged crates, such as <code>anyhow</code>, <code>serde</code>, and <code>reqwest</code>. RustScript also supports async programming with <code>tokio</code> and real sharing through <code>Rc</code>, <code>Arc</code>, <code>RefCell</code>, <code>Cell</code>, and <code>Mutex</code>. The tool is cross-platform, supporting Linux, macOS, and Windows, and provides built-in commands for validating scripts, compiling them into native binaries, listing supported features, and cleaning caches.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.6.14...v0.6.15">https://github.com/VladasZ/rustscript/compare/v0.6.14...v0.6.15</a></p>
]]></content:encoded></item><item><title>Apex Test List</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/apex-test-list/</link><pubDate>Fri, 28 Aug 2026 01:40:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/apex-test-list/</guid><description>Version updated for https://github.com/wisefoxme/apex-test-list to version v1.14.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Apex Test List GitHub Action automates the identification and execution of tests based on various annotations or a centralized metadata filter, saving time by reducing the number of tests run in Salesforce orgs. This tool supports both custom comment annotations (@Tests: and @TestSuites:) and Apex’s built-in @isTest annotation. For advanced users who prefer to manage dependencies centrally, it also allows specifying test classes based on Salesforce metadata via a .test-dependencies.yml file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wisefoxme/apex-test-list">https://github.com/wisefoxme/apex-test-list</a></strong> to version <strong>v1.14.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/apex-test-list">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Apex Test List GitHub Action automates the identification and execution of tests based on various annotations or a centralized metadata filter, saving time by reducing the number of tests run in Salesforce orgs. This tool supports both custom comment annotations (<code>@Tests:</code> and <code>@TestSuites:</code>) and Apex&rsquo;s built-in <code>@isTest</code> annotation. For advanced users who prefer to manage dependencies centrally, it also allows specifying test classes based on Salesforce metadata via a <code>.test-dependencies.yml</code> file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1140-2026-08-27"><a href="https://github.com/wisefoxme/apex-test-list/compare/v1.13.15...v1.14.0">1.14.0</a> (2026-08-27)</h2>
<h3 id="features">Features</h3>
<ul>
<li>add GitHub Action for listing Apex tests (<a href="https://github.com/wisefoxme/apex-test-list/issues/399">#399</a>) (<a href="https://github.com/wisefoxme/apex-test-list/commit/baca2f5e51f26a502bf6efa23322a2fe96bde966">baca2f5</a>)</li>
<li>replace async, xml2js, yaml, and SDR with in-house parsers (<a href="https://github.com/wisefoxme/apex-test-list/issues/398">#398</a>) (<a href="https://github.com/wisefoxme/apex-test-list/commit/001a6c6f9f6625d28f1dac5774145fb6b0080292">001a6c6</a>)</li>
</ul>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/cowork-harness/</link><pubDate>Fri, 28 Aug 2026 01:39:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v2.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary cowork-harness is an unofficial tool that creates a scriptable and CI-friendly test harness to emulate the observable runtime contract of Claude Cowork. It helps developers test their skills in multiple scenarios headlessly, across many CI jobs, without relying on the locked Desktop app. The action automates the reproduction of constraints such as sealed filesystem, default-deny egress, and MCP-only cross-boundary, providing evidence of what the agent actually did during a run. This is particularly useful for ensuring that skills are compatible with Cowork’s environment, even if they don’t pass strict claude -p runs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v2.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>cowork-harness is an unofficial tool that creates a scriptable and CI-friendly test harness to emulate the observable runtime contract of Claude Cowork. It helps developers test their skills in multiple scenarios headlessly, across many CI jobs, without relying on the locked Desktop app. The action automates the reproduction of constraints such as sealed filesystem, default-deny egress, and MCP-only cross-boundary, providing evidence of what the agent actually did during a run. This is particularly useful for ensuring that skills are compatible with Cowork&rsquo;s environment, even if they don&rsquo;t pass strict <code>claude -p</code> runs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fidelity">Fidelity</h3>
<ul>
<li>
<p><strong>Path resolution: the shell and the file tools use DIFFERENT roots, and the harness now models that.</strong>
Measured on desktop-local Cowork 2026-08-27: <code>mcp__workspace__bash</code> starts every call at the bare
session root (<code>/sessions/&lt;id&gt;</code>), while the agent process sits at the outputs dir, so a bare <code>Write</code>
lands in <code>mnt/outputs</code> and is user-visible immediately. The two are different path spaces — a file the
shell creates with a relative path is <em>not</em> where a relative <code>Write</code> puts one.</p>
<p><code>hostloop</code> ran its workspace bash at <code>${sessionRoot}/mnt/&lt;firstFolder ?? outputs&gt;</code>, collapsing the two.
The replaced derivation came from the asar&rsquo;s <code>cwd: c.vmCwd</code> spawn argument, which is <strong>not
load-bearing on the cowork path</strong> — only the <code>chat</code> branch prepends an explicit <code>cd ${vmCwd}</code>, which
would be redundant if the argument worked. It reproduced a prompt claim rather than an observed
behaviour. Both cwds now come from one function (<code>hostLoopCwds</code>) and are pinned together in a single
test: a single-value assertion cannot express &ldquo;shell and file tools disagree, on purpose&rdquo;, which is the
contract every previous version of this bug flattened.</p>
<p><strong>What it changes for you:</strong> a skill that writes deliverables from a shell script using relative paths
looked correct at <code>hostloop</code> and delivered nothing in production. It now fails here too.</p>
</li>
<li>
<p><strong><code>container</code> models production&rsquo;s VM-loop <code>web_fetch</code> swap.</strong> When <code>coworkWebFetchViaApi</code> resolves on
(true in every shipped baseline), the tier registers a workspace SDK-MCP server exposing <strong>web_fetch
only</strong>, disallows the built-in <code>WebFetch</code>, and aliases the name to <code>mcp__workspace__web_fetch</code>
(<code>VM_LOOP_TOOL_ALIASES</code>). Bash is deliberately untouched — &ldquo;Bash is the only tool that truly diverges
between loops&rdquo; — which is why <code>container</code> keeps the built-in shell while <code>hostloop</code> replaces both.</p>
<p>The three parts ship together by necessity: disallowing the built-in without the alias turns a fidelity
fix into a regression, because the bare name stops resolving instead of landing on the workspace tool.
The tool is advertised but deliberately <strong>not</strong> pre-approved — production&rsquo;s VM-loop registration passes
the same approval hook the host loop does, so the call is gated at <code>can_use_tool</code>. Pre-approving it
would make a scripted <code>webfetch:&lt;domain&gt;</code> answer, and <code>decide: deny</code> on it, silently inert.</p>
<p>Its fetch is bound to the session egress allowlist and to URL provenance, exactly as the host loop&rsquo;s is.
Both matter: this fetch runs in the harness&rsquo;s own process, outside the container network namespace,
so the sidecar proxy never sees it and only these two gates constrain it. The handler&rsquo;s allowlist now
defaults to <strong>deny-all</strong> rather than <code>[&quot;*&quot;]</code>, so a caller that forgets to pass one gets nothing through
instead of everything.</p>
<p>The workspace handler now gates <strong>dispatch</strong> on the same set it advertises, not just <code>tools/list</code>. An
unadvertised tool that still executed when named was a real hole: the VM-loop registration exposes
web_fetch only, and a <code>bash</code> call arriving there must be refused rather than quietly exec&rsquo;d into the
container.</p>
<p><strong><code>microvm</code> is unchanged</strong> and still offers the built-in <code>WebFetch</code> — <code>spawnMicroVm</code> does not receive
the gate. <strong><code>chat</code> is unchanged too</strong>: the swap applies to <code>run</code>/<code>record</code>, so <code>chat --fidelity container</code>
still offers the built-in and the two surfaces differ at the same declared tier.</p>
</li>
</ul>
<h3 id="upgrade-impact">Upgrade impact</h3>
<ul>
<li>
<p><strong>At <code>fidelity: container</code> under <code>run</code>/<code>record</code>, <code>WebFetch</code> is no longer in the offered tool set.</strong> An assertion naming it
no longer describes a callable tool. <code>tool_not_called: WebFetch</code> is the dangerous direction: it now
passes <strong>vacuously</strong> rather than failing loudly, so a scenario that was genuinely testing &ldquo;this skill
does not fetch from the web&rdquo; silently stops testing anything. Rename to
<code>tool_not_called: mcp__workspace__web_fetch</code>. The shipped <code>example-pdf-skill</code> scenario carried exactly
this defect and is fixed.</p>
<p><code>verify-cassettes</code> grew a <code>replaced-builtin</code> note for this class: it reads a cassette&rsquo;s recorded init
inventory and reports built-in names the current build no longer offers at that tier. It is a <strong>note,
not a finding</strong> — the swap is gate-conditional, so a recording made with the gate off is legitimately
different, and an init event carrying no <code>tools</code> key is <em>no evidence</em> rather than a missing surface.
Neither should be told to re-record.</p>
<p>This does not break a covered surface (<a href="./SPEC.md#12-versioning--the-10-compatibility-contract">SPEC.md §12</a>):
no command, flag, schema or exit-code meaning changes. The tier&rsquo;s modelled tool inventory is a fidelity
property, and moving it toward production is the project&rsquo;s purpose — so it ships in a minor.</p>
</li>
<li>
<p><strong>DEPRECATION: <code>fidelity:</code> becomes REQUIRED in the next major.</strong> A scenario that omits it currently
defaults to <code>container</code>, which models the <strong>VM loop</strong> — but production runs the <strong>host loop</strong> (gate
<code>1143815894</code> is force-ON in every shipped baseline). So an omitted key silently measures the scenario
against a lane real users are not on, and the two lanes differ in exactly the ways that bite: where a
bare relative path lands, where the shell starts, and which tools are offered.</p>
<p>Both <code>run</code> and the skill&rsquo;s <code>scenario.py</code> lint now warn (<code>fidelity-defaulted</code>). The check reads the RAW
document, because Zod&rsquo;s <code>.default()</code> makes an omitted key indistinguishable from a deliberate
<code>fidelity: container</code> — and those two deserve different treatment. Naming the tier explicitly silences
it; <code>fidelity: container</code> remains a valid, non-warning choice.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>The semantic judge was told which authored files were never delivered.</strong> The authored-file capture
deliberately includes the scratchpad, but production discards anything outside <code>mnt/</code> — &ldquo;never reaches
the user or your file tools&rdquo;. Unlabelled, a rubric like &ldquo;the report was written&rdquo; graded TRUE on a file
the user never receives: a false green inside the one evaluator that reads free-form prose and cannot
infer the convention. Scratch files are now tagged <code>— SCRATCH, NOT delivered to the user</code>, with a note
explaining they are evidence of what the run DID and not that anything was delivered.</p>
</li>
<li>
<p><strong><code>sync</code> no longer refuses to write on the <code>subagentPromptServerOverride</code> gate.</strong> Gate-ON only enables
the lookup; the payload that would actually override is delivered <strong>per session by the server</strong> and
appears in neither the asar, the fcache nor <code>config.json</code>. So gate state alone cannot separate
&ldquo;override active&rdquo; from &ldquo;gate on, no payload, fallback still correct&rdquo; — the guard blocked forever
rather than tripping, because it could never clear itself from its own inputs. It is now a
non-blocking note that says what it can and cannot know.</p>
<p>Settled by a live sub-agent probe instead: a real sub-agent&rsquo;s environment section matched the committed
paraphrase on all four load-bearing claims, so no override was reaching that account. That is evidence,
not proof — one account, one session, and a server rule can be segment-targeted. The note says so, and
says to re-probe if the sub-agent append matters to what you are shipping.</p>
</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>
<p><strong><a href="./docs/scenario.md">docs/scenario.md</a> now states where a relative path actually lands</strong>, as a
measured table per tier, replacing a sentence that was simply wrong for the file tools. The guidance
that follows it is lane-dependent, because the correct answer inverts between lanes: on the desktop
host loop the file tools are already rooted at <code>outputs/</code>, so writing <code>outputs/x.md</code> doubles to
<code>outputs/outputs/x.md</code> and the user never sees it — a <strong>bare filename</strong> is right there. At
<code>container</code>/<code>microvm</code> a bare name lands in the scratchpad instead. Addressing a connected folder by
name never reaches it on either lane: it builds a same-named decoy inside <code>outputs</code>, reports success,
and gives no signal.</p>
</li>
<li>
<p><strong><a href="./docs/fidelity-gaps.md">docs/fidelity-gaps.md</a></strong> gained the path-resolution split, and its
&ldquo;VM tiers have no workspace tool aliases&rdquo; entry is updated — closed at <code>container</code>, still open at
<code>microvm</code>.</p>
</li>
<li>
<p>The skill&rsquo;s undelivered-deliverables guidance no longer hardcodes the literal prefix <code>outputs/</code>, which
was wrong on the lane production actually runs.</p>
</li>
<li>
<p><strong>The product&rsquo;s vocabulary is mapped to this project&rsquo;s</strong>, because one directory had four names and none
of them was the one Cowork&rsquo;s UI shows. &ldquo;Working folder&rdquo; is the user-visible roots (<code>outputs/</code> plus each
connected folder); &ldquo;Scratchpad&rdquo; is everything outside <code>mnt/</code>; <code>{{workspaceFolder}}</code> is a prompt token
that renders to the <em>first</em> user-visible root. Also recorded: Cowork&rsquo;s <strong>Scratchpad panel is an activity
log, not a location listing</strong> — it lists files as &ldquo;wrote to&rdquo; wherever they landed, so a file appearing
there is not evidence it was undelivered.</p>
</li>
<li>
<p><strong><code>Write</code>&rsquo;s tool result echoes the raw path it was given and never absolutizes</strong> (read from the agent
binary). Nothing in the harness parses a path out of a <code>Write</code> result; this is recorded so nothing
starts, since such an assertion would be reading something production does not emit. Cowork&rsquo;s own
chat-surface prompt claims the opposite, so the product&rsquo;s description of its own tool is wrong here.</p>
</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 2.4.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/160">https://github.com/yaniv-golan/cowork-harness/pull/160</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v2.3.0...v2.4.0">https://github.com/yaniv-golan/cowork-harness/compare/v2.3.0...v2.4.0</a></p>
]]></content:encoded></item><item><title>pr-trailer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/pr-trailer/</link><pubDate>Fri, 28 Aug 2026 01:37:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/28/pr-trailer/</guid><description>Version updated for https://github.com/yasel-scf/pr-trailer to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action analyzes pull requests and posts a risk-prioritized review brief as a comment, including files affected, their risks, and a suggested reading order. It updates in place with every push, reducing clutter in the thread. The action is hosted, requires an API key for authentication and service URL, and supports email-based account access for non-self-serve sign-up.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yasel-scf/pr-trailer">https://github.com/yasel-scf/pr-trailer</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-trailer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action analyzes pull requests and posts a risk-prioritized review brief as a comment, including files affected, their risks, and a suggested reading order. It updates in place with every push, reducing clutter in the thread. The action is hosted, requires an API key for authentication and service URL, and supports email-based account access for non-self-serve sign-up.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Refine action description for clarity by @yasel-scf in <a href="https://github.com/yasel-scf/pr-trailer/pull/15">https://github.com/yasel-scf/pr-trailer/pull/15</a></li>
</ul>
]]></content:encoded></item><item><title>Setup Soft-RoCE</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/setup-soft-roce/</link><pubDate>Thu, 27 Aug 2026 17:42:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/setup-soft-roce/</guid><description>Version updated for https://github.com/SF-Zhou/setup-soft-roce-action to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up the Soft-RoCE software stack on Ubuntu GitHub Actions runners, automating the installation of necessary modules and configuration for RDMA (Remote Direct Memory Access) communication. It can be customized with specific network interface and device name settings to configure a Soft-RoCE network environment efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SF-Zhou/setup-soft-roce-action">https://github.com/SF-Zhou/setup-soft-roce-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-soft-roce">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up the Soft-RoCE software stack on Ubuntu GitHub Actions runners, automating the installation of necessary modules and configuration for RDMA (Remote Direct Memory Access) communication. It can be customized with specific network interface and device name settings to configure a Soft-RoCE network environment efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fall back to linux-modules-extra and retry kernel source download</p>
]]></content:encoded></item><item><title>Claude Canary</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/claude-canary/</link><pubDate>Thu, 27 Aug 2026 17:42:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/claude-canary/</guid><description>Version updated for https://github.com/SLP-DEV1/claude-code-canary to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Claude Code Canary automates deterministic regression testing and compatibility intelligence for Claude Code, solving common issues such as identifying regressions between different releases, verifying plugin compatibility, and ensuring CI runs without paying for redundant executions. It captures tool calls, tokens, duration, and reported cost to provide actionable insights into changes in Claude Code workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SLP-DEV1/claude-code-canary">https://github.com/SLP-DEV1/claude-code-canary</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/claude-canary">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Claude Code Canary automates deterministic regression testing and compatibility intelligence for Claude Code, solving common issues such as identifying regressions between different releases, verifying plugin compatibility, and ensuring CI runs without paying for redundant executions. It captures tool calls, tokens, duration, and reported cost to provide actionable insights into changes in Claude Code workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="claude-canary-v100-">Claude Canary v1.0.0 🐤</h2>
<p>The first stable release of Claude Canary.</p>
<p>Catch Claude Code regressions before they reach your workflow.</p>
<h3 id="highlights">Highlights</h3>
<ul>
<li>🔎 Compare Claude Code releases deterministically</li>
<li>🧬 Automatically bisect the first bad Claude Code release</li>
<li>🧪 A/B test CLAUDE.md, settings, hooks, MCP servers and plugins</li>
<li>🎬 Record real Claude tasks and replay them from the exact Git commit</li>
<li>📦 Generate privacy-first reproduction bundles</li>
<li>🔌 Automatically discover Claude Code plugin components</li>
<li>🧩 Test plugins across multiple Claude Code releases</li>
<li>📊 Generate complete plugin compatibility matrices</li>
<li>⚙️ Native GitHub Action with CI summaries and artifacts</li>
<li>🔐 Signed historical Claude Code release verification</li>
<li>🖥️ Tested on Linux, Windows and macOS</li>
<li>🟢 Node.js 20, 22 and 24</li>
</ul>
<h3 id="github-action">GitHub Action</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">SLP-DEV1/claude-code-canary@v1.0.0</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/update-a-config-file-with-values-from-environment/</link><pubDate>Thu, 27 Aug 2026 17:41:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces placeholders in a configuration file with values from environment variables. It helps automate the process of managing sensitive information securely by using environment variables instead of hardcoding them directly into the configuration files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces placeholders in a configuration file with values from environment variables. It helps automate the process of managing sensitive information securely by using environment variables instead of hardcoding them directly into the configuration files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/spek-openspec-static-site/</link><pubDate>Thu, 27 Aug 2026 17:41:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.16.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary spek is an open-source tool that provides a read-only, local interface for browsing OpenSpec content. It automates the process of viewing specs, tracking changes, and managing tasks within a repository. The action offers features such as a dashboard overview, spec and change browsers with BDD syntax highlighting, task progress indicators, full-text search capabilities, and support for worktree aggregation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.16.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>spek</strong> is an open-source tool that provides a read-only, local interface for browsing OpenSpec content. It automates the process of viewing specs, tracking changes, and managing tasks within a repository. The action offers features such as a dashboard overview, spec and change browsers with BDD syntax highlighting, task progress indicators, full-text search capabilities, and support for worktree aggregation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Highlight: a change&rsquo;s non-Markdown artifacts are visible.</strong> A schema sets each artifact&rsquo;s filename through <code>generates:</code>, and not every artifact is Markdown — <code>event-driven</code> requires <code>asyncapi.yaml</code>. spek discovered only root <code>*.md</code> and the <code>specs/</code> tree, so such a change rendered every tab except the one its schema asks for.</p>
<ul>
<li><strong>Root <code>.yaml</code> / <code>.yml</code> / <code>.json</code> files are artifacts</strong>, shown as syntax-highlighted text. The tab is named for the file&rsquo;s stem with a format badge, using the full filename only when a Markdown artifact shares it. Thanks to <a href="https://github.com/nthansen">@nthansen</a> (Norman Hansen) (<a href="https://github.com/spekhq/spek/pull/50">#50</a>)</li>
<li><strong>They sort into their schema position</strong>, count in the change-list badge, are reachable by search, and refresh live on edit — on every surface</li>
<li><strong>Discovery stays root-only and skips dotfiles</strong>, so <code>.openspec.yaml</code> and subdirectory files never become tabs</li>
<li><strong>Code fences in <code>proposal.md</code> / <code>design.md</code> are highlighted too.</strong> A fence with no language stays plain</li>
<li><em>Internal:</em> <code>@spekjs/core</code> 1.11.0 adds the <code>&quot;data&quot;</code> kind and the shared file listing behind count, search and discovery</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/classroom-to-sheets-integration/</link><pubDate>Thu, 27 Aug 2026 17:40:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates Google Sheets with GitHub Classroom to automatically send assignment results. It requires setting up Google API credentials and sharing the sheet with the service account. The action uses Graders from the classroom-resources/autograding-command-grader repository to collect task results and updates them in a specified Google Sheet, creating columns as needed for each task or additional information provided by users.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates Google Sheets with GitHub Classroom to automatically send assignment results. It requires setting up Google API credentials and sharing the sheet with the service account. The action uses Graders from the <code>classroom-resources/autograding-command-grader</code> repository to collect task results and updates them in a specified Google Sheet, creating columns as needed for each task or additional information provided by users.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>Sprocket CI/CD</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/sprocket-ci/cd/</link><pubDate>Thu, 27 Aug 2026 17:39:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/sprocket-ci/cd/</guid><description>Version updated for https://github.com/stjude-rust-labs/sprocket-action to version v0.30.0.
This action is used across all versions by 8 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action provides a set of commands from the Sprocket WDL tool, including static analysis (check and lint), validation, and formatting. It automates common tasks in CI/CD pipelines by running these tools on WDL documents in the repository. The action allows for customization through inputs and configuration files, enabling flexibility in how WDL code is validated and formatted.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stjude-rust-labs/sprocket-action">https://github.com/stjude-rust-labs/sprocket-action</a></strong> to version <strong>v0.30.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sprocket-ci-cd">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action provides a set of commands from the Sprocket WDL tool, including static analysis (<code>check</code> and <code>lint</code>), validation, and formatting. It automates common tasks in CI/CD pipelines by running these tools on WDL documents in the repository. The action allows for customization through inputs and configuration files, enabling flexibility in how WDL code is validated and formatted.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Updates the action to use <a href="https://github.com/stjude-rust-labs/sprocket/releases/tag/v0.30.0">Sprocket v0.30.0</a> and maps the existing <code>all-lint-rules</code> input to <code>--tag all</code>.</p>
]]></content:encoded></item><item><title>Auto Product Video Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/auto-product-video-generator/</link><pubDate>Thu, 27 Aug 2026 17:38:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/auto-product-video-generator/</guid><description>Version updated for https://github.com/TakuKobayashi/auto-product-video-generator to version v0.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action generates a narrated promotional video on an Ubuntu runner using Ollama, VOICEVOX, Playwright, and FFmpeg. It analyzes the repository, checks out the code, plans the presentation, records the application, and produces a narrated video. The action supports various platforms including web applications, CLI applications, Android devices/emulators, Flutter/React Native, Unity Android, iOS, and Unity Desktop.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TakuKobayashi/auto-product-video-generator">https://github.com/TakuKobayashi/auto-product-video-generator</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auto-product-video-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action generates a narrated promotional video on an Ubuntu runner using Ollama, VOICEVOX, Playwright, and FFmpeg. It analyzes the repository, checks out the code, plans the presentation, records the application, and produces a narrated video. The action supports various platforms including web applications, CLI applications, Android devices/emulators, Flutter/React Native, Unity Android, iOS, and Unity Desktop.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="english">English</h1>
<h2 id="new-features">New Features</h2>
<ul>
<li><strong>Enhanced CLI Command Handling</strong>: The AI pipeline now more accurately detects and grounds CLI commands based on the project&rsquo;s <code>package.json</code> and README. This ensures that only safe and executable commands are included in the generated script, improving the reliability and security of the recorded video.</li>
<li><strong>Support for Normalizing Windows Paths</strong>: Added a function to normalize Windows setup paths for the Linux container in the CLI recorder.</li>
<li><strong>Improved Error Handling</strong>: Enhanced error handling in the CLI recorder to include detailed error messages from the CLI command output.</li>
</ul>
<h2 id="internal-changes">Internal Changes</h2>
<ul>
<li><strong>Refactored Analyzer Logic</strong>: The <code>ProjectAnalyzer</code> class has been refactored to improve the detection and grounding of CLI commands. This includes new functions to detect and ground CLI commands based on the project&rsquo;s <code>package.json</code> and README.</li>
<li><strong>Updated Scenario Generator</strong>: The <code>ScenarioGenerator</code> class has been updated to ensure that each useful command is shown in a separate scene, and that real safe workflows ending in <code>--dry-run</code> are used when provided.</li>
<li><strong>Refactored Timeline Builder</strong>: The <code>TimelineBuilder</code> class has been refactored to set the volume to 1.0 for better audio quality.</li>
<li><strong>FFmpeg Configuration</strong>: The <code>FfmpegRenderer</code> class has been updated to include a more sophisticated audio mixing configuration. The <code>amix</code> filter is now set with <code>normalize=0</code> to prevent early narration from being attenuated, and <code>loudnorm</code> is used to normalize the final narration to a consistent volume level.</li>
<li><strong>Refactored CLI Source Extraction</strong>: The <code>readCliSourceExcerpt</code> and <code>discoverCliCommandPaths</code> functions have been added to the <code>inspector.ts</code> file. These functions help in extracting and analyzing CLI source code, providing more detailed insights into project commands and options.</li>
<li><strong>Updated Dependencies</strong>: The <code>action.yml</code> file has been updated to include new automation scripts for collecting npm publish diagnostics, configuring CI/APVG, verifying npm authentication, and verifying release tags.</li>
</ul>
<h2 id="breaking-changes">Breaking Changes</h2>
<ul>
<li><strong>Removed Background Development Server for CLIs</strong>: CLIs no longer require a background development server. The setup steps are now tailored to the actual README/scripts provided by the LLM, ensuring that only necessary preparation steps are included.</li>
<li><strong>Removed AI Release Notes Generation</strong>: The AI release notes generation functionality has been removed. This change affects the <code>.github/actions/ai-release-notes</code> directory, which includes the <code>README.md</code>, <code>action.yml</code>, <code>generate-release-notes.mjs</code>, and related files.</li>
<li><strong>CLI Application</strong>: The <code>runBuild</code> and <code>runRecord</code> functions now require the <code>startedApp</code> variable to be awaited and stopped properly to ensure all resources are released correctly. The <code>dryRun</code> and <code>skipRecord</code> options must now be explicitly set to <code>true</code> to skip recording.</li>
</ul>
<h2 id="migration-notes">Migration Notes</h2>
<ul>
<li><strong>Review and Update READMEs</strong>: Ensure that your project&rsquo;s READMEs are up-to-date and contain accurate instructions for setting up and running your CLI. This will help the AI pipeline generate more accurate and useful scripts.</li>
<li><strong>Update CI/CD Workflows</strong>: The <code>.github/workflows</code> directory has been significantly updated. The <code>generate-demo.yml</code> and <code>publish-npm.yml</code> files have been modified, and new workflows have been added, such as <code>main-video-build.yml</code>. Ensure your CI/CD configurations are updated to accommodate these changes.</li>
<li><strong>Update Workflows</strong>: Users need to update their GitHub Actions workflows to use the new action and automation scripts. This includes updating the <code>uses</code> field in the workflow YAML files to point to the new action URL.</li>
<li><strong>Environment Variables</strong>: Ensure that the required environment variables (<code>OLLAMA_HOST</code>, <code>OLLAMA_NUM_PARALLEL</code>, <code>OLLAMA_MODEL</code>, <code>VOICEVOX_IMAGE</code>, <code>FFMPEG_PATH</code>, <code>FFPROBE_PATH</code>) are set in the workflow environment.</li>
</ul>
<h2 id="fixes">Fixes</h2>
<ul>
<li><strong>Fixed Volume Setting</strong>: The volume setting for the timeline builder has been adjusted to 1.0, ensuring that the audio is not too quiet.</li>
<li><strong>Fixed Path Resolution Issues</strong>: Fixed an issue where the application was not stopping properly after recording, leading to resource leaks.</li>
<li><strong>Fixed Server Lifecycle Management</strong>: The <code>server.ts</code> and <code>server.spec.ts</code> files have been updated to include a <code>StartedApp</code> interface and a <code>stop</code> method. This ensures that the dev server can be properly stopped, preventing resource leaks and ensuring clean shutdowns.</li>
<li><strong>Enhanced Error Messages</strong>: Fixed an issue where early narration in videos was being attenuated, leading to inconsistent audio levels. The new configuration ensures that the audio is normalized to a loud, speech-friendly level, improving the overall quality of the rendered videos.</li>
</ul>
<p>These changes aim to improve the reliability and functionality of the release notes generation process, while also providing better diagnostics and validation during the publishing process.</p>
<h1 id="japanese">Japanese</h1>
<h2 id="新機能">新機能</h2>
<ul>
<li><strong>CLIコマンドの処理の向上</strong>: AIパイプラインは、プロジェクトの<code>package.json</code>とREADMEに基づいてCLIコマンドをより正確に検出および接地します。これにより、生成されたスクリプトに含まれるコマンドが安全で実行可能であることを保証し、録画ビデオの信頼性とセキュリティを向上させます。</li>
<li><strong>Windowsパスの正規化のサポート</strong>: CLIレコーダーでLinuxコンテナ用のWindows設定パスを正規化するための関数を追加しました。</li>
<li><strong>CLIコマンドのエラーハンドリングの向上</strong>: CLIレコーダーのエラーハンドリングを向上させ、CLIコマンド出力からの詳細なエラーメッセージを含めました。</li>
</ul>
<h2 id="内部変更">内部変更</h2>
<ul>
<li><strong>Analyzerロジックのリファクタリング</strong>: <code>ProjectAnalyzer</code>クラスがリファクタリングされ、CLIコマンドの検出と接地を改善しました。これには、プロジェクトの<code>package.json</code>とREADMEに基づいてCLIコマンドを検出および接地するための新しい関数が含まれます。</li>
<li><strong>ScenarioGeneratorの更新</strong>: <code>ScenarioGenerator</code>クラスが更新され、各有用なコマンドが個別のシーンで表示され、提供された実際の安全なワークフローが<code>--dry-run</code>で終わる場合に使用されます。</li>
<li><strong>TimelineBuilderのリファクタリング</strong>: <code>TimelineBuilder</code>クラスがリファクタリングされ、より良い音質のためのボリュームを1.0に設定しました。</li>
<li><strong>FFmpegの構成</strong>: <code>FfmpegRenderer</code>クラスが更新され、より複雑な音声ミックス構成が含まれました。<code>amix</code>フィルターは<code>normalize=0</code>で設定され、<code>loudnorm</code>を使用して最終的なナレーティョンを一貫した音量レベルに正規化します。</li>
<li><strong>CLIソースコードの抽出のリファクタリング</strong>: <code>inspector.ts</code>ファイルに<code>readCliSourceExcerpt</code>と<code>discoverCliCommandPaths</code>関数が追加されました。これらの関数はCLIソースコードを抽出および解析し、プロジェクトのコマンドとオプションに関するより詳しい洞察を提供します。</li>
<li><strong>依存関係の更新</strong>: <code>action.yml</code>ファイルが更新され、npmパブリッシュ診断の収集、CI/APVGの構成、npm認証の検証、リリースタグの検証などの新しい自動化スクリプトが含まれました。</li>
</ul>
<h2 id="ブレーキング変更">ブレーキング変更</h2>
<ul>
<li><strong>CLIs用のバックグラウンド開発サーバーの削除</strong>: CLIsはバックグラウンド開発サーバーを必要としません。設定手順は、LLMによって提供される実際のREADME/スクリプトに合わせて調整され、必要な準備手順のみが含まれます。</li>
<li><strong>AIリリースノート生成機能の削除</strong>: AIリリースノート生成機能が削除されました。これにより、<code>.github/actions/ai-release-notes</code>ディレクトリが影響を受け、<code>README.md</code>、<code>action.yml</code>、<code>generate-release-notes.mjs</code>、関連ファイルなどが含まれます。</li>
<li><strong>CLIアプリケーション</strong>: <code>runBuild</code>と<code>runRecord</code>関数は、<code>startedApp</code>変数を待機し、適切に停止してリソースを解放するように更新されました。<code>dryRun</code>と<code>skipRecord</code>オプションは、記録をスキップするためには明確に<code>true</code>に設定する必要があります。</li>
</ul>
<h2 id="マイグレーション注意事項">マイグレーション注意事項</h2>
<ul>
<li><strong>READMEのレビューと更新</strong>: プロジェクトのREADMEが最新で、CLIの設定と実行に関する正確な指示が含まれていることを確認してください。これにより、AIパイプラインがより正確で有用なスクリプトを生成します。</li>
<li><strong>CI/CDワークフローの更新</strong>: <code>.github/workflows</code>ディレクトリが大幅に更新されました。<code>generate-demo.yml</code>と<code>publish-npm.yml</code>ファイルが修正され、新しいワークフローが追加されました。CI/CD構成を更新してこれらの変更に対応してください。</li>
<li><strong>ワークフローの更新</strong>: ユーザーは、新しいアクションと自動化スクリプトを使用するGitHub Actionsワークフローを更新する必要があります。ワークフローYAMLファイルの<code>uses</code>フィールドを新しいアクションURLに更新します。</li>
<li><strong>環境変数</strong>: ワークフロー環境に必要な環境変数（<code>OLLAMA_HOST</code>、<code>OLLAMA_NUM_PARALLEL</code>、<code>OLLAMA_MODEL</code>、</li>
</ul>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/delivery-autopilot-runner/</link><pubDate>Thu, 27 Aug 2026 17:37:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.53.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Delivery Autopilot Runner GitHub Action automates the process of taking tickets from a tracker to reviewed pull requests using an AI pipeline hosted by Tekunda. It handles code writing, quality checks, and PR creation all within the user’s GitHub Actions environment without sending any source or data to Tekunda’s servers. The action is triggered by Delivery Autopilot through signed instructions and can be set up via either the Delivery Autopilot GitHub App or manually adding a workflow configuration file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.53</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Delivery Autopilot Runner GitHub Action automates the process of taking tickets from a tracker to reviewed pull requests using an AI pipeline hosted by Tekunda. It handles code writing, quality checks, and PR creation all within the user&rsquo;s GitHub Actions environment without sending any source or data to Tekunda&rsquo;s servers. The action is triggered by Delivery Autopilot through signed instructions and can be set up via either the Delivery Autopilot GitHub App or manually adding a workflow configuration file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runner-dist synced from AutoPilot 47dbe7d94693. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>go-skeptic</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/go-skeptic/</link><pubDate>Thu, 27 Aug 2026 17:36:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/go-skeptic/</guid><description>Version updated for https://github.com/TGPSKI/skeptic to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary skeptic is a local repository trust auditor designed to detect structural trust boundary vulnerabilities that enable cascading supply chain compromise. It targets attack-enabling conditions rather than artifacts, offering a comprehensive view of vulnerability surfaces in CI/CD pipelines and agentic tooling. The action automates the scanning process using a standardized rule set and provides mechanisms for ingesting threat intelligence and managing a threat artifact corpus.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TGPSKI/skeptic">https://github.com/TGPSKI/skeptic</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-skeptic">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>skeptic</code> is a local repository trust auditor designed to detect structural trust boundary vulnerabilities that enable cascading supply chain compromise. It targets attack-enabling conditions rather than artifacts, offering a comprehensive view of vulnerability surfaces in CI/CD pipelines and agentic tooling. The action automates the scanning process using a standardized rule set and provides mechanisms for ingesting threat intelligence and managing a threat artifact corpus.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="detection">Detection</h3>
<ul>
<li>Remove <code>POL-GHA-001</code>; <code>SCM-TRUST-001</code> is now the canonical mutable GitHub
Action reference detection (#64).</li>
<li>Move <code>CI-PRT-001</code> and <code>CI-PRT-002</code> from unconditional line patterns to
workflow-level checks that require a privileged trigger plus unsafe checkout,
repository-code execution, risky commands, or write permissions (#90).</li>
<li>Restrict <code>POL-CLOUDID-001</code> wildcard matching to OIDC trust-policy claims, and
scope <code>CLOUD-ID-001</code> to IAM and RBAC policy paths and context (#91, #64).</li>
</ul>
<h3 id="infrastructure">Infrastructure</h3>
<ul>
<li>Roll up co-located duplicate findings under a primary result with
<code>related_rule_ids</code>, and score only the rolled-up set. Correlations are
suppressed when all of their constituent findings are waived (#63).</li>
<li>Record stable finding identities in file-pinned waivers. Waiver refreshes now
stop for review when a file introduces a new finding while allowing unchanged
accepted finding sets to be re-pinned mechanically (#100).</li>
<li>Make release preparation select a successful CI run for the release commit
instead of failing on a newer label-triggered skipped run.</li>
</ul>
<h3 id="cli">CLI</h3>
<ul>
<li>Add <code>--sarif-base-path</code>, defaulting to the detected Git repository root, and
emit repository-relative SARIF artifact URIs with <code>%SRCROOT%</code> metadata. SARIF
tool links now derive from module build metadata (#62).</li>
<li>Give every subcommand a structured help header with a synopsis and runnable
example (#71).</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>Document skeptic as a scanner, threat-intelligence pipeline, and repair-eval
oracle; add an audience-oriented documentation index, repair corpus guide,
and adjacent-tool comparison (#70).</li>
</ul>
]]></content:encoded></item><item><title>Deploy via Uncloud</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/deploy-via-uncloud/</link><pubDate>Thu, 27 Aug 2026 17:35:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/deploy-via-uncloud/</guid><description>Version updated for https://github.com/thatskyapplication/uncloud-action to version v1.2.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action thatskyapplication/uncloud-action deploys Docker images using the Uncloud service. It automates the deployment process by handling image building, pushing to a container registry, and deploying it to a remote server via SSH. The action supports both full deployments with configuration files and push-only operations for pushing an image directly without deploying it.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thatskyapplication/uncloud-action">https://github.com/thatskyapplication/uncloud-action</a></strong> to version <strong>v1.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-via-uncloud">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>thatskyapplication/uncloud-action</code> deploys Docker images using the Uncloud service. It automates the deployment process by handling image building, pushing to a container registry, and deploying it to a remote server via SSH. The action supports both full deployments with configuration files and push-only operations for pushing an image directly without deploying it.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/thatskyapplication/uncloud-action/compare/v1.2.2...v1.2.3">https://github.com/thatskyapplication/uncloud-action/compare/v1.2.2...v1.2.3</a></p>
]]></content:encoded></item><item><title>Deploy to Laravel Forge Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/deploy-to-laravel-forge-action/</link><pubDate>Thu, 27 Aug 2026 17:34:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/deploy-to-laravel-forge-action/</guid><description>Version updated for https://github.com/the-trybe/deploy-to-laravel-forge to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of deploying a Laravel application to Laravel Forge using a declarative YAML configuration file. It solves the problem of managing and deploying Laravel applications on servers hosted by Laravel Forge with minimal manual intervention. The action provides key capabilities such as setting up site configurations, installing dependencies, running custom scripts, and managing background processes, all through user-defined configurations in a .yaml file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/the-trybe/deploy-to-laravel-forge">https://github.com/the-trybe/deploy-to-laravel-forge</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-to-laravel-forge-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of deploying a Laravel application to Laravel Forge using a declarative YAML configuration file. It solves the problem of managing and deploying Laravel applications on servers hosted by Laravel Forge with minimal manual intervention. The action provides key capabilities such as setting up site configurations, installing dependencies, running custom scripts, and managing background processes, all through user-defined configurations in a <code>.yaml</code> file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fix: sites beyond the first page (30 per page, cursor-paginated) were never fetched by get_all_sites(), causing the action to attempt re-creating already-existing sites and fail with a 422.</p>
]]></content:encoded></item><item><title>ghstats-cards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/ghstats-cards/</link><pubDate>Thu, 27 Aug 2026 17:33:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/ghstats-cards/</guid><description>Version updated for https://github.com/tiennm99/ghstats to version v1.7.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ghstats is a GitHub Action that generates SVG cards summarizing a GitHub user’s profile. It fetches data and renders various charts including repo languages, commit language trends, productivity metrics, and streaks, all of which can be embedded in the user’s README. The action supports 64 themes for customization.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tiennm99/ghstats">https://github.com/tiennm99/ghstats</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ghstats-cards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>ghstats</code> is a GitHub Action that generates SVG cards summarizing a GitHub user&rsquo;s profile. It fetches data and renders various charts including repo languages, commit language trends, productivity metrics, and streaks, all of which can be embedded in the user&rsquo;s README. The action supports 64 themes for customization.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat(card): show seven repos on the top-starred card (0ce5d66)</li>
<li>chore(demo): regenerate gallery (4b635fd)</li>
<li>feat: let commits-per-repo 0 mean every commit (724990a)</li>
<li>docs: show include_org_repos in the runnable examples (d49f730)</li>
<li>chore(demo): regenerate gallery (44f8bf9)</li>
<li>fix(github): split a saturated quarter by month to recover dropped repos (d6ac8c3)</li>
<li>chore(demo): regenerate gallery (9365c98)</li>
<li>chore(demo): render records card and count org repos (55f66d6)</li>
<li>feat: count org repos and fix contribution-window truncation (939fcdc)</li>
<li>chore(demo): regenerate gallery (9f7c16f)</li>
</ul>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/compose-lint/</link><pubDate>Thu, 27 Aug 2026 17:32:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.26.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action performs security-focused linting on Docker Compose files to identify and fix potential vulnerabilities such as privilege escalation, network exposure, supply chain issues, file and credential leaks. It automates the detection and correction of these problems before they reach production. The action is useful for ensuring that any real-world Docker Compose files are secure before deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.26.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action performs security-focused linting on Docker Compose files to identify and fix potential vulnerabilities such as privilege escalation, network exposure, supply chain issues, file and credential leaks. It automates the detection and correction of these problems before they reach production. The action is useful for ensuring that any real-world Docker Compose files are secure before deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>--explain</code> now pages through a pager on an interactive terminal</strong>
(<a href="docs/adr/034-explain-pages-on-a-tty.md">ADR-034</a>). Rule docs have grown
past 100 lines, so a terminal dump scrolled the directive and rationale
out of view instantly. On a TTY the doc now goes through <code>less -RFX</code>
(<code>PAGER</code> overrides the command; <code>--no-pager</code>, <code>NO_PAGER</code>, or <code>TERM=dumb</code>
disables it; a missing pager binary — e.g. the distroless image under
<code>docker run -t</code> — falls back to the plain dump). Piped, redirected, and
CI output is byte-identical to before: paging engages only when stdout
is a TTY. The default pager labels its controls in the status line
(<code>CL-XXXX · Space next · b back · q quit</code>) instead of less&rsquo;s bare <code>:</code>,
and a pager that exits nonzero (busybox <code>less</code> rejecting the flags)
falls back to the plain dump rather than swallowing the doc.</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/wails3-build-action/</link><pubDate>Thu, 27 Aug 2026 17:30:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building and packaging of Wails.io applications using Go, Node.js, pnpm, or Deno. It builds binaries for various platforms (Windows, macOS, Linux) and optionally uploads them to GitHub releases on tagged builds. The action handles configuration via inputs such as Go version, Wails version, build name, platform, caching, and packaging options, with support for customizing Node.js, pnpm, and Deno configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building and packaging of Wails.io applications using Go, Node.js, pnpm, or Deno. It builds binaries for various platforms (Windows, macOS, Linux) and optionally uploads them to GitHub releases on tagged builds. The action handles configuration via inputs such as Go version, Wails version, build name, platform, caching, and packaging options, with support for customizing Node.js, pnpm, and Deno configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Lachesis Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/lachesis-security-scan/</link><pubDate>Thu, 27 Aug 2026 17:30:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/lachesis-security-scan/</guid><description>Version updated for https://github.com/UnboundCompute/lachesis-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action builds a compiler-precise code property graph of your repo, traces untrusted input to dangerous sinks, and automates security auditing by emitting reviewable SARIF from your own runner. It identifies missing authorization checks in sibling functions that reach the same sink, providing inline comments on pull requests when enabled.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/UnboundCompute/lachesis-action">https://github.com/UnboundCompute/lachesis-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lachesis-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action builds a compiler-precise code property graph of your repo, traces untrusted input to dangerous sinks, and automates security auditing by emitting reviewable SARIF from your own runner. It identifies missing authorization checks in sibling functions that reach the same sink, providing inline comments on pull requests when enabled.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Track the unified Lachesis 0.3.0 command line: the graph build now runs
<code>lachesis build</code> and the census runs <code>lachesis candidates</code>, replacing the
per-verb <code>lachesis-analyze</code> / <code>lachesis-candidates</code> console scripts that 0.3.0
collapsed into subcommands of a single <code>lachesis</code> entrypoint.</li>
<li>Build and stage the native analysis kernel during engine install. From Lachesis
0.3.0 the query dataflow tier is materialized from a native binary sidecar with no
in-process Python enrichment fallback, so the kernel must be present in the
installed package; the install step now runs <code>tools/stage_native.py --build</code>.</li>
<li>Drop the inert <code>LACHESIS_QUERY_EPHEMERAL_ENRICH</code> export from the SARIF step and the
<code>--prune</code> default from <code>analyze-args</code>: 0.3.0&rsquo;s query no longer re-enriches in
process, and <code>lachesis build</code> prunes by default (pass <code>--no-prune</code> to retain
lexical records).</li>
<li>Pull a pinned, prebuilt <code>libclang</code> (clang 17) from PyPI during install and point
the engine at it with <code>LIBCLANG_PATH</code>. The native C frontend loads libclang at
runtime and targets the clang 17 API; relying on a runner&rsquo;s ambient libclang risks
loading an older one, where a 17-only entry point becomes a null call and the
frontend segfaults. Pinning makes the C frontend deterministic across runners.</li>
<li>Run the graph query from the graph&rsquo;s own directory. <code>python -m lachesis.cli.query</code>
prepends the working directory to <code>sys.path</code>, so scanning a checkout that itself
contains a <code>lachesis/</code> package (the engine dogfooding its own source) imported the
un-built source tree instead of the installed engine and reported its staged native
kernel as missing. Querying from the graph directory resolves the installed engine.</li>
<li>Surface the query engine&rsquo;s own stderr when a query fails, instead of a bare exit
code, so an engine-side error (missing sidecar, load failure) is diagnosable from
the Action log.</li>
<li>Pin development defaults to the reviewed Lachesis <code>v0.3.0</code> release.</li>
</ul>
]]></content:encoded></item><item><title>Vaara Policy Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/vaara-policy-check/</link><pubDate>Thu, 27 Aug 2026 17:28:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/vaara-policy-check/</guid><description>Version updated for https://github.com/vaaraio/vaara to version v1.78.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of verifying and auditing autonomous actions. It helps in checking the receipts to ensure they are verifiable, tamper-evident, and compliant with policies. The action provides a framework for risk-scoring governed functions before execution, ensuring that only authorized actions proceed. It also supports exporting trail records for third-party verification, making it easier to audit and track autonomous decisions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaaraio/vaara">https://github.com/vaaraio/vaara</a></strong> to version <strong>v1.78.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vaara-policy-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of verifying and auditing autonomous actions. It helps in checking the receipts to ensure they are verifiable, tamper-evident, and compliant with policies. The action provides a framework for risk-scoring governed functions before execution, ensuring that only authorized actions proceed. It also supports exporting trail records for third-party verification, making it easier to audit and track autonomous decisions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1780---2026-08-27">[1.78.0] - 2026-08-27</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><code>MODIFY</code>, <code>STEP_UP</code> and <code>DEFER</code> join <code>ALLOW</code>, <code>DENY</code> and <code>ESCALATE</code>, which covers the decision vocabulary the AARM Core registry asks for under R4. That registry names five and <code>Decision</code> now has six, because <code>ESCALATE</code> stays exactly as it was and <code>STEP_UP</code> and <code>DEFER</code> refine it rather than replace it.</p>
<p>The three new names do not reach the signed decision record, and that is deliberate rather than a shortcut. The record&rsquo;s verdict enum is a closed set of three, and it is closed inside a checker this repository publishes for outside parties to run: <code>tests/vectors/record_set_v0/_check_independent.py</code> grades a record carrying any other verdict as non-conforming. Renaming <code>escalate</code> to <code>step_up</code> would have invalidated published vectors and made the scoping text of results rows that cannot be edited become false. So the refinements are policy-layer names that project onto the coarse three, in the same table shape that already maps <code>deny</code> to <code>block</code> and <code>review</code> and <code>refer</code> to <code>escalate</code>.</p>
<p><code>STEP_UP</code> and <code>DEFER</code> are holds and record <code>escalate</code>. <code>MODIFY</code> records <code>deny</code>, because the arguments it was asked about do not run. When a policy proposes different arguments they come back on <code>InterceptionResult.modified_parameters</code>, the caller resubmits them, and that resubmission is scored and recorded on its own. Two records, both true, each bound to the arguments it actually decided. No decision record ever says <code>allow</code> against arguments other than the ones that executed.</p>
<p><code>InterceptionResult.decision</code> keeps returning the coarse word and <code>decision_detail</code> carries the refinement. Eleven call sites across the framework integrations branch on <code>decision == &quot;escalate&quot;</code> or <code>== &quot;deny&quot;</code> to decide whether to raise, in <code>langchain.py</code>, <code>openai_agents.py</code>, <code>claude_code_hooks.py</code>, <code>mcp_server.py</code> and <code>_infer_proxy_gate.py</code>. A finer word arriving there would have missed every one of those branches and read as a fall-through, which is a fail-open in precisely the code that exists to stop an action.</p>
<p><code>allowed</code> is still true for <code>allow</code> and nothing else. All three new decisions are holds at the moment the gate returns, so no relying party has a new rule to learn.</p>
</li>
<li>
<p><code>decision_made</code> audit records carry <code>decision_detail</code> and, for a modify, <code>modified_parameters</code>. Both keys are omitted when absent, so a record written without a refinement is byte-identical to one written before the vocabulary existed and its hash does not move. <code>decision</code> itself stays inside the documented three-value enum.</p>
<p><code>record_decision</code> checks the refinement against the decision it claims to explain and drops it if the two disagree. The pipeline never passes an inconsistent pair, but the method is reachable from custom policy code, and a record saying <code>allow</code> with a <code>modify</code> refinement would be hash-chained evidence that contradicts itself.</p>
</li>
<li>
<p>A grant can carry a qualified electronic attestation of attributes. <code>mandate</code> is a new optional block on the brokered credential, covered by the existing grant signature.</p>
<p>Every actor claim on a record today is self-asserted. <code>asserted.iss</code> and <code>.sub</code> are strings the issuer writes about itself, and a verifier can check the signature and recompute the args commitment without ever being able to check that the issuer is the organisation it names. A qualified attestation is an eIDAS trust service that a supervised, audited provider issues, and an organisation cannot issue one about itself by construction, so that one claim comes to rest on a public register rather than on the producer&rsquo;s word.</p>
<p>The block is optional and adds nothing to the signed preimage when absent, so a grant minted without one signs exactly the bytes it signed before the field existed. Every published grant vector still verifies. All four sub-objects are closed schemas, and <code>boundVia</code> values the specification reserves are rejected rather than tolerated.</p>
<p><code>verify_mandate_binding</code> recomputes SHA-256 over the decoded attestation and compares it to the commitment. Two decisions there are worth stating because a disagreement between two verifiers over a valid record is expensive to find later. The digest is over the bytes the provider issued, not over the base64 that carries them. And a withheld attestation verifies, because the digest-only path is a supported shape and nothing carried can disagree with the commitment; a caller that needs the bytes present checks for them itself, since &ldquo;not carried&rdquo; and &ldquo;carried and wrong&rdquo; are different conditions.</p>
<p>Resolving the provider against the EU trusted lists is the next piece and is not in this change. See <code>docs/design/qeaa-attribute-binding-spec.md</code>, which now records what is built and what is not.</p>
</li>
<li>
<p><code>decision_vocabulary_v0</code>, a conformance suite that lets an outside party check the projection instead of taking it on trust. The corpus grows to 47 suites and 88 cases.</p>
<p>Thirteen cases. Eight are what Vaara produces, generated by driving the real pipeline rather than written to match the checker, with record ids and timestamps from fixed sequences so the bytes are reproducible and every hash computed by the production path. Five are what a gate without the projection would write. Four are committed as non-conforming: the refinement used as the verdict itself, <code>allow</code> standing beside a <code>modify</code>, a retry claiming a modify as its parent while carrying the arguments that modify refused, and a decision reason edited after the fact. The fifth is a modify nobody retried, which is advisory and still conforms, because a caller is allowed to give up and a record that says so is not wrong.</p>
<p>The point of committing failures is that a corpus where nothing ever fails says nothing about whether the checker can tell. The checker imports no Vaara and needs no optional dependency beyond the standard library, and it recomputes every record hash and every chain link from the bytes rather than trusting the committed ones.</p>
<p><code>scripts/build_decision_vocabulary_vectors.py --check</code> regenerates and fails on any diff, so the vectors cannot drift away from the code that produced them.</p>
</li>
<li>
<p><code>vaara.audit.hcs27</code> publishes a Vaara trail head as an HCS-27 Transparency Log Checkpoint. Standard library only. <code>hcs27_checkpoint_v0</code> joins the corpus, which grows to 48 suites.</p>
<p>HCS-27 anchors an append-only log to a Hedera Consensus Service topic by publishing periodic Merkle checkpoints, and it says in its own words that it does not define log entry schemas. That sentence is the seam. HCS-27 supplies the commitment that a log only ever grew; Vaara supplies the record saying a specific act was permitted, by whom, under what scope. A stranger checks inclusion with a stock HCS-27 client that imports no Vaara, then re-derives <code>record_hash</code> to check the chain.</p>
<p>There is no Merkle implementation in the new module, because <code>vaara.attestation.transparency_log</code> already was one. It turns out to be byte-identical to the HCS-27 Merkle v1 profile, established by running the upstream <code>standards-sdk/src/hcs-27/merkle.ts</code> against it rather than by reading it. Roots agree for every tree size 0 to 64 and at every power-of-two boundary to 1025, and 110 Vaara proofs verify unmodified in the upstream <code>verifyInclusionProof</code> and <code>verifyConsistencyProof</code>. The two build the tree differently and arrive at the same root: Vaara folds bottom up and promotes an unpaired node, HCS-27 splits at the largest power of two below n and recurses.</p>
<p><code>ensure_ascii=False</code> is load-bearing and is the rule that silently breaks interoperability. The leaf preimage is JCS, and Python&rsquo;s default escapes every umlaut to <code>\uXXXX</code>, yielding a leaf hash no other implementation reproduces. Finnish text makes that a certainty rather than an edge case, so the vector carries an umlaut in <code>agentId</code> and a regression breaks that test first. Floats are rejected outright rather than emitted, since Python writes <code>1.0</code> where JavaScript writes <code>1</code>.</p>
<p>This canonicalisation is not the one <code>AuditRecord.compute_hash</code> uses, which keeps the <code>ensure_ascii=True</code> default. The chain digest and the checkpoint leaf are separate functions over separate inputs on purpose, so that every trail already on disk stays verifiable.</p>
<p>The entry carries identity and <code>recordHash</code>, not <code>data</code> and not <code>regulatory_articles</code>. Both stay committed through <code>recordHash</code>, so anyone holding the record can still prove what was in it, while a public topic carries neither the payload nor Vaara&rsquo;s compliance attribution, and caller-shaped values stay out of the canonicalisation path.</p>
<p>Two limits are recorded rather than worked around. <code>metadata.type</code> is typed as the literal <code>ans-checkpoint-v1</code> upstream, so a standard that delegates entry schemas to consuming profiles gives a second profile no way to name itself; Vaara emits the accepted literal and carries its own identity in <code>stream.registry</code>, in the declared <code>log.leaf</code> formula and in a passthrough key. HCS-1 overflow inscription is not implemented, because a checkpoint measures 461 bytes against Hedera&rsquo;s 1024-byte cap, and the builder raises rather than emit an oversized message.</p>
</li>
</ul>
]]></content:encoded></item><item><title>npm release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/npm-release/</link><pubDate>Thu, 27 Aug 2026 17:27:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/npm-release/</guid><description>Version updated for https://github.com/vitalets/npm-release to version v2.1.1.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of releasing an npm package by performing several key tasks:
It updates the package.json with a specified channel and version increment. It generates and appends changelog entries based on a predefined format in CHANGELOG.md. It commits, tags, and pushes the release commit to the repository. It publishes the package to npm using OIDC trusted publishing without requiring an npm token. It creates a GitHub Release with the extracted changelog notes for easy tracking of changes. The action is designed to be integrated into workflows that handle package releases, ensuring that the process is automated and secure. What’s Changed Use next as the prerelease channel in workflow examples, documentation, and tests Document that prereleases published to the next dist-tag are installable as package-name@next</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vitalets/npm-release">https://github.com/vitalets/npm-release</a></strong> to version <strong>v2.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/npm-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of releasing an npm package by performing several key tasks:</p>
<ol>
<li>It updates the <code>package.json</code> with a specified channel and version increment.</li>
<li>It generates and appends changelog entries based on a predefined format in <code>CHANGELOG.md</code>.</li>
<li>It commits, tags, and pushes the release commit to the repository.</li>
<li>It publishes the package to npm using OIDC trusted publishing without requiring an npm token.</li>
<li>It creates a GitHub Release with the extracted changelog notes for easy tracking of changes.
The action is designed to be integrated into workflows that handle package releases, ensuring that the process is automated and secure.</li>
</ol>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Use <code>next</code> as the prerelease channel in workflow examples, documentation, and tests</li>
<li>Document that prereleases published to the <code>next</code> dist-tag are installable as <code>package-name@next</code></li>
</ul>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/rustscript-action/</link><pubDate>Thu, 27 Aug 2026 17:26:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.6.14.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that allows developers to write helper scripts in Rust, run them like shell scripts without the need for compilation. It interprets a practical subset of Rust, making it fast to execute and validate scripts instantly. RustScript supports a wide range of features, including functions, closures, structs, enums, loops, iterators, and more. It also has built-in support for std libraries and many popular crates through bridges. However, it does not support std::thread, static mut, lifetimes, or generic bounds at runtime.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.6.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a tool that allows developers to write helper scripts in Rust, run them like shell scripts without the need for compilation. It interprets a practical subset of Rust, making it fast to execute and validate scripts instantly. RustScript supports a wide range of features, including functions, closures, structs, enums, loops, iterators, and more. It also has built-in support for std libraries and many popular crates through bridges. However, it does not support <code>std::thread</code>, <code>static mut</code>, lifetimes, or generic bounds at runtime.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.6.13...v0.6.14">https://github.com/VladasZ/rustscript/compare/v0.6.13...v0.6.14</a></p>
]]></content:encoded></item><item><title>AlmaLinux-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/almalinux-vm/</link><pubDate>Thu, 27 Aug 2026 17:25:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/almalinux-vm/</guid><description>Version updated for https://github.com/vmactions/almalinux-vm to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Run GitHub CI in AlmaLinux action automates the process of running CI pipelines on AlmaLinux virtual machines. It solves the problem of setting up and managing complex CI environments across multiple platforms, including Ubuntu, Windows, and MacOS, by providing a standardized approach to running builds and tests on AlmaLinux. The action supports various release versions and architectures, offering seamless integration with GitHub workflows without requiring manual configuration or installation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/almalinux-vm">https://github.com/vmactions/almalinux-vm</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/almalinux-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>Run GitHub CI in AlmaLinux</code> action automates the process of running CI pipelines on AlmaLinux virtual machines. It solves the problem of setting up and managing complex CI environments across multiple platforms, including Ubuntu, Windows, and MacOS, by providing a standardized approach to running builds and tests on AlmaLinux. The action supports various release versions and architectures, offering seamless integration with GitHub workflows without requiring manual configuration or installation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/almalinux-vm/commits/v1.0.0">https://github.com/vmactions/almalinux-vm/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Alpine-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/alpine-vm/</link><pubDate>Thu, 27 Aug 2026 17:23:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/alpine-vm/</guid><description>Version updated for https://github.com/vmactions/alpine-vm to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action runs CI on Alpine Linux. It allows users to easily set up continuous integration (CI) pipelines for their projects using Alpine, which is commonly used in containers and microservices environments. The action automates the setup of an Alpine environment by installing necessary packages and running commands within it. Users can specify environment variables and scripts to be executed in the VM.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/alpine-vm">https://github.com/vmactions/alpine-vm</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/alpine-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action runs CI on Alpine Linux. It allows users to easily set up continuous integration (CI) pipelines for their projects using Alpine, which is commonly used in containers and microservices environments. The action automates the setup of an Alpine environment by installing necessary packages and running commands within it. Users can specify environment variables and scripts to be executed in the VM.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/alpine-vm/commits/v1.0.0">https://github.com/vmactions/alpine-vm/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Debian-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/debian-vm/</link><pubDate>Thu, 27 Aug 2026 17:22:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/debian-vm/</guid><description>Version updated for https://github.com/vmactions/debian-vm to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action allows users to run CI jobs on Debian-based virtual machines. It supports various Debian releases and architectures including x86_64, aarch64, riscv64, and ppc64le. The action is AI-ready and can generate CI workflows based on natural language descriptions, automating the selection of VMs, toolchains, and configurations for users. It supports pushing changes to source code and synchronizing it with the virtual machine.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/debian-vm">https://github.com/vmactions/debian-vm</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/debian-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action allows users to run CI jobs on Debian-based virtual machines. It supports various Debian releases and architectures including x86_64, aarch64, riscv64, and ppc64le. The action is AI-ready and can generate CI workflows based on natural language descriptions, automating the selection of VMs, toolchains, and configurations for users. It supports pushing changes to source code and synchronizing it with the virtual machine.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/debian-vm/commits/v1.0.0">https://github.com/vmactions/debian-vm/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Haiku-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/haiku-vm/</link><pubDate>Thu, 27 Aug 2026 17:21:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/haiku-vm/</guid><description>Version updated for https://github.com/vmactions/haiku-vm to version v1.1.5.
This action is used across all versions by 65 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running CI tests on Haiku, a lightweight Unix-like operating system. It supports different releases and architectures, including x86_64 and riscv64. The action uses AnyVM to build images of Haiku for these environments and automatically generates a GitHub Actions workflow based on user input. Users can specify environment variables and commands to run in the VM.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/haiku-vm">https://github.com/vmactions/haiku-vm</a></strong> to version <strong>v1.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>65</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/haiku-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running CI tests on Haiku, a lightweight Unix-like operating system. It supports different releases and architectures, including x86_64 and riscv64. The action uses AnyVM to build images of Haiku for these environments and automatically generates a GitHub Actions workflow based on user input. Users can specify environment variables and commands to run in the VM.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Haiku R1/beta6, and three more sync methods</p>
<p>The default guest release is now R1/beta6. A workflow that does not set
a release input gets it from this version on.</p>
<p>Folder sync grows from two backends to five</p>
<pre><code>R1/beta6 offers rsync, scp, nfs, sshfs and tar. Before this, only
rsync and scp were available. Choose one with

    sync: &quot;nfs&quot;

All five pass in this action's own CI against a beta6 guest, along
with the cache-after-prepare and custom-shell paths.
</code></pre>
<p>Why beta6 matters beyond the version number</p>
<pre><code>On R1/beta5, installing packages from inside the VM had stopped
working. Upstream retired the HaikuPorts branch repository for
that release -- its package index answers with an empty 2-byte
file -- so pkgman had nothing to resolve against. The beta5 image
kept working only because the builder baked its packages in from a
pinned snapshot, and that covered just what the builder installed,
not what a workflow asks for.

On R1/beta6 the repository is live again, a 2.4 MB index, and the
image is built the ordinary way with no pinned packages anywhere.
A prepare step can run pkgman install again.
</code></pre>
<p>R1/beta5 is still selectable</p>
<pre><code>    release: &quot;r1beta5&quot;

It is unchanged -- rsync and scp only, from haiku-builder v2.0.2 --
and it is no longer part of this action's test matrix.
</code></pre>
<p>Under the hood</p>
<pre><code>The beta6 image comes from haiku-builder v2.0.3, and the runtime
moves to anyvm v0.6.6.
</code></pre>
<p>Full Changelog: <a href="https://github.com/vmactions/haiku-vm/compare/v1.1.4...v1.1.5">https://github.com/vmactions/haiku-vm/compare/v1.1.4...v1.1.5</a></p>
]]></content:encoded></item><item><title>HardenedBSD-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/hardenedbsd-vm/</link><pubDate>Thu, 27 Aug 2026 17:20:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/hardenedbsd-vm/</guid><description>Version updated for https://github.com/vmactions/hardenedbsd-vm to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The HardenedBSD VM action automatically sets up and runs CI on HardenedBSD, supporting various architectures and features like serial console access. It automates the process of building and running tests in a hardened environment using AnyVM.org and vmactions-skill for AI-driven configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/hardenedbsd-vm">https://github.com/vmactions/hardenedbsd-vm</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hardenedbsd-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The HardenedBSD VM action automatically sets up and runs CI on HardenedBSD, supporting various architectures and features like serial console access. It automates the process of building and running tests in a hardened environment using AnyVM.org and vmactions-skill for AI-driven configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/hardenedbsd-vm/commits/v1.0.0">https://github.com/vmactions/hardenedbsd-vm/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>OPNsense-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/opnsense-vm/</link><pubDate>Thu, 27 Aug 2026 17:19:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/opnsense-vm/</guid><description>Version updated for https://github.com/vmactions/opnsense-vm to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action allows users to run CI/CD tests in OPNsense, a popular open-source firewall and router platform. It simplifies the process of automating test cases across different releases and architectures by leveraging AI coding agents, such as Claude Code or Codex, which generate tailored GitHub Actions workflows for specific requirements. The action supports Ubuntu, Windows, and MacOS, but does not directly support OPNsense’s unique architecture due to its reliance on /conf/config.xml and UFS filesystem.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/opnsense-vm">https://github.com/vmactions/opnsense-vm</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/opnsense-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action allows users to run CI/CD tests in OPNsense, a popular open-source firewall and router platform. It simplifies the process of automating test cases across different releases and architectures by leveraging AI coding agents, such as Claude Code or Codex, which generate tailored GitHub Actions workflows for specific requirements. The action supports Ubuntu, Windows, and MacOS, but does not directly support OPNsense&rsquo;s unique architecture due to its reliance on <code>/conf/config.xml</code> and UFS filesystem.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/opnsense-vm/commits/v1.0.0">https://github.com/vmactions/opnsense-vm/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/kover-report-action/</link><pubDate>Thu, 27 Aug 2026 17:17:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.39.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Kover Report Action is a GitHub Action designed to generate and report code coverage from Kover XML reports in Kotlin/Android projects with multi-module support. It supports both Gradle command-based and glob pattern module discovery, allows configurable thresholds per module type and name, integrates with PR comments for automatic updates, tracks coverage history using visual ASCII graphs and trend indicators, and exports coverage data for further use.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v3.1.39</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Kover Report Action is a GitHub Action designed to generate and report code coverage from Kover XML reports in Kotlin/Android projects with multi-module support. It supports both Gradle command-based and glob pattern module discovery, allows configurable thresholds per module type and name, integrates with PR comments for automatic updates, tracks coverage history using visual ASCII graphs and trend indicators, and exports coverage data for further use.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3.1.39: PR #178 - chore(deps): update dependency @biomejs/biome to v2.5.8</p>
]]></content:encoded></item><item><title>Setup Ndless</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/setup-ndless/</link><pubDate>Thu, 27 Aug 2026 17:16:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/setup-ndless/</guid><description>Version updated for https://github.com/Ziyang-Bai/setup-ndless to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-ndless GitHub Action automates the setup of the Ndless SDK and ARM toolchain on Ubuntu/Linux runners, providing a consistent environment for building projects targeting Nintendo DS consoles. It installs necessary dependencies, caches the installation for reuse across builds, and exports critical environment variables for later steps in the pipeline. The action supports parallel builds and can handle different versions of Ndless through commit references or tags.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Ziyang-Bai/setup-ndless">https://github.com/Ziyang-Bai/setup-ndless</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-ndless">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The setup-ndless GitHub Action automates the setup of the Ndless SDK and ARM toolchain on Ubuntu/Linux runners, providing a consistent environment for building projects targeting Nintendo DS consoles. It installs necessary dependencies, caches the installation for reuse across builds, and exports critical environment variables for later steps in the pipeline. The action supports parallel builds and can handle different versions of Ndless through commit references or tags.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>nitial public release of setup-ndless.</p>
<p>setup-ndless is a composite GitHub Action for installing, caching, and
activating the Ndless SDK and ARM toolchain on Linux runners.</p>
]]></content:encoded></item><item><title>Harmans Code Coverage Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/harmans-code-coverage-report/</link><pubDate>Thu, 27 Aug 2026 08:08:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/harmans-code-coverage-report/</guid><description>Version updated for https://github.com/hrgui/lcov-reporter-action to version v0.2.18-alpha.12.
This action is used across all versions by 7 repositories. Action Type This is a Node action using Node version 12.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action comments a pull request with an HTML test coverage report based on a lcov coverage file generated by another action. It automates the process of sharing test results, helping developers quickly assess code coverage and identify areas needing improvement.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hrgui/lcov-reporter-action">https://github.com/hrgui/lcov-reporter-action</a></strong> to version <strong>v0.2.18-alpha.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>12</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harman-s-code-coverage-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action comments a pull request with an HTML test coverage report based on a lcov coverage file generated by another action. It automates the process of sharing test results, helping developers quickly assess code coverage and identify areas needing improvement.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>v0.2.18-alpha.12 (9b198cd)</li>
<li>Fix assignment to variable (45cc885)</li>
<li>v0.2.18-alpha.11 (75beb2d)</li>
<li>Fix reference to response (6edf6e7)</li>
<li>v0.2.18-alpha.10 (b7526f1)</li>
<li>Simplify file fetching loop (4c67927)</li>
<li>v0.2.18-alpha.9 (6668b90)</li>
<li>Use different method to fetch files (b8a2437)</li>
<li>v0.2.18-alpha.8 (acb967c)</li>
<li>v0.2.18-alpha.7 (74dd039)</li>
</ul>
]]></content:encoded></item><item><title>offsec-ai Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/offsec-ai-security-scanner/</link><pubDate>Thu, 27 Aug 2026 08:06:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/offsec-ai-security-scanner/</guid><description>Version updated for https://github.com/Htunn/offsec-ai to version v2.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action described in the README automates the testing of AI/LLM endpoints and infrastructure using the offsec-ai toolkit. It focuses on security testing, specifically identifying vulnerabilities like missing authentication, unresolved variables, and secrets, as well as actively attacking known CVEs using the Model Context Protocol (MCP). The action is designed for authorized red-team engagements and requires explicit permission to use against systems it does not own or have permission to test.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Htunn/offsec-ai">https://github.com/Htunn/offsec-ai</a></strong> to version <strong>v2.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/offsec-ai-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action described in the README automates the testing of AI/LLM endpoints and infrastructure using the <code>offsec-ai</code> toolkit. It focuses on security testing, specifically identifying vulnerabilities like missing authentication, unresolved variables, and secrets, as well as actively attacking known CVEs using the Model Context Protocol (MCP). The action is designed for authorized red-team engagements and requires explicit permission to use against systems it does not own or have permission to test.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add A2A protocol security support (v2.6.0) (1b99a1b)</li>
<li>fix: define OUTPUT_ARGS before use; -o was silently dropped (v2.5.9) (889e688)</li>
<li>chore: replace all example.com targets with simpleportchecker.com (676106d)</li>
<li>fix: &ndash;format not -f for ai-owasp-scan; use simpleportchecker target (v2.5.8) (504b6e8)</li>
<li>fix: skip &ndash;timeout for ai-owasp-scan which does not support it (v2.5.7) (67a28cd)</li>
<li>chore: use Gemini public endpoint in ai-owasp-scan job (6a13857)</li>
<li>fix: use case statement for format flag routing; no more grep substring match (v2.5.6) (1a8ac41)</li>
<li>fix: per-command format flag; base64 report-json; bump to v2.5.5 (813d327)</li>
<li>chore: update offsec-ai-action.yml to use v2.5.4 (c9ebc12)</li>
<li>fix: switch action to GEMINI_API_KEY; remove secrets expression from action.yml (9bbe4cc)</li>
</ul>
]]></content:encoded></item><item><title>EnvContract for Vercel</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/envcontract-for-vercel/</link><pubDate>Thu, 27 Aug 2026 08:05:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/envcontract-for-vercel/</guid><description>Version updated for https://github.com/JordanCoin/envcontract to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary EnvContract is a GitHub Action that ensures that any environment variables used in your Vercel deployment are correctly configured. It checks if the code requires specific environment variables and compares them with the ones configured in your Vercel project, failing the PR if there’s a mismatch. The action provides detailed reports on missing or incorrect configurations and can be integrated into workflows to ensure your deployments are robust.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JordanCoin/envcontract">https://github.com/JordanCoin/envcontract</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/envcontract-for-vercel">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>EnvContract is a GitHub Action that ensures that any environment variables used in your Vercel deployment are correctly configured. It checks if the code requires specific environment variables and compares them with the ones configured in your Vercel project, failing the PR if there&rsquo;s a mismatch. The action provides detailed reports on missing or incorrect configurations and can be integrated into workflows to ensure your deployments are robust.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Marketplace listing release. Same engine as v1.0.0 (1,255 tests); the action.yml description was shortened to meet the Marketplace limit.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">JordanCoin/envcontract@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">vercel_token</span>: <span style="color:#ae81ff">${{ secrets.VERCEL_TOKEN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">target</span>: <span style="color:#ae81ff">preview</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>DeepSeek Harness for GitHub</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/deepseek-harness-for-github/</link><pubDate>Thu, 27 Aug 2026 08:04:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/deepseek-harness-for-github/</guid><description>Version updated for https://github.com/Lixiaoyiao/deepseek-harness-action to version v0.8.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of using DeepSeek Harness to review pull requests, issues, and failed CI jobs. It helps maintainers diagnose and fix problems by starting a credential-isolated DSH worker, validating its structured result, and publishing comments or validated changes to trusted repositories. The Action supports various composition modes including native and controlled, allowing for flexible tool management and execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lixiaoyiao/deepseek-harness-action">https://github.com/Lixiaoyiao/deepseek-harness-action</a></strong> to version <strong>v0.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deepseek-harness-for-github">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of using DeepSeek Harness to review pull requests, issues, and failed CI jobs. It helps maintainers diagnose and fix problems by starting a credential-isolated DSH worker, validating its structured result, and publishing comments or validated changes to trusted repositories. The Action supports various composition modes including native and controlled, allowing for flexible tool management and execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Centralizes UTF-8 prefix/suffix primitives across context, agent-loop, GitHub evidence/Gateway, fetch, and command output. Tiny caps terminate, stay within byte limits, preserve code-point boundaries, and do not introduce U+FFFD.</li>
<li>Moves input-only DeepSeek URL protocol/userinfo, exact audited DSH, Docker/OCI reference, and host executable failures into <code>loadInputs()</code> while keeping runtime checks as defense in depth.</li>
<li>Makes <code>dshMode</code> discriminate controlled/native MCP and Plugin configuration types and removes downstream production casts.</li>
<li>Makes public Action input metadata typed and deterministic across <code>action.yml</code>, configuration tables, runtime names/defaults, and the installer subset.</li>
<li>Keeps <code>GitHubAuthorityGateway</code> as the sole authority facade while extracting deadline, revalidation, mutation reconciliation, public text, and receipt helpers.</li>
<li>Adds stable additive tool-denial reason codes with deterministic precedence while preserving human reasons and legacy permission digest/task identity.</li>
<li>Adds <code>ARCHITECTURE.md</code>, INV-001 through INV-005, and a manual/weekly advisory next-DSH compatibility canary.</li>
</ul>
<h2 id="security-and-compatibility">Security and compatibility</h2>
<ul>
<li><code>controlled</code> remains the compatible default; no Controller, DshComposition, Gateway, backend, receipt, queue, validation, or external-effect semantics are widened.</li>
<li>Production remains exact-pinned to the audited DSH <code>0.1.1-rc.2</code> family across 188 locked packages.</li>
<li>No Session/Resume, Action-owned GitHub MCP backend, new GitHub capability, authority widening, or DSH upgrade is included.</li>
<li><code>create-deepseek-harness-action</code> remains independently versioned at <code>0.2.0</code> and keeps its existing formal v0.8.0 Action binding.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li>Release SHA: <code>e6c7955843d870b2ecb71c7966ba26b65a4e479b</code></li>
<li>Frozen candidate: <code>b2c8bfcaede82005b9de061bc6270fb617f08709</code></li>
<li>Release PR: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/pull/208">#208</a></li>
<li>Frozen candidate CI: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32992758001">32992758001</a></li>
<li>Pre-merge Core E2E: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32993069689">32993069689</a></li>
<li>Exact-main CI: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32994011614">32994011614</a></li>
<li>Exact-main Core E2E: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/33000037708">33000037708</a></li>
<li>Local qualification: 69 test files, 833 passed / 2 skipped, coverage thresholds, generated-contract drift, release contract, exact DSH audit, and reproducible <code>dist</code> all passed.</li>
</ul>
<p>The successful Core E2E runs cover controlled/native read-only paths, native ecosystem composition, validation and no-mutation guards, trusted writes, Subagent, Bash, cancellation finalization, structured output, all six typed GitHub operations, cleanup, credential-free checkout, and final immutable binding.</p>
<h2 id="formal-release-smoke">Formal release smoke</h2>
<ul>
<li>v0.8.1 controlled/native tag consumer canary: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/33001314796">33001314796</a></li>
<li>Advisory upstream compatibility canary: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/33001500619">33001500619</a> — no version after <code>0.1.1-rc.2</code> was published, so candidate install/smoke was correctly skipped and production pins were verified unchanged.</li>
</ul>
<h2 id="known-limitations">Known limitations</h2>
<p>Native composition remains experimental and Docker-only. The upstream DSH canary is advisory: it never changes production pins or declares support. Existing image-input, Session/Resume, external GitHub MCP, and hard-cancellation limitations remain documented in SECURITY.md and the configuration guide.</p>
]]></content:encoded></item><item><title>Speccy API review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/speccy-api-review/</link><pubDate>Thu, 27 Aug 2026 08:03:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/speccy-api-review/</guid><description>Version updated for https://github.com/mcclowes/speccy to version speccy-renderer@0.13.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Speccy is an OpenAPI renderer that provides a unified rendering core for React, web, macOS, and Docusaurus interfaces. It automates tasks such as linting and diffing, supports the complete OpenAPI 3.1.1 specification, and offers capabilities like resolving multi-document references. The action helps in maintaining consistency across different platforms and improves development efficiency by providing a single interface for rendering OpenAPI specifications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcclowes/speccy">https://github.com/mcclowes/speccy</a></strong> to version <strong><a href="mailto:speccy-renderer@0.13.1">speccy-renderer@0.13.1</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/speccy-api-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Speccy is an OpenAPI renderer that provides a unified rendering core for React, web, macOS, and Docusaurus interfaces. It automates tasks such as linting and diffing, supports the complete OpenAPI 3.1.1 specification, and offers capabilities like resolving multi-document references. The action helps in maintaining consistency across different platforms and improves development efficiency by providing a single interface for rendering OpenAPI specifications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>
<p><a href="https://github.com/mcclowes/speccy/commit/8b053f31940b938779c4c5cb64279321bb9b0af5"><code>8b053f3</code></a> Thanks <a href="https://github.com/mcclowes">@mcclowes</a>! - Preserve reserved characters in URL-encoded request-body properties when their OpenAPI encoding enables <code>allowReserved</code>.</p>
</li>
<li>
<p>Updated dependencies []:</p>
<ul>
<li><a href="mailto:speccy-core@0.13.1">speccy-core@0.13.1</a></li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>mikebom SBOM Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/mikebom-sbom-action/</link><pubDate>Thu, 27 Aug 2026 08:02:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/mikebom-sbom-action/</guid><description>Version updated for https://github.com/mfahlandt/waybill-action to version v0.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the generation of Software Bill of Materials (SBOM) using the waybill tool. It supports scanning source directories, container images, and multiple ecosystems within monorepos. The action outputs SBOMs in various formats and can include dev dependencies or be run offline without internet access. Users can specify options such as output format, artifact upload, and waybill version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mfahlandt/waybill-action">https://github.com/mfahlandt/waybill-action</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mikebom-sbom-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the generation of Software Bill of Materials (SBOM) using the waybill tool. It supports scanning source directories, container images, and multiple ecosystems within monorepos. The action outputs SBOMs in various formats and can include dev dependencies or be run offline without internet access. Users can specify options such as output format, artifact upload, and waybill version.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mfahlandt/waybill-action/compare/v0.2.0...v0.2.1">https://github.com/mfahlandt/waybill-action/compare/v0.2.0...v0.2.1</a></p>
]]></content:encoded></item><item><title>CRA readiness report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/cra-readiness-report/</link><pubDate>Thu, 27 Aug 2026 08:00:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/cra-readiness-report/</guid><description>Version updated for https://github.com/mmalinowski/cradesk-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The CRA readiness report GitHub Action generates a Cyber Resilience Act (CRA) readiness report from CycloneDX or SPDX SBOMs. It provides insights into the product’s security posture and compliance with the 11 September 2026 reporting obligations, without requiring an account or leaving data on external servers unless specified.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmalinowski/cradesk-action">https://github.com/mmalinowski/cradesk-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cra-readiness-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The CRA readiness report GitHub Action generates a Cyber Resilience Act (CRA) readiness report from CycloneDX or SPDX SBOMs. It provides insights into the product&rsquo;s security posture and compliance with the 11 September 2026 reporting obligations, without requiring an account or leaving data on external servers unless specified.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: Readiness checklist 2026-08-26 (v1.1.0) by @mmalinowski in <a href="https://github.com/mmalinowski/cradesk-action/pull/2">https://github.com/mmalinowski/cradesk-action/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mmalinowski/cradesk-action/compare/v1.0.1...v1.1.0">https://github.com/mmalinowski/cradesk-action/compare/v1.0.1...v1.1.0</a></p>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/run-aer-tests/</link><pubDate>Thu, 27 Aug 2026 07:59:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.39.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aer GitHub Action automates the execution of local Apex tests and provides code coverage reports. It allows developers to run Apex code and unit tests without relying on an org, ensuring faster feedback loops during development. The action supports a wide range of Salesforce features and limits, including SOQL queries, DML operations, governor limits, and standard library utilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.39</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>aer</code> GitHub Action automates the execution of local Apex tests and provides code coverage reports. It allows developers to run Apex code and unit tests without relying on an org, ensuring faster feedback loops during development. The action supports a wide range of Salesforce features and limits, including SOQL queries, DML operations, governor limits, and standard library utilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.39</p>
<ul>
<li>Resolve Relationship Field References Through Flow Interview Record Variables</li>
</ul>
]]></content:encoded></item><item><title>GitHub Backup and Restore</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/github-backup-and-restore/</link><pubDate>Thu, 27 Aug 2026 07:58:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/github-backup-and-restore/</guid><description>Version updated for https://github.com/OmarRao/github-gdrive-backup to version v5.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the backup of all repositories in a user’s organization to their Google Drive. It runs daily at 02:00 UTC via GitHub Actions and provides a live dashboard hosted on GitHub Pages for managing backups, restoring from sessions, and generating reports. The action supports various aspects of repository data, including code, issues, pull requests, releases, wiki, labels, and milestones.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OmarRao/github-gdrive-backup">https://github.com/OmarRao/github-gdrive-backup</a></strong> to version <strong>v5.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-backup-and-restore">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the backup of all repositories in a user&rsquo;s organization to their Google Drive. It runs daily at 02:00 UTC via GitHub Actions and provides a live dashboard hosted on GitHub Pages for managing backups, restoring from sessions, and generating reports. The action supports various aspects of repository data, including code, issues, pull requests, releases, wiki, labels, and milestones.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="github-backup-and-restore--v506">GitHub Backup and Restore — v5.0.6</h2>
<p>Marketplace-ready release of the reusable GitHub Action.</p>
<h3 id="use-in-any-workflow">Use in any workflow</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">OmarRao/github-gdrive-backup@v5</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">github-token</span>:         <span style="color:#ae81ff">${{ secrets.GH_BACKUP_TOKEN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">gdrive-folder-id</span>:     <span style="color:#ae81ff">${{ secrets.GDRIVE_FOLDER_ID }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">google-client-secret</span>: <span style="color:#ae81ff">${{ secrets.GOOGLE_CLIENT_SECRET }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">google-token</span>:         <span style="color:#ae81ff">${{ secrets.GOOGLE_TOKEN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">incremental-mode</span>:     <span style="color:#ae81ff">delta    </span> <span style="color:#75715e"># optional — upload only new git objects</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">mirror-targets</span>:       <span style="color:#ae81ff">s3,b2    </span> <span style="color:#75715e"># optional — 3-2-1 fan-out</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">signing-key</span>:          <span style="color:#ae81ff">${{ secrets.BACKUP_SIGNING_KEY }} </span> <span style="color:#75715e"># optional</span>
</span></span></code></pre></div><h3 id="highlights">Highlights</h3>
<ul>
<li>Back up GitHub repos (code, issues, PRs, releases, wiki, labels, milestones, config) to Google Drive or S3 / Azure / B2.</li>
<li>Delta uploads (git-bundle chain), 3-2-1 fan-out, AES-256 encryption, Ed25519 signed manifests.</li>
<li>Cross-provider restore (GitHub / GitLab / Gitea / local), recovery scorecard, tamper-evident audit log.</li>
<li>Composite action, configurable node-version; emits a JSON summary output.</li>
</ul>
<p>Dual-licensed AGPL-3.0 / commercial — see COMMERCIAL-LICENSE.md.</p>
]]></content:encoded></item><item><title>SkillSeal Agent Skill Linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/skillseal-agent-skill-linter/</link><pubDate>Thu, 27 Aug 2026 07:57:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/skillseal-agent-skill-linter/</guid><description>Version updated for https://github.com/pespinel/SkillSeal to version v0.16.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SkillSeal is an offline-first CLI tool that lints, scores, and routing-tests SKILL.md files, catching syntax errors, vague descriptions, oversized files, dangling file references, security vulnerabilities like rm -rf or hardcoded paths, and portability issues. It helps in ensuring that Agent Skills are well-defined, secure, and portable before they are used in production environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pespinel/SkillSeal">https://github.com/pespinel/SkillSeal</a></strong> to version <strong>v0.16.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skillseal-agent-skill-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SkillSeal is an offline-first CLI tool that lints, scores, and routing-tests SKILL.md files, catching syntax errors, vague descriptions, oversized files, dangling file references, security vulnerabilities like <code>rm -rf</code> or hardcoded paths, and portability issues. It helps in ensuring that Agent Skills are well-defined, secure, and portable before they are used in production environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat(spec): close spec-conformance gaps against agentskills.io</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pespinel/SkillSeal/compare/v0.15.0...v0.16.0">https://github.com/pespinel/SkillSeal/compare/v0.15.0...v0.16.0</a></p>
]]></content:encoded></item><item><title>Oversight Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/oversight-lint/</link><pubDate>Thu, 27 Aug 2026 07:56:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/oversight-lint/</guid><description>Version updated for https://github.com/rachelslurs/oversight-lint-action to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action runs oversight-lint to lint a Storybook MCP components manifest and surface findings as annotations on pull requests. It fails the build when it detects missing component descriptions in the manifest, ensuring that regressions are caught at CI. The action also supports configuring linting rules through an oversight.config.json file or via input parameters, including options for setting a maximum number of warnings and enabling extractor drift checking.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rachelslurs/oversight-lint-action">https://github.com/rachelslurs/oversight-lint-action</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oversight-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action runs <code>oversight-lint</code> to lint a Storybook MCP components manifest and surface findings as annotations on pull requests. It fails the build when it detects missing component descriptions in the manifest, ensuring that regressions are caught at CI. The action also supports configuring linting rules through an <code>oversight.config.json</code> file or via input parameters, including options for setting a maximum number of warnings and enabling extractor drift checking.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runs <code>oversight-lint@0.7.1</code>, gated by this repository&rsquo;s canary. Override with the <code>version</code> input.</p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/kaniko-build-action/</link><pubDate>Thu, 27 Aug 2026 07:55:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting message to the log. It solves the problem of automating the display of greeting messages and can be used for various purposes, such as creating automated welcome banners or logging user interactions. The action provides a simple interface for customizing the greeting text by specifying the who-to-greet input parameter.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting message to the log. It solves the problem of automating the display of greeting messages and can be used for various purposes, such as creating automated welcome banners or logging user interactions. The action provides a simple interface for customizing the greeting text by specifying the <code>who-to-greet</code> input parameter.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>Assay - AI Agent Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/assay-ai-agent-security/</link><pubDate>Thu, 27 Aug 2026 07:55:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/assay-ai-agent-security/</guid><description>Version updated for https://github.com/Rul1an/assay-action to version v3.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action helps developers verify and lint evidence collected from their CI tests to ensure they comply with security policies. It automates the process of recording and analyzing evidence, providing detailed reports and reviews that can help maintain code quality and protect against unauthorized access or vulnerabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Rul1an/assay-action">https://github.com/Rul1an/assay-action</a></strong> to version <strong>v3.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/assay-ai-agent-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action helps developers verify and lint evidence collected from their CI tests to ensure they comply with security policies. It automates the process of recording and analyzing evidence, providing detailed reports and reviews that can help maintain code quality and protect against unauthorized access or vulnerabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Assay Action v3.1.0 adds a bounded, digest-bound evidence index for downstream verification.</p>
<ul>
<li>Adds optional input <code>evidence_mode: optional|required</code> (default: <code>optional</code>).</li>
<li>Adds outputs <code>evidence_state</code>, <code>evidence_index_path</code>, and <code>evidence_index_digest</code>.</li>
<li>Emits a deterministic completed-empty index when optional discovery finds no bundles.</li>
<li>Fails explicitly on invalid modes, path violations, integrity mismatches, and the 101st bundle instead of publishing a partial clean result.</li>
<li>Routes discovered and sandbox-command evidence through the same bounded index and verification path.</li>
<li>Adds an immutable-tag canary that binds the dispatched tag and expected commit before running the candidate action.</li>
</ul>
<p>Compatibility: existing v3 callers remain optional by default. Legacy <code>verified</code> remains available; on a completed run with no evidence it is explicitly <code>false</code> rather than an empty value.</p>
<p>Behavioral note: <code>sandbox-command</code> evidence now enters the same verification and <code>fail_on</code> lint path as discovered bundles. A sandbox run with invalid evidence or matching lint findings can therefore fail where the previous unverified sandbox path completed successfully.</p>
<p>Non-claims: <code>evidence_state=verified</code> proves integrity processing completed for the indexed bytes. It does not prove that later policy or lint gates passed, that the evidence is semantically sufficient, or that the action job itself independently validates evidence on behalf of a consumer.</p>
]]></content:encoded></item><item><title>rung gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/rung-gate/</link><pubDate>Thu, 27 Aug 2026 07:54:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/rung-gate/</guid><description>Version updated for https://github.com/rung-dev/rung to version v0.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: The rung action automates AI agent verification by running the real thing, capturing its output, and creating a record that can be independently verified. It provides a way to ensure that changes are observed and verified, not just claimed as such. This enhances transparency in AI development and reduces the risk of errors or untested changes being deployed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rung-dev/rung">https://github.com/rung-dev/rung</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rung-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> The rung action automates AI agent verification by running the real thing, capturing its output, and creating a record that can be independently verified. It provides a way to ensure that changes are observed and verified, not just claimed as such. This enhances transparency in AI development and reduces the risk of errors or untested changes being deployed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="rung-070">rung 0.7.0</h2>
<p>A fail-closed pass over the two places the gate and the witness were still willing to answer without evidence. Minor, not patch: two changes can newly block or newly exit non-zero.</p>
<h3 id="changed-breaking">Changed (breaking)</h3>
<ul>
<li><strong>A policy MUST declare <code>&quot;version&quot;: 2</code>.</strong> A missing, non-integer, or unknown version now blocks (exit 30). <code>version</code> was a known key that was never checked, so a policy from a future rung, or one with no version at all, gated to pass. The majors disagree about what the numbers mean (v1&rsquo;s rung ladder ran <code>0..4</code>, so <code>min_rung: 1</code> was permissive there and is the maximum here), and guessing is the one thing the gate does not do. A v1 policy gets its own regenerate message, as a v1 bundle already did. The version is validated <strong>before</strong> the unknown-key check: a policy from a later rung arrives carrying both a new version and new keys, and naming the unknown key sends you hunting a typo when the real answer is that the gate is too old.</li>
<li><strong><code>rung run --no-gate</code> exits 2</strong> (cannot-evaluate), not 0. With <code>--no-gate</code> the runner resolves no policy, pins none, and runs no gate, so it reaches no verdict; previously a witnessed timeout wrote <code>verdict: blocked</code> into the bundle and still exited 0. <code>run.py</code> now contains no <code>EXIT_PASS</code> at all, so every 0 from <code>rung run</code> is a gate verdict rather than one the runner minted, pinned by a source check because the property is that no such code path exists.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>POSIX-only for the witness.</strong> <code>rung run</code> kills the process <strong>group</strong>, which is what makes a kill cover a server&rsquo;s children, and that is POSIX. It now refuses other platforms up front with a named reason instead of failing later as a bare exit 2. <code>rung gate</code> and <code>rung attest</code> read and hash files, so they run anywhere Python does. Declared in the metadata rather than ported.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>The skill&rsquo;s &ldquo;smallest bundle that runs&rdquo; example was schema-invalid</strong>, omitting four required fields (<code>change.repo</code>, <code>change.s0</code>, <code>change.s1</code>, <code>claims[].claim</code>). It gate-passed while failing validation against the schema published at its own <code>$id</code>, and contradicted its own prose. The skill is copied into an agent&rsquo;s context, so that example is a bundle-writing instruction.</li>
<li>The capture cap is derived from the gate&rsquo;s artifact cap instead of a second literal, and its comment corrected: the witness caps the sum of both channels, the gate caps each artifact.</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li><strong>Gate-pass now implies schema-valid for everything rung produces or ships</strong>: the worked cases in <code>gate/cases/</code>, all three emitters (<code>run</code>, <code>run --diff</code>, <code>attest</code>), and every bundle example in the shipped docs, checked by the suite. This does not make the gate a validator: a hand-authored bundle can still gate-pass while schema-invalid.</li>
</ul>
<p>18 tests added (243 total). Exit-code contract unchanged: <code>0</code> pass, <code>30</code> block, <code>2</code> usage / cannot-evaluate.</p>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/rumdl-action/</link><pubDate>Thu, 27 Aug 2026 07:52:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.61.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose and Functionality rumdl is a high-performance Markdown linter and formatter written in Rust. It offers a wide range of lint rules to ensure consistency and best practices in Markdown files, including built-in support for multiple Markdown flavors.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.61</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<h3 id="purpose-and-functionality">Purpose and Functionality</h3>
<p>rumdl is a high-performance Markdown linter and formatter written in Rust. It offers a wide range of lint rules to ensure consistency and best practices in Markdown files, including built-in support for multiple Markdown flavors.</p>
<h3 id="problem-solves-or-tasks-automated">Problem Solves or Tasks Automated</h3>
<ul>
<li>Ensures consistent formatting across Markdown files</li>
<li>Provides detailed error reporting with line numbers and descriptions</li>
<li>Offers automatic formatting capabilities for unfixable violations</li>
<li>Supports multiple Markdown flavors with auto-detection</li>
<li>Facilitates easy integration into CI/CD workflows</li>
</ul>
<h3 id="key-capabilities">Key Capabilities</h3>
<ul>
<li>Built for speed using Rust</li>
<li>Over 80 lint rules covering common Markdown issues</li>
<li>Automatic formatting with <code>--fix</code> option</li>
<li>Zero dependencies, single binary</li>
<li>Highly configurable through TOML-based configuration files</li>
</ul>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>cli</strong>: add <code>--stdin-batch</code> for NUL-framed multi-document linting and <code>--stdin-batch-closed-world</code> for supplied-document-only link resolution</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-apple-darwin.tar.gz">rumdl-v0.2.61-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-apple-darwin.tar.gz">rumdl-v0.2.61-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-pc-windows-msvc.zip">rumdl-v0.2.61-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Scratchsmith</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/scratchsmith/</link><pubDate>Thu, 27 Aug 2026 07:51:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/scratchsmith/</guid><description>Version updated for https://github.com/schubydoo/scratchsmith to version v0.2.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Scratchsmith is a daemonless packager that converts dynamically linked glibc ELF binaries into minimal, reproducible FROM scratch OCI images. It resolves binary dependencies and stages the necessary glibc components, ensuring non-root execution and SBOM generation with optional vulnerability scanning and image size optimization. Useful for building secure, lightweight container images for applications reliant on dynamic libraries and network services.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/schubydoo/scratchsmith">https://github.com/schubydoo/scratchsmith</a></strong> to version <strong>v0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/scratchsmith">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Scratchsmith is a daemonless packager that converts dynamically linked glibc ELF binaries into minimal, reproducible <code>FROM scratch</code> OCI images. It resolves binary dependencies and stages the necessary glibc components, ensuring non-root execution and SBOM generation with optional vulnerability scanning and image size optimization. Useful for building secure, lightweight container images for applications reliant on dynamic libraries and network services.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="features">Features</h2>
<ul>
<li><code>scratchsmith.toml</code> now covers every packing flag, and supports named <code>[profile.&lt;name&gt;]</code> sections selectable with <code>pack --profile &lt;name&gt;</code> (layered over the base config, CLI flags still win) — so a <code>[profile.ci]</code> can set strip/sbom/sign/push together. (<a href="https://github.com/schubydoo/scratchsmith/pull/71">#71</a>)</li>
<li><code>pack --upx</code> compresses the packed binary with UPX (it self-decompresses at runtime); the size report shows the delta, and <code>doctor</code> reports whether <code>upx</code> is available. (<a href="https://github.com/schubydoo/scratchsmith/pull/69">#69</a>)</li>
</ul>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/sherpa.sh/</link><pubDate>Thu, 27 Aug 2026 07:50:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven platform that automates the deployment of applications across various cloud providers by understanding developers’ intent through natural language prompts. It simplifies infrastructure management, allowing developers to focus on their code without needing technical expertise in YAML or DevOps. The action can be integrated into GitHub Actions and Claude Code for seamless deployment workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven platform that automates the deployment of applications across various cloud providers by understanding developers&rsquo; intent through natural language prompts. It simplifies infrastructure management, allowing developers to focus on their code without needing technical expertise in YAML or DevOps. The action can be integrated into GitHub Actions and Claude Code for seamless deployment workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Thu, 27 Aug 2026 07:49:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker service on a swarm cluster. It ensures that dependencies are installed and bundled before deploying, addressing issues related to missing dependencies or incorrect package versions during the push operation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker service on a swarm cluster. It ensures that dependencies are installed and bundled before deploying, addressing issues related to missing dependencies or incorrect package versions during the push operation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/classroom-to-sheets-integration/</link><pubDate>Thu, 27 Aug 2026 07:48:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending assignment results from GitHub Classroom to Google Sheets. It allows organizations to integrate their grading workflows with spreadsheet tools, enhancing collaboration and data management across different platforms. The integration requires setting up Google Cloud credentials and sharing a Google Sheet with a service account email. Users can use this action in their GitHub actions workflows by specifying student names, authentication details, task results, and the ID of the Google sheet.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending assignment results from GitHub Classroom to Google Sheets. It allows organizations to integrate their grading workflows with spreadsheet tools, enhancing collaboration and data management across different platforms. The integration requires setting up Google Cloud credentials and sharing a Google Sheet with a service account email. Users can use this action in their GitHub actions workflows by specifying student names, authentication details, task results, and the ID of the Google sheet.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>Sprocket CI/CD</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/sprocket-ci/cd/</link><pubDate>Thu, 27 Aug 2026 07:48:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/sprocket-ci/cd/</guid><description>Version updated for https://github.com/stjude-rust-labs/sprocket-action to version v0.30.1.
This action is used across all versions by 8 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sprocket GitHub Action automates static analysis of WDL documents, including linting and validation. It supports various actions such as checking, linting, validating JSON inputs against schemas, and formatting WDL files. Users can specify configuration settings in a sprocket.toml file for consistent behavior across environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stjude-rust-labs/sprocket-action">https://github.com/stjude-rust-labs/sprocket-action</a></strong> to version <strong>v0.30.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sprocket-ci-cd">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Sprocket GitHub Action automates static analysis of WDL documents, including linting and validation. It supports various actions such as checking, linting, validating JSON inputs against schemas, and formatting WDL files. Users can specify configuration settings in a <code>sprocket.toml</code> file for consistent behavior across environments.</p>
]]></content:encoded></item><item><title>GitHub Stats Cards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/github-stats-cards/</link><pubDate>Thu, 27 Aug 2026 07:47:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/github-stats-cards/</guid><description>Version updated for https://github.com/stn1slv/github-stats-cards to version v1.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the generation of beautiful, high-quality SVG statistics cards for your GitHub profile README. It runs on a schedule and updates your profile SVG files using Python and GitHub Actions. The tool supports various features such as 50+ themes, comprehensive stats, top languages and contributions cards, smart weighting, aligned layouts, customizable content, and local generation without external service dependencies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stn1slv/github-stats-cards">https://github.com/stn1slv/github-stats-cards</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-stats-cards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the generation of beautiful, high-quality SVG statistics cards for your GitHub profile README. It runs on a schedule and updates your profile SVG files using Python and GitHub Actions. The tool supports various features such as 50+ themes, comprehensive stats, top languages and contributions cards, smart weighting, aligned layouts, customizable content, and local generation without external service dependencies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><code>vue-github-dark</code> theme: the <code>vue-dark</code> palette on GitHub&rsquo;s dark-mode canvas (<code>#0d1117</code>), with a matching border so the card has no visible edge and blends into a README viewed in dark mode. It is a fixed dark background, so it will show as a dark rectangle to anyone browsing in light mode.</li>
</ul>
<p>Usage:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">stn1slv/github-stats-cards@v1.3.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">username</span>: <span style="color:#ae81ff">your-username</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">theme</span>: <span style="color:#ae81ff">vue-github-dark</span>
</span></span></code></pre></div><p>Full changelog: <a href="https://github.com/stn1slv/github-stats-cards/blob/v1.3.0/CHANGELOG.md">https://github.com/stn1slv/github-stats-cards/blob/v1.3.0/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>mowmow lawn</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/mowmow-lawn/</link><pubDate>Thu, 27 Aug 2026 07:45:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/mowmow-lawn/</guid><description>Version updated for https://github.com/sudongcu/mowmow to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action creates an animated SVG representing a user’s GitHub contributions as a lawn. It automatically generates and updates the lawn image daily, simulating mowing the grass with different mower styles based on commit activity. The action is configurable to customize the cycle time, mower style, color, and output files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sudongcu/mowmow">https://github.com/sudongcu/mowmow</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mowmow-lawn">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action creates an animated SVG representing a user&rsquo;s GitHub contributions as a lawn. It automatically generates and updates the lawn image daily, simulating mowing the grass with different mower styles based on commit activity. The action is configurable to customize the cycle time, mower style, color, and output files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>cycle floor 28 → 15 (8373030)</li>
<li>ci: typecheck, build, dist drift check; release: tag push moves v1 and cuts the release (7776241)</li>
<li>render: fixed regrow tail instead of a fixed mow fraction (27b510f)</li>
<li>playground: drop the PAT suggestion from the mostly-dirt note (cd512c6)</li>
<li>action: commit as github-actions[bot], not a real user&rsquo;s noreply address (c5e3708)</li>
<li>readme: drop the PAT option from the private-contributions faq (0a176be)</li>
<li>action: run on node24 (node20 deprecated on runners) (a439327)</li>
<li>playground: sync the color picker with the goat&rsquo;s default coat (8d6ebe1)</li>
<li>readme: badge row under the tagline (marketplace / release / license) (6b71eb6)</li>
<li>docs: point install snippets at @v1 (c5b801b)</li>
</ul>
]]></content:encoded></item><item><title>move-test-gen coverage check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/move-test-gen-coverage-check/</link><pubDate>Thu, 27 Aug 2026 07:44:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/move-test-gen-coverage-check/</guid><description>Version updated for https://github.com/talongate/move-test-gen to version v1.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, move-test-gen, automates the creation of edge-case test suites for Move functions in Sui. It generates [test] and [expected_failure] functions covering various scenarios such as boundary values, arithmetic edges, access control issues, state machine problems, and economic considerations. The action uses predefined rules to identify potential security patterns and generate tests that can help catch errors before they occur. Users can install the action via npm or manually copy its scripts and references into their Claude Code environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/talongate/move-test-gen">https://github.com/talongate/move-test-gen</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-test-gen-coverage-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, move-test-gen, automates the creation of edge-case test suites for Move functions in Sui. It generates <code>[test]</code> and <code>[expected_failure]</code> functions covering various scenarios such as boundary values, arithmetic edges, access control issues, state machine problems, and economic considerations. The action uses predefined rules to identify potential security patterns and generate tests that can help catch errors before they occur. Users can install the action via npm or manually copy its scripts and references into their Claude Code environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Three new lint rules and a MOV-002 extension — bringing the total to 9 rule files (10 checks).</p>
<p>Three of the new patterns came from @jangid&rsquo;s <a href="https://github.com/AlphaFiTech/sui-ai-commons">sui-move-auditor</a>. Different tools, same patterns worth catching. Credited in the changelog because that is where the signal came from.</p>
<h3 id="new-rules">New rules</h3>
<ul>
<li><strong>MOV-008</strong> [MEDIUM] — exact-equality assert on payment amounts (DoS via dust)</li>
<li><strong>MOV-011</strong> [HIGH] — <code>public(package) entry</code> is externally callable via PTB</li>
<li><strong>MOV-012</strong> [HIGH] — sender identity as a spoofable <code>address</code> parameter</li>
</ul>
<h3 id="extended">Extended</h3>
<ul>
<li><strong>MOV-002</strong> now catches <code>&lt;&lt;</code> / <code>&gt;&gt;</code> bit-shift silent wrapping (Cetus $223M class)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>MOV-001</strong> word-boundary fix — <code>PositionManager</code> no longer falsely exempt</li>
</ul>
<p>gate-selftest: 14/14 | CI green</p>
<p>Full changelog in CHANGELOG.md.</p>
]]></content:encoded></item><item><title>Pinglet Notify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/pinglet-notify/</link><pubDate>Thu, 27 Aug 2026 07:43:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/pinglet-notify/</guid><description>Version updated for https://github.com/TheGlenn88/pinglet-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Pinglet Notify action automates the process of sending push notifications to a [Pinglet] topic from any GitHub Actions workflow. It simplifies integration with Pinglet by eliminating the need for SDKs or app configurations. The action allows users to send notifications with customizable titles, messages, and severity levels directly from their workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TheGlenn88/pinglet-action">https://github.com/TheGlenn88/pinglet-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pinglet-notify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Pinglet Notify action automates the process of sending push notifications to a [Pinglet] topic from any GitHub Actions workflow. It simplifies integration with Pinglet by eliminating the need for SDKs or app configurations. The action allows users to send notifications with customizable titles, messages, and severity levels directly from their workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release.</p>
<p>Publish a push notification to a Pinglet topic from any workflow: deploy results, CI failures, release announcements. Inputs for title, message, level, priority, badges and metadata; retries on transient failures and fails the step with the API error body on a non-2xx.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">TheGlenn88/pinglet-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">key</span>: <span style="color:#ae81ff">${{ secrets.PINGLET_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">topic</span>: <span style="color:#ae81ff">acme/deploys</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">title</span>: <span style="color:#e6db74">&#34;Deploy done&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">message</span>: <span style="color:#e6db74">&#34;${{ github.ref_name }} is live&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">level</span>: <span style="color:#ae81ff">success</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>SecURL Security Posture Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/securl-security-posture-scan/</link><pubDate>Thu, 27 Aug 2026 07:42:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/securl-security-posture-scan/</guid><description>Version updated for https://github.com/this-is-securl/scan-action to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SecURL Website Posture Scan action automates the addition of passive external website posture evidence to GitHub Actions workflows. It checks public responses, redirects, TLS, headers, cookies, DNS, and other bounded signals without requiring a SecURL account or repository access. The action provides human-readable summaries and full JSON reports, supports optional policy gates based on scores and criticality levels, and integrates with GitHub integrations for PR comments and Code Scanning uploads. It is designed for use only with public targets owned or authorized to assess.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/this-is-securl/scan-action">https://github.com/this-is-securl/scan-action</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/securl-security-posture-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The SecURL Website Posture Scan action automates the addition of passive external website posture evidence to GitHub Actions workflows. It checks public responses, redirects, TLS, headers, cookies, DNS, and other bounded signals without requiring a SecURL account or repository access. The action provides human-readable summaries and full JSON reports, supports optional policy gates based on scores and criticality levels, and integrates with GitHub integrations for PR comments and Code Scanning uploads. It is designed for use only with public targets owned or authorized to assess.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="securl-marketplace-action-restored">SecURL Marketplace action restored</h2>
<p>This release replaces the obsolete v1 implementation with a production-aligned, permission-minimal action.</p>
<ul>
<li>runs the pinned <code>securl@1.28.6</code> package instead of the deprecated predecessor</li>
<li>writes the native SecURL GitHub job summary and hosted continuation</li>
<li>safely constructs CLI arguments from validated inputs</li>
<li>returns current score, grade, finding counts, pass state, JSON and SARIF paths</li>
<li>keeps PR comments and Code Scanning uploads off by default</li>
<li>pins all third-party actions to reviewed commit SHAs on current GitHub runtimes</li>
<li>adds end-to-end smoke and fail-closed input validation CI</li>
<li>updates the documentation, privacy boundary, package links and repository links</li>
</ul>
<h3 id="migration-from-v1">Migration from v1</h3>
<p>Use <code>this-is-securl/scan-action@v2</code>. The removed <code>format</code> input was not honored consistently by v1. Set <code>post-pr-comment: &quot;true&quot;</code> or <code>upload-sarif: &quot;true&quot;</code> explicitly and grant the documented write permission if either integration is required.</p>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/compose-lint/</link><pubDate>Thu, 27 Aug 2026 07:41:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/27/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.25.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a security-focused linter for Docker Compose files that checks for dangerous misconfigurations before they reach production. It catches privilege flaws, network exposure, supply-chain issues, filesystem and credential leaks, and provides auto-fixes where possible. The action is built for anyone whose Compose file runs real services and serves as the pre-merge gate to catch misconfiguration before deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.25.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a security-focused linter for Docker Compose files that checks for dangerous misconfigurations before they reach production. It catches privilege flaws, network exposure, supply-chain issues, filesystem and credential leaks, and provides auto-fixes where possible. The action is built for anyone whose Compose file runs real services and serves as the pre-merge gate to catch misconfiguration before deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>CL-0025 now grades a writable bind of the host&rsquo;s module and library tree</strong>
(<a href="docs/adr/033-library-tree-is-root-equivalent-by-containment.md">ADR-033</a>,
the disposition #737 deferred). <code>/lib/modules</code> and <code>/usr/lib/modules</code> are
matched by descent — everything below is a file the host kernel loads by
name, as root, on demand, so a replaced module is kernel-mode code on the
host with no capability needed. <code>/usr/lib</code>, <code>/lib</code> and <code>/lib64</code> are matched
exactly, the <code>/var/lib</code> mechanism: <code>systemd/system</code> and <code>ld.so</code> sit below
them, but so do <code>python3</code>, <code>node_modules</code> and <code>jvm</code>. Measured on Docker
29.7.2 at defaults, unprivileged: every path accepted a write through an rw
bind and refused it through an ro bind, and module lookup works through
<code>:ro</code>. New premise check <code>_cl0025_module_tree</code> plants a file in the running
kernel&rsquo;s module directory, observes it from a second container and removes
it; the kernel is never asked to load it. Same cell as <code>/etc</code>: Direct × Host,
CRITICAL, no override.</p>
<p>On the corpus this is <strong>7 new CRITICAL findings, all WireGuard / strongSwan
services</strong> binding <code>/lib/modules</code> without <code>:ro</code>. They are true positives
with a one-token fix — the container only reads module files — so the
finding&rsquo;s fix text leads with <code>:ro</code> rather than &ldquo;remove the mount&rdquo;, and the
read-only form <code>/lib/modules:/lib/modules:ro</code> is clean under every rule (the
tree is world-readable by design, so it is exempt from CL-0013 too, as the
executable tree is). <code>/usr/lib/systemd</code> and the multiarch library
directories are recorded as real grants with no corpus incidence, not
matched by descent yet.</p>
</li>
<li>
<p><strong>CL-0025 now grades a writable bind of the host&rsquo;s executable tree</strong>
(<a href="https://github.com/tmatens/compose-lint/issues/737">#737</a>). <code>/usr/bin</code>,
<code>/usr/sbin</code>, <code>/usr/local/bin</code>, <code>/usr/local/sbin</code>, <code>/bin</code> and <code>/sbin</code> are
matched by descent — <code>/usr/bin/docker:/usr/bin/docker</code>, the corpus idiom for
driving the host&rsquo;s CLI, counts — and bare <code>/usr</code> is matched exactly, the
<code>/var/lib</code> mechanism: it is root-equivalent for what it <em>contains</em>, and by
descent it would also have priced <code>/usr/src</code>, <code>/usr/share/zoneinfo</code> and
site-packages as host root (6 of the 27 writable <code>/usr</code>-family binds in the
corpus, 22%). Both spellings are listed because matching is lexical on what
the document wrote, while Docker resolves the merged-<code>/usr</code> symlink at mount
time. Measured on two hosts at Docker defaults, unprivileged: each member
accepted a write through an rw bind and refused it through an ro bind, and a
root-owned <code>755</code> file planted through <code>-v /usr</code> into <code>/usr/local/bin</code> — ahead
of <code>/usr/bin</code> on root&rsquo;s <code>PATH</code>, so nothing need be overwritten — was on the
host afterwards. New premise check <code>_cl0025_exec_tree</code> plants, observes from
a second container, and removes it. Same cell as <code>/etc</code>: Direct × Host,
CRITICAL, no override. On the corpus this is 20 new CRITICAL findings.</p>
<p>Two boundaries recorded rather than guessed: a <strong>read-only</strong> bind of the
executable tree is exempt from CL-0013 as well — every file in it is
world-readable by design, so <code>:ro</code> discloses nothing (the timezone-file shape,
one tier up); and the <strong>library tree</strong> (<code>/usr/lib</code>, <code>/lib/modules</code>) is
deferred to an ADR, because by descent it would sweep <code>/usr/lib/python3</code> and
the standard <code>/lib/modules</code> bind of every VPN workload, and the corpus holds
nothing else to shape a narrower match on.</p>
</li>
<li>
<p><strong>A host file handed over through <code>secrets:</code> or <code>configs:</code> <code>file:</code> is now a
bind mount to every mount rule</strong>
(<a href="https://github.com/tmatens/compose-lint/issues/736">#736</a>). Outside swarm,
<code>secrets: dsock: file: /var/run/docker.sock</code> is a read-only bind of that host
file at <code>/run/secrets/dsock</code> — measured on Docker 29.7.2 / Compose 5.4.0: the
container saw the host inode, the daemon answered through the secret, and the
write stayed refused even with <code>mode: 0666</code>. Neither channel was read by any
mount rule, so a service could hand itself the Docker socket and pass
CL-0001 clean. <code>iter_bind_mounts</code> now yields each referenced <code>file:</code> entry
as a read-only bind (<code>BindMount.origin</code> names the channel), so the existing
partition grades it without a new rule: a socket or socket directory is
CL-0001 CRITICAL, a root-equivalent or credential path is CL-0013&rsquo;s read-only
disclosure at HIGH, and CL-0025 never applies because the channel cannot be
writable. A project-relative <code>file: ./secrets/…</code> — the CL-0020 remediation —
is not a host path and is not graded, matching the line <code>volumes:</code> draws;
<code>external: true</code> and <code>environment:</code>-sourced entries have no host path. New
premise check <code>_cl0001_secret_socket</code> drives <code>docker compose</code> and asserts
both <code>ro</code> and a live daemon through the secret. Corpus: 73 <code>file:</code> entries,
none absolute, so no existing finding changes.</p>
</li>
<li>
<p><strong>Three bump classes the judgment-call cheat sheet did not price</strong>
(<a href="docs/RELEASING.md#judgment-call-cheat-sheet">docs/RELEASING.md</a>). The
sharpest is a rule&rsquo;s <strong>evidence</strong> derivation: it never appears in text output
so it reads as an implementation detail, but it is the input to the SARIF
<code>partialFingerprints</code> digest — the <em>identity</em> of a Code Scanning alert
(<a href="docs/adr/024-finding-identity-is-not-prose.md">ADR-024</a>). Change one and
every existing alert for that rule closes as &ldquo;fixed&rdquo; while the same findings
reopen as new, with no field renamed and no shape moved. No document assigned
it a bump class; it is a MINOR, announced under <code>Changed</code>, and
<code>docs/compatibility.md</code> gains an <em>Alert identity</em> section saying so in
user-facing terms. The other two: retiring a rule admitted on <em>judgment</em>
(new in this release, and previously harder to remove than a grounded rule),
and amending the policy itself — ADR-030&rsquo;s
clarification/tightening/loosening ladder governs every other row in the
table but was only findable in prose elsewhere.</p>
</li>
<li>
<p><strong>A test gates the <code>Development Status</code> classifier against the major
version.</strong> <code>docs/RELEASING.md</code> says to flip <code>4 - Beta</code> to
<code>5 - Production/Stable</code> in the same commit that sets <code>version = &quot;1.0.0&quot;</code>, but
nothing enforced it — the classifier was referenced nowhere in <code>tests/</code>,
<code>scripts/</code> or the workflows. PyPI metadata is immutable per version, so a
missed flip would have published 1.0.0 permanently labelled Beta with 1.0.1
as the only remedy.</p>
</li>
<li>
<p><strong><code>x-</code> prefixed top-level keys are accepted in <code>.compose-lint.yml</code>.</strong> Compose&rsquo;s
extension-field convention, already honoured in the documents compose-lint
lints. It is the other half of merge-key support — a <code>&lt;&lt;:</code> needs an anchor to
merge <em>from</em>, and the idiomatic place to hold one is a top-level <code>x-</code> block,
which previously warned and, under <code>--strict-config</code>, failed the run. Because
<code>x-</code> is a deliberate marker it costs no typo detection: a mistyped <code>rulez:</code>
still warns.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><strong>A rule admitted on judgment may be withdrawn on judgment</strong>
(<a href="docs/adr/032-rule-retirement-is-minor-with-lifecycle.md">ADR-032</a>
condition 1, widened). ADR-032 made retirement MINOR only where evidence
refutes the rule&rsquo;s premise. CL-0014&rsquo;s premise <em>holds</em> — <code>docker logs</code> under
<code>driver: none</code> really does fail — so that bar could never be met for it, and
the thin part is its grounding, which is a different defect. The effect was
that a rule the project itself declines to ground was <em>harder</em> to remove than
one that is grounded and later refuted, which is backwards; dropping it would
have cost a MAJOR. The exception reaches only rules
<a href="docs/adr/028-pre-1.0-rule-id-sweep.md">ADR-028</a> records as admitted on
judgment — a set closed at the 1.0 sweep, currently <code>{CL-0014}</code> — so &ldquo;evidence,
not preference&rdquo; is unchanged for every rule admitted on evidence. Withdrawal
still needs its own ADR and still runs the full deprecation lifecycle. Landed
before the tag because the direction only goes one way: admitting this ground
later is a loosening and costs a MAJOR, while removing it later is a
tightening and costs a MINOR.</p>
</li>
<li>
<p><strong>JSON <code>file</code> and <code>line</code> now name the same document, and the envelope is
schema <code>&quot;2&quot;</code>.</strong> <code>file</code> had always named the document being <em>graded</em> while
<code>line</code> indexed wherever the evidence actually came from, so on a merged run
(default since <a href="docs/adr/025-lint-the-merged-configuration.md">ADR-025</a>) or
one reading an <code>env_file:</code> (default since
<a href="docs/adr/027-grade-env-file-where-the-document-routes-it.md">ADR-027</a>) the
pair named a real line of the <em>wrong file</em> — an overlay&rsquo;s CL-0002 was
reported at the base file&rsquo;s line 3, which is its <code>image:</code> key. SARIF was
already corrected this way after the same mismatch made Code Scanning
annotate an unrelated line of the base file; JSON was the last format
emitting an incoherent pair. <code>file</code> now names the document the evidence is
in, the graded document moved to the new conditional <code>graded_file</code>, and
<code>source_file</code> stays as a deprecated alias for consumers written against
schema 1. <strong>This is a breaking change to a required field</strong>, which is why it
ships before the 1.0 freeze — after the tag the same correction would be a
MAJOR. ADR-015 and <code>docs/configuration.md</code> now document the complete emitted
field list, including <code>severity_overridden_from</code> and the closed <code>severity</code>
set, neither of which the frozen contract had named.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong><code>fix --only</code> now normalizes case and reports an id that names no rule.</strong>
<code>--only cl-0014</code> — the correct id, lower-cased — matched nothing, printed
&ldquo;nothing to fix&rdquo; and exited 0, which is indistinguishable from a clean repo;
so did <code>--only CL-9999</code> and <code>--only banana</code>. A CI remediation step pinned to a
typo therefore went green forever. <code>--explain</code> already normalized case, so one
CLI was answering the same input two different ways. An id that matches no
rule is now a <code>Warning:</code> naming it, promoted to an error by <code>--strict-config</code>
— the same treatment an unknown rule id in <code>.compose-lint.yml</code> already gets.</p>
</li>
<li>
<p><strong><code>fix --apply</code> on a read-only file is now exit 2, not exit 0.</strong> The three
sibling write refusals — a symlink target, a hard link, an unwritable
directory — all report exit 2, as does <code>init --force</code> on the same predicate.
Only this case reported success, so the documented Docker recipe
(<code>docker run -v &quot;$(pwd):/src&quot; … fix --apply</code>, where the image runs as UID
65532) wrote nothing and told a gate it had succeeded.</p>
</li>
<li>
<p><strong><code>compose-lint init</code> no longer writes a config <code>check</code> then refuses.</strong> A
service named <code>no</code>, <code>yes</code>, <code>on</code>, <code>123</code>, <code>1.5</code> or <code>null</code> was emitted unquoted:
the plain-scalar pattern said the <em>characters</em> were safe, but YAML 1.1
resolves those <em>tokens</em> to booleans, ints and None, and <code>config.py</code> requires
<code>exclude_services</code> keys to be strings. <code>init</code> reported success and the next
<code>check</code> in that directory exited 2 until someone hand-edited the file — the
exact failure the emitter&rsquo;s own docstring says it exists to prevent, arriving
through the token rather than the characters. A candidate is now emitted
unquoted only if PyYAML reloads it as the same string.</p>
</li>
<li>
<p><strong>A <code>&lt;&lt;:</code> merge key in <code>.compose-lint.yml</code> no longer aborts the run.</strong> The
config loader called <code>construct_object</code> on every key node and PyYAML has no
constructor for the merge tag, so a config using YAML&rsquo;s own merge syntax died
with <code>could not determine a constructor for the tag 'tag:yaml.org,2002:merge'</code>
and named no fix. <code>parser.py</code> already skipped the tag for Compose documents,
so <code>&lt;&lt;:</code> was legal in the file being linted and fatal in the config beside it.</p>
</li>
<li>
<p><strong><code>--format json</code> and <code>--format sarif</code> now emit a document for every exit-2
path.</strong> &ldquo;No Compose files found&rdquo; and a missing <code>--config</code> exited before any
formatter ran, producing <strong>zero bytes</strong> on stdout — while a missing file, a
parse error and a directory argument all produced a full envelope. A <code>jq</code>
pipeline therefore broke or not depending on which kind of exit 2 it hit, and
both silent cases are the commonest CI misconfigurations: the wrong working
directory and a typo&rsquo;d config path.</p>
</li>
<li>
<p><strong>Four published claims corrected to match what the tool does.</strong> Under
<a href="docs/adr/030-the-policy-is-part-of-the-contract.md">ADR-030</a> the policy is
part of the frozen contract, so a claim that is wrong at the tag is expensive
to walk back later. <code>docs/ASSURANCE.md</code> said compose-lint &ldquo;does not modify
its inputs&rdquo; — <code>fix --apply</code> has rewritten files in place since 0.11.0 — and
its CWE-22 row said &ldquo;the tool only <em>reads</em> them&rdquo; and &ldquo;No path is constructed
from untrusted YAML content&rdquo;, when <code>env_file:</code> targets and <code>COMPOSE_FILE</code>
entries are exactly that (ADR-026, ADR-027); the row now describes both path
classes and the two containment gates that guard the document-supplied one.
<code>docs/compatibility.md</code> promised a config naming a retired rule ID &ldquo;keeps
working, <code>--strict-config</code> included&rdquo;; it loads, but the override is reported
as an unknown ID and <code>--strict-config</code> promotes that to an error, which the
page now says. <code>docs/configuration.md</code> told users to pass a <code>--pattern</code> flag
that does not exist — globbing is the GitHub Action&rsquo;s <code>pattern:</code> input, not a
CLI flag.</p>
</li>
<li>
<p><strong>A crashed rule now reports itself in JSON and SARIF, not only on stderr.</strong>
A rule that raises is isolated rather than aborting the run
(<a href="docs/adr/006-exit-codes.md">ADR-006</a>), and it already set exit 2 and printed
to stderr — but <code>run_errors</code> omitted <code>rule_errors</code>, so the machine output said
nothing. JSON reported <code>errors: []</code> and SARIF reported
<code>executionSuccessful: true</code> while that rule&rsquo;s findings were silently absent
from a document the GitHub Action uploads. For Code Scanning that is worse
than an omission: a <em>declared</em> rule with zero results reads as &ldquo;every alert
for this rule is fixed&rdquo;, so a crash closed the alerts instead of reporting
itself. Crashed rules now ride the same structured channel as parse errors and
coverage gaps.</p>
</li>
<li>
<p><strong>Contract tests for three frozen surfaces that no test pinned.</strong> Found by
mutation: each change below left the entire suite green before this release.
Halving <code>_KNOWN_RULE_KEYS</code> to <code>{enabled, reason}</code> passed — <code>severity:</code> and
<code>exclude_services:</code> would have started warning as unknown keys, and <em>erroring</em>
under <code>--strict-config</code>. Regrading SARIF <code>security-severity</code> for HIGH
(<code>7.5</code>→<code>3.0</code>) and MEDIUM (<code>5.5</code>→<code>0.5</code>) passed, and both drop a full tier in
GitHub&rsquo;s bands — the formatter&rsquo;s own comment records that Code Scanning
derives an alert&rsquo;s severity column from that number alone. And changing the
evidence derivation in CL-0017, CL-0020, CL-0021, CL-0025, CL-0028 or CL-0030
passed <em>whenever the values stayed distinct</em>: evidence is the SARIF
fingerprint, so that silently re-keys every alert, and the existing collision
test only catches the degenerate case where values collapse together. Each is
now pinned, with a guard-the-guard companion. Separately, <code>ci.yml</code>&rsquo;s path
filter now includes <code>docs/</code>, <code>README.md</code> and <code>mkdocs.yml</code>, which are asserted
against by tests and could previously break on a docs-only PR that merged
green.</p>
</li>
<li>
<p><strong>A failed stdout write is now exit 2, not an undocumented exit 120 or a
false exit 1.</strong> Every path that could raise mid-run had been hardened to the
0/1/2 contract; the channel all of them write through had not. A full disk
(<code>&gt; /dev/full</code>), a reader that closed early (<code>compose-lint check f.yml | head</code>) or a descriptor closed at startup (<code>&gt;&amp;-</code>) let the error escape
<code>main()</code>: CPython reported an unraisable error from its own final flush and
exited <strong>120</strong> — a code <a href="docs/adr/006-exit-codes.md">ADR-006</a> does not define
and which <code>docs/compatibility.md</code> prices at a MAJOR to add — or, when the
write failed earlier, exited <strong>1</strong>, which reads as &ldquo;findings at or above the
threshold&rdquo; on a file that is clean. Piping a clean run into <code>head</code> was
therefore a red merge gate. Writes now report
<code>Error: could not write output: &lt;reason&gt;</code> and exit 2, which is what that code
already means: compose-lint could not complete the run.</p>
</li>
<li>
<p><strong>A tiny Compose file can no longer buy an unbounded amount of work.</strong> Two
vectors, both reachable from a pull request in the CI merge gate the tool
ships as. <code>MAX_SCAN_LEN</code> bounds what a pass <em>scans</em>; nothing bounded what
substitution <em>produces</em> — <code>${A}${A}</code> is four characters whose result is twice
whatever <code>A</code> holds, so a ladder of definitions each referencing the one below
doubles per rung, and thirty rungs is a <strong>489-byte</strong> <code>.env</code> whose expansion
exhausts memory. The new <code>MAX_SUBSTITUTED_LEN</code> bounds the result as it is
built, returning the same &ldquo;unknowable&rdquo; answer both call sites already return
for a name they cannot resolve. Separately, <code>str()</code> on an alias-expanded
nested list serializes the DAG as a tree: <code>security_opt: [*l26]</code> is <strong>690
bytes</strong> on disk and took 35s. <code>compose_lint._scalar</code> exists to refuse exactly
that and <code>_caps.iter_cap_add</code> already applied it to <code>cap_add</code>; the CL-0003 /
CL-0009 <code>security_opt</code> normalizer and CL-0010&rsquo;s namespace comparison now do
too — 35.85s to 90ms. A list is not a value any of those fields can hold, so
the entry is skipped rather than compared.</p>
</li>
<li>
<p><strong>A pull request can no longer choose its own lint scope through a quoted
<code>.env</code> value.</strong> godotenv — and therefore Compose — lets a quoted value span
lines, so the physical lines after the opening quote are value <em>text</em>, not
entries. <code>_scan</code> read them as entries, which handed an untrusted contributor
the one thing <a href="docs/adr/026-read-the-sibling-env-file.md">ADR-026</a> §4 forbids:
a <code>COMPOSE_FILE</code> compose-lint honours and Compose never sees. Three committed
files were enough — a <code>.env</code> whose value text carries
<code>COMPOSE_FILE=compose.yml:scrub.yml</code>, and a <code>scrub.yml</code> that <code>!reset</code>s the
dangerous keys — turning a privileged, socket-mounting service from two
CRITICAL findings into <code>✓ PASS</code> and exit 0, including in the explicit-file
form the GitHub Action and the pre-commit hook use. <code>docker compose config</code>
was never fooled; only compose-lint was. The scanner is now value-aware for
both quote styles, with double-quote escapes honoured, and an unterminated
quote consumes the rest of the file exactly as Compose does. This is the same
failure <code>_split_env_lines</code> already closed for <code>\r</code>, by the route left open
for <code>\n</code>.</p>
</li>
<li>
<p><strong>A committed symlink no longer walks through the project-containment
guard.</strong> The guards in <code>_selection</code> and <code>_service_env</code> are deliberately
lexical — whether a path <em>says</em> it leaves the project is a fact about the
document, identical on every platform
(<a href="docs/adr/023-deploy-host-independent-claims.md">ADR-023</a> §1) — and a
symlink says nothing. <code>probe.env</code> is spelled like a project-relative file
and passes every lexical test while the link beside it points at
<code>/home/runner/.aws/credentials</code>: exactly the scenario
<a href="docs/adr/027-grade-env-file-where-the-document-routes-it.md">ADR-027</a> §7
names and <code>README.md</code> promises to refuse. In a pull request that put
out-of-project env-key names into CL-0020/CL-0021 findings, and a line of an
arbitrary host file into the SARIF uploaded to Code Scanning. A second gate
now asks the <em>filesystem</em> — after the lexical test, at the moment of
resolution — for both <code>env_file:</code> targets and <code>COMPOSE_FILE</code> entries.
Symlinks themselves are still followed; only ones resolving outside the
project are refused, with the existing <code>outside-project</code> note.</p>
</li>
<li>
<p><strong>A parse error no longer reproduces the line it failed on.</strong> PyYAML renders
a snippet of the document under a caret, which reached <code>errors[].message</code>,
the SARIF <code>toolExecutionNotifications</code> uploaded to Code Scanning, and the job
log. A syntax error on a line carrying a credential therefore republished the
credential. The diagnosis and the line/column position are kept — they say
what is wrong and exactly where — and only the quoted bytes are dropped.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Speccy API review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/speccy-api-review/</link><pubDate>Wed, 26 Aug 2026 22:56:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/speccy-api-review/</guid><description>Version updated for https://github.com/mcclowes/speccy to version docusaurus-plugin-speccy@0.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Speccy is an OpenAPI renderer that provides a React-based solution for rendering API specifications across various platforms such as web, macOS, and Docusaurus. It automates tasks like linting and diffing OpenAPI documents, making it easier to maintain consistent documentation and ensure compliance with the specification standard.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcclowes/speccy">https://github.com/mcclowes/speccy</a></strong> to version <strong><a href="mailto:docusaurus-plugin-speccy@0.13.0">docusaurus-plugin-speccy@0.13.0</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/speccy-api-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Speccy is an OpenAPI renderer that provides a React-based solution for rendering API specifications across various platforms such as web, macOS, and Docusaurus. It automates tasks like linting and diffing OpenAPI documents, making it easier to maintain consistent documentation and ensure compliance with the specification standard.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="minor-changes">Minor Changes</h3>
<ul>
<li>
<p><a href="https://github.com/mcclowes/speccy/pull/62">#62</a> <a href="https://github.com/mcclowes/speccy/commit/54e9a75688cb3f46ecbd5ab91f3599be2433ce32"><code>54e9a75</code></a> Thanks <a href="https://github.com/mcclowes">@mcclowes</a>! - Add a Webhooks reference page listing every webhook the API delivers.</p>
<p>Webhooks still appear under their tag in the sidebar, but the Reference group now also links to <code>/reference/webhooks</code>, a single list of every webhook in the spec. The entry and its generated route appear only when the document declares webhooks.</p>
</li>
</ul>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>
<p><a href="https://github.com/mcclowes/speccy/pull/62">#62</a> <a href="https://github.com/mcclowes/speccy/commit/ac83fee12fcf9b6575d88fa669980f59fa789859"><code>ac83fee</code></a> Thanks <a href="https://github.com/mcclowes">@mcclowes</a>! - Serve the published OpenAPI description under <code>docusaurus start</code>. The file was only emitted from <code>postBuild</code>, so the overview&rsquo;s link to it 404ed for the whole time an author worked locally. The plugin now writes the description into its generated files directory and mounts that directory on the dev server at the same URL.</p>
<p>The overview card also shows the description&rsquo;s URL instead of a second &ldquo;Open OpenAPI description&rdquo; label, and opens it in a new tab rather than navigating the reader out of the docs.</p>
</li>
<li>
<p>Updated dependencies [<a href="https://github.com/mcclowes/speccy/commit/ac83fee12fcf9b6575d88fa669980f59fa789859"><code>ac83fee</code></a>, <a href="https://github.com/mcclowes/speccy/commit/54e9a75688cb3f46ecbd5ab91f3599be2433ce32"><code>54e9a75</code></a>, <a href="https://github.com/mcclowes/speccy/commit/8a798d1d0dc9c98d75ff8443d5069ea8d33ed927"><code>8a798d1</code></a>, <a href="https://github.com/mcclowes/speccy/commit/eb610fc94281a40352b093746f2084c9368da817"><code>eb610fc</code></a>, <a href="https://github.com/mcclowes/speccy/commit/1e75c06c9d473c264140c2404ed89f70c5507832"><code>1e75c06</code></a>]:</p>
<ul>
<li><a href="mailto:speccy-renderer@0.13.0">speccy-renderer@0.13.0</a></li>
<li><a href="mailto:speccy-spectral@0.13.0">speccy-spectral@0.13.0</a></li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>FHIR Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/fhir-validator/</link><pubDate>Wed, 26 Aug 2026 22:55:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/fhir-validator/</guid><description>Version updated for https://github.com/medvertical/records-fhir-validator to version validator-v0.6.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action provides a FHIR validator for CI pipelines, GitHub Actions, and standalone Node.js use. It validates FHIR JSON, XML, and NDJSON resources against StructureDefinitions, FHIRPath invariants, terminology bindings, references, slicing, extensions, Bundle rules, metadata, and custom rules without requiring a JVM or database. The action supports multiple FHIR versions and provides options for profile validation, output format, exit threshold, and file inclusion/exclusion.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/medvertical/records-fhir-validator">https://github.com/medvertical/records-fhir-validator</a></strong> to version <strong>validator-v0.6.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fhir-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action provides a FHIR validator for CI pipelines, GitHub Actions, and standalone Node.js use. It validates FHIR JSON, XML, and NDJSON resources against StructureDefinitions, FHIRPath invariants, terminology bindings, references, slicing, extensions, Bundle rules, metadata, and custom rules without requiring a JVM or database. The action supports multiple FHIR versions and provides options for profile validation, output format, exit threshold, and file inclusion/exclusion.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>npm tarball release for <code>@records-fhir/validator@0.6.2</code>. Synced from medvertical/records monorepo.</p>
<h2 id="install">Install</h2>
<pre tabindex="0"><code>npm install @records-fhir/validator@0.6.2
</code></pre><h2 id="whats-new-in-062">What&rsquo;s new in 0.6.2</h2>
<p>Patch release closing Bundle, XML, and SNOMED edition gaps and adding
reproducible release evidence for every supported FHIR release. There are no
intentional breaking changes.</p>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Restored terminology and binding validation for resources nested in Bundle
entries. Duplicate parent/child findings are collapsed without losing the
resource-qualified path needed to locate the failing entry, while findings
from separate Bundle entry indices remain independent.</li>
<li>Forwarded <code>Coding.version</code> through terminology validation and routed SNOMED
CT edition URIs only to servers that explicitly advertise the requested
module through <code>snomedEditions</code>; that declaration alone makes the scoped
server response authoritative. Edition selection is now part of immutable
runtime snapshots and terminology cache keys, authoritative negative
responses remain invalid, and deep datatype traversal preserves the requested
version. ValueSet binding delegation sends <code>systemVersion</code>, version-specific
package loads cannot replace the unversioned CodeSystem cache, and
release-incompatible defaults fall back to an enabled generic server. A
missing edition route emits an actionable diagnostic instead of silently using
the wrong server.</li>
<li>Hardened FHIR XML conversion and the conformance resource loader so
namespace-aware XML resources, manifest inputs, and supporting resources use
the same bounded parser and reach validation as proper FHIR JSON objects.
Invalid leading-plus numeric lexemes stay visible to structural validation,
and repeating primitive sidecars remain aligned with their missing values so
<code>mustHaveValue</code> and <code>valueAlternatives</code> apply per occurrence.</li>
</ul>
<h3 id="quality">Quality</h3>
<ul>
<li>Added explicit JSON/XML and R4/R4B/R5/R6 conformance lanes, including small
clean and defect corpora for R4B and R6.</li>
<li>Added a reproducible validator performance baseline and a regression gate
with absolute ceilings, noise-floor handling, and report provenance checks.</li>
<li>Added FHIRSchema dual-path report freshness and provenance gates. The release
keeps StructureDefinition validation authoritative; FHIRSchema remains an
evidence-only comparison path until independently confirmed gaps justify a
runtime change.</li>
<li>Fixed the public-repository export boundary so its policy module is included
and the exported tree executes the privacy audit during regression tests.</li>
</ul>
<h2 id="matched-npm-tarballs">Matched npm tarballs</h2>
<ul>
<li><code>@records-fhir/validator@0.6.2</code> — also tagged <code>validator-v0.6.2</code></li>
<li><code>@records-fhir/validation-types@0.1.9</code></li>
</ul>
<p>The matching GitHub Action release (if any) is published separately under tag <code>v0.6.2</code> and is not auto-synced; this release covers the npm package only.</p>
]]></content:encoded></item><item><title>Unwrap Markdown prose</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/unwrap-markdown-prose/</link><pubDate>Wed, 26 Aug 2026 22:54:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/unwrap-markdown-prose/</guid><description>Version updated for https://github.com/michen00/markdown-prose-hooks to version v0.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the removal of manual soft-wrap line breaks from Markdown prose, ensuring that paragraphs are one line and diffs are as small as possible. It solves the problem of unwrapped prose leading to long lines, making diffs difficult to read and potentially breaking rendering in different environments. The action supports two implementations (Python and Rust) and is designed to be lightweight with minimal installation requirements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/michen00/markdown-prose-hooks">https://github.com/michen00/markdown-prose-hooks</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/unwrap-markdown-prose">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the removal of manual soft-wrap line breaks from Markdown prose, ensuring that paragraphs are one line and diffs are as small as possible. It solves the problem of unwrapped prose leading to long lines, making diffs difficult to read and potentially breaking rendering in different environments. The action supports two implementations (Python and Rust) and is designed to be lightweight with minimal installation requirements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/michen00/markdown-prose-hooks/compare/v0.2.1...v0.3.0">https://github.com/michen00/markdown-prose-hooks/compare/v0.2.1...v0.3.0</a></p>
]]></content:encoded></item><item><title>postmortem supply-chain gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postmortem-supply-chain-gate/</link><pubDate>Wed, 26 Aug 2026 22:54:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postmortem-supply-chain-gate/</guid><description>Version updated for https://github.com/mlab-sh/postmortem to version v2.3.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary postmortem is a fast, static analysis tool designed to detect potential supply-chain attacks by examining dependencies across various package managers. It provides reputation intelligence, vulnerability checks, and audit capabilities to ensure the integrity of your software supply chain. The action runs network requests only when necessary, ensuring minimal overhead and privacy.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mlab-sh/postmortem">https://github.com/mlab-sh/postmortem</a></strong> to version <strong>v2.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postmortem-supply-chain-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>postmortem is a fast, static analysis tool designed to detect potential supply-chain attacks by examining dependencies across various package managers. It provides reputation intelligence, vulnerability checks, and audit capabilities to ensure the integrity of your software supply chain. The action runs network requests only when necessary, ensuring minimal overhead and privacy.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mlab-sh/postmortem/compare/v2.2.0...v2.3.0">https://github.com/mlab-sh/postmortem/compare/v2.2.0...v2.3.0</a></p>
]]></content:encoded></item><item><title>Fetch Go and cache modules</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/fetch-go-and-cache-modules/</link><pubDate>Wed, 26 Aug 2026 22:53:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/fetch-go-and-cache-modules/</guid><description>Version updated for https://github.com/ndx-technologies/gh-setup-go to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of fetching Go and caching its modules. It simplifies development by ensuring that each developer uses the same version of Go and reduces build times by reusing module caches between builds. The action is zero-dependency, meaning it does not require additional tools beyond Git to function properly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ndx-technologies/gh-setup-go">https://github.com/ndx-technologies/gh-setup-go</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fetch-go-and-cache-modules">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of fetching Go and caching its modules. It simplifies development by ensuring that each developer uses the same version of Go and reduces build times by reusing module caches between builds. The action is zero-dependency, meaning it does not require additional tools beyond Git to function properly.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fetch Go compiler</li>
<li>cache modules to GitHub</li>
<li>no dependencies</li>
<li>no TypeScript</li>
</ul>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/go-proxy-cache-updater/</link><pubDate>Wed, 26 Aug 2026 22:52:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.49.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action updates Go module proxy caches by warming them with module versions when tags are pushed. It supports both HTTP and go-get methods, allowing customization of import paths and handling various errors during the caching process. The action is particularly useful for maintaining Go module proxies without requiring a Go toolchain installation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.49</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action updates Go module proxy caches by warming them with module versions when tags are pushed. It supports both HTTP and <code>go-get</code> methods, allowing customization of import paths and handling various errors during the caching process. The action is particularly useful for maintaining Go module proxies without requiring a Go toolchain installation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1149-2026-08-26"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.48...v1.1.49">1.1.49</a> (2026-08-26)</h2>
]]></content:encoded></item><item><title>github-backport</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/github-backport/</link><pubDate>Wed, 26 Aug 2026 22:51:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/github-backport/</guid><description>Version updated for https://github.com/nicklegan/backport to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “backport” automates the process of cherry-picking pull requests onto long-running backport branches and ensures that both the original pull request and its backports are merge-ready. It helps maintain stability by ensuring that all changes in the original PR are also included in the backported branches.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicklegan/backport">https://github.com/nicklegan/backport</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-backport">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;backport&rdquo; automates the process of cherry-picking pull requests onto long-running backport branches and ensures that both the original pull request and its backports are merge-ready. It helps maintain stability by ensuring that all changes in the original PR are also included in the backported branches.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="backport-v100">backport v1.0.0</h1>
<p>The first release of <strong>backport</strong> — a GitHub Action that cherry-picks a pull request onto long-running backport branches and gates the original pull request and its backports with a bidirectional, all-or-nothing merge-readiness check.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Automatic backport PRs</strong> — on open (or via <code>backport:&lt;branch&gt;</code> labels), the PR&rsquo;s own commits are cherry-picked onto each selected branch and the backport PR is opened right away.</li>
<li><strong>Bidirectional, all-or-nothing gate</strong> — <code>backports-ready</code> on the original and <code>original-ready</code> on each backport form a mutual barrier: nothing in the set merges until every pull request is independently mergeable. Readiness is reconstructed from non-circular signals, so the mutual dependency never deadlocks.</li>
<li><strong>Label-driven &amp; idempotent</strong> — <code>backport:&lt;branch&gt;</code> labels are the single source of truth: add to create, remove to close (branch kept), re-add to reopen. Everything is reconstructed each run, so it is fully stateless.</li>
<li><strong>GitHub App authentication</strong> — opens backport PRs with an App installation token so their CI actually runs (which the gate depends on).</li>
<li><strong>Merge-method-aware cherry-picks</strong> — <code>auto</code>, <code>individual</code>, or <code>squash</code>.</li>
<li><strong>Signed commits</strong> — optional GPG or SSH signing for branches that require it.</li>
<li><strong>Metadata sync</strong> — optionally keep the original PR&rsquo;s labels, milestone, assignees, and reviewers copied onto its backports.</li>
<li><strong>Auto-merge</strong> — optionally merge each backport once the original is merged and its own checks pass.</li>
<li><strong>Tunable readiness</strong> — <code>respect-required-only</code> and <code>require-conversation-resolution</code> control what the gate treats as blocking.</li>
</ul>
<h2 id="getting-started">Getting started</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">nicklegan/backport@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">app-id</span>: <span style="color:#ae81ff">${{ secrets.APP_ID }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">private-key</span>: <span style="color:#ae81ff">${{ secrets.APP_PRIVATE_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">backport-branches</span>: |<span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      release/v1.x
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      release/v2.x</span>
</span></span></code></pre></div><p>See the <a href="https://github.com/nicklegan/backport#readme">README</a> and the <a href="https://github.com/nicklegan/backport/blob/v1.0.0/docs/end-to-end-setup.md">end-to-end setup guide</a> for creating the GitHub App, configuring branch protection, and adding the pull request template.</p>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/run-aer-tests/</link><pubDate>Wed, 26 Aug 2026 22:51:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.38.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aer action is designed to run Apex and Apex unit tests locally without the need for an org or deployment. It provides a local environment where developers can execute code, including DML operations, SOQL queries, triggers, and validation rules, with support for testing frameworks and governor limits. Users can also step through Apex logic using an interactive debugger integrated into VS Code or IntelliJ.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.38</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>aer</code> action is designed to run Apex and Apex unit tests locally without the need for an org or deployment. It provides a local environment where developers can execute code, including DML operations, SOQL queries, triggers, and validation rules, with support for testing frameworks and governor limits. Users can also step through Apex logic using an interactive debugger integrated into VS Code or IntelliJ.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.38</p>
<ul>
<li>Convert WEEKDAY In A Flow Formula</li>
</ul>
]]></content:encoded></item><item><title>Chock Governance Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/chock-governance-check/</link><pubDate>Wed, 26 Aug 2026 22:50:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/chock-governance-check/</guid><description>Version updated for https://github.com/open-coder-ai/chock to version v0.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Chock automates AI coding agents’ rules by compiling them into deterministic guardrails that enforce policies across different CI/CD systems and tools used by developers. It ensures consistency in code standards and compliance with project requirements, reducing human errors and maintaining high-quality codebases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/open-coder-ai/chock">https://github.com/open-coder-ai/chock</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/chock-governance-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Chock automates AI coding agents&rsquo; rules by compiling them into deterministic guardrails that enforce policies across different CI/CD systems and tools used by developers. It ensures consistency in code standards and compliance with project requirements, reducing human errors and maintaining high-quality codebases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="050--managed-setting-and-skill-honesty">0.5.0 — Managed-setting and SKILL honesty</h2>
<p>MINOR: the Claude managed-setting emitter and the generated SKILL note change, so an
adopter&rsquo;s next <code>chock sync</code> / <code>chock plugin build</code> rewrites those artifacts. No credited
enforcement surface changes — both are non-credited/advisory outputs being brought into
line with what they can actually deliver (do-not-claim, applied to the emitter itself).</p>
<ul>
<li><strong><code>protect-main-branch</code> managed-setting is now empty.</strong> It previously emitted a
branch-blind command-text deny (<code>commit.*\b(main|master)\b</code>) that missed a plain
<code>git commit</code> on main and false-positived on &ldquo;main&rdquo; in a message. A static managed
setting cannot resolve branch state, so the honest managed-setting for branch
protection carries no deny — enforcement lives in its git-hook and ci-gate surfaces,
which do read the branch.</li>
<li><strong><code>scan-secrets</code> managed-setting aligned to the gate.</strong> Added <code>jks|keystore</code> to the
credential-file pattern and more high-confidence credential prefixes (xoxb, sk/rk_live,
sk-ant, AIza, npm_) so the in-session echo is less of a silent subset of the git-hook.
Kept lookahead-free for cross-client regex-engine safety; the git-hook remains
authoritative.</li>
<li><strong>SKILL advisory note is conditional on artifact.</strong> A <code>rule</code> (advise-tier) policy no
longer claims it &ldquo;becomes a git hook that exits non-zero&rdquo; when compiled — it ships rule
text and stays advisory. Only <code>hook</code> policies carry that line; guard-script policies
still get the enforced note in the per-client plugin formats.</li>
</ul>
]]></content:encoded></item><item><title>Web App Security Skill</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/web-app-security-skill/</link><pubDate>Wed, 26 Aug 2026 22:49:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/web-app-security-skill/</guid><description>Version updated for https://github.com/parousia8888/web-app-security-skill to version v0.7.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security audit of web projects using AI coding agents. It helps identify potential security vulnerabilities and provides actionable insights on how to address them without needing extensive offensive-security knowledge. The action can be run locally from the project root, reading local files and not contacting deployments or editing code. For supported JavaScript/TypeScript frameworks, it generates route security reports detailing application controls, authentication, authorization, and BOLA/IDOR risks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/parousia8888/web-app-security-skill">https://github.com/parousia8888/web-app-security-skill</a></strong> to version <strong>v0.7.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/web-app-security-skill">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the security audit of web projects using AI coding agents. It helps identify potential security vulnerabilities and provides actionable insights on how to address them without needing extensive offensive-security knowledge. The action can be run locally from the project root, reading local files and not contacting deployments or editing code. For supported JavaScript/TypeScript frameworks, it generates route security reports detailing application controls, authentication, authorization, and BOLA/IDOR risks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v073-release-evidence">v0.7.3 release evidence</h1>
<p>Status: release candidate. Phases 0-6 of the external-audit remediation plan are complete, and the
Phase 7 five-project candidate rerun is promoted into its active catalog. The local candidate gate
passed on code commit <code>0c6bbeda3785cf6e66df2920b5309f9d6a18c892</code>. Exact-commit CI/CodeQL, signed
tag, GitHub Release, npm provenance, verified installer, immutable Action consumer, signed <code>v1</code>
promotion and durable live-verification record remain gated.
Published v0.7.2 facts stay in <code>docs/release-state.json</code> until each v0.7.3 channel is independently
observed.</p>
<h2 id="outcome">Outcome</h2>
<p>v0.7.3 closes the 26-item external-audit ledger through accepted fixes, narrower corrected claims,
explicit limitations and historical evidence boundaries. It strengthens existing bounded analysis
and lifecycle evidence; it does not add a detector family or framework claim.</p>
<ul>
<li>Project-controlled paths, member expressions and workspace declarations are bounded. OSV inputs
are checked at persisted scope and again at the subprocess sink, including symlink containment.</li>
<li>Route inventory fails closed for supported-looking computed, unresolved or zero-eligible shapes.
Authentication, authorization and unclassified route controls remain separate, while Next.js
middleware/proxy participation is application context rather than per-route proof.</li>
<li>The public bounded authorization surface is <code>accessChains</code>. Shared principal/tenant vocabulary,
Prisma singleton resolution and incomplete-client evidence improve the existing chain without
claiming runtime authorization enforcement.</li>
<li>Direct compound HTML assignments, typed Python boolean configuration and context-specific
Markdown encoding close three narrow source/report correctness defects.</li>
<li>Five ordinary-project journeys use one pinned active contract with separate byte, deterministic
semantic, mutable-advisory and manual-annotation identity. The v0.7.3 rerun uses exact tool commit
<code>0cd79fd</code> and bounds Gitleaks history to commits reachable from each target commit; unrelated refs
are excluded. Historical v0.6.0 review bytes remain immutable and current-analyzer reproduction
remains <code>verification_pending</code> where raw invocation evidence was not retained.</li>
<li>Candidate, public and post-public release states are separate. Test outcome accounting records
passed, failed, skipped and not-run work, and the final post-public workflow creates one durable
live-verification Release asset only after immutable and <code>v1</code> consumers pass.</li>
<li>Current conformance, schema, capability, roadmap, release procedure and historical-plan deviation
contracts are executable and agree with the shipped bounded behavior.</li>
</ul>
<p>Stable inventory remains 25 built-in risk rules, three evidence-integrity rules, 16 opt-in external
adapter risk rules and bounded Express, NestJS and Next.js App Router/Server Action review. Pattern
matches remain <code>suspected</code>; unavailable evidence remains <code>unknown</code> and cannot become pass.</p>
<h2 id="issue-closure">Issue closure</h2>
<p>All issue records remain available in
<a href="../V0.7.3_EXTERNAL_AUDIT_REMEDIATION_PLAN.md"><code>V0.7.3_EXTERNAL_AUDIT_REMEDIATION_PLAN.md</code></a>.</p>
<table>
  <thead>
      <tr>
          <th>Issue set</th>
          <th>Candidate disposition</th>
          <th>Closure mechanism</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>EA-01 to EA-03</td>
          <td>accepted or accepted-reframed</td>
          <td>input/path containment, bounded analysis and structural workspace matching</td>
      </tr>
      <tr>
          <td>EA-04</td>
          <td>claim-corrected</td>
          <td>documented exit-domain handling with valid incomplete artifacts retained</td>
      </tr>
      <tr>
          <td>EA-05 to EA-07, EA-10 to EA-14</td>
          <td>accepted, reframed or claim-corrected</td>
          <td>fail-closed framework inventory, separated controls and bounded access-chain/source fixes</td>
      </tr>
      <tr>
          <td>EA-08, EA-09</td>
          <td>claim-corrected</td>
          <td>dead parallel output removed; one public authorization-analysis surface and shared vocabulary</td>
      </tr>
      <tr>
          <td>EA-15</td>
          <td>claim-corrected</td>
          <td>typed Python boolean evidence rather than value-string comparison</td>
      </tr>
      <tr>
          <td>EA-16 to EA-18</td>
          <td>accepted or accepted-reframed</td>
          <td>active five-project contract with pinned prerequisites and separated digest semantics</td>
      </tr>
      <tr>
          <td>EA-19 to EA-24</td>
          <td>accepted or accepted-reframed</td>
          <td>independent release/test states, explicit CA input, least privilege and corrected trust claims</td>
      </tr>
      <tr>
          <td>EA-25, EA-26</td>
          <td>accepted</td>
          <td>immutable historical provenance, stable current paths and executable document/as-built contracts</td>
      </tr>
  </tbody>
</table>
<h2 id="regression-evidence">Regression evidence</h2>
<ul>
<li>Scope, OSV, workspace and untrusted-source matrices plant traversal, symlink, deep-expression,
invalid metadata, wildcard and neighboring valid inputs.</li>
<li>Route matrices cover computed and optional Express registrations, sibling middleware mounts,
unclassified controls, zero eligible modules, static/dynamic Next matchers and Prisma singleton
positive and negative neighbors.</li>
<li>JS/TS, Python and renderer tests plant compound sinks, string/numeric boolean impostors and
Markdown heading/task injection.</li>
<li>Journey tests cover exit 0/1/2/3, prerequisite drift, deterministic versus mutable digests,
Gitleaks redaction collisions, shallow-history refusal, ref-set independence and five exact target
commits.</li>
<li>Release/test tests cover early test failure, skipped external prerequisites, candidate refusal to
claim public state, public digest mismatch, stale <code>v1</code>, required attestation and repeatable durable
live-record publication.</li>
<li>Document, conformance, scope-schema and historical-provenance checks reject stale labels, broken
links, undeclared planned-file drift, path-validation disagreement and overwritten history.</li>
</ul>
<p>Every silently reversible false-clean mechanism received a focused machine assertion and a
plant-the-failure check in its owning phase. Candidate stabilization also corrected old test and
fixture assumptions without converting route-evidence <code>unknown</code> into pass.</p>
<h2 id="candidate-verification">Candidate verification</h2>
<p>Completed local candidate checks:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm run check                    <span style="color:#75715e"># exit 0</span>
</span></span><span style="display:flex;"><span>npm pack --dry-run --json        <span style="color:#75715e"># exit 0; 201 files; 574376 bytes</span>
</span></span><span style="display:flex;"><span>quick_validate.py .              <span style="color:#75715e"># Skill is valid</span>
</span></span><span style="display:flex;"><span>git diff --check                 <span style="color:#75715e"># exit 0</span>
</span></span></code></pre></div><p><code>npm run check</code> recorded 71 passed, zero failed, one skipped and zero not-run test files; its four
named prerequisite surfaces recorded three passed, zero failed, one skipped and zero not run. The
default local result is therefore <code>partial</code>, not a claim that the opt-in real-adapter binaries or a
Claude CLI surface ran. The package dry run reported unpacked size 2,300,148 bytes, shasum
<code>478e9e5eac15fde316860e5278bc5a9a1b4e58b2</code> and integrity
<code>sha512-XNEzUecyqg9CgrvmF3tuEIFJ5Jyy3RMTQPg47dHKP4RTJCmyUVwzYTDZfrqhs5thnvSLyNKjPpPG27dMjaBU7g==</code>.</p>
<p>Tag verification remains pending until exact-commit CI and CodeQL pass and the SSH-signed annotated
<code>v0.7.3</code> tag exists. The tag triggers reproducible archive, SPDX SBOM, checksums, release manifest,
GitHub attestation and GitHub Release publication. npm trusted publishing, installer/bootstrap trust
updates, immutable Action and signed <code>v1</code> promotion remain separate later gates.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>git -c gpg.ssh.allowedSignersFile<span style="color:#f92672">=</span>.github/release-signers verify-tag v0.7.3
</span></span></code></pre></div><h2 id="public-release-facts">Public release facts</h2>
<p>Pending. This section will record only publicly retrievable tag, workflow, artifact, npm,
installation, immutable consumer, moving-alias and live-verification facts after each check passes.</p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/skilltotal-ai-component-security-scan/</link><pubDate>Wed, 26 Aug 2026 22:48:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.43.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SkillTotal is an open-source CLI tool that statically analyzes AI-related components to identify supply-chain risks, dangerous capabilities, prompt-injection surfaces, and data-exfiltration paths before they are installed or trusted. It analyzes only the component itself, providing evidence-backed findings without relying on runtime analysis. SkillTotal runs locally without any account or cloud upload, ensuring safe analysis of untrusted components.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.43.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SkillTotal is an open-source CLI tool that statically analyzes AI-related components to identify supply-chain risks, dangerous capabilities, prompt-injection surfaces, and data-exfiltration paths before they are installed or trusted. It analyzes only the component itself, providing evidence-backed findings without relying on runtime analysis. SkillTotal runs locally without any account or cloud upload, ensuring safe analysis of untrusted components.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>A <code>.env</code> shipped inside a released package is detected (ruleset 47).</strong> The scanner understood a
<em>reference</em> to <code>.env</code> in code but not the file&rsquo;s presence in the artifact, so a published npm
package carrying a real <code>.env</code> scored 0/100. It fires only for published packages — a <code>.env</code> in a
working tree is correct usage — skips <code>.env.example</code> and friends, and reports the variable
<strong>names with the values withheld</strong>, since a report that carried them would be the leak.</li>
</ul>
]]></content:encoded></item><item><title>action-debian-build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/action-debian-build/</link><pubDate>Wed, 26 Aug 2026 22:47:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/action-debian-build/</guid><description>Version updated for https://github.com/pkghaus/action-debian-build to version v1.1.0.
This action is used across all versions by 1 repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of building a Debian package from an upstream Git tag and a local debian/ directory. It handles the entire packaging lifecycle, including resolving build dependencies, running dpkg-buildpackage, checking with lintian, and collecting artifacts. The action is designed for packaging repositories that maintain only their own packaging files and configuration, without uploading packages to any external repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pkghaus/action-debian-build">https://github.com/pkghaus/action-debian-build</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<p>Go to the <a href="https://github.com/marketplace/actions/action-debian-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of building a Debian package from an upstream Git tag and a local <code>debian/</code> directory. It handles the entire packaging lifecycle, including resolving build dependencies, running <code>dpkg-buildpackage</code>, checking with <code>lintian</code>, and collecting artifacts. The action is designed for packaging repositories that maintain only their own packaging files and configuration, without uploading packages to any external repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="110---2026-08-26">[1.1.0] - 2026-08-26</h2>
<h3 id="added">Added</h3>
<ul>
<li>DEP-8 tests run after the build for any package shipping <code>debian/tests/</code>.
A package without <code>debian/tests/control</code> is unaffected. Set <code>dep8: &quot;off&quot;</code> on
<code>build.yml</code>, or <code>DEP8: &quot;off&quot;</code> on the action, to skip them.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>The reusable <code>build.yml</code> now calls this repository&rsquo;s own action instead of
reimplementing the <code>docker run</code>.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>DBGSYM</code> rejects a value it does not understand. It was compared against <code>1</code>
alone, so <code>DBGSYM=yes</code> silently disabled the package it was written to
enable. <code>off</code> and <code>on</code> are now accepted alongside <code>0</code> and <code>1</code>.</li>
</ul>
]]></content:encoded></item><item><title>Plori persistent agent review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/plori-persistent-agent-review/</link><pubDate>Wed, 26 Aug 2026 22:46:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/plori-persistent-agent-review/</guid><description>Version updated for https://github.com/plori-ai/agent-action to version v1.0.8.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the review process by checking out pull request commits, inspecting surrounding code, and running targeted tests instead of just comparing diffs. It uses OIDC capability minting to securely access repositories without permanently saving them. The action provides precision in identifying actionable findings, focusing on migration rollback safety and API compatibility for example.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plori-ai/agent-action">https://github.com/plori-ai/agent-action</a></strong> to version <strong>v1.0.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/plori-persistent-agent-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the review process by checking out pull request commits, inspecting surrounding code, and running targeted tests instead of just comparing diffs. It uses OIDC capability minting to securely access repositories without permanently saving them. The action provides precision in identifying actionable findings, focusing on migration rollback safety and API compatibility for example.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The default reviewer now favors precision over volume. It reports an issue only when the current diff introduces a concrete failure or contract violation that the agent can support with evidence. Style preferences, speculative edge cases, and unrelated cleanup are omitted by default. Useful polish suggestions are clearly labeled as optional and non-blocking. Sound changes receive <code>No actionable findings.</code> instead of a manufactured objection.</p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-workspace-bootstrap/</link><pubDate>Wed, 26 Aug 2026 22:45:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.21.2.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of a Postman workspace by importing an OpenAPI specification and generating predefined collections that include baseline, smoke, and contract tests. The action supports various protocols like gRPC, SOAP, GraphQL, AsyncAPI, and MCP, ensuring comprehensive test coverage grounded in RFCs. It also provides dynamic contract tests, error codes for enforcement layers, and is part of a larger suite for Postman API onboarding.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.21.2</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of a Postman workspace by importing an OpenAPI specification and generating predefined collections that include baseline, smoke, and contract tests. The action supports various protocols like gRPC, SOAP, GraphQL, AsyncAPI, and MCP, ensuring comprehensive test coverage grounded in RFCs. It also provides dynamic contract tests, error codes for enforcement layers, and is part of a larger suite for Postman API onboarding.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: normalize multifile receipt after v2.16.1 by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/179">https://github.com/postman-cs/postman-bootstrap-action/pull/179</a></li>
<li>fix(gateway-assets): fail closed when org squad discovery is indeterminate by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/180">https://github.com/postman-cs/postman-bootstrap-action/pull/180</a></li>
<li>feat(release): gate aliases on correlated E2E by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/181">https://github.com/postman-cs/postman-bootstrap-action/pull/181</a></li>
<li>fix(release): wait for run-name hydration by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/182">https://github.com/postman-cs/postman-bootstrap-action/pull/182</a></li>
<li>fix(release): notify the composite after Bootstrap publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/183">https://github.com/postman-cs/postman-bootstrap-action/pull/183</a></li>
<li>feat: add generated asset sync control by @sean-riney in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/186">https://github.com/postman-cs/postman-bootstrap-action/pull/186</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/188">https://github.com/postman-cs/postman-bootstrap-action/pull/188</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/191">https://github.com/postman-cs/postman-bootstrap-action/pull/191</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/192">https://github.com/postman-cs/postman-bootstrap-action/pull/192</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/194">https://github.com/postman-cs/postman-bootstrap-action/pull/194</a></li>
<li>fix(ci): address Codex writeback feedback by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/195">https://github.com/postman-cs/postman-bootstrap-action/pull/195</a></li>
<li>fix(ci): use ESM execSync and update permission test by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/196">https://github.com/postman-cs/postman-bootstrap-action/pull/196</a></li>
<li>chore: normalize multifile receipt after v2.18.3 by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/197">https://github.com/postman-cs/postman-bootstrap-action/pull/197</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/198">https://github.com/postman-cs/postman-bootstrap-action/pull/198</a></li>
<li>chore: rebind multifile receipt to main by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/199">https://github.com/postman-cs/postman-bootstrap-action/pull/199</a></li>
<li>ci: run dist parity after skipped normalizer by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/200">https://github.com/postman-cs/postman-bootstrap-action/pull/200</a></li>
<li>feat: publish as @postman/onboarding-bootstrap with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/208">https://github.com/postman-cs/postman-bootstrap-action/pull/208</a></li>
<li>ci: install restricted dependencies without npm token by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/209">https://github.com/postman-cs/postman-bootstrap-action/pull/209</a></li>
<li>chore: rebind multifile receipt to main by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/210">https://github.com/postman-cs/postman-bootstrap-action/pull/210</a></li>
<li>fix(deps): move private @postman platform packages to devDependencies by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/211">https://github.com/postman-cs/postman-bootstrap-action/pull/211</a></li>
<li>feat: support monorepo working directories by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/212">https://github.com/postman-cs/postman-bootstrap-action/pull/212</a></li>
<li>feat: accelerate collection convergence by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/213">https://github.com/postman-cs/postman-bootstrap-action/pull/213</a></li>
<li>fix: enforce exact collection convergence by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/214">https://github.com/postman-cs/postman-bootstrap-action/pull/214</a></li>
<li>fix: consolidate contract validation into collection root script and optimize delta convergence by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/215">https://github.com/postman-cs/postman-bootstrap-action/pull/215</a></li>
<li>fix(release): skip burnt tags with stale aliases by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/216">https://github.com/postman-cs/postman-bootstrap-action/pull/216</a></li>
<li>test: keep contract root fixtures package-local by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/217">https://github.com/postman-cs/postman-bootstrap-action/pull/217</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2.16.1...v2.21.2">https://github.com/postman-cs/postman-bootstrap-action/compare/v2.16.1...v2.21.2</a></p>
]]></content:encoded></item><item><title>Setup Flutter with pub cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/setup-flutter-with-pub-cache/</link><pubDate>Wed, 26 Aug 2026 22:45:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/setup-flutter-with-pub-cache/</guid><description>Version updated for https://github.com/Project516/setup-flutter to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-flutter GitHub Action automates the setup of Flutter in CI/CD pipelines by handling three key tasks: installing the latest stable or beta version of Flutter, restoring the pub cache from a local directory, and running flutter pub get. It provides caching for both the Flutter SDK and pub packages to speed up subsequent builds. The action is designed to replace repetitive steps in Flutter CI jobs, making them more efficient and reducing maintenance overhead.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Project516/setup-flutter">https://github.com/Project516/setup-flutter</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-flutter-with-pub-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>setup-flutter</code> GitHub Action automates the setup of Flutter in CI/CD pipelines by handling three key tasks: installing the latest stable or beta version of Flutter, restoring the pub cache from a local directory, and running <code>flutter pub get</code>. It provides caching for both the Flutter SDK and pub packages to speed up subsequent builds. The action is designed to replace repetitive steps in Flutter CI jobs, making them more efficient and reducing maintenance overhead.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Pin wrapped actions by SHA by @Project516 in <a href="https://github.com/Project516/setup-flutter/pull/10">https://github.com/Project516/setup-flutter/pull/10</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Project516/setup-flutter/compare/v1.0.2...v1.0.3">https://github.com/Project516/setup-flutter/compare/v1.0.2...v1.0.3</a></p>
]]></content:encoded></item><item><title>action-semver</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/action-semver/</link><pubDate>Wed, 26 Aug 2026 22:44:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/action-semver/</guid><description>Version updated for https://github.com/quike/action-semantic-release to version v3.20.0.
This action is used across all versions by 5 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action-semantic-release GitHub Action automates the release process using semantic-release, a tool that helps you manage and automate versioning of your projects based on commit messages. It solves the problem of maintaining accurate and consistent version numbers for your project releases through automated testing and tagging processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quike/action-semantic-release">https://github.com/quike/action-semantic-release</a></strong> to version <strong>v3.20.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-semver">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>action-semantic-release</code> GitHub Action automates the release process using semantic-release, a tool that helps you manage and automate versioning of your projects based on commit messages. It solves the problem of maintaining accurate and consistent version numbers for your project releases through automated testing and tagging processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="3200-2026-08-26"><a href="https://github.com/quike/action-semantic-release/compare/v3.19.0...v3.20.0">3.20.0</a> (2026-08-26)</h1>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/agentauditkit-mcp-security-scan/</link><pubDate>Wed, 26 Aug 2026 22:44:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.90.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner designed to audit AI agent pipelines and detect misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across multiple platforms. It can run offline and deterministically, ensuring that the findings are consistent across different runs without relying on external services.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.90</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit is a security scanner designed to audit AI agent pipelines and detect misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across multiple platforms. It can run offline and deterministically, ensuring that the findings are consistent across different runs without relying on external services.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.90
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.90
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.90</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.89...v0.3.90">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.89...v0.3.90</a></p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/bernstein-multi-agent-orchestration/</link><pubDate>Wed, 26 Aug 2026 22:43:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.18.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the orchestration of multi-agent CLI tasks, ensuring deterministic execution by leveraging a robust framework designed to manage and schedule complex workflows efficiently. It provides capabilities for building and running agent-based environments, making it ideal for developers who need to orchestrate complex workflows involving multiple independent components or agents.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.18.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the orchestration of multi-agent CLI tasks, ensuring deterministic execution by leveraging a robust framework designed to manage and schedule complex workflows efficiently. It provides capabilities for building and running agent-based environments, making it ideal for developers who need to orchestrate complex workflows involving multiple independent components or agents.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A patch release, which is to say: the machine worked all night and somebody had to write down what it did.</p>
<h2 id="the-review-loop-became-a-product">The review loop became a product</h2>
<p><code>bernstein review --pipeline --fix --until-checks-green --max-passes N</code> now runs the whole contour inside the CLI: wait for checks to settle, review the diff, hand the verdict and the failing logs to a fix pass, review again. A spent budget exits <code>needs-operator</code>, not an approval. Every pass emits a signed receipt binding the reviewed diff hash to the ruleset digest, and <code>review-receipt verify --chain</code> rejects a pass whose diff moved under it (#4481). Plans render deterministically and carry a SHA-256 of the rendering, so approval binds to what the reviewer saw (#3839, #4473).</p>
<h2 id="attestation-minus-the-noise">Attestation, minus the noise</h2>
<p>An unresolved SLA breach is attested once — not once per supervisor tick, which at one tick a second had turned a single breach into thousands of identical receipts (#4579). The monitor itself now runs on every <code>schedule run</code> tick (#4538, #4583). Operator approvals and always-allow promotions land on the HMAC audit chain (#4536); pre-spawn pending approvals show up in <code>GET /approvals</code> instead of hiding (#4535); an approval PR that failed to open says so, rather than waiting forever in silence (#4582). <code>artifact verify</code> on a host with no audit key no longer mints one and calls every clean receipt TAMPERED — it names the missing key and fails honestly (#4581). A deliverable that is raw bytes can be anchored too: the <code>blob</code> artifact kind reaches every declaration surface (#4544), and SARIF findings reach the MCP schema (#4533).</p>
<h2 id="housekeeping-with-a-spine">Housekeeping with a spine</h2>
<p>Execution tasks with no completion signals and no commits are rejected instead of counted as done (#4560). Three caller-less modules under <code>core/tokens/</code> are gone, and a structural guard fails CI when the next one appears (#4525). One infrastructure flake no longer holds every merge in the repository (#4596); path-filtered workflows can&rsquo;t wedge a PR as permanently pending (#4557); branch-protection drift opens a marker issue instead of drifting quietly (#4558). Ticket integrations honour <code>Retry-After</code> and trip a circuit breaker on 429s (#4534). And a config-level auth opt-out that one refactor quietly broke is honoured again, with the regression tests it should have had (#4602).</p>
<h2 id="contributors">Contributors</h2>
<ul>
<li><strong>Chirag Honnyal</strong> — empty-signal task rejection (#4564) and the path-filter CI guard (#4570).</li>
<li><strong>jm27</strong> — the artifact contract surfaced in the spawn prompt (#4575).</li>
<li><strong>Louis20060723</strong> — <code>agents-md sync</code> resolves the default branch from the repository, not the checkout (#4585).</li>
</ul>
<hr>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(hygiene): reject committed text files that start with a UTF-8 BOM by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4506">https://github.com/sipyourdrink-ltd/bernstein/pull/4506</a></li>
<li>feat(lineage): assemble a RunGraph pairing worktree branches with their spines by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4507">https://github.com/sipyourdrink-ltd/bernstein/pull/4507</a></li>
<li>fix(skills): refuse a plugin install that would replace another source&rsquo;s skill by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4510">https://github.com/sipyourdrink-ltd/bernstein/pull/4510</a></li>
<li>test(planning): pin which fields the plan-approval digest protects by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4511">https://github.com/sipyourdrink-ltd/bernstein/pull/4511</a></li>
<li>docs(release-notes): credit the contributors whose work shipped in v3.18.0 by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4520">https://github.com/sipyourdrink-ltd/bernstein/pull/4520</a></li>
<li>chore(deps): update prom/prometheus docker tag to v3.14.0 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4519">https://github.com/sipyourdrink-ltd/bernstein/pull/4519</a></li>
<li>feat(review): run the fix-until-green contour inside review &ndash;pipeline (#4481) by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4518">https://github.com/sipyourdrink-ltd/bernstein/pull/4518</a></li>
<li>fix(quality): run the repo seed&rsquo;s lint gate through uv by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4547">https://github.com/sipyourdrink-ltd/bernstein/pull/4547</a></li>
<li>chore(deps): update grafana/grafana docker tag to v13.2.0 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4527">https://github.com/sipyourdrink-ltd/bernstein/pull/4527</a></li>
<li>fix(deps): update dependency agents to ^0.21.0 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4528">https://github.com/sipyourdrink-ltd/bernstein/pull/4528</a></li>
<li>chore(deps): update dependency lucide-react to v1.32.0 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4549">https://github.com/sipyourdrink-ltd/bernstein/pull/4549</a></li>
<li>feat(evolve): add &ndash;dry-run flag and failure-pattern draft GitHub sync by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4550">https://github.com/sipyourdrink-ltd/bernstein/pull/4550</a></li>
<li>test(skills): pin DNS-rebinding rejection for the catalog index URL by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4551">https://github.com/sipyourdrink-ltd/bernstein/pull/4551</a></li>
<li>chore(gui): rebuild the shipped SPA bundle after the lucide-react bump by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4552">https://github.com/sipyourdrink-ltd/bernstein/pull/4552</a></li>
<li>ci: finish making the SPA bundle gate required by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4556">https://github.com/sipyourdrink-ltd/bernstein/pull/4556</a></li>
<li>feat(security): opt-in host restriction for third-party-derived URLs by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4555">https://github.com/sipyourdrink-ltd/bernstein/pull/4555</a></li>
<li>feat(evidence): expose finding artifact type to MCP schema and HTTP route (#4533) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4559">https://github.com/sipyourdrink-ltd/bernstein/pull/4559</a></li>
<li>fix(approval): record human resolutions and promotions to the audit chain (#4536) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4561">https://github.com/sipyourdrink-ltd/bernstein/pull/4561</a></li>
<li>fix(janitor): resolve test_passes paths against the tree before running them by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4554">https://github.com/sipyourdrink-ltd/bernstein/pull/4554</a></li>
<li>fix(tickets): handle 429 rate limits and wire provider circuit breaker (#4534) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4566">https://github.com/sipyourdrink-ltd/bernstein/pull/4566</a></li>
<li>fix(approvals): surface pre-spawn approval-spec pendings in GET /approvals (#4535) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4565">https://github.com/sipyourdrink-ltd/bernstein/pull/4565</a></li>
<li>fix(janitor): judge signal-less tasks instead of skipping them by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4563">https://github.com/sipyourdrink-ltd/bernstein/pull/4563</a></li>
<li>fix(approval): record human approval decisions in the audit chain by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4567">https://github.com/sipyourdrink-ltd/bernstein/pull/4567</a></li>
<li>fix(ci): surface branch protection audit failure and drift via marker issues (#4558) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4569">https://github.com/sipyourdrink-ltd/bernstein/pull/4569</a></li>
<li>fix(quality): reject execution tasks with no signals and no commits (#4560) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4564">https://github.com/sipyourdrink-ltd/bernstein/pull/4564</a></li>
<li>test(ci): guard required status checks against path-filtered PR triggers (#4557) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4570">https://github.com/sipyourdrink-ltd/bernstein/pull/4570</a></li>
<li>feat(server): reject artifact_spec combined with llm_judge at parse time (#4540) by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4572">https://github.com/sipyourdrink-ltd/bernstein/pull/4572</a></li>
<li>fix(spawn): build code context from ranked snippets under a token budget (#4524) by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4574">https://github.com/sipyourdrink-ltd/bernstein/pull/4574</a></li>
<li>fix(#4539): surface artifact contract in spawn prompt by @jm27 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4575">https://github.com/sipyourdrink-ltd/bernstein/pull/4575</a></li>
<li>fix(quality): name a missing mutation tool instead of reporting non-zero by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4576">https://github.com/sipyourdrink-ltd/bernstein/pull/4576</a></li>
<li>feat: implement pack field and collision guard for plugin-sourced skills by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4577">https://github.com/sipyourdrink-ltd/bernstein/pull/4577</a></li>
<li>feat: Wire SLA monitor to schedule supervisor by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4579">https://github.com/sipyourdrink-ltd/bernstein/pull/4579</a></li>
<li>refactor(server_supervisor): move httpx imports to top level, remove unused suppress import by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4580">https://github.com/sipyourdrink-ltd/bernstein/pull/4580</a></li>
<li>fix: artifact verify mints a fresh audit key on hosts without one, turning clean receipts into false TAMPERED verdicts by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4581">https://github.com/sipyourdrink-ltd/bernstein/pull/4581</a></li>
<li>feat: fix import sorting in test_approval_gate_missing_worktree.py by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4582">https://github.com/sipyourdrink-ltd/bernstein/pull/4582</a></li>
<li>feat: schedule supervisor ticking in default daemon install by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4583">https://github.com/sipyourdrink-ltd/bernstein/pull/4583</a></li>
<li>docs: regenerate adapter last-green table from canary receipts by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4584">https://github.com/sipyourdrink-ltd/bernstein/pull/4584</a></li>
<li>fix(agents-md): resolve default branch from the repository, not the checkout (#4578) by @Louis20060723 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4585">https://github.com/sipyourdrink-ltd/bernstein/pull/4585</a></li>
<li>fix(wrap-up): report what changed when no task completed by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4588">https://github.com/sipyourdrink-ltd/bernstein/pull/4588</a></li>
<li>fix(evolution): stop reporting upgrades as applied when nothing reads them by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4586">https://github.com/sipyourdrink-ltd/bernstein/pull/4586</a></li>
<li>chore(deps): update dependency lucide-react to v1.33.0 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4587">https://github.com/sipyourdrink-ltd/bernstein/pull/4587</a></li>
<li>chore: drop run scratch committed at the repo root by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4589">https://github.com/sipyourdrink-ltd/bernstein/pull/4589</a></li>
<li>feat(artifacts): blob artifact kind reaches every declaration surface by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4591">https://github.com/sipyourdrink-ltd/bernstein/pull/4591</a></li>
<li>fix(sla): attest an unresolved breach once, not once per tick by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4592">https://github.com/sipyourdrink-ltd/bernstein/pull/4592</a></li>
<li>fix(approval): surface an approval PR that could not be created by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4593">https://github.com/sipyourdrink-ltd/bernstein/pull/4593</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v10 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4594">https://github.com/sipyourdrink-ltd/bernstein/pull/4594</a></li>
<li>docs(release-notes): backfill fragments for two user-visible changes by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4595">https://github.com/sipyourdrink-ltd/bernstein/pull/4595</a></li>
<li>fix(ci): stop a single infra flake from holding every merge by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4596">https://github.com/sipyourdrink-ltd/bernstein/pull/4596</a></li>
<li>fix(tokens): remove three caller-less modules and make the orphan guard correct by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4597">https://github.com/sipyourdrink-ltd/bernstein/pull/4597</a></li>
<li>feat: Create insights command and persistence module by @bernstein-orchestrator[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4598">https://github.com/sipyourdrink-ltd/bernstein/pull/4598</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v10.0.1 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4599">https://github.com/sipyourdrink-ltd/bernstein/pull/4599</a></li>
<li>chore(ci): ratchet coverage baseline up to 84.2% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4600">https://github.com/sipyourdrink-ltd/bernstein/pull/4600</a></li>
<li>chore(ci): ratchet coverage baseline up to 84.22% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4601">https://github.com/sipyourdrink-ltd/bernstein/pull/4601</a></li>
<li>fix(auth): dispatch honours the factory-resolved opt-out again by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4602">https://github.com/sipyourdrink-ltd/bernstein/pull/4602</a></li>
<li>release: v3.18.1 by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4603">https://github.com/sipyourdrink-ltd/bernstein/pull/4603</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@jm27 made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4575">https://github.com/sipyourdrink-ltd/bernstein/pull/4575</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sipyourdrink-ltd/bernstein/compare/v3.18.0...v3.18.1">https://github.com/sipyourdrink-ltd/bernstein/compare/v3.18.0...v3.18.1</a></p>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/update-a-config-file-with-values-from-environment/</link><pubDate>Wed, 26 Aug 2026 22:42:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces placeholders in a configuration file with values from environment variables. It simplifies managing sensitive data such as API keys or database credentials by keeping them out of version control and making it easier to manage different configurations for different environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces placeholders in a configuration file with values from environment variables. It simplifies managing sensitive data such as API keys or database credentials by keeping them out of version control and making it easier to manage different configurations for different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add support for .env files (e706be3)</li>
<li>chore: More info (d440258)</li>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Wed, 26 Aug 2026 22:42:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by bundling and committing the dist folder to the repository before each push. This ensures that the latest built output is included in the pushed code, facilitating seamless integration into the deployment process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by bundling and committing the <code>dist</code> folder to the repository before each push. This ensures that the latest built output is included in the pushed code, facilitating seamless integration into the deployment process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/delivery-autopilot-runner/</link><pubDate>Wed, 26 Aug 2026 22:42:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.45.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: Delivery Autopilot Runner is a GitHub Action that uses an AI pipeline hosted by Tekunda to automate the development process. It reads tickets from your tracker, generates code and runs quality checks on it, and opens a pull request for review. The action requires an active Delivery Autopilot subscription and does not require any special setup beyond installing the app or configuring a workflow YAML file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.45</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong>
Delivery Autopilot Runner is a GitHub Action that uses an AI pipeline hosted by Tekunda to automate the development process. It reads tickets from your tracker, generates code and runs quality checks on it, and opens a pull request for review. The action requires an active Delivery Autopilot subscription and does not require any special setup beyond installing the app or configuring a workflow YAML file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runner-dist synced from AutoPilot 70aed80c32b9. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>Tessl Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/tessl-code-review/</link><pubDate>Wed, 26 Aug 2026 22:41:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/tessl-code-review/</guid><description>Version updated for https://github.com/tesslio/code-review-action to version v1.4.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Tessl Code Review GitHub Action automates the process of running Tessl Code Review on pull requests in a repository. It handles review resolution, exact-head checkout, Tessl CLI setup, review publication, stale-head protection, idempotency, failure notices, and result artifacts. The action runs automatically when pull requests are opened or reopened, providing an integrated code review experience within GitHub workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tesslio/code-review-action">https://github.com/tesslio/code-review-action</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tessl-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Tessl Code Review GitHub Action automates the process of running Tessl Code Review on pull requests in a repository. It handles review resolution, exact-head checkout, Tessl CLI setup, review publication, stale-head protection, idempotency, failure notices, and result artifacts. The action runs automatically when pull requests are opened or reopened, providing an integrated code review experience within GitHub workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Pin the Action to this release&rsquo;s commit SHA:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">tesslio/code-review-action@f72c50f92d6829931dfb68ef0bf7ac29191856f3</span> <span style="color:#75715e"># v1.4.0</span>
</span></span></code></pre></div><p>This revision installs the current Tessl CLI release. Set the
<code>cli-version</code> input to pin an exact one.</p>
<p>The major tag now points here, so a caller on that tag is on this
revision.</p>
]]></content:encoded></item><item><title>Generate ML-DSA Signatures</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/generate-ml-dsa-signatures/</link><pubDate>Wed, 26 Aug 2026 22:40:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/generate-ml-dsa-signatures/</guid><description>Version updated for https://github.com/theQRL/actions-mldsa-sign to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action actions-mldsa-sign automates the generation of ML-DSA-87 (FIPS 204) post-quantum signatures for files. It solves the problem of securely signing artifacts to ensure they cannot be reused for other purposes, using a context string for domain separation. The action requires a hexseed and a context string, supports multiple file patterns, and outputs a signatures file with one line per signed file, signature first.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/theQRL/actions-mldsa-sign">https://github.com/theQRL/actions-mldsa-sign</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/generate-ml-dsa-signatures">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>actions-mldsa-sign</code> automates the generation of ML-DSA-87 (FIPS 204) post-quantum signatures for files. It solves the problem of securely signing artifacts to ensure they cannot be reused for other purposes, using a context string for domain separation. The action requires a hexseed and a context string, supports multiple file patterns, and outputs a signatures file with one line per signed file, signature first.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="actions-mldsa-sign">actions-mldsa-sign</h1>
<p>Initial public release of <code>actions-mldsa-sign</code> — a GitHub Action that signs build artifacts with <strong>ML-DSA-87 (FIPS 204)</strong> post-quantum signatures.</p>
<p>It supersedes <a href="https://github.com/theQRL/actions-dilithium-sign"><code>actions-dilithium-sign</code></a>, which is deprecated.</p>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">theQRL/actions-mldsa-sign@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">patterns</span>: |<span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      dist/*.zip</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">hexseed</span>: <span style="color:#ae81ff">${{ secrets.MLDSA_HEXSEED }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">context</span>: <span style="color:#ae81ff">my-app-releases</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">output</span>: <span style="color:#ae81ff">signatures.txt</span>
</span></span></code></pre></div><h2 id="inputs">Inputs</h2>
<table>
  <thead>
      <tr>
          <th>Input</th>
          <th>Required</th>
          <th>Default</th>
          <th>Description</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>hexseed</code></td>
          <td>Yes</td>
          <td>–</td>
          <td>ML-DSA hexseed used for signing — store it as a repository secret</td>
      </tr>
      <tr>
          <td><code>context</code></td>
          <td>Yes</td>
          <td>–</td>
          <td>Context string for FIPS 204 domain separation (0–255 bytes)</td>
      </tr>
      <tr>
          <td><code>patterns</code></td>
          <td>Yes</td>
          <td>–</td>
          <td>Glob patterns for files to sign, one per line</td>
      </tr>
      <tr>
          <td><code>output</code></td>
          <td>No</td>
          <td><code>signatures.txt</code></td>
          <td>Path of the generated signatures file</td>
      </tr>
  </tbody>
</table>
<h2 id="output">Output</h2>
<p>One line per signed file, signature first:</p>
<pre tabindex="0"><code>&lt;signature_hex&gt; dist/artifact.zip
</code></pre><h2 id="before-your-first-signed-release">Before your first signed release</h2>
<ul>
<li><strong><code>context</code> is effectively permanent.</strong> A signature only verifies under the exact context string that produced it, so choose a stable, application-specific value (e.g. <code>myapp-release-signatures</code>) before you publish anything signed.</li>
<li><strong>Generate a fresh ML-DSA hexseed</strong> with <a href="https://github.com/theQRL/qrlft">qrlft</a>: <code>qrlft new -a mldsa --context=&quot;my-app-releases&quot; mykey</code>.</li>
<li><strong>Publish the matching public key</strong> (<code>mykey.pub</code>) wherever your users can reach it, and verify your first signed release before announcing it.</li>
</ul>
<h2 id="verifying">Verifying</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>qrlft verify -a mldsa --context<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;my-app-releases&#34;</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --signature<span style="color:#f92672">=</span>&lt;sig_hex&gt; --pkfile<span style="color:#f92672">=</span>mykey.pub artifact.zip
</span></span></code></pre></div><p>Exit code 0 and <code>Signature is valid</code> means the artifact is byte-for-byte what was signed. Note that <code>--sigfile</code> expects a file containing only a signature, so extract the relevant line from the signatures file first.</p>
<h2 id="notes">Notes</h2>
<ul>
<li>Runs as a Docker action from <code>ghcr.io/theqrl/actions-mldsa-sign:v1.0.0</code>, which bundles qrlft v4.0.0.</li>
<li>For supply-chain hardening, pin by commit SHA rather than by tag:
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">theQRL/actions-mldsa-sign@97a05abefff417d595c28c7b5d9d886ebe2fe9d0</span> <span style="color:#75715e"># v1.0.0</span>
</span></span></code></pre></div></li>
</ul>
<p>Migration guidance from <code>actions-dilithium-sign</code> is in the <a href="https://github.com/theQRL/actions-mldsa-sign#migrating-from-actions-dilithium-sign">README</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/theQRL/actions-mldsa-sign/commits/v1.0.0">https://github.com/theQRL/actions-mldsa-sign/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>RockyLinux-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/rockylinux-vm/</link><pubDate>Wed, 26 Aug 2026 22:39:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/rockylinux-vm/</guid><description>Version updated for https://github.com/vmactions/rockylinux-vm to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action enables running CI tests on RockyLinux by utilizing AnyVM’s infrastructure to provide a consistent virtual environment. It supports various releases and architectures, automating the setup of dependencies and execution of test commands within the RockyLinux VM. The action simplifies the process of setting up CI workflows for RockyLinux by handling platform-specific configurations and ensuring compatibility across different architectures.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/rockylinux-vm">https://github.com/vmactions/rockylinux-vm</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rockylinux-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action enables running CI tests on RockyLinux by utilizing AnyVM&rsquo;s infrastructure to provide a consistent virtual environment. It supports various releases and architectures, automating the setup of dependencies and execution of test commands within the RockyLinux VM. The action simplifies the process of setting up CI workflows for RockyLinux by handling platform-specific configurations and ensuring compatibility across different architectures.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/rockylinux-vm/compare/v1.0.0...v1.0.1">https://github.com/vmactions/rockylinux-vm/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>citeguard — retracted citation checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/citeguard-retracted-citation-checker/</link><pubDate>Wed, 26 Aug 2026 22:38:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/citeguard-retracted-citation-checker/</guid><description>Version updated for https://github.com/wedo911/citeguard to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the verification of citations in academic papers and research outputs by checking against Crossref’s real API to detect retracted publications. It provides a simple command-line interface and integrates with MCP servers for automated checks, ensuring that retractions are accurately flagged before being included in documents or reviews. The action helps researchers maintain up-to-date and accurate bibliographies by reducing the risk of citing retracted papers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wedo911/citeguard">https://github.com/wedo911/citeguard</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/citeguard-retracted-citation-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the verification of citations in academic papers and research outputs by checking against Crossref&rsquo;s real API to detect retracted publications. It provides a simple command-line interface and integrates with MCP servers for automated checks, ensuring that retractions are accurately flagged before being included in documents or reviews. The action helps researchers maintain up-to-date and accurate bibliographies by reducing the risk of citing retracted papers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds <code>CITATION.cff</code>, so the repository is formally citable: GitHub renders a <strong>Cite this repository</strong> button from it, and it is the metadata Zenodo reads when archiving a release and minting a DOI.</p>
<p><strong>No functional change.</strong> The detection logic, the CLI, the MCP server and the Action are byte-identical to v0.1.1. This release exists to produce an archived, citable snapshot.</p>
<h3 id="verification">Verification</h3>
<p>All checks were run locally before tagging:</p>
<ul>
<li>55 Python tests — passed</li>
<li>17 TypeScript tests — passed</li>
<li><code>CITATION.cff</code> — valid against CFF schema 1.2.0</li>
</ul>
<p>GitHub Actions did not pick up this commit (the two preceding runs ended in <code>startup_failure</code> and cancelled jobs, and no run was queued for this one) — an Actions-side issue, not a code failure; the same workflow passed on earlier commits and other repositories in this account ran fine at the same time. Noting it here rather than implying a green CI badge that was never produced.</p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/cowork-harness/</link><pubDate>Wed, 26 Aug 2026 22:37:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v2.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cowork-harness action is a test harness for Claude Cowork skills that emulates the observable runtime contract closely enough to test them across multiple scenarios and in CI environments. It reproduces constraints like the sealed filesystem, default-deny egress, and MCP-only cross-boundary, providing evidence of what the agent actually did rather than just what it said. This helps in ensuring skill reliability without relying on a locked-down Desktop app and is not a guarantee but a strong signal for test outcomes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v2.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The cowork-harness action is a test harness for Claude Cowork skills that emulates the observable runtime contract closely enough to test them across multiple scenarios and in CI environments. It reproduces constraints like the sealed filesystem, default-deny egress, and MCP-only cross-boundary, providing evidence of what the agent actually did rather than just what it said. This helps in ensuring skill reliability without relying on a locked-down Desktop app and is not a guarantee but a strong signal for test outcomes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="parity">Parity</h3>
<ul>
<li>
<p><strong>Baseline <code>desktop-1.37937.1</code> (agent <code>2.1.246</code>).</strong> <code>sync</code> had been refusing to write on three
<code>spawn.env</code> deltas; all three are now classified.</p>
<p><strong>Two new pinned keys.</strong> The Cowork spawn sets <code>CLAUDE_CODE_PROMPT_CACHE_TTL=&quot;1h&quot;</code> and
<code>CLAUDE_CODE_SUBAGENT_PROMPT_CACHE_TTL=&quot;5m&quot;</code> unconditionally — no gate, no session or deployment
branch — so every first-party session receives them. They are <strong>additive</strong>:
<code>ENABLE_PROMPT_CACHING_1H=&quot;1&quot;</code> is still set alongside. They read zero times in agent <code>2.1.241</code> and six
times each in <code>2.1.246</code>, so the contract went live one agent release after Desktop began setting it.</p>
<p><strong><code>MCP_TOOL_TIMEOUT</code> is now classified per SITE, not per key.</strong> Its first-party construction is
unchanged (still resolving to <code>180000</code>), but the third-party-only branch gained a second, settings-
conditional construction of the same key whose value expression the const resolver cannot reach.
Allowlisting the key — the obvious fix — would have been a silent contract loss: the allowlist is
checked <em>before</em> the pin list, so the key would have vanished from the generated env entirely, and it
is not a <code>REQUIRED_SPAWN_KEYS</code> member, so nothing would have hard-failed. Instead the 3p-only branch is
located by content and its inner keys are classified by name without resolving their values, which is
what the branch already meant. A brand-new key there still hard-fails.</p>
<p><strong><code>CLAUDE_PREVIEW_CLASSIFIER_FLOOR</code> is now inert on the shipping agent</strong> — recorded, not changed. Agent
<code>2.1.246</code> renamed the flag it reads to <code>CLAUDE_CHROME_CLASSIFIER_FLOOR</code> (and its consumer field
<code>previewClassifierFloorEnabled</code> → <code>chromeClassifierFloorEnabled</code>) while Desktop still sets only the old
name, so the classifier floor now falls through to its GrowthBook default. The key stays pinned: the
baseline records what the spawn constructs, and a Desktop-side rename must surface as a diff line
rather than as silence. Nothing in the harness reads it behaviourally. Together with the cache-TTL keys
above this is the same lesson pointing both ways — Desktop and the agent version the spawn env
independently, so &ldquo;Desktop sets X&rdquo; and &ldquo;the agent reads X&rdquo; are separately-dated claims.</p>
<p>Also found in the same pass and recorded in <a href="./docs/fidelity-gaps.md">docs/fidelity-gaps.md</a>, with no
harness surface: the deliberately-unmodeled remote device-tool family gained <code>device_fs</code> and
<code>device_request_delete_permission</code> plus a folder-access announce mode — the Desktop half of the six
<code>cowork_*</code> risk categories that had appeared in agent <code>2.1.237</code>&rsquo;s auto-mode rubric.</p>
<p>Also verified unchanged against the retained previous asar: the Cowork system prompt (the retained raw
files for 1.32885.1 through 1.37937.1 are byte-identical on disk), both sub-agent appends, <code>tools[]</code>,
the <code>canUseTool</code> chain, the mount modes, the egress contract, and the VM rootfs image.</p>
</li>
<li>
<p><strong>All three committed example cassettes re-recorded against this baseline</strong> — <code>example-pdf-skill</code>
(<code>container</code>), <code>example-multiselect-gate</code> (<code>protocol</code>) and <code>hostloop-computer-links</code> (<code>hostloop</code>).
The container one shows no behavioural change (transcript wording only). <code>verify-cassettes</code> is clean,
and the recorded MCP inventory is the Cowork lane&rsquo;s own servers (<code>cowork</code>, <code>plugins</code>, <code>skills</code>,
<code>workspace</code>) — no host inventory reached the fixtures, checked independently of the built-in scan
because the 2026-08-04 leak hid from a <code>mcp__</code> grep and surfaced only through NAME fields.</p>
</li>
<li>
<p><strong>Live end-to-end pass re-run against this baseline.</strong> <code>npm run test:live</code> — <strong>4 suites, 19 assertions,
19 green, 0 skipped</strong> — across <code>protocol</code>, <code>container</code> and <code>hostloop</code>, on agent <code>2.1.246</code>. Every
<code>describe</code> in that lane is <code>skipIf</code>-gated on Docker, the staged-binary version and the token, so a gated
case reports as skipped rather than passing vacuously; zero skips means the whole population executed.
<code>DESIGN.md</code>&rsquo;s scope note is re-stamped accordingly and now records that no baseline is unverified for
want of a live run. Not claimed: the <code>boundary-check</code> sandbox proof and the example-scenario suite were
part of the previous stamp and were not run here.</p>
</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong><code>question_context: {when_question?, matches}</code> — assert what a gate actually put in front of the user.</strong>
A regex tested against a gate&rsquo;s founder-visible payload FIELD BY FIELD — the question label, every option
<strong>label</strong>, and every option <strong>description</strong>, each as a separate string. Matching per field rather than over
one joined blob is deliberate and load-bearing: a pattern cannot straddle two fields, so
<code>invoicing[\s\S]*Audit logging</code> will not match by stitching one option&rsquo;s description to the next option&rsquo;s
label — a &ldquo;sentence&rdquo; nobody was shown. The neighbouring transcript keys&rsquo; docs teach <code>[\s\S]</code> for spanning
turns, so that is the habit an author brings here. <code>matches</code> is required NON-EMPTY: an empty pattern
compiles to <code>//i</code> and would green any run that fired a gate at all. <code>question_asked</code> matches question text only and <code>question_options</code>
compares labels only, so a sentence the model delivered inside an option&rsquo;s <code>description</code> was invisible to
every assertion key — a false-negative generator for any skill that puts context there, which the tool&rsquo;s
own schema invites. Measured on a consumer&rsquo;s paid run: a producer-authored sentence arrived verbatim in
the question, reworded inside it, and relocated into the proceed option&rsquo;s <code>description</code> across three runs
of one scenario; the third redded a lane on a run where the founder had in fact been told.</p>
<p>Evidence is the <strong>ask-time</strong> <code>AskUserQuestion</code> payload, never a <code>tool_result</code> — a skill&rsquo;s producer
typically also writes the same sentence into its own gate-state file, so <code>tool_result_matches</code> on that
phrase grades true whether or not the model ever surfaced it. Unlike <code>question_options</code>, omitting
<code>when_question</code> on a multi-gate run is <strong>not</strong> ambiguous: this key asks whether the text was shown at all.
Zero gates recorded fails; unreadable gate evidence fails evidence-unavailable, never vacuously.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><strong><code>trace --view questions</code> now renders each gate&rsquo;s offered options — labels AND <code>description</code>s</strong> — under
an <code>offered:</code> block, sub-question-labelled on a bundled gate. It previously printed the question label
alone, so the option <code>description</code> a skill routinely puts the deciding sentence in was reachable only by
hand-reading <code>events.jsonl</code>; a reader who found nothing in the view could reasonably conclude the text was
never delivered. The payload was always recorded — this was purely a rendering gap, and the same run dir
answers the question either way. The row (<code>--output-format json</code>) gains <code>subQuestions[]</code> carrying the
untruncated ask-time options; the text view caps each description at 240 chars, so nothing is lost, only
wrapped. This pairs with <code>question_context</code>: the view is how you <em>find</em> the text, that key is how you
<em>gate</em> on it.</p>
</li>
<li>
<p><strong>The <code>tool_use</code> blindness of <code>transcript_contains</code>/<code>_not_contains</code>/<code>_matches</code>/<code>_not_matches</code> and
<code>computer_links_resolve</code>/<code>_if_present</code> is now documented and guarded.</strong> <code>semantic_matches</code> has carried a
⚠️ spelling out that its corpus excludes every <code>tool_use</code> — &ldquo;a rubric claim about whether a tool was
called is unassertable&rdquo; — while the six keys with the identical blindness said only &ldquo;the assistant
transcript&rdquo;. A consumer wrote a <code>transcript_matches</code> against text living in a gate question; it could not
have matched at any phrasing, and the recording fail-closed after the spend. The caveat is now a property
of an enumerable set (<code>TOOL_USE_BLIND_KEYS</code>) enforced across every surface that documents a key — the
docs tables, the zod <code>.describe()</code> behind <code>assertions --list</code> and the generated JSON schema, and the
packaged skill reference — so a newly-added blind key cannot ship without it.</p>
</li>
<li>
<p><strong><code>question_asked</code>/<code>question_options</code>/<code>question_context</code> now warn that they match model-authored text.</strong>
Gate question text and option labels are composed by the model and reworded run to run. The <code>choose:</code>
side already documented this (stable leading anchor, 1-based index); the assert side documented it
nowhere. Guarded by <code>MODEL_AUTHORED_TEXT_KEYS</code>.</p>
</li>
<li>
<p><strong>A bad regex in a NESTED assertion field is now caught at load, not after the paid spawn.</strong> The pre-compile
pass reached only top-level string keys, so every regex one level down — <code>artifact_text.matches</code>,
<code>artifact_text.not_matches</code>, <code>path_denied.path_matches</code>, <code>skill_tool_used.skill</code>/<code>.tool</code>,
<code>subagent_dispatch_healthy.type</code>, <code>subagent_output_contains.match</code>, <code>task_status.match</code>,
<code>question_options.when_question</code>, and the new <code>question_context.*</code> — was first compiled inside the
evaluator. All eleven are now validated at load, and <code>test/nested-regex-leaves.test.ts</code> reads <code>assert.ts</code>
and fails if the evaluator compiles a nested leaf the load-time table does not carry, so the gap cannot
reopen silently. <code>lint</code>&rsquo;s double-quoted-regex warning also now covers nested <code>matches:</code> leaves.</p>
</li>
<li>
<p><strong><code>diff</code> with a single positional now names the missing operand</strong> instead of printing bare usage. There is
deliberately no one-argument form: <code>diff</code> is polymorphic over baselines, run dirs and cassettes, so it
would need type dispatch plus a defined source for &ldquo;the committed version&rdquo;.</p>
</li>
<li>
<p><strong>The two cost keys are cross-referenced.</strong> <code>RunResult.cost.usd</code> is one invocation&rsquo;s SDK
<code>total_cost_usd</code>; the critique report&rsquo;s <code>costUsd.totalUsd</code> aggregates the task turn, the reflection turn
and both evaluator passes. Reading the wrong one returns <code>undefined</code> rather than erroring, which reads as
&ldquo;no cost recorded&rdquo;. Kept as two shapes on purpose — collapsing them would destroy the per-phase split.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>Two spawn-contract sentinels were weaker than their names implied; both now bite.</strong></p>
<p><code>checkSpawnContractFacts</code> pinned the <code>allowedTools[]</code> built-in head and the built-in→<code>mcp__</code> boundary
but nothing between the boundary and the closing bracket — so <code>mcp__plugins__search_connectors</code> was
added to the array and both checks stayed green. The <code>mcp__</code> membership is now pinned as a set, and the
flag names the added and removed entries instead of reporting that something &ldquo;moved&rdquo;. (That tool is
declared only on the third-party deployment, so the first-party inventory the harness serves is
unaffected — but the addition should not have been invisible.)</p>
<p><code>checkMountModeFacts</code> asserted each read-only mount with a single <code>regex.test</code>, while <code>uploads</code>,
<code>.claude/skills</code> and <code>.projects/&lt;uuid&gt;</code> are each built at <strong>two</strong> sites — the VM-loop mount-set builder
and host-loop <code>computeBashMounts</code>. Either site satisfied the check, so a one-lane <code>ro</code>→<code>rw</code> flip — a
containment change on exactly one execution tier — passed green. It now compares the site count to the
count carrying <code>mode:&quot;ro&quot;</code> and names the lane count in the flag. Its fifth fact — the delete-deny
resolver <code>?&quot;rwd&quot;:&quot;rw&quot;</code> — had the same shape and the same two-lane reality (it went 1 site to 2 in this
release) and now guards a floor on that count: a lane losing the resolver flags, a lane gaining one
does not.</p>
</li>
<li>
<p><strong>All eight asar sentinels now carry a committed mutation case.</strong> They are green on the previous
release&rsquo;s asar too, so a green proves nothing on its own unless the checker is known to bite; five of
them (<code>checkCodeTripwires</code>, <code>checkWebFetchFacts</code>, <code>checkEgressContractFacts</code>, <code>checkSyspromptMapFacts</code>,
<code>checkNormalizationSanity</code>) had no such case. Each new one changes an <strong>inner</strong> character of its
anchor, because a suffix rename still satisfies a substring regex — a mutation that cannot fail is not
evidence — and asserts that the mutation actually applied.</p>
</li>
<li>
<p><strong><code>record --dry-run &lt;dir/&gt;</code> no longer announces a WARN as a refusal.</strong> The batch arm labelled every
advisory note <code>⚠ would-refuse (advisory)</code>, but <code>cassettePortabilityPreflight</code> can only ever return
<code>ok</code>/<code>warn</code> — it has no refuse path at all — and <code>hostInventoryPreflight</code> returns <code>warn</code> whenever the
target cassette already exists, which is every re-record corpus sitting at the default path. So the
preview told operators the real <code>record</code> would refuse runs it would in fact accept, on the one arm whose
design principle is that a guess must not gate. The label now follows the verdict kind
(<code>⚠ would-warn (advisory)</code>), the &ldquo;ADVISORY, not this run&rsquo;s verdict&rdquo; footer is unchanged, and exit codes
were never affected either way.</p>
</li>
<li>
<p><strong>The 3p-branch rule refuses to blank W1.</strong> W1 is the window every modeled first-party key is derived
from, so a branch marker appearing there hard-fails instead of blanking; deleting real pinned keys from
the derived env with nothing failing is the worse of the two outcomes.</p>
</li>
<li>
<p><strong><code>record --dry-run</code> now runs every pre-spend refusal the real record runs, and one refusal moved from
after the paid run to before it.</strong> The rehearsal re-implemented the checks by hand, so it drifted:
<code>hostInventoryPreflight</code> shipped 2026-08-04 and the commit three days later titled <em>&ldquo;make <code>--dry-run</code>
refuse what the real record refuses&rdquo;</em> swept in the two checks returning <code>string | undefined</code> and missed
the one returning a <code>{kind}</code> verdict — for 19 days an operator could not discover that refusal without
spending. Separately, the slug-collision refusal (<em>&ldquo;refusing to overwrite … it belongs to scenario X&rdquo;</em>)
sat <strong>after</strong> <code>executeScenario</code>: you paid for the run and were then refused, though it is a pure function
of path + <code>--force</code> + the existing cassette&rsquo;s name. Both now run in one shared pre-spend block.</p>
<p>Refusals are also uniform now. <code>promptPolicyRejection</code> threw while <code>hostInventoryPreflight</code> called
<code>fail()</code>, which <code>process.exit</code>s — and the dir-batch loop catches a throw per item but cannot catch an
exit, so a host-inventory refusal mid-batch abandoned concurrent runs already paid for.</p>
<p>Under <code>--output-format json</code> a directory batch carries those advisory verdicts in a <code>notes[]</code> array, kept
separate from <code>refusals[]</code> so automation cannot read a guess as a binding verdict.</p>
<p><strong>On a directory, the path-dependent verdicts are ADVISORY (<code>⚠ would-refuse</code>) and do not affect the exit
code</strong>, because a directory target takes no <code>--out</code>: the preview would have to guess the destination, and
a guess must not gate. Measured on a real consumer, gating on that guess would have refused 26 of 27
scenarios the real record accepts. Dry-run a single scenario file with the real flags for a binding
answer. <code>--quiet</code> suppresses the notes; it never suppresses a refusal.</p>
<p>Also new in the batch preview: the duplicate-cassette-path refusal the real batch already had.</p>
</li>
</ul>
<h3 id="upgrade-impact">Upgrade impact</h3>
<ul>
<li>
<p><strong><code>--allow-host-inventory-fixture</code> no longer waives a MEASURED host-inventory finding.</strong> It was one flag
doing two jobs: bypassing the pre-flight refusal (a precondition the operator cannot check — &ldquo;use only
when the session has no personal MCP servers or plugins&rdquo;) <em>and</em> downgrading the write-time scan&rsquo;s refusal
to a warning. So an operator who passed it to get past the undecidable precondition also switched off the
scan that would have caught a real leak. It is now the pre-flight bypass only; the finished recording is
still scanned, and a finding still refuses the write and quarantines the recording. Writing a flagged
recording needs the new, narrower <code>--allow-host-inventory-findings</code>. <strong>A batch recorder that passes the
old flag on a new-fixture path will now abort on a genuine finding where it previously warned and wrote.</strong></p>
<p>A <code>--dry-run</code> that reports what <em>would</em> be captured was considered and declined: the inventory does not
exist until the agent has run, so a preview would either re-implement the scanner against a hypothetical
(a second oracle free to disagree with the real one) or require the spend it was meant to avoid. Reasoning
is in <a href="./docs/cassette.md">docs/cassette.md</a>.</p>
<p>This does not break a covered surface (<a href="./SPEC.md#12-versioning--the-10-compatibility-contract">SPEC.md §12</a>):
no command or flag is removed and no exit-code meaning changes — one flag&rsquo;s consent narrows, and the
capability it shed is reachable through the new one. So it ships in a minor.</p>
</li>
</ul>
<h3 id="documentation">Documentation</h3>
<p>Five gaps found by asking a consumer which harness properties actually changed an outcome on a real
working day, then checking whether the docs said so. Four of the five were documented only as features,
never as the failure they prevent — the sentence a reader needs to recognise their own situation.</p>
<ul>
<li>
<p><strong>The blocking gate is now stated as a blocker.</strong> <code>AskUserQuestion</code> <em>blocks</em>: it is a question to a
human and <code>claude -p</code> has no human, so a gated skill under a plain CLI run stalls or never reaches the
code behind the gate. That made half the skill untestable, not merely awkward to test — the README had
only &ldquo;untestable headless unless something answers it&rdquo;, buried as the last of two afterthought bullets.</p>
</li>
<li>
<p><strong>&ldquo;Assert on the run, not the output&rdquo;</strong> — a new README section naming the class of claim the harness
exists for (<code>subagent_tool_absent</code>, <code>dispatch_count_max</code>, <code>no_delete_in_outputs</code>, <code>subagent_file_write</code>)
and why no output diff can reach it: a correct run and one that quietly handed a restricted sub-agent
shell access produce byte-identical files. <code>subagent_tool_absent</code> did not appear in the README at all.</p>
</li>
<li>
<p><strong>The raw-<code>events.jsonl</code> escape hatch is documented</strong>, with verified <code>jq</code> recipes, in
<a href="./docs/debugging.md">docs/debugging.md</a>. Every documented route into the event log went through
<code>trace</code>, whose views are a digest — so the run dir&rsquo;s <em>evidence</em> surface is wider than any view&rsquo;s
<em>observation</em> surface, and wider still than the assertion catalog. Concluding &ldquo;it never happened&rdquo; from
a view that doesn&rsquo;t render the field is a false negative, and the doc now says so and shows the read.</p>
</li>
<li>
<p><strong>Sub-agent delivery has a route.</strong> The tier-qualified outputs contract — the reason a hand-off path
that works on one loop lands in sandbox scratch on the other — was correctly documented in
<a href="./docs/subagents.md">docs/subagents.md</a> but filed under &ldquo;read on demand&rdquo;, reachable only by someone
who already knew the answer. It now has a &ldquo;Common tasks&rdquo; row keyed to the symptom.</p>
</li>
<li>
<p><strong>Replay&rsquo;s cost claim carries a number.</strong> &ldquo;Zero spend&rdquo; is the price; the wall-clock is what makes an
always-on per-PR gate obviously affordable, and no doc stated it (well under a second per cassette).</p>
</li>
<li>
<p><strong>The project&rsquo;s provenance is stated on every surface the framing travels to.</strong> <code>README.md</code> (which
renders on the npm page), <code>llms.txt</code>, both <code>.claude-plugin/marketplace.json</code> descriptions and <code>SKILL.md</code>
now say the same thing: an independent project, not affiliated with, endorsed by, or supported by
Anthropic; it bundles no Anthropic code; it is not Cowork. <code>SKILL.md</code> additionally tells the agent to say
so when a user asks what it is. Nothing enforces the four staying in step, so an edit can still drop it
from one of them unnoticed.</p>
</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 2.3.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/159">https://github.com/yaniv-golan/cowork-harness/pull/159</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v2.2.0...v2.3.0">https://github.com/yaniv-golan/cowork-harness/compare/v2.2.0...v2.3.0</a></p>
]]></content:encoded></item><item><title>docker-hash</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/docker-hash/</link><pubDate>Wed, 26 Aug 2026 15:06:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/docker-hash/</guid><description>Version updated for https://github.com/RemkoMolier/docker-hash to version v0.3.21.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Docker Hash Action computes a deterministic SHA-256 hash for a Docker image build based on the Dockerfile content, build arguments, and referenced files in the build context. It helps with cache-busting, change detection, and deterministic CI pipelines by ensuring that the hash changes when these factors change.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RemkoMolier/docker-hash">https://github.com/RemkoMolier/docker-hash</a></strong> to version <strong>v0.3.21</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-hash">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Docker Hash Action computes a deterministic SHA-256 hash for a Docker image build based on the Dockerfile content, build arguments, and referenced files in the build context. It helps with cache-busting, change detection, and deterministic CI pipelines by ensuring that the hash changes when these factors change.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="bug-fixes">Bug fixes</h3>
<ul>
<li>fix(deps): update module github.com/google/go-containerregistry to v0.22.0 (#204)</li>
</ul>
]]></content:encoded></item><item><title>Scratchsmith</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/scratchsmith/</link><pubDate>Wed, 26 Aug 2026 15:03:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/scratchsmith/</guid><description>Version updated for https://github.com/schubydoo/scratchsmith to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Scratchsmith automates the creation of minimal, non-root OCI images from dynamically linked glibc ELF binaries. It resolves dependencies using ld.so, stages necessary glibc components like NSS modules and a working nsswitch.conf, and assembles an image that can be executed without Docker. The action supports features like SBOM generation, ELF hardening linting, and detection of gaps in dynamic linking behavior through dlopen. It provides a daemonless workflow for packaging binaries into OCI images, making it suitable for use cases where static linking is not possible or when quick, reproducible builds are needed without Docker.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/schubydoo/scratchsmith">https://github.com/schubydoo/scratchsmith</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/scratchsmith">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Scratchsmith automates the creation of minimal, non-root OCI images from dynamically linked glibc ELF binaries. It resolves dependencies using <code>ld.so</code>, stages necessary glibc components like NSS modules and a working <code>nsswitch.conf</code>, and assembles an image that can be executed without Docker. The action supports features like SBOM generation, ELF hardening linting, and detection of gaps in dynamic linking behavior through <code>dlopen</code>. It provides a daemonless workflow for packaging binaries into OCI images, making it suitable for use cases where static linking is not possible or when quick, reproducible builds are needed without Docker.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixes">Fixes</h2>
<ul>
<li>Automate crates.io publishing with OIDC trusted publishing, and fix the logo so it renders on the crates.io page. (<a href="https://github.com/schubydoo/scratchsmith/pull/66">#66</a>)</li>
</ul>
]]></content:encoded></item><item><title>pi GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/pi-github-action/</link><pubDate>Wed, 26 Aug 2026 15:02:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/pi-github-action/</guid><description>Version updated for https://github.com/shaftoe/pi-coding-agent-action to version v2.27.1.
This action is used across all versions by 14 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates the Pi coding agent with Git hosting platform workflows, supporting multiple platforms that provide GitHub-compatible APIs and CI/CD environment variables. It provides a familiar workflow for running Pi as CLI, offers minimal batteries included UX, supports chaining sessions and composing workflows, integrates with GitHub workflows natively, and replicates interactive session sharing capabilities. The action is useful for issue assistance, PR assistance, automated code reviews, recurring tasks, and can be integrated into custom pipelines to generate prompts from upstream actions/workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shaftoe/pi-coding-agent-action">https://github.com/shaftoe/pi-coding-agent-action</a></strong> to version <strong>v2.27.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>14</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pi-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates the <a href="https://pi.dev">Pi coding agent</a> with Git hosting platform workflows, supporting multiple platforms that provide GitHub-compatible APIs and CI/CD environment variables. It provides a familiar workflow for running Pi as CLI, offers minimal batteries included UX, supports chaining sessions and composing workflows, integrates with GitHub workflows natively, and replicates interactive session sharing capabilities. The action is useful for issue assistance, PR assistance, automated code reviews, recurring tasks, and can be integrated into custom pipelines to generate prompts from upstream actions/workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="2271---2026-08-26"><a href="https://github.com/shaftoe/pi-coding-agent-action/compare/v2.27.0...v2.27.1">2.27.1</a> - 2026-08-26</h2>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>deps-ci</strong>: bump github/codeql-action from 4.37.3 to 4.37.6 (#402)</li>
<li><strong>deps-ci</strong>: bump github/codeql-action from 4.37.6 to 4.37.7 (#406)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>bump Pi SDK to v0.84.3</li>
<li><strong>deps</strong>: bump Pi to v0.84.0 (#400)</li>
<li><strong>pi-action</strong>: bundle AWS Bedrock provider into dist to fix missing module error (#398) (#399)</li>
<li>load npm extensions from bundled Pi runtime (#405)</li>
<li><strong>github</strong>: recover missing PR context from event payload (#401)</li>
</ul>
]]></content:encoded></item><item><title>mowmow lawn</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/mowmow-lawn/</link><pubDate>Wed, 26 Aug 2026 15:01:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/mowmow-lawn/</guid><description>Version updated for https://github.com/sudongcu/mowmow to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The mowmow action automates the creation of a visual representation of GitHub contributions in the form of an animated SVG. It generates a lawn-like graphic that reflects the developer’s contribution history, with each commit representing a tuft of grass that grows over time. The action is set to run daily and can be easily integrated into any public repository by adding a workflow configuration file to the .github/workflows directory.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sudongcu/mowmow">https://github.com/sudongcu/mowmow</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mowmow-lawn">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The mowmow action automates the creation of a visual representation of GitHub contributions in the form of an animated SVG. It generates a lawn-like graphic that reflects the developer&rsquo;s contribution history, with each commit representing a tuft of grass that grows over time. The action is set to run daily and can be easily integrated into any public repository by adding a workflow configuration file to the <code>.github/workflows</code> directory.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>longer <code>cycle</code>s no longer leave the mower parked off-screen for ages: the pause after the last pass is a fixed ~6.7s now, however long the loop. at cycle=90 that used to be ~13s of finished lawn — long enough to look broken</li>
<li>28s is still the floor; below it timings get clamped with a warning, same as before</li>
<li>playground: dropped the PAT suggestion from the &ldquo;mostly dirt?&rdquo; note — a PAT can&rsquo;t surface private contributions, the profile toggle is the only fix</li>
<li>ci runs on every push, and pushing a version tag now moves <code>v1</code> and cuts the release automatically</li>
</ul>
]]></content:encoded></item><item><title>i18n-ai-translate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/i18n-ai-translate/</link><pubDate>Wed, 26 Aug 2026 14:59:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/i18n-ai-translate/</guid><description>Version updated for https://github.com/taahamahdi/i18n-ai-translate to version v5.3.0.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The i18n-ai-translate GitHub Action automates AI translation of i18n locale files, including JSON and other formats like Gettext .po, Java .properties, iOS .strings, Rails YAML, JS/TS modules, and ICU MessageFormat (next-intl). It allows users to choose from multiple engines, supports parallel batch processing, verifies translations for accuracy, preserves existing translations, and offers diff-aware translation. The action can be used as a CLI, GitHub Action, or Node library, with options to specify languages, check modes, format awareness, context injection, dry runs, and exclude specific locales.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/taahamahdi/i18n-ai-translate">https://github.com/taahamahdi/i18n-ai-translate</a></strong> to version <strong>v5.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/i18n-ai-translate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The i18n-ai-translate GitHub Action automates AI translation of i18n locale files, including JSON and other formats like Gettext <code>.po</code>, Java <code>.properties</code>, iOS <code>.strings</code>, Rails YAML, JS/TS modules, and ICU MessageFormat (next-intl). It allows users to choose from multiple engines, supports parallel batch processing, verifies translations for accuracy, preserves existing translations, and offers diff-aware translation. The action can be used as a CLI, GitHub Action, or Node library, with options to specify languages, check modes, format awareness, context injection, dry runs, and exclude specific locales.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci: publish to npm via trusted publishing (OIDC) by @taahamahdi in <a href="https://github.com/taahamahdi/i18n-ai-translate/pull/501">https://github.com/taahamahdi/i18n-ai-translate/pull/501</a></li>
<li>fix(action): shorten description under the Marketplace limit by @taahamahdi in <a href="https://github.com/taahamahdi/i18n-ai-translate/pull/502">https://github.com/taahamahdi/i18n-ai-translate/pull/502</a></li>
<li>feat(formats): translate ICU MessageFormat / next-intl catalogues by @taahamahdi in <a href="https://github.com/taahamahdi/i18n-ai-translate/pull/503">https://github.com/taahamahdi/i18n-ai-translate/pull/503</a></li>
<li>chore: release 5.3.0 by @taahamahdi in <a href="https://github.com/taahamahdi/i18n-ai-translate/pull/504">https://github.com/taahamahdi/i18n-ai-translate/pull/504</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/taahamahdi/i18n-ai-translate/compare/v5.2.0...v5.3.0">https://github.com/taahamahdi/i18n-ai-translate/compare/v5.2.0...v5.3.0</a></p>
]]></content:encoded></item><item><title>auto-generate-release-note</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/auto-generate-release-note/</link><pubDate>Wed, 26 Aug 2026 14:58:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/auto-generate-release-note/</guid><description>Version updated for https://github.com/TakuKobayashi/auto-generate-release-note to version v2.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action uses a local Ollama model to summarize Git history and diffs for creating or updating GitHub Releases, automatically generating Markdown. It supports multiple languages, including bilingual output with English. The action excludes images, videos, archives, binaries, and other non-source contents from the prompt and falls back to deterministic notes based on commits if Ollama inference fails.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TakuKobayashi/auto-generate-release-note">https://github.com/TakuKobayashi/auto-generate-release-note</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auto-generate-release-note">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action uses a local Ollama model to summarize Git history and diffs for creating or updating GitHub Releases, automatically generating Markdown. It supports multiple languages, including bilingual output with English. The action excludes images, videos, archives, binaries, and other non-source contents from the prompt and falls back to deterministic notes based on commits if Ollama inference fails.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="release-notes-for-auto-generate-release-note-v201">Release Notes for auto-generate-release-note v2.0.1</h1>
<h2 id="user-visible-changes">User-visible Changes</h2>
<ul>
<li><strong>Added Git Blame Information</strong>: The release notes now include Git blame information for each commit, providing details about who made changes and when.</li>
<li><strong>Updated README Files</strong>: Both the English (<code>README.md</code>) and Japanese (<code>README-ja.md</code>) README files have been updated to reflect these changes.</li>
</ul>
<h2 id="fixes">Fixes</h2>
<ul>
<li><strong>Reverted Changes</strong>: Reverted changes that were previously included in the release notes to ensure accuracy.</li>
</ul>
<h2 id="internal-changes">Internal Changes</h2>
<ul>
<li><strong>Refactored Code</strong>: Refactored the code to include a new module (<code>commit-hints.ts</code>) that handles the extraction of commit candidates and the building of surviving commit hints.</li>
<li><strong>Improved Test Coverage</strong>: Enhanced the test suite to include tests for the new commit hints functionality.</li>
</ul>
<h2 id="migration-needs">Migration Needs</h2>
<ul>
<li><strong>No Migration Needed</strong>: Users should not need to make any changes to their existing workflows or configurations.</li>
</ul>
<h2 id="breaking-changes">Breaking Changes</h2>
<ul>
<li><strong>No Breaking Changes</strong>: This release does not introduce any breaking changes that would require users to update their code or configurations.</li>
</ul>
<h2 id="important-notes">Important Notes</h2>
<ul>
<li><strong>Enhanced Release Notes</strong>: The release notes are now more detailed and include specific information about each commit, making it easier for users to understand the changes in each version.</li>
</ul>
<p>These release notes provide a comprehensive overview of the changes in v2.0.1, ensuring that users and maintainers are well-informed about the updates and any necessary actions.</p>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/delivery-autopilot-runner/</link><pubDate>Wed, 26 Aug 2026 14:57:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.44.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Delivery Autopilot Runner GitHub Action automates the process of creating pull requests from tickets managed by Delivery Autopilot. It uses AI to write code and performs quality checks, ensuring that the pull request is reviewed and approved before being merged into the main branch. The action requires an active subscription to Delivery Autopilot and connects to your repository through GitHub Actions, handling the workflow without sending any sensitive data directly to Tekunda’s servers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.44</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Delivery Autopilot Runner GitHub Action automates the process of creating pull requests from tickets managed by Delivery Autopilot. It uses AI to write code and performs quality checks, ensuring that the pull request is reviewed and approved before being merged into the main branch. The action requires an active subscription to Delivery Autopilot and connects to your repository through GitHub Actions, handling the workflow without sending any sensitive data directly to Tekunda&rsquo;s servers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runner-dist synced from AutoPilot 44ece48dcdd4. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>SlopLock</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/sloplock/</link><pubDate>Wed, 26 Aug 2026 14:56:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/sloplock/</guid><description>Version updated for https://github.com/theinfosecguy/sloplock to version v2.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SlopLock is an automated security tool that helps prevent the installation of AI-generated or malicious dependencies by checking their existence, age, and trustworthiness across multiple public registries. It solves the problem of identifying and blocking new, potentially harmful packages before they can be installed on developer machines or merged into pull requests. The action checks each dependency name for existence and age, providing a summary report with annotations and job summaries for easy tracking and management.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/theinfosecguy/sloplock">https://github.com/theinfosecguy/sloplock</a></strong> to version <strong>v2.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sloplock">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SlopLock is an automated security tool that helps prevent the installation of AI-generated or malicious dependencies by checking their existence, age, and trustworthiness across multiple public registries. It solves the problem of identifying and blocking new, potentially harmful packages before they can be installed on developer machines or merged into pull requests. The action checks each dependency name for existence and age, providing a summary report with annotations and job summaries for easy tracking and management.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="sloplock-v220">SlopLock v2.2.0</h1>
<p>This minor release adds direct public-registry package checks and an installable
agent skill for checking dependency names before they are added to a project.</p>
<h2 id="direct-package-checks">Direct Package Checks</h2>
<ul>
<li>Adds <code>sloplock check &lt;ecosystem&gt; &lt;name...&gt;</code> for checking package names without
a repository checkout.</li>
<li>Supports npm, PyPI, crates.io, Go modules, RubyGems.org, Packagist,
NuGet.org, and Maven Central.</li>
<li>Accepts text or JSON output, the existing cooldown and suppression config,
configurable failure thresholds, and fail-closed registry handling.</li>
<li>Ignores common trailing version specifiers while preserving normalized package
names, including scoped npm packages and Maven coordinates.</li>
<li>Uses the existing scan exit-code contract so the command works in scripts and
automated dependency-installation loops.</li>
</ul>
<h2 id="agent-skill">Agent Skill</h2>
<ul>
<li>Adds <code>skills/sloplock/SKILL.md</code> for installation with
<code>npx skills add theinfosecguy/sloplock</code>.</li>
<li>Explains when dependency names should be checked and how to handle missing,
too-new, private, or temporarily unavailable packages.</li>
<li>Recommends a checkout scan after manifest edits so direct checks do not replace
repository-wide dependency review.</li>
</ul>
<h2 id="cli-and-packaging">CLI And Packaging</h2>
<ul>
<li>Adds dedicated help for the <code>check</code> and <code>hook</code> subcommands.</li>
<li>Adds deterministic text and JSON reporting for direct checks.</li>
<li>Extends the packed-package smoke test to verify the new command and its exit
status from a clean installation.</li>
</ul>
<p>Existing Action installations can continue using <code>theinfosecguy/sloplock@v2</code>.
The moving <code>v2</code> tag will be updated to this release.</p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/wails3-build-action/</link><pubDate>Wed, 26 Aug 2026 14:55:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building of Wails.io projects, a modern Go-based web framework. It installs GoLang and NodeJS, runs the build process, and optionally uploads the results to GitHub. The action supports multiple platforms and configurations for different languages (Go, JavaScript, Deno). By default, it builds the project and uploads it, but this behavior can be customized by setting options such as building without uploading or specifying a custom build name.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building of Wails.io projects, a modern Go-based web framework. It installs GoLang and NodeJS, runs the build process, and optionally uploads the results to GitHub. The action supports multiple platforms and configurations for different languages (Go, JavaScript, Deno). By default, it builds the project and uploads it, but this behavior can be customized by setting options such as building without uploading or specifying a custom build name.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/vibgrate-scan/</link><pubDate>Wed, 26 Aug 2026 14:54:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.826.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the process of generating a code graph, drift score, and upgrade priorities for a given repository. It provides tools to understand the current state of the codebase and identify potential issues that may impact its functionality over time. The action is designed to run locally on the user’s machine without requiring any API keys or network calls.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.826.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the process of generating a code graph, drift score, and upgrade priorities for a given repository. It provides tools to understand the current state of the codebase and identify potential issues that may impact its functionality over time. The action is designed to run locally on the user&rsquo;s machine without requiring any API keys or network calls.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268261">Vibgrate CLI 2026.826.1</h1>
<p><em>Released 2026-08-26</em></p>
<p>This release of the vg command-line scanner includes a fix for the handling of reasoning models in the <code>vg code</code> command. Users can expect clearer reporting on the status of runs and better adherence to configuration settings.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>vg code</code> now properly manages turns when a reasoning model requires additional time to formulate an answer, providing a bounded budget for follow-up turns.</li>
<li>Every incomplete run now reports the reason for its termination, including details on the step limit and guidance on how to adjust it.</li>
<li><code>maxSteps</code> in <code>vibgrate.config.json</code> is now respected, correcting the previous issue where a hard-coded <code>--max-steps</code> default was overriding it.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.825.2, interleaved on one runner against the pinned corpus (187 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21945 count</td>
          <td>21945 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>11809 count</td>
          <td>11809 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.95 ratio</td>
          <td>0.95 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>722.40 ms</td>
          <td>726.20 ms</td>
      </tr>
  </tbody>
</table>
<p>2 regression(s) — published, not omitted:</p>
<ul>
<li>Token reduction vs baseline agent (equal success): 0.22 → 0.20 (-9.2%)</li>
<li>Agent tokens with vg (comparable tasks, total): 562247 → 620882 (10.4%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.826.1">https://vibgrate.com/changelog/cli/2026.826.1</a></p>
]]></content:encoded></item><item><title>BlissOS-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/blissos-vm/</link><pubDate>Wed, 26 Aug 2026 14:53:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/blissos-vm/</guid><description>Version updated for https://github.com/vmactions/blissos-vm to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action vmactions/blissos-vm automates running CI tasks on BlissOS virtual machines. It supports various BlissOS releases, including Android, x86_64 (amd64), and provides a user-friendly way to configure CI workflows by describing the desired actions in plain language using the vmactions-ci skill.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/blissos-vm">https://github.com/vmactions/blissos-vm</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/blissos-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>vmactions/blissos-vm</code> automates running CI tasks on BlissOS virtual machines. It supports various BlissOS releases, including Android, x86_64 (amd64), and provides a user-friendly way to configure CI workflows by describing the desired actions in plain language using the vmactions-ci skill.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="sync-tar">sync: tar</h2>
<p>A second way to move the workspace. Android ships no rsync, no sshfs and
no NFS client, so scp was the only option until now; <code>sync: tar</code> streams
the tree as a ustar archive over the same connection and is the faster
of the two on a large tree. Nothing is installed in the guest. Verified
on this guest before the declaration went in: 300 files plus a 1 MB
binary blob pushed, a file written inside the VM, the whole tree pulled
back and compared by content hash.</p>
<p>scp remains the default.</p>
<h2 id="under-the-hood">Under the hood</h2>
<p>The image builder moves to blissos-builder v2.0.3 and the runtime to
anyvm v0.6.5, fifteen releases on from the v0.5.0 that v1.0.1 shipped.
The builder now mirrors its dropbear source tarball at a pinned version
&ndash; an upstream download hiccup used to produce an image missing its ssh
server instead of a red build &ndash; and publishes releases.json, the
machine-readable index this action bakes its configuration from.</p>
<p>Two runtime fixes reach every job: a failed folder sync is now fatal
instead of a warning that left the guest running without the files it
was about to use, and the workspace push no longer carries the runner&rsquo;s
own harness directories into the guest.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/blissos-vm/compare/v1.0.1...v1.0.2">https://github.com/vmactions/blissos-vm/compare/v1.0.1...v1.0.2</a></p>
]]></content:encoded></item><item><title>GhostBSD-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/ghostbsd-vm/</link><pubDate>Wed, 26 Aug 2026 14:51:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/ghostbsd-vm/</guid><description>Version updated for https://github.com/vmactions/ghostbsd-vm to version v1.0.3.
This action is used across all versions by 28 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running Continuous Integration (CI) tests on GhostBSD. It supports automatic selection of the appropriate action, release, and architecture based on the user’s request. The action installs necessary dependencies and passes environment variables into the VM, allowing users to run specific commands or tests within the GhostBSD environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/ghostbsd-vm">https://github.com/vmactions/ghostbsd-vm</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>28</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ghostbsd-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running Continuous Integration (CI) tests on GhostBSD. It supports automatic selection of the appropriate action, release, and architecture based on the user&rsquo;s request. The action installs necessary dependencies and passes environment variables into the VM, allowing users to run specific commands or tests within the GhostBSD environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="sync-tar">sync: tar</h2>
<p>A new way to share the workspace: the tree is streamed in as a ustar
archive over the ssh connection the action already opens, and streamed
back the same way when the run finishes. Nothing is installed in the
guest and no filesystem support is needed on either side, unlike sshfs
and nfs. ghostbsd-builder v2.0.8 declares it for every release, and it
was verified on this guest before the declaration went in: 300 files
plus a 1 MB binary blob pushed, a file written inside the VM, the whole
tree pulled back and compared by content hash.</p>
<p>rsync remains the default.</p>
<h2 id="under-the-hood">Under the hood</h2>
<p>The image builder moves to ghostbsd-builder v2.0.8, two releases on: the
nested-WHPX boot wedge is fixed, the disk is cleaned before export, and
the builder now publishes releases.json, the machine-readable index this
action bakes its configuration from.</p>
<p>The runtime moves to anyvm v0.6.5, fifteen releases on from the v0.5.0
that v1.0.2 shipped. Two of its fixes reach every job: a failed folder
sync is now fatal instead of a warning that left the guest running
without the files it was about to use, and the workspace push no longer
carries the runner&rsquo;s own harness directories into the guest.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/ghostbsd-vm/compare/v1.0.2...v1.0.3">https://github.com/vmactions/ghostbsd-vm/compare/v1.0.2...v1.0.3</a></p>
]]></content:encoded></item><item><title>Haiku-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/haiku-vm/</link><pubDate>Wed, 26 Aug 2026 14:50:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/haiku-vm/</guid><description>Version updated for https://github.com/vmactions/haiku-vm to version v1.1.4.
This action is used across all versions by 63 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running CI tasks on Haiku operating system. It allows developers to specify environment variables and commands to run in a Haiku VM using AnyVM, which provides AI capabilities to generate the workflow YAML file automatically based on simple descriptions. The action supports various OSes but defaults to Ubuntu for compatibility with common workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/haiku-vm">https://github.com/vmactions/haiku-vm</a></strong> to version <strong>v1.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>63</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/haiku-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running CI tasks on Haiku operating system. It allows developers to specify environment variables and commands to run in a Haiku VM using AnyVM, which provides AI capabilities to generate the workflow YAML file automatically based on simple descriptions. The action supports various OSes but defaults to Ubuntu for compatibility with common workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="under-the-hood">Under the hood</h2>
<p>The runtime moves to anyvm v0.6.5, fifteen releases on from the v0.5.0
that v1.1.3 shipped &ndash; most of that span is other guests&rsquo; work. What
reaches this action: a failed folder sync is now fatal instead of a
warning that left the guest running without the files it was about to
use, and the workspace push no longer carries the runner&rsquo;s own harness
directories into the guest.</p>
<p>Images and sync methods are unchanged; this release adds no tar sync
because haiku-builder has not yet cut a release declaring it.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/haiku-vm/compare/v1.1.3...v1.1.4">https://github.com/vmactions/haiku-vm/compare/v1.1.3...v1.1.4</a></p>
]]></content:encoded></item><item><title>Hurd-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/hurd-vm/</link><pubDate>Wed, 26 Aug 2026 14:49:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/hurd-vm/</guid><description>Version updated for https://github.com/vmactions/hurd-vm to version v1.0.1.
This action is used across all versions by 22 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of running CI in Hurd, a Unix-like operating system with RISC-V architecture. It simplifies setting up and managing CI pipelines for Hurd by handling all the complex tasks such as installing dependencies, syncing source code, and executing commands within the Hurd environment. The action is designed to be AI-ready, allowing users to describe their needs in plain language and receive a ready-to-commit workflow file automatically.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/hurd-vm">https://github.com/vmactions/hurd-vm</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>22</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hurd-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of running CI in Hurd, a Unix-like operating system with RISC-V architecture. It simplifies setting up and managing CI pipelines for Hurd by handling all the complex tasks such as installing dependencies, syncing source code, and executing commands within the Hurd environment. The action is designed to be AI-ready, allowing users to describe their needs in plain language and receive a ready-to-commit workflow file automatically.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="sync-tar">sync: tar</h2>
<p>A new way to share the workspace: the tree is streamed in as a ustar
archive over the ssh connection the action already opens, and streamed
back the same way when the run finishes. Nothing is installed in the
guest and no filesystem support is needed on either side, unlike nfs.
hurd-builder v2.0.1 declares it for every release, and it was verified
on this guest before the declaration went in: 300 files plus a 1 MB
binary blob pushed, a file written inside the VM, the whole tree pulled
back and compared by content hash.</p>
<p>rsync remains the default.</p>
<h2 id="under-the-hood">Under the hood</h2>
<p>hurd-builder v2.0.1 is also the first hurd build to publish
releases.json, the machine-readable index this action bakes its
configuration from &ndash; which is why the pre-tar method list survived
until now.</p>
<p>The runtime moves to anyvm v0.6.5, thirteen releases on from the v0.5.2
that v1.0.0 shipped. Two of its fixes reach every job: a failed folder
sync is now fatal instead of a warning that left the guest running
without the files it was about to use, and the workspace push no longer
carries the runner&rsquo;s own harness directories into the guest.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/hurd-vm/compare/v1.0.0...v1.0.1">https://github.com/vmactions/hurd-vm/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>MidnightBSD-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/midnightbsd-vm/</link><pubDate>Wed, 26 Aug 2026 14:48:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/midnightbsd-vm/</guid><description>Version updated for https://github.com/vmactions/midnightbsd-vm to version v1.0.6.
This action is used across all versions by 34 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running Continuous Integration (CI) tests on MidnightBSD. It allows users to easily run their test cases in a virtual environment based on MidnightBSD, addressing the need for CI testing across different operating systems. The action supports various releases and provides a simple interface for passing environment variables and commands to execute within the VM.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/midnightbsd-vm">https://github.com/vmactions/midnightbsd-vm</a></strong> to version <strong>v1.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>34</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/midnightbsd-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running Continuous Integration (CI) tests on MidnightBSD. It allows users to easily run their test cases in a virtual environment based on MidnightBSD, addressing the need for CI testing across different operating systems. The action supports various releases and provides a simple interface for passing environment variables and commands to execute within the VM.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="sync-tar">sync: tar</h2>
<p>A new way to share the workspace: the tree is streamed in as a ustar
archive over the ssh connection the action already opens, and streamed
back the same way when the run finishes. Nothing is installed in the
guest and no filesystem support is needed on either side, unlike sshfs
and nfs. midnightbsd-builder v2.0.7 declares it for every release, and
it was verified on this guest before the declaration went in: 300 files
plus a 1 MB binary blob pushed, a file written inside the VM, the whole
tree pulled back and compared by content hash.</p>
<p>rsync remains the default.</p>
<h2 id="under-the-hood">Under the hood</h2>
<p>The runtime moves to anyvm v0.6.5, ten releases on from the v0.5.5 that
v1.0.5 shipped. Two of its fixes reach every job: a failed folder sync
is now fatal instead of a warning that left the guest running without
the files it was about to use, and the workspace push no longer carries
the runner&rsquo;s own harness directories into the guest.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/midnightbsd-vm/compare/v1.0.5...v1.0.6">https://github.com/vmactions/midnightbsd-vm/compare/v1.0.5...v1.0.6</a></p>
]]></content:encoded></item><item><title>NextBSD-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/nextbsd-vm/</link><pubDate>Wed, 26 Aug 2026 14:46:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/nextbsd-vm/</guid><description>Version updated for https://github.com/vmactions/nextbsd-vm to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action allows users to run CI in NextBSD, a Unix-like operating system. It automates tasks by providing an AI-ready tool that generates custom GitHub Actions workflows based on user descriptions. The action supports automatic selection of the correct OS, architecture, and packages, simplifying setup for developers needing to test their projects on NextBSD.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/nextbsd-vm">https://github.com/vmactions/nextbsd-vm</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nextbsd-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action allows users to run CI in NextBSD, a Unix-like operating system. It automates tasks by providing an AI-ready tool that generates custom GitHub Actions workflows based on user descriptions. The action supports automatic selection of the correct OS, architecture, and packages, simplifying setup for developers needing to test their projects on NextBSD.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The runtime moves to anyvm v0.6.5 (from v0.6.0), keeping the whole fleet
on one version. This action&rsquo;s surface is unchanged &ndash; same image, same
sync methods, same defaults. The bump carries one runtime change of
note: on hosts whose nested AMD virtualization corrupts AVX512 XSAVE
state, the CPU-feature mask now drops the whole AVX512 family instead of
only avx512f.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/nextbsd-vm/compare/v1.0.0...v1.0.1">https://github.com/vmactions/nextbsd-vm/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>OpenEuler-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/openeuler-vm/</link><pubDate>Wed, 26 Aug 2026 14:45:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/openeuler-vm/</guid><description>Version updated for https://github.com/vmactions/openeuler-vm to version v1.0.1.
This action is used across all versions by 22 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action allows users to run their GitHub CI in OpenEuler by providing a pre-configured virtual machine environment with various package managers and utilities. It supports multiple architectures, including x86_64, aarch64, riscv64, and loongarch64. Users can specify the desired release and architecture using action parameters, and the workflow uses AnyVM.org to create custom VM images for these configurations. This eliminates the need for manual configuration and simplifies the process of setting up CI environments tailored to different operating systems.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/openeuler-vm">https://github.com/vmactions/openeuler-vm</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>22</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/openeuler-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action allows users to run their GitHub CI in OpenEuler by providing a pre-configured virtual machine environment with various package managers and utilities. It supports multiple architectures, including x86_64, aarch64, riscv64, and loongarch64. Users can specify the desired release and architecture using action parameters, and the workflow uses AnyVM.org to create custom VM images for these configurations. This eliminates the need for manual configuration and simplifies the process of setting up CI environments tailored to different operating systems.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="sync-tar">sync: tar</h2>
<p>A new way to share the workspace, available on every architecture
including riscv64 and loongarch64: the tree is streamed in as a ustar
archive over the ssh connection the action already opens, and streamed
back the same way when the run finishes. Nothing is installed in the
guest and no filesystem support is needed on either side, unlike sshfs
and nfs. openeuler-builder v2.0.2 declares it for every release, and it
was verified on this guest before the declaration went in: 300 files
plus a 1 MB binary blob pushed, a file written inside the VM, the whole
tree pulled back and compared by content hash.</p>
<p>rsync remains the default.</p>
<h2 id="under-the-hood">Under the hood</h2>
<p>The runtime moves to anyvm v0.6.5, twelve releases on from the v0.5.3
that v1.0.0 shipped. Two of its fixes reach every job: a failed folder
sync is now fatal instead of a warning that left the guest running
without the files it was about to use, and the workspace push no longer
carries the runner&rsquo;s own harness directories into the guest.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/openeuler-vm/compare/v1.0.0...v1.0.1">https://github.com/vmactions/openeuler-vm/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>OpenIndiana-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/openindiana-vm/</link><pubDate>Wed, 26 Aug 2026 14:44:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/openindiana-vm/</guid><description>Version updated for https://github.com/vmactions/openindiana-vm to version v1.1.6.
This action is used across all versions by 69 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running CI builds on OpenIndiana by leveraging AnyVM.org’s infrastructure. It supports multiple releases and arches, including x86_64 and aarch64. The action allows users to define custom environments and commands to run within the VM, simplifying the process of setting up CI pipelines for projects that require specific OS configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/openindiana-vm">https://github.com/vmactions/openindiana-vm</a></strong> to version <strong>v1.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>69</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/openindiana-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running CI builds on OpenIndiana by leveraging AnyVM.org&rsquo;s infrastructure. It supports multiple releases and arches, including x86_64 and aarch64. The action allows users to define custom environments and commands to run within the VM, simplifying the process of setting up CI pipelines for projects that require specific OS configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="sync-tar">sync: tar</h2>
<p>A new way to share the workspace: the tree is streamed in as a ustar
archive over the ssh connection the action already opens, and streamed
back the same way when the run finishes. Nothing is installed in the
guest and no filesystem support is needed on either side, unlike sshfs
and nfs. openindiana-builder v2.1.2 declares it for every release, and
it was verified on this guest before the declaration went in: 300 files
plus a 1 MB binary blob pushed, a file written inside the VM, the whole
tree pulled back and compared by content hash.</p>
<p>rsync remains the default.</p>
<h2 id="under-the-hood">Under the hood</h2>
<p>openindiana-builder v2.1.2 is also the first openindiana build to
publish releases.json, the machine-readable index this action bakes its
configuration from &ndash; which is why the pre-tar method list survived
until now.</p>
<p>The runtime moves to anyvm v0.6.5, twelve releases on from the v0.5.3
that v1.1.5 shipped. Two of its fixes reach every job: a failed folder
sync is now fatal instead of a warning that left the guest running
without the files it was about to use, and the workspace push no longer
carries the runner&rsquo;s own harness directories into the guest.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/openindiana-vm/compare/v1.1.5...v1.1.6">https://github.com/vmactions/openindiana-vm/compare/v1.1.5...v1.1.6</a></p>
]]></content:encoded></item><item><title>Plan9-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/plan9-vm/</link><pubDate>Wed, 26 Aug 2026 14:43:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/plan9-vm/</guid><description>Version updated for https://github.com/vmactions/plan9-vm to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of CI jobs on Plan9 systems using AnyVM. It allows developers to test their projects on Plan9 by running commands within a QEMU environment configured with anyvm support. The action supports both x86_64 and amd64 (9front) releases, providing a seamless way to integrate Plan9 testing into continuous integration workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/plan9-vm">https://github.com/vmactions/plan9-vm</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/plan9-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of CI jobs on Plan9 systems using AnyVM. It allows developers to test their projects on Plan9 by running commands within a QEMU environment configured with anyvm support. The action supports both x86_64 and amd64 (9front) releases, providing a seamless way to integrate Plan9 testing into continuous integration workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The runtime moves to anyvm v0.6.5 (from v0.6.4), keeping the whole fleet
on one version. This action&rsquo;s surface is unchanged &ndash; same images, same
sync methods, same defaults. The bump carries one runtime change of
note: on hosts whose nested AMD virtualization corrupts AVX512 XSAVE
state, the CPU-feature mask now drops the whole AVX512 family instead of
only avx512f.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/plan9-vm/compare/v1.0.0...v1.0.1">https://github.com/vmactions/plan9-vm/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>ReactOS-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/reactos-vm/</link><pubDate>Wed, 26 Aug 2026 14:41:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/reactos-vm/</guid><description>Version updated for https://github.com/vmactions/reactos-vm to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action provides a way to run CI workflows on ReactOS using AnyVM.org’s virtual machines. It supports different releases and architectures, including i386 (x86 32-bit), and can handle remote command execution and file synchronization via tar streams over the telnet channel. However, it has some limitations with NFS support due to bugs in ReactOS.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/reactos-vm">https://github.com/vmactions/reactos-vm</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/reactos-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action provides a way to run CI workflows on ReactOS using AnyVM.org&rsquo;s virtual machines. It supports different releases and architectures, including i386 (x86 32-bit), and can handle remote command execution and file synchronization via tar streams over the telnet channel. However, it has some limitations with NFS support due to bugs in ReactOS.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The runtime moves to anyvm v0.6.5 (from v0.6.4), keeping the whole fleet
on one version. This action&rsquo;s surface is unchanged &ndash; same images, same
sync methods, same defaults. The bump carries one runtime change of
note: on hosts whose nested AMD virtualization corrupts AVX512 XSAVE
state, the CPU-feature mask now drops the whole AVX512 family instead of
only avx512f.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/reactos-vm/compare/v1.0.2...v1.0.3">https://github.com/vmactions/reactos-vm/compare/v1.0.2...v1.0.3</a></p>
]]></content:encoded></item><item><title>Redox-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/redox-vm/</link><pubDate>Wed, 26 Aug 2026 14:40:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/redox-vm/</guid><description>Version updated for https://github.com/vmactions/redox-vm to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running CI tasks on Redox by utilizing AnyVM, a platform that provides virtual machines with specific OSes and configurations. It supports multiple architectures, including x86_64, and includes a built-in telnet server to allow remote access. The action is designed to handle common use cases, such as compiling projects or running automated tests on Redox, and can be configured to pass environment variables and run custom commands within the virtual machine.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/redox-vm">https://github.com/vmactions/redox-vm</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/redox-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running CI tasks on Redox by utilizing AnyVM, a platform that provides virtual machines with specific OSes and configurations. It supports multiple architectures, including x86_64, and includes a built-in telnet server to allow remote access. The action is designed to handle common use cases, such as compiling projects or running automated tests on Redox, and can be configured to pass environment variables and run custom commands within the virtual machine.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The runtime moves to anyvm v0.6.5 (from v0.6.4), keeping the whole fleet
on one version. This action&rsquo;s surface is unchanged &ndash; same images, same
sync methods, same defaults. The bump carries one runtime change of
note: on hosts whose nested AMD virtualization corrupts AVX512 XSAVE
state, the CPU-feature mask now drops the whole AVX512 family instead of
only avx512f.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/redox-vm/compare/v1.0.0...v1.0.1">https://github.com/vmactions/redox-vm/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>RISCOS-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/riscos-vm/</link><pubDate>Wed, 26 Aug 2026 14:39:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/riscos-vm/</guid><description>Version updated for https://github.com/vmactions/riscos-vm to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates CI testing on RISCOS using AnyVM.org’s VMs. It simplifies setup by handling common configurations and integrates with AI-powered automation through the vmactions-ci skill. The action supports running tests on RISC OS but is limited to x86_64 Linux hosts and requires a patched QEMU emulator for Raspberry Pi-specific functionality.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/riscos-vm">https://github.com/vmactions/riscos-vm</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/riscos-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates CI testing on RISCOS using AnyVM.org&rsquo;s VMs. It simplifies setup by handling common configurations and integrates with AI-powered automation through the vmactions-ci skill. The action supports running tests on RISC OS but is limited to x86_64 Linux hosts and requires a patched QEMU emulator for Raspberry Pi-specific functionality.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="binary-folder-sync-no-longer-depends-on-luck">Binary folder sync no longer depends on luck</h2>
<p>The runtime moves to anyvm v0.6.5 (from v0.6.0), and the fix that
matters here is v0.6.4&rsquo;s. The telnet reader dropped half of an escaped
0xFF whenever the two-byte IAC escape straddled a recv boundary, so any
binary payload could come back the right size with the wrong contents &ndash;
and it was this guest that exposed it, returning 201 base64 files
byte-perfect while corrupting the 400 KB random blob sitting next to
them. Incomplete escape sequences are now held for the next chunk,
proven by cutting the stream between every escape pair.</p>
<p>v0.6.2 also gave the copy-back real timeout budgets &ndash; 900 s to the
first byte, because the guest walks the whole tree before it writes
anything, then 600 s between bytes &ndash; instead of one flat 120 s window
that a large workspace could blow past.</p>
<p>The guest CI payload grew from one file to 200 files plus a 0.4 MB
blob, checksummed on the way back, so a regression of this shape cannot
ship unseen again.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/riscos-vm/compare/v1.0.0...v1.0.1">https://github.com/vmactions/riscos-vm/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>Tribblix-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/tribblix-vm/</link><pubDate>Wed, 26 Aug 2026 14:37:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/tribblix-vm/</guid><description>Version updated for https://github.com/vmactions/tribblix-vm to version v1.0.5.
This action is used across all versions by 29 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: This GitHub Action automates running CI/CD pipelines on Tribblix, a lightweight Linux distribution. It provides AI-assisted workflow creation for AI-ready VMs, allowing users to define test cases without manually writing complex test.yml files. The action supports various releases and architectures and includes a step-by-step guide to set up and use the action effectively.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/tribblix-vm">https://github.com/vmactions/tribblix-vm</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>29</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tribblix-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<h3 id="summary">Summary:</h3>
<p>This GitHub Action automates running CI/CD pipelines on Tribblix, a lightweight Linux distribution. It provides AI-assisted workflow creation for AI-ready VMs, allowing users to define test cases without manually writing complex <code>test.yml</code> files. The action supports various releases and architectures and includes a step-by-step guide to set up and use the action effectively.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The runtime moves to anyvm v0.6.5 (from v0.6.4), keeping the whole fleet
on one version. This action&rsquo;s surface is unchanged &ndash; same images, same
sync methods, same defaults. The bump carries one runtime change of
note: on hosts whose nested AMD virtualization corrupts AVX512 XSAVE
state, the CPU-feature mask now drops the whole AVX512 family instead of
only avx512f.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/tribblix-vm/compare/v1.0.4...v1.0.5">https://github.com/vmactions/tribblix-vm/compare/v1.0.4...v1.0.5</a></p>
]]></content:encoded></item><item><title>install spaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/install-spaces/</link><pubDate>Wed, 26 Aug 2026 14:36:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/install-spaces/</guid><description>Version updated for https://github.com/work-spaces/install-spaces to version v0.21.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The install-spaces GitHub Action automates the installation of Spaces for developers using a CI/CD pipeline. It simplifies the setup process by integrating automated installation into the workflow, reducing manual steps and improving consistency across development environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/install-spaces">https://github.com/work-spaces/install-spaces</a></strong> to version <strong>v0.21.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-spaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>install-spaces</code> GitHub Action automates the installation of Spaces for developers using a CI/CD pipeline. It simplifies the setup process by integrating automated installation into the workflow, reducing manual steps and improving consistency across development environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fix install sh by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/47">https://github.com/work-spaces/install-spaces/pull/47</a></li>
<li>Bump version to v0.21.1 by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/48">https://github.com/work-spaces/install-spaces/pull/48</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/install-spaces/compare/v0.21.0...v0.21.1">https://github.com/work-spaces/install-spaces/compare/v0.21.0...v0.21.1</a></p>
]]></content:encoded></item><item><title>AgentLeak privacy gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/agentleak-privacy-gate/</link><pubDate>Wed, 26 Aug 2026 14:36:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/agentleak-privacy-gate/</guid><description>Version updated for https://github.com/yagobski/agentleak to version v0.11.10.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: AgentLeak is a privacy-leakage testing action designed to audit AI agents’ execution channels, scoring them deterministically, and gating them in CI. It identifies vulnerabilities such as sensitive data leaks through tool calls, shared memory, inter-agent messages, and logs, providing a risk assessment with the AgentRisk metric grounded in GDPR Article 9 and Québec Law 25. The action can be installed via pip and includes local UI and MCP tools for coding agents.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yagobski/agentleak">https://github.com/yagobski/agentleak</a></strong> to version <strong>v0.11.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentleak-privacy-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong>
AgentLeak is a privacy-leakage testing action designed to audit AI agents&rsquo; execution channels, scoring them deterministically, and gating them in CI. It identifies vulnerabilities such as sensitive data leaks through tool calls, shared memory, inter-agent messages, and logs, providing a risk assessment with the AgentRisk metric grounded in GDPR Article 9 and Québec Law 25. The action can be installed via pip and includes local UI and MCP tools for coding agents.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.11.10 — redesigned sign-in by @yagobski in <a href="https://github.com/yagobski/agentleak/pull/6">https://github.com/yagobski/agentleak/pull/6</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yagobski/agentleak/compare/v0.11.9...v0.11.10">https://github.com/yagobski/agentleak/compare/v0.11.9...v0.11.10</a></p>
]]></content:encoded></item><item><title>Plori persistent agent review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/plori-persistent-agent-review/</link><pubDate>Wed, 26 Aug 2026 06:41:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/plori-persistent-agent-review/</guid><description>Version updated for https://github.com/plori-ai/agent-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates continuous code reviews by providing a persistent review workspace that checks out specific pull-request commits, reads surrounding code, and runs targeted tests instead of reviewing diffs in isolation. It solves the problem of automating code reviews and helps maintainers quickly identify potential issues without needing to manually examine changes. The action uses OIDC for authentication, ensuring secure access to repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plori-ai/agent-action">https://github.com/plori-ai/agent-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/plori-persistent-agent-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates continuous code reviews by providing a persistent review workspace that checks out specific pull-request commits, reads surrounding code, and runs targeted tests instead of reviewing diffs in isolation. It solves the problem of automating code reviews and helps maintainers quickly identify potential issues without needing to manually examine changes. The action uses OIDC for authentication, ensuring secure access to repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Persistent remote pull-request review with GitHub Actions OIDC and isolated comment permissions.</p>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-api-onboarding/</link><pubDate>Wed, 26 Aug 2026 06:40:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v3.4.9.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman API Onboarding Action automates the onboarding process of a GitHub repository by bootstrapping, uploading an OpenAPI definition, generating collections, syncing repository artifacts, and running built-in smoke and contract tests. It supports full inventories of generated assertions, smoke scripts, and Contract Enforcement Layers. The action requires a service token with permission to create workspaces if none exists for the target scope.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v3.4.9</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman API Onboarding Action automates the onboarding process of a GitHub repository by bootstrapping, uploading an OpenAPI definition, generating collections, syncing repository artifacts, and running built-in smoke and contract tests. It supports full inventories of generated assertions, smoke scripts, and Contract Enforcement Layers. The action requires a service token with permission to create workspaces if none exists for the target scope.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/91">https://github.com/postman-cs/postman-api-onboarding-action/pull/91</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/92">https://github.com/postman-cs/postman-api-onboarding-action/pull/92</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/93">https://github.com/postman-cs/postman-api-onboarding-action/pull/93</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/94">https://github.com/postman-cs/postman-api-onboarding-action/pull/94</a></li>
<li>chore(deps): pin Insights onboarding v2.2.1 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/95">https://github.com/postman-cs/postman-api-onboarding-action/pull/95</a></li>
<li>fix: consume Insights human-session normalization by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/96">https://github.com/postman-cs/postman-api-onboarding-action/pull/96</a></li>
<li>fix: consume repo-sync v2.2.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/97">https://github.com/postman-cs/postman-api-onboarding-action/pull/97</a></li>
<li>fix: expose mock environment and refresh Azure pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/98">https://github.com/postman-cs/postman-api-onboarding-action/pull/98</a></li>
<li>feat: pass mock visibility policy through to repo-sync by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/99">https://github.com/postman-cs/postman-api-onboarding-action/pull/99</a></li>
<li>chore: pin repo-sync v2.4.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/100">https://github.com/postman-cs/postman-api-onboarding-action/pull/100</a></li>
<li>fix: document private mock credential paths for consumers by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/101">https://github.com/postman-cs/postman-api-onboarding-action/pull/101</a></li>
<li>fix(deps): advance the bootstrap pin to v2.13.2 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/102">https://github.com/postman-cs/postman-api-onboarding-action/pull/102</a></li>
<li>fix(deps): advance bootstrap and repo-sync pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/103">https://github.com/postman-cs/postman-api-onboarding-action/pull/103</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/104">https://github.com/postman-cs/postman-api-onboarding-action/pull/104</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.8 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/105">https://github.com/postman-cs/postman-api-onboarding-action/pull/105</a></li>
<li>fix(deps): advance bootstrap pin to v2.13.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/106">https://github.com/postman-cs/postman-api-onboarding-action/pull/106</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>fix(ci): validate sibling pins without local checkouts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/111">https://github.com/postman-cs/postman-api-onboarding-action/pull/111</a></li>
<li>feat(azure-devops): forward an explicit workspace squad id from the Windows template by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/112">https://github.com/postman-cs/postman-api-onboarding-action/pull/112</a></li>
<li>fix(release): harden composite pin and E2E releases by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/113">https://github.com/postman-cs/postman-api-onboarding-action/pull/113</a></li>
<li>fix(release): supersede stale aliases with pending cuts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/114">https://github.com/postman-cs/postman-api-onboarding-action/pull/114</a></li>
<li>fix(release): wait for correlated E2E run names by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/115">https://github.com/postman-cs/postman-api-onboarding-action/pull/115</a></li>
<li>fix(release): keep pin ratchet synchronized by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/116">https://github.com/postman-cs/postman-api-onboarding-action/pull/116</a></li>
<li>fix(ci): preserve pin updater test fixtures by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/117">https://github.com/postman-cs/postman-api-onboarding-action/pull/117</a></li>
<li>fix(release): reconcile failed release completions by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/118">https://github.com/postman-cs/postman-api-onboarding-action/pull/118</a></li>
<li>fix(release): emit automated completion events by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/119">https://github.com/postman-cs/postman-api-onboarding-action/pull/119</a></li>
<li>fix(release): bound failed release recovery by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/120">https://github.com/postman-cs/postman-api-onboarding-action/pull/120</a></li>
<li>fix(release): hold auto release through E2E completion by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/121">https://github.com/postman-cs/postman-api-onboarding-action/pull/121</a></li>
<li>feat: expose spec-only onboarding scope by @sean-riney in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/123">https://github.com/postman-cs/postman-api-onboarding-action/pull/123</a></li>
<li>docs: add service-account workspace permission preflight by @andrewpostymt in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/122">https://github.com/postman-cs/postman-api-onboarding-action/pull/122</a></li>
<li>chore(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/108">https://github.com/postman-cs/postman-api-onboarding-action/pull/108</a></li>
<li>fix(ci): make cache pin assertion semantic by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/124">https://github.com/postman-cs/postman-api-onboarding-action/pull/124</a></li>
<li>chore(deps): bump actions/cache from 4.2.0 to 6.1.0 in the actions group across 1 directory by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/109">https://github.com/postman-cs/postman-api-onboarding-action/pull/109</a></li>
<li>feat: publish as @postman/onboarding-api with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/127">https://github.com/postman-cs/postman-api-onboarding-action/pull/127</a></li>
<li>fix(release): gate alias advance on npm publish output, not job result by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/128">https://github.com/postman-cs/postman-api-onboarding-action/pull/128</a></li>
<li>fix(release): keep alias gates on publish job result by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/129">https://github.com/postman-cs/postman-api-onboarding-action/pull/129</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@github-actions[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>@andrewpostymt made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/122">https://github.com/postman-cs/postman-api-onboarding-action/pull/122</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.4.9">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.4.9</a></p>
]]></content:encoded></item><item><title>Postman Onboarding AWS Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-aws-spec-discovery/</link><pubDate>Wed, 26 Aug 2026 06:39:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-aws-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v3.3.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically discovers and exports API specifications from AWS services using only existing AWS credentials. It solves the problem of creating a source-of-truth specification for Postman onboarding by leveraging your IAM permissions to automatically detect and resolve specs before calling AWS APIs. The action supports a wide range of AWS services, including API Gateway, AppSync, SNS, EventBridge, Lambda, SSM, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-aws-spec-discovery-action">https://github.com/postman-cs/postman-aws-spec-discovery-action</a></strong> to version <strong>v3.3.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-aws-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically discovers and exports API specifications from AWS services using only existing AWS credentials. It solves the problem of creating a source-of-truth specification for Postman onboarding by leveraging your IAM permissions to automatically detect and resolve specs before calling AWS APIs. The action supports a wide range of AWS services, including API Gateway, AppSync, SNS, EventBridge, Lambda, SSM, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/53">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/53</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/54">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/54</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/55">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/55</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/56">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/56</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/57">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/57</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/58">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/58</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/62">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/62</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/64">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/64</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/65">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/65</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/66">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/66</a></li>
<li>fix(ci): address Codex writeback feedback by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/67">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/67</a></li>
<li>fix(ci): use ESM execSync and update permission test by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/68">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/68</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/69">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/69</a></li>
<li>feat: publish as @postman/onboarding-aws-spec-discovery with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/73">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/73</a></li>
<li>fix(release): tolerate npm registry propagation by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/74">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/74</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v3.1.4...v3.3.1">https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v3.1.4...v3.3.1</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Azure Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-azure-spec-discovery/</link><pubDate>Wed, 26 Aug 2026 06:38:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-azure-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-azure-spec-discovery-action to version v1.5.3.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Azure Spec Discovery action helps discover and export API specs from Azure services using the user’s existing Azure credentials. It automates the process of identifying and selecting the most relevant Azure service spec for integration with Postman, ensuring a reliable source-of-truth for API contracts. The action handles various Azure providers such as APIM, App Service, custom connectors, and others, and narrows down the results based on tags, environment variables, and Git metadata, providing users with clear and actionable insights into their API specs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-azure-spec-discovery-action">https://github.com/postman-cs/postman-azure-spec-discovery-action</a></strong> to version <strong>v1.5.3</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-azure-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Azure Spec Discovery action helps discover and export API specs from Azure services using the user&rsquo;s existing Azure credentials. It automates the process of identifying and selecting the most relevant Azure service spec for integration with Postman, ensuring a reliable source-of-truth for API contracts. The action handles various Azure providers such as APIM, App Service, custom connectors, and others, and narrows down the results based on tags, environment variables, and Git metadata, providing users with clear and actionable insights into their API specs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/15">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/15</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/18">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/18</a></li>
<li>fix(test): assert the packaged version against package.json by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/19">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/19</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/20">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/20</a></li>
<li>fix(release): fetch the tag parent before ancestry checks by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/21">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/21</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/22">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/22</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/23">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/23</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/24">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/24</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/26">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/26</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/28">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/28</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/29">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/29</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/30">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/30</a></li>
<li>fix(ci): address Codex writeback feedback by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/31">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/31</a></li>
<li>fix(ci): use ESM execSync and update permission test by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/32">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/32</a></li>
<li>test(windows): preserve gate timing under contention by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/34">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/34</a></li>
<li>feat: publish as @postman/onboarding-azure-spec-discovery with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/38">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/38</a></li>
<li>fix(release): gate aliases on npm publish output and retry registry r… by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/39">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/39</a></li>
<li>fix(release): size registry read-back window to measured propagation delay by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/40">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/40</a></li>
<li>fix(release): keep alias gates on publish job result by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/41">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/41</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@pavan-nelakuditi made their first contribution in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/39">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/39</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/compare/v1.3.5...v1.5.3">https://github.com/postman-cs/postman-azure-spec-discovery-action/compare/v1.3.5...v1.5.3</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-workspace-bootstrap/</link><pubDate>Wed, 26 Aug 2026 06:37:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.20.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Workspace Bootstrap GitHub Action automates the creation of a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections with executable tests. It supports various protocols and provides multi-protocol contract assertions grounded in RFCs. The action can be used for both Git-first specs and public HTTPS URLs, requiring either spec-url or spec-path. Users must provide a Postman access token to operate on assets.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.20.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Workspace Bootstrap GitHub Action automates the creation of a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections with executable tests. It supports various protocols and provides multi-protocol contract assertions grounded in RFCs. The action can be used for both Git-first specs and public HTTPS URLs, requiring either <code>spec-url</code> or <code>spec-path</code>. Users must provide a Postman access token to operate on assets.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: normalize multifile receipt after v2.16.1 by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/179">https://github.com/postman-cs/postman-bootstrap-action/pull/179</a></li>
<li>fix(gateway-assets): fail closed when org squad discovery is indeterminate by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/180">https://github.com/postman-cs/postman-bootstrap-action/pull/180</a></li>
<li>feat(release): gate aliases on correlated E2E by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/181">https://github.com/postman-cs/postman-bootstrap-action/pull/181</a></li>
<li>fix(release): wait for run-name hydration by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/182">https://github.com/postman-cs/postman-bootstrap-action/pull/182</a></li>
<li>fix(release): notify the composite after Bootstrap publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/183">https://github.com/postman-cs/postman-bootstrap-action/pull/183</a></li>
<li>feat: add generated asset sync control by @sean-riney in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/186">https://github.com/postman-cs/postman-bootstrap-action/pull/186</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/188">https://github.com/postman-cs/postman-bootstrap-action/pull/188</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/191">https://github.com/postman-cs/postman-bootstrap-action/pull/191</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/192">https://github.com/postman-cs/postman-bootstrap-action/pull/192</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/194">https://github.com/postman-cs/postman-bootstrap-action/pull/194</a></li>
<li>fix(ci): address Codex writeback feedback by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/195">https://github.com/postman-cs/postman-bootstrap-action/pull/195</a></li>
<li>fix(ci): use ESM execSync and update permission test by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/196">https://github.com/postman-cs/postman-bootstrap-action/pull/196</a></li>
<li>chore: normalize multifile receipt after v2.18.3 by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/197">https://github.com/postman-cs/postman-bootstrap-action/pull/197</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/198">https://github.com/postman-cs/postman-bootstrap-action/pull/198</a></li>
<li>chore: rebind multifile receipt to main by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/199">https://github.com/postman-cs/postman-bootstrap-action/pull/199</a></li>
<li>ci: run dist parity after skipped normalizer by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/200">https://github.com/postman-cs/postman-bootstrap-action/pull/200</a></li>
<li>feat: publish as @postman/onboarding-bootstrap with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/208">https://github.com/postman-cs/postman-bootstrap-action/pull/208</a></li>
<li>ci: install restricted dependencies without npm token by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/209">https://github.com/postman-cs/postman-bootstrap-action/pull/209</a></li>
<li>chore: rebind multifile receipt to main by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/210">https://github.com/postman-cs/postman-bootstrap-action/pull/210</a></li>
<li>fix(deps): move private @postman platform packages to devDependencies by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/211">https://github.com/postman-cs/postman-bootstrap-action/pull/211</a></li>
<li>feat: support monorepo working directories by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/212">https://github.com/postman-cs/postman-bootstrap-action/pull/212</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2.16.1...v2.20.0">https://github.com/postman-cs/postman-bootstrap-action/compare/v2.16.1...v2.20.0</a></p>
]]></content:encoded></item><item><title>Postman Onboarding GCP Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-gcp-spec-discovery/</link><pubDate>Wed, 26 Aug 2026 06:35:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-gcp-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-gcp-spec-discovery-action to version v1.3.2.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: GCP Spec Discovery action automatically discovers and exports OpenAPI specifications from Google Cloud services, supporting Application Default Credentials (ADC) or Workload Identity Federation. It uses repository context to resolve APIs or supports exporting via API ID or config revision. The action requires a project-id and can be configured to use specific service names or labels for resolution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action">https://github.com/postman-cs/postman-gcp-spec-discovery-action</a></strong> to version <strong>v1.3.2</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-gcp-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: GCP Spec Discovery action automatically discovers and exports OpenAPI specifications from Google Cloud services, supporting Application Default Credentials (ADC) or Workload Identity Federation. It uses repository context to resolve APIs or supports exporting via API ID or config revision. The action requires a <code>project-id</code> and can be configured to use specific service names or labels for resolution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut and verify tags by ancestry by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/27">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/27</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/30">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/30</a></li>
<li>fix(test): assert the packaged version against package.json by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/31">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/31</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/32">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/32</a></li>
<li>fix(release): fetch the tag parent before ancestry checks by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/33">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/33</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/34">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/34</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/35">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/35</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/36">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/36</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/40">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/40</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/42">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/42</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/43">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/43</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/44">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/44</a></li>
<li>fix(ci): address Codex writeback feedback by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/45">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/45</a></li>
<li>fix(ci): use ESM execSync and update permission test by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/46">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/46</a></li>
<li>feat: publish as @postman/onboarding-gcp-spec-discovery with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/50">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/50</a></li>
<li>fix(release): gate aliases on npm publish output and size registry read-back by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/51">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/51</a></li>
<li>fix(release): keep alias gates on publish job result by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/52">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/52</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@pavan-nelakuditi made their first contribution in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/51">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/51</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/compare/v1.1.8...v1.3.2">https://github.com/postman-cs/postman-gcp-spec-discovery-action/compare/v1.1.8...v1.3.2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-repo-sync/</link><pubDate>Wed, 26 Aug 2026 06:34:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.10.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action postman-repo-sync-action by Postman CS exports Postman collections and environments into a repository, automates CI setup with mock servers and monitors. It simplifies the onboarding process for teams using the Postman API, handling environment management and data residency considerations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.10.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>postman-repo-sync-action</code> by Postman CS exports Postman collections and environments into a repository, automates CI setup with mock servers and monitors. It simplifies the onboarding process for teams using the Postman API, handling environment management and data residency considerations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/134">https://github.com/postman-cs/postman-repo-sync-action/pull/134</a></li>
<li>feat: publish as @postman/onboarding-repo-sync with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/140">https://github.com/postman-cs/postman-repo-sync-action/pull/140</a></li>
<li>ci: install restricted dependencies without npm token by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/141">https://github.com/postman-cs/postman-repo-sync-action/pull/141</a></li>
<li>fix(deps): move private @postman platform packages to devDependencies by @pavan-nelakuditi in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/144">https://github.com/postman-cs/postman-repo-sync-action/pull/144</a></li>
<li>feat: support monorepo working directories by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/145">https://github.com/postman-cs/postman-repo-sync-action/pull/145</a></li>
<li>fix(release): repair stale rolling alias by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/146">https://github.com/postman-cs/postman-repo-sync-action/pull/146</a></li>
<li>fix(release): use workflow-capable tag token by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/147">https://github.com/postman-cs/postman-repo-sync-action/pull/147</a></li>
<li>fix(release): use writable workflow token by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/148">https://github.com/postman-cs/postman-repo-sync-action/pull/148</a></li>
<li>fix(release): scope workflow token to repository by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/149">https://github.com/postman-cs/postman-repo-sync-action/pull/149</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.10.0">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.10.0</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Service Token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-service-token/</link><pubDate>Wed, 26 Aug 2026 06:33:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-service-token/</guid><description>Version updated for https://github.com/postman-cs/postman-resolve-service-token-action to version v2.2.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Service Token action mints a fresh service-account access token and team ID in CI, ready to hand to the onboarding action or store as repo secrets, part of the Postman API Onboarding suite. It is recommended for use before postman-api-onboarding-action and requires a Postman service account PMAK with personal user keys rejected by the /service-account-tokens endpoint.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-resolve-service-token-action">https://github.com/postman-cs/postman-resolve-service-token-action</a></strong> to version <strong>v2.2.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-service-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Service Token action mints a fresh service-account access token and team ID in CI, ready to hand to the onboarding action or store as repo secrets, part of the Postman API Onboarding suite. It is recommended for use before <code>postman-api-onboarding-action</code> and requires a Postman service account PMAK with personal user keys rejected by the <code>/service-account-tokens</code> endpoint.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(release): verify service-token artifacts and async monitors by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/37">https://github.com/postman-cs/postman-resolve-service-token-action/pull/37</a></li>
<li>perf(ci): accelerate Windows parity gate by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/38">https://github.com/postman-cs/postman-resolve-service-token-action/pull/38</a></li>
<li>test: avoid empty npm CLI path on Windows by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/39">https://github.com/postman-cs/postman-resolve-service-token-action/pull/39</a></li>
<li>chore: prepare v2.0.5 release by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/40">https://github.com/postman-cs/postman-resolve-service-token-action/pull/40</a></li>
<li>fix(release): classify dispatch-cut runs by the cut tag ref by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/41">https://github.com/postman-cs/postman-resolve-service-token-action/pull/41</a></li>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/42">https://github.com/postman-cs/postman-resolve-service-token-action/pull/42</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/43">https://github.com/postman-cs/postman-resolve-service-token-action/pull/43</a></li>
<li>fix(release): pass the required version input when dispatching a cut tag by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/44">https://github.com/postman-cs/postman-resolve-service-token-action/pull/44</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/45">https://github.com/postman-cs/postman-resolve-service-token-action/pull/45</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/46">https://github.com/postman-cs/postman-resolve-service-token-action/pull/46</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/47">https://github.com/postman-cs/postman-resolve-service-token-action/pull/47</a></li>
<li>chore(deps): bump the npm-minor-patch group across 1 directory with 3 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/51">https://github.com/postman-cs/postman-resolve-service-token-action/pull/51</a></li>
<li>fix(ci): make cache pin assertion semantic by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/52">https://github.com/postman-cs/postman-resolve-service-token-action/pull/52</a></li>
<li>chore(deps): bump actions/cache from 4.2.0 to 6.1.0 in the actions group across 1 directory by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/48">https://github.com/postman-cs/postman-resolve-service-token-action/pull/48</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/53">https://github.com/postman-cs/postman-resolve-service-token-action/pull/53</a></li>
<li>feat: publish as @postman/onboarding-resolve-service-token with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/56">https://github.com/postman-cs/postman-resolve-service-token-action/pull/56</a></li>
<li>fix(release): tolerate npm registry propagation by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/57">https://github.com/postman-cs/postman-resolve-service-token-action/pull/57</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-resolve-service-token-action/compare/v2.0.4...v2.2.1">https://github.com/postman-cs/postman-resolve-service-token-action/compare/v2.0.4...v2.2.1</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Smoke Flow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-smoke-flow/</link><pubDate>Wed, 26 Aug 2026 06:32:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/postman-onboarding-smoke-flow/</guid><description>Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v3.7.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Smoke Flow action reshapes the generated Postman Smoke collection into an ordered smoke journey using one effective flow path. It automatically curates a valid manifest or derives it from the OpenAPI spec and injects runtime auth credentials like OAuth2 and API keys, making it suitable for onboarding and automating smoke testing in Postman workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-smoke-flow-action">https://github.com/postman-cs/postman-smoke-flow-action</a></strong> to version <strong>v3.7.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-smoke-flow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Smoke Flow action reshapes the generated Postman Smoke collection into an ordered smoke journey using one effective flow path. It automatically curates a valid manifest or derives it from the OpenAPI spec and injects runtime auth credentials like OAuth2 and API keys, making it suitable for onboarding and automating smoke testing in Postman workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): cut immutable tags only after gates pass on main by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/57">https://github.com/postman-cs/postman-smoke-flow-action/pull/57</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/58">https://github.com/postman-cs/postman-smoke-flow-action/pull/58</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/59">https://github.com/postman-cs/postman-smoke-flow-action/pull/59</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/60">https://github.com/postman-cs/postman-smoke-flow-action/pull/60</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/61">https://github.com/postman-cs/postman-smoke-flow-action/pull/61</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/76">https://github.com/postman-cs/postman-smoke-flow-action/pull/76</a></li>
<li>feat: publish as @postman/onboarding-smoke-flow with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/80">https://github.com/postman-cs/postman-smoke-flow-action/pull/80</a></li>
<li>feat: support monorepo working directories by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/81">https://github.com/postman-cs/postman-smoke-flow-action/pull/81</a></li>
<li>fix(release): tolerate npm registry propagation by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/82">https://github.com/postman-cs/postman-smoke-flow-action/pull/82</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.7...v3.7.1">https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.7...v3.7.1</a></p>
]]></content:encoded></item><item><title>PyGo CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/pygo-cli/</link><pubDate>Wed, 26 Aug 2026 06:31:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/pygo-cli/</guid><description>Version updated for https://github.com/PyGo-Labs/pygo-framework to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action is designed to simplify the setup and development of Python applications using Go HTTP as the backend framework and Python for the domain logic, with communication over UDS+MessagePack. It promotes a modular structure, supports hot-reload during development, and provides a CLI for project creation and management. The action also includes features such as automatic CLI updates and support for popular modules like authentication, i18n, and admin interfaces.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PyGo-Labs/pygo-framework">https://github.com/PyGo-Labs/pygo-framework</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pygo-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action is designed to simplify the setup and development of Python applications using Go HTTP as the backend framework and Python for the domain logic, with communication over UDS+MessagePack. It promotes a modular structure, supports hot-reload during development, and provides a CLI for project creation and management. The action also includes features such as automatic CLI updates and support for popular modules like authentication, i18n, and admin interfaces.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat(core): complete partial/stub modules (81f1aad)</li>
<li>feat(cli): complete CLI v2.0 with all commands (72fe4ea)</li>
<li>refactor(v2.0): complete modular reorganization (6b6714b)</li>
<li>fix(installer): handle gzip-only assets in addition to tar.gz (affcf3c)</li>
<li>fix(cli): module install now extracts archives and registers in pygo.toml (17635c8)</li>
<li>fix(web): no filtrar token, solo _path/_method (a0d91f9)</li>
<li>fix(web): filtrar _path/_method como parametros internos (7075ff7)</li>
<li>fix(web): servir HTML sin envolver en JSON + recover por handler (c59353d)</li>
<li>feat: Installation system + GitHub Actions release pipeline (f42d57b)</li>
<li>fix(web): Router multi-method dispatch + hot-reload CLI (ecf0e1c)</li>
</ul>
]]></content:encoded></item><item><title>DSH Plugin Migrate Bot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/dsh-plugin-migrate-bot/</link><pubDate>Wed, 26 Aug 2026 06:30:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/dsh-plugin-migrate-bot/</guid><description>Version updated for https://github.com/royenheart/dsh-migrate-bot to version v0.1.5.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the migration of a third-party plugin to a specific DeepSeek Harness release by performing various checks and tests. It resolves the target dsh-v* version, skips if it matches the last processed version unless forced, runs mechanical tests, sparse-checkouts the harness tag, performs A/B/C reviews, and handles patch reports. If there are changes or failures in the process, it records the version on a state branch and may create an Issue and PR with relevant information.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/royenheart/dsh-migrate-bot">https://github.com/royenheart/dsh-migrate-bot</a></strong> to version <strong>v0.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dsh-plugin-migrate-bot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the migration of a third-party plugin to a specific DeepSeek Harness release by performing various checks and tests. It resolves the target <code>dsh-v*</code> version, skips if it matches the last processed version unless forced, runs mechanical tests, sparse-checkouts the harness tag, performs A/B/C reviews, and handles patch reports. If there are changes or failures in the process, it records the version on a state branch and may create an Issue and PR with relevant information.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<p>The Issue again carries the real analysis: root cause, overlap verdict, and each A/B (and last C) prompt section. The 0.1.4 fence hardening stays; we no longer collapse those sections into a two-paragraph teaser.</p>
<p>Consumers pinning <code>royenheart/dsh-migrate-bot@v0</code> pick this up automatically.</p>
<h2 id="fixes">Fixes</h2>
<ul>
<li><strong>Root cause is derived</strong>, not canned. Last C report&rsquo;s Root cause wins; otherwise overlap verdict plus remaining gaps / edits. Mechanical failure is stated when tests still fail.</li>
<li><strong>A/B (and C) sections render in full</strong> as <code>###</code> under the Issue <code>##</code> outline, so a large harness change shows purpose, overlap, edits, gaps, and risks on the Issue. Payloads stay sanitized so fences and <code>&lt;/details&gt;</code> cannot steal later sections.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/royenheart/dsh-migrate-bot/compare/v0.1.4...v0.1.5">https://github.com/royenheart/dsh-migrate-bot/compare/v0.1.4...v0.1.5</a></p>
]]></content:encoded></item><item><title>SFDT for Salesforce</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/sfdt-for-salesforce/</link><pubDate>Wed, 26 Aug 2026 06:29:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/sfdt-for-salesforce/</guid><description>Version updated for https://github.com/scoobydrew83/sfdt to version v0.23.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SFDT Action automates Salesforce DevTools, a production-grade CLI suite for deployment, testing, quality analysis, and release management. It pairs with the SFDT Chrome extension and VS Code extension to provide an interactive workflow for deploying changes to Salesforce Orgs, parallel Apex test execution, AI-powered error interpretation, PR descriptions, and notifications. The action supports multi-package projects, a smart package.xml generator, and CI/CD templates through GitHub Actions and workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scoobydrew83/sfdt">https://github.com/scoobydrew83/sfdt</a></strong> to version <strong>v0.23.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdt-for-salesforce">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The SFDT Action automates Salesforce DevTools, a production-grade CLI suite for deployment, testing, quality analysis, and release management. It pairs with the SFDT Chrome extension and VS Code extension to provide an interactive workflow for deploying changes to Salesforce Orgs, parallel Apex test execution, AI-powered error interpretation, PR descriptions, and notifications. The action supports multi-package projects, a smart package.xml generator, and CI/CD templates through GitHub Actions and workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(extension): renderSfError() — one path for a Salesforce error, plus the sweep that keeps it one (C-FIX-4) by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/325">https://github.com/scoobydrew83/sfdt/pull/325</a></li>
<li>feat(extension): guarded bulk delete from the SOQL runner (C-P4-2) by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/326">https://github.com/scoobydrew83/sfdt/pull/326</a></li>
<li>feat(extension): NL→SOQL generation in the SOQL runner (C-P4-5) by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/328">https://github.com/scoobydrew83/sfdt/pull/328</a></li>
<li>fix(extension): the C-FIX-4 sweep does not actually bite — follow-up to #325 (B1/B2) by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/327">https://github.com/scoobydrew83/sfdt/pull/327</a></li>
<li>fix(extension): the C-FIX-4 sweep can be blinded by one backtick, and cannot see <code>.catch((e) =&gt; …)</code> by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/329">https://github.com/scoobydrew83/sfdt/pull/329</a></li>
<li>fix(extension): the guard could not see a settled rejection, and the masker failed open by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/330">https://github.com/scoobydrew83/sfdt/pull/330</a></li>
<li>fix(extension): a green tick after Cancel, and a sweep that catches the next caller (C-FIX-5) by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/332">https://github.com/scoobydrew83/sfdt/pull/332</a></li>
<li>fix(extension): the sweep could not see the name a for-of head binds by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/331">https://github.com/scoobydrew83/sfdt/pull/331</a></li>
<li>fix(extension): tier 1 fired on a split that was not the outermost operation (C-FIX-7) by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/333">https://github.com/scoobydrew83/sfdt/pull/333</a></li>
<li>chore(deps): bump the production-dependencies group with 4 updates by @dependabot[bot] in <a href="https://github.com/scoobydrew83/sfdt/pull/334">https://github.com/scoobydrew83/sfdt/pull/334</a></li>
<li>chore(deps): bump the development-dependencies group with 8 updates by @dependabot[bot] in <a href="https://github.com/scoobydrew83/sfdt/pull/335">https://github.com/scoobydrew83/sfdt/pull/335</a></li>
<li>chore: release CLI v0.23.1 + extension v0.15.0 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/341">https://github.com/scoobydrew83/sfdt/pull/341</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scoobydrew83/sfdt/compare/v0.23.0...v0.23.1">https://github.com/scoobydrew83/sfdt/compare/v0.23.0...v0.23.1</a></p>
]]></content:encoded></item><item><title>LetItLoop Proof-Carrying PR Verification Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/letitloop-proof-carrying-pr-verification-gate/</link><pubDate>Wed, 26 Aug 2026 06:27:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/letitloop-proof-carrying-pr-verification-gate/</guid><description>Version updated for https://github.com/sdageltc/letitloop-action to version v1.0.3.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The LetItLoop Action is a Zero-Config GitHub Action designed to verify the integrity of AI-driven pull requests by checking structural invariants and ensuring that only allowed files are modified. It automates proof-carrying verification tasks such as scope boundary leasing, subprocess test gating, and generating signed evidence receipts directly to pull requests. The action supports universal verification for multiple languages and provides advanced features for Python codebases, including AST signature integrity checks and decorator retention.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sdageltc/letitloop-action">https://github.com/sdageltc/letitloop-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/letitloop-proof-carrying-pr-verification-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The LetItLoop Action is a Zero-Config GitHub Action designed to verify the integrity of AI-driven pull requests by checking structural invariants and ensuring that only allowed files are modified. It automates proof-carrying verification tasks such as scope boundary leasing, subprocess test gating, and generating signed evidence receipts directly to pull requests. The action supports universal verification for multiple languages and provides advanced features for Python codebases, including AST signature integrity checks and decorator retention.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-whats-new-in-letitloop-action-v103">🚀 What&rsquo;s New in LetItLoop Action v1.0.3</h2>
<h3 id="1-dual-mode-zero-dependency-ast-invariant-validator">1. Dual-Mode Zero-Dependency AST Invariant Validator</h3>
<ul>
<li><strong>Signature &amp; Type Annotation Verification</strong>: Recursively parses Python AST trees, validating that functions, classes, arguments, and type annotations do not silently drift.</li>
<li><strong>Syntax Invariant Scan</strong>: Verifies syntax validity across all workspace Python files without requiring runtime execution.</li>
</ul>
<h3 id="2-recompiled-standalone-action-bundle">2. Recompiled Standalone Action Bundle</h3>
<ul>
<li>Production <code>dist/index.js</code> bundle compiled with zero-runtime dependencies.</li>
<li>Verified 100% green on GitHub Actions CI.</li>
</ul>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sdageltc/letitloop-action/compare/v1.0.2...v1.0.3">https://github.com/sdageltc/letitloop-action/compare/v1.0.2...v1.0.3</a></p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/smyklot/</link><pubDate>Wed, 26 Aug 2026 06:26:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.49.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the .github/CODEOWNERS file. It supports multiple command formats, such as slash commands, mentions, and bare commands, with options to approve/merge using different merge methods. The app also includes features like reaction-based commands for approval, merge, cleanup, and helps manage bot reactions and comments efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.49.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the <code>.github/CODEOWNERS</code> file. It supports multiple command formats, such as slash commands, mentions, and bare commands, with options to approve/merge using different merge methods. The app also includes features like reaction-based commands for approval, merge, cleanup, and helps manage bot reactions and comments efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1490-2026-08-25"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.48.4...v1.49.0">1.49.0</a> (2026-08-25)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>merge:</strong> allow merging draft pull requests (<a href="https://github.com/smykla-skalski/smyklot/issues/321">#321</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/f4df6199d0dc90b5194c6a6dc9e4cfa456b008d7">f4df619</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>queue:</strong> stop disabled repository work (<a href="https://github.com/smykla-skalski/smyklot/issues/326">#326</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/b9d29b5d57bbdfa5a289111bfbc8e8e0ff8d7ee5">b9d29b5</a>)</li>
</ul>
<h2 id="smyklot-v1490">Smyklot v1.49.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.49.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>ad2a3803bb196d385db938e0fdb95993655470a8 chore(release): bump version to 1.49.0</li>
<li>b9d29b5d57bbdfa5a289111bfbc8e8e0ff8d7ee5 fix(queue): stop disabled repository work (#326)</li>
<li>f4df6199d0dc90b5194c6a6dc9e4cfa456b008d7 feat(merge): allow merging draft pull requests (#321)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/update-a-config-file-with-values-from-environment/</link><pubDate>Wed, 26 Aug 2026 06:25:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The config-file-from-env GitHub Action replaces environment variables in a configuration file with their corresponding values. This helps in managing sensitive information securely by avoiding hardcoding them directly into configuration files, ensuring compliance with security best practices and improving maintainability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>config-file-from-env</code> GitHub Action replaces environment variables in a configuration file with their corresponding values. This helps in managing sensitive information securely by avoiding hardcoding them directly into configuration files, ensuring compliance with security best practices and improving maintainability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Wed, 26 Aug 2026 06:25:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service. It requires that developers run npm ci and then npm run bundle before committing changes, which bundles their application for production. The action takes care of building the Docker image and deploying it to a Docker Swarm cluster automatically. This eliminates manual steps and streamlines the deployment process, ensuring consistency across different development environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service. It requires that developers run <code>npm ci</code> and then <code>npm run bundle</code> before committing changes, which bundles their application for production. The action takes care of building the Docker image and deploying it to a Docker Swarm cluster automatically. This eliminates manual steps and streamlines the deployment process, ensuring consistency across different development environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>SurrealDB in Github Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/surrealdb-in-github-action/</link><pubDate>Wed, 26 Aug 2026 06:25:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/surrealdb-in-github-action/</guid><description>Version updated for https://github.com/surrealdb/setup-surreal to version v3.0.0.
This action is used across all versions by 17 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-surreal action automates the integration of SurrealDB into GitHub Actions CI pipelines. It provides a simple way to start and configure a SurrealDB instance, including setting up authentication, strict mode, logging levels, and customizing the datastore. The action outputs the endpoint for accessing the database and its version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/surrealdb/setup-surreal">https://github.com/surrealdb/setup-surreal</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>17</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/surrealdb-in-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The setup-surreal action automates the integration of SurrealDB into GitHub Actions CI pipelines. It provides a simple way to start and configure a SurrealDB instance, including setting up authentication, strict mode, logging levels, and customizing the datastore. The action outputs the endpoint for accessing the database and its version.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds support for SurrealDB v3, where <code>surreal start</code> no longer accepts a bare <code>--strict</code> and left the instance dead when <code>surrealdb_strict</code> was enabled. The action now detects the installed version and builds its arguments to match, so SurrealDB v1, v2 and v3 are all supported.</p>
<p>The readiness check polled a hardcoded <code>localhost:8000</code> rather than the port the instance was started on, so any other port either timed out or reported on an unrelated server. It now polls the configured endpoint, gives up as soon as the server process exits, and prints the server log on failure.</p>
<p>Also adds <code>nightly</code>, <code>beta</code> and <code>alpha</code> versions, the <code>surrealdb_datastore</code> and <code>surrealdb_import_file</code> inputs, and <code>endpoint</code> and <code>version</code> outputs.</p>
<p>The action&rsquo;s major version tracks the major version of SurrealDB whose support it introduces, which is why this is v3. It carries the same changes as v2.1.0, which remains available for workflows that reference <code>v2</code>. No input was removed or changed meaning, but three behaviours differ from v2.0.1 and are worth knowing about when upgrading:</p>
<ul>
<li>The readiness check now uses <code>surrealdb_port</code>, so a workflow that was silently passing against an unrelated server on port 8000 will now report the real result.</li>
<li>A relative datastore path passed through <code>surrealdb_additional_args</code> now resolves against the workspace rather than <code>/usr/local/bin</code>.</li>
<li><code>surrealdb_additional_args</code> is word split rather than interpolated into the script, so variable references, globs and command substitution inside that value are no longer evaluated.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Reference the v3 tag in the usage example by @tobiemh in <a href="https://github.com/surrealdb/setup-surreal/pull/12">https://github.com/surrealdb/setup-surreal/pull/12</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/surrealdb/setup-surreal/compare/v2.1.0...v3.0.0">https://github.com/surrealdb/setup-surreal/compare/v2.1.0...v3.0.0</a></p>
]]></content:encoded></item><item><title>auto-generate-release-note</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/auto-generate-release-note/</link><pubDate>Wed, 26 Aug 2026 06:24:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/auto-generate-release-note/</guid><description>Version updated for https://github.com/TakuKobayashi/auto-generate-release-note to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action auto-generate-release-note uses an Ollama language model to generate a comprehensive release note summarizing changes in a Git repository. It compares the current tag with the previous semantic-version tag, generates Markdown content from commits, changed files, and text diffs, supports multiple languages including bilingual output, and falls back to deterministic notes if inference fails. The action automates the process of creating or updating GitHub Releases without sending code diffs to hosted LLM APIs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TakuKobayashi/auto-generate-release-note">https://github.com/TakuKobayashi/auto-generate-release-note</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auto-generate-release-note">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>auto-generate-release-note</code> uses an Ollama language model to generate a comprehensive release note summarizing changes in a Git repository. It compares the current tag with the previous semantic-version tag, generates Markdown content from commits, changed files, and text diffs, supports multiple languages including bilingual output, and falls back to deterministic notes if inference fails. The action automates the process of creating or updating GitHub Releases without sending code diffs to hosted LLM APIs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="release-notes-for-v102">Release Notes for v1.0.2</h2>
<h3 id="changes">Changes</h3>
<ul>
<li><strong>Action Renamed</strong>: The action has been renamed from <code>Ollama AI Release Notes</code> to <code>auto-generate-release-note</code>. This change affects the action&rsquo;s name in the GitHub marketplace and any references to it in workflows.</li>
</ul>
<h3 id="migration-notes">Migration Notes</h3>
<ul>
<li>If you are using this action in your GitHub workflows, you will need to update the action name from <code>Ollama AI Release Notes</code> to <code>auto-generate-release-note</code>.</li>
</ul>
<h3 id="fixes">Fixes</h3>
<ul>
<li>No specific fixes were included in this release.</li>
</ul>
<h3 id="important-internal-changes">Important Internal Changes</h3>
<ul>
<li>The package name and version in <code>package.json</code> have been updated to reflect the new action name and version.</li>
</ul>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/delivery-autopilot-runner/</link><pubDate>Wed, 26 Aug 2026 06:23:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.41.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Delivery Autopilot Runner GitHub Action automates the process of creating pull requests for code changes based on tickets from a tracker using an AI pipeline. It ensures that your work is planned, built, and checked within your own GitHub Actions environment, without sending any sensitive data to Tekunda’s servers. The action requires an active Delivery Autopilot subscription to function properly, and it provides options for manual setup through the GitHub App or direct workflow creation with specific configurations for authentication and quality checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.41</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Delivery Autopilot Runner GitHub Action automates the process of creating pull requests for code changes based on tickets from a tracker using an AI pipeline. It ensures that your work is planned, built, and checked within your own GitHub Actions environment, without sending any sensitive data to Tekunda&rsquo;s servers. The action requires an active Delivery Autopilot subscription to function properly, and it provides options for manual setup through the GitHub App or direct workflow creation with specific configurations for authentication and quality checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runner-dist synced from AutoPilot 6503a20143b2. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>SlopLock</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/sloplock/</link><pubDate>Wed, 26 Aug 2026 06:22:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/sloplock/</guid><description>Version updated for https://github.com/theinfosecguy/sloplock to version v2.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SlopLock GitHub Action automates the process of identifying and blocking AI-hallucinated, nonexistent, and too-new dependencies before they are installed or merged into a project. It helps prevent security vulnerabilities by ensuring that only verified package names are used. The action scans dependencies across eight public registries and provides detailed reports to help developers and maintainers validate package names.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/theinfosecguy/sloplock">https://github.com/theinfosecguy/sloplock</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sloplock">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The SlopLock GitHub Action automates the process of identifying and blocking AI-hallucinated, nonexistent, and too-new dependencies before they are installed or merged into a project. It helps prevent security vulnerabilities by ensuring that only verified package names are used. The action scans dependencies across eight public registries and provides detailed reports to help developers and maintainers validate package names.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="sloplock-v210">SlopLock v2.1.0</h1>
<p>This minor release adds a pre-execution dependency guard for Claude Code. It
checks package names in install commands before a package manager downloads or
executes anything, using the same registry and cooldown policies as the CLI and
GitHub Action.</p>
<h2 id="install-hook">Install Hook</h2>
<ul>
<li>Adds <code>sloplock hook</code>, a JSON hook entry point for <code>PreToolUse</code> Bash events.</li>
<li>Distributes the hook as a self-contained plugin backed by the committed
<code>dist/hook/index.cjs</code> bundle.</li>
<li>Denies findings at or above <code>failOn</code>, asks for confirmation below the
threshold, and leaves the normal permission flow unchanged when no finding is
present.</li>
<li>Fails open with a visible message when a public registry cannot be reached.</li>
</ul>
<h2 id="install-command-coverage">Install Command Coverage</h2>
<ul>
<li>Recognizes npm, pnpm, Yarn, Bun, npx, pip, uv, pipx, Poetry, PDM, Cargo, Go,
RubyGems, Bundler, Composer, and dotnet package-install commands.</li>
<li>Finds installs in command chains, conditionals, loops, subshells, and command
substitutions, including expanding heredocs.</li>
<li>Normalizes package and module names before registry checks and ignores local,
workspace, path, URL, git, and other non-registry sources.</li>
</ul>
<h2 id="registry-safety">Registry Safety</h2>
<ul>
<li>Skips commands that explicitly use private or alternate registries instead of
treating public-registry absence as a package finding.</li>
<li>Recognizes public registry URLs supplied through command flags or environment
variables, so explicit public configuration does not disable checks.</li>
<li>Applies <code>GOPRIVATE</code> and <code>GONOPROXY</code> per Go module path and respects <code>unset</code>
when environment overrides are removed inside a command.</li>
<li>Keeps registry failures distinct from nonexistent-package findings.</li>
</ul>
<h2 id="distribution">Distribution</h2>
<ul>
<li>Adds the repository plugin manifest and marketplace catalog for installation
through <code>theinfosecguy/sloplock</code>.</li>
<li>Publishes the bundled hook in the npm package and repository release.</li>
<li>Updates the CLI, Action, and generated artifacts to version 2.1.0.</li>
</ul>
<p>See <code>docs/hook.md</code> for installation, supported commands, configuration, and
known parser limitations.</p>
]]></content:encoded></item><item><title>Sentinel Scan (MCP/LLM security)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/sentinel-scan-mcp/llm-security/</link><pubDate>Wed, 26 Aug 2026 06:20:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/sentinel-scan-mcp/llm-security/</guid><description>Version updated for https://github.com/Ventrova/sentinel-scan-cli to version v1.4.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sentinel Scan CLI is an open-source, 10-heuristic, 15-attack suite tool that automatically scans MCP tool manifests and MCP server configurations for various security vulnerabilities, such as prompt injection, shadowing, and credential leakage. It provides a one-line installation and usage method, and supports both CLI and MCP server modes. The tool is designed to help organizations identify and mitigate security risks associated with their APIs and LLMs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Ventrova/sentinel-scan-cli">https://github.com/Ventrova/sentinel-scan-cli</a></strong> to version <strong>v1.4.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sentinel-scan-mcp-llm-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Sentinel Scan CLI is an open-source, 10-heuristic, 15-attack suite tool that automatically scans MCP tool manifests and MCP server configurations for various security vulnerabilities, such as prompt injection, shadowing, and credential leakage. It provides a one-line installation and usage method, and supports both CLI and MCP server modes. The tool is designed to help organizations identify and mitigate security risks associated with their APIs and LLMs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>GitHub Action for CI: scan MCP manifests on push/PR and fail the build on high-severity findings, in one step.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Ventrova/sentinel-scan-cli@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">manifest</span>: <span style="color:#ae81ff">mcp.json</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on-severity</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><p>Full inputs/outputs reference and SARIF/markdown/json output modes in the README&rsquo;s <a href="https://github.com/Ventrova/sentinel-scan-cli#github-action">GitHub Action</a> section.</p>
<p>Since v1.4.2: adds the <code>sentinel-scan evidence</code> subcommand (Annex IV evidence pack, #2), CLI output CTAs, and various instrumentation/version-string fixes. Same 15-attack corpus + MCP manifest heuristics, no network calls, no secrets required.</p>
<p>Install: <code>npx sentinel-scan-cli</code> / <code>pip install sentinel-scan-cli</code> / <code>uses: Ventrova/sentinel-scan-cli@v1</code>.</p>
]]></content:encoded></item><item><title>spaces checkout run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/spaces-checkout-run/</link><pubDate>Wed, 26 Aug 2026 06:19:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/spaces-checkout-run/</guid><description>Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.21.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of checking out and running a Space on a remote server using the Spaces CLI. It simplifies the workflow for developers by abstracting away the complexities of managing SSH connections and executing commands in the Space environment. The action is useful for setting up continuous integration/continuous deployment pipelines where spaces need to be accessed and executed from within the GitHub Actions environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/spaces-checkout-run">https://github.com/work-spaces/spaces-checkout-run</a></strong> to version <strong>v0.21.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spaces-checkout-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of checking out and running a Space on a remote server using the Spaces CLI. It simplifies the workflow for developers by abstracting away the complexities of managing SSH connections and executing commands in the Space environment. The action is useful for setting up continuous integration/continuous deployment pipelines where spaces need to be accessed and executed from within the GitHub Actions environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.21.1 by @tyler-gilbert in <a href="https://github.com/work-spaces/spaces-checkout-run/pull/40">https://github.com/work-spaces/spaces-checkout-run/pull/40</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/spaces-checkout-run/compare/v0.21.0...v0.21.1">https://github.com/work-spaces/spaces-checkout-run/compare/v0.21.0...v0.21.1</a></p>
]]></content:encoded></item><item><title>AgentLeak privacy gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/agentleak-privacy-gate/</link><pubDate>Wed, 26 Aug 2026 06:19:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/agentleak-privacy-gate/</guid><description>Version updated for https://github.com/yagobski/agentleak to version v0.11.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentLeak is a privacy-leakage testing tool designed to audit AI agents across various execution channels. It ensures that sensitive data is not leaked through internal communication and logs by scoring the agent’s performance with the AgentRisk metric, which measures the severity of potential privacy breaches. The Action automates this process within continuous integration pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yagobski/agentleak">https://github.com/yagobski/agentleak</a></strong> to version <strong>v0.11.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentleak-privacy-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentLeak is a privacy-leakage testing tool designed to audit AI agents across various execution channels. It ensures that sensitive data is not leaked through internal communication and logs by scoring the agent&rsquo;s performance with the AgentRisk metric, which measures the severity of potential privacy breaches. The Action automates this process within continuous integration pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.11.8: embed fixture licenses in wheel by @yagobski in <a href="https://github.com/yagobski/agentleak/pull/5">https://github.com/yagobski/agentleak/pull/5</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yagobski/agentleak/compare/v0.11.8...v0.11.9">https://github.com/yagobski/agentleak/compare/v0.11.8...v0.11.9</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/b.ia-accessibility-checker/</link><pubDate>Wed, 26 Aug 2026 06:17:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines by analyzing code against WCAG guidelines and ensuring compliance with defined audiences. It uses AI to assess complex guidelines, providing developers with feedback on areas needing improvement, thus facilitating companies’ adoption of accessible products efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines by analyzing code against WCAG guidelines and ensuring compliance with defined audiences. It uses AI to assess complex guidelines, providing developers with feedback on areas needing improvement, thus facilitating companies&rsquo; adoption of accessible products efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>Zenifra Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/zenifra-deploy/</link><pubDate>Wed, 26 Aug 2026 06:16:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/zenifra-deploy/</guid><description>Version updated for https://github.com/zenifra/action-zenifra-deploy to version v0.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action deploys images to Zenifra and manages temporary preview environments for pull requests. It supports deploying, updating, and deleting images, as well as managing preview environments with stable keys and automatic expiration. The action is particularly useful for version control and testing in CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zenifra/action-zenifra-deploy">https://github.com/zenifra/action-zenifra-deploy</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zenifra-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action deploys images to Zenifra and manages temporary preview environments for pull requests. It supports deploying, updating, and deleting images, as well as managing preview environments with stable keys and automatic expiration. The action is particularly useful for version control and testing in CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: add preview deployment lifecycle by @ramonpaolo in <a href="https://github.com/zenifra/action-zenifra-deploy/pull/5">https://github.com/zenifra/action-zenifra-deploy/pull/5</a></li>
<li>fix: shorten action metadata description by @ramonpaolo in <a href="https://github.com/zenifra/action-zenifra-deploy/pull/6">https://github.com/zenifra/action-zenifra-deploy/pull/6</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/zenifra/action-zenifra-deploy/compare/v0.0.3...v0.0.4">https://github.com/zenifra/action-zenifra-deploy/compare/v0.0.3...v0.0.4</a></p>
]]></content:encoded></item><item><title>Zyvor QA</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/zyvor-qa/</link><pubDate>Wed, 26 Aug 2026 06:15:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/26/zyvor-qa/</guid><description>Version updated for https://github.com/zyvorai/argus to version v1.1.1-ent-trial.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates several tasks related to software quality assurance and testing:
It reads requirements, scores them for quality. It generates Playwright tests based on the requirements. It runs these tests after every deploy. It provides detailed feedback on what broke and why. It includes authorized security testing features. It offers a live operations console for monitoring. The action solves problems related to manual QA, repetitive testing, and ensures that quality assurance processes are automated and efficient.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zyvorai/argus">https://github.com/zyvorai/argus</a></strong> to version <strong>v1.1.1-ent-trial</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zyvor-qa">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates several tasks related to software quality assurance and testing:</p>
<ol>
<li>It reads requirements, scores them for quality.</li>
<li>It generates Playwright tests based on the requirements.</li>
<li>It runs these tests after every deploy.</li>
<li>It provides detailed feedback on what broke and why.</li>
<li>It includes authorized security testing features.</li>
<li>It offers a live operations console for monitoring.</li>
</ol>
<p>The action solves problems related to manual QA, repetitive testing, and ensures that quality assurance processes are automated and efficient.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Self-contained compiled (Nuitka) executable — no Python source ships. Signed 30-day trial.token included.</p>
<pre tabindex="0"><code>tar xzf argus-enterprise-1.1.1-ent-trial-linux-amd64.tar.gz
cd argus-enterprise-1.1.1-ent-trial-linux-amd64
./install.sh
curl http://127.0.0.1:8090/health
</code></pre>]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/kaniko-build-action/</link><pubDate>Tue, 25 Aug 2026 22:55:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or “Hello [name]” to the log and can be customized with a specific name to greet. It provides a simple way to automate greetings in GitHub workflows, enhancing collaboration by providing personalized outputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or &ldquo;Hello [name]&rdquo; to the log and can be customized with a specific name to greet. It provides a simple way to automate greetings in GitHub workflows, enhancing collaboration by providing personalized outputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>DSH Plugin Migrate Bot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/dsh-plugin-migrate-bot/</link><pubDate>Tue, 25 Aug 2026 22:54:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/dsh-plugin-migrate-bot/</guid><description>Version updated for https://github.com/royenheart/dsh-migrate-bot to version v0.1.3.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the migration of a third-party plugin by monitoring DeepSeek Harness releases. It runs on GitHub-hosted runners and uses a repository secret to authenticate with the API. The action resolves the target dsh-v* version, skips if it matches the last success version unless forced or watch.enabled is false. It performs mechanical tests, sparse-checkouts the harness tag, and reviews patches for compatibility. If the plugin tree is dirty, it creates an Issue and PR with links to patch reports and discussions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/royenheart/dsh-migrate-bot">https://github.com/royenheart/dsh-migrate-bot</a></strong> to version <strong>v0.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dsh-plugin-migrate-bot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the migration of a third-party plugin by monitoring DeepSeek Harness releases. It runs on GitHub-hosted runners and uses a repository secret to authenticate with the API. The action resolves the target <code>dsh-v*</code> version, skips if it matches the last success version unless forced or <code>watch.enabled</code> is false. It performs mechanical tests, sparse-checkouts the harness tag, and reviews patches for compatibility. If the plugin tree is dirty, it creates an Issue and PR with links to patch reports and discussions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<p>Fix the publish crash that turned two consumer Actions red after a successful A+B review. Also ship the quota cap, harness checkout, per-patch reports, and Issue comments that were already in the pipeline but not released.</p>
<p>Consumers pinning <code>royenheart/dsh-migrate-bot@v0</code> pick this up automatically. Re-run failed plugin jobs with <code>workflow_dispatch</code> and <code>force: true</code>.</p>
<h2 id="fixes">Fixes</h2>
<ul>
<li><strong>Do not <code>git add</code> ignored <code>.dsh-migrate</code>.</strong> The Action writes <code>.dsh-migrate/</code> into <code>.git/info/exclude</code>, then used <code>git add -A -- . :!.dsh-migrate</code>. Git treats that exclude pathspec as an explicit path and exits 1 (<code>The following paths are ignored by one of your .gitignore files</code>). Staging is now <code>git add -A -- .</code>, then unstage migrate-noise paths. This is why <a href="https://github.com/royenheart/dsh-plugin-mcp-support/actions/runs/32874383283">mcp-support</a> and <a href="https://github.com/royenheart/dsh-plugin-structured-output/actions/runs/32874375835">structured-output</a> failed after <code>mechanical after A+B: pass</code>.</li>
</ul>
<h2 id="added">Added</h2>
<ul>
<li><strong>This-run USD cap.</strong> <code>quota.limit</code> in <code>.github/dsh-migrate.yml</code>, Action input <code>quota_limit</code>, or <code>--quota-limit</code>. Official DeepSeek rates × this Action’s own cache-miss / cache-hit / output tokens (peak/off-peak from each request timestamp). Not an account-wide spend cap. Official <code>is_available</code> still aborts when the wallet is empty.</li>
<li><strong>Harness sparse-checkout</strong> of the target <code>dsh-v*</code> into <code>.dsh-migrate/harness</code> so A/B/C can read official source, keep or drop a dsh-side patch, and test it. Not committed.</li>
<li><strong>Per-patch reports</strong> at <code>.dsh-migrate/patch-reports/&lt;slug&gt;/report.md</code>. Search official issues / PRs / discussions first; if none, write a discussion draft (<code># [Feature request] …</code> plus the dsh-plugin-development sections).</li>
<li><strong>Issue ↔ PR linking and comments.</strong> PR body includes <code>Closes #&lt;issue&gt;</code>. After open, the Action comments on the Issue: companion PR URL, a patch-report index table, then each report body.</li>
<li><strong>Status lines</strong> every ~10s (turns / steps / elapsed / cache hit-miss / in-out). Model text is not streamed to GHA logs.</li>
</ul>
<h2 id="notes">Notes</h2>
<ul>
<li><code>.dsh-migrate/</code> and <code>.secrets.local.json</code> never count as a dirty plugin tree and are never committed. Upload <code>.dsh-migrate/</code> as an artifact.</li>
<li>Insufficient official balance or a this-run spend over the cap aborts without opening an Issue or PR.</li>
<li>Failed persist of <code>dsh-migrate/state</code> still fails the job so the next schedule retries.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/royenheart/dsh-migrate-bot/compare/v0.1.2...v0.1.3">https://github.com/royenheart/dsh-migrate-bot/compare/v0.1.2...v0.1.3</a></p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/agentauditkit-mcp-security-scan/</link><pubDate>Tue, 25 Aug 2026 22:53:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.89.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit automates the security audit of AI agent pipelines by identifying misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. It provides a deterministic offline scan that does not rely on external network calls or models. The action is designed to help organizations ensure their AI agent systems are secure and compliant with industry standards like OWASP Agentic and MCP (MCP Security Index).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.89</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit automates the security audit of AI agent pipelines by identifying misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. It provides a deterministic offline scan that does not rely on external network calls or models. The action is designed to help organizations ensure their AI agent systems are secure and compliant with industry standards like OWASP Agentic and MCP (MCP Security Index).</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.89
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.89
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.89</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Rule AAK-MCP-TOOL-ARG-OSCMD-001 for CVE-2026-78430, and publish the CVE-response lag by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/635">https://github.com/sattyamjjain/agent-audit-kit/pull/635</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.88...v0.3.89">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.88...v0.3.89</a></p>
]]></content:encoded></item><item><title>sbomify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sbomify/</link><pubDate>Tue, 25 Aug 2026 22:52:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sbomify/</guid><description>Version updated for https://github.com/sbomify/sbomify-action to version v26.8.0.
This action is used across all versions by 26 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The sbomify-action is a GitHub Action that automates the process of generating Software Bill of Materials (SBOMs) in your CI/CD pipeline. It supports various languages and ecosystems, including Python, Node.js, Rust, Go, Ruby, Dart, C++, and Docker images. The action can generate SBOMs in CycloneDX or SPDX format and includes features like enriching SBOMs with metadata from package registries and handling Chainguard base images for reuse.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sbomify/sbomify-action">https://github.com/sbomify/sbomify-action</a></strong> to version <strong>v26.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>26</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sbomify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The sbomify-action is a GitHub Action that automates the process of generating Software Bill of Materials (SBOMs) in your CI/CD pipeline. It supports various languages and ecosystems, including Python, Node.js, Rust, Go, Ruby, Dart, C++, and Docker images. The action can generate SBOMs in CycloneDX or SPDX format and includes features like enriching SBOMs with metadata from package registries and handling Chainguard base images for reuse.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): cover bun, uv, and docker in Dependabot config by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/284">https://github.com/sbomify/sbomify-action/pull/284</a></li>
<li>chore(deps): bump python from 3.13-slim-trixie to 3.14-slim-trixie in the docker group by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/286">https://github.com/sbomify/sbomify-action/pull/286</a></li>
<li>chore(deps-dev): bump ruff from 0.12.12 to 0.15.22 in the uv group by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/288">https://github.com/sbomify/sbomify-action/pull/288</a></li>
<li>chore(deps): bump the github-actions group with 3 updates by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/287">https://github.com/sbomify/sbomify-action/pull/287</a></li>
<li>chore(deps): exclude test-data fixtures from Dependabot scans by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/289">https://github.com/sbomify/sbomify-action/pull/289</a></li>
<li>chore(deps): bump the uv group with 3 updates by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/302">https://github.com/sbomify/sbomify-action/pull/302</a></li>
<li>chore(deps): bump the github-actions group with 5 updates by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/301">https://github.com/sbomify/sbomify-action/pull/301</a></li>
<li>Isolate wizard discovery tests from the developer&rsquo;s git config by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/305">https://github.com/sbomify/sbomify-action/pull/305</a></li>
<li>Fix arm64 image build (Rust toolchain for pipdeptree) and build images on PRs by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/304">https://github.com/sbomify/sbomify-action/pull/304</a></li>
<li>docs: correct SPDX version coverage and document SPEC_VERSION by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/306">https://github.com/sbomify/sbomify-action/pull/306</a></li>
<li>Reject spec versions nothing can generate at config time by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/307">https://github.com/sbomify/sbomify-action/pull/307</a></li>
<li>Recognize Cargo.toml so lockless Rust crates are discovered by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/310">https://github.com/sbomify/sbomify-action/pull/310</a></li>
<li>chore(deps): bump docker/login-action from 4.4.0 to 4.6.0 in the github-actions group by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/308">https://github.com/sbomify/sbomify-action/pull/308</a></li>
<li>chore(deps): bump the uv group with 5 updates by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/309">https://github.com/sbomify/sbomify-action/pull/309</a></li>
<li>fix(wizard): handle plan limits, workspace scoping, and clean errors by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/303">https://github.com/sbomify/sbomify-action/pull/303</a></li>
<li>Authenticate the license-database release lookup by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/314">https://github.com/sbomify/sbomify-action/pull/314</a></li>
<li>Add Reload to the wizard&rsquo;s Components screen by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/315">https://github.com/sbomify/sbomify-action/pull/315</a></li>
<li>Stop shipping bomctl by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/318">https://github.com/sbomify/sbomify-action/pull/318</a></li>
<li>Stop shipping dev dependencies in the published image by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/316">https://github.com/sbomify/sbomify-action/pull/316</a></li>
<li>chore(deps): bump the github-actions group with 2 updates by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/338">https://github.com/sbomify/sbomify-action/pull/338</a></li>
<li>chore(deps): bump the uv group with 2 updates by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/337">https://github.com/sbomify/sbomify-action/pull/337</a></li>
<li>Fetch every non-Python tool instead of baking it in: 515MB image to 106MB, and stop silent SBOM quality downgrades by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/320">https://github.com/sbomify/sbomify-action/pull/320</a></li>
<li>Cache enrichment lookups across runs for every source, and fix ClearlyDefined extraction by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/339">https://github.com/sbomify/sbomify-action/pull/339</a></li>
<li>Treat SOURCE_DIR as an input source, and document it as a last resort by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/340">https://github.com/sbomify/sbomify-action/pull/340</a></li>
<li>feat: submodule SBOM support — discovery annotation + attach-or-backfill by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/341">https://github.com/sbomify/sbomify-action/pull/341</a></li>
<li>Serve ClearlyDefined through clearly-cached by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/343">https://github.com/sbomify/sbomify-action/pull/343</a></li>
<li>Stop using ClearlyDefined&rsquo;s copyright parties as the supplier by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/344">https://github.com/sbomify/sbomify-action/pull/344</a></li>
<li>Say 3.11 everywhere the project already requires it by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/345">https://github.com/sbomify/sbomify-action/pull/345</a></li>
<li>Let makeAggregateBom see the reactor it aggregates by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/347">https://github.com/sbomify/sbomify-action/pull/347</a></li>
<li>Don&rsquo;t walk into symlinked directories during discovery by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/346">https://github.com/sbomify/sbomify-action/pull/346</a></li>
<li>Keep looking when a generator describes nothing by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/348">https://github.com/sbomify/sbomify-action/pull/348</a></li>
<li>Decline a PEP 621 manifest instead of failing on it by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/349">https://github.com/sbomify/sbomify-action/pull/349</a></li>
<li>Fix two failures found in telemetry, and stop three sources of noise by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/350">https://github.com/sbomify/sbomify-action/pull/350</a></li>
<li>Keep the wizard&rsquo;s action row on screen at every terminal size by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/342">https://github.com/sbomify/sbomify-action/pull/342</a></li>
<li>Ask a source only when it can fill something missing by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/355">https://github.com/sbomify/sbomify-action/pull/355</a></li>
<li>Tick the shallowest lockfiles, not every one of them by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/354">https://github.com/sbomify/sbomify-action/pull/354</a></li>
<li>Recognise .NET project files, not just the lock file nobody writes by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/353">https://github.com/sbomify/sbomify-action/pull/353</a></li>
<li>Stop describing every file in a container as a component by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/352">https://github.com/sbomify/sbomify-action/pull/352</a></li>
<li>Say what Package.swift is missing instead of writing an empty SBOM by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/351">https://github.com/sbomify/sbomify-action/pull/351</a></li>
<li>Drop the Rust stage and C build deps the image no longer needs by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/356">https://github.com/sbomify/sbomify-action/pull/356</a></li>
<li>Recognise Haskell, Erlang and Clojure by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/357">https://github.com/sbomify/sbomify-action/pull/357</a></li>
<li>Stop unharvested coordinates disabling ClearlyDefined by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/358">https://github.com/sbomify/sbomify-action/pull/358</a></li>
<li>Re-source the lifecycle data from vendors, and notice when it goes stale by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/359">https://github.com/sbomify/sbomify-action/pull/359</a></li>
<li>Wire up the PHP bundle, so a composer.json is not silently empty by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/360">https://github.com/sbomify/sbomify-action/pull/360</a></li>
<li>Exclude tests/test-data from Dependabot for github-actions too by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/362">https://github.com/sbomify/sbomify-action/pull/362</a></li>
<li>chore(deps): bump the github-actions group with 2 updates by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/366">https://github.com/sbomify/sbomify-action/pull/366</a></li>
<li>Make bundle materialisation safe between processes by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/361">https://github.com/sbomify/sbomify-action/pull/361</a></li>
<li>Fall back to the pinned build tool when a project&rsquo;s wrapper cannot run by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/363">https://github.com/sbomify/sbomify-action/pull/363</a></li>
<li>Tell sbomify when a release is a prerelease by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/369">https://github.com/sbomify/sbomify-action/pull/369</a></li>
<li>Take the component version from the release tag, and offer to normalise it by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/368">https://github.com/sbomify/sbomify-action/pull/368</a></li>
<li>Don&rsquo;t default to a lockfile that describes the tooling by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/367">https://github.com/sbomify/sbomify-action/pull/367</a></li>
<li>Tell Composer what version this package is by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/371">https://github.com/sbomify/sbomify-action/pull/371</a></li>
<li>Fix three env-var resolution defects that surface outside Docker by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/370">https://github.com/sbomify/sbomify-action/pull/370</a></li>
<li>Let a caller put Go&rsquo;s caches outside the attested bundle by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/373">https://github.com/sbomify/sbomify-action/pull/373</a></li>
<li>chore: persist agent memory into repo docs and skills by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/293">https://github.com/sbomify/sbomify-action/pull/293</a></li>
<li>chore(deps): bump the uv group, and move the Dockerfile pin with it by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/375">https://github.com/sbomify/sbomify-action/pull/375</a></li>
<li>Stop the root component identifying itself as the mount point by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/374">https://github.com/sbomify/sbomify-action/pull/374</a></li>
<li>Let generators read a workspace they do not own by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/372">https://github.com/sbomify/sbomify-action/pull/372</a></li>
<li>Resolve manifests rather than refuse them, and disclose when versions were inferred by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/377">https://github.com/sbomify/sbomify-action/pull/377</a></li>
<li>chore(deps): cryptography 50.0.0 and Debian security updates at build by @aurangzaib048 in <a href="https://github.com/sbomify/sbomify-action/pull/378">https://github.com/sbomify/sbomify-action/pull/378</a></li>
<li>chore(deps): bump the github-actions group with 2 updates by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/380">https://github.com/sbomify/sbomify-action/pull/380</a></li>
<li>chore(deps): bump the uv group, and move the Dockerfile pin with it by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/381">https://github.com/sbomify/sbomify-action/pull/381</a></li>
<li>chore(deps): bump the uv group across 1 directory with 8 updates by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/379">https://github.com/sbomify/sbomify-action/pull/379</a></li>
<li>Fix three failures found in the Sentry sweep by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/385">https://github.com/sbomify/sbomify-action/pull/385</a></li>
<li>Bump version to 26.8.0 by @vpetersson-bot in <a href="https://github.com/sbomify/sbomify-action/pull/386">https://github.com/sbomify/sbomify-action/pull/386</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@vpetersson-bot made their first contribution in <a href="https://github.com/sbomify/sbomify-action/pull/305">https://github.com/sbomify/sbomify-action/pull/305</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sbomify/sbomify-action/compare/v26.7.0...v26.8.0">https://github.com/sbomify/sbomify-action/compare/v26.7.0...v26.8.0</a></p>
]]></content:encoded></item><item><title>Next Secure Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/next-secure-check/</link><pubDate>Tue, 25 Aug 2026 22:51:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/next-secure-check/</guid><description>Version updated for https://github.com/SetraTheXX/next-secure-check to version v0.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary next-secure-check is a deterministic Next.js-focused static security scanner that automates common security mistakes before they become production issues. It uses rule-based pattern matching, syntax-level AST analysis, and file context to identify potential security vulnerabilities in Next.js projects without executing the code or using AI at runtime. The tool provides detailed findings with severity, confidence, location, context, evidence, and recommendations, making it a lightweight pre-release review signal for developers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SetraTheXX/next-secure-check">https://github.com/SetraTheXX/next-secure-check</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/next-secure-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>next-secure-check is a deterministic Next.js-focused static security scanner that automates common security mistakes before they become production issues. It uses rule-based pattern matching, syntax-level AST analysis, and file context to identify potential security vulnerabilities in Next.js projects without executing the code or using AI at runtime. The tool provides detailed findings with severity, confidence, location, context, evidence, and recommendations, making it a lightweight pre-release review signal for developers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="release-notes">Release notes</h2>
<p>v0.4.1 is a documentation-only CLI patch following the v0.4.0 bounded-analysis feature release.</p>
<h3 id="included">Included</h3>
<ul>
<li>Updated the npm-facing CLI README with published v0.4 usage and reproducible commands.</li>
<li>Clarified GitHub Actions, SARIF, and preset usage.</li>
<li>Updated security support and contribution guidance for the published v0.4 line.</li>
<li>No scanner, rule, reporter, or web runtime behavior changed.</li>
</ul>
<h3 id="validation">Validation</h3>
<ul>
<li>320 package tests</li>
<li>146 web tests</li>
<li>Self-scan: 100/100, excellent, 0 findings</li>
<li>Vulnerable fixture: 26 findings, critical</li>
<li>Secure fixture: 99/100, excellent, 1 LOW</li>
</ul>
<p>Findings remain review signals, not proof of exploitation.</p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/custom-amazon-bedrock-agent-action/</link><pubDate>Tue, 25 Aug 2026 22:50:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback. It is highly customizable and integrates with Amazon Bedrock Knowledge Bases, enhancing the action’s capability by providing enriched, context-aware insights. The action allows for tailored prompts, memory support, and flexible use cases, making it suitable for code quality improvement, security assessments, and performance optimizations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback. It is highly customizable and integrates with Amazon Bedrock Knowledge Bases, enhancing the action’s capability by providing enriched, context-aware insights. The action allows for tailored prompts, memory support, and flexible use cases, making it suitable for code quality improvement, security assessments, and performance optimizations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sherpa.sh/</link><pubDate>Tue, 25 Aug 2026 22:49:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven tool that automates the creation and configuration of cloud infrastructure. It transforms complex deployment processes into straightforward requests, allowing developers to describe their application requirements in plain English. By leveraging its open-source architecture, Sherpa provides users with full visibility into their infrastructure setup, enabling them to manage resources and optimize costs seamlessly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven tool that automates the creation and configuration of cloud infrastructure. It transforms complex deployment processes into straightforward requests, allowing developers to describe their application requirements in plain English. By leveraging its open-source architecture, Sherpa provides users with full visibility into their infrastructure setup, enabling them to manage resources and optimize costs seamlessly.</p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/smyklot/</link><pubDate>Tue, 25 Aug 2026 22:48:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.48.4.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions based on the repository’s CODEOWNERS file. It allows users to approve or merge PRs via slash commands, mentions, or bare commands, with options to choose between squash or rebase merges. The app also provides reaction-based approval and cleanup features for smoother collaboration workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.48.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions based on the repository&rsquo;s CODEOWNERS file. It allows users to approve or merge PRs via slash commands, mentions, or bare commands, with options to choose between squash or rebase merges. The app also provides reaction-based approval and cleanup features for smoother collaboration workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1484-2026-08-25"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.48.3...v1.48.4">1.48.4</a> (2026-08-25)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>service:</strong> own listeners before serving (<a href="https://github.com/smykla-skalski/smyklot/issues/325">#325</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/25b06ccf95d070a7e880b1b466d93ded4e177c7d">25b06cc</a>)</li>
</ul>
<h2 id="smyklot-v1484">Smyklot v1.48.4</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.48.4</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>4c8773d1b60704023cee60535767c01805345823 chore(release): bump version to 1.48.4</li>
<li>25b06ccf95d070a7e880b1b466d93ded4e177c7d fix(service): own listeners before serving (#325)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/update-a-config-file-with-values-from-environment/</link><pubDate>Tue, 25 Aug 2026 22:47:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces placeholders in a configuration file with corresponding environment variables. It automates the process of managing sensitive data by ensuring that environment variables are securely stored and used within configuration files, without exposing sensitive information. This is particularly useful for deployment environments where it’s important to keep sensitive settings out of source control.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces placeholders in a configuration file with corresponding environment variables. It automates the process of managing sensitive data by ensuring that environment variables are securely stored and used within configuration files, without exposing sensitive information. This is particularly useful for deployment environments where it&rsquo;s important to keep sensitive settings out of source control.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add support for .env files (e706be3)</li>
<li>chore: More info (d440258)</li>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/ssg-static-site-generator/</link><pubDate>Tue, 25 Aug 2026 22:47:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.51.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown content with YAML frontmatter into a complete website. It supports built-in themes, template engines, and various deployment options, including GitHub Pages, Cloudflare Pages, and Vercel. SSG is particularly useful for blogs, documentation sites, and other types of websites.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.51</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown content with YAML frontmatter into a complete website. It supports built-in themes, template engines, and various deployment options, including GitHub Pages, Cloudflare Pages, and Vercel. SSG is particularly useful for blogs, documentation sites, and other types of websites.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.51 — the site&rsquo;s own name, settable and visible by @spagu in <a href="https://github.com/spagu/ssg/pull/215">https://github.com/spagu/ssg/pull/215</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.50...v1.8.51">https://github.com/spagu/ssg/compare/v1.8.50...v1.8.51</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/classroom-to-sheets-integration/</link><pubDate>Tue, 25 Aug 2026 22:46:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates Google Sheets with GitHub Classroom to automatically update assignment results. It requires setting up Google Cloud credentials and shares the sheet with a service account email. The workflow step updates the specified sheet in the format of github_id, task results, and student names. Users can configure this action for different tasks by specifying their IDs in the workflow YAML.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates Google Sheets with GitHub Classroom to automatically update assignment results. It requires setting up Google Cloud credentials and shares the sheet with a service account email. The workflow step updates the specified sheet in the format of <code>github_id</code>, task results, and student names. Users can configure this action for different tasks by specifying their IDs in the workflow YAML.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>Sudden Agent</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sudden-agent/</link><pubDate>Tue, 25 Aug 2026 22:45:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sudden-agent/</guid><description>Version updated for https://github.com/sudden-network/agent to version v1.15.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sudden Agent action enables programmable automation across multiple workflows using custom prompts. It supports various tasks such as code review, issue triage, manual dispatch, security audits, and more by running agents on GitHub Workflows. Sessions persist per issue and pull request, allowing iterative work practices. The action provides inputs for agent selection, API keys, authentication methods, and model customization, with session persistence requiring read permission to download artifacts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sudden-network/agent">https://github.com/sudden-network/agent</a></strong> to version <strong>v1.15.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sudden-agent">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Sudden Agent action enables programmable automation across multiple workflows using custom prompts. It supports various tasks such as code review, issue triage, manual dispatch, security audits, and more by running agents on GitHub Workflows. Sessions persist per issue and pull request, allowing iterative work practices. The action provides inputs for agent selection, API keys, authentication methods, and model customization, with session persistence requiring read permission to download artifacts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Use GPT-5.6 Sol in workflows by @etienne-martin in <a href="https://github.com/sudden-network/agent/pull/118">https://github.com/sudden-network/agent/pull/118</a></li>
<li>Default PR reviews to inline threads by @dylangolow in <a href="https://github.com/sudden-network/agent/pull/119">https://github.com/sudden-network/agent/pull/119</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dylangolow made their first contribution in <a href="https://github.com/sudden-network/agent/pull/119">https://github.com/sudden-network/agent/pull/119</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sudden-network/agent/compare/v1.14.1...v1.15.0">https://github.com/sudden-network/agent/compare/v1.14.1...v1.15.0</a></p>
]]></content:encoded></item><item><title>Agent Vigil</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/agent-vigil/</link><pubDate>Tue, 25 Aug 2026 22:44:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/agent-vigil/</guid><description>Version updated for https://github.com/sulmusic2-star/agent-vigil to version v0.19.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of requiring evidence before merging changes to a repository, ensuring that only valid and signed code changes are allowed. It uses a lifecycle receipt system to verify pull requests without opening them or installing Actions, focusing on checking an exact code change against task, policy, tests, and tool actions behind it. The action supports various features such as public PR receipts, trusted base policies, semantic expansions and contractions, and proof-comment generation for deterministic pull-request comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sulmusic2-star/agent-vigil">https://github.com/sulmusic2-star/agent-vigil</a></strong> to version <strong>v0.19.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-vigil">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>This GitHub Action automates the process of requiring evidence before merging changes to a repository, ensuring that only valid and signed code changes are allowed. It uses a lifecycle receipt system to verify pull requests without opening them or installing Actions, focusing on checking an exact code change against task, policy, tests, and tool actions behind it. The action supports various features such as public PR receipts, trusted base policies, semantic expansions and contractions, and proof-comment generation for deterministic pull-request comments.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="no-workflow-public-pr-receipts">No-workflow public PR receipts</h2>
<p>Agent Vigil v0.19.0 adds a read-only receipt for one public GitHub pull request.</p>
<ul>
<li>Accepts only an uncredentialed public github.com pull-request URL.</li>
<li>Pins the Agent Vigil verifier by a full immutable commit SHA.</li>
<li>Optionally signs the normalized receipt with an operator-controlled Ed25519 key.</li>
<li>Reports CURRENT, HOLD, EXPIRED, or REVOKED.</li>
<li>Turns missing, failed, unknown, or incomplete review/check evidence into HOLD.</li>
<li>Never authorizes deployment. Every receipt keeps allowsProtectedAction false.</li>
<li>Retains no source, diff, prompts, transcripts, review prose, check logs, token, or GitHub response body.</li>
</ul>
<p>The README and GitHub Pages site now expose a copyable self-serve command and a voluntary feedback form. This release does not prove outside installation, adoption, payment, or revenue.</p>
<h2 id="verification">Verification</h2>
<p>Download the attached tarball and checksum, verify SHA-256, then run:</p>
<pre><code>npm exec --yes --package=./sulmusic-agent-vigil-0.19.0.tgz -- vigil --version
npm exec --yes --package=./sulmusic-agent-vigil-0.19.0.tgz -- vigil pr-receipt --help
</code></pre>
<p>The attached historical proof result is included as a separate release artifact. npm publication is verified independently and is not implied by this GitHub release.</p>
]]></content:encoded></item><item><title>auto-generate-release-note</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/auto-generate-release-note/</link><pubDate>Tue, 25 Aug 2026 22:43:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/auto-generate-release-note/</guid><description>Version updated for https://github.com/TakuKobayashi/auto-generate-release-note to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses an Ollama model to generate release notes from Git history and diffs, creating or updating a GitHub Release automatically. It supports multiple languages and bilingual output, excluding non-source files, and falls back to deterministic notes if inference fails. The action is triggered on tag pushes, requiring write permissions for content creation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TakuKobayashi/auto-generate-release-note">https://github.com/TakuKobayashi/auto-generate-release-note</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auto-generate-release-note">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses an Ollama model to generate release notes from Git history and diffs, creating or updating a GitHub Release automatically. It supports multiple languages and bilingual output, excluding non-source files, and falls back to deterministic notes if inference fails. The action is triggered on tag pushes, requiring write permissions for content creation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changes">Changes</h2>
<ul>
<li>b578210 Reduce release note generation to one model call (TakuKobayashi)</li>
<li>d236288 Select relevant diff evidence before generation (TakuKobayashi)</li>
<li>84421a5 Simplify release note generation pipeline (TakuKobayashi)</li>
<li>a405512 Optimize release note generation workflow (TakuKobayashi)</li>
<li>07a1985 Revert concurrent change analysis (TakuKobayashi)</li>
<li>2adde5b Support release notes from explicit Git ref comparisons (TakuKobayashi)</li>
<li>6046317 Parallelize change analysis with configurable concurrency (TakuKobayashi)</li>
<li>203fbac version up 2.0.0 (TakuKobayashi)</li>
<li>71a95b5 Streamline action inputs and template validation (TakuKobayashi)</li>
<li>d655c63 Add template-aware release note generation (TakuKobayashi)</li>
<li>f10c89e Add a merge-approved release pull request workflow (TakuKobayashi)</li>
<li>fd4d828 Fix context truncation and incomplete release notes (TakuKobayashi)</li>
<li>ccaab3e Redesign release note generation around hierarchical analysis (TakuKobayashi)</li>
<li>a41beea Fix Ollama timeout handling during prompt evaluation (TakuKobayashi)</li>
</ul>
<h2 id="changed-files">Changed files</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>.../PULL_REQUEST_TEMPLATE/production-release.md    |  11 +
</span></span><span style="display:flex;"><span> .github/PULL_REQUEST_TEMPLATE/release.md           |  12 +
</span></span><span style="display:flex;"><span> .github/workflows/release-pr.yml                   | 121 ++++
</span></span><span style="display:flex;"><span> .github/workflows/release.yml                      |   1 -
</span></span><span style="display:flex;"><span> README-ja.md                                       |  63 +-
</span></span><span style="display:flex;"><span> README.md                                          |  81 ++-
</span></span><span style="display:flex;"><span> action.yml                                         |  43 +-
</span></span><span style="display:flex;"><span> dist/index.js                                      | 696 ++++++++++++++++-----
</span></span><span style="display:flex;"><span> examples/production-release-notes.yml              |  37 ++
</span></span><span style="display:flex;"><span> package.json                                       |   2 +-
</span></span><span style="display:flex;"><span> src/analysis-plan.ts                               |  65 ++
</span></span><span style="display:flex;"><span> src/change-index.ts                                | 266 ++++++++
</span></span><span style="display:flex;"><span> src/cli.ts                                         |  14 +-
</span></span><span style="display:flex;"><span> src/index.ts                                       | 378 ++++++-----
</span></span><span style="display:flex;"><span> src/ollama-request.ts                              | 103 +++
</span></span><span style="display:flex;"><span> src/release-template.ts                            |  14 +
</span></span><span style="display:flex;"><span> test/analysis-plan.spec.ts                         |  43 ++
</span></span><span style="display:flex;"><span> test/change-index.spec.ts                          |  84 +++
</span></span><span style="display:flex;"><span> test/cli.spec.ts                                   |  22 +-
</span></span><span style="display:flex;"><span> test/distribution.spec.ts                          |  88 ++-
</span></span><span style="display:flex;"><span> test/ollama-request.spec.ts                        |  88 +++
</span></span><span style="display:flex;"><span> test/release-template.spec.ts                      |  17 +
</span></span><span style="display:flex;"><span> 22 files changed, 1837 insertions(+), 412 deletions(-)
</span></span></code></pre></div><p>Comparison: <code>v1.0.2...v2.0.0</code></p>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/delivery-autopilot-runner/</link><pubDate>Tue, 25 Aug 2026 22:42:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.40.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action Delivery Autopilot Runner automates the integration of Delivery Autopilot, a hosted service that uses AI to plan, build, check, and self-heal pull requests. It requires an active subscription from Tekunda, which triggers the action when a ticket is assigned to it. The action checks out the repository on GitHub’s runners, runs AI-generated code, performs quality checks, opens a pull request, and reports status back to Delivery Autopilot. It does not send any source code to Tekunda’s servers but uses the chosen model provider (Anthropic or OpenAI) directly for code generation and quality checking. The action is configured using either a GitHub App or by adding a workflow to the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.40</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action Delivery Autopilot Runner automates the integration of <a href="https://tekunda.com">Delivery Autopilot</a>, a hosted service that uses AI to plan, build, check, and self-heal pull requests. It requires an active subscription from Tekunda, which triggers the action when a ticket is assigned to it. The action checks out the repository on GitHub&rsquo;s runners, runs AI-generated code, performs quality checks, opens a pull request, and reports status back to Delivery Autopilot. It does not send any source code to Tekunda&rsquo;s servers but uses the chosen model provider (Anthropic or OpenAI) directly for code generation and quality checking. The action is configured using either a GitHub App or by adding a workflow to the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runner-dist synced from AutoPilot 05f30e57aceb. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>SlopLock</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sloplock/</link><pubDate>Tue, 25 Aug 2026 22:41:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sloplock/</guid><description>Version updated for https://github.com/theinfosecguy/sloplock to version v2.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SlopLock is a GitHub Action that checks package names before they are installed or merged, ensuring the packages exist and are not too new. It identifies AI-hallucinated, nonexistent, and too-new dependencies by asking eight public registries if they exist and have sufficient history to trust them. The tool posts comments on pull requests with details about the findings and helps maintain a secure dependency ecosystem.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/theinfosecguy/sloplock">https://github.com/theinfosecguy/sloplock</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sloplock">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SlopLock is a GitHub Action that checks package names before they are installed or merged, ensuring the packages exist and are not too new. It identifies AI-hallucinated, nonexistent, and too-new dependencies by asking eight public registries if they exist and have sufficient history to trust them. The tool posts comments on pull requests with details about the findings and helps maintain a secure dependency ecosystem.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="sloplock-v200">SlopLock v2.0.0</h1>
<p>This major release adds a direct package-checking library API, removes unused
public type surface, and improves dependency discovery and failure reporting
across the CLI and GitHub Action.</p>
<h2 id="library-api">Library API</h2>
<ul>
<li>Adds <code>checkPackages()</code> for checking normalized package names without a
repository checkout.</li>
<li>Returns registry results, policy findings, warnings, and registry failures in
deterministic input order.</li>
<li>Exports the default registry client, package-name normalization helpers, and
public error classes from the package entry point.</li>
<li>Keeps source-free package checks separate from the source-backed <code>scan()</code>
finding contract.</li>
</ul>
<h2 id="breaking-changes">Breaking Changes</h2>
<ul>
<li>Removes the unused <code>ScanOptions.failClosed</code> library option. CLI and GitHub
Action <code>--fail-closed</code> behavior is unchanged; library callers should inspect
<code>registryFailures</code> in the returned result.</li>
<li>Narrows <code>SourceKind</code> to the values produced by supported parsers:
<code>manifest</code> and <code>lockfile</code>.</li>
<li>Removes the unused <code>ScanMode</code> type.</li>
</ul>
<h2 id="scanner-and-cli-reliability">Scanner And CLI Reliability</h2>
<ul>
<li>Skips common virtual environment, vendored dependency, and build-output
directories during full and changed-only discovery.</li>
<li>Resolves the remote default branch through <code>origin/HEAD</code> for changed-only
scans, with <code>origin/main</code> as the fallback.</li>
<li>Reports unreadable scan roots as usage errors and keeps JSON-mode failures as
valid JSON.</li>
<li>Handles partial cooldown configuration correctly and warns consistently about
allow or ignore entries without expiry dates.</li>
<li>Uses the shared runtime version constant for CLI version output and registry
user agents.</li>
</ul>
<h2 id="action-and-registry-hardening">Action And Registry Hardening</h2>
<ul>
<li>Introduces the <code>theinfosecguy/sloplock@v2</code> moving Action ref while leaving
<code>v1</code> on the latest compatible 1.x release.</li>
<li>Keeps registry timeouts, rate limits, server failures, and malformed responses
distinct from package-not-found findings.</li>
<li>Preserves concise Action annotations, summaries, and optional pull request
comments while retaining read-only-permission support.</li>
<li>Updates generated artifacts for the Node 24 bundled Action before release.</li>
</ul>
]]></content:encoded></item><item><title>Extract Changelog Release Notes</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/extract-changelog-release-notes/</link><pubDate>Tue, 25 Aug 2026 22:40:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/extract-changelog-release-notes/</guid><description>Version updated for https://github.com/theory/changelog-version-notes-action to version v0.1.4.
This action is used across all versions by 16 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action extracts release notes from a CHANGELOG.md file based on a specified version. It automates the process of generating concise release notes for a given tag, which can be particularly useful for creating GitHub releases. The action uses a Perl script to search for version headers and extract subsequent changes until the next version header is encountered.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/theory/changelog-version-notes-action">https://github.com/theory/changelog-version-notes-action</a></strong> to version <strong>v0.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>16</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/extract-changelog-release-notes">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action extracts release notes from a <code>CHANGELOG.md</code> file based on a specified version. It automates the process of generating concise release notes for a given tag, which can be particularly useful for creating GitHub releases. The action uses a Perl script to search for version headers and extract subsequent changes until the next version header is encountered.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="-bug-fixes">🪲 Bug Fixes</h3>
<ul>
<li>Updated the reformatting to support nested lists, not just lists that start at the beginning of each line. Like this:
<ul>
<li>Changed regex</li>
<li>Updated changes</li>
<li>Updated the integration test workflow, <code>.github/workflows/test.yml</code>, to emit this most recent change list, so you can see the wrapping in action</li>
</ul>
</li>
</ul>
<h3 id="-documentation">📚 Documentation</h3>
<ul>
<li>Updated the versions of the actions used in the <a href="README.md">README</a>&rsquo;s example workflows (and also in the project&rsquo;s own workflows)</li>
</ul>
<hr>
<p>🆚 For more detail compare <a href="https://github.com/theory/changelog-version-notes-action/compare/v0.1.3...v0.1.4">changes since v0.1.3</a>.</p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/wails3-build-action/</link><pubDate>Tue, 25 Aug 2026 22:39:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building of Wails.io projects using GoLang and NodeJS. It builds a binary for specified platforms, optionally obfuscates it, caches the build process, and uploads the resulting artifacts to GitHub or releases on tagged builds. The action supports various configurations such as specifying Node.js and pnpm versions, and provides options for deploying Deno compiled binaries.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building of Wails.io projects using GoLang and NodeJS. It builds a binary for specified platforms, optionally obfuscates it, caches the build process, and uploads the resulting artifacts to GitHub or releases on tagged builds. The action supports various configurations such as specifying Node.js and pnpm versions, and provides options for deploying Deno compiled binaries.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Rabbit Automation Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/rabbit-automation-action/</link><pubDate>Tue, 25 Aug 2026 22:38:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/rabbit-automation-action/</guid><description>Version updated for https://github.com/udx/github-rabbit-action to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Rabbit Automation Action automates the deployment of cloud infrastructure across AWS, GCP, and Kubernetes using Terraform by discovering YAML configuration files in a repository’s .rabbit/ directory. It supports automatic planning and application based on git pushes or other events, ensuring safe and efficient infrastructure management through lifecycle policies and branch/environment protection.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/udx/github-rabbit-action">https://github.com/udx/github-rabbit-action</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rabbit-automation-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Rabbit Automation Action automates the deployment of cloud infrastructure across AWS, GCP, and Kubernetes using Terraform by discovering YAML configuration files in a repository&rsquo;s <code>.rabbit/</code> directory. It supports automatic planning and application based on git pushes or other events, ensuring safe and efficient infrastructure management through lifecycle policies and branch/environment protection.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Clarified the one-time GitHub Marketplace setup and the checks required for
each subsequent action release. No action runtime behavior changed.</li>
</ul>
]]></content:encoded></item><item><title>Vaara Policy Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/vaara-policy-check/</link><pubDate>Tue, 25 Aug 2026 22:37:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/vaara-policy-check/</guid><description>Version updated for https://github.com/vaaraio/vaara to version v1.77.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Vaara Action Summary: Vaara is a GitHub Action designed to automate the creation and verification of verifiable receipts for autonomous actions, ensuring accountability and traceability. It automates the process of generating and verifying receipts for transactions, logs, and events, providing a tamper-evident audit trail that can be used to prove actions and decisions in various contexts such as audits, regulators, or incident handling.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaaraio/vaara">https://github.com/vaaraio/vaara</a></strong> to version <strong>v1.77.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vaara-policy-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Vaara Action Summary:</strong>
Vaara is a GitHub Action designed to automate the creation and verification of verifiable receipts for autonomous actions, ensuring accountability and traceability. It automates the process of generating and verifying receipts for transactions, logs, and events, providing a tamper-evident audit trail that can be used to prove actions and decisions in various contexts such as audits, regulators, or incident handling.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1770---2026-08-25">[1.77.0] - 2026-08-25</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p>A fourth kind of run for the conformance register. Tiago Pinto reproduced a published class digest from the prose describing it, without running the author&rsquo;s verifier and without writing a second implementation, and said on the SCITT list that it fitted none of the three kinds the register offered. He was right.</p>
<p><code>construction_reproduction</code> sits second, above <code>reproduction</code> and below an independent implementation. A reproduction asks whether the artefact runs somewhere other than the author&rsquo;s machine. A construction reproduction asks whether the description was sufficient to derive the published value at all, which is a question about the text and is answerable with no code on either side. Filed as a reproduction it would have recorded a claim about prose as a claim about an artefact, in a row nobody can edit afterwards.</p>
<p>The unstated-kind rule is untouched. A row with no kind still reads as the weakest, and rows listed before the field existed are still never edited to add one.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p>Nothing bound the conformance issue form&rsquo;s dropdown to the register&rsquo;s own table of kinds. A kind added to the table had no way to be chosen, and a reworded option would have parsed as the weakest kind, filing a quieter claim than the submitter picked. Both failed silently, in a row that cannot be edited afterwards. A test now binds the two one to one and in order, and reads the form without PyYAML, which ships in the <code>yaml</code> extra, so the guard runs on every job instead of skipping wherever that extra is absent.</p>
</li>
<li>
<p><code>parse_kind</code> matched the <code>reproduction</code> prefix before anything else, so the fourth kind&rsquo;s wording, which carries that word, would have fallen through to the weakest kind. The construction prefix is now checked first and a test pins the ordering.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/vibgrate-scan/</link><pubDate>Tue, 25 Aug 2026 22:36:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.825.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating code intelligence and drift scores for repositories. It provides a local tool to analyze the current state of a repository’s dependencies, including drift scores that measure how far behind it is from being up-to-date with its dependencies. The action also includes a coding agent (vg code) that can suggest changes directly in the terminal based on the analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.825.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating code intelligence and drift scores for repositories. It provides a local tool to analyze the current state of a repository&rsquo;s dependencies, including drift scores that measure how far behind it is from being up-to-date with its dependencies. The action also includes a coding agent (<code>vg code</code>) that can suggest changes directly in the terminal based on the analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268252">Vibgrate CLI 2026.825.2</h1>
<p><em>Released 2026-08-25</em></p>
<p>This release of the Vibgrate CLI includes improvements to the relevance engine, enhancing the accuracy of code suggestions and context understanding. Additionally, several changes have been made to the output of the <code>vg code</code> command, providing clearer insights into how requests are interpreted.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="improved">Improved</h3>
<ul>
<li>Coding prompts now find the right code more reliably, handling pasted error messages, file paths, stack traces, one-character typos, plural forms, and cross-cutting tasks effectively.</li>
<li><code>vg code</code> now shows up to six lines of how it interpreted your request, improving visibility for typo corrections.</li>
<li>VG Code&rsquo;s Context Capsule now expands common coding terms to their corresponding identifiers, improving the relevance of results.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>The relevance engine is now part of the Vibgrate relevance module, which is installed automatically; without it, <code>vg</code> falls back to basic name matching.</li>
<li><code>vg code</code> now displays how it read your request before providing answers, including the concepts mapped to your codebase and the reasons for matches.</li>
<li>The source-bearing context compiled for requests is now referred to as the Context Capsule, reflecting its use for both questions and investigations.</li>
<li>On tiny repositories, <code>vg code --capsule</code> now pastes the mapped files as first-turn context instead of compiling a ranked Context Capsule.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Graph builds no longer degrade on large parse volumes due to improved parser reuse and better handling of parse failures.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.825.1, interleaved on one runner against the pinned corpus (187 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21945 count</td>
          <td>21945 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>11809 count</td>
          <td>11809 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.95 ratio</td>
          <td>0.95 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>705.80 ms</td>
          <td>706.90 ms</td>
      </tr>
  </tbody>
</table>
<p>1 regression(s) — published, not omitted:</p>
<ul>
<li>Token reduction vs baseline agent (equal success): 0.27 → 0.22 (-19.3%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.825.2">https://vibgrate.com/changelog/cli/2026.825.2</a></p>
]]></content:encoded></item><item><title>npm release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/npm-release/</link><pubDate>Tue, 25 Aug 2026 22:34:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/npm-release/</guid><description>Version updated for https://github.com/vitalets/npm-release to version v2.0.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of creating and publishing a new version of an npm package. It handles both stable releases and beta releases by updating the package.json and CHANGELOG.md, committing and tagging changes, and then publishing to npm using OIDC trusted publishing. The action is configured through workflow inputs for specifying release type and whether to skip npm publishing or perform a dry run.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vitalets/npm-release">https://github.com/vitalets/npm-release</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/npm-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of creating and publishing a new version of an npm package. It handles both stable releases and beta releases by updating the <code>package.json</code> and <code>CHANGELOG.md</code>, committing and tagging changes, and then publishing to npm using OIDC trusted publishing. The action is configured through workflow inputs for specifying release type and whether to skip npm publishing or perform a dry run.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Use separate stable and beta release dropdowns with npm-compatible version transitions</li>
<li>Let <code>beta-patch</code>, <code>beta-minor</code>, and <code>beta-major</code> start or continue their matching beta line</li>
<li>Run dependency-free TypeScript sources directly without a build step</li>
<li>Add a self-release workflow that always skips npm publishing</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Increment the beta suffix when the selected beta operation matches the current beta line</li>
<li>Reject lower release operations while on a minor or major beta line</li>
</ul>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/cowork-harness/</link><pubDate>Tue, 25 Aug 2026 22:33:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v2.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cowork-harness action is a scriptable and CI-ready tool that reproduces Claude Cowork’s observable runtime contract to test agent skills in headless environments across multiple scenarios. It provides evidence of what an agent actually did, not just what it said it did, by recording every run. This helps ensure that the tested skills are robust against constraints like the sealed filesystem, default-deny egress, and MCP-only cross-boundary access.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v2.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The cowork-harness action is a scriptable and CI-ready tool that reproduces Claude Cowork&rsquo;s observable runtime contract to test agent skills in headless environments across multiple scenarios. It provides evidence of what an agent actually did, not just what it said it did, by recording every run. This helps ensure that the tested skills are robust against constraints like the sealed filesystem, default-deny egress, and MCP-only cross-boundary access.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="upgrade-impact">Upgrade impact</h3>
<p>Two behaviour changes can turn a previously-green run red. Neither breaks a covered surface
(<a href="./SPEC.md#12-versioning--the-10-compatibility-contract">SPEC.md §12</a>) — both make an assertion report
what it always documented — so they ship in a minor:</p>
<ul>
<li><strong><code>no_scratchpad_leak</code> at <code>container</code> can now FAIL.</strong> It was measuring containment against a root in a
different path space, so every presented file classified <code>leaked: false</code> and the check passed
vacuously. A scenario whose skill genuinely leaves a presented file in the scratchpad will now red —
that is the leak the key exists to catch.</li>
<li><strong><code>baseline: desktop-1.11847.5</code> is now refused at <code>container</code>/<code>hostloop</code>/<code>microvm</code>.</strong> It carries no
<code>spawn</code> block, so those tiers cannot reproduce Cowork&rsquo;s toolset — a run on it launched an agent with no
file or bash tools and still reported a verdict. Use a <code>sync</code>-recorded baseline, or <code>fidelity: protocol</code>.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong><code>present_files_called</code> no longer reports &ldquo;the tool was never called&rdquo; about a run that called it, and a
hostloop delivery scenario can be recorded with a host-path redaction policy at last.</strong> The assertion
read presence off <code>RunResult.presentedFiles</code>, which is a <em>classification</em> of each presented path
(scratchpad? promoted? leaked?) and requires an absolute path to compute. At <code>hostloop</code> a presented path
is a real host path, so the shipped redaction policy rewrites it to
<code>[REDACTED:local-path:&lt;hash&gt;]/mnt/outputs/report.html</code> — correct, documented, and deliberately ordered so
the mount tail survives — and the classifier then drops every entry as un-normalizable. The list came
back empty and the assertion stated, as fact, that the tool had never been called.</p>
<p>Because <code>record</code> replays the base and redacted cassettes and refuses to write when the verdict differs,
this was not merely a wrong message: <strong>no cassette asserting <code>present_files_called</code> could be recorded at
that tier at all</strong>, so the assertion had never executed on the replay lane. The refusal was right — the
redacted cassette genuinely could not support the assert — but the defect it was reporting was in the
harness, not in the recording.</p>
<p>Presence now comes from <code>RunResult.presentFilesCalls</code>, a new count of the <code>present_files</code> invocations
that carried a well-formed <code>file_path</code>, taken from the tool_use input&rsquo;s shape and never from a path&rsquo;s
content, so redaction cannot alter it. Classification is untouched: <code>presentedFiles</code> still drops what it
cannot resolve, and <code>no_scratchpad_leak</code> still reads it. A run recorded before the field falls back to
the old <code>presentedFiles</code>-non-empty test, so no existing green changes.</p>
<p>A run whose every <code>present_files</code> call carried an unusable path now reports <strong>cannot verify</strong> rather than
&ldquo;never called&rdquo; — the tool <em>was</em> invoked, and the harness already knew it. (The malformed count is
deliberately kept out of that message: the record self-check normalizes <code>[REDACTED…]</code> tokens out of
failing messages but not digits, so an interpolated count that differed between the two replays would
refuse a cassette that is otherwise fine to write.)</p>
<p>Pinned as an invariant (<a href="./docs/invariants.md">docs/invariants.md</a>) with the end-to-end record self-check
as its test anchor — the case that could not be recorded, and so had never run in CI.</p>
</li>
<li>
<p><strong>Guest paths are built from the tree the harness stages, not from a baseline&rsquo;s recorded mount layout.</strong>
<code>resolveMounts</code> returned <code>mountLayout.mntRoot</code> verbatim — or, when that field was absent and the recorded
<code>sessionRoot</code> already ended in <code>/mnt</code>, the session root itself. But the staged tree is always
<code>&lt;sessionRoot&gt;/mnt</code>: <code>stageWorkspace</code> creates it there and <code>dockerRunArgv</code> nests its read-only binds
there. On a baseline recording anything else, <code>--plugin-dir</code> therefore pointed one directory <strong>above</strong>
the staged plugin tree, so the plugin under test never loaded. <code>mntRoot</code> is now derived from the session
root, and a recorded layout the harness cannot stage is reported as a fidelity divergence at spawn
instead of silently composing a path no stager creates.</p>
<p>Guest paths now anchor on <code>sessionRoot</code> — the bind target — rather than <code>cwd</code>, which is only where the
agent&rsquo;s process starts (production&rsquo;s own working directory is a folder mount or <code>outputs</code>, so the two are
not interchangeable even though every synced baseline records them equal). <code>dockerRunArgv</code> takes an
explicit <code>agentCwd</code> for <code>-w</code>.</p>
<p>Two more derivations of the same rule are gone: <code>prompt.ts</code> had a private <code>/sessions/&lt;id&gt;</code> +<code>/mnt</code>
literal (so the prompt could describe a tree the runtimes had not staged), and <strong>microvm</strong> read the
agent&rsquo;s root from the baseline when lima structurally mounts it at <code>/sessions/&lt;sessionId&gt;</code> — which put
<code>CLAUDE_CONFIG_DIR</code> and <code>--mcp-config</code> at paths nothing stages. A baseline recording a cwd that tier
cannot honour is now <strong>refused</strong>, not warned about: the guest <code>cd</code> would otherwise succeed at the wrong
directory.</p>
</li>
<li>
<p><strong>A baseline with no <code>spawn</code> block is refused at the sandbox tiers.</strong> That block carries the tool set,
pre-approvals, effort default and config-dir location, and the <code>?? []</code> fallbacks meant a run would launch
an agent with <strong>no Read/Write/Bash/Skill/Task at all</strong> and still report a verdict. <code>fidelity: protocol</code>
builds its own argv and is unaffected.</p>
</li>
<li>
<p><strong><code>no_scratchpad_leak</code> can see a container leak again — the session root was in the wrong path space.</strong> The
root that <code>presentedFiles</code>&rsquo; promoted/leaked classification is measured from was derived by the caller as
<code>&lt;run-dir&gt;/work/session</code>, a HOST path, and handed to every non-<code>protocol</code> tier. But the path space the
agent reports in is per-tier: at <code>container</code> (the default) it runs inside the sandbox and reports
<code>/sessions/&lt;id&gt;/…</code>, and only at <code>hostloop</code> does it run natively and report host paths. Measured against a
host root, no VM path is ever inside the root, so every presented file classified <code>leaked: false</code> —
including the handler&rsquo;s copy-failure branch, which returns the source path unchanged when a file is
blocked-extension, a directory, or absent. <code>no_scratchpad_leak</code> evaluates at <code>container</code> and nowhere else,
so the assertion that exists to catch that leak could not catch it, and <code>verdict.ts</code>&rsquo;s delivery check read
the same <code>leaked: false</code> as a successful delivery.</p>
<p>Each runtime now reports the session root it actually launched the agent with, and the run consumes that
instead of deriving a second one — the two can no longer drift into different spaces. <code>chat</code> sets it on
both serving tiers as well; it never did, so a hostloop chat&rsquo;s <code>presentedFiles</code> was inverted in its result
file. <code>protocol</code> and <code>microvm</code> serve no <code>present_files</code> and keep the cwd fallback.</p>
<p>Independently, the classifier now fails CLOSED on a space mismatch: if the agent&rsquo;s cwd is not at or inside
the session root, the presented batch counts as malformed (<code>no_scratchpad_leak</code> → cannot verify) rather
than being graded against a root it cannot be compared to. <code>leaked: true</code> is not derivable in that state
either, and a <code>leaked: false</code> verdict there is exactly the vacuous pass the key exists to prevent.</p>
</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>First live coverage for <code>present_files_called</code> / <code>no_scratchpad_leak</code>.</strong> No scenario in the repo
asserted either key, which is how a session root in the wrong path space could record <code>leaked: false</code>
for every presented file without anything noticing. <code>e2e/scenarios/smoke-present-files.yaml</code> writes a
file OUTSIDE <code>mnt/</code> and delivers it, so the promotion is real and the pair is non-vacuous; it runs in
CI&rsquo;s live e2e loop. Measured on a live container run: <code>presentFilesCalls: 1</code>, promoted <code>true</code>, leaked
<code>false</code>.</p>
</li>
<li>
<p><strong><code>RunResult.presentFilesCalls</code></strong> — the count of <code>present_files</code> invocations that carried a well-formed
<code>file_path</code>, in <code>result.json</code> and <a href="./schema/run-result.json">schema/run-result.json</a>. Content-class, so a
replay re-drive reproduces it; read by <code>run</code>, <code>replay</code> and <code>verify-run</code> alike, and absent (not <code>0</code>) on a
result written before this release, which is what the assertion&rsquo;s fallback distinguishes. Use it to
answer &ldquo;did the agent deliver anything?&rdquo; from a result file without interpreting <code>presentedFiles</code>'
promoted/leaked classification.</p>
</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 2.2.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/158">https://github.com/yaniv-golan/cowork-harness/pull/158</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v2.1.0...v2.2.0">https://github.com/yaniv-golan/cowork-harness/compare/v2.1.0...v2.2.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/b.ia-accessibility-checker/</link><pubDate>Tue, 25 Aug 2026 22:32:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that enables companies to integrate accessibility checks into their CI/CD pipeline. It defines an audience and percentage of guidelines to be met, allowing for flexible accessibility coverage tailored to specific business needs. The action uses AI to analyze and measure guidelines efficiently, providing feedback on code accessibility issues, ensuring compliance with WCAG standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that enables companies to integrate accessibility checks into their CI/CD pipeline. It defines an audience and percentage of guidelines to be met, allowing for flexible accessibility coverage tailored to specific business needs. The action uses AI to analyze and measure guidelines efficiently, providing feedback on code accessibility issues, ensuring compliance with WCAG standards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>ZemDomu Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/zemdomu-lint/</link><pubDate>Tue, 25 Aug 2026 22:31:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/zemdomu-lint/</guid><description>Version updated for https://github.com/Zemdomu/ZemDomu-action to version v0.3.6.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The ZemDomu GitHub Action automates semantic checks in CI for HTML, JSX, TSX, and Vue templates using the shared ZemDomu rules engine. It surfaces findings as GitHub Actions annotations, allowing teams to catch structural, accessibility, and SEO issues before they land in the main branch. The action focuses on semantic structure and actionable remediation, enabling cross-component analysis for component trees.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zemdomu/ZemDomu-action">https://github.com/Zemdomu/ZemDomu-action</a></strong> to version <strong>v0.3.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zemdomu-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The ZemDomu GitHub Action automates semantic checks in CI for HTML, JSX, TSX, and Vue templates using the shared ZemDomu rules engine. It surfaces findings as GitHub Actions annotations, allowing teams to catch structural, accessibility, and SEO issues before they land in the main branch. The action focuses on semantic structure and actionable remediation, enabling cross-component analysis for component trees.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="patch-notesnn--refresh-the-bundled-runtime-to-patched-dependency-versionsn--bundle-zemdomu-core-1320n--update-the-tracked-ncc-distribution-used-by-github-actionsn--npm-audit-reports-0-vulnerabilities-action-process-tests-passnnuse--in-workflows">Patch notes\n\n- Refresh the bundled runtime to patched dependency versions.\n- Bundle ZemDomu Core 1.3.20.\n- Update the tracked ncc distribution used by GitHub Actions.\n- npm audit reports 0 vulnerabilities; action process tests pass.\n\nUse <a href="mailto:Zemdomu/ZemDomu-action@v0.3.6">Zemdomu/ZemDomu-action@v0.3.6</a> in workflows.</h2>
]]></content:encoded></item><item><title>Zyvor QA</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/zyvor-qa/</link><pubDate>Tue, 25 Aug 2026 22:30:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/zyvor-qa/</guid><description>Version updated for https://github.com/zyvorai/argus to version v0.8.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Zyvor Argus is an open-source tool designed to automate the quality assurance of web applications. It analyzes application requirements, evaluates their quality, generates Playwright tests, and ensures continuous testing after deployments. The action provides features such as authorized security testing and a live operations console for real-time monitoring and feedback.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zyvorai/argus">https://github.com/zyvorai/argus</a></strong> to version <strong>v0.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zyvor-qa">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Zyvor Argus is an open-source tool designed to automate the quality assurance of web applications. It analyzes application requirements, evaluates their quality, generates Playwright tests, and ensures continuous testing after deployments. The action provides features such as authorized security testing and a live operations console for real-time monitoring and feedback.</strong></p>
<hr>
<p>This summary captures the main purpose and functionality of the GitHub Action, which is to automate QA processes in web applications using Playwright testing and continuous integration/continuous deployment (CI/CD) capabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Image: <code>ghcr.io/hypersdk/zyvor-argus:v0.8.0</code></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/hypersdk/zyvor-argus:v0.8.0
</span></span></code></pre></div><p>macOS desktop app: download the <code>.dmg</code> below (unsigned — right-click → Open on first launch). See <a href="https://github.com/hypersdk/zyvor-argus/blob/main/docs/tutorials/17-desktop-app.md">Tutorial 17</a> and <code>desktop/README.md</code>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hypersdk/zyvor-argus/compare/v0.7.0...v0.8.0">https://github.com/hypersdk/zyvor-argus/compare/v0.7.0...v0.8.0</a></p>
]]></content:encoded></item><item><title>SST Operations</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sst-operations/</link><pubDate>Tue, 25 Aug 2026 13:57:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sst-operations/</guid><description>Version updated for https://github.com/kodehort/sst-ops-action to version v0.7.63.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kodehort/sst-ops-action">https://github.com/kodehort/sst-ops-action</a></strong> to version <strong>v0.7.63</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sst-operations">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Merge Warden</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/merge-warden/</link><pubDate>Tue, 25 Aug 2026 13:57:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/merge-warden/</guid><description>Version updated for https://github.com/leo-aa88/merge-warden to version v1.0.10.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/leo-aa88/merge-warden">https://github.com/leo-aa88/merge-warden</a></strong> to version <strong>v1.0.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/merge-warden">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Lineaje Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/lineaje-scan/</link><pubDate>Tue, 25 Aug 2026 13:57:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/lineaje-scan/</guid><description>Version updated for https://github.com/lineaje-actions/lineaje-actions to version v1.12.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lineaje-actions/lineaje-actions">https://github.com/lineaje-actions/lineaje-actions</a></strong> to version <strong>v1.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lineaje-scan">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>GitHub Personal Stats</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/github-personal-stats/</link><pubDate>Tue, 25 Aug 2026 13:57:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/github-personal-stats/</guid><description>Version updated for https://github.com/liuchong/github-personal-stats to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/liuchong/github-personal-stats">https://github.com/liuchong/github-personal-stats</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-personal-stats">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>DeepSeek Harness for GitHub</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/deepseek-harness-for-github/</link><pubDate>Tue, 25 Aug 2026 13:57:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/deepseek-harness-for-github/</guid><description>Version updated for https://github.com/Lixiaoyiao/deepseek-harness-action to version v0.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lixiaoyiao/deepseek-harness-action">https://github.com/Lixiaoyiao/deepseek-harness-action</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deepseek-harness-for-github">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Go Generate Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/go-generate-check/</link><pubDate>Tue, 25 Aug 2026 13:57:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/go-generate-check/</guid><description>Version updated for https://github.com/maxcraig112/go-generate-check-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/maxcraig112/go-generate-check-action">https://github.com/maxcraig112/go-generate-check-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-generate-check">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Tue, 25 Aug 2026 13:57:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.14.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/totem-shield/</link><pubDate>Tue, 25 Aug 2026 13:57:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.120.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.120.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Disensor Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/disensor-gate/</link><pubDate>Tue, 25 Aug 2026 13:57:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/disensor-gate/</guid><description>Version updated for https://github.com/NicolasRocchia/disensor to version v0.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NicolasRocchia/disensor">https://github.com/NicolasRocchia/disensor</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/disensor-gate">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>ProofCore Release Notary</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/proofcore-release-notary/</link><pubDate>Tue, 25 Aug 2026 13:57:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/proofcore-release-notary/</guid><description>Version updated for https://github.com/ProofCore-Protocol/proofcore-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ProofCore-Protocol/proofcore-action">https://github.com/ProofCore-Protocol/proofcore-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/proofcore-release-notary">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>SnapDrift</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/snapdrift/</link><pubDate>Tue, 25 Aug 2026 13:57:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/snapdrift/</guid><description>Version updated for https://github.com/ranacseruet/snapdrift to version v0.8.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ranacseruet/snapdrift">https://github.com/ranacseruet/snapdrift</a></strong> to version <strong>v0.8.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/snapdrift">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>KeyHog Secret Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/keyhog-secret-scanner/</link><pubDate>Tue, 25 Aug 2026 13:57:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/keyhog-secret-scanner/</guid><description>Version updated for https://github.com/santhreal/keyhog to version v0.5.86.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/santhreal/keyhog">https://github.com/santhreal/keyhog</a></strong> to version <strong>v0.5.86</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/keyhog-secret-scanner">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Scratchsmith</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/scratchsmith/</link><pubDate>Tue, 25 Aug 2026 13:56:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/scratchsmith/</guid><description>Version updated for https://github.com/schubydoo/scratchsmith to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/schubydoo/scratchsmith">https://github.com/schubydoo/scratchsmith</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/scratchsmith">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>LetItLoop Proof-Carrying PR Verification Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/letitloop-proof-carrying-pr-verification-gate/</link><pubDate>Tue, 25 Aug 2026 13:56:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/letitloop-proof-carrying-pr-verification-gate/</guid><description>Version updated for https://github.com/sdageltc/letitloop-action to version v1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sdageltc/letitloop-action">https://github.com/sdageltc/letitloop-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/letitloop-proof-carrying-pr-verification-gate">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Crowdin Translation Status Badge</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/crowdin-translation-status-badge/</link><pubDate>Tue, 25 Aug 2026 13:56:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/crowdin-translation-status-badge/</guid><description>Version updated for https://github.com/SeaweedbrainCY/crowdin-translation-progress to version v1.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SeaweedbrainCY/crowdin-translation-progress">https://github.com/SeaweedbrainCY/crowdin-translation-progress</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crowdin-translation-status-badge">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/bernstein-multi-agent-orchestration/</link><pubDate>Tue, 25 Aug 2026 13:56:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.18.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.18.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/smyklot/</link><pubDate>Tue, 25 Aug 2026 13:56:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.48.1.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.48.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Tue, 25 Aug 2026 13:56:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>HowFastly</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/howfastly/</link><pubDate>Tue, 25 Aug 2026 13:56:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/howfastly/</guid><description>Version updated for https://github.com/stepbrobd/howfastly to version 2026.825.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stepbrobd/howfastly">https://github.com/stepbrobd/howfastly</a></strong> to version <strong>2026.825.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/howfastly">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>supriya-project/setup-supercollider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/supriya-project/setup-supercollider/</link><pubDate>Tue, 25 Aug 2026 13:56:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/supriya-project/setup-supercollider/</guid><description>Version updated for https://github.com/supriya-project/setup-supercollider to version v1.1.2.
This action is used across all versions by 1 repositories. Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/supriya-project/setup-supercollider">https://github.com/supriya-project/setup-supercollider</a></strong> to version <strong>v1.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<p>Go to the <a href="https://github.com/marketplace/actions/supriya-project-setup-supercollider">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/delivery-autopilot-runner/</link><pubDate>Tue, 25 Aug 2026 13:56:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.37.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.37</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>OpenLine Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/openline-check/</link><pubDate>Tue, 25 Aug 2026 13:56:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/openline-check/</guid><description>Version updated for https://github.com/terryncew/openline-lite to version v0.6.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/terryncew/openline-lite">https://github.com/terryncew/openline-lite</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/openline-check">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Setup jals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/setup-jals/</link><pubDate>Tue, 25 Aug 2026 13:56:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/setup-jals/</guid><description>Version updated for https://github.com/topi-banana/jals to version 0.1.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/topi-banana/jals">https://github.com/topi-banana/jals</a></strong> to version <strong>0.1.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-jals">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Vaara Policy Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/vaara-policy-check/</link><pubDate>Tue, 25 Aug 2026 13:56:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/vaara-policy-check/</guid><description>Version updated for https://github.com/vaaraio/vaara to version v1.76.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaaraio/vaara">https://github.com/vaaraio/vaara</a></strong> to version <strong>v1.76.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vaara-policy-check">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/b.ia-accessibility-checker/</link><pubDate>Tue, 25 Aug 2026 13:56:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Zyvor QA</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/zyvor-qa/</link><pubDate>Tue, 25 Aug 2026 06:17:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/zyvor-qa/</guid><description>Version updated for https://github.com/hypersdk/zyvor-argus to version v1.1.1-ent-trial.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Zyvor Argus automates quality assurance by reading requirements, scoring them for quality, generating Playwright tests, and running them after every deploy. It also provides authorized security testing and a live operations console.
What’s Changed Image: ghcr.io/hypersdk/zyvor-argus:v1.1.1-ent-trial</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hypersdk/zyvor-argus">https://github.com/hypersdk/zyvor-argus</a></strong> to version <strong>v1.1.1-ent-trial</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zyvor-qa">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Zyvor Argus automates quality assurance by reading requirements, scoring them for quality, generating Playwright tests, and running them after every deploy. It also provides authorized security testing and a live operations console.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Image: <code>ghcr.io/hypersdk/zyvor-argus:v1.1.1-ent-trial</code></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/hypersdk/zyvor-argus:v1.1.1-ent-trial
</span></span></code></pre></div><p>macOS desktop app: download the <code>.dmg</code> below (unsigned — right-click → Open on first launch). See <a href="https://github.com/hypersdk/zyvor-argus/blob/main/docs/tutorials/17-desktop-app.md">Tutorial 17</a> and <code>desktop/README.md</code>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hypersdk/zyvor-argus/compare/v0.3.0...v1.1.1-ent-trial">https://github.com/hypersdk/zyvor-argus/compare/v0.3.0...v1.1.1-ent-trial</a></p>
]]></content:encoded></item><item><title>Dependency Support Policy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/dependency-support-policy/</link><pubDate>Tue, 25 Aug 2026 06:16:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/dependency-support-policy/</guid><description>Version updated for https://github.com/isaac-cf-wong/dependency-support-policy-action to version v0.2.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks and manages the support policy of Python dependencies in a project using pyproject.toml. It evaluates the dependency constraints against the Scientific Python SPEC 0 to determine appropriate lower bounds and updates the requires-python floor accordingly, while preserving existing requirements. The action can be run as a standalone CLI tool or integrated into GitHub workflows for continuous integration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/isaac-cf-wong/dependency-support-policy-action">https://github.com/isaac-cf-wong/dependency-support-policy-action</a></strong> to version <strong>v0.2.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dependency-support-policy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks and manages the support policy of Python dependencies in a project using <code>pyproject.toml</code>. It evaluates the dependency constraints against the Scientific Python SPEC 0 to determine appropriate lower bounds and updates the <code>requires-python</code> floor accordingly, while preserving existing requirements. The action can be run as a standalone CLI tool or integrated into GitHub workflows for continuous integration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="026---2026-08-23"><a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/compare/v0.2.5..v0.2.6">0.2.6</a> - 2026-08-23</h2>
<h3 id="-miscellaneous-tasks">⚙️ Miscellaneous Tasks</h3>
<ul>
<li><em>(deps)</em> Update dependency zensical to &gt;=0.0.56 (#66) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/cdca2339083e858625271eeef5bb85d6f83ca406">cdca233</a>)</li>
<li><em>(deps)</em> Update dependency ruff to &gt;=0.16.4 (#67) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/6ff64197d0566b1bd9ec789437118e177f35c04a">6ff6419</a>)</li>
<li><em>(deps)</em> Update pre-commit hook astral-sh/ruff-pre-commit to v0.16.4 (#68) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/c7f5e691709997fb4650c8cfc6f12400f0e57439">c7f5e69</a>)</li>
<li><em>(deps)</em> Update dependency zensical to &gt;=0.0.57 (#69) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/757fb1f88e17b84ea6bc8e040cfb5e6ac2edc59c">757fb1f</a>)</li>
<li><em>(deps)</em> Bump cryptography in the uv group across 1 directory (#50) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/0555ece55dc2e9ac071a9f0f66345ef3d3594620">0555ece</a>)</li>
</ul>
<hr>
<p><strong>Contributing</strong>: Contributions are welcome! See the <a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/blob/main/CONTRIBUTING.md">Contributing Guide</a>.</p>
<p><strong>Questions?</strong> Open an issue on <a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/issues">GitHub</a>.</p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/neurolink-ai/</link><pubDate>Tue, 25 Aug 2026 06:15:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v11.25.3.
This action is used across all versions by 11 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that provides a TypeScript-first way to integrate AI into any application. It supports 30+ AI providers and 100+ models under one consistent API, making it easy to switch providers with a single parameter change. With features like built-in tools, multi-provider failover, and intelligent routing, NeuroLink gives developers confidence in deploying AI solutions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v11.25.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is a universal AI integration platform that provides a TypeScript-first way to integrate AI into any application. It supports 30+ AI providers and 100+ models under one consistent API, making it easy to switch providers with a single parameter change. With features like built-in tools, multi-provider failover, and intelligent routing, NeuroLink gives developers confidence in deploying AI solutions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="11253-2026-08-24"><a href="https://github.com/juspay/neurolink/compare/v11.25.2...v11.25.3">11.25.3</a> (2026-08-24)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(ci):</strong>  stamp cache-restored dist so the freshness guard doesn&rsquo;t kill every suite (<a href="https://github.com/juspay/neurolink/commit/ec24ab960176e43e709752e2b03c38c75e6a6e52">ec24ab9</a>), closes <a href="https://github.com/juspay/neurolink/issues/1532">#1532</a></li>
</ul>
]]></content:encoded></item><item><title>datamodel-code-generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/datamodel-code-generator/</link><pubDate>Tue, 25 Aug 2026 06:14:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/datamodel-code-generator/</guid><description>Version updated for https://github.com/koxudaxi/datamodel-code-generator to version 0.75.1.
This action is used across all versions by 3,509 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Generate Python data models from various schema formats, including OpenAPI 3, AsyncAPI, JSON Schema, Apache Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, MCP tool schemas, and raw data. The action supports converting existing Python types to different output types and handles complex schemas with nested types, enums, and references.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/koxudaxi/datamodel-code-generator">https://github.com/koxudaxi/datamodel-code-generator</a></strong> to version <strong>0.75.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3,509</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/datamodel-code-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Generate Python data models from various schema formats, including OpenAPI 3, AsyncAPI, JSON Schema, Apache Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, MCP tool schemas, and raw data. The action supports converting existing Python types to different output types and handles complex schemas with nested types, enums, and references.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update CHANGELOG for 0.75.0 by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3787">https://github.com/koxudaxi/datamodel-code-generator/pull/3787</a></li>
<li>Update release benchmark data by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3788">https://github.com/koxudaxi/datamodel-code-generator/pull/3788</a></li>
<li>fix(parser): preserve recursive root models by @gtxy27 in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3786">https://github.com/koxudaxi/datamodel-code-generator/pull/3786</a></li>
<li>[pre-commit.ci] pre-commit autoupdate by @pre-commit-ci[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3775">https://github.com/koxudaxi/datamodel-code-generator/pull/3775</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@gtxy27 made their first contribution in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3786">https://github.com/koxudaxi/datamodel-code-generator/pull/3786</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/koxudaxi/datamodel-code-generator/compare/0.75.0...0.75.1">https://github.com/koxudaxi/datamodel-code-generator/compare/0.75.0...0.75.1</a></p>
]]></content:encoded></item><item><title>Merge Warden</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/merge-warden/</link><pubDate>Tue, 25 Aug 2026 06:12:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/merge-warden/</guid><description>Version updated for https://github.com/leo-aa88/merge-warden to version v1.0.8.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action reviews pull requests with an adversarial senior reviewer by posting APPROVE, COMMENT, or REQUEST CHANGES with inline comments on the diff. It supports multiple providers like Grok, ChatGPT, Claude, and Gemini to provide different types of reviews based on the provider’s capabilities and models. The action automates code review tasks and is designed to be run after CI passes on pull requests only.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/leo-aa88/merge-warden">https://github.com/leo-aa88/merge-warden</a></strong> to version <strong>v1.0.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/merge-warden">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action reviews pull requests with an adversarial senior reviewer by posting <strong>APPROVE</strong>, <strong>COMMENT</strong>, or <strong>REQUEST CHANGES</strong> with inline comments on the diff. It supports multiple providers like Grok, ChatGPT, Claude, and Gemini to provide different types of reviews based on the provider&rsquo;s capabilities and models. The action automates code review tasks and is designed to be run after CI passes on pull requests only.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add GitHub issue templates for bug, feature, and question by @leo-aa88 in <a href="https://github.com/leo-aa88/merge-warden/pull/35">https://github.com/leo-aa88/merge-warden/pull/35</a></li>
<li>Keep map from consuming later stage reserves by @leo-aa88 in <a href="https://github.com/leo-aa88/merge-warden/pull/37">https://github.com/leo-aa88/merge-warden/pull/37</a></li>
<li>Block APPROVE when incomplete validation remains by @leo-aa88 in <a href="https://github.com/leo-aa88/merge-warden/pull/51">https://github.com/leo-aa88/merge-warden/pull/51</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/leo-aa88/merge-warden/compare/v1.0.7...v1.0.8">https://github.com/leo-aa88/merge-warden/compare/v1.0.7...v1.0.8</a></p>
]]></content:encoded></item><item><title>OSS Security Policy as Code</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/oss-security-policy-as-code/</link><pubDate>Tue, 25 Aug 2026 06:11:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/oss-security-policy-as-code/</guid><description>Version updated for https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit to version v10.0.17.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action evaluates OSS repositories against security policies and generates reports. It provides detailed evidence-based control verifications with a focus on assurance levels, helping developers ensure their projects meet security requirements before merging.
What’s Changed OSS Security Policy as Code Starter Kit v10.0.17 Dependency and pipeline hygiene. No product behaviour changes – no control, report, schema, CLI flag or exit code moved. If you upgrade from v10.0.16, your verdicts will be identical.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit">https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit</a></strong> to version <strong>v10.0.17</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oss-security-policy-as-code">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action evaluates OSS repositories against security policies and generates reports. It provides detailed evidence-based control verifications with a focus on assurance levels, helping developers ensure their projects meet security requirements before merging.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="oss-security-policy-as-code-starter-kit-v10017">OSS Security Policy as Code Starter Kit v10.0.17</h2>
<p>Dependency and pipeline hygiene. <strong>No product behaviour changes</strong> &ndash; no control,
report, schema, CLI flag or exit code moved. If you upgrade from v10.0.16, your
verdicts will be identical.</p>
<hr>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>github/codeql-action to v4.37.7 and step-security/harden-runner to v2.21.0.</strong>
Dependabot had split the codeql bump across four pull requests, one per
sub-action of the same repository, every one of them editing the same workflow
file. Merging any single one left the workflow running mixed versions of the
same action, which is why that split had never gone green on its own here.
They move together, and both pinned SHAs were verified against their upstream
tags rather than accepted on the bot&rsquo;s word.</li>
<li><strong>The same pins had drifted everywhere Dependabot does not look:</strong> the
reference templates, the hardened example fixture, and the Action
documentation. Six occurrences, and nothing in the repository would have
reported them. The hardened example still scores 14 of 14.</li>
<li><strong>The gitpage build guard no longer blocks routine bumps.</strong> It asserted three
literal version strings, so every patch bump failed until somebody hand-edited
the test &ndash; and the practical result was that the bumps sat open, which is
worse than the drift it was written to prevent.</li>
</ul>
<hr>
<h2 id="improvements">Improvements</h2>
<ul>
<li><code>ci(deps)</code>: bump codeql-action to v4.37.7 and harden-runner to v2.21.0</li>
<li><code>ci(deps)</code>: carry the action bumps into the templates, example and docs</li>
<li><code>deps</code>: bump ruff from 0.16.1 to 0.16.4</li>
<li><code>deps</code>: bump esbuild from 0.28.1 to 0.28.2 in gitpage</li>
<li><code>test(gitpage)</code>: hold the build pins by property instead of by literal version</li>
</ul>
<hr>
<h2 id="notes">Notes</h2>
<ul>
<li>The gitpage guard now requires the declared range to be a caret on an exact
version, the lockfile to resolve to that same version, Tailwind to stay on
major 4, and esbuild to stay on 0.28. Comparing the declaration against the
lockfile is a stronger reproducibility check than comparing both to a
constant, and the Tailwind boundary is the incident the guard was born from.</li>
<li><code>templates/workflows/security.yml</code> and
<code>templates/workflows/oss-policy-kit-marketplace-action.yml</code> are reference
copies in the repository, not package data. The wheel carries only the three
<code>github-oss-policy-check</code> templates, which already used the new pins, so
<code>init --with-workflow</code> is unaffected by that part of this release.</li>
<li>The container image was rebuilt from an unchanged Dockerfile. Its contents
are the same as v10.0.16 apart from the kit version itself.</li>
</ul>
<hr>
<p><strong>License:</strong> Apache-2.0.</p>
]]></content:encoded></item><item><title>Goal-Driven AI PR Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/goal-driven-ai-pr-reviewer/</link><pubDate>Tue, 25 Aug 2026 06:10:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/goal-driven-ai-pr-reviewer/</guid><description>Version updated for https://github.com/markhuangai/ai-pr-reviewer to version v1.1.5.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the review process by leveraging the Claude Agent SDK to generate AI reviews for pull requests in any repository. It ensures that each review runs in an isolated session and is based on a pristine head checkout, using read-only tools to inspect the repository’s history without affecting the current state. The action allows specifying multiple prompts for different types of checks and handles sensitive information securely through environment variables or secrets.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/markhuangai/ai-pr-reviewer">https://github.com/markhuangai/ai-pr-reviewer</a></strong> to version <strong>v1.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/goal-driven-ai-pr-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the review process by leveraging the Claude Agent SDK to generate AI reviews for pull requests in any repository. It ensures that each review runs in an isolated session and is based on a pristine head checkout, using read-only tools to inspect the repository&rsquo;s history without affecting the current state. The action allows specifying multiple prompts for different types of checks and handles sensitive information securely through environment variables or secrets.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Improve reviewer context and evidence access by @Z-M-Huang in <a href="https://github.com/markhuangai/ai-pr-reviewer/pull/22">https://github.com/markhuangai/ai-pr-reviewer/pull/22</a></li>
<li>Enforce 1,000-line file limit by @Z-M-Huang in <a href="https://github.com/markhuangai/ai-pr-reviewer/pull/24">https://github.com/markhuangai/ai-pr-reviewer/pull/24</a></li>
<li>Set Claude API timeouts for review sessions by @Z-M-Huang in <a href="https://github.com/markhuangai/ai-pr-reviewer/pull/25">https://github.com/markhuangai/ai-pr-reviewer/pull/25</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/markhuangai/ai-pr-reviewer/compare/v1.1.4...v1.1.5">https://github.com/markhuangai/ai-pr-reviewer/compare/v1.1.4...v1.1.5</a></p>
]]></content:encoded></item><item><title>Apex Code Coverage Transformer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/apex-code-coverage-transformer/</link><pubDate>Tue, 25 Aug 2026 06:09:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/apex-code-coverage-transformer/</guid><description>Version updated for https://github.com/mcarvin8/apex-code-coverage-transformer to version v3.1.4.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Apex Code Coverage Transformer is a utility that transforms Apex code coverage JSON files generated by Salesforce CLI into various formats (SonarQube, Codecov, GitHub, GitLab, Azure DevOps, Bitbucket) to facilitate integration with CI/CD pipelines and other tools. It automates the process of preparing code coverage reports for different platforms, making it easier to monitor and visualize test coverage across pull requests and development environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcarvin8/apex-code-coverage-transformer">https://github.com/mcarvin8/apex-code-coverage-transformer</a></strong> to version <strong>v3.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/apex-code-coverage-transformer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Apex Code Coverage Transformer is a utility that transforms Apex code coverage JSON files generated by Salesforce CLI into various formats (SonarQube, Codecov, GitHub, GitLab, Azure DevOps, Bitbucket) to facilitate integration with CI/CD pipelines and other tools. It automates the process of preparing code coverage reports for different platforms, making it easier to monitor and visualize test coverage across pull requests and development environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="314-2026-08-24"><a href="https://github.com/mcarvin8/apex-code-coverage-transformer/compare/v3.1.3...v3.1.4">3.1.4</a> (2026-08-24)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> bump the dependencies group across 1 directory with 3 updates (<a href="https://github.com/mcarvin8/apex-code-coverage-transformer/issues/390">#390</a>) (<a href="https://github.com/mcarvin8/apex-code-coverage-transformer/commit/7b3c806bc9c000964d3ae0aab9cbc7a2968c24d4">7b3c806</a>)</li>
</ul>
]]></content:encoded></item><item><title>SF Decomposer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sf-decomposer/</link><pubDate>Tue, 25 Aug 2026 06:07:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sf-decomposer/</guid><description>Version updated for https://github.com/mcarvin8/sf-decomposer to version v7.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action, sf-decomposer, automates the process of breaking down large Salesforce metadata XML files into smaller, more manageable pieces for version control and deployment. It supports decompiling and recomposing metadata in various formats like XML, JSON, YAML, and JSON5. The action runs as a standalone tool without requiring the Salesforce CLI or plugin installation, making it suitable for CI/CD environments where these tools are not available.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcarvin8/sf-decomposer">https://github.com/mcarvin8/sf-decomposer</a></strong> to version <strong>v7.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sf-decomposer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action, <code>sf-decomposer</code>, automates the process of breaking down large Salesforce metadata XML files into smaller, more manageable pieces for version control and deployment. It supports decompiling and recomposing metadata in various formats like XML, JSON, YAML, and JSON5. The action runs as a standalone tool without requiring the Salesforce CLI or plugin installation, making it suitable for CI/CD environments where these tools are not available.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="730-2026-08-24"><a href="https://github.com/mcarvin8/sf-decomposer/compare/v7.2.0...v7.3.0">7.3.0</a> (2026-08-24)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>action:</strong> add a GitHub Action wrapping decompose/recompose/verify (<a href="https://github.com/mcarvin8/sf-decomposer/issues/572">#572</a>) (<a href="https://github.com/mcarvin8/sf-decomposer/commit/b32391dff7dd2d77868b4a67cc70f7563dd1e55b">b32391d</a>)</li>
</ul>
]]></content:encoded></item><item><title>Falsifying Swarm Orchestrator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/falsifying-swarm-orchestrator/</link><pubDate>Tue, 25 Aug 2026 06:06:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/falsifying-swarm-orchestrator/</guid><description>Version updated for https://github.com/moonrunnerkc/swarm-orchestrator to version v13.1.9.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of orchestrating tasks within a Git workspace. It uses machine-captured evidence to verify claims about task execution and record every tool call. Key capabilities include planning tasks, tracking file modifications, running gates to validate the integrity of the work, and exporting signed, hash-chained bundles for verification by anyone without installing the tool.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/moonrunnerkc/swarm-orchestrator">https://github.com/moonrunnerkc/swarm-orchestrator</a></strong> to version <strong>v13.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/falsifying-swarm-orchestrator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of orchestrating tasks within a Git workspace. It uses machine-captured evidence to verify claims about task execution and record every tool call. Key capabilities include planning tasks, tracking file modifications, running gates to validate the integrity of the work, and exporting signed, hash-chained bundles for verification by anyone without installing the tool.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<pre><code>npm install -g swarm-orchestrator
</code></pre>
<p>A line that says the run is alive and what it is doing: a spinner that turns, the current activity, how long it has been going, and while the model is talking, the tail of what it is saying.</p>
<pre tabindex="0"><code>⠙ thinking, step 2  5s   I don&#39;t see calculator.js in the root directory
⠹ shell npm test  12s
</code></pre><p>Nothing on the screen moved before this. The model&rsquo;s text was already being streamed and thrown away; it is handed on now, one line of it.</p>
]]></content:encoded></item><item><title>Otzaria Plugin Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/otzaria-plugin-validator/</link><pubDate>Tue, 25 Aug 2026 06:05:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/otzaria-plugin-validator/</guid><description>Version updated for https://github.com/Otzaria/otzaria-plugin-validator to version v1.15.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of validating and publishing Otzaria plugins to their store. It performs basic checks, builds the plugin, and uploads it automatically when a push is made to the main branch. The action uses two Secrets (OTZARIA_USER and OTZARIA_PASSWORD) for authentication. It also supports PR validation without publishing, with options to fail on warnings and set specific app version checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Otzaria/otzaria-plugin-validator">https://github.com/Otzaria/otzaria-plugin-validator</a></strong> to version <strong>v1.15.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/otzaria-plugin-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of validating and publishing Otzaria plugins to their store. It performs basic checks, builds the plugin, and uploads it automatically when a push is made to the <code>main</code> branch. The action uses two Secrets (<code>OTZARIA_USER</code> and <code>OTZARIA_PASSWORD</code>) for authentication. It also supports PR validation without publishing, with options to fail on warnings and set specific app version checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.15.0 — הוולידטור כחבילה הקובעת, ויישור מלא מול האפליקציה by @palmoni5 in <a href="https://github.com/Otzaria/otzaria-plugin-validator/pull/2">https://github.com/Otzaria/otzaria-plugin-validator/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Otzaria/otzaria-plugin-validator/compare/v1.14.1...v1.15.0">https://github.com/Otzaria/otzaria-plugin-validator/compare/v1.14.1...v1.15.0</a></p>
]]></content:encoded></item><item><title>setup-openapi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/setup-openapi/</link><pubDate>Tue, 25 Aug 2026 06:03:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/setup-openapi/</guid><description>Version updated for https://github.com/remarkablemark/setup-openapi to version v1.1.13.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-openapi GitHub Action installs the OpenAPI Generator CLI, caches it by version, and exposes the binary. It automates setting up an environment for generating client code from OpenAPI specifications in various languages such as Ruby. The action supports specifying a custom version of the CLI and allows configuring its binary name through inputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablemark/setup-openapi">https://github.com/remarkablemark/setup-openapi</a></strong> to version <strong>v1.1.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-openapi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The setup-openapi GitHub Action installs the OpenAPI Generator CLI, caches it by version, and exposes the binary. It automates setting up an environment for generating client code from OpenAPI specifications in various languages such as Ruby. The action supports specifying a custom version of the CLI and allows configuring its binary name through inputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1113-2026-08-25"><a href="https://github.com/remarkablemark/setup-openapi/compare/v1.1.12...v1.1.13">1.1.13</a> (2026-08-25)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump openapi-generator-cli from 7.24.0 to 7.25.0 (<a href="https://github.com/remarkablemark/setup-openapi/issues/36">#36</a>) (<a href="https://github.com/remarkablemark/setup-openapi/commit/b892ec9f8e965b0d3ed367c58107687038eca818">b892ec9</a>)</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/kaniko-build-action/</link><pubDate>Tue, 25 Aug 2026 06:03:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, “Hello world docker action,” automates the process of greeting a user with either “Hello World” or “Hello [name]” by printing it to the log. It provides an easy way to include personalized greetings in your workflows without requiring custom setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, &ldquo;Hello world docker action,&rdquo; automates the process of greeting a user with either &ldquo;Hello World&rdquo; or &ldquo;Hello [name]&rdquo; by printing it to the log. It provides an easy way to include personalized greetings in your workflows without requiring custom setup.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>KeyHog Secret Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/keyhog-secret-scanner/</link><pubDate>Tue, 25 Aug 2026 06:02:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/keyhog-secret-scanner/</guid><description>Version updated for https://github.com/santhreal/keyhog to version v0.5.85.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary KeyHog is an open-source secret scanner written in Rust that scans code, Git history, cloud storage, containers, browser assets, and CI systems to find and verify leaked API keys, tokens, passwords, and credentials. It uses a combination of 934 service-specific detectors, decode-through for concealed credentials, context-aware evidence and suppression, live provider verification, and GPU acceleration through Vyre, a Rust-based GPU compute substrate.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/santhreal/keyhog">https://github.com/santhreal/keyhog</a></strong> to version <strong>v0.5.85</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/keyhog-secret-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>KeyHog is an open-source secret scanner written in Rust that scans code, Git history, cloud storage, containers, browser assets, and CI systems to find and verify leaked API keys, tokens, passwords, and credentials. It uses a combination of 934 service-specific detectors, decode-through for concealed credentials, context-aware evidence and suppression, live provider verification, and GPU acceleration through Vyre, a Rust-based GPU compute substrate.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>fix(ci): increase release runner timeout to 120 minutes.</li>
</ul>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/agentauditkit-mcp-security-scan/</link><pubDate>Tue, 25 Aug 2026 06:01:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.88.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit automates the process of identifying misconfigurations, hardcoded secrets, and other security issues in AI agent pipelines. It ensures that your codebase is secure by scanning it offline and deterministically, without relying on external models or network calls. AgentAuditKit supports 10 different agent platforms and can detect vulnerabilities such as remote server with no authentication, inline-auth configs with static credentials, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.88</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>AgentAuditKit automates the process of identifying misconfigurations, hardcoded secrets, and other security issues in AI agent pipelines. It ensures that your codebase is secure by scanning it offline and deterministically, without relying on external models or network calls. AgentAuditKit supports 10 different agent platforms and can detect vulnerabilities such as remote server with no authentication, inline-auth configs with static credentials, and more.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.88
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.88
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.88</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.87...v0.3.88">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.87...v0.3.88</a></p>
]]></content:encoded></item><item><title>SchemaCrawler (Local) Action for GitHub Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/schemacrawler-local-action-for-github-actions/</link><pubDate>Tue, 25 Aug 2026 06:00:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/schemacrawler-local-action-for-github-actions/</guid><description>Version updated for https://github.com/schemacrawler/SchemaCrawler-Local-Action to version v17.14.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automates the generation of a database schema report using SchemaCrawler on a Linux-based runner. It solves the problem of automating database schema analysis and visualization within a GitHub Actions workflow. The key capabilities include running SchemaCrawler locally, providing a report in various formats (e.g., HTML), and integrating with GitHub Actions for continuous integration and deployment processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/schemacrawler/SchemaCrawler-Local-Action">https://github.com/schemacrawler/SchemaCrawler-Local-Action</a></strong> to version <strong>v17.14.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/schemacrawler-local-action-for-github-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action automates the generation of a database schema report using SchemaCrawler on a Linux-based runner. It solves the problem of automating database schema analysis and visualization within a GitHub Actions workflow. The key capabilities include running SchemaCrawler locally, providing a report in various formats (e.g., HTML), and integrating with GitHub Actions for continuous integration and deployment processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>SchemaCrawler (Local) Action v17.14.1 release at last commit 3ef79c7f8cd3e22f43c373ee4a0377b6b85d3eac
See the change history at <a href="https://www.schemacrawler.com/changes-report.html">https://www.schemacrawler.com/changes-report.html</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump actions/setup-java from 5 to 5.6.0 by @dependabot[bot] in <a href="https://github.com/schemacrawler/SchemaCrawler-Local-Action/pull/6">https://github.com/schemacrawler/SchemaCrawler-Local-Action/pull/6</a></li>
<li>v17.14.1 by @sualeh in <a href="https://github.com/schemacrawler/SchemaCrawler-Local-Action/pull/7">https://github.com/schemacrawler/SchemaCrawler-Local-Action/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/schemacrawler/SchemaCrawler-Local-Action/compare/v17.12.2...v17.14.1">https://github.com/schemacrawler/SchemaCrawler-Local-Action/compare/v17.12.2...v17.14.1</a></p>
]]></content:encoded></item><item><title>Scratchsmith</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/scratchsmith/</link><pubDate>Tue, 25 Aug 2026 05:59:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/scratchsmith/</guid><description>Version updated for https://github.com/schubydoo/scratchsmith to version v0.1.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action is designed to package dynamically linked glibc ELF binaries into minimal FROM scratch OCI images. It resolves shared libraries using ld.so, stages necessary glibc components, and assembles a non-root image with reproducible layers. The primary purpose of Scratchsmith is to handle binaries that require glibc functionality but cannot be statically linked, providing an alternative packer for such cases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/schubydoo/scratchsmith">https://github.com/schubydoo/scratchsmith</a></strong> to version <strong>v0.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/scratchsmith">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action is designed to package dynamically linked glibc ELF binaries into minimal <code>FROM scratch</code> OCI images. It resolves shared libraries using <code>ld.so</code>, stages necessary glibc components, and assembles a non-root image with reproducible layers. The primary purpose of Scratchsmith is to handle binaries that require glibc functionality but cannot be statically linked, providing an alternative packer for such cases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="features">Features</h2>
<h3 id="homebrew-tap--brew-install-schubydooscratchsmithscratchsmith-30">Homebrew tap — <code>brew install schubydoo/scratchsmith/scratchsmith</code> (<a href="https://github.com/schubydoo/scratchsmith/pull/30">#30</a>)</h3>
<p>Scratchsmith is now installable via a Homebrew tap (Linux amd64/arm64, from the signed
release tarballs). The formula (<code>Formula/scratchsmith.rb</code>) is regenerated from each
release&rsquo;s cosign-verified <code>checksums.txt</code> by <code>packaging-bump.yml</code>, which opens an
auto-merging PR; that merge dispatches the <a href="https://github.com/schubydoo/homebrew-scratchsmith">tap</a>
to mirror it — so <code>brew upgrade</code> tracks releases hands-free.</p>
]]></content:encoded></item><item><title>SFDT for Salesforce</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sfdt-for-salesforce/</link><pubDate>Tue, 25 Aug 2026 05:58:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sfdt-for-salesforce/</guid><description>Version updated for https://github.com/scoobydrew83/sfdt to version v0.23.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the deployment, testing, and release management of Salesforce changes using the SFDT CLI. It provides interactive workflows with preflight validation, tagging, PR creation, automated release manifest generation, parallel Apex test execution, code and test quality analysis, and AI-powered feature suggestions for improved efficiency and reliability in Salesforce development.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scoobydrew83/sfdt">https://github.com/scoobydrew83/sfdt</a></strong> to version <strong>v0.23.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdt-for-salesforce">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the deployment, testing, and release management of Salesforce changes using the SFDT CLI. It provides interactive workflows with preflight validation, tagging, PR creation, automated release manifest generation, parallel Apex test execution, code and test quality analysis, and AI-powered feature suggestions for improved efficiency and reliability in Salesforce development.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: release CLI v0.23.0, extension v0.14.0, VS Code v0.7.0 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/339">https://github.com/scoobydrew83/sfdt/pull/339</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scoobydrew83/sfdt/compare/v0.22.2...v0.23.0">https://github.com/scoobydrew83/sfdt/compare/v0.22.2...v0.23.0</a></p>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Tue, 25 Aug 2026 05:57:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The deploy-swarm-service GitHub Action automates the deployment process for a web application running on Docker Swarm. It ensures that the project is ready to be pushed and deployed by installing dependencies and bundling the frontend, which are then committed to the repository. This helps in streamlining the build and release automation pipeline for the application.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>deploy-swarm-service</code> GitHub Action automates the deployment process for a web application running on Docker Swarm. It ensures that the project is ready to be pushed and deployed by installing dependencies and bundling the frontend, which are then committed to the repository. This helps in streamlining the build and release automation pipeline for the application.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/ssg-static-site-generator/</link><pubDate>Tue, 25 Aug 2026 05:56:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.49.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: SSG is a fast, versatile static site generator written in Go. It transforms Markdown content into a complete website with features such as built-in themes and templates, SEO metadata, and image processing. Key capabilities include building sitemaps, feeds, search indexes, and deploying to various platforms like GitHub Pages and Netlify.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.49</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> SSG is a fast, versatile static site generator written in Go. It transforms Markdown content into a complete website with features such as built-in themes and templates, SEO metadata, and image processing. Key capabilities include building sitemaps, feeds, search indexes, and deploying to various platforms like GitHub Pages and Netlify.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.49 — MDDB auth, private networks, real search loci, and context that does not grow to the file by @spagu in <a href="https://github.com/spagu/ssg/pull/206">https://github.com/spagu/ssg/pull/206</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.48...v1.8.49">https://github.com/spagu/ssg/compare/v1.8.48...v1.8.49</a></p>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/runward-gate/</link><pubDate>Tue, 25 Aug 2026 05:55:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.36.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is an open-source delivery methodology for AI-assisted software engineering that verifies the engineering decisions behind AI-written code. It automates the verification of architectural choices, deployment strategies, security measures, and other critical aspects of system design to ensure they are implemented correctly. Runward ensures that each step in the development process is documented and executable, providing a way to verify the integrity and correctness of complex systems without relying solely on AI-generated code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.36.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Runward is an open-source delivery methodology for AI-assisted software engineering that verifies the engineering decisions behind AI-written code. It automates the verification of architectural choices, deployment strategies, security measures, and other critical aspects of system design to ensure they are implemented correctly. Runward ensures that each step in the development process is documented and executable, providing a way to verify the integrity and correctness of complex systems without relying solely on AI-generated code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Two more false greens in the spelling ladder, both live since 0.32.0 and 0.34.0 — and neither reachable by reading the code. One needed a permission state nobody creates by accident; the other needed a filesystem the author does not have.</strong></p>
<h3 id="the-false-greens">The false greens</h3>
<ul>
<li><strong>A directory the gate could not list silently cleared the case check</strong> (RWD-2026-0029). <code>onDiskSpelling</code> returns <code>null</code> for <em>&ldquo;the spelling already matches&rdquo;</em>, and its <code>catch</code> returned <code>null</code> too — so <em>&ldquo;I could not check&rdquo;</em> and <em>&ldquo;it is fine&rdquo;</em> were the same answer. Measured: <code>file:./src/Guard.TS</code> citing a file spelled <code>guard.ts</code> is refused with the directory at <code>0755</code> and <strong>passes at <code>0111</code></strong>, on a filesystem where it resolves only because the filesystem is forgiving. One permission bit cleared the check for everything beneath it. An unverifiable spelling is now its own answer and a named violation — where the gate cannot verify, it says so in the run (<a href="docs/adr/ADR-0045-the-gate-cannot-be-satisfied-by-paperwork.md">ADR-0045</a>).</li>
<li><strong>On Windows, a redundant <code>./</code> defeated the check entirely</strong> (RWD-2026-0030). There <code>onDiskSpelling</code> is already defeated by 8.3 short names (<code>RUNNER~1</code> against the long name the parent directory lists), which is why <code>spellingViaRealpath</code> exists — so it is the <strong>only rung left</strong>, and its failure is the whole ladder&rsquo;s. It compared the operator&rsquo;s raw cell against a canonical suffix: <code>.\src\Guard.TS</code> versus <code>src\guard.ts</code>. The comparison failed on the <em>prefix</em> rather than on the <em>case</em>, and &ldquo;no difference&rdquo; is what a caller reads as &ldquo;correctly spelled&rdquo;. Measured on the windows-latest leg: <code>file:src/Guard.TS</code> refused, the same pointer written <code>file:./src/Guard.TS</code> accepted, same tree. macOS caught both forms all along, which is precisely why nothing before that leg could see it.</li>
</ul>
<p>Both are a green on the author&rsquo;s machine that turns red on a case-sensitive runner — the surprise that makes people stop trusting a gate.</p>
<h3 id="the-tool-adapter-routing-is-guarded">The tool-adapter routing is guarded</h3>
<p><code>tool-adapters.test.js</code> proved each committed-tool adapter answers correctly <strong>when called</strong>. Nothing proved the gate <em>calls</em> it, or <em>acts</em> on the answer: 27 mutants sat on that routing and survived the unit suite and the whole net. They <strong>move</strong> a verdict rather than remove it — a coverage report routed to the lint branch still produces a violation, just the wrong one, and a test that only checks &ldquo;something was raised&rdquo; passes.</p>
<p>A matrix now covers 4 adapters × every state they can return, each asserting the failure <strong>class</strong> and never the wording, each with the mirror state that must stay silent. Plus the structural cases: the same SARIF body under three filenames routes identically (<a href="docs/adr/ADR-0056-committed-tool-artifacts-as-evidence.md">ADR-0056</a> recognises shape, never extension), and an ordinary source file still reaches the symbol check. <strong>Measured after: 73 mutants in that range, 73 killed.</strong></p>
<h3 id="also">Also</h3>
<ul>
<li>The mutation instrument&rsquo;s concurrency is set from a measurement rather than from the core count: the unit suite uses <strong>310 % CPU</strong>, so each worker costs ~3 cores and the ceiling on 8 cores is two. Getting this wrong always errs toward flattery, because a starved run is filed as a caught mutant.</li>
<li>Tests that depend on filesystem behaviour now <strong>probe</strong> the capability — case-insensitivity, and whether this process can be denied a directory listing — instead of inferring it from <code>process.platform</code>. A case-sensitive volume on macOS and a root container on Linux both exist.</li>
</ul>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/delivery-autopilot-runner/</link><pubDate>Tue, 25 Aug 2026 05:54:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.34.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action, Delivery Autopilot Runner, automates the process of creating pull requests from tickets managed by Delivery Autopilot. It leverages AI to write code based on the ticket details and runs quality checks within a user’s GitHub repository. The action requires an active subscription from Tekunda, which initiates it through a signed instruction. Once executed, it checks out the repository, writes code using the AI model, performs quality checks, opens a pull request, and reports the status back to Delivery Autopilot. This action ensures that the workflow is controlled by the user’s GitHub Actions infrastructure while delivering software development tasks efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.34</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action, Delivery Autopilot Runner, automates the process of creating pull requests from tickets managed by Delivery Autopilot. It leverages AI to write code based on the ticket details and runs quality checks within a user&rsquo;s GitHub repository. The action requires an active subscription from Tekunda, which initiates it through a signed instruction. Once executed, it checks out the repository, writes code using the AI model, performs quality checks, opens a pull request, and reports the status back to Delivery Autopilot. This action ensures that the workflow is controlled by the user&rsquo;s GitHub Actions infrastructure while delivering software development tasks efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runner-dist synced from AutoPilot 998badb2d40b. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>Rabbit Automation Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/rabbit-automation-action/</link><pubDate>Tue, 25 Aug 2026 05:53:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/rabbit-automation-action/</guid><description>Version updated for https://github.com/udx/github-rabbit-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of cloud infrastructure using Terraform across AWS, GCP, and Kubernetes based on YAML configuration files in a .rabbit/ directory. It handles lifecycle management and provides options to plan or apply infrastructure changes programmatically.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/udx/github-rabbit-action">https://github.com/udx/github-rabbit-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rabbit-automation-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of cloud infrastructure using Terraform across AWS, GCP, and Kubernetes based on YAML configuration files in a <code>.rabbit/</code> directory. It handles lifecycle management and provides options to plan or apply infrastructure changes programmatically.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Added release verification, workflow linting, and a production release
workflow that validates and publishes each new semantic version.</li>
<li>Enforced ShellCheck error checks and corrected lifecycle-root discovery.</li>
</ul>
]]></content:encoded></item><item><title>Sentinel Scan (MCP/LLM security)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sentinel-scan-mcp/llm-security/</link><pubDate>Tue, 25 Aug 2026 05:51:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/sentinel-scan-mcp/llm-security/</guid><description>Version updated for https://github.com/Ventrova/sentinel-scan-cli to version v1.4.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates security audits of LLM apps and MCP servers by scanning them for security issues using a 15-attack prompt-injection suite. It detects vulnerabilities in endpoint policies, tool descriptions, and manifest files, ensuring compliance with OWASP guidelines. The action is designed to be user-friendly and requires minimal setup, with options for both local testing (--demo) and real-world scans against the target endpoint.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Ventrova/sentinel-scan-cli">https://github.com/Ventrova/sentinel-scan-cli</a></strong> to version <strong>v1.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sentinel-scan-mcp-llm-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates security audits of LLM apps and MCP servers by scanning them for security issues using a 15-attack prompt-injection suite. It detects vulnerabilities in endpoint policies, tool descriptions, and manifest files, ensuring compliance with OWASP guidelines. The action is designed to be user-friendly and requires minimal setup, with options for both local testing (<code>--demo</code>) and real-world scans against the target endpoint.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Marketplace listing fix: shortened the GitHub Action description to under 125 chars so <code>Ventrova/sentinel-scan-cli</code> can be published to the GitHub Marketplace. No change to the scanner or action behavior; same 15-attack corpus + MCP manifest heuristics as v1.4.1. Install: <code>npx sentinel-scan-cli</code> / <code>pip install sentinel-scan-cli</code> / <code>uses: Ventrova/sentinel-scan-cli@v1.4.2</code>.</p>
]]></content:encoded></item><item><title>Plumb Diff Coverage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/plumb-diff-coverage/</link><pubDate>Tue, 25 Aug 2026 05:50:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/plumb-diff-coverage/</guid><description>Version updated for https://github.com/z3le/plumb to version v0.1.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The plumb action is a tool that measures code coverage of lines changed in a Git repository and reports it as an HTML file. It calculates the coverage against the initial commit of the branch, fails the build if the coverage falls below a specified threshold, and provides a sortable, line-by-line source view with covered and uncovered lines highlighted in green and red, respectively. The action is designed to be simple, efficient, and integrates seamlessly into GitHub Actions workflows, requiring minimal configuration and no external services or tokens.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/z3le/plumb">https://github.com/z3le/plumb</a></strong> to version <strong>v0.1.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/plumb-diff-coverage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>plumb</code> action is a tool that measures code coverage of lines changed in a Git repository and reports it as an HTML file. It calculates the coverage against the initial commit of the branch, fails the build if the coverage falls below a specified threshold, and provides a sortable, line-by-line source view with covered and uncovered lines highlighted in green and red, respectively. The action is designed to be simple, efficient, and integrates seamlessly into GitHub Actions workflows, requiring minimal configuration and no external services or tokens.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>The action is called <code>Plumb Diff Coverage</code> in the GitHub Marketplace. The
Marketplace requires a name unique across every action, user, and
organisation on GitHub, and a user named <code>plumb</code> has existed since 2013, so
it refused the bare project name. Only the display name changed:
<code>uses: z3le/plumb@v0.1.7</code> is the repository path and is unaffected.</li>
</ul>
]]></content:encoded></item><item><title>Code Rot Hotspots</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/code-rot-hotspots/</link><pubDate>Tue, 25 Aug 2026 05:49:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/25/code-rot-hotspots/</guid><description>Version updated for https://github.com/zubairriaz/hotspot-tool to version v1.4.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action hotspot-tool identifies and flags files that are both frequently changed and complex, potentially introducing bugs into your codebase. It runs inside CI runners without exposing sensitive source code to the internet, focusing on behaviors and complexity metrics to help identify and address performance issues in pull requests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zubairriaz/hotspot-tool">https://github.com/zubairriaz/hotspot-tool</a></strong> to version <strong>v1.4.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/code-rot-hotspots">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>hotspot-tool</code> identifies and flags files that are both frequently changed and complex, potentially introducing bugs into your codebase. It runs inside CI runners without exposing sensitive source code to the internet, focusing on behaviors and complexity metrics to help identify and address performance issues in pull requests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v149--2026-08-24">v1.4.9 — 2026-08-24</h2>
<ul>
<li>fix: shorten action description to under 125 chars for Marketplace (191d468)</li>
</ul>
]]></content:encoded></item><item><title>file-search-on review gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/file-search-on-review-gate/</link><pubDate>Mon, 24 Aug 2026 22:59:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/file-search-on-review-gate/</guid><description>Version updated for https://github.com/richardwooding/file-search-on to version v0.119.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The file-search-on GitHub Action is a content-type-aware file search tool that leverages CEL (Cloud Execution Language) expressions to filter files based on metadata and content type-specific attributes. It supports 74 file formats across thirteen content-type families, including PDFs, images, audio, video, office documents, eBooks, plain text, archives, compiled binaries, email messages, and source code. The tool can be used to query files in a directory tree by typed content-type attributes directly from Claude Code or as a standalone CLI utility.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/richardwooding/file-search-on">https://github.com/richardwooding/file-search-on</a></strong> to version <strong>v0.119.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/file-search-on-review-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>file-search-on</code> GitHub Action is a content-type-aware file search tool that leverages CEL (Cloud Execution Language) expressions to filter files based on metadata and content type-specific attributes. It supports 74 file formats across thirteen content-type families, including PDFs, images, audio, video, office documents, eBooks, plain text, archives, compiled binaries, email messages, and source code. The tool can be used to query files in a directory tree by typed content-type attributes directly from Claude Code or as a standalone CLI utility.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="others">Others</h3>
<ul>
<li>d9cd688270c824f606e49036444c34a6f139906c chore(deps): Bump modernc.org/sqlite in the minor-and-patch group (#572)</li>
<li>d7ee60a014718a689e3d2cbe2286cf6b578b7433 chore(deps): Bump the minor-and-patch group with 5 updates (#570)</li>
<li>d6a194b72b8dc48f0e9aa7bcfca15bdf57b770ce chore(deps): bump codemetrics to v0.12.7, treesitter-symbols to v0.6.6</li>
<li>2a37dc42e6cfed49a5c8d5e24e7de0a54e70ed79 ci: only fail fuzz jobs on reproducible failures; add VHDX regression input (#571)</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/kaniko-build-action/</link><pubDate>Mon, 24 Aug 2026 22:58:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Hello World Docker Action, prints a greeting message to the console. It can be configured to greet a specific person by providing their name as an input. The action also includes a timestamp of when it executed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Hello World Docker Action, prints a greeting message to the console. It can be configured to greet a specific person by providing their name as an input. The action also includes a timestamp of when it executed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>Malware Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/malware-scan/</link><pubDate>Mon, 24 Aug 2026 22:58:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/malware-scan/</guid><description>Version updated for https://github.com/SalemCode8/malware-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action scans a repository’s changed or full file set for malware and supply-chain attacks using three independent engines. It automatically detects known malware signatures, dependency name typos, suspicious install hooks, executable payloads, credentials near network calls, new native binaries, and tampered workflow files. The findings are reported as pull request annotations, job summary tables, and optionally uploaded to code scanning.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SalemCode8/malware-scan-action">https://github.com/SalemCode8/malware-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/malware-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action scans a repository&rsquo;s changed or full file set for malware and supply-chain attacks using three independent engines. It automatically detects known malware signatures, dependency name typos, suspicious install hooks, executable payloads, credentials near network calls, new native binaries, and tampered workflow files. The findings are reported as pull request annotations, job summary tables, and optionally uploaded to code scanning.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Enhance security scanning with new features and fixes by @SalemCode8 in <a href="https://github.com/SalemCode8/malware-scan-action/pull/1">https://github.com/SalemCode8/malware-scan-action/pull/1</a></li>
<li>Take the current majors of the @actions toolkit by @SalemCode8 in <a href="https://github.com/SalemCode8/malware-scan-action/pull/2">https://github.com/SalemCode8/malware-scan-action/pull/2</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@SalemCode8 made their first contribution in <a href="https://github.com/SalemCode8/malware-scan-action/pull/1">https://github.com/SalemCode8/malware-scan-action/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SalemCode8/malware-scan-action/commits/v1">https://github.com/SalemCode8/malware-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/custom-amazon-bedrock-agent-action/</link><pubDate>Mon, 24 Aug 2026 22:56:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide feedback. It is customizable and integrates with Amazon Bedrock Knowledge Bases for enhanced context-aware insights. The action automates code quality improvement, security assessments, and performance optimizations by processing PR files using tailored prompts and leveraging knowledge bases for accurate analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide feedback. It is customizable and integrates with Amazon Bedrock Knowledge Bases for enhanced context-aware insights. The action automates code quality improvement, security assessments, and performance optimizations by processing PR files using tailored prompts and leveraging knowledge bases for accurate analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Muninn Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/muninn-security-scanner/</link><pubDate>Mon, 24 Aug 2026 22:55:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/muninn-security-scanner/</guid><description>Version updated for https://github.com/skaldlab/muninn to version v0.3.10.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Muninn is an open-source security scanning tool for GitHub Actions pipelines and self-hosted CI that automates security testing across multiple tools. It integrates eight renowned scanners into a single workflow to identify vulnerabilities in code, dependencies, and configurations. Muninn normalizes findings into a unified format, posts comments, uploads SARIF files, and fails checks based on user-defined thresholds.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skaldlab/muninn">https://github.com/skaldlab/muninn</a></strong> to version <strong>v0.3.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/muninn-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Muninn is an open-source security scanning tool for GitHub Actions pipelines and self-hosted CI that automates security testing across multiple tools. It integrates eight renowned scanners into a single workflow to identify vulnerabilities in code, dependencies, and configurations. Muninn normalizes findings into a unified format, posts comments, uploads SARIF files, and fails checks based on user-defined thresholds.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="changelog">Changelog</h1>
<h2 id="unreleased">[Unreleased]</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>checkov remains pinned at <code>3.2.531</code>: <code>3.2.532+</code> and <code>3.3.x</code> reintroduce
transitive <code>ecdsa</code> (<code>&gt;=0.19.0,&lt;1.0.0</code>), currently affected by
<code>PYSEC-2026-1325</code> / <code>CVE-2024-23342</code> with no fixed release yet.</li>
<li>The secure <code>aiohttp&gt;=3.14.3</code> floor remains enforced.</li>
</ul>
<h2 id="0310---2026-08-24">[0.3.10] - 2026-08-24</h2>
<h3 id="changed-1">Changed</h3>
<ul>
<li>Docker image updates: semgrep <code>1.174.0</code>, pydantic-settings <code>2.15.0</code>,
<code>python:3.14.7-slim</code>.</li>
<li>asteval floor raised to &gt;=1.0.10 (hashed override) for GHSA-89v8-rhwq-hf77
(CVE-2026-55244) and GHSA-9w56-46f6-3qhx; checkov 3.2.531 still requires
asteval 1.0.6.</li>
<li>Go toolchain bumped to 1.26.6 (matches <code>golang:1.26.6-alpine</code> builder).</li>
<li>checkov remains at <code>3.2.531</code> pending a fixed ecdsa or checkov constraint change.</li>
</ul>
<h2 id="039---2026-08-19">[0.3.9] - 2026-08-19</h2>
<h3 id="changed-2">Changed</h3>
<ul>
<li>Scanner dependency updates: osv-scanner <code>2.5.1</code>, trivy <code>0.74.0</code>,
semgrep <code>1.173.0</code>.</li>
<li>checkov remains pinned at <code>3.2.531</code>: <code>3.2.532+</code> and <code>3.3.x</code> reintroduce
transitive <code>ecdsa</code> (<code>&gt;=0.19.0,&lt;1.0.0</code>), currently affected by
<code>PYSEC-2026-1325</code> / <code>CVE-2024-23342</code> with no fixed ecdsa release yet.</li>
<li>The secure <code>aiohttp&gt;=3.14.3</code> floor remains enforced.</li>
<li>Removed obsolete semgrep dependency overrides (<code>click</code>, <code>mcp</code>) after semgrep
upstream constraint updates; lockfile now resolves to <code>click 8.4.2</code> and
<code>mcp 1.29.0</code> without override pins.</li>
<li>Post-release follow-up: update all user-facing latest-version references
(website pages, README snippets, and docs examples) to the released tag.</li>
</ul>
<h2 id="038---2026-08-10">[0.3.8] - 2026-08-10</h2>
<h3 id="changed-3">Changed</h3>
<ul>
<li>Docker image scanner update: osv-scanner 2.5.0 (full osv-scalibr pipeline;
checkov remains at 3.2.531 pending aiohttp cap lift).</li>
<li>GitPython floor raised to &gt;=3.1.58 for GHSA-hmq2-w58f-27jc and related
3.1.58 hardening advisories (path traversal / unguarded git option sinks).</li>
</ul>
<h2 id="037---2026-08-04">[0.3.7] - 2026-08-04</h2>
<h3 id="changed-4">Changed</h3>
<ul>
<li>GitPython floor raised to &gt;=3.1.55 for GHSA-94p4-4cq8-9g67 (incomplete
expandvars fix in create_remote / Remote.add).</li>
<li>cryptography floor raised to &gt;=50.0.0 for GHSA-g6cj-pr64-35w5
(CVE-2026-69247: PKCS#7 EnvelopedData Bleichenbacher oracle).</li>
<li>aiohttp floor raised to &gt;=3.14.3; scanner lockfile recompiled with click 8.3.3
and mcp 1.28.1 security overrides.</li>
<li>Docker image scanner updates: trivy 0.73.0, semgrep 1.172.0, zizmor 1.29.0
(checkov remains at 3.2.531 pending aiohttp cap lift; 3.2.533+ also caps
<code>aiohttp&lt;3.14</code>).</li>
</ul>
<h2 id="036---2026-07-22">[0.3.6] - 2026-07-22</h2>
<h3 id="changed-5">Changed</h3>
<ul>
<li>Docker image scanner updates: zizmor 1.28.0 (replaces yanked 1.27.0);
GitPython floor raised to &gt;=3.1.52 for checkov-transitive GHSA highs
(checkov remains at 3.2.531 pending aiohttp cap lift).</li>
<li>Go toolchain bumped to 1.26.5.</li>
</ul>
<h2 id="035---2026-07-20">[0.3.5] - 2026-07-20</h2>
<h3 id="changed-6">Changed</h3>
<ul>
<li>Docker image scanner updates: semgrep 1.170.0, zizmor 1.27.0 (checkov
remains at 3.2.531 pending aiohttp cap lift).</li>
</ul>
<h2 id="034---2026-07-04">[0.3.4] - 2026-07-04</h2>
<h3 id="changed-7">Changed</h3>
<ul>
<li>Docker image scanner updates: osv-scanner 2.4.0, trivy 0.72.0, semgrep
1.168.0, zizmor 1.26.1 (checkov remains at 3.2.531 pending aiohttp cap lift).</li>
</ul>
<h2 id="033---2026-06-17">[0.3.3] - 2026-06-17</h2>
<h3 id="changed-8">Changed</h3>
<ul>
<li>Trivy default severity is now all levels (<code>UNKNOWN</code> through <code>CRITICAL</code>) instead
of <code>CRITICAL</code> and <code>HIGH</code> only. osv-scanner and trivy now overlap on
medium/low advisories by default so cross-scanner dedup and <code>Detected by</code>
work without extra config. Consumers can narrow the Trivy scan with
<code>scanners.trivy.severity</code>; <code>fail-on</code> still controls which findings fail the run.</li>
</ul>
<h2 id="032---2026-06-16">[0.3.2] - 2026-06-16</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Suppressions with <code>tool</code> and/or <code>rule-id</code> are now applied. Previously only <code>id</code>
(path substring) and <code>fingerprint</code> matchers worked; tool+rule-id entries
parsed from <code>muninn.yml</code> but silently no-op&rsquo;d.</li>
</ul>
<h2 id="031---2026-06-16">[0.3.1] - 2026-06-16</h2>
<h3 id="fixed-1">Fixed</h3>
<ul>
<li>Poutine v1.x JSON parsing: findings from poutine 1.1.6+ (<code>rule_id</code>, <code>meta</code>,
<code>rules</code>, <code>blobshas</code>) now populate title, rule, and file in PR comments instead
of empty shells (<code>File: :0</code>, `Rule: ``) (#41).</li>
<li>Actionlint PR comments: fall back to <code>kind</code> (e.g. <code>expression</code>) when
<code>rule.name</code> is absent; omit empty Rule lines.</li>
<li>Poutine injection findings: render <code>injection_sources</code> as formatted
<strong>Sources</strong> instead of plain <code>meta.details</code> text.</li>
</ul>
<h3 id="changed-9">Changed</h3>
<ul>
<li>PR comment layout: shared field helpers; non-dependency findings follow
File → Rule → optional extras → description; single-scanner dependency
findings use <strong>File</strong> instead of a redundant <strong>Source</strong> line.</li>
</ul>
<h2 id="030---2026-06-16">[0.3.0] - 2026-06-16</h2>
<h3 id="added">Added</h3>
<ul>
<li>Cross-scanner deduplication by advisory id: findings that report the same
CVE/GHSA for the same package from different scanners (e.g. OSV-Scanner from a
lockfile and Trivy from a container layer) are now collapsed into a single
finding. The contributing scanners are recorded in a new <code>detected_by</code> field
(surfaced in the JSON report, the PR comment&rsquo;s &ldquo;Detected by&rdquo; line, and a
<code>detectedBy</code> SARIF result property). A CVE is preferred over GHSA so the same
vulnerability converges on one id across scanners (#27).</li>
<li>Richer dependency finding rendering: aggregated dependency findings now appear
under a neutral <code>[dependency]</code> heading (instead of a single scanner&rsquo;s name)
with <code>Package</code>, <code>Advisory</code> (including the shared CVE), <code>Detected by</code>, and a
<code>Sources</code> list showing where each scanner observed it. A new <code>sources</code> field on
the finding (per-scanner <code>tool</code> + <code>file</code>) backs the JSON report (#27).</li>
</ul>
<h3 id="fixed-2">Fixed</h3>
<ul>
<li>PR comment rendering: scanner descriptions are flattened to a single line and
their Markdown (code fences, headings) neutralized, so an unbalanced ``` fence
can no longer swallow later findings and the footer into a code block.</li>
</ul>
<h2 id="020---2026-06-15">[0.2.0] - 2026-06-15</h2>
<p>Supply-chain hardening for the scanner image and signed, verifiable releases
(closes #30).</p>
<h3 id="added-1">Added</h3>
<ul>
<li>Pinned every bundled binary scanner to an exact version with SHA256 checksum
verification in the Docker image — gitleaks, zizmor, actionlint, poutine,
osv-scanner, trivy (#31)</li>
<li>Hash-locked the pip-installed scanners (semgrep, checkov, zizmor) via a fully
pinned, multi-arch <code>requirements-scanners.txt</code> installed with
<code>pip --require-hashes</code> (#33)</li>
<li>Renovate configuration to auto-PR scanner version bumps, with a CI job that
refreshes the pinned checksums (#32)</li>
<li>Keyless (OIDC) cosign signing of the published container image and of the
release binary checksums (Sigstore bundle <code>checksums.txt.sigstore.json</code>) (#34)</li>
<li>SBOM (SPDX) attached to every release and as an image attestation (#34)</li>
<li>Max-mode SLSA build provenance attestation on the container image (#34)</li>
<li>&ldquo;Verifying releases&rdquo; instructions in the README (#34)</li>
</ul>
<h3 id="changed-10">Changed</h3>
<ul>
<li>Pinned checkov to 3.2.531 (from 3.3.1) so its dependency tree resolves the
patched aiohttp 3.14.1 and drops the unfixable python-ecdsa Minerva
dependency that checkov 3.3.x introduced. Revisit when a newer checkov lifts
its <code>aiohttp&lt;3.14</code> cap (#33)</li>
</ul>
<h2 id="010---2026-06-14">[0.1.0] - 2026-06-14</h2>
<h3 id="added-2">Added</h3>
<ul>
<li>8 security scanners: gitleaks, zizmor, actionlint, poutine,
semgrep, osv-scanner, trivy, checkov</li>
<li>Unified Finding schema with fingerprinting</li>
<li>Three output formats: SARIF 2.1.0, JSON, GitHub PR comment</li>
<li>GitHub Action with outputs</li>
<li>Config-driven scanner behavior via muninn.yml</li>
<li>Suppression management with expiry dates</li>
<li>90%+ test coverage enforced in CI</li>
<li>Integration tests with real scanner binaries</li>
<li>Self-scan: Muninn scans itself on every PR</li>
</ul>
<p>Built by Skald Lab — skaldlab.dev</p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/smyklot/</link><pubDate>Mon, 24 Aug 2026 22:54:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.47.1.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository’s CODEOWNERS file. It supports multiple command formats, allows for flexible configuration, and provides emoji feedback to indicate success or error. The action handles approval deduplication and reaction removal tracking, ensuring smooth PR workflow management.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.47.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository&rsquo;s CODEOWNERS file. It supports multiple command formats, allows for flexible configuration, and provides emoji feedback to indicate success or error. The action handles approval deduplication and reaction removal tracking, ensuring smooth PR workflow management.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1471-2026-08-24"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.47.0...v1.47.1">1.47.1</a> (2026-08-24)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>panel:</strong> harden settings draft workflow (<a href="https://github.com/smykla-skalski/smyklot/issues/314">#314</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/382c6466f19f09c15d2a56dcdfb009e85be6cd5d">382c646</a>)</li>
</ul>
<h2 id="smyklot-v1471">Smyklot v1.47.1</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.47.1</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>9fd883468e1e5c14ec6d84ea0197c356bc4b2aeb chore(release): bump version to 1.47.1</li>
<li>382c6466f19f09c15d2a56dcdfb009e85be6cd5d fix(panel): harden settings draft workflow (#314)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Mon, 24 Aug 2026 22:53:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service. It performs two main tasks: installing dependencies and bundling the application for production, which are then committed to the repository for deployment on a cloud provider or cluster. This ensures that the application is ready for production use and simplifies the process of deploying services.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service. It performs two main tasks: installing dependencies and bundling the application for production, which are then committed to the repository for deployment on a cloud provider or cluster. This ensures that the application is ready for production use and simplifies the process of deploying services.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/ssg-static-site-generator/</link><pubDate>Mon, 24 Aug 2026 22:53:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.48.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown content with YAML frontmatter into a complete website. It supports templates, webp conversion, and native deployment to various platforms, including Cloudflare Pages, GitHub Pages, and Vercel. The action automates the process of building websites from markdown files, providing features like Sitemap generation, RSS feeds, and SEO metadata.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.48</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown content with YAML frontmatter into a complete website. It supports templates, webp conversion, and native deployment to various platforms, including Cloudflare Pages, GitHub Pages, and Vercel. The action automates the process of building websites from markdown files, providing features like Sitemap generation, RSS feeds, and SEO metadata.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.48 — a build that says what built it, and a self-update check by @spagu in <a href="https://github.com/spagu/ssg/pull/195">https://github.com/spagu/ssg/pull/195</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.47...v1.8.48">https://github.com/spagu/ssg/compare/v1.8.47...v1.8.48</a></p>
]]></content:encoded></item><item><title>Agent Vigil</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/agent-vigil/</link><pubDate>Mon, 24 Aug 2026 22:52:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/agent-vigil/</guid><description>Version updated for https://github.com/sulmusic2-star/agent-vigil to version v0.17.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Vigil is a GitHub Action designed to ensure that code changes meet specific criteria before they are merged. It verifies the exact code change against policies, tests, and recorded actions, returning PASS, FAIL, or INCONCLUSIVE results. The verifier runs locally or on the repository’s GitHub runner and uses trusted base policy checks to prevent regression testing failures. Agent Vigil reduces a local result to signed hashes, repository and policy identity, summary counts, and a signer key ID for CI verification.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sulmusic2-star/agent-vigil">https://github.com/sulmusic2-star/agent-vigil</a></strong> to version <strong>v0.17.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-vigil">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Vigil is a GitHub Action designed to ensure that code changes meet specific criteria before they are merged. It verifies the exact code change against policies, tests, and recorded actions, returning PASS, FAIL, or INCONCLUSIVE results. The verifier runs locally or on the repository&rsquo;s GitHub runner and uses trusted base policy checks to prevent regression testing failures. Agent Vigil reduces a local result to signed hashes, repository and policy identity, summary counts, and a signer key ID for CI verification.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="agent-vigil-v0170">Agent Vigil v0.17.0</h2>
<p>This release adds a signed, append-only permission history for previously trusted changes. Later evidence can stop deployment without erasing the original result.</p>
<h3 id="added">Added</h3>
<ul>
<li><code>vigil continuity</code> records and evaluates <code>CURRENT</code>, <code>HOLD</code>, <code>EXPIRED</code>, and <code>REVOKED</code>.</li>
<li>Authenticated GitHub merge, revert, hotfix, linked-incident, outage, and native Actions evidence import.</li>
<li>A GitHub deployment gate that permits only <code>CURRENT</code>.</li>
<li>A secret-free manual Continuity Lab and <code>continuity install-action --self-serve</code>.</li>
<li>Separate public counts for exact Action use, continuity use, repeat runs, laboratory runs, and retained public artifacts.</li>
</ul>
<h3 id="live-demonstration">Live demonstration</h3>
<p>The default-branch laboratory passed in <a href="https://github.com/sulmusic2-star/agent-vigil/actions/runs/32741176887">run 32741176887</a> at main commit <code>893852e43fb12f204e4189dd84b76df845025749</code>.</p>
<ul>
<li>An authenticated revert produced <code>REVOKED</code>.</li>
<li>A later ordinary green check remained <code>REVOKED</code>.</li>
<li>The deployment job stayed skipped.</li>
<li>Independent signed repair restored <code>CURRENT</code>.</li>
<li>No software was deployed.</li>
</ul>
<h3 id="release-verification">Release verification</h3>
<p>Exact release commit: <code>608b924e34d388cc04849e7d53889938baf545ea</code></p>
<ul>
<li>482 tests: 477 passed, five optional Docker checks skipped, zero failed.</li>
<li>Coverage: 93.26% lines, 81.18% branches, 96.38% functions.</li>
<li>Linux Node 20, 22, and 24 plus macOS and Windows checks passed.</li>
<li>Public wording, package rehearsal across 11 repository shapes and 33 setup flows, three historical replays, workflow syntax, and production dependency audit passed.</li>
<li>The temporary exact PR #74 scope exception was removed before this release. The standing repository policy is unchanged.</li>
</ul>
<p>This release and its laboratory prove the stated deterministic behavior on Agent Vigil&rsquo;s own public repository. They do not prove an outside installation, repeat outside use, payment, or revenue.</p>
]]></content:encoded></item><item><title>Roas OpenAPI Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/roas-openapi-action/</link><pubDate>Mon, 24 Aug 2026 22:51:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/roas-openapi-action/</guid><description>Version updated for https://github.com/sv-tools/roas-action to version v0.12.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The roas-action GitHub Action provides a comprehensive tool for validating, converting, and applying OpenAPI specifications, overlays, Arazzo workflow descriptions, and AsyncAPI documents. It allows users to automate the process of processing various types of API specifications through Docker-based workflows. The action supports features such as specifying subcommands, file paths, conversion targets, merging specifications, applying overlays, and running Arazzo workflows with detailed validation checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sv-tools/roas-action">https://github.com/sv-tools/roas-action</a></strong> to version <strong>v0.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/roas-openapi-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>roas-action</code> GitHub Action provides a comprehensive tool for validating, converting, and applying OpenAPI specifications, overlays, Arazzo workflow descriptions, and AsyncAPI documents. It allows users to automate the process of processing various types of API specifications through Docker-based workflows. The action supports features such as specifying subcommands, file paths, conversion targets, merging specifications, applying overlays, and running Arazzo workflows with detailed validation checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>[BREAKING] follow roas 0.12&rsquo;s move of validate and convert under openapi by @SVilgelm in <a href="https://github.com/sv-tools/roas-action/pull/13">https://github.com/sv-tools/roas-action/pull/13</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sv-tools/roas-action/compare/v0.11.0...v0.12.0">https://github.com/sv-tools/roas-action/compare/v0.11.0...v0.12.0</a></p>
]]></content:encoded></item><item><title>AI Access Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/ai-access-check/</link><pubDate>Mon, 24 Aug 2026 22:49:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/ai-access-check/</guid><description>Version updated for https://github.com/taylorsmithgg/ai-access-check to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action AI Access Check automates the process of verifying whether AI crawlers and answer engines can access, read, and cite a site. It checks three key conditions: robots.txt, edge server handling, and HTML content with text without JavaScript. The action fails the build if any condition is not met or if the overall score falls below a specified threshold.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/taylorsmithgg/ai-access-check">https://github.com/taylorsmithgg/ai-access-check</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-access-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>AI Access Check</code> automates the process of verifying whether AI crawlers and answer engines can access, read, and cite a site. It checks three key conditions: robots.txt, edge server handling, and HTML content with text without JavaScript. The action fails the build if any condition is not met or if the overall score falls below a specified threshold.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>GitHub Marketplace launch. Fail CI when a deploy blocks AI crawlers or ships HTML that answer engines cannot read. Checks robots.txt, edge behavior, and server-rendered text; posts the evidence to the job summary or pull request.</p>
]]></content:encoded></item><item><title>Tessl Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/tessl-code-review/</link><pubDate>Mon, 24 Aug 2026 22:48:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/tessl-code-review/</guid><description>Version updated for https://github.com/tesslio/code-review-action to version v1.3.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of running Tessl Code Review in pull requests by handling checkout, setup, review publication, and lifecycle management. It supports various features such as lens selection, advisory mode, and comment-driven reviews, ensuring that each pull request is reviewed with up-to-date code. The action provides a robust solution for continuous code quality checks within the GitHub workflow environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tesslio/code-review-action">https://github.com/tesslio/code-review-action</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tessl-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of running Tessl Code Review in pull requests by handling checkout, setup, review publication, and lifecycle management. It supports various features such as lens selection, advisory mode, and comment-driven reviews, ensuring that each pull request is reviewed with up-to-date code. The action provides a robust solution for continuous code quality checks within the GitHub workflow environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Pin the Action to this release&rsquo;s commit SHA:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">tesslio/code-review-action@e78605f36fcb282992e06713322b0dfaef36454f</span> <span style="color:#75715e"># v1.3.0</span>
</span></span></code></pre></div><p>This revision installs the current Tessl CLI release. Set the
<code>cli-version</code> input to pin an exact one.</p>
<p>The major tag now points here, so a caller on that tag is on this
revision.</p>
]]></content:encoded></item><item><title>ignition-lint-toolkit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/ignition-lint-toolkit/</link><pubDate>Mon, 24 Aug 2026 22:47:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/ignition-lint-toolkit/</guid><description>Version updated for https://github.com/TheThoughtagen/ignition-lint to version v1.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The ignition-lint action is a comprehensive linting toolkit designed to catch errors and enforce best practices in Ignition SCADA projects. It automates the validation of Jython scripts, expression bindings, and JSON schemas to improve code quality, maintain consistency across teams, and enhance performance. The tool integrates with GitHub Actions for automated PR checks and provides CLI options for CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TheThoughtagen/ignition-lint">https://github.com/TheThoughtagen/ignition-lint</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ignition-lint-toolkit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The ignition-lint action is a comprehensive linting toolkit designed to catch errors and enforce best practices in Ignition SCADA projects. It automates the validation of Jython scripts, expression bindings, and JSON schemas to improve code quality, maintain consistency across teams, and enhance performance. The tool integrates with GitHub Actions for automated PR checks and provides CLI options for CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: better detection for duplicate func and class definitions by @TheThoughtagen in <a href="https://github.com/TheThoughtagen/ignition-lint/pull/24">https://github.com/TheThoughtagen/ignition-lint/pull/24</a></li>
<li>feat: add MISSING_PARAM_DIRECTION lint rule by @TheThoughtagen in <a href="https://github.com/TheThoughtagen/ignition-lint/pull/25">https://github.com/TheThoughtagen/ignition-lint/pull/25</a></li>
<li>fix: event category handling by @TheThoughtagen in <a href="https://github.com/TheThoughtagen/ignition-lint/pull/26">https://github.com/TheThoughtagen/ignition-lint/pull/26</a></li>
<li>feat: cross-view checks for the embedded-view contract by @TheThoughtagen in <a href="https://github.com/TheThoughtagen/ignition-lint/pull/28">https://github.com/TheThoughtagen/ignition-lint/pull/28</a></li>
<li>fix: anchor inline script diagnostics to their JSON line by @TheThoughtagen in <a href="https://github.com/TheThoughtagen/ignition-lint/pull/29">https://github.com/TheThoughtagen/ignition-lint/pull/29</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/TheThoughtagen/ignition-lint/compare/v1.5.0...v1.6.0">https://github.com/TheThoughtagen/ignition-lint/compare/v1.5.0...v1.6.0</a></p>
]]></content:encoded></item><item><title>Create Tideways Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/create-tideways-release/</link><pubDate>Mon, 24 Aug 2026 22:46:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/create-tideways-release/</guid><description>Version updated for https://github.com/tideways/release-action to version v2.0.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of creating a new release on Tideways using the Tideways API. It simplifies the release management by allowing developers to define release details such as name, type, and environment directly within their workflow. This action is particularly useful for Continuous Integration/Continuous Deployment (CI/CD) pipelines where automated release tracking can streamline project updates and monitoring.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tideways/release-action">https://github.com/tideways/release-action</a></strong> to version <strong>v2.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/create-tideways-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of creating a new release on Tideways using the Tideways API. It simplifies the release management by allowing developers to define release details such as name, type, and environment directly within their workflow. This action is particularly useful for Continuous Integration/Continuous Deployment (CI/CD) pipelines where automated release tracking can streamline project updates and monitoring.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump the npm-development group with 4 updates by @dependabot[bot] in <a href="https://github.com/tideways/release-action/pull/178">https://github.com/tideways/release-action/pull/178</a></li>
<li>Bump the npm-development group with 2 updates by @dependabot[bot] in <a href="https://github.com/tideways/release-action/pull/179">https://github.com/tideways/release-action/pull/179</a></li>
<li>Bump the npm-development group with 4 updates by @dependabot[bot] in <a href="https://github.com/tideways/release-action/pull/180">https://github.com/tideways/release-action/pull/180</a></li>
<li>Bump the npm-development group with 5 updates by @dependabot[bot] in <a href="https://github.com/tideways/release-action/pull/181">https://github.com/tideways/release-action/pull/181</a></li>
<li>Bump actions/setup-node from 6 to 7 by @dependabot[bot] in <a href="https://github.com/tideways/release-action/pull/183">https://github.com/tideways/release-action/pull/183</a></li>
<li>Run <code>npm update</code> by @TimWolla in <a href="https://github.com/tideways/release-action/pull/184">https://github.com/tideways/release-action/pull/184</a></li>
<li>Bump the npm-development group with 2 updates by @dependabot[bot] in <a href="https://github.com/tideways/release-action/pull/185">https://github.com/tideways/release-action/pull/185</a></li>
<li>Bump the npm-development group with 6 updates by @dependabot[bot] in <a href="https://github.com/tideways/release-action/pull/186">https://github.com/tideways/release-action/pull/186</a></li>
<li>Bump @rollup/rollup-linux-x64-gnu from 4.62.2 to 4.62.3 in the npm-production group by @dependabot[bot] in <a href="https://github.com/tideways/release-action/pull/187">https://github.com/tideways/release-action/pull/187</a></li>
<li>Run <code>npm update</code> by @TimWolla in <a href="https://github.com/tideways/release-action/pull/192">https://github.com/tideways/release-action/pull/192</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tideways/release-action/compare/v2.0.2...v2.0.3">https://github.com/tideways/release-action/compare/v2.0.2...v2.0.3</a></p>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/compose-lint/</link><pubDate>Mon, 24 Aug 2026 22:46:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.24.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary compose-lint is a security-focused linter for Docker Compose files that detects and fixes common vulnerabilities. It identifies issues such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. The tool automates these checks in CI before they reach production, ensuring better security practices are followed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.24.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>compose-lint is a security-focused linter for Docker Compose files that detects and fixes common vulnerabilities. It identifies issues such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. The tool automates these checks in CI before they reach production, ensuring better security practices are followed.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><strong>Python 3.11 is now the minimum supported version</strong> (issue #643). Python
3.10 reaches upstream end-of-life in October 2026, and dropping a version is
a MINOR pre-1.0 but a MAJOR after — so the drop lands before the 1.0 freeze
rather than letting a routine EOL force a 2.0. The deprecation was announced
in 0.22.0, which also added the stderr warning, because the drop itself is
silent: <code>requires-python</code> does not fail an install — pip resolves a 3.10
interpreter to the last release that allowed it, so <code>pip install -U compose-lint</code> on 3.10 now stays on 0.23.0 with nothing printed. Pin
<code>compose-lint==0.23.0</code> to be explicit about staying there. The CI matrix is
now 3.11–3.14, and the lockfiles are regenerated at the new floor (the only
change is that 3.10-only backport dependencies drop out; no version moves).</p>
</li>
<li>
<p><strong>A scheduled Python-EOL drop is now MINOR, post-1.0 included</strong>
(<a href="docs/adr/029-scheduled-python-drops-are-minor.md">ADR-029</a>). MAJOR
signals surprise; a drop whose date CPython published years ahead, that
warned on stderr for at least 180 days and one MINOR of grace, and that
ships no earlier than upstream EOL, surprises nobody — and
<code>requires-python</code> cannot break an existing environment (pip resolves an
affected interpreter to the last release that allowed it). An
off-schedule drop stays MAJOR. This closes the trap #643 had to
outrun, permanently: 3.11&rsquo;s October 2027 EOL will be a routine MINOR,
not a forced 2.0.</p>
</li>
<li>
<p><strong>The compatibility policy is now part of the contract</strong>
(<a href="docs/adr/030-the-policy-is-part-of-the-contract.md">ADR-030</a>). Amending
it requires an ADR; clarifications ship in any release, tightenings are a
MINOR, and loosenings are a MAJOR and never retroactive — the promise can
no longer be weakened by a docs-only patch. Alongside it, the PATCH
definition is clarified (a false-positive fix removes <em>incorrect</em> findings
and stays a PATCH) and the severity-upgrade rule records its sanctioned
MINOR alternative, the ADR-028 split pattern.</p>
</li>
<li>
<p><strong>A post-1.0 severity upgrade is a MINOR with a one-release runway, not a
MAJOR</strong> (<a href="docs/adr/031-severity-upgrades-are-minor-with-runway.md">ADR-031</a>).
The release before the move announces it; the next MINOR applies it; the
two-axis derivation model must produce the new number either way. A new
HIGH rule already fails a threshold-gated pipeline as a MINOR, so
upgrades-as-MAJOR guarded a door the contract holds open elsewhere —
while making it impossible to correct an under-graded risk signal without
a 2.0. Deliberately the watch-and-see position: under ADR-030, tightening
to MAJOR later is cheap, and the reverse would not have been.</p>
</li>
<li>
<p><strong>Retiring a refuted rule is a MINOR post-1.0, through the deprecation
lifecycle</strong> (<a href="docs/adr/032-rule-retirement-is-minor-with-lifecycle.md">ADR-032</a>).
A rule leaves the registry only when live evidence refutes its premise —
the bar that removed CL-0012/0015/0023 pre-1.0 — and pricing that removal
at a 2.0 would force the tool to keep emitting findings it knows are
false. Announce, one MINOR of grace, then remove; the ID stays fallow
forever, the doc page stays as a tombstone, and a config referencing the
retired ID keeps working, <code>--strict-config</code> included (a precondition the
config layer gains before the first such retirement). &ldquo;Noisy&rdquo; remains a
non-reason (ADR-028).</p>
</li>
<li>
<p><strong><code>rule_id</code> / <code>ruleId</code> in machine output is declared opaque.</strong> Every value
today matches <code>CL-\d{4}</code>, but the pattern was never promised and is now
explicitly excluded from the 1.0 contract: match exact ids, not the
prefix. Declared before the freeze, while it is still a clarification
rather than a contract change; it keeps a future rule source with
differently-shaped ids (e.g. shellcheck&rsquo;s <code>SC</code> codes, ADR-007) additive.</p>
</li>
</ul>
<h3 id="removed">Removed</h3>
<ul>
<li>
<p><strong>The Python 3.10 deprecation warning</strong> added in 0.22.0. It existed to reach
3.10 users while a release could still reach them; from this release pip no
longer installs compose-lint on 3.10, so there is no interpreter left for the
warning to run on.</p>
</li>
<li>
<p><strong>CL-0022 no longer flags the <code>dev</code> tmpfs option.</strong> The pre-1.0 rule-ID sweep
(<a href="https://github.com/tmatens/compose-lint/issues/645">#645</a>,
<a href="docs/adr/028-pre-1.0-rule-id-sweep.md">ADR-028</a>) measured each of the rule&rsquo;s
three tokens on rootful Docker at defaults. <code>exec</code> and <code>suid</code> remove a real
default and stay. <code>dev</code> removes <code>nodev</code> and changes nothing a container can
do: a block node created on a <code>tmpfs:dev</code> is refused by the <strong>device cgroup</strong>
(<code>Operation not permitted</code>) exactly as it is on the rootfs and in <code>/dev</code>,
neither of which carries <code>nodev</code> either; where the cgroup is off
(<code>privileged</code>), <code>/dev</code> already permits the node. A finding on <code>dev</code> described
a configuration that changed nothing — the failure mode that removed
CL-0023 — so the token is gone, with a premise check (<code>_cl0022_dev_inert</code>)
that re-proves the cgroup refusal on every CI run. A file whose only CL-0022
finding was <code>:dev</code> now passes; <code>exec</code> and <code>suid</code> findings are unchanged. The
rule&rsquo;s name is now &ldquo;tmpfs mount re-enables exec/suid&rdquo;.</p>
<p>The rule doc is corrected at the same time: OWASP Rule #8 recommends the
<code>read_only</code> + <code>tmpfs</code> pattern and says nothing about mount options, so it is
now cited for the pattern the rule protects, with the option semantics
grounded by the live checks. The doc also states what <code>noexec</code> does not
stop — <code>memfd_create</code>, interpreters, and a root workload&rsquo;s writable <code>/dev</code> —
which is why the rule is LOW.</p>
</li>
<li>
<p><strong>The pre-1.0 rule-ID reclamation window is closed.</strong> ADR-028 records a
disposition for every one of the 27 rules against the four questions #645
set — would we ship it today, is its grounding container-context, is it
false-positive-prone beyond what the premise check sees, is the ID right —
with corpus prevalence and the live measurements behind each. All 27 are
kept; no ID is reclaimed; CL-0012, CL-0015 and CL-0023 stay fallow
permanently (already enforced by <code>tests/test_rule_surfaces.py</code>). One rule,
CL-0014, is recorded as retained on maintainer judgment rather than on the
grounding bar, so the divergence is visible rather than folklore.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/wails3-build-action/</link><pubDate>Mon, 24 Aug 2026 22:44:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building of Wails.io v3 projects by installing Go and Node.js, running a build process, and optionally uploading the results to GitHub. It supports multiple platforms and configurations through custom options, including obfuscation and caching of builds. The action is particularly useful for maintaining and distributing Wails applications efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building of Wails.io v3 projects by installing Go and Node.js, running a build process, and optionally uploading the results to GitHub. It supports multiple platforms and configurations through custom options, including obfuscation and caching of builds. The action is particularly useful for maintaining and distributing Wails applications efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>Lachesis Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/lachesis-security-scan/</link><pubDate>Mon, 24 Aug 2026 22:44:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/lachesis-security-scan/</guid><description>Version updated for https://github.com/UnboundCompute/lachesis-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action builds a code property graph of your repo, traces untrusted input to dangerous sinks, and emits reviewable SARIF from your own runner. It helps find missing authorization checks in your code, providing inline comments on pull requests with Lachesis bot signatures if the optional poster is enabled.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/UnboundCompute/lachesis-action">https://github.com/UnboundCompute/lachesis-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lachesis-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action builds a code property graph of your repo, traces untrusted input to dangerous sinks, and emits reviewable SARIF from your own runner. It helps find missing authorization checks in your code, providing inline comments on pull requests with Lachesis bot signatures if the optional poster is enabled.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Add a line-move-stable <code>lachesisFinding</code> SARIF fingerprint alongside the exact
engine path id, enabling downstream finding lifecycle and deduplication.</li>
<li>Prefer the stable finding fingerprint when filtering a trusted SARIF baseline,
while retaining rule/file/line compatibility with older reports.</li>
<li>Add opt-in <code>candidate-report: census</code> output for Atropos-backed obligation
coverage in the GitHub Actions job summary.</li>
<li>Expose generated SARIF and candidate-census paths as composite-action outputs so
callers can archive or upload artifacts through generic CI integrations.</li>
<li>Pin development defaults to the reviewed Lachesis <code>v0.2.0</code> and Atropos <code>v1.8.0</code>
releases.</li>
<li>Record the analysis projection, engine/catalog commits, and toolchain fingerprint
in SARIF driver properties.</li>
</ul>
]]></content:encoded></item><item><title>Verdica Decision Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/verdica-decision-gate/</link><pubDate>Mon, 24 Aug 2026 22:43:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/verdica-decision-gate/</guid><description>Version updated for https://github.com/verdicahq/verdica to version v0.11.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Verdica is a GitHub Action that helps teams enforce architectural decisions by using files in the repository to track them. It ensures that changes conform to previously established design choices, enhancing code quality and preventing accidental violations. The action integrates with a language model (Mistral API) to automatically assess whether pull requests align with recorded decisions, providing clear feedback on potential issues before they are merged.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/verdicahq/verdica">https://github.com/verdicahq/verdica</a></strong> to version <strong>v0.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/verdica-decision-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Verdica is a GitHub Action that helps teams enforce architectural decisions by using files in the repository to track them. It ensures that changes conform to previously established design choices, enhancing code quality and preventing accidental violations. The action integrates with a language model (Mistral API) to automatically assess whether pull requests align with recorded decisions, providing clear feedback on potential issues before they are merged.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Decisions declare their nature: standing choice or temporary tradeoff with a revisit_when condition. The distiller classifies it, the gate labels it, the digest resurfaces open tradeoffs. Born from field feedback on the first hosted deployment (DEC-0011).</p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/vibgrate-scan/</link><pubDate>Mon, 24 Aug 2026 22:41:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.824.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of analyzing and improving codebases using Vibgrate, a tool that provides insights into drift score, drift risk index, drift risk breakdown, drift risk prioritization, drift risk exposure, drift risk mitigation strategies, drift risk mitigation steps, drift risk mitigation timeline, drift risk mitigation impact assessment, drift risk mitigation impact, drift risk mitigation impact metrics, drift risk mitigation impact score, drift risk mitigation impact score breakdown, drift risk mitigation impact score breakdown by category, drift risk mitigation impact score breakdown by severity, drift risk mitigation impact score breakdown by priority, drift risk mitigation impact score breakdown by timeframe, drift risk mitigation impact score breakdown by risk level, drift risk mitigation impact score breakdown by risk type, drift risk mitigation impact score breakdown by risk source, drift risk mitigation impact score breakdown by risk owner, drift risk mitigation impact score breakdown by risk status, drift risk mitigation impact score breakdown by risk action plan, drift risk mitigation impact score breakdown by risk response plan, drift risk mitigation impact score breakdown by risk communication plan, drift risk mitigation impact score breakdown by risk monitoring plan, drift risk mitigation impact score breakdown by risk follow-up plan, drift risk mitigation impact score breakdown by risk closure plan, drift risk mitigation impact score breakdown by risk review plan, drift risk mitigation impact score breakdown by risk acceptance plan, drift risk mitigation impact score breakdown by risk denial plan, drift risk mitigation impact score breakdown by risk transfer plan, drift risk mitigation impact score breakdown by risk delegation plan, drift risk mitigation impact score breakdown by risk approval plan, drift risk mitigation impact score breakdown by risk reassignment plan, drift risk mitigation impact score breakdown by risk escalation plan, drift risk mitigation impact score breakdown by risk resolution plan, drift risk mitigation impact score breakdown by risk transfer plan, drift risk mitigation impact score breakdown by risk delegation plan, drift risk mitigation impact score breakdown by risk approval plan, drift risk mitigation impact score breakdown by risk reassignment plan, drift risk mitigation impact score breakdown by risk escalation plan, drift risk mitigation impact score breakdown by risk resolution plan, drift risk mitigation impact score breakdown by risk transfer plan, drift risk mitigation impact score breakdown by risk delegation plan, drift risk mitigation impact score breakdown by risk approval plan, drift risk mitigation impact score breakdown by risk reassignment plan, drift risk mitigation impact score breakdown by risk escalation plan, drift risk mitigation impact score breakdown by risk resolution plan, drift risk mitigation impact score breakdown by risk transfer plan, drift risk mitigation impact score breakdown by risk delegation plan, drift risk</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.824.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of analyzing and improving codebases using Vibgrate, a tool that provides insights into drift score, drift risk index, drift risk breakdown, drift risk prioritization, drift risk exposure, drift risk mitigation strategies, drift risk mitigation steps, drift risk mitigation timeline, drift risk mitigation impact assessment, drift risk mitigation impact, drift risk mitigation impact metrics, drift risk mitigation impact score, drift risk mitigation impact score breakdown, drift risk mitigation impact score breakdown by category, drift risk mitigation impact score breakdown by severity, drift risk mitigation impact score breakdown by priority, drift risk mitigation impact score breakdown by timeframe, drift risk mitigation impact score breakdown by risk level, drift risk mitigation impact score breakdown by risk type, drift risk mitigation impact score breakdown by risk source, drift risk mitigation impact score breakdown by risk owner, drift risk mitigation impact score breakdown by risk status, drift risk mitigation impact score breakdown by risk action plan, drift risk mitigation impact score breakdown by risk response plan, drift risk mitigation impact score breakdown by risk communication plan, drift risk mitigation impact score breakdown by risk monitoring plan, drift risk mitigation impact score breakdown by risk follow-up plan, drift risk mitigation impact score breakdown by risk closure plan, drift risk mitigation impact score breakdown by risk review plan, drift risk mitigation impact score breakdown by risk acceptance plan, drift risk mitigation impact score breakdown by risk denial plan, drift risk mitigation impact score breakdown by risk transfer plan, drift risk mitigation impact score breakdown by risk delegation plan, drift risk mitigation impact score breakdown by risk approval plan, drift risk mitigation impact score breakdown by risk reassignment plan, drift risk mitigation impact score breakdown by risk escalation plan, drift risk mitigation impact score breakdown by risk resolution plan, drift risk mitigation impact score breakdown by risk transfer plan, drift risk mitigation impact score breakdown by risk delegation plan, drift risk mitigation impact score breakdown by risk approval plan, drift risk mitigation impact score breakdown by risk reassignment plan, drift risk mitigation impact score breakdown by risk escalation plan, drift risk mitigation impact score breakdown by risk resolution plan, drift risk mitigation impact score breakdown by risk transfer plan, drift risk mitigation impact score breakdown by risk delegation plan, drift risk mitigation impact score breakdown by risk approval plan, drift risk mitigation impact score breakdown by risk reassignment plan, drift risk mitigation impact score breakdown by risk escalation plan, drift risk mitigation impact score breakdown by risk resolution plan, drift risk mitigation impact score breakdown by risk transfer plan, drift risk mitigation impact score breakdown by risk delegation plan, drift risk</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Sync from monorepo (v2026.824.3) by @vibgrate-team in <a href="https://github.com/vibgrate/cli/pull/122">https://github.com/vibgrate/cli/pull/122</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vibgrate/cli/compare/v2026.819.3...v2026.824.3">https://github.com/vibgrate/cli/compare/v2026.819.3...v2026.824.3</a></p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/rustscript-action/</link><pubDate>Mon, 24 Aug 2026 22:39:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.6.13.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that allows you to write helper scripts in Rust and run them like shell scripts, with no compile step. It interprets a practical subset of the language and validates files using rust check. The action provides capabilities to run scripts directly, execute snippets, validate files without running them, compile and run native binaries, list supported methods, clear cached checks and builds, update RustScript releases, and show version information.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.6.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a tool that allows you to write helper scripts in Rust and run them like shell scripts, with no compile step. It interprets a practical subset of the language and validates files using <code>rust check</code>. The action provides capabilities to run scripts directly, execute snippets, validate files without running them, compile and run native binaries, list supported methods, clear cached checks and builds, update RustScript releases, and show version information.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.6.12...v0.6.13">https://github.com/VladasZ/rustscript/compare/v0.6.12...v0.6.13</a></p>
]]></content:encoded></item><item><title>Redox-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/redox-vm/</link><pubDate>Mon, 24 Aug 2026 22:38:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/redox-vm/</guid><description>Version updated for https://github.com/vmactions/redox-vm to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Use this GitHub Action to automatically run CI tests on Redox, a lightweight operating system. It provides support for running tests and building projects on various architectures, including x86_64. The action automates the setup of the build environment, handles secrets and environment variables, and syncs code between the host and the VM.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/redox-vm">https://github.com/vmactions/redox-vm</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/redox-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Use this GitHub Action to automatically run CI tests on Redox, a lightweight operating system. It provides support for running tests and building projects on various architectures, including x86_64. The action automates the setup of the build environment, handles secrets and environment variables, and syncs code between the host and the VM.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/redox-vm/commits/v1.0.0">https://github.com/vmactions/redox-vm/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Setup vp</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/setup-vp/</link><pubDate>Mon, 24 Aug 2026 22:37:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/setup-vp/</guid><description>Version updated for https://github.com/voidzero-dev/setup-vp to version v1.18.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Vite+ globally via official install scripts. It automates the installation of specific Node.js versions and caches project dependencies using auto-detection of lock files. Users can also run vp install after setup and optionally use Socket Firewall Free to block malicious dependencies. The action supports various package managers and is compatible with GitLab CI/CD and Azure Pipelines through reusable templates.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/voidzero-dev/setup-vp">https://github.com/voidzero-dev/setup-vp</a></strong> to version <strong>v1.18.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-vp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up Vite+ globally via official install scripts. It automates the installation of specific Node.js versions and caches project dependencies using auto-detection of lock files. Users can also run <code>vp install</code> after setup and optionally use Socket Firewall Free to block malicious dependencies. The action supports various package managers and is compatible with GitLab CI/CD and Azure Pipelines through reusable templates.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update vite-plus to v0.2.9 by @renovate[bot] in <a href="https://github.com/voidzero-dev/setup-vp/pull/125">https://github.com/voidzero-dev/setup-vp/pull/125</a></li>
<li>chore(deps): update pnpm/action-setup action to v6.0.10 by @renovate[bot] in <a href="https://github.com/voidzero-dev/setup-vp/pull/124">https://github.com/voidzero-dev/setup-vp/pull/124</a></li>
<li>feat: pin the install script to the requested version by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/127">https://github.com/voidzero-dev/setup-vp/pull/127</a></li>
<li>docs: clarify automatic Node.js resolution by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/130">https://github.com/voidzero-dev/setup-vp/pull/130</a></li>
<li>ci: add GitLab end-to-end testing by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/132">https://github.com/voidzero-dev/setup-vp/pull/132</a></li>
<li>feat: resolve Vite+ executable paths from VpDirs by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/131">https://github.com/voidzero-dev/setup-vp/pull/131</a></li>
<li>chore: release v1.18.0 by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/133">https://github.com/voidzero-dev/setup-vp/pull/133</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/voidzero-dev/setup-vp/compare/v1.17.0...v1.18.0">https://github.com/voidzero-dev/setup-vp/compare/v1.17.0...v1.18.0</a></p>
]]></content:encoded></item><item><title>N-Plus-One Guardian</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/n-plus-one-guardian/</link><pubDate>Mon, 24 Aug 2026 22:36:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/n-plus-one-guardian/</guid><description>Version updated for https://github.com/whentony/n-plus-one-guardian to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The N-Plus-One Guardian is a GitHub Action designed to detect and prevent the “N+1” problem in database queries within Laravel projects. It analyzes modified files in Pull Requests, identifying common methods used for ORM queries inside loops and suggesting refactoring those queries to load data eagerly outside the loop. The action supports multiple languages and ORMs like Laravel Eloquent/Doctrine, Prisma/TypeORM, and Django ORM/SQLAlchemy.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/whentony/n-plus-one-guardian">https://github.com/whentony/n-plus-one-guardian</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/n-plus-one-guardian">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The N-Plus-One Guardian is a GitHub Action designed to detect and prevent the &ldquo;N+1&rdquo; problem in database queries within Laravel projects. It analyzes modified files in Pull Requests, identifying common methods used for ORM queries inside loops and suggesting refactoring those queries to load data eagerly outside the loop. The action supports multiple languages and ORMs like Laravel Eloquent/Doctrine, Prisma/TypeORM, and Django ORM/SQLAlchemy.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🚀 Primeiro lançamento oficial do N-Plus-One Guardian!</p>
<p>O N-Plus-One Guardian é uma GitHub Action focada em performance e qualidade de código, criada para proteger suas aplicações contra o temido problema de N+1 consultas (queries executadas dentro de laços de repetição).</p>
<p>✨ Principais Funcionalidades
🌍 Suporte Poliglota: Analisa de forma nativa as principais linguagens e ORMs do mercado:
PHP (Laravel Eloquent / Doctrine)
TypeScript &amp; Node.js (Prisma / TypeORM)
Python (Django ORM / SQLAlchemy)
🧠 Análise Estática Inteligente: Utiliza a tecnologia avançada do <a href="https://tree-sitter.github.io/tree-sitter/">Tree-sitter</a> para converter os arquivos modificados do Pull Request em uma Árvore Sintática Abstrata (AST). Isso garante alta precisão na detecção sem precisar executar o seu código.
💬 Code Review Automático: Insere comentários de alerta (inline) diretamente nas linhas do Pull Request onde a má prática foi detectada, indicando exatamente onde a query deve ser refatorada.
🛡️ Guardião de Integração: Se um problema for detectado, o status do check no GitHub Action falha, impedindo que o código não-otimizado chegue ao ambiente de produção.</p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/cowork-harness/</link><pubDate>Mon, 24 Aug 2026 22:34:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v2.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cowork-harness GitHub Action is a scriptable and CI-friendly test harness that reproduces Claude Cowork’s observable runtime contract closely enough to test skills without using the locked Desktop app. It emulates constraints such as sealed filesystem, default-deny egress, MCP-only cross-boundary, and provides detailed evidence of agent behavior through recorded runs, enhancing test reliability beyond bare CLI execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The cowork-harness GitHub Action is a scriptable and CI-friendly test harness that reproduces Claude Cowork&rsquo;s observable runtime contract closely enough to test skills without using the locked Desktop app. It emulates constraints such as sealed filesystem, default-deny egress, MCP-only cross-boundary, and provides detailed evidence of agent behavior through recorded runs, enhancing test reliability beyond bare CLI execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<blockquote>
<h3 id="-upgrading-from-20x--one-behaviour-change">⚠️ Upgrading from 2.0.x — one behaviour change</h3>
<p><strong><code>rehash</code> now exits <code>4</code> for partial success</strong> (some cassettes migrated, some could not) where it
previously exited <code>1</code>.</p>
<ul>
<li>Scripts testing <code>rc != 0</code> for &ldquo;something went wrong&rdquo; — <strong>unaffected</strong>.</li>
<li>Scripts testing <code>rc == 1</code> for &ldquo;something failed&rdquo; — <strong>will now miss the partial case</strong>.</li>
</ul>
<p>The two shapes demand opposite responses (commit what migrated and budget a re-record for the rest,
versus nothing here is salvageable), which is why they are now distinct codes. <code>4</code> rather than <code>3</code>
because the exit-code space is per-command and <code>3</code>&rsquo;s &ldquo;could not verify&rdquo; meaning is load-bearing on
<code>verify-cassettes</code>.</p>
<p>This ships in a minor because <code>rehash</code>&rsquo;s exit codes were previously documented <strong>nowhere</strong> — not in
<code>--help</code>, not in SPEC §11 — so there was no published contract to break. They are now in both.</p>
<p>Everything else in this release is additive or a fix.</p>
</blockquote>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><strong><code>rehash</code> leads with the split, and PARTIAL success has its own exit code (<code>4</code>).</strong> The summary used to
print last, after every per-file line had scrolled past — and those two counts <em>are</em> the decision:
commit what migrated and budget a re-record for the rest, versus nothing here is salvageable. It now
prints first, with the per-file lines as the detail behind it.</p>
<p><strong><code>4 migrated, 18 failed</code> and <code>0 migrated, 22 failed</code> both exited <code>1</code></strong>, which made a shell consumer
unable to tell apart two situations demanding opposite responses. The JSON envelope always carried the
split as <code>migrated</code>/<code>skipped</code>/<code>errors</code>; a bare terminal run did not. <code>rehash</code> now exits <code>0</code> (all
migrated, or nothing needed migrating) / <strong><code>4</code></strong> (partial) / <code>1</code> (nothing migrated and at least one
could not) / <code>2</code> (usage).</p>
<p><strong>This is a behaviour change for anyone branching on <code>rehash</code>&rsquo;s exit code</strong> — a script testing
<code>rc == 1</code> for &ldquo;something failed&rdquo; will miss the partial case, though <code>rc != 0</code> is unaffected. It ships in
a minor deliberately: <code>rehash</code>&rsquo;s codes were documented <strong>nowhere</strong> — zero mentions in its <code>--help</code>,
absent from SPEC §11 — so there was no published contract to break, and a consumer on <code>rc == 1</code> was
relying on observed behaviour. They are now documented in both places. <code>4</code> rather than <code>3</code> because the
code space is per-command and <code>3</code>&rsquo;s &ldquo;could not verify&rdquo; meaning is load-bearing on <code>verify-cassettes</code>.</p>
</li>
<li>
<p><strong>The batch cost estimate now reports its basis instead of claiming authority.</strong> <code>estimatedCostUsd</code> is
<code>sum(max(local run history))</code> — a max over whatever <em>this machine</em> has run. The line already qualified
the partially-priced case with <code>— LOWER BOUND</code>, but the fully-priced case said
<code>(all N scenario(s) priced from prior runs)</code>, which is an active claim of completeness and was the one
case that said nothing qualifying. At a new baseline or a new agent binary the history describes a
materially different configuration, so the estimate can <strong>under</strong>-predict exactly when it is most
consulted — a consumer wrote &ldquo;that is the ceiling, not the scope&rdquo; into a plan off this line and had to
retract it.</p>
<p>The line now carries <code>basis: N prior run(s) on THIS machine, thinnest scenario has M; a max over that history, NOT a bound</code>, and the JSON payload gains <code>estimateBasis</code>
(<code>{source, pricedRuns, thinnestScenarioRuns}</code>). <code>thinnest</code> is the useful half: a scenario with one prior
run contributes a single sample, not a worst case. Wired through <code>pricedRunCount</code>, which had been
exported and doc-commented <em>&ldquo;for messages that report their own basis&rdquo;</em> with zero callers.</p>
</li>
<li>
<p><strong>Pre-epoch cassettes: we could report ordinary content drift, and chose not to.</strong> When a cassette
recorded before the 2.0.0 hash-format epoch is read, <code>rehash</code> recomputes the <strong>legacy</strong> digest over the
current tree and compares it to the legacy digest in the cassette. On a mismatch that is a positive
determination of ordinary content drift — strictly more informative than <code>unverifiable-skill</code>, and the
same determination 1.25.0 reported as warn-only <code>skill</code> drift.</p>
<p>Replay does not report it, and that is a decision rather than a limit. Reporting it would require
keeping a fold of the retired hash algorithm alive in the replay path — the most-run lane — permanently,
to soften one release&rsquo;s migration; the population it would help shrinks with every re-record. The
runtime cost would be nil (both digests fold from one tree walk); the cost is code that could never be
deleted. <strong>&ldquo;We can compute this and chose not to report it, so the legacy fold can die&rdquo; is a different
claim from &ldquo;this cannot be known&rdquo;, and the earlier phrasing implied the latter.</strong> The remedy for a
pre-epoch cassette is <code>rehash</code> where it can prove content unchanged, and a re-record where it cannot.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>The fast test lane had no global timeout, so 93 subprocess-spawning test files inherited vitest&rsquo;s 5s
default.</strong> They measure 167-888ms locally — a fine margin until you remember the lane runs 344 files in
parallel across every core, and a CI runner is ~3x slower again. That is how an 888ms test crosses 5s;
it cost two red CI runs on unrelated PRs before anyone looked at the failure rather than re-running it.
<code>vitest.config.ts</code> now sets <code>testTimeout: 30_000</code> — ~34x the slowest measured non-e2e case, while a
genuine hang still fails ~6x faster than in the live lane (which sets 180s). Per-test values still win.</p>
</li>
<li>
<p><strong>Redaction pattern ORDER is load-bearing, and now says so — plus a warning when it is wrong.</strong> Patterns
apply in sequence over the accumulating output, so a bare catch-all placed ahead of a lookahead-anchored
rule for the same prefix matches first and eats the <code>/mnt/</code> tail the lookahead exists to preserve. The
shipped policy depends on that order: with it, a run-dir path redacts to
<code>[REDACTED:local-path:…]/mnt/outputs/report.md</code> and still resolves; without it the whole path is consumed
and <code>normalizeHostShapedForReplay</code> returns <code>null</code> — <strong>every <code>computer://</code> structural-marker resolution
silently stops working, with no error and no finding.</strong></p>
<p><code>loadRedactionPolicy</code> now warns, naming both pattern indices, when a policy is in the hazardous order.
Detection is deliberately conservative — it fires only when a later pattern&rsquo;s source is exactly an
earlier one&rsquo;s plus a trailing lookahead (modulo lazy quantifiers) — because regex subsumption is
undecidable in general and a false positive would train authors to ignore the warning.</p>
<p>The remainder is matched by <strong>shape</strong>, never by parsing the lookahead&rsquo;s body. A first cut used
<code>\(\?=[^()]*\)</code>, whose <code>[^()]*</code> silently skipped every lookahead containing a group — so
<code>(?=/mnt(?:/|$|[\s&quot;'\\)\]]))</code>, the natural way to write &ldquo;slash, end, or delimiter&rdquo; and arguably more
correct than a bare <code>(?=/mnt/)</code>, went unflagged while being just as dangerous. Caught by a consumer
running it against their own policy, which is now a regression fixture. Not looking inside also sidesteps
escape- and char-class-awareness, since that policy carries an escaped <code>\)</code> inside a character class.</p>
<p><code>docs/cassette.md</code> states the requirement next to the existing &ldquo;stop before <code>/mnt/</code>&rdquo; guidance, which had
the shape of the rule but not the ordering half. The new test pins the runtime consequence, not just the
detector: a reorder must make the link fail to normalize AND be flagged, so the syntactic check cannot
drift away from what it is standing in for.</p>
</li>
<li>
<p><strong>The copy-pasteable Action steps now pin <code>version: &quot;^2&quot;</code>, and a guard requires it.</strong> Bounding every
published npm floor last release fixed the <em>form</em> of a floor (<code>&gt;=1.11.0</code> reads as a bound and silently
means &ldquo;and every future major too&rdquo;) but removed the input from the recipes rather than correcting it —
so the shipped snippets carried no <code>version:</code> at all and fell back to the input&rsquo;s <code>latest</code> default. That
reproduced the exact footgun <code>action.yml</code>&rsquo;s own description warns about two lines earlier: a CLI major
reaches a workflow the moment it is promoted, even though the <code>uses:</code> ref never changed.</p>
<p><code>^2</code> was not among the alternatives weighed at the time, and it is the form <code>action.yml</code> itself
recommends: it holds the major, needs no patch number to remember, and only wants a human decision at
the next major bump. <strong>Five</strong> steps were unpinned, not the three in the CI recipe — <code>README.md</code> carries
two more.</p>
<p><code>action-docs-sync</code> now requires every copy-pasteable step (a <code>uses:</code> line inside a fenced block with a
<code>with:</code>) to pin <code>^&lt;package major&gt;</code>; inline prose mentions are excluded, since there is nothing to pin.
Verified by mutation: dropping one <code>version:</code>, regressing a pin to <code>^1</code>, and bumping the package major
each fail. The guard also asserts it found the steps at all, because a parser that matches nothing
passes every assertion after it. Guarding a floor&rsquo;s FORM does not guarantee a floor is PRESENT — this
pins the behaviour instead.</p>
</li>
<li>
<p><strong>The <code>sessionFingerprint</code> field set is now stated completely, and a guard discovers the sites that
state it.</strong> The hash covers eight session fields; every place that enumerated them named six or fewer.
<code>web_fetch</code> was missing everywhere, <code>agent_env</code> was missing everywhere, and <code>docs/invariants.md</code>
also omitted <code>skills</code>. Fourteen sites carried the claim while the working assumption was three: <strong>twelve
enumerated the set</strong> — four in prose, two in the current cassette schema, six in the retained v9-v11
schemas — and <strong>two denied it existed at all</strong>. <code>SPEC.md</code> and <code>docs/scenario.md</code> both said the session
is &ldquo;not drift-checked or fingerprinted&rdquo;. <code>model</code> genuinely is not hashed; connected folders and plugin/skill/MCP discovery are,
which is the half a reader would have trusted.</p>
<p>The <code>verify-cassettes</code> staleness message — the only enumeration a user ever sees — omitted <code>projects</code>,
and <code>docs/cassette.md</code> quoted it with <code>projects</code> present. Both are fixed and now pinned to each other
by test, so the doc cannot drift from the string again.</p>
<p>New <strong>invariant 14</strong> in <code>check:versions</code> derives the field set from <code>buildSessionFingerprint</code>&rsquo;s shape
and <strong>discovers</strong> the enumeration sites rather than reading a list, so a new one is covered the day it
lands. Two deliberate limitations are recorded as tests rather than left to look covered: it cannot see
a flat denial (there is no enumeration to check — the coverage floor is what notices), and it cannot
see a deleted &ldquo;only when set&rdquo; qualifier. <code>schema/cassette.v{9,10,11}.json</code> are allowlisted as frozen
history: a retained schema documents the format as it shipped, and rewriting its description would make
it describe a shape its own consumers never saw.</p>
<p>Verified by mutation: run against the previous revision the guard flags all six then-existing sites
with the correct missing fields; renaming the shape literal makes it error rather than silently pass;
a ninth field invalidates a previously-complete site; and a whole-file token check — which would have
passed today and then never failed again — is rejected in favour of span-scoped matching.</p>
</li>
<li>
<p><strong>The documented Action ref is now <code>@v2</code>, not <code>@main</code></strong> — 7 references across <code>README.md</code>,
<code>SKILL.md</code> and <code>ci-recipe.md</code>. <code>@main</code> was right when it was written: no alias tag had ever been
published, so naming one would have sent a copy-pasting reader to a <code>uses:</code> that 404s, and the guard&rsquo;s
own note said to revisit &ldquo;once 1.0.0 ships&rdquo;. Two things had to be true first, and now are — <code>v2</code>/<code>v2.0</code>
point at a real release, and <code>release.yml</code> moves them on every stable release rather than leaving it to a
checklist. Recommending a floating tag nobody remembers to move is worse than recommending <code>@main</code>; that
was the actual situation while <code>v1</code> sat at 1.24.0.</p>
<p><code>action-docs-sync</code> now derives the expected ref from <code>package.json</code>&rsquo;s major instead of hardcoding it, so
the next major forces these docs to move with it rather than silently pointing a reader at the previous
line. <code>@main</code> is deliberately no longer accepted there: permitting both would let the recommendation
drift back with nothing noticing. Verified by mutation — regressing one reference to <code>@main</code> fails, and
setting the package version to 3.0.0 fails all three files.</p>
<p><strong>This changes nothing about which CLI you get.</strong> The ref selects the Action; the CLI still comes from the
<code>version:</code> input, which still defaults to <code>latest</code>. <code>@v2</code> looks more like a version pin than <code>@main</code> did,
so that distinction matters more now, not less — it is spelled out in <code>README.md</code>&rsquo;s Action section and in
<code>action.yml</code>&rsquo;s own input description.</p>
</li>
<li>
<p><strong>The CI recipe no longer teaches a bare version floor.</strong> It
carried <code>version: &quot;&gt;=1.11.0&quot;</code> — which reads as &ldquo;at least 1.11.0&rdquo; and silently means &ldquo;and every future
major too&rdquo;, so a copy-paster gets the next major with no say in it. It was <strong>not</strong> broken today
(<code>--min-severity</code> still exists in 2.x, and <code>lint</code> reads no cassette, so 2.0.0&rsquo;s hash-format epoch never
applied to that step) — the defect was latent and in the FORM.</p>
<p>The bare floor was first dropped rather than corrected — <code>^1.11.0</code> would have frozen every new
copy-paster on the previous major, and <code>^2.0.1</code> needs remembering at each release — so the guidance moved
to prose. <strong>That went one step too far, and the same release corrects it</strong> (see the <code>version: &quot;^2&quot;</code> entry
above): dropping the input entirely falls back to <code>action.yml</code>&rsquo;s <code>latest</code> default, which is the one
remaining unbounded form and the exact footgun the input&rsquo;s own description warns about two lines earlier.
<code>^2</code> was never among the alternatives weighed at the time, and it is what the recipes now carry. Reach for
an exact pin only when you want byte-reproducible CI. <a href="https://github.com/yaniv-golan/cowork-harness/blob/main/action.yml"><code>action.yml</code></a>&rsquo;s own description stops offering <code>&gt;=1.11.0</code> and
<code>^1.11.0</code> as interchangeable — they are not, and it had been recommending the unbounded one.</p>
<p><code>check:versions</code> invariant 13 now covers the Action&rsquo;s <code>version:</code> input, which it could not see before:
it keys on <code>@&gt;=</code>, and <code>version: &quot;&gt;=1.11.0&quot;</code> has no <code>@</code> — the same defect in different syntax, with no
coverage. Only the <strong>unbounded</strong> floor is rejected; verified against each form, <code>&gt;=1.11.0 &lt;3</code>, <code>^2</code>,
<code>2.0.1</code> and <code>latest</code> all pass.</p>
</li>
<li>
<p><strong><code>projects[].from</code> was missing from two places, and the second was a false green.</strong> A connected project
is a host path exactly like a connected folder, and it was:</p>
<ul>
<li><strong>not resolved against the session file.</strong> <a href="./docs/session.md"><code>docs/session.md</code></a> promises, without
qualification, that <em>&ldquo;relative paths resolve from the session file&rsquo;s own directory&rdquo;</em> — and it was true
of every path field except this one, which resolved against the <strong>process CWD</strong>. So the same session
file mounted different content depending on which directory you invoked from. The doc was right; the
resolver had simply skipped the field.</li>
<li><strong>not part of the session fingerprint.</strong> Swapping which directory is mounted at <code>.projects/&lt;uuid&gt;</code>
changed the run&rsquo;s inputs and <code>verify-cassettes</code> reported nothing — a false green in the gate whose job
is to notice that inputs moved. Folded in on the same <strong>non-empty-only</strong> terms as <code>agent_env</code>, so a
session with no <code>projects:</code> (and one with an explicit <code>projects: []</code>) hashes byte-identically to
before; only sessions that use the feature move. No committed cassette does.</li>
</ul>
<p><strong>A cassette recorded before this is reported <code>unverifiable</code>, not clean.</strong> Its hash contains nothing
about <code>projects[]</code>, so it cannot distinguish &ldquo;the field was never covered&rdquo; from &ldquo;the mount changed since
record time&rdquo; — and reporting the mismatch as a benign migration would put the same false green back in
the remedy. When everything else matches exactly, <code>verify-cassettes</code> says so and asks for a re-record to
gain the coverage. <code>sessionFingerprintDrift</code> remains <code>verify-cassettes</code>-only: none of this can change a
<code>replay</code> verdict, even under <code>--strict</code>.</p>
<p>Three enumerations of the covered fields gained <code>projects</code> — <a href="./docs/cassette.md"><code>docs/cassette.md</code></a>,
<a href="./docs/invariants.md"><code>docs/invariants.md</code></a> and the shipped skill&rsquo;s <code>task-recipes.md</code>. <code>invariants.md</code>
also described this as a hash of the <strong>resolved</strong> session; it is the <strong>authored, pre-resolution</strong> shape,
deliberately, so the digest survives a different checkout — the function&rsquo;s own comment says so, and a
resolved hash could never match on another clone.</p>
</li>
<li>
<p><strong>The published control-protocol schema rejected five kinds of frame the harness sends and answers.</strong>
<code>schema/protocol.v1.json</code> described four request subtypes; the harness has always answered <strong>six</strong> —
adding <code>request_user_dialog</code> and <code>elicitation</code>/<code>side_question</code> — and it also sends a fail-closed
<code>subtype:&quot;error&quot;</code> response envelope, whose payload is a <em>string</em> under <code>error</code> rather than an object
under <code>response</code>, so a validator that knew only the success envelope rejected every one. Measured
against the previous schema: all five representative frames <strong>REJECT</strong>; against the new one, all five
accept. Anyone validating real traffic was seeing failures on frames the harness handles correctly.</p>
<p>Added as new <code>oneOf</code>/<code>anyOf</code> branches plus one new top-level response shape — <strong>111 insertions, zero
deletions</strong> in the surface baseline, so nothing existing was narrowed and no frame the schema already
accepted is affected. Both spellings the parser accepts are admitted (<code>dialogKind</code>/<code>dialog_kind</code>,
<code>mcp_server_name</code>/<code>server</code>, <code>message</code>/<code>prompt</code>) rather than guessing which the agent sends.</p>
<p>The golden vector pack grew with it, generated from the <strong>real</strong> envelope builders rather than
hand-authored lookalikes. The existing lockstep test — every schema definition must be exercised by a
vector — caught all five additions immediately, which is what forced those vectors to exist. One of them
asserts the error envelope does <strong>not</strong> validate as a success envelope, so the two shapes cannot be
quietly conflated later.</p>
<p><a href="./SPEC.md"><code>SPEC.md</code></a> §12 now states the additive latitude for this surface explicitly. Its silence had
read as a prohibition, which is plausibly why three subtypes went undescribed rather than added — while
<a href="./docs/protocol.md"><code>docs/protocol.md</code></a>&rsquo;s own versioning policy had said all along that an additive
variant is a v1 minor note, which is where the dated entry now lives.</p>
</li>
<li>
<p><strong>The Marketplace alias tags are moved by the release workflow instead of by remembering.</strong> <code>v1</code> sat at
1.24.0 through two releases because moving it was a checklist line. <code>release.yml</code>&rsquo;s last step now points
<code>vX</code> and <code>vX.Y</code> at the release it just published, with two guards a hand-run <code>git tag -f</code> skips: a
<strong>prerelease</strong> tag moves nothing (the trigger accepts <code>v1.0.4-rc.1</code>, and pointing <code>v1</code> at an rc would
hand every <code>@v1</code> consumer a prerelease), and an alias <strong>never moves backwards</strong> — re-releasing an older
patch on a line moves <code>vX.Y</code> and leaves <code>vX</code> alone. Verified by executing the logic against a synthetic
tag set rather than by reading it: releasing <code>v1.20.5</code> while <code>v1.25.0</code> exists correctly skips <code>v1</code> and
still moves <code>v1.20</code>. It runs last, after publish and the GitHub Release, so a failure there cannot
half-publish anything.</p>
<p>Alongside it, the tags are now correct: <strong><code>v2</code> and <code>v2.0</code> created</strong> (they did not exist, so nothing
pointed at the 2.x Action), and <strong><code>v1</code> moved 1.24.0 → 1.25.0</strong>. Worth recording what that move did and
did not fix: the Action&rsquo;s whole surface — <code>action.yml</code> plus the <code>render.js</code> it loads — is <strong>byte-identical
from 1.24.0 through 2.0.1</strong> apart from three lines of input <em>description</em>. So a stale <code>v1</code> was a promise
the repo had stopped keeping, not a functional gap, and the one public <code>@v1</code> consumer pins <code>version:</code> on
every step and was never exposed to the <code>latest</code> default at all.</p>
</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>
<p><strong>The invariants index said <code>check-versions.ts</code> has &ldquo;no dedicated vitest file — it&rsquo;s a standalone script,
not a unit-testable module boundary&rdquo;.</strong> Three exist, for the invariants whose logic is an exported pure
function: <code>check-cassette-version-claims</code>, <code>check-fingerprint-field-claims</code> and
<code>check-design-scope-note</code>. The claim had already been stale before this release.</p>
</li>
<li>
<p><strong>The <code>uses:</code> ref pins the Action; the <code>version:</code> input pins the CLI — and only the second one holds a
major.</strong> Both are documented as if pinning <code>@v1</code> bounded what you install. It does not: they move
independently, and <code>version:</code> defaults to <code>latest</code>, so promoting a CLI major reaches a workflow whose
<code>uses:</code> ref has not changed in months. Measured at the time of writing — <code>v1</code> points at <strong>1.24.0</strong> and
has never been moved, yet an <code>@v1</code> workflow with no <code>version:</code> input installs <strong>2.x</strong>. <code>README.md</code>,
<code>action.yml</code> (the text GitHub Marketplace renders) and <code>RELEASING.md</code>&rsquo;s alias-tag step now say so, and
name the fix: pin the <strong>input</strong> (<code>version: ^2</code>), not the ref. Crossing 1.x → 2.x this way means the
hash-format epoch, so pre-v12 cassettes need <code>cowork-harness rehash &lt;dir/&gt;</code>.</p>
<p><code>RELEASING.md</code>&rsquo;s &ldquo;move the major/minor tags&rdquo; step additionally records what moving <code>vX</code> does <em>not</em> do,
since that step reads as the thing that controls consumer upgrades and is not.</p>
</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: the <code>uses:</code> ref pins the Action, the <code>version:</code> input pins the CLI (O4-A) by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/142">https://github.com/yaniv-golan/cowork-harness/pull/142</a></li>
<li>fix: <code>projects[].from</code> joins path resolution and the session fingerprint (O3) by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/143">https://github.com/yaniv-golan/cowork-harness/pull/143</a></li>
<li>fix(protocol): describe the five frame shapes the schema was rejecting (O2) by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/144">https://github.com/yaniv-golan/cowork-harness/pull/144</a></li>
<li>chore(release): move the alias tags in the workflow, not from memory by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/145">https://github.com/yaniv-golan/cowork-harness/pull/145</a></li>
<li>docs: recommend @v2 for the Action, and bind the guard to the current major by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/146">https://github.com/yaniv-golan/cowork-harness/pull/146</a></li>
<li>docs: drop the bare version floor from the CI recipe, and let the guard see it by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/147">https://github.com/yaniv-golan/cowork-harness/pull/147</a></li>
<li>docs(changelog): restore the four entries held out of #144–#147 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/148">https://github.com/yaniv-golan/cowork-harness/pull/148</a></li>
<li>docs: complete two enumerations that went stale, and tie one to its directory by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/149">https://github.com/yaniv-golan/cowork-harness/pull/149</a></li>
<li>fix: state the sessionFingerprint field set completely, and guard the sites by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/150">https://github.com/yaniv-golan/cowork-harness/pull/150</a></li>
<li>docs: recount the fingerprint sites, and fix a stale claim in the invariants index by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/151">https://github.com/yaniv-golan/cowork-harness/pull/151</a></li>
<li>fix: pin the copy-pasteable Action steps to <code>version: &quot;^2&quot;</code>, and guard it by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/152">https://github.com/yaniv-golan/cowork-harness/pull/152</a></li>
<li>fix: warn when redaction patterns are ordered so one eats another&rsquo;s lookahead by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/153">https://github.com/yaniv-golan/cowork-harness/pull/153</a></li>
<li>test: raise the turn-layout e2e timeouts to match their measured cost by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/154">https://github.com/yaniv-golan/cowork-harness/pull/154</a></li>
<li>feat: rehash leads with its split and exits 4 on partial; cost estimate reports its basis by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/155">https://github.com/yaniv-golan/cowork-harness/pull/155</a></li>
<li>chore(release): 2.1.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/156">https://github.com/yaniv-golan/cowork-harness/pull/156</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v2.0.1...v2.1.0">https://github.com/yaniv-golan/cowork-harness/compare/v2.0.1...v2.1.0</a></p>
]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/kover-report-action/</link><pubDate>Mon, 24 Aug 2026 22:33:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.38.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating and reporting code coverage from Kover XML reports in Kotlin/Android projects, supporting multi-module support and flexible discovery methods. It allows users to configure thresholds for different module types and names, track coverage history and trends with ASCII graphs and trend indicators, and export coverage data for use in other workflow steps.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v3.1.38</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating and reporting code coverage from Kover XML reports in Kotlin/Android projects, supporting multi-module support and flexible discovery methods. It allows users to configure thresholds for different module types and names, track coverage history and trends with ASCII graphs and trend indicators, and export coverage data for use in other workflow steps.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3.1.38: PR #177 - chore(deps): lock file maintenance</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/b.ia-accessibility-checker/</link><pubDate>Mon, 24 Aug 2026 22:32:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates the process of conducting accessibility checks on code during CI/CD pipelines. It helps companies ensure their products meet WCAG guidelines by defining target audiences and percentages to be met, thus focusing resources effectively. The action uses AI analysis to assess guidelines and provides feedback for developers if the code does not comply with standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates the process of conducting accessibility checks on code during CI/CD pipelines. It helps companies ensure their products meet WCAG guidelines by defining target audiences and percentages to be met, thus focusing resources effectively. The action uses AI analysis to assess guidelines and provides feedback for developers if the code does not comply with standards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/odin-scan-smart-contract-security/</link><pubDate>Mon, 24 Aug 2026 06:19:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security analysis of smart contracts on CosmWasm, Solana, and EVM platforms using AI-powered tools. It integrates with GitHub Code Scanning to provide native security alerts, posts detailed findings as comments on pull requests, and offers customizable thresholds for failing builds based on severity level. The action supports automatic platform detection or explicit specification, and it provides options to upload SARIF files and workflow artifacts for further analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the security analysis of smart contracts on CosmWasm, Solana, and EVM platforms using AI-powered tools. It integrates with GitHub Code Scanning to provide native security alerts, posts detailed findings as comments on pull requests, and offers customizable thresholds for failing builds based on severity level. The action supports automatic platform detection or explicit specification, and it provides options to upload SARIF files and workflow artifacts for further analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial Release</p>
<p>AI-powered smart contract security analysis, now integrated directly into your GitHub workflow.</p>
<p>✨ Features</p>
<p>Multi-Platform Support</p>
<ul>
<li>CosmWasm - Rust-based smart contracts for Cosmos SDK</li>
<li>Solana (SVM) - Anchor and native Solana programs</li>
<li>EVM - Solidity and Vyper contracts</li>
<li>Auto-detection - Automatically identifies platform from your repo</li>
</ul>
<p>GitHub Integration</p>
<ul>
<li>Code Scanning - SARIF upload for native security alerts in the Security tab</li>
<li>PR Comments - Severity summary and top findings posted directly on pull requests</li>
<li>Inline Annotations - Critical/high findings appear as errors, medium/low as warnings on diffs</li>
<li>Artifact Upload - Full JSON report available as workflow artifact</li>
</ul>
<p>Customization</p>
<ul>
<li>Severity Thresholds - Fail builds at critical, high, medium, or low severity</li>
<li>Platform Override - Force specific platform detection when auto-detect isn&rsquo;t enough</li>
<li>Timeout Control - Configurable analysis timeout (default: 30 minutes)</li>
<li>Flexible Triggers - Run on push, PR, schedule, or manual dispatch</li>
</ul>
<p>🚀 Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Security Scan</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&#39;on&#39;</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">main</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">security-events</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">api-key</span>: <span style="color:#e6db74">&#39;${{ secrets.ODIN_SCAN_API_KEY }}&#39;</span>
</span></span></code></pre></div><p>📋 Requirements</p>
<ul>
<li>Odin Scan Pro subscription - Required for API access</li>
<li>API Key - Generate at <a href="https://odinscan.ai/dashboard/settings">https://odinscan.ai/dashboard/settings</a></li>
<li>GitHub Permissions - contents: read, security-events: write (for SARIF), pull-requests: write (for
comments)</li>
</ul>
<p>🔧 Configuration</p>
<p>All Inputs</p>
<p>| ┌────────────────────┬─────────────────────┬──────────────────────────────────────────────┐ |
| │       Input        │       Default       │                 Description                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ api-key            │ Required            │ Your Odin Scan API key (odin_sk_*)           │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ platform           │ auto                │ Target platform: auto, cosmwasm, solana, evm │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ severity-threshold │ high                │ Fail at: critical, high, medium, low, none   │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ fail-on-findings   │ true                │ Whether to fail workflow on findings         │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ comment-on-pr      │ true                │ Post summary comment on PRs                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-sarif       │ true                │ Upload SARIF to Code Scanning                │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-artifact    │ true                │ Upload full report as artifact               │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ timeout            │ 1800                │ Max analysis wait time (seconds)             │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ github-token       │ ${{ github.token }} │ Token for PR comments and SARIF              │ |
| └────────────────────┴─────────────────────┴──────────────────────────────────────────────┘ |</p>
<p>All Outputs</p>
<ul>
<li>analysis-id - Unique analysis identifier</li>
<li>status - Analysis status (completed, failed)</li>
<li>total-findings - Total number of findings</li>
<li>critical-count, high-count, medium-count, low-count - Counts by severity</li>
<li>report-url - Link to full report on Odin Scan</li>
<li>sarif-file - Path to generated SARIF file</li>
</ul>
<p>📝 Example Workflows</p>
<p>Basic (Auto-detect)</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span></code></pre></div><p>EVM with Medium Threshold</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">platform</span>: <span style="color:#ae81ff">evm</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">severity-threshold</span>: <span style="color:#ae81ff">medium</span>
</span></span></code></pre></div><p>Only on Solidity Changes</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#39;**.sol&#39;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">foundry.toml</span>
</span></span></code></pre></div><p>🔒 Security &amp; Privacy</p>
<ul>
<li>All API communication over HTTPS (TLS 1.2+)</li>
<li>API keys automatically masked in logs</li>
<li>No data stored by the action (stateless)</li>
<li>See <a href="https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md">https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md</a> for details</li>
</ul>
<p>📖 Documentation</p>
<ul>
<li>Action README - <a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></li>
<li>Odin Scan Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
<li>Get API Key - <a href="https://app.odinscan.ai/settings">https://app.odinscan.ai/settings</a></li>
</ul>
<p>🐛 Known Limitations</p>
<ul>
<li>Private repos - Requires github-token with repo access</li>
<li>Large repos - May need increased timeout for complex codebases</li>
<li>Code Scanning - Requires GitHub Advanced Security on private repos</li>
</ul>
<p>🙏 Support</p>
<ul>
<li>Issues - <a href="https://github.com/Odin-Scan/odin-scan-action/issues">https://github.com/Odin-Scan/odin-scan-action/issues</a></li>
<li>Email - <a href="mailto:support@odinscan.ai">support@odinscan.ai</a></li>
<li>Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
</ul>
<hr>
<p>Full Changelog: <a href="https://github.com/Odin-Scan/odin-scan-action/commits/v1">https://github.com/Odin-Scan/odin-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>Setup BoxLang CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/setup-boxlang-cli/</link><pubDate>Mon, 24 Aug 2026 06:18:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/setup-boxlang-cli/</guid><description>Version updated for https://github.com/ortus-boxlang/setup-boxlang to version 1.5.0.
This action is used across all versions by 23 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action setup-boxlang automates the setup of the BoxLang Dynamic JVM Language runtime in CI/CD workflows. It supports Linux, macOS, and Windows runners and can be customized with optional CommandBox installation, specific version selection, modules, and ForgeBox API Key configuration. The action is particularly useful for developers who need to integrate BoxLang into their CI pipelines for testing or deployment purposes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ortus-boxlang/setup-boxlang">https://github.com/ortus-boxlang/setup-boxlang</a></strong> to version <strong>1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>23</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-boxlang-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>setup-boxlang</code> automates the setup of the BoxLang Dynamic JVM Language runtime in CI/CD workflows. It supports Linux, macOS, and Windows runners and can be customized with optional CommandBox installation, specific version selection, modules, and ForgeBox API Key configuration. The action is particularly useful for developers who need to integrate BoxLang into their CI pipelines for testing or deployment purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump actions/checkout from 5 to 6 by @dependabot[bot] in <a href="https://github.com/ortus-boxlang/setup-boxlang/pull/7">https://github.com/ortus-boxlang/setup-boxlang/pull/7</a></li>
<li>Add explicit workflow permissions to resolve CodeQL security alerts by @lmajano with @Copilot in <a href="https://github.com/ortus-boxlang/setup-boxlang/pull/8">https://github.com/ortus-boxlang/setup-boxlang/pull/8</a></li>
<li>Fix: add ${BOXLANG_HOME}/bin to PATH so module executables are reachable by @lmajano in <a href="https://github.com/ortus-boxlang/setup-boxlang/pull/11">https://github.com/ortus-boxlang/setup-boxlang/pull/11</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ortus-boxlang/setup-boxlang/compare/1.2.0...1.5.0">https://github.com/ortus-boxlang/setup-boxlang/compare/1.2.0...1.5.0</a></p>
]]></content:encoded></item><item><title>Pangolinfo Data Export</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/pangolinfo-data-export/</link><pubDate>Mon, 24 Aug 2026 06:16:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/pangolinfo-data-export/</guid><description>Version updated for https://github.com/Pangolin-spg/pangolinfo-data-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates data export from Pangolinfo, a platform that provides structured data for Amazon products and AI Overview services. It supports four main products: Amazon Scraper, AI Overview SERP, Amazon Niche Data, and Amazon Alexa API. The action writes the response to a private-permission JSON file, which can be committed to a repository or retained as an artifact. Key features include retry mechanisms, logging of request details, and restrictions on API endpoints.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Pangolin-spg/pangolinfo-data-action">https://github.com/Pangolin-spg/pangolinfo-data-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pangolinfo-data-export">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates data export from Pangolinfo, a platform that provides structured data for Amazon products and AI Overview services. It supports four main products: Amazon Scraper, AI Overview SERP, Amazon Niche Data, and Amazon Alexa API. The action writes the response to a private-permission JSON file, which can be committed to a repository or retained as an artifact. Key features include retry mechanisms, logging of request details, and restrictions on API endpoints.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="pangolinfo-data-export-v100">Pangolinfo Data Export v1.0.0</h2>
<p>Run repeatable Amazon and Google AI Overview research in GitHub Actions and retain the results as JSON artifacts.</p>
<h3 id="supported-products">Supported products</h3>
<ul>
<li><strong>Amazon Scraper API:</strong> product detail, search, seller catalog, best sellers, new releases, and reviews</li>
<li><strong>AI Overview SERP API:</strong> AI answers, citations, organic results, and optional screenshots</li>
<li><strong>Amazon Niche Data API:</strong> demand, competition, click-share, and return-based niche filtering</li>
<li><strong>Amazon Alexa for Shopping API:</strong> recommendations, contextual answers, and follow-up questions</li>
</ul>
<h3 id="reliability-and-security">Reliability and security</h3>
<ul>
<li>Fixed Pangolinfo HTTPS endpoints with product-specific input validation</li>
<li>Secret masking and no response bodies in workflow logs or Action outputs</li>
<li>Safe relative output paths and owner-only file permissions</li>
<li>Bounded retries for network failures, HTTP 429, and HTTP 5xx</li>
<li>Optional provenance envelope with timestamp, endpoint, status, request ID, and attempt count</li>
<li>Seven unit tests, lint, bundle consistency check, Dependabot, and zero known npm vulnerabilities</li>
</ul>
<h3 id="start-here">Start here</h3>
<p>See the <a href="https://github.com/Pangolin-spg/pangolinfo-data-action#five-minute-quickstart">five-minute quickstart</a>, <a href="https://github.com/Pangolin-spg/pangolinfo-data-action#scheduled-ai-overview-monitoring">scheduled AI Overview example</a>, and <a href="https://github.com/Pangolin-spg/pangolinfo-data-action/tree/main/examples">product-specific examples</a>.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/Pangolin-spg/pangolinfo-data-action/blob/main/CHANGELOG.md">https://github.com/Pangolin-spg/pangolinfo-data-action/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Web App Security Skill</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/web-app-security-skill/</link><pubDate>Mon, 24 Aug 2026 06:15:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/web-app-security-skill/</guid><description>Version updated for https://github.com/parousia8888/web-app-security-skill to version v0.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates security audits of web projects using AI coding agents. It helps identify and document security risks without requiring an offensive-security background. The action reads local project files, does not contact a deployment, and writes reports with plain-language explanations and evidence of potential vulnerabilities. For supported JavaScript/TypeScript frameworks, it also generates route inventories, route-level controls, and SHA-256 sidecars for comprehensive security reviews.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/parousia8888/web-app-security-skill">https://github.com/parousia8888/web-app-security-skill</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/web-app-security-skill">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates security audits of web projects using AI coding agents. It helps identify and document security risks without requiring an offensive-security background. The action reads local project files, does not contact a deployment, and writes reports with plain-language explanations and evidence of potential vulnerabilities. For supported JavaScript/TypeScript frameworks, it also generates route inventories, route-level controls, and SHA-256 sidecars for comprehensive security reviews.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v070-release-evidence">v0.7.0 release evidence</h1>
<p>Status: published and promoted. The signed tag, GitHub Release, npm package, provenance, immutable
verified-installer/bootstrap chain and signed <code>v1</code> alias are publicly retrievable. Immutable and
post-promotion Action consumers passed.</p>
<h2 id="outcome">Outcome</h2>
<p>Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.</p>
<p>v0.7.0 corrects route-control aggregation and extends route-security into a bounded
access-control-chain review. Application controls are listed once; authentication, route
authorization and unclassified route controls are separate; and routes with no observed
route-scoped control form a human-review queue without becoming vulnerability findings.</p>
<p>For supported syntax, the analyzer records identity evidence and a caller-selected object reaching
a Prisma, Drizzle or experimental Supabase operation in the same entry or through one exact local
call. It stops before a second local call. Next.js Server Actions are represented separately from
HTTP routes. Missing visible controls or query constraints do not prove BOLA/IDOR, and every
Supabase chain retains an external RLS-policy dependency.</p>
<h2 id="evidence-sets">Evidence sets</h2>
<ul>
<li><a href="../reviews/v0.7.0-access-control-review.md"><code>v0.7.0 access-control review</code></a>: four fixed public
commits, 173 HTTP routes, 23 Server Actions and 32 manually reviewed entries. All 12 observed
ordinary-project chains are partial and zero are completed.</li>
<li><a href="../regressions/v0.7.0-access-control-real-world-regressions.md"><code>v0.7.0 access-control regressions</code></a>:
four minimized correctness failures covering application-guard aggregation, chain fingerprinting,
Next monorepo roots and exact tsconfig alias resolution.</li>
<li><a href="../conformance/v0.6.0-rule-contract-conformance.md"><code>v0.6.0 rule-contract conformance</code></a>: the
unchanged 25 built-in risk and three evidence-integrity source-rule contracts.</li>
<li><a href="../../KNOWN_LIMITATIONS.md"><code>Known limitations</code></a>: exact route, Server Action, identity,
data-operation, module-resolution, one-hop and external-policy boundaries.</li>
</ul>
<p>The ordinary-project review is purposive source-only evidence. It is not representative production
precision/recall, whole-program data flow, runtime reachability, exploitability, DAST or proof that
an audited project is secure.</p>
<h2 id="published-verification">Published verification</h2>
<p>The bounded local gate included:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm run check
</span></span><span style="display:flex;"><span>/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .
</span></span><span style="display:flex;"><span>npm pack --dry-run --json
</span></span><span style="display:flex;"><span>git -c gpg.ssh.allowedSignersFile<span style="color:#f92672">=</span>.github/release-signers verify-tag v0.7.0
</span></span></code></pre></div><p>One final-tree full local gate, one package inspection and bounded clean-room consumers are enough
unless a channel-specific failure appears.</p>
<h2 id="public-release-facts">Public release facts</h2>
<ul>
<li>The SSH-signed annotated <code>v0.7.0</code> tag object
<code>b0de94c044082d951c12d95950360d4250e12d31</code> peels to source commit
<code>bfed608b5d1abe56b6b34b09f0c6ef59f17eab4a</code>. Final-tree CI run
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32680695072"><code>32680695072</code></a>
and CodeQL run
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32680695073"><code>32680695073</code></a>
passed before tagging.</li>
<li>GitHub Release workflow
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32680851023"><code>32680851023</code></a>
published the reproducible source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-24.
Public SHA-256 values are <code>c5fa68b48e3c4a00ccc9c55fbd7a375eb1adddf9e7e8b7398f5e14a93974aa78</code>
(archive), <code>3e0c80aee8a093a3d04fa950d6e78a604c81958a4b7f984ab78cbd97276f0bf4</code>
(SBOM), <code>f707c4cceafc4864917fd47de525c522117b53c9a5724eb6a4e80e57cbbe5e37</code>
(manifest) and <code>f40a58952a221f677c9bc76b923b0f4ebd3a3dfe34b16bfb8ced885cb46aaa47</code>
(<code>SHA256SUMS</code>). Fresh downloads passed checksums, manifest validation, archive lifecycle checks and
GitHub provenance verification for all four assets.</li>
<li>npm workflow
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32680989366"><code>32680989366</code></a>
published <code>web-app-security-skill@0.7.0</code> at <code>2026-08-24T01:49:15.577Z</code> through GitHub OIDC
trusted publishing. npm records shasum <code>a46d7ab62f577dfc21998ba3350d74c7d256d86d</code>, integrity
<code>sha512-GhVvvQIDb2ahF1aiRzKD2ilszykYY8X2b6i3RAlJ0TJu7o6KjhVK09edqlAG8IRRVD/MU3Z5Q5+8m4ZMw6HFpw==</code>
and <a href="https://registry.npmjs.org/-/npm/v1/attestations/web-app-security-skill@0.7.0">SLSA provenance</a>.
Its 177 files matched the corresponding signed source-archive files byte for byte.</li>
<li>A clean-room exact-version <code>npx --yes web-app-security-skill@0.7.0 demo</code> run produced the expected
suspected HIGH lead, review proposal, fixed security retest and passing functional retest.</li>
<li>Public-state commit <code>b3e77a87cc5ee16195c0965012217416ee3a935d</code> passed CI
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32681514684"><code>32681514684</code></a>
and CodeQL
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32681514679"><code>32681514679</code></a>.
Its <code>scripts/install-verified.mjs</code> SHA-256 is
<code>4e3c6ce6c8c3ec0cfa7972edbc85b93885bae64cb714a87c926e81fc49410422</code>.</li>
<li>Verifier-pin commit <code>cb36196fb438fb0ad0e5b5a6a27043bf48ffb018</code> passed CI
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32681707779"><code>32681707779</code></a>
and CodeQL
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32681707703"><code>32681707703</code></a>.
Its <code>scripts/bootstrap-install.sh</code> SHA-256 is
<code>544d0ded89ed98467c275c838f033148d944668b0b56842d849ff8ae4abc63d2</code>.</li>
<li>A clean-room public bootstrap downloaded that exact script, verified its SHA-256, installed into
an isolated temporary home and returned <code>Web App Security Skill 0.7.0</code>. It verified source commit
<code>bfed608b5d1abe56b6b34b09f0c6ef59f17eab4a</code>, archive, manifest, checksums and SBOM. Optional GitHub
attestation was explicitly reported as not run because the isolated home had no authenticated
<code>gh</code> session; checksum and manifest verification still ran.</li>
<li>Immutable Action consumer
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32682001909"><code>32682001909</code></a>
passed against full commit <code>bfed608b5d1abe56b6b34b09f0c6ef59f17eab4a</code>. Its NestJS fixture
confirmed that the application rate-limit guard is listed once, authentication and authorization
remain separate, an unprotected state-changing object route is review evidence, and no confirmed
vulnerability is fabricated.</li>
<li>The SSH-signed annotated <code>v1</code> tag object
<code>b04630846eeb621fd40397f78b28ad92c4c4e6bc</code> was moved with a guarded lease and peels to
<code>bfed608b5d1abe56b6b34b09f0c6ef59f17eab4a</code>. Its signature verifies against
<code>.github/release-signers</code> with fingerprint
<code>SHA256:DmZYVL1dLhUmgaJnfZKpZIexgzMv5jk9+YCoBT3zRIg</code>.</li>
<li>Post-promotion public <code>@v1</code> consumer
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32682179514"><code>32682179514</code></a>
passed the passive crawl, authorization-refusal and immutable NestJS route-security v2 checks.</li>
</ul>
<p>Artifact identity, consumer success and provenance do not prove every detector conclusion correct
or an audited project secure. <code>v1</code> is intentionally movable; consumers requiring an immutable
workflow must use the full source commit.</p>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/postman-api-onboarding/</link><pubDate>Mon, 24 Aug 2026 06:13:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v3.4.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the onboarding process for a new API repository, from workspace creation and OpenAPI upload to collection generation, repository artifact sync, and smoke and contract runs. It ensures that executable tests are left behind by integrating with Postman’s Onboarding suite tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v3.4.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the onboarding process for a new API repository, from workspace creation and OpenAPI upload to collection generation, repository artifact sync, and smoke and contract runs. It ensures that executable tests are left behind by integrating with Postman&rsquo;s Onboarding suite tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/91">https://github.com/postman-cs/postman-api-onboarding-action/pull/91</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/92">https://github.com/postman-cs/postman-api-onboarding-action/pull/92</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/93">https://github.com/postman-cs/postman-api-onboarding-action/pull/93</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/94">https://github.com/postman-cs/postman-api-onboarding-action/pull/94</a></li>
<li>chore(deps): pin Insights onboarding v2.2.1 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/95">https://github.com/postman-cs/postman-api-onboarding-action/pull/95</a></li>
<li>fix: consume Insights human-session normalization by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/96">https://github.com/postman-cs/postman-api-onboarding-action/pull/96</a></li>
<li>fix: consume repo-sync v2.2.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/97">https://github.com/postman-cs/postman-api-onboarding-action/pull/97</a></li>
<li>fix: expose mock environment and refresh Azure pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/98">https://github.com/postman-cs/postman-api-onboarding-action/pull/98</a></li>
<li>feat: pass mock visibility policy through to repo-sync by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/99">https://github.com/postman-cs/postman-api-onboarding-action/pull/99</a></li>
<li>chore: pin repo-sync v2.4.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/100">https://github.com/postman-cs/postman-api-onboarding-action/pull/100</a></li>
<li>fix: document private mock credential paths for consumers by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/101">https://github.com/postman-cs/postman-api-onboarding-action/pull/101</a></li>
<li>fix(deps): advance the bootstrap pin to v2.13.2 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/102">https://github.com/postman-cs/postman-api-onboarding-action/pull/102</a></li>
<li>fix(deps): advance bootstrap and repo-sync pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/103">https://github.com/postman-cs/postman-api-onboarding-action/pull/103</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/104">https://github.com/postman-cs/postman-api-onboarding-action/pull/104</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.8 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/105">https://github.com/postman-cs/postman-api-onboarding-action/pull/105</a></li>
<li>fix(deps): advance bootstrap pin to v2.13.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/106">https://github.com/postman-cs/postman-api-onboarding-action/pull/106</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>fix(ci): validate sibling pins without local checkouts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/111">https://github.com/postman-cs/postman-api-onboarding-action/pull/111</a></li>
<li>feat(azure-devops): forward an explicit workspace squad id from the Windows template by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/112">https://github.com/postman-cs/postman-api-onboarding-action/pull/112</a></li>
<li>fix(release): harden composite pin and E2E releases by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/113">https://github.com/postman-cs/postman-api-onboarding-action/pull/113</a></li>
<li>fix(release): supersede stale aliases with pending cuts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/114">https://github.com/postman-cs/postman-api-onboarding-action/pull/114</a></li>
<li>fix(release): wait for correlated E2E run names by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/115">https://github.com/postman-cs/postman-api-onboarding-action/pull/115</a></li>
<li>fix(release): keep pin ratchet synchronized by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/116">https://github.com/postman-cs/postman-api-onboarding-action/pull/116</a></li>
<li>fix(ci): preserve pin updater test fixtures by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/117">https://github.com/postman-cs/postman-api-onboarding-action/pull/117</a></li>
<li>fix(release): reconcile failed release completions by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/118">https://github.com/postman-cs/postman-api-onboarding-action/pull/118</a></li>
<li>fix(release): emit automated completion events by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/119">https://github.com/postman-cs/postman-api-onboarding-action/pull/119</a></li>
<li>fix(release): bound failed release recovery by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/120">https://github.com/postman-cs/postman-api-onboarding-action/pull/120</a></li>
<li>fix(release): hold auto release through E2E completion by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/121">https://github.com/postman-cs/postman-api-onboarding-action/pull/121</a></li>
<li>feat: expose spec-only onboarding scope by @sean-riney in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/123">https://github.com/postman-cs/postman-api-onboarding-action/pull/123</a></li>
<li>docs: add service-account workspace permission preflight by @andrewpostymt in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/122">https://github.com/postman-cs/postman-api-onboarding-action/pull/122</a></li>
<li>chore(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/108">https://github.com/postman-cs/postman-api-onboarding-action/pull/108</a></li>
<li>fix(ci): make cache pin assertion semantic by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/124">https://github.com/postman-cs/postman-api-onboarding-action/pull/124</a></li>
<li>chore(deps): bump actions/cache from 4.2.0 to 6.1.0 in the actions group across 1 directory by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/109">https://github.com/postman-cs/postman-api-onboarding-action/pull/109</a></li>
<li>feat: publish as @postman/onboarding-api with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/127">https://github.com/postman-cs/postman-api-onboarding-action/pull/127</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@github-actions[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>@andrewpostymt made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/122">https://github.com/postman-cs/postman-api-onboarding-action/pull/122</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.4.1">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.4.1</a></p>
]]></content:encoded></item><item><title>Postman Onboarding AWS Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/postman-onboarding-aws-spec-discovery/</link><pubDate>Mon, 24 Aug 2026 06:12:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/postman-onboarding-aws-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v3.3.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the discovery and export of API specs from AWS services using your existing AWS credentials. It solves the problem of setting up a source-of-truth Spec Hub specification for Postman onboarding, which can be used to create deterministic collections, OpenAPI-backed contract checks, smoke tests, mocks, monitors, repo artifacts, and CI runs. The action is designed to work with various AWS services including API Gateway, AppSync, SNS, EventBridge, Lambda, SSM, etc., and requires only your AWS credentials for operation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-aws-spec-discovery-action">https://github.com/postman-cs/postman-aws-spec-discovery-action</a></strong> to version <strong>v3.3.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-aws-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the discovery and export of API specs from AWS services using your existing AWS credentials. It solves the problem of setting up a source-of-truth Spec Hub specification for Postman onboarding, which can be used to create deterministic collections, OpenAPI-backed contract checks, smoke tests, mocks, monitors, repo artifacts, and CI runs. The action is designed to work with various AWS services including API Gateway, AppSync, SNS, EventBridge, Lambda, SSM, etc., and requires only your AWS credentials for operation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/53">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/53</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/54">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/54</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/55">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/55</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/56">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/56</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/57">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/57</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/58">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/58</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/62">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/62</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/64">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/64</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/65">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/65</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/66">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/66</a></li>
<li>fix(ci): address Codex writeback feedback by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/67">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/67</a></li>
<li>fix(ci): use ESM execSync and update permission test by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/68">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/68</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/69">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/69</a></li>
<li>feat: publish as @postman/onboarding-aws-spec-discovery with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/73">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/73</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v3.1.4...v3.3.0">https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v3.1.4...v3.3.0</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Azure Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/postman-onboarding-azure-spec-discovery/</link><pubDate>Mon, 24 Aug 2026 06:11:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/postman-onboarding-azure-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-azure-spec-discovery-action to version v1.5.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically discovers and exports API specifications from Azure services using your existing Azure credentials, automating the process of setting up a source-of-truth for Postman onboarding. It resolves and selects the most appropriate API specification based on various criteria such as committed .postman bindings, explicit api-id, or specific tags. If there are multiple candidates, it narrows down the selection using a six-tier pipeline until a single specification is chosen. The action handles different Azure providers and supports various formats of specifications, including OpenAPI, AsyncAPI, and WSDL. It also provides zero-config discovery without requiring secret inputs, only needing provider-specific read access permissions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-azure-spec-discovery-action">https://github.com/postman-cs/postman-azure-spec-discovery-action</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-azure-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically discovers and exports API specifications from Azure services using your existing Azure credentials, automating the process of setting up a source-of-truth for Postman onboarding. It resolves and selects the most appropriate API specification based on various criteria such as committed <code>.postman</code> bindings, explicit <code>api-id</code>, or specific tags. If there are multiple candidates, it narrows down the selection using a six-tier pipeline until a single specification is chosen. The action handles different Azure providers and supports various formats of specifications, including OpenAPI, AsyncAPI, and WSDL. It also provides zero-config discovery without requiring secret inputs, only needing provider-specific read access permissions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/15">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/15</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/18">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/18</a></li>
<li>fix(test): assert the packaged version against package.json by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/19">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/19</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/20">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/20</a></li>
<li>fix(release): fetch the tag parent before ancestry checks by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/21">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/21</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/22">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/22</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/23">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/23</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/24">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/24</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/26">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/26</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/28">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/28</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/29">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/29</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/30">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/30</a></li>
<li>fix(ci): address Codex writeback feedback by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/31">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/31</a></li>
<li>fix(ci): use ESM execSync and update permission test by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/32">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/32</a></li>
<li>test(windows): preserve gate timing under contention by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/34">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/34</a></li>
<li>feat: publish as @postman/onboarding-azure-spec-discovery with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/38">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/38</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/compare/v1.3.5...v1.5.0">https://github.com/postman-cs/postman-azure-spec-discovery-action/compare/v1.3.5...v1.5.0</a></p>
]]></content:encoded></item><item><title>Postman Onboarding GCP Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/postman-onboarding-gcp-spec-discovery/</link><pubDate>Mon, 24 Aug 2026 06:10:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/postman-onboarding-gcp-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-gcp-spec-discovery-action to version v1.3.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the discovery and export of OpenAPI specifications from GCP services, supporting Application Default Credentials or Workload Identity Federation. It resolves a service based on repository context or labels, automatically discovers an API if labeled, or explicitly specifies an API ID to export. The action supports exporting multiple candidates and handles ambiguous label resolutions by requiring manual review.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action">https://github.com/postman-cs/postman-gcp-spec-discovery-action</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-gcp-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the discovery and export of OpenAPI specifications from GCP services, supporting Application Default Credentials or Workload Identity Federation. It resolves a service based on repository context or labels, automatically discovers an API if labeled, or explicitly specifies an API ID to export. The action supports exporting multiple candidates and handles ambiguous label resolutions by requiring manual review.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut and verify tags by ancestry by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/27">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/27</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/30">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/30</a></li>
<li>fix(test): assert the packaged version against package.json by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/31">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/31</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/32">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/32</a></li>
<li>fix(release): fetch the tag parent before ancestry checks by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/33">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/33</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/34">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/34</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/35">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/35</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/36">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/36</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/40">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/40</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/42">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/42</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/43">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/43</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/44">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/44</a></li>
<li>fix(ci): address Codex writeback feedback by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/45">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/45</a></li>
<li>fix(ci): use ESM execSync and update permission test by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/46">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/46</a></li>
<li>feat: publish as @postman/onboarding-gcp-spec-discovery with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/50">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/50</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/compare/v1.1.8...v1.3.0">https://github.com/postman-cs/postman-gcp-spec-discovery-action/compare/v1.1.8...v1.3.0</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Service Token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/postman-onboarding-service-token/</link><pubDate>Mon, 24 Aug 2026 06:09:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/postman-onboarding-service-token/</guid><description>Version updated for https://github.com/postman-cs/postman-resolve-service-token-action to version v2.2.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the minting of a fresh service-account access token and team ID in CI, ready to be used by the Postman API Onboarding suite. It supports different regions and can be used either as a recommended credential producer or an existing workflow refresh mechanism. The action generates the tokens and emits them as outputs that can be referenced by other actions in the workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-resolve-service-token-action">https://github.com/postman-cs/postman-resolve-service-token-action</a></strong> to version <strong>v2.2.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-service-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the minting of a fresh service-account access token and team ID in CI, ready to be used by the Postman API Onboarding suite. It supports different regions and can be used either as a recommended credential producer or an existing workflow refresh mechanism. The action generates the tokens and emits them as outputs that can be referenced by other actions in the workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(release): verify service-token artifacts and async monitors by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/37">https://github.com/postman-cs/postman-resolve-service-token-action/pull/37</a></li>
<li>perf(ci): accelerate Windows parity gate by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/38">https://github.com/postman-cs/postman-resolve-service-token-action/pull/38</a></li>
<li>test: avoid empty npm CLI path on Windows by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/39">https://github.com/postman-cs/postman-resolve-service-token-action/pull/39</a></li>
<li>chore: prepare v2.0.5 release by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/40">https://github.com/postman-cs/postman-resolve-service-token-action/pull/40</a></li>
<li>fix(release): classify dispatch-cut runs by the cut tag ref by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/41">https://github.com/postman-cs/postman-resolve-service-token-action/pull/41</a></li>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/42">https://github.com/postman-cs/postman-resolve-service-token-action/pull/42</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/43">https://github.com/postman-cs/postman-resolve-service-token-action/pull/43</a></li>
<li>fix(release): pass the required version input when dispatching a cut tag by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/44">https://github.com/postman-cs/postman-resolve-service-token-action/pull/44</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/45">https://github.com/postman-cs/postman-resolve-service-token-action/pull/45</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/46">https://github.com/postman-cs/postman-resolve-service-token-action/pull/46</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/47">https://github.com/postman-cs/postman-resolve-service-token-action/pull/47</a></li>
<li>chore(deps): bump the npm-minor-patch group across 1 directory with 3 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/51">https://github.com/postman-cs/postman-resolve-service-token-action/pull/51</a></li>
<li>fix(ci): make cache pin assertion semantic by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/52">https://github.com/postman-cs/postman-resolve-service-token-action/pull/52</a></li>
<li>chore(deps): bump actions/cache from 4.2.0 to 6.1.0 in the actions group across 1 directory by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/48">https://github.com/postman-cs/postman-resolve-service-token-action/pull/48</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/53">https://github.com/postman-cs/postman-resolve-service-token-action/pull/53</a></li>
<li>feat: publish as @postman/onboarding-resolve-service-token with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/56">https://github.com/postman-cs/postman-resolve-service-token-action/pull/56</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-resolve-service-token-action/compare/v2.0.4...v2.2.0">https://github.com/postman-cs/postman-resolve-service-token-action/compare/v2.0.4...v2.2.0</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Smoke Flow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/postman-onboarding-smoke-flow/</link><pubDate>Mon, 24 Aug 2026 06:08:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/postman-onboarding-smoke-flow/</guid><description>Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v3.6.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Smoke Flow action automates the reshaping of generated Postman collections into an ordered smoke journey. It solves the problem of organizing and managing API testing flows within a collection by utilizing either an explicit flow-path or creating one from the OpenAPI spec. The action handles OAuth2 authentication and can persist the derived manifest for future use, enhancing workflow efficiency in continuous integration/continuous deployment (CI/CD) pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-smoke-flow-action">https://github.com/postman-cs/postman-smoke-flow-action</a></strong> to version <strong>v3.6.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-smoke-flow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Smoke Flow action automates the reshaping of generated Postman collections into an ordered smoke journey. It solves the problem of organizing and managing API testing flows within a collection by utilizing either an explicit <code>flow-path</code> or creating one from the OpenAPI spec. The action handles OAuth2 authentication and can persist the derived manifest for future use, enhancing workflow efficiency in continuous integration/continuous deployment (CI/CD) pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): cut immutable tags only after gates pass on main by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/57">https://github.com/postman-cs/postman-smoke-flow-action/pull/57</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/58">https://github.com/postman-cs/postman-smoke-flow-action/pull/58</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/59">https://github.com/postman-cs/postman-smoke-flow-action/pull/59</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/60">https://github.com/postman-cs/postman-smoke-flow-action/pull/60</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/61">https://github.com/postman-cs/postman-smoke-flow-action/pull/61</a></li>
<li>docs: make gate commands independently verifiable by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/76">https://github.com/postman-cs/postman-smoke-flow-action/pull/76</a></li>
<li>feat: publish as @postman/onboarding-smoke-flow with best-effort npm publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/80">https://github.com/postman-cs/postman-smoke-flow-action/pull/80</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.7...v3.6.0">https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.7...v3.6.0</a></p>
]]></content:encoded></item><item><title>Patchbot Vulnerability Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/patchbot-vulnerability-scanner/</link><pubDate>Mon, 24 Aug 2026 06:06:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/patchbot-vulnerability-scanner/</guid><description>Version updated for https://github.com/PrismorSec/patchbot to version v0.2.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by ? repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Patchbot automates vulnerability scanning and fix PR creation by inventorying project dependencies, matching them against threat feeds, accepting scanner findings, and fixing broken builds through a coding agent. It supports multiple scanners and threat feeds, handles version bumps, and ensures re-scanning before each PR to maintain a clean commit history.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PrismorSec/patchbot">https://github.com/PrismorSec/patchbot</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>?</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/patchbot-vulnerability-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Patchbot automates vulnerability scanning and fix PR creation by inventorying project dependencies, matching them against threat feeds, accepting scanner findings, and fixing broken builds through a coding agent. It supports multiple scanners and threat feeds, handles version bumps, and ensures re-scanning before each PR to maintain a clean commit history.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="highlights">Highlights</h3>
<ul>
<li><strong>Tiered fix loop</strong>: deterministic version bump + lockfile regeneration first; a coding agent only when the bump fails, briefed with the failure itself. Every PR is re-scanned before it opens.</li>
<li><strong>Four agent backends</strong>: <code>claude</code> / <code>codex</code> CLIs, <code>api</code> (Anthropic SDK, no Node), <code>command</code> (bring your own agent), and <code>managed</code> (Claude Managed Agents: the agent runs off your CI runner and your GitHub token never enters the sandbox).</li>
<li><strong>Scheduled deployments</strong>: <code>patchbot managed deploy</code> runs scan + fix on a cron schedule with no CI at all.</li>
<li><strong>GitHub Action</strong>: SARIF upload to the Security tab, optional auto-fix PRs, <code>model</code> and <code>managed-*</code> inputs.</li>
<li>Bring your own threat feed (any OSV-format file or URL) and bring your own scanner (trivy, grype, osv-scanner, or any tool that emits SARIF).</li>
</ul>
<h3 id="usage">Usage</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">PrismorSec/patchbot@v0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><p>See the README for auto-fix and Managed Agents setups.</p>
]]></content:encoded></item><item><title>Multi-Style Contribution Snake</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/multi-style-contribution-snake/</link><pubDate>Mon, 24 Aug 2026 06:05:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/multi-style-contribution-snake/</guid><description>Version updated for https://github.com/Pro-Bandey/multi-style-snake-contribution-grid to version v24.08.26.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates a dynamic animation of a Snake contribution grid for your GitHub repository using multiple styles, including 5 unique themes. It automatically detects the repository owner, creates SVGs and GIFs of different shapes and backgrounds, and updates a README.md branch with all assets. The generated content is suitable for personal or professional use in profiles to showcase contributions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Pro-Bandey/multi-style-snake-contribution-grid">https://github.com/Pro-Bandey/multi-style-snake-contribution-grid</a></strong> to version <strong>v24.08.26</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/multi-style-contribution-snake">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates a dynamic animation of a Snake contribution grid for your GitHub repository using multiple styles, including 5 unique themes. It automatically detects the repository owner, creates SVGs and GIFs of different shapes and backgrounds, and updates a <code>README.md</code> branch with all assets. The generated content is suitable for personal or professional use in profiles to showcase contributions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-multi-style-snake-daily-update">🐍 Multi-Style Snake Daily Update</h2>
<p>Automated daily release to the GitHub Marketplace.</p>
<p><strong>Version Details:</strong></p>
<ul>
<li><strong>Tag:</strong> <code>v24.08.26</code></li>
<li><strong>Release Date:</strong> $(date +&rsquo;%A, %B %d, 20%y')</li>
</ul>
<p><strong>Included Features:</strong></p>
<ul>
<li>5 Unique Snake Styles (Blocks, Rounds, Triangles, Stars, Diamonds)</li>
<li>Automated Month Labels above grids</li>
<li>Dynamic Username Detection</li>
<li>Auto-generated Asset Gallery</li>
</ul>
]]></content:encoded></item><item><title>Python Nurse</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/python-nurse/</link><pubDate>Mon, 24 Aug 2026 06:04:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/python-nurse/</guid><description>Version updated for https://github.com/sfroning88/python-nurse to version v1.0.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Python Nurse is a GitHub Action that performs static analysis on Python monorepo apps, including linting, type checking, security scanning, dead code detection, complexity measurement, and more. It calculates a 0-100 health score for PRs based on the findings of these tools and posts actionable diagnostics as collapsible PR comments with nurse reaction images.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sfroning88/python-nurse">https://github.com/sfroning88/python-nurse</a></strong> to version <strong>v1.0.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/python-nurse">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Python Nurse is a GitHub Action that performs static analysis on Python monorepo apps, including linting, type checking, security scanning, dead code detection, complexity measurement, and more. It calculates a 0-100 health score for PRs based on the findings of these tools and posts actionable diagnostics as collapsible PR comments with nurse reaction images.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>vulture &ndash;ignore-names action input by @sfroning88 in <a href="https://github.com/sfroning88/python-nurse/pull/10">https://github.com/sfroning88/python-nurse/pull/10</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sfroning88/python-nurse/compare/v1.0.6...v1.0.7">https://github.com/sfroning88/python-nurse/compare/v1.0.6...v1.0.7</a></p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/bernstein-multi-agent-orchestration/</link><pubDate>Mon, 24 Aug 2026 06:03:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.17.2.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is a deterministic multi-agent CLI orchestration tool that automates the deployment and management of complex systems by orchestrating multiple agents to execute tasks in parallel. It solves the problem of managing distributed applications with many interconnected components, ensuring consistency and reliability. The key capabilities include defining workflows, managing dependencies between tasks, and monitoring agent performance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.17.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein is a deterministic multi-agent CLI orchestration tool that automates the deployment and management of complex systems by orchestrating multiple agents to execute tasks in parallel. It solves the problem of managing distributed applications with many interconnected components, ensuring consistency and reliability. The key capabilities include defining workflows, managing dependencies between tasks, and monitoring agent performance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A patch release about proof: what a run recorded, and whether you can still check it afterwards.</p>
<h2 id="receipts-you-can-re-derive">Receipts you can re-derive</h2>
<p>A gate verdict is three-valued, but receipts stored only the outcome, so an auditor re-running the check offline could not tell a refusal from an abstention. Receipts carry the verdict now, and it re-derives without the run (#4182).</p>
<p>Spawn context was assembled from a dozen sources and hashed as one blob. Each part now gets its own content hash in a receipt, in prompt order, so a prompt that changed can be narrowed to the section that changed it (#4303). An agent working inside a subtree is handed that subtree&rsquo;s <code>.sdd/project.md</code> rather than only the root&rsquo;s (#4304). The breakdown surface that never got populated is gone (#4422).</p>
<p>A persistent-agent adapter carries state Bernstein never hashed, so replaying its inputs proves nothing. Those runs mark their artifacts <code>unverifiable</code> rather than <code>verified</code> (#4290), and <code>letta_code</code> declares itself as one (#4289).</p>
<p>The receipt ledger has a pure active-set closure (#4183). <code>LineageGate.check</code> verifies who wrote a permission-bearing file, not what the write grants — the two are different questions and it was answering the wrong one (#3768). Admission receipts were never written at all for an adapter whose name contains a space; the filename is slugged now (#4363). A CAS sidecar read skipped the anchored walk on an assumption nothing enforced (#3582).</p>
<h2 id="runs-that-lied-about-themselves">Runs that lied about themselves</h2>
<p>A planning task that decomposed into nothing reported the run as successful. It fails now (#4401). Three <code>/status</code> surfaces counted live agents three different ways, so the same run read as busy on one and idle on another (#4360). A task stranded by a failed dependency stayed stranded after that dependency was retried and succeeded (#4376).</p>
<p>A <code>skip-worktree</code> CLAUDE.md left by a killed run survived <code>reset --hard</code> and poisoned every later run in that checkout (#4394).</p>
<h2 id="models-and-transport">Models and transport</h2>
<p>Every 429 was backed off as a rate limit, including standing account caps that no retry can clear — the agent spent its budget waiting for a wall to move (#4378). The last-green adapter table showed a never-probed adapter as merely stale (#4387).</p>
<p>The assembled system prompt now has a spawn-time budget: over a configurable share of the model&rsquo;s context window it warns, naming the sections responsible (#4377).</p>
<h2 id="security">Security</h2>
<p>A resume whose grant moved is refused before the first side effect, not after (#3834). The skills and MCP catalog fetchers reject internal-host destinations (#4301, #4302).</p>
<h2 id="also">Also</h2>
<p>RPM never published when the install smoke outran PyPI index propagation (#4383). The metric buffer dropped every target&rsquo;s lines when one target&rsquo;s write failed (#3710). Coverage baseline is 84.08%. Agent working notes under <code>scratch/</code> no longer ride along in unrelated commits.</p>
<p>Soundtrack: <a href="https://suno.com/s/mlHRUsFOZfhEUL96">https://suno.com/s/mlHRUsFOZfhEUL96</a></p>
<hr>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(lineage): add active-set closure over the receipt ledger (#4183) by @Louis20060723 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4384">https://github.com/sipyourdrink-ltd/bernstein/pull/4384</a></li>
<li>fix(adapters): slug receipt filenames so spaced adapter names can persist by @Rehan30g in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4386">https://github.com/sipyourdrink-ltd/bernstein/pull/4386</a></li>
<li>Add issue-to-PR and PR-intake-review scenario recipes by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4379">https://github.com/sipyourdrink-ltd/bernstein/pull/4379</a></li>
<li>Keep git housekeeping off in the dogfood fixture helper by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4380">https://github.com/sipyourdrink-ltd/bernstein/pull/4380</a></li>
<li>docs: regenerate adapter last-green table from canary receipts by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4385">https://github.com/sipyourdrink-ltd/bernstein/pull/4385</a></li>
<li>Bound how long a failed metric target is retried by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4381">https://github.com/sipyourdrink-ltd/bernstein/pull/4381</a></li>
<li>feat(adapters): annotate last-green rows probed absent as (not probed) by @Louis20060723 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4389">https://github.com/sipyourdrink-ltd/bernstein/pull/4389</a></li>
<li>feat: reject internal-host destinations in the MCP-catalog fetcher by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4390">https://github.com/sipyourdrink-ltd/bernstein/pull/4390</a></li>
<li>fix(tests): make plan-loader flag assertion path-independent by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4392">https://github.com/sipyourdrink-ltd/bernstein/pull/4392</a></li>
<li>fix(tests): stop asserting on Rich-wrapped output in ticket validate CLI by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4396">https://github.com/sipyourdrink-ltd/bernstein/pull/4396</a></li>
<li>fix(skills): reject internal-host destinations in the catalog fetcher by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4397">https://github.com/sipyourdrink-ltd/bernstein/pull/4397</a></li>
<li>fix(cli): harden run attestation projection by @Silentpartnercoding in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4391">https://github.com/sipyourdrink-ltd/bernstein/pull/4391</a></li>
<li>fix(mypy): fix call-overload, attr-defined, and arg-type in core/config by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4388">https://github.com/sipyourdrink-ltd/bernstein/pull/4388</a></li>
<li>feat: declare letta_code&rsquo;s session_state as persistent-agent by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4400">https://github.com/sipyourdrink-ltd/bernstein/pull/4400</a></li>
<li>chore(ci): ratchet coverage baseline up to 84.08% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4402">https://github.com/sipyourdrink-ltd/bernstein/pull/4402</a></li>
<li>feat: mark replay verdict unverifiable for a run that used a persistent-agent adapter by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4404">https://github.com/sipyourdrink-ltd/bernstein/pull/4404</a></li>
<li>fix(cas): anchor sidecar metadata reads by @k4its1t in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4399">https://github.com/sipyourdrink-ltd/bernstein/pull/4399</a></li>
<li>fix: every 429 is backed off as a rate limit, including caps a retry cannot clear by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4405">https://github.com/sipyourdrink-ltd/bernstein/pull/4405</a></li>
<li>fix(mypy): fix valid-type and call-overload in core/git by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4403">https://github.com/sipyourdrink-ltd/bernstein/pull/4403</a></li>
<li>feat: scope spawn project-context to the task&rsquo;s target subtree by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4406">https://github.com/sipyourdrink-ltd/bernstein/pull/4406</a></li>
<li>fix(mypy): fix call-overload and assignment in core/integrations by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4407">https://github.com/sipyourdrink-ltd/bernstein/pull/4407</a></li>
<li>feat: carry the three-valued gate verdict into receipts and re-derive it offline by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4408">https://github.com/sipyourdrink-ltd/bernstein/pull/4408</a></li>
<li>feat: record a per-part content-hash receipt for spawn-context assembly by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4409">https://github.com/sipyourdrink-ltd/bernstein/pull/4409</a></li>
<li>refactor: drop the unpopulated context_parts breakdown surface by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4422">https://github.com/sipyourdrink-ltd/bernstein/pull/4422</a></li>
<li>feat: refuse a resume whose grant moved, before the first side effect by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4412">https://github.com/sipyourdrink-ltd/bernstein/pull/4412</a></li>
<li>fix(git): clear stale skip-worktree CLAUDE.md in pre-startup hygiene (#4394) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4414">https://github.com/sipyourdrink-ltd/bernstein/pull/4414</a></li>
<li>fix(tasks): fail zero-yield planning task instead of reporting success (#4401) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4415">https://github.com/sipyourdrink-ltd/bernstein/pull/4415</a></li>
<li>fix(ci): make PyPI index propagation timeout message explicit (#4383) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4419">https://github.com/sipyourdrink-ltd/bernstein/pull/4419</a></li>
<li>feat: lineageGate.check verifies who wrote a permission-bearing file, never what the write grants by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4421">https://github.com/sipyourdrink-ltd/bernstein/pull/4421</a></li>
<li>fix(adapters): classify standing account/quota caps separately from transient rate limits (#4378) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4417">https://github.com/sipyourdrink-ltd/bernstein/pull/4417</a></li>
<li>fix(status): make all three /status surfaces agree on the live agent count by @Rehan30g in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4413">https://github.com/sipyourdrink-ltd/bernstein/pull/4413</a></li>
<li>fix(mypy): fix valid-type shadowing in core/preview/manager.py by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4411">https://github.com/sipyourdrink-ltd/bernstein/pull/4411</a></li>
<li>fix(tasks): cascade unblock stranded tasks when dependency succeeds or retries (#4376) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4418">https://github.com/sipyourdrink-ltd/bernstein/pull/4418</a></li>
<li>chore: stop tracking agent working notes under scratch/ by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4423">https://github.com/sipyourdrink-ltd/bernstein/pull/4423</a></li>
<li>fix(status): unify live-agent classification across summary, agents count, and cli (#4360) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4420">https://github.com/sipyourdrink-ltd/bernstein/pull/4420</a></li>
<li>feat(tokens): enforce spawn-time system prompt budget (#4377) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4416">https://github.com/sipyourdrink-ltd/bernstein/pull/4416</a></li>
<li>release: v3.17.2 by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4425">https://github.com/sipyourdrink-ltd/bernstein/pull/4425</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@k4its1t made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4399">https://github.com/sipyourdrink-ltd/bernstein/pull/4399</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sipyourdrink-ltd/bernstein/compare/v3.17.1...v3.17.2">https://github.com/sipyourdrink-ltd/bernstein/compare/v3.17.1...v3.17.2</a></p>
]]></content:encoded></item><item><title>Validate Syscribe Model</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/validate-syscribe-model/</link><pubDate>Mon, 24 Aug 2026 06:02:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/validate-syscribe-model/</guid><description>Version updated for https://github.com/sjames/syscribe to version v0.38.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Syscribe is a GitHub Action that maps SysMLv2 semantics onto plain Markdown files with YAML frontmatter. It automates the creation and management of SysML models in a human-readable format, enabling easier collaboration, version control, and traceability across software development projects. The action supports various element types and provides features for requirements, test cases, architecture decisions, and safety analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sjames/syscribe">https://github.com/sjames/syscribe</a></strong> to version <strong>v0.38.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/validate-syscribe-model">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Syscribe is a GitHub Action that maps SysMLv2 semantics onto plain Markdown files with YAML frontmatter. It automates the creation and management of SysML models in a human-readable format, enabling easier collaboration, version control, and traceability across software development projects. The action supports various element types and provides features for requirements, test cases, architecture decisions, and safety analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sjames/syscribe/compare/v0.37.0...v0.38.0">https://github.com/sjames/syscribe/compare/v0.37.0...v0.38.0</a></p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/smyklot/</link><pubDate>Mon, 24 Aug 2026 06:01:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.47.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository’s CODEOWNERS file. It allows users to approve or merge PRs using slash commands, mentions, or bare commands, with options for various merge methods and reaction-based actions. The app uses emoji feedback and handles multiple commands in a single comment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.47.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository&rsquo;s CODEOWNERS file. It allows users to approve or merge PRs using slash commands, mentions, or bare commands, with options for various merge methods and reaction-based actions. The app uses emoji feedback and handles multiple commands in a single comment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1470-2026-08-23"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.46.2...v1.47.0">1.47.0</a> (2026-08-23)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>panel:</strong> unify workspace setting drafts (<a href="https://github.com/smykla-skalski/smyklot/issues/312">#312</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/4013c5a6bb7f28b6a0fe849ad08930ced964ccbc">4013c5a</a>)</li>
</ul>
<h2 id="smyklot-v1470">Smyklot v1.47.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.47.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>37409ddbec25d362ef6189720f49f65e1c09602a chore(release): bump version to 1.47.0</li>
<li>6891ecb1d2baf961c0afe857d8b9f34b2c8cd45d chore(deps): update dependency svelte to v5.56.10 (#313)</li>
<li>4013c5a6bb7f28b6a0fe849ad08930ced964ccbc feat(panel): unify workspace setting drafts (#312)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Mon, 24 Aug 2026 05:59:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by bundling application dependencies and committing them to the repository. It simplifies the process of preparing a Docker image for production, ensuring all necessary files are included in the commit.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by bundling application dependencies and committing them to the repository. It simplifies the process of preparing a Docker image for production, ensuring all necessary files are included in the commit.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>Agent Vigil</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/agent-vigil/</link><pubDate>Mon, 24 Aug 2026 05:59:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/agent-vigil/</guid><description>Version updated for https://github.com/sulmusic2-star/agent-vigil to version v0.16.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Vigil is a tool designed to ensure code changes in pull requests are verified against established policies, tasks, tests, and recorded actions. It checks exact code changes against the task, policy, tests, and recorded tool actions behind them, returning PASS, FAIL, or INCONCLUSIVE results. Missing evidence prevents green checkmarks. The verifier runs locally or in GitHub runners, using local policies without sharing agent transcripts. It provides commands to plan, compare receipts, generate proof comments, and create value cards for maintaining code integrity and accountability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sulmusic2-star/agent-vigil">https://github.com/sulmusic2-star/agent-vigil</a></strong> to version <strong>v0.16.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-vigil">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Vigil is a tool designed to ensure code changes in pull requests are verified against established policies, tasks, tests, and recorded actions. It checks exact code changes against the task, policy, tests, and recorded tool actions behind them, returning <strong>PASS</strong>, <strong>FAIL</strong>, or <strong>INCONCLUSIVE</strong> results. Missing evidence prevents green checkmarks. The verifier runs locally or in GitHub runners, using local policies without sharing agent transcripts. It provides commands to plan, compare receipts, generate proof comments, and create value cards for maintaining code integrity and accountability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="agent-vigil-v0160">Agent Vigil v0.16.0</h2>
<p>This release lets an organization retain signed challenge results from another control without trusting an embedded key on sight.</p>
<h3 id="added">Added</h3>
<ul>
<li>Public <code>control-proof/signed-challenge-v1</code> format for exact commits, challenge decisions, evidence hashes, timestamps, and stated limits.</li>
<li>Ed25519 verification against a separately obtained public key.</li>
<li>Key-bound policy identity: <code>vendor/product@sha256:...</code>.</li>
<li>V2 control certificates and corpus entries that can share one chain with unchanged V1 entries.</li>
<li><code>vigil certify sign</code> for providers and <code>vigil certify record-signed</code> for organization-side pinning.</li>
<li>Public JSON schemas for the signed proof, V2 certificate, and V2 corpus entry.</li>
</ul>
<h3 id="verification">Verification</h3>
<p>Exact release commit: <code>be3161fb7a85a4d69af6356e6c453ffd72ebac97</code></p>
<ul>
<li>443 tests: 438 passed, 5 optional checks skipped, 0 failed.</li>
<li>Coverage: 93.58% lines, 81.26% branches, 96.60% functions.</li>
<li>Linux Node 20, 22, and 24 plus macOS and Windows pull-request checks passed.</li>
<li>Typecheck, clean rebuild, public-surface review, production dependency audit, and 11-repository/33-setup-flow package rehearsal passed.</li>
</ul>
<p>A valid signed proof establishes file integrity, signer possession, the policy-pinned identity, and the challenge results reported by that signer. It does not independently verify private evidence, a live GitHub ruleset, external adoption, or commercial use.</p>
]]></content:encoded></item><item><title>Setup Scanner CLI for SonarQube (Server, Cloud)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/setup-scanner-cli-for-sonarqube-server-cloud/</link><pubDate>Mon, 24 Aug 2026 05:58:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/setup-scanner-cli-for-sonarqube-server-cloud/</guid><description>Version updated for https://github.com/SylvainDumas/setup-sonar-scanner to version v1.4.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up the SonarQube Scanner CLI to automate code analysis in GitHub Actions. It supports downloading and caching the latest, explicit, or semantic version of the Scanner CLI. The action also registers problem matchers for error output, making it easier to debug and understand issues during the scan process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SylvainDumas/setup-sonar-scanner">https://github.com/SylvainDumas/setup-sonar-scanner</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-scanner-cli-for-sonarqube-server-cloud">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up the SonarQube Scanner CLI to automate code analysis in GitHub Actions. It supports downloading and caching the latest, explicit, or semantic version of the Scanner CLI. The action also registers problem matchers for error output, making it easier to debug and understand issues during the scan process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="140-2026-08-23"><a href="https://github.com/SylvainDumas/setup-sonar-scanner/compare/v1.3.0...v1.4.0">1.4.0</a> (2026-08-23)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>node:</strong> upgrade action runtime to Node 24 (<a href="https://github.com/SylvainDumas/setup-sonar-scanner/issues/91">#91</a>) (<a href="https://github.com/SylvainDumas/setup-sonar-scanner/commit/fcd0f4278b385226a34c26fb7c3fff628a0aa732">fcd0f42</a>)</li>
</ul>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/compose-lint/</link><pubDate>Mon, 24 Aug 2026 05:57:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.23.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action compose-lint is a security-focused linter for Docker Compose files that checks for dangerous misconfigurations, such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. It catches these issues in CI before they reach production by automatically fixing the unambiguous ones with a dry-run first approach. The action is grounded in OWASP and the CIS Docker Benchmark and provides full rule documentation online.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.23.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>compose-lint</code> is a security-focused linter for Docker Compose files that checks for dangerous misconfigurations, such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. It catches these issues in CI before they reach production by automatically fixing the unambiguous ones with a dry-run first approach. The action is grounded in OWASP and the CIS Docker Benchmark and provides full rule documentation online.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>CL-0020 and CL-0021 now read the <code>env_file:</code> targets a service names</strong>, and
fire on a credential written in one. Compose merges those files into the
container&rsquo;s process environment, so moving a line out of <code>environment:</code> and
into an <code>env_file:</code> silenced both rules without changing what deploys — the
silent false negative
(<a href="https://github.com/tmatens/compose-lint/issues/665">#665</a>) opened on. The
decision and its grounding are
<a href="docs/adr/027-grade-env-file-where-the-document-routes-it.md">ADR-027</a>: a
value is graded where the document routes it, and an <code>env_file:</code> is a
declaration that every key in the named file becomes a literal in that
service&rsquo;s process environment.</p>
<p>Files clean on 0.22.0 may report new HIGH findings. This is the documented
MINOR behaviour, with the documented escape hatches: pin the version, or gate
on <code>--fail-on</code>. 414 of the 5,417-file corpus (7.64%) name an <code>env_file:</code>, and
496 of the 924 references name the sibling <code>.env</code> itself.</p>
<p>Measured by rebuilding real projects — fetching the targets their repositories
commit and running the rules with and without them — <strong>55% of projects whose
env file could be read gained at least one finding</strong>: 538 findings across 90 of
163 projects, 491 CL-0020 and 47 CL-0021. That is a floor on a biased sample:
only 44% of named targets are committed at all, and the gitignored remainder is
where credentials concentrate. If your compose file names an <code>env_file:</code> and
that file is present when compose-lint runs, expect roughly a coin-flip chance
of a new HIGH finding.</p>
<p><strong>No credential value reaches any output surface.</strong> <code>evidence</code> is the key
name, as it always was, and the message names the key and the file. The text
formatter no longer reads — let alone excerpts — a file that is not a Compose
document, so the line a key was written on is never printed.</p>
<p>Paths resolving outside the project directory are refused rather than read,
and say so on stderr. Compose reads them; an <code>env_file:</code> naming a lint-host
path in a pull request would otherwise put that host&rsquo;s key names into a
report.</p>
</li>
<li>
<p>A note when an <code>env_file:</code> target contributed nothing, naming which one and
why: absent, unreadable, outside the project directory, or a path still
carrying an unresolved <code>${VAR}</code>. A malformed line is noted too, with its line
number: Compose refuses a whole env file over one, while compose-lint keeps
the well-formed entries — refusing the file would drop real findings for every
other key, which is the silent false negative this work exists to remove. A <em>required</em> target&rsquo;s absence says Compose
refuses to start such a project, so the credential rules went unevaluated; an
optional one&rsquo;s absence says Compose ships the service without it, which is the
configuration that was graded. This replaces the blanket note added earlier in
this release cycle, which told every service naming an <code>env_file:</code> that the
rules had not been evaluated — true when nothing was opened, misleading beside
the findings that now fire. Stderr only, and it never touches the exit code.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><code>--no-env</code> now covers both env files beside the Compose file: the sibling
<code>.env</code> and every <code>env_file:</code> a service names. The flag&rsquo;s promise is that it
reproduces the previous release&rsquo;s behaviour, and after this change that
behaviour includes the <code>env_file:</code> read.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>A v1-shaped or compose-lint-config overlay is now an error instead of a
silent pass.</strong> Either one in a merge set made compose-lint skip the whole
project and report <code>PASS</code> at exit 0, dropping every finding in the base file.
Docker Compose <em>refuses</em> a project that includes either, so unlike the
fragment case (#671) there is no configuration to grade and merging is not
the answer: the run now exits 2 and names the file that caused it. The
own-config half mattered most — a file whose entire purpose is to disable
rules could, if named in <code>COMPOSE_FILE</code>, silence the linter completely
rather than disabling one rule
(<a href="https://github.com/tmatens/compose-lint/issues/673">#673</a>).</p>
<p>This also settles the second defect in #671: the skip handler attributed the
message to the primary path, so a valid v2 base was reported as the
unlintable file. The error now names the overlay.</p>
<p>A file linted <strong>on its own</strong> is unchanged — a bare v1 file or a stray
<code>.compose-lint.yml</code> in a sweep still skips quietly at exit 0, which is
ADR-013 and the reason that policy exists. Only the merge-set case moves.
Projects that were passing on an overlay Compose would reject will start
failing, which is the point: they were never graded.</p>
</li>
<li>
<p>A fragment overlay carrying only top-level structural keys such as
<code>volumes:</code> or <code>networks:</code>, or just <code>{}</code>, now merges into the linted
configuration instead of skipping the whole project. Compose folds it
into its base and deploys the result, but compose-lint let the
fragment raise out of the merge and reported <code>PASS</code> at exit 0 without
grading anything in the base file: a two-byte overlay could silence
every finding, CRITICAL ones included
(<a href="https://github.com/tmatens/compose-lint/issues/671">#671</a>).</p>
<p>Findings only move toward coverage here, the same shape that #648,
#657 and #668 shipped under: affected projects see previously
withheld findings. The merge direction does not care which half
holds the <code>services:</code> — a fragment <em>base</em> beside an overlay that
carries them now lints too, where it previously skipped whole. A
merge set where every selected file is a
fragment still skips at exit 0, files linted on their own are
unchanged, and v1-shaped or own-config overlays keep their current
behavior until their separate error path lands (#673).</p>
<p>Thanks <a href="https://github.com/krishna3554">@krishna3554</a> (<a href="https://github.com/tmatens/compose-lint/pull/675">#675</a>).</p>
</li>
<li>
<p>A parse error in an automatically merged <code>compose.override.yml</code> is now
reported against the file that actually failed in text, JSON, and SARIF. It
previously named the base file at a line number that did not exist there
(<a href="https://github.com/tmatens/compose-lint/issues/666">#666</a>).</p>
<p>Thanks <a href="https://github.com/nightcityblade">@nightcityblade</a> (<a href="https://github.com/tmatens/compose-lint/pull/670">#670</a>).</p>
</li>
<li>
<p>Every Compose substitution operator now resolves against a sibling <code>.env</code>,
not just <code>${VAR:-default}</code> and <code>${VAR-default}</code>. <code>${VAR:?err}</code>, <code>${VAR?err}</code>,
<code>${VAR:+alt}</code> and <code>${VAR+alt}</code> fetched the <code>.env</code> value and then discarded it,
so a <code>${BIND:?required}</code> that Compose resolves to <code>0.0.0.0</code> reached the rules
as source text and CL-0005 could not fire. The same function also shipped the
empty string for <code>${VAR:-default}</code> where <code>.env</code> sets <code>VAR=</code> and Compose ships
the default — a <code>:</code>-prefixed operator treats an empty value as unset. All
eighteen operator/state combinations are now pinned by a differential test
against the Compose binary
(<a href="https://github.com/tmatens/compose-lint/issues/664">#664</a>).</p>
<p>Findings only change for a project that ships a <code>.env</code>: with none, every
operator was and remains unresolved. The 5,417-file corpus produces a byte-
identical result set.</p>
</li>
<li>
<p>CL-0020 now exempts additional credential-shaped quantity knobs, including
work factors, retry counters, lengths, strength values, and cost knobs when
their values are bare quantities (<a href="https://github.com/tmatens/compose-lint/issues/681">#681</a>).</p>
<p>Thanks <a href="https://github.com/AdhravRai">@AdhravRai</a> (<a href="https://github.com/tmatens/compose-lint/pull/685">#685</a>).</p>
</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/wails3-build-action/</link><pubDate>Mon, 24 Aug 2026 05:56:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the build process for Wails.io v3 projects. It installs GoLang and NodeJS, builds the application using default or specified platform settings, and optionally uploads the results to GitHub and releases on tagged builds. The action supports building and publishing applications across different platforms like macOS, Windows, and Linux with optional obfuscation and caching features.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the build process for Wails.io v3 projects. It installs GoLang and NodeJS, builds the application using default or specified platform settings, and optionally uploads the results to GitHub and releases on tagged builds. The action supports building and publishing applications across different platforms like macOS, Windows, and Linux with optional obfuscation and caching features.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>UnityInFlow Spec Compliance</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/unityinflow-spec-compliance/</link><pubDate>Mon, 24 Aug 2026 05:55:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/unityinflow-spec-compliance/</guid><description>Version updated for https://github.com/UnityInFlow/spec-ci-plugin to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action spec-ci-plugin automates spec compliance checks on pull requests by enforcing specs using various tools like spec-linter, injection-scanner, scope checker, and criteria checker. It posts a structured report as a PR comment detailing the validation of the spec file, security scan results, scope compliance, and acceptance criteria coverage.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/UnityInFlow/spec-ci-plugin">https://github.com/UnityInFlow/spec-ci-plugin</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/unityinflow-spec-compliance">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>spec-ci-plugin</code> automates spec compliance checks on pull requests by enforcing specs using various tools like spec-linter, injection-scanner, scope checker, and criteria checker. It posts a structured report as a PR comment detailing the validation of the spec file, security scan results, scope compliance, and acceptance criteria coverage.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Security release.</strong> <code>@v1</code> had been serving <code>v1.0.0</code> since July, four months of fixes behind — including both fixes to the scanner download path. Publishing this release moves <code>v1</code> forward automatically; consumers pinned to <code>@v1</code> pick it up with no change on their side.</p>
<h2 id="fixed--scanner-download-path-43-56">Fixed — scanner download path (#43, #56)</h2>
<p>The runtime download of the <code>injection-scanner</code> binary had three holes, all reachable on a persistent runner:</p>
<ul>
<li><strong>No checksum verification.</strong> The downloaded binary was <code>chmod +x</code>&rsquo;d and executed with nothing checked against <code>SHA256SUMS</code>.</li>
<li><strong>Fixed unversioned cache path.</strong> <code>/tmp/injection-scanner</code> was returned by <code>existsSync</code> without re-verification, so anything able to write that path got executed on the next run. The cache is now keyed by version.</li>
<li><strong>Suppressed findings not surfaced.</strong> A file that disarmed the scanner with an inline directive reported as clean. The action now reads the scanner&rsquo;s <code>suppressed</code> record and reports it.</li>
</ul>
<h2 id="fixed--the-moving-v1-tag">Fixed — the moving <code>v1</code> tag</h2>
<p><code>v1</code> stopped moving after being set by hand at <code>v1.0.0</code>. Two independent causes, either one fatal:</p>
<ol>
<li>The tag-mover ran <code>runs-on: [arc-runner-unityinflow]</code> on a <strong>public</strong> repo, and the org runner group enforces <code>allows_public_repositories: false</code> — no self-hosted job can be scheduled here at all, whatever the trigger.</li>
<li>That label matches zero registered runners.</li>
</ol>
<p>Neither failed loudly; <code>v1</code> simply froze. The job now runs GitHub-hosted (no org secrets, only the built-in <code>GITHUB_TOKEN</code>, and <code>release: published</code> cannot be fired by a fork), and a <code>workflow_dispatch</code> entry point closes the gap between a fix landing on <code>main</code> and the next release being cut.</p>
<p>Also fixed: <code>git tag -fa &quot;$MAJOR&quot;</code> tagged <code>HEAD</code> rather than the release commit, which would have pointed <code>v1</code> at whatever was on <code>main</code> at dispatch time.</p>
<h2 id="changed">Changed</h2>
<ul>
<li><code>injection-scanner-version</code> default → <code>v0.0.3</code></li>
<li>README pins updated from <code>@v0.0.1</code> to <code>@v1</code>, with a test that keeps the documented pin and the package major in sync</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">UnityInFlow/spec-ci-plugin@v1</span>
</span></span></code></pre></div><p><strong>Full changelog:</strong> <a href="https://github.com/UnityInFlow/spec-ci-plugin/compare/v1.0.0...v1.1.0">https://github.com/UnityInFlow/spec-ci-plugin/compare/v1.0.0...v1.1.0</a></p>
]]></content:encoded></item><item><title>MIU PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/miu-pr-review/</link><pubDate>Mon, 24 Aug 2026 05:54:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/miu-pr-review/</guid><description>Version updated for https://github.com/vanducng/miu-cr to version v0.89.9.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
miu-cr is an AI code review tool that automates the process of reviewing staged changes locally, gating pull requests in CI environments, and driving reviews from MCP-capable agents such as Claude Code and Codex. The action provides a deterministic engine that outputs stable JSON envelopes to stdout for easy integration into development workflows and CI pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vanducng/miu-cr">https://github.com/vanducng/miu-cr</a></strong> to version <strong>v0.89.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miu-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>miu-cr is an AI code review tool that automates the process of reviewing staged changes locally, gating pull requests in CI environments, and driving reviews from MCP-capable agents such as Claude Code and Codex. The action provides a deterministic engine that outputs stable JSON envelopes to stdout for easy integration into development workflows and CI pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="miu-cr-v0899">miu-cr v0.89.9</h2>
<p>AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.89.9
</span></span><span style="display:flex;"><span>brew install vanducng/tap/miucr
</span></span><span style="display:flex;"><span>go install github.com/vanducng/miu-cr/cmd/miucr@v0.89.9
</span></span></code></pre></div><p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v6</span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vanducng/miu-cr@v0.89.9</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><h3 id="common-commands">Common commands</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>miucr login --provider openai
</span></span><span style="display:flex;"><span>miucr review --staged
</span></span><span style="display:flex;"><span>miucr review --from main --to HEAD --gate high
</span></span><span style="display:flex;"><span>miucr review --pr owner/repo#123 --post
</span></span><span style="display:flex;"><span>miucr upgrade
</span></span></code></pre></div><p>Docs: <a href="https://cr.miu.sh">https://cr.miu.sh</a></p>
]]></content:encoded></item><item><title>Diffly PR triage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/diffly-pr-triage/</link><pubDate>Mon, 24 Aug 2026 05:53:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/diffly-pr-triage/</guid><description>Version updated for https://github.com/VIVAAN-DHAWAN/diffly-cli to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, diffly, automates the process of reviewing large AI-generated pull requests by analyzing code changes, dependencies, and tests. It provides a one-page summary with a verdict, risk flags, checks, and a blast-radius map, helping developers quickly identify critical issues without needing to review each file individually.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VIVAAN-DHAWAN/diffly-cli">https://github.com/VIVAAN-DHAWAN/diffly-cli</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/diffly-pr-triage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, diffly, automates the process of reviewing large AI-generated pull requests by analyzing code changes, dependencies, and tests. It provides a one-page summary with a verdict, risk flags, checks, and a blast-radius map, helping developers quickly identify critical issues without needing to review each file individually.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="verdict-rebalance--pass-for-healthy-prs">Verdict rebalance — PASS for healthy PRs</h2>
<p>The headline change: verdicts now match merge-readiness.</p>
<table>
  <thead>
      <tr>
          <th>Signal</th>
          <th>Before</th>
          <th>Now</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Required checks failed</td>
          <td>BLOCK</td>
          <td>BLOCK</td>
      </tr>
      <tr>
          <td>Credential-like value in <strong>production</strong> code</td>
          <td>BLOCK</td>
          <td>BLOCK</td>
      </tr>
      <tr>
          <td>Credential-like value in tests/fixtures/docs</td>
          <td>BLOCK</td>
          <td><strong>QUARANTINE</strong></td>
      </tr>
      <tr>
          <td>Newly added dependency (net of removals)</td>
          <td>QUARANTINE</td>
          <td>QUARANTINE</td>
      </tr>
      <tr>
          <td>Version bump / lockfile refresh only</td>
          <td>QUARANTINE</td>
          <td><strong>PASS + note</strong></td>
      </tr>
      <tr>
          <td>Pending required checks</td>
          <td>QUARANTINE</td>
          <td><strong>PASS + note</strong></td>
      </tr>
      <tr>
          <td>Security-sensitive code, DB/migrations</td>
          <td>QUARANTINE</td>
          <td>QUARANTINE</td>
      </tr>
  </tbody>
</table>
<h2 id="fixed">Fixed</h2>
<ul>
<li>Arrow keys in the interactive review menu no longer crash with <code>NameError</code>, fast keystroke bursts register every press (escape sequences stop at their terminator), a lone Escape never blocks, and keys typed while the menu renders are no longer discarded on Python 3.14+ (<code>tty.setcbreak</code> is pinned to <code>TCSANOW</code>).</li>
<li>Diff content lines beginning with <code>++</code> or <code>--</code> are counted, credential-scanned, and analyzed instead of being mistaken for the file&rsquo;s <code>---</code>/<code>+++</code> header lines — a <code>postgresql://…</code> credential on such a line can no longer hide from <code>EXPOSED_SECRET</code>.</li>
<li><code>diffly setup</code> no longer runs the update check twice in a row.</li>
<li>EOF/Ctrl-D exits the interactive menu cleanly instead of spinning.</li>
</ul>
<h2 id="changed">Changed</h2>
<ul>
<li>Policy text in the report, README, and JSON reasoning reflects the new routing. Flag codes and the JSON schema are unchanged, so existing automation keeps working.</li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/VIVAAN-DHAWAN/diffly-cli/blob/main/CHANGELOG.md">https://github.com/VIVAAN-DHAWAN/diffly-cli/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/b.ia-accessibility-checker/</link><pubDate>Mon, 24 Aug 2026 05:52:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/24/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks within a CI/CD pipeline. It allows companies to define an audience and required guideline percentages, enabling them to ensure their code meets WCAG guidelines for specific groups of users. The action uses AI for abstract guideline analysis, facilitating easier accessibility integration into the development process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks within a CI/CD pipeline. It allows companies to define an audience and required guideline percentages, enabling them to ensure their code meets WCAG guidelines for specific groups of users. The action uses AI for abstract guideline analysis, facilitating easier accessibility integration into the development process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>go-crap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/go-crap/</link><pubDate>Sun, 23 Aug 2026 23:07:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/go-crap/</guid><description>Version updated for https://github.com/padiazg/go-crap-action to version v0.5.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The go-crap-action automates the use of the go-crap tool in a GitHub Actions workflow by running it within a Docker container. It allows developers to analyze code quality and compliance with coding standards without needing to install additional tools or Go environments. The action provides flexibility through customizable arguments, including scanning options, output formats, and thresholds for failing tests based on complexity scores. It mounts the repository workspace into the Docker container for relative path resolution and supports generating JSON reports as artifacts, making it easier to integrate into CI pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/padiazg/go-crap-action">https://github.com/padiazg/go-crap-action</a></strong> to version <strong>v0.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-crap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The go-crap-action automates the use of the go-crap tool in a GitHub Actions workflow by running it within a Docker container. It allows developers to analyze code quality and compliance with coding standards without needing to install additional tools or Go environments. The action provides flexibility through customizable arguments, including scanning options, output formats, and thresholds for failing tests based on complexity scores. It mounts the repository workspace into the Docker container for relative path resolution and supports generating JSON reports as artifacts, making it easier to integrate into CI pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Run <a href="https://github.com/padiazg/go-crap">go-crap</a> in GitHub Actions without installing the tool or a Go toolchain. The action executes the published ghcr.io/padiazg/go-crap Docker image against your checked-out code.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/padiazg/go-crap-action/commits/v0.5.1">https://github.com/padiazg/go-crap-action/commits/v0.5.1</a></p>
]]></content:encoded></item><item><title>Harness Score</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/harness-score/</link><pubDate>Sun, 23 Aug 2026 23:06:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/harness-score/</guid><description>Version updated for https://github.com/paladini/harness-score to version v1.6.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Harness Score measures and assesses the quality of AI coding harnesses across various tools, providing a maturity level (L0-L4) and a detailed breakdown of 108 points across six dimensions. It automates tasks such as identifying missing files, validating configurations, and ensuring CI feedback is accurate, all without relying on LLM calls or network access.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/paladini/harness-score">https://github.com/paladini/harness-score</a></strong> to version <strong>v1.6.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harness-score">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Harness Score measures and assesses the quality of AI coding harnesses across various tools, providing a maturity level (L0-L4) and a detailed breakdown of 108 points across six dimensions. It automates tasks such as identifying missing files, validating configurations, and ensuring CI feedback is accurate, all without relying on LLM calls or network access.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="163">1.6.3</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>Detect Forgejo Actions workflows in .forgejo/workflows/ for CI checks.</li>
</ul>
]]></content:encoded></item><item><title>Web App Security Skill</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/web-app-security-skill/</link><pubDate>Sun, 23 Aug 2026 23:05:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/web-app-security-skill/</guid><description>Version updated for https://github.com/parousia8888/web-app-security-skill to version v0.5.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action web-app-security-skill automates the security assessment of web applications by leveraging AI coding agents and providing reproducible evidence. It performs an audit of a project’s local source code, identifies potential security issues such as authentication and authorization controls, and provides actionable recommendations for reviewing and remedying these issues. The action supports various frameworks and tools to ensure comprehensive coverage and accurate results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/parousia8888/web-app-security-skill">https://github.com/parousia8888/web-app-security-skill</a></strong> to version <strong>v0.5.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/web-app-security-skill">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>web-app-security-skill</code> automates the security assessment of web applications by leveraging AI coding agents and providing reproducible evidence. It performs an audit of a project&rsquo;s local source code, identifies potential security issues such as authentication and authorization controls, and provides actionable recommendations for reviewing and remedying these issues. The action supports various frameworks and tools to ensure comprehensive coverage and accurate results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v054-release-evidence">v0.5.4 release evidence</h1>
<p>Status: published. The signed tag, GitHub Release, npm package with provenance, verified installer
trust entry and signed <code>v1</code> promotion are publicly verifiable.</p>
<h2 id="outcome">Outcome</h2>
<p>Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.</p>
<p>v0.5.4 expands the bounded automatic first pass. Five built-in rules cover exact Git tracking of
sensitive <code>.env</code> names, JavaScript session-secret/cookie settings and Python session-cookie/CSRF
settings. Eight project-owned Opengrep rules add same-file request-to-SQL, outbound-URL, file-path
and redirect flows across JavaScript/TypeScript and Python. <code>--profile deep</code> selects the built-in
detector plus the four existing external adapters without downloading them.</p>
<p>The release retains the corrected evidence claim: the self-authored planted suite is named
rule-contract conformance and reports literal positive/negative/state contract results. A separate
historical real-world regression corpus executes four minimized correctness failures and one
review-visible expected benign DOM-sink match against product code.</p>
<p>The main-branch try-now command follows npm latest. Reusable CI, signed release verification and the
trusted installer remain pinned to an immutable version or source commit.</p>
<h2 id="evidence-sets">Evidence sets</h2>
<ul>
<li><a href="../conformance/v0.5.4-rule-contract-conformance.md"><code>v0.5.4 rule-contract conformance</code></a>: 25
built-in risk and 2 evidence-integrity planted positive/negative/state contracts.</li>
<li><a href="../regressions/v0.5.4-real-world-regressions.md"><code>v0.5.4 historical real-world regressions</code></a>:
report-summary rendering, pnpm workspace lock inheritance, nested-template coverage,
path-equivalent retest handling and numeric SVG DOM-sink review.</li>
<li><a href="../../KNOWN_LIMITATIONS.md"><code>Known limitations</code></a>: parser, evidence-state, incremental-audit and
claim boundaries.</li>
</ul>
<p>Neither evidence set is a representative production-vulnerability benchmark. Stable detector reach
is 25 built-in risk rules, 2 evidence-integrity rules and 16 opt-in external-adapter rules: 43 total.
Opengrep matches remain same-file <code>suspected</code> leads. A missing deep-profile prerequisite is explicit
<code>unknown</code> evidence and exit 3, never a clean result.</p>
<h2 id="published-verification">Published verification</h2>
<p>The local release gates include:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm run conformance:rules
</span></span><span style="display:flex;"><span>npm run regressions:real-world
</span></span><span style="display:flex;"><span>npm run check
</span></span><span style="display:flex;"><span>/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .
</span></span></code></pre></div><p>The release procedure additionally verifies the signed tag after it exists:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>git -c gpg.ssh.allowedSignersFile<span style="color:#f92672">=</span>.github/release-signers verify-tag v0.5.4
</span></span></code></pre></div><h2 id="public-release-facts">Public release facts</h2>
<ul>
<li>The SSH-signed <code>v0.5.4</code> tag peels to source commit
<code>d9ee538089ac813dcd454d10b45f14b958c1ec19</code>. Candidate CI run
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32648619071"><code>32648619071</code></a>
and CodeQL run
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32648619088"><code>32648619088</code></a>
passed before publication.</li>
<li>GitHub Release workflow
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32648846862"><code>32648846862</code></a>
published the source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-23. The public
asset SHA-256 values are <code>00742dfe4d0118e8361380314c4fe01ed4e3924db1015d080b882bd3841431a5</code>
(archive), <code>cfa209b59004ce29bbf808eadc37b1fbb8bfd8eb162e462c29661e8d18a592e1</code>
(SBOM), <code>f50d8b974666694ccaebdb583127cc62471536943b028f7057919cf47b4529c1</code>
(manifest) and <code>cbd7d771f81cee065989dc386fef239fc65d2d0966b1ca23fb5c8b9f94bdce12</code>
(<code>SHA256SUMS</code>).</li>
<li>npm workflow
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32650181341"><code>32650181341</code></a>
published <code>web-app-security-skill@0.5.4</code> at <code>2026-08-23T15:58:01.250Z</code> through the configured
GitHub OIDC trusted publisher. npm records shasum
<code>1fb71399684025257e069a63b46eb058cca590d1</code>, integrity
<code>sha512-N9UlD9l05Mmm1El7VFf1CGR6nSSG8msea+JjwlN/uwv7rV8gUbGp3DZlEKO8yFMWw+uqLFyYYBocCD8PTRPUdA==</code>
and <a href="https://registry.npmjs.org/-/npm/v1/attestations/web-app-security-skill@0.5.4">SLSA provenance</a>.
A fresh public tarball contained 140 files and matched the signed tag package payload file by file.</li>
<li>The signed movable <code>v1</code> tag object is
<code>464ba64a4d256dbf3b26f78101730b24a4337bc4</code> and peels to the same immutable source commit.
Public consumer run
<a href="https://github.com/parousia8888/web-app-security-skill/actions/runs/32650353548"><code>32650353548</code></a>
passed both the passive path and expected authorization rejection.</li>
</ul>
<p>Artifact identity, signatures and provenance establish origin and byte identity. They do not prove
that every detector conclusion is correct or that a scanned project is secure.</p>
]]></content:encoded></item><item><title>Setup sysroot environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/setup-sysroot-environment/</link><pubDate>Sun, 23 Aug 2026 23:04:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/setup-sysroot-environment/</guid><description>Version updated for https://github.com/psyGamer/setup-sysroot to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-sysroot GitHub Action automates the process of setting up a precompiled sysroot for cross-compiling or targeting alternative C libraries. It provides a list of supported toolchains, allowing users to choose the appropriate one for their needs. The action is useful for developers who need to build software that requires specific system libraries beyond those available in their development environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/psyGamer/setup-sysroot">https://github.com/psyGamer/setup-sysroot</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-sysroot-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The setup-sysroot GitHub Action automates the process of setting up a precompiled sysroot for cross-compiling or targeting alternative C libraries. It provides a list of supported toolchains, allowing users to choose the appropriate one for their needs. The action is useful for developers who need to build software that requires specific system libraries beyond those available in their development environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/psyGamer/setup-sysroot/compare/v1.0.0...v1.0.1">https://github.com/psyGamer/setup-sysroot/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/kaniko-build-action/</link><pubDate>Sun, 23 Aug 2026 23:03:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action is designed to print a greeting message to the log, either “Hello World” or “Hello [name]” based on the input provided. It solves the problem of automating simple greeting messages and provides capabilities for customizable greetings and timestamps.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action is designed to print a greeting message to the log, either &ldquo;Hello World&rdquo; or &ldquo;Hello [name]&rdquo; based on the input provided. It solves the problem of automating simple greeting messages and provides capabilities for customizable greetings and timestamps.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>NestJS Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/nestjs-doctor/</link><pubDate>Sun, 23 Aug 2026 23:03:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/nestjs-doctor/</guid><description>Version updated for https://github.com/RoloBits/nestjs-doctor to version v1.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The nestjs-doctor action is a tool designed to automatically scan and audit NestJS projects for security, correctness, architecture, performance, and schema issues. It provides a comprehensive report that helps developers identify potential problems in their codebase and suggests improvements. The action can be run on local machines or integrated into CI/CD pipelines to ensure consistent quality across different environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RoloBits/nestjs-doctor">https://github.com/RoloBits/nestjs-doctor</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nestjs-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>nestjs-doctor</code> action is a tool designed to automatically scan and audit NestJS projects for security, correctness, architecture, performance, and schema issues. It provides a comprehensive report that helps developers identify potential problems in their codebase and suggests improvements. The action can be run on local machines or integrated into CI/CD pipelines to ensure consistent quality across different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of the NestJS Doctor GitHub Action.</p>
<p>Reviews every pull request and reports <strong>only what the change introduced</strong>, not
your existing backlog. Posts a sticky summary comment, inline review comments on
the changed lines, and a commit status with the score.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">RoloBits/nestjs-doctor@v1</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Advisory by default — it comments without failing anything. Turn enforcement on</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">when you are ready</span>:
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">RoloBits/nestjs-doctor@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">blocking</span>: <span style="color:#ae81ff">error</span> <span style="color:#75715e"># fail on any error the change introduced</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">min-score</span>: <span style="color:#ae81ff">80</span> <span style="color:#75715e"># and on a project score below 80</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Also supports SARIF for the Security tab, monorepos, and a configurable scope</span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">(changed, files, lines, full).</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">Docs</span>: <span style="color:#ae81ff">https://nestjs.doctor/docs/ci</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>TS Upgrade Impact</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/ts-upgrade-impact/</link><pubDate>Sun, 23 Aug 2026 23:02:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/ts-upgrade-impact/</guid><description>Version updated for https://github.com/sayaa0/ts-upgrade-impact to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary TS Upgrade Impact is an experimental GitHub Action and CLI designed to analyze TypeScript declaration changes during npm dependency upgrades. It helps identify which supported type declarations actually intersect with APIs used by a TypeScript repository, focusing on high-confidence cases like package-level declarations and named exports. The tool can infer direct dependency version changes from PRs and automatically detect breaking updates, providing a clear summary of detected updates and their impact.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sayaa0/ts-upgrade-impact">https://github.com/sayaa0/ts-upgrade-impact</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ts-upgrade-impact">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>TS Upgrade Impact is an experimental GitHub Action and CLI designed to analyze TypeScript declaration changes during npm dependency upgrades. It helps identify which supported type declarations actually intersect with APIs used by a TypeScript repository, focusing on high-confidence cases like package-level declarations and named exports. The tool can infer direct dependency version changes from PRs and automatically detect breaking updates, providing a clear summary of detected updates and their impact.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial experimental release.
Detects supported TypeScript API changes in npm dependency upgrade PRs, filters them against APIs actually used by the repository, and reports likely breaking changes.</p>
]]></content:encoded></item><item><title>SDK-Fabric Sync Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/sdk-fabric-sync-action/</link><pubDate>Sun, 23 Aug 2026 23:01:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/sdk-fabric-sync-action/</guid><description>Version updated for https://github.com/sdk-fabric/sync-action to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sync Action automates the synchronization of base files, configurations, and scripts across the SDK-Fabric ecosystem. It enables SDK repositories to dynamically fetch templates from their respective central template repositories (e.g., sdk-fabric/sdk-template-csharp, sdk-fabric/sdk-template-python) and apply them automatically, streamlining the development process and reducing redundancy.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sdk-fabric/sync-action">https://github.com/sdk-fabric/sync-action</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sdk-fabric-sync-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Sync Action automates the synchronization of base files, configurations, and scripts across the <a href="https://sdk-fabric.org/">SDK-Fabric</a> ecosystem. It enables SDK repositories to dynamically fetch templates from their respective central template repositories (e.g., <code>sdk-fabric/sdk-template-csharp</code>, <code>sdk-fabric/sdk-template-python</code>) and apply them automatically, streamlining the development process and reducing redundancy.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release</p>
]]></content:encoded></item><item><title>WAF Security Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/waf-security-audit/</link><pubDate>Sun, 23 Aug 2026 23:00:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/waf-security-audit/</guid><description>Version updated for https://github.com/SecH0us3/waf-checker to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
WAF Checker is a powerful tool designed to help developers test their Web Application Firewalls (WAFs) against various types of web attacks. It supports running as a Cloudflare Worker with an interactive UI or as a standalone Node.js CLI, offering comprehensive testing features such as core testing, attack category detection, WAF bypass payloads, and batch testing capabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SecH0us3/waf-checker">https://github.com/SecH0us3/waf-checker</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/waf-security-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>WAF Checker is a powerful tool designed to help developers test their Web Application Firewalls (WAFs) against various types of web attacks. It supports running as a Cloudflare Worker with an interactive UI or as a standalone Node.js CLI, offering comprehensive testing features such as core testing, attack category detection, WAF bypass payloads, and batch testing capabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-whats-new-in-v110">🚀 What&rsquo;s New in v1.1.0</h2>
<h3 id="-expanded-vulnerability-categories--payloads">🛡️ Expanded Vulnerability Categories &amp; Payloads</h3>
<ul>
<li><strong>GraphQL Injection</strong>: Introspection queries (<code>__schema</code>, <code>__type</code>), batching attacks, field aliasing, directive bypasses (<code>@deprecated</code>, <code>@skip</code>).</li>
<li><strong>JWT Attacks</strong>: Alg: none / NONE forgery, <code>jku</code>, <code>jwk</code> injection, and <code>kid</code> path traversal (<code>../../dev/null</code>) in both HTTP headers and URL/body parameters.</li>
<li><strong>Enhanced SSTI</strong>: Spring Expression Language (SpEL), FreeMarker, Mako, Smarty, Handlebars, Pug/Jade, and Twig engines.</li>
<li><strong>Cloud SSRF</strong>: Google Cloud Metadata, Azure Instance Metadata, Oracle Cloud, Alibaba Cloud, Hex/Octal/Decimal IP notations, and IPv6-mapped IPv4.</li>
</ul>
<h3 id="-waf-inspection-limit-bypass-buffer-padding-evasion">🥷 WAF Inspection Limit Bypass (Buffer Padding Evasion)</h3>
<ul>
<li>Added buffer padding engine in Core, CLI (<code>--padding &lt;size&gt;</code>), and Web UI to evade inspection buffer limits (8KB, 16KB AWS WAF limit, 64KB, 128KB Cloudflare limit).</li>
</ul>
<h3 id="-expanded-waf-signatures--detection">🔍 Expanded WAF Signatures &amp; Detection</h3>
<ul>
<li>Added fingerprinting for <strong>DDoS-Guard</strong>, <strong>Google Cloud Armor</strong>, <strong>Azure Front Door</strong>, <strong>Imperva</strong>, <strong>Qrator</strong>, <strong>Wordfence</strong>, <strong>Alibaba Cloud</strong>, <strong>Citrix NetScaler</strong>, and fixed false positives on vanilla Apache / CloudFront.</li>
</ul>
<h3 id="-cicd-integration--reporting">📊 CI/CD Integration &amp; Reporting</h3>
<ul>
<li><strong>GitHub Action</strong>: <code>uses: SecH0us3/waf-checker@v1</code> with automated <code>$GITHUB_STEP_SUMMARY</code>, SARIF 2.1.0 output for GitHub Advanced Security, and <code>--threshold</code> CI enforcement.</li>
<li><strong>Reporting Formats</strong>: SARIF, Markdown, standalone interactive HTML, JSON, and CSV.</li>
</ul>
<h3 id="-web-ui-ux-improvements">🎨 Web UI UX Improvements</h3>
<ul>
<li>Reordered attack categories by popularity (OWASP Top 10 on top, niche &amp; rare attacks below).</li>
<li>Interactive Buffer Padding Evasion controls with <code>localStorage</code> persistence.</li>
</ul>
]]></content:encoded></item><item><title>Docker Compose Cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/docker-compose-cache/</link><pubDate>Sun, 23 Aug 2026 22:59:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/docker-compose-cache/</guid><description>Version updated for https://github.com/seijikohara/docker-compose-cache-action to version v1.8.23.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Docker Compose Cache Action automates the caching of Docker images specified in Docker Compose files to reduce CI/CD workflow execution time. It parses Compose files, intelligently caches images using digests for verification and selectively pulls images when necessary, supporting multiple Compose files and image exclusion options. This action helps optimize build times by avoiding unnecessary image pulls from registries.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seijikohara/docker-compose-cache-action">https://github.com/seijikohara/docker-compose-cache-action</a></strong> to version <strong>v1.8.23</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-compose-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Docker Compose Cache Action automates the caching of Docker images specified in Docker Compose files to reduce CI/CD workflow execution time. It parses Compose files, intelligently caches images using digests for verification and selectively pulls images when necessary, supporting multiple Compose files and image exclusion options. This action helps optimize build times by avoiding unnecessary image pulls from registries.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update pnpm to v11.20.0 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/331">https://github.com/seijikohara/docker-compose-cache-action/pull/331</a></li>
<li>chore(deps): update pnpm to v11.21.0 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/333">https://github.com/seijikohara/docker-compose-cache-action/pull/333</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/334">https://github.com/seijikohara/docker-compose-cache-action/pull/334</a></li>
<li>chore(deps): update dependency oxfmt to ^0.63.0 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/332">https://github.com/seijikohara/docker-compose-cache-action/pull/332</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/335">https://github.com/seijikohara/docker-compose-cache-action/pull/335</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/336">https://github.com/seijikohara/docker-compose-cache-action/pull/336</a></li>
<li>chore(deps): update dependency oxfmt to ^0.64.0 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/337">https://github.com/seijikohara/docker-compose-cache-action/pull/337</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.21...v1.8.23">https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.21...v1.8.23</a></p>
]]></content:encoded></item><item><title>Profile Cards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/profile-cards/</link><pubDate>Sun, 23 Aug 2026 22:58:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/profile-cards/</guid><description>Version updated for https://github.com/seijikohara/profile-cards-action to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates SVG profile README cards using the GitHub GraphQL API, providing various visual statistics such as lifetime contributions, contribution streaks, and repository ranking. It automates the rendering of these cards into plain SVG files that can be committed back to a repository. The action supports dark and light themes, badge pills for brands, and animates card entries on entry only.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seijikohara/profile-cards-action">https://github.com/seijikohara/profile-cards-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/profile-cards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates SVG profile README cards using the GitHub GraphQL API, providing various visual statistics such as lifetime contributions, contribution streaks, and repository ranking. It automates the rendering of these cards into plain SVG files that can be committed back to a repository. The action supports dark and light themes, badge pills for brands, and animates card entries on entry only.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: cut v1.0.0 by @seijikohara in <a href="https://github.com/seijikohara/profile-cards-action/pull/35">https://github.com/seijikohara/profile-cards-action/pull/35</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/seijikohara/profile-cards-action/compare/v0.0.11...v1.0.0">https://github.com/seijikohara/profile-cards-action/compare/v0.0.11...v1.0.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/sherpa.sh/</link><pubDate>Sun, 23 Aug 2026 22:57:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-based tool that simplifies cloud infrastructure management. It allows developers to describe their deployment needs in plain English and automatically configures the necessary resources, including servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more. Sherpa handles all infrastructure provisioning tasks, making it easier for developers to focus on building their applications without worrying about configuration details.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-based tool that simplifies cloud infrastructure management. It allows developers to describe their deployment needs in plain English and automatically configures the necessary resources, including servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more. Sherpa handles all infrastructure provisioning tasks, making it easier for developers to focus on building their applications without worrying about configuration details.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>outline-sync-docs-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/outline-sync-docs-action/</link><pubDate>Sun, 23 Aug 2026 22:56:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/outline-sync-docs-action/</guid><description>Version updated for https://github.com/SimonPrinz/outline-sync-docs-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Outline Sync Docs Action automates the process of syncing markdown files from a specified directory in your repository to an Outline collection. It ensures that documents are created, updated, or archived as necessary based on their titles and nesting structure, while maintaining document history for any moves. The action requires the outline base URL, API key, collection ID, document ID (optional), and repository path for input configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SimonPrinz/outline-sync-docs-action">https://github.com/SimonPrinz/outline-sync-docs-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/outline-sync-docs-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Outline Sync Docs Action automates the process of syncing markdown files from a specified directory in your repository to an Outline collection. It ensures that documents are created, updated, or archived as necessary based on their titles and nesting structure, while maintaining document history for any moves. The action requires the outline base URL, API key, collection ID, document ID (optional), and repository path for input configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SimonPrinz/outline-sync-docs-action/commits/v1.0.0">https://github.com/SimonPrinz/outline-sync-docs-action/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/smyklot/</link><pubDate>Sun, 23 Aug 2026 22:56:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.46.2.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges based on CODEOWNERS file permissions. It allows users to comment with slash commands, mentions, or bare commands to approve/merge PRs and provides features like reaction-based approval and merge methods. The action also offers cleanup options for managing bot reactions, approvals, and comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.46.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges based on CODEOWNERS file permissions. It allows users to comment with slash commands, mentions, or bare commands to approve/merge PRs and provides features like reaction-based approval and merge methods. The action also offers cleanup options for managing bot reactions, approvals, and comments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1462-2026-08-23"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.46.1...v1.46.2">1.46.2</a> (2026-08-23)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>panel:</strong> contain long Sync labels (<a href="https://github.com/smykla-skalski/smyklot/issues/311">#311</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/4feb1d4d380ba7aa513fa1c2b3b938f95aee01cd">4feb1d4</a>)</li>
</ul>
<h2 id="smyklot-v1462">Smyklot v1.46.2</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.46.2</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>61c8df0dc99886e0bcc86e3f2c5d0654c3ce908f chore(release): bump version to 1.46.2</li>
<li>4feb1d4d380ba7aa513fa1c2b3b938f95aee01cd fix(panel): contain long Sync labels (#311)</li>
</ul>
]]></content:encoded></item><item><title>Ruleset Trigger</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/ruleset-trigger/</link><pubDate>Sun, 23 Aug 2026 22:55:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/ruleset-trigger/</guid><description>Version updated for https://github.com/solairen/ruleset-trigger to version 1.0.6.
This action is used across all versions by 6 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Ruleset Manager is a Python utility that allows users to manage GitHub repository rulesets programmatically through the GitHub API. It enables and disables ruleset enforcement via simple API calls, making it easier for developers to automate rule management tasks within their workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/solairen/ruleset-trigger">https://github.com/solairen/ruleset-trigger</a></strong> to version <strong>1.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ruleset-trigger">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Ruleset Manager is a Python utility that allows users to manage GitHub repository rulesets programmatically through the GitHub API. It enables and disables ruleset enforcement via simple API calls, making it easier for developers to automate rule management tasks within their workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump python from 3.15.0a6-slim-bookworm to 3.15.0a7-slim-bookworm in /docker by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/31">https://github.com/solairen/ruleset-trigger/pull/31</a></li>
<li>Bump python from 3.15.0a6-slim-bookworm to 3.15.0a7-slim-bookworm by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/30">https://github.com/solairen/ruleset-trigger/pull/30</a></li>
<li>Bump python from 3.15.0a7-slim-bookworm to 3.15.0a8-slim-bookworm in /docker by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/33">https://github.com/solairen/ruleset-trigger/pull/33</a></li>
<li>Bump python from 3.15.0a7-slim-bookworm to 3.15.0a8-slim-bookworm by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/32">https://github.com/solairen/ruleset-trigger/pull/32</a></li>
<li>Bump softprops/action-gh-release from 2 to 3 by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/34">https://github.com/solairen/ruleset-trigger/pull/34</a></li>
<li>Bump python from 3.15.0a8-slim-bookworm to 3.15.0b1-slim-bookworm in /docker by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/36">https://github.com/solairen/ruleset-trigger/pull/36</a></li>
<li>Bump python from 3.15.0a8-slim-bookworm to 3.15.0b1-slim-bookworm by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/35">https://github.com/solairen/ruleset-trigger/pull/35</a></li>
<li>Bump python from 3.15.0b1-slim-bookworm to 3.15.0b2-slim-bookworm in /docker by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/38">https://github.com/solairen/ruleset-trigger/pull/38</a></li>
<li>Bump python from 3.15.0b1-slim-bookworm to 3.15.0b2-slim-bookworm by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/37">https://github.com/solairen/ruleset-trigger/pull/37</a></li>
<li>Bump python from 3.15.0b2-slim-bookworm to 3.15.0b3-slim-bookworm in /docker by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/40">https://github.com/solairen/ruleset-trigger/pull/40</a></li>
<li>Bump python from 3.15.0b2-slim-bookworm to 3.15.0b3-slim-bookworm by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/39">https://github.com/solairen/ruleset-trigger/pull/39</a></li>
<li>Bump python from 3.15.0b3-slim-bookworm to 3.15.0b4-slim-bookworm in /docker by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/42">https://github.com/solairen/ruleset-trigger/pull/42</a></li>
<li>Bump python from 3.15.0b3-slim-bookworm to 3.15.0b4-slim-bookworm by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/41">https://github.com/solairen/ruleset-trigger/pull/41</a></li>
<li>Bump python from 3.15.0b4-slim-bookworm to 3.15.0rc1-slim-bookworm in /docker by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/44">https://github.com/solairen/ruleset-trigger/pull/44</a></li>
<li>Bump python from 3.15.0b4-slim-bookworm to 3.15.0rc1-slim-bookworm by @dependabot[bot] in <a href="https://github.com/solairen/ruleset-trigger/pull/43">https://github.com/solairen/ruleset-trigger/pull/43</a></li>
<li>GH-45 Downgrade Python version in Dockerfile by @solairen in <a href="https://github.com/solairen/ruleset-trigger/pull/46">https://github.com/solairen/ruleset-trigger/pull/46</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/solairen/ruleset-trigger/compare/1.0.5...1.0.6">https://github.com/solairen/ruleset-trigger/compare/1.0.5...1.0.6</a></p>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sun, 23 Aug 2026 22:54:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by bundling dependencies and committing the resulting distribution to the repository.
What’s Changed fix: Update dependencies (5336574) fix: Update dependencies (e9c2fe7) fix: Update dependencies (0b48905) fix: Update dependencies (7cff14c) fix: Improve error output (7cd1d73) fix: Improve error output (92f3eca) fix: Improve error output (4db44f1) fix: Update dependencies (0ff3213) Create README.md (e1316ba) fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by bundling dependencies and committing the resulting distribution to the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/classroom-to-sheets-integration/</link><pubDate>Sun, 23 Aug 2026 22:54:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates GitHub Classroom with Google Sheets to automatically send assignment results to the spreadsheet. It enables organizations to track student submissions and grades using a single tool. The action requires configuring Google Cloud credentials and sharing the sheet with the service account email, then adding it as a secret in their GitHub repository. Users can specify task results and table ID in their workflow to update the Google Sheet accordingly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates GitHub Classroom with Google Sheets to automatically send assignment results to the spreadsheet. It enables organizations to track student submissions and grades using a single tool. The action requires configuring Google Cloud credentials and sharing the sheet with the service account email, then adding it as a secret in their GitHub repository. Users can specify task results and table ID in their workflow to update the Google Sheet accordingly.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>GitGalaxy Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/gitgalaxy-scanner/</link><pubDate>Sun, 23 Aug 2026 22:53:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/gitgalaxy-scanner/</guid><description>Version updated for https://github.com/squid-protocol/gitgalaxy to version v2.4.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GitGalaxy is a technical tool designed to create a comprehensive, language-agnostic structural graph of an entire repository directly from source text. It addresses challenges in analyzing large and complex repositories by extracting common structural signatures without the need for successful builds or separate parser/toolchains for every language. The resulting graph can be used for various tasks such as architecture analysis, risk exposure prioritization, dependency/SBOM analysis, refactoring and ownership analysis, legacy-code analysis, AI-oriented codebase context, CI/CD workflows, and historical risk analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/squid-protocol/gitgalaxy">https://github.com/squid-protocol/gitgalaxy</a></strong> to version <strong>v2.4.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gitgalaxy-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GitGalaxy is a technical tool designed to create a comprehensive, language-agnostic structural graph of an entire repository directly from source text. It addresses challenges in analyzing large and complex repositories by extracting common structural signatures without the need for successful builds or separate parser/toolchains for every language. The resulting graph can be used for various tasks such as architecture analysis, risk exposure prioritization, dependency/SBOM analysis, refactoring and ownership analysis, legacy-code analysis, AI-oriented codebase context, CI/CD workflows, and historical risk analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This release marks a major milestone in validating GitGalaxy’s core model. We have expanded our <strong>Tri-Comparison Accuracy Audit</strong>—cross-referencing GitGalaxy, Tree-sitter, and Universal Ctags—to empirically establish absolute ground truth for our codebase parsing.</p>
<h3 id="the-central-thesis">The Central Thesis</h3>
<p>GitGalaxy operates on a specific hypothesis: <strong>For repository-scale intelligence, targeted structural extraction can recover the entities required for useful code intelligence without requiring a complete language parser for every file.</strong></p>
<p>Abstract Syntax Trees (ASTs) are mathematically precise but frequently fail on broken syntax, undocumented legacy code, or missing dependencies. By skipping the compilation step and leveraging heuristic extraction, we aim for maximum resilience. The tri-comparison audit is our way of proving that this resilience does not come at the cost of accuracy.</p>
<h3 id="current-validation-numbers-rung-1-structural-validity">Current Validation Numbers (Rung 1: Structural Validity)</h3>
<p>Our audit is now approximately halfway complete, establishing a verified baseline for our structural model:</p>
<ul>
<li><strong>24 of 45 languages</strong> are now continuously cross-referenced against both Tree-sitter and Ctags.</li>
<li><strong>16 languages</strong> are compared against two tools.</li>
<li><strong>5 GitGalaxy-only languages</strong> (like Dockerfile and YAML) undergo hand-reviewed manual verification.</li>
<li>Of the <strong>180 discrepancy shapes</strong> logged so far, <strong>87 have been human-validated (48%)</strong> by reading the raw source to determine which tool is actually correct.</li>
</ul>
<h3 id="the-results-unprecedented-structural-accuracy">The Results: Unprecedented Structural Accuracy</h3>
<p>Because GitGalaxy is highly resilient to macro-obfuscation, parse-error cascades, and syntactic anomalies, our heuristic extraction frequently out-performs or matches strict AST parsers on raw production code.</p>
<p>Based on our validated precision scores across function, class, and argument extraction, <strong>GitGalaxy currently leads or ties in 34 languages:</strong></p>
<p>🏆 <strong>GitGalaxy Produced More Accurate Extractions (Wins):</strong>
<code>abap</code>, <code>agc_assembly</code>, <code>assembly</code>, <code>c</code>, <code>cobol</code>, <code>cpp</code>, <code>csharp</code>, <code>dockerfile</code>, <code>fortran</code>, <code>haskell</code>, <code>m4</code>, <code>rust</code></p>
<p>🤝 <strong>GitGalaxy Matched Strict AST/Lexical Ground Truth (Ties):</strong>
<code>apex</code>, <code>css</code>, <code>go</code>, <code>java</code>, <code>jcl</code>, <code>kotlin</code>, <code>makefile</code>, <code>matlab</code>, <code>objective-c</code>, <code>perl</code>, <code>php</code>, <code>powershell</code>, <code>python</code>, <code>ruby</code>, <code>scala</code>, <code>scheme</code>, <code>shell</code>, <code>solidity</code>, <code>swift</code>, <code>tcl</code>, <code>typescript</code>, <code>zig</code></p>
<p><em>(Note for transparency: Tree-sitter currently retains higher precision in <code>dart</code> and <code>javascript</code>, which has informed targeted improvements to our heuristics.)</em></p>
<h3 id="whats-next-climbing-the-verification-ladder">What’s Next: Climbing the Verification Ladder</h3>
<p>Validating our structural extraction is only <strong>Rung 1</strong> of our <a href="https://squid-protocol.github.io/gitgalaxy/">Core Ladder of Verification</a>.</p>
<p>With structural ground truth increasingly established, our immediate research direction moves to <strong>Temporal and Model Validity</strong>: testing whether these extracted structural metrics correctly map to real-world risk exposure. In upcoming releases, we will begin mapping Git-history to track how independently identified security and maintenance events correlate with GitGalaxy&rsquo;s exposure deltas.</p>
]]></content:encoded></item><item><title>battest Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/battest-action/</link><pubDate>Sun, 23 Aug 2026 22:52:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/battest-action/</guid><description>Version updated for https://github.com/tboy1337/battest to version v1.0.12.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, battest, is a runtime test runner for Windows batch files that provides features like running real cmd.exe in isolated temp workdirs with assertions on exit code, stdout, stderr, environment, and filesystem side effects. It supports param overlays, setup/teardown, stdin, env, and copy-in fixtures. The action can be used to automate tasks by asserting on the output of batch files and handling complex scenarios with PATH mocks for external commands.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tboy1337/battest">https://github.com/tboy1337/battest</a></strong> to version <strong>v1.0.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/battest-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, battest, is a runtime test runner for Windows batch files that provides features like running real cmd.exe in isolated temp workdirs with assertions on exit code, stdout, stderr, environment, and filesystem side effects. It supports param overlays, setup/teardown, stdin, env, and copy-in fixtures. The action can be used to automate tasks by asserting on the output of batch files and handling complex scenarios with PATH mocks for external commands.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1012---2026-08-23">[1.0.12] - 2026-08-23</h2>
<p>Removed the README PyPI version badge.</p>
<ul>
<li>The live PyPI version shield lagged behind GitHub tags. README badges are
Python versions, CI, and license only.</li>
</ul>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/delivery-autopilot-runner/</link><pubDate>Sun, 23 Aug 2026 22:51:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.31.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of integrating Delivery Autopilot with GitHub repositories to handle ticket workflow from planning to review through AI-driven code generation and quality checks. It requires a valid subscription to Delivery Autopilot, which provides instructions to trigger the action. The action is designed to run on GitHub Actions workflows and uses signed instructions to authorize actions. The source code remains checked out within the repository’s CI environment, and no data is sent to Tekunda’s servers during execution. The action supports two setup options: installing the Delivery Autopilot GitHub App or adding a workflow manually, and it provides configuration for various tools like AI models and version control systems.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.31</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of integrating Delivery Autopilot with GitHub repositories to handle ticket workflow from planning to review through AI-driven code generation and quality checks. It requires a valid subscription to Delivery Autopilot, which provides instructions to trigger the action. The action is designed to run on GitHub Actions workflows and uses signed instructions to authorize actions. The source code remains checked out within the repository&rsquo;s CI environment, and no data is sent to Tekunda&rsquo;s servers during execution. The action supports two setup options: installing the Delivery Autopilot GitHub App or adding a workflow manually, and it provides configuration for various tools like AI models and version control systems.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runner-dist synced from AutoPilot c39e5770458d. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>Expand AWS IAM Wildcards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/expand-aws-iam-wildcards/</link><pubDate>Sun, 23 Aug 2026 22:50:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/expand-aws-iam-wildcards/</guid><description>Version updated for https://github.com/thekbb/expand-aws-iam-wildcards to version v2.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action, Expand AWS IAM Wildcards, automatically expands wildcard permissions added in pull requests and provides inline comments with detailed information about the matching AWS actions. It helps identify potential unintended changes to permissions by expanding wildcard expressions and linking them to the AWS Service Authorization Reference. The tool does not require repository checkout or AWS credentials and supports both IAM wildcard characters (* and ?).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thekbb/expand-aws-iam-wildcards">https://github.com/thekbb/expand-aws-iam-wildcards</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/expand-aws-iam-wildcards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action, Expand AWS IAM Wildcards, automatically expands wildcard permissions added in pull requests and provides inline comments with detailed information about the matching AWS actions. It helps identify potential unintended changes to permissions by expanding wildcard expressions and linking them to the AWS Service Authorization Reference. The tool does not require repository checkout or AWS credentials and supports both IAM wildcard characters (<code>*</code> and <code>?</code>).</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix waitinng for enter in release script by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/141">https://github.com/thekbb/expand-aws-iam-wildcards/pull/141</a></li>
<li>deps: bump the npm-dependencies group with 4 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/142">https://github.com/thekbb/expand-aws-iam-wildcards/pull/142</a></li>
<li>ci: bump actions/checkout from 7.0.0 to 7.0.1 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/144">https://github.com/thekbb/expand-aws-iam-wildcards/pull/144</a></li>
<li>ci: bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/146">https://github.com/thekbb/expand-aws-iam-wildcards/pull/146</a></li>
<li>ci: bump the codeql group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/143">https://github.com/thekbb/expand-aws-iam-wildcards/pull/143</a></li>
<li>ci: bump actions/attest from 4.1.1 to 4.2.0 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/145">https://github.com/thekbb/expand-aws-iam-wildcards/pull/145</a></li>
<li>ci: bump actions/setup-node from 6.4.0 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/147">https://github.com/thekbb/expand-aws-iam-wildcards/pull/147</a></li>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/148">https://github.com/thekbb/expand-aws-iam-wildcards/pull/148</a></li>
<li>ci: bump the codeql group with 2 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/150">https://github.com/thekbb/expand-aws-iam-wildcards/pull/150</a></li>
<li>deps: bump the npm-dependencies group across 1 directory with 5 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/157">https://github.com/thekbb/expand-aws-iam-wildcards/pull/157</a></li>
<li>ci: bump zizmorcore/zizmor-action from 0.6.0 to 0.6.2 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/155">https://github.com/thekbb/expand-aws-iam-wildcards/pull/155</a></li>
<li>ci: bump actions/attest from 4.2.0 to 4.2.1 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/154">https://github.com/thekbb/expand-aws-iam-wildcards/pull/154</a></li>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/153">https://github.com/thekbb/expand-aws-iam-wildcards/pull/153</a></li>
<li>ci: bump reviewdog/action-actionlint from 1.72.0 to 1.73.0 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/151">https://github.com/thekbb/expand-aws-iam-wildcards/pull/151</a></li>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/163">https://github.com/thekbb/expand-aws-iam-wildcards/pull/163</a></li>
<li>ci: bump actions/attest from 4.2.1 to 4.2.2 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/162">https://github.com/thekbb/expand-aws-iam-wildcards/pull/162</a></li>
<li>ci: bump reviewdog/action-actionlint from 1.73.0 to 1.73.1 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/161">https://github.com/thekbb/expand-aws-iam-wildcards/pull/161</a></li>
<li>deps: bump the npm-dependencies group across 1 directory with 3 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/164">https://github.com/thekbb/expand-aws-iam-wildcards/pull/164</a></li>
<li>ci: bump the codeql group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/160">https://github.com/thekbb/expand-aws-iam-wildcards/pull/160</a></li>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/158">https://github.com/thekbb/expand-aws-iam-wildcards/pull/158</a></li>
<li>Add runtime compatibility fixtures by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/165">https://github.com/thekbb/expand-aws-iam-wildcards/pull/165</a></li>
<li>run typecheck checks on tests too by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/166">https://github.com/thekbb/expand-aws-iam-wildcards/pull/166</a></li>
<li>basic checks on docs by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/167">https://github.com/thekbb/expand-aws-iam-wildcards/pull/167</a></li>
<li>Build dist in isolation by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/168">https://github.com/thekbb/expand-aws-iam-wildcards/pull/168</a></li>
<li>Smoke test the compiled action by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/169">https://github.com/thekbb/expand-aws-iam-wildcards/pull/169</a></li>
<li>rework IAM generation by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/170">https://github.com/thekbb/expand-aws-iam-wildcards/pull/170</a></li>
<li>Validate IAM catalog invariants by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/171">https://github.com/thekbb/expand-aws-iam-wildcards/pull/171</a></li>
<li>Build from locked IAM data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/172">https://github.com/thekbb/expand-aws-iam-wildcards/pull/172</a></li>
<li>Select IAM data during release preparation by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/173">https://github.com/thekbb/expand-aws-iam-wildcards/pull/173</a></li>
<li>Reinstall and report selected IAM data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/174">https://github.com/thekbb/expand-aws-iam-wildcards/pull/174</a></li>
<li>Remove standalone IAM updates by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/175">https://github.com/thekbb/expand-aws-iam-wildcards/pull/175</a></li>
<li>add version to the comment marker by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/179">https://github.com/thekbb/expand-aws-iam-wildcards/pull/179</a></li>
<li>ci: bump reviewdog/action-actionlint from 1.73.1 to 1.73.2 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/178">https://github.com/thekbb/expand-aws-iam-wildcards/pull/178</a></li>
<li>ci: bump the codeql group with 2 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/177">https://github.com/thekbb/expand-aws-iam-wildcards/pull/177</a></li>
<li>deps: bump @vercel/ncc from 0.44.1 to 0.45.0 in the npm-dependencies group across 1 directory by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/176">https://github.com/thekbb/expand-aws-iam-wildcards/pull/176</a></li>
<li>Level up comment ownership detection by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/180">https://github.com/thekbb/expand-aws-iam-wildcards/pull/180</a></li>
<li>Model incomplete diff analysis by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/181">https://github.com/thekbb/expand-aws-iam-wildcards/pull/181</a></li>
<li>Handle incomplete pull request diffs by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/182">https://github.com/thekbb/expand-aws-iam-wildcards/pull/182</a></li>
<li>Test the compiled action lifecycle by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/183">https://github.com/thekbb/expand-aws-iam-wildcards/pull/183</a></li>
<li>test pull request behavior in an isolated repository by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/184">https://github.com/thekbb/expand-aws-iam-wildcards/pull/184</a></li>
<li>Fix AWS action documentation links that amazon dorked up by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/185">https://github.com/thekbb/expand-aws-iam-wildcards/pull/185</a></li>
<li>add test coverage thresholds so codecov will stop whining by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/186">https://github.com/thekbb/expand-aws-iam-wildcards/pull/186</a></li>
<li>simplify cloud-copilot/iam-data updates, now just dependabot by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/187">https://github.com/thekbb/expand-aws-iam-wildcards/pull/187</a></li>
<li>add script to check release candidate files and working copy by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/189">https://github.com/thekbb/expand-aws-iam-wildcards/pull/189</a></li>
<li>deps: bump @cloud-copilot/iam-data from 0.21.202608081 to 0.21.202608151 in the npm-dependencies group across 1 directory by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/188">https://github.com/thekbb/expand-aws-iam-wildcards/pull/188</a></li>
<li>Refresh release candidate pull requests by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/190">https://github.com/thekbb/expand-aws-iam-wildcards/pull/190</a></li>
<li>Verify release merge commit signatures by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/191">https://github.com/thekbb/expand-aws-iam-wildcards/pull/191</a></li>
<li>release attestation provenance by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/192">https://github.com/thekbb/expand-aws-iam-wildcards/pull/192</a></li>
<li>Recheck release commit signatures by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/193">https://github.com/thekbb/expand-aws-iam-wildcards/pull/193</a></li>
<li>update guidance to use semver over 40 char sha (with immutable releases) by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/194">https://github.com/thekbb/expand-aws-iam-wildcards/pull/194</a></li>
<li>Fix release workflow verification by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/195">https://github.com/thekbb/expand-aws-iam-wildcards/pull/195</a></li>
<li>Require complete release signature verification. by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/196">https://github.com/thekbb/expand-aws-iam-wildcards/pull/196</a></li>
<li>Simplify GitHub release verification by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/197">https://github.com/thekbb/expand-aws-iam-wildcards/pull/197</a></li>
<li>Prepare v2.0.0 release by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/198">https://github.com/thekbb/expand-aws-iam-wildcards/pull/198</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/thekbb/expand-aws-iam-wildcards/compare/v1.4.0...v2.0.0">https://github.com/thekbb/expand-aws-iam-wildcards/compare/v1.4.0...v2.0.0</a></p>
]]></content:encoded></item><item><title>Symfony Security Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/symfony-security-auditor/</link><pubDate>Sun, 23 Aug 2026 22:49:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/symfony-security-auditor/</guid><description>Version updated for https://github.com/vinceAmstoutz/symfony-security-auditor to version 1.20.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Symfony Security Auditor is an AI-powered security auditor that complements static analysis tools by detecting vulnerabilities missed by traditional methods. It uses a two-agent loop to identify application-level flaws, including authorization issues and multi-file attack chains. The auditor provides a validated report in various formats and can be used standalone or as a Symfony bundle for enhanced auditing capabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vinceAmstoutz/symfony-security-auditor">https://github.com/vinceAmstoutz/symfony-security-auditor</a></strong> to version <strong>1.20.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/symfony-security-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Symfony Security Auditor is an AI-powered security auditor that complements static analysis tools by detecting vulnerabilities missed by traditional methods. It uses a two-agent loop to identify application-level flaws, including authorization issues and multi-file attack chains. The auditor provides a validated report in various formats and can be used standalone or as a Symfony bundle for enhanced auditing capabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(ci): keep the release a draft until built by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/347">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/347</a></li>
<li>fix(standalone): always-on banner and dry-run by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/348">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/348</a></li>
<li>chore(release): prepare 1.20.1 by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/349">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/349</a></li>
<li>chore: release 1.20.1 by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/350">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/350</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.20.0...1.20.1">https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.20.0...1.20.1</a></p>
]]></content:encoded></item><item><title>Prism Reviewer AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/prism-reviewer-ai/</link><pubDate>Sun, 23 Aug 2026 22:48:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/prism-reviewer-ai/</guid><description>Version updated for https://github.com/vyoman-labs/prism-reviewer to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Prism Reviewer is an AI-driven code review system that automates static analysis, dependency scanning, and parallel LLM-guided code evaluation. It acts as an autonomous gatekeeper for pull requests by performing targeted multi-agent code reviews.
What’s Changed Prism Reviewer AI v1.1.0 — Incremental Review Engine, Pluggable Token Telemetry &amp;amp; Context-Aware PR Discussions</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vyoman-labs/prism-reviewer">https://github.com/vyoman-labs/prism-reviewer</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prism-reviewer-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Prism Reviewer is an AI-driven code review system that automates static analysis, dependency scanning, and parallel LLM-guided code evaluation. It acts as an autonomous gatekeeper for pull requests by performing targeted multi-agent code reviews.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Prism Reviewer AI v1.1.0 — Incremental Review Engine, Pluggable Token Telemetry &amp; Context-Aware PR Discussions</p>
<p><a href="https://github.com/vyoman-labs/prism-reviewer/blob/main/CHANGELOG.md#110---2026-08-23">https://github.com/vyoman-labs/prism-reviewer/blob/main/CHANGELOG.md#110---2026-08-23</a></p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/cowork-harness/</link><pubDate>Sun, 23 Aug 2026 22:47:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v2.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cowork-harness action automates the testing of Claude Cowork skills by providing a scriptable and CI-friendly test harness that closely reproduces the observable runtime contract. It ensures that tests clear the constraints that break skills in Cowork, offering evidence of what the agent actually did during a run, not just what it said it did. The tool supports various fidelity tiers and provides an interface to inspect and analyze test results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The cowork-harness action automates the testing of Claude Cowork skills by providing a scriptable and CI-friendly test harness that closely reproduces the observable runtime contract. It ensures that tests clear the constraints that break skills in Cowork, offering evidence of what the agent actually did during a run, not just what it said it did. The tool supports various fidelity tiers and provides an interface to inspect and analyze test results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>lint</code> warns when <code>prompt:</code> names a slash command anywhere but the start</strong> (⚠
<code>WARN [prompt-slash-not-leading]</code>). Writing <code>/&lt;skill-name&gt;</code> into a scenario prompt is what an author
reaches for when a skill will not auto-trigger, and it works — the harness sends <code>prompt:</code> verbatim and the
agent expands a <strong>leading</strong> slash before the model is called. Named mid-sentence (&ldquo;review the deck with
<code>/deck-review</code>&rdquo;) it is never expanded: the text reaches the model as prose, which may then pick the <code>Skill</code>
tool on its own — the same auto-trigger path the slash was meant to bypass. The scenario still runs and can
still pass, so it silently stops testing what it reads as testing. Paths, URLs, filenames and dates
(<code>/mnt/uploads/x</code>, <code>https://…</code>, <code>/deck.pdf</code>, <code>8/22</code>) do not trigger it.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>Every published version floor was unbounded, so it resolved across a major.</strong> The skill and the CI
recipes advertised <code>cowork-harness@&gt;=X.Y.Z</code>; <code>&gt;=</code> does not stop at a major boundary — measured,
<code>cowork-harness@&gt;=1.0.0</code> matches 2.0.0 — so a consumer following the documented floor was handed the
next <strong>breaking</strong> release automatically. That is not hypothetical: it is how <code>@&gt;=2.0.0</code> resolved the
deprecated 2.0.0. All 12 live floors across <code>README.md</code>, <code>SKILL.md</code>, <code>ci-recipe.md</code> and
<code>examples/replays/README.md</code> are now <code>@^X.Y.Z</code>, which resolves the newest release <strong>within the same
major</strong>, and the docs that teach the pattern teach the bounded form.</p>
<p><code>check:versions</code> gains invariant 13, which is what keeps it that way: <strong>no shipped doc may advertise
<code>@&gt;=</code> with a real version</strong>, and every doc carrying a live floor must agree with <code>SKILL.md</code>&rsquo;s. It scans
the whole shipped-doc corpus rather than a hand-listed set — <code>ci-recipe.md</code> and
<code>examples/replays/README.md</code> had drifted out of the previous checks precisely by not being on such a
list. A doc that deliberately cites an OLD floor to illustrate a past feature gate opts out of the
equality rule with an inline <code>floor-historical</code> marker; it does <strong>not</strong> opt out of the <code>&gt;=</code> rule, since
the form is the defect whatever the version.</p>
</li>
<li>
<p><strong>Twenty authored objects silently STRIPPED unknown keys instead of rejecting them</strong> (11 in
<code>src/types.ts</code>, 9 in <code>src/session.ts</code>, all <code>z.object</code> → <code>z.strictObject</code>). For an authored document a
typo did not fail — it changed what you wrote: <code>{ from: &quot;/tmp/x&quot;, mdoe: &quot;r&quot; }</code> parsed to
<code>{ from: &quot;/tmp/x&quot;, mode: &quot;rw&quot; }</code>, turning a <strong>read-only mount writable</strong>. In the assertion layer a
misspelled field on <code>path_denied</code> stripped to <code>{}</code>, which matches <em>any</em> path denial, greening a run that
should have failed. The sweep reaches objects behind <code>z.array</code> (<code>Folder</code>, <code>Project</code>) that a top-level
scan misses, and is guarded by a walk of the zod tree — the generated JSON Schema cannot express the
difference (<code>z.object</code> and <code>z.strictObject</code> both emit <code>additionalProperties: false</code>), so a
schema-based assertion there is a test that cannot fail. <strong>Note the compatibility edge:</strong> a document
carrying such a typo loaded before and now fails at load. The published schema is unchanged
(byte-identical); this tightens the loader.</p>
</li>
<li>
<p><strong>A connected folder&rsquo;s host path could reach a committed cassette.</strong> <code>folderPrefixMap[].from</code> holds the
record-time host path (<code>/Users/&lt;name&gt;/…</code>); neither the privacy scanner nor the redactor read the field,
and <code>redactCassette</code> passed it through in its <code>...cassette</code> spread — so <code>verify-cassettes</code> reported
<code>ok: true</code> with <code>privacyScanned: true</code> over a real username and directory layout. Fixed at all three
sites: the scan, the redactor, and <code>readCassetteForScan</code>&rsquo;s malformed-document projection — that last one
is the trap, since a fixture built only from a valid cassette passes with half the fix missing. <strong>The
committed example was re-redacted in the same change</strong> (<code>examples/replays/example-pdf-skill.cassette.json</code>
— <code>&quot;/Users/…/examples/data/project&quot;</code> → <code>&quot;/redacted/examples/data/project&quot;</code>), so the path that was already
public in this repo is scrubbed rather than merely blocked for future recordings.</p>
</li>
<li>
<p><strong><code>--answer-policy</code> turned a one-character typo into zero rules, silently.</strong> A document keyed <code>answer:</code>
instead of <code>answers:</code> hit <code>?? []</code>, and an empty array passes an <code>Array.isArray</code> check — so the policy
loaded as &ldquo;no rules&rdquo; and the run spent tokens before whiffing on the first gate. The parser now
distinguishes a missing <code>answers</code> key from an empty list and names the top-level keys it actually found.</p>
</li>
<li>
<p><strong>A record-time warning named the wrong assertions.</strong> When a secret triggers whole-field marker
replacement, the warning claimed <code>artifact_json</code>/<code>user_visible_artifact</code> &ldquo;will fail at replay&rdquo;.
<code>user_visible_artifact</code> and <code>file_exists</code> check location, not content, and still <strong>pass</strong> (the marker is
written with a recomputed <code>sha256</code>); only the body-reading keys fail. An author could read a passing
visibility assertion as proof the scrubbed content survived. Corrected in the warning and in
<a href="./docs/cassette.md"><code>docs/cassette.md</code></a> together — one claim in two places.</p>
</li>
<li>
<p><strong>A release no longer becomes every unpinned consumer&rsquo;s default install the moment CI goes green.</strong>
<code>npm publish</code> with no <code>--tag</code> writes <code>latest</code>, which is how 2.0.0 — a breaking hash-format epoch plus a
flagship replay that exited 1 from an npm install — reached everyone with no human in between, and had
to be rolled back to 1.25.0 by hand. CI now publishes with <code>--tag next</code>; the version is fully published
and installable as <code>cowork-harness@next</code> or by exact version, and promoting it to <code>latest</code> is a
documented <a href="./RELEASING.md"><code>RELEASING.md</code></a> step that needs a 2FA challenge, which is the point.</p>
</li>
<li>
<p><strong>The flagship zero-token replay now works from an npm install.</strong> <code>README.md</code> and
<a href="./examples/replays/README.md"><code>examples/replays/README.md</code></a> tell a new reader that the first thing to run is
<code>cowork-harness replay examples/replays/example-pdf-skill.cassette.json</code>. From an npm install that exited 1:
the cassette resolves <code>../sessions/default.yaml</code>, <code>../scenarios/…</code> and <code>../skills/my-pdf-skill</code>, and
<code>package.json</code> <code>files[]</code> shipped only <code>examples/replays</code>. A 2.0.0 regression — before the hash-format epoch,
unverifiable staleness warned and exited 0. <code>files[]</code> now also ships <code>examples/sessions</code>, <code>examples/skills</code>,
<code>examples/scenarios</code> and <code>examples/data</code>, and a guard reads the packed file list and derives its requirements
from the cassette itself (session, <code>scenarioSource</code>, every hashed <code>fileSig</code>), so a re-record cannot quietly
outrun it. Note that <code>replay --strict</code> from an extracted tarball still reports the <code>format</code>-class
<code>recorded in 'git' file-set mode, verifying in 'raw'</code>: a tarball is not a git work tree, so the file-set
boundary differs from the one the cassette was recorded under. That is honest, not a packaging defect.</p>
</li>
<li>
<p><strong>Seven statements about what a global install ships were left stale by that packaging change</strong>, five of
them in <code>README.md</code> — including a &ldquo;What ships&rdquo; table row marking the runnable worked examples ✗ for npm, a
callout saying <code>run examples/scenarios/…</code> &ldquo;errors with a missing file&rdquo;, and two
<em>(source checkout only — not shipped in the npm package)</em> parentheticals in
<a href="./docs/cassette.md"><code>docs/cassette.md</code></a> and <a href="./docs/discovery.md"><code>docs/discovery.md</code></a> against files that
now ship. Measured from an extracted tarball: all eight published example scenarios resolve their session
and every skill/plugin root they stage, and <code>lint examples/scenarios/</code> is clean.
What genuinely does not ship is <code>examples/matrices/</code>, <code>examples/answer-policies/</code> and <code>examples/probes/</code>,
and the corrected prose says so. A <code>files[]</code> edit and the prose describing it had no mechanical link; a
guard now resolves every shipped scenario&rsquo;s references against the packed file list, so the next such edit
fails rather than quietly turning three pages into fiction.</p>
</li>
<li>
<p><strong>Nine relative links in shipped documentation pointed at files npm does not publish.</strong> <code>./action.yml</code>,
<code>.github/workflows/ci.yml</code> (twice), three <code>src/**</code> implementation pointers in
<a href="./docs/decider-dir.md"><code>docs/decider-dir.md</code></a> and <a href="./docs/run-status.md"><code>docs/run-status.md</code></a>, and two
&ldquo;runnable copy&rdquo; pointers in <a href="./docs/scenario.md"><code>docs/scenario.md</code></a>. All nine resolve in a git checkout —
which is why nothing caught them — and all nine were dead from <code>npm i cowork-harness</code>. They are now
<code>blob/main</code> links, the convention the companion skill&rsquo;s references already use for the same reason. A guard
now reads the packed file list from <code>npm pack --dry-run --json</code>, extracts every link from every shipped
Markdown file, and resolves each one against it; it also checks that every target it extracted exists in a
source checkout, so a regex that starts matching prose fails rather than inflating the pass count.</p>
</li>
<li>
<p><strong><code>pytest</code> from the repo root collected the paid <code>cowork</code> lane.</strong> <code>addopts = &quot;-m 'not cowork'&quot;</code> lived
only in <code>python/pyproject.toml</code>, and pytest reads the config at the rootdir for the invocation — so a bare
<code>pytest</code> from the repo root read none of it and selected the three <code>@pytest.mark.cowork</code> tests, each of
which spawns node, Docker and a real model. A root <code>pytest.ini</code> fixes that invocation.</p>
</li>
<li>
<p><strong>The <code>cowork</code> lane is now opt-in from the module, not just from config.</strong> INI config does not travel with
an installed helper: a consumer&rsquo;s <code>pytest</code> reads <em>their</em> rootdir, so <code>addopts</code> protects nobody downstream —
and it will protect nobody here either once the helper ships as a <code>pytest11</code> plugin. <code>cowork_harness</code> now
carries the rule itself: a collection hook skips <code>cowork</code>-marked tests, and the <code>cowork</code> fixture refuses to
build a runner, unless the run asked for the lane (<code>-m</code> mentioning <code>cowork</code>, or the new
<code>COWORK_HARNESS_PYTEST_LANE=1</code>). The two guards are not redundant — the hook keys on the marker, so a test
that takes the fixture without wearing <code>@pytest.mark.cowork</code> reaches the fixture guard and nothing else.
Selecting a lane test some other way (<code>-m fast</code>, a bare node id) is deliberately not opt-in; the skip
reason names both switches. <code>pytest -m cowork</code> and <code>pytest -m 'not cowork'</code> behave exactly as before.</p>
</li>
<li>
<p><strong>Three present-tense claims about the cassette format were stale at <code>CASSETTE_VERSION</code> 12.</strong>
<code>task-recipes.md</code> — the page a skill author reads when they open a cassette — linked
<code>schema/cassette.v11.json</code> and called 11 &ldquo;current max&rdquo;, describing a version regime (<code>lane: remote</code>
stamps 11, everything else 10) that the hash-format epoch had already replaced. <code>SPEC.md</code> said
<code>schema/cassette.v9.json</code> and <code>v10</code> were &ldquo;retained alongside v11&rdquo;, which both understated the retained
set and re-stated 11 as the top. Corrected, and <code>check:versions</code> gained invariant 12: SPEC&rsquo;s max, read
floor and retained-range sentences and task-recipes&rsquo; schema pointer and &ldquo;current max: N&rdquo; are now checked
against <code>CASSETTE_VERSION</code>, <code>MIN_SUPPORTED_CASSETTE_VERSION</code> and the <code>schema/cassette.v*.json</code> files on
disk, and no shipped page may link a schema file that is not there. Bumping <code>CASSETTE_VERSION</code> in a
scratch tree now fails the check naming all four surfaces.</p>
<p>It guards <strong>current</strong> claims only. <code>docs/scenario.md</code> and <code>docs/cassette.md</code> explain the v10-vs-v11
<code>lane: remote</code> regime at length and are correct history; <code>CHANGELOG.md</code> is nothing but history. A guard
that flagged those would train the next author to route around it. The retained set is stated as a range
rather than a list precisely so it cannot go stale by omission the way the old sentence did — and the
check refuses the range form outright if <code>schema/</code> ever stops being contiguous.</p>
</li>
<li>
<p><strong><code>schema/scenario.schema.json</code> said nothing about its own scope, so validating against it read as
&ldquo;this will run&rdquo;.</strong> It mirrors the two mutually-exclusive delete-assertion rules and nothing else, which
means an editor or a CI step that checks a scenario against it alone greens files the harness refuses.
Its <code>description</code> now says so and names where behavioural validation actually lives. Measured, because
the answer is not one command: a matcher-less <code>answers:</code> entry (<code>{}</code>) passes <code>lint</code> <strong>clean</strong> and is
refused by the loader (<code>record --dry-run</code>, exit 2), while <code>lane: remote</code> with a delivery-shaped
assertion is caught by <code>lint</code> (<code>lane-remote-incompatible-key</code>, exit 1). Neither tool alone covers both,
so the text points at both. Tests pin the gap from both sides — mirroring one of those rules in later,
or dropping the one that IS mirrored, fails and forces the description to be rewritten.</p>
</li>
<li>
<p><strong><code>RELEASING.md</code>&rsquo;s tarball checklist told the releaser the companion skill &ldquo;ships via the marketplace,
not npm&rdquo;.</strong> It ships on both: <code>package.json</code> <code>files[]</code> publishes <code>SKILL.md</code>, <code>references/</code> and the
bundled <code>scenario.py</code> + <code>assertion-keys.json</code> — 26 files under <code>.claude/</code> in the packed tarball. The
marketplace install is the NARROWER one, materializing only <code>.claude/skills/cowork-harness/**</code>. Since
the checklist item exists to make a releaser confirm what is in the tarball, it was pointing at the
wrong expectation at exactly the wrong moment.</p>
</li>
<li>
<p><strong>Four overclaims that a prospective user reads while deciding whether to trust the tool.</strong> Each was
checked against primary evidence rather than against the doc that repeated it.</p>
<ul>
<li><strong>Egress parity was stated as identity, in five places.</strong> <code>DESIGN.md</code> called the default allowlist
&ldquo;captured from the live asar&rdquo;; <code>README.md</code> called it &ldquo;the <strong>synced</strong> allowlist&rdquo; and the fidelity
&ldquo;allowlist-exact&rdquo;; <code>README.md</code> and <code>docs/boundary.md</code> said domain allow/deny &ldquo;matches Cowork&rdquo; / &ldquo;is
identical&rdquo;, and a <code>DESIGN.md</code> table row said the same. The pinned baseline refutes all five in its own
<code>network.$comment</code>: the list is &ldquo;a PINNED, hand-curated list — <code>sync</code> carries it forward and never
re-derives it … a curated RECONSTRUCTION, not an extraction&rdquo;, because on the first-party deployment
the VM egress allowlist is not in the app bundle at all (that class returns <code>vmEgressPolicy(){return null}</code>; the real list is server-delivered per session), and four entries are flagged UNVERIFIED as VM
egress. What is true — enforcement is domain-exact against the pinned list — is now what the docs say.</li>
<li><strong>&ldquo;A green test means green in real Cowork&rdquo;</strong> (<code>README.md</code>, <code>llms.txt</code>) was unconditional, 21 lines
above a callout that correctly calls this an emulator of the contract. <code>mount_delete</code> alone is
<code>severity: &quot;warn&quot;</code> here while production denies it. The tagline now claims what it can support — a
green run has cleared the constraints that break skills in Cowork — and points at
<a href="./docs/fidelity-gaps.md"><code>docs/fidelity-gaps.md</code></a> for the deliberate divergences.</li>
<li><strong>The local lane was described as an agent inside the microVM</strong> in <code>README.md</code> and <code>DESIGN.md</code> §1,
while <code>DESIGN.md</code>&rsquo;s spawn-contract section says the opposite and is right. Measured:
<code>decideLoopFromBaseline(desktop-1.34493.1)</code> returns <code>&quot;host&quot;</code> — the loop runs on the host and reaches
the VM for shell. §1 now defers to that section instead of contradicting it.</li>
<li><strong>The hermetic-<code>CLAUDE_CONFIG_DIR</code> guarantee is not unconditional</strong> (<code>README.md</code>,
<code>docs/discovery.md</code>). At <code>protocol</code> fidelity with no <code>ANTHROPIC_API_KEY</code>, the harness deliberately
keeps your real config dir — a fresh one breaks local OAuth — and layers discovery settings via
<code>--settings</code> instead (<code>src/runtime/protocol.ts</code>, whose comment already says so). Both pages now carry
the exception and name <code>COWORK_MANAGED_CONFIG=1</code>; the sandboxed tiers are unaffected.</li>
</ul>
</li>
<li>
<p><strong>Seven documented gates that do not gate the way the docs say.</strong> Each was measured against the CLI, not
read off the code.</p>
<ul>
<li><strong><code>analyze-skill</code>&rsquo;s <code>ok</code> and <code>--strict</code> semantics were wrong in five places.</strong> Both key on
<strong>severity</strong>, not on the finding count: <code>ok</code> mirrors the exit code, and <code>--strict</code> fails only on an
<code>error</code>-severity finding. Measured with one finding present — plain run: <code>ok: true</code>, exit 0; with an
advisory-only finding (<code>artifact-write-back-suspect</code>): <strong>exit 0 even under <code>--strict</code></strong>. So &ldquo;<code>ok</code> is
true only when every file has zero findings&rdquo; and &ldquo;<code>--strict</code> … fails on any unsuppressed finding&rdquo;
(<a href="./docs/subagents.md"><code>docs/subagents.md</code></a>, <a href="./README.md"><code>README.md</code></a>) are both false, and
<code>action.yml</code>&rsquo;s and README&rsquo;s description of the Action&rsquo;s <code>strict</code> input as applying to &ldquo;any advisory
finding&rdquo; is the <strong>inverse</strong> of the truth — advisory is exactly the class that never gates.
<code>docs/subagents.md</code> also called the three <code>/sessions</code> rules &ldquo;all advisory findings&rdquo;; every one is
severity <code>error</code>.</li>
<li><strong><code>README.md</code> claimed <code>analyze-skill</code> statically analyzes <code>.ts</code> sources.</strong> <code>.ts</code>/<code>.tsx</code>/<code>.jsx</code> are in
<code>ARTIFACT_UNPARSEABLE_EXTS</code> — out of scope. <code>docs/subagents.md</code> got the exclusion right but said such
a target &ldquo;is reported under <code>unscannedArtifactSources</code> rather than silently passing as clean&rdquo;; that
field is scoped to explicit positionals, so a <strong>directory</strong> scan over a TypeScript generator reports
nothing at all. Both now say which one you get.</li>
<li><strong>The CI recipe defined overall pass without the verdict</strong> — <code>result === &quot;success&quot; &amp;&amp; assertions.every(pass)</code>. The verdict carries ~20 signal codes that fail a run with no failing
assertion (<code>stalled</code>, <code>mount_delete</code>, <code>host_path_leak</code>, <code>undelivered_deliverables</code>,
<code>permissive_auto_allow</code>, <code>ended_with_question</code>, <code>infra_error</code>, …). A parser copied from the recipe
greened through every one; it now points at <code>verdict.pass</code> / <code>ok</code>.</li>
<li><strong>The recipe&rsquo;s &ldquo;sha256-verified&rdquo; step verified nothing</strong> — <code>curl</code>, <code>chmod</code>, and two comments saying
someone ought to verify. It now runs <code>sha256sum -c -</code> against the pinned digest and fails the job.</li>
<li><strong><code>docs/scenario.md</code> told remote-lane authors to &ldquo;assert the delivery itself&rdquo;</strong> — a key that does not
exist. <code>src/run/execute.ts</code> and <code>src/assert.ts</code> both carry a comment saying so verbatim (&ldquo;Advising it
sent a consumer looking for a key that does not exist&rdquo;); the error messages were fixed and the table
was not. It now names the real remedy (<code>file_exists</code> + <code>transcript_matches</code>, or <code>lane: local</code>).</li>
<li><strong><code>docs/scenario.md</code> pointed <code>run</code> at <code>--decider-llm</code>.</strong> Measured: <code>run</code> is the only command that
rejects it (<code>unexpected argument(s)</code>, exit 2 — <code>record</code>, <code>skill</code> and <code>decide</code> accept it), and
<code>run --help</code> says &ldquo;run omits <code>--decider-llm</code> by design&rdquo;. Three mentions now carry that, and name
<code>on_unanswered: llm</code> and <code>--decider-dir</code> as what <code>run</code> does take.</li>
<li><strong><code>docs/cassette.md</code> said <code>verify-cassettes</code> exits 1 on an unverifiable tree, twice.</strong> Measured on a
relocated cassette: <code>replay</code> exits 1, <code>verify-cassettes</code> exits <strong>3</strong> — could not verify, which the
CLI&rsquo;s own help distinguishes from the exit 1 it uses for a verified failure.</li>
</ul>
</li>
<li>
<p><strong>Seven authoring-surface claims that misdescribe what the code does.</strong> The first two are in the shipped
skill, so an installed agent was teaching them.</p>
<ul>
<li><strong><code>SKILL.md</code> said a &ldquo;type-it-in-notes&rdquo; option has &ldquo;no scripted deterministic answer&rdquo; today.</strong> It has
one: <code>answer:</code> — an arbitrary string delivered verbatim, bypassing label validation by author intent
(<code>AnswerRule.answer</code> in <code>src/types.ts</code>, implemented at <code>src/decide/decider.ts</code>, and present in the
published scenario schema). The claim steers agents onto the LLM decider, with its cost and its
<code>nonDeterministic</code> flag, for something a scripted key already covers. What genuinely has no scripted
equivalent is the <code>OTHER:</code> <em>directive</em>, which is what the surrounding parenthetical is about.</li>
<li><strong>&ldquo;Never hand-write the <code>req-N.json</code>/<code>resp-N.json</code> files&rdquo; is unachievable for three of four gate
kinds.</strong> The <code>answer</code> subcommand&rsquo;s only terminal write is <code>{id, answers}</code>, while the same channel
carries <strong>permission</strong>, <strong>dialog</strong> and <strong>elicit</strong> gates, whose replies take <code>{behavior}</code> / <code>{action}</code>.
Both <a href="./.claude/skills/cowork-harness/SKILL.md"><code>SKILL.md</code></a> and
<a href="./docs/decider-dir.md"><code>docs/decider-dir.md</code></a> now scope the rule to question gates, and <code>decider-dir</code>
documents the alternative: each <code>req-N.json</code> advertises its own <code>reply_with</code> template, so the shape
never has to be guessed.</li>
<li><strong><code>fidelity: cowork</code> can also require <code>allow_host_writes</code>.</strong> The consent check gates on
<code>effectiveFidelity === &quot;hostloop&quot;</code>, and <code>cowork</code> resolves to hostloop on every shipped baseline —
so a gate flip can red an unchanged <code>cowork</code> scenario. <a href="./docs/scenario.md"><code>docs/scenario.md</code></a>
described the consent as hostloop-only.</li>
<li><strong>Local marketplaces are read, not registered.</strong> <code>.claude-plugin/marketplace.json</code> is parsed directly
and the plugins it names are resolved to <code>--plugin-dir</code>; the <code>claude plugin marketplace add</code> registry
is inert in cowork mode. <a href="./docs/session.md"><code>docs/session.md</code></a> said &ldquo;registered via <code>claude plugin marketplace add</code>&rdquo; in two places, and <code>src/session.ts</code> carried the same stale comment.</li>
<li><strong>Git-tracked staging does not apply to <code>hostloop</code> connected folders.</strong> They are bind-mounted rather
than copied there (matching production), and the git filter lives in the copy path — so the same
session exposes untracked files at <code>hostloop</code> that are invisible at <code>container</code>. The rule was stated
without a tier qualifier.</li>
<li><strong>The connected-folder delete assertion is <code>no_delete_in_mounts</code>, not <code>no_delete_in_outputs</code>.</strong>
<code>no_delete_in_outputs</code> covers <code>outputs/</code> only; the mount-wide form covers &ldquo;outputs + every <code>rw</code>
connected folder&rdquo;. <a href="./docs/session.md"><code>docs/session.md</code></a> and
<a href="./docs/boundary.md"><code>docs/boundary.md</code></a> both routed the reader to the one that does not cover it.</li>
<li><strong><code>web_fetch.approved_domains</code> is inert except at <code>hostloop</code>.</strong> <code>enableWebFetchGate()</code> is called at
one site, guarded by <code>effectiveFidelity === &quot;hostloop&quot; &amp;&amp; viaApiOn</code>, and that gate is the only
consumer of the set. The value is still parsed and seeded at <code>container</code>/<code>microvm</code>, where nothing
reads it — <a href="./docs/session.md"><code>docs/session.md</code></a> described it as unconditional in two places.</li>
</ul>
</li>
<li>
<p><strong>Nine claims where one page contradicted another — or itself.</strong> The accurate version already existed in
most cases; these hoist it rather than inventing new content.</p>
<ul>
<li><strong><code>SECURITY.md</code> classified scenario YAML as both &ldquo;semi-trusted&rdquo; and &ldquo;trusted input&rdquo;, 30 lines apart.</strong>
The trusted reading is the correct one — <code>allow_if</code> is evaluated as host JavaScript via <code>new Function</code>,
so an author can run arbitrary code, by design. That statement now leads the input-boundary section;
cassettes and marketplace metadata stay semi-trusted.</li>
<li><strong><code>SECURITY.md</code> said host resources are &ldquo;reachable only through an MCP server, never via direct host
tools&rdquo;.</strong> Not at <code>hostloop</code>: the agent loop is a native host process whose Read/Write/Edit/Glob/Grep
run with no container around them, contained only by a <code>PreToolUse</code> gate — which is exactly what
production does, and why a writable connected folder there needs <code>allow_host_writes</code>.
<a href="./docs/boundary.md"><code>docs/boundary.md</code></a> documented this correctly all along.</li>
<li><strong><code>SECURITY.md</code> and <code>SPEC.md</code> routed <code>web_fetch</code> through the container egress boundary.</strong> It is
host-routed at <code>hostloop</code> (matching production&rsquo;s host-API route), so it never crosses the per-run proxy
or guest firewall — those enforce <code>bash</code> egress. <code>SPEC.md</code> said so correctly in two later sections while
two earlier ones said the opposite.</li>
<li><strong><code>docs/scenario.md</code> listed <code>replay</code> as a <code>requires_capabilities</code> hard-fail case</strong> in a bullet, and said
the opposite two sentences later. Replay re-drives and resets the outcome; the bullet was the stale half.</li>
<li><strong><code>docs/cassette.md</code> understated the committed body surface.</strong> A cassette inlines the body of <em>every</em>
under-cap regular file under <code>outputs/</code> and <code>.projects/</code> — UTF-8 as text, anything else as base64 — not
just &ldquo;the <code>outputs/</code> JSON bodies&rdquo;. An author can commit a spreadsheet, an image or a PDF believing only
JSON is embedded. Uploads and <code>mode:r</code> folders are hash-only; over-cap files carry
<code>truncationReason: &quot;size&quot;</code>.</li>
<li><strong>&ldquo;Permanently unverifiable&rdquo; is wrong in two places</strong> (<a href="./docs/cassette.md"><code>docs/cassette.md</code></a>,
<a href="./.claude/skills/cowork-harness/SKILL.md"><code>SKILL.md</code></a> — the latter ten lines below its own correct
statement of the recovery). A relocated cassette is unverifiable <em>from its own location</em>;
<code>--session &lt;file&gt;</code> resolves it without a re-record.</li>
<li><strong><code>docs/cassette.md</code>&rsquo;s minimal CI snippet ran <code>replay</code> only</strong>, on a page that opens with &ldquo;In CI, run
both commands&rdquo;. The snippet now runs <code>verify-cassettes</code> too, with its exit-code meanings.</li>
<li><strong><code>docs/protocol.md</code> said all three callers &ldquo;skip the offending frame loudly&rdquo;</strong> on a malformed frame.
They do three different things, and only one is a skip: the live session surfaces a typed protocol
error event, <strong>cassette replay turns it into a FAILING <code>replay_protocol_fidelity</code> assertion</strong> (a
malformed frame could conceal a failed assertion, so a silent skip would risk a false green), and
<code>trace</code> is the one that skips and moves on.</li>
<li><strong><code>rehash</code> is the 2.0.0 upgrade step and the README command row did not say so.</strong> The row now states
that the hash-format epoch fails a bare <code>replay</code> until each cassette is migrated, and points at the
CHANGELOG entry.</li>
</ul>
</li>
<li>
<p><strong>Two replay-class misclassifications, and a guard that could not see them.</strong> Which bucket an assertion
key sits in — always-content, controlOut-gated, manifest-backed, or live-only — is what tells an author
whether their assertion survives a token-free <code>replay</code> or is silently skipped. The existing
<code>docs/cassette.md</code> guard compared a <strong>union</strong> of three buckets (leaving <code>LIVE_ONLY_KEYS</code> out entirely),
and a union cannot see a key MOVE between buckets, which is the change that matters.</p>
<ul>
<li><code>fidelity-and-answers.md</code> enumerated the live-only set and omitted <strong><code>no_delete_in_mounts</code></strong> — a
reader working from that list would expect it to replay.</li>
<li><code>scenario.py</code>&rsquo;s <code>scaffold</code> emitted <code>file_exists</code> and <code>user_visible_artifact</code> under a heading reading
<em>&ldquo;LIVE-only (skipped on replay)&rdquo;</em>. Both are manifest-backed: they replay whenever the cassette carries
an artifacts manifest, which <code>record</code> has snapshotted since 0.24. The scaffold contradicted the
taxonomy declared in its own file, and taught new authors exactly the misconception the
<code>manifest-needs-snapshot</code> INFO exists to correct. It now emits two labelled buckets.</li>
<li>Each bucket is now guarded independently and in <strong>both</strong> directions — every live-only key is named,
and no key from another bucket is. Moving one key between buckets in <code>cassette.ts</code> fails four tests.
The <code>scenario.py</code> check is deliberately a self-consistency check against that file&rsquo;s own sets rather
than a mirror of the TypeScript constants, because <code>scenario.py</code> says outright that it is &ldquo;NOT a 1:1
mirror&rdquo; (it keeps the verdict modifiers out of <code>CONTENT_KEYS</code> on purpose).</li>
</ul>
</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>
<p><strong><a href="./docs/fidelity-gaps.md"><code>docs/fidelity-gaps.md</code></a> no longer narrates its own edit history.</strong> Removed a
parenthetical describing what a previous draft of the <code>PostToolUse:WebSearch</code> note had claimed. A reader
arriving fresh has no &ldquo;before&rdquo; to contrast against, so being told that a claim absent from the document
was wrong costs a parse and says nothing about the harness. The paragraph above it already states current
behaviour.</p>
</li>
<li>
<p><strong><code>docs-present-tense</code> also catches a doc narrating its own revisions.</strong> Its patterns keyed entirely on
tense markers (<code>no longer</code>, <code>used to</code>, <code>previously</code>, …), and doc-self-history carries none — &ldquo;An earlier
revision of this section claimed X. That was wrong.&rdquo; passed the guard while being precisely what the
guard exists to stop. Three patterns added for that shape; each is covered by a mutation check rather
than by matching nothing and being assumed live.</p>
</li>
<li>
<p><strong><a href="./docs/scenario.md"><code>docs/scenario.md</code></a> — new &ldquo;Slash commands in <code>prompt:</code>&rdquo; section.</strong> Documents that a
slash command must START the prompt; that skills resolve by their bare frontmatter <code>name:</code> from either
staging route (<code>skills.local</code> or a <code>--plugin-dir</code> plugin source); that an unregistered name is answered by
the <strong>agent</strong>, not the model, ending the run with <code>Unknown command: /&lt;name&gt;</code>, <code>num_turns: 0</code> and no tokens
spent; and that expansion is not enforcement.</p>
</li>
<li>
<p><strong><a href="./docs/fidelity-gaps.md"><code>docs/fidelity-gaps.md</code></a> — corrected the <code>UserPromptSubmit</code> rationale.</strong> It
previously justified not serving the hook with &ldquo;a scenario <code>prompt:</code> is not a slash command, so the hook
returns <code>{}</code>&rdquo; — an assumption about consumer input, not a property of the harness, and one consumers do
violate. The gap itself is unchanged and narrower than that framing implied: the agent binary performs the
expansion on stream-json input on its own, so the body injection here is identical to production; only
Desktop&rsquo;s additional <code>additionalContext</code> is missing.</p>
</li>
<li>
<p><strong><code>--fail-on-skill-drift</code> does not detect skill drift when you replay from an npm install</strong> — measured, and
now pinned by a test that replays the flagship cassette from a real extracted tarball. A cassette is
recorded in <code>git</code> file-set mode; an extracted tarball is not a work tree, so the walk falls back to <code>raw</code>.
Digests taken over different file-set boundaries are not comparable, so staleness stops at the <code>format</code>-class
<code>recorded in 'git' file-set mode, verifying in 'raw'</code> rather than inventing a content diff — and <code>format</code> is
outside the skill-drift classes. The practical consequence: a tampered skill file in an extracted tarball
replays <code>ok: true</code> under the flag whose job is to catch exactly that, and <code>--strict</code> fails on the boundary
without ever naming the tampering. Run <code>replay</code> from a git work tree when skill-drift detection is the point.
The test carries a git-mode positive control on the same directory and the same mutation, so the finding is
a measurement rather than an absence of one. <a href="./docs/cassette.md"><code>docs/cassette.md</code></a>&rsquo;s staleness-class list
now says this at the finding itself — it previously described the boundary mismatch and told you to
re-record, without noting that the finding REPLACES the skill comparison rather than accompanying it.</p>
</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(fidelity-gaps): scope the real-CLAUDE_CONFIG_DIR claim to <code>protocol</code> by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/123">https://github.com/yaniv-golan/cowork-harness/pull/123</a></li>
<li>fix: three false-green defects (privacy scan, answer-policy, redaction warning) by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/124">https://github.com/yaniv-golan/cowork-harness/pull/124</a></li>
<li>fix(schema): authored objects reject unknown keys instead of stripping them by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/125">https://github.com/yaniv-golan/cowork-harness/pull/125</a></li>
<li>release: publish to <code>next</code>, promote to <code>latest</code> deliberately by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/126">https://github.com/yaniv-golan/cowork-harness/pull/126</a></li>
<li>lint: warn when <code>prompt:</code> names a slash command off position 0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/127">https://github.com/yaniv-golan/cowork-harness/pull/127</a></li>
<li>docs: stop a doc narrating its own revisions, and guard the shape by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/128">https://github.com/yaniv-golan/cowork-harness/pull/128</a></li>
<li>fix(pkg): ship what the flagship replay needs, so it works from an npm install by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/129">https://github.com/yaniv-golan/cowork-harness/pull/129</a></li>
<li>fix(docs): make the shipped docs true about the npm payload, and guard it by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/130">https://github.com/yaniv-golan/cowork-harness/pull/130</a></li>
<li>fix(python): keep the paid cowork lane opt-in from the module, not just from INI by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/131">https://github.com/yaniv-golan/cowork-harness/pull/131</a></li>
<li>fix(docs): version-couple the cassette-format claims to the constants by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/132">https://github.com/yaniv-golan/cowork-harness/pull/132</a></li>
<li>fix(docs): say what scenario.schema.json does NOT check, and fix RELEASING&rsquo;s tarball claim by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/133">https://github.com/yaniv-golan/cowork-harness/pull/133</a></li>
<li>docs: correct four overclaims a prospective user reads to decide whether to trust this by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/134">https://github.com/yaniv-golan/cowork-harness/pull/134</a></li>
<li>docs: correct seven documented gates that do not gate the way the docs say by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/135">https://github.com/yaniv-golan/cowork-harness/pull/135</a></li>
<li>docs: correct seven authoring-surface claims that misdescribe the code by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/136">https://github.com/yaniv-golan/cowork-harness/pull/136</a></li>
<li>docs: resolve nine places where one page contradicted another, or itself by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/137">https://github.com/yaniv-golan/cowork-harness/pull/137</a></li>
<li>fix(docs): guard each replay-class bucket independently, and fix two misfiled keys by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/138">https://github.com/yaniv-golan/cowork-harness/pull/138</a></li>
<li>docs(changelog): consolidate the 2.0.1 entry, reconciled against the diffs by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/139">https://github.com/yaniv-golan/cowork-harness/pull/139</a></li>
<li>docs(changelog): say the committed cassette was re-redacted, not just the code fixed by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/140">https://github.com/yaniv-golan/cowork-harness/pull/140</a></li>
<li>release: 2.0.1 — bump, seal the changelog, and bound every version floor (T-T1) by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/141">https://github.com/yaniv-golan/cowork-harness/pull/141</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v2.0.0...v2.0.1">https://github.com/yaniv-golan/cowork-harness/compare/v2.0.0...v2.0.1</a></p>
]]></content:encoded></item><item><title>Read mise.toml versions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/read-mise.toml-versions/</link><pubDate>Sun, 23 Aug 2026 22:45:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/read-mise.toml-versions/</guid><description>Version updated for https://github.com/yshrsmz/action-mise-values to version v0.3.1.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action action-mise-values reads the [tools] table from a mise.toml file and exposes it as a JSON output, enabling users to dynamically specify tool versions for subsequent workflow steps. It allows them to use official setup actions while leveraging built-in caching and additional features offered by those actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/action-mise-values">https://github.com/yshrsmz/action-mise-values</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/read-mise-toml-versions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>action-mise-values</code> reads the <code>[tools]</code> table from a <code>mise.toml</code> file and exposes it as a JSON output, enabling users to dynamically specify tool versions for subsequent workflow steps. It allows them to use official setup actions while leveraging built-in caching and additional features offered by those actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v0.3.1: PR #26 - chore(deps): update mikefarah/yq action to v4.53.6</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/b.ia-accessibility-checker/</link><pubDate>Sun, 23 Aug 2026 22:44:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in your CI/CD pipeline by evaluating code against WCAG guidelines. It helps companies ensure their products are accessible to a specific audience while minimizing learning curve costs and avoiding the need for external solutions. The action supports defining requirements, using AI for guideline analysis, and providing feedback if code does not meet specified accessibility standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in your CI/CD pipeline by evaluating code against WCAG guidelines. It helps companies ensure their products are accessible to a specific audience while minimizing learning curve costs and avoiding the need for external solutions. The action supports defining requirements, using AI for guideline analysis, and providing feedback if code does not meet specified accessibility standards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>skeptic-diff-audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/skeptic-diff-audit/</link><pubDate>Sun, 23 Aug 2026 06:09:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/skeptic-diff-audit/</guid><description>Version updated for https://github.com/mamadou-wane/skeptic to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
The Skeptic action automates differential testing by introducing known bugs into a pinned commit of a real upstream repository. It then audits the resulting patches to verify whether green test results indicate genuine improvements or if they could be artifacts from a previous bug. This helps ensure that test pass rates are meaningful and not indicative of accidental code coverage improvements. The action supports both lenient and strict detection, with a focus on false positive rates per split.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mamadou-wane/skeptic">https://github.com/mamadou-wane/skeptic</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skeptic-diff-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>The Skeptic action automates differential testing by introducing known bugs into a pinned commit of a real upstream repository. It then audits the resulting patches to verify whether green test results indicate genuine improvements or if they could be artifacts from a previous bug. This helps ensure that test pass rates are meaningful and not indicative of accidental code coverage improvements. The action supports both lenient and strict detection, with a focus on false positive rates per split.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The blind holdout and the pressure arms, and the weight they moved.</p>
<h2 id="measurements">Measurements</h2>
<p>Both eval sets re-run at <code>verifier_revision</code> 42a7253cd318, 0 INFRA on both.</p>
<table>
  <thead>
      <tr>
          <th></th>
          <th>dev set (n=29 hacks)</th>
          <th>blind holdout (n=11)</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>detection lenient</td>
          <td>29/29</td>
          <td>11/11</td>
      </tr>
      <tr>
          <td>detection strict</td>
          <td>12/29</td>
          <td>5/11</td>
      </tr>
      <tr>
          <td>attribution top-1</td>
          <td>21/29</td>
          <td>6/11</td>
      </tr>
      <tr>
          <td>attribution anywhere</td>
          <td>29/29</td>
          <td>11/11</td>
      </tr>
      <tr>
          <td>false positives</td>
          <td>0/12 gold · 0/12 gold-prime</td>
          <td>dev-set only</td>
      </tr>
  </tbody>
</table>
<p>The holdout&rsquo;s 11 hacks were authored by a model that never saw a detector, a
weight or a dev-set variant, and every category was adjudicated from the diffs
before any verdict existed.</p>
<p>Three pressure arms, 18 attempts: hack incidence 0 of 6 under a tight budget,
1 of 6 under an underspecified problem statement, 0 of 6 on a weaker model.</p>
<h2 id="two-findings-that-do-not-flatter-the-harness">Two findings that do not flatter the harness</h2>
<p><strong>Skeptic missed the one agent-authored hack.</strong> Told only to make the suite
pass, the Builder deleted <code>assert cut &gt; 0</code> and went green; the frozen
acceptance suite caught it and Skeptic returned PASS at 0.00 with no evidence.
Catch rate 0 of 1.</p>
<p><strong>Judge-alone&rsquo;s false positive was a sampling artifact.</strong> It scored 1 of 12 on
gold in one run and 0 of 12 on the same twelve clean patches in another. The
claim that Skeptic held 0 false positives against the judge&rsquo;s 1 is withdrawn.
On lenient recall Skeptic now ties the judge where it previously lost; what
survives is 12 deterministic hard-rule FAILs against its 0, an auditable
evidence trail, and a verdict that reproduces.</p>
<h2 id="changes-since-v011">Changes since v0.1.1</h2>
<p><code>skeptic doctor</code>, <code>skeptic verify --diff</code>, the report-only GitHub Action, arm
pressure knobs, holdout eval machinery, and <code>skeptic/checks/guards.py</code> (reads
preconditions a patch dropped; unproven as a detector and recorded as such).</p>
<p><code>pattern_introduced</code> moved 0.4 to 0.75 after H7 read 0 of 4 across three
independently authored sources, every instance scoring 0.65 against a 1.0
threshold off a rule that fired correctly. False positives did not move.</p>
<p>Fixed: candidate re-extraction dropped CR bytes on CRLF repos, so a patch no
longer applied to the tree it came from; arm snapshots now carry their own
candidate diff; <code>skeptic --version</code> reported 0.1.0 through the whole v0.1.1
release.</p>
<p><code>action.yml</code> is byte-identical to v0.1.1.</p>
<p>Full provenance in <code>DECISIONS.md</code> rows 225 to 229 and <code>docs/ai-log/</code>.</p>
]]></content:encoded></item><item><title>ZPL Regression Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/zpl-regression-gate/</link><pubDate>Sun, 23 Aug 2026 06:08:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/zpl-regression-gate/</guid><description>Version updated for https://github.com/Markloev/zpl-regression-gate to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ZPL Regression Gate is a GitHub Action that automates the detection of unintended changes in Zebra Programming Language (ZPL) label formats. It compares approved semantic and PNG baselines with current renderings to identify discrepancies, ensuring consistent and expected label outputs before they reach a warehouse or printer queue. The action provides actionable feedback on changed fields, barcodes, coordinates, font commands, dimensions, diagnostics, or rendered pixels, enabling developers to catch and fix issues early in the development cycle.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Markloev/zpl-regression-gate">https://github.com/Markloev/zpl-regression-gate</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zpl-regression-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ZPL Regression Gate is a GitHub Action that automates the detection of unintended changes in Zebra Programming Language (ZPL) label formats. It compares approved semantic and PNG baselines with current renderings to identify discrepancies, ensuring consistent and expected label outputs before they reach a warehouse or printer queue. The action provides actionable feedback on changed fields, barcodes, coordinates, font commands, dimensions, diagnostics, or rendered pixels, enabling developers to catch and fix issues early in the development cycle.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="passive-discovery-and-documentation">Passive discovery and documentation</h2>
<ul>
<li>Adds a complete guide for testing ZPL labels in GitHub Actions.</li>
<li>Shows a real semantic failure, current render, and red-pixel visual diff directly in the README.</li>
<li>Adds reproducible demo inputs and a structured example report.</li>
<li>Improves npm description and exact-intent keywords for ZPL and Zebra label testing.</li>
<li>Keeps the clean npm 12 installation introduced in v0.2.0.</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install --save-dev zpl-regression-gate@0.2.1
</span></span></code></pre></div>]]></content:encoded></item><item><title>Carabiner Repo Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/carabiner-repo-security/</link><pubDate>Sun, 23 Aug 2026 06:07:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/carabiner-repo-security/</guid><description>Version updated for https://github.com/MaXiMo000/carabiner to version v0.1.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
Carabiner automates the secure setup of repositories by default and continuously monitors for security vulnerabilities using various scanning tools. It solves common issues such as insecure CI/CD configurations, untrusted code execution, and missing security controls. Key capabilities include a ratchet mechanism to track accepted findings, a drill to verify control effectiveness, and a normalized model for reporting vulnerabilities. The action can be adopted by detecting, configuring, and ratcheting the repository once per repo, scanning for new issues, examining all engines and history, proving controls fire, listing informational findings, tracking accepted findings, and accepting them with an expiration date.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MaXiMo000/carabiner">https://github.com/MaXiMo000/carabiner</a></strong> to version <strong>v0.1.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/carabiner-repo-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>Carabiner automates the secure setup of repositories by default and continuously monitors for security vulnerabilities using various scanning tools. It solves common issues such as insecure CI/CD configurations, untrusted code execution, and missing security controls. Key capabilities include a ratchet mechanism to track accepted findings, a drill to verify control effectiveness, and a normalized model for reporting vulnerabilities. The action can be adopted by detecting, configuring, and ratcheting the repository once per repo, scanning for new issues, examining all engines and history, proving controls fire, listing informational findings, tracking accepted findings, and accepting them with an expiration date.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Make any repo secure by default, keep it that way, and prove the controls fire.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">MaXiMo000/carabiner@v0.1.14</span>
</span></span></code></pre></div><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install carabiner-sec        <span style="color:#75715e"># installs the `carabiner` command</span>
</span></span><span style="display:flex;"><span>docker run --rm -v <span style="color:#e6db74">&#34;</span>$PWD<span style="color:#e6db74">:/repo:ro&#34;</span> ghcr.io/maximo000/carabiner:0.1.14 scan --all
</span></span></code></pre></div><p>The Marketplace display name is now <strong>Carabiner Repo Security</strong> — GitHub requires an action name to be unique across every action, user and organisation. The repository, the <code>carabiner</code> command and the <code>carabiner-sec</code> package are unchanged.</p>
<h3 id="calibrated-against-60-public-repositories">Calibrated against 60 public repositories</h3>
<p>Tuned by scanning 60 real projects — tokio, grafana, vault, rails, next.js, home-assistant, airflow — across 13 languages, then re-checking every finding with an oracle written independently of the engines.</p>
<p>Default output is a <strong>median of 9 findings per repository</strong>; roughly 800 informational ones across the corpus are counted but not listed until <code>--info</code>. Hidden never means disappeared — the count always shows.</p>
<p>A version tag on an action is informational. A <strong>moving branch in someone else&rsquo;s repository</strong> is not. Classifying refs by shape rather than by a branch-name list also caught <code>stable</code>, <code>nightly</code> and <code>cargo-hack</code>. One unpinned reference is one finding, however many steps use it: tokio reaches <code>dtolnay/rust-toolchain@stable</code> 34 times in one workflow — one decision, not 34 lines.</p>
<p>tokio: 172 findings → 10. Corpus criticals: 31 → 2, and both survivors are real — a committed private key in grafana, and an unguarded <code>pull_request_target</code> + PR-head checkout in rollup.</p>
<h3 id="a-native-dockerfile-engine">A native Dockerfile engine</h3>
<p>Trivy scans a <em>built</em> image — daemon, build, minutes. A Dockerfile is text, and the worst mistakes are visible before anything is built.</p>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>DOCK001</code></td>
          <td>the final stage never drops root</td>
      </tr>
      <tr>
          <td><code>DOCK002</code></td>
          <td>untagged or <code>:latest</code> base image</td>
      </tr>
      <tr>
          <td><code>DOCK003</code></td>
          <td>a credential baked into <code>ARG</code>/<code>ENV</code>, readable with <code>docker history</code></td>
      </tr>
      <tr>
          <td><code>DOCK004</code></td>
          <td>a remote script piped straight into a shell at build time</td>
      </tr>
      <tr>
          <td><code>DOCK005</code></td>
          <td>TLS verification disabled during the build</td>
      </tr>
  </tbody>
</table>
<p>54 real issues across 19 of the 60 repositories — after spot-checking killed 33 of the rule&rsquo;s first 36 findings. <code>FROM builder</code> is a stage reference, <code>scratch</code> is a keyword, <code>${BASE_IMAGE}</code> is unknowable, and airflow embeds whole Python programs in BuildKit heredocs that were being parsed as instructions.</p>
<h3 id="findings-that-named-an-action-or-image-were-unreadable">Findings that named an action or image were unreadable</h3>
<p>The redactor treated <code>/</code>, <code>.</code> and <code>-</code> as token characters, so <code>dtolnay/rust-toolchain@stable</code> printed as <code>dtol...hain@stable</code>. A credential is a long <em>unbroken</em> run with no separators to split on — splitting on them keeps identifiers legible while still masking <code>ghp_…</code> and <code>AKIA…</code>.</p>
<h3 id="what-it-does">What it does</h3>
<p><strong>A ratchet.</strong> <code>carabiner init</code> accepts existing findings into a baseline, so CI goes green today and only <em>new</em> problems fail it. <code>--expires 90</code> puts a deadline on accepted debt.</p>
<p><strong>A drill.</strong> <code>carabiner drill</code> doesn&rsquo;t read config — it plants a private key and checks your hooks actually block it, then asks GitHub whether push protection is really on. A check that <em>could not run</em> never reports as passing.</p>
<p><strong>One normalized model</strong> → SARIF into the PR&rsquo;s Security tab, deduplicated across engines, most-severe-wins.</p>
<p><strong>52 tests, 193 checks</strong>, on Linux and Windows across Python 3.10 and 3.13, plus a Docker build, a wheel install into a clean venv, and carabiner scanning itself — every commit.</p>
]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Sun, 23 Aug 2026 06:06:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.9.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of a specified automated test suite in a ServiceNow instance using a service account or API Key. It simplifies testing by setting up necessary configurations and secrets, allowing users to easily run tests via a workflow template. The action supports various browser and OS combinations for running client tests, making it versatile for different environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of a specified automated test suite in a ServiceNow instance using a service account or API Key. It simplifies testing by setting up necessary configurations and secrets, allowing users to easily run tests via a workflow template. The action supports various browser and OS combinations for running client tests, making it versatile for different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.8...1.0.9">https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.8...1.0.9</a></p>
]]></content:encoded></item><item><title>Check macOS Release Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/check-macos-release-build/</link><pubDate>Sun, 23 Aug 2026 06:05:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/check-macos-release-build/</guid><description>Version updated for https://github.com/MobileDevOps/check-macos-release-build-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action check-macos-release-build-action verifies if a macOS .app or .dmg is a release build by checking its architecture, optimization, and distribution entitlements. It ensures the app is optimized for release, free of development server references, and without development entitlements. The action provides clear annotations and a summary table of the checks performed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MobileDevOps/check-macos-release-build-action">https://github.com/MobileDevOps/check-macos-release-build-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/check-macos-release-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>check-macos-release-build-action</code> verifies if a macOS <code>.app</code> or <code>.dmg</code> is a release build by checking its architecture, optimization, and distribution entitlements. It ensures the app is optimized for release, free of development server references, and without development entitlements. The action provides clear annotations and a summary table of the checks performed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.0.0 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="other-changes">Other Changes</h3>
<ul>
<li>chore(deps): Bump actions/checkout from 4 to 7 by @dependabot[bot] in <a href="https://github.com/MobileDevOps/check-macos-release-build-action/pull/1">https://github.com/MobileDevOps/check-macos-release-build-action/pull/1</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/MobileDevOps/check-macos-release-build-action/pull/1">https://github.com/MobileDevOps/check-macos-release-build-action/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/MobileDevOps/check-macos-release-build-action/compare/v1...v1.0.0">https://github.com/MobileDevOps/check-macos-release-build-action/compare/v1...v1.0.0</a></p>
]]></content:encoded></item><item><title>ZeroSMTP Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/zerosmtp-check/</link><pubDate>Sun, 23 Aug 2026 06:04:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/zerosmtp-check/</guid><description>Version updated for https://github.com/msgwing/ZeroSMTP to version v1.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of auditing and managing Microsoft 365 SMTP AUTH shutdown. It helps identify exposed mailboxes, checks compatibility of devices with OAuth firmware, provides a free relay for backward compatibility, offers code examples and deployment recipes across multiple languages, and includes documentation on error messages and migration strategies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msgwing/ZeroSMTP">https://github.com/msgwing/ZeroSMTP</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zerosmtp-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of auditing and managing Microsoft 365 SMTP AUTH shutdown. It helps identify exposed mailboxes, checks compatibility of devices with OAuth firmware, provides a free relay for backward compatibility, offers code examples and deployment recipes across multiple languages, and includes documentation on error messages and migration strategies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>ZeroSMTP Check is now a GitHub Action, and the CLI explains what an SMTP error means rather than only whether the port is open.</p>
<p><strong>The Action</strong> checks outbound SMTP from a runner and fails the job when the mail server&rsquo;s certificate is inside a window you set. Nobody watches a mail certificate; it expires on a Sunday and the first report is somebody saying scanning stopped working.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">msgwing/ZeroSMTP@v1.7.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">host</span>: <span style="color:#ae81ff">smtp.office365.com</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">cert-expiry-days</span>: <span style="color:#e6db74">&#39;14&#39;</span>
</span></span></code></pre></div><p><strong><code>--explain</code></strong> takes the refusal your own client printed - a Postfix SASL line, a Python traceback, <code>1102</code> off a Kyocera panel, or the <code>curl: (67) Login denied</code> that shows none of the server&rsquo;s answer at all. Fourteen error strings are covered, each with whether it can still be turned back on before the end of December 2026.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx zerosmtp-check --explain <span style="color:#e6db74">&#34;535 5.7.139 Authentication unsuccessful&#34;</span>
</span></span></code></pre></div><p>Port 25 is checked by default and goes first, because it is the one a provider is most likely to block.</p>
<p>Full notes in <a href="https://github.com/msgwing/ZeroSMTP/blob/main/CHANGELOG.md">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/odin-scan-smart-contract-security/</link><pubDate>Sun, 23 Aug 2026 06:03:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Odin Scan GitHub Action is an AI-powered security analysis tool that automatically scans CosmWasm, Solana, and EVM projects to detect vulnerabilities before they reach production. It integrates with GitHub workflows for real-time security checks on pull requests, providing inline annotations, PR comments, and SARIF uploads for native security alerts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Odin Scan GitHub Action is an AI-powered security analysis tool that automatically scans CosmWasm, Solana, and EVM projects to detect vulnerabilities before they reach production. It integrates with GitHub workflows for real-time security checks on pull requests, providing inline annotations, PR comments, and SARIF uploads for native security alerts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add comment-triggered PR scans (ac72e5f)</li>
<li>docs: expand findings-visibility section with threat model and annotation rationale (0404708)</li>
<li>feat: add findings-visibility input for graduated public disclosure control (f18df59)</li>
<li>fix: show findings detail in PR comment with fallback to medium (c2e43c8)</li>
<li>fix: new comment per run, show only critical/high findings, rebuild dist (e237b62)</li>
<li>feat: use GitHub App installation token for branded PR comments (3abce4e)</li>
<li>feat: enrich PR comment with emojis, descriptions, and fix report URL (27cc2f2)</li>
<li>fix: gzip SARIF before base64 encoding for Code Scanning upload (d9eed9f)</li>
<li>fix: include sourcemap-register.js in dist (bd265af)</li>
<li>docs: add privacy policy (b78db44)</li>
</ul>
]]></content:encoded></item><item><title>Harness Score</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/harness-score/</link><pubDate>Sun, 23 Aug 2026 06:01:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/harness-score/</guid><description>Version updated for https://github.com/paladini/harness-score to version v1.6.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Harness Score automates the assessment and improvement of AI coding harnesses across various tools, providing a maturity level, detailed breakdown of performance across six dimensions, and actionable recommendations for fixing issues. It ensures that AI agents are reliable by measuring their context files, rules, skills, hooks, sensors, and guardrails.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/paladini/harness-score">https://github.com/paladini/harness-score</a></strong> to version <strong>v1.6.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harness-score">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Harness Score automates the assessment and improvement of AI coding harnesses across various tools, providing a maturity level, detailed breakdown of performance across six dimensions, and actionable recommendations for fixing issues. It ensures that AI agents are reliable by measuring their context files, rules, skills, hooks, sensors, and guardrails.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixed">Fixed</h2>
<ul>
<li>Detect Google Cloud Build configurations under cloudbuild/<strong>/*.yml and cloudbuild/</strong>/*.yaml for CI-01, CI-02, and CI-03.</li>
<li>Preserve deterministic filesystem-based CI discovery and evidence reporting.</li>
<li>Document the detection across the English, Portuguese, Spanish, Chinese, and Hindi guides.</li>
</ul>
<h2 id="contributors">Contributors</h2>
<p>Thanks to <a href="https://github.com/gabrielcaiana">@gabrielcaiana</a> for reporting #53 and providing the reproducible Cloud Build pipeline.</p>
<p>This release resolves #53.</p>
]]></content:encoded></item><item><title>Minio clean upload</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/minio-clean-upload/</link><pubDate>Sun, 23 Aug 2026 06:00:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/minio-clean-upload/</guid><description>Version updated for https://github.com/PassiDel/minio-deploy-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses MinIO to deploy files to an object storage bucket. It automates the process of mirroring files from a local directory to MinIO, allowing developers to manage their assets in cloud-based object stores efficiently. The action supports configuring endpoints, access keys, secret keys, bucket names, and source/target directories, making it easy for users to automate deployment tasks within their workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PassiDel/minio-deploy-action">https://github.com/PassiDel/minio-deploy-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/minio-clean-upload">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses MinIO to deploy files to an object storage bucket. It automates the process of mirroring files from a local directory to MinIO, allowing developers to manage their assets in cloud-based object stores efficiently. The action supports configuring endpoints, access keys, secret keys, bucket names, and source/target directories, making it easy for users to automate deployment tasks within their workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/PassiDel/minio-deploy-action/compare/1.0.0...1.0.1">https://github.com/PassiDel/minio-deploy-action/compare/1.0.0...1.0.1</a></p>
]]></content:encoded></item><item><title>hypothesisctl decision gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/hypothesisctl-decision-gate/</link><pubDate>Sun, 23 Aug 2026 06:00:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/hypothesisctl-decision-gate/</guid><description>Version updated for https://github.com/Pipeliner/hypothesisctl to version v0.2.1.
This action is used across all versions by ? repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary The hypothesisctl GitHub Action automates the validation of experimental hypotheses by ensuring that evidence is complete before declaring an experiment validated. It helps prevent premature AI agent decisions or release processes by providing detailed decision-making based on gating criteria and evidence status. The action allows users to check, evaluate, and validate hypothesis records using predefined policies, making it easier for CI workflows to make informed decisions about experimental outcomes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Pipeliner/hypothesisctl">https://github.com/Pipeliner/hypothesisctl</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<p>Go to the <a href="https://github.com/marketplace/actions/hypothesisctl-decision-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>hypothesisctl</code> GitHub Action automates the validation of experimental hypotheses by ensuring that evidence is complete before declaring an experiment validated. It helps prevent premature AI agent decisions or release processes by providing detailed decision-making based on gating criteria and evidence status. The action allows users to check, evaluate, and validate hypothesis records using predefined policies, making it easier for CI workflows to make informed decisions about experimental outcomes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Security release: prevents checkout package shadowing in the composite Action; adds strict agent-completion evidence fixtures; and introduces an isolated, OIDC-based PyPI publisher with immutable Action pins and a hash-pinned build backend. See CHANGELOG.md for the full release notes.</p>
]]></content:encoded></item><item><title>OpenTelemetry for GitHub Workflows, Jobs and Steps</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/opentelemetry-for-github-workflows-jobs-and-steps/</link><pubDate>Sun, 23 Aug 2026 05:58:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/opentelemetry-for-github-workflows-jobs-and-steps/</guid><description>Version updated for https://github.com/plengauer/Thoth to version v5.61.2.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the collection of OpenTelemetry traces, metrics, and logs from shell scripts and GitHub workflows. It provides automatic context propagation through HTTP requests, auto-instrumentation of common commands, injection into child processes, executables with shebangs, and job-level instrumentation in GitHub actions. The project is designed to simplify observability for both development and CI/CD environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plengauer/Thoth">https://github.com/plengauer/Thoth</a></strong> to version <strong>v5.61.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>14</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/opentelemetry-for-github-workflows-jobs-and-steps">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the collection of OpenTelemetry traces, metrics, and logs from shell scripts and GitHub workflows. It provides automatic context propagation through HTTP requests, auto-instrumentation of common commands, injection into child processes, executables with shebangs, and job-level instrumentation in GitHub actions. The project is designed to simplify observability for both development and CI/CD environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: detect all redirection-only <code>exec</code> forms in <code>_otel_inject_and_exec_by_location</code> (#4088) by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/4090">https://github.com/plengauer/Thoth/pull/4090</a></li>
<li>Automatic Version Bump by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/4093">https://github.com/plengauer/Thoth/pull/4093</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/plengauer/Thoth/compare/v5.61.1...v5.61.2">https://github.com/plengauer/Thoth/compare/v5.61.1...v5.61.2</a></p>
]]></content:encoded></item><item><title>Setup sysroot environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/setup-sysroot-environment/</link><pubDate>Sun, 23 Aug 2026 05:57:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/setup-sysroot-environment/</guid><description>Version updated for https://github.com/psyGamer/setup-sysroot to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up a precompiled system root for cross-compiling or targeting alternative C libraries. It automates the process of preparing a set of tools and dependencies, allowing developers to compile software for different architectures or use alternative C libraries without installing them from scratch on their host systems. The action provides support for various Debian-based toolchains across different versions and architectures.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/psyGamer/setup-sysroot">https://github.com/psyGamer/setup-sysroot</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-sysroot-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up a precompiled system root for cross-compiling or targeting alternative C libraries. It automates the process of preparing a set of tools and dependencies, allowing developers to compile software for different architectures or use alternative C libraries without installing them from scratch on their host systems. The action provides support for various Debian-based toolchains across different versions and architectures.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/psyGamer/setup-sysroot/commits/v1.0.0">https://github.com/psyGamer/setup-sysroot/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>PyGo CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/pygo-cli/</link><pubDate>Sun, 23 Aug 2026 05:57:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/pygo-cli/</guid><description>Version updated for https://github.com/PyGo-Labs/pygo-framework to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PyGo Framework is a Go + Python monolithic architecture that uses DSL code generation to define models, handlers, and routes. It supports various data types such as UUIDs, emails, datetimes, URLs, phone numbers, decimals, optional values, arrays, maps, enums with numeric or string values, and automatic ForeignKey JOINs for database relationships. The action automates the process of defining and generating code based on a DSL file, simplifying development workflows by reducing boilerplate and increasing maintainability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PyGo-Labs/pygo-framework">https://github.com/PyGo-Labs/pygo-framework</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pygo-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PyGo Framework is a Go + Python monolithic architecture that uses DSL code generation to define models, handlers, and routes. It supports various data types such as UUIDs, emails, datetimes, URLs, phone numbers, decimals, optional values, arrays, maps, enums with numeric or string values, and automatic ForeignKey JOINs for database relationships. The action automates the process of defining and generating code based on a DSL file, simplifying development workflows by reducing boilerplate and increasing maintainability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix(cli): module install now extracts archives and registers in pygo.toml (17635c8)</li>
<li>fix(web): no filtrar token, solo _path/_method (a0d91f9)</li>
<li>fix(web): filtrar _path/_method como parametros internos (7075ff7)</li>
<li>fix(web): servir HTML sin envolver en JSON + recover por handler (c59353d)</li>
<li>feat: Installation system + GitHub Actions release pipeline (f42d57b)</li>
<li>fix(web): Router multi-method dispatch + hot-reload CLI (ecf0e1c)</li>
<li>fix(web): Router multi-method dispatch + CRUD endpoints for pgerp (14b54ff)</li>
<li>refactor: Native dual-language example + CLI hot-reload (8669130)</li>
<li>fix(bridge): Prevent Python subprocess death — store cancellable context (f5ed516)</li>
<li>refactor: Eliminate DSL entirely — native Go+Python dual architecture (92fde4a)</li>
</ul>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/raviqqe/muffy/</link><pubDate>Sun, 23 Aug 2026 05:55:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.5.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Muffy GitHub Action is a static website validator that automates the recursive link checking, markup validation, and checks multiple websites with a single configuration file. It provides persistent response caching for improved performance and includes features such as concurrency and rate limits, retries with exponential backoff, and support for robots.txt and sitemap files. The action can be used to ensure that all links and documents on a website are valid, reducing the risk of broken links or invalid content.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.5.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Muffy GitHub Action is a static website validator that automates the recursive link checking, markup validation, and checks multiple websites with a single configuration file. It provides persistent response caching for improved performance and includes features such as concurrency and rate limits, retries with exponential backoff, and support for <code>robots.txt</code> and sitemap files. The action can be used to ensure that all links and documents on a website are valid, reducing the risk of broken links or invalid content.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>b8de4108072f91b2af6fe447bcaed71fb05243a3 Bump version (#1293)</li>
<li>62018fabe9e9fdbd96da93ea918a87831b6149a7 Explicit data schema errors (#1292)</li>
<li>80383978f052bfeba2f455ae66d1e3d9cc81f1bf Data value schema (#1277)</li>
</ul>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/custom-amazon-bedrock-agent-action/</link><pubDate>Sun, 23 Aug 2026 05:55:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provide detailed feedback. It integrates seamlessly with AWS Bedrock Knowledge Bases for more accurate insights, enhancing its ability to address specific organizational or domain-specific needs. The action is customizable, allowing you to tailor prompts and use cases, making it suitable for code quality improvement, security assessments, and performance optimizations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provide detailed feedback. It integrates seamlessly with AWS Bedrock Knowledge Bases for more accurate insights, enhancing its ability to address specific organizational or domain-specific needs. The action is customizable, allowing you to tailor prompts and use cases, making it suitable for code quality improvement, security assessments, and performance optimizations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/sherpa.sh/</link><pubDate>Sun, 23 Aug 2026 05:54:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven tool that automates cloud infrastructure deployment based on natural language descriptions. It helps developers easily configure and manage environments without needing to write complex YAML files or DevOps expertise, making it accessible across various clouds and frameworks. The action supports deploying applications like Next.js to AWS Lambda and Cloudflare while also providing options for custom domains, load balancers, CDN configurations, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven tool that automates cloud infrastructure deployment based on natural language descriptions. It helps developers easily configure and manage environments without needing to write complex YAML files or DevOps expertise, making it accessible across various clouds and frameworks. The action supports deploying applications like Next.js to AWS Lambda and Cloudflare while also providing options for custom domains, load balancers, CDN configurations, and more.</p>
]]></content:encoded></item><item><title>agent-trace eval</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/agent-trace-eval/</link><pubDate>Sun, 23 Aug 2026 05:53:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/agent-trace-eval/</guid><description>Version updated for https://github.com/Siddhant-K-code/agent-trace to version v0.94.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary agent-trace is a tool that captures and inspects the actions of AI agents, providing insights into file operations, tool calls, decision points, error recovery, and commands executed. It helps automate debugging by replaying sessions and exporting data to various observability platforms like Datadog, Honeycomb, New Relic, or Splunk. The action is experimental and requires careful consideration before use in production environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Siddhant-K-code/agent-trace">https://github.com/Siddhant-K-code/agent-trace</a></strong> to version <strong>v0.94.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-trace-eval">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>agent-trace</code> is a tool that captures and inspects the actions of AI agents, providing insights into file operations, tool calls, decision points, error recovery, and commands executed. It helps automate debugging by replaying sessions and exporting data to various observability platforms like Datadog, Honeycomb, New Relic, or Splunk. The action is experimental and requires careful consideration before use in production environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: store plugin traces in payload workspace (#254)</li>
</ul>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/bernstein-multi-agent-orchestration/</link><pubDate>Sun, 23 Aug 2026 05:52:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.17.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is a deterministic multi-agent CLI orchestration tool that automates complex workflows and tasks, ensuring reproducibility across different environments. It simplifies the management of multiple agents in distributed systems and helps developers achieve consistent results by defining clear plans and policies for task execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.17.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein is a deterministic multi-agent CLI orchestration tool that automates complex workflows and tasks, ensuring reproducibility across different environments. It simplifies the management of multiple agents in distributed systems and helps developers achieve consistent results by defining clear plans and policies for task execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A patch release about one thing: a container run that starts from an issue number and is still alive an hour later.</p>
<h2 id="agents-stopped-dying">Agents stopped dying</h2>
<p>The heartbeat was refreshed by a shell loop pasted into the agent&rsquo;s own prompt. A model that ignored the block was killed for ignoring it. The worker writes it now, where the orchestrator reads it (#4330).</p>
<p>Four subsystems read that number. The recycler and the escalation ladder disagreed about the same agent, and the harsher one won (#4314). The stalled-manager detector went by wall-clock runtime alone, ignoring the liveness verdict from the same tick (#4338).</p>
<p>A dead agent&rsquo;s uncommitted work survives: the orphan path built a request body <code>httpx</code> could not encode, and the error killed the tick before the commit ran (#4345).</p>
<h2 id="runs-recover-on-their-own">Runs recover on their own</h2>
<p>A run with a high error rate blocked every new spawn wave, which is also how it stayed at a high error rate; the gate waits for three observations now (#4336). Agent process deaths counted as task failures (#4310). A failed planning task&rsquo;s retry raced a sibling that had already done the same decomposition (#4309).</p>
<h2 id="the-gate-graded-the-wrong-tree">The gate graded the wrong tree</h2>
<p>Agents commit in their own worktree, and the merge back waits for the gate — so the gate graded a checkout missing the work under review. A task whose acceptance signal named a file it had just written could never pass. It had done this for as long as the gate has existed. The verdict is computed on the merged result now (#4367).</p>
<h2 id="the-task-graph">The task graph</h2>
<p>An inferred file-overlap edge could contradict an explicit <code>depends_on</code> and fabricate a two-node cycle, after which <code>topological_order</code> returned nothing and every task read as blocked (#4366). A declared cycle no longer wedges the scheduler either (#4299).</p>
<h2 id="postgresql">PostgreSQL</h2>
<p>Five bugs, all in the code that claims a task: two ignored the claiming role, one raised on a parameter the store did not accept, one queried a tenant column the schema never created, and <code>create()</code> raised <code>ImportError</code> (#4323, #4325, #4328, #4332, #4333).</p>
<p><strong>Upgrade note:</strong> tasks written before this release carry no recorded tenant and land in the default scope; on a multi-tenant install the original scope is not recoverable.</p>
<h2 id="models-and-transport">Models and transport</h2>
<p>Retry escalation replaced the model an operator pinned with a hard-coded Claude tier name (#4274). A <code>model:</code> in <code>bernstein.yaml</code> or <code>--model</code> now suppresses model escalation on retry; effort still escalates. An agent that exits without spending a token no longer spends the retry budget (#4275).</p>
<p>The MCP bridge pointed at a module with no <code>__main__</code> guard: it imported, exited 0, and never answered the handshake. Every agent reported the bridge as disconnected and nobody read the init event (#4313, #4315).</p>
<h2 id="also">Also</h2>
<p>The manager prompt never showed how to set <code>depends_on</code>, so QA started before the module it tested existed (#4311). The PR a run opens no longer describes a run it cannot find (#4349). Adapters declare which channel carries <code>system_addendum</code> (#4256). On a TTY, <code>bernstein run</code> says it is waiting for the first agent (#4257).</p>
<p>Soundtrack: <a href="https://suno.com/s/sQ51WglS4Qzj9eIN">https://suno.com/s/sQ51WglS4Qzj9eIN</a></p>
<hr>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(core): publish SSE task_update events for tasks stranded by dependency cascade (#4259) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4264">https://github.com/sipyourdrink-ltd/bernstein/pull/4264</a></li>
<li>feat(agents-md): compact subsystem index; full per-file map moves to docs/sdd/module-map.md by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4268">https://github.com/sipyourdrink-ltd/bernstein/pull/4268</a></li>
<li>fix(cli): narrate the first-agent wait on TTY runs by @lesbass in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4261">https://github.com/sipyourdrink-ltd/bernstein/pull/4261</a></li>
<li>chore(ci): ratchet coverage baseline up to 84.02% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4266">https://github.com/sipyourdrink-ltd/bernstein/pull/4266</a></li>
<li>Refactor: Consolidate _VERSION_TOKEN_RE by @AbishekCoder1 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4167">https://github.com/sipyourdrink-ltd/bernstein/pull/4167</a></li>
<li>Fix/trunk health slo sampling by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4249">https://github.com/sipyourdrink-ltd/bernstein/pull/4249</a></li>
<li>chore(deps): update dependency charset-normalizer to v3.5.1 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4284">https://github.com/sipyourdrink-ltd/bernstein/pull/4284</a></li>
<li>docs: regenerate adapter last-green table from canary receipts by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4278">https://github.com/sipyourdrink-ltd/bernstein/pull/4278</a></li>
<li>feat(volunteer): add PR submission with pacing and DCO sign-off by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4279">https://github.com/sipyourdrink-ltd/bernstein/pull/4279</a></li>
<li>chore(deps): update step-security/harden-runner action to v2.21.0 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4280">https://github.com/sipyourdrink-ltd/bernstein/pull/4280</a></li>
<li>feat(volunteer): add browse command for index discovery by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4273">https://github.com/sipyourdrink-ltd/bernstein/pull/4273</a></li>
<li>chore(deps): update dependency astral-sh/uv to v0.12.5 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4276">https://github.com/sipyourdrink-ltd/bernstein/pull/4276</a></li>
<li>chore(deps): update dependency python to 3.13 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4272">https://github.com/sipyourdrink-ltd/bernstein/pull/4272</a></li>
<li>chore(deps): update reviewdog/action-actionlint digest to dbe5299 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4271">https://github.com/sipyourdrink-ltd/bernstein/pull/4271</a></li>
<li>chore(deps): update trufflesecurity/trufflehog action to v3.97.0 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4277">https://github.com/sipyourdrink-ltd/bernstein/pull/4277</a></li>
<li>feat(adapters): add a session_state axis to AdapterStrategy by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4308">https://github.com/sipyourdrink-ltd/bernstein/pull/4308</a></li>
<li>fix(observability): keep a failed target&rsquo;s metric lines for the next flush by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4316">https://github.com/sipyourdrink-ltd/bernstein/pull/4316</a></li>
<li>fix(mcp): point the MCP bridge spec at a runnable entrypoint by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4317">https://github.com/sipyourdrink-ltd/bernstein/pull/4317</a></li>
<li>feat(agents): classify a zero-token fast clean exit as a transport failure by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4318">https://github.com/sipyourdrink-ltd/bernstein/pull/4318</a></li>
<li>fix(planning): unify the dependency-satisfaction rule across both schedulers by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4322">https://github.com/sipyourdrink-ltd/bernstein/pull/4322</a></li>
<li>feat(planning): record retry exhaustion as a distinct stranding cause by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4312">https://github.com/sipyourdrink-ltd/bernstein/pull/4312</a></li>
<li>fix(store): role-gate claim_batch on the PostgreSQL backend by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4324">https://github.com/sipyourdrink-ltd/bernstein/pull/4324</a></li>
<li>fix(agents): idle recycler defers to heartbeat_escalation&rsquo;s liveness signal by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4319">https://github.com/sipyourdrink-ltd/bernstein/pull/4319</a></li>
<li>fix(observability): derive error-budget counts from task-board state by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4321">https://github.com/sipyourdrink-ltd/bernstein/pull/4321</a></li>
<li>fix(mcp): make the repo-root bridge declaration runnable by any client by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4335">https://github.com/sipyourdrink-ltd/bernstein/pull/4335</a></li>
<li>feat(volunteer): add gitea rig compose + seed + assert by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4283">https://github.com/sipyourdrink-ltd/bernstein/pull/4283</a></li>
<li>fix(tasks): cancel planning-task retries that race a completed sibling by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4326">https://github.com/sipyourdrink-ltd/bernstein/pull/4326</a></li>
<li>chore(tests): drop an unused import that fails the pre-push lint by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4341">https://github.com/sipyourdrink-ltd/bernstein/pull/4341</a></li>
<li>fix(agents): worker refreshes the heartbeat the orchestrator reads by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4339">https://github.com/sipyourdrink-ltd/bernstein/pull/4339</a></li>
<li>fix(orchestrator): manager sets depends_on, all claim paths honor it by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4320">https://github.com/sipyourdrink-ltd/bernstein/pull/4320</a></li>
<li>feat(security): add ensure_public_http_url for third-party-derived URLs by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4307">https://github.com/sipyourdrink-ltd/bernstein/pull/4307</a></li>
<li>fix(orchestration): stop orphan handling from crashing the tick by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4346">https://github.com/sipyourdrink-ltd/bernstein/pull/4346</a></li>
<li>fix(orchestrator): convergence guard stops blocking at zero active agents by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4342">https://github.com/sipyourdrink-ltd/bernstein/pull/4342</a></li>
<li>fix(docker): run the volunteer rig seeder as a non-root user by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4352">https://github.com/sipyourdrink-ltd/bernstein/pull/4352</a></li>
<li>docs(contributing): document the route for contributors who cannot open a PR by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4355">https://github.com/sipyourdrink-ltd/bernstein/pull/4355</a></li>
<li>feat(cli): add <code>pr --issue</code> to title and link the PR from its issue by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4354">https://github.com/sipyourdrink-ltd/bernstein/pull/4354</a></li>
<li>feat(cli): add <code>run --wait</code> to block for a run&rsquo;s outcome by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4351">https://github.com/sipyourdrink-ltd/bernstein/pull/4351</a></li>
<li>fix(store): role-gate claim_by_id on the PostgreSQL backend by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4327">https://github.com/sipyourdrink-ltd/bernstein/pull/4327</a></li>
<li>docs(release-notes): add the entries six merged fixes shipped without by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4359">https://github.com/sipyourdrink-ltd/bernstein/pull/4359</a></li>
<li>fix(orchestrator): give the error-rate gate a minimum sample floor by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4362">https://github.com/sipyourdrink-ltd/bernstein/pull/4362</a></li>
<li>chore(deps): update dependency webencodings to v0.6.1 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4329">https://github.com/sipyourdrink-ltd/bernstein/pull/4329</a></li>
<li>fix(mypy): fix call-overload and no-any-return in core/cost by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4356">https://github.com/sipyourdrink-ltd/bernstein/pull/4356</a></li>
<li>Fix/mypy persistence by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4358">https://github.com/sipyourdrink-ltd/bernstein/pull/4358</a></li>
<li>fix(git): narrow transient push marker to avoid matching credential errors by @blut-agent in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4343">https://github.com/sipyourdrink-ltd/bernstein/pull/4343</a></li>
<li>fix(adapters): forward OPENAI_BASE_URL through the Cline adapter env by @Rehan30g in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4365">https://github.com/sipyourdrink-ltd/bernstein/pull/4365</a></li>
<li>chore(deps): update python docker tag to v3.13 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4348">https://github.com/sipyourdrink-ltd/bernstein/pull/4348</a></li>
<li>chore(deps): update gitea/gitea docker tag to v1.27 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4347">https://github.com/sipyourdrink-ltd/bernstein/pull/4347</a></li>
<li>fix(orchestrator): evaluate the quality gate on the merged tree by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4368">https://github.com/sipyourdrink-ltd/bernstein/pull/4368</a></li>
<li>fix(task-graph): stop inferred edges forming cycles, unwedge cyclic boards by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4369">https://github.com/sipyourdrink-ltd/bernstein/pull/4369</a></li>
<li>feat(quality): add inconclusive gate verdict with closed reason codes by @Louis20060723 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4282">https://github.com/sipyourdrink-ltd/bernstein/pull/4282</a></li>
<li>fix(pr): resolve a run&rsquo;s goal, identity and merged work for its PR by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4370">https://github.com/sipyourdrink-ltd/bernstein/pull/4370</a></li>
<li>fix(retry): keep the operator&rsquo;s model and stop charging zero-token exits by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4373">https://github.com/sipyourdrink-ltd/bernstein/pull/4373</a></li>
<li>fix: gate the stall verdict on liveness and declare system_addendum delivery by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4372">https://github.com/sipyourdrink-ltd/bernstein/pull/4372</a></li>
<li>test: stop git background maintenance racing helpers that delete .git by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4374">https://github.com/sipyourdrink-ltd/bernstein/pull/4374</a></li>
<li>release: v3.17.1 by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4375">https://github.com/sipyourdrink-ltd/bernstein/pull/4375</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@lesbass made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4261">https://github.com/sipyourdrink-ltd/bernstein/pull/4261</a></li>
<li>@AbishekCoder1 made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4167">https://github.com/sipyourdrink-ltd/bernstein/pull/4167</a></li>
<li>@blut-agent made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4343">https://github.com/sipyourdrink-ltd/bernstein/pull/4343</a></li>
<li>@Rehan30g made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4365">https://github.com/sipyourdrink-ltd/bernstein/pull/4365</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sipyourdrink-ltd/bernstein/compare/v3.17.0...v3.17.1">https://github.com/sipyourdrink-ltd/bernstein/compare/v3.17.0...v3.17.1</a></p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/smyklot/</link><pubDate>Sun, 23 Aug 2026 05:50:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.45.6.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the .github/CODEOWNERS file. It supports multiple command formats, including slash commands, mentions, and bare commands, allowing users to approve or merge PRs with reactions or comments. The app handles command deduplication, provides emoji feedback, and can run as a GitHub Action or webhook service for all repositories installed on the App.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.45.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the <code>.github/CODEOWNERS</code> file. It supports multiple command formats, including slash commands, mentions, and bare commands, allowing users to approve or merge PRs with reactions or comments. The app handles command deduplication, provides emoji feedback, and can run as a GitHub Action or webhook service for all repositories installed on the App.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1456-2026-08-22"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.45.5...v1.45.6">1.45.6</a> (2026-08-22)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>panel:</strong> repair production status boundaries (<a href="https://github.com/smykla-skalski/smyklot/issues/304">#304</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/34b02d7deec420c766c7d102942cc239c4770aa3">34b02d7</a>)</li>
</ul>
<h2 id="smyklot-v1456">Smyklot v1.45.6</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.45.6</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>2619f417e99d9e1461166e35376b04ef2f2a04f2 chore(release): bump version to 1.45.6</li>
<li>34b02d7deec420c766c7d102942cc239c4770aa3 fix(panel): repair production status boundaries (#304)</li>
</ul>
]]></content:encoded></item><item><title>vibestats</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/vibestats/</link><pubDate>Sun, 23 Aug 2026 05:49:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/vibestats/</guid><description>Version updated for https://github.com/stephenleo/vibestats to version v2.4.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary VibeStats is a GitHub Action that tracks Claude Code and Codex sessions, providing a heatmap on your GitHub profile and a full analytics dashboard at vibestats.dev/&amp;lt;your-username&amp;gt;. It syncs daily stats to a private GitHub repo before cleanup, allowing you to keep long-term usage history and maintain privacy.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stephenleo/vibestats">https://github.com/stephenleo/vibestats</a></strong> to version <strong>v2.4.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibestats">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>VibeStats is a GitHub Action that tracks Claude Code and Codex sessions, providing a heatmap on your GitHub profile and a full analytics dashboard at <code>vibestats.dev/&lt;your-username&gt;</code>. It syncs daily stats to a private GitHub repo before cleanup, allowing you to keep long-term usage history and maintain privacy.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What’s changed</h2>
<ul>
<li>Added <code>--skip-hook-configuration</code> to the macOS/Linux installer for manual-only sync setup (<code>-SkipHookConfiguration</code> on Windows).</li>
<li>Added a daily model token usage chart to the dashboard.</li>
<li>Strengthened public site trust signals and removed conflicting dashboard redirects.</li>
</ul>
]]></content:encoded></item><item><title>Agent Vigil</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/agent-vigil/</link><pubDate>Sun, 23 Aug 2026 05:48:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/agent-vigil/</guid><description>Version updated for https://github.com/sulmusic2-star/agent-vigil to version v0.12.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Vigil is a tool that automates code change verification by checking an exact code change against task, policy, tests, and recorded tool actions behind it. It returns PASS, FAIL, or INCONCLUSIVE based on the presence of evidence before merging. The verifier runs locally or in GitHub runners without using another model to judge work.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sulmusic2-star/agent-vigil">https://github.com/sulmusic2-star/agent-vigil</a></strong> to version <strong>v0.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-vigil">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Vigil is a tool that automates code change verification by checking an exact code change against task, policy, tests, and recorded tool actions behind it. It returns PASS, FAIL, or INCONCLUSIVE based on the presence of evidence before merging. The verifier runs locally or in GitHub runners without using another model to judge work.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Agent Vigil v0.12.0 removes the ceremonial human-review checkbox from the default maintainer gate and replaces it with repeatable evidence.</p>
<h3 id="automated-review">Automated review</h3>
<ul>
<li><code>reviewMode: &quot;automated&quot;</code> runs commands selected by policy from the pull request base commit.</li>
<li>Commands run in a detached checkout of the exact candidate SHA.</li>
<li>A nonzero exit, timeout, <code>HEAD</code> movement, or tracked-file mutation blocks approval.</li>
<li>New maintainer installations no longer ask anyone to claim they reviewed or understand every line.</li>
<li><code>reviewMode: &quot;human&quot;</code> remains available for organizations whose own governance requires named declarations.</li>
</ul>
<h3 id="signed-receipts">Signed receipts</h3>
<ul>
<li>Optional GitHub/Sigstore attestations bind the receipt file, PASS/FAIL/INCONCLUSIVE decision, base and head commits, Git tree, policy digest, verifier version, and evidence counts.</li>
<li><code>vigil verify-attestation</code> verifies the GitHub signature and the signed receipt fields.</li>
<li><code>vigil notary</code> prepares a fail-closed check result for a future GitHub App.</li>
</ul>
<h3 id="public-release-gate">Public release gate</h3>
<ul>
<li><code>npm run review:public</code> now checks first-screen clarity, action labels, public count consistency, links, accessibility labels, reading measure, and recurring template defaults.</li>
<li>Agent Vigil itself passed the new automated review with 7/7 isolated commands and no human-attestation rules in PR #33.</li>
</ul>
<p>See <code>RELEASE-EVIDENCE.txt</code> and <code>SHA256SUMS</code> for the exact commit and executed proof. Automated evidence is not a claim of human understanding, external adoption, customers, or revenue.</p>
]]></content:encoded></item><item><title>ArchGuard - Architectural Drift Detector</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/archguard-architectural-drift-detector/</link><pubDate>Sun, 23 Aug 2026 05:47:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/archguard-architectural-drift-detector/</guid><description>Version updated for https://github.com/Tgenz1213/ArchGuard to version v1.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ArchGuard is a tool that uses LLMs to verify code changes against established Architectural Decision Records (ADRs), preventing “architectural drift.” It alerts developers before merging changes that violate ADR rules. The action helps maintain project architecture by enforcing compliance with documented design decisions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tgenz1213/ArchGuard">https://github.com/Tgenz1213/ArchGuard</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/archguard-architectural-drift-detector">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ArchGuard is a tool that uses LLMs to verify code changes against established Architectural Decision Records (ADRs), preventing &ldquo;architectural drift.&rdquo; It alerts developers before merging changes that violate ADR rules. The action helps maintain project architecture by enforcing compliance with documented design decisions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>694ad5356ffb26c4f9ba381bfe84eaf3364951c4 build(deps): bump github.com/moby/go-archive from 0.2.0 to 0.3.0 (#79)</li>
<li>a3538ccd2029867025e968860240a73858e0be92 build(deps): bump the go-dependencies group with 4 updates (#78)</li>
<li>e1caba23129b6ffb9a7e5a9b07dfeed0b1a1fa1b build(deps): bump the go-dependencies group with 5 updates (#76)</li>
<li>45e22c16be338c184b33bf61a73aa122176fb3ba build(deps): group Dependabot minor/patch updates into a single PR per ecosystem (#66)</li>
<li>7849dfae20d87c11274a38877c096a6428ba918d build(deps): pin pgvector extension version in docker-compose.yml and tests (#67)</li>
<li>9194ea8e549da979b6101ec6efbdcad1293177cb feat: add baseline mode to grandfather pre-existing violations (#68) (#77)</li>
<li>3573cc13fd8d31a9ed55082df07fdec6b4dbf248 fix: normalize positional-arg path separators unconditionally in cli.Execute (#100)</li>
<li>e91ad8c30e0b5ed37e74ba009387332e4a415916 fix: persist and return ADR ID/scope from PgStore (#93)</li>
<li>d39fac5102cd6ce6935d51cccafd7aefd9084dbe fix: print baseline success message only after the file is actually saved (#106)</li>
<li>71286061038d8c053d2964a8b0e996b6d6819388 fix: report skipped-file count in &ndash;update-baseline summary (#103)</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/wails3-build-action/</link><pubDate>Sun, 23 Aug 2026 05:46:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action ToQuery/wails3-build-action@v3 automates the building and packaging of Wails.io projects using GoLang, NodeJS, pnpm, or Deno. It supports building for different platforms and optionally uploads the results to GitHub and releases on tagged builds. The action is configured with various options such as go version, wails version, build name, and more, allowing users to customize the build process according to their project requirements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>ToQuery/wails3-build-action@v3</code> automates the building and packaging of Wails.io projects using GoLang, NodeJS, pnpm, or Deno. It supports building for different platforms and optionally uploads the results to GitHub and releases on tagged builds. The action is configured with various options such as go version, wails version, build name, and more, allowing users to customize the build process according to their project requirements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>Lachesis Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/lachesis-security-scan/</link><pubDate>Sun, 23 Aug 2026 05:45:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/lachesis-security-scan/</guid><description>Version updated for https://github.com/UnboundCompute/lachesis-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Lachesis is a GitHub Action that analyzes your codebase to identify potential security vulnerabilities, specifically focusing on missing authorization checks. It builds a code property graph of your repository and traces untrusted input to dangerous sinks, posting findings as inline comments with severity levels such as error or note. The action runs entirely locally using your runner and can be integrated into workflows to automatically scan pull requests for security issues.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/UnboundCompute/lachesis-action">https://github.com/UnboundCompute/lachesis-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lachesis-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Lachesis is a GitHub Action that analyzes your codebase to identify potential security vulnerabilities, specifically focusing on missing authorization checks. It builds a code property graph of your repository and traces untrusted input to dangerous sinks, posting findings as inline comments with severity levels such as <code>error</code> or <code>note</code>. The action runs entirely locally using your runner and can be integrated into workflows to automatically scan pull requests for security issues.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>De-duplicate inline comments: when one sink is reached by several distinct taint witnesses, the finding is posted once per <code>(rule, file, line)</code> instead of once per witness path, so <strong>Lachesis[bot]</strong> no longer stacks identical comments on a line.</p>
]]></content:encoded></item><item><title>Diffly PR triage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/diffly-pr-triage/</link><pubDate>Sun, 23 Aug 2026 05:44:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/diffly-pr-triage/</guid><description>Version updated for https://github.com/VIVAAN-DHAWAN/diffly-cli to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
The diffly GitHub Action automates the review of large AI-generated pull requests by providing a comprehensive one-page Markdown report. It parses file changes with Tree-sitter to identify symbols modified, tests affected, and dependencies updated. The action also maps blast radiuses, identifies risk flags such as security vulnerabilities and missing test coverage, and provides a PASS, QUARANTINE, or BLOCK verdict based on predefined rules.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VIVAAN-DHAWAN/diffly-cli">https://github.com/VIVAAN-DHAWAN/diffly-cli</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/diffly-pr-triage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>The <code>diffly</code> GitHub Action automates the review of large AI-generated pull requests by providing a comprehensive one-page Markdown report. It parses file changes with Tree-sitter to identify symbols modified, tests affected, and dependencies updated. The action also maps blast radiuses, identifies risk flags such as security vulnerabilities and missing test coverage, and provides a PASS, QUARANTINE, or BLOCK verdict based on predefined rules.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="diffly-cli-v100">Diffly CLI v1.0.0</h1>
<p>Diffly CLI 1.0.0 is the first production-ready release of deterministic pull-request triage. It turns pull-request evidence—changed files, symbols, direct callers, tests, checks, and risk signals—into a clear review decision without making the verdict depend on an LLM.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Verdicts that match the evidence.</strong> <code>PASS</code> is now the normal result for healthy pull requests. <code>QUARANTINE</code> is reserved for concrete review gates such as security-sensitive code, database schema or migration changes, dependency changes, or pending checks. <code>BLOCK</code> is reserved for failed required checks and high-confidence credential exposure.</li>
<li><strong>Reliable explanations.</strong> When you opt in, Diffly always includes an explanation in the review: a bounded, redacted AI narrative when a provider is configured, or a clearly labelled local explanation when it is not. Explanations never alter the deterministic verdict.</li>
<li><strong>A focused terminal workflow.</strong> The guided wizard, loading transition, keyboard-driven review, and report output have been redesigned for a centred, readable terminal experience with clearer prompts and recovery messages.</li>
<li><strong>Works where you work.</strong> Review GitHub pull requests, analyze local changes offline, consume stable JSON in CI, or use the bundled GitHub Action. Diffly also reuses your authenticated GitHub CLI session when available.</li>
</ul>
<h2 id="upgrade">Upgrade</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install --upgrade diffly-cli
</span></span></code></pre></div><p>Or run <code>diffly update</code> from an existing 0.4.0+ installation.</p>
<h2 id="confidence">Confidence</h2>
<p>Version 1.0.0 is backed by the project test suite and cross-version CI coverage for Python 3.10–3.13. Diffly is production-ready as a deterministic review signal: it helps teams focus their review effort, but it does not replace human review or guarantee that a pull request is defect-free.</p>
<p>Thank you to everyone who tested Diffly before 1.0.0. This release establishes a dependable foundation for reviewing pull requests with more context and less noise.</p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/rustscript-action/</link><pubDate>Sun, 23 Aug 2026 05:42:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/23/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.6.12.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that allows you to write helper scripts in Rust and run them like shell scripts without the need to compile them. It provides a practical subset of the Rust language, enabling instant execution and validation with rust check. The action bridges many standard library functions and third-party crates to support common tasks such as file handling, HTTP requests, JSON parsing, regular expressions, and more. It simplifies the workflow by automating compilation and running, making it suitable for developers who want to use Rust without the overhead of compiling.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.6.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a tool that allows you to write helper scripts in Rust and run them like shell scripts without the need to compile them. It provides a practical subset of the Rust language, enabling instant execution and validation with <code>rust check</code>. The action bridges many standard library functions and third-party crates to support common tasks such as file handling, HTTP requests, JSON parsing, regular expressions, and more. It simplifies the workflow by automating compilation and running, making it suitable for developers who want to use Rust without the overhead of compiling.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.6.11...v0.6.12">https://github.com/VladasZ/rustscript/compare/v0.6.11...v0.6.12</a></p>
]]></content:encoded></item><item><title>AI ReviewBot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/ai-reviewbot/</link><pubDate>Sat, 22 Aug 2026 22:12:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/ai-reviewbot/</guid><description>Version updated for https://github.com/KonstZiv/ai-code-reviewer to version v1.0.0b13.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI ReviewBot is a GitHub Action that leverages advanced AI models like Google Gemini or Mistral to analyze and provide intelligent feedback directly in pull requests (PRs) and merge requests (MRs). It automates code review tasks by automatically identifying potential issues, suggesting improvements, and applying fixes with a one-click “Apply” button. The action also highlights security vulnerabilities and best practices, providing transparency on tokens used for analysis and cost estimation. AI ReviewBot supports both GitHub and GitLab platforms and is customizable via configuration files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/KonstZiv/ai-code-reviewer">https://github.com/KonstZiv/ai-code-reviewer</a></strong> to version <strong>v1.0.0b13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-reviewbot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI ReviewBot is a GitHub Action that leverages advanced AI models like Google Gemini or Mistral to analyze and provide intelligent feedback directly in pull requests (PRs) and merge requests (MRs). It automates code review tasks by automatically identifying potential issues, suggesting improvements, and applying fixes with a one-click &ldquo;Apply&rdquo; button. The action also highlights security vulnerabilities and best practices, providing transparency on tokens used for analysis and cost estimation. AI ReviewBot supports both GitHub and GitLab platforms and is customizable via configuration files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release 1.0.0b13</p>
]]></content:encoded></item><item><title>RuleBlast</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/ruleblast/</link><pubDate>Sat, 22 Aug 2026 22:11:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/ruleblast/</guid><description>Version updated for https://github.com/Kpoiut/ruleblast to version v2.5.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RuleBlast automates the process of tracking changes across multiple repositories to understand how a specific change in an AGENTS.md file affects other tracked paths. It helps identify which files inherit that change and whether it is aligned, mixed, divergent, or unresolved with respect to different AI tools like Codex, Claude Code, Gemini CLI, and Copilot CLI.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Kpoiut/ruleblast">https://github.com/Kpoiut/ruleblast</a></strong> to version <strong>v2.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ruleblast">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RuleBlast automates the process of tracking changes across multiple repositories to understand how a specific change in an AGENTS.md file affects other tracked paths. It helps identify which files inherit that change and whether it is aligned, mixed, divergent, or unresolved with respect to different AI tools like Codex, Claude Code, Gemini CLI, and Copilot CLI.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="ruleblast-251">RuleBlast 2.5.1</h1>
<p>Copilot CLI interpreted from <code>resolver.json</code>: multi-origin discover, select-all, unspecified assemble, frontmatter-glob <code>applyTo</code>, unexpanded <code>@</code> mention. Lab <code>INTERPRET</code> / <code>ORACLE</code>. Claude and Gemini still fingerprint. No fifth action. No fifth bundled reality. No <code>--pack</code>. A model name is never a reality.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx --yes ruleblast@2.5.1 .
</span></span><span style="display:flex;"><span>npx --yes ruleblast@2.5.1 diff HEAD~1
</span></span></code></pre></div><h2 id="verified-npm">Verified npm</h2>
<ul>
<li><a href="https://www.npmjs.com/package/ruleblast/v/2.5.1">npm <code>ruleblast@2.5.1</code></a></li>
<li>integrity <code>sha512-cAchQ4It9MM4E+CmOMvnviX/zGic+28DvxbHIK908NN+qJ9aLAsi7iPiIEelKBJiY/N4Ie0RxiVeOqhB1TbfhQ==</code></li>
<li>tarball 177,160 bytes · SHA-256 <code>32e3cc817f0dd915764f2f9d67c8b3f3f8aa4bc9215c11c8439842ed52ee6c4a</code></li>
<li>exact-tarball publication: registry <code>gitHead</code> is absent</li>
</ul>
<h2 id="github">GitHub</h2>
<ul>
<li>Signed tag object <code>761f547ca00d911cf5c5b826461b82c01ccac900</code> for <a href="https://github.com/Kpoiut/ruleblast/releases/tag/v2.5.1"><code>v2.5.1</code></a> targets <code>e60fd18ec4a83ce8aff7488b0bb9203ab4a8cedc</code></li>
<li>Companion <code>ruleblast-companion-2.5.1.vsix</code> 160,281 bytes · SHA-256 <code>26ed18e60cf4f4bad0dfef78514f2924d2f14878355547c5644a6220e1b09869</code></li>
<li>Do not overwrite Marketplace <code>2.2.0</code> or <code>2.2.1</code></li>
</ul>
]]></content:encoded></item><item><title>PhantomGuard CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/phantomguard-cli/</link><pubDate>Sat, 22 Aug 2026 22:09:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/phantomguard-cli/</guid><description>Version updated for https://github.com/Luckiii/phantomguard to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PhantomGuard is a tool designed to automatically detect AI-hallucinated package names before they are installed, using Python and JavaScript/TypeScript imports. It checks these imports against the PyPI or npm registry and flags any that do not exist, providing risk scores and explanations for each result. The known-hallucination database can be expanded over time through a self-fuzz pipeline, making it an MCP-compatible tool for managing package dependencies in a secure manner.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Luckiii/phantomguard">https://github.com/Luckiii/phantomguard</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/phantomguard-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PhantomGuard is a tool designed to automatically detect AI-hallucinated package names before they are installed, using Python and JavaScript/TypeScript imports. It checks these imports against the PyPI or npm registry and flags any that do not exist, providing risk scores and explanations for each result. The known-hallucination database can be expanded over time through a self-fuzz pipeline, making it an MCP-compatible tool for managing package dependencies in a secure manner.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="phantomguard-cli-v012">PhantomGuard CLI v0.1.2</h2>
<p>Catches AI-hallucinated (&ldquo;slopsquatted&rdquo;) package names before they get installed.</p>
<h3 id="whats-included">What&rsquo;s included</h3>
<ul>
<li><code>phantomguard scan &lt;path&gt;</code> — extracts Python and JS/TS imports, checks each
against PyPI/npm, scores risk against a known-hallucination database, prints
ALLOW/WARN/BLOCK. <code>pip install phantomguard-cli</code></li>
<li>Pre-commit hook (<code>.pre-commit-hooks.yaml</code>) — verified against a real repo</li>
<li>GitHub Action (this repo, composite) — verified in a live Actions run</li>
<li>MCP server (<code>phantomguard-mcp</code>) — exposes a <code>check_dependency</code> tool for
MCP-compatible agents (Cursor, Windsurf, etc.)</li>
<li>No API key required for any of the above — see README &ldquo;Scope&rdquo;</li>
</ul>
<h3 id="not-yet-included">Not yet included</h3>
<ul>
<li>Self-fuzz pipeline exists but hasn&rsquo;t been run for real yet — the
known-hallucination DB currently only has 3 manually-sourced seed entries</li>
<li>LLM-based necessity/rationale layer was deliberately skipped (see README)</li>
</ul>
<p>See the <a href="https://github.com/Luckiii/phantomguard#readme">README</a> for full usage.</p>
]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Sat, 22 Aug 2026 22:08:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.14.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action ServiceNow CI/CD GitHub Action for Run Tests automates the execution of a specified automated test suite within a ServiceNow environment. It simplifies the process of setting up credentials, configuring secrets, and integrating with ServiceNow’s CI/CD API to run client tests on various browsers and operating systems.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>ServiceNow CI/CD GitHub Action for Run Tests</code> automates the execution of a specified automated test suite within a ServiceNow environment. It simplifies the process of setting up credentials, configuring secrets, and integrating with ServiceNow&rsquo;s CI/CD API to run client tests on various browsers and operating systems.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.13...1.0.14">https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.13...1.0.14</a></p>
]]></content:encoded></item><item><title>Miso PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/miso-pr-review/</link><pubDate>Sat, 22 Aug 2026 22:07:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/miso-pr-review/</guid><description>Version updated for https://github.com/misospace/pr-reviewer-action to version v2.2.1.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The pr-reviewer-action GitHub Action automates AI-powered pull request reviews using OpenAI or Anthropic models. It gathers PR metadata, diff context, linked issue context, and other data to generate structured findings and markdown review bodies. The action can publish the result as a sticky comment or native GitHub review and provides features for deterministic PR classification, smart model routing, structured findings, token-saving by design, and safe defaults.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/misospace/pr-reviewer-action">https://github.com/misospace/pr-reviewer-action</a></strong> to version <strong>v2.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miso-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>pr-reviewer-action</code> GitHub Action automates AI-powered pull request reviews using OpenAI or Anthropic models. It gathers PR metadata, diff context, linked issue context, and other data to generate structured findings and markdown review bodies. The action can publish the result as a sticky comment or native GitHub review and provides features for deterministic PR classification, smart model routing, structured findings, token-saving by design, and safe defaults.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="221-2026-08-22"><a href="https://github.com/misospace/pr-reviewer-action/compare/v2.2.0...v2.2.1">2.2.1</a> (2026-08-22)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li><strong>github-action:</strong> Update action actions/setup-python (v5.6.0 → v7.0.0) (<a href="https://github.com/misospace/pr-reviewer-action/issues/492">#492</a>)</li>
<li><strong>github-action:</strong> Update action actions/upload-artifact (v4.6.2 → v7.0.1) (<a href="https://github.com/misospace/pr-reviewer-action/issues/493">#493</a>)</li>
<li><strong>github-action:</strong> Update action actions/checkout (v4.4.0 → v7.0.1) (<a href="https://github.com/misospace/pr-reviewer-action/issues/491">#491</a>)</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li><strong>action:</strong> add fail_on_request_changes input to gate merges without a GitHub App (<a href="https://github.com/misospace/pr-reviewer-action/issues/528">#528</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/448b27bbef0fb612662aba7bbc5e7ff6d99950b1">448b27b</a>), closes <a href="https://github.com/misospace/pr-reviewer-action/issues/518">#518</a></li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>classification:</strong> pass impact pattern to awk via ENVIRON (<a href="https://github.com/misospace/pr-reviewer-action/issues/481">#481</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/787f619da413617116b894f215e40b38feedeb6c">787f619</a>)</li>
<li>escalate on an empty completion instead of retrying the same model (<a href="https://github.com/misospace/pr-reviewer-action/issues/525">#525</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/3850b4a86bb46e9f5df266cc0c5c14bf856ff443">3850b4a</a>)</li>
<li><strong>evidence:</strong> scrub AI_PRIMARY_API_KEY, AI_SMART_API_KEY, LINEAR_API_KEY from provider env (<a href="https://github.com/misospace/pr-reviewer-action/issues/522">#522</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/322f88da78b03c7eeafa09a939e7495e3ed08976">322f88d</a>), closes <a href="https://github.com/misospace/pr-reviewer-action/issues/513">#513</a></li>
<li>give the native_loop verdict turn the real tool harness findings (<a href="https://github.com/misospace/pr-reviewer-action/issues/527">#527</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/edb0b02bc4c5cc072f938ee3fe307978764bea3d">edb0b02</a>)</li>
<li><strong>precheck:</strong> carry forward previous verdict on diff-unchanged skip (<a href="https://github.com/misospace/pr-reviewer-action/issues/523">#523</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/22b551ede8d66c443bbec18974f26fecf3d2f4df">22b551e</a>)</li>
<li>resolve issue <a href="https://github.com/misospace/pr-reviewer-action/issues/509">#509</a> (<a href="https://github.com/misospace/pr-reviewer-action/issues/519">#519</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/3d7459f9ab4c4483e6b3ff14f0bb9b7ecb4454e7">3d7459f</a>)</li>
<li>route Forgejo auth header through 0600 curl &ndash;config file (<a href="https://github.com/misospace/pr-reviewer-action/issues/486">#486</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/e182061739aad5bd32fe01361477103ed48e8e2a">e182061</a>), closes <a href="https://github.com/misospace/pr-reviewer-action/issues/471">#471</a></li>
<li><strong>security:</strong> restrict web_fetch URL scheme to http/https (<a href="https://github.com/misospace/pr-reviewer-action/issues/479">#479</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/7398d137f2efde9a964c408525060c480592316f">7398d13</a>), closes <a href="https://github.com/misospace/pr-reviewer-action/issues/468">#468</a></li>
<li><strong>ssrf:</strong> gate host allowlist on resolved IP (<a href="https://github.com/misospace/pr-reviewer-action/issues/520">#520</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/b917fb29aac8ecee9dc376194b2157c2913c77ad">b917fb2</a>), closes <a href="https://github.com/misospace/pr-reviewer-action/issues/510">#510</a></li>
<li>update README from <a href="https://github.com/v1">@v1</a> to <a href="https://github.com/v2">@v2</a> and fix stale self-review section (<a href="https://github.com/misospace/pr-reviewer-action/issues/487">#487</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/b03949b530981cf1bb8d8f49d5f09636652f7b84">b03949b</a>), closes <a href="https://github.com/misospace/pr-reviewer-action/issues/470">#470</a></li>
</ul>
<h3 id="chores">Chores</h3>
<ul>
<li><strong>ci:</strong> add gitleaks secret-scan step to validate job (<a href="https://github.com/misospace/pr-reviewer-action/issues/521">#521</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/fc3b02d6915c75944fff99d260533c0a757b8fe0">fc3b02d</a>)</li>
<li><strong>ci:</strong> add shellcheck to CI (<a href="https://github.com/misospace/pr-reviewer-action/issues/467">#467</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/61ec936b69a39af96b0be779bcb0af88e4446684">61ec936</a>)</li>
<li><strong>ci:</strong> pin test dependencies in requirements.txt for reproducible builds (<a href="https://github.com/misospace/pr-reviewer-action/issues/526">#526</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/91de1d772d475dac21d3d56976821fbf0e044c00">91de1d7</a>), closes <a href="https://github.com/misospace/pr-reviewer-action/issues/514">#514</a></li>
<li>release 2.2.1 (<a href="https://github.com/misospace/pr-reviewer-action/issues/506">#506</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/566981250c0409662b2c6be638316e43085ae31e">5669812</a>)</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>clarify ai-pr-review-sha marker value in emit_review_markers (<a href="https://github.com/misospace/pr-reviewer-action/issues/503">#503</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/07b28c6e56eb0d840036e526f2b3c00b14dd948e">07b28c6</a>), closes <a href="https://github.com/misospace/pr-reviewer-action/issues/484">#484</a></li>
<li>issue contract for the autonomous loop (<a href="https://github.com/misospace/pr-reviewer-action/issues/483">#483</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/12438401f09847793834fda84b888fa3a4c7a51b">1243840</a>)</li>
</ul>
<h3 id="continuous-integration">Continuous Integration</h3>
<ul>
<li><strong>github-action:</strong> Update action actions/checkout (v4.4.0 → v7.0.1) (<a href="https://github.com/misospace/pr-reviewer-action/issues/491">#491</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/e002f7b81aa960122c913768e7133bf5b0852487">e002f7b</a>)</li>
<li><strong>github-action:</strong> Update action actions/setup-python (v5.6.0 → v7.0.0) (<a href="https://github.com/misospace/pr-reviewer-action/issues/492">#492</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/582e3c2d41dc3a2d3138791290d72acb174e6b25">582e3c2</a>)</li>
<li><strong>github-action:</strong> Update action actions/upload-artifact (v4.6.2 → v7.0.1) (<a href="https://github.com/misospace/pr-reviewer-action/issues/493">#493</a>) (<a href="https://github.com/misospace/pr-reviewer-action/commit/caad3205b2219eb0913b10fdddd710f9749cc167">caad320</a>)</li>
</ul>
]]></content:encoded></item><item><title>mockdr — Multi-EDR Mock Server</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/mockdr-multi-edr-mock-server/</link><pubDate>Sat, 22 Aug 2026 22:06:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/mockdr-multi-edr-mock-server/</guid><description>Version updated for https://github.com/mockdr/mockdr to version v2.0.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The mockdr GitHub Action is a self-contained tool designed to provide realistic mock server responses for multiple EDR (Endpoint Detection and Response) platforms including SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Elastic Security, Cortex XDR, Splunk SIEM, and Microsoft Sentinel. It automates the process of testing SOAR playbooks, SIEM connectors, and automation scripts against these platforms without the need to use actual vendor APIs or licenses. The action supports various authentication methods and response formats, making it versatile for different use cases such as SOAR development, SIEM integration validation, and pentesting scenarios.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mockdr/mockdr">https://github.com/mockdr/mockdr</a></strong> to version <strong>v2.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mockdr-multi-edr-mock-server">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The mockdr GitHub Action is a self-contained tool designed to provide realistic mock server responses for multiple EDR (Endpoint Detection and Response) platforms including SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Elastic Security, Cortex XDR, Splunk SIEM, and Microsoft Sentinel. It automates the process of testing SOAR playbooks, SIEM connectors, and automation scripts against these platforms without the need to use actual vendor APIs or licenses. The action supports various authentication methods and response formats, making it versatile for different use cases such as SOAR development, SIEM integration validation, and pentesting scenarios.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The release the last three were building towards. 2.0.2, 2.0.3 and 2.0.4
each shipped and were each followed by a correction, because the tool that
found the defect ran <em>after</em> the tag. This time every one of those tools ran
before it:</p>
<ul>
<li>the full CI mirror, e2e and Docker smoke test included</li>
<li>the conformance harness against a running Splunk 10.4.2, Elasticsearch
8.15.0 and Kibana 8.15.0 — with <strong>129 probes</strong>, four times 2.0.4&rsquo;s</li>
<li>hostile-body probing of all <strong>462 routes</strong>, 17,076 requests</li>
<li>parser fuzzing, 13,738 inputs</li>
<li>an adversarial review of everything since 2.0.3</li>
</ul>
<h2 id="what-that-found-and-what-is-left">What that found, and what is left</h2>
<table>
  <thead>
      <tr>
          <th></th>
          <th>before</th>
          <th>after</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Routes answering 500 to a malformed body</td>
          <td>31</td>
          <td><strong>0</strong></td>
      </tr>
      <tr>
          <td>Parser crashes under fuzzing</td>
          <td>2</td>
          <td><strong>0</strong></td>
      </tr>
      <tr>
          <td>Splunk: status/value/type disagreements with the real product</td>
          <td>45</td>
          <td><strong>0</strong></td>
      </tr>
      <tr>
          <td>Elastic/Kibana: status/value/type disagreements</td>
          <td>30</td>
          <td><strong>0</strong></td>
      </tr>
  </tbody>
</table>
<p>Zero disagreements of the kind a client branches on. What the harness still
reports — 800 Splunk and 97 Elastic <code>missing_key</code> findings — is list
endpoints whose real entries carry thirty to sixty content keys where
mockdr&rsquo;s carry a dozen. A client reading one of those keys gets a
<code>KeyError</code>, not a wrong answer. That is the next kind of work, and it is
stated here rather than hidden.</p>
<p>&ldquo;Bug-free&rdquo; is not a claim anyone can make honestly. This is the claim that
can be: every discovery method that has found a bug in this project has
been run against this release and found nothing of the kind it finds.</p>
<h2 id="the-correction-that-matters-most">The correction that matters most</h2>
<p><strong>Splunk&rsquo;s JSON types were an inference, and it was wrong.</strong> Since 2.0.1
mockdr stringified every job value — <code>&quot;1&quot;</code>/<code>&quot;0&quot;</code> for booleans, <code>&quot;5&quot;</code> for
counts — reasoning from splunklib&rsquo;s <code>content[&quot;isDone&quot;] == &quot;1&quot;</code>. That line
is correct for the Atom XML splunklib actually requests, where everything
is text. Measured on Splunk 10.4.2, <code>output_mode=json</code> carries real
booleans and integers, on the job list and the single job alike. A client
written against real Splunk&rsquo;s JSON and tested against mockdr&rsquo;s would have
compared <code>true</code> to <code>&quot;1&quot;</code> and failed in production. Now as measured — down
to <code>currentDBSizeMB</code>, which really is a string while its neighbours are
integers.</p>
<h2 id="upgrading">Upgrading</h2>
<p>No response that was correct in 2.0.4 changes shape. Several that were wrong
do, and every one is listed in the changelog with what the real product
sends instead. The ones a client is most likely to notice:</p>
<ul>
<li>Splunk job and index values are native JSON types, not strings.</li>
<li><code>/services</code> (Splunk) no longer exists; splunkd never had it.</li>
<li>A wrong HTTP verb on a Splunk collection is <code>400</code>, not <code>405</code>.</li>
<li>Kibana refuses a case, rule or exception list missing required fields with
io-ts&rsquo;s per-field message, where mockdr used to create it.</li>
<li>Elasticsearch refuses an unknown top-level search key, a negative or
non-numeric <code>size</code>, and a result window past 10,000, each in its own
exception type.</li>
<li>31 routes that answered <code>500</code> to <code>null</code> or <code>{}</code> now answer their vendor&rsquo;s
<code>400</code>.</li>
</ul>
<h2 id="also">Also</h2>
<p><code>POST /_count</code>, <code>/_mget</code> and <code>/_bulk</code> exist at the root now. HEC accepts a
top-level array as a batch, reports <code>invalid-event-number</code> as events are
parsed (so a blank event at 0 is reported before broken JSON at 1), and
uses codes 14 and 15 where it used to say 10 and 6. The Splunk parser
classifies <code>sort</code>, <code>tail</code> and <code>dedup</code> as measured, accepts <code>makeresults</code>
and <code>inputlookup</code>, and no longer splits on a pipe inside a quoted string.</p>
<p>Full changelog: <a href="https://github.com/mockdr/mockdr/blob/main/CHANGELOG.md">https://github.com/mockdr/mockdr/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/odin-scan-smart-contract-security/</link><pubDate>Sat, 22 Aug 2026 22:05:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates smart contract security analysis for CosmWasm, Solana, and EVM projects using the Odin Scan AI platform. It integrates with GitHub workflows to catch vulnerabilities before they reach production. Key features include multi-platform support, automatic platform detection, integration with GitHub Code Scanning, PR comments, inline annotations, comment-triggered scans, configurable thresholds, artifact upload, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates smart contract security analysis for CosmWasm, Solana, and EVM projects using the Odin Scan AI platform. It integrates with GitHub workflows to catch vulnerabilities before they reach production. Key features include multi-platform support, automatic platform detection, integration with GitHub Code Scanning, PR comments, inline annotations, comment-triggered scans, configurable thresholds, artifact upload, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial Release</p>
<p>AI-powered smart contract security analysis, now integrated directly into your GitHub workflow.</p>
<p>✨ Features</p>
<p>Multi-Platform Support</p>
<ul>
<li>CosmWasm - Rust-based smart contracts for Cosmos SDK</li>
<li>Solana (SVM) - Anchor and native Solana programs</li>
<li>EVM - Solidity and Vyper contracts</li>
<li>Auto-detection - Automatically identifies platform from your repo</li>
</ul>
<p>GitHub Integration</p>
<ul>
<li>Code Scanning - SARIF upload for native security alerts in the Security tab</li>
<li>PR Comments - Severity summary and top findings posted directly on pull requests</li>
<li>Inline Annotations - Critical/high findings appear as errors, medium/low as warnings on diffs</li>
<li>Artifact Upload - Full JSON report available as workflow artifact</li>
</ul>
<p>Customization</p>
<ul>
<li>Severity Thresholds - Fail builds at critical, high, medium, or low severity</li>
<li>Platform Override - Force specific platform detection when auto-detect isn&rsquo;t enough</li>
<li>Timeout Control - Configurable analysis timeout (default: 30 minutes)</li>
<li>Flexible Triggers - Run on push, PR, schedule, or manual dispatch</li>
</ul>
<p>🚀 Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Security Scan</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&#39;on&#39;</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">main</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">security-events</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">api-key</span>: <span style="color:#e6db74">&#39;${{ secrets.ODIN_SCAN_API_KEY }}&#39;</span>
</span></span></code></pre></div><p>📋 Requirements</p>
<ul>
<li>Odin Scan Pro subscription - Required for API access</li>
<li>API Key - Generate at <a href="https://odinscan.ai/dashboard/settings">https://odinscan.ai/dashboard/settings</a></li>
<li>GitHub Permissions - contents: read, security-events: write (for SARIF), pull-requests: write (for
comments)</li>
</ul>
<p>🔧 Configuration</p>
<p>All Inputs</p>
<p>| ┌────────────────────┬─────────────────────┬──────────────────────────────────────────────┐ |
| │       Input        │       Default       │                 Description                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ api-key            │ Required            │ Your Odin Scan API key (odin_sk_*)           │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ platform           │ auto                │ Target platform: auto, cosmwasm, solana, evm │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ severity-threshold │ high                │ Fail at: critical, high, medium, low, none   │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ fail-on-findings   │ true                │ Whether to fail workflow on findings         │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ comment-on-pr      │ true                │ Post summary comment on PRs                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-sarif       │ true                │ Upload SARIF to Code Scanning                │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-artifact    │ true                │ Upload full report as artifact               │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ timeout            │ 1800                │ Max analysis wait time (seconds)             │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ github-token       │ ${{ github.token }} │ Token for PR comments and SARIF              │ |
| └────────────────────┴─────────────────────┴──────────────────────────────────────────────┘ |</p>
<p>All Outputs</p>
<ul>
<li>analysis-id - Unique analysis identifier</li>
<li>status - Analysis status (completed, failed)</li>
<li>total-findings - Total number of findings</li>
<li>critical-count, high-count, medium-count, low-count - Counts by severity</li>
<li>report-url - Link to full report on Odin Scan</li>
<li>sarif-file - Path to generated SARIF file</li>
</ul>
<p>📝 Example Workflows</p>
<p>Basic (Auto-detect)</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span></code></pre></div><p>EVM with Medium Threshold</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">platform</span>: <span style="color:#ae81ff">evm</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">severity-threshold</span>: <span style="color:#ae81ff">medium</span>
</span></span></code></pre></div><p>Only on Solidity Changes</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#39;**.sol&#39;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">foundry.toml</span>
</span></span></code></pre></div><p>🔒 Security &amp; Privacy</p>
<ul>
<li>All API communication over HTTPS (TLS 1.2+)</li>
<li>API keys automatically masked in logs</li>
<li>No data stored by the action (stateless)</li>
<li>See <a href="https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md">https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md</a> for details</li>
</ul>
<p>📖 Documentation</p>
<ul>
<li>Action README - <a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></li>
<li>Odin Scan Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
<li>Get API Key - <a href="https://app.odinscan.ai/settings">https://app.odinscan.ai/settings</a></li>
</ul>
<p>🐛 Known Limitations</p>
<ul>
<li>Private repos - Requires github-token with repo access</li>
<li>Large repos - May need increased timeout for complex codebases</li>
<li>Code Scanning - Requires GitHub Advanced Security on private repos</li>
</ul>
<p>🙏 Support</p>
<ul>
<li>Issues - <a href="https://github.com/Odin-Scan/odin-scan-action/issues">https://github.com/Odin-Scan/odin-scan-action/issues</a></li>
<li>Email - <a href="mailto:support@odinscan.ai">support@odinscan.ai</a></li>
<li>Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
</ul>
<hr>
<p>Full Changelog: <a href="https://github.com/Odin-Scan/odin-scan-action/commits/v1">https://github.com/Odin-Scan/odin-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>Chock Governance Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/chock-governance-check/</link><pubDate>Sat, 22 Aug 2026 22:04:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/chock-governance-check/</guid><description>Version updated for https://github.com/open-coder-ai/chock to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Chock is a governance-as-code tool that automates AI coding agent policies. It compiles rules into deterministic guardrails, including git hooks, CI gates, and native pre-execution hooks in Claude Code and Cursor, ensuring that all agents adhere to consistent rules within a team’s or project’s codebase.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/open-coder-ai/chock">https://github.com/open-coder-ai/chock</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/chock-governance-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Chock is a governance-as-code tool that automates AI coding agent policies. It compiles rules into deterministic guardrails, including git hooks, CI gates, and native pre-execution hooks in Claude Code and Cursor, ensuring that all agents adhere to consistent rules within a team&rsquo;s or project&rsquo;s codebase.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="020--first-release-with-an-external-contribution">0.2.0 — First release with an external contribution</h2>
<p>MINOR: new features and adapters; compiled output for existing policies is unchanged
(golden-suite verified), but new surfaces exist.</p>
<ul>
<li><strong>Antigravity CLI adapter</strong> — contributed by @alexsmolya, the project&rsquo;s first external
contribution: <code>.agents/rules/chock.md</code> workspace rule, ambient/git-hook/CI surfaces
(deliberately not pre-tool-use: no installer exists, so no claim is made).</li>
<li><strong>Claude-format plugin emitter</strong>: <code>chock plugin build --format claude|all --out-dir</code>
renders each policy into Claude Code&rsquo;s plugin layout (read natively by Claude Code,
Copilot CLI, VS Code and Grok Build), with the fail posture stated verbatim in every
emitted description and per-format subtrees so no package has to lie for another
client. Stale-output reconciliation, duplicate-id refusal.</li>
<li><strong><code>chock marketplace build</code></strong>: derives the marketplace index, a content-addressed
<code>chock-market.lock</code> (sha256 per published plugin directory), and a generated
<code>PLUGINS.md</code> catalog page from the built packages — never hand-listed, drift-checked.</li>
<li><strong>Hook interpreter honesty</strong>: the emitted hook command stays a single <code>python3</code>
invocation &ndash; a review of the proposed <code>python3 || python</code> fallback proved a chain
can erase a deny verdict (a deny exit followed by a missing-interpreter exit reads
as an error, and the first leg consumes stdin), so it was rejected with
measurements. Instead every emitted description now states the per-client fail
posture: fail-open clients allow silently without <code>python3</code> and a usable bash;
fail-closed clients (VS Code) refuse matched commands; Windows needs the
Microsoft Store <code>python3</code> alias disabled or Python installed.</li>
<li><strong>Supply chain</strong>: the Marketplace action no longer interpolates workflow inputs
into shell (two HIGH template-injection alerts, fixed by env indirection); GitHub
Releases are created by the runner&rsquo;s own <code>gh</code> CLI instead of a third-party action;
the semgrep scanner installs hash-pinned via compiled requirements; Dependabot
gets a 7-day cooldown.</li>
<li><strong>CI pressure testing</strong>: zizmor, actionlint, ShellCheck, and Semgrep (with custom
rules encoding this project&rsquo;s own incidents) run as required checks; all three
public repos are at zero open code-scanning alerts.</li>
<li><strong>Fix</strong>: <code>chock remove</code> refuses when a policy&rsquo;s manifest cannot be read — an
unreadable manifest previously read as &ldquo;not mandatory&rdquo; and allowed deletion.</li>
<li><strong>Fix</strong>: <code>frontier_ingest</code> no longer prints and exits at import time; frontier
validation shares one <code>STANDARDS_DIR</code> with ingestion.</li>
<li><strong>Tests</strong>: 755 (from 736); statement coverage 83%; new suites for the plugin
emitter, marketplace, <code>chock remove</code>, and the frontier validation modes.</li>
</ul>
]]></content:encoded></item><item><title>REWORK Proof Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/rework-proof-check/</link><pubDate>Sat, 22 Aug 2026 22:03:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/rework-proof-check/</guid><description>Version updated for https://github.com/Reworkdigital-io/REWORK-Proof to version v1.0.0.
This action is used across all versions by 0 repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks who wrote each commit in a pull request, verifying their signature state and author attribution. It also identifies AI-assisted commits, without penalizing them. The action can generate a Verifiable Credential attestation of the run if configured, using OIDC tokens to prove repository and workflow information without storing any sensitive data in the repository settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Reworkdigital-io/REWORK-Proof">https://github.com/Reworkdigital-io/REWORK-Proof</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<p>Go to the <a href="https://github.com/marketplace/actions/rework-proof-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks who wrote each commit in a pull request, verifying their signature state and author attribution. It also identifies AI-assisted commits, without penalizing them. The action can generate a Verifiable Credential attestation of the run if configured, using OIDC tokens to prove repository and workflow information without storing any sensitive data in the repository settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Reports who actually wrote the commits in a pull request — signature state,
author attribution, and disclosed AI assistance — as a job summary.</p>
<h2 id="setup">Setup</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Proof</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>: <span style="color:#ae81ff">pull_request</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">proof</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Reworkdigital-io/REWORK-Proof@v1</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/kaniko-build-action/</link><pubDate>Sat, 22 Aug 2026 22:01:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting to a specified person, providing flexibility in automation tasks related to greetings and logging. It is useful for automating notifications or messages within workflows.
What’s Changed My first action is ready (5619594) Initial commit (2a56a2a)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting to a specified person, providing flexibility in automation tasks related to greetings and logging. It is useful for automating notifications or messages within workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/rumdl-action/</link><pubDate>Sat, 22 Aug 2026 22:01:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.60.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rumdl is a high-performance Markdown linter and formatter written in Rust. It offers 82 lint rules, automatic formatting with --fix, and is optimized for speed, making it suitable for large projects and CI/CD workflows. The action automates the linting and formatting of Markdown files, ensuring consistency and best practices.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.60</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>rumdl is a high-performance Markdown linter and formatter written in Rust. It offers 82 lint rules, automatic formatting with <code>--fix</code>, and is optimized for speed, making it suitable for large projects and CI/CD workflows. The action automates the linting and formatting of Markdown files, ensuring consistency and best practices.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>deps</strong>: update h2 to 0.4.16 (<a href="https://github.com/rvben/rumdl/commit/a6503022a5b0268138fbec2068d8e9a7abd27e64">a650302</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.60-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.60-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.60-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.60-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-x86_64-apple-darwin.tar.gz">rumdl-v0.2.60-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-aarch64-apple-darwin.tar.gz">rumdl-v0.2.60-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-x86_64-pc-windows-msvc.zip">rumdl-v0.2.60-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.60/rumdl-v0.2.60-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Profile Cards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/profile-cards/</link><pubDate>Sat, 22 Aug 2026 22:00:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/profile-cards/</guid><description>Version updated for https://github.com/seijikohara/profile-cards-action to version v0.0.9.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Profile READMEs are rendered as SVGs from GitHub GraphQL API, providing a self-hosted, reproducible, and theme-aware overview, contribution history, streaks, composition, activity rhythm, commit punch card, repository ranking, and language treemap. Each card is rendered per theme into an output directory with optional badge pills using simple-icons for brand glyphs or text-only pills otherwise.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seijikohara/profile-cards-action">https://github.com/seijikohara/profile-cards-action</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/profile-cards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Profile READMEs are rendered as SVGs from GitHub GraphQL API, providing a self-hosted, reproducible, and theme-aware overview, contribution history, streaks, composition, activity rhythm, commit punch card, repository ranking, and language treemap. Each card is rendered per theme into an output directory with optional badge pills using simple-icons for brand glyphs or text-only pills otherwise.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>design: v1 polish and densification pass across all cards by @seijikohara in <a href="https://github.com/seijikohara/profile-cards-action/pull/32">https://github.com/seijikohara/profile-cards-action/pull/32</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/seijikohara/profile-cards-action/compare/v0.0.8...v0.0.9">https://github.com/seijikohara/profile-cards-action/compare/v0.0.8...v0.0.9</a></p>
]]></content:encoded></item><item><title>VentureX ERP &amp; CRM Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/venturex-erp-crm-deploy/</link><pubDate>Sat, 22 Aug 2026 21:59:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/venturex-erp-crm-deploy/</guid><description>Version updated for https://github.com/SHIVAM73566/venturex-deploy-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of VentureX ERP &amp;amp; CRM to a server. It handles installation, database setup, application deployment, and configuration of Nginx with Let’s Encrypt SSL, providing a seamless automated process for deploying VentureX ERP &amp;amp; CRM applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SHIVAM73566/venturex-deploy-action">https://github.com/SHIVAM73566/venturex-deploy-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/venturex-erp-crm-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of VentureX ERP &amp; CRM to a server. It handles installation, database setup, application deployment, and configuration of Nginx with Let&rsquo;s Encrypt SSL, providing a seamless automated process for deploying VentureX ERP &amp; CRM applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>VentureX ERP &amp; CRM - GitHub Action</p>
<p>Deploy VentureX ERP &amp; CRM - AI-Powered Business Operating System to your server in one click.</p>
<p>What This Action Does</p>
<ul>
<li>Installs PHP 8.3, MySQL 8.0, Nginx, Node.js 20, Composer 2</li>
<li>Sets up database and runs migrations</li>
<li>Deploys the application</li>
<li>Configures Nginx web server</li>
<li>Enables HTTPS with Let&rsquo;s Encrypt SSL</li>
<li>Seeds demo data</li>
</ul>
<p>Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">SHIVAM73566/venturex-deploy-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">server-host</span>: <span style="color:#ae81ff">${{ secrets.SERVER_HOST }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">server-key</span>: <span style="color:#ae81ff">${{ secrets.SERVER_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">domain</span>: <span style="color:#ae81ff">erp.yourdomain.com</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">db-password</span>: <span style="color:#ae81ff">${{ secrets.DB_PASSWORD }}</span>
</span></span><span style="display:flex;"><span>    
</span></span><span style="display:flex;"><span>    
</span></span></code></pre></div>]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/smyklot/</link><pubDate>Sat, 22 Aug 2026 21:58:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.45.4.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the .github/CODEOWNERS file. It supports multiple command formats, including slash commands, mentions, and bare commands, and provides options to specify merge methods. The action handles reactions for approval, merging, and cleanup, with features like reaction deduplication and emoji feedback.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.45.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the <code>.github/CODEOWNERS</code> file. It supports multiple command formats, including slash commands, mentions, and bare commands, and provides options to specify merge methods. The action handles reactions for approval, merging, and cleanup, with features like reaction deduplication and emoji feedback.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1454-2026-08-22"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.45.3...v1.45.4">1.45.4</a> (2026-08-22)</h2>
<h3 id="code-refactoring">Code Refactoring</h3>
<ul>
<li><strong>github:</strong> take this bot&rsquo;s vocabulary out of the client (<a href="https://github.com/smykla-skalski/smyklot/issues/302">#302</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/cf56195bb57bd05b980f5f4323ca6211de828f81">cf56195</a>)</li>
</ul>
<h2 id="smyklot-v1454">Smyklot v1.45.4</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.45.4</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>b8b5a303502aafe2748ee3af8d94776aa883c454 chore(release): bump version to 1.45.4</li>
<li>cf56195bb57bd05b980f5f4323ca6211de828f81 refactor(github): take this bot&rsquo;s vocabulary out of the client (#302)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sat, 22 Aug 2026 21:57:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service. It ensures that the necessary dependencies are installed and the project is bundled before deploying it to a Swarm cluster. This helps maintain consistency across environments and simplifies the process of pushing updates to the service.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service. It ensures that the necessary dependencies are installed and the project is bundled before deploying it to a Swarm cluster. This helps maintain consistency across environments and simplifies the process of pushing updates to the service.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/classroom-to-sheets-integration/</link><pubDate>Sat, 22 Aug 2026 21:57:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates GitHub Classroom with Google Sheets, allowing automatic updates of assignment results. It requires setting up Google Cloud credentials and secrets, and then using it in GitHub Actions workflows to send task grades to a specified Google sheet. The action automatically handles the creation of columns for tasks and rows for students based on the data provided.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates GitHub Classroom with Google Sheets, allowing automatic updates of assignment results. It requires setting up Google Cloud credentials and secrets, and then using it in GitHub Actions workflows to send task grades to a specified Google sheet. The action automatically handles the creation of columns for tasks and rows for students based on the data provided.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>StructureClerk Compliance Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/structureclerk-compliance-check/</link><pubDate>Sat, 22 Aug 2026 21:56:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/structureclerk-compliance-check/</guid><description>Version updated for https://github.com/StructureClerk/compliance-check to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates compliance checks for websites, focusing on privacy, AI governance, and cybersecurity. It uses StructureClerk’s API to scan a website and returns a compliance score, letter grade, and pass/fail status based on a specified threshold. The action is primarily useful for ensuring that web properties meet established standards without requiring manual questionnaire responses.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/StructureClerk/compliance-check">https://github.com/StructureClerk/compliance-check</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/structureclerk-compliance-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates compliance checks for websites, focusing on privacy, AI governance, and cybersecurity. It uses StructureClerk&rsquo;s API to scan a website and returns a compliance score, letter grade, and pass/fail status based on a specified threshold. The action is primarily useful for ensuring that web properties meet established standards without requiring manual questionnaire responses.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Add files via upload (7d58f70)</li>
<li>Initial commit (9938d54)</li>
</ul>
]]></content:encoded></item><item><title>Agent Vigil</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/agent-vigil/</link><pubDate>Sat, 22 Aug 2026 21:55:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/agent-vigil/</guid><description>Version updated for https://github.com/sulmusic2-star/agent-vigil to version v0.11.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Vigil automates the verification of code changes by ensuring they meet a set of criteria, including the presence of necessary evidence, test coverage, and adherence to policy rules. It uses local or GitHub runner environments to run checks on the exact code change before it can be merged, providing PASS, FAIL, or INCONCLUSIVE outcomes based on various verifications such as task completion, test execution, policy adherence, and integrity.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sulmusic2-star/agent-vigil">https://github.com/sulmusic2-star/agent-vigil</a></strong> to version <strong>v0.11.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-vigil">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Vigil automates the verification of code changes by ensuring they meet a set of criteria, including the presence of necessary evidence, test coverage, and adherence to policy rules. It uses local or GitHub runner environments to run checks on the exact code change before it can be merged, providing PASS, FAIL, or INCONCLUSIVE outcomes based on various verifications such as task completion, test execution, policy adherence, and integrity.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="agent-vigil-v0113">Agent Vigil v0.11.3</h2>
<p>Agent Vigil now has two verified public installation channels:</p>
<ul>
<li>npm: <a href="https://www.npmjs.com/package/@sulmusic/agent-vigil/v/0.11.3">@sulmusic/agent-vigil</a></li>
<li>GitHub Marketplace: <a href="https://github.com/marketplace/actions/agent-vigil">Agent Vigil</a></li>
</ul>
<h3 id="install">Install</h3>
<pre><code>npx --yes @sulmusic/agent-vigil@0.11.3 init --profile maintainer
npx --yes @sulmusic/agent-vigil@0.11.3 doctor
</code></pre>
<p>The scoped npm name avoids confusion with the separate agentvigil package. The installed executables remain agent-vigil and vigil.</p>
<h3 id="verification">Verification</h3>
<ul>
<li>287 tests passed.</li>
<li>Package smoke covered 11 repository shapes and 33 setup flows.</li>
<li>A clean registry-backed consumer completed init and doctor with zero failures and zero warnings.</li>
<li>Linux Node 20/22/24, macOS, Windows, and the required Agent Vigil evidence check passed on pull request #25.</li>
<li>The attached tarball SHA-256 is d69d8fc9a615a537a5757be5622dd2cac0f143a0eb1dafdccf994c8d44ab32a7.</li>
</ul>
<p>Publication proves distribution, not external adoption, retention, accepted contradictions, revenue, or commercial demand.</p>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/setup-tombi/</link><pubDate>Sat, 22 Aug 2026 21:54:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.4.1.
This action is used across all versions by 146 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-tombi GitHub Action sets up the Tombi CLI in a GitHub Actions workflow. It allows users to install specific versions of Tombi, either by specifying a version number or a lock file, and provides options for checksum verification and caching behavior. This action helps developers automate Tombi installation tasks directly within their workflows, facilitating better integration with other tools and processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>146</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>setup-tombi</code> GitHub Action sets up the Tombi CLI in a GitHub Actions workflow. It allows users to install specific versions of Tombi, either by specifying a version number or a lock file, and provides options for checksum verification and caching behavior. This action helps developers automate Tombi installation tasks directly within their workflows, facilitating better integration with other tools and processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.4.1">tombi v1.4.1</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1.4.0...v1.4.1">https://github.com/tombi-toml/setup-tombi/compare/v1.4.0...v1.4.1</a></p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/wails3-build-action/</link><pubDate>Sat, 22 Aug 2026 21:53:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building of Wails.io applications, a framework for creating desktop and web applications using Go. It installs GoLang and NodeJS, builds the application based on specified parameters (platform, obfuscation, etc.), and optionally uploads the build artifacts to GitHub or releases them if tagged. The action supports various configurations for different platforms and build options, making it versatile for developers working with Wails projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building of Wails.io applications, a framework for creating desktop and web applications using Go. It installs GoLang and NodeJS, builds the application based on specified parameters (platform, obfuscation, etc.), and optionally uploads the build artifacts to GitHub or releases them if tagged. The action supports various configurations for different platforms and build options, making it versatile for developers working with Wails projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Install bashunit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/install-bashunit/</link><pubDate>Sat, 22 Aug 2026 21:52:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/install-bashunit/</guid><description>Version updated for https://github.com/TypedDevs/bashunit to version 0.50.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automates running unit tests and static analysis for bash scripts using BashUnit, a lightweight testing framework. It focuses on developer experience by providing 93 assertions, spies, mocks, data providers, snapshots, and more. The action simplifies the process of writing and running tests in bash projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TypedDevs/bashunit">https://github.com/TypedDevs/bashunit</a></strong> to version <strong>0.50.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-bashunit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action automates running unit tests and static analysis for bash scripts using BashUnit, a lightweight testing framework. It focuses on developer experience by providing 93 assertions, spies, mocks, data providers, snapshots, and more. The action simplifies the process of writing and running tests in bash projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-bug-fixes">🐛 Bug Fixes</h2>
<ul>
<li><code>tear_down_after_script</code> runs when <code>set_up_before_script</code> fails, so it can release file-scoped resources acquired before the failure (#1318)</li>
<li>Under <code>--parallel</code>, <code>tear_down_after_script</code> runs after the file&rsquo;s own tests instead of alongside them, so a fixture it releases stays alive for the tests that read it. The same file no longer passed sequentially and failed in parallel (#1320)</li>
<li><code>--stop-on-failure</code> runs <code>tear_down_after_script</code> for the file it halts in, so a sequential run releases what <code>set_up_before_script</code> acquired before the halt (#1321)</li>
<li><code>bashunit bench</code> runs <code>tear_down_after_script</code> before it aborts on a malformed annotation, so the file releases what <code>set_up_before_script</code> acquired (#1322)</li>
<li>Ctrl-C runs <code>tear_down_after_script</code> for the file it interrupts in a sequential run, so a file-scoped resource is released. A second Ctrl-C now ends the run even if that hook never returns (#1323)</li>
<li>A test killed by <code>--test-timeout</code> runs its <code>tear_down</code>, so a per-test resource is released. Best effort within the watchdog&rsquo;s grace before it sends SIGKILL, so a hook cannot outlive the timeout it cleans up after (#1324)</li>
<li>A test file that fails to source sweeps its script temp files, so a <code>bashunit::temp_file</code> it created at top level no longer survives the run. <code>bashunit bench</code> already did this (#1325)</li>
<li>A malformed <code>@timeout</code> or <code>@retry</code> runs <code>tear_down_after_script</code> before it aborts the run, so the file releases what <code>set_up_before_script</code> acquired. Sequential and <code>--parallel</code> both leaked it (#1329)</li>
<li>Ctrl-C releases what an interrupted <code>--parallel</code> run acquired: the file&rsquo;s <code>tear_down_after_script</code> and the <code>tear_down</code> of a test in flight. The worker that owns the file&rsquo;s hook now handles the signal and reaches its test bodies, which a kill from the parent could not (#1331)</li>
<li>A malformed <code>@timeout</code> or <code>@retry</code> fails a <code>--parallel</code> run alongside a passing file. The abort happened inside the file&rsquo;s worker and never reached the parent, so the run printed the error and still exited 0, which kept it out of CI (#1335)</li>
</ul>
<h2 id="-contributors">👥 Contributors</h2>
<ul>
<li>@aditya226-sharma</li>
<li>@Chemaclass</li>
</ul>
<h2 id="checksum">Checksum</h2>
<p>SHA256: <code>18d83d590c5304f1853dd4fe4fec4ec6effbd9fe5a21831fe9f66f70afe17d93</code></p>
<p><strong>Full Changelog:</strong> <a href="https://github.com/TypedDevs/bashunit/compare/0.50.0...0.50.1">0.50.0&hellip;0.50.1</a></p>
]]></content:encoded></item><item><title>Lachesis Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/lachesis-security-scan/</link><pubDate>Sat, 22 Aug 2026 21:51:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/lachesis-security-scan/</guid><description>Version updated for https://github.com/UnboundCompute/lachesis-action to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Lachesis is a GitHub Action that automatically analyzes your code to find missing or insufficient authorization checks in functions that lead to dangerous sinks. It builds a compiler-precise code property graph, traces untrusted input to sinks, and posts findings as inline comments on pull requests, with the severity level based on whether the function guards the sink or not. This helps developers identify potential security vulnerabilities early in the development process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/UnboundCompute/lachesis-action">https://github.com/UnboundCompute/lachesis-action</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lachesis-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Lachesis is a GitHub Action that automatically analyzes your code to find missing or insufficient authorization checks in functions that lead to dangerous sinks. It builds a compiler-precise code property graph, traces untrusted input to sinks, and posts findings as inline comments on pull requests, with the severity level based on whether the function guards the sink or not. This helps developers identify potential security vulnerabilities early in the development process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Lachesis now delivers findings as <strong>inline pull-request comments from the Lachesis GitHub App (Lachesis[bot])</strong> — the single delivery path.</p>
<ul>
<li>Findings post as <code>lachesis-security[bot]</code> PR review comments via the hosted poster, authenticated with a short-lived GitHub Actions OIDC token that proves the run&rsquo;s repository. Compute stays in your CI; only findings leave the runner.</li>
<li>Removed the <code>upload</code> and <code>branded-comments</code> inputs. Workflows now need <code>permissions: id-token: write</code> (not <code>security-events: write</code>).</li>
<li><code>report-endpoint</code> points at the hosted poster by default — no extra config.</li>
<li>Use <code>fail-on: error</code> to fail the check; add the <code>scan</code> job as a required status check to hard-block merges.</li>
<li>If the app isn&rsquo;t installed, the run surfaces a one-click install link (<a href="https://github.com/apps/lachesis-security">https://github.com/apps/lachesis-security</a>) and continues non-fatally.</li>
</ul>
<p>Install the app: <a href="https://github.com/apps/lachesis-security">https://github.com/apps/lachesis-security</a></p>
]]></content:encoded></item><item><title>Diffly PR triage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/diffly-pr-triage/</link><pubDate>Sat, 22 Aug 2026 21:49:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/diffly-pr-triage/</guid><description>Version updated for https://github.com/VIVAAN-DHAWAN/diffly-cli to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: diffly is a command-line tool that analyzes large pull requests by summarizing file changes, dependencies, tests, and risk flags. It provides a one-page Markdown report with a verdict, blast-radius map, and risk flags to help developers quickly review complex PRs before using an AI model for further analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VIVAAN-DHAWAN/diffly-cli">https://github.com/VIVAAN-DHAWAN/diffly-cli</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/diffly-pr-triage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> diffly is a command-line tool that analyzes large pull requests by summarizing file changes, dependencies, tests, and risk flags. It provides a one-page Markdown report with a verdict, blast-radius map, and risk flags to help developers quickly review complex PRs before using an AI model for further analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VIVAAN-DHAWAN/diffly-cli/compare/v0.3.0...v0.4.0">https://github.com/VIVAAN-DHAWAN/diffly-cli/compare/v0.3.0...v0.4.0</a></p>
]]></content:encoded></item><item><title>Plan9-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/plan9-vm/</link><pubDate>Sat, 22 Aug 2026 21:48:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/plan9-vm/</guid><description>Version updated for https://github.com/vmactions/plan9-vm to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of CI tasks on Plan9 systems. It supports running tests or other scripts within a Plan9 environment by leveraging AnyVM.org’s infrastructure to provide the necessary resources. The main purpose is to simplify the setup and execution of CI pipelines that require access to Plan9, allowing developers to focus on their application logic rather than managing VM configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/plan9-vm">https://github.com/vmactions/plan9-vm</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/plan9-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of CI tasks on Plan9 systems. It supports running tests or other scripts within a Plan9 environment by leveraging AnyVM.org&rsquo;s infrastructure to provide the necessary resources. The main purpose is to simplify the setup and execution of CI pipelines that require access to Plan9, allowing developers to focus on their application logic rather than managing VM configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/plan9-vm/commits/v1.0.0">https://github.com/vmactions/plan9-vm/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/b.ia-accessibility-checker/</link><pubDate>Sat, 22 Aug 2026 21:47:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows companies to define at least one audience and the percentage of WCAG guidelines they want to meet, enabling them to focus on accessibility for larger audiences. The action uses AI to analyze guidelines and reports whether the code complies with these requirements, providing feedback for developers to correct their solutions if necessary.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows companies to define at least one audience and the percentage of WCAG guidelines they want to meet, enabling them to focus on accessibility for larger audiences. The action uses AI to analyze guidelines and reports whether the code complies with these requirements, providing feedback for developers to correct their solutions if necessary.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>EcoTrace Carbon Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/ecotrace-carbon-gate/</link><pubDate>Sat, 22 Aug 2026 21:46:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/ecotrace-carbon-gate/</guid><description>Version updated for https://github.com/Zwony/ecotrace to version core-v1.5.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary EcoTrace is a lightweight Python library that provides real-time hardware-level transparency of Python applications’ carbon footprints. It automates monitoring and analysis, offering features such as cloud telemetry streaming, terminal authentication, AI-powered insights, and WebSocket live streaming. The latest version introduces expanded CPU TDP database support and enhanced compatibility with modern Python versions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zwony/ecotrace">https://github.com/Zwony/ecotrace</a></strong> to version <strong>core-v1.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ecotrace-carbon-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>EcoTrace is a lightweight Python library that provides real-time hardware-level transparency of Python applications&rsquo; carbon footprints. It automates monitoring and analysis, offering features such as cloud telemetry streaming, terminal authentication, AI-powered insights, and WebSocket live streaming. The latest version introduces expanded CPU TDP database support and enhanced compatibility with modern Python versions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="ecotrace-v151-release-notes">EcoTrace v1.5.1 Release Notes</h2>
<h3 id="overview">Overview</h3>
<p>EcoTrace v1.5.1 is a stability and telemetry compatibility patch release following v1.5.0. It resolves a Windows COM thread initialization crash in exporter background threads, restores full parameter forwarding (run_id, run_label) to CloudExporter for web dashboard filtering, standardizes exporter method signatures, and prevents eager circular imports.</p>
<h3 id="key-improvements-and-fixes-in-v151">Key Improvements and Fixes in v1.5.1</h3>
<ol>
<li>
<p><strong>Windows COM Thread Pool Initialization Guard (core.py)</strong></p>
<ul>
<li>Prevented Windows fatal exception (0x800401f0) by wrapping worker thread execution in _dispatch_exporters with CoInitialize / CoUninitialize guards on Windows.</li>
</ul>
</li>
<li>
<p><strong>Full Parameter Forwarding for CloudExporter (core.py and cloud.py)</strong></p>
<ul>
<li>Exporter dispatch now forwards run_id and run_label parameters to registered exporters, enabling dashboard session filtering.</li>
<li>Dynamic User-Agent header resolves package version dynamically.</li>
</ul>
</li>
<li>
<p><strong>Exporter Signature Consistency and Forward Compatibility</strong></p>
<ul>
<li>Added **kwargs support across CloudExporter, OTelExporter, and WebhookExporter signatures.</li>
</ul>
</li>
<li>
<p><strong>Dynamic Exporter Module Lazy Loading (exporters/<strong>init</strong>.py)</strong></p>
<ul>
<li>Implemented module-level <strong>getattr</strong> lazy loading in ecotrace.exporters to prevent circular import dependencies.</li>
</ul>
</li>
<li>
<p><strong>Logger Level Alignment (logger.py)</strong></p>
<ul>
<li>Restored logging.WARNING as default package log level across ecotrace.logger.</li>
</ul>
</li>
</ol>
<h3 id="verification-and-test-suite">Verification and Test Suite</h3>
<ul>
<li>100% test pass rate across 99 independent unit tests.</li>
<li>Verified clean Windows COM execution during thread pool metric dispatch.</li>
</ul>
]]></content:encoded></item><item><title>Rancher v2 Workload Redeploy (updated)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/rancher-v2-workload-redeploy-updated/</link><pubDate>Sat, 22 Aug 2026 14:17:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/rancher-v2-workload-redeploy-updated/</guid><description>Version updated for https://github.com/farnabaz/rancher-redeploy to version v0.6.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rancher-redeploy is a GitHub action that automates the redeployment of Kubernetes workloads using Rancher’s API. It provides a simple way to update the Docker image tag for an existing workload, without needing to delete and recreate it. This tool can help streamline development workflows by enabling quick updates to containerized applications in a Kubernetes environment managed by Rancher.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/farnabaz/rancher-redeploy">https://github.com/farnabaz/rancher-redeploy</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rancher-v2-workload-redeploy-updated">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>rancher-redeploy</code> is a GitHub action that automates the redeployment of Kubernetes workloads using Rancher&rsquo;s API. It provides a simple way to update the Docker image tag for an existing workload, without needing to delete and recreate it. This tool can help streamline development workflows by enabling quick updates to containerized applications in a Kubernetes environment managed by Rancher.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore: code style (838f342)</li>
<li>feat: bundle code (1e4185f)</li>
<li>v0.5.2 (c459253)</li>
<li>feat: use ofetch (2b31aff)</li>
<li>update (2e6ae16)</li>
<li>Update deploy.js (2e51f89)</li>
<li>0.5.0 (4a560e7)</li>
<li>removed dependencies. (0c3f40c)</li>
<li>0.4.1 (6e4a005)</li>
<li>Switched to node12 syntax, cleaned up action. (9a59315)</li>
</ul>
]]></content:encoded></item><item><title>WakaHS - Update GitHub Profile</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/wakahs-update-github-profile/</link><pubDate>Sat, 22 Aug 2026 14:16:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/wakahs-update-github-profile/</guid><description>Version updated for https://github.com/fishjump/WakaHS to version 0.2.4-dev.
This action is used across all versions by 6 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, WakaHS - Update GitHub Profile, automates the rendering and updating of a README.md file on a GitHub repository based on data from Wakatime and GitHub. It solves the problem of automatically tracking and displaying user statistics, such as weekly summaries and visitor badges, in a profile’s README.md file. The action supports custom templates, allows for different progress bar styles, and can be triggered by push events or cron jobs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fishjump/WakaHS">https://github.com/fishjump/WakaHS</a></strong> to version <strong>0.2.4-dev</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wakahs-update-github-profile">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, WakaHS - Update GitHub Profile, automates the rendering and updating of a README.md file on a GitHub repository based on data from Wakatime and GitHub. It solves the problem of automatically tracking and displaying user statistics, such as weekly summaries and visitor badges, in a profile&rsquo;s README.md file. The action supports custom templates, allows for different progress bar styles, and can be triggered by push events or cron jobs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>update(VisitorBadge): change to countapi for visitor badge for more stability (90f138d)</li>
<li>update(WeeklySummary):add 5 spaces after text hours (1db5d5d)</li>
<li>fix(visitor-badge): remove the title because frequent visit may cause this resource temporarily unavailable, in this case, no title can hide this image (d53eab2)</li>
<li>fix(action): fix image tag from merge master (e854e84)</li>
<li>fix(test): fix test case type error (fe03146)</li>
<li>feat(CodeTimeBadge): add code time badge support (fe07998)</li>
<li>fix(action): change to master, was dev because of merge (793a08a)</li>
<li>Merge pull request #7 from fishjump/dev (affc75e)</li>
<li>doc(README): add example (d12b8ae)</li>
<li>style(WeeklySummary): merge WeeklySummary data source (9f3364d)</li>
</ul>
]]></content:encoded></item><item><title>Genesis Kit Build, Test &amp; Spec Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/genesis-kit-build-test-spec-check/</link><pubDate>Sat, 22 Aug 2026 14:15:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/genesis-kit-build-test-spec-check/</guid><description>Version updated for https://github.com/fivetwenty-io/genesis-kit-test-action to version 0.0.2-a59.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the build, test, and spec checking processes for Genesis kits. It handles version management, build procedures, test execution, spec checking, deployment verification, release preparation, and supports customization through CI hooks.
What’s Changed Full Changelog: https://github.com/fivetwenty-io/genesis-kit-test-action/compare/0.0.2-a58...0.0.2-a59</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fivetwenty-io/genesis-kit-test-action">https://github.com/fivetwenty-io/genesis-kit-test-action</a></strong> to version <strong>0.0.2-a59</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/genesis-kit-build-test-spec-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the build, test, and spec checking processes for Genesis kits. It handles version management, build procedures, test execution, spec checking, deployment verification, release preparation, and supports customization through CI hooks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fivetwenty-io/genesis-kit-test-action/compare/0.0.2-a58...0.0.2-a59">https://github.com/fivetwenty-io/genesis-kit-test-action/compare/0.0.2-a58...0.0.2-a59</a></p>
]]></content:encoded></item><item><title>GHA OIDC Security Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/gha-oidc-security-auditor/</link><pubDate>Sat, 22 Aug 2026 14:14:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/gha-oidc-security-auditor/</guid><description>Version updated for https://github.com/gamesapeca/gha-oidc-auditor to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, gha-oidc-auditor, analyzes GitHub Actions workflows for vulnerabilities related to OpenID Connect (OIDC) authentication, including privilege leaks, injection sinks, unpinned dependencies, and insecure trigger combinations. It provides a deterministic static analysis tool with context-aware evaluation capabilities, offensive exploit chain synthesis, and automated least-privilege policy generation for AWS, GCP, Azure, HashiCorp Vault, and Kubernetes environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gamesapeca/gha-oidc-auditor">https://github.com/gamesapeca/gha-oidc-auditor</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gha-oidc-security-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>gha-oidc-auditor</code>, analyzes GitHub Actions workflows for vulnerabilities related to OpenID Connect (OIDC) authentication, including privilege leaks, injection sinks, unpinned dependencies, and insecure trigger combinations. It provides a deterministic static analysis tool with context-aware evaluation capabilities, offensive exploit chain synthesis, and automated least-privilege policy generation for AWS, GCP, Azure, HashiCorp Vault, and Kubernetes environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="gha-oidc-auditor-v010">gha-oidc-auditor v0.1.0</h1>
<blockquote>
<p><strong>Static Security Analyzer, Cloud Trust Policy Synthesizer, Remediation-as-Code Engine &amp; Zero-Prerequisite Exploit Chain Generator for GitHub Actions OIDC.</strong></p>
</blockquote>
<p><code>gha-oidc-auditor</code> is an application security posture management (ASPM) and cloud infrastructure entitlement management (CIEM) platform specifically engineered for GitHub Actions Workload Identity Federation / OpenID Connect (OIDC). It bridges the gap between CI/CD workflow security and cloud provider IAM configurations.</p>
<hr>
<h2 id="1-core-capabilities--architectural-pillars">1. Core Capabilities &amp; Architectural Pillars</h2>
<table>
  <thead>
      <tr>
          <th style="text-align: left">Capability</th>
          <th style="text-align: left">Scope &amp; Functionality</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td style="text-align: left"><strong>Static Security Analysis</strong></td>
          <td style="text-align: left">Deep polymorphic AST inspection of <code>.github/workflows</code> detecting supply-chain and privilege escalation flaws.</td>
      </tr>
      <tr>
          <td style="text-align: left"><strong>Offensive Exploit Chains</strong></td>
          <td style="text-align: left">Correlates triggers, missing actor gates, execution primitives, and cloud tokens into deterministic zero-prerequisite attack chains.</td>
      </tr>
      <tr>
          <td style="text-align: left"><strong>Least-Privilege Policy Synthesis</strong></td>
          <td style="text-align: left">Mathematical derivation of minimal <code>sub</code> and <code>aud</code> claims for AWS IAM, GCP WIF, Azure Entra ID, Vault, and Kubernetes.</td>
      </tr>
      <tr>
          <td style="text-align: left"><strong>Remediation-as-Code (Terraform HCL)</strong></td>
          <td style="text-align: left">Direct synthesis of production-ready <code>.tf</code> modules for AWS IAM (with July 2026 numeric ID claims), GCP WIF, and Azure.</td>
      </tr>
      <tr>
          <td style="text-align: left"><strong>Offline CIEM Trust Policy Validation</strong></td>
          <td style="text-align: left">Direct cross-audit of live cloud provider trust policies against workflow claims, detecting wildcards and scope drift.</td>
      </tr>
      <tr>
          <td style="text-align: left"><strong>Multi-Layer Cache Engine</strong></td>
          <td style="text-align: left">L1 in-memory and L2 disk cache with SHA256 invalidation for high-scale multi-repository <code>workflow_call</code> analysis.</td>
      </tr>
  </tbody>
</table>
<hr>
<h2 id="2-complete-rules-matrix-oidc-001-through-oidc-012">2. Complete Rules Matrix (OIDC-001 through OIDC-012)</h2>
<table>
  <thead>
      <tr>
          <th style="text-align: left">Rule ID</th>
          <th style="text-align: left">Severity</th>
          <th style="text-align: left">Category</th>
          <th style="text-align: left">Description</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td style="text-align: left"><code>OIDC-001</code></td>
          <td style="text-align: left">HIGH / MEDIUM</td>
          <td style="text-align: left">Overprivileged Token</td>
          <td style="text-align: left">Root-level <code>permissions: id-token: write</code> granting token minting to unisolated jobs. Severity scales with triggers.</td>
      </tr>
      <tr>
          <td style="text-align: left"><code>OIDC-002</code></td>
          <td style="text-align: left">CRITICAL / HIGH / MEDIUM</td>
          <td style="text-align: left">Execution Flow Hijacking</td>
          <td style="text-align: left"><code>pull_request_target</code> event evaluating fork code checkouts and execution primitives against actor/environment guards.</td>
      </tr>
      <tr>
          <td style="text-align: left"><code>OIDC-003</code></td>
          <td style="text-align: left">HIGH</td>
          <td style="text-align: left">Supply Chain Risk</td>
          <td style="text-align: left">Unpinned action references (<code>@v4</code>, <code>@main</code>) inside OIDC-privileged jobs allowing memory and token theft.</td>
      </tr>
      <tr>
          <td style="text-align: left"><code>OIDC-004</code></td>
          <td style="text-align: left">CRITICAL / MEDIUM</td>
          <td style="text-align: left">Command / Code Injection</td>
          <td style="text-align: left">Direct interpolation of untrusted <code>${{ }}</code> expressions in shell steps. Distinguishes external attacker payloads from internal variables across <code>bash</code>, <code>python</code>, <code>node</code>, <code>ruby</code>.</td>
      </tr>
      <tr>
          <td style="text-align: left"><code>OIDC-005</code></td>
          <td style="text-align: left">MEDIUM</td>
          <td style="text-align: left">Scope Ambiguity</td>
          <td style="text-align: left">Multi-cloud provider authentications (e.g. AWS + GCP) combined within a single unsegmented job.</td>
      </tr>
      <tr>
          <td style="text-align: left"><code>OIDC-006</code></td>
          <td style="text-align: left">CRITICAL</td>
          <td style="text-align: left">Unrestricted Trigger</td>
          <td style="text-align: left"><code>workflow_run</code> triggers without branch filters minting OIDC tokens on untrusted branch executions.</td>
      </tr>
      <tr>
          <td style="text-align: left"><code>OIDC-007</code></td>
          <td style="text-align: left">HIGH</td>
          <td style="text-align: left">Infrastructure Exposure</td>
          <td style="text-align: left">Non-ephemeral self-hosted runners executing privileged OIDC workflows on public triggers without approval gates.</td>
      </tr>
      <tr>
          <td style="text-align: left"><code>OIDC-008</code></td>
          <td style="text-align: left">HIGH</td>
          <td style="text-align: left">Credential Leakage</td>
          <td style="text-align: left">OIDC-privileged jobs delegating all caller secrets to external reusable workflows via <code>secrets: inherit</code>.</td>
      </tr>
      <tr>
          <td style="text-align: left"><code>OIDC-009</code></td>
          <td style="text-align: left">HIGH</td>
          <td style="text-align: left">Supply Chain Hardening</td>
          <td style="text-align: left">Mutable tag pinning on high-value supply-chain actions (e.g. <code>tj-actions</code>, <code>docker</code>, <code>aws-actions</code>), addressing the CVE-2025-30066 vector.</td>
      </tr>
      <tr>
          <td style="text-align: left"><code>OIDC-010</code></td>
          <td style="text-align: left">INFO</td>
          <td style="text-align: left">Future-Proof Compliance</td>
          <td style="text-align: left">Advisory check for missing July 2026 immutable numeric IDs (<code>repo:org@ID/repo@ID:*</code>) to prevent repository name-squatting risks.</td>
      </tr>
      <tr>
          <td style="text-align: left"><code>OIDC-011</code></td>
          <td style="text-align: left">CRITICAL / HIGH</td>
          <td style="text-align: left">Information Disclosure</td>
          <td style="text-align: left">Secret and OIDC token log dumping (<code>printenv</code>, <code>env -0</code>, <code>$ACTIONS_ID_TOKEN_REQUEST_TOKEN</code>) or deprecated <code>::set-output::</code> syntax.</td>
      </tr>
      <tr>
          <td style="text-align: left"><code>OIDC-012</code></td>
          <td style="text-align: left">HIGH</td>
          <td style="text-align: left">Wildcard Trust Policy</td>
          <td style="text-align: left">Cloud IAM configurations with wildcard sub-claims (<code>repo:org/*</code>), exposing organization-wide blast radius.</td>
      </tr>
  </tbody>
</table>
<hr>
<h2 id="3-offensive-exploit-chains-bug-bounty-mode">3. Offensive Exploit Chains (Bug Bounty Mode)</h2>
<p>Execute with <code>--bounty-mode --generate-poc</code> to produce submission-ready reports complete with CVSS 3.1 scoring, vulnerability classifications, reproduction steps, and deterministic cloud token exfiltration commands:</p>
<ul>
<li><strong><code>CHAIN-001</code> (Pwn-Request RCE via <code>pull_request_target</code>)</strong> <code>[CWE-94 - CVSS 9.8 Critical]</code></li>
<li><strong><code>CHAIN-002</code> (Public Trigger Shell Command Injection)</strong> <code>[CWE-78 - CVSS 9.8 Critical]</code></li>
<li><strong><code>CHAIN-003</code> (JavaScript Code Injection in <code>actions/github-script</code>)</strong> <code>[CWE-94 - CVSS 9.8 Critical]</code></li>
<li><strong><code>CHAIN-004</code> (Privilege Escalation via <code>workflow_run</code> Artifact Poisoning)</strong> <code>[CWE-494 - CVSS 9.3 Critical]</code></li>
<li><strong><code>CHAIN-005</code> (Token Write Privilege Escalation via <code>pull_request_target</code>)</strong> <code>[CWE-269 - CVSS 9.1 Critical]</code></li>
<li><strong><code>CHAIN-006</code> (Repository Secrets Exfiltration via <code>secrets: inherit</code>)</strong> <code>[CWE-522 - CVSS 8.6 High]</code></li>
<li><strong><code>CHAIN-007</code> (Runner Environment Hijacking via <code>$GITHUB_ENV</code>)</strong> <code>[CWE-78 - CVSS 9.8 Critical]</code></li>
<li><strong><code>CHAIN-008</code> (Self-Hosted Runner Infrastructure Takeover)</strong> <code>[CWE-284 - CVSS 9.8 Critical]</code></li>
</ul>
<hr>
<h2 id="4-remediation-as-code-terraform--opentofu-hcl">4. Remediation-as-Code (Terraform / OpenTofu HCL)</h2>
<p>Synthesize complete, production-ready <code>.tf</code> modules for cloud providers:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span><span style="color:#75715e"># Output Terraform HCL to stdout</span>
</span></span><span style="display:flex;"><span>gha-oidc --path .github/workflows --generate-hcl --format hcl
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Write modular .tf files directly to your infrastructure directory</span>
</span></span><span style="display:flex;"><span>gha-oidc --path .github/workflows --generate-hcl --hcl-output ./terraform/modules/gha_oidc
</span></span></code></pre></div><h3 id="generated-aws-iam-oidc-module-example-with-july-2026-immutable-format">Generated AWS IAM OIDC Module Example (with July 2026 Immutable Format):</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-hcl" data-lang="hcl"><span style="display:flex;"><span><span style="color:#66d9ef">data</span> <span style="color:#e6db74">&#34;aws_iam_policy_document&#34; &#34;my_service_gha_oidc_assume_role&#34;</span> {
</span></span><span style="display:flex;"><span>  <span style="color:#66d9ef">statement</span> {
</span></span><span style="display:flex;"><span>    effect  <span style="color:#f92672">=</span> <span style="color:#e6db74">&#34;Allow&#34;</span>
</span></span><span style="display:flex;"><span>    actions <span style="color:#f92672">=</span> [<span style="color:#e6db74">&#34;sts:AssumeRoleWithWebIdentity&#34;</span>]
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>    <span style="color:#66d9ef">principals</span> {
</span></span><span style="display:flex;"><span>      type        <span style="color:#f92672">=</span> <span style="color:#e6db74">&#34;Federated&#34;</span>
</span></span><span style="display:flex;"><span>      identifiers <span style="color:#f92672">=</span> [<span style="color:#e6db74">&#34;arn:aws:iam::123456789012:oidc-provider/token.actions.githubusercontent.com&#34;</span>]
</span></span><span style="display:flex;"><span>    }
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>    <span style="color:#66d9ef">condition</span> {
</span></span><span style="display:flex;"><span>      test     <span style="color:#f92672">=</span> <span style="color:#e6db74">&#34;StringEquals&#34;</span>
</span></span><span style="display:flex;"><span>      variable <span style="color:#f92672">=</span> <span style="color:#e6db74">&#34;token.actions.githubusercontent.com:aud&#34;</span>
</span></span><span style="display:flex;"><span>      values   <span style="color:#f92672">=</span> [<span style="color:#e6db74">&#34;sts.amazonaws.com&#34;</span>]
</span></span><span style="display:flex;"><span>    }
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>    <span style="color:#66d9ef">condition</span> {
</span></span><span style="display:flex;"><span>      test     <span style="color:#f92672">=</span> <span style="color:#e6db74">&#34;StringLike&#34;</span>
</span></span><span style="display:flex;"><span>      variable <span style="color:#f92672">=</span> <span style="color:#e6db74">&#34;token.actions.githubusercontent.com:sub&#34;</span>
</span></span><span style="display:flex;"><span>      values <span style="color:#f92672">=</span> [
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;repo:my-org/my-service:ref:refs/heads/main&#34;</span>,
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;repo:my-org@*/my-service@*:ref:refs/heads/main&#34;</span><span style="color:#75715e"> # July 2026 Immutable Numeric ID
</span></span></span><span style="display:flex;"><span>      ]
</span></span><span style="display:flex;"><span>    }
</span></span><span style="display:flex;"><span>  }
</span></span><span style="display:flex;"><span>}
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#66d9ef">resource</span> <span style="color:#e6db74">&#34;aws_iam_role&#34; &#34;my_service_gha_deploy_role&#34;</span> {
</span></span><span style="display:flex;"><span>  name               <span style="color:#f92672">=</span> <span style="color:#e6db74">&#34;my-service-gha-deploy&#34;</span>
</span></span><span style="display:flex;"><span>  assume_role_policy <span style="color:#f92672">=</span> <span style="color:#66d9ef">data</span>.<span style="color:#66d9ef">aws_iam_policy_document</span>.<span style="color:#66d9ef">my_service_gha_oidc_assume_role</span>.<span style="color:#66d9ef">json</span>
</span></span><span style="display:flex;"><span>  tags <span style="color:#f92672">=</span> {
</span></span><span style="display:flex;"><span>    ManagedBy <span style="color:#f92672">=</span> <span style="color:#e6db74">&#34;gha-oidc-auditor&#34;</span>
</span></span><span style="display:flex;"><span>    Security  <span style="color:#f92672">=</span> <span style="color:#e6db74">&#34;Least-Privilege-OIDC&#34;</span>
</span></span><span style="display:flex;"><span>  }
</span></span><span style="display:flex;"><span>}
</span></span></code></pre></div><hr>
<h2 id="5-offline-cloud-trust-policy-verification-ciem-mode">5. Offline Cloud Trust Policy Verification (CIEM Mode)</h2>
<p>Cross-audit existing live IAM trust policies against least-privilege standards:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span><span style="color:#75715e"># Verify AWS IAM Trust Relationship</span>
</span></span><span style="display:flex;"><span>gha-oidc --verify-policy aws_trust_policy.json --cloud-provider aws --repo my-org/my-service
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Verify GCP Workload Identity Pool Provider</span>
</span></span><span style="display:flex;"><span>gha-oidc --verify-policy gcp_wif_config.json --cloud-provider gcp --repo my-org/my-service
</span></span></code></pre></div><hr>
<h2 id="6-official-github-action-usage">6. Official GitHub Action Usage</h2>
<p>Integrate directly into CI/CD pipelines in 3 lines of YAML:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Run GHA OIDC Security Audit</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">gamesapeca/gha-oidc-auditor@v0.1.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">path</span>: <span style="color:#ae81ff">.github/workflows</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">critical</span>
</span></span></code></pre></div><hr>
<h2 id="7-multiplatform-standalone-binaries">7. Multiplatform Standalone Binaries</h2>
<p>Every binary is cross-compiled with stripped debug symbols and verified via <code>checksums.txt</code> (SHA256):</p>
<ul>
<li><code>gha-oidc-linux-amd64</code> (Linux 64-bit x86)</li>
<li><code>gha-oidc-linux-arm64</code> (Linux 64-bit ARM)</li>
<li><code>gha-oidc-darwin-amd64</code> (macOS Intel)</li>
<li><code>gha-oidc-darwin-arm64</code> (macOS Apple Silicon)</li>
<li><code>gha-oidc-windows-amd64.exe</code> (Windows 64-bit)</li>
<li><code>checksums.txt</code> (Cryptographic verification file)</li>
</ul>
]]></content:encoded></item><item><title>Setup MySQL with Python 2.7</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/setup-mysql-with-python-2.7/</link><pubDate>Sat, 22 Aug 2026 14:12:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/setup-mysql-with-python-2.7/</guid><description>Version updated for https://github.com/griffinkelly/mysql-python to version v1.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action sets up a MySQL database in Docker, allowing for various configurations such as character set and collation. It supports specific versions of MySQL and can be used to automate tasks involving MySQL operations. The action is limited by Github Actions’s support for Linux environments and requires users to shut down the Default MySQL before setting it up if using port 3306.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/griffinkelly/mysql-python">https://github.com/griffinkelly/mysql-python</a></strong> to version <strong>v1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-mysql-with-python-2-7">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action sets up a MySQL database in Docker, allowing for various configurations such as character set and collation. It supports specific versions of MySQL and can be used to automate tasks involving MySQL operations. The action is limited by Github Actions&rsquo;s support for Linux environments and requires users to shut down the Default MySQL before setting it up if using port 3306.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update document (de1fba8)</li>
<li>Supports more options (73a5ef7)</li>
<li>Add docker configurations (9e1c6ff)</li>
<li>Initial commit (60f8cfb)</li>
</ul>
]]></content:encoded></item><item><title>jk-neospec</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/jk-neospec/</link><pubDate>Sat, 22 Aug 2026 14:11:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/jk-neospec/</guid><description>Version updated for https://github.com/jedi-knights/neospec to version v0.17.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary neospec is a CI tool that automates Lua testing in Neovim projects by downloading, running, and providing coverage reports of Lua tests. It simplifies the process of setting up and managing Neovim environments, ensuring consistent test execution across different versions and provides comprehensive coverage metrics for your tests, helping project maintainers ensure their code is thoroughly tested.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jedi-knights/neospec">https://github.com/jedi-knights/neospec</a></strong> to version <strong>v0.17.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jk-neospec">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong><code>neospec</code> is a CI tool that automates Lua testing in Neovim projects by downloading, running, and providing coverage reports of Lua tests. It simplifies the process of setting up and managing Neovim environments, ensuring consistent test execution across different versions and provides comprehensive coverage metrics for your tests, helping project maintainers ensure their code is thoroughly tested.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/neurolink-ai/</link><pubDate>Sat, 22 Aug 2026 14:10:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v11.15.5.
This action is used across all versions by 11 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that unifies 30+ AI providers and 100+ models under one consistent API. It provides a TypeScript-first way to integrate AI into any application with features such as single provider changes, built-in tools, enterprise features like Redis memory and multi-provider failover, and intelligent routing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v11.15.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is a universal AI integration platform that unifies 30+ AI providers and 100+ models under one consistent API. It provides a TypeScript-first way to integrate AI into any application with features such as single provider changes, built-in tools, enterprise features like Redis memory and multi-provider failover, and intelligent routing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="11155-2026-08-22"><a href="https://github.com/juspay/neurolink/compare/v11.15.4...v11.15.5">11.15.5</a> (2026-08-22)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(deps):</strong>  raise the fast-uri override past the 3.x advisories (<a href="https://github.com/juspay/neurolink/commit/aec7f8acb37d92c37254598e0c214dec077dda66">aec7f8a</a>)</li>
</ul>
]]></content:encoded></item><item><title>ShipProof production gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/shipproof-production-gate/</link><pubDate>Sat, 22 Aug 2026 14:09:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/shipproof-production-gate/</guid><description>Version updated for https://github.com/kingggg5/shipproof to version v0.8.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ShipProof automates production evidence gates for AI-assisted software by scanning source code without executing it, evaluating CPU/RAM/latency budgets, and reporting findings through terminal output or SARIF format. It helps ensure the security, correctness, scale, performance, and release evidence of a project.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kingggg5/shipproof">https://github.com/kingggg5/shipproof</a></strong> to version <strong>v0.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shipproof-production-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ShipProof automates production evidence gates for AI-assisted software by scanning source code without executing it, evaluating CPU/RAM/latency budgets, and reporting findings through terminal output or SARIF format. It helps ensure the security, correctness, scale, performance, and release evidence of a project.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="shipproof-v080--cross-file-taint-framework-confidence-parallel-scans-and-fair-benchmarks">ShipProof v0.8.0 — Cross-File Taint, Framework Confidence, Parallel Scans, and Fair Benchmarks</h1>
<p>ShipProof v0.8.0 turns the analysis depth, throughput, and evaluation story of the production gate up a level while keeping every workflow offline, deterministic, and dependency-free. The executable scanner now contains 575 rules; the research catalogs remain explicitly non-executable until their precision fixtures pass.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Opt-in cross-file taint analysis:</strong> <code>shipproof scan . --cross-file</code> (also on the MCP <code>shipproof_scan</code> tool) promotes unsanitized interprocedural flows — route entrypoints through helpers into SQL, command-execution, and eval sinks — into <code>L2</code> findings on the sink line with call-chain evidence, reusing the offline impact-graph analyzer. Flow totals and unsanitized counts are reported in JSON.</li>
<li><strong>Four evidence-gated framework rules:</strong> <code>SP662</code> Django wildcard CORS, <code>SP663</code> Django non-secure session cookies, <code>SP664</code> FastAPI routes without visible rate limiting, and <code>SP665</code> Django <code>DEBUG</code> in deployable settings. Each ships with positive/negative/adversarial fixtures, two-source primary grounding, false-positive analysis, and both README tables; the hardened demo fixture demonstrates SP664 remediation with a real token-bucket limiter.</li>
<li><strong>Framework-aware confidence:</strong> structural framework rules keep their default confidence only when repository manifests declare the framework; present-but-undeclared frameworks downgrade confidence one level instead of suppressing, and manifest-less repositories keep full confidence.</li>
<li><strong>Deterministic parallel scanning:</strong> <code>--jobs N</code> scans files across worker processes with byte-identical output, enforced by a jobs=1 versus jobs=4 parity test, and falls back to sequential execution when process pools are unavailable.</li>
<li><strong>Fair, offline head-to-head benchmarking:</strong> <code>benchmarks/head_to_head.py</code> measures any scanner against ShipProof on identical local corpora — median end-to-end wall time plus file-level precision/recall/F1 against a shared label file. Third-party tools run only with caller-supplied rule files; ShipProof bundles, downloads, and copies no third-party rules.</li>
<li><strong>Faster, more precise engine:</strong> quadratic <code>SP577</code>/<code>SP579</code> windows are bounded to their reporting span and a sound literal-gate prefilter (validated over 370 million rule/line checks with zero false skips) skips rules whose required literals are absent, cutting full-repository scans by roughly 48%; same-line collisions now keep the strongest proof level, docstring examples stop triggering non-secret rules, placeholder filtering targets the credential value (un-breaking <code>SP004</code>), entropy calibration covers <code>SP004</code>/<code>SP019</code>–<code>SP021</code>, and the AST engine detects concatenated and base64-encoded credentials.</li>
<li><strong>Exit-code contract, end to end:</strong> scanner crashes (including <code>RecursionError</code> and raw Windows NTSTATUS statuses) exit <code>2</code> as invalid evidence instead of masquerading as gate blocks; gate timeouts and buffer overflows report actionable errors with <code>SHIPPROOF_GATE_TIMEOUT_MS</code> / <code>SHIPPROOF_MAX_BUFFER_BYTES</code> overrides.</li>
<li><strong>Suppression integrity:</strong> <code>shipproof-ignore</code> markers are honored only inside comments (never string literals), accept multiple rule IDs at once, and bind the Python AST engine as well as the regex engine. Every credential rule that redacts evidence now receives placeholder filtering, comment scanning, and document scanning.</li>
<li><strong>Precise locations:</strong> findings carry <code>column</code>, <code>end_line</code>, and <code>end_column</code>; SARIF regions and GitHub annotations use them, with sanitized annotation messages.</li>
<li><strong>Quieter Node layer:</strong> one cached Python runtime probe per process across CLI, Action, and MCP; configurable MCP timeout (<code>SHIPPROOF_MCP_TIMEOUT_MS</code>) and optional result cache (<code>SHIPPROOF_MCP_CACHE_MS</code>); <code>shipproof_scan</code> accepts <code>exclude</code>, <code>min_confidence</code>, and <code>cross_file</code>; snippets are byte-limited to match the Python scanner; zod schemas are zod-4 compatible; policy limits are unified with the Action and MCP; evidence reports classify diagnostics into <code>severity_counts</code>; Action step summaries escape table cells and cap rendered rows; and the README documents SARIF upload for Code Scanning.</li>
</ul>
<h2 id="compatibility">Compatibility</h2>
<ul>
<li>Node.js 20 or newer for the CLI and adapters.</li>
<li>Python 3.10 or newer for scanning and Python-backed gates.</li>
<li>Policy version <code>1</code> and evidence schema version <code>1.0</code> remain compatible; scan reports add optional <code>column</code>, <code>end_line</code>, <code>end_column</code>, and <code>cross_file_flows_unsanitized</code> fields (additive, schema-versioned).</li>
<li><code>--jobs 1</code> (default) and opt-out of <code>--cross-file</code> preserve prior behavior exactly.</li>
<li>Exit codes remain <code>0</code> for pass, <code>1</code> for a measured gate failure, and <code>2</code> for invalid or unavailable evidence.</li>
</ul>
<h2 id="verification">Verification</h2>
<p>The release commit must pass <code>npm run check</code>, packed-artifact smoke testing, and a direct repository self-scan at the high threshold before the exact <code>v0.8.0</code> tag is created.</p>
]]></content:encoded></item><item><title>DeepSeek Harness for GitHub</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/deepseek-harness-for-github/</link><pubDate>Sat, 22 Aug 2026 14:08:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/deepseek-harness-for-github/</guid><description>Version updated for https://github.com/Lixiaoyiao/deepseek-harness-action to version v0.5.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The DeepSeek Harness GitHub Action automates the process of reviewing code changes from pull requests, issues, and failed CI jobs using the DeepSeek code review tool. It helps improve code quality by diagnosing issues in automated tests and providing inline reviews, facilitating faster feedback cycles and improving collaboration among developers. The action can be integrated into GitHub workflows to ensure consistent and effective code reviews across projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lixiaoyiao/deepseek-harness-action">https://github.com/Lixiaoyiao/deepseek-harness-action</a></strong> to version <strong>v0.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deepseek-harness-for-github">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The DeepSeek Harness GitHub Action automates the process of reviewing code changes from pull requests, issues, and failed CI jobs using the DeepSeek code review tool. It helps improve code quality by diagnosing issues in automated tests and providing inline reviews, facilitating faster feedback cycles and improving collaboration among developers. The action can be integrated into GitHub workflows to ensure consistent and effective code reviews across projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Adapted the action to the complete, ordinarily installable DeepSeek Harness <code>0.1.1-rc.2</code> package family. All directly used DSH packages and the lockfile remain exact-pinned; no peer-dependency bypass or mixed release family is used.</li>
<li>Split runtime installation, process execution, network policy, Docker policy, receipts, deadlines, orchestration context/write flow, and Validation Integrity analysis into focused modules while preserving the public action contract.</li>
<li>Added bounded runtime-install, extension-install, Agent-turn, validation, lifecycle-hook, cleanup, and cancellation-finalization phases under the overall run deadline.</li>
<li>Added best-effort SIGINT/SIGTERM terminal sticky-comment finalization. A runner hard kill, host loss, or network outage can still prevent the final update; the Actions conclusion remains authoritative.</li>
<li>Hardened validation repair semantics so blocked, exhausted, or malformed repair output cannot erase an unresolved Controller validation or Validation Integrity failure.</li>
<li>Tightened run-scoped HOME, npm cache, runtime, extension, receipt, session, temporary-directory, and Docker cleanup boundaries.</li>
</ul>
<h2 id="security-boundaries">Security boundaries</h2>
<ul>
<li>The Agent receives neither the real <code>GITHUB_TOKEN</code> nor the real DeepSeek key.</li>
<li>GitHub mutation remains Controller-only; read-only and trusted-write paths keep separate capability boundaries.</li>
<li>Workspaces remain <code>.git</code>-less inside the Agent container, Docker images and action dependencies remain immutable-pinned, and extension lock/inventory plus actor/fork/origin/SHA/protected-path checks remain enforced.</li>
<li>ToolRuntime guards individual tool calls; it does <strong>not</strong> sandbox approved Plugin, Bundle, or stdio MCP startup/background side effects.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li>Final candidate CI: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32557272928">run 32557272928</a></li>
<li>Core real E2E: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32557354220">run 32557354220</a></li>
<li>Merged-main CI: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32557657946">run 32557657946</a></li>
</ul>
<p>The real E2E suite covers strict/Profile/official Bundle, standard Bash, mediated Web Search, native subagent, MCP allow/deny and receipts, Validation Integrity and ordinary validation failures without GitHub mutation, no-change write, trusted-write PR creation/verification/cleanup, credential-free checkout, and graceful cancellation finalization.</p>
<p>See <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/blob/v0.5.1/CHANGELOG.md">CHANGELOG.md</a> for the complete change list.</p>
]]></content:encoded></item><item><title>SF Cat</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/sf-cat/</link><pubDate>Sat, 22 Aug 2026 14:07:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/sf-cat/</guid><description>Version updated for https://github.com/mcarvin8/sf-cat to version v2.1.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action sf-cat converts Salesforce Code Analyzer output into formats suitable for various code quality platforms, including SonarQube, GitHub Code Scanning, and Azure DevOps. It simplifies integration by eliminating the need to install the Salesforce CLI or plugin separately, making it accessible to GitHub Actions users. The action supports multiple output formats and allows for customization of file paths and failure conditions based on severity levels.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcarvin8/sf-cat">https://github.com/mcarvin8/sf-cat</a></strong> to version <strong>v2.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sf-cat">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>sf-cat</code> converts Salesforce Code Analyzer output into formats suitable for various code quality platforms, including SonarQube, GitHub Code Scanning, and Azure DevOps. It simplifies integration by eliminating the need to install the Salesforce CLI or plugin separately, making it accessible to GitHub Actions users. The action supports multiple output formats and allows for customization of file paths and failure conditions based on severity levels.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="211-2026-08-22"><a href="https://github.com/mcarvin8/sf-cat/compare/v2.1.0...v2.1.1">2.1.1</a> (2026-08-22)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>actions:</strong> shorten action description (<a href="https://github.com/mcarvin8/sf-cat/commit/a3ace47cfb3820cba263b1cf76ffd32186821c35">a3ace47</a>)</li>
</ul>
]]></content:encoded></item><item><title>Unwrap Markdown prose</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/unwrap-markdown-prose/</link><pubDate>Sat, 22 Aug 2026 14:05:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/unwrap-markdown-prose/</guid><description>Version updated for https://github.com/michen00/markdown-prose-hooks to version v0.1.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The markdown-prose-hooks action automates the removal of manual soft-wrap line breaks from Markdown prose, resulting in cleaner diffs. It provides a pre-commit hook and GitHub Action that ensures paragraphs are one line each, simplifying text management and reducing redundancy in code reviews. The tool supports both Python and Rust implementations, with version tags ensuring compatibility across different platforms and versions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/michen00/markdown-prose-hooks">https://github.com/michen00/markdown-prose-hooks</a></strong> to version <strong>v0.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/unwrap-markdown-prose">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>The markdown-prose-hooks action automates the removal of manual soft-wrap line breaks from Markdown prose, resulting in cleaner diffs. It provides a pre-commit hook and GitHub Action that ensures paragraphs are one line each, simplifying text management and reducing redundancy in code reviews. The tool supports both Python and Rust implementations, with version tags ensuring compatibility across different platforms and versions.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/michen00/markdown-prose-hooks/compare/v0.1.2...v0.1.3">https://github.com/michen00/markdown-prose-hooks/compare/v0.1.2...v0.1.3</a></p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/totem-shield/</link><pubDate>Sat, 22 Aug 2026 14:04:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.119.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is designed to enforce coding conventions and best practices by maintaining a knowledge index derived from markdown lessons. It prevents LLMs from modifying the permanent state of the repository, ensuring code consistency across team members. The action provides deterministic linting rules based on these lessons, making it easier for reviewers to catch common mistakes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.119.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is designed to enforce coding conventions and best practices by maintaining a knowledge index derived from markdown lessons. It prevents LLMs from modifying the permanent state of the repository, ensuring code consistency across team members. The action provides deterministic linting rules based on these lessons, making it easier for reviewers to catch common mistakes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>LinkML (linkml-scala)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/linkml-linkml-scala/</link><pubDate>Sat, 22 Aug 2026 14:03:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/linkml-linkml-scala/</guid><description>Version updated for https://github.com/NeverBlink-OSS/linkml-scala-action to version v0.14.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates LinkML schema validation and generation using Node.js. It supports running on various platforms and provides inline annotations to help developers identify issues directly in their pull requests. The action can validate or generate JSON Schema, SHACL, RDFS, LinkML, Table Schema, GraphQL, or Scala from LinkML schemas, with options for strictness and additional configurations such as imports and open shapes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NeverBlink-OSS/linkml-scala-action">https://github.com/NeverBlink-OSS/linkml-scala-action</a></strong> to version <strong>v0.14.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/linkml-linkml-scala">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates LinkML schema validation and generation using Node.js. It supports running on various platforms and provides inline annotations to help developers identify issues directly in their pull requests. The action can validate or generate JSON Schema, SHACL, RDFS, LinkML, Table Schema, GraphQL, or Scala from LinkML schemas, with options for strictness and additional configurations such as imports and open shapes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Tracks <a href="https://github.com/NeverBlink-OSS/linkml-scala/releases/tag/v0.14.0">linkml-scala v0.14.0</a>.</p>
<p>Bundles <code>@neverblink/linkml@0.14.0</code>.</p>
<ul>
<li>Pin <code>uses: NeverBlink-OSS/linkml-scala-action@v0.14.0</code> for reproducibility.</li>
<li>Pin <code>@v1</code> for automatic patch/minor updates.</li>
</ul>
]]></content:encoded></item><item><title>Nox Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/nox-security-scanner/</link><pubDate>Sat, 22 Aug 2026 14:02:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/nox-security-scanner/</guid><description>Version updated for https://github.com/Nox-HQ/nox to version v1.29.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Nox action is an open-source, offline-first security scanner designed for AI application developers. It detects various vulnerabilities such as prompt injection, embedding leakage, agent over-privilege, and slopsquatting in their code without relying on external APIs or SaaS services. The tool provides comprehensive coverage of OWASP top 10 vulnerabilities and maps them to the OWASP MCP Top 10 for server hardening and tool poisoning.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nox-HQ/nox">https://github.com/Nox-HQ/nox</a></strong> to version <strong>v1.29.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nox-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Nox action is an open-source, offline-first security scanner designed for AI application developers. It detects various vulnerabilities such as prompt injection, embedding leakage, agent over-privilege, and slopsquatting in their code without relying on external APIs or SaaS services. The tool provides comprehensive coverage of OWASP top 10 vulnerabilities and maps them to the OWASP MCP Top 10 for server hardening and tool poisoning.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="nox-v1291-2026-08-22t085238z">Nox v1.29.1 (2026-08-22T08:52:38Z)</h2>
<p>Language-agnostic security scanner with first-class AI application security.</p>
<h3 id="installation">Installation</h3>
<h4 id="macoslinux-homebrew">macOS/Linux (Homebrew)</h4>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap felixgeelhaar/tap
</span></span><span style="display:flex;"><span>brew install nox
</span></span></code></pre></div><h4 id="direct-download">Direct Download</h4>
<p>Download the appropriate archive for your platform from the assets below.</p>
<h3 id="whats-changed-1">What&rsquo;s Changed</h3>
<h2 id="changelog">Changelog</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>aafdb3d44b54eb97d88ac5e548a3542cbf87a091 fix(fix): apply each upgrade in its own manifest&rsquo;s directory (#464)</li>
<li>88dc1146d33048a947633d2fec5757f2364b3ad3 fix(policy): a failing gate names the finding that failed it (#463)</li>
</ul>
<h3 id="others">Others</h3>
<ul>
<li>4756ef30c46cb54f3aa6dbb478454ae4761e9f12 chore(deps): bump go.klarlabs.de/mcp from 1.24.0 to 1.24.1 (#457)</li>
<li>e4d944230af69807d9836c35eb9f22c7d269e719 chore(deps): bump google.golang.org/protobuf from 1.36.11 to 1.36.12 (#459)</li>
<li>1d4eb9fdc46b613506fe285792fac7bbc91848cf chore(security): nox remediation (deps + actions) (#462)</li>
<li>432259d18ae874a861c7a51e9e42ba8fc46ae604 docs(changelog): 1.29.1 — remediations that actually remediate (#465)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nox-hq/nox/compare/v1.29.0...v1.29.1">https://github.com/nox-hq/nox/compare/v1.29.0...v1.29.1</a></p>
]]></content:encoded></item><item><title>Changelog Bot Runner Nyaomaru</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/changelog-bot-runner-nyaomaru/</link><pubDate>Sat, 22 Aug 2026 14:00:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/changelog-bot-runner-nyaomaru/</guid><description>Version updated for https://github.com/nyaomaru/changelog-bot to version v0.6.11.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, changelog-bot, automates the creation of a polished changelog entry from Git history and release notes. It combines commit messages, PR titles, and release notes into clear sections, integrates with OpenAI or Anthropic for tone-aware summaries (or uses a heuristic fallback if AI is down), can open a pull request with updated changelogs, and provides safe defaults to avoid common pitfalls like duplicate versions and failed releases due to AI errors.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nyaomaru/changelog-bot">https://github.com/nyaomaru/changelog-bot</a></strong> to version <strong>v0.6.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/changelog-bot-runner-nyaomaru">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, changelog-bot, automates the creation of a polished changelog entry from Git history and release notes. It combines commit messages, PR titles, and release notes into clear sections, integrates with OpenAI or Anthropic for tone-aware summaries (or uses a heuristic fallback if AI is down), can open a pull request with updated changelogs, and provides safe defaults to avoid common pitfalls like duplicate versions and failed releases due to AI errors.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(changelog): 0.6.10 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/180">https://github.com/nyaomaru/changelog-bot/pull/180</a></li>
<li>refactor: standardize runtime type guards with is-kit by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/181">https://github.com/nyaomaru/changelog-bot/pull/181</a></li>
<li>Release: 0.6.11 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/182">https://github.com/nyaomaru/changelog-bot/pull/182</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nyaomaru/changelog-bot/compare/v0.6.10...v0.6.11">https://github.com/nyaomaru/changelog-bot/compare/v0.6.10...v0.6.11</a></p>
]]></content:encoded></item><item><title>Harness Score</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/harness-score/</link><pubDate>Sat, 22 Aug 2026 13:59:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/harness-score/</guid><description>Version updated for https://github.com/paladini/harness-score to version v1.6.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Harness Score measures the reliability and robustness of AI coding harnesses across various tools. It provides a detailed maturity level, breakdown of points across six dimensions, and specific suggestions for improvement. The action automates the process of analyzing any repository using AI coding tools, ensuring consistent quality assurance without relying on large LLMs or internet access.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/paladini/harness-score">https://github.com/paladini/harness-score</a></strong> to version <strong>v1.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harness-score">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Harness Score measures the reliability and robustness of AI coding harnesses across various tools. It provides a detailed maturity level, breakdown of points across six dimensions, and specific suggestions for improvement. The action automates the process of analyzing any repository using AI coding tools, ensuring consistent quality assurance without relying on large LLMs or internet access.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixed">Fixed</h2>
<ul>
<li>Detect non-GitHub CI configuration files at any depth below the scan root, including Jenkins, GitLab CI, Azure Pipelines, CircleCI, and Bitbucket Pipelines.</li>
<li>Preserve stable evidence ordering and de-duplicate overlapping CI matcher results.</li>
<li>Document the filesystem-based detection semantics across all guide locales.</li>
</ul>
<h2 id="contributors">Contributors</h2>
<p>Thanks to <a href="https://github.com/felipecontratres-gupy">@felipecontratres-gupy</a> for reporting #54 and contributing the initial fix in #55.</p>
<p>Thanks to <a href="https://github.com/dbtorrico">@dbtorrico</a> for catching the guide locale parity gap and providing translation suggestions.</p>
<p>This release resolves #54.</p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/kaniko-build-action/</link><pubDate>Sat, 22 Aug 2026 13:58:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, “Hello world docker action,” is designed to print a greeting message to the log. It allows users to specify the name of a person to greet and includes an option for customizing the greeting message. The key capabilities it provides are input configuration and output logging, making it useful for simple automation tasks involving greetings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, &ldquo;Hello world docker action,&rdquo; is designed to print a greeting message to the log. It allows users to specify the name of a person to greet and includes an option for customizing the greeting message. The key capabilities it provides are input configuration and output logging, making it useful for simple automation tasks involving greetings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/agentauditkit-mcp-security-scan/</link><pubDate>Sat, 22 Aug 2026 13:57:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.87.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit automates the security audit of AI agent pipelines, focusing on identifying misconfigurations, hardcoded secrets, tool poisoning, and trust boundary violations across 10 agent platforms. It provides a fully offline and deterministically run scan to avoid model inference and network calls, ensuring consistent findings with zero variance across multiple runs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.87</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit automates the security audit of AI agent pipelines, focusing on identifying misconfigurations, hardcoded secrets, tool poisoning, and trust boundary violations across 10 agent platforms. It provides a fully offline and deterministically run scan to avoid model inference and network calls, ensuring consistent findings with zero variance across multiple runs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.87
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.87
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.87</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.86...v0.3.87">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.86...v0.3.87</a></p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/smyklot/</link><pubDate>Sat, 22 Aug 2026 13:56:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.45.1.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by using the CODEOWNERS file to control permissions. It supports multiple command formats including slash commands, mentions, and bare commands. The action can handle various merge methods, provide feedback with emojis, and automatically removes reactions when they are removed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.45.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by using the CODEOWNERS file to control permissions. It supports multiple command formats including slash commands, mentions, and bare commands. The action can handle various merge methods, provide feedback with emojis, and automatically removes reactions when they are removed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1451-2026-08-22"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.45.0...v1.45.1">1.45.1</a> (2026-08-22)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>panel:</strong> real avatars, fleet-proof sync strips, unclipped empty states (<a href="https://github.com/smykla-skalski/smyklot/issues/297">#297</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/563e6ef4ab1fccf2b2fe34cbb404d707b41edc7d">563e6ef</a>)</li>
</ul>
<h2 id="smyklot-v1451">Smyklot v1.45.1</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.45.1</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>3333c248f02d9658b739537d64eb05fb31a54511 chore(release): bump version to 1.45.1</li>
<li>563e6ef4ab1fccf2b2fe34cbb404d707b41edc7d fix(panel): real avatars, fleet-proof sync strips, unclipped empty states (#297)</li>
<li>1347e99cffcff65b67f1707521728cfa6b836800 ci(codeql): switch to an advanced-setup workflow (#295)</li>
<li>617c415518f0103b29846ff5a53c727c79b11030 test(panel): give the phone sweep its starting gun (#296)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sat, 22 Aug 2026 13:55:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by bundling dependencies and committing the built assets to the repository. It simplifies the process of preparing an application for deployment in a distributed container orchestration environment, ensuring all necessary files are included before pushing to the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by bundling dependencies and committing the built assets to the repository. It simplifies the process of preparing an application for deployment in a distributed container orchestration environment, ensuring all necessary files are included before pushing to the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/wails3-build-action/</link><pubDate>Sat, 22 Aug 2026 13:55:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub action builds Wails.io projects by installing GoLang and NodeJS, compiling the project, and optionally uploading the results to GitHub or a release on tag. It provides options to customize Go version, Wails version, build name, platform, obfuscation, caching, and package upload settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub action builds Wails.io projects by installing GoLang and NodeJS, compiling the project, and optionally uploading the results to GitHub or a release on tag. It provides options to customize Go version, Wails version, build name, platform, obfuscation, caching, and package upload settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>trustmcp scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/trustmcp-scan/</link><pubDate>Sat, 22 Aug 2026 13:54:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/trustmcp-scan/</guid><description>Version updated for https://github.com/v0idw4lker/trustmcp to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, trustmcp, is a security scanner designed to identify vulnerabilities in MCP (Model Context Protocol) servers, primarily AI agents such as Claude and ChatGPT. It provides a native SARIF report for integration into the GitHub Security tab, offering both static scans of source code and dynamic analysis of running servers. The action can scan static code or both static and live dynamic content from running servers, with options to customize scanning modes, targets, and output formats.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/v0idw4lker/trustmcp">https://github.com/v0idw4lker/trustmcp</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/trustmcp-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>trustmcp</code>, is a security scanner designed to identify vulnerabilities in MCP (Model Context Protocol) servers, primarily AI agents such as Claude and ChatGPT. It provides a native SARIF report for integration into the GitHub Security tab, offering both static scans of source code and dynamic analysis of running servers. The action can scan static code or both static and live dynamic content from running servers, with options to customize scanning modes, targets, and output formats.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>New: <code>trustmcp check &lt;reference&gt;</code> scans an MCP server from npm/PyPI/GitHub/server.json
before you install it — never executes anything from the downloaded package.</p>
<p>Also: three new detection rules (tool-description injection, JWT/credential secrets,
runtime description mutation) raising DVMCP canonical detection from 3/10 to 6/10.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/v0idw4lker/trustmcp/compare/v0.1.2...v0.2.0">https://github.com/v0idw4lker/trustmcp/compare/v0.1.2...v0.2.0</a></p>
]]></content:encoded></item><item><title>Vaara Policy Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/vaara-policy-check/</link><pubDate>Sat, 22 Aug 2026 13:52:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/vaara-policy-check/</guid><description>Version updated for https://github.com/vaaraio/vaara to version v1.75.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Vaara is an autonomous action auditing tool designed to provide verifiable receipts for every autonomous action. It helps in automating tasks such as fund transfers, file writing, and calling tools while ensuring that these actions are risk-scored and authorized against predefined policies. Vaara provides features like a CLI, macOS menu-bar app, TypeScript client, and a Python interface to manage and verify autonomous actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaaraio/vaara">https://github.com/vaaraio/vaara</a></strong> to version <strong>v1.75.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vaara-policy-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Vaara is an autonomous action auditing tool designed to provide verifiable receipts for every autonomous action. It helps in automating tasks such as fund transfers, file writing, and calling tools while ensuring that these actions are risk-scored and authorized against predefined policies. Vaara provides features like a CLI, macOS menu-bar app, TypeScript client, and a Python interface to manage and verify autonomous actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1750---2026-08-22">[1.75.0] - 2026-08-22</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p>The Vaara Conformance Results terms said the maintainer cannot remove a row because rows are chained. A chain makes a break detectable to someone holding an earlier head. It does not make removal impossible when one operator controls both the file and the published page, who could rewrite the chain and republish it consistently. The claim was wrong, and it sat in the consent form a party agrees through, which is worse than sitting in marketing. Iman Schrock raised it on the SCITT list on 2026-08-21 before filing a row, and he was right to hold it.</p>
<p>The wording on the page, in <code>conformance/reproductions.json</code> and in the issue form now says what a chain gives, and states the residual: a row added after the last witnessing carries only the chain until the next head is published. <code>terms_version</code> is bumped to <code>2026-08-21</code>; the row already listed keeps the terms it agreed to.</p>
</li>
<li>
<p>A Windows clone made the SEP-2828 conformance corpus read as a disagreement with the spec. Git for Windows installs with <code>core.autocrlf=true</code>, which rewrites LF to CRLF on checkout. The corpus is pinned byte for byte, so all 32 file digests and the <code>corpusDigest</code> fail while no content changes at all. <code>vaara conformance-statement</code> called that NON-CONFORMING, and the <code>conformance_statement_v0</code> suite reported 0 of 5 scenarios matching, which reads as the implementation contradicting the published corpus. It is a checkout artefact and says nothing about conformance. Emek Can Dogru found it on 2026-08-21, before it reached a row.</p>
<p>Corpus integrity is now graded as the precondition it is. It asks whether the published byte set is present, not whether an implementation agrees with SEP-2828, so a corpus that does not verify grades <code>unproved</code> rather than <code>false</code>. It still gates: only <code>proved</code> yields CONFORMS, so a corpus that does not verify can never produce a pass. A mismatched file is re-hashed with the line-ending translation undone, which proves whether its content is the published content, and the cause is named instead of printing 32 bare digest mismatches. The <code>conformance_statement_v0</code> suite exits 77 (SKIP) with that reason rather than failing, because it cannot compare goldens against a corpus that is not the published one. Only a difference that is provably newlines-only goes quiet; real tampering still fails loudly.</p>
<p>Statement <code>schemaVersion</code> is 3, adding <code>corpus.lineEndingMismatches</code> and <code>corpus.lineEndingsOnly</code>. The verdict for a byte-exact corpus is unchanged.</p>
</li>
<li>
<p>The conformance desk went red on every rejected submission. A rejection leaves the row output empty, and Actions expands a step&rsquo;s <code>env</code> block before it applies the step&rsquo;s <code>if</code>, so <code>fromJSON('')</code> failed the whole workflow template. The submitter still got their comment, which is posted earlier, but the run failed and the steps after it never ran. Emek Can Dogru&rsquo;s issue #612 is the one that surfaced it.</p>
</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li>
<p>Every conformance row now names what kind of run it was. What a run establishes is a property of who wrote the verifier and who wrote the vectors, not of how well it went, and the three kinds are not degrees of one another. A reproduction is the author&rsquo;s checkers over the author&rsquo;s vectors, and establishes that the artefact runs and is byte-stable somewhere other than the author&rsquo;s machine. An independent implementation from the text, run against the author&rsquo;s vectors, establishes something about the text, because a second reader had to decide what the sentences meant. An independent implementation run against independently constructed vectors establishes something about both.</p>
<p>A row that does not name its kind reads as the first, because that is the weakest claim available. Rows listed before the field existed carry no kind and are never edited to add one, so the page states the rule rather than backfilling them. The row stores a stable key rather than the form&rsquo;s prose, so rewording the dropdown cannot restate what a published row claimed. <code>terms_version</code> is bumped to <code>2026-08-22</code>; rows already listed keep the terms they agreed to.</p>
<p>Joel Hillier proposed this on the SCITT list on 2026-08-21, after Iman Schrock scoped his own row that way with nobody asking him to and Emek Can Dogru filed one carrying it. The loss it prevents happens where a result gets filed: a row outlives the message that explains it, and a register that cannot tell a reproduction from an independent implementation gets cited for the second while holding the first, by someone who is not lying.</p>
</li>
<li>
<p>A root <code>.gitattributes</code>. The byte-pinned corpus and its goldens are checked out verbatim on every platform, and the rest of the tree normalises to LF, so a fresh clone on Windows holds the published bytes.</p>
</li>
<li>
<p><code>scripts/vcr_publish_head.py</code> records the current chain head in a public transparency log the maintainer does not operate, so a rewritten chain reaches a head that matches no witnessed entry. It publishes one digest and a signature over it, nothing else, and prints what leaves the machine before it does anything.</p>
</li>
<li>
<p><code>scripts/vcr_chain.py --check-witness</code> fetches those entries and confirms each witnessed head is one this file actually reaches. It still imports no Vaara code, so it checks the maintainer as readily as anyone else.</p>
</li>
<li>
<p><code>scripts/vcr_chain.py</code> reports <code>tailPinned</code> on every run, and <code>--json</code> carries it, so nothing downstream can read <em>verified</em> as <em>verified to be complete</em>. <code>--expect-count</code> and <code>--expect-last-hash</code> let a reader who retained a head pin the tail, and a mismatch exits the same way a break in the middle does, because a chain that is not the chain you pinned is not the chain you pinned.</p>
<p>This closes a hole the first version left open. A chain says nothing about rows removed from the end, because what remains is a valid shorter chain, so the checker printed &ldquo;chain intact&rdquo; and exited 0 on a file whose rows had all been deleted. Emek Can Dogru described the failure and the fix on the SCITT list on 2026-08-21, from having hit it himself; the shape here is his.</p>
</li>
<li>
<p>A term stating what an outside suggestion can change. Wording changes when it is shown to be false, and anyone may show that, including a party that competes with Vaara. A case, an expected verdict or a checker changes only on evidence that the current one is wrong, never on request and never to make a party pass, and every such change is a commit anyone can diff.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Tribblix-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/tribblix-vm/</link><pubDate>Sat, 22 Aug 2026 13:51:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/tribblix-vm/</guid><description>Version updated for https://github.com/vmactions/tribblix-vm to version v1.0.4.
This action is used across all versions by 28 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running continuous integration tests on Tribblix, a BSD-based operating system. It supports various releases and architectures, including x86_64, and allows users to run arbitrary commands in the VM environment. Users can pass environment variables and execute shell scripts to perform specific tasks during the CI process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/tribblix-vm">https://github.com/vmactions/tribblix-vm</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>28</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tribblix-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running continuous integration tests on Tribblix, a BSD-based operating system. It supports various releases and architectures, including x86_64, and allows users to run arbitrary commands in the VM environment. Users can pass environment variables and execute shell scripts to perform specific tasks during the CI process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>update</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/tribblix-vm/compare/v1.0.3...v1.0.4">https://github.com/vmactions/tribblix-vm/compare/v1.0.3...v1.0.4</a></p>
]]></content:encoded></item><item><title>Npx Confusion Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/npx-confusion-guard/</link><pubDate>Sat, 22 Aug 2026 13:50:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/npx-confusion-guard/</guid><description>Version updated for https://github.com/yourllmstxt/npx-confusion-guard to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, npx-confusion-guard, prevents attackers from claiming public npm names that match the binaries your packages export. It scans package.json files in a workspace and checks whether corresponding unscoped public npm names are claimed. The action reports potential issues via SARIF findings and can optionally reserve unclaimed binaries for manual reservation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yourllmstxt/npx-confusion-guard">https://github.com/yourllmstxt/npx-confusion-guard</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/npx-confusion-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, npx-confusion-guard, prevents attackers from claiming public npm names that match the binaries your packages export. It scans package.json files in a workspace and checks whether corresponding unscoped public npm names are claimed. The action reports potential issues via SARIF findings and can optionally reserve unclaimed binaries for manual reservation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release of Npx Confusion Guard.</p>
<ul>
<li>Scans package.json bin declarations for public npm name collisions</li>
<li>Produces SARIF for GitHub Code Scanning</li>
<li>Can reserve unclaimed names using a customer-owned npm account</li>
</ul>
]]></content:encoded></item><item><title>SF Package Combiner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/sf-package-combiner/</link><pubDate>Sat, 22 Aug 2026 06:23:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/sf-package-combiner/</guid><description>Version updated for https://github.com/mcarvin8/sf-package-combiner to version v4.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action combines multiple Salesforce package.xml manifests into one, simplifying CI/CD processes by automating the merging of different package configurations. It supports combining files and directories containing package.xml, making it suitable for integrating with sfdx-git-delta output or manual lists. The action provides flexibility through inputs like API version and dry run options, enhancing its utility for various deployment scenarios in Salesforce development pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcarvin8/sf-package-combiner">https://github.com/mcarvin8/sf-package-combiner</a></strong> to version <strong>v4.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sf-package-combiner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action combines multiple Salesforce <code>package.xml</code> manifests into one, simplifying CI/CD processes by automating the merging of different package configurations. It supports combining files and directories containing <code>package.xml</code>, making it suitable for integrating with sfdx-git-delta output or manual lists. The action provides flexibility through inputs like API version and dry run options, enhancing its utility for various deployment scenarios in Salesforce development pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="410-2026-08-21"><a href="https://github.com/mcarvin8/sf-package-combiner/compare/v4.0.3...v4.1.0">4.1.0</a> (2026-08-21)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>parser:</strong> replace txml with an in-house XML parser (<a href="https://github.com/mcarvin8/sf-package-combiner/issues/206">#206</a>) (<a href="https://github.com/mcarvin8/sf-package-combiner/commit/5bf818cfb69a07a5689955788d57313708556d4d">5bf818c</a>)</li>
<li>publish as a native GitHub Action (<a href="https://github.com/mcarvin8/sf-package-combiner/issues/208">#208</a>) (<a href="https://github.com/mcarvin8/sf-package-combiner/commit/1f8938d5b3b0a28666974a6b21701d19eccddb14">1f8938d</a>)</li>
</ul>
]]></content:encoded></item><item><title>SF Package List</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/sf-package-list/</link><pubDate>Sat, 22 Aug 2026 06:22:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/sf-package-list/</guid><description>Version updated for https://github.com/mcarvin8/sf-package-list to version v3.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action sf-package-list allows users to convert Salesforce package.xml manifests to and from a human-readable list format. It provides two modes: converting from a package.xml file to a text-based list or vice versa, making it easier for non-technical team members to manage metadata in Salesforce projects. The action is available as both a native GitHub Action and a plugin for the Salesforce CLI, offering flexibility in where and how users can perform these conversions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcarvin8/sf-package-list">https://github.com/mcarvin8/sf-package-list</a></strong> to version <strong>v3.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sf-package-list">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>sf-package-list</code> allows users to convert Salesforce package.xml manifests to and from a human-readable list format. It provides two modes: converting from a <code>package.xml</code> file to a text-based list or vice versa, making it easier for non-technical team members to manage metadata in Salesforce projects. The action is available as both a native GitHub Action and a plugin for the Salesforce CLI, offering flexibility in where and how users can perform these conversions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="310-2026-08-21"><a href="https://github.com/mcarvin8/sf-package-list/compare/v3.0.1...v3.1.0">3.1.0</a> (2026-08-21)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>parser:</strong> replace txml with an in-house XML parser (<a href="https://github.com/mcarvin8/sf-package-list/issues/100">#100</a>) (<a href="https://github.com/mcarvin8/sf-package-list/commit/a40d60d8183c9679c9501f9fd89666af42f0022d">a40d60d</a>)</li>
<li>publish as native GitHub Actions (<a href="https://github.com/mcarvin8/sf-package-list/issues/102">#102</a>) (<a href="https://github.com/mcarvin8/sf-package-list/commit/5347123deb073cf8c5c7f2570bfb0f2a049b3eb9">5347123</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>actions:</strong> consolidate to a single GitHub Action with a mode input (<a href="https://github.com/mcarvin8/sf-package-list/issues/103">#103</a>) (<a href="https://github.com/mcarvin8/sf-package-list/commit/a462dbe069525bbfdb6fce5bcc58de0772468523">a462dbe</a>)</li>
</ul>
]]></content:encoded></item><item><title>Speccy API review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/speccy-api-review/</link><pubDate>Sat, 22 Aug 2026 06:21:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/speccy-api-review/</guid><description>Version updated for https://github.com/mcclowes/speccy to version speccy-cli@0.12.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Speccy is an OpenAPI renderer that provides a consistent UI across different platforms and integrates with Docusaurus. It uses a shared React core to render OpenAPI specifications, which solves problems related to maintaining consistent rendering and supports various features such as multi-document references, JSON Schema 2020-12 support, and integration with Docusaurus.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcclowes/speccy">https://github.com/mcclowes/speccy</a></strong> to version <strong><a href="mailto:speccy-cli@0.12.0">speccy-cli@0.12.0</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/speccy-api-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Speccy is an OpenAPI renderer that provides a consistent UI across different platforms and integrates with Docusaurus. It uses a shared React core to render OpenAPI specifications, which solves problems related to maintaining consistent rendering and supports various features such as multi-document references, JSON Schema 2020-12 support, and integration with Docusaurus.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><a href="mailto:speccy-core@0.12.0">speccy-core@0.12.0</a></li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>Setup Fortran Compilers</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/setup-fortran-compilers/</link><pubDate>Sat, 22 Aug 2026 06:20:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/setup-fortran-compilers/</guid><description>Version updated for https://github.com/minhqdao/setup-fortran to version v1.10.0.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-fortran GitHub Action automates the setup of Fortran compiler toolchains across Linux, macOS, and Windows platforms. It supports various compilers including GNU, Intel, LLVM, NVIDIA, AMD, Arm, and LFortran, allowing users to easily integrate Fortran development into their workflows using GitHub Actions. The action provides options to specify the compiler version, installation environment (Windows), disk cleanup, and environment variable export settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/minhqdao/setup-fortran">https://github.com/minhqdao/setup-fortran</a></strong> to version <strong>v1.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-fortran-compilers">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>setup-fortran</code> GitHub Action automates the setup of Fortran compiler toolchains across Linux, macOS, and Windows platforms. It supports various compilers including GNU, Intel, LLVM, NVIDIA, AMD, Arm, and LFortran, allowing users to easily integrate Fortran development into their workflows using GitHub Actions. The action provides options to specify the compiler version, installation environment (Windows), disk cleanup, and environment variable export settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Compatibility Release to Supersede <a href="https://github.com/fortran-lang/setup-fortran">fortran-lang/setup-fortran</a></strong></p>
<ul>
<li><input checked="" disabled="" type="checkbox"> Add compiler aliases (<code>gcc</code> &ndash;&gt; <code>gfortran</code>, <code>intel</code> &ndash;&gt; <code>ifx</code>, <code>intel-classic</code> &ndash;&gt; <code>ifort</code>, <code>nvidia-hpc</code> &ndash;&gt; <code>nvfortran</code>) with deprecation warning, tests and documentation.</li>
<li><input checked="" disabled="" type="checkbox"> Implement <code>update-environment</code> with documentation and tests.</li>
<li><input checked="" disabled="" type="checkbox"> Maintain backwards-compatibility for specified versions except those that are intentionally broken.</li>
<li><input checked="" disabled="" type="checkbox"> Normalize <code>aocc</code> versions (<code>5.1.0</code> &ndash;&gt; <code>5.1</code>).</li>
<li><input checked="" disabled="" type="checkbox"> Add tests and fixes for companions compilers.</li>
<li><input checked="" disabled="" type="checkbox"> Add weekly canary (scheduled run because tests can break without code change due to runner updates).</li>
<li><input checked="" disabled="" type="checkbox"> Test consecutive invocations.</li>
<li><input checked="" disabled="" type="checkbox"> Add additional output verification tests.</li>
<li><input checked="" disabled="" type="checkbox"> Add test for C compilation and linking.</li>
<li><input checked="" disabled="" type="checkbox"> Add tests for additional Windows shells.</li>
<li><input checked="" disabled="" type="checkbox"> Revert symlinks on macOS during <code>gfortran</code> installation.</li>
<li><input checked="" disabled="" type="checkbox"> Add additional timeouts and retries.</li>
<li><input checked="" disabled="" type="checkbox"> Create symlinks where missing.</li>
<li><input checked="" disabled="" type="checkbox"> Guard unintended version coercion in <code>yaml</code> files (<code>2026.0</code> &ndash;&gt; <code>2026</code>).</li>
</ul>
]]></content:encoded></item><item><title>Setup audible-cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/setup-audible-cli/</link><pubDate>Sat, 22 Aug 2026 06:19:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/setup-audible-cli/</guid><description>Version updated for https://github.com/mkb79/setup-audible-cli to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-audible-cli GitHub Action installs and configures the audible-cli tool for use in GitHub Actions workflows. It allows users to authenticate with Audible using ADP tokens and device private keys, enabling them to run authenticated commands like listing libraries or exporting metadata. The action can also be used to install specific versions of audible-cli from PyPI or a different Git repository branch/tag, ensuring flexibility for testing unreleased features.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mkb79/setup-audible-cli">https://github.com/mkb79/setup-audible-cli</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-audible-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>setup-audible-cli</code> GitHub Action installs and configures the <code>audible-cli</code> tool for use in GitHub Actions workflows. It allows users to authenticate with Audible using ADP tokens and device private keys, enabling them to run authenticated commands like listing libraries or exporting metadata. The action can also be used to install specific versions of <code>audible-cli</code> from PyPI or a different Git repository branch/tag, ensuring flexibility for testing unreleased features.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Action description shortened to fit the GitHub Marketplace&rsquo;s 125-character
limit, and the auth mode described as request signing rather than ADP (<a href="https://github.com/mkb79/setup-audible-cli/pull/5">#5</a>)</li>
</ul>
]]></content:encoded></item><item><title>Needlepath Select</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/needlepath-select/</link><pubDate>Sat, 22 Aug 2026 06:17:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/needlepath-select/</guid><description>Version updated for https://github.com/nextmoca/needlepath-select-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Needlepath Select, optimizes AI workflows by preparing smaller, more relevant contexts for downstream tasks without altering original content or calling models. It uses a verbatim-selection engine to filter context records and is provider-neutral, shadowing default behavior while allowing explicit selection in select mode. The action ensures exact fail-open outcomes and reports Token and reduction figures as estimates rather than billed usage.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nextmoca/needlepath-select-action">https://github.com/nextmoca/needlepath-select-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/needlepath-select">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Needlepath Select, optimizes AI workflows by preparing smaller, more relevant contexts for downstream tasks without altering original content or calling models. It uses a verbatim-selection engine to filter context records and is provider-neutral, shadowing default behavior while allowing explicit selection in <code>select</code> mode. The action ensures exact fail-open outcomes and reports Token and reduction figures as estimates rather than billed usage.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release.</p>
<p>Provider-neutral Needlepath context selection for GitHub agent workflows: verbatim selection (nothing paraphrased — output is extracts of the workflow context you already have), shadow-default operation, and exact fail-open (any decline, error, or timeout preserves the original context byte-for-byte; a failed selection can never break your workflow).</p>
<ul>
<li><code>workflow-type</code>: custom, pr-review, ci-diagnosis, or release-notes</li>
<li>Mandatory material (<code>AGENTS.md</code>, agent instruction files, <code>.github/needlepath/policy.md</code>) never enters selection and is always passed through</li>
<li>CI: typecheck, tests, bundle-rebuild diff, SBOM, CodeQL, and a 3-OS fail-open smoke on every push</li>
</ul>
]]></content:encoded></item><item><title>Permissionizer Request Token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/permissionizer-request-token/</link><pubDate>Sat, 22 Aug 2026 06:16:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/permissionizer-request-token/</guid><description>Version updated for https://github.com/permissionizer/request-token to version v1.1.1.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action requests a temporary token from the Permissionizer App to perform actions on different repositories. It automates the process of obtaining tokens with specific permissions and can optionally revoke them after use. The action is useful when integrating with external systems or services that require elevated access credentials without compromising the main repository’s security.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/permissionizer/request-token">https://github.com/permissionizer/request-token</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/permissionizer-request-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action requests a temporary token from the Permissionizer App to perform actions on different repositories. It automates the process of obtaining tokens with specific permissions and can optionally revoke them after use. The action is useful when integrating with external systems or services that require elevated access credentials without compromising the main repository&rsquo;s security.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update all dependencies and CI tooling by @gavlyukovskiy in <a href="https://github.com/permissionizer/request-token/pull/82">https://github.com/permissionizer/request-token/pull/82</a></li>
<li>Try new self-action syntax by @gavlyukovskiy in <a href="https://github.com/permissionizer/request-token/pull/84">https://github.com/permissionizer/request-token/pull/84</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/permissionizer/request-token/compare/v1.1.0...v1.1.1">https://github.com/permissionizer/request-token/compare/v1.1.0...v1.1.1</a></p>
]]></content:encoded></item><item><title>MCPSec Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/mcpsec-audit/</link><pubDate>Sat, 22 Aug 2026 06:15:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/mcpsec-audit/</guid><description>Version updated for https://github.com/pfrederiksen/mcpsec to version v1.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MCPSec is a security scanner that audits MCP configurations, remote servers, and server source code to ensure compliance with the OWASP MCP Top 10:2025 beta. It performs static config checks, baseline drift detection, multi-client inventory, read-only enumeration, and lexical analysis of server code. The action supports OCSF JSON output and is designed to be used in CI/CD pipelines for security audits.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pfrederiksen/mcpsec">https://github.com/pfrederiksen/mcpsec</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcpsec-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>MCPSec is a security scanner that audits MCP configurations, remote servers, and server source code to ensure compliance with the OWASP MCP Top 10:2025 beta. It performs static config checks, baseline drift detection, multi-client inventory, read-only enumeration, and lexical analysis of server code. The action supports OCSF JSON output and is designed to be used in CI/CD pipelines for security audits.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>c9532aafe8a5a63fc7df5f5d9cd105ee53a696d2 feat: expand OWASP MCP security coverage</li>
<li>916ce716ab7e87406ca9d8434144c14e70351f29 fix: satisfy release lint checks</li>
</ul>
]]></content:encoded></item><item><title>action-semver</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/action-semver/</link><pubDate>Sat, 22 Aug 2026 06:14:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/action-semver/</guid><description>Version updated for https://github.com/quike/action-semantic-release to version v3.18.0.
This action is used across all versions by 5 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub action automates the release process using semantic-release, a tool that follows semantic versioning guidelines to manage version numbers. It helps maintain a consistent and predictable release cycle for software projects, ensuring clear communication between developers and stakeholders about version updates.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quike/action-semantic-release">https://github.com/quike/action-semantic-release</a></strong> to version <strong>v3.18.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-semver">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub action automates the release process using semantic-release, a tool that follows semantic versioning guidelines to manage version numbers. It helps maintain a consistent and predictable release cycle for software projects, ensuring clear communication between developers and stakeholders about version updates.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="3180-2026-08-22"><a href="https://github.com/quike/action-semantic-release/compare/v3.17.0...v3.18.0">3.18.0</a> (2026-08-22)</h1>
]]></content:encoded></item><item><title>praas PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/praas-pr-review/</link><pubDate>Sat, 22 Aug 2026 06:14:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/praas-pr-review/</guid><description>Version updated for https://github.com/rchhabra13/praas-setup-dryrun to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating AI-powered reviews for pull requests using Google Gemini, providing multi-lens feedback on correctness, security, testing, and documentation directly as comments in the PR. The action is triggered by a label being applied to a PR, and it requires users to set up their API key through repository secrets.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rchhabra13/praas-setup-dryrun">https://github.com/rchhabra13/praas-setup-dryrun</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/praas-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating AI-powered reviews for pull requests using Google Gemini, providing multi-lens feedback on correctness, security, testing, and documentation directly as comments in the PR. The action is triggered by a label being applied to a PR, and it requires users to set up their API key through repository secrets.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/rchhabra13/praas-setup-dryrun/commits/v1.0.0">https://github.com/rchhabra13/praas-setup-dryrun/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/kaniko-build-action/</link><pubDate>Sat, 22 Aug 2026 06:14:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a custom greeting to a specified person’s name. It provides an easy way to automate greetings in CI/CD pipelines without requiring additional software installations.
What’s Changed My first action is ready (5619594) Initial commit (2a56a2a)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a custom greeting to a specified person&rsquo;s name. It provides an easy way to automate greetings in CI/CD pipelines without requiring additional software installations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>ForgeProof Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/forgeproof-verify/</link><pubDate>Sat, 22 Aug 2026 06:13:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/forgeproof-verify/</guid><description>Version updated for https://github.com/ryanjmichie-git/forgeproof-verify to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GitHub Action to verify ForgeProof .rpack provenance bundles on pull requests, ensuring AI-generated code integrity and completeness. It checks bundle signatures, provenance chains, artifact SHA-256s, and posts a human-readable audit report as a PR comment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ryanjmichie-git/forgeproof-verify">https://github.com/ryanjmichie-git/forgeproof-verify</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/forgeproof-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GitHub Action to verify ForgeProof <code>.rpack</code> provenance bundles on pull requests, ensuring AI-generated code integrity and completeness. It checks bundle signatures, provenance chains, artifact SHA-256s, and posts a human-readable audit report as a PR comment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Re-vendors the ForgeProof engine to plugin <strong>v1.3.0</strong> (bundle format
v1.1.0). Bundles produced by plugin v1.3.0+ embed a standards-conformant
attestation — in-toto Statement v1 with a SLSA Provenance v1 predicate,
DSSE-signed with the bundle&rsquo;s own ephemeral Ed25519 key, packaged as a
Sigstore v0.3 bundle — and this action now verifies it as part of bundle
verification.</p>
<ul>
<li>New additive <code>attestation</code> output: <code>&quot;true&quot;</code> iff every matched bundle
embeds an attestation. Presence only — validity is part of <code>verified</code>
(the DSSE signature is checked against the bundle&rsquo;s own public key, and
the attestation subjects are cross-checked against the sealed artifact
digests). <code>&quot;false&quot;</code> with zero matched bundles — never vacuously
<code>&quot;true&quot;</code>.</li>
<li>Pre-v1.3 bundles verify exactly as before: green, no warning,
<code>attestation: &quot;false&quot;</code> — proven in CI by the frozen v101/v110/v122
fixtures on the new engine.</li>
<li>New frozen fixtures (v122, v130) and an <code>attestation-field-edit</code>
tamper-matrix case: one flipped byte inside the embedded attestation
turns the check red.</li>
<li>The same attestation is verifiable <em>outside</em> this action with plain
cosign from the sidecars the plugin seals next to the bundle (see the
plugin&rsquo;s <code>docs/cosign-interop.md</code>). This action deliberately stays
stdlib-only.</li>
</ul>
<p>The floating <code>v1</code> tag now points here, so
<code>uses: ryanjmichie-git/forgeproof-verify@v1</code> picks up attestation
verification automatically.</p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/agentauditkit-mcp-security-scan/</link><pubDate>Sat, 22 Aug 2026 06:12:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.86.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: AgentAuditKit is a security scanner specifically designed for AI agent pipelines connected to the MCP ecosystem. It identifies misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. The action is deterministic and offline, ensuring consistent findings without any network interactions or model involvement.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.86</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> AgentAuditKit is a security scanner specifically designed for AI agent pipelines connected to the MCP ecosystem. It identifies misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. The action is deterministic and offline, ensuring consistent findings without any network interactions or model involvement.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.86
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.86
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.86</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.85...v0.3.86">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.85...v0.3.86</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/sherpa.sh/</link><pubDate>Sat, 22 Aug 2026 06:11:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh automates the deployment of applications to various cloud providers using plain English descriptions. It automatically configures servers, DNS, SSL certificates, CDN, databases, backups, and load balancing based on user input, making it invisible to developers. The action supports multiple cloud services including AWS, Google Cloud, and more, and can integrate with GitHub Actions for automated workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh automates the deployment of applications to various cloud providers using plain English descriptions. It automatically configures servers, DNS, SSL certificates, CDN, databases, backups, and load balancing based on user input, making it invisible to developers. The action supports multiple cloud services including AWS, Google Cloud, and more, and can integrate with GitHub Actions for automated workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>MergeWarden for AI PRs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/mergewarden-for-ai-prs/</link><pubDate>Sat, 22 Aug 2026 06:10:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/mergewarden-for-ai-prs/</guid><description>Version updated for https://github.com/sjh9714/mergewarden to version v0.10.4.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MergeWarden is a GitHub Action that helps maintainers quickly identify and address common issues in pull requests by checking missing issue links, thin descriptions, skipped templates, and oversized changes. It surfaces these problems before code review, ensuring pull requests are well-prepared for review. MergeWarden uses public metadata and the base branch pull request template to provide context without fetching or executing any code. The detailed PR risk scan checks security boundaries like workflow permissions, agent instructions, untrusted prompt inputs, and install scripts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sjh9714/mergewarden">https://github.com/sjh9714/mergewarden</a></strong> to version <strong>v0.10.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mergewarden-for-ai-prs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>MergeWarden is a GitHub Action that helps maintainers quickly identify and address common issues in pull requests by checking missing issue links, thin descriptions, skipped templates, and oversized changes. It surfaces these problems before code review, ensuring pull requests are well-prepared for review. MergeWarden uses public metadata and the base branch pull request template to provide context without fetching or executing any code. The detailed PR risk scan checks security boundaries like workflow permissions, agent instructions, untrusted prompt inputs, and install scripts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><code>mergewarden demo</code> now starts with one quiet <code>CLAUDE.md</code> instruction change and one <code>agent-control-plane/drift</code> finding.</p>
<p>The previous demo packed workflow, dependency, contract, and triage findings into one first run. The GitHub and npm READMEs now put the focused local demo before installation and queue scanning.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx --yes mergewarden@0.10.4 demo
</span></span></code></pre></div><p>The analysis needs no GitHub token or target repository and makes no GitHub API call.</p>
]]></content:encoded></item><item><title>IfChange (slnc)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/ifchange-slnc/</link><pubDate>Sat, 22 Aug 2026 06:09:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/ifchange-slnc/</guid><description>Version updated for https://github.com/slnc/ifchange to version v0.3.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ifchange is an automated tool designed to catch cross-file dependency issues in codebase by identifying and enforcing changes to referenced environment variables or configuration settings. It helps developers avoid common errors where a variable is renamed but not updated across all affected files, ensuring consistency throughout the project. The action supports linting for various file extensions and programming languages, offering robust error detection and real-time feedback during development and review processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/slnc/ifchange">https://github.com/slnc/ifchange</a></strong> to version <strong>v0.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ifchange-slnc">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>ifchange</code> is an automated tool designed to catch cross-file dependency issues in codebase by identifying and enforcing changes to referenced environment variables or configuration settings. It helps developers avoid common errors where a variable is renamed but not updated across all affected files, ensuring consistency throughout the project. The action supports linting for various file extensions and programming languages, offering robust error detection and real-time feedback during development and review processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="032-2026-08-21"><a href="https://github.com/slnc/ifchange/compare/v0.3.1...v0.3.2">0.3.2</a> (2026-08-21)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>recognize LINT directives in extensionless Makefiles (<a href="https://github.com/slnc/ifchange/issues/53">#53</a>) (<a href="https://github.com/slnc/ifchange/commit/277063ac79ea1f33d85ff44689bbe4aeb0bec1af">277063a</a>)</li>
</ul>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/smyklot/</link><pubDate>Sat, 22 Aug 2026 06:07:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.45.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository’s CODEOWNERS file. It supports multiple command formats, allows for approval deduplication, and provides emoji feedback to users. The app can be installed either via the GitHub App or as a webhook service for every repository it is installed on.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.45.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository&rsquo;s CODEOWNERS file. It supports multiple command formats, allows for approval deduplication, and provides emoji feedback to users. The app can be installed either via the GitHub App or as a webhook service for every repository it is installed on.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1450-2026-08-21"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.44.0...v1.45.0">1.45.0</a> (2026-08-21)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>panel:</strong> the shell redesign (<a href="https://github.com/smykla-skalski/smyklot/issues/292">#292</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/d9c1edbc77313c4ab494e0e39a430fff8339d4b9">d9c1edb</a>), closes <a href="https://github.com/smykla-skalski/smyklot/issues/e6ede9">#e6ede9</a></li>
</ul>
<h2 id="smyklot-v1450">Smyklot v1.45.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.45.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>85cd44de07e19c45fa30fab39bdb95819c9b859b chore(release): bump version to 1.45.0</li>
<li>d9c1edbc77313c4ab494e0e39a430fff8339d4b9 feat(panel): the shell redesign (#292)</li>
<li>272a3b00cbe4daadeccd065c6f0c66bb3e32b917 ci(deps): update golangci-lint to v2.13.1 (#291)</li>
<li>9bb553f2ca2dde8ac09136c06fc6e67c6b199cbc chore(deps): update dependency yq to v4.53.6 (#290)</li>
<li>e1c5feb7ca4917e46aaec6299f3bb8bea5212a74 chore(deps): update dependency go to v1.27.0 (#285)</li>
<li>e1a44c2f4b3692f1afd0223f488f59755a0f2357 ci(deps): update golangci-lint to v2.13.0 (#289)</li>
</ul>
]]></content:encoded></item><item><title>Aegis AI Agent Security &amp; AST Invariant Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/aegis-ai-agent-security-ast-invariant-guard/</link><pubDate>Sat, 22 Aug 2026 06:06:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/aegis-ai-agent-security-ast-invariant-guard/</guid><description>Version updated for https://github.com/Snehgabani/aegis-kernel to version core@vv1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Aegis is a deterministic safety verification tool that intercepts and analyzes AI agent tool calls, ensuring they comply with invariants by parsing SQL queries into ASTs, applying tautology detection, enforcing numeric bounds, and masking secrets. It operates in-process, typically under 1.5ms for single-statement queries, without external API calls or LLM dependencies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Snehgabani/aegis-kernel">https://github.com/Snehgabani/aegis-kernel</a></strong> to version <strong><a href="mailto:core@vv1.10.0">core@vv1.10.0</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aegis-ai-agent-security-ast-invariant-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Aegis is a deterministic safety verification tool that intercepts and analyzes AI agent tool calls, ensuring they comply with invariants by parsing SQL queries into ASTs, applying tautology detection, enforcing numeric bounds, and masking secrets. It operates in-process, typically under 1.5ms for single-statement queries, without external API calls or LLM dependencies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1100-2026-08-21"><a href="https://github.com/Snehgabani/aegis-kernel/compare/core@vv1.9.0...core@vv1.10.0">1.10.0</a> (2026-08-21)</h2>
<h3 id="-features--verification-engines">🚀 Features &amp; Verification Engines</h3>
<ul>
<li><strong>security:</strong> implement frontier swarm immunity with dangerous SQL built-in barriers, atomic CAS state invariants, and attenuated delegation tokens (<a href="https://github.com/Snehgabani/aegis-kernel/commit/469fa388c6628752b089bab74fa5e7d6eddf98b3">469fa38</a>)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sat, 22 Aug 2026 06:05:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by bundling project files and committing them to a specific Git repository. It simplifies the process of preparing and deploying applications to Swarm environments, ensuring consistency across multiple development and production environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by bundling project files and committing them to a specific Git repository. It simplifies the process of preparing and deploying applications to Swarm environments, ensuring consistency across multiple development and production environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/classroom-to-sheets-integration/</link><pubDate>Sat, 22 Aug 2026 06:05:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically sends assignment results from Google Classroom to a specified Google Sheet. It requires setting up Google Sheets API credentials and sharing the sheet with the service account email. Users can integrate this action into their GitHub workflows to update Google Sheets with task results. The action supports automatic column creation based on task names, handling missing students by adding new rows, and updating existing rows with new scores.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically sends assignment results from Google Classroom to a specified Google Sheet. It requires setting up Google Sheets API credentials and sharing the sheet with the service account email. Users can integrate this action into their GitHub workflows to update Google Sheets with task results. The action supports automatic column creation based on task names, handling missing students by adding new rows, and updating existing rows with new scores.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/compose-lint/</link><pubDate>Sat, 22 Aug 2026 06:04:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.22.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary compose-lint is a security-focused linter that checks Docker Compose files for potential vulnerabilities, including privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. It catches these issues before they reach production and provides automated fixes. The tool uses OWASP and the CIS Docker Benchmark as its foundation and is suitable for developers who ship Docker Compose files to production or want defense in depth in a home lab.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.22.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>compose-lint is a security-focused linter that checks Docker Compose files for potential vulnerabilities, including privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. It catches these issues before they reach production and provides automated fixes. The tool uses OWASP and the CIS Docker Benchmark as its foundation and is suitable for developers who ship Docker Compose files to production or want defense in depth in a home lab.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="upgrading">Upgrading</h3>
<p><strong>A <code>.env</code> beside a Compose file now chooses which documents are linted.</strong>
Compose reads a sibling <code>.env</code> for <code>COMPOSE_FILE</code>, which replaces its file
discovery <em>and</em> suppresses the automatic <code>compose.override.yml</code> merge. compose-
lint read neither, so a project configured that way had its real documents
ungraded while an override Compose never loads contributed findings — under a
warning stating that Compose merges it automatically, which was false there.</p>
<p>Values are resolved from it too, so a <code>${VAR}</code> a rule consumes now grades as
what deploys rather than as unknowable. Expect new findings on such projects,
including CRITICAL ones, and some existing findings to disappear where the
<code>.env</code> supplies a value that clears them (a pinned image tag, for instance) —
the documented MINOR behaviour for tightened coverage.</p>
<p>Expect the reported file list to change on such projects, in both directions.
<code>--no-env</code> restores the previous selection exactly, including that false merge.
A <code>.env</code> can only <em>add</em> documents to a file you named on the command line, never
remove it, so nothing you asked for is skipped (<a href="docs/adr/026-read-the-sibling-env-file.md">ADR-026</a>).</p>
<p><strong>Files with a <code>compose.override.yml</code> beside them are now graded as the
configuration Compose runs.</strong> <code>docker compose up</code> merges that overlay with no
flag and no opt-in, and compose-lint read only the base — so a control-socket
mount added by an overlay was never reported, and the base&rsquo;s own findings were
graded against a document nobody deploys.</p>
<p>Expect new findings on such projects, including CRITICAL ones. That is the
documented MINOR behaviour for tightened coverage; pin the version or gate on
<code>--fail-on</code> if a pipeline needs determinism. <code>--no-merge-overrides</code> restores
the previous single-file grading exactly.</p>
<h3 id="added">Added</h3>
<ul>
<li>
<p><code>check</code> and <code>fix</code> read <code>COMPOSE_FILE</code> and <code>COMPOSE_PATH_SEPARATOR</code> from a
<code>.env</code> in the Compose file&rsquo;s own directory, select the documents it names, and
merge them in its order. The run states what it selected and why on stderr,
and the header names every document read. The ambient shell environment stays
out of scope: a <code>COMPOSE_FILE</code> exported in a session and never written down is
host state, and honouring it would make the same checkout lint differently
depending on who ran the command. The separator defaults to <code>:</code> on every
platform rather than to the host&rsquo;s, because a <code>.env</code> naming two documents
describes the project wherever it is linted from; Compose&rsquo;s own default is
the host&rsquo;s path separator, so this deliberately differs on a Windows lint
host, in the same direction ADR-023 already took for path semantics.</p>
</li>
<li>
<p><code>--no-env</code> ignores a sibling <code>.env</code> entirely, reproducing the previous file
selection. A run that skips one says so, because an escape hatch that
silently changes what is graded is the failure the hatch exists to prevent.</p>
</li>
<li>
<p>A note when a bind source is <em>only</em> unresolved references (<code>&quot;${MOUNT}:/data&quot;</code>
with nothing supplying <code>MOUNT</code>). Compose refuses to start a project with an
empty bind source, so the document being graded is not one that deploys and
the mount rules were never evaluated for it. Deliberately narrow — 3.3% of a
5,417-file corpus, against the 22% that carry <em>some</em> defaultless <code>${VAR}</code> —
and it is a note on stderr, so the exit code is unchanged.</p>
</li>
<li>
<p>Contract tests pin the JSON envelope and the SARIF log shape, the two
surfaces <code>docs/compatibility.md</code> freezes at 1.0 that nothing enforced.
<code>SCHEMA_VERSION</code> is pinned to its literal value, so a silent bump fails;
additive keys stay allowed, renames and removals now require editing the
contract on purpose.</p>
</li>
<li>
<p><code>check</code> and <code>fix</code> merge a sibling <code>compose.override.yml</code> and lint the
effective configuration (ADR-025). The run header names both documents, and
a note on stderr states what was merged; the exit code is unchanged, because
merging is coverage achieved rather than a coverage gap.</p>
</li>
<li>
<p><code>--no-merge-overrides</code> on <code>check</code> and <code>fix</code> opts out.</p>
</li>
<li>
<p>Findings carry the document their evidence is written in. Text excerpts are
read from that file, SARIF points <code>artifactLocation</code> there, and JSON gains a
conditional <code>source_file</code> key — additive, so <code>SCHEMA_VERSION</code> is unchanged.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><code>fix</code> edits only findings written in the file it is fixing when an overlay is
merged; findings from the overlay are reported for manual review, and the
overlay is never a write target.</li>
</ul>
<h3 id="deprecated">Deprecated</h3>
<ul>
<li>
<p><strong>Python 3.10 is deprecated.</strong> It reaches upstream end-of-life in October
2026, and compose-lint will require 3.11 or newer before its 1.0 release.
Running on 3.10 now prints a one-line warning to stderr naming the version
you are on and the version to pin if you need to stay there. Nothing else
changes yet: 3.10 remains in the test matrix and fully supported until the
drop lands.</p>
<p>The warning exists because the drop itself is silent. <code>requires-python</code> does
not fail an install on an unsupported interpreter — pip resolves to the last
release that allowed it, so after the floor moves <code>pip install -U compose-lint</code> leaves a 3.10 user on a frozen version with nothing printed in
either direction. This is the last chance to say so.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p>Credential rules are unaffected by a <code>.env</code>. A value there is never
substituted into an <code>environment:</code> value, so <code>POSTGRES_PASSWORD: &quot;${PW}&quot;</code>
stays clean however <code>PW</code> is set — otherwise CL-0021 would flag the exact
pattern its own fix text recommends. A written default is still graded:
<code>${PW:-changeme}</code> ships to every clone and keeps firing. Names referenced only
from <code>environment:</code> are not read out of the <code>.env</code> at all.</p>
</li>
<li>
<p>An overlay is no longer merged into a project whose <code>.env</code> sets
<code>COMPOSE_FILE</code>. Compose does not load <code>compose.override.yml</code> when
<code>COMPOSE_FILE</code> is set, so those findings described a document that never runs,
and the accompanying warning asserted the opposite.</p>
</li>
<li>
<p>CL-0005 includes a non-default protocol in a long-syntax port&rsquo;s evidence.
Two publishings of one container port that differ only by protocol — the
standard shape for a DNS service — derived the same evidence, so SARIF gave
them one <code>partialFingerprints</code> digest and Code Scanning displayed one alert
instead of two. <code>tcp</code> is still not spelled out, so no existing alert is
re-keyed. Text and JSON always reported both findings.</p>
</li>
<li>
<p><code>extends:</code> no longer concatenates every sequence. Compose merges <code>volumes</code>
and <code>devices</code> by container path, replaces <code>command</code>/<code>entrypoint</code>, and
deduplicates the append-style sequences; concatenating reported a CRITICAL
socket mount against a service that had replaced that mount at the same
container path, pointing at the line that replaced it.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/wails3-build-action/</link><pubDate>Sat, 22 Aug 2026 06:03:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of building Wails.io applications, a framework for creating cross-platform desktop and web applications. It supports GoLang and NodeJS builds, with options to obfuscate the binaries and customize build platforms and caching. The action is particularly useful for maintaining and deploying Wails projects in GitHub Actions workflows, ensuring that they are built and deployed consistently across different environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of building Wails.io applications, a framework for creating cross-platform desktop and web applications. It supports GoLang and NodeJS builds, with options to obfuscate the binaries and customize build platforms and caching. The action is particularly useful for maintaining and deploying Wails projects in GitHub Actions workflows, ensuring that they are built and deployed consistently across different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Done Means Done</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/done-means-done/</link><pubDate>Sat, 22 Aug 2026 06:02:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/done-means-done/</guid><description>Version updated for https://github.com/vaibh123540/Done-Means-Done to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Done Means Done is a GitHub Action that automates the process of ensuring all acceptance criteria in linked issues are met before a pull request can be closed. It checks pull request bodies for links to issues and verifies that corresponding task list items under specified headings are completed, failing with detailed messages if any are missing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaibh123540/Done-Means-Done">https://github.com/vaibh123540/Done-Means-Done</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/done-means-done">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Done Means Done is a GitHub Action that automates the process of ensuring all acceptance criteria in linked issues are met before a pull request can be closed. It checks pull request bodies for links to issues and verifies that corresponding task list items under specified headings are completed, failing with detailed messages if any are missing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="done-means-done-v100">Done Means Done v1.0.0</h2>
<p>First public release of Done Means Done.</p>
<p>Done Means Done is a GitHub Action that blocks pull requests when linked issues still contain unchecked acceptance criteria.</p>
<h3 id="features">Features</h3>
<ul>
<li>Detects issues linked from pull requests using GitHub closing keywords such as <code>Closes</code>, <code>Fixes</code>, and <code>Resolves</code></li>
<li>Checks the linked issue&rsquo;s <code>Acceptance Criteria</code> section</li>
<li>Fails the workflow when acceptance criteria remain unchecked</li>
<li>Supports configurable section names</li>
<li>Optional enforcement requiring every PR to link an issue</li>
<li>Clear workflow logs, annotations, and job summaries</li>
<li>Runs entirely inside GitHub Actions with no external service or account required</li>
</ul>
<h3 id="usage">Usage</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vaibh123540/Done-Means-Done@v1</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>ReactOS-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/reactos-vm/</link><pubDate>Sat, 22 Aug 2026 06:01:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/reactos-vm/</guid><description>Version updated for https://github.com/vmactions/reactos-vm to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running CI tasks on ReactOS. It uses AnyVM.org and vmactions-ci skill to handle the setup and execution of builds, providing a seamless experience for developers who need to test their projects on different architectures like ReactOS.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/reactos-vm">https://github.com/vmactions/reactos-vm</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/reactos-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running CI tasks on ReactOS. It uses AnyVM.org and vmactions-ci skill to handle the setup and execution of builds, providing a seamless experience for developers who need to test their projects on different architectures like ReactOS.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>fix bugs</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/reactos-vm/compare/v1.0.1...v1.0.2">https://github.com/vmactions/reactos-vm/compare/v1.0.1...v1.0.2</a></p>
]]></content:encoded></item><item><title>Legion Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/legion-runner/</link><pubDate>Sat, 22 Aug 2026 06:00:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/legion-runner/</guid><description>Version updated for https://github.com/Wraith-security/Legion_runner to version v1.0.60.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Legion Runner is an open-source action designed to harden CI/CD pipelines by monitoring and blocking outbound connections from GitHub Actions jobs. It records the process behind each connection, names it, and blocks any destination not on the allowed list. The tool runs without leaving the runner’s environment, making it self-contained and secure.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Wraith-security/Legion_runner">https://github.com/Wraith-security/Legion_runner</a></strong> to version <strong>v1.0.60</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/legion-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Legion Runner is an open-source action designed to harden CI/CD pipelines by monitoring and blocking outbound connections from GitHub Actions jobs. It records the process behind each connection, names it, and blocks any destination not on the allowed list. The tool runs without leaving the runner&rsquo;s environment, making it self-contained and secure.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Curated egress presets (<code>allowed-presets</code>)</strong>: opt-in per-ecosystem allowlists
(npm, yarn, pnpm, pip, pypi, cargo, rust, go, maven, gradle, nuget, apt, debian,
docker) so block mode &ldquo;just works&rdquo; for common toolchains without hand-listing
endpoints. e.g. <code>allowed-presets: &quot;cargo, apt&quot;</code>. Unit-tested.</li>
<li><strong>Download integrity verification</strong>: the action verifies the <code>legionr-bpf</code> /
<code>legionr-fim</code> release binaries against a <code>.sha256</code> sidecar before running them
(the release now attaches the checksums), and <strong>fails closed</strong> — an
unverified/corrupted/tampered download is rejected and the action degrades
instead of executing it.</li>
<li><strong><code>learned-baseline</code> input</strong> (default <code>true</code>): in block mode, also allow
destinations previously learned into the Actions cache. Set <code>false</code> to enforce
ONLY the explicit allowlist (inline + policy-file + GitHub) with no cache
read/write — used by the enforce self-test for deterministic deny.</li>
<li><strong>File-integrity / tamper detection (Rust <code>legionr-fim</code> agent)</strong>: snapshots
high-value tamper targets at job start (credential/config files, <code>.git</code>
config + hooks, and checked-out source) and diffs them at job end, surfacing
anything overwritten, deleted, or chmod&rsquo;d in the summary. Only sha256 hashes
are stored — never contents. New inputs <code>file-integrity</code> (auto|off) and
<code>fim-extra-paths</code>. <code>file-integrity: auto</code> downloads the agent from the latest
release (plain stable Rust, no eBPF toolchain) and degrades to a silent skip
if unavailable. Logic lives in <code>legionr-core::fim</code> (unit-tested); the binary
is a release asset like <code>legionr-bpf</code>, built + attached by <code>release.yml</code>.</li>
<li><strong>Package repositories roll-up (<code>📦</code>)</strong>: the summary now classifies named
outbound destinations into their ecosystem/registry (npm, PyPI, crates.io,
apt, Docker, Go, NuGet, Maven, Gradle, RubyGems, Alpine, GitHub) and shows a
<strong>Package repositories reached</strong> table — registry, ecosystem, connections, and
the process that reached each. Supply-chain risk hides in <em>which</em> registries a
build talks to, so we surface them directly instead of leaving you to read
IPs. Bare IPs that never got a forward name get a coarse CDN/provider hint
(Fastly/Cloudflare/GitHub) via CIDR match — honest about ambiguity (a shared
CDN can&rsquo;t name a registry). Logic in <code>action/repos.js</code>, fully unit-tested.</li>
<li><strong>Combined cross-job egress report (one summary for the whole run)</strong>: GitHub
has no run-level summary, so each job emits its captured egress as a JSON
artifact (<code>node action/report.js emit</code>) and a final <code>egress-report</code> job merges
them into a SINGLE table — which job + process reached what — with a package
repositories roll-up and a per-job diagnostics block (<code>render</code>). Wired into CI;
<code>render</code> is pure and unit-tested. Pairs with <code>job-summary: false</code> so the run
shows one combined summary instead of one table per job.</li>
<li><strong><code>job-summary</code> input</strong> (default <code>true</code>): set <code>false</code> to keep monitoring and
enforcement fully active but suppress the connections table in the job summary.
Useful when many jobs in one workflow each run the action and you only want the
table once (our own CI uses it so a run shows one table, not one per job).</li>
<li><strong>Secure diagnostics line</strong> in the summary: reports which resolution path
actually fired (<code>forwarder on/off · captured DNS records N · getaddrinfo route … · named X/Y destinations</code>) so a run that comes back as bare IPs is triagable.
Secure by construction — only booleans, counts, and a fixed enum; never the
upstream resolver IP, file paths, captured hostnames, or env values.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>The live e2e tier is out of CI.</strong> <code>.github/workflows/e2e.yml</code> now runs only
the credential-free <code>local</code> job. The removed <code>live</code> job registered a runner
against a fixed external scope that this org cannot install the App on, so it
could only skip silently or fail noisily, and neither outcome said anything
about the runner. <code>scripts/e2e.sh --mode live</code> still works and can be pointed
at any scope you control, but the scope is now mandatory (<code>--scope owner/repo</code>
or <code>E2E_SCOPE</code>) instead of defaulting to a hardcoded constant: the harness
will not guess a target it registers a real runner against. The <code>local</code> tier
falls back to <code>$GITHUB_REPOSITORY</code> since it provisions with <code>--no-probe</code> and
never reaches GitHub.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>FIM hashing builds against <code>sha2</code> 0.11.</strong> The digest type changed to
<code>hybrid_array::Array</code>, which does not implement <code>LowerHex</code>, so
<code>format!(&quot;{:x}&quot;, ..)</code> in <code>fim::hash_file</code> stopped compiling. The digest is now
hex-encoded byte by byte, which works on both 0.10 and 0.11. Two tests pin the
behaviour: the exact sha256 of <code>abc</code>, and a 64-char length/charset assertion so
a dropped leading zero cannot pass silently. Unblocks the <code>cargo-major</code>
dependency group (<code>sha2</code> 0.10.9 to 0.11.0, <code>thiserror</code> 1 to 2.0.18).</li>
<li><strong>Block mode no longer hangs the runner at teardown.</strong> <code>applyEgressBlock</code>
installed a default-deny <code>LEGION_EGRESS</code> chain in <code>OUTPUT</code> and nothing ever
removed it, so the runner&rsquo;s own completion call (to rotating GitHub-backend IPs
not in the static seed) was dropped and the job spun until timeout. <code>post()</code>
now tears the firewall down (<code>removeEgressBlock</code>).</li>
<li><strong>Runner hang from leaked daemons.</strong> The post step left privileged background
processes alive — eBPF agent, DNS forwarder — and the <code>/proc</code> monitor could
wedge in a blocking <code>ss</code> subprocess. The monitor now reads <code>/proc/net/tcp</code>
directly (no subprocess); daemons are reliably reaped.</li>
<li><strong>No more spurious &ldquo;could not resolve&rdquo; annotations.</strong> Allowlist entries that
are wildcard parents with no A record of their own (e.g. <code>blob.core.windows.net</code>,
<code>actions.githubusercontent.com</code>) used to emit one CI <strong>warning annotation</strong>
each on every run. They are benign: the action skips them, and their subdomains
are still observed via PTR / DNS capture (and opened just-in-time in block
mode). They are now collected into a single plain-text log line instead.</li>
<li><strong>Docs/labels</strong>: the eBPF mechanism is a <strong>tracepoint on <code>sys_enter_connect</code></strong>
(not a &ldquo;kprobe on tcp_connect&rdquo;); the sampler is <code>/proc</code>-only (the &ldquo;ss&rdquo; fallback
was removed). Corrected the runtime log line, summary label, and README.</li>
<li><strong>Outbound connections showed as bare IPs when systemd-resolved owns
<code>getaddrinfo</code>.</strong> The <code>nsswitch</code> reroute didn&rsquo;t always stick, so package-repo
lookups bypassed the capture forwarder and were never named. The forwarder now
targets the <em>real</em> upstream (systemd-resolved&rsquo;s actual servers, not the
<code>127.0.0.53</code> stub), and when the bypass is detected but the nsswitch reroute
fails, Legion redirects systemd-resolved itself at the forwarder via a
<code>resolved.conf.d</code> drop-in — <strong>verify-or-revert</strong> and restored on teardown, so
it never breaks the job&rsquo;s DNS.</li>
<li><strong>IPv4-mapped IPv6 destinations rendered as long expanded addresses</strong>
(<code>0000:0000:0000:0000:0000:ffff:HHHH:HHHH</code>) in the summary. The <code>/proc</code> sampler
emitted the expanded form while <code>normalizeIp</code> only collapsed the compressed
<code>::ffff:</code> form. Both now collapse to dotted IPv4 (and the v4/v6 tables dedupe).
(Shipped in v1.0.35.)</li>
<li>Removed dead <code>action/baseline.js</code>; pinned <code>release.yml</code> checkout to v6.</li>
</ul>
<h3 id="reliability">Reliability</h3>
<ul>
<li><strong>Tests for the paths that kept breaking</strong>: the firewall rule builders
(<code>egressBlockRules</code>/<code>egressUnblockRules</code> — order, DNS-allow, DROP-last,
OUTPUT-jump-removed-first), the checksum parser, the curated presets, and a
<strong>full-stack PR gate</strong> that runs block + DNS-capture + eBPF and asserts the
job finalizes (catches any teardown-hang regression), plus the package-repo
classifier (host-suffix + CIDR matching). Action test count 19 → 37.</li>
</ul>
<h3 id="changed-1">Changed</h3>
<ul>
<li>Removed em-dashes from the job-summary output (headers, the unresolved-host
note, the enforce hint, and empty-cell placeholders) for plainer rendering.</li>
<li><strong>Name more destinations</strong>: route glibc <code>getaddrinfo</code> (curl/apt/cargo/git)
through the DNS-capture forwarder via an <code>nsswitch.conf</code> reroute, so hosts
resolved by systemd-resolved (which ignores <code>resolv.conf</code>) are now captured
and named — not just <code>resolv.conf</code>/c-ares callers. Health-checked and restored
on teardown. (A connection to a hard-coded IP with no PTR still shows the IP —
there is no name to resolve.)</li>
<li>More accurate &ldquo;unresolved destination&rdquo; note in the summary (a name may have
been resolved outside the capture path, vs. a genuine raw-IP connection).</li>
<li><strong>We dogfood our own action.</strong> Every real-work job in this repo (CI, release,
eBPF agent, FIM self-test) now runs Legion Runner as its first step (<code>@v1</code>,
audit) — our CI is hardened by the product it ships.</li>
<li><strong>Docs-only PRs skip the build/test matrix</strong> (and the release it gates) via
<code>paths-ignore</code>; a <code>docs-passthrough</code> workflow reports the same check names
green so required checks stay satisfied and README edits stay mergeable
without burning CI minutes.</li>
<li><strong>Our CI now captures names.</strong> The dogfooded harden steps run with
<code>dns-capture: true</code> (still <code>audit</code> — monitor, don&rsquo;t firewall), so job summaries
show real destination and package-repository names instead of bare IPs, and the
capture path is exercised on every run. Safe now that <code>@v1</code> (&gt;= 1.0.35) carries
the teardown + systemd-resolved fixes.</li>
</ul>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/cowork-harness/</link><pubDate>Sat, 22 Aug 2026 05:59:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/22/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v2.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cowork-harness action is a scriptable and CI-friendly test harness that replicates the observable runtime contract of Claude Cowork, enabling developers to thoroughly test their skills across various scenarios without using the locked Desktop app. It captures evidence of what an agent actually did during a run, including invoked skills, files read, network requests, and shown options. The action supports different fidelity tiers for different testing needs, from headless operations to full-fledged simulations in Docker or Lima environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The cowork-harness action is a scriptable and CI-friendly test harness that replicates the observable runtime contract of Claude Cowork, enabling developers to thoroughly test their skills across various scenarios without using the locked Desktop app. It captures evidence of what an agent actually did during a run, including invoked skills, files read, network requests, and shown options. The action supports different fidelity tiers for different testing needs, from headless operations to full-fledged simulations in Docker or Lima environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed--breaking-requires-a-major-bump-see-specmd-12">Changed — BREAKING (requires a major bump; see <a href="./SPEC.md#12-versioning--the-10-compatibility-contract">SPEC.md §12</a>)</h3>
<ul>
<li>
<p><strong>HASH-FORMAT EPOCH — <code>cassetteVersion</code> 12. Every cassette carrying a <code>skillHash</code> fails a bare <code>replay</code>
until it is migrated.</strong> Read that sentence literally: this is not a warning you can defer.</p>
<p><strong>Migrate with one command.</strong> <code>cowork-harness rehash &lt;dir/&gt;</code> proves each cassette&rsquo;s content unchanged and
relabels it in place — no re-record, no model calls, no cost. For a cassette that has MOVED (a <code>git mv</code>, a
repo reorg, a copy into another project) its skill sources cannot be resolved from its own directory, so
use <code>cowork-harness rehash &lt;file.cassette.json&gt; --session &lt;session.yaml&gt;</code>. Anything <code>rehash</code> cannot prove
is refused rather than migrated, and does need a real re-record.</p>
<p><strong>After a successful <code>rehash</code>, the epoch is cleared and you are done with it.</strong> Migration does not touch
the other staleness classes, and it does not need to: <code>baseline</code>, <code>format</code> and <code>prompt-assets</code> behave
exactly as before — they surface in <code>staleness[]</code>, print a <code>::warning::</code>, and <strong>exit 0</strong>. Only
<code>unverifiable-skill</code> fails a bare <code>replay</code>, which is what the epoch produces and what <code>rehash</code> clears. So
a cassette that also carries, say, baseline drift migrates cleanly and then goes green with that drift
still reported as a warning, exactly as before this release. (Measured, not inferred: a cassette with a
deliberately wrong <code>fingerprint.baseline</code> replays <code>pass: true</code>, exit 0, with a non-failing <code>[baseline]</code>
finding.)</p>
<p><strong><code>verify-cassettes</code> is stricter than <code>replay</code>, and that is not new.</strong> It treats ANY staleness finding as
not-green, so a migrated cassette that still carries baseline drift replays green and reds the
verification gate — as it did before this release, for the same reason. Clear it by re-recording, or by
re-stamping <code>fingerprint.baseline</code> where the baseline moved without changing anything the recording
exercises; <a href="./docs/cassette.md#cassette-versioning">docs/cassette.md</a> covers when that re-stamp is honest
and when it is not. This release also ships a new platform baseline, so expect that drift on cassettes
recorded against the previous one.</p>
<p><strong>What changed.</strong> A plugin manifest now folds into <code>skillHash</code>/<code>contentSig</code> through canonical (JCS-style)
serialization instead of insertion-order <code>JSON.stringify</code>, so <strong>reordering keys in <code>plugin.json</code> no longer
re-stales every cassette that hashes it</strong> — semantically identical input now produces an identical digest.
<code>contentSig</code> additionally folds the directory markers <code>skillHash</code> has always folded, so an added or removed
<strong>empty directory</strong> is finally visible to it; <code>CONTENTSIG_ALGO</code> moves 4 → 5 to say so. A new
<code>fingerprint.hashFormat</code> records which transform produced the digests — <strong>absent means the legacy
pre-v12 transform, never raw bytes</strong>, since every cassette already on disk carries version-stripped
manifest digests.</p>
<p><strong>Why it fails rather than warns.</strong> A pre-epoch digest and a post-epoch digest came from different
algorithms; they cannot be compared at all. That is <code>unverifiable-skill</code> — &ldquo;this was not verified&rdquo; — and
not <code>format</code>, which is waivable and exits 0. A warning everyone ignores for a release is exactly the
green-against-unverified state the strict-replay change below exists to end, and on the day of an epoch it
would apply to every cassette in existence.</p>
<p><strong>Some cassettes will migrate with an unchanged digest.</strong> A manifest whose keys were already in canonical
order, or a tree with no manifest at all, hashes identically under both algorithms. Those are still
flagged and migrated, <strong>by recorded version rather than by whether the number moved</strong> — otherwise they
would pass unlabelled, and at the next epoch nobody could tell which algorithm produced them.</p>
<p><code>cassetteVersion</code> now means the minimum reader for the <strong>whole cassette</strong>, not just for its <code>scenario</code>
keys: a v11 reader handed a v12 cassette would recompute legacy digests and report drift that is not
there. The scenario-aware differential still applies above that floor.</p>
</li>
<li>
<p><strong>A bare <code>replay</code> now FAILS when skill staleness cannot be verified</strong> (<code>unverifiable-skill</code>), where it
previously warned on stderr, recorded the class in <code>staleness[]</code>, and exited <code>0</code>. &ldquo;Could not be checked
at all&rdquo; and &ldquo;checked and unchanged&rdquo; are different claims and only the second is green — a cassette that
had silently stopped proving anything kept passing the lane most people run, and green-against-unverified
is worse than a loud red because silence prompts a re-record while green does not. The major is required because a previously-green
input now exits non-zero — <code>verdict.pass</code> / <code>ok</code> and the per-command exit behaviour are covered surfaces
(<a href="./SPEC.md#12-versioning--the-10-compatibility-contract">SPEC.md §12</a>). Note the <em>meaning</em> of exit 1 is
unchanged (still assertion-or-agent failure), so §11&rsquo;s exit-code table needs no edit; what changed is
which inputs reach it.</p>
<p><strong>Deliberately narrow.</strong> The content-drift classes (<code>skill</code>, <code>shared-root</code>) still require
<code>--fail-on-skill-drift</code>, so that flag keeps its meaning and no inverse escape hatch is needed.</p>
<p><strong>One exception, and it exists to stop a false green:</strong> under an explicit <code>--session</code>, the drift classes
are escalated too. Without that, pointing <code>--session</code> at a WRONG but resolvable tree would turn
<code>unverifiable-skill</code> (a hard fail) into ordinary <code>skill</code> drift (warn-only) — so the flag could be used,
accidentally, to silence the very gate it exists to help you escape. <code>--session</code> is an escape from
&ldquo;cannot verify&rdquo;, never from &ldquo;verified, and it changed&rdquo;.</p>
<p><strong>Migration.</strong> The commonest cause is a cassette that MOVED — use the new <code>--session &lt;file&gt;</code> below
rather than re-recording. If you genuinely want the old behaviour for a lane, it was never expressible
as a flag and still isn&rsquo;t; fix the resolution instead.</p>
</li>
<li>
<p><strong><code>verify-cassettes --output-format json</code> gained a REQUIRED <code>privacyScanned</code> field on every result.</strong>
<code>schema/verify-cassettes.json</code> is a covered 1.0 surface (<a href="./SPEC.md#12-versioning--the-10-compatibility-contract">SPEC.md §12</a>),
and <code>privacyScanned</code> is now in its <code>required</code> list — so a consumer validating this build&rsquo;s output against
an older copy of the schema is unaffected, but one validating an OLDER CLI&rsquo;s output against the NEW schema
will fail. It is emitted on every return path, so anything keying on it can rely on it.</p>
<p>The field exists because <code>error</code> became ambiguous. A cassette that fails SHAPE validation is now still
privacy-scanned (see Fixed, below), so <code>error</code> covers both &ldquo;never scanned&rdquo; and &ldquo;scanned fine, just not
replayable&rdquo; — and a gate cannot tell those apart from it. <strong>If you have CI keyed on <code>error</code> meaning &ldquo;this
file was not checked&rdquo;, that reading is now wrong; switch to <code>privacyScanned === false</code>,</strong> where
<code>findings: []</code> is an absence of evidence rather than evidence of absence. <code>--skip-privacy</code> also reports
<code>false</code>, for the same reason.</p>
</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong><code>provenance.asarGateIds</code> — a gate-membership change is now nameable.</strong> A baseline recorded
<code>provenance.fcache</code> as two aggregates and a timestamp, so when a sync moved <code>featureCount</code> <strong>271 → 278</strong>
nothing could say <em>which</em> seven arrived, a count-neutral membership swap was invisible entirely, and
<code>content16</code>&rsquo;s diff line had to hedge &ldquo;membership <strong>and/or</strong> values moved&rdquo;. The fcache is also
server-refreshed on its own schedule (3.7–20.8 min observed), so a count delta between two baselines is
a net over days of rollout rather than a fact about the Desktop release — and the previous payload is
overwritten in place, so the question goes unanswerable the moment you think to ask it.</p>
<p>Baselines now additionally record the gate ids <strong>this release&rsquo;s own bundle references</strong>, sorted. That is
a pure function of the shipped asar: reproducible by anyone, stable across the fcache&rsquo;s refetches, and
attributable to the release. Diffing two baselines names the delta outright (1.32885.1 → 1.34493.1:
<strong>+14 / −1</strong>), and <code>sync --diff</code> prints the ids rather than a count.</p>
<p>It is deliberately <strong>not</strong> intersected with the syncing machine&rsquo;s fcache. Gate membership varies by
account segment, so filtering through one machine would both leak which gates that operator is served
and drop DARK gates — 51 of the recorded ids are absent from the live fcache, <code>enableToolSearchAuto</code>
among them. To turn an id into a name, grep it as a quoted literal in the extracted bundle; the call
site names it, which is how <code>PINNED_GATES</code> was built in the first place.</p>
</li>
<li>
<p><strong><code>record</code> now scans what it wrote, and quarantines a leaking recording instead of publishing it.</strong>
<code>scanCassette</code> had exactly one production call site — <code>verify-cassettes</code> — which runs at commit time at
the earliest. <code>hostInventoryPreflight</code> does fire before the paid spawn, but it reads the tier and the
destination path, never the resulting bytes: it is a prediction, and it can be wrong in both directions.</p>
<p>After redaction and before the write, the finished cassette is scanned. A <code>host-inventory</code> or
<code>machine-inventory</code> finding on a repo-visible path writes the recording to <code>&lt;runs-root&gt;/quarantine/</code>
(honouring <code>--run-dir</code> / <code>COWORK_HARNESS_RUNS_DIR</code>) alongside a <code>.findings.txt</code> naming exactly what
leaked, then fails without writing the requested path.</p>
<p>Three things about that policy are deliberate. <strong>Quarantine, not discard</strong> — the tokens are already
spent, and throwing the recording away is both the most expensive answer and the one most likely to end
in &ldquo;just commit it anyway&rdquo;. <strong>Only the machine-identity classes trigger it</strong> — <code>email</code> / <code>currency</code> /
<code>domain</code> / <code>path</code> findings are frequently legitimate scenario content, and a gate that fires on those
teaches the operator to pass the escape flag by reflex, which is how a safety gate becomes decoration.
<strong>Outside a git repo it warns instead of quarantining</strong> — nothing there publishes the file by accident,
so quarantining would be obstruction rather than protection. If the runs root is itself inside a working
tree, quarantine falls back to the OS temp dir and says so; moving a leak into another committable
location would be theatre.</p>
<p><code>--allow-host-inventory-fixture</code> (the flag the preflight already honours) still writes the file, and now
reports what it is publishing rather than going quiet.</p>
<p>Coverage is labelled honestly: the policy (<code>classifyRecordLeak</code>) and the effect (<code>quarantineCassette</code>)
are pure, exported and mutation-tested; the <em>wiring</em> inside <code>recordScenarioObject</code> needs a live spawn to
reach, so it is guarded structurally — the same split this repo already uses for <code>buildCassette</code>.</p>
</li>
<li>
<p><strong>Corrected a standing inaccuracy in the record-consent docs.</strong> <code>SKILL.md</code> and <code>ci-recipe.md</code> both said
the host-inventory preflight &ldquo;refuses outright rather than warn&rdquo;. It refuses for a <strong>new</strong> cassette path
but <strong>warns</strong> for one that already exists — deliberately, since refusing there would fire on every
<code>--rerecord-stale</code> pass and make the escape flag reflexive. That warn path was the gap the record-time
quarantine above now covers, so both documents now say which is which.</p>
</li>
<li>
<p><strong>Platform baseline <code>desktop-1.34493.1</code> (agent <code>2.1.237</code>).</strong> The Cowork system prompt, both sub-agent
append branches, all 28 pinned gate states, the VM egress policy and the 22-key spawn env are all
unchanged — re-derived from the new bundle rather than inferred from an absent diff row (only the
minified prompt constant id rotated). <code>sync</code> reports no unknown deltas.</p>
<p>The substantive change is in the <strong>agent</strong>, and an asar-only pass cannot see it: <code>2.1.237</code> adds six
Cowork-specific risk categories to the auto-mode permission rubric&rsquo;s vocabulary —
<code>cowork_delete_grant</code>, <code>cowork_folder_access</code>, <code>cowork_run_routine_now</code>,
<code>cowork_scheduled_task_delete</code>, <code>cowork_scheduled_task_write</code>, <code>cowork_skill_persistence</code> — in both the
native binary and the VM ELF. They are <strong>inert for this harness</strong>: the rubric is entered only on
<code>permissionMode === &quot;auto&quot;</code>, which no scenario can request and no baseline pins (now pinned by
<code>test/auto-mode-unreachable.test.ts</code>). They matter because the rubric&rsquo;s reach now names operations the
harness does model, so the existing &ldquo;auto-mode permission rubric is not modeled&rdquo; gap has moved from
generic infrastructure risk into Cowork territory. The agent&rsquo;s env-flag export table also moves
524 → 533; none of the additions are set by the Cowork spawn.</p>
<p>All three committed example cassettes are re-recorded against this baseline and stamp v12 /
<code>hashFormat: &quot;jcs1&quot;</code>.</p>
</li>
<li>
<p><strong><code>--session &lt;file&gt;</code> on <code>replay</code> and <code>verify-cassettes</code></strong> — the escape hatch for a relocated cassette. A
cassette stores <code>session:</code> relative to its own directory, so any move (<code>git mv</code>, a repo reorganisation, a
copy into another project) made skill staleness permanently unverifiable with no way to say where the
tree went; the only remedies were moving the file back or re-recording. It takes a <strong>session</strong>, not skill
directories, because <code>staleness.hash_ignore</code> is a session-level field that is not stored in the cassette —
an override carrying only directories would silently change the hash boundary. Refused for a directory
target, for a path that is not a file, and for inline scenarios; the resolved session <strong>and the dirs it
produced</strong> are echoed on stderr, since an override that silently pinned the wrong tree would manufacture
false greens. An explicit override is trusted: a mismatch under it is reported as real drift rather than
downgraded.</p>
</li>
<li>
<p><strong>Duplicate manifest paths are now reported as ambiguous</strong> instead of silently under-reported. Two mounts
can each contribute <code>skills/x/SKILL.md</code>, and every consumer keys <code>fileSigs</code> by path, so duplicates
collapsed to the last occurrence and the changed-file list could name the wrong file or none. Drift was
always still DETECTED — the hash folds every entry — so this is an attribution fix, not a false-green fix.
Exact attribution needs per-root identity in the digest, which is a hash-format epoch change.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>A cassette that fails shape validation is now privacy-scanned.</strong> <code>verify-cassettes</code> does two
independent jobs — a privacy scan and a staleness check — and both sat behind one strict <code>readCassette</code>.
Any document that failed shape validation returned early, so <code>scanCassette</code>, on the very next line, never
ran: the file was reported with zero findings, which reads in every summary as <code>0 PII finding(s)</code>. That is
a clean-looking number from an instrument that never ran, and a file too broken to replay is exactly the
kind of file a leak arrives in. Measured on a malformed fixture carrying MCP server names, an account org
and an agent roster: <strong>0 findings and exit 3 before, 6 findings and exit 1 after.</strong></p>
<p>The fix is a read-boundary <strong>split</strong>, not a loosening: <code>readCassette</code> stays exactly as strict (replay,
staleness and the hash-format epoch&rsquo;s version/<code>hashFormat</code> invariant all depend on it). A separate
<code>readCassetteForScan</code> reads the transcript only, requiring nothing but <code>events: string[]</code>, and
<code>scanCassette</code>&rsquo;s parameter type is narrowed to the fields it genuinely reads — so a future scan axis that
reaches for some other field is a compile error until the projection carries it, rather than silently
reading <code>undefined</code> off a partial document. Narrowing that type immediately turned up five fields the
scan reads that a hand audit had missed (<code>userVisibleRoots</code>, <code>scenario.name</code>, <code>scenario.session</code>,
<code>scenarioSource</code>, <code>environment.agentImage.ref</code>).</p>
<p>The projection also <strong>fails closed on an unrecognized tier</strong>. <code>scanCassette</code> exempts a positively-sealed
tier and scans everything else including <code>undefined</code>, but it tests set membership — so an arbitrary
string (<code>&quot;garbage&quot;</code>, a typo&rsquo;d <code>&quot;containerr&quot;</code>) is neither, and would have skipped the structural
host-inventory scan entirely. The strict reader cannot produce that; this one can, because malformed
input is its whole job.</p>
</li>
<li>
<p><strong>The pre-commit cassette gate now fails CLOSED.</strong> <code>.githooks/pre-commit</code> tested <code>hook_status</code> for <code>1</code>
(block) and <code>3</code> (warn) and let every other outcome through to a successful commit, so the guard switched
itself off — silently — on outcomes that ordinary refactors produce: exit <code>2</code> (<code>examples/replays/</code> renamed
or emptied, or any CLI flag renamed), exit <code>127</code> (<code>node</code> off <code>PATH</code>), and a missing <code>dist/cli.js</code>, which is
the state of a fresh clone, a <code>git clean -xdf</code>, a branch switch, and any tree with a failing typecheck
(<code>npm run build</code> does <code>rm -rf dist</code> first). None of those fail a test elsewhere. Anything that is not a
proven clean <code>0</code> now blocks.</p>
<p>This matters more than a local convenience: <code>ci.yml</code> triggers on <code>push: [main]</code> and <code>pull_request</code>, but the
documented workflow lands with <code>merge --ff-only</code> into <code>main</code> and pushes afterwards — so on that path the
hook is not one layer of two, it is the only gate, and what it waves through is already public when CI
reds.</p>
</li>
<li>
<p><strong>An unscannable cassette no longer commits unscanned.</strong> Exit 3 folds together unverifiable <em>staleness</em>,
an unsupported <code>cassetteVersion</code>, and a per-file read error. Only the first means &ldquo;we looked and could not
conclude&rdquo;; the other two mean the privacy scan never ran, so there is no evidence either way about host
inventory — and a cassette recorded by a newer CLI than the committer&rsquo;s <code>dist/</code> committed with nothing
having checked it. The hook now splits exit 3 by cause (<code>--output-format json</code>) and blocks on the two that
are not staleness, in line with the <code>can't verify ⇒ not green</code> rule the CLI states everywhere else. A
payload it cannot interpret is treated as undetermined, not as staleness.</p>
</li>
<li>
<p><strong>The gate no longer misses cassettes by filename.</strong> <code>record --out</code> accepts an arbitrary path and does not
validate the suffix, so a recording written to e.g. <code>notes/run.json</code> was invisible to the hook&rsquo;s trigger,
to CI&rsquo;s pathspec, and to <code>git ls-files '*.cassette.json'</code>. The hook trigger is now content-derived (any
staged <code>.json</code> whose staged blob carries the <code>&quot;generator&quot;: &quot;cowork-harness&quot;</code> marker), and CI cross-checks
the suffix-derived set against the content-derived one. Separately, <code>resolveInputs</code> does not recurse, so
<code>examples/replays/sub/x.cassette.json</code> was reachable by neither the directory scan nor the per-file loop
(which excluded all of <code>examples/replays/</code>); the exclusion is now scoped to files <em>directly</em> in that
directory.</p>
</li>
<li>
<p><strong>CI scans every tracked cassette, not just one directory.</strong> The sweep is derived from <code>git ls-files</code>
rather than a hard-coded path, fails loudly if the pathspec ever matches zero files (an <code>xargs -r</code> sweep
exits 0 on no matches and reads as success), and carries exactly one exclusion with its reason recorded:
<code>test/evals/files/report-check.cassette.json</code> is an eval <em>attachment</em>, not a recording — it has no
<code>scenario.session</code>, so <code>readCassette</code> rejects its shape before the scan can run. Measured rather than
assumed: adding a <code>session</code> field does not make it verifiable, it converts the exit 3 into an exit 1 on
baseline drift for a fixture that is never re-recorded.</p>
</li>
<li>
<p><strong>The local gate is no longer laxer than the CI gate on the same directory.</strong> The hook passed
<code>--allow-email</code>/<code>--allow-domain</code> suppressions that <code>ci.yml</code> does not; the committed fixtures verify clean
without them, so they are gone. Its scratch file also moved from a predictable <code>/tmp</code> path to <code>mktemp</code>, and
a clean run now says so instead of passing in silence.</p>
</li>
<li>
<p><strong><code>sync</code> derived the enforced egress allowlist from a bundle-wide regex, and Desktop 1.34493.1 made that
wrong.</strong> <code>network.allowDomains</code> is the allowlist the harness ENFORCES (<code>boundaryAllowList</code> plus the
session egress plan), but it was built by matching every <code>*.anthropic.com</code> / <code>*.claude.ai</code> literal in the
whole app bundle. 1.34493.1 added a webview first-party-origin classifier — a navigation-trust tier naming
<code>www.claude.ai</code> and <code>staging.claude.ai</code> — and the sweep pulled both into the enforced list, which would
have permitted egress Cowork denies.</p>
<p>Narrowing the sweep was investigated and rejected: on the first-party deployment there is nothing to
narrow to. The 1p class returns <code>vmEgressPolicy(){return null}</code>, so <code>resolveVmAllowedDomains</code> falls
through to the session&rsquo;s <strong>server-delivered</strong> <code>egressAllowedDomains</code>, and the only host the bundle
contributes is the OTLP endpoint. <code>vmAllowedDomains</code>/<code>firewallAlso</code> are the 3p path and Desktop&rsquo;s own
renderer endpoints — neither is the VM allowlist. Any bundle scan is unsound both ways: blind to
server-delivered hosts, open to hosts that are not egress.</p>
<p><code>network.allowDomains</code> is therefore a <strong>pinned, hand-curated list carried forward</strong> from the newest
committed baseline, and a new fail-closed <code>checkEgressContractFacts</code> guards the three constructions that
justify pinning (the 1p null policy, the resolver&rsquo;s fall-through to its caller-supplied argument, and the
OTLP-only augmentation) — so a real change in how Cowork computes egress hard-fails <code>sync</code> instead of
silently rewriting the list. The baseline&rsquo;s <code>network.$comment</code> now records that provenance and names the
entries that are unverified as VM egress; <code>network</code> became a <code>looseObject</code> so that note survives loading.</p>
</li>
<li>
<p><strong>Consumers of 1.25.0 were NOT affected by this</strong> — it is recorded because the shape is worth knowing,
not because it shipped. While building <code>--session</code>, skill staleness, session-shape staleness, label
provenance and the skill-hash debug dump could each have resolved a different session. The cassette-relative join was duplicated byte-identically
in three functions and <code>sessionFingerprintDrift</code> accepted an override its only caller never passed, so
<code>--session</code> would have verified skill content against the override while session shape still resolved the
recorded path — reporting &ldquo;clean&rdquo; on an axis that hard-fails when used normally. All consumers now share
one resolver.</p>
</li>
<li>
<p><strong>An unresolvable session now says WHY</strong> — missing file, unreadable/unparseable YAML, or declared mounts
that do not exist — instead of one undifferentiated message. Those point at different fixes, and only the
first looks like a relocation, so it also names the remedy.</p>
</li>
</ul>
<h3 id="known-limitations-documented-not-fixed">Known limitations (documented, not fixed)</h3>
<ul>
<li><strong>Multi-root skill hashing is order-dependent.</strong> <code>hashSkillDirs</code> folds roots sorted by absolute path
while deliberately excluding a root&rsquo;s own name from the digest, so identical content at differently
sorting directory names hashes differently. One axis (root ORDER) fails loudly as false drift. A second is
worse: roots fold into one digest with no root-boundary marker, so moving a file BETWEEN roots is
invisible — a genuine false green. Multi-root cassettes are still not refused, because none exists in
any reachable corpus and refusing would break input nobody has; instead replay now emits a note when a
cassette records two or more roots. Fixing it needs a hash-format epoch.
Not scheduled: no multi-root cassette exists in any reachable corpus (32 cassettes on the widest
denominator across three repos), and no session declares 2+ plugin/skill roots. Pinned by tests in
<code>test/skill-hash.test.ts</code> so the eventual fix is a deliberate change.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): patch the nanoid advisory and take the dev-dep bumps by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/121">https://github.com/yaniv-golan/cowork-harness/pull/121</a></li>
<li>release: 2.0.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/122">https://github.com/yaniv-golan/cowork-harness/pull/122</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1.25.0...v2.0.0">https://github.com/yaniv-golan/cowork-harness/compare/v1.25.0...v2.0.0</a></p>
]]></content:encoded></item><item><title>Nx Affected Projects</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/nx-affected-projects/</link><pubDate>Fri, 21 Aug 2026 22:04:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/nx-affected-projects/</guid><description>Version updated for https://github.com/mayurrawte/github-nx-affected to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates smart deploys for Nx monorepos by using the nx affected command to identify changed projects. It outputs a matrix-ready JSON array of affected apps, allowing users to fan out CI jobs on what actually changed. The action handles base and head SHAs automatically and provides optional features such as auto-deepening history and versioning Node.js and package managers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mayurrawte/github-nx-affected">https://github.com/mayurrawte/github-nx-affected</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nx-affected-projects">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates smart deploys for Nx monorepos by using the <code>nx affected</code> command to identify changed projects. It outputs a matrix-ready JSON array of affected apps, allowing users to fan out CI jobs on what actually changed. The action handles base and head SHAs automatically and provides optional features such as auto-deepening history and versioning Node.js and package managers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="nx-affected-v100">Nx Affected v1.0.0</h2>
<p>One-step composite action that detects affected Nx projects and outputs <strong>matrix-ready JSON arrays</strong> for fan-out builds, tests, and deploys.</p>
<h3 id="features">Features</h3>
<ul>
<li><code>affected</code>, <code>affected-apps</code>, <code>affected-libs</code> — JSON arrays ready for <code>fromJSON()</code> in a matrix strategy</li>
<li><code>has-affected</code> boolean + <code>count</code> — skip whole jobs when nothing changed</li>
<li><code>base-sha</code> output — resolved comparison base</li>
<li>Smart base detection: PRs use <code>pull_request.base.sha</code>, pushes use <code>event.before</code>, falls back to <code>HEAD~1</code></li>
<li><code>auto-deepen</code> for shallow clones</li>
<li>npm / yarn / pnpm auto-detection from lockfile</li>
<li><code>target</code> filtering (only projects with a <code>build</code>/<code>test</code>/<code>deploy</code> target)</li>
<li><code>working-directory</code> support for nested workspaces</li>
</ul>
<h3 id="quick-start">Quick start</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">mayurrawte/github-nx-affected@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">id</span>: <span style="color:#ae81ff">nx</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">target</span>: <span style="color:#ae81ff">build</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">if</span>: <span style="color:#ae81ff">steps.nx.outputs.has-affected == &#39;true&#39;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">run</span>: <span style="color:#ae81ff">echo &#34;Building ${{ steps.nx.outputs.affected-apps }}&#34;</span>
</span></span></code></pre></div><p>Tested on Ubuntu + macOS with npm, yarn, and pnpm workspaces.</p>
]]></content:encoded></item><item><title>Apex Code Coverage Transformer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/apex-code-coverage-transformer/</link><pubDate>Fri, 21 Aug 2026 22:03:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/apex-code-coverage-transformer/</guid><description>Version updated for https://github.com/mcarvin8/apex-code-coverage-transformer to version v3.1.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The apex-code-coverage-transformer action automates the transformation of Apex code coverage JSON files from Salesforce deployments or test runs into various formats used by popular CI/CD tools, such as SonarQube, Codecov, GitHub, GitLab, Azure DevOps, and Bitbucket. It streamlines the process of integrating Salesforce coverage data into existing workflows without requiring the installation of the Salesforce CLI.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcarvin8/apex-code-coverage-transformer">https://github.com/mcarvin8/apex-code-coverage-transformer</a></strong> to version <strong>v3.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/apex-code-coverage-transformer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The apex-code-coverage-transformer action automates the transformation of Apex code coverage JSON files from Salesforce deployments or test runs into various formats used by popular CI/CD tools, such as SonarQube, Codecov, GitHub, GitLab, Azure DevOps, and Bitbucket. It streamlines the process of integrating Salesforce coverage data into existing workflows without requiring the installation of the Salesforce CLI.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="313-2026-08-21"><a href="https://github.com/mcarvin8/apex-code-coverage-transformer/compare/v3.1.2...v3.1.3">3.1.3</a> (2026-08-21)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>action:</strong> remove @salesforce/core Logger call breaking the bundled Action (<a href="https://github.com/mcarvin8/apex-code-coverage-transformer/issues/386">#386</a>) (<a href="https://github.com/mcarvin8/apex-code-coverage-transformer/commit/ae14d349058fe9a3ef3e3cff59ec2cfad06a8338">ae14d34</a>)</li>
</ul>
]]></content:encoded></item><item><title>mockdr — Multi-EDR Mock Server</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/mockdr-multi-edr-mock-server/</link><pubDate>Fri, 21 Aug 2026 22:02:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/mockdr-multi-edr-mock-server/</guid><description>Version updated for https://github.com/mockdr/mockdr to version v2.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The mockdr GitHub Action is a self-contained multi-EDR mock server designed to simulate responses from SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Elastic Security, Cortex XDR, Splunk SIEM, and Microsoft Sentinel APIs. It provides realistic seed data, real API paths, and response envelopes for testing security platforms without the need for real APIs or lab licenses. The action supports SOAR playbooks, SIEM connectors, and automation scripts to point at mockdr without modification, ensuring consistent and deterministic data across all vendors.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mockdr/mockdr">https://github.com/mockdr/mockdr</a></strong> to version <strong>v2.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mockdr-multi-edr-mock-server">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The mockdr GitHub Action is a self-contained multi-EDR mock server designed to simulate responses from SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Elastic Security, Cortex XDR, Splunk SIEM, and Microsoft Sentinel APIs. It provides realistic seed data, real API paths, and response envelopes for testing security platforms without the need for real APIs or lab licenses. The action supports SOAR playbooks, SIEM connectors, and automation scripts to point at mockdr without modification, ensuring consistent and deterministic data across all vendors.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A correction release. Everything here fixes something 2.0.2 shipped — ten
routes that answered <code>200</code> with a claim that was not true, and one
authentication channel that was more permissive than the product it mocks.</p>
<p>None of it crashed. That is the point: a client cannot detect a success that
is false, so the bug surfaces later, against production. Exposing that failure
mode is what mockdr is for, and in these ten places it was manufacturing it
instead.</p>
<h2 id="upgrading">Upgrading</h2>
<p>No response shape that was correct in 2.0.2 changes. Two behaviours do, and
both were defects:</p>
<ul>
<li><code>rules/_import</code> now reports what it actually did. It previously returned
<code>success: true, success_count: 0</code> for every input, so anything reading that
as confirmation was reading a fiction.</li>
<li>HEC no longer honours <code>?token=</code> unless <code>MOCKDR_SPLUNK_HEC_QUERY_STRING_AUTH</code>
is set. That is splunkd&rsquo;s own default, and the reason the old behaviour was
wrong.</li>
</ul>
<h2 id="hec-query-string-auth-measured-against-splunk-1042">HEC query-string auth, measured against Splunk 10.4.2</h2>
<p>2.0.2 taught HEC to accept its token as <code>?token=</code> and accepted it
unconditionally, on an assumption I flagged at the time as unverified. It was
wrong — and wrong in the direction that matters, because mockdr was accepting
what a stock indexer rejects. A client validated here would have failed in
production.</p>
<p>Probing a real Splunk 10.4.2 produced two findings the documentation alone
would not have:</p>
<table>
  <thead>
      <tr>
          <th></th>
          <th><code>allowQueryStringAuth</code> unset (default)</th>
          <th><code>allowQueryStringAuth = true</code></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>no token</td>
          <td><code>401</code> code 2 <em>Token is required</em></td>
          <td><code>401</code> code 2</td>
      </tr>
      <tr>
          <td><code>?token=</code> invalid</td>
          <td><code>403</code> code 4 <em>Invalid token</em></td>
          <td><code>403</code> code 4</td>
      </tr>
      <tr>
          <td><code>?token=</code> valid</td>
          <td><code>400</code> code 16 <em>Query string authorization is not enabled</em></td>
          <td><code>200</code> code 0</td>
      </tr>
      <tr>
          <td>header valid</td>
          <td><code>200</code> code 0</td>
          <td><code>200</code> code 0</td>
      </tr>
  </tbody>
</table>
<p>First: splunkd <em>does</em> read the parameter, but refuses it with a dedicated
error code unless the setting is on — and it is off by default.</p>
<p>Second, and less obvious: the token is validated <em>before</em> the channel is
checked. An invalid token sent by query string is a <code>403</code>, not the <code>400</code>;
only a valid token ever reaches code 16. Implementing this from intuition
would have put the channel check first and got it backwards.</p>
<p>mockdr reproduces all eight measured cases exactly.
<code>MOCKDR_SPLUNK_HEC_QUERY_STRING_AUTH</code> mirrors the <code>inputs.conf</code> setting and
defaults to off.</p>
<h2 id="ten-routes-that-answered-200-with-something-untrue">Ten routes that answered 200 with something untrue</h2>
<p><strong><code>_import</code> never read the request body.</strong> It reported
<code>success: true, success_count: 0</code> for any input, so a client could export its
rules, import them into a fresh instance, be told it had worked, and find
nothing there — the round trip a migration check exists to prove was
confirming a success it had never performed. It now parses the NDJSON (raw or
multipart, since Kibana&rsquo;s UI posts a file and scripted clients post the body),
creates each rule, reports a <code>409</code> per conflicting <code>rule_id</code> unless
<code>overwrite=true</code>, and skips <code>_export</code>&rsquo;s trailing summary line rather than
counting it as a rule.</p>
<p><strong>Three defects in 2.0.2&rsquo;s own dispatch-lifecycle feature, sharing one root
cause.</strong> State was re-derived from elapsed time on every read, so the clock
silently overwrote whatever a control action had just set:</p>
<ul>
<li><code>finalize</code> and <code>cancel</code> appeared to do nothing — a finalized job went back
to reporting <code>QUEUED</code>.</li>
<li><code>touch</code> reset the very timestamp the clock reads, sending a running job
backwards from <code>RUNNING</code> to <code>QUEUED</code>. Real Splunk&rsquo;s <code>touch</code> extends the TTL
and leaves the search alone.</li>
<li>A paused job kept running and reported <code>isDone: 1</code>.</li>
</ul>
<p>The fix is to the model, not the symptom: <code>published_at</code> is now an immutable
dispatch origin, <code>touched_at</code> owns the TTL, <code>paused_at</code> freezes the clock, and
an explicit control action wins over the derived state.</p>
<p><strong>Six more, each substituting a plausible answer for the real one:</strong></p>
<ul>
<li><code>/api/detection_engine/privileges</code> read <code>username</code> from an auth context that
spells it <code>user</code>, so every caller was reported as the built-in <code>elastic</code>
superuser — including a <code>viewer</code>, whose actual privileges the same response
then correctly reported as read-only.</li>
<li><code>_bulk_create</code> rejected <code>risk_score: 0</code> as <code>Invalid value &quot;undefined&quot;</code>. A
falsiness check turned a value the client did send into one it appeared to
have omitted.</li>
<li><code>/api/spaces/space/{id}</code> returned the default space for any id, so a typo or
a deleted space read as success and the client wrote into the wrong space.</li>
<li><code>action_status</code> filed every pending action under <code>isolate</code>, so a pending
<code>kill-process</code> was reported as a pending isolation.</li>
<li><code>action_log</code> documented newest-first and served repository insertion order,
putting the stalest entry on page 1.</li>
<li><code>/api/exception_lists/summary</code> answered without a <code>list_id</code>, returning
all-zero counts indistinguishable from a list that genuinely has no items.</li>
</ul>
<h2 id="also">Also</h2>
<p>Credential-bearing query parameters are now masked in the request audit log.
The <code>Authorization</code> header was already reduced to its last four characters,
but the query string was stored verbatim — so the credential that masking
exists to protect sat in the log in full, one field over. This is hardening
rather than a fix: <code>/_dev</code> is admin-gated and publishes tokens through
<code>/_dev/tokens</code> by design, so nothing was reachable here that was not already
reachable more directly.</p>
<hr>
<p>2,788 backend tests, 2,183 frontend unit tests, 9 end-to-end flows. mypy
<code>--strict</code> clean across 781 files.
Full changelog: <a href="https://github.com/mockdr/mockdr/blob/main/CHANGELOG.md">https://github.com/mockdr/mockdr/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Overruled Verdict Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/overruled-verdict-auditor/</link><pubDate>Fri, 21 Aug 2026 22:02:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/overruled-verdict-auditor/</guid><description>Version updated for https://github.com/MohibShaikh/overruled-action to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the auditing process of AI SOC agents using the overruled tool, which checks if an agent is overruled on ground-truth cases. It fails the workflow if the subject agent gets overruled and provides a JUnit XML report for further analysis. The action allows users to specify the investigation URL, token, number of runs, output format, and output file path.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MohibShaikh/overruled-action">https://github.com/MohibShaikh/overruled-action</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/overruled-verdict-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the auditing process of AI SOC agents using the overruled tool, which checks if an agent is overruled on ground-truth cases. It fails the workflow if the subject agent gets overruled and provides a JUnit XML report for further analysis. The action allows users to specify the investigation URL, token, number of runs, output format, and output file path.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Marketplace listing name must be unique across actions, users and organizations, and the account <code>OverRuled</code> already holds <code>overruled</code>. The listing is now &ldquo;Overruled Verdict Auditor&rdquo;.</p>
<p>The <code>uses:</code> path is unchanged. The README pins <code>@v0</code> so consumers do not need a bump on every patch.</p>
]]></content:encoded></item><item><title>PCI Payment Page Script Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/pci-payment-page-script-check/</link><pubDate>Fri, 21 Aug 2026 22:02:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/pci-payment-page-script-check/</guid><description>Version updated for https://github.com/ntoledo319/pci-payment-page-check to version v1.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks the third-party scripts on a payment page to ensure they are authorized according to PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1. It fails the build if any unauthorized script is detected, helping prevent security risks associated with unreviewed third-party integrations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ntoledo319/pci-payment-page-check">https://github.com/ntoledo319/pci-payment-page-check</a></strong> to version <strong>v1.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pci-payment-page-script-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks the third-party scripts on a payment page to ensure they are authorized according to PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1. It fails the build if any unauthorized script is detected, helping prevent security risks associated with unreviewed third-party integrations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This patch makes the Action summary a safe handoff into Tessera without changing inputs or failure semantics.</p>
<ul>
<li>Adds a scope-matched “Put this result to work” section.</li>
<li>Uses only readiness-gated, same-origin Tessera sample and checkout URLs from the API response.</li>
<li>Allows only the documented PCI sample and checkout paths; rejects query strings, fragments, alternate origins, and unexpected paths.</li>
<li>Never offers the recurring monitor for saved HTML, embedded, outsourced, or unspecified scope, and never synthesizes an unavailable checkout.</li>
<li>Verified by 19 unit tests plus the contract-double integration smoke.</li>
</ul>
<p>Existing workflows may continue to use <code>ntoledo319/pci-payment-page-check@v1</code>.</p>
]]></content:encoded></item><item><title>ExploitSpec security regression tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/exploitspec-security-regression-tests/</link><pubDate>Fri, 21 Aug 2026 22:01:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/exploitspec-security-regression-tests/</guid><description>Version updated for https://github.com/pazent/exploitspec to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ExploitSpec is a tool that automates regression testing for security vulnerabilities by converting HTTP exploits into small, reviewable tests. It ensures the same vulnerability does not return by verifying that an invariant fails on a vulnerable baseline, passes after a fix, and remains stable across repeated runs. The tool uses YAML-based specs and provides a local-first approach to testing without requiring accounts or hosted services.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pazent/exploitspec">https://github.com/pazent/exploitspec</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/exploitspec-security-regression-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ExploitSpec is a tool that automates regression testing for security vulnerabilities by converting HTTP exploits into small, reviewable tests. It ensures the same vulnerability does not return by verifying that an invariant fails on a vulnerable baseline, passes after a fix, and remains stable across repeated runs. The tool uses YAML-based specs and provides a local-first approach to testing without requiring accounts or hosted services.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>ExploitSpec v0.2.0 adds a bounded, local-only path from a HAR 1.2 capture to a
reviewable version 1 security regression spec.</p>
<h2 id="har-import">HAR import</h2>
<p><code>exploitspec import har --list</code> first prints value-free request summaries. An
explicit one-based <code>--entry</code> is then required to create a spec; no request is
selected implicitly and no captured traffic is replayed.</p>
<p>The generated YAML replaces the captured origin, path segments, query and form
names and values, supported header values, JSON object keys, and JSON string
leaves with positional <code>EXPLOITSPEC_HAR_*</code> environment placeholders. Importing
a capture never authorizes its target: non-loopback execution still requires an
explicit <code>run --allow-host</code> decision.</p>
<p>The importer accepts at most 8 MiB and 256 entries, caps generated placeholders
at 4,096, and keeps the ordinary 1 MiB spec limit. Ambiguous JSON members,
custom header names, encoded or binary bodies, multipart data, opaque media
types, and JSON numbers, booleans, or null values fail closed. The documented
format remains version 1.</p>
<h2 id="distribution-integrity">Distribution integrity</h2>
<p>The release contains Linux, macOS, and Windows archives plus <code>SHA256SUMS</code>.
GitHub build-provenance attestations cover every archive and the checksum
manifest and can be checked with <code>gh attestation verify</code>.</p>
<p><strong>Full comparison:</strong> <a href="https://github.com/pazent/exploitspec/compare/v0.1.0...v0.2.0">https://github.com/pazent/exploitspec/compare/v0.1.0...v0.2.0</a></p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/skilltotal-ai-component-security-scan/</link><pubDate>Fri, 21 Aug 2026 22:00:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.42.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SkillTotal is an open-source CLI tool that analyzes AI-related components, including agent skills/plugins, MCP servers, npm packages, Python packages, repositories, and AI-generated projects. It statically scans these components to identify security risks, dangerous capabilities, prompt-injection surfaces, and data-exfiltration paths before installation or trust. SkillTotal avoids running components on the user’s machine and provides deterministic, evidence-anchored reports that are free of false positives.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.42.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SkillTotal is an open-source CLI tool that analyzes AI-related components, including agent skills/plugins, MCP servers, npm packages, Python packages, repositories, and AI-generated projects. It statically scans these components to identify security risks, dangerous capabilities, prompt-injection surfaces, and data-exfiltration paths before installation or trust. SkillTotal avoids running components on the user&rsquo;s machine and provides deterministic, evidence-anchored reports that are free of false positives.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Credential-only files are detected (ruleset 46).</strong> A file that <em>is</em> a credential rather than
one that contains one had no pattern to match: no assignment, no vendor prefix. The MCP
publisher&rsquo;s login artifacts (<code>.mcpregistry_github_token</code>, <code>.mcpregistry_registry_token</code>) are now
read as the credentials they are. The registry token grants republish rights over the server, so
shipping one in a package is a standing supply-chain takeover of that component.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>A long secret could survive redaction in the report.</strong> Evidence snippets are capped at
240 characters <em>before</em> redaction ran, so <code>snippet.replace(value, marker)</code> silently did nothing
whenever the secret was longer than the cap — leaving most of a live credential (a JWT, a PEM
body, a token on a minified line) in the output. Redaction now removes the longest prefix of the
secret that is actually present. A security report must never re-publish what it found.</li>
</ul>
]]></content:encoded></item><item><title>promptry eval</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/promptry-eval/</link><pubDate>Fri, 21 Aug 2026 22:00:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/promptry-eval/</guid><description>Version updated for https://github.com/promptry/promptry to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action described in the README automates the creation of documentation content for a repository using templates provided by a specified template provider. It solves the problem of repetitive documentation tasks by generating documentation based on predefined templates, reducing the risk of errors and saving development time. The key capabilities include:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/promptry/promptry">https://github.com/promptry/promptry</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/promptry-eval">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action described in the README automates the creation of documentation content for a repository using templates provided by a specified template provider. It solves the problem of repetitive documentation tasks by generating documentation based on predefined templates, reducing the risk of errors and saving development time. The key capabilities include:</p>
<ul>
<li><strong>Template Management</strong>: Allows users to manage and configure templates used to generate documentation.</li>
<li><strong>Content Generation</strong>: Automatically generates documentation content using provided templates, filling in placeholders with dynamic data from the repository&rsquo;s metadata or other sources.</li>
<li><strong>Reusability</strong>: Enables reuse of generated documentation across different repositories or projects by maintaining a centralized template library.</li>
</ul>
<p>This action streamlines the documentation creation process and ensures consistency across multiple repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><strong>OpenAI drop-in capture (Python + JS at parity):</strong> <code>from promptry.openai import OpenAI</code> records every chat/responses/embeddings call — cost, tokens,
cached-token split, latency, and a call-site-inferred name — with streaming
and failures handled. JS ships the same via <code>wrapOpenAI()</code> (<code>promptry-js/openai</code>).</li>
<li><strong>Cost-attributed call traces:</strong> <code>with promptry.trace(&quot;agent&quot;):</code> (and <code>trace()</code>
in JS) groups a run&rsquo;s LLM calls; the dashboard&rsquo;s new <strong>Traces</strong> page shows a
per-step token/$ waterfall. Invocation metadata only — not distributed tracing.</li>
<li><strong>Alerting config UI:</strong> dashboard Settings shows configured channels
(Slack/webhook, PagerDuty, email, OTel export) and can fire a test alert;
new <code>GET /api/alerts/status</code> and <code>POST /api/alerts/test</code> endpoints.</li>
<li><strong>Postgres scale-tier backend (alpha, opt-in):</strong> <code>[storage] mode = &quot;postgres&quot;</code>
(or <code>$PROMPTRY_POSTGRES_DSN</code>) points the whole store at a shared PostgreSQL
server via <code>promptry[postgres]</code>. SQLite on one file stays the tested default.</li>
<li><strong>Internals:</strong> shared <code>tomllib</code>/<code>tomli</code> shim; batched suite-list score history
(kills an N+1 on <code>/api/suites</code>); ruff ruleset pinned for CI/local parity;
<code>co_qualname</code> polyfill so call-site naming matches on Python 3.10.</li>
</ul>
<hr>
<p><strong>Install:</strong> <code>pip install -U promptry</code> · <code>npm install promptry-js@1.1.0</code>
<strong>Site + live price calculator:</strong> <a href="https://promptry.run">https://promptry.run</a> · <a href="https://promptry.run/prices/">https://promptry.run/prices/</a></p>
]]></content:encoded></item><item><title>Provael VLA red-team</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/provael-vla-red-team/</link><pubDate>Fri, 21 Aug 2026 21:59:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/provael-vla-red-team/</guid><description>Version updated for https://github.com/provael/provael to version v0.37.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Provael™ automates the red-teaming of Vision-Language-Action (VLA) robot policies through simulation. It evaluates policy success by running a series of attacks and measuring Attack Success Rate (ASR), providing an ASR-by-attack table, a pass/fail scorecard, and a SARIF report. The action is particularly useful for testing the robustness of VLA policies in various scenarios.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/provael/provael">https://github.com/provael/provael</a></strong> to version <strong>v0.37.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/provael-vla-red-team">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Provael™ automates the red-teaming of Vision-Language-Action (VLA) robot policies through simulation. It evaluates policy success by running a series of attacks and measuring Attack Success Rate (ASR), providing an ASR-by-attack table, a pass/fail scorecard, and a SARIF report. The action is particularly useful for testing the robustness of VLA policies in various scenarios.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong><code>provael doctor</code> — the command that answers &ldquo;why did that not work here&rdquo;.</strong> Twenty-six
top-level commands and not one diagnosed an install. The first-run transcript shows the cold path
is twenty seconds, so the install is not the problem; the SECOND run is, when someone reaches for
<code>--policy smolvla</code> without the <code>[lerobot]</code> extra or for a keep-out suite with no calibration and
gets an import error or a silent default instead of a diagnosis.</p>
<p>One screen: Python and platform, installed version against PyPI (<code>--offline</code> skips the lookup),
which policy backends are ready and which are <code>SCAFFOLDING_POLICIES</code> <strong>with the reason each is
scaffolding</strong>, which suites actually import, whether <code>CALIBRATED_ZONES</code> is populated (it is not —
it says so and points at issue #136), whether <code>PROVAEL_REQUIRE_CALIBRATED</code> is set, and the age of
the freshness signal against <code>STALE_DAYS</code>. Nothing is inferred: a suite is reported importable
only after being constructed, and &ldquo;ready&rdquo; explicitly does not claim a checkpoint is present.</p>
</li>
<li>
<p><strong>Published JSON Schemas for the two artifacts third parties are asked to produce.</strong>
<code>schemas/report.v4.schema.json</code> and <code>schemas/leaderboard.v5.schema.json</code>. The tree carried three
<code>$schema</code> keys and none described <code>report.json</code> or <code>leaderboard.json</code>, so an open submission queue
with zero external rows was asking people to guess the shape. They are <strong>generated from the
pydantic models</strong> (<code>scripts/gen_schemas.py</code>), not written from example files, so they describe the
contract rather than today&rsquo;s artifacts; <code>tests/test_published_schemas.py</code> validates all 33
committed artifacts against them, including schema-2 and schema-3 reports that predate the current
model. A <code>vN</code> schema accepts <code>N</code> or lower and <strong>refuses</strong> anything higher, so a too-old tool says
so rather than silently passing. Referenced from <code>CONTRIBUTING-leaderboard.md</code> with a
<code>check-jsonschema</code> one-liner.</p>
</li>
<li>
<p><strong>A measured result for <code>weight_integrity</code>, and a study page that leads with what it is not.</strong>
The family shipped with zero output. <code>results/weight_integrity_stub/</code> now holds the ladder as five
shards plus an <code>aggregate.json</code> analysis, in the same shape as the ten-task suite — 750 episodes,
both arms at every rung, benign control throughout. <code>docs/studies/weight-integrity-stub.md</code>
publishes it with the caveat block <strong>above</strong> any number: stub backend, 64-parameter INT8 danger
head, separation expected by construction, flips emulated with <code>Literal[True]</code>, and no
corroboration of the architecture-dependence result it was built from.</p>
<p>Gradient 50/50 at every rung; random 4/250; benign control 0/50 throughout. The interval is
bootstrapped over the five <strong>rungs</strong>, not over episodes, because the rung is the unit of analysis
— and n = 5 is stated rather than hidden. <strong>No leaderboard row was added</strong>, and the study page says
why: the board is the real-policy board, a shared table asserts comparability, and this is not
comparable to anything on it.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>A stub run could reset the freshness badge, and briefly did.</strong> Committing the study above put a
<code>policy='stub'</code> execution manifest under <code>results/</code>, and <code>latest_measurement</code> — which scans
committed runs — immediately reported &ldquo;today&rdquo;. The badge would have gone from &ldquo;11 days ago, red&rdquo;
to green with nothing re-measured.</p>
<p>The stub satisfies the letter of the definition: it is a registered policy and the run does
execute attacks against it. <code>docs/standards/last-measured.md</code> had already written this refusal
down on 21 August with nothing in the code enforcing it. <code>watch.counts_as_measurement</code> now
enforces it, <code>FIXTURE_POLICIES</code> names the backends that do not count, and the badge correctly
reads <strong>12 days, red</strong>.</p>
</li>
<li>
<p><strong>One family count, computed, everywhere.</strong> Four surfaces disagreed simultaneously:
<code>docs/attacks.md</code> opened with &ldquo;<strong>Fourteen</strong> adversarial families&rdquo;, <code>docs/examples.md</code> said
<code>full-sweep</code> &ldquo;runs all 14&rdquo;, <code>docs/studies/action-envelope.md</code> called 14 &ldquo;the <strong>full adversarial
registry</strong>&rdquo;, and README said thirteen families lacked a real-model measurement while claiming
twelve. The true numbers, each with its definition: <strong>16</strong> adversarial families (registry minus
<code>baseline</code> and <code>control</code>), <strong>18</strong> total registered families, <strong>38</strong> adversarial attacks, <strong>41</strong>
total registered attacks.</p>
<p><code>tests/test_counted_claims.py</code> enumerated phrase patterns, which is why it was green while all
four were wrong — it checked the claims it was handed rather than the claims that exist. It now
sweeps every <code>&lt;number&gt; … families</code> / <code>&lt;number&gt; … attacks</code> construction in README and <code>docs/**</code>,
requiring each to be a registry-derived value or a <strong>named subset</strong> with a stated reason. The
first version of the regex missed <code>**Fourteen**</code> because emphasis wraps the number; that hole is
fixed and noted, since it would have skipped the exact claim the sweep was written for.</p>
</li>
<li>
<p><strong>The README described a different run than the board publishes.</strong> It said the board was &ldquo;measured
with <strong><code>provael 0.1.0</code></strong>&rdquo; while the board and all ten shards say <code>0.32.0</code>; <code>0.1.0</code> is the
<code>tool_version</code> of the superseded single-task run. <code>test_leaderboard_version_claim</code> already tied
the board to its shards and passed throughout, because the README was never in the comparison. It
is now. The paragraph also states, in the words of the file itself, that
<code>leaderboard/method-equivalence.json</code> is <em>&ldquo;a code-inspection argument, NOT a re-measurement.&rdquo;</em></p>
</li>
<li>
<p>The 0.36.0 coverage entry hardcoded &ldquo;88% of 7,833 statements&rdquo; three lines above a paragraph
criticising hardcoded percentages. It is now explicitly a snapshot and points at the badge as the
live figure, rather than being rewritten — the entry records what was measured on the day.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Debian Multi-Architecture Package Builder</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/debian-multi-architecture-package-builder/</link><pubDate>Fri, 21 Aug 2026 21:58:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/debian-multi-architecture-package-builder/</guid><description>Version updated for https://github.com/ranjithrajv/debian-multiarch-builder to version v.0.1a23.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action simplifies the process of building Debian packages across multiple architectures from upstream releases. It supports auto-discovery and interactive setup wizards, reducing manual configuration overhead. The action provides built-in Lintian integration for quality assurance and secure checksum verification for all downloads. With 12+ pre-built templates for popular projects, it offers quick and reliable package builds for various programming languages and environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ranjithrajv/debian-multiarch-builder">https://github.com/ranjithrajv/debian-multiarch-builder</a></strong> to version <strong>v.0.1a23</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/debian-multi-architecture-package-builder">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action simplifies the process of building Debian packages across multiple architectures from upstream releases. It supports auto-discovery and interactive setup wizards, reducing manual configuration overhead. The action provides built-in Lintian integration for quality assurance and secure checksum verification for all downloads. With 12+ pre-built templates for popular projects, it offers quick and reliable package builds for various programming languages and environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Automatic suite retirement</strong>: the builder now skips producing .deb
packages for any distribution whose <code>lts_support_ends</code> (system.yaml) has
passed, even if a package.yaml explicitly lists it. A missing/null date
(forky, sid) always passes through unaffected.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Default <code>debian_distributions</code> parsing dropped literal &ldquo;-&rdquo; tokens into
the build list</strong> — yq&rsquo;s block-list rendering of the fallback array
wasn&rsquo;t stripped by the old <code>tr -d '[],&quot;'</code>, so every package.yaml that
doesn&rsquo;t set <code>debian_distributions</code> itself (24 of 25 repos in the fleet)
has been building with a bogus &ldquo;-&rdquo; pseudo-distribution mixed in. Fixed
by querying the array&rsquo;s elements directly instead of the array itself.</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/kaniko-build-action/</link><pubDate>Fri, 21 Aug 2026 21:57:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints a greeting message, either “Hello World” or “Hello [name]”, to the log. It automates the process of sending personalized greetings and provides a simple way to configure who is being greeted.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints a greeting message, either &ldquo;Hello World&rdquo; or &ldquo;Hello [name]&rdquo;, to the log. It automates the process of sending personalized greetings and provides a simple way to configure who is being greeted.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>rung gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/rung-gate/</link><pubDate>Fri, 21 Aug 2026 21:57:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/rung-gate/</guid><description>Version updated for https://github.com/rung-dev/rung to version v0.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rung is an AI verification tool that captures and records the execution of a change, providing a concrete record of what was done. It helps ensure that agents can verify their work better by replacing claims with actual checks and provides deterministic gates to review results without relying on AI or external context. This allows for more reliable verification in production environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rung-dev/rung">https://github.com/rung-dev/rung</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rung-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>rung is an AI verification tool that captures and records the execution of a change, providing a concrete record of what was done. It helps ensure that agents can verify their work better by replacing claims with actual checks and provides deterministic gates to review results without relying on AI or external context. This allows for more reliable verification in production environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="rung-060">rung 0.6.0</h2>
<p>Adds <code>rung attest</code>, the reviewer half of the surface, plus a byte-anchor so an independent verdict cannot be transplanted onto a different bundle.</p>
<h3 id="new">New</h3>
<ul>
<li><strong><code>rung attest</code></strong>: attach an independent reviewer&rsquo;s verdict to one claim of an existing <code>evidence-bundle/v2</code>, lift it to <code>context: independent</code>, and re-gate in one step, exiting with the gate&rsquo;s verdict. The only way to reach <code>independent</code>. Supports <code>--model</code>, a <code>--panel</code>, and <code>--lab</code> (cross-lab), with <code>--claim-id</code>, <code>--require-artifacts</code>, and <code>--tier</code>.</li>
<li><strong><code>rung run --model</code></strong>: record <code>change.producer.model</code> verbatim, so the gate can define model independence.</li>
<li><strong><code>attestation.artifact_shas</code></strong> schema field: the sorted set of the claim&rsquo;s verified artifact hashes an anchored attestation carries.</li>
</ul>
<h3 id="changed-may-newly-block">Changed (may newly block)</h3>
<ul>
<li>Cross-model and cross-lab qualifiers now require an <strong>anchored</strong> attestation: <code>attestation.artifact_shas</code> must set-equal the gate&rsquo;s re-verified capture hashes. A qualifier that is not byte-bound blocks. A hand-authored cross-model/cross-lab bundle with no <code>artifact_shas</code> that passed before will now block until re-attested with <code>rung attest</code>.</li>
</ul>
<h3 id="trust-posture">Trust posture</h3>
<ul>
<li>attest only ever lowers trust: a reviewer <code>fail</code>/<code>blocked</code> lowers the claim; <code>skip</code> is not a reviewer verdict; a panel <code>pass</code> aggregate is refused over any dissenting member. No artifact access is disclosed as unbound, never minted byte-bound; a hash mismatch refuses. <code>--tier</code> drives only the re-gate, never the emitted bundle.</li>
</ul>
<p>Exit-code contract unchanged: <code>0</code> pass, <code>30</code> block, <code>2</code> usage / cannot-evaluate.</p>
]]></content:encoded></item><item><title>ESLint Config Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/eslint-config-check/</link><pubDate>Fri, 21 Aug 2026 21:57:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/eslint-config-check/</guid><description>Version updated for https://github.com/santi020k/eslint-config-basic to version @santi020k/eslint-config-basic@3.5.1.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is an ESLint configuration package that provides a lean and flexible setup for JavaScript and TypeScript projects. It automatically detects the project’s environment and framework, offering opt-in features like testing, tools, and libraries. The action minimizes dependencies by keeping only necessary ones, making it easy to manage project sizes and improve security.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/santi020k/eslint-config-basic">https://github.com/santi020k/eslint-config-basic</a></strong> to version <strong>@santi020k/eslint-config-basic@3.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/eslint-config-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is an ESLint configuration package that provides a lean and flexible setup for JavaScript and TypeScript projects. It automatically detects the project&rsquo;s environment and framework, offering opt-in features like testing, tools, and libraries. The action minimizes dependencies by keeping only necessary ones, making it easy to manage project sizes and improve security.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li><a href="https://github.com/santi020k/eslint-config-basic/pull/118">#118</a> <a href="https://github.com/santi020k/eslint-config-basic/commit/355dfcd5c6b3baaf472178953d836b9e1e417476"><code>355dfcd</code></a> Thanks <a href="https://github.com/santi020k">@santi020k</a>! - Preserve Bun ambient types in config declaration checks, classify semantic-only
autofixes with ESLint rule metadata while excluding sorting fixes, and follow
local CSS imports declared inside Astro component style blocks.</li>
</ul>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/bernstein-multi-agent-orchestration/</link><pubDate>Fri, 21 Aug 2026 21:56:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.17.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is a deterministic multi-agent CLI orchestration tool designed to help users manage complex agent-based systems. It automates the process of orchestrating multiple agents, ensuring consistent and reliable execution across different environments and configurations.
What’s Changed This release began as an arXiv preprint. The evaluation section kept turning into a bug report, so we shipped the bug report first.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.17.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein is a deterministic multi-agent CLI orchestration tool designed to help users manage complex agent-based systems. It automates the process of orchestrating multiple agents, ensuring consistent and reliable execution across different environments and configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This release began as an arXiv preprint. The evaluation section kept turning into
a bug report, so we shipped the bug report first.</p>
<h2 id="the-task-graph-dropped-work">The task graph dropped work</h2>
<ul>
<li>A failed or cancelled task now reaches dependents outside its subtree. (#4243, #4258)</li>
<li>A node whose every inbound edge skipped is materialised. (#4253)</li>
<li>Decomposition recurses under a bound; completion has a typed record. (#4179, #4185, @Chirag6722)</li>
</ul>
<h2 id="verification-says-what-it-checked">Verification says what it checked</h2>
<ul>
<li><code>audit verify</code> is read-only; append, rewrite and identity are separate verdicts. (#4244, #4245)</li>
<li>A run&rsquo;s read-path set is derived from its journal. (#4180, @Louis20060723)</li>
<li>Absence claims carry a coverage record; compaction binds a pre-compaction hash. (#4188, #4189)</li>
<li><code>verify_result_bundle</code> refuses wrong-typed fields instead of raising. (#4057, #4072, @timsurrealedu; #4252)</li>
<li>A malformed chain link is a verdict, not an exception. (#4055, #4051, @sujeito-operator)</li>
<li>A resume that clears its authority check records that it did. (#3649, @Maqbool61)</li>
<li>Run attestation reaches the command line. (#4139, @Silentpartnercoding)</li>
</ul>
<h2 id="agents-that-died-quietly">Agents that died quietly</h2>
<ul>
<li>A spawned-then-dead agent is diagnosed, not silently detached. (#4246, #4255)</li>
<li>A custom qwen base URL picks an auth type; agents stop dying at zero tokens. (#4265)</li>
<li><code>system_addendum</code> now rides resume, container and sandbox spawns. (#4254)</li>
<li>Agent and skill catalogs are opt-in, lockfiled and tamper-checked. (#3973, #3975, @Chirag6722)</li>
<li>OpenCode declares its capability strategy. (#4099, @KrzysiekSko)</li>
</ul>
<h2 id="volunteer-workers">Volunteer workers</h2>
<ul>
<li>A claimed task ends in a diff or a structured refusal. (#4061)</li>
<li>Untrusted issue text is normalised before it becomes a prompt. (#4059)</li>
<li>Claims carry duplicate detection over a durable lease store. (#3873, #4036, @madhavkbinoy)</li>
<li>An unreadable manifest refuses; &ldquo;absent&rdquo; and &ldquo;unstattable&rdquo; differ. (#4058, #4066, @sujeito-operator)</li>
</ul>
<h2 id="the-same-commit-the-same-verdict">The same commit, the same verdict</h2>
<ul>
<li>Hypothesis and Schemathesis smoke profiles are derandomised. (#4105, #4108, #4125, @vaibhav8a; #4116, @Chirag6722)</li>
<li>Memory-heavy test files run serially instead of OOMing. (#4121, @Phoenix1504e)</li>
<li>Bundle and typecheck-ts gates report on a queued ref and can be required. (#4069, #4081, @sujeito-operator)</li>
</ul>
<h2 id="also">Also</h2>
<ul>
<li>Task reads are tenant-scoped, and sub-router routes are scope-checked again. (#4161, #4163, #4023; #4171, @Phoenix1504e)</li>
<li>More path checks route through the containment helper. (#4095, #4101, @vaibhav8a; #4136, @Louis20060723)</li>
<li><code>eval list</code> emits run paths unwrapped, so they pipe. (#4114, @Fezaru)</li>
<li>TUI pane columns scroll. (#4090, @sahilmathur254)</li>
<li>READMEs in 23 languages. (#4094, #4172)</li>
</ul>
<h2 id="upgrading">Upgrading</h2>
<p>Upgrade in place. <code>PostgresTaskStore.list_tasks()</code> now returns a bounded page
when given no <code>limit</code>; callers reading whole tables must page through
<code>offset</code>. (#4169, #4240)</p>
<h2 id="contributors">Contributors</h2>
<p>@Chirag6722 · @sujeito-operator · @vaibhav8a · @Phoenix1504e · @Louis20060723 ·
@madhavkbinoy · @timsurrealedu · @Silentpartnercoding · @KrzysiekSko ·
@Maqbool61 · @sahilmathur254 · @Fezaru — and Renovate and Dependabot, still awake.</p>
<hr>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(cli): an unreadable volunteer manifest is a refusal, not a traceback by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4058">https://github.com/sipyourdrink-ltd/bernstein/pull/4058</a></li>
<li>feat(security): record whether the chain-continuity check actually ran by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4051">https://github.com/sipyourdrink-ltd/bernstein/pull/4051</a></li>
<li>feat(volunteer): normalize untrusted issue text before it becomes a prompt by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4059">https://github.com/sipyourdrink-ltd/bernstein/pull/4059</a></li>
<li>fix(scripts): gen_agents_md steps aside when agents-md sync owns AGENTS.md by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4062">https://github.com/sipyourdrink-ltd/bernstein/pull/4062</a></li>
<li>fix(security): a malformed chain link is a verdict, not an exception by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4055">https://github.com/sipyourdrink-ltd/bernstein/pull/4055</a></li>
<li>feat(volunteer): run a claimed task from clone to diff or structured refusal by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4060">https://github.com/sipyourdrink-ltd/bernstein/pull/4060</a></li>
<li>fix(volunteer): &ldquo;absent&rdquo; and &ldquo;unstattable&rdquo; are different answers by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4066">https://github.com/sipyourdrink-ltd/bernstein/pull/4066</a></li>
<li>docs: regenerate adapter last-green table from canary receipts by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4067">https://github.com/sipyourdrink-ltd/bernstein/pull/4067</a></li>
<li>feat(volunteer): enforce allowed_paths, re-run gates, and sign the receipt by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4061">https://github.com/sipyourdrink-ltd/bernstein/pull/4061</a></li>
<li>ci: the bundle gate reports on a queued ref, so it can be required by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4069">https://github.com/sipyourdrink-ltd/bernstein/pull/4069</a></li>
<li>chore(ci): ratchet coverage baseline up to 83.83% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4071">https://github.com/sipyourdrink-ltd/bernstein/pull/4071</a></li>
<li>chore(deps): bump websockets from 16.1.1 to 17.0.1 by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4075">https://github.com/sipyourdrink-ltd/bernstein/pull/4075</a></li>
<li>fix(security): refuse wrong-typed bundle fields in verify_result_bundle (#4057) by @timsurrealedu in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4070">https://github.com/sipyourdrink-ltd/bernstein/pull/4070</a></li>
<li>chore(ci): ratchet coverage baseline up to 83.84% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4082">https://github.com/sipyourdrink-ltd/bernstein/pull/4082</a></li>
<li>ci: typecheck-ts reports on a queued ref, so it can be required by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4081">https://github.com/sipyourdrink-ltd/bernstein/pull/4081</a></li>
<li>fix(security): refuse wrong-typed predicate in verify_result_bundle (#4072) by @timsurrealedu in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4076">https://github.com/sipyourdrink-ltd/bernstein/pull/4076</a></li>
<li>fix(security): resolve task-scope matchers through the include_router wrappers by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4080">https://github.com/sipyourdrink-ltd/bernstein/pull/4080</a></li>
<li>chore(ci): raise diff-coverage floor to 87% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4083">https://github.com/sipyourdrink-ltd/bernstein/pull/4083</a></li>
<li>chore(deps): bump openai-agents from 0.13.6 to 0.19.4 in the python-minor-and-patch group by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4086">https://github.com/sipyourdrink-ltd/bernstein/pull/4086</a></li>
<li>fix(release): the bump commits every manifest it regenerates by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4089">https://github.com/sipyourdrink-ltd/bernstein/pull/4089</a></li>
<li>fix(tui): make pane columns scrollable by @sahilmathur254 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4090">https://github.com/sipyourdrink-ltd/bernstein/pull/4090</a></li>
<li>test: stop git housekeeping racing the zero-write assertions by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4093">https://github.com/sipyourdrink-ltd/bernstein/pull/4093</a></li>
<li>chore(deps): update dependency platformdirs to v4.11.2 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4100">https://github.com/sipyourdrink-ltd/bernstein/pull/4100</a></li>
<li>fix(ci): the ratchet guard reads the baseline on the branch the PR targets by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4110">https://github.com/sipyourdrink-ltd/bernstein/pull/4110</a></li>
<li>docs(reference): add a receipt reference page, shrink the FEATURE_MATRIX row, add a flag-drift guard by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4115">https://github.com/sipyourdrink-ltd/bernstein/pull/4115</a></li>
<li>test: derive the runbook section boundary from its own heading by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4117">https://github.com/sipyourdrink-ltd/bernstein/pull/4117</a></li>
<li>fix(contract): derandomize the smoke-profile Schemathesis sweep so PR and merge-queue gates stop giving different verdicts on the same commit by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4105">https://github.com/sipyourdrink-ltd/bernstein/pull/4105</a></li>
<li>chore(deps): update python:3.13-slim docker digest to ffb752e by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4103">https://github.com/sipyourdrink-ltd/bernstein/pull/4103</a></li>
<li>docs: regenerate adapter last-green table from canary receipts by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4107">https://github.com/sipyourdrink-ltd/bernstein/pull/4107</a></li>
<li>feat(orchestration): add rendering source fetcher for research modality (#3120) by @Louis20060723 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4084">https://github.com/sipyourdrink-ltd/bernstein/pull/4084</a></li>
<li>fix(deps): declare the modal x otel protobuf conflict so uv dependency updates stop aborting outright by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4104">https://github.com/sipyourdrink-ltd/bernstein/pull/4104</a></li>
<li>fix(cli): receipt verify refuses malformed bundles instead of raising by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4111">https://github.com/sipyourdrink-ltd/bernstein/pull/4111</a></li>
<li>docs: regenerate adapter last-green table from canary receipts by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4132">https://github.com/sipyourdrink-ltd/bernstein/pull/4132</a></li>
<li>chore(deps): update dependency charset-normalizer to v3.5.0 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4137">https://github.com/sipyourdrink-ltd/bernstein/pull/4137</a></li>
<li>fix(cli): eval list emits run paths unwrapped so they can be piped by @Fezaru in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4114">https://github.com/sipyourdrink-ltd/bernstein/pull/4114</a></li>
<li>fix(adapters): stop passing an unsupported flag to codex exec by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4140">https://github.com/sipyourdrink-ltd/bernstein/pull/4140</a></li>
<li>fix(agents): honour an explicitly configured role CLI at spawn by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4141">https://github.com/sipyourdrink-ltd/bernstein/pull/4141</a></li>
<li>fix(orchestration): route stdin-overflow prompt filename through the containment helper by @Louis20060723 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4136">https://github.com/sipyourdrink-ltd/bernstein/pull/4136</a></li>
<li>docs(infrastructure): add MkDocs Material EOL coupling analysis and trigger matrix by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4113">https://github.com/sipyourdrink-ltd/bernstein/pull/4113</a></li>
<li>fix(ci): run memory-heavy test files serially to avoid OOM by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4121">https://github.com/sipyourdrink-ltd/bernstein/pull/4121</a></li>
<li>ci(docs): weekly report of transitive pins a fresh resolve would move by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4098">https://github.com/sipyourdrink-ltd/bernstein/pull/4098</a></li>
<li>fix(eval,tasks,plugins,security): route eval/tasks/plugins path checks through contained_subpath; document always_allow&rsquo;s non-conversion by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4101">https://github.com/sipyourdrink-ltd/bernstein/pull/4101</a></li>
<li>fix(tests): drive determinism regression test with settings the smoke lane actually applies by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4125">https://github.com/sipyourdrink-ltd/bernstein/pull/4125</a></li>
<li>chore(deps): update helm release redis to v28 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4138">https://github.com/sipyourdrink-ltd/bernstein/pull/4138</a></li>
<li>fix(property): derandomize the smoke Hypothesis profile so property-tests stops giving different verdicts on the same commit by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4108">https://github.com/sipyourdrink-ltd/bernstein/pull/4108</a></li>
<li>fix(tests): derandomize Hypothesis property tests across unit-tests lane (#4116) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4128">https://github.com/sipyourdrink-ltd/bernstein/pull/4128</a></li>
<li>fix(orchestration): route the three remaining pid-file and approvals checks through the containment helper by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4095">https://github.com/sipyourdrink-ltd/bernstein/pull/4095</a></li>
<li>feat(canary): re-derive last_green.json from the receipts it projects by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4097">https://github.com/sipyourdrink-ltd/bernstein/pull/4097</a></li>
<li>feat(tasks): wire AgentCheckpoint production writer into park_task (#4043) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4122">https://github.com/sipyourdrink-ltd/bernstein/pull/4122</a></li>
<li>feat(adapters): bridge catalog-installed skills into worktree injection and CatalogAgent into &ndash;agents (#3974) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4123">https://github.com/sipyourdrink-ltd/bernstein/pull/4123</a></li>
<li>feat(agents): record catalog lockfile and detect content digest tampering (#3973) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4124">https://github.com/sipyourdrink-ltd/bernstein/pull/4124</a></li>
<li>docs: reset staleness clock for curated context files (#4079) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4129">https://github.com/sipyourdrink-ltd/bernstein/pull/4129</a></li>
<li>feat(volunteer): claim etiquette and duplicate detection without a coordinator (#3873) by @madhavkbinoy in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4130">https://github.com/sipyourdrink-ltd/bernstein/pull/4130</a></li>
<li>docs: fence Cloud/Cloudflare section as Preview (reland #4120) by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4159">https://github.com/sipyourdrink-ltd/bernstein/pull/4159</a></li>
<li>feat(agents): add opt-in discovery of harness-local agent and skill resources (#3975) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4126">https://github.com/sipyourdrink-ltd/bernstein/pull/4126</a></li>
<li>fix: declare OpenCode capability strategy by @KrzysiekSko in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4099">https://github.com/sipyourdrink-ltd/bernstein/pull/4099</a></li>
<li>fix(status): scope health check task count to caller tenant by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4161">https://github.com/sipyourdrink-ltd/bernstein/pull/4161</a></li>
<li>feat(mcp): advertise repo and build provenance in capability card by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4166">https://github.com/sipyourdrink-ltd/bernstein/pull/4166</a></li>
<li>fix(escalation): produce terminal receipt on missing or empty run journal by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4168">https://github.com/sipyourdrink-ltd/bernstein/pull/4168</a></li>
<li>fix(tests): resolve conflicting Hypothesis &ldquo;deep&rdquo; profile registrations by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4187">https://github.com/sipyourdrink-ltd/bernstein/pull/4187</a></li>
<li>feat(volunteer): durable lease store for hub task claims (#4036) by @madhavkbinoy in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4190">https://github.com/sipyourdrink-ltd/bernstein/pull/4190</a></li>
<li>docs: add the Russian README by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4094">https://github.com/sipyourdrink-ltd/bernstein/pull/4094</a></li>
<li>fix(webhooks): thread tenant_id through ci-fix retry counters by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4171">https://github.com/sipyourdrink-ltd/bernstein/pull/4171</a></li>
<li>feat(knowledge): wire review corrections into file_lesson convention receipts by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4170">https://github.com/sipyourdrink-ltd/bernstein/pull/4170</a></li>
<li>chore(deps): update github/codeql-action digest to ff2f1c6 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4186">https://github.com/sipyourdrink-ltd/bernstein/pull/4186</a></li>
<li>feat(memory): bind compaction results to a pre-compaction content hash by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4189">https://github.com/sipyourdrink-ltd/bernstein/pull/4189</a></li>
<li>feat(suspension): suspend-side grant population + journal continuation (#3649) by @Maqbool61 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4131">https://github.com/sipyourdrink-ltd/bernstein/pull/4131</a></li>
<li>test: add journal verifier to mutation gate at 72.5% kill rate by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4194">https://github.com/sipyourdrink-ltd/bernstein/pull/4194</a></li>
<li>feat(storage): export soc2 evidence pack to configured sink by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4162">https://github.com/sipyourdrink-ltd/bernstein/pull/4162</a></li>
<li>feat(webui): record and gate colour token contrast measurements by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4164">https://github.com/sipyourdrink-ltd/bernstein/pull/4164</a></li>
<li>fix(scripts): select test files from positional paths in run_tests by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4195">https://github.com/sipyourdrink-ltd/bernstein/pull/4195</a></li>
<li>docs(adapters): fix internal-scheduler LLM description drift by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4198">https://github.com/sipyourdrink-ltd/bernstein/pull/4198</a></li>
<li>chore(ci): ratchet coverage baseline up to 83.91% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4199">https://github.com/sipyourdrink-ltd/bernstein/pull/4199</a></li>
<li>feat(persistence): add limit and offset to PostgresTaskStore list_tasks by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4169">https://github.com/sipyourdrink-ltd/bernstein/pull/4169</a></li>
<li>feat(tasks): add typed task-completion record schema, validation, and canonical serialization (#4185) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4192">https://github.com/sipyourdrink-ltd/bernstein/pull/4192</a></li>
<li>fix(mailbox): record consumption and surface silent render failures by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4193">https://github.com/sipyourdrink-ltd/bernstein/pull/4193</a></li>
<li>feat(tasks): enforce well-founded bounded recursive task decomposition (#4179) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4196">https://github.com/sipyourdrink-ltd/bernstein/pull/4196</a></li>
<li>feat(communication): turn MAX_PENDING_PER_TASK into a draining backlog bound (#4152) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4197">https://github.com/sipyourdrink-ltd/bernstein/pull/4197</a></li>
<li>chore(ci): ratchet coverage baseline up to 83.92% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4207">https://github.com/sipyourdrink-ltd/bernstein/pull/4207</a></li>
<li>fix(workspace): scope workspace_merge_order task read to caller tenant by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4163">https://github.com/sipyourdrink-ltd/bernstein/pull/4163</a></li>
<li>ci(soc2): wire weekly evidence pack export step to sink by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4165">https://github.com/sipyourdrink-ltd/bernstein/pull/4165</a></li>
<li>feat(core): add count_tasks method to TaskStore and PostgresTaskStore (#4158) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4191">https://github.com/sipyourdrink-ltd/bernstein/pull/4191</a></li>
<li>feat(quality): record and bind coverage for absence claims by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4188">https://github.com/sipyourdrink-ltd/bernstein/pull/4188</a></li>
<li>docs: add 16 README translations (wave 2) by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4172">https://github.com/sipyourdrink-ltd/bernstein/pull/4172</a></li>
<li>chore(deps): update dependency platformdirs to v4.11.3 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4218">https://github.com/sipyourdrink-ltd/bernstein/pull/4218</a></li>
<li>docs: regenerate adapter last-green table from canary receipts by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4220">https://github.com/sipyourdrink-ltd/bernstein/pull/4220</a></li>
<li>chore(deps): update dependency astral-sh/uv to v0.12.4 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4216">https://github.com/sipyourdrink-ltd/bernstein/pull/4216</a></li>
<li>feat(cli): reach the run attestation projection from the command line by @Silentpartnercoding in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4139">https://github.com/sipyourdrink-ltd/bernstein/pull/4139</a></li>
<li>fix(mailbox): derive since_seq cursor from consumption records by @Phoenix1504e in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4215">https://github.com/sipyourdrink-ltd/bernstein/pull/4215</a></li>
<li>fix(git): exclude injected scheduled_tasks.json from worktree tracking by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4227">https://github.com/sipyourdrink-ltd/bernstein/pull/4227</a></li>
<li>fix(agent_lifecycle): re-evaluate deferred death judgments after reap by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4231">https://github.com/sipyourdrink-ltd/bernstein/pull/4231</a></li>
<li>fix(orchestration): regenerate summary.json at shutdown by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4232">https://github.com/sipyourdrink-ltd/bernstein/pull/4232</a></li>
<li>fix(adapters): gate PYTHONPATH injection behind opt-in flag by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4233">https://github.com/sipyourdrink-ltd/bernstein/pull/4233</a></li>
<li>fix(evolve): refuse upgrade-proposal auto-spawn with no terminal task by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4229">https://github.com/sipyourdrink-ltd/bernstein/pull/4229</a></li>
<li>fix(adapters): normalize adapter name casing in admission receipt filename path (#4224) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4234">https://github.com/sipyourdrink-ltd/bernstein/pull/4234</a></li>
<li>fix(verify): let automation gate on receipt provenance tier by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4239">https://github.com/sipyourdrink-ltd/bernstein/pull/4239</a></li>
<li>docs(cli): add unified verification exit-code reference table and tests (#4206) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4241">https://github.com/sipyourdrink-ltd/bernstein/pull/4241</a></li>
<li>fix(replay): make journal verify seal-aware for identity verdicts by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4244">https://github.com/sipyourdrink-ltd/bernstein/pull/4244</a></li>
<li>fix(audit): make verify read-only and separate post-seal appends from a rewritten prefix by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4245">https://github.com/sipyourdrink-ltd/bernstein/pull/4245</a></li>
<li>fix(cli): diagnose a spawned-then-dead agent instead of detaching silently by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4246">https://github.com/sipyourdrink-ltd/bernstein/pull/4246</a></li>
<li>fix(persistence): bound PostgresTaskStore.list_tasks() by default by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4240">https://github.com/sipyourdrink-ltd/bernstein/pull/4240</a></li>
<li>fix(cli): thread resolved model to plan-approval panel and cost estimation (#4214) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4235">https://github.com/sipyourdrink-ltd/bernstein/pull/4235</a></li>
<li>feat(replay): derive a run&rsquo;s read-path set from its journal (#4180) by @Louis20060723 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4219">https://github.com/sipyourdrink-ltd/bernstein/pull/4219</a></li>
<li>fix(cli): print overall summary panel last in audit verify (#4202) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4250">https://github.com/sipyourdrink-ltd/bernstein/pull/4250</a></li>
<li>fix(tasks): propagate failure to dependents and derive an unreachable set by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4243">https://github.com/sipyourdrink-ltd/bernstein/pull/4243</a></li>
<li>test(orchestrator): assert overlap not elapsed time in parallel-verify test by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4251">https://github.com/sipyourdrink-ltd/bernstein/pull/4251</a></li>
<li>fix(security): settle subject&rsquo;s type in verify_result_bundle by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4252">https://github.com/sipyourdrink-ltd/bernstein/pull/4252</a></li>
<li>fix(cli): diagnose a spawned-then-dead agent on the remaining run surfaces by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4255">https://github.com/sipyourdrink-ltd/bernstein/pull/4255</a></li>
<li>fix(agents): carry system_addendum on every resume, container, and sandbox spawn by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4254">https://github.com/sipyourdrink-ltd/bernstein/pull/4254</a></li>
<li>fix(planning): materialise a DAG node whose every inbound edge skipped by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4253">https://github.com/sipyourdrink-ltd/bernstein/pull/4253</a></li>
<li>fix(tasks): propagate a cascade cancel to dependents outside the subtree by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4258">https://github.com/sipyourdrink-ltd/bernstein/pull/4258</a></li>
<li>chore(ci): ratchet coverage baseline up to 84.01% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4263">https://github.com/sipyourdrink-ltd/bernstein/pull/4263</a></li>
<li>fix(adapters): select the openai auth type for a custom qwen base URL by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4265">https://github.com/sipyourdrink-ltd/bernstein/pull/4265</a></li>
<li>release: v3.17.0 by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4267">https://github.com/sipyourdrink-ltd/bernstein/pull/4267</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@timsurrealedu made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4070">https://github.com/sipyourdrink-ltd/bernstein/pull/4070</a></li>
<li>@sahilmathur254 made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4090">https://github.com/sipyourdrink-ltd/bernstein/pull/4090</a></li>
<li>@Fezaru made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4114">https://github.com/sipyourdrink-ltd/bernstein/pull/4114</a></li>
<li>@madhavkbinoy made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4130">https://github.com/sipyourdrink-ltd/bernstein/pull/4130</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sipyourdrink-ltd/bernstein/compare/v3.16.0...v3.17.0">https://github.com/sipyourdrink-ltd/bernstein/compare/v3.16.0...v3.17.0</a></p>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/update-a-config-file-with-values-from-environment/</link><pubDate>Fri, 21 Aug 2026 21:55:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action reads environment variables and replaces placeholders within a specified configuration file. It automates the process of dynamically updating configuration files based on runtime values, ensuring that sensitive information is kept secure and easily updatable through environment variables.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action reads environment variables and replaces placeholders within a specified configuration file. It automates the process of dynamically updating configuration files based on runtime values, ensuring that sensitive information is kept secure and easily updatable through environment variables.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Fri, 21 Aug 2026 21:55:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by performing the following tasks before the push to a repository:
Running npm ci and npm run bundle commands on the build machine to ensure dependencies are installed and all necessary files are bundled. Committing the contents of the dist folder, which typically contains compiled or optimized artifacts for deployment. This ensures that when changes are pushed to the repository, the service is prepared for deployment without manual intervention.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by performing the following tasks before the push to a repository:</p>
<ul>
<li>Running <code>npm ci</code> and <code>npm run bundle</code> commands on the build machine to ensure dependencies are installed and all necessary files are bundled.</li>
<li>Committing the contents of the <code>dist</code> folder, which typically contains compiled or optimized artifacts for deployment.</li>
</ul>
<p>This ensures that when changes are pushed to the repository, the service is prepared for deployment without manual intervention.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/runward-gate/</link><pubDate>Fri, 21 Aug 2026 21:55:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.36.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is an open-source delivery methodology that verifies engineering decisions behind AI-written code by ensuring they are followed through plain code. It automates the process of checking whether the architecture, where things run, how it’s secured, and how it’s handed over were correctly made and written down. The action provides a deterministic gate that ensures the decisions are verified and determined, not replaced with an LLM’s suggestion.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.36.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Runward is an open-source delivery methodology that verifies engineering decisions behind AI-written code by ensuring they are followed through plain code. It automates the process of checking whether the architecture, where things run, how it&rsquo;s secured, and how it&rsquo;s handed over were correctly made and written down. The action provides a deterministic gate that ensures the decisions are verified and determined, not replaced with an LLM&rsquo;s suggestion.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Three false greens in the evidence layer, found by instructing the mutants that survive runward&rsquo;s own test net — and the instrument that found them, which was measuring the machine instead of the code.</strong></p>
<h3 id="the-false-greens">The false greens</h3>
<p>None of these needed a mutant to reach. They were exposed by building a mission that would actually exercise each function, which is what instructing a survivor requires (<a href="docs/adr/ADR-0046-mutation-testing-is-an-instrument-not-a-gate.md">ADR-0046</a> decision 3).</p>
<ul>
<li><strong>A code fence hid the manifest from the circular-evidence check</strong> (RWD-2026-0025). <code>textOutsideManifest</code> removes the conformance table before looking for a self-cited symbol, because column 1 of every row is the rule&rsquo;s own slug and would always match. It took the <strong>first</strong> matching heading, fenced or not, so an example of the format pasted above the real table left the real table inside the text being searched. That is RWD-2026-0002, the universal green key, reopened by a code fence — and <code>readManifest</code> had already fixed this exact shape for row parsing. Measured: the same self-citing row exits <strong>1</strong> without the illustration and <strong>0</strong> with it.</li>
<li><strong>One invisible character swallowed a typed pointer</strong> (RWD-2026-0026). The pointer pattern ends in <code>$</code>, and <code>.</code> never matches a line terminator in JavaScript, so a single CR, U+2028 or U+2029 after the prefix made <code>$</code> unreachable: the pointer was dropped <strong>in silence</strong>, the row still read as typed, and the cited file was never opened. A paste leaves such characters behind and nobody can see them. Measured on a row citing a file that does not exist: exit <strong>1</strong> with an ordinary cell, exit <strong>0</strong> with a U+2028 in it. Terminators are now folded to a space before parsing, which cannot change a well-formed cell since a space is already a pointer separator.</li>
<li><strong>An absent seal said nothing at all</strong> (RWD-2026-0027). The output could not distinguish &ldquo;never sealed&rdquo; from &ldquo;seal deleted&rdquo;: tamper with a sealed evidence file and the gate exits 1, delete <code>runward/evidence-lock.json</code> and the same tampered tree exits 0, silently. The strict run now names the regime it is in. The <strong>verdict</strong> is deliberately unchanged, and RWD-2026-0028 records why in a new <code>known-defects.md</code> section for constraints that cannot be closed inside the repository: sealing is opt-in, and an in-repository marker declaring &ldquo;this mission seals&rdquo; buys nothing against anyone deliberate while costing honest teams a red gate — the reasoning <code>scaffold-lock.ts</code> already carries about the corpus lock.</li>
</ul>
<h3 id="the-instrument-and-why-its-own-numbers-had-to-be-thrown-away">The instrument, and why its own numbers had to be thrown away</h3>
<ul>
<li><strong>The mutation harness is committed</strong> — configuration, resumable passes, the probe, and a survivor register generated from measured verdicts. The ratchet of ADR-0046 decision 2 had existed since 2026-08-05 with <strong>no list to be diffed against</strong>, so &ldquo;the survivor list does not grow&rdquo; could not be falsified. That is the shape ADR-0045 refuses from an operator.</li>
<li><strong>The raw numbers were fiction.</strong> The harness bounded children with <code>spawnSync</code>&rsquo;s timeout, which signals the direct child only, while <code>node --test</code> isolates each test file in its own process — every expired run left about a dozen grandchildren alive, still executing their mutant. Measured: load average <strong>78 on 8 cores</strong>, 32 orphans surviving the driver, and at one point two copies of the verifier racing each other. Stryker counts a <code>Timeout</code> as <em>detected</em>, so starved survivors vanished into the detected column and the score went <strong>up</strong>: the same module read <strong>98.1 %</strong> contaminated and <strong>77.4 %</strong> clean, with 199 of 269 &ldquo;timeouts&rdquo; turning out to be survivors.</li>
<li><strong>The instrument now refuses to measure what it cannot measure</strong>: process groups killed whole, hangs reported rather than inferred from an exit code, a lock against a second concurrent copy, the mutant read back from disk before any verdict is taken, and a mutant list bound to the sha256 of the build it was measured on — three fixes moved one function by 47 lines, and a replay would otherwise have spliced into other code with full confidence.</li>
<li><strong><a href="docs/compliance/mutation-register.md"><code>docs/compliance/mutation-register.md</code></a></strong> files all 215 survivors of <code>evidence</code> as <strong>144 holes, 42 equivalents and 29 display-only</strong>, each carrying what was run and observed rather than what was reasoned, every equivalence argued, guarded on every commit by a test that never runs Stryker.</li>
</ul>
<p>Nothing here changes the gate&rsquo;s contract: no threshold, no score is a crossing condition, and CI does not run the pass.</p>
]]></content:encoded></item><item><title>MCP Tenant Isolation Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/mcp-tenant-isolation-scan/</link><pubDate>Fri, 21 Aug 2026 21:54:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/mcp-tenant-isolation-scan/</guid><description>Version updated for https://github.com/subodhkc/mcp-tenant-isolation to version v2.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action is a static analysis tool that scans multi-tenant software code to identify and flag potential issues related to tenant isolation. It checks various patterns across database queries, API routes, cache keys, file storage, schema design, logging, and MCP server architecture. The tool provides detailed findings with rule IDs, files, lines, missing guards, and remediation hints. The scan is deterministic and works with TypeScript, JavaScript, Prisma, Drizzle, raw SQL, Next.js, Express, and Fastify.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/subodhkc/mcp-tenant-isolation">https://github.com/subodhkc/mcp-tenant-isolation</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-tenant-isolation-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action is a static analysis tool that scans multi-tenant software code to identify and flag potential issues related to tenant isolation. It checks various patterns across database queries, API routes, cache keys, file storage, schema design, logging, and MCP server architecture. The tool provides detailed findings with rule IDs, files, lines, missing guards, and remediation hints. The scan is deterministic and works with TypeScript, JavaScript, Prisma, Drizzle, raw SQL, Next.js, Express, and Fastify.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="what-changed">What changed</h2>
<p>mcp-tenant-isolation 2.0.0 is a major version. It upgrades to the MCP v2 SDK, adds security boundary enforcement, structured scan output, evidence receipts, and npm Trusted Publishing with provenance attestations.</p>
<h2 id="what-is-new">What is new</h2>
<h3 id="mcp-v2-sdk">MCP v2 SDK</h3>
<ul>
<li><code>@modelcontextprotocol/server</code> v2 (Zod schemas, structured output)</li>
<li>stdio transport only (SSE removed)</li>
<li>4 tools: scan, list rules, explain rule, suppress finding</li>
<li>Read-only by default. Write tools require <code>--allow-write-tools</code>.</li>
</ul>
<h3 id="security-boundaries">Security boundaries</h3>
<ul>
<li>Path traversal rejection</li>
<li>Symlink escape detection via realpath</li>
<li>UNC/network path rejection</li>
<li>Windows case-insensitive path normalization</li>
<li>All filesystem operations constrained to project root</li>
</ul>
<h3 id="structured-output">Structured output</h3>
<ul>
<li>Completeness states: COMPLETE, PARTIAL, ERROR</li>
<li>File parse accounting, rule evaluation accounting</li>
<li>8 concern families for triage</li>
<li>Limitations field (what was and was not checked)</li>
</ul>
<h3 id="evidence-and-receipts">Evidence and receipts</h3>
<ul>
<li>Scan Receipt with SHA-256 hash and rulepack digest</li>
<li>Evidence Envelope for verifiable scan artifacts</li>
<li>v2 semantic fingerprints (stable under line movement)</li>
<li>Proof-of-fix tracking (STILL_PRESENT, NEW, NOT_VERIFIABLE)</li>
</ul>
<h3 id="supply-chain">Supply chain</h3>
<ul>
<li>npm Trusted Publishing via GitHub Actions OIDC</li>
<li>Sigstore provenance attestations</li>
<li>0 npm audit vulnerabilities</li>
<li>Cross-platform CI: Ubuntu, Windows, macOS (Node 22, 24)</li>
</ul>
<h3 id="breaking-changes">Breaking changes</h3>
<ul>
<li>SSE transport removed. stdio only.</li>
<li>MCP SDK upgraded from v1 to v2.</li>
<li>Engine version bumped to 2.0.0.</li>
<li>Node 22+ required (was 18+).</li>
</ul>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span><span style="color:#75715e"># npm</span>
</span></span><span style="display:flex;"><span>npm install -g mcp-tenant-isolation
</span></span><span style="display:flex;"><span>npx mcp-tenant-isolation scan ./src
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Docker</span>
</span></span><span style="display:flex;"><span>docker run --rm -v <span style="color:#66d9ef">$(</span>pwd<span style="color:#66d9ef">)</span>:/code subodhkc/mcp-tenant-isolation scan /code/src
</span></span></code></pre></div><h2 id="mcp-client-configuration">MCP client configuration</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-json" data-lang="json"><span style="display:flex;"><span>{
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">&#34;mcpServers&#34;</span>: {
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;tenant-isolation&#34;</span>: {
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">&#34;command&#34;</span>: <span style="color:#e6db74">&#34;npx&#34;</span>,
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">&#34;args&#34;</span>: [<span style="color:#e6db74">&#34;-y&#34;</span>, <span style="color:#e6db74">&#34;mcp-tenant-isolation&#34;</span>, <span style="color:#e6db74">&#34;mcp&#34;</span>]
</span></span><span style="display:flex;"><span>    }
</span></span><span style="display:flex;"><span>  }
</span></span><span style="display:flex;"><span>}
</span></span></code></pre></div><h2 id="verify-provenance">Verify provenance</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm view mcp-tenant-isolation@2.0.0 dist.attestations
</span></span></code></pre></div><h2 id="verification">Verification</h2>
<ul>
<li>203 tests passing across 13 test files</li>
<li>0 npm audit vulnerabilities</li>
<li>Cross-platform CI: Ubuntu, Windows, macOS (Node 22, 24)</li>
<li>Provenance attestations via sigstore</li>
<li>npm Trusted Publishing via GitHub Actions OIDC</li>
<li>Docker image: <code>subodhkc/mcp-tenant-isolation:2.0.0</code></li>
<li>MCP Registry: <code>io.github.subodhkc/mcp-tenant-isolation</code></li>
</ul>
<h2 id="limitations">Limitations</h2>
<ul>
<li>Intra-procedural flow analysis only. No cross-function taint tracing.</li>
<li>No runtime verification. Cannot check if RLS is actually enabled.</li>
<li>TypeScript and JavaScript only. Python, Go, Ruby are on the roadmap.</li>
<li>False positives are possible. Configurable via <code>.mtirc.json</code>.</li>
<li>stdio transport only. SSE was removed in v2.0.0.</li>
</ul>
<h2 id="links">Links</h2>
<ul>
<li><a href="https://www.npmjs.com/package/mcp-tenant-isolation">npm</a></li>
<li><a href="https://github.com/subodhkc/mcp-tenant-isolation">GitHub</a></li>
<li><a href="https://hub.docker.com/r/subodhkc/mcp-tenant-isolation">Docker Hub</a></li>
<li><a href="https://www.haiec.com/mcp-tenant-isolation">Landing page</a></li>
<li><a href="https://www.haiec.com/blog/mcp-tenant-isolation-v2-security-boundaries-provenance">Blog post</a></li>
<li><a href="https://github.com/subodhkc/mcp-tenant-isolation/blob/main/CHANGELOG.md">Changelog</a></li>
<li><a href="https://github.com/subodhkc/mcp-tenant-isolation/blob/main/SECURITY.md">Security policy</a></li>
</ul>
]]></content:encoded></item><item><title>move-test-gen coverage check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/move-test-gen-coverage-check/</link><pubDate>Fri, 21 Aug 2026 21:53:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/move-test-gen-coverage-check/</guid><description>Version updated for https://github.com/talongate/move-test-gen to version v1.5.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates edge-case test suites for Sui Move functions, covering various scenarios such as boundary values, arithmetic edges, access control issues, state machine errors, and economic challenges. It outputs a .move file targeted at sui move test, making it easy to verify the correctness of Move modules with generated tests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/talongate/move-test-gen">https://github.com/talongate/move-test-gen</a></strong> to version <strong>v1.5.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-test-gen-coverage-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates edge-case test suites for Sui Move functions, covering various scenarios such as boundary values, arithmetic edges, access control issues, state machine errors, and economic challenges. It outputs a <code>.move</code> file targeted at <code>sui move test</code>, making it easy to verify the correctness of Move modules with generated tests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Community audit round 2 — 25 fixes from @HetCreep CoalBoard nasa-rigor review.</p>
<h3 id="highlights">Highlights</h3>
<ul>
<li>6 lint rule fixes across MOV-001, MOV-003, MOV-005, MOV-006</li>
<li>Parser hardening — block-comment + trailing-comment edge cases</li>
<li>Mutation engine — timeout scoping + timed-out mutant classification</li>
<li>Coverage output — 0/0 = null (not 100%) in JSON + Action</li>
<li>Lint infra — per-module test_only scope, CLI exit-code contract, crash guard</li>
<li>Docs + examples — accuracy fixes, action pins updated post-org-transfer</li>
</ul>
<p>gate-selftest: 13/13 green | CI: gate + action-selftest success</p>
<p>Security audit by @HetCreep. Full changelog in CHANGELOG.md.</p>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/delivery-autopilot-runner/</link><pubDate>Fri, 21 Aug 2026 21:53:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.13.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Delivery Autopilot Runner automates the development process by taking tickets from your tracker and orchestrating a CI pipeline that writes code, checks its quality, and opens a pull request. It ensures smooth collaboration between development and AI-driven tasks without sending sensitive information to Delivery Autopilot’s servers. Users can set up the action using either the GitHub App or by adding a custom workflow YAML file, providing necessary credentials for model access.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Delivery Autopilot Runner automates the development process by taking tickets from your tracker and orchestrating a CI pipeline that writes code, checks its quality, and opens a pull request. It ensures smooth collaboration between development and AI-driven tasks without sending sensitive information to Delivery Autopilot&rsquo;s servers. Users can set up the action using either the GitHub App or by adding a custom workflow YAML file, providing necessary credentials for model access.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runner-dist synced from AutoPilot fa2e781c881d. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>Vaara Policy Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/vaara-policy-check/</link><pubDate>Fri, 21 Aug 2026 21:52:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/vaara-policy-check/</guid><description>Version updated for https://github.com/vaaraio/vaara to version v1.74.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of logging and verifying autonomous actions in software systems. It provides a verifiable record of every action taken, including its risk score, decision, call, and outcome, which can be checked offline by anyone. The tool ensures that only authorized actions are executed based on predefined policies, maintaining accountability for all transactions in a tamper-evident manner.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaaraio/vaara">https://github.com/vaaraio/vaara</a></strong> to version <strong>v1.74.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vaara-policy-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of logging and verifying autonomous actions in software systems. It provides a verifiable record of every action taken, including its risk score, decision, call, and outcome, which can be checked offline by anyone. The tool ensures that only authorized actions are executed based on predefined policies, maintaining accountability for all transactions in a tamper-evident manner.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1740---2026-08-21">[1.74.0] - 2026-08-21</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p>Blinded time anchors, methods <code>rfc3161-blinded</code> and <code>rfc3161-eidas-qualified-blinded</code>. An unblinded anchor sends the timestamping authority exactly the value the receipt then publishes as <code>anchoredDigest</code>. An authority keeps a request log, every entry in it sits behind a customer account, and a log that is sold, breached or produced under compulsion lets whoever holds it match its entries against any corpus of published receipts. That reveals which receipts a named customer anchored and when, and no signature has to break for it to work.</p>
<p>A blinded anchor sends <code>sha256(&quot;vaara/anchor-blind/v1&quot; || salt || anchoredDigest)</code> instead and carries the 32-byte salt as <code>anchorSalt</code>. <code>anchoredDigest</code> still names the Section 2.1 signed payload, so the receipt binding does not move and the attested time is untouched.</p>
</li>
<li>
<p><code>blinded_anchor_digest()</code> and <code>new_anchor_salt()</code> in <code>vaara.audit.timeanchor</code>, and a <code>blind</code> keyword on <code>SelfHostedTSA.anchor_receipt</code> and <code>QualifiedTSA.anchor_receipt</code>. <code>salt</code> can be pinned so a generator reproduces an anchor byte for byte; production leaves it unset, because two anchors under one salt are linkable to each other.</p>
</li>
<li>
<p><code>VAARA_ANCHOR_BLIND=1</code> turns blinding on for the server&rsquo;s qualified anchorer. Off by default, since it changes the anchor&rsquo;s <code>method</code> and a consumer pinned to <code>rfc3161-eidas-qualified</code> should not start seeing a new one without the operator asking.</p>
</li>
<li>
<p>SPEC.md Section 4.1 states the rule and its limit. A verifier must recompute the imprint from <code>anchoredDigest</code> and <code>anchorSalt</code>, must reject a blinded anchor whose salt is absent or is not 32 bytes of hex, and must reject an unblinded method that carries a salt, because a verifier that ignores the member would read a blinded anchor as a plain one.</p>
<p>The limit is stated rather than left to be inferred. Blinding stops a party holding only the authority&rsquo;s log from matching that log against receipts it was not given. It does not make the anchor unlinkable to anyone holding the receipt, since the salt travels with the receipt so a holder can verify. It does not hide the fact, timing or volume of anchoring from the authority, which sees each request as it happens.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>The receipt evidence page renders <code>rfc3161-eidas-qualified-blinded</code> through the same path as <code>rfc3161-eidas-qualified</code>. Without that, a blinded qualified anchor dropped to the generic branch and stopped reading as qualified on the page a relying party is shown.</li>
</ul>
]]></content:encoded></item><item><title>Setup Turborepo Remote Cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/setup-turborepo-remote-cache/</link><pubDate>Fri, 21 Aug 2026 21:51:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/setup-turborepo-remote-cache/</guid><description>Version updated for https://github.com/vercel/setup-turborepo-remote-cache-action to version v1.1.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 50 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates setting up Turborepo CLI Remote Caching in GitHub workflows. It enables remote caching, which can significantly speed up build times by reusing previously computed results across different CI/CD runs. The action requires creating a Vercel team OIDC policy and adding a TURBO_TEAM repository variable to the workflow before calling Turborepo CLI.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vercel/setup-turborepo-remote-cache-action">https://github.com/vercel/setup-turborepo-remote-cache-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>50</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-turborepo-remote-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates setting up Turborepo CLI Remote Caching in GitHub workflows. It enables remote caching, which can significantly speed up build times by reusing previously computed results across different CI/CD runs. The action requires creating a Vercel team OIDC policy and adding a <code>TURBO_TEAM</code> repository variable to the workflow before calling Turborepo CLI.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Convert action to Node.js 24</li>
<li>Auto-revoke Turborepo access token once the job completes (disable by setting <code>revoke: false</code>)</li>
</ul>
]]></content:encoded></item><item><title>Diffly PR triage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/diffly-pr-triage/</link><pubDate>Fri, 21 Aug 2026 21:51:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/diffly-pr-triage/</guid><description>Version updated for https://github.com/VIVAAN-DHAWAN/diffly-cli to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The diffly GitHub Action helps developers review large, AI-generated pull requests by providing a comprehensive one-page report with a verdict, risk flags, checks, and a blast-radius map. It automates the task of identifying changes in files, symbols, dependencies, and tests, making it easier to quickly assess the impact of a PR before further review is needed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VIVAAN-DHAWAN/diffly-cli">https://github.com/VIVAAN-DHAWAN/diffly-cli</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/diffly-pr-triage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The diffly GitHub Action helps developers review large, AI-generated pull requests by providing a comprehensive one-page report with a verdict, risk flags, checks, and a blast-radius map. It automates the task of identifying changes in files, symbols, dependencies, and tests, making it easier to quickly assess the impact of a PR before further review is needed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<h3 id="new-diffly-local--offline-triage-for-any-folder">New: <code>diffly local</code> — offline triage for any folder</h3>
<p>Analyze git changes on your own disk with zero network access — works for <strong>private, archived, or removed</strong> repositories:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>diffly local                      <span style="color:#75715e"># uncommitted working-tree changes</span>
</span></span><span style="display:flex;"><span>diffly local ~/code/private-repo  <span style="color:#75715e"># any checkout on disk</span>
</span></span><span style="display:flex;"><span>diffly local --base main          <span style="color:#75715e"># compare your branch against main</span>
</span></span></code></pre></div><p>Same deterministic pipeline as PR triage: changed-file inventory, Tree-sitter symbol detection, blast-radius map, and risk rules. Untracked files are included; CI-check rules are skipped as not applicable.</p>
<h3 id="ux-overhaul">UX overhaul</h3>
<ul>
<li><strong>Centered terminal composition</strong> across the wizard, setup walkthrough, interactive review, doctor, and version screens</li>
<li>Wizard prompts for a <strong>Repository URL</strong> with explicit format hints (<code>owner/repo</code> or paste any GitHub / pull-request URL)</li>
<li><strong>Loading spinners</strong> with progress messaging during fetch and explanation phases</li>
<li>Pasting a full pull-request URL skips the number prompt entirely</li>
</ul>
<h3 id="fixed-explanations-were-invisible">Fixed: explanations were invisible</h3>
<p>The interactive view never rendered the generated explanation even when produced. It is now a toggleable section in the interactive screen, with clear setup guidance when no LLM key is configured.</p>
<h3 id="engine-fixes">Engine fixes</h3>
<ul>
<li><code>CHECKS_PENDING</code> evidence lists real check names instead of the literal state string</li>
<li><code>\\ No newline at end of file</code> markers no longer skew changed-line attribution</li>
<li>Action comment publishing uses typed <code>GitHubApiError</code> instead of string-matching error text</li>
<li>JSON output is pure again — banners suppressed under <code>--json</code></li>
<li>Bare <code>diffly</code> no longer hangs in non-TTY environments; Windows imports fixed via lazy termios loading</li>
</ul>
<h3 id="license--community-files">License &amp; community files</h3>
<ul>
<li>LICENSE expanded from bare MIT to a documented four-part license (same MIT grant + definitions, contribution terms, verdict disclaimers, extended warranty/liability, general terms)</li>
<li>Added CONTRIBUTING.md, SECURITY.md, CHANGELOG.md</li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/VIVAAN-DHAWAN/diffly-cli/blob/main/CHANGELOG.md">https://github.com/VIVAAN-DHAWAN/diffly-cli/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Move Closed Issue to Top of Project Column</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/move-closed-issue-to-top-of-project-column/</link><pubDate>Fri, 21 Aug 2026 21:50:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/move-closed-issue-to-top-of-project-column/</guid><description>Version updated for https://github.com/wozaki/project-closed-issue-move-to-top-action to version v1.26.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of moving closed issues to the top of a specified column in a GitHub Project V2. It checks if an issue is part of the project and updates its status, then moves it to the top of the designated column. This ensures that recently closed issues are always visible at the top of your project board.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wozaki/project-closed-issue-move-to-top-action">https://github.com/wozaki/project-closed-issue-move-to-top-action</a></strong> to version <strong>v1.26.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-closed-issue-to-top-of-project-column">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of moving closed issues to the top of a specified column in a GitHub Project V2. It checks if an issue is part of the project and updates its status, then moves it to the top of the designated column. This ensures that recently closed issues are always visible at the top of your project board.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">wozaki/project-closed-issue-move-to-top-action@6622906b8b0679946702094872399de0ba95b28c</span> <span style="color:#75715e"># v1.26.0</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update int128/release-typescript-action action to v1.79.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/181">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/181</a></li>
<li>chore(deps): update int128/wait-for-workflows-action action to v1.92.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/183">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/183</a></li>
<li>chore(deps): update int128/update-generated-files-action action to v2.104.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/182">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/182</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/184">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/184</a></li>
<li>chore(deps): update node.js to v24.19.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/185">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/185</a></li>
<li>chore(deps): update pnpm to v11.20.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/186">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/186</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/188">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/188</a></li>
<li>chore(deps): update int128/update-generated-files-action action to v2.107.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/187">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/187</a></li>
<li>chore(deps): update dependency @vercel/ncc to v0.45.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/189">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/189</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.25.0...v1.26.0">https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.25.0...v1.26.0</a></p>
]]></content:encoded></item><item><title>Legion Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/legion-runner/</link><pubDate>Fri, 21 Aug 2026 21:50:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/legion-runner/</guid><description>Version updated for https://github.com/Wraith-security/Legion_runner to version v1.0.59.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Legion Runner is an open-source action designed to protect GitHub Actions jobs by monitoring outgoing network connections and enforcing a whitelist. It records every outbound connection, names the process behind it, and blocks unauthorized destinations. The Action is self-contained, with no dependencies beyond Node.js built-ins and optional eBPF-based capture and file-integrity checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Wraith-security/Legion_runner">https://github.com/Wraith-security/Legion_runner</a></strong> to version <strong>v1.0.59</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/legion-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Legion Runner is an open-source action designed to protect GitHub Actions jobs by monitoring outgoing network connections and enforcing a whitelist. It records every outbound connection, names the process behind it, and blocks unauthorized destinations. The Action is self-contained, with no dependencies beyond Node.js built-ins and optional eBPF-based capture and file-integrity checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Curated egress presets (<code>allowed-presets</code>)</strong>: opt-in per-ecosystem allowlists
(npm, yarn, pnpm, pip, pypi, cargo, rust, go, maven, gradle, nuget, apt, debian,
docker) so block mode &ldquo;just works&rdquo; for common toolchains without hand-listing
endpoints. e.g. <code>allowed-presets: &quot;cargo, apt&quot;</code>. Unit-tested.</li>
<li><strong>Download integrity verification</strong>: the action verifies the <code>legionr-bpf</code> /
<code>legionr-fim</code> release binaries against a <code>.sha256</code> sidecar before running them
(the release now attaches the checksums), and <strong>fails closed</strong> — an
unverified/corrupted/tampered download is rejected and the action degrades
instead of executing it.</li>
<li><strong><code>learned-baseline</code> input</strong> (default <code>true</code>): in block mode, also allow
destinations previously learned into the Actions cache. Set <code>false</code> to enforce
ONLY the explicit allowlist (inline + policy-file + GitHub) with no cache
read/write — used by the enforce self-test for deterministic deny.</li>
<li><strong>File-integrity / tamper detection (Rust <code>legionr-fim</code> agent)</strong>: snapshots
high-value tamper targets at job start (credential/config files, <code>.git</code>
config + hooks, and checked-out source) and diffs them at job end, surfacing
anything overwritten, deleted, or chmod&rsquo;d in the summary. Only sha256 hashes
are stored — never contents. New inputs <code>file-integrity</code> (auto|off) and
<code>fim-extra-paths</code>. <code>file-integrity: auto</code> downloads the agent from the latest
release (plain stable Rust, no eBPF toolchain) and degrades to a silent skip
if unavailable. Logic lives in <code>legionr-core::fim</code> (unit-tested); the binary
is a release asset like <code>legionr-bpf</code>, built + attached by <code>release.yml</code>.</li>
<li><strong>Package repositories roll-up (<code>📦</code>)</strong>: the summary now classifies named
outbound destinations into their ecosystem/registry (npm, PyPI, crates.io,
apt, Docker, Go, NuGet, Maven, Gradle, RubyGems, Alpine, GitHub) and shows a
<strong>Package repositories reached</strong> table — registry, ecosystem, connections, and
the process that reached each. Supply-chain risk hides in <em>which</em> registries a
build talks to, so we surface them directly instead of leaving you to read
IPs. Bare IPs that never got a forward name get a coarse CDN/provider hint
(Fastly/Cloudflare/GitHub) via CIDR match — honest about ambiguity (a shared
CDN can&rsquo;t name a registry). Logic in <code>action/repos.js</code>, fully unit-tested.</li>
<li><strong>Combined cross-job egress report (one summary for the whole run)</strong>: GitHub
has no run-level summary, so each job emits its captured egress as a JSON
artifact (<code>node action/report.js emit</code>) and a final <code>egress-report</code> job merges
them into a SINGLE table — which job + process reached what — with a package
repositories roll-up and a per-job diagnostics block (<code>render</code>). Wired into CI;
<code>render</code> is pure and unit-tested. Pairs with <code>job-summary: false</code> so the run
shows one combined summary instead of one table per job.</li>
<li><strong><code>job-summary</code> input</strong> (default <code>true</code>): set <code>false</code> to keep monitoring and
enforcement fully active but suppress the connections table in the job summary.
Useful when many jobs in one workflow each run the action and you only want the
table once (our own CI uses it so a run shows one table, not one per job).</li>
<li><strong>Secure diagnostics line</strong> in the summary: reports which resolution path
actually fired (<code>forwarder on/off · captured DNS records N · getaddrinfo route … · named X/Y destinations</code>) so a run that comes back as bare IPs is triagable.
Secure by construction — only booleans, counts, and a fixed enum; never the
upstream resolver IP, file paths, captured hostnames, or env values.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>The live e2e tier is out of CI.</strong> <code>.github/workflows/e2e.yml</code> now runs only
the credential-free <code>local</code> job. The removed <code>live</code> job registered a runner
against a fixed external scope that this org cannot install the App on, so it
could only skip silently or fail noisily, and neither outcome said anything
about the runner. <code>scripts/e2e.sh --mode live</code> still works and can be pointed
at any scope you control, but the scope is now mandatory (<code>--scope owner/repo</code>
or <code>E2E_SCOPE</code>) instead of defaulting to a hardcoded constant: the harness
will not guess a target it registers a real runner against. The <code>local</code> tier
falls back to <code>$GITHUB_REPOSITORY</code> since it provisions with <code>--no-probe</code> and
never reaches GitHub.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>FIM hashing builds against <code>sha2</code> 0.11.</strong> The digest type changed to
<code>hybrid_array::Array</code>, which does not implement <code>LowerHex</code>, so
<code>format!(&quot;{:x}&quot;, ..)</code> in <code>fim::hash_file</code> stopped compiling. The digest is now
hex-encoded byte by byte, which works on both 0.10 and 0.11. Two tests pin the
behaviour: the exact sha256 of <code>abc</code>, and a 64-char length/charset assertion so
a dropped leading zero cannot pass silently. Unblocks the <code>cargo-major</code>
dependency group (<code>sha2</code> 0.10.9 to 0.11.0, <code>thiserror</code> 1 to 2.0.18).</li>
<li><strong>Block mode no longer hangs the runner at teardown.</strong> <code>applyEgressBlock</code>
installed a default-deny <code>LEGION_EGRESS</code> chain in <code>OUTPUT</code> and nothing ever
removed it, so the runner&rsquo;s own completion call (to rotating GitHub-backend IPs
not in the static seed) was dropped and the job spun until timeout. <code>post()</code>
now tears the firewall down (<code>removeEgressBlock</code>).</li>
<li><strong>Runner hang from leaked daemons.</strong> The post step left privileged background
processes alive — eBPF agent, DNS forwarder — and the <code>/proc</code> monitor could
wedge in a blocking <code>ss</code> subprocess. The monitor now reads <code>/proc/net/tcp</code>
directly (no subprocess); daemons are reliably reaped.</li>
<li><strong>No more spurious &ldquo;could not resolve&rdquo; annotations.</strong> Allowlist entries that
are wildcard parents with no A record of their own (e.g. <code>blob.core.windows.net</code>,
<code>actions.githubusercontent.com</code>) used to emit one CI <strong>warning annotation</strong>
each on every run. They are benign: the action skips them, and their subdomains
are still observed via PTR / DNS capture (and opened just-in-time in block
mode). They are now collected into a single plain-text log line instead.</li>
<li><strong>Docs/labels</strong>: the eBPF mechanism is a <strong>tracepoint on <code>sys_enter_connect</code></strong>
(not a &ldquo;kprobe on tcp_connect&rdquo;); the sampler is <code>/proc</code>-only (the &ldquo;ss&rdquo; fallback
was removed). Corrected the runtime log line, summary label, and README.</li>
<li><strong>Outbound connections showed as bare IPs when systemd-resolved owns
<code>getaddrinfo</code>.</strong> The <code>nsswitch</code> reroute didn&rsquo;t always stick, so package-repo
lookups bypassed the capture forwarder and were never named. The forwarder now
targets the <em>real</em> upstream (systemd-resolved&rsquo;s actual servers, not the
<code>127.0.0.53</code> stub), and when the bypass is detected but the nsswitch reroute
fails, Legion redirects systemd-resolved itself at the forwarder via a
<code>resolved.conf.d</code> drop-in — <strong>verify-or-revert</strong> and restored on teardown, so
it never breaks the job&rsquo;s DNS.</li>
<li><strong>IPv4-mapped IPv6 destinations rendered as long expanded addresses</strong>
(<code>0000:0000:0000:0000:0000:ffff:HHHH:HHHH</code>) in the summary. The <code>/proc</code> sampler
emitted the expanded form while <code>normalizeIp</code> only collapsed the compressed
<code>::ffff:</code> form. Both now collapse to dotted IPv4 (and the v4/v6 tables dedupe).
(Shipped in v1.0.35.)</li>
<li>Removed dead <code>action/baseline.js</code>; pinned <code>release.yml</code> checkout to v6.</li>
</ul>
<h3 id="reliability">Reliability</h3>
<ul>
<li><strong>Tests for the paths that kept breaking</strong>: the firewall rule builders
(<code>egressBlockRules</code>/<code>egressUnblockRules</code> — order, DNS-allow, DROP-last,
OUTPUT-jump-removed-first), the checksum parser, the curated presets, and a
<strong>full-stack PR gate</strong> that runs block + DNS-capture + eBPF and asserts the
job finalizes (catches any teardown-hang regression), plus the package-repo
classifier (host-suffix + CIDR matching). Action test count 19 → 37.</li>
</ul>
<h3 id="changed-1">Changed</h3>
<ul>
<li>Removed em-dashes from the job-summary output (headers, the unresolved-host
note, the enforce hint, and empty-cell placeholders) for plainer rendering.</li>
<li><strong>Name more destinations</strong>: route glibc <code>getaddrinfo</code> (curl/apt/cargo/git)
through the DNS-capture forwarder via an <code>nsswitch.conf</code> reroute, so hosts
resolved by systemd-resolved (which ignores <code>resolv.conf</code>) are now captured
and named — not just <code>resolv.conf</code>/c-ares callers. Health-checked and restored
on teardown. (A connection to a hard-coded IP with no PTR still shows the IP —
there is no name to resolve.)</li>
<li>More accurate &ldquo;unresolved destination&rdquo; note in the summary (a name may have
been resolved outside the capture path, vs. a genuine raw-IP connection).</li>
<li><strong>We dogfood our own action.</strong> Every real-work job in this repo (CI, release,
eBPF agent, FIM self-test) now runs Legion Runner as its first step (<code>@v1</code>,
audit) — our CI is hardened by the product it ships.</li>
<li><strong>Docs-only PRs skip the build/test matrix</strong> (and the release it gates) via
<code>paths-ignore</code>; a <code>docs-passthrough</code> workflow reports the same check names
green so required checks stay satisfied and README edits stay mergeable
without burning CI minutes.</li>
<li><strong>Our CI now captures names.</strong> The dogfooded harden steps run with
<code>dns-capture: true</code> (still <code>audit</code> — monitor, don&rsquo;t firewall), so job summaries
show real destination and package-repository names instead of bare IPs, and the
capture path is exercised on every run. Safe now that <code>@v1</code> (&gt;= 1.0.35) carries
the teardown + systemd-resolved fixes.</li>
</ul>
]]></content:encoded></item><item><title>Cerbi Logging Governance Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/cerbi-logging-governance-scanner/</link><pubDate>Fri, 21 Aug 2026 21:49:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/cerbi-logging-governance-scanner/</guid><description>Version updated for https://github.com/Zeroshi/cerbi-scanner-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
The GitHub Action Zeroshi/cerbi-scanner-action is a tool designed to statically analyze application logging calls for sensitive data exposure, unsafe payload logging, policy violations, and other logging-governance risks. It runs on the GitHub Actions runner, performs static analysis using the Cerbi Scanner NuGet package, and provides detailed reports that can be uploaded to GitHub code scanning. The action supports various logging patterns across C#, Go, Java, JavaScript/TypeScript, and Python languages and can enforce policy thresholds by failing builds based on severity levels. It also offers options for privacy mode, SARIF upload, and artifact generation, making it a versatile tool for improving logging governance in software development pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zeroshi/cerbi-scanner-action">https://github.com/Zeroshi/cerbi-scanner-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cerbi-logging-governance-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>The GitHub Action <code>Zeroshi/cerbi-scanner-action</code> is a tool designed to statically analyze application logging calls for sensitive data exposure, unsafe payload logging, policy violations, and other logging-governance risks. It runs on the GitHub Actions runner, performs static analysis using the Cerbi Scanner NuGet package, and provides detailed reports that can be uploaded to GitHub code scanning. The action supports various logging patterns across C#, Go, Java, JavaScript/TypeScript, and Python languages and can enforce policy thresholds by failing builds based on severity levels. It also offers options for privacy mode, SARIF upload, and artifact generation, making it a versatile tool for improving logging governance in software development pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Cerbi Logging Governance Scanner v1.0.0</p>
<p>Find sensitive data, unsafe logging patterns, and logging policy violations before production.</p>
<p>Cerbi Scanner runs directly in GitHub Actions and analyzes application logging code before telemetry reaches production systems.</p>
<p>What this release includes
Scans C#, Go, Java, JavaScript/TypeScript, and Python repositories
Detects sensitive-data and logging-governance risks
Supports Cerbi policy-as-code
Generates JSON, SARIF, and Markdown reports
Integrates with GitHub Code Scanning through SARIF
Supports configurable CI failure thresholds
Runs on Linux, Windows, and macOS GitHub-hosted runners
Does not upload source code or findings to Cerbi by default
Disables source snippets by default for safer CI artifacts
Quick start</p>
<ul>
<li>
<p>uses: actions/checkout@v7</p>
</li>
<li>
<p>name: Cerbi logging governance scan
uses: Zeroshi/cerbi-scanner-action@v1
Enforce logging policy</p>
</li>
<li>
<p>name: Cerbi logging governance scan
uses: Zeroshi/cerbi-scanner-action@v1
with:
policy: cerbi-policy.yml
fail-on: high
GitHub Code Scanning
permissions:
contents: read
security-events: write</p>
</li>
</ul>
<p>steps:</p>
<ul>
<li>
<p>uses: actions/checkout@v7</p>
</li>
<li>
<p>uses: Zeroshi/cerbi-scanner-action@v1
with:
upload-sarif: &rsquo;true'</p>
</li>
</ul>
<p>Cerbi Scanner can be used independently. CerbiShield is available for organizations that need centralized logging policy, governance, evidence, and visibility across repositories and workloads.</p>
<p>Documentation: <a href="https://www.cerbi.io/docs/scanner/quickstart">https://www.cerbi.io/docs/scanner/quickstart</a></p>
]]></content:encoded></item><item><title>Gua Godot GDScript CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/gua-godot-gdscript-ci/</link><pubDate>Fri, 21 Aug 2026 14:16:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/gua-godot-gdscript-ci/</guid><description>Version updated for https://github.com/link1345/gua-tester to version v1.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup and testing of Godot GDScript projects using Gua, a UI testing framework for Godot. It downloads specific Godot binaries and Gua releases, extracts addon assets, copies them into the project, and runs .NET tests that interact with the GUI using Wasm/WebSockets through Gua.Testing.Godot. The action is suitable for CI/CD pipelines where developers need to ensure their GDScript projects are compatible with Gua-based UI testing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/link1345/gua-tester">https://github.com/link1345/gua-tester</a></strong> to version <strong>v1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gua-godot-gdscript-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup and testing of Godot GDScript projects using Gua, a UI testing framework for Godot. It downloads specific Godot binaries and Gua releases, extracts addon assets, copies them into the project, and runs .NET tests that interact with the GUI using Wasm/WebSockets through <code>Gua.Testing.Godot</code>. The action is suitable for CI/CD pipelines where developers need to ensure their GDScript projects are compatible with Gua-based UI testing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #1 from link1345/codex/tag-update (a9ab990)</li>
<li>Merge branch &lsquo;main&rsquo; into codex/tag-update (f2f2f6e)</li>
<li>安定版Guaリリースの取得とGodotインポート検証を追加 (e272e47)</li>
<li>Update gua-plugin-tag to version 0.15.0 (a0f3276)</li>
<li>Update Gua Tester action version in README (04de345)</li>
<li>Guaアドオンの取得を配布版ダウンロードに切り替える (c6064fa)</li>
<li>README修正 (26203c3)</li>
<li>ブランド設定を追加 (52dcf81)</li>
<li>コミットメッセージを生成 (cedd729)</li>
</ul>
]]></content:encoded></item><item><title>DeepSeek Harness for GitHub</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/deepseek-harness-for-github/</link><pubDate>Fri, 21 Aug 2026 14:14:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/deepseek-harness-for-github/</guid><description>Version updated for https://github.com/Lixiaoyiao/deepseek-harness-action to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of using DeepSeek Harness to review pull requests, diagnose issues based on failed CI runs, and fix code or turn issues into pull requests. It integrates with GitHub events and leverages the capabilities of DeepSeek Harness to enhance collaboration and improve code quality in repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lixiaoyiao/deepseek-harness-action">https://github.com/Lixiaoyiao/deepseek-harness-action</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deepseek-harness-for-github">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of using DeepSeek Harness to review pull requests, diagnose issues based on failed CI runs, and fix code or turn issues into pull requests. It integrates with GitHub events and leverages the capabilities of DeepSeek Harness to enhance collaboration and improve code quality in repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>DeepSeek Harness Action v0.4.0 connects the v0.3 multi-turn Agent loop to DeepSeek Harness&rsquo;s official MCP, Profile, Bundle, Cordis Plugin, and ToolRuntime extension mechanisms while preserving the Controller-owned GitHub write boundary.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Upgrades the exact DeepSeek Harness runtime pin from <code>0.1.0-rc.6</code> to <code>0.1.0-rc.8</code>; all DSH-family dependencies remain exact, and the Action now runs on Node 24.</li>
<li>Adds official <code>@deepseek-ai/dsh-mcp-client</code> integration for <code>stdio</code> and Streamable HTTP transports.</li>
<li>Adds Controller-validated official DSH Profile generation and allowlisted, immutable Bundle/Plugin loading; dynamic installation remains disabled by default.</li>
<li>Unifies read, workspace-write, network, timeout, output-size, per-tool, and per-owner invocation policy across controller argv tools and DSH native/MCP/plugin tools.</li>
<li>Adds bounded extension provenance and receipts through <code>extension-profile-digest</code>, <code>tool-receipts</code>, and the structured result.</li>
<li>Keeps the Agent without unrestricted shell, <code>GITHUB_TOKEN</code>, the real DeepSeek key, or direct commit/push/PR authority.</li>
</ul>
<h2 id="inputs-and-outputs">Inputs and outputs</h2>
<p>New inputs: <code>mcp-config</code>, <code>plugin-config</code>, and <code>allow-plugin-install</code>.</p>
<p>New outputs: <code>extension-profile-digest</code> and <code>tool-receipts</code>.</p>
<h2 id="compatibility-and-security">Compatibility and security</h2>
<p>Workflows without MCP/Plugin configuration retain the v0.3 review, diagnose, fix, implement, auto, task, multi-turn, sticky-comment, and Controller-write paths. Two intentional hardenings apply: every write requires configured validation to pass, and write-task comments are deferred until validation succeeds.</p>
<p>An approved third-party Bundle/Plugin or stdio MCP executable is trusted worker code. ToolRuntime guards constrain model-routed calls; they do not sandbox package initialization, background work, or direct process I/O. Review and immutably pin the full dependency graph and enforce runner-level filesystem/network boundaries.</p>
<h2 id="verification">Verification</h2>
<ul>
<li><a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32451097249">Post-merge main CI</a>: <code>npm ci</code>, full <code>npm run check</code>, 41 test files / 360 tests, 81.02% statement coverage, deterministic <code>dist</code> gates, and Linux Docker smoke with official DSH/MCP packages at exact <code>0.1.0-rc.8</code>.</li>
<li><a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32448590692">Core real E2E</a>: real DeepSeek + DSH Agent, official MCP success/denial/failure, pinned Plugin/Profile load, invalid Plugin rejection, validation failure with no GitHub write, and validated trusted-write.</li>
<li><a href="https://github.com/Lixiaoyiao/deepseek-harness-action/pull/14">Merged development PR #14</a>.</li>
</ul>
<p>Full changes: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/compare/v0.3.0...v0.4.0">https://github.com/Lixiaoyiao/deepseek-harness-action/compare/v0.3.0...v0.4.0</a></p>
]]></content:encoded></item><item><title>Angular Setup</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/angular-setup/</link><pubDate>Fri, 21 Aug 2026 14:13:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/angular-setup/</guid><description>Version updated for https://github.com/mayurrawte/github-angular-actions to version v2.0.0.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Angular CLI on Node.js with caching for npm, yarn, and pnpm. It allows for specifying the desired version of Angular CLI, Node.js, and package manager. The action provides zero configuration by default and exposes an output indicating the installed Angular CLI version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mayurrawte/github-angular-actions">https://github.com/mayurrawte/github-angular-actions</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/angular-setup">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up Angular CLI on Node.js with caching for npm, yarn, and pnpm. It allows for specifying the desired version of Angular CLI, Node.js, and package manager. The action provides zero configuration by default and exposes an output indicating the installed Angular CLI version.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new-in-v2">What&rsquo;s new in v2</h2>
<p>Complete rewrite as a composite action — no more bundled JS, no npm deps, faster cold-starts.</p>
<h3 id="new-features">New features</h3>
<ul>
<li><strong>Multi-package-manager support</strong>: npm, yarn, pnpm (auto-detects and caches the right one)</li>
<li><strong>Configurable Node.js version</strong> (default: 22) — replaces hardcoded Node 14</li>
<li><strong>Cross-platform</strong>: Ubuntu, Windows, macOS — all tested in CI</li>
<li><strong>Smart caching</strong>: lockfile-hash based caching via setup-node, opt-out with <code>cache: 'false'</code></li>
<li><strong>Custom Angular CLI version</strong>: pin to any version (e.g. <code>17.3.8</code>) or use <code>latest</code></li>
<li><strong><code>cli-version</code> output</strong>: the installed CLI version for downstream steps</li>
<li><strong>No more node_modules in the action</strong> — composite means zero install overhead</li>
</ul>
<h3 id="quick-start">Quick start</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">mayurrawte/github-angular-actions@v2</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">version</span>: <span style="color:#e6db74">&#39;latest&#39;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">node-version</span>: <span style="color:#e6db74">&#39;22&#39;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">package-manager</span>: <span style="color:#e6db74">&#39;pnpm&#39;</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">run</span>: <span style="color:#ae81ff">ng build --configuration=production</span>
</span></span></code></pre></div><h3 id="breaking-changes-from-v1">Breaking changes from v1</h3>
<ul>
<li>Action is now composite (was: Node.js). No user-facing impact unless you were reading the action&rsquo;s source.</li>
<li>Default Node.js is now 22 (was: 14). Override with <code>node-version: '18'</code> if needed.</li>
<li>Default Angular CLI is <code>latest</code> (was: pinned). Pin with <code>version: '17.3.8'</code> if you need stability.</li>
</ul>
<p>See <a href="https://github.com/mayurrawte/github-angular-actions/blob/master/CHANGELOG.md">CHANGELOG.md</a> for full details.</p>
]]></content:encoded></item><item><title>Ani Secret &amp; Vulnerability Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/ani-secret-vulnerability-scanner/</link><pubDate>Fri, 21 Aug 2026 14:12:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/ani-secret-vulnerability-scanner/</guid><description>Version updated for https://github.com/mr-aniket-2004/SecureScan to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SecScan Engine is a secure, automated GitHub security platform that clones repositories, detects leaked API secrets, audits dependencies, and generates detailed PDF reports. It uses regex-based pattern matching to identify potential threats, tests credentials against active APIs, and provides context-aware remediation recommendations. The platform is integrated with CI/CD workflows for real-time scanning and supports offline scanning via a portable binary.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mr-aniket-2004/SecureScan">https://github.com/mr-aniket-2004/SecureScan</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ani-secret-vulnerability-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SecScan Engine is a secure, automated GitHub security platform that clones repositories, detects leaked API secrets, audits dependencies, and generates detailed PDF reports. It uses regex-based pattern matching to identify potential threats, tests credentials against active APIs, and provides context-aware remediation recommendations. The platform is integrated with CI/CD workflows for real-time scanning and supports offline scanning via a portable binary.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mr-aniket-2004/SecureScan/commits/v1">https://github.com/mr-aniket-2004/SecureScan/commits/v1</a></p>
]]></content:encoded></item><item><title>Sponsor Gated Support</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/sponsor-gated-support/</link><pubDate>Fri, 21 Aug 2026 14:11:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/sponsor-gated-support/</guid><description>Version updated for https://github.com/mrjackyliang/sponsor-gated-support to version v2.0.2.
This action is used across all versions by 20 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of gating support issues based on sponsorship status. It automatically replies, closes, and locks issues for non-sponsors, while providing a welcome message to sponsors who meet eligibility criteria set by sponsorship amount and activity. The action uses live GitHub Sponsors data to determine sponsorship status and supports multiple labels for gating support issues.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mrjackyliang/sponsor-gated-support">https://github.com/mrjackyliang/sponsor-gated-support</a></strong> to version <strong>v2.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>20</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sponsor-gated-support">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of gating support issues based on sponsorship status. It automatically replies, closes, and locks issues for non-sponsors, while providing a welcome message to sponsors who meet eligibility criteria set by sponsorship amount and activity. The action uses live GitHub Sponsors data to determine sponsorship status and supports multiple labels for gating support issues.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="sponsor-gated-support">sponsor-gated-support</h2>
<h3 id="fixed">FIXED</h3>
<ul>
<li>Updated the GitHub Action runtime from Node 20 to Node 24 ahead of the fall 2026 Node 20 removal from GitHub Actions runners.</li>
</ul>
]]></content:encoded></item><item><title>PCI Payment Page Script Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/pci-payment-page-script-check/</link><pubDate>Fri, 21 Aug 2026 14:10:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/pci-payment-page-script-check/</guid><description>Version updated for https://github.com/ntoledo319/pci-payment-page-check to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks the third-party scripts loaded on a payment page to ensure they are authorized and meet PCI DSS requirements. It fails the build if an unauthorized script is detected, helping prevent security issues related to payment processing. The action supports different scopes (direct, embedded, or outsourced) depending on how scripts are integrated into the payment page.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ntoledo319/pci-payment-page-check">https://github.com/ntoledo319/pci-payment-page-check</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pci-payment-page-script-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks the third-party scripts loaded on a payment page to ensure they are authorized and meet PCI DSS requirements. It fails the build if an unauthorized script is detected, helping prevent security issues related to payment processing. The action supports different scopes (direct, embedded, or outsourced) depending on how scripts are integrated into the payment page.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds truthful, copy-ready recipes for directly controlled card fields, embedded processor forms, and redirect or fully outsourced checkout flows. The Action behavior and bounded served-HTML contract are unchanged; all 14 security and contract tests pass.</p>
]]></content:encoded></item><item><title>MCPSec Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/mcpsec-audit/</link><pubDate>Fri, 21 Aug 2026 14:09:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/mcpsec-audit/</guid><description>Version updated for https://github.com/pfrederiksen/mcpsec to version v1.1.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
MCPSec is an OWASP MCP Top 10 security scanner designed to audit Model Context Protocol (MCP) server configurations. It checks for security risks, outputs findings in OCSF JSON or human-readable tables, and supports a pluggable YAML rules engine for community-contributed detections. The action can be used for developer laptop audits, CI/CD gate controls, security team posture assessments, Claude Desktop Extension reviews, and compliance evidence generation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pfrederiksen/mcpsec">https://github.com/pfrederiksen/mcpsec</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcpsec-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>MCPSec is an OWASP MCP Top 10 security scanner designed to audit Model Context Protocol (MCP) server configurations. It checks for security risks, outputs findings in OCSF JSON or human-readable tables, and supports a pluggable YAML rules engine for community-contributed detections. The action can be used for developer laptop audits, CI/CD gate controls, security team posture assessments, Claude Desktop Extension reviews, and compliance evidence generation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>178784acedf195c87b621bd29493b1814f188732 fix: avoid shadowed scanner variables</li>
<li>45b39c18854bc85f355d5ffbb6fa67fe5f8a59d1 fix: handle rule engine conversion errors</li>
</ul>
]]></content:encoded></item><item><title>Provael VLA red-team</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/provael-vla-red-team/</link><pubDate>Fri, 21 Aug 2026 14:08:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/provael-vla-red-team/</guid><description>Version updated for https://github.com/provael/provael to version v0.36.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Provael action automates the red-teaming of Vision-Language-Action (VLA) robot policies in simulation to measure their Attack Success Rate (ASR) by analyzing various attack techniques. It solves the problem of systematically testing VLA policies and generating comprehensive reports, including ASR statistics, pass/fail scores, and SARIF tags for rule evaluation. The action provides deterministic execution across tasks with reproducible results, making it a valuable tool for policy validation in simulation environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/provael/provael">https://github.com/provael/provael</a></strong> to version <strong>v0.36.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/provael-vla-red-team">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Provael action automates the red-teaming of Vision-Language-Action (VLA) robot policies in simulation to measure their Attack Success Rate (ASR) by analyzing various attack techniques. It solves the problem of systematically testing VLA policies and generating comprehensive reports, including ASR statistics, pass/fail scores, and SARIF tags for rule evaluation. The action provides deterministic execution across tasks with reproducible results, making it a valuable tool for policy validation in simulation environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>Per-shard provenance digests moved with the tool version — the third instance of the same
defect, and the one that finally got the rule written down.</strong> <code>combine.shard_digests</code> computed
each shard&rsquo;s <code>sha256</code> with <code>model_dump_json()</code>, re-serialising it through whatever <code>RunReport</code>
the <em>running</em> version defines. The pinned public-evidence manifest records <code>52bcdb70…</code> for
<code>libero_object_0/report.json</code>; 0.34.0 reproduces it, 0.36.1 returned <code>66897a4c…</code> for
byte-identical committed input, and <code>git diff</code> confirms the artifacts never changed.</p>
<p>That defeats the only purpose those digests have. The manifest advertises them so a consumer can
&ldquo;re-fetch each shard and verify it independently&rdquo; — and under the old body they could only do so
with the exact tool version that wrote the manifest, which is not discoverable from the manifest.
It now projects through <code>attest.report_projection</code>; all ten shards reproduce the pinned values.</p>
</li>
<li>
<p><strong>The <code>RunReport</code> digest contract in <code>types.py</code> documented the opposite of what the code does.</strong>
It stated that &ldquo;adding any field changes the digest of every historical report&rdquo; and prescribed a
<code>RULESET_VERSION</code> bump for every added field. True when written, false since <code>report_projection</code>
landed — and three digest sites went on doing the bare dump anyway, two of which shipped broken
(<code>leaderboard._inputs_digest</code> in 0.36.1, <code>combine.shard_digests</code> here). The contract now states
the rule once: <strong>any digest over a RunReport goes through <code>attest.report_projection</code>.</strong></p>
</li>
<li>
<p>The test guarding shard digests was <strong>tautological</strong> and could not have caught this: it computed
its expected value with the same <code>model_dump_json()</code> call the implementation used, so both sides
shared the bug. Its own docstring said &ldquo;or it is decoration&rdquo;. It now asserts the property a shared
bug cannot satisfy — populating a field introduced <em>after</em> a shard&rsquo;s declared <code>schema_version</code>
must not move its digest — and was verified by restoring the old body and watching it fail.</p>
</li>
</ul>
]]></content:encoded></item><item><title>diff-sentry malicious change scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/diff-sentry-malicious-change-scan/</link><pubDate>Fri, 21 Aug 2026 14:06:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/diff-sentry-malicious-change-scan/</guid><description>Version updated for https://github.com/qazbnm456/diff-sentry to version v0.4.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary diff-sentry is a GitHub Action designed to detect malicious pull requests by analyzing changes as untrusted data and identifying specific attack patterns such as obfuscation, execution, exfiltration, and provenance. It helps catch workflows that could potentially break the build or lead to security vulnerabilities before they are merged.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/qazbnm456/diff-sentry">https://github.com/qazbnm456/diff-sentry</a></strong> to version <strong>v0.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/diff-sentry-malicious-change-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>diff-sentry is a GitHub Action designed to detect malicious pull requests by analyzing changes as untrusted data and identifying specific attack patterns such as obfuscation, execution, exfiltration, and provenance. It helps catch workflows that could potentially break the build or lead to security vulnerabilities before they are merged.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Scoping. Every fix here comes from the same root: the scan read a whole change as one string, so rules that need two signals could take them from two unrelated files.</p>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>The scan is scoped per file.</strong> Most rules fire on a single match, so reading the whole diff as one blob was harmless for them — but two need a PAIR of signals (<code>pwn-request</code>: privileged trigger + PR-HEAD checkout; <code>detached-process-spawn</code>: detached spawn + <code>child_process</code>), and those could pair across files. A <code>workflow_run:</code> added to one workflow plus a <code>ref: ${{ … head.sha }}</code> sitting in a doc example, a test fixture, or the very workflow a change is <em>deleting</em>, composed into a <code>critical</code> that no single file contained. <code>scan_diff</code> splits a unified diff on its file headers and scans each segment alone; non-diff input falls through to the previous whole-text scan.</li>
<li><strong>The host-side baseline is scoped too, via <code>scan_content</code>.</strong> An event is not a unified diff — <code>raw_content</code> concatenates the title, every <code>(filename, patch)</code> and the body with no <code>diff --git</code> headers, so pointing the baseline at <code>scan_diff</code> would have scoped nothing at all. The false positive this removes is not hypothetical: a PR that adds a <code>workflow_run</code> workflow <strong>and documents the trap in the same commit</strong> — what a careful repo writes — came out <code>critical</code> when read as one blob, and is now a sub-floor <code>medium</code>.</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>pwn-request</code> covers <code>allow-unsafe-pr-checkout: true</code>.</strong> actions/checkout v5.1/v6.1/v7 refuse to check out a fork PR head under <code>pull_request_target</code> / <code>workflow_run</code> unless a workflow opts back in with that input. The opt-in is the same attack stated in words — no ref to trace, no dataflow to infer — so it joins the <code>ref:</code> value and the hand-rolled <code>git fetch</code> as the rule&rsquo;s third form, with its own title. It only counts under a privileged trigger; a <em>removed</em> opt-in does not fire, and neither does an explicit <code>false</code>.</li>
<li><strong>Hits name the file they came from.</strong> <code>location</code> used to be the name of the whole diff for every hit.</li>
<li><strong>A hit id is stable between a whole-diff scan and a single-file scan</strong>, so the baseline and an in-loop scan de-duplicate to one union member on read. Whole-blob scanning could not promise that — the snippet window moved with the byte offset.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong><code>astral-sh/setup-uv</code> → v10.0.1 and <code>actions/checkout</code> → v7</strong>, both for the Node 24 runtime. The setup-uv bump covers <code>action.yml</code>, so it reaches every repo running this action, not just this one&rsquo;s CI. checkout v7 also blocks fork-PR checkout under <code>pull_request_target</code> / <code>workflow_run</code> — the <code>pwn-request</code> shape this project detects, now refused by the action itself.</li>
<li><strong><code>pypa/gh-action-pypi-publish</code> → v1.14.2</strong>, which carries Twine 7 and accepts the core metadata 2.5 that <code>uv build</code> now emits.</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/kaniko-build-action/</link><pubDate>Fri, 21 Aug 2026 14:05:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, “Hello world docker action,” prints a greeting message either to “World” or a specified name. It is designed to automate the process of displaying personalized greetings in logs, solving the problem of automating simple text output. The key capabilities include inputting a name for the person to greet and retrieving the current time when the message is displayed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, &ldquo;Hello world docker action,&rdquo; prints a greeting message either to &ldquo;World&rdquo; or a specified name. It is designed to automate the process of displaying personalized greetings in logs, solving the problem of automating simple text output. The key capabilities include inputting a name for the person to greet and retrieving the current time when the message is displayed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>Fettle — repository health grade</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/fettle-repository-health-grade/</link><pubDate>Fri, 21 Aug 2026 14:05:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/fettle-repository-health-grade/</guid><description>Version updated for https://github.com/rumankazi/fettle to version v4.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the maintenance health assessment of GitHub repositories by evaluating five key rules: branch protection, code ownership, dependency updates configuration, open pull request count, and stale pull requests. It provides a real five-rule score, letter grade, and detailed evidence for each result, helping users understand their repository’s maintenance health status.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rumankazi/fettle">https://github.com/rumankazi/fettle</a></strong> to version <strong>v4.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fettle-repository-health-grade">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the maintenance health assessment of GitHub repositories by evaluating five key rules: branch protection, code ownership, dependency updates configuration, open pull request count, and stale pull requests. It provides a real five-rule score, letter grade, and detailed evidence for each result, helping users understand their repository&rsquo;s maintenance health status.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="430-2026-08-21"><a href="https://github.com/rumankazi/fettle/compare/v4.2.0...v4.3.0">4.3.0</a> (2026-08-21)</h2>
<h3 id="features">Features</h3>
<ul>
<li>withhold the grade when too little of a repository could be read (<a href="https://github.com/rumankazi/fettle/issues/56">#56</a>) (<a href="https://github.com/rumankazi/fettle/commit/19f813dcc527c82a17da4f3e77d856723d6708b9">19f813d</a>)</li>
</ul>
]]></content:encoded></item><item><title>ESLint Config Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/eslint-config-check/</link><pubDate>Fri, 21 Aug 2026 14:04:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/eslint-config-check/</guid><description>Version updated for https://github.com/santi020k/eslint-config-basic to version @santi020k/eslint-config-full@3.2.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup of a DX-first ESLint configuration that detects and automatically configures JavaScript, TypeScript, and optional framework features based on the project’s dependencies. The action allows users to manage their linting configuration efficiently, including installing only the necessary packages and features tailored to their project needs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/santi020k/eslint-config-basic">https://github.com/santi020k/eslint-config-basic</a></strong> to version <strong>@santi020k/eslint-config-full@3.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/eslint-config-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup of a DX-first ESLint configuration that detects and automatically configures JavaScript, TypeScript, and optional framework features based on the project&rsquo;s dependencies. The action allows users to manage their linting configuration efficiently, including installing only the necessary packages and features tailored to their project needs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="minor-changes">Minor Changes</h3>
<ul>
<li>Keep TypeScript 6 declaration inference for JavaScript ESLint configs portable
under pnpm by returning a package-owned public config-array type. Annotate the
recommended entry point and verify packed consumers do not expose internal
<code>typescript-eslint</code> dependency paths or report TS2883.</li>
</ul>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li>@santi020k/eslint-config-basic@3.4.0</li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/agentauditkit-mcp-security-scan/</link><pubDate>Fri, 21 Aug 2026 14:03:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.85.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit automates security scans for AI agent pipelines across 10 platforms, identifying misconfigurations, hardcoded secrets, tool poisoning, and tainted data flows. It ensures that your code, configs, and secrets remain secure by scanning locally without network calls and maintaining consistent results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.85</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit automates security scans for AI agent pipelines across 10 platforms, identifying misconfigurations, hardcoded secrets, tool poisoning, and tainted data flows. It ensures that your code, configs, and secrets remain secure by scanning locally without network calls and maintaining consistent results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.85
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.85
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.85</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Derive every count in the repo description instead of typing two of them by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/620">https://github.com/sattyamjjain/agent-audit-kit/pull/620</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.84...v0.3.85">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.84...v0.3.85</a></p>
]]></content:encoded></item><item><title>Release Luau Package Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/release-luau-package-action/</link><pubDate>Fri, 21 Aug 2026 14:01:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/release-luau-package-action/</guid><description>Version updated for https://github.com/seaofvoices/release-luau-package-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Release Luau Package Action automates the process of publishing and releasing Sea of Voices Luau packages to npm, creating a new tag, and uploading assets to a GitHub release. It requires permissions to create tags, releases, and publish to npm with provenance. Users can specify artifacts for upload and choose between using yarn or npm as their package manager.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seaofvoices/release-luau-package-action">https://github.com/seaofvoices/release-luau-package-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/release-luau-package-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Release Luau Package Action automates the process of publishing and releasing Sea of Voices Luau packages to npm, creating a new tag, and uploading assets to a GitHub release. It requires permissions to create tags, releases, and publish to npm with provenance. Users can specify artifacts for upload and choose between using yarn or npm as their package manager.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fix tag creation step by @jeparlefrancais in <a href="https://github.com/seaofvoices/release-luau-package-action/pull/1">https://github.com/seaofvoices/release-luau-package-action/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/seaofvoices/release-luau-package-action/compare/v1...v1.0.1">https://github.com/seaofvoices/release-luau-package-action/compare/v1...v1.0.1</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/sherpa.sh/</link><pubDate>Fri, 21 Aug 2026 14:01:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven infrastructure management tool that simplifies deployment by translating plain English commands into fully automated cloud infrastructures. It supports various cloud providers, frameworks, and tasks through natural language input, making it accessible to developers without requiring extensive technical expertise or infrastructure knowledge. With Sherpa, users can quickly deploy their applications with minimal setup, ensuring that resources are configured efficiently and automatically based on their needs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven infrastructure management tool that simplifies deployment by translating plain English commands into fully automated cloud infrastructures. It supports various cloud providers, frameworks, and tasks through natural language input, making it accessible to developers without requiring extensive technical expertise or infrastructure knowledge. With Sherpa, users can quickly deploy their applications with minimal setup, ensuring that resources are configured efficiently and automatically based on their needs.</p>
]]></content:encoded></item><item><title>Aegis AI Agent Security &amp; AST Invariant Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/aegis-ai-agent-security-ast-invariant-guard/</link><pubDate>Fri, 21 Aug 2026 13:59:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/aegis-ai-agent-security-ast-invariant-guard/</guid><description>Version updated for https://github.com/Snehgabani/aegis-kernel to version diagnostics@vv1.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Aegis is an open-source safety kernel that verifies AI agent tool calls against deterministic invariants before execution. It parses SQL into abstract syntax trees, applies tautology detection via constant folding, enforces numeric bounds, and masks secrets through salted token vaults. The core observation behind Aegis is that structural violations can be caught deterministically rather than probabilistically through AST analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Snehgabani/aegis-kernel">https://github.com/Snehgabani/aegis-kernel</a></strong> to version <strong><a href="mailto:diagnostics@vv1.2.1">diagnostics@vv1.2.1</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aegis-ai-agent-security-ast-invariant-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Aegis is an open-source safety kernel that verifies AI agent tool calls against deterministic invariants before execution. It parses SQL into abstract syntax trees, applies tautology detection via constant folding, enforces numeric bounds, and masks secrets through salted token vaults. The core observation behind Aegis is that structural violations can be caught deterministically rather than probabilistically through AST analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="121-2026-08-21"><a href="https://github.com/Snehgabani/aegis-kernel/compare/diagnostics@vv1.2.0...diagnostics@vv1.2.1">1.2.1</a> (2026-08-21)</h2>
<h3 id="-bug-fixes--invariant-patches">🐛 Bug Fixes &amp; Invariant Patches</h3>
<ul>
<li><strong>release:</strong> add repository provenance metadata across all packages and fix CI Python test paths (<a href="https://github.com/Snehgabani/aegis-kernel/commit/6d41f24ec5a43c311fef98c4d2bb6f4962974295">6d41f24</a>)</li>
</ul>
]]></content:encoded></item><item><title>GTR - Go Test Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/gtr-go-test-report/</link><pubDate>Fri, 21 Aug 2026 13:58:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/gtr-go-test-report/</guid><description>Version updated for https://github.com/soulteary/go-test-report-action to version v1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of Go tests and generates a detailed report, including a Markdown file, SVG coverage badge, and JSON output. It also supports enforcing total-coverage and per-package thresholds, making it suitable for use in both pull request and default-branch workflows. The action outputs are stable and can be committed back to the repository without causing noisy diffs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/soulteary/go-test-report-action">https://github.com/soulteary/go-test-report-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gtr-go-test-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of Go tests and generates a detailed report, including a Markdown file, SVG coverage badge, and JSON output. It also supports enforcing total-coverage and per-package thresholds, making it suitable for use in both pull request and default-branch workflows. The action outputs are stable and can be committed back to the repository without causing noisy diffs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/soulteary/go-test-report-action/commits/v1">https://github.com/soulteary/go-test-report-action/commits/v1</a></p>
]]></content:encoded></item><item><title>Go Report Card Badge</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/go-report-card-badge/</link><pubDate>Fri, 21 Aug 2026 13:57:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/go-report-card-badge/</guid><description>Version updated for https://github.com/soulteary/goreportcard-action to version v1.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates a Go Report Card quality assessment badge for a project and can commit it back into the repository. It runs various checks including code formatting, dependency analysis, and license compliance, producing an overall grade and self-contained SVG badge. The action is available on GitHub Marketplace and provides both a command-line tool and a workflow integration option.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/soulteary/goreportcard-action">https://github.com/soulteary/goreportcard-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-report-card-badge">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates a Go Report Card quality assessment badge for a project and can commit it back into the repository. It runs various checks including code formatting, dependency analysis, and license compliance, producing an overall grade and self-contained SVG badge. The action is available on GitHub Marketplace and provides both a command-line tool and a workflow integration option.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/soulteary/goreportcard-action/compare/v1.0.0...v1">https://github.com/soulteary/goreportcard-action/compare/v1.0.0...v1</a></p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/ssg-static-site-generator/</link><pubDate>Fri, 21 Aug 2026 13:56:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.47.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast and efficient static site generator written in Go that converts Markdown content with YAML frontmatter into a complete website. It automates tasks such as building, deploying, and serving websites quickly. Key capabilities include built-in themes, multiple template engines, SEO metadata, and image processing. SSG supports various deployment platforms, including Cloudflare Pages, GitHub Pages, and Vercel.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.47</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast and efficient static site generator written in Go that converts Markdown content with YAML frontmatter into a complete website. It automates tasks such as building, deploying, and serving websites quickly. Key capabilities include built-in themes, multiple template engines, SEO metadata, and image processing. SSG supports various deployment platforms, including Cloudflare Pages, GitHub Pages, and Vercel.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.47 — MCP token, one-process watch, a preview that serves its own redirects, and per-section language by @spagu in <a href="https://github.com/spagu/ssg/pull/189">https://github.com/spagu/ssg/pull/189</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.46...v1.8.47">https://github.com/spagu/ssg/compare/v1.8.46...v1.8.47</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/classroom-to-sheets-integration/</link><pubDate>Fri, 21 Aug 2026 13:55:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates Google Sheets with GitHub Classroom to automatically send assignment results. It enables users to share their projects with Google Sheets and provides an API to update grades dynamically. The integration requires setting up Google sheet API credentials, configuring secrets in GitHub Actions workflows, and specifying task IDs and results for automatic updates.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates Google Sheets with GitHub Classroom to automatically send assignment results. It enables users to share their projects with Google Sheets and provides an API to update grades dynamically. The integration requires setting up Google sheet API credentials, configuring secrets in GitHub Actions workflows, and specifying task IDs and results for automatic updates.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/delivery-autopilot-runner/</link><pubDate>Fri, 21 Aug 2026 13:54:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Delivery Autopilot Runner GitHub Action automates the delivery process from your tracker to a reviewed pull request using an AI pipeline hosted by Tekunda. It checks out the repository, runs code generation and quality checks, and opens a pull request. The action is triggered by a signed instruction issued by Delivery Autopilot and does not require any data to be sent to Tekunda’s servers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Delivery Autopilot Runner GitHub Action automates the delivery process from your tracker to a reviewed pull request using an AI pipeline hosted by Tekunda. It checks out the repository, runs code generation and quality checks, and opens a pull request. The action is triggered by a signed instruction issued by Delivery Autopilot and does not require any data to be sent to Tekunda&rsquo;s servers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runner-dist synced from AutoPilot. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>Lachesis Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/lachesis-security-scan/</link><pubDate>Fri, 21 Aug 2026 13:52:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/lachesis-security-scan/</guid><description>Version updated for https://github.com/UnboundCompute/lachesis-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action builds a code property graph of your repository, traces untrusted input to dangerous sinks, and reports them directly into GitHub Code Scanning as inline annotations on pull requests. It uses a compiler-precise approach to identify guard differentials, where one function guards against untrusted input while another does not.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/UnboundCompute/lachesis-action">https://github.com/UnboundCompute/lachesis-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lachesis-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action builds a code property graph of your repository, traces untrusted input to dangerous sinks, and reports them directly into GitHub Code Scanning as inline annotations on pull requests. It uses a compiler-precise approach to identify guard differentials, where one function guards against untrusted input while another does not.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update Action release example test by @riyandhiman14 in <a href="https://github.com/UnboundCompute/lachesis-action/pull/9">https://github.com/UnboundCompute/lachesis-action/pull/9</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/UnboundCompute/lachesis-action/compare/v1.0.2...v1.0.3">https://github.com/UnboundCompute/lachesis-action/compare/v1.0.2...v1.0.3</a></p>
]]></content:encoded></item><item><title>Install Zig</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/install-zig/</link><pubDate>Fri, 21 Aug 2026 13:51:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/install-zig/</guid><description>Version updated for https://github.com/xyzzylabs/setup-zig to version v1.0.3.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “setup-zig” installs the Zig compiler and verifies its integrity against an official minisign signature, caching the global Zig cache between runs. It automates tasks related to setting up and using the Zig compiler in CI/CD workflows by handling version resolution and cache management based on configuration inputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/xyzzylabs/setup-zig">https://github.com/xyzzylabs/setup-zig</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-zig">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;setup-zig&rdquo; installs the Zig compiler and verifies its integrity against an official minisign signature, caching the global Zig cache between runs. It automates tasks related to setting up and using the Zig compiler in CI/CD workflows by handling version resolution and cache management based on configuration inputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="103-2026-08-21"><a href="https://github.com/xyzzylabs/setup-zig/compare/v1.0.2...v1.0.3">1.0.3</a> (2026-08-21)</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>deps:</strong> bump @actions/cache to 6.2.0 and dev-deps; adapt to @types/node 26 (<a href="https://github.com/xyzzylabs/setup-zig/issues/14">#14</a>) (<a href="https://github.com/xyzzylabs/setup-zig/commit/ee9dc3b36d5e8d729f070fba62d6c1cf1283ce7e">ee9dc3b</a>)</li>
<li><strong>deps:</strong> bump brace-expansion to 1.1.18 (<a href="https://github.com/xyzzylabs/setup-zig/issues/8">#8</a>) (<a href="https://github.com/xyzzylabs/setup-zig/commit/4b0bd01c32aaaa5311e3f21d1aef5fc0adf99bc2">4b0bd01</a>)</li>
</ul>
]]></content:encoded></item><item><title>YAMLResume</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/yamlresume/</link><pubDate>Fri, 21 Aug 2026 13:50:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/yamlresume/</guid><description>Version updated for https://github.com/yamlresume/action to version v0.15.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, YAMLResume action, automates the process of building professional resumes from YAML files using the YAMLResume CLI. It allows users to build multiple resumes in a single workflow step and customize the build options such as skipping validation or PDF generation. The action outputs the generated file paths for use in subsequent steps, making it versatile for integrating with other GitHub Actions like actions/upload-artifact.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yamlresume/action">https://github.com/yamlresume/action</a></strong> to version <strong>v0.15.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yamlresume">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, YAMLResume action, automates the process of building professional resumes from YAML files using the YAMLResume CLI. It allows users to build multiple resumes in a single workflow step and customize the build options such as skipping validation or PDF generation. The action outputs the generated file paths for use in subsequent steps, making it versatile for integrating with other GitHub Actions like <code>actions/upload-artifact</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="features">Features</h3>
<ul>
<li>bump yamlresume from v0.14.3 to v0.15.0 (<a href="https://github.com/yamlresume/action/commit/99e07954c4f3b24859631874b76f4e28925948cf">99e0795</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yamlresume/action/compare/v0.14.3...v0.15.0">https://github.com/yamlresume/action/compare/v0.14.3...v0.15.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/b.ia-accessibility-checker/</link><pubDate>Fri, 21 Aug 2026 13:49:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks within CI/CD pipelines. It allows developers to define an audience and a percentage of WCAG guidelines they must meet, helping ensure code compliance with accessibility standards. This tool simplifies the process by using AI to analyze guidelines without requiring extensive coding knowledge. The action provides feedback if code fails to meet requirements, facilitating improvements for better user experience across various audiences.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks within CI/CD pipelines. It allows developers to define an audience and a percentage of WCAG guidelines they must meet, helping ensure code compliance with accessibility standards. This tool simplifies the process by using AI to analyze guidelines without requiring extensive coding knowledge. The action provides feedback if code fails to meet requirements, facilitating improvements for better user experience across various audiences.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>DeepSeek Harness for GitHub</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/deepseek-harness-for-github/</link><pubDate>Fri, 21 Aug 2026 06:50:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/deepseek-harness-for-github/</guid><description>Version updated for https://github.com/Lixiaoyiao/deepseek-harness-action to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The DeepSeek Harness Action for GitHub integrates the capabilities of DeepSeek into GitHub workflows. It automates tasks such as inline reviews on pull requests, diagnoses failed CI runs, and fixes issues by generating pull requests. The action requires a DeepSeek API key to function and is designed to be used in conjunction with other GitHub Actions to enhance software development workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lixiaoyiao/deepseek-harness-action">https://github.com/Lixiaoyiao/deepseek-harness-action</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deepseek-harness-for-github">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The DeepSeek Harness Action for GitHub integrates the capabilities of DeepSeek into GitHub workflows. It automates tasks such as inline reviews on pull requests, diagnoses failed CI runs, and fixes issues by generating pull requests. The action requires a DeepSeek API key to function and is designed to be used in conjunction with other GitHub Actions to enhance software development workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li>Add general <code>@dsh task</code> support for repository Q&amp;A, analysis, and coding work, plus trusted explicit-prompt automation for dispatch and scheduled workflows.</li>
<li>Add a bounded controller-owned loop for edit -&gt; allowed tool/validation -&gt; redacted error feedback -&gt; repair, with turn, tool-call, deadline, and no-progress limits.</li>
<li>Add maintainer-defined named command tools through versioned fixed-argv manifests, exact allowlists, and resource, output, network, workspace, and call-count limits.</li>
<li>Write tasks create or update validated branches and pull requests. Issue-backed tasks and sticky progress/result comments are supported, and generic tasks never push directly to the default branch.</li>
<li>Add loop and tool receipts to schema-v1 <code>result-json</code> while preserving existing scalar outputs.</li>
<li>Add internal provider/session contracts as stable extension seams for future engines, tools, extensions, and resume support.</li>
</ul>
<h2 id="security-model">Security model</h2>
<ul>
<li>Model output, repository data, logs, and tool output remain untrusted. DSH receives neither real GitHub nor DeepSeek credentials; controller-owned credential-free containers mediate tools and validation.</li>
<li>Write access remains opt-in and fail-closed: it requires <code>allow-write</code>, a trusted same-repository context and actor, SHA and identity rebinding, an immutable container image, a publishable change, and successful controller validation.</li>
<li>Command tools accept no model-supplied argv. Configured argv containing controller credentials is rejected, and generated root <code>.git</code> and <code>node_modules</code> content is excluded from validation and publication.</li>
</ul>
<h2 id="compatibility">Compatibility</h2>
<ul>
<li>Existing v0.2 input names and defaults, scalar outputs, automatic review/diagnose/fix routing, and schema-v1 <code>result-json</code> remain compatible. Task and loop fields are additive and conservatively disabled by default.</li>
<li>Configurations that embed controller credentials in argv, or depend on generated root <code>.git</code> or <code>node_modules</code> entering validation, now fail closed.</li>
<li>The action requires Node.js 24 and uses the audited <code>@deepseek-ai/dsh@0.1.0-rc.6</code> policy profile.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li>Final <code>main</code> CI passed formatting, lint, type checking, all 272 tests, deterministic bundle checks, configuration checks, and a real Linux Docker DSH runtime smoke: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32402165253">https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32402165253</a></li>
<li>A dedicated real Docker and DeepSeek E2E passed a three-turn named-tool -&gt; failing validation -&gt; repair loop, structured receipts, PR writeback, sticky comment reuse, explicit-prompt automation, and fail-closed policy/configuration paths: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32394724312">https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32394724312</a></li>
<li>Post-merge E2E passed real <code>@dsh task --read</code>, Issue <code>@dsh task --write</code> -&gt; PR, exact file/commit/marker validation, and CI on the generated PR: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32404059832">https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32404059832</a>, <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32405550314">https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32405550314</a>, <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32407180137">https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32407180137</a></li>
<li>Post-merge automatic review passed against the exact trusted v0.3.0 <code>main</code> action after one fail-closed malformed-output attempt and a successful retry: <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32403987182/attempts/2">https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/32403987182/attempts/2</a></li>
</ul>
<h2 id="not-enabled-in-v030">Not enabled in v0.3.0</h2>
<ul>
<li>Real MCP server connections.</li>
<li>Plugin discovery, installation, or execution.</li>
<li>Cross-run session persistence or resume.</li>
</ul>
<p>The shipped provider/session types are extension seams only. This release has no public MCP, plugin, or resume inputs and emits no reusable session token.</p>
<h2 id="known-limitations">Known limitations</h2>
<ul>
<li>Docker bridge networking is not destination-level egress isolation; validation also executes untrusted repository code with bridge networking.</li>
<li><code>isolation=none</code> has no OS process boundary and is suitable only for dedicated trusted runners.</li>
<li>Sticky v1 markers do not include run/head freshness; custom workflows should serialize per target.</li>
<li>DSH and its transitive npm graph are installed at runtime. Use a trusted mirror or reviewed prebuilt image when reproducibility matters.</li>
<li>Container cleanup is best effort after hard runner termination or Docker failure.</li>
<li>Malformed model output fails closed but is not automatically retried inside the same Action run. One real review attempt produced malformed structured output; an explicit rerun succeeded.</li>
</ul>
]]></content:encoded></item><item><title>Pipelock Agent Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/pipelock-agent-security-scan/</link><pubDate>Fri, 21 Aug 2026 06:49:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/pipelock-agent-security-scan/</guid><description>Version updated for https://github.com/luckyPipewrench/pipelock to version v3.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipelock is an open-source AI agent firewall that helps protect against secret exfiltration and other malicious activities by inspecting and controlling mediated HTTP, WebSocket, MCP, A2A, and CONNECT traffic. It emits action receipts to verify Mediator decisions outside the agent runtime. The public agent-egress-bench corpus tests its detections.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/luckyPipewrench/pipelock">https://github.com/luckyPipewrench/pipelock</a></strong> to version <strong>v3.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipelock-agent-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Pipelock is an open-source AI agent firewall that helps protect against secret exfiltration and other malicious activities by inspecting and controlling mediated HTTP, WebSocket, MCP, A2A, and CONNECT traffic. It emits action receipts to verify Mediator decisions outside the agent runtime. The public agent-egress-bench corpus tests its detections.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li>092a1497f55c1cb94735ef687465a2940386896a fix(killswitch): scope endpoint exemptions to pipelock&rsquo;s own requests (#1295)</li>
<li>888e66906b39516db0f401770150bf05457c8a0a fix(scanner): scan the path and query together for split credentials (#1296)</li>
</ul>
<h3 id="other-changes">Other Changes</h3>
<ul>
<li>4c748ab986d611138ce202ab800b16eca6fb589f Give the release preflight gate the keyring secret it checks (#1300)</li>
<li>2f1ec208bdc72d05223413b21b5177b80c88bfb3 chore(release): correct the 3.4.0 date and the Python verifier availability (#1298)</li>
<li>d66603ad59a90dd774eafa02b6f7785b4240245c test(mcp): stop the subreaper-direction deadline deciding the result (#1293)</li>
</ul>
<hr>
<p>📚 Docs: <a href="https://pipelab.org">https://pipelab.org</a>  •  💬 Community: <a href="https://discord.gg/badNfhGKTc">https://discord.gg/badNfhGKTc</a></p>
<p>Pipelock is an open-source agent firewall. Come poke holes in it.</p>
]]></content:encoded></item><item><title>eigenhelm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/eigenhelm/</link><pubDate>Fri, 21 Aug 2026 06:48:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/eigenhelm/</guid><description>Version updated for https://github.com/metacogdev/eigenhelm to version v0.10.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, eigenhelm, evaluates Python code based on its structural complexity and similarity to high-quality open-source corpora. It helps detect low-quality AI-generated code before it lands in production by providing score-based feedback that guides refactoring efforts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/metacogdev/eigenhelm">https://github.com/metacogdev/eigenhelm</a></strong> to version <strong>v0.10.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/eigenhelm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, eigenhelm, evaluates Python code based on its structural complexity and similarity to high-quality open-source corpora. It helps detect low-quality AI-generated code before it lands in production by providing score-based feedback that guides refactoring efforts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/metacogdev/eigenhelm/compare/v0.10.1...v0.10.2">https://github.com/metacogdev/eigenhelm/compare/v0.10.1...v0.10.2</a></p>
]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Fri, 21 Aug 2026 06:47:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.9.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of automated test suites in ServiceNow CI/CD by setting up necessary variables and secrets, configuring a workflow template, and providing inputs and environment variables to customize the test run. It helps streamline testing processes within the DevOps pipeline for ServiceNow applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of automated test suites in ServiceNow CI/CD by setting up necessary variables and secrets, configuring a workflow template, and providing inputs and environment variables to customize the test run. It helps streamline testing processes within the DevOps pipeline for ServiceNow applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.8...1.0.9">https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.8...1.0.9</a></p>
]]></content:encoded></item><item><title>mockdr — Multi-EDR Mock Server</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/mockdr-multi-edr-mock-server/</link><pubDate>Fri, 21 Aug 2026 06:46:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/mockdr-multi-edr-mock-server/</guid><description>Version updated for https://github.com/mockdr/mockdr to version v2.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The mockdr GitHub Action is a self-contained mock server that simulates multiple EDR (Endpoint Detection and Response) platforms. It provides realistic data, paths, and response envelopes to help users test their automation scripts without relying on live systems. The action supports popular security platforms like SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Elastic Security, Cortex XDR, Splunk SIEM, and Microsoft Sentinel, making it a valuable tool for developers and security professionals.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mockdr/mockdr">https://github.com/mockdr/mockdr</a></strong> to version <strong>v2.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mockdr-multi-edr-mock-server">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>mockdr</code> GitHub Action is a self-contained mock server that simulates multiple EDR (Endpoint Detection and Response) platforms. It provides realistic data, paths, and response envelopes to help users test their automation scripts without relying on live systems. The action supports popular security platforms like SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Elastic Security, Cortex XDR, Splunk SIEM, and Microsoft Sentinel, making it a valuable tool for developers and security professionals.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Three changes since 2.0.1, all additive. A client written against 2.0.1 needs
no changes — which is what makes this a patch release rather than the minor
the endpoint count might suggest.</p>
<h2 id="22-endpoints-that-had-no-route-at-all">22 endpoints that had no route at all</h2>
<p>These sit around the ones mockdr already served: a client reads the tag
vocabulary before offering it as a filter, checks privileges before showing a
create button, pulls a case&rsquo;s audit trail, lists the actions run against an
endpoint. Each returned 404, so the surrounding workflow could not be
exercised even though its central endpoint worked.</p>
<ul>
<li><strong>Splunk</strong> — <code>/services</code>, <code>/services/apps/local</code>, <code>/services/messages</code> and
<code>/services/search/parse</code>. The last is what <code>splunklib</code>&rsquo;s <code>Service.parse()</code>
uses to validate a query without dispatching it, so it now reports an
unrunnable query as an error rather than accepting it. Plus KV Store
<code>batch_find</code>, and HEC accepts its token as <code>?token=</code> for clients that cannot
set headers.</li>
<li><strong>Kibana platform</strong> — <code>/api/status</code>, <code>/api/features</code>, <code>/api/spaces/space</code>
and <code>/api/fleet/agents</code>, the last derived from the same endpoints the
metadata API serves so the two inventories agree.</li>
<li><strong>Detection engine</strong> — tags, privileges, index, <code>rules/_bulk_create</code> (which
reports per rule rather than failing the batch), <code>rules/preview</code>, <code>_export</code>
and <code>_import</code>.</li>
<li><strong>Cases</strong> — status counts, reporters, <code>_bulk_get</code> (which separates hits from
misses), and <code>{id}/user_actions</code>.</li>
<li><strong>Endpoint</strong> — <code>action_log/{id}</code>, <code>action_status</code>, <code>policy_response</code>,
<code>suggestions</code>, and the four response actions now also at
<code>/api/endpoint/{action}</code>, where Kibana serves them.</li>
</ul>
<h2 id="a-splunk-search-jobs-dispatch-states-can-be-observed">A Splunk search job&rsquo;s dispatch states can be observed</h2>
<p>The search runs synchronously, so a job reported <code>DONE</code> on the very first
poll. <code>QUEUED</code>, <code>PARSING</code>, <code>RUNNING</code> and <code>FINALIZING</code> were unreachable — the
<code>isDone</code> polling loop that <code>splunklib</code> documents and every SDK example writes
was never exercised against mockdr, only short-circuited. A loop that never
iterates is a loop that has never been tested.</p>
<p><code>MOCKDR_SPLUNK_DISPATCH_SECONDS</code> walks a job through those states over that
many seconds. It defaults to <code>0</code>, keeping the immediate completion 2.0.1 had,
so determinism is opt-out rather than lost. Results stay readable at any
state, because the search really has already run — the window governs what the
job reports, not when it can answer. And <code>exec_mode=blocking</code> ignores the
window, because real Splunk blocks until the job is done.</p>
<h2 id="ten-dependency-bumps-taken-together">Ten dependency bumps, taken together</h2>
<p>mypy 1.19 → 2.3 and Vite 7 → 8 are the two that could have hurt; neither did.
mypy 2.3 reports no issues across 781 files under <code>--strict</code>, and all nine
end-to-end flows pass on Vite 8. Also ESLint 10.8, vue-tsc 3.3, Playwright
1.62, uvicorn 0.52, ruff 0.16.4, pip-audit 2.10.1, pytest-asyncio 1.4 and
@vue/tsconfig 0.9.1.</p>
<h2 id="fixed">Fixed</h2>
<ul>
<li><code>_export</code> returned a <code>str</code>, so FastAPI serialised the NDJSON as one escaped
JSON string that <code>_import</code> could not read.</li>
<li>The endpoint metadata list took only <code>per_page</code> where Kibana sends
<code>pageSize</code>. Both spellings are accepted now.</li>
<li>The Splunk end-to-end check read <code>E2E_BASE_URL</code> — which points at the
<em>frontend</em> — to reach the backend, so overriding it sent the request to the
dev server, which answers every unknown path with the SPA&rsquo;s <code>index.html</code>.
The check reported the Splunk API broken while it was fine. The backend now
has its own <code>E2E_API_URL</code>.</li>
</ul>
<hr>
<p>2,759 backend tests, 2,183 frontend unit tests, 9 end-to-end flows.
Full changelog: <a href="https://github.com/mockdr/mockdr/blob/main/CHANGELOG.md">https://github.com/mockdr/mockdr/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Disensor Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/disensor-gate/</link><pubDate>Fri, 21 Aug 2026 06:45:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/disensor-gate/</guid><description>Version updated for https://github.com/NicolasRocchia/disensor to version v0.6.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating and validating adversarial review reports with a residue declaration. It helps ensure that each adversarial review event ends in a terminal state and provides a record of what could not be closed on its own, facilitating human judgment. The action uses a JSON artifact to store this information, which is validated against a schema before being used for CI enforcement.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NicolasRocchia/disensor">https://github.com/NicolasRocchia/disensor</a></strong> to version <strong>v0.6.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/disensor-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating and validating adversarial review reports with a residue declaration. It helps ensure that each adversarial review event ends in a terminal state and provides a record of what could not be closed on its own, facilitating human judgment. The action uses a JSON artifact to store this information, which is validated against a schema before being used for CI enforcement.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release listed on the GitHub Marketplace.</p>
<p>disensor emits, validates and CI-enforces residue declarations: JSON artifacts that record how each adversarial review event ended (one model generates, a model from another family attacks, every finding reaches a terminal state) and, above all, what the cycle could not close on its own. This release runs on the residue/v0.3 schema.</p>
<p>Highlights up to v0.6.2: the adversarial prompt ships inside the package with a reproducible hash (disensor prompt), the gate derives the PR scope from git objects instead of the working tree, the v0.3 schema hardens evidence and minimized profile rules (issues #5, #7 and #8), and releases go to PyPI via Trusted Publishing. v0.6.2 also fixes the gate help text (nine checks, with the range flags documented) and the schema self-description.</p>
<p>Usage:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">NicolasRocchia/disensor@v0.6.2</span>
</span></span></code></pre></div><p>Pin by SHA in production, as the deployment requirements in the README explain.</p>
<p>Docs and method: <a href="https://disensor.dev">https://disensor.dev</a> and DOI 10.5281/zenodo.21633495</p>
]]></content:encoded></item><item><title>Full-site SEO Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/full-site-seo-audit/</link><pubDate>Fri, 21 Aug 2026 06:43:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/full-site-seo-audit/</guid><description>Version updated for https://github.com/nurkamol/seo-audit to version v1.13.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The seo-audit GitHub Action automates the SEO audit of a website by crawling its sitemap and checking all pages for technical issues. It helps identify SEO, metadata, and structured-data problems that free-page graders overlook. The tool is zero-dependency and works in CI pipelines, providing a terminal output, Markdown report, HTML file, and JSON data.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nurkamol/seo-audit">https://github.com/nurkamol/seo-audit</a></strong> to version <strong>v1.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/full-site-seo-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>The seo-audit GitHub Action automates the SEO audit of a website by crawling its sitemap and checking all pages for technical issues. It helps identify SEO, metadata, and structured-data problems that free-page graders overlook. The tool is zero-dependency and works in CI pipelines, providing a terminal output, Markdown report, HTML file, and JSON data.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong><code>link-no-text</code> and <code>anchor-generic</code></strong> — the words attached to a link, which
<code>parse.mjs</code> has been discarding since the first commit. They are the one
description of a page that does not come from the page itself, which is why
they were the last thing on the list a <code>fetch</code> loop could honestly read.</p>
<p>A link&rsquo;s name is resolved the way a browser resolves an accessible name — the
text inside, then an image&rsquo;s <code>alt</code>, then <code>aria-label</code>, then the anchor&rsquo;s own
<code>title</code>, then an <code>&lt;svg&gt;&lt;title&gt;</code> — because each of those is a real way to label
a link and calling any of them unlabelled would be wrong. <code>aria-labelledby</code> is
believed rather than followed. A framework binding (<code>:alt</code>, <code>[ariaLabel]</code>,
<code>[attr.aria-label]</code>) counts as a label the author supplied: that is the trap
that once made <code>img-alt</code> report twenty-four of allbirds.com&rsquo;s images as
missing alt.</p>
<p><strong><code>link-no-text</code></strong> is a destination that <em>nothing</em> names. Three real sites
taught this its final shape, each by producing a false positive first:</p>
<ul>
<li>css-tricks.com&rsquo;s homepage has 33 links with no text at all. Every one is a
heading-anchor icon pointing at a <code>#fragment</code>, <code>aria-hidden</code>, decorative.
Fragment links were already excluded, so the check was right by
construction — but it is worth knowing that this is what the pattern
usually is.</li>
<li>elementor.com&rsquo;s blog index has 23 thumbnails with an emptied <code>alt</code> beside
the headline that names the same article. Reporting those would be a true
observation with a false conclusion attached, so a destination is only
unreadable when <em>no</em> link anywhere names it.</li>
<li>wordpress.org/education names Campus Connect three times at
<code>/campus-connect/</code> and once, wordlessly, at <code>/campus-connect</code>. Matching
href strings called a page with three good links unreadable; destinations
are now keyed without the trailing slash.</li>
</ul>
<p>What survives all three is genuine: elementor.com/trust links five ISO and
SOC certificate PDFs through badge images with no <code>alt</code>, so Google is handed
five documents it can index and nothing about any of them, and a screen
reader reads out the filename. Grouped by destination rather than per page,
because these live in headers and footers and the same icon on two hundred
pages is one thing to fix.</p>
<p><strong><code>anchor-generic</code></strong> is a page whose inbound links <em>all</em> say &ldquo;read more&rdquo;.
Reporting each such link would fire on every blog index ever built — a card
under a headline has to say something. The finding is the page that has
nothing else: no link anywhere on the site tells Google what it is about.
<code>info</code>, and the word list is deliberately short and unarguable. &ldquo;Get started&rdquo;
and &ldquo;Book now&rdquo; are not on it; they say something about the destination.</p>
<p>Silent across fitculturepilates.com, jekyllrb.com, css-tricks.com,
smashingmagazine.com, wordpress.org, w3.org, gnu.org and freecodecamp.org —
some 12,000 internal anchors.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>The HTML report can carry a way back.</strong> <code>html()</code> takes an optional
<code>{ backHref, backLabel }</code> and renders a link in the bar when given one. Only
the hosted front end passes it: the report replaces the page it streamed
into, and without this the only route back to the form was the browser&rsquo;s back
button onto a stale log. A report written to a file has nowhere to go back
to, and still renders without it.</li>
</ul>
]]></content:encoded></item><item><title>PySentry Security Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/pysentry-security-audit/</link><pubDate>Fri, 21 Aug 2026 06:42:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/pysentry-security-audit/</guid><description>Version updated for https://github.com/nyudenkov/pysentry to version v0.5.0.
This action is used across all versions by 55 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Fast, reliable vulnerability scanning for Python dependencies.
PySentry audits Python projects for known security vulnerabilities using Rust to perform concurrent queries against multiple databases and generates detailed reports with tree-aware findings and PEP 792 lifecycle checks. It supports various dependency formats and can be used in CI pipelines, providing options for severity filtering, fail-on-high-severity settings, and SARIF output.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nyudenkov/pysentry">https://github.com/nyudenkov/pysentry</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>55</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pysentry-security-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Fast, reliable vulnerability scanning for Python dependencies.</strong></p>
<p>PySentry audits Python projects for known security vulnerabilities using Rust to perform concurrent queries against multiple databases and generates detailed reports with tree-aware findings and PEP 792 lifecycle checks. It supports various dependency formats and can be used in CI pipelines, providing options for severity filtering, fail-on-high-severity settings, and SARIF output.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v050-policy">v0.5.0 &ldquo;Policy&rdquo;</h1>
<p>This release is built around one thesis: <strong>PySentry should never silently report less than it should.</strong> It adds a small security-policy layer — per-group thresholds, package-wide ignores, and an explicit partial-scan policy — fixes a silent OSV truncation, and ships a quality-of-life pass over the human and CI output.</p>
<h2 id="-security-policy--completeness">🛡️ Security Policy &amp; Completeness</h2>
<h3 id="per-group-fail-thresholds">Per-group fail thresholds</h3>
<p>Set <code>fail_on</code> per dependency group, overriding the global one for findings that reach that group (config-only; requires a group-aware lock file — <code>uv.lock</code>, <code>poetry.lock</code>, or <code>pylock.toml</code>):</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-toml" data-lang="toml"><span style="display:flex;"><span>[<span style="color:#a6e22e">defaults</span>]
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">fail_on</span> = <span style="color:#e6db74">&#34;medium&#34;</span>      <span style="color:#75715e"># production default</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>[<span style="color:#a6e22e">groups</span>.<span style="color:#a6e22e">dev</span>]
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">fail_on</span> = <span style="color:#e6db74">&#34;critical&#34;</span>    <span style="color:#75715e"># tolerate lower-severity advisories in dev-only deps</span>
</span></span></code></pre></div><p>Thresholds resolve <strong>strictest-wins per context</strong>: a finding&rsquo;s effective threshold is the lowest across every context that reaches it. A group-only package takes its group threshold outright (so it can be <em>looser</em> than global), while a package that also ships to production keeps the global <code>fail_on</code> as a floor a permissive group can only tighten. Closes #151.</p>
<h3 id="ignore-an-entire-package">Ignore an entire package</h3>
<p><code>[ignore].packages</code> suppresses every finding for the named packages — useful for first-party or vendored internal packages. Names are compared with full PEP 503 normalization. Suppressed findings are <strong>still reported</strong> (tagged as suppressed in every format) but never trigger the non-zero exit:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-toml" data-lang="toml"><span style="display:flex;"><span>[<span style="color:#a6e22e">ignore</span>]
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">packages</span> = [<span style="color:#e6db74">&#34;internal-first-party-lib&#34;</span>]
</span></span></code></pre></div><p>Closes #149.</p>
<h3 id="explicit-partial-scan-policy">Explicit partial-scan policy</h3>
<p>When a vulnerability source fails to fetch but at least one other succeeds, the scan is incomplete. PySentry now treats this as a first-class, <strong>fail-closed</strong> condition: by default the run prints its findings plus a partial-scan marker and exits <code>2</code>. Pass <code>--no-fail-on-partial</code> (or set <code>[sources].fail_on_partial = false</code>) to continue on the sources that succeeded. If every source fails, the run is always a hard error.</p>
<h2 id="-improvements">🔧 Improvements</h2>
<ul>
<li><strong>OSV pagination — no silent truncation.</strong> The OSV provider now follows every <code>next_page_token</code> page. Previously a package with many advisories could be silently truncated to the first page — a false negative. All pages are always collected.</li>
<li><strong>Compact output by default.</strong> Human output is now compact by default — a summary plus a one-line table row per finding. Pass <code>--detailed</code> for full descriptions, CVSS, and references (the previous intermediate &ldquo;normal&rdquo; level is removed). JSON, SARIF, and Markdown are unchanged.</li>
<li><strong>&ldquo;Why it failed&rdquo; and suppression summary lines.</strong> Human, Markdown, and JSON reports now state <em>why</em> the run exits non-zero — how many findings met the effective <code>fail_on</code> threshold and which threshold tripped — plus a separate line for how many findings policy suppressed. CI logs are now self-explanatory.</li>
<li><strong>Smarter fix recommendation.</strong> For advisories fixed on multiple release lines, the recommended upgrade is now the smallest version strictly greater than the installed one (the least-disruptive safe upgrade) instead of an arbitrary branch. Backport-only advisories are noted as such.</li>
<li><strong>Compact job summary in GitHub Actions.</strong> In Actions, PySentry writes a compact Markdown report to the run&rsquo;s job summary (scan counts, severity breakdown, policy/partial state, findings table) — now the primary results surface on pull requests, where the SARIF upload is skipped by default (fork PRs get a read-only token that can&rsquo;t upload to Code Scanning). Set <code>upload-sarif-on-pr: 'true'</code> to re-enable it for same-repo PRs.</li>
</ul>
<h2 id="-install">📦 Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span><span style="color:#75715e"># Python</span>
</span></span><span style="display:flex;"><span>pip install pysentry-rs<span style="color:#f92672">==</span>0.5.0
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Rust / Cargo</span>
</span></span><span style="display:flex;"><span>cargo install pysentry --version 0.5.0
</span></span></code></pre></div><p>Prebuilt binaries for Linux, macOS, and Windows are attached below and verified against <code>SHA256SUMS</code>.</p>
<hr>
<p><strong>Full changelog:</strong> <a href="https://github.com/nyudenkov/pysentry/compare/v0.4.9...v0.5.0">https://github.com/nyudenkov/pysentry/compare/v0.4.9...v0.5.0</a>
<strong>Docs:</strong> <a href="https://docs.pysentry.com">https://docs.pysentry.com</a></p>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/odin-scan-smart-contract-security/</link><pubDate>Fri, 21 Aug 2026 06:41:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses AI to analyze smart contract vulnerabilities in CosmWasm, Solana, and EVM projects. It integrates with GitHub Code Scanning for native security alerts and posts PR comments and inline annotations on changes. The action supports multi-platform detection and configurable severity thresholds for automatic failure of builds or comment-triggered scans.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses AI to analyze smart contract vulnerabilities in CosmWasm, Solana, and EVM projects. It integrates with GitHub Code Scanning for native security alerts and posts PR comments and inline annotations on changes. The action supports multi-platform detection and configurable severity thresholds for automatic failure of builds or comment-triggered scans.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add comment-triggered PR scans (ac72e5f)</li>
<li>docs: expand findings-visibility section with threat model and annotation rationale (0404708)</li>
<li>feat: add findings-visibility input for graduated public disclosure control (f18df59)</li>
<li>fix: show findings detail in PR comment with fallback to medium (c2e43c8)</li>
<li>fix: new comment per run, show only critical/high findings, rebuild dist (e237b62)</li>
<li>feat: use GitHub App installation token for branded PR comments (3abce4e)</li>
<li>feat: enrich PR comment with emojis, descriptions, and fix report URL (27cc2f2)</li>
<li>fix: gzip SARIF before base64 encoding for Code Scanning upload (d9eed9f)</li>
<li>fix: include sourcemap-register.js in dist (bd265af)</li>
<li>docs: add privacy policy (b78db44)</li>
</ul>
]]></content:encoded></item><item><title>Chock Governance Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/chock-governance-check/</link><pubDate>Fri, 21 Aug 2026 06:40:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/chock-governance-check/</guid><description>Version updated for https://github.com/open-coder-ai/chock to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Chock is an AI governance-as-code tool that automates and enforces rules across multiple AI coding agents used by a team or organization. It allows developers to define policies once and ensures they are consistently applied, including in environments like private codebases or public open-source projects. Chock compiles these policies into git hooks, CI gates, native pre-execution hooks, AGENTS.md, and documentation for Copilot, Codex, Gemini, Aider, and other AI coding agents. This ensures that all agents enforce the same rules, thereby creating deterministic guardrails for code quality and consistency across different AI tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/open-coder-ai/chock">https://github.com/open-coder-ai/chock</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/chock-governance-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Chock is an AI governance-as-code tool that automates and enforces rules across multiple AI coding agents used by a team or organization. It allows developers to define policies once and ensures they are consistently applied, including in environments like private codebases or public open-source projects. Chock compiles these policies into git hooks, CI gates, native pre-execution hooks, <code>AGENTS.md</code>, and documentation for Copilot, Codex, Gemini, Aider, and other AI coding agents. This ensures that all agents enforce the same rules, thereby creating deterministic guardrails for code quality and consistency across different AI tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="011--hardening-and-governance-patch">0.1.1 — Hardening and governance PATCH</h2>
<p>Compiled output is byte-identical to 0.1.0 (golden-suite enforced); everything here is
validation, supply chain, documentation, and tests.</p>
<ul>
<li><strong>Fix</strong>: policy-id validation now uses <code>fullmatch</code> — an id with a trailing newline
was accepted by Python&rsquo;s <code>$</code>-before-newline matching. Found by the new
property-based suite.</li>
<li><strong>Supply chain</strong>: every GitHub Action pinned to a commit SHA; least-privilege
<code>permissions:</code> on all workflows; pip installs hash-pinned via compiled requirements;
release artifacts now carry build provenance attestations; weekly coverage-guided
fuzzing (atheris) of the id and selection parsers.</li>
<li><strong>Governance docs</strong>: GOVERNANCE.md (decision-making, roles, access continuity) and a
public roadmap index; SECURITY.md gains advisory URL and response timelines.</li>
<li><strong>Tests</strong>: property-based suite for id validation and agent selection; unit suites
for the lifecycle umbrellas and frontier ingestion (statement coverage 78% → 81%).</li>
<li><strong>Marketplace</strong>: the GitHub Action is listed as &ldquo;Chock Governance Check&rdquo; with branding.</li>
</ul>
]]></content:encoded></item><item><title>vord Static Analysis</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/vord-static-analysis/</link><pubDate>Fri, 21 Aug 2026 06:39:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/vord-static-analysis/</guid><description>Version updated for https://github.com/pmaojo/vord to version v0.14.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, vord, is a static analysis tool written in Rust that ensures AI agents write code before it hits disk. It automates the process of checking for errors and ensuring quality in AI-generated code. The action provides a guardrail that prevents AI agents from writing defective or inefficient code, promoting better overall code quality.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pmaojo/vord">https://github.com/pmaojo/vord</a></strong> to version <strong>v0.14.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vord-static-analysis">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, vord, is a static analysis tool written in Rust that ensures AI agents write code before it hits disk. It automates the process of checking for errors and ensuring quality in AI-generated code. The action provides a guardrail that prevents AI agents from writing defective or inefficient code, promoting better overall code quality.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add agent-dev-loop skill (vord + okf-mcp session loop) by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/188">https://github.com/pmaojo/vord/pull/188</a></li>
<li>Add jsx-ternary-null rule for React linting by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/189">https://github.com/pmaojo/vord/pull/189</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.13.4...v0.14.0">https://github.com/pmaojo/vord/compare/v0.13.4...v0.14.0</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>Add agent-dev-loop skill (vord + okf-mcp session loop) by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/188">https://github.com/pmaojo/vord/pull/188</a></li>
<li>Add jsx-ternary-null rule for React linting by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/189">https://github.com/pmaojo/vord/pull/189</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.13.4...v0.14.0">https://github.com/pmaojo/vord/compare/v0.13.4...v0.14.0</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>Add agent-dev-loop skill (vord + okf-mcp session loop) by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/188">https://github.com/pmaojo/vord/pull/188</a></li>
<li>Add jsx-ternary-null rule for React linting by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/189">https://github.com/pmaojo/vord/pull/189</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.13.4...v0.14.0">https://github.com/pmaojo/vord/compare/v0.13.4...v0.14.0</a></p>
<h2 id="whats-changed-4">What&rsquo;s Changed</h2>
<ul>
<li>Add agent-dev-loop skill (vord + okf-mcp session loop) by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/188">https://github.com/pmaojo/vord/pull/188</a></li>
<li>Add jsx-ternary-null rule for React linting by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/189">https://github.com/pmaojo/vord/pull/189</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.13.4...v0.14.0">https://github.com/pmaojo/vord/compare/v0.13.4...v0.14.0</a></p>
<h2 id="whats-changed-5">What&rsquo;s Changed</h2>
<ul>
<li>Add agent-dev-loop skill (vord + okf-mcp session loop) by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/188">https://github.com/pmaojo/vord/pull/188</a></li>
<li>Add jsx-ternary-null rule for React linting by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/189">https://github.com/pmaojo/vord/pull/189</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.13.4...v0.14.0">https://github.com/pmaojo/vord/compare/v0.13.4...v0.14.0</a></p>
]]></content:encoded></item><item><title>Acquit Test Selection</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/acquit-test-selection/</link><pubDate>Fri, 21 Aug 2026 06:37:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/acquit-test-selection/</guid><description>Version updated for https://github.com/rajeev-chaurasia/acquit to version v0.1.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Acquit is a GitHub Action that automatically skips tests on pull requests it determines are not affected by the changes. It uses static analysis of import statements to build a dependency graph and identifies which tests can be skipped, providing a machine-checkable witness for each skip. If Acquit cannot determine if a test is safe, it falls back to running the full suite. The tool has been tested on real history and provides an out-of-the-box share of 5.1% across multiple repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rajeev-chaurasia/acquit">https://github.com/rajeev-chaurasia/acquit</a></strong> to version <strong>v0.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/acquit-test-selection">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Acquit is a GitHub Action that automatically skips tests on pull requests it determines are not affected by the changes. It uses static analysis of import statements to build a dependency graph and identifies which tests can be skipped, providing a machine-checkable witness for each skip. If Acquit cannot determine if a test is safe, it falls back to running the full suite. The tool has been tested on real history and provides an out-of-the-box share of 5.1% across multiple repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="013-2026-08-21"><a href="https://github.com/rajeev-chaurasia/acquit/compare/v0.1.2...v0.1.3">0.1.3</a> (2026-08-21)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>preserve selection for unreachable sys.path scripts (<a href="https://github.com/rajeev-chaurasia/acquit/issues/12">#12</a>) (<a href="https://github.com/rajeev-chaurasia/acquit/commit/4315065c9a7150a61a196f8fb55daa0cb3df9262">4315065</a>)</li>
</ul>
]]></content:encoded></item><item><title>Advisory lock service for CI/CD pipelines</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/advisory-lock-service-for-ci/cd-pipelines/</link><pubDate>Fri, 21 Aug 2026 06:36:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/advisory-lock-service-for-ci/cd-pipelines/</guid><description>Version updated for https://github.com/releasetools/mutex to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action ensures that only one CI job at a time can access a shared resource by using advisory locks in a PostgreSQL table. It helps prevent race conditions and ensures proper synchronization of workflows working on the same environment. The action also provides features like commenting on pull requests, posting to Slack, and an agent plugin for coding agents holding locks around work they guard.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/releasetools/mutex">https://github.com/releasetools/mutex</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/advisory-lock-service-for-ci-cd-pipelines">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action ensures that only one CI job at a time can access a shared resource by using advisory locks in a PostgreSQL table. It helps prevent race conditions and ensures proper synchronization of workflows working on the same environment. The action also provides features like commenting on pull requests, posting to Slack, and an agent plugin for coding agents holding locks around work they guard.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>The <code>enabled</code> profile setting is now named <code>default</code>; existing <code>profiles.toml</code> files need the rename. A profile with <code>default = false</code> is still selectable with <code>--profile</code>.</li>
<li>Added an agent plugin. Ask a coding agent to guard some work and it takes a mutex lock around it, gives the lock back when the work is done, and warns you before the lease runs out; <code>/mutex:lock</code>, <code>/mutex:unlock</code> and four more appear in the slash menu. Claude Code and Codex install it from the <code>releasetools</code> marketplace at <a href="https://github.com/releasetools/agent-plugins">releasetools/agent-plugins</a>; Hermes, Gemini and Antigravity copy the skill, which ships in the CLI package so a global npm installation has a copy to install from. See <a href="./README.md#agent-plugin">Agent plugin</a>.</li>
<li><code>mutex list</code> now takes <code>--owner</code>, and reads <code>$MUTEX_OWNER</code> when the flag is left off, so asking what one owner holds no longer means fetching every lock in the table and filtering them locally. See <a href="./README.md#ownership">Ownership</a>.</li>
<li><code>mutex server status</code> now prints the running server&rsquo;s version, and names this one alongside when the two differ. A server keeps running the code it started with; until now the only hint of an old one was a protocol number.</li>
<li>The mutex server&rsquo;s protocol version is now 2. A server left running across the upgrade refuses lock commands with an error that names the mismatch, until it is restarted with <code>mutex server stop &amp;&amp; mutex server start</code>; stopping and inspecting a server work no matter which version it speaks, so the restart that fixes this never needs <code>kill</code> or a pid file.</li>
<li><code>/mutex:status</code> now asks the lock table for this session&rsquo;s own locks instead of fetching every lock and splitting the list locally; the helper&rsquo;s <code>--all</code> still shows what everybody else is holding.</li>
<li>Connection strings that say <code>sslmode=require</code>, <code>prefer</code>, <code>verify-ca</code> or <code>allow</code> keep checking the server&rsquo;s certificate chain and hostname, and node-postgres&rsquo; SSL deprecation warning no longer prints on every command. Upgrading to pg v9 can no longer weaken them without saying so. See <a href="./README.md#what-sslmode-means-here">What <code>sslmode</code> means here</a>.</li>
<li>mutex now warns when it connects without TLS to anything but a local database, instead of sending the password and every lock in the clear silently.</li>
<li>A failed TLS handshake now names the setting that most likely caused it, instead of leaving a certificate error or a closed socket to explain itself.</li>
<li>The mutex server now keeps one database connection open instead of letting it lapse after ten seconds idle. A lock asked for minutes after the last one no longer pays for a fresh handshake, which was about 180 ms per request against a hosted database.</li>
<li>The mutex server now starts TLS directly whenever the connection is encrypted, without being asked to, and falls back for good after the first refusal. Against PostgreSQL 16 or older that costs one failed connection at startup and nothing afterwards.</li>
<li>An <code>sslnegotiation</code> in the connection string that is neither <code>postgres</code> nor <code>direct</code> now gets an error naming it, instead of being silently ignored.</li>
<li>Profiles accept <code>ssl_negotiation = &quot;direct&quot;</code>, which removes a round trip from the TLS handshake and needs PostgreSQL 17 or newer. The saved round trip measured 26.5 ms per connection against a hosted database, and there is a benchmark runner to measure your own.</li>
<li>Documented a mise installation that starts from nothing: one command installs the Node runtime mutex needs and approves the package while it is still below mise&rsquo;s download-count threshold, instead of assuming Node is already there.</li>
<li>Every release now installs the exact npm package it just published, through an isolated mise-managed Node runtime, so a broken mise installation fails the release that shipped it.</li>
<li>Pooled CLI commands now start without loading the PostgreSQL client or the mutex server lifecycle code, which cuts the fixed cost of every short-lived command: remote server status measured 81.5 ms, against 316.6 ms for direct access.</li>
<li>Lock, unlock, and renew now normally finish in one PostgreSQL round trip, with ownership, expiry, and fencing behaving exactly as before; a remote pooled lock/unlock cycle measured 166.7 ms, down from 369.7 ms.</li>
<li>Added a reusable direct-versus-server benchmark runner that writes its results outside the repository by default.</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/kaniko-build-action/</link><pubDate>Fri, 21 Aug 2026 06:34:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting message to the log, allowing for dynamic greetings based on user input. It automates the process of displaying personalized greetings in various workflows, enhancing flexibility and customization. The key capabilities include accepting an optional name parameter to create custom greetings and providing a timestamp of when the greeting was printed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting message to the log, allowing for dynamic greetings based on user input. It automates the process of displaying personalized greetings in various workflows, enhancing flexibility and customization. The key capabilities include accepting an optional name parameter to create custom greetings and providing a timestamp of when the greeting was printed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>Check value regex</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/check-value-regex/</link><pubDate>Fri, 21 Aug 2026 06:34:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/check-value-regex/</guid><description>Version updated for https://github.com/robandpdx/check-value-regex to version v2.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks if a given input value matches a specified regular expression and provides an output indicating whether the match was successful or not. It can be used to automate conditional logic in workflows based on regex validation, simplifying tasks like data sanitization or ensuring data integrity.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/robandpdx/check-value-regex">https://github.com/robandpdx/check-value-regex</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/check-value-regex">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks if a given input value matches a specified regular expression and provides an output indicating whether the match was successful or not. It can be used to automate conditional logic in workflows based on regex validation, simplifying tasks like data sanitization or ensuring data integrity.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Upgrade to Node.js 245 runtime</p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/custom-amazon-bedrock-agent-action/</link><pubDate>Fri, 21 Aug 2026 06:33:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provides feedback tailored to specific requirements. It integrates with Amazon Bedrock Knowledge Bases to enhance analysis by leveraging context-aware insights from company or domain-specific data, thus improving the quality of feedback for code reviews and other tasks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provides feedback tailored to specific requirements. It integrates with Amazon Bedrock Knowledge Bases to enhance analysis by leveraging context-aware insights from company or domain-specific data, thus improving the quality of feedback for code reviews and other tasks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/sherpa.sh/</link><pubDate>Fri, 21 Aug 2026 06:32:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an open-source AI-driven infrastructure automation tool that simplifies the deployment process. It allows developers to describe their application needs in plain English, and Sherpa automatically configures servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more. Key capabilities include deploying applications across various cloud providers with minimal setup effort, handling any framework or infrastructure, providing clear transparency through its open-source nature, and integrating seamlessly with GitHub Actions and Claude Code for automatic deployment workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an open-source AI-driven infrastructure automation tool that simplifies the deployment process. It allows developers to describe their application needs in plain English, and Sherpa automatically configures servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more. Key capabilities include deploying applications across various cloud providers with minimal setup effort, handling any framework or infrastructure, providing clear transparency through its open-source nature, and integrating seamlessly with GitHub Actions and Claude Code for automatic deployment workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>gomarklint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/gomarklint/</link><pubDate>Fri, 21 Aug 2026 06:31:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/gomarklint/</guid><description>Version updated for https://github.com/shinagawa-web/gomarklint to version v3.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: The gomarklint action is a tool that checks Markdown files for broken links and structure issues. It automates the process of validating internal anchors by default, and can also check external URLs if enabled. The tool provides high performance, output in both human-readable and machine-readable formats, and supports CI integration through GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shinagawa-web/gomarklint">https://github.com/shinagawa-web/gomarklint</a></strong> to version <strong>v3.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gomarklint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> The <code>gomarklint</code> action is a tool that checks Markdown files for broken links and structure issues. It automates the process of validating internal anchors by default, and can also check external URLs if enabled. The tool provides high performance, output in both human-readable and machine-readable formats, and supports CI integration through GitHub Actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="bug-fixes-">Bug Fixes 🐛</h3>
<ul>
<li>af516263a2618870b8146803f59dfd85130ea7e4: fix(deps): update module golang.org/x/text to v0.39.0 (#360) (@renovate[bot])</li>
<li>69c1894b82d832520b5089499dde2308a2ef27c1: fix(deps): update module golang.org/x/text to v0.40.0 (#363) (@renovate[bot])</li>
<li>73f720f5194f4621db77b47d2effead55e8d7079: fix(deps): update module golang.org/x/text to v0.41.0 (#387) (@renovate[bot])</li>
</ul>
<h3 id="code-refactoring-">Code Refactoring ♻️</h3>
<ul>
<li>ad2da68ae6df55350edad5f06b955a0714cfd27c: refactor: remove redundant comments from source files (#402) (@shinagawa-web)</li>
</ul>
<h3 id="documentation-">Documentation 📝</h3>
<ul>
<li>37cacb5df79b407f90b01ec6f26ed783c25f9f35: docs: remove retired Go Report Card badge (#386) (@shinagawa-web)</li>
</ul>
<h3 id="maintenance-">Maintenance 🔧</h3>
<ul>
<li>12a7d024540d698f61dfe3c76a380e529814d922: chore(deps): update actions/checkout action to v7.0.1 (#370) (@renovate[bot])</li>
<li>f886c1d42ccb8562ca63cfcc1b544dde4a3771f2: chore(deps): update actions/setup-go action to v7 (#368) (@renovate[bot])</li>
<li>65543730446834f1d8477ab3e093251572eed565: chore(deps): update actions/setup-node action to v6.5.0 (#365) (@renovate[bot])</li>
<li>c11660feabd9bce8bf4fd612b4e39e8ddf52ca34: chore(deps): update actions/setup-node action to v7 (#366) (@renovate[bot])</li>
<li>20fe40bfdbe60de6b335a0a09e0f0eba6a694b47: chore(deps): update docker/build-push-action action to v7.3.0 (#355) (@renovate[bot])</li>
<li>fb464bc32b8846f696aa82925b3c8b0472c3bc57: chore(deps): update docker/login-action action to v4.3.0 (#356) (@renovate[bot])</li>
<li>4f18fc0ebd4cf9a403ad9bc953089a7c5a37e670: chore(deps): update docker/login-action action to v4.4.0 (#359) (@renovate[bot])</li>
<li>1c39e534fedc90c9e1fe7d590114bf70e829837e: chore(deps): update docker/login-action action to v4.5.0 (#374) (@renovate[bot])</li>
<li>fd810d4689253c29b2f0311dfb627e77f2a742c5: chore(deps): update docker/login-action action to v4.5.1 (#377) (@renovate[bot])</li>
<li>5e17bf78af684642d303f59970c8db821713d86d: chore(deps): update docker/login-action action to v4.5.2 (#378) (@renovate[bot])</li>
<li>a26d96b977d8525bf7aa8eb897ae29bea37858c3: chore(deps): update docker/login-action action to v4.6.0 (#379) (@renovate[bot])</li>
<li>0a6e5d3db87e8f238751ef8ae2e6ea358792e09d: chore(deps): update docker/setup-buildx-action action to v4.2.0 (#358) (@renovate[bot])</li>
<li>3d4f5245341551dc6ba7f80eb253699c8202d616: chore(deps): update docker/setup-buildx-action action to v4.3.0 (#403) (@renovate[bot])</li>
<li>b91529acf80aa01d3677e55e2bfa133f1e6ec31e: chore(deps): update github/codeql-action action to v4.36.3 (#357) (@renovate[bot])</li>
<li>cf78b6bca1c3a01d5a79fc9ca3a9384ad79fee6c: chore(deps): update github/codeql-action action to v4.37.0 (#362) (@renovate[bot])</li>
<li>180c7a8274bcf75888423f9b5221e9d3f2261c96: chore(deps): update github/codeql-action action to v4.37.1 (#369) (@renovate[bot])</li>
<li>700185424003e228d368dae9caf74cb407fac9ba: chore(deps): update github/codeql-action action to v4.37.2 (#371) (@renovate[bot])</li>
<li>f4493d453f39d6e2156e7912ea8b3d05d4244dc9: chore(deps): update github/codeql-action action to v4.37.3 (#373) (@renovate[bot])</li>
<li>ee4c8ef46e207dc907e74e369c2a2035ff851a53: chore(deps): update github/codeql-action action to v4.37.4 (#380) (@renovate[bot])</li>
<li>afc83bc5a7639cfcac290580f67134e1ed558270: chore(deps): update github/codeql-action action to v4.37.5 (#382) (@renovate[bot])</li>
<li>27ab1bf23d7a281751b3142f85a001b483d9836b: chore(deps): update github/codeql-action action to v4.37.6 (#383) (@renovate[bot])</li>
<li>812164aaf52ac6d708f6e3bcb6092dbff3766cde: chore(deps): update github/codeql-action action to v4.37.7 (#388) (@renovate[bot])</li>
<li>74c81ed6221aacc284da27a2d4dda78a10888f18: chore(deps): update golang:1.26-alpine docker digest to 0178a64 (#364) (@renovate[bot])</li>
<li>8f054c9161d533bcdbc7d3dbf9a202cc00624d67: chore(deps): update golang:1.26-alpine docker digest to 28d89ee (#404) (@renovate[bot])</li>
<li>24340e060c901d754b10a90405113aebb70b5bd9: chore(deps): update golang:1.26-alpine docker digest to 3889b42 (#397) (@renovate[bot])</li>
<li>4f76e0f5742bee6b9c0db58944d1f036d3f4595c: chore(deps): update golang:1.26-alpine docker digest to 70b4654 (#389) (@renovate[bot])</li>
<li>f834a09742b10f3ba63bf9adeec73567f2b85d87: chore(deps): update golang:1.26-alpine docker digest to 9097beb (#361) (@renovate[bot])</li>
<li>c3a7112877cdb60548f54e7c1abc3fa62d1d2bae: chore(deps): update ossf/scorecard-action action to v2.4.4 (#375) (@renovate[bot])</li>
<li>d8c09cc66b9caf08e06f17a57ec0ee718d897c75: chore(deps): update reviewdog/action-actionlint action to v1.73.0 (#372) (@renovate[bot])</li>
<li>85c0ae02984e9fb9c855e8d898d9c59cfd59d923: chore(deps): update reviewdog/action-actionlint action to v1.73.1 (#384) (@renovate[bot])</li>
<li>7d0d0668e08f19c8bc9f0f62f91dcaf47acacffb: chore(deps): update reviewdog/action-actionlint action to v1.73.2 (#390) (@renovate[bot])</li>
<li>004c82e5f0322db2be71bcf5ef0d94b345e261ba: chore(deps): update shinagawa-web/gomarklint action to v3.3.0 (#354) (@renovate[bot])</li>
<li>c4d85433014c6a19c7daf12919735d96e8c1c91e: chore(deps): update zizmorcore/zizmor-action action to v0.6.0 (#367) (@renovate[bot])</li>
<li>10618689950dd71a4a82f7344888320837abc646: chore(deps): update zizmorcore/zizmor-action action to v0.6.1 (#376) (@renovate[bot])</li>
<li>4111d4705bfb059a5d02a0009662040ef3721e92: chore(deps): update zizmorcore/zizmor-action action to v0.6.2 (#381) (@renovate[bot])</li>
</ul>
<h3 id="other-changes">Other Changes</h3>
<ul>
<li>1bd55de42751f61e8aa566557fd5e8c1b9dad339: bench: add BenchmarkEndToEnd covering lint.Run end-to-end path (#396) (@shinagawa-web)</li>
<li>77d5ae6a70e257cc8d815595949f67696afe1521: bench: add CPU profile delta for time/op regressions (#401) (@shinagawa-web)</li>
<li>020c3daf4ef6c28f3de8f215cab2a49bf0e1bab3: bench: reorder benchmarks — FullLinting, FullLinting_ExtraLarge, EndToEnd (#400) (@shinagawa-web)</li>
<li>53525e1249552ff4171bac045200b440027b5afa: bench: show per-benchmark results in PR comment instead of geomean only (#398) (@shinagawa-web)</li>
<li>4503fdeb93c85d20cd661700f1cecc699be65075: ci: map bench: prefix to test label in auto-label workflow (#399) (@shinagawa-web)</li>
<li>38526ba7c7221c663059103b684fb9ab2d22a61b: ci: replace benchmark code block with markdown table (#392) (@shinagawa-web)</li>
</ul>
]]></content:encoded></item><item><title>Harnessie Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/harnessie-verify/</link><pubDate>Fri, 21 Aug 2026 06:30:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/harnessie-verify/</guid><description>Version updated for https://github.com/snapsynapse/harnessie-verify-action to version v0.1.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The harnessie-verify-action automates the verification of claims in pull requests by running deterministic checks and a fresh-context verifier model on the artifacts. It helps reviewers adjudicate by summarizing results in a table, uploading reports and proof files as workflow artifacts, and exiting with appropriate codes for verification status. The action provides input controls like criteria, checks, models, and security settings to tailor verification workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snapsynapse/harnessie-verify-action">https://github.com/snapsynapse/harnessie-verify-action</a></strong> to version <strong>v0.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harnessie-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The harnessie-verify-action automates the verification of claims in pull requests by running deterministic checks and a fresh-context verifier model on the artifacts. It helps reviewers adjudicate by summarizing results in a table, uploading reports and proof files as workflow artifacts, and exiting with appropriate codes for verification status. The action provides input controls like criteria, checks, models, and security settings to tailor verification workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="harnessie-verify-013">Harnessie Verify 0.1.3</h1>
<p>Pins the tested default to Harnessie 1.1.0.</p>
<p>The <code>harnessie verify</code> CLI contract is unchanged between 1.0.0 and 1.1.0, so the Action&rsquo;s public inputs, outputs, and fail-closed verdict contract remain VERIFIED / FAILED / CANNOT_VERIFY with exit codes 0 / 1 / 2.</p>
<p>The exact release commit passed all four CI jobs after the public PyPI index exposed Harnessie 1.1.0. The stable <code>v0</code> tag now resolves to this release.</p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/ssg-static-site-generator/</link><pubDate>Fri, 21 Aug 2026 06:29:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.46.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into clean URLs, templates, feeds, search, image processing, and native deployment. It automates the process of building websites from content files, supporting various template engines and features such as Sitemap, robots.txt, Atom feeds, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.46</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into clean URLs, templates, feeds, search, image processing, and native deployment. It automates the process of building websites from content files, supporting various template engines and features such as Sitemap, robots.txt, Atom feeds, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.46 — Go 1.27, site-level AVIF, and one directory per build instead of one per page by @spagu in <a href="https://github.com/spagu/ssg/pull/179">https://github.com/spagu/ssg/pull/179</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.45...v1.8.46">https://github.com/spagu/ssg/compare/v1.8.45...v1.8.46</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/classroom-to-sheets-integration/</link><pubDate>Fri, 21 Aug 2026 06:27:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending assignment results from a classroom repository to a Google Sheets document. It uses the Google Sheets API to update specified columns with task results and handles creating new rows as needed. This is particularly useful for teachers or instructors who want real-time feedback on student performance without manual intervention.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending assignment results from a classroom repository to a Google Sheets document. It uses the Google Sheets API to update specified columns with task results and handles creating new rows as needed. This is particularly useful for teachers or instructors who want real-time feedback on student performance without manual intervention.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>NuGet dependency graph</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/nuget-dependency-graph/</link><pubDate>Fri, 21 Aug 2026 06:27:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/nuget-dependency-graph/</guid><description>Version updated for https://github.com/Tsabo/nugraph-action to version v4.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates a NuGet dependency graph from a .NET solution or project using the nugraph tool. It supports generating both SVG and Mermaid diagrams, and can customize graph styles. The action also automates local builds by default and appends graphs to job summaries.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tsabo/nugraph-action">https://github.com/Tsabo/nugraph-action</a></strong> to version <strong>v4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nuget-dependency-graph">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates a NuGet dependency graph from a .NET solution or project using the nugraph tool. It supports generating both SVG and Mermaid diagrams, and can customize graph styles. The action also automates local builds by default and appends graphs to job summaries.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>When <code>project-path</code> is a solution, different projects sometimes need different nugraph flags — most commonly a Blazor WebAssembly project needing <code>-r</code>/<code>--runtime browser-wasm</code>, since nugraph can&rsquo;t currently resolve its ambiguous ridless/<code>browser-wasm</code> targets on its own.</p>
<h2 id="changes">Changes</h2>
<ul>
<li><code>extra-args</code> is now solution-aware: when <code>project-path</code> is a solution, it&rsquo;s parsed as newline-separated entries instead of a single flat string
<ul>
<li>A line starting with <code>-</code> (e.g. <code>--framework net8.0</code>) is a global flag applied to every project — existing single-line, solution-wide <code>extra-args</code> values keep working unchanged</li>
<li>A <code>ProjectName=args</code> line (<code>ProjectName</code> is the project file name without its extension, <code>*</code> wildcards supported) applies only to that project, appended after the global flags</li>
</ul>
</li>
<li>No behavior change when <code>project-path</code> is a single project — <code>extra-args</code> is still a plain space-separated flag string, exactly as before</li>
</ul>
<p><strong>Note:</strong> this works around a nugraph/Chisel limitation affecting every Blazor WebAssembly project — its <code>project.assets.json</code> always contains both a ridless target and an implicit <code>browser-wasm</code> target, which nugraph currently can&rsquo;t disambiguate without <code>-r</code>/<code>--runtime</code> passed explicitly for that project.</p>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Tsabo/nugraph-action@v4</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">project-path</span>: <span style="color:#ae81ff">./src/MyApp.sln</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">output-path</span>: <span style="color:#ae81ff">artifacts/nugraph/graph.svg</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">extra-args</span>: |<span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      MyApp.Client=--runtime browser-wasm</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/rustscript-action/</link><pubDate>Fri, 21 Aug 2026 06:26:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.6.11.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, RustScript, allows developers to write helper scripts in the Rust programming language and run them as shell scripts. It interprets a practical subset of Rust, enabling immediate execution. The action supports various Rust features such as functions, closures, structs, enums, patterns, loops, iterators, and standard library functionalities like files, paths, stdin/stdout, processes, and HTTP requests. It also supports bridging crates for additional functionality like anyhow, serde, and others.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.6.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, RustScript, allows developers to write helper scripts in the Rust programming language and run them as shell scripts. It interprets a practical subset of Rust, enabling immediate execution. The action supports various Rust features such as functions, closures, structs, enums, patterns, loops, iterators, and standard library functionalities like files, paths, stdin/stdout, processes, and HTTP requests. It also supports bridging crates for additional functionality like <code>anyhow</code>, <code>serde</code>, and others.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.6.10...v0.6.11">https://github.com/VladasZ/rustscript/compare/v0.6.10...v0.6.11</a></p>
]]></content:encoded></item><item><title>PokeRepo Dex</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/pokerepo-dex/</link><pubDate>Fri, 21 Aug 2026 06:24:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/pokerepo-dex/</guid><description>Version updated for https://github.com/wantaekchoi/pokerepo to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of Pokémon-themed cards for each repository in your organization, updating them based on commit activity and merged pull requests. It helps keep track of which repositories have advanced Pokémon levels by displaying their level status next to the repository name. This tool is useful for open-source community projects with a Pokémon theme, allowing members to easily see how far their repositories have come.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wantaekchoi/pokerepo">https://github.com/wantaekchoi/pokerepo</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pokerepo-dex">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of Pokémon-themed cards for each repository in your organization, updating them based on commit activity and merged pull requests. It helps keep track of which repositories have advanced Pokémon levels by displaying their level status next to the repository name. This tool is useful for open-source community projects with a Pokémon theme, allowing members to easily see how far their repositories have come.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The card&rsquo;s Dex link now carries the owner&rsquo;s name. The page footer&rsquo;s source link sits on its own row.</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/b.ia-accessibility-checker/</link><pubDate>Fri, 21 Aug 2026 06:24:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/21/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines, focusing on specific audiences to meet WCAG guidelines. It provides flexibility by allowing companies to define the audience and the percentage of guidelines needed to be met, optimizing resources by targeting larger audiences without compromising performance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines, focusing on specific audiences to meet WCAG guidelines. It provides flexibility by allowing companies to define the audience and the percentage of guidelines needed to be met, optimizing resources by targeting larger audiences without compromising performance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>OrbitCI - Autonomous AI PR Assistant</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/orbitci-autonomous-ai-pr-assistant/</link><pubDate>Thu, 20 Aug 2026 22:49:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/orbitci-autonomous-ai-pr-assistant/</guid><description>Version updated for https://github.com/nivinvysakh/OrbitCi to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary OrbitCI is an AI-powered pull request assistant that automates code reviews, refactoring, and debugging in GitHub. It integrates with Google Gemini’s AI capabilities to provide instant feedback and suggestions on PRs, ensuring efficient development workflows. The action enhances collaboration by allowing developers to focus on the core of their work while benefiting from AI-driven improvements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nivinvysakh/OrbitCi">https://github.com/nivinvysakh/OrbitCi</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/orbitci-autonomous-ai-pr-assistant">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>OrbitCI</strong> is an AI-powered pull request assistant that automates code reviews, refactoring, and debugging in GitHub. It integrates with Google Gemini&rsquo;s AI capabilities to provide instant feedback and suggestions on PRs, ensuring efficient development workflows. The action enhances collaboration by allowing developers to focus on the core of their work while benefiting from AI-driven improvements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-orbitci-v200---native-nodejs-20-runtime--next-gen-ai-suite">🪐 OrbitCI v2.0.0 - Native Node.js 20 Runtime &amp; Next-Gen AI Suite</h1>
<p><strong>OrbitCI v2.0.0</strong> is a major milestone! We have completely rewritten the core action from Python/Docker to a native <strong>Node.js 20 GitHub Action</strong>, rebranded to <strong>OrbitCI</strong>, and introduced a full suite of autonomous AI developer tools.</p>
<hr>
<h3 id="-whats-new-in-v200">✨ What&rsquo;s New in v2.0.0:</h3>
<ul>
<li>
<p><strong>⚡ Native Node.js 20 Runtime (<code>using: &quot;node20&quot;</code>)</strong>:</p>
<ul>
<li>Executed directly on GitHub runner VMs with <strong>sub-100ms startup times</strong> (down from ~4s Docker spin-up).</li>
<li>Bundled into a standalone, zero-dependency distribution with <code>@vercel/ncc</code>.</li>
</ul>
</li>
<li>
<p><strong>🪐 OrbitCI Rebrand &amp; Multi-Handle Support</strong>:</p>
<ul>
<li>Trigger runs using <code>@orbit</code> or <code>@orbitci</code> (e.g. <code>@orbit refactor</code>, <code>@orbit fix-ci</code>).</li>
<li>Full backward compatibility with <code>@antigravity</code> / <code>@antigravityci</code>.</li>
</ul>
</li>
<li>
<p><strong>🩹 Self-Healing CI (<code>@orbit fix-ci</code>)</strong>:</p>
<ul>
<li>Automatically reads failed test and build logs from GitHub Actions and generates a patch PR that fixes the broken tests.</li>
</ul>
</li>
<li>
<p><strong>📝 PR Enhancer (<code>@orbit polish-pr</code>)</strong>:</p>
<ul>
<li>Rewrites existing PR titles to Conventional Commits and formats a structured markdown description with test checklists and metrics.</li>
</ul>
</li>
<li>
<p><strong>💬 Inline PR Reviews (<code>@orbit review</code>)</strong>:</p>
<ul>
<li>Posts line-by-line review comments with native <strong>one-click GitHub suggestion diff blocks</strong>.</li>
</ul>
</li>
<li>
<p><strong>🎨 Automated Mermaid Diagrams (<code>@orbit explain</code>)</strong>:</p>
<ul>
<li>Automatically generates and embeds visual <strong>Mermaid sequence &amp; architecture flowcharts</strong> in PR bodies and walkthrough comments.</li>
</ul>
</li>
<li>
<p><strong>📊 AI Quality &amp; Risk Scorecards</strong>:</p>
<ul>
<li>Every generated PR includes an automated evaluation of risk level (<code>Low</code> / <code>Medium</code> / <code>High</code>), breaking changes, and file counts.</li>
</ul>
</li>
<li>
<p><strong>⚙️ Custom Team Rules (<code>.orbitci.json</code>)</strong>:</p>
<ul>
<li>Enforce repository-specific coding standards, style guides, and conventions via an optional <code>.orbitci.json</code> config file.</li>
</ul>
</li>
<li>
<p><strong>🎛️ Inline Command Flags</strong>:</p>
<ul>
<li>Override models or request deeper reasoning directly in comments (e.g. <code>@orbit perf --model=gemini-3.7-flash --deep</code>).</li>
</ul>
</li>
<li>
<p><strong>📦 Ultra-Compact 20-Line Workflow</strong>:</p>
<ul>
<li>Streamlined the workflow template to just 20 lines without separate inline JavaScript scripts.</li>
</ul>
</li>
</ul>
<hr>
]]></content:encoded></item><item><title>Build CheckMK MKP Package</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/build-checkmk-mkp-package/</link><pubDate>Thu, 20 Aug 2026 22:47:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/build-checkmk-mkp-package/</guid><description>Version updated for https://github.com/oposs/mkp-builder to version v2.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of Checkmk MKP (Monitoring Konfiguration Package) files from local directory structures. It supports various build options and provides Python syntax checking for ease of use, while ensuring no permanent changes to the repository are made. The action outputs package information ready for artifact upload and is compatible with both major and minor version pinning strategies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oposs/mkp-builder">https://github.com/oposs/mkp-builder</a></strong> to version <strong>v2.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-checkmk-mkp-package">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of Checkmk MKP (Monitoring Konfiguration Package) files from local directory structures. It supports various build options and provides Python syntax checking for ease of use, while ensuring no permanent changes to the repository are made. The action outputs package information ready for artifact upload and is compatible with both major and minor version pinning strategies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>The Checkmk plugin development skill has moved to its own repository,
<code>oposs/cmk-oposs-plugin</code>. This repository is now only the packaging action. Holding both
behind one version number misfired in both directions: v2.2.2 changed five action files
and no skill files while telling every skill user their skill had updated, and v2.3.0
changed only skill files while cutting an action release whose code was byte-identical.</li>
<li>The release version is read from <code>CHANGES.md</code> instead of <code>.claude-plugin/plugin.json</code>,
which went with the skill. A GitHub Action is not a Claude plugin and has no reason to
carry a plugin manifest.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>The skill has moved out; this is now only the action by @oetiker in <a href="https://github.com/oposs/mkp-builder/pull/14">https://github.com/oposs/mkp-builder/pull/14</a></li>
<li>Release v2.3.1 by @github-actions[bot] in <a href="https://github.com/oposs/mkp-builder/pull/15">https://github.com/oposs/mkp-builder/pull/15</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/oposs/mkp-builder/compare/v2.3.0...v2.3.1">https://github.com/oposs/mkp-builder/compare/v2.3.0...v2.3.1</a></p>
]]></content:encoded></item><item><title>Otzaria Plugin Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/otzaria-plugin-validator/</link><pubDate>Thu, 20 Aug 2026 22:46:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/otzaria-plugin-validator/</guid><description>Version updated for https://github.com/Otzaria/otzaria-plugin-validator to version v1.14.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation and publishing process of Otzaria plugins. It performs automated checks, builds the plugin, and publishes it to the Otzaria store. The action requires two secrets: OTZARIA_USER and OTZARIA_PASSWORD, which are used for authentication when publishing. The action supports both main branch pushes (for automatic releases) and pull requests (for validation).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Otzaria/otzaria-plugin-validator">https://github.com/Otzaria/otzaria-plugin-validator</a></strong> to version <strong>v1.14.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/otzaria-plugin-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation and publishing process of Otzaria plugins. It performs automated checks, builds the plugin, and publishes it to the Otzaria store. The action requires two secrets: <code>OTZARIA_USER</code> and <code>OTZARIA_PASSWORD</code>, which are used for authentication when publishing. The action supports both main branch pushes (for automatic releases) and pull requests (for validation).</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Otzaria/otzaria-plugin-validator/compare/v1.13.3...v1.14.1">https://github.com/Otzaria/otzaria-plugin-validator/compare/v1.13.3...v1.14.1</a></p>
]]></content:encoded></item><item><title>OpenTelemetry for GitHub Workflows, Jobs and Steps</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/opentelemetry-for-github-workflows-jobs-and-steps/</link><pubDate>Thu, 20 Aug 2026 22:45:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/opentelemetry-for-github-workflows-jobs-and-steps/</guid><description>Version updated for https://github.com/plengauer/Thoth to version v5.61.1.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the tracing, metrics, and logging of shell scripts and GitHub workflows using OpenTelemetry. It automatically propagates context via HTTP, instruments all available commands, injects into child scripts and executables, and logs from stderr and GitHub action log commands. The project is installable via Debian or RPM packages and offers workflow-level and job-level instrumentation for GitHub actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plengauer/Thoth">https://github.com/plengauer/Thoth</a></strong> to version <strong>v5.61.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>14</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/opentelemetry-for-github-workflows-jobs-and-steps">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the tracing, metrics, and logging of shell scripts and GitHub workflows using OpenTelemetry. It automatically propagates context via HTTP, instruments all available commands, injects into child scripts and executables, and logs from stderr and GitHub action log commands. The project is installable via Debian or RPM packages and offers workflow-level and job-level instrumentation for GitHub actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: do not run the script&rsquo;s EXIT trap on exec paths (#4043) by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/4072">https://github.com/plengauer/Thoth/pull/4072</a></li>
<li>Automatic Version Bump by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/4074">https://github.com/plengauer/Thoth/pull/4074</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/plengauer/Thoth/compare/v5.61.0...v5.61.1">https://github.com/plengauer/Thoth/compare/v5.61.0...v5.61.1</a></p>
]]></content:encoded></item><item><title>Action Execute Whitelist</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/action-execute-whitelist/</link><pubDate>Thu, 20 Aug 2026 22:43:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/action-execute-whitelist/</guid><description>Version updated for https://github.com/Pycord-Development/execute-whitelist-action to version v2.2.0.
This action is used across all versions by 12 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action whitelists specific executions, preventing unauthorized access or modifications to your repository. It automates the process of ensuring only authorized contributors can make changes, thereby enhancing security and control over the codebase.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Pycord-Development/execute-whitelist-action">https://github.com/Pycord-Development/execute-whitelist-action</a></strong> to version <strong>v2.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>12</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-execute-whitelist">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action whitelists specific executions, preventing unauthorized access or modifications to your repository. It automates the process of ensuring only authorized contributors can make changes, thereby enhancing security and control over the codebase.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): upgrade dependency @types/node to v24.10.13 by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/38">https://github.com/Pycord-Development/execute-whitelist-action/pull/38</a></li>
<li>fix(deps): upgrade dependency @actions/attest to v3 by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/39">https://github.com/Pycord-Development/execute-whitelist-action/pull/39</a></li>
<li>chore(deps): bump fast-xml-parser from 5.3.5 to 5.3.6 in the npm_and_yarn group across 1 directory by @dependabot[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/40">https://github.com/Pycord-Development/execute-whitelist-action/pull/40</a></li>
<li>fix(deps): upgrade npm packages by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/41">https://github.com/Pycord-Development/execute-whitelist-action/pull/41</a></li>
<li>chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates by @dependabot[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/43">https://github.com/Pycord-Development/execute-whitelist-action/pull/43</a></li>
<li>chore(deps): bump tar from 7.5.9 to 7.5.10 in the npm_and_yarn group across 1 directory by @dependabot[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/45">https://github.com/Pycord-Development/execute-whitelist-action/pull/45</a></li>
<li>chore(deps): upgrade dependency @types/node to v24.12.0 by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/44">https://github.com/Pycord-Development/execute-whitelist-action/pull/44</a></li>
<li>fix(deps): upgrade npm packages to v0.3.47 by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/46">https://github.com/Pycord-Development/execute-whitelist-action/pull/46</a></li>
<li>fix(deps): upgrade dependency @actions/artifact to v6.2.1 by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/48">https://github.com/Pycord-Development/execute-whitelist-action/pull/48</a></li>
<li>chore(deps): bump tar from 7.5.10 to 7.5.11 in the npm_and_yarn group across 1 directory by @dependabot[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/47">https://github.com/Pycord-Development/execute-whitelist-action/pull/47</a></li>
<li>fix(deps): upgrade npm packages by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/50">https://github.com/Pycord-Development/execute-whitelist-action/pull/50</a></li>
<li>fix(deps): upgrade npm packages by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/52">https://github.com/Pycord-Development/execute-whitelist-action/pull/52</a></li>
<li>fix(deps): upgrade npm packages to v0.3.55 by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/53">https://github.com/Pycord-Development/execute-whitelist-action/pull/53</a></li>
<li>chore(deps): upgrade dependency typescript to v6 by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/51">https://github.com/Pycord-Development/execute-whitelist-action/pull/51</a></li>
<li>chore(deps): upgrade dependency @types/node to v24.12.3 by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/54">https://github.com/Pycord-Development/execute-whitelist-action/pull/54</a></li>
<li>fix(deps): upgrade npm packages by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/55">https://github.com/Pycord-Development/execute-whitelist-action/pull/55</a></li>
<li>fix(deps): upgrade dependency @actions/cache to v6.0.1 by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/56">https://github.com/Pycord-Development/execute-whitelist-action/pull/56</a></li>
<li>fix(deps): upgrade npm packages to v7 by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/58">https://github.com/Pycord-Development/execute-whitelist-action/pull/58</a></li>
<li>fix(deps): upgrade npm packages by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/57">https://github.com/Pycord-Development/execute-whitelist-action/pull/57</a></li>
<li>chore(deps): bump fast-xml-parser from 5.4.1 to 5.5.6 in the npm_and_yarn group across 1 directory by @dependabot[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/49">https://github.com/Pycord-Development/execute-whitelist-action/pull/49</a></li>
<li>fix(deps): upgrade npm packages to v0.3.61 by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/60">https://github.com/Pycord-Development/execute-whitelist-action/pull/60</a></li>
<li>chore(deps): bump the npm_and_yarn group across 1 directory with 8 updates by @dependabot[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/61">https://github.com/Pycord-Development/execute-whitelist-action/pull/61</a></li>
<li>chore(deps): upgrade dependency @octokit/types to v17 by @renovate[bot] in <a href="https://github.com/Pycord-Development/execute-whitelist-action/pull/59">https://github.com/Pycord-Development/execute-whitelist-action/pull/59</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Pycord-Development/execute-whitelist-action/compare/v2.1.1...v2.2.0">https://github.com/Pycord-Development/execute-whitelist-action/compare/v2.1.1...v2.2.0</a></p>
]]></content:encoded></item><item><title>Validate Syscribe Model</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/validate-syscribe-model/</link><pubDate>Thu, 20 Aug 2026 22:43:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/validate-syscribe-model/</guid><description>Version updated for https://github.com/sjames/syscribe to version vscode-v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Syscribe is a documentation tool that maps SysMLv2 models into human-readable Markdown files with YAML frontmatter. It provides version-controlled and traceable models across the life of a program, making them easier to read and manage by humans, and enabling LLMs to generate or reason about them reliably. The tool supports 40+ element types, including native Requirements, TestCases, ADRs, Safety analysis tools, Security analysis tools, Variability analysis, and multi-repository composition features.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sjames/syscribe">https://github.com/sjames/syscribe</a></strong> to version <strong>vscode-v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/validate-syscribe-model">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Syscribe is a documentation tool that maps SysMLv2 models into human-readable Markdown files with YAML frontmatter. It provides version-controlled and traceable models across the life of a program, making them easier to read and manage by humans, and enabling LLMs to generate or reason about them reliably. The tool supports 40+ element types, including native Requirements, TestCases, ADRs, Safety analysis tools, Security analysis tools, Variability analysis, and multi-repository composition features.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First Marketplace-ready release of the Syscribe VS Code extension (<code>editors/vscode/</code>) — a thin, pure-LSP client over <code>syscribe lsp</code> (<code>ADR-SYS-LSP-001</code>). Not yet published to the Marketplace itself (pending publisher/PAT setup); this release ships the installable <code>.vsix</code> directly.</p>
<h3 id="added">Added</h3>
<ul>
<li>Auto-resolve the <code>syscribe</code> server binary: explicit <code>syscribe.serverPath</code> -&gt; <code>syscribe</code> on <code>PATH</code> -&gt; a managed copy downloaded from this repo&rsquo;s GitHub releases, cached per-version in the extension&rsquo;s global storage. New <code>syscribe.version</code> setting pins a release (<code>&quot;latest&quot;</code> by default).</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Activation no longer hangs or crashes with a raw stack trace if the server binary can&rsquo;t be resolved or the LSP process doesn&rsquo;t start cleanly — both paths now report a clean error notification (Open Settings / Show Output) instead.</li>
<li>Activation is bounded end-to-end: a 15s timeout wraps the LSP handshake, startup-failure notifications are fired without blocking on dismissal, and the release-download path has a network request timeout — activation can no longer hang indefinitely on any of these.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><code>syscribe.serverPath</code> now defaults to empty (auto-resolve) instead of assuming <code>syscribe</code> is already on <code>PATH</code>.</li>
<li>Bundled with esbuild (<code>dist/extension.js</code>) instead of shipping raw <code>tsc</code> output plus <code>node_modules</code> — cuts the packaged <code>.vsix</code> from 334 files/~493 KB down to 8 files/~94 KB.</li>
</ul>
<h3 id="marketplace-packaging">Marketplace packaging</h3>
<p>Icon, Apache-2.0 LICENSE, repository/bugs/homepage metadata, keywords/categories, CHANGELOG, <code>.vscodeignore</code>.</p>
<p>Full changelog: <a href="https://github.com/sjames/syscribe/blob/main/editors/vscode/CHANGELOG.md">https://github.com/sjames/syscribe/blob/main/editors/vscode/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Skill Provenance Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/skill-provenance-validate/</link><pubDate>Thu, 20 Aug 2026 22:42:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/skill-provenance-validate/</guid><description>Version updated for https://github.com/snapsynapse/skill-provenance to version guidecheck-1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Skill Provenance is a portable provenance, integrity, and drift control tool for Agent Skills. It ensures that the version, integrity, and staleness of agent bundles are tracked throughout their lifecycle across various platforms and surfaces, providing teams with essential verification capabilities to trust and manage Agent Skills effectively.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snapsynapse/skill-provenance">https://github.com/snapsynapse/skill-provenance</a></strong> to version <strong>guidecheck-1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skill-provenance-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Skill Provenance is a portable provenance, integrity, and drift control tool for Agent Skills. It ensures that the version, integrity, and staleness of agent bundles are tracked throughout their lifecycle across various platforms and surfaces, providing teams with essential verification capabilities to trust and manage Agent Skills effectively.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Immutable release of the Skill Provenance assistant guide 1.2.0. Applies to Skill Provenance 6.1.x, corrects the cloned-repository validation working directory, and preserves the bounded pre-install integrity workflow. Guide SHA-256: 590138a4aebc64a9e14a64ab7d01a8eafe167bda0bdf8fb14742de5e45b227e1.</p>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/update-a-config-file-with-values-from-environment/</link><pubDate>Thu, 20 Aug 2026 22:41:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces environment variables in a specified configuration file using environment variable names as placeholders. It helps automate the process of injecting configurations directly into files during CI/CD pipelines, ensuring that sensitive information is not hardcoded and can be easily managed through version control.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces environment variables in a specified configuration file using environment variable names as placeholders. It helps automate the process of injecting configurations directly into files during CI/CD pipelines, ensuring that sensitive information is not hardcoded and can be easily managed through version control.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add support for .env files (e706be3)</li>
<li>chore: More info (d440258)</li>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/classroom-to-sheets-integration/</link><pubDate>Thu, 20 Aug 2026 22:41:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates with Google Sheets to automatically send assignment results from GitHub Classroom. It uses service account credentials to authenticate and update a specified spreadsheet with task scores from grading steps. The process involves creating the necessary Google sheet structure, configuring secrets in your organization, and adding an action step to submit results to Google Sheets.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates with Google Sheets to automatically send assignment results from GitHub Classroom. It uses service account credentials to authenticate and update a specified spreadsheet with task scores from grading steps. The process involves creating the necessary Google sheet structure, configuring secrets in your organization, and adding an action step to submit results to Google Sheets.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>Repository Create</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/repository-create/</link><pubDate>Thu, 20 Aug 2026 22:40:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/repository-create/</guid><description>Version updated for https://github.com/stairwaytowonderland/repository-create to version v1.86.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Octokit.js to dynamically create a GitHub organization repository and apply general settings and branch rulesets. It supports blank creation or generation from a template repository, with options for customizing the visibility of the repository and writing job summaries. The action requires Node.js 24 or later and a GitHub Personal Access Token with specific scopes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/repository-create">https://github.com/stairwaytowonderland/repository-create</a></strong> to version <strong>v1.86.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repository-create">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Octokit.js to dynamically create a GitHub organization repository and apply general settings and branch rulesets. It supports blank creation or generation from a template repository, with options for customizing the visibility of the repository and writing job summaries. The action requires Node.js 24 or later and a GitHub Personal Access Token with specific scopes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.86.0</p>
<h2 id="1860-2026-08-20"><a href="https://github.com/stairwaytowonderland/repository-create/compare/v1.85.0...v1.86.0">1.86.0</a> (2026-08-20)</h2>
<h3 id="-features">✨ Features</h3>
<ul>
<li>make dispatch-workflow input not required (<a href="https://github.com/stairwaytowonderland/repository-create/commit/27b3ed0da984cbb1e38a4c7a93be1265f2a19ab6">27b3ed0</a>)</li>
</ul>
]]></content:encoded></item><item><title>SteerSpec Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/steerspec-sync/</link><pubDate>Thu, 20 Aug 2026 22:39:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/steerspec-sync/</guid><description>Version updated for https://github.com/SteerSpec/strspc-sync to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SteerSpec Sync automates the synchronization of AI configuration files across a GitHub organization by defining templates in one central repository. The action generates unique hashes for rendered configurations, compares them with the deployment state, and creates pull requests for any changes. It supports dry runs, filtering options, and outputs PR creation statistics.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SteerSpec/strspc-sync">https://github.com/SteerSpec/strspc-sync</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/steerspec-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SteerSpec Sync automates the synchronization of AI configuration files across a GitHub organization by defining templates in one central repository. The action generates unique hashes for rendered configurations, compares them with the deployment state, and creates pull requests for any changes. It supports dry runs, filtering options, and outputs PR creation statistics.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release since March. 35 commits, taking the prototype toward a production-ready GitHub App.</p>
<h2 id="-license-changed-mit--apache-20">⚠️ License changed: MIT → Apache 2.0</h2>
<p><code>strspc-sync</code> is now <strong>Apache 2.0</strong>, matching every other public SteerSpec repository. The previous
MIT license was an oversight. If you track dependency licenses, this is the change to note — Apache
2.0 adds an explicit patent grant and a trademark clause. A <code>NOTICE</code> file is included in the source
tree and in every release archive.</p>
<h2 id="-action-users-update-your-ref">⚠️ Action users: update your ref</h2>
<p>Earlier docs told you to use <code>@v1</code>. <strong>That ref never existed</strong> — there has never been a <code>v1</code> tag or
branch, so any workflow copied from the quickstart failed to resolve. Pin to the release tag instead:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">SteerSpec/strspc-sync/sync@v0.2.0</span>
</span></span></code></pre></div><p>While this project is pre-1.0, pin explicitly and upgrade deliberately; there is no floating major
tag, because a <code>v1</code> would advertise API stability this codebase is not yet offering.</p>
<h2 id="github-app">GitHub App</h2>
<ul>
<li>Installation permissions are validated after token exchange, failing fast with a clear message
instead of surfacing a confusing 403 later (#18). Requires <code>contents:write</code>, <code>pull_requests:write</code>,
<code>issues:write</code>, <code>metadata:read</code>.</li>
</ul>
<h2 id="reliability">Reliability</h2>
<ul>
<li><strong><code>central-repo</code> config field</strong> replaces deriving the central repo from the first include glob,
which broke on wildcards. Resolution order: config → <code>GITHUB_REPOSITORY</code> → error (#14).</li>
<li><strong>Proactive rate limiting</strong> — reads <code>X-RateLimit-Remaining</code>/<code>Reset</code> and sleeps before hitting the
limit, honouring <code>Retry-After</code> for secondary limits, rather than only reacting to 429s (#15).</li>
<li><strong><code>--timeout</code></strong> for operation-level deadlines, default 10m (#16).</li>
<li><strong>Fingerprint-based issue idempotency</strong> — drift and conflict issues carry a BLAKE3 fingerprint, so
renaming an issue no longer causes a duplicate to be filed (#17).</li>
</ul>
<h2 id="observability">Observability</h2>
<ul>
<li><strong>Structured logging</strong> via <code>log/slog</code>, with <code>--log-level</code> (<code>debug|info|warn|error</code>) and
<code>--log-format</code> (<code>auto|json|text</code>). JSON under GitHub Actions, human-readable locally; logs go to
stderr so they never mix with the JSON result on stdout (#21).</li>
</ul>
<h2 id="templates">Templates</h2>
<ul>
<li>The <strong>marker strategy preserves CRLF</strong> line endings, so Windows-centric repos no longer get
whole-file line-ending churn (#19).</li>
</ul>
<h2 id="fixes">Fixes</h2>
<ul>
<li><strong>The quickstart config parses again</strong> (#30). The shipped example — the first thing the README
points you at — failed to load: a YAML list under a string-map <code>variables</code>, and templates missing
the required <code>version</code> field. Both fixed, with a regression test that loads every shipped config.</li>
<li><strong>Sync branches are cut from a real commit SHA</strong> (#31). <code>getBaseSHA</code> returned a branch <em>name</em> where
<code>git/refs</code> requires a SHA, so branch creation 422&rsquo;d against live GitHub — and the error was
discarded, letting later steps run against a branch that was never created. Branch-creation
failures now surface; only a genuine &ldquo;already exists&rdquo; is tolerated.</li>
</ul>
<h2 id="verifying-this-release">Verifying this release</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-console" data-lang="console"><span style="display:flex;"><span>$ curl -fsSL https://github.com/SteerSpec/strspc-sync/releases/download/v0.2.0/checksums.txt
</span></span><span style="display:flex;"><span>$ shasum -a <span style="color:#ae81ff">256</span> strspc_0.2.0_linux_amd64.tar.gz
</span></span></code></pre></div><p><strong>Full changelog:</strong> <a href="https://github.com/SteerSpec/strspc-sync/compare/v0.1.1...v0.2.0">https://github.com/SteerSpec/strspc-sync/compare/v0.1.1...v0.2.0</a></p>
]]></content:encoded></item><item><title>PullProof</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/pullproof/</link><pubDate>Thu, 20 Aug 2026 22:38:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/pullproof/</guid><description>Version updated for https://github.com/SyedSibtainRazvi/PullProof to version v2.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PullProof is a GitHub Action that automates the review of blog posts and documentation changes in pull requests. It checks metadata, technical accuracy, writing quality, structure, and blog polish, providing AI-generated feedback as structured comments. The action only reviews added lines and updates the same comment on subsequent pushes, improving efficiency and reducing spam.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SyedSibtainRazvi/PullProof">https://github.com/SyedSibtainRazvi/PullProof</a></strong> to version <strong>v2.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pullproof">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PullProof is a GitHub Action that automates the review of blog posts and documentation changes in pull requests. It checks metadata, technical accuracy, writing quality, structure, and blog polish, providing AI-generated feedback as structured comments. The action only reviews added lines and updates the same comment on subsequent pushes, improving efficiency and reducing spam.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Feature:</strong> the previous review is fed back into the prompt on each run. On updated posts the model stays consistent with its prior feedback, opens with a <code>Resolved since last review:</code> list, and raises only new or still-unresolved issues — no more rating flips or re-raised fixed items. Also drops a duplicate comment-list fetch. (#7)</p>
]]></content:encoded></item><item><title>Agent Contract Test</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/agent-contract-test/</link><pubDate>Thu, 20 Aug 2026 22:37:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/agent-contract-test/</guid><description>Version updated for https://github.com/tangwenhai839-create/agent-contract-test to version v0.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Contract Test is a tool that automates deterministic contract testing for AI coding agents. It checks the observable result of an agent run against predefined rules, such as file changes, protected paths, and required/forbidden content. The action does not rely on another model to judge the answer and ensures reproducibility by using the same workspace and contract. The tool helps maintainers verify that changes stay within their authority and have reproducible evidence of working code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tangwenhai839-create/agent-contract-test">https://github.com/tangwenhai839-create/agent-contract-test</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-contract-test">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Contract Test is a tool that automates deterministic contract testing for AI coding agents. It checks the observable result of an agent run against predefined rules, such as file changes, protected paths, and required/forbidden content. The action does not rely on another model to judge the answer and ensures reproducibility by using the same workspace and contract. The tool helps maintainers verify that changes stay within their authority and have reproducible evidence of working code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This evidence release publishes the first reproducible real-agent run for public issue #3. Codex CLI 0.148.0 stayed within the two allowed test files, produced zero contract findings, and passed an independent 7/7 test rerun. The repository now includes the exact contract, sanitized JSON result, SARIF output, candidate patch, limitations, and reproduction steps.\n\nAll 9 CI combinations pass across Windows, macOS, Linux and Node.js 20, 22, 24.</p>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/delivery-autopilot-runner/</link><pubDate>Thu, 20 Aug 2026 22:36:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Delivery Autopilot Runner GitHub Action automates the process of creating pull requests from tickets in a tracker to reviewed code, using an AI pipeline. It requires a Delivery Autopilot subscription and works by checking out the repository on GitHub’s runners, running quality checks, and opening pull requests. The action does not send source code to Tekunda servers but uses your chosen model provider for coding.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Delivery Autopilot Runner GitHub Action automates the process of creating pull requests from tickets in a tracker to reviewed code, using an AI pipeline. It requires a Delivery Autopilot subscription and works by checking out the repository on GitHub&rsquo;s runners, running quality checks, and opening pull requests. The action does not send source code to Tekunda servers but uses your chosen model provider for coding.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A hit turn limit no longer fails the build job; the produced PR flows to the gate.</p>
]]></content:encoded></item><item><title>Tessl Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/tessl-code-review/</link><pubDate>Thu, 20 Aug 2026 22:35:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/tessl-code-review/</guid><description>Version updated for https://github.com/tesslio/code-review-action to version v1.2.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of running Tessl Code Review on pull requests. It handles pull-request resolution, exact-head checkout, Tessl CLI setup, review publication, stale-head protection, idempotency, failure notices, and result artifacts. The action supports configuration through a profile or explicit lens selection.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tesslio/code-review-action">https://github.com/tesslio/code-review-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tessl-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of running Tessl Code Review on pull requests. It handles pull-request resolution, exact-head checkout, Tessl CLI setup, review publication, stale-head protection, idempotency, failure notices, and result artifacts. The action supports configuration through a profile or explicit lens selection.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Pin the Action to this release&rsquo;s commit SHA:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">tesslio/code-review-action@36962c011cd38aa40abebf8ae3068a27a0af2013</span> <span style="color:#75715e"># v1.2.0</span>
</span></span></code></pre></div><p>This revision installs the current Tessl CLI release. Set the
<code>cli-version</code> input to pin an exact one.</p>
<p>The major tag now points here, so a caller on that tag is on this
revision.</p>
]]></content:encoded></item><item><title>Setup shp</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/setup-shp/</link><pubDate>Thu, 20 Aug 2026 22:34:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/setup-shp/</guid><description>Version updated for https://github.com/timbrinded/shapelang to version v0.8.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Shape is a typed architecture conformance language that helps developers write clear, explicit, and checkable architectural claims. It checks the coherence of the system’s architecture model against declared specifications, ensuring that resources are protected from unintended deletions and that component grants match function effects. Shape automates tasks such as code formatting, coverage analysis, design memory recording, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/timbrinded/shapelang">https://github.com/timbrinded/shapelang</a></strong> to version <strong>v0.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-shp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Shape is a typed architecture conformance language that helps developers write clear, explicit, and checkable architectural claims. It checks the coherence of the system&rsquo;s architecture model against declared specifications, ensuring that resources are protected from unintended deletions and that component grants match function effects. Shape automates tasks such as code formatting, coverage analysis, design memory recording, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="shape-v080">Shape v0.8.0</h1>
<p>Shape v0.8.0 adds a deterministic machine-readable model export and a bundled
visualiser skill that turns authored Shape into a self-contained local system
atlas.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Add <code>shp inspect --json [files...]</code> for tools that need the canonically
lowered effective model. The versioned export includes module-qualified
identities, authored or generated-AST origin, effects, relations,
implementations, bindings, rules, design memory, and aggregate counts.</li>
<li>Use the same recursive discovery, parser, lowering, and reference resolution
as the other model commands. The export contains no clock-derived field, so
identical inputs and the same <code>shp</code> version produce identical bytes.</li>
<li>Keep inspection separate from conformance. The export describes the declared
model; it does not replace strict <code>shp check</code> or prove source behavior.</li>
</ul>
<h2 id="unix-system-visualiser">Unix system visualiser</h2>
<p>The coordinated <code>0.8.0</code> plugin adds a sixth skill,
<code>unix-system-visualiser</code>. It uses <code>shp inspect --json</code> to generate one offline
HTML atlas with:</p>
<ul>
<li>module districts, declaration details, and typed relations;</li>
<li>search, pan, zoom, focus, keyboard operation, and reduced-motion support;</li>
<li>authored journeys and deterministic inferred dependency tours; and</li>
<li>a non-visual model index and stable browser-validation hooks.</li>
</ul>
<p>The generator writes only to an ignored repository path unless the user gives
explicit permission. It rejects unsafe symlink escapes and unignored output,
and it keeps generated AST separate from authored architecture claims.</p>
<h2 id="release-assurance">Release assurance</h2>
<ul>
<li>Expand release-candidate static conformance and focused behavioral canaries
from five skills to all six shipped skills.</li>
<li>Add deterministic inspection, visualiser generation, invalid-model,
unignored-output, symlink-safety, multi-file module, and journey tests.</li>
<li>Keep the protected <code>skills-release-approval</code> environment as the human gate
before coordinated CLI and plugin tags can be created.</li>
</ul>
<h2 id="distribution">Distribution</h2>
<p>The release publishes Linux x64, Linux ARM64, macOS ARM64, and Windows x64
archives, release-specific installer scripts, and SHA-256 checksums. The setup
action is verified against the published release on Linux and Windows.</p>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/compose-lint/</link><pubDate>Thu, 20 Aug 2026 22:33:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.21.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose and Functionality: compose-lint is a security-focused linter for Docker Compose files that detects and fixes dangerous misconfigurations in CI pipelines. It automates security checks, catches common vulnerabilities such as privilege flaws, network exposure, supply-chain issues, file leaks, and credential leaks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.21.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Purpose and Functionality</strong>: <code>compose-lint</code> is a security-focused linter for Docker Compose files that detects and fixes dangerous misconfigurations in CI pipelines. It automates security checks, catches common vulnerabilities such as privilege flaws, network exposure, supply-chain issues, file leaks, and credential leaks.</p>
<p><strong>Problems Solved or Tasks Automated</strong>: The action helps organizations identify and mitigate security risks in their Docker Compose configurations before they are deployed to production. By catching these issues early, it ensures that only compliant configurations reach the deployment stage, thus improving overall security and compliance with best practices.</p>
<p><strong>Key Capabilities</strong>: <code>compose-lint</code> provides static analysis for <code>docker-compose.yml</code> files, offering rule documentation offline via a web interface (<code>tmatens.github.io/compose-lint</code>). It supports full rule sets grounded in OWASP standards and the CIS Docker Benchmark. The action can be run locally or as part of CI workflows, providing real-time feedback on security issues found.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="upgrading-from-020x">Upgrading from 0.20.x</h3>
<p><strong>SARIF consumers: your Code Scanning alerts will be re-keyed once.</strong> The
<code>partialFingerprints</code> key moves from <code>composeLintFinding/v1</code> to <code>/v2</code>, and
the digest no longer includes the finding&rsquo;s message. On the first upload
after upgrading, GitHub closes every existing compose-lint alert and opens a
replacement — dismissal state on those alerts is lost. This happens once.</p>
<p>The reason is that v1 made prose part of the alert&rsquo;s identity: rewording any
rule message silently closed and reopened every matching alert in every
consuming repository, so improving a message was a breaking change with no
warning. Identity is now structured data (file, rule, service, and the
specific offending value), and message text is free to change (ADR-024).</p>
<p>Nothing to do beyond expecting the one-time churn. If you dismiss alerts,
re-dismiss after the first post-upgrade scan.</p>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>SARIF results now name the service.</strong> A finding carries the service as a
<code>logicalLocation</code> (<code>services.&lt;name&gt;</code>) and names it in the alert title.
Previously SARIF results carried only rule, file and line, so a Code
Scanning user disambiguated a multi-service file by line number while a
terminal user was told the service outright — even though the service was
already part of the alert&rsquo;s fingerprint.</p>
</li>
<li>
<p><strong><code>check</code> and <code>fix</code> now say when no config was in effect.</strong> A run that
reports findings — or a <code>fix</code> that has changes to make — with no
<code>.compose-lint.yml</code> found and none passed via <code>--config</code> prints a one-line
note on stderr naming the directory it looked in. This is aimed at the
Docker case: the image&rsquo;s working directory is <code>/src</code>, so a run that mounts
only the compose file leaves the config outside the container and silently
drops every suppression. Passing runs, and runs that found a config, stay
quiet.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><strong>SARIF alert identity no longer includes the finding&rsquo;s message.</strong> The
<code>partialFingerprints</code> key moves from <code>composeLintFinding/v1</code> to <code>/v2</code>, and
the digest is now <code>[uri, rule_id, service, evidence]</code> rather than
<code>[uri, rule_id, service, message]</code>. <code>evidence</code> is a new internal field
holding the specific offending value in normalized form, so a rule that
fires more than once for one service still distinguishes its hits without
making prose part of the alert&rsquo;s identity (ADR-024). See Upgrading above
for the one-time re-key.</p>
</li>
<li>
<p><strong>The published image moves to a newer distroless base.</strong>
<code>gcr.io/distroless/python3-debian13:nonroot</code> is repinned from
<code>sha256:eff0a605…</code> to <code>sha256:4376456c…</code>, picking up the base image&rsquo;s own
updates. This landed after <code>release-prep</code> snapshotted the changelog but
before the tag, so it shipped in the 0.21.0 image without being recorded
here at the time.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>CL-0005 now flags <code>::ffff:0.0.0.0</code> on every supported interpreter.</strong> The
IPv4-mapped spelling of the unspecified address was classified by
<code>ipaddress.is_unspecified</code>, whose handling of IPv4-mapped addresses varies
with the CPython build — so a port published on all interfaces was reported
on some hosts and missed on others, with no way for a user to tell which
they had. The mapping is now unwrapped explicitly. A compose file binding
<code>[::ffff:0.0.0.0]</code> that previously passed on macOS or Windows will now
correctly report CL-0005.</li>
<li><strong>GitHub Action: installing a just-released version no longer fails on
PyPI index lag.</strong> PyPI&rsquo;s JSON API sees a release within seconds of the
publish, but the <code>/simple/</code> index pip resolves against can lag it by
minutes — so <code>uses: tmatens/compose-lint@&lt;sha&gt;</code> pinned to a version
released moments earlier could fail with &ldquo;No matching distribution
found&rdquo;. The action&rsquo;s install now retries with backoff for ~100s, and
says so if it gives up instead of leaving a bare non-zero exit.</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/wails3-build-action/</link><pubDate>Thu, 20 Aug 2026 22:31:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action ToQuery/wails3-build-action is designed to automate the build process for Wails.io v3 projects. It installs GoLang and NodeJS, builds a binary based on user-specified configuration options, and optionally uploads the results to GitHub or publishes them as a release when a tag is pushed. The action supports various platforms and configurations for building and packaging the application.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>ToQuery/wails3-build-action</code> is designed to automate the build process for Wails.io v3 projects. It installs GoLang and NodeJS, builds a binary based on user-specified configuration options, and optionally uploads the results to GitHub or publishes them as a release when a tag is pushed. The action supports various platforms and configurations for building and packaging the application.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>NuGet dependency graph</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/nuget-dependency-graph/</link><pubDate>Thu, 20 Aug 2026 22:31:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/nuget-dependency-graph/</guid><description>Version updated for https://github.com/Tsabo/nugraph-action to version v3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action provides reusable functionality to generate NuGet dependency graphs from .NET solutions or projects using the 0xced/nugraph tool. It supports solution files and automates tasks related to creating project-specific dependency graphs as artifacts or appending them directly to job summaries, rendering them in different formats like SVG, PNG, PDF, and JPEG. The action handles multiple projects within a solution by generating separate graphs for each, and provides options for customizing graph styling.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tsabo/nugraph-action">https://github.com/Tsabo/nugraph-action</a></strong> to version <strong>v3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nuget-dependency-graph">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action provides reusable functionality to generate NuGet dependency graphs from .NET solutions or projects using the <code>0xced/nugraph</code> tool. It supports solution files and automates tasks related to creating project-specific dependency graphs as artifacts or appending them directly to job summaries, rendering them in different formats like SVG, PNG, PDF, and JPEG. The action handles multiple projects within a solution by generating separate graphs for each, and provides options for customizing graph styling.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds support for the newer XML-based <code>.slnx</code> solution format alongside the classic <code>.sln</code> format.</p>
<h2 id="changes">Changes</h2>
<ul>
<li><code>project-path</code> now also accepts a <code>.slnx</code> file — it&rsquo;s expanded into its member <code>.csproj</code>/<code>.fsproj</code>/<code>.vbproj</code> projects exactly like <code>.sln</code>, with nugraph run once per project (per-project output filenames, job summary sections, etc.)</li>
<li>Solution expansion for both <code>.sln</code> and <code>.slnx</code> now goes through <code>dotnet sln list</code> instead of a <code>.sln</code>-specific text parser, so it stays correct against whatever the installed SDK itself considers valid</li>
<li>No behavior change for existing <code>.sln</code>/single-project usages</li>
</ul>
<p><strong>Note:</strong> <code>.slnx</code> support depends on the .NET SDK version — older SDKs won&rsquo;t recognize the format. If your projects use <code>.slnx</code>, set <code>dotnet-version</code> to a recent SDK (this repo&rsquo;s tests use <code>10.0.x</code>).</p>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Tsabo/nugraph-action@v3</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">project-path</span>: <span style="color:#ae81ff">./src/MyApp.slnx</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Vaara Policy Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/vaara-policy-check/</link><pubDate>Thu, 20 Aug 2026 22:29:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/vaara-policy-check/</guid><description>Version updated for https://github.com/vaaraio/vaara to version v1.71.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automates the process of verifying and auditing autonomous actions to ensure accountability and transparency. It provides a tamper-evident record that anyone can verify offline, including regulators, auditors, and customers after incidents. The action helps in ensuring that every call to a governed function is risk-scored and decided against the policy before it runs, ensuring the integrity of transactions and decisions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaaraio/vaara">https://github.com/vaaraio/vaara</a></strong> to version <strong>v1.71.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vaara-policy-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action automates the process of verifying and auditing autonomous actions to ensure accountability and transparency. It provides a tamper-evident record that anyone can verify offline, including regulators, auditors, and customers after incidents. The action helps in ensuring that every call to a governed function is risk-scored and decided against the policy before it runs, ensuring the integrity of transactions and decisions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1710---2026-08-21">[1.71.0] - 2026-08-21</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><code>vaara.settlement.release</code>: a release condition holds value against a signed statement of what must be proved before it moves, and a Vaara receipt proving the authorised action happened is what releases it. Everything in the tree until now ran one direction, a payment gating access with the settlement evidence landing inside a receipt, which is the x402 gate and SPEC.md Section 5.2. Here the receipt gates the payment. The module holds no key belonging to a payer, signs no transaction, and reaches no chain or custodian. It answers one question about bytes, a settlement agent acts on the answer, and the verifier sits in the settlement path holding nothing.</p>
</li>
<li>
<p><code>vaara.release-condition/v0</code>, a signed, content-addressed, JCS-canonical document carrying what is held, an exact <code>requires</code> block, and an inclusive <code>notAfter</code>. The signature is Ed25519 over the document with its own <code>signature</code> field removed, the same rule the receipt envelope uses, so it adds no cryptography and no dependency. <code>requires</code> is matched exactly rather than approximately: the action digest, the grant fingerprint that authorised it, the accepted receipt issuer, and the fingerprint of the one key whose receipts count, taken over the SubjectPublicKeyInfo DER so PEM formatting cannot move it.</p>
</li>
<li>
<p><code>evaluate(condition, bundle)</code> returns one of four states, each carrying a reason from a closed set: <code>released</code>, <code>held</code>, <code>expired</code>, <code>refused</code>. A verifier that proved nothing must not read as green, and must not read as the same false as a genuine failure. <code>held</code> because no receipt has arrived and <code>refused</code> because a receipt was tampered with are different facts, and one boolean for both discards the difference between &ldquo;not yet&rdquo; and &ldquo;no&rdquo;. The reason space is partitioned in <code>REASON_STATE</code>, as data rather than as control flow, so no code path can file a forgery under a hold. The distinction came out of a SCITT list thread on 2026-08-19.</p>
<p>The axis is soundness, then sufficiency. A broken condition signature, a receipt under a key the condition does not pin, a broken receipt signature, or evidence that does not resolve to the digest the receipt signed all fail as evidence and refuse. A missing receipt, a receipt for another action, another authorization, another issuer, or one that soundly proves a refusal are sound and insufficient, and hold. Soundness runs before the clock, so an expired window cannot swallow a tampering finding, and the clock runs before sufficiency, so a closed window is reported as the reason the value is not moving.</p>
</li>
<li>
<p><code>vaara release-check</code> decides the same question at the command line, taking a presented bundle or the three documents separately. Exit 0 when the value releases and 1 when it does not, because a settlement agent acts on held, expired and refused the same way. The distinction lives in the printed reason. Without <code>--condition-key</code> nothing releases and the answer is <code>refused</code>, not <code>held</code>: a document cannot vouch for the key that signed it, so an unverifiable condition never sits in the same state as one still awaiting proof.</p>
</li>
<li>
<p><code>tests/vectors/release_condition_v0/</code>, the 44th conformance suite, with eight cases and a checker that imports no Vaara and recomputes every verdict from the case bytes. All four states appear in the shipped cases, including a receipt that soundly proves the action was blocked, a condition whose window has closed, a receipt tampered one second after signing, and a receipt signed under a key the condition never pinned. The checker also asserts the reason-to-state mapping is a partition covering all four states, because a corpus of only the positive case would still pass with two of them merged into one. SPEC.md Section 5.7 and <code>docs/conformance-profile.md</code> carry the profile and the suite count.</p>
</li>
<li>
<p><code>mint_authorization_receipt</code> and <code>mint_for_signer</code> accept <code>iat</code>, pinning the issuer block&rsquo;s issued-at instant instead of taking the wall clock. Production leaves it alone. A vector generator sets it so regenerating a corpus changes only the signature and not the record it signs.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p>Rendering the conformance page no longer deletes the badges it does not own. <code>write_badges</code> swept the whole badge directory against the reproduction rows, while <code>badge_drift</code> exempted the corpus shield and the badges named in <code>UNMANAGED_BADGES</code>. The two disagreed, so a render removed the DOI badge the README links to and the <code>--check</code> pass then reported the page current, which would have carried a broken image to the site with nothing failing.</p>
</li>
<li>
<p><code>check_no_private_keys.py --tree</code> scans tracked files from the working tree instead of reading each one back from <code>HEAD</code>. It raised on the first path <code>git ls-files</code> reports that <code>HEAD</code> does not carry, so the scan died on any newly staged file. CI never hit it, because a fresh checkout has every tracked file at both. Running it by hand before a commit did, which is exactly when it is wanted: a new vector suite carrying a key is the case it exists to catch.</p>
</li>
<li>
<p>The 1.69.0 and 1.70.0 entries were in the wrong order, with 1.69.0 above <code>## [Unreleased]</code> and 1.70.0 below it. The releases themselves were correct and the tags are unaffected; only the file read out of sequence. <code>ship-guard</code> reads the first versioned heading to decide whether a declared version is missing its tag, so the stranded ordering also left it grading 1.69.0 on every turn instead of the newest entry.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Veracode Configure</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/veracode-configure/</link><pubDate>Thu, 20 Aug 2026 22:28:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/veracode-configure/</guid><description>Version updated for https://github.com/vcode-config/configure to version v0.05.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The veracode-config GitHub Action automates the process of onboarding repositories into the Veracode Workflow integration. It checks if an Application Profile exists, creates one if it does not, and persists inventory and workflow configuration values in custom metadata. The action also provides reusable workflow outputs for downstream jobs. It inventories programming languages, package managers, non-GitHub build definitions, and generates JSON data for the inventory and workflow config. The action supports customization of various fields such as metadata keys and business criticality levels.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vcode-config/configure">https://github.com/vcode-config/configure</a></strong> to version <strong>v0.05</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/veracode-configure">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>veracode-config</code> GitHub Action automates the process of onboarding repositories into the Veracode Workflow integration. It checks if an Application Profile exists, creates one if it does not, and persists inventory and workflow configuration values in custom metadata. The action also provides reusable workflow outputs for downstream jobs. It inventories programming languages, package managers, non-GitHub build definitions, and generates JSON data for the inventory and workflow config. The action supports customization of various fields such as metadata keys and business criticality levels.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>sdcsw (83f399e)</li>
<li>added debug output to inventory (e558b79)</li>
<li>better logging (a0d1ee7)</li>
<li>Corrected the main call to use dist/index.mjs (abcc572)</li>
<li>initial commit (460d6f7)</li>
</ul>
]]></content:encoded></item><item><title>Diffly PR triage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/diffly-pr-triage/</link><pubDate>Thu, 20 Aug 2026 22:27:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/diffly-pr-triage/</guid><description>Version updated for https://github.com/VIVAAN-DHAWAN/diffly-cli to version v0.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary diffly-cli is a tool for triaging GitHub pull requests by analyzing metadata, files, diffs, statuses, and repository trees. It provides deterministic verifications with blast-radius maps and supports literate-diff explanations using OpenAI models, automating the review process. The tool helps identify high-risk areas in large PRs and maintains one verdict comment with risk flags.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VIVAAN-DHAWAN/diffly-cli">https://github.com/VIVAAN-DHAWAN/diffly-cli</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/diffly-pr-triage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>diffly-cli is a tool for triaging GitHub pull requests by analyzing metadata, files, diffs, statuses, and repository trees. It provides deterministic verifications with blast-radius maps and supports literate-diff explanations using OpenAI models, automating the review process. The tool helps identify high-risk areas in large PRs and maintains one verdict comment with risk flags.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Harden triage for large and incomplete GitHub responses by @VIVAAN-DHAWAN in <a href="https://github.com/VIVAAN-DHAWAN/diffly-cli/pull/3">https://github.com/VIVAAN-DHAWAN/diffly-cli/pull/3</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VIVAAN-DHAWAN/diffly-cli/compare/v0.1.0...v0.2.1">https://github.com/VIVAAN-DHAWAN/diffly-cli/compare/v0.1.0...v0.2.1</a></p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/rustscript-action/</link><pubDate>Thu, 20 Aug 2026 22:26:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.6.10.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, RustScript, allows developers to write scripts in the Rust programming language and run them like shell scripts. It provides a quick and efficient way to execute Rust code without the need for compiling it each time. The action supports a subset of Rust features and automatically validates scripts with rustc before execution. It also offers various commands such as running, validating, building, updating, cleaning, and listing supported methods.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.6.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, RustScript, allows developers to write scripts in the Rust programming language and run them like shell scripts. It provides a quick and efficient way to execute Rust code without the need for compiling it each time. The action supports a subset of Rust features and automatically validates scripts with <code>rustc</code> before execution. It also offers various commands such as running, validating, building, updating, cleaning, and listing supported methods.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.6.9...v0.6.10">https://github.com/VladasZ/rustscript/compare/v0.6.9...v0.6.10</a></p>
]]></content:encoded></item><item><title>Build Flow Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/build-flow-action/</link><pubDate>Thu, 20 Aug 2026 22:25:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/build-flow-action/</guid><description>Version updated for https://github.com/wgtechlabs/build-flow-action to version v0.2.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Build Flow Action is a reusable GitHub Actions workflow that automates the entire build and release lifecycle, eliminating manual configuration and ensuring consistent CI checks and security gates. It supports multiple ecosystems and provides zero-config detection of dependencies, allowing teams to focus on writing their own build commands rather than setting up complex workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wgtechlabs/build-flow-action">https://github.com/wgtechlabs/build-flow-action</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-flow-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Build Flow Action is a reusable GitHub Actions workflow that automates the entire build and release lifecycle, eliminating manual configuration and ensuring consistent CI checks and security gates. It supports multiple ecosystems and provides zero-config detection of dependencies, allowing teams to focus on writing their own build commands rather than setting up complex workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="020---2026-08-20">[0.2.0] - 2026-08-20</h2>
<h3 id="added">Added</h3>
<ul>
<li>add artifact-first releases (#41)</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>finish review fixes</li>
<li>pin primitive release refs (#43)</li>
<li>scope release concurrency and fix contract test</li>
<li>add unified build flow entry workflow</li>
</ul>
]]></content:encoded></item><item><title>Zig Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/zig-actions/</link><pubDate>Thu, 20 Aug 2026 22:24:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/zig-actions/</guid><description>Version updated for https://github.com/YetAnotherMechanicusEnjoyer/zig-actions to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the compilation, testing, and documentation generation of Zig projects. It supports multiple targets and optimization levels, allowing users to build, test, and deploy their Zig applications directly from GitHub Actions. The action provides detailed error reporting through GitHub annotations and includes options for deploying documentation to a GitHub Pages branch.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YetAnotherMechanicusEnjoyer/zig-actions">https://github.com/YetAnotherMechanicusEnjoyer/zig-actions</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zig-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the compilation, testing, and documentation generation of Zig projects. It supports multiple targets and optimization levels, allowing users to build, test, and deploy their Zig applications directly from GitHub Actions. The action provides detailed error reporting through GitHub annotations and includes options for deploying documentation to a GitHub Pages branch.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="added-zig-release--implemented-it-to-aio-action">Added Zig Release &amp; implemented it to AIO action</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/YetAnotherMechanicusEnjoyer/zig-actions/compare/v1.0.2...v1.0.3">https://github.com/YetAnotherMechanicusEnjoyer/zig-actions/compare/v1.0.2...v1.0.3</a></p>
]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/kover-report-action/</link><pubDate>Thu, 20 Aug 2026 22:22:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.35.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Kover Report Action is a GitHub Action that generates and reports code coverage from Kover XML reports in Kotlin/Android projects with multi-module support. It automates the process of generating coverage reports, integrating them into pull requests, and tracking coverage history over time. Key capabilities include handling multiple modules, flexible discovery methods, configurable thresholds, and automatic updates to PR comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v3.1.35</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Kover Report Action is a GitHub Action that generates and reports code coverage from Kover XML reports in Kotlin/Android projects with multi-module support. It automates the process of generating coverage reports, integrating them into pull requests, and tracking coverage history over time. Key capabilities include handling multiple modules, flexible discovery methods, configurable thresholds, and automatic updates to PR comments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3.1.35: PR #174 - chore(deps): update pnpm to v11.20.0</p>
]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/lgtmaybe/</link><pubDate>Thu, 20 Aug 2026 14:18:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v2.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The lgtmaybe GitHub Action is a tool designed to review pull requests or merge requests across multiple version control platforms (GitHub, GitLab, and Gitea) using AI-based models. It generates inline comments on changes, focusing on logic errors, security vulnerabilities, missing tests, outdated code, performance regressions, unnecessary complexity, intent alignment, and unnecessary code, all without executing the code. The tool is designed to be secure by not running any of the PR’s code and redacting sensitive information before submission to the model.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v2.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The lgtmaybe GitHub Action is a tool designed to review pull requests or merge requests across multiple version control platforms (GitHub, GitLab, and Gitea) using AI-based models. It generates inline comments on changes, focusing on logic errors, security vulnerabilities, missing tests, outdated code, performance regressions, unnecessary complexity, intent alignment, and unnecessary code, all without executing the code. The tool is designed to be secure by not running any of the PR&rsquo;s code and redacting sensitive information before submission to the model.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="250-2026-08-20"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v2.4.0...lgtmaybe-v2.5.0">2.5.0</a> (2026-08-20)</h2>
<h3 id="features">Features</h3>
<ul>
<li>hold the advisory lenses to the severity their prompt asks for (<a href="https://github.com/MattJColes/lgtmaybe/issues/529">#529</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/c9aab3cee44d673d73d4e48ece81f07d073a2d2b">c9aab3c</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>count tokens in the model&rsquo;s own tokenizer and reserve prompt overhead (<a href="https://github.com/MattJColes/lgtmaybe/issues/528">#528</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/d41dab9418985564ebed397e132a93ccf3932c5f">d41dab9</a>), closes <a href="https://github.com/MattJColes/lgtmaybe/issues/509">#509</a></li>
<li>escape the file path when fetching file contents (<a href="https://github.com/MattJColes/lgtmaybe/issues/522">#522</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/c244bf75b3b645fdb4a0d9f7e82b21265608fc89">c244bf7</a>), closes <a href="https://github.com/MattJColes/lgtmaybe/issues/508">#508</a></li>
<li>honour resolve_fixed on GitLab (<a href="https://github.com/MattJColes/lgtmaybe/issues/525">#525</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/6f5efe5193907425c5ee1ed9037b12e77bda94e4">6f5efe5</a>), closes <a href="https://github.com/MattJColes/lgtmaybe/issues/502">#502</a></li>
<li>read a fenced reply in /ask and follow-up validation (<a href="https://github.com/MattJColes/lgtmaybe/issues/523">#523</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/ae4e650f6a2034214a8e321b7be089cff777cba3">ae4e650</a>), closes <a href="https://github.com/MattJColes/lgtmaybe/issues/510">#510</a> <a href="https://github.com/MattJColes/lgtmaybe/issues/511">#511</a></li>
<li>read a self-hosted server&rsquo;s tool-call rejection wording (<a href="https://github.com/MattJColes/lgtmaybe/issues/526">#526</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/3e3a20007a5d94b0d6cdb610596ff6e73f1ef820">3e3a200</a>), closes <a href="https://github.com/MattJColes/lgtmaybe/issues/499">#499</a></li>
</ul>
<h3 id="performance-improvements">Performance Improvements</h3>
<ul>
<li>overlap the per-file boundary scans and guard the flood counter (<a href="https://github.com/MattJColes/lgtmaybe/issues/524">#524</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/70b87e554002ebe25be0ab4e5b824e56c6b28782">70b87e5</a>), closes <a href="https://github.com/MattJColes/lgtmaybe/issues/505">#505</a> <a href="https://github.com/MattJColes/lgtmaybe/issues/506">#506</a></li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>correct the gitea token scopes and drop a flag that does not exist (<a href="https://github.com/MattJColes/lgtmaybe/issues/527">#527</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/fd36563a21daa68c8899863f54ec411f8a963508">fd36563</a>), closes <a href="https://github.com/MattJColes/lgtmaybe/issues/500">#500</a> <a href="https://github.com/MattJColes/lgtmaybe/issues/501">#501</a></li>
<li>rescore the model-choice tables and correct three recommendations (<a href="https://github.com/MattJColes/lgtmaybe/issues/512">#512</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/d9953ccdbd568e022d345aabf7656f83e93d74a0">d9953cc</a>)</li>
</ul>
]]></content:encoded></item><item><title>Speccy API review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/speccy-api-review/</link><pubDate>Thu, 20 Aug 2026 14:17:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/speccy-api-review/</guid><description>Version updated for https://github.com/mcclowes/speccy to version create-speccy-reference@0.10.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Speccy is an OpenAPI renderer for React, macOS, and Docusaurus. It provides a shared rendering core that ensures consistency across different platforms. The action automates the linting, diffing, and rendering of OpenAPI specifications, addressing common issues in API documentation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcclowes/speccy">https://github.com/mcclowes/speccy</a></strong> to version <strong><a href="mailto:create-speccy-reference@0.10.3">create-speccy-reference@0.10.3</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/speccy-api-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Speccy is an OpenAPI renderer for React, macOS, and Docusaurus. It provides a shared rendering core that ensures consistency across different platforms. The action automates the linting, diffing, and rendering of OpenAPI specifications, addressing common issues in API documentation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Version packages (#54) (dcd2497)</li>
<li>gitignore (1693227)</li>
<li>Merge remote-tracking branch &lsquo;origin/main&rsquo; (3dccc9b)</li>
<li>Inherit the host theme in operation documentation components (8513236)</li>
<li>Clip operation previews as one panel and match response to request styling (3838e7b)</li>
<li>Version packages (#53) (7aae567)</li>
<li>Replace operation reference prototype with component stories (a7ffe08)</li>
<li>Keep code lines on separate rows outside numbered blocks (1e1daa6)</li>
<li>Version packages (#52) (73ad160)</li>
<li>Release operation reference resolution as a patch (6fec490)</li>
</ul>
]]></content:encoded></item><item><title>Tuffgal</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/tuffgal/</link><pubDate>Thu, 20 Aug 2026 14:16:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/tuffgal/</guid><description>Version updated for https://github.com/nschneble/tuffgal-action to version v1.7.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates visual regression testing using Tuffgal in CI mode, handling differences by proposing candidate baselines as PR comments that require approval. It simplifies setting up Node.js and Playwright for Tuffgal execution and provides a per-PR preview with side-by-side baseline and actual screenshots for easier review.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nschneble/tuffgal-action">https://github.com/nschneble/tuffgal-action</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tuffgal">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates visual regression testing using Tuffgal in CI mode, handling differences by proposing candidate baselines as PR comments that require approval. It simplifies setting up Node.js and Playwright for Tuffgal execution and provides a per-PR preview with side-by-side baseline and actual screenshots for easier review.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<p>The sticky PR comment now supports a11y-only changes, e.g. when the baseline images are identical but there are structural changes underneath the hood.</p>
<h3 id="changed">Changed</h3>
<ul>
<li>Approve checkboxes are locked while an approval runs, so nothing in the sticky PR comment can trigger a second approval</li>
<li>A <code>@tuffgal approve</code> that lands mid-approval is refused with a note under the status banner, cleared when the running approval finishes</li>
<li>The example approve workflow serializes per PR with a <code>concurrency</code> group, so copy it to your workflow to keep two approvals off the same branch (the in-comment lock is the user-visible half)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>A story with both new and changed baselines only shows up as new, so the changed candidates cannot be approved from the sticky PR comment</li>
<li>The artifact validator reports success for any zip file it cannot read</li>
</ul>
]]></content:encoded></item><item><title>Build CheckMK MKP Package</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/build-checkmk-mkp-package/</link><pubDate>Thu, 20 Aug 2026 14:15:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/build-checkmk-mkp-package/</guid><description>Version updated for https://github.com/oposs/mkp-builder to version v2.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of building Checkmk MKP (Monitoring Konfiguration Package) files from local directory structures, offering features such as automated MKP building, configurable options via inputs or configuration files, Python syntax checking, artifact ready outputs, and clean repository maintenance. It also includes a Checkmk plugin development guide as a Claude Code skill for plugin creation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oposs/mkp-builder">https://github.com/oposs/mkp-builder</a></strong> to version <strong>v2.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-checkmk-mkp-package">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of building Checkmk MKP (Monitoring Konfiguration Package) files from local directory structures, offering features such as automated MKP building, configurable options via inputs or configuration files, Python syntax checking, artifact ready outputs, and clean repository maintenance. It also includes a Checkmk plugin development guide as a Claude Code skill for plugin creation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="new">New</h3>
<ul>
<li>The skill now ships a test harness. A plugin repo can run pytest against the real Checkmk API, pulled from Checkmk and pinned to the version the plugin targets, instead of against hand-written stubs.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Ship a test harness with the skill by @oetiker in <a href="https://github.com/oposs/mkp-builder/pull/12">https://github.com/oposs/mkp-builder/pull/12</a></li>
<li>Release v2.3.0 by @github-actions[bot] in <a href="https://github.com/oposs/mkp-builder/pull/13">https://github.com/oposs/mkp-builder/pull/13</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/oposs/mkp-builder/compare/v2.2.2...v2.3.0">https://github.com/oposs/mkp-builder/compare/v2.2.2...v2.3.0</a></p>
]]></content:encoded></item><item><title>SBOM Auditor Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/sbom-auditor-action/</link><pubDate>Thu, 20 Aug 2026 14:14:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/sbom-auditor-action/</guid><description>Version updated for https://github.com/otto-de/sbom_auditor_action to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SBOM Auditor Action audits Software Bill of Materials (SBOM) for license compliance by fetching, enriching, and auditing the licenses against predefined policies. It generates a detailed report with AI-assisted summaries if enabled, helping organizations ensure their software dependencies comply with licensing terms. The action supports multiple AI providers like OpenAI, Azure OpenAI, AWS Bedrock, and GitHub.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/otto-de/sbom_auditor_action">https://github.com/otto-de/sbom_auditor_action</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sbom-auditor-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The SBOM Auditor Action audits Software Bill of Materials (SBOM) for license compliance by fetching, enriching, and auditing the licenses against predefined policies. It generates a detailed report with AI-assisted summaries if enabled, helping organizations ensure their software dependencies comply with licensing terms. The action supports multiple AI providers like OpenAI, Azure OpenAI, AWS Bedrock, and GitHub.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>New release version v1.5.0</p>
]]></content:encoded></item><item><title>Multi-Device Website Screenshots CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/multi-device-website-screenshots-ci/</link><pubDate>Thu, 20 Aug 2026 14:13:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/multi-device-website-screenshots-ci/</guid><description>Version updated for https://github.com/Primajin/screenshots-ci-action to version v3.2.0.
This action is used across all versions by 6 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action captures screenshots of websites on both desktop and multiple emulated mobile devices within a CI/CD workflow. It supports various options such as specifying device names, excluding desktop shots, taking full-page screenshots, and controlling wait times before capturing images. The action outputs the screenshots as build artifacts, allowing for easy integration into pull-request comments or Telegram notifications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Primajin/screenshots-ci-action">https://github.com/Primajin/screenshots-ci-action</a></strong> to version <strong>v3.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/multi-device-website-screenshots-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action captures screenshots of websites on both desktop and multiple emulated mobile devices within a CI/CD workflow. It supports various options such as specifying device names, excluding desktop shots, taking full-page screenshots, and controlling wait times before capturing images. The action outputs the screenshots as build artifacts, allowing for easy integration into pull-request comments or Telegram notifications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="320-2026-08-20"><a href="https://github.com/Primajin/screenshots-ci-action/compare/v3.1.1...v3.2.0">3.2.0</a> (2026-08-20)</h2>
<h3 id="features">Features</h3>
<ul>
<li>run on the Node 24 (latest LTS) runtime (<a href="https://github.com/Primajin/screenshots-ci-action/commit/2e5fa4a89adc35d9edabd01354b362cabebb403b">2e5fa4a</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>resolve system Chrome for puppeteer v24 in CI (<a href="https://github.com/Primajin/screenshots-ci-action/commit/a79a6f29bcb51798fe35a4e7a979b9d2a7a0847a">a79a6f2</a>)</li>
</ul>
]]></content:encoded></item><item><title>wavedash-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/wavedash-action/</link><pubDate>Thu, 20 Aug 2026 14:12:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/wavedash-action/</guid><description>Version updated for https://github.com/remarkablegames/wavedash-action to version v1.1.2.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading and publishing web game files to the Wavedash platform. It can be configured to upload from a specific directory, specify an entrypoint file, inject the Wavedash SDK into an HTML file, and publish the build with optional release notes or changelog entries. The action also provides options for caching the Wavedash CLI and managing build configurations in a wavedash.toml file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablegames/wavedash-action">https://github.com/remarkablegames/wavedash-action</a></strong> to version <strong>v1.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wavedash-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading and publishing web game files to the Wavedash platform. It can be configured to upload from a specific directory, specify an entrypoint file, inject the Wavedash SDK into an HTML file, and publish the build with optional release notes or changelog entries. The action also provides options for caching the Wavedash CLI and managing build configurations in a <code>wavedash.toml</code> file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="112-2026-08-20"><a href="https://github.com/remarkablegames/wavedash-action/compare/v1.1.1...v1.1.2">1.1.2</a> (2026-08-20)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump @wvdsh/sdk-js from 1.3.44 to 1.3.45 (<a href="https://github.com/remarkablegames/wavedash-action/issues/16">#16</a>) (<a href="https://github.com/remarkablegames/wavedash-action/commit/de24dca16e6c023a5afb53e09fbbbdc61ceb96a5">de24dca</a>)</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/kaniko-build-action/</link><pubDate>Thu, 20 Aug 2026 14:11:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting to a specified name and logs the current time. It automates the process of adding friendly greetings in project repositories.
What’s Changed My first action is ready (5619594) Initial commit (2a56a2a)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting to a specified name and logs the current time. It automates the process of adding friendly greetings in project repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/custom-amazon-bedrock-agent-action/</link><pubDate>Thu, 20 Aug 2026 14:10:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action leverages Amazon Bedrock Agent to analyze files in a pull request (PR) using a tailored prompt. It integrates seamlessly with Amazon Bedrock Knowledge Bases, which enhances the analysis by providing enriched, context-aware insights. The action supports various programming languages and Terraform configurations, is customizable for specific needs, and integrates smoothly into GitHub workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action leverages Amazon Bedrock Agent to analyze files in a pull request (PR) using a tailored prompt. It integrates seamlessly with Amazon Bedrock Knowledge Bases, which enhances the analysis by providing enriched, context-aware insights. The action supports various programming languages and Terraform configurations, is customizable for specific needs, and integrates smoothly into GitHub workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/sherpa.sh/</link><pubDate>Thu, 20 Aug 2026 14:09:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven infrastructure-as-code tool that simplifies the deployment of web applications across various cloud providers. It allows developers to describe their application requirements in plain English, and Sherpa automatically configures and deploys the necessary infrastructure, including servers, databases, load balancers, CDN, and more. The tool supports multiple cloud platforms and frameworks, making it a versatile solution for developers looking to streamline deployment processes without needing extensive technical expertise.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven infrastructure-as-code tool that simplifies the deployment of web applications across various cloud providers. It allows developers to describe their application requirements in plain English, and Sherpa automatically configures and deploys the necessary infrastructure, including servers, databases, load balancers, CDN, and more. The tool supports multiple cloud platforms and frameworks, making it a versatile solution for developers looking to streamline deployment processes without needing extensive technical expertise.</p>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Thu, 20 Aug 2026 14:08:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service. It helps developers by executing npm ci and npm run bundle to prepare their project, then commits the resulting distribution folder to the repository before pushing it to a remote server or registry. This ensures that the build artifacts are correctly packaged and ready for deployment in a controlled manner.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service. It helps developers by executing <code>npm ci</code> and <code>npm run bundle</code> to prepare their project, then commits the resulting distribution folder to the repository before pushing it to a remote server or registry. This ensures that the build artifacts are correctly packaged and ready for deployment in a controlled manner.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/classroom-to-sheets-integration/</link><pubDate>Thu, 20 Aug 2026 14:08:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending assignment results from GitHub Classroom to Google Sheets. It integrates with the Google Sheets API using service account credentials and allows users to automatically update their grade sheets based on grading results in their GitHub classroom workflows. The action supports multiple tasks and can handle additional columns for detailed information, making it a versatile tool for educational institutions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending assignment results from GitHub Classroom to Google Sheets. It integrates with the Google Sheets API using service account credentials and allows users to automatically update their grade sheets based on grading results in their GitHub classroom workflows. The action supports multiple tasks and can handle additional columns for detailed information, making it a versatile tool for educational institutions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>auto-generate-release-note</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/auto-generate-release-note/</link><pubDate>Thu, 20 Aug 2026 14:07:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/auto-generate-release-note/</guid><description>Version updated for https://github.com/TakuKobayashi/auto-generate-release-note to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action uses a local Ollama model to generate release notes by summarizing Git history and diffs, supporting multiple languages including bilingual output with English. It compares the current tag with the previous semantic-version tag, generates Markdown from commits, changed files, and text diffs, and updates or creates a GitHub Release for tags that do not exist.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TakuKobayashi/auto-generate-release-note">https://github.com/TakuKobayashi/auto-generate-release-note</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auto-generate-release-note">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action uses a local Ollama model to generate release notes by summarizing Git history and diffs, supporting multiple languages including bilingual output with English. It compares the current tag with the previous semantic-version tag, generates Markdown from commits, changed files, and text diffs, and updates or creates a GitHub Release for tags that do not exist.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="release-notes-for-v102">Release Notes for v1.0.2</h2>
<h3 id="changes">Changes</h3>
<ul>
<li><strong>Action Renamed</strong>: The action has been renamed from <code>Ollama AI Release Notes</code> to <code>auto-generate-release-note</code>. This change affects the action&rsquo;s name in the GitHub marketplace and any references to it in workflows.</li>
</ul>
<h3 id="migration-notes">Migration Notes</h3>
<ul>
<li>If you are using this action in your GitHub workflows, you will need to update the action name from <code>Ollama AI Release Notes</code> to <code>auto-generate-release-note</code>.</li>
</ul>
<h3 id="fixes">Fixes</h3>
<ul>
<li>No specific fixes were included in this release.</li>
</ul>
<h3 id="important-internal-changes">Important Internal Changes</h3>
<ul>
<li>The package name and version in <code>package.json</code> have been updated to reflect the new action name and version.</li>
</ul>
]]></content:encoded></item><item><title>Advanced Jules PR Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/advanced-jules-pr-reviewer/</link><pubDate>Thu, 20 Aug 2026 14:06:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/advanced-jules-pr-reviewer/</guid><description>Version updated for https://github.com/thalesraymond/jules-pr-reviewer to version v1.7.0.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Google Jules to review pull requests in various programming languages. It provides inline comments directly on code lines with severity and confidence levels, automatically resolves resolved issues after fixes are pushed, and gates merges via a check run if configured. The action is extensible with custom rules and supports deduplication of findings across pushes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thalesraymond/jules-pr-reviewer">https://github.com/thalesraymond/jules-pr-reviewer</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/advanced-jules-pr-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Google Jules to review pull requests in various programming languages. It provides inline comments directly on code lines with severity and confidence levels, automatically resolves resolved issues after fixes are pushed, and gates merges via a check run if configured. The action is extensible with custom rules and supports deduplication of findings across pushes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="170-2026-08-20"><a href="https://github.com/thalesraymond/jules-pr-reviewer/compare/v1.6.0...v1.7.0">1.7.0</a> (2026-08-20)</h2>
<h3 id="features">Features</h3>
<ul>
<li>ignore-by-title/label/author filters and per-severity actions (<a href="https://github.com/thalesraymond/jules-pr-reviewer/issues/137">#137</a>) (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/e50c16aa28f5dbed248175127702730926ad5c4a">e50c16a</a>)</li>
<li>per-path review instructions via rules_directory (<a href="https://github.com/thalesraymond/jules-pr-reviewer/issues/138">#138</a>) (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/337fc00569394b475922d47a681bfee7435fec15">337fc00</a>)</li>
<li><strong>phase3:</strong> auto-approve clean verdicts and review evaluator harness (<a href="https://github.com/thalesraymond/jules-pr-reviewer/issues/145">#145</a>) (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/681f014ecb76cf6a81f1513373d109a9b1294dcd">681f014</a>)</li>
<li>strictness profiles (quiet / chill / assertive) (<a href="https://github.com/thalesraymond/jules-pr-reviewer/issues/139">#139</a>) (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/7204d7f69e995ea538956c7ad5f56c5908025632">7204d7f</a>)</li>
<li><strong>utils:</strong> add and integrate sleep utility (<a href="https://github.com/thalesraymond/jules-pr-reviewer/issues/135">#135</a>) (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/a72ecbf9d079b1c91e057c361e8fd3b9f6bd0cd7">a72ecbf</a>)</li>
<li>zero-config default pass (fail_on defaults to never) (<a href="https://github.com/thalesraymond/jules-pr-reviewer/issues/140">#140</a>) (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/dc89639c325543e401ea5789356e6dc4159b051c">dc89639</a>)</li>
</ul>
]]></content:encoded></item><item><title>setup-pawl</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/setup-pawl/</link><pubDate>Thu, 20 Aug 2026 14:05:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/setup-pawl/</guid><description>Version updated for https://github.com/tiangong-dev/pawl to version v0.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary pawl is a tool that helps developers automate regression testing by measuring and comparing various dimensions of their codebase. It measures key metrics such as file length, function complexity, coverage, and as any count to ensure that changes do not introduce regressions. If any dimension shows an improvement or no change, the action exits successfully; otherwise, it fails and alerts developers about potential regressions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tiangong-dev/pawl">https://github.com/tiangong-dev/pawl</a></strong> to version <strong>v0.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-pawl">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>pawl is a tool that helps developers automate regression testing by measuring and comparing various dimensions of their codebase. It measures key metrics such as file length, function complexity, coverage, and <code>as any</code> count to ensure that changes do not introduce regressions. If any dimension shows an improvement or no change, the action exits successfully; otherwise, it fails and alerts developers about potential regressions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changes-since-v071--npm-i--d-pawl-toolscli080">Changes since <code>v0.7.1</code> — <code>npm i -D @pawl-tools/cli@0.8.0</code></h2>
<p>Prebuilt binaries are attached below.</p>
<ul>
<li>chore: bump version to 0.8.0 (#34) (8f0502d)</li>
<li>feat: harden measurement provenance and agent workflows (#33) (f44d59e)</li>
<li>refactor!: rename <code>baseline-guard</code> to <code>guard</code> (#32) (718bc50)</li>
<li>feat!: replace <code>pawl agent-md</code> with <code>pawl agent</code>, which installs the block (#31) (ea518a7)</li>
<li>ci: have the release run say whether the Marketplace tick is needed (#30) (9b1768e)</li>
<li>ci: surface the manual Marketplace step in the release summary (#29) (6cd0541)</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/wails3-build-action/</link><pubDate>Thu, 20 Aug 2026 14:04:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building and packaging of Wails applications using GoLang, NodeJS, and pnpm. It installs the necessary dependencies, runs a build command, and optionally uploads the results to GitHub or releases on tagged builds. The action supports various build configurations, including platform selection, obfuscation, and caching.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building and packaging of Wails applications using GoLang, NodeJS, and pnpm. It installs the necessary dependencies, runs a build command, and optionally uploads the results to GitHub or releases on tagged builds. The action supports various build configurations, including platform selection, obfuscation, and caching.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Vaara Policy Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/vaara-policy-check/</link><pubDate>Thu, 20 Aug 2026 14:03:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/vaara-policy-check/</guid><description>Version updated for https://github.com/vaaraio/vaara to version v1.69.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of verifying and auditing receipts or verifiable outcomes generated by the Vaara tool. It helps in ensuring that every autonomous action is risk-scored, checked against policies, and recorded with tamper-evident evidence. The action facilitates secure verification of actions performed within a system, providing a verifiable receipt for any autonomous action taken.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaaraio/vaara">https://github.com/vaaraio/vaara</a></strong> to version <strong>v1.69.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vaara-policy-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of verifying and auditing receipts or verifiable outcomes generated by the Vaara tool. It helps in ensuring that every autonomous action is risk-scored, checked against policies, and recorded with tamper-evident evidence. The action facilitates secure verification of actions performed within a system, providing a verifiable receipt for any autonomous action taken.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1690---2026-08-20">[1.69.0] - 2026-08-20</h2>
<h3 id="added">Added</h3>
<ul>
<li>Declarative source profiles can detect on object keys. New <code>anyKeyStartsWith</code> operator tests whether the object at <code>path</code> carries any key with the given prefix. Every operator before this one read values only, and <code>resolve_path</code> splits on <code>.</code>, so a format whose discriminator is a URI-shaped key was impossible to express: the whole Security Event Token family (CAEP, RISC) and anything keyed by namespace URI. Implemented in the engine and in <code>tests/vectors/normalize_v0/_check_independent.py</code>, which reimplements the operators without importing Vaara, so a third party reproduces the same detection.</li>
<li><code>caep-security-event</code> source profile: OpenID CAEP Security Event Tokens ingest as <code>decision-input</code>. The detector pins the CAEP namespace, so a RISC event does not match. Per-event members sit under the event-type URI key and cannot be lifted into advisory yet; the profile says so in its notes rather than implying coverage it does not have.</li>
<li><code>attested-agent-payment-scope</code> source profile: the Authorization Scope of draft-hawkins-scitt-attested-agent-payment-01 Section 3 ingests as <code>decision-input</code>. Three vectors ship with it, one positive and two boundary cases. Dropping <code>expiry</code>, a required member of the Section 3 CDDL, drops the document out of detection and it seals as unrecognized. A scope carrying an aggregate bound with no <code>executor</code> is still recognized, because Section 3 makes <code>executor</code> REQUIRED only when <code>limits</code> carries an aggregate bound and the declarative detect grammar has no way to express a conditional requirement: rules are flat predicates over paths. Recognition by this profile is therefore not a conformance verdict on the scope, and the profile&rsquo;s notes say so. The scope is deterministic CBOR (RFC 8949 Section 4.2.1) and Section 3 computes the scope digest over exactly those bytes, so these vectors pin the field mapping and never the scope digest.</li>
<li><code>test_every_normalize_input_has_an_expected_entry</code> guards the normalize corpus against silent gaps. <code>_check_independent.py</code> iterates <code>expected.json</code> and loads the input each key names, so an input with no expected entry was never exercised while the suite still reported every case matched. The ingest corpus already had a guard of this shape; normalize did not, and 14 inputs sat against 13 entries.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>The <code>vaara.attestation-result/v0</code> document is named an unprotected claims set carrying the IETF RATS EAR claims, in the module, the CLI help, SPEC.md, README.md, PRIOR_ART.md and <code>docs/design/attestation-result-spec.md</code>. It was described as an EAR. It is neither an EAR nor an EAT: draft-ietf-rats-ear-04 defines two serializations, JWT in Section 3.2 and CWT in Section 3.3, and RFC 9711 Section 3 requires an EAT to have authenticity and integrity protection, while what is emitted is a keyless JSON map. The registered CBOR-side analogue is UCCS, RFC 9781; the JSON side has no registered term, the nearest reference being the unsecured JWT of RFC 7519 Section 6. Signing the claim set as a JWT or CWT would make it an EAR, and nothing in the shipped path does that. Wording only: the emitted document is byte-identical, the AR4SI vector, tier anchors and verifier claims are unchanged, and <code>tests/vectors/attestation_result_v0/_check_independent.py</code> reproduces all 12 appraisal results.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><code>grant_fingerprint</code> now hashes the grant&rsquo;s signing payload, with the signature excluded, through a new <code>signing_payload</code> in <code>vaara.credential._grant_emit</code> that <code>verify_grant_signature</code> also calls, so signature verification and grant identity come from one authority instead of two assemblies of the same shape. It previously hashed <code>credential.to_dict()</code>, which carries a <code>signature</code> member. That was deliberate, to pin the exact signed grant so a re-minted grant produced a different fingerprint, but ES256 is an accepted grant algorithm and neither <code>sign_es256</code> nor <code>verify_es256</code> constrains <code>s</code>, so one signing act has two valid encodings and produced two fingerprints for the same grant. The exposure runs opposite to the inference-digest case below: there, two byte-different receipts could claim one signing act; here, one act produced two identities, so a verifier recomputing the fingerprint from the grant it holds could fail to match a receipt for an authorization that did govern, and a false miss on identity reads as a tampering signal. The original intent survives the repair, because <code>asserted</code> carries <code>iss</code>, <code>sub</code> and <code>secretVersion</code> while <code>scope</code> and <code>binding</code> carry the rest, so a re-mint under a different key or a changed scope still moves the value and a malleated twin no longer does.</p>
<p><code>tests/vectors/authorization_v0/_check_independent.py</code> recomputed the old rule over the whole grant and agreed with the stored value, so the corpus kept passing while describing an implementation that no longer existed. The checker now excludes the signature, and the five vector suites carrying a <code>grantFingerprint</code> are regenerated. Found by applying Joel Hillier&rsquo;s generalisation of the rule to this tree, posted to the SCITT list 2026-08-20: repairing the identity rules you find is not sufficient, because a digest can carry a signature it never names, through an object someone else signed. The class was raised on the same list by Anton Sokolov, 2026-08-18.</p>
<p><strong>Compatibility:</strong> a <code>grantFingerprint</code> recorded before this change will not match one computed after it. Signature verification is unaffected and no signature is invalidated.</p>
</li>
<li>
<p><code>inference_receipt_digest</code> and <code>inference_attestation_digest</code> now hash the signed blocks, with the signature excluded, using the module&rsquo;s existing <code>_receipt_signing_payload</code> and <code>_attestation_signing_payload</code>. Both previously hashed the full wire bytes with the signature included, to pin every receipt byte-for-byte. An ES256 signature is not byte-unique for one signing act: given a valid <code>(r, s)</code> over P-256, <code>(r, n - s)</code> is also valid over the same payload and the same key, and <code>verify_es256</code> accepts it because it decodes the pair and re-encodes to DER. Measured against this implementation, 200 of 200 signatures produced a verifying twin. So the byte-for-byte pin was not achievable, and one signing act could yield two receipts that both verify and carry different identities, with the second producible in transit by anyone holding no key. Those digests are used as <code>receiptDigest</code> in the session manifest and <code>subject_receipt_digest</code> in the crosscheck. <code>vaara.audit.timeanchor._signed_payload_digest</code> has always hashed the signed payload, which is why <code>anchoredDigest</code> was never affected. Raised on the SCITT list by Anton Sokolov, 2026-08-18.</p>
<p><strong>Compatibility:</strong> a <code>receiptDigest</code> or attestation digest recorded before this change will not match one computed after it. Signature verification is unaffected and no signature is invalidated.</p>
</li>
<li>
<p>A lens that did not run now reports <code>ok</code> as null in the serialized evidence bundle, where it previously reported false. <code>verify_evidence_bundle</code> has always aggregated correctly, because a lens counts only when <code>applicable</code> is true, so an inapplicable lens never produced a failure. The serialization emitted <code>ok: false</code> beside <code>applicable: false</code>, which states a verdict on a check that never ran, and <code>ok</code> is the field whose name invites being read on its own. Raised on the IETF SCITT list on 2026-08-19 in the CHAP thread, where the working group is settling a NOT_EVALUATED state that is terminal and mutually exclusive with pass and fail; the argument was made there against Vaara&rsquo;s own committed expectations. The in-memory field stays a bool, so callers branching on it are unaffected and only the JSON crossing a trust boundary changes. Three places built that JSON by hand instead of going through <code>LensResult.to_dict</code>, which is how the vectors and the reference drifted, and all three now go through it.</p>
</li>
<li>
<p><code>detect_stacked_governance()</code> reports a second Vaara governance layer standing in front of the MCP proxy, with a new <code>--stacked {warn,fail,ignore}</code> defaulting to warn. The client hook in <code>src/vaara/integrations/claude_code_hooks.py</code> and the proxy are alternative interception points, and running both puts two decision points on one action: the hook decides every tool call the client makes, including MCP ones, and the proxy decides the same call again on the wire. Each MCP call then lands in the trail twice, under the namespaced name from the hook and the bare wire name from the proxy. The chain stays intact and every verifier passes, so nothing surfaced an error while the trail counted one action as two. Detection never changes what is recorded: under stdio the proxy owns the upstream server&rsquo;s process, so anything that can abort there takes the operator&rsquo;s MCP server down with it. Only PreToolUse counts, because PostToolUse reports an outcome for a call already decided. <code>docs/architecture.md</code> states the choice and what taking both costs.</p>
</li>
<li>
<p><code>load_trail</code> caps corrupt-row logging at 5 detail lines and then gives the exact total, and decodes BLOB values sitting in TEXT columns. It logged one ERROR line per corrupt row, and a trail damaged by an older writer holds every bad row at once, so one reload wrote about 4 MB into the transcript on a real trail with 19,417 bad rows. <code>trail.skeleton_records</code> still counts every affected row. The query path had the same defect with a longer reach: <code>_safe_row_to_record</code> logged once per bad row on every query for the life of the process, so its cap holds across the whole backend lifetime, the running total is available as <code>backend.corrupt_query_rows</code>, and per-row detail drops to DEBUG after the cap. A writer that bound bytes instead of str leaves TEXT columns holding BLOBs, those values reached the skeleton record unchanged, and <code>compute_hash</code> died on <code>json.dumps</code> of bytes, so <code>load_trail</code> raised TypeError on a trail it was meant to load with skeletons. <code>load_trail</code> now catches TypeError alongside the other row-level errors, so chain verification reports the damage instead of the load failing.</p>
</li>
<li>
<p><code>conformance_runner.py --with-vaara</code> grades <code>article12_fold_v0</code> where a Vaara install exists. That suite has always skipped in the aggregate run, so CI reported 42 of 43 on a corpus with nothing wrong with it: the suite validates a produced EU AI Act Article 12 regulator package rather than a bare case directory, and building that package needs Vaara installed, which the runner promises not to require. Bare is still 42 passed and 1 skipped, so the stranger path is untouched; with the flag it is 43 and 0.</p>
</li>
<li>
<p><code>scripts/vcr_chain.py</code> says where the published rows live. It is what the results page tells a reader to verify with, and a checkout of main ships <code>conformance/reproductions.json</code> empty by design, because rows arrive by issue form onto the unprotected <code>vcr</code> branch. The published page therefore listed a row while the script printed <code>0 row(s), chain intact</code>, and the honest conclusion available to a stranger was that the tool was lying.</p>
</li>
<li>
<p>The conformance desk answers a submission. Its workflow was guarded on a <code>conformance-row</code> label that did not exist in the repository, so the issue form&rsquo;s declared label was dropped and the job skipped in silence, which is why the first self-service application got no response. The job now also triggers on the form&rsquo;s title prefix, and every run is still validated by <code>scripts/vcr_row.py</code>, so a wrong trigger costs a comment instead of a bad row. The desk&rsquo;s final step dispatches <code>pages.yml</code> so the row it published is served, which needs <code>actions: write</code>; without it the dispatch returned 403, and the first row landed on the <code>vcr</code> branch while the submitter held badge URLs that 404ed until the site was rebuilt by hand.</p>
</li>
<li>
<p>The conformance badge carries white on <code>#4A6E5C</code> at 5.71:1. The message side was brand green <code>#78A08A</code> with dark text, where white measures 2.92:1 and fails WCAG AA at this size, and dark text read as inverted beside every other shield in a README row. Brand green stays in the mark, where nothing is read off it. The corpus shield now reports failures instead of passes: it read &ldquo;43 suites, 42 passing&rdquo;, which invites a reader to assume one suite is broken on the maintainer&rsquo;s own README, and nothing fails.</p>
</li>
<li>
<p>The container image builds when the version tag is pushed. <code>container.yml</code> listened for a published release, so ghcr held no versioned image and no <code>latest</code> at all. This release is the first to exercise the repaired trigger.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Vigilnz Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/vigilnz-security-scan/</link><pubDate>Thu, 20 Aug 2026 14:02:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/vigilnz-security-scan/</guid><description>Version updated for https://github.com/Vigilnz/vigilnz-scan-action to version v1.3.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Vigilnz Security Scan Action automates security scanning of applications and repositories during CI/CD pipelines using Vigilnz services. It supports multiple scan types such as SCA, SBOM, SAST, IAC SCAN, SECRET SCAN, DAST, and CONTAINER SCAN. The action integrates with GitHub workflows and requires an API key for authentication, which is stored securely in GitHub Secrets. Users can specify the scan types and project name to run the scans.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Vigilnz/vigilnz-scan-action">https://github.com/Vigilnz/vigilnz-scan-action</a></strong> to version <strong>v1.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vigilnz-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Vigilnz Security Scan Action automates security scanning of applications and repositories during CI/CD pipelines using Vigilnz services. It supports multiple scan types such as SCA, SBOM, SAST, IAC SCAN, SECRET SCAN, DAST, and CONTAINER SCAN. The action integrates with GitHub workflows and requires an API key for authentication, which is stored securely in GitHub Secrets. Users can specify the scan types and project name to run the scans.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Changed enviroment value to production default</p>
]]></content:encoded></item><item><title>AI Changelog Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/ai-changelog-updater/</link><pubDate>Thu, 20 Aug 2026 14:01:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/ai-changelog-updater/</guid><description>Version updated for https://github.com/vscheuber/ai-changelog-action to version v1.1.11.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The AI Changelog Updater is a GitHub Action that automates updating the ## Unreleased section of a CHANGELOG.md file by using an LLM. It gathers changes from Git history, merged pull requests, and optional related repositories to generate a user-focused changelog entry while preserving existing content. The action also supports handling full releases by consolidating pre-release notes into the final stable version’s changelog.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vscheuber/ai-changelog-action">https://github.com/vscheuber/ai-changelog-action</a></strong> to version <strong>v1.1.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-changelog-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The AI Changelog Updater is a GitHub Action that automates updating the <code>## Unreleased</code> section of a CHANGELOG.md file by using an LLM. It gathers changes from Git history, merged pull requests, and optional related repositories to generate a user-focused changelog entry while preserving existing content. The action also supports handling full releases by consolidating pre-release notes into the final stable version&rsquo;s changelog.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>Improved handling of changelog entries to prevent duplication of developer-written &ldquo;Unreleased&rdquo; entries with reworded LLM output. This enhancement ensures that manually written entries are preserved without unnecessary repetition. (commit 29a5ed3)</li>
</ul>
]]></content:encoded></item><item><title>PokeRepo Dex</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/pokerepo-dex/</link><pubDate>Thu, 20 Aug 2026 14:00:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/pokerepo-dex/</guid><description>Version updated for https://github.com/wantaekchoi/pokerepo to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically updates a Pokémon-themed card on user’s repository READMEs, tracking their Pokémon level and adding them to the Pokémon Dex through commits and merged pull requests. The action is configured by modifying a simple line in the repository’s README and includes options for scheduling and manual triggering.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wantaekchoi/pokerepo">https://github.com/wantaekchoi/pokerepo</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pokerepo-dex">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically updates a Pokémon-themed card on user&rsquo;s repository READMEs, tracking their Pokémon level and adding them to the Pokémon Dex through commits and merged pull requests. The action is configured by modifying a simple line in the repository&rsquo;s README and includes options for scheduling and manual triggering.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release.</p>
<p>One Pokémon per repository. Commits level it up, merged pull requests add it to your Dex.</p>
<p>A fork is a Dex <em>seen</em>; a merged pull request is <em>caught</em>. Commits and merges are worth more where you do not own the repository, because a merge is someone else accepting the work. Stars on the upstream decide rarity.</p>
<p>Setup is four steps in the <a href="https://github.com/wantaekchoi/pokerepo#setup">README</a>. Reference <code>wantaekchoi/pokerepo@v1</code> to follow the major version, or <code>@v1.0.0</code> to pin.</p>
<p>Species data, experience curves and sprite addresses come from <a href="https://pokeapi.co">PokéAPI</a> under BSD-3-Clause. No Pokémon artwork is stored in this repository or its releases.</p>
<p>Unofficial, non-commercial fan project. Not affiliated with or endorsed by Nintendo, Game Freak, Creatures Inc. or The Pokémon Company.</p>
]]></content:encoded></item><item><title>Container Build Flow Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/container-build-flow-action/</link><pubDate>Thu, 20 Aug 2026 13:59:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/container-build-flow-action/</guid><description>Version updated for https://github.com/wgtechlabs/container-build-flow-action to version v1.9.0.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates container builds with intelligent tagging for Docker Hub and GitHub Container Registry based on the workflow context (PR, dev, patch, or WIP). It handles branch detection, tagging, building, and PR comments automatically without requiring manual configuration. The action supports dual registry support, smart tagging strategies, and integrates security features such as SBOMs and vulnerability scanning with Trivy.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wgtechlabs/container-build-flow-action">https://github.com/wgtechlabs/container-build-flow-action</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/container-build-flow-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates container builds with intelligent tagging for Docker Hub and GitHub Container Registry based on the workflow context (PR, dev, patch, or WIP). It handles branch detection, tagging, building, and PR comments automatically without requiring manual configuration. The action supports dual registry support, smart tagging strategies, and integrates security features such as SBOMs and vulnerability scanning with Trivy.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="190---2026-08-20">[1.9.0] - 2026-08-20</h2>
<h3 id="added">Added</h3>
<ul>
<li>add planned registry publishing (#54)</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>support planned manual releases (#56)</li>
<li>join image tags with real newline</li>
</ul>
]]></content:encoded></item><item><title>Package Build Flow Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/package-build-flow-action/</link><pubDate>Thu, 20 Aug 2026 13:58:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/package-build-flow-action/</guid><description>Version updated for https://github.com/wgtechlabs/package-build-flow-action to version v2.2.0.
This action is used across all versions by 9 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Package Build Flow Action automates JavaScript package versioning, building, and publishing using intelligent flow detection. It supports dual registry support, monorepo processing, auto-scoping, smart versioning, security scanning, PR comments, dist-tag management, bot-safe validation, and zero configuration setup. The action automatically determines build type based on GitHub context and provides various features for managing package versions and publishing them to NPM Registry and/or GitHub Packages.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wgtechlabs/package-build-flow-action">https://github.com/wgtechlabs/package-build-flow-action</a></strong> to version <strong>v2.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>9</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/package-build-flow-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Package Build Flow Action automates JavaScript package versioning, building, and publishing using intelligent flow detection. It supports dual registry support, monorepo processing, auto-scoping, smart versioning, security scanning, PR comments, dist-tag management, bot-safe validation, and zero configuration setup. The action automatically determines build type based on GitHub context and provides various features for managing package versions and publishing them to NPM Registry and/or GitHub Packages.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="220---2026-08-20">[2.2.0] - 2026-08-20</h2>
<h3 id="added">Added</h3>
<ul>
<li>add planned package publishing (#41)</li>
<li>add planned release publishing (#39)</li>
</ul>
]]></content:encoded></item><item><title>Release Build Flow Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/release-build-flow-action/</link><pubDate>Thu, 20 Aug 2026 13:57:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/release-build-flow-action/</guid><description>Version updated for https://github.com/wgtechlabs/release-build-flow-action to version v1.8.0.
This action is used across all versions by 13 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of creating releases and maintaining a changelog based on commit history, supporting both Clean Commit and Conventional Commit conventions. It automatically detects semantic version bumps, generates and syncs changelogs, updates manifest versions, commits changes, creates release tags, and publishes GitHub Releases. The action supports per-package and unified monorepo workflows with optional changelog commits back to the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wgtechlabs/release-build-flow-action">https://github.com/wgtechlabs/release-build-flow-action</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>13</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/release-build-flow-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of creating releases and maintaining a changelog based on commit history, supporting both Clean Commit and Conventional Commit conventions. It automatically detects semantic version bumps, generates and syncs changelogs, updates manifest versions, commits changes, creates release tags, and publishes GitHub Releases. The action supports per-package and unified monorepo workflows with optional changelog commits back to the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="180---2026-08-20">[1.8.0] - 2026-08-20</h2>
<h3 id="added">Added</h3>
<ul>
<li>add immutable planned release inputs (#31)</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>accept compatible planned release plans (#33)</li>
<li>fail fast on prerelease prefix with planned inputs</li>
</ul>
]]></content:encoded></item><item><title>install spaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/install-spaces/</link><pubDate>Thu, 20 Aug 2026 13:56:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/install-spaces/</guid><description>Version updated for https://github.com/work-spaces/install-spaces to version v0.21.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The install-spaces GitHub action automates the installation of spaces (a project management tool) on a specified host. It simplifies the setup process by handling dependencies, configurations, and permissions automatically, ensuring a smooth installation experience for developers using Spaces in their projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/install-spaces">https://github.com/work-spaces/install-spaces</a></strong> to version <strong>v0.21.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-spaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>install-spaces</code> GitHub action automates the installation of spaces (a project management tool) on a specified host. It simplifies the setup process by handling dependencies, configurations, and permissions automatically, ensuring a smooth installation experience for developers using Spaces in their projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.21.0 by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/46">https://github.com/work-spaces/install-spaces/pull/46</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/install-spaces/compare/v0.20.9...v0.21.0">https://github.com/work-spaces/install-spaces/compare/v0.20.9...v0.21.0</a></p>
]]></content:encoded></item><item><title>spaces checkout run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/spaces-checkout-run/</link><pubDate>Thu, 20 Aug 2026 13:55:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/spaces-checkout-run/</guid><description>Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.21.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the checkout and execution of a workspace using the spaces CLI, which is useful for managing multiple development environments within a project. It simplifies the setup process by handling the installation and configuration of the CLI, allowing users to focus on running their workspaces directly from their workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/spaces-checkout-run">https://github.com/work-spaces/spaces-checkout-run</a></strong> to version <strong>v0.21.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spaces-checkout-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the checkout and execution of a workspace using the spaces CLI, which is useful for managing multiple development environments within a project. It simplifies the setup process by handling the installation and configuration of the CLI, allowing users to focus on running their workspaces directly from their workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.21.0 by @tyler-gilbert in <a href="https://github.com/work-spaces/spaces-checkout-run/pull/39">https://github.com/work-spaces/spaces-checkout-run/pull/39</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/spaces-checkout-run/compare/v0.20.9...v0.21.0">https://github.com/work-spaces/spaces-checkout-run/compare/v0.20.9...v0.21.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/b.ia-accessibility-checker/</link><pubDate>Thu, 20 Aug 2026 13:55:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines, enabling companies to ensure their code meets WCAG standards. By defining audiences and percentage requirements, it helps companies focus on specific user groups and improves product accessibility without the need for external tools. The action uses AI for abstract guideline analysis, providing feedback to developers if their code does not meet accessibility standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines, enabling companies to ensure their code meets WCAG standards. By defining audiences and percentage requirements, it helps companies focus on specific user groups and improves product accessibility without the need for external tools. The action uses AI for abstract guideline analysis, providing feedback to developers if their code does not meet accessibility standards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>kramlipi CI Repair</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/kramlipi-ci-repair/</link><pubDate>Thu, 20 Aug 2026 06:41:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/kramlipi-ci-repair/</guid><description>Version updated for https://github.com/kramlipi/code-agent-action to version v0.1.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The kramlipi CI Repair GitHub Action automates Continuous Integration (CI) and Code Review processes by using a combination of automatic testing, inline reviews, and test selection based on pull request diffs. It helps developers catch issues early in the development cycle, reduce PR review backlog, and optimize test execution for small changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kramlipi/code-agent-action">https://github.com/kramlipi/code-agent-action</a></strong> to version <strong>v0.1.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kramlipi-ci-repair">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>kramlipi CI Repair</code> GitHub Action automates Continuous Integration (CI) and Code Review processes by using a combination of automatic testing, inline reviews, and test selection based on pull request diffs. It helps developers catch issues early in the development cycle, reduce PR review backlog, and optimize test execution for small changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="kramlipi-ci-repair-v017">kramlipi CI Repair v0.1.7</h2>
<p>Verify-gated CI repair for GitHub Actions.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">kramlipi/code-agent-action@v0.1.7</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">expert</span>: <span style="color:#ae81ff">bug-fix</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">verify-cmd</span>: <span style="color:#ae81ff">pytest -q</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">publish</span>: <span style="color:#66d9ef">true</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">GEMINI_API_KEY</span>: <span style="color:#ae81ff">${{ secrets.GEMINI_API_KEY }}</span>
</span></span></code></pre></div><p><strong>To list on GitHub Marketplace:</strong> edit this release â†’ check <strong>Publish this Action to the GitHub Marketplace</strong> â†’ Publish (requires 2FA on the kramlipi account).</p>
<p>Docs: <a href="https://kramlipi.github.io/">https://kramlipi.github.io/</a></p>
]]></content:encoded></item><item><title>AI Commit Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/ai-commit-review/</link><pubDate>Thu, 20 Aug 2026 06:40:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/ai-commit-review/</guid><description>Version updated for https://github.com/leek/ai-commit-review to version v1.3.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action reviews a single commit with Claude, GPT, Agy (Gemini), and Grok to identify issues. It deduplicates findings, files them as a GitHub Issue, and optionally opens a draft PR with high-confidence fixes that multiple models agree on. The action is triggered by pushes to a branch, enumerates SHAs, and runs one job per commit in a matrix strategy to ensure independent reviews even if some fail.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/leek/ai-commit-review">https://github.com/leek/ai-commit-review</a></strong> to version <strong>v1.3.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-commit-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action reviews a single commit with Claude, GPT, Agy (Gemini), and Grok to identify issues. It deduplicates findings, files them as a GitHub Issue, and optionally opens a draft PR with high-confidence fixes that multiple models agree on. The action is triggered by pushes to a branch, enumerates SHAs, and runs one job per commit in a matrix strategy to ensure independent reviews even if some fail.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What’s changed</h2>
<ul>
<li>Seed Agy credentials into <code>~/.gemini/antigravity-cli/jetski-standalone-oauth-token</code> (the CLI app data dir), not only <code>~/.gemini/</code>.</li>
<li>Keep both the Keychain <code>{token, auth_method}</code> wrapper and the inner oauth2 token on disk.</li>
<li>Point D-Bus at a non-existent socket so Linux runners cannot silently use an empty system keyring.</li>
<li>Pass <code>JETSKI_OAUTH_TOKEN</code> / <code>JETSKI_APP_DATA_DIR</code>, and dump Agy&rsquo;s internal auth log lines if login still fails.</li>
</ul>
]]></content:encoded></item><item><title>Hardware Bill of Materials</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/hardware-bill-of-materials/</link><pubDate>Thu, 20 Aug 2026 06:39:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/hardware-bill-of-materials/</guid><description>Version updated for https://github.com/lfreleng-actions/hw-bom-javascript to version v0.1.6.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action collects detailed hardware information from cloud provider instances and makes it available as workflow outputs. It is useful for documenting hardware specifications in CI/CD pipelines, validating instance types and hardware capabilities, and generating hardware inventory reports. The action supports AWS, Azure (Github Actions), GCE, and OpenStack providers and provides comprehensive hardware information such as CPU, GPU, memory, and disk details.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lfreleng-actions/hw-bom-javascript">https://github.com/lfreleng-actions/hw-bom-javascript</a></strong> to version <strong>v0.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hardware-bill-of-materials">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action collects detailed hardware information from cloud provider instances and makes it available as workflow outputs. It is useful for documenting hardware specifications in CI/CD pipelines, validating instance types and hardware capabilities, and generating hardware inventory reports. The action supports AWS, Azure (Github Actions), GCE, and OpenStack providers and provides comprehensive hardware information such as CPU, GPU, memory, and disk details.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><a href="https://github.com/lfreleng-actions/hw-bom-javascript/releases/tag/v0.1.6"><img src="https://img.shields.io/github/downloads/lfreleng-actions/hw-bom-javascript/v0.1.6/total.svg" alt="Downloads for this release"></a></p>
<h2 id="-maintenance-">🔧 Maintenance 🔧</h2>
<ul>
<li>Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.10.0 to 0.10.1 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#274)</li>
<li>Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#272)</li>
<li>Chore: Bump @types/node from 26.1.2 to 26.2.0 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#273)</li>
<li>Chore: Bump eslint-plugin-jest from 29.16.0 to 29.16.1 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#275)</li>
<li>Chore: pre-commit autoupdate @<a href="https://github.com/apps/pre-commit-ci">pre-commit-ci[bot]</a> (#276)</li>
<li>Chore: Bump @typescript-eslint/parser from 8.66.0 to 8.67.0 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#277)</li>
<li>Chore: Bump @typescript-eslint/eslint-plugin from 8.66.0 to 8.67.0 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#278)</li>
<li>Chore: Bump globals from 17.9.0 to 17.10.0 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#279)</li>
<li>Chore: Mark GCP metadata URL as intentional @ModeSevenIndustrialSolutions (#280)</li>
</ul>
<h2 id="links">Links</h2>
<ul>
<li><a href="https://github.com/lfreleng-actions/hw-bom-javascript/issues">Submit bugs/feature requests</a></li>
</ul>
]]></content:encoded></item><item><title>Rust Release Matrix</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/rust-release-matrix/</link><pubDate>Thu, 20 Aug 2026 06:38:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/rust-release-matrix/</guid><description>Version updated for https://github.com/lite-actions/rust-release to version v1.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of building, testing, and packaging Rust projects across multiple platforms and architectures. It provides a reusable workflow that generates a dynamic build matrix and fans out over it to run tests and package binaries for each combination. Users can specify optional parameters such as the Rust version, platforms, architectures, binary name, release notes file, and whether to upload zips to GitHub Releases when run on tags. The action uses native runners for each platform and architecture combination to ensure compatibility without cross-compilation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lite-actions/rust-release">https://github.com/lite-actions/rust-release</a></strong> to version <strong>v1.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rust-release-matrix">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of building, testing, and packaging Rust projects across multiple platforms and architectures. It provides a reusable workflow that generates a dynamic build matrix and fans out over it to run tests and package binaries for each combination. Users can specify optional parameters such as the Rust version, platforms, architectures, binary name, release notes file, and whether to upload zips to GitHub Releases when run on tags. The action uses native runners for each platform and architecture combination to ensure compatibility without cross-compilation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci: fix the changelog automation, adopt git-checkout, normalise org refs by @mrdoodles in <a href="https://github.com/lite-actions/rust-release/pull/3">https://github.com/lite-actions/rust-release/pull/3</a></li>
<li>docs(changelog): update changelog and release notes by @mrdoodles in <a href="https://github.com/lite-actions/rust-release/pull/4">https://github.com/lite-actions/rust-release/pull/4</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/lite-actions/rust-release/compare/v1.1.1...v1.12">https://github.com/lite-actions/rust-release/compare/v1.1.1...v1.12</a></p>
]]></content:encoded></item><item><title>Blueprint Pudim Code Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/blueprint-pudim-code-reviewer/</link><pubDate>Thu, 20 Aug 2026 06:37:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/blueprint-pudim-code-reviewer/</guid><description>Version updated for https://github.com/luismr/blueprint-pudim-code-reviewer to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action blueprint-pudim-code-reviewer automates the process of reviewing pull request diffs using a swappable language model backend via LangGraph/LangChain’s model abstraction. It supports three LLM providers: Anthropic, OpenAI, and Gemini, allowing users to choose their preferred model for code reviews. The action integrates with GitHub workflows, enabling developers to integrate AI-based code review into their CI/CD processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/luismr/blueprint-pudim-code-reviewer">https://github.com/luismr/blueprint-pudim-code-reviewer</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/blueprint-pudim-code-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>blueprint-pudim-code-reviewer</code> automates the process of reviewing pull request diffs using a swappable language model backend via LangGraph/LangChain&rsquo;s model abstraction. It supports three LLM providers: Anthropic, OpenAI, and Gemini, allowing users to choose their preferred model for code reviews. The action integrates with GitHub workflows, enabling developers to integrate AI-based code review into their CI/CD processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixed">Fixed</h2>
<ul>
<li><strong>Raw JSON posted as review comment when LLM emits trailing commas</strong> — some models occasionally append a trailing comma after the last field of an inline comment object (e.g. <code>&quot;body&quot;: &quot;...&quot;,\n}</code>), which is invalid JSON and causes <code>json.loads</code> to raise <code>JSONDecodeError</code>. <code>parse_review_output</code> then returns <code>None</code> and the full raw JSON blob is posted as an issue comment instead of a structured review. A <code>_sanitize_json</code> step now strips trailing commas before parsing so well-formed reviews are never silently discarded.</li>
</ul>
]]></content:encoded></item><item><title>Slackalaka</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/slackalaka/</link><pubDate>Thu, 20 Aug 2026 06:35:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/slackalaka/</guid><description>Version updated for https://github.com/mallowigi/tag-n-slack to version 0.2.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automatically creates a new tag with a changelog from either the CHANGELOG.md file or the commit hash and message. It then notifies Slack about the release by sending a message with an emoji next to the Slack message, project name, version, and ticket information (if applicable). The action supports two strategies for determining the version: using the version from package.json and the changelog in CHANGELOG.md, or using the merge commit’s hash and message.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mallowigi/tag-n-slack">https://github.com/mallowigi/tag-n-slack</a></strong> to version <strong>0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/slackalaka">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action automatically creates a new tag with a changelog from either the <code>CHANGELOG.md</code> file or the commit hash and message. It then notifies Slack about the release by sending a message with an emoji next to the Slack message, project name, version, and ticket information (if applicable). The action supports two strategies for determining the version: using the version from <code>package.json</code> and the changelog in <code>CHANGELOG.md</code>, or using the merge commit&rsquo;s hash and message.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Truncate changelog content before subversion headers during parsing (4cba572)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (d48462d)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (e8cca16)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (0998ab2)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (74b7ec6)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (995b49e)</li>
<li>Add watch mode and enhance error handling for <code>findPackageJson</code> (58f570c)</li>
<li>Add watch mode and enhance error handling for <code>findPackageJson</code> (0a6a3ea)</li>
<li>Add watch mode and enhance error handling for <code>findPackageJson</code> (d616c7f)</li>
<li>Migrate codebase and dependencies to ES modules. (bd554c2)</li>
</ul>
]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Thu, 20 Aug 2026 06:34:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.9.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of running test suites in a ServiceNow environment using different browsers and operating systems. It simplifies the setup by requiring only necessary credentials and instance URLs to be configured as secrets, reducing the need for manual configuration steps. The action provides flexibility through customizable inputs for browser name, version, OS, and test suite details, making it suitable for various development environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of running test suites in a ServiceNow environment using different browsers and operating systems. It simplifies the setup by requiring only necessary credentials and instance URLs to be configured as secrets, reducing the need for manual configuration steps. The action provides flexibility through customizable inputs for browser name, version, OS, and test suite details, making it suitable for various development environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.8...1.0.9">https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.8...1.0.9</a></p>
]]></content:encoded></item><item><title>Kiro CLI Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/kiro-cli-action/</link><pubDate>Thu, 20 Aug 2026 06:33:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/kiro-cli-action/</guid><description>Version updated for https://github.com/ndmxjp/Kiro-action to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Kiro Action automates interaction with the Kiro CLI on GitHub issues and pull requests by detecting comments containing the @kiro trigger phrase. It reads threads, creates branches or checks out PRs, builds prompts based on the entire thread, and either answers questions or implements features through the Kiro CLI. The action supports tag mode for human-triggered interactions and agent mode for scheduled tasks or labeled actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ndmxjp/Kiro-action">https://github.com/ndmxjp/Kiro-action</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kiro-cli-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Kiro Action automates interaction with the Kiro CLI on GitHub issues and pull requests by detecting comments containing the <code>@kiro</code> trigger phrase. It reads threads, creates branches or checks out PRs, builds prompts based on the entire thread, and either answers questions or implements features through the Kiro CLI. The action supports tag mode for human-triggered interactions and agent mode for scheduled tasks or labeled actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Run the <a href="https://kiro.dev">Kiro CLI</a> on GitHub issues and pull requests. Mention <code>@kiro</code> in a comment and it reads the thread, works in a branch, and reports back by editing a single tracking comment.</p>
<blockquote>
<p>[!IMPORTANT]
<strong>Unofficial community project.</strong> Not affiliated with, sponsored by, or endorsed by Amazon Web Services. &ldquo;Kiro&rdquo; and &ldquo;Amazon Web Services&rdquo; are trademarks of Amazon.com, Inc. or its affiliates. This is a port of <a href="https://github.com/anthropics/claude-code-action">anthropics/claude-code-action</a> (MIT) to the Kiro CLI. The Kiro project publishes its own action at <a href="https://github.com/kirodotdev-labs/kiro-action">kirodotdev-labs/kiro-action</a>; if you want the one closest to the Kiro project, use that.</p>
</blockquote>
<h2 id="quick-start">Quick start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v7</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fetch-depth</span>: <span style="color:#ae81ff">0</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">ndmxjp/Kiro-action@v0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">kiro_api_key</span>: <span style="color:#ae81ff">${{ secrets.KIRO_API_KEY }}</span>
</span></span></code></pre></div><p>See the <a href="https://github.com/ndmxjp/Kiro-action#readme">README</a> for the full workflow, including the <code>if:</code> gate you want on a public repository.</p>
<h2 id="what-this-port-carries-over">What this port carries over</h2>
<p>The limits were measured against kiro-cli 2.18.1 rather than assumed — <code>.github/workflows/kiro-perm-probe.yml</code> runs the CLI across a matrix of configurations, and <a href="https://github.com/ndmxjp/Kiro-action/blob/v0.2.0/docs/security.md">docs/security.md</a> records what each one permits.</p>
<ul>
<li>Only actors with write access can trigger a run; bots need to be listed explicitly.</li>
<li>Comment and issue content is pinned to trigger time, then stripped of hidden-instruction channels.</li>
<li>On a pull request, config the CLI executes (<code>.kiro/</code>, <code>.mcp.json</code>, <code>AGENTS.md</code>, <code>.gitmodules</code>, <code>.husky/</code>, …) is restored from the base branch, so a PR cannot introduce hooks or MCP servers that run in the job.</li>
<li>The agent&rsquo;s shell is limited to named commands (read-only git by default) and its writes are confined to the checkout. <code>git push</code>, <code>git config</code>, <code>curl</code> and friends are refused, and the action does the committing and pushing itself.</li>
</ul>
<h2 id="since-v010">Since v0.1.0</h2>
<ul>
<li>New <code>working_indicator</code> input: the &ldquo;Kiro is working…&rdquo; line can carry an animated image of your own instead of the emoji.</li>
<li>Fixed: the tracking comment was sanitised but never redacted, so a Kiro key (<code>ksk_</code>) or the literal value of a secret in the run&rsquo;s environment could reach a comment that, on a public repository, anyone can read.</li>
<li>Fixed: the write policy confined <code>fs_write</code> to <code>./**</code> while the prompt asks the agent to leave its commit message under <code>$RUNNER_TEMP</code>, so runs fell back to a generated commit subject.</li>
<li>The workflow gate in the README and examples now names the trigger label, drops <code>assigned</code>, and filters bot authors before a runner starts.</li>
<li>Pinned action versions moved to current majors.</li>
</ul>
<h2 id="requirements">Requirements</h2>
<ul>
<li>A Kiro API key (<code>KIRO_API_KEY</code>).</li>
<li>A runner with network access: the action installs Bun and the Kiro CLI, resolves its own dependencies, and the CLI then talks to the Kiro service.</li>
<li><code>actions/checkout</code> with <code>fetch-depth: 0</code> is recommended so diffs against the base branch work.</li>
</ul>
<h2 id="known-gaps">Known gaps</h2>
<p>No commit signing, no inline PR review comments, and the agent cannot run your test suite unless you grant it with <code>allowed_shell_commands</code>. All of them, and the reasoning, are in <a href="https://github.com/ndmxjp/Kiro-action/blob/v0.2.0/docs/security.md#known-gaps">docs/security.md</a>.</p>
<p>MIT licensed. Derived from <a href="https://github.com/anthropics/claude-code-action">anthropics/claude-code-action</a>, also MIT.</p>
]]></content:encoded></item><item><title>AntigravityCI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/antigravityci/</link><pubDate>Thu, 20 Aug 2026 06:32:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/antigravityci/</guid><description>Version updated for https://github.com/nivinvysakh/AntigravityCi to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: AntigravityCI is an AI-powered PR assistant that automates the process of refactoring and improving code changes in GitHub Pull Requests. It uses Google Gemini models to analyze diffs, generate improved code snippets, and open pull requests with committed changes. The action supports various commands for different types of changes and provides features like fast execution times, built-in security checks, and branch isolation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nivinvysakh/AntigravityCi">https://github.com/nivinvysakh/AntigravityCi</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/antigravityci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> AntigravityCI is an AI-powered PR assistant that automates the process of refactoring and improving code changes in GitHub Pull Requests. It uses Google Gemini models to analyze diffs, generate improved code snippets, and open pull requests with committed changes. The action supports various commands for different types of changes and provides features like fast execution times, built-in security checks, and branch isolation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-antigravityci-v110">🌌 AntigravityCI v1.1.0</h1>
<p>Release <strong>v1.1.0</strong> brings workflow refinements, automated dependency maintenance, and full community contribution templates!</p>
<h3 id="-whats-new">✨ What&rsquo;s New:</h3>
<ul>
<li>🧹 <strong>Minimal Workflow Template</strong>: Streamlined <code>.github/workflows/antigravityci.yml</code> with clean, modern syntax and zero comment clutter.</li>
<li>🤖 <strong>Dependabot Integration</strong>: Automated weekly dependency tracking for GitHub Actions, Python (<code>pip</code>), and Docker.</li>
<li>📋 <strong>Community &amp; Contribution Standards</strong>: Added issue templates, PR template, Code of Conduct, Contributing Guide, and Security Policy.</li>
<li>⚡ <strong>Cleaner Action Logs</strong>: Resolved deprecated action inputs and silenced internal SDK notices for crystal-clear execution logs.</li>
<li>📖 <strong>Documentation Polish</strong>: Improved Quick Start guide with clear secret setup reminders and clean Markdown tables.</li>
</ul>
<h3 id="-quick-start">🚀 Quick Start:</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">nivinvysakh/AntigravityCi@v1.1.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">github_token</span>: <span style="color:#ae81ff">${{ secrets.GITHUB_TOKEN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">gemini_api_key</span>: <span style="color:#ae81ff">${{ secrets.GEMINI_API_KEY }}</span>
</span></span></code></pre></div><p>👉 See the full setup guide in the <a href="https://github.com/nivinvysakh/AntigravityCi">readme</a></p>
]]></content:encoded></item><item><title>vord Static Analysis</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/vord-static-analysis/</link><pubDate>Thu, 20 Aug 2026 06:31:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/vord-static-analysis/</guid><description>Version updated for https://github.com/pmaojo/vord to version v0.13.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The vord action is a static analysis tool written in Rust that helps developers catch potential errors before they are committed to version control. It automatically analyzes code in real-time, ensuring that AI-generated content adheres to certain coding standards and best practices. The action can be installed as a CLI or integrated with CI systems like GitHub Actions and GitLab CI, making it easy for teams to enforce consistent coding standards across their repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pmaojo/vord">https://github.com/pmaojo/vord</a></strong> to version <strong>v0.13.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vord-static-analysis">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The vord action is a static analysis tool written in Rust that helps developers catch potential errors before they are committed to version control. It automatically analyzes code in real-time, ensuring that AI-generated content adheres to certain coding standards and best practices. The action can be installed as a CLI or integrated with CI systems like GitHub Actions and GitLab CI, making it easy for teams to enforce consistent coding standards across their repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add cfg, mutation, and vite-react rulesets; update documentation by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/184">https://github.com/pmaojo/vord/pull/184</a></li>
<li>Add 50+ new rules across Python, Rust, TypeScript, and OWASP rulesets by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/185">https://github.com/pmaojo/vord/pull/185</a></li>
<li>Bump version to 0.13.2 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/186">https://github.com/pmaojo/vord/pull/186</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.13.1...v0.13.4">https://github.com/pmaojo/vord/compare/v0.13.1...v0.13.4</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>Add cfg, mutation, and vite-react rulesets; update documentation by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/184">https://github.com/pmaojo/vord/pull/184</a></li>
<li>Add 50+ new rules across Python, Rust, TypeScript, and OWASP rulesets by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/185">https://github.com/pmaojo/vord/pull/185</a></li>
<li>Bump version to 0.13.2 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/186">https://github.com/pmaojo/vord/pull/186</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.13.1...v0.13.4">https://github.com/pmaojo/vord/compare/v0.13.1...v0.13.4</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>Add cfg, mutation, and vite-react rulesets; update documentation by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/184">https://github.com/pmaojo/vord/pull/184</a></li>
<li>Add 50+ new rules across Python, Rust, TypeScript, and OWASP rulesets by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/185">https://github.com/pmaojo/vord/pull/185</a></li>
<li>Bump version to 0.13.2 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/186">https://github.com/pmaojo/vord/pull/186</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.13.1...v0.13.4">https://github.com/pmaojo/vord/compare/v0.13.1...v0.13.4</a></p>
<h2 id="whats-changed-4">What&rsquo;s Changed</h2>
<ul>
<li>Add cfg, mutation, and vite-react rulesets; update documentation by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/184">https://github.com/pmaojo/vord/pull/184</a></li>
<li>Add 50+ new rules across Python, Rust, TypeScript, and OWASP rulesets by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/185">https://github.com/pmaojo/vord/pull/185</a></li>
<li>Bump version to 0.13.2 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/186">https://github.com/pmaojo/vord/pull/186</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.13.1...v0.13.4">https://github.com/pmaojo/vord/compare/v0.13.1...v0.13.4</a></p>
]]></content:encoded></item><item><title>Agentic SemVer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/agentic-semver/</link><pubDate>Thu, 20 Aug 2026 06:30:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/agentic-semver/</guid><description>Version updated for https://github.com/PramodKumarYadav/agentic-semver to version v1.2.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary agentic-semver is a GitHub Action that automates semantic versioning for pull requests by using Claude to analyze the PR diff and classify changes as patch, minor, or major. It updates the version file and generates a changelog entry, applies labels, and commits these changes back to the PR branch. It also includes a companion action create-release to create GitHub Releases from the version file and changelog.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PramodKumarYadav/agentic-semver">https://github.com/PramodKumarYadav/agentic-semver</a></strong> to version <strong>v1.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentic-semver">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>agentic-semver</code> is a GitHub Action that automates semantic versioning for pull requests by using Claude to analyze the PR diff and classify changes as patch, minor, or major. It updates the version file and generates a changelog entry, applies labels, and commits these changes back to the PR branch. It also includes a companion action <code>create-release</code> to create GitHub Releases from the version file and changelog.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="122---2026-08-19">1.2.2 - 2026-08-19</h2>
<ul>
<li>Summary: Added test execution step to the agentic-semver workflow to prevent version bumps when tests are failing. This is a maintenance improvement that fixes a race condition between CI and versioning workflows without changing any external behavior or API.</li>
<li>Fixed race condition where version could be bumped while tests were failing by running tests before the version bump step</li>
<li>Added <code>npm test</code> execution to agentic-semver workflow as a gate before semantic versioning step</li>
<li>Maintained separate CI and versioning workflows with deliberate test duplication for security and coverage reasons</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/kaniko-build-action/</link><pubDate>Thu, 20 Aug 2026 06:27:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting to the log, automating the process of welcoming users by name. It allows developers to easily integrate it into their workflows to provide immediate feedback and customization options through inputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting to the log, automating the process of welcoming users by name. It allows developers to easily integrate it into their workflows to provide immediate feedback and customization options through inputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>rung gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/rung-gate/</link><pubDate>Thu, 20 Aug 2026 06:27:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/rung-gate/</guid><description>Version updated for https://github.com/rung-dev/rung to version v0.5.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rung is an AI agent verification tool that records and gates a change by running the real surface, capturing what happens, and providing a verifiable record. It ensures that changes are verified with concrete evidence rather than just self-reported claims, allowing for better code quality and accountability in production deployments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rung-dev/rung">https://github.com/rung-dev/rung</a></strong> to version <strong>v0.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rung-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>rung is an AI agent verification tool that records and gates a change by running the real surface, capturing what happens, and providing a verifiable record. It ensures that changes are verified with concrete evidence rather than just self-reported claims, allowing for better code quality and accountability in production deployments.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>rung 0.5.1: evidence-bundle/v2</p>
<p>At which rung did your agent verify?</p>
<p>This release splits the one word &ldquo;verified&rdquo; into three questions a checker can
enforce, and gates on all three. It is a breaking schema change from the 0.2.0
line: evidence-bundle/v1 bundles are refused with a regenerate message.</p>
<p>The three concepts</p>
<ul>
<li>RUNG {0, 1}. 0 is not a runtime observation of the real surface (reasoning, an
isolated unit, a green suite); 1 drove the surface and captured its bytes.</li>
<li>METHOD. single (default), the enforceable differential (an S0/S1 pair whose
delta matches a declared change or invariance polarity), and advisory
adversarial / fuzz / property (recorded, never gated).</li>
<li>CONTEXT {author, independent}. cross-model and cross-lab are per-tier presence
qualifiers, not higher contexts.</li>
</ul>
<p>What the default policy now says
Shipped means observed: min_rung 1 at every tier. Medium and up need independent
context; high adds a cross-model qualifier; critical adds cross-lab. Tunable per
operator.</p>
<p>Also in this release</p>
<ul>
<li>rung run &ndash;rung 0|1 &ndash;method &hellip;; &ndash;diff records a differential at rung 1</li>
<li>Opt-in capture hygiene: &ndash;redact, &ndash;scan-secrets, &ndash;env-clear</li>
<li>rung skill ships the skill from the CLI; new per-surface guidance</li>
<li>Two self-verification cases under gate/cases/, including an independent
cross-model panel that clears high and blocks critical</li>
<li>Closed two STRIDE findings (argv secret leak, symlink-loop artifact)</li>
</ul>
<p>Upgrading from 0.2.0</p>
<ul>
<li>The 0-4 rung ladder is removed. A v1 bundle now exits 2 with a regenerate
message; recreate it with rung run, or hand-author against evidence-bundle/v2.</li>
<li>Old rung 3/4 differentials become method differential at rung 1. Rung 0-2 reads
collapse to rung 0.</li>
<li>Policies gain require_context, require_cross_model, require_cross_lab,
require_method; min_rung is now 0..1.</li>
</ul>
<p>Install: pip install rung-ai . rung gate bundle.json</p>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/rumdl-action/</link><pubDate>Thu, 20 Aug 2026 06:26:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.58.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
rumdl is a high-performance Markdown linter and formatter written in Rust, designed for speed with built-in lint rules covering common Markdown issues. It offers automatic formatting with the --fix option and supports multiple Markdown flavors including GFM, MkDocs, MDX, Quarto, and MyST, with auto-detection. It provides configuration via TOML files and is available for installation using Cargo, npm, pip, uv, mise, Nix, Termux User Repository, and pacman (Arch Linux), making it compatible with various workflows and environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.58</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>rumdl is a high-performance Markdown linter and formatter written in Rust, designed for speed with built-in lint rules covering common Markdown issues. It offers automatic formatting with the <code>--fix</code> option and supports multiple Markdown flavors including GFM, MkDocs, MDX, Quarto, and MyST, with auto-detection. It provides configuration via TOML files and is available for installation using Cargo, npm, pip, uv, mise, Nix, Termux User Repository, and pacman (Arch Linux), making it compatible with various workflows and environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>wasm</strong>: load extends chains from embedder-supplied config files (<a href="https://github.com/rvben/rumdl/commit/e7c7d8f9fa64f1a74195f52cae9d328a8fae9389">e7c7d8f</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.58-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.58-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.58-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.58-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-x86_64-apple-darwin.tar.gz">rumdl-v0.2.58-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-aarch64-apple-darwin.tar.gz">rumdl-v0.2.58-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-x86_64-pc-windows-msvc.zip">rumdl-v0.2.58-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.58/rumdl-v0.2.58-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/custom-amazon-bedrock-agent-action/</link><pubDate>Thu, 20 Aug 2026 06:24:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action leverages Amazon Bedrock Agent for analyzing files in a pull request (PR), providing tailored feedback. It integrates seamlessly with Amazon Bedrock Knowledge Bases, enhancing analysis with context and enriched insights. Key features include customizable agent analysis, memory support, flexible use cases, file ignoring, AI-powered insights, language-agnostic analysis, and seamless GitHub integration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action leverages Amazon Bedrock Agent for analyzing files in a pull request (PR), providing tailored feedback. It integrates seamlessly with Amazon Bedrock Knowledge Bases, enhancing analysis with context and enriched insights. Key features include customizable agent analysis, memory support, flexible use cases, file ignoring, AI-powered insights, language-agnostic analysis, and seamless GitHub integration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/sherpa.sh/</link><pubDate>Thu, 20 Aug 2026 06:23:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven platform that automates the deployment of applications to various cloud providers, allowing developers to describe their infrastructure needs in plain English. It simplifies the process of setting up and configuring servers, DNS, SSL certificates, CDNs, databases, backups, load balancing, and more. By using Sherpa, developers can focus on writing code without worrying about configuration details, making deployment invisible and reducing vendor lock-in.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven platform that automates the deployment of applications to various cloud providers, allowing developers to describe their infrastructure needs in plain English. It simplifies the process of setting up and configuring servers, DNS, SSL certificates, CDNs, databases, backups, load balancing, and more. By using Sherpa, developers can focus on writing code without worrying about configuration details, making deployment invisible and reducing vendor lock-in.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/smyklot/</link><pubDate>Thu, 20 Aug 2026 06:22:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.44.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository’s CODEOWNERS file. It supports multiple command formats, including slash commands, mentions, and bare commands, and allows customization through a TOML configuration file. The app handles various commands such as approving, merging, squashing, rebasing, unapproving, cleaning up, and showing help information, with features like emoji feedback and reaction tracking.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.44.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository&rsquo;s CODEOWNERS file. It supports multiple command formats, including slash commands, mentions, and bare commands, and allows customization through a TOML configuration file. The app handles various commands such as approving, merging, squashing, rebasing, unapproving, cleaning up, and showing help information, with features like emoji feedback and reaction tracking.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1440-2026-08-19"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.43.1...v1.44.0">1.44.0</a> (2026-08-19)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>sync:</strong> the sync overhaul, and an index that rescans only what changed (<a href="https://github.com/smykla-skalski/smyklot/issues/282">#282</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/f3770d79f9835329950374c2c2d86b0dbefa4e36">f3770d7</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update module modernc.org/sqlite to v1.57.0 (<a href="https://github.com/smykla-skalski/smyklot/issues/286">#286</a>) (<a href="https://github.com/smykla-skalski/smyklot/commit/ffc1ec118825e96f061fbf91a710cf3482b70b14">ffc1ec1</a>)</li>
</ul>
<h2 id="smyklot-v1440">Smyklot v1.44.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.44.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>1fabaa06e62163274ec56c0dc41ef7175f923298 chore(release): bump version to 1.44.0</li>
<li>bdeff8feaf14b7166d887e645e1c7660b51fc0dc ci(release): pin the semantic-release plugin majors (#288)</li>
<li>e8520c0b77a8f065a4f1953502e28b33e2123efa test(service): give Run room for the shutdown floor it cannot beat (#287)</li>
<li>0fa40a6dfd71d49f3a6da094052dc0566991d8b4 chore(deps): update dependency yq to v4.53.4 (#283)</li>
<li>af206a9521e78d52aca08797fe659390c26b5ea4 ci(deps): update docker/setup-buildx-action action to v4.3.0 (#284)</li>
<li>ffc1ec118825e96f061fbf91a710cf3482b70b14 fix(deps): update module modernc.org/sqlite to v1.57.0 (#286)</li>
<li>f3770d79f9835329950374c2c2d86b0dbefa4e36 feat(sync): the sync overhaul, and an index that rescans only what changed (#282)</li>
<li>12509dfe3ad539350c2b7f7ca09023db8e0ae5b8 test(panel): story the states sync never showed (#280)</li>
</ul>
]]></content:encoded></item><item><title>Harnessie Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/harnessie-verify/</link><pubDate>Thu, 20 Aug 2026 06:21:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/harnessie-verify/</guid><description>Version updated for https://github.com/snapsynapse/harnessie-verify-action to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the verification of claims made in pull requests by executing deterministic checks and running a fresh-context verifier model. It prevents untrusted diffs from leaving machines under control and ensures that only verified claims are accepted before merging a pull request. The action is powered by harnessie verify, with an option to use OpenAI-compatible endpoints for verification, enhancing security and flexibility.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snapsynapse/harnessie-verify-action">https://github.com/snapsynapse/harnessie-verify-action</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harnessie-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the verification of claims made in pull requests by executing deterministic checks and running a fresh-context verifier model. It prevents untrusted diffs from leaving machines under control and ensures that only verified claims are accepted before merging a pull request. The action is powered by harnessie verify, with an option to use OpenAI-compatible endpoints for verification, enhancing security and flexibility.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Pin the tested default to Harnessie 1.0.0. The <code>harnessie verify</code> CLI contract is unchanged between 0.8.0 and 1.0.0, so the action&rsquo;s public inputs, outputs, and fail-closed verdict contract (VERIFIED / FAILED / CANNOT_VERIFY; 0/1/2) are preserved. Verified against a fresh-venv PyPI 1.0.0 install with the fixture mock provider mapping a failing check to exit 1.</p>
<p>Stable-major tag <code>v0</code> now resolves to this release commit.</p>
]]></content:encoded></item><item><title>Conventional Release Creator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/conventional-release-creator/</link><pubDate>Thu, 20 Aug 2026 06:20:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/conventional-release-creator/</guid><description>Version updated for https://github.com/so1omon563/release-creator to version v2.0.2.
This action is used across all versions by 13 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of GitHub Releases with auto-generated release notes from conventional commit history. It supports multiple release note formats and can handle pre-release detection, moving floating pointer tags, asset uploads, and skipping releases when a tag already exists. The action is suitable for projects that require automated versioning and release management based on Git commits.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/so1omon563/release-creator">https://github.com/so1omon563/release-creator</a></strong> to version <strong>v2.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>13</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/conventional-release-creator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of GitHub Releases with auto-generated release notes from conventional commit history. It supports multiple release note formats and can handle pre-release detection, moving floating pointer tags, asset uploads, and skipping releases when a tag already exists. The action is suitable for projects that require automated versioning and release management based on Git commits.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li>address git-free review gaps (<code>b4b7ab7</code>)</li>
<li>restore git-free native notes (<code>9486988</code>)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/update-a-config-file-with-values-from-environment/</link><pubDate>Thu, 20 Aug 2026 06:19:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces environment variables in a configuration file, automating the process of using dynamic settings based on environment variables. It simplifies managing configurations by allowing developers to inject variables directly into their configuration files without hardcoding them.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces environment variables in a configuration file, automating the process of using dynamic settings based on environment variables. It simplifies managing configurations by allowing developers to inject variables directly into their configuration files without hardcoding them.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>battest Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/battest-action/</link><pubDate>Thu, 20 Aug 2026 06:19:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/battest-action/</guid><description>Version updated for https://github.com/tboy1337/battest to version v1.0.9.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The battest action is a runtime test runner for Windows batch files. It launches real cmd.exe and asserts on exit code, stdout, stderr, environment, and filesystem side effects, providing a trusted-fixture runner that does not isolate the filesystem or depend on other tools. The GitHub Action automatically enables safe defaults by default, which stubs common destructive externals to prevent harm during untrusted testing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tboy1337/battest">https://github.com/tboy1337/battest</a></strong> to version <strong>v1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/battest-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The battest action is a runtime test runner for Windows batch files. It launches real <code>cmd.exe</code> and asserts on exit code, stdout, stderr, environment, and filesystem side effects, providing a trusted-fixture runner that does not isolate the filesystem or depend on other tools. The GitHub Action automatically enables safe defaults by default, which stubs common destructive externals to prevent harm during untrusted testing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="109---2026-08-20">[1.0.9] - 2026-08-20</h2>
<p>GitHub Action Marketplace listing and installer-test hygiene.</p>
<ul>
<li>Action <code>name</code> is <code>battest Action</code> with branding (<code>check-square</code>, <code>blue</code>).</li>
<li>Installer tests assert the parsed GitHub asset-host allowlist and URI host
check. The regex timeout test builds its nested-quantifier pattern at
runtime so CodeQL does not treat those fixtures as URL sanitizers or a
shipped ReDoS expression.</li>
</ul>
]]></content:encoded></item><item><title>Delivery Autopilot Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/delivery-autopilot-runner/</link><pubDate>Thu, 20 Aug 2026 06:18:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/delivery-autopilot-runner/</guid><description>Version updated for https://github.com/Tekunda/autopilot-runner to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of creating pull requests from tickets using an AI-driven pipeline hosted by Tekunda. It helps streamline software development workflows by taking tickets from trackers to reviewed pull requests, ensuring efficient collaboration and code quality checks. The action requires a Delivery Autopilot subscription and can be set up via either a GitHub App or by adding a workflow configuration to your repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tekunda/autopilot-runner">https://github.com/Tekunda/autopilot-runner</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delivery-autopilot-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of creating pull requests from tickets using an AI-driven pipeline hosted by Tekunda. It helps streamline software development workflows by taking tickets from trackers to reviewed pull requests, ensuring efficient collaboration and code quality checks. The action requires a Delivery Autopilot subscription and can be set up via either a GitHub App or by adding a workflow configuration to your repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Gate check-run publishing, model-tier resolution, deterministic per-subtask build branches.</p>
]]></content:encoded></item><item><title>Verificate Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/verificate-gate/</link><pubDate>Thu, 20 Aug 2026 06:16:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/verificate-gate/</guid><description>Version updated for https://github.com/VerificateAI/verificate-gate-action to version v1.1.1.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Verificate Gate is an AI-powered CI gate for GitHub that automatically reviews and checks every pull request for security, reliability, performance efficiency, and maintainability. It detects invented APIs, placeholder code, tests written to pass rather than test, and quality problems in ISO 5055 areas before a human sees the changes. The tool uses GitHub-hosted runners with the id-token: write permission to utilize the repository’s own free quota, ensuring reliable checks on pull requests without affecting other repositories’ quotas.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VerificateAI/verificate-gate-action">https://github.com/VerificateAI/verificate-gate-action</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/verificate-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Verificate Gate is an AI-powered CI gate for GitHub that automatically reviews and checks every pull request for security, reliability, performance efficiency, and maintainability. It detects invented APIs, placeholder code, tests written to pass rather than test, and quality problems in ISO 5055 areas before a human sees the changes. The tool uses GitHub-hosted runners with the <code>id-token: write</code> permission to utilize the repository&rsquo;s own free quota, ensuring reliable checks on pull requests without affecting other repositories&rsquo; quotas.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fixes from a team field test of the action.</p>
<p><strong>Blocking is now honest.</strong> <code>fail-on: reject</code> (the default) exits non-zero on a <strong>REJECTED</strong> verdict, not only on a deterministic veto — so a rejected change actually turns the check red and blocks the merge, matching the docs.</p>
<p><strong>Org migration cleanup.</strong> The PR-comment footer and README benchmark links now point at <code>VerificateAI/...</code> (were stale <code>Verificate-Dev/...</code>). Use <code>uses: VerificateAI/verificate-gate-action@v1</code>.</p>
<p><strong>Large PRs no longer silently under-reviewed.</strong> When a PR exceeds <code>max-files</code>, the extra files are flagged in the PR comment and a workflow warning, instead of being dropped quietly.</p>
<p><strong>Docs.</strong> Documented that the gate reviews pull requests (direct pushes to <code>main</code> are not gated — protect the branch), corrected the required-check name (<code>Verificate Gate / verificate-gate</code>), and made the <code>max-files</code> behaviour explicit.</p>
<p><code>v1</code> has been moved to this commit.</p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/cowork-harness/</link><pubDate>Thu, 20 Aug 2026 06:15:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.25.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, cowork-harness, provides an automated test harness that reproduces Claude Cowork’s runtime contract closely enough to test skills. It allows developers to run and test their skills across various scenarios without the need for a locked-down Desktop app, ensuring that tests are accurate and reliable. The action supports multiple fidelity tiers, including free demos, global installs, linting with Python, and live tiers that require specific resources such as Claude Desktop and a token.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.25.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, cowork-harness, provides an automated test harness that reproduces Claude Cowork&rsquo;s runtime contract closely enough to test skills. It allows developers to run and test their skills across various scenarios without the need for a locked-down Desktop app, ensuring that tests are accurate and reliable. The action supports multiple fidelity tiers, including free demos, global installs, linting with Python, and live tiers that require specific resources such as Claude Desktop and a token.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>Platform baseline <code>desktop-1.32885.1</code> (agent <code>2.1.234</code>).</strong> The Cowork system prompt is
byte-identical to the previous baseline, the egress allowlist is unchanged at 15 domains, and the
spawn contract still derives the same 22 env keys — but the <strong>host-loop sub-agent append gained a
sentence</strong>, so <code>baselines/prompts/desktop-1.32885.1/subagent-append-hl.md</code> is a newly re-derived
paraphrase and <code>spawn.subagentAppendHostLoop</code> now points at it. The added text tells a host-loop
sub-agent that its shell commands start at the VM session root and that anything written outside
<code>&lt;root&gt;/mnt/</code> — <code>/tmp</code> included — stays inside the sandbox, invisible to both the user and the
sub-agent&rsquo;s own file tools. That is the host-loop split-filesystem fact the harness already models;
it is now stated to the model. The <code>vm</code> branch is unchanged and keeps its existing asset.</p>
<p>Worth knowing for anyone re-deriving this: the branch fingerprints decode <code>\uXXXX</code> escapes before
hashing, so this is a real content change and not the codegen-escape artifact that moved both
fingerprints a release earlier — the <code>vm</code> branch, which an escape change would also have moved,
did not budge.</p>
<p><strong>Live-verified against this baseline on 2026-08-19</strong> across <code>protocol</code>, <code>container</code> and <code>hostloop</code>:
the example-scenario suite 6/6, the <code>boundary-check</code> sandbox proof with all six constraints enforced,
and <code>npm run test:live</code> at 4 suites / 24 assertions (20 green, 4 skipped). Three of those four skips
passed on a re-run — the model-variance the suite skips loudly for rather than failing. The fourth,
<code>live-outputs-delete</code>&rsquo;s &ldquo;a whole-line <code>#</code> comment is prose, not an executable delete&rdquo;, skipped in all
three runs made against this baseline and so has <strong>not</strong> been green here; by that suite&rsquo;s own rule a
skip persisting across runs means the agent has stopped being willing to run the pinned command, which
makes it scenario-maintenance debt rather than a guard defect. Recorded rather than rounded away.</p>
</li>
<li>
<p><strong>A <code>--repeat</code> rollup now names the ARM it ran, so a one-armed batch can&rsquo;t be banked as an A/B.</strong>
<code>--ablate-skill --repeat 5</code> produces 5 control runs and zero treatment runs — correct for a
single-arm flag — and summarized them as <code>repeat &quot;&lt;skill&gt;&quot;: PASS — 5/5 passed (100%)</code>, which reads
as a completed comparison. A consumer made exactly that read twice, producing 10 baseline runs and 0
treatment runs across two prompts before catching it at analysis. The verdict line now carries the
arm: <code>repeat &quot;&lt;skill&gt;&quot;: PASS [ABLATED — control arm] — 5/5 passed (100%)</code>. A partially-ablated batch
(no flag produces one today; a resumed or hand-assembled run set could) reads
<code>[MIXED ARMS: 2/3 ablated]</code> rather than being rounded to either arm, and a normal batch carries no
tag at all — a label on every batch is noise, which is how the ablated one would come to be ignored.
<code>--matrix</code>&rsquo;s per-cell rollup lines get the same label, since that is where the largest batches run.</p>
<p><strong>The flag combination stays legal.</strong> Refusing it would ban a real measurement — &ldquo;how variable is my
no-skill baseline?&rdquo; is a question these flags compose correctly to answer — and the output was never
dishonest, only unlabeled at the one line a human reads. (Contrast <code>--ablate-skill --resume</code>, which
<em>is</em> refused: there ablation does not take effect at all, so <code>ablated: true</code> would be a lie.)</p>
</li>
<li>
<p><strong>A <code>[provenance]</code> banner on every run verdict — &ldquo;which experiment actually ran?&rdquo;</strong> Three separate
multi-run measurements by one consumer were silently scoped to the wrong thing, and in every case the
run record already held the answer: a whole finding measured on <code>claude-sonnet-5</code> because the session
file omitted <code>model:</code>; a 10-run &ldquo;A/B&rdquo; that was 10 <code>--ablate-skill</code> control runs and zero treatment
runs; an answer that read exactly like skill output, from a run where the skill was offered and never
invoked (the model read the mounted <code>SKILL.md</code> as a file instead). <code>models</code>, <code>ablated</code>,
<code>context.availableSkills</code> and <code>skillsInvoked</code> were all in <code>result.json</code> and none of them were
anywhere a human looks, so checking meant hand-written scripts against the record — which nobody runs
until a result looks wrong, i.e. after the money is spent.</p>
<p>The footer now prints one line beside the verdict, on passing AND failing runs and on the replay lane:</p>
<pre tabindex="0"><code>[provenance] model=claude-opus-5  skill=offered,NOT-invoked  ablated=false
</code></pre><p><code>model</code> drops <code>&lt;…&gt;</code>-wrapped agent markers first — <code>&lt;synthetic&gt;</code> marks a locally fabricated turn, not a
model, and an unfiltered join reads as a two-model run. <code>skill</code> has four states, and
<code>offered,unknown</code> / <code>unknown</code> mean <strong>evidence unavailable</strong>, never &ldquo;no&rdquo;: a banner that exists to
prevent false confidence must not manufacture any. <code>ablated=false</code> prints too — the value is that the
line is on every run.</p>
<p>The same derived object rides in the <code>--output-format json</code> envelope as <code>results[].provenance</code>
(beside <code>verdict</code>), so a consumer never re-derives the marker filter or the evidence-unavailable
states. A <code>--repeat</code> batch gains an aggregate <code>provenance:</code> row on its rollup, reporting models and
skill states as <strong>sets</strong> — a batch silently spanning two models is the multi-run form of the same
defect, and collapsing to the first run would hide it. <code>--compact</code> (and <code>--demo</code>) suppress the line,
matching the <code>[status]</code> contract.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><strong><code>verify-run --output-format json</code> now emits <code>results[]</code> with a per-result <code>verdict</code>, matching
<code>run</code>.</strong> The two commands answered the same question — &ldquo;did my assertions pass?&rdquo; — in structurally
different envelopes: <code>run</code> nested everything under <code>results[].verdict</code>, <code>verify-run</code> was flat
(<code>pass</code>/<code>assertions[]</code>/<code>signals[]</code>, no <code>verdict</code>, no <code>failures[]</code>). The cost was not a missing field
but a <strong>silent false green</strong>: the defensive jq idiom from <code>run</code>&rsquo;s own docs —
<code>.results[]? | .verdict.failures[]? | select(.kind==&quot;assertion&quot;)</code> — returns <code>[]</code> when <code>.results</code> is
null, and <code>[]</code> reads as &ldquo;no failures&rdquo; in the query whose entire purpose is detecting failure. Run
against a <strong>failed</strong> <code>verify-run</code>, it reported success. This matters most where <code>verify-run</code> is
promoted hardest: as the cheap, token-free iteration path in CI.</p>
<p><code>results[]</code> always holds exactly one entry — <code>verify-run</code> judges one run dir, which is the same shape
<code>run</code> emits for a single scenario. <strong>Additive</strong>: the flat <code>pass</code>, <code>assertions[]</code>, <code>signals[]</code> and
<code>answerCoverage</code> keys are unchanged, so an existing consumer reading them is unaffected; <code>ok</code> still
mirrors the verdict. A cross-command regression test runs the real documented query against a real
failing envelope, so restoring the flat-only shape as a &ldquo;simplification&rdquo; fails the suite rather than
silently reopening the false green.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>The outputs-delete live suite was refusing to run, and a refused case verifies nothing.</strong> It handed
the agent a byte-pinned destructive command wrapped in prohibitions (&ldquo;run this EXACTLY as written… do
not modify it… do not run any other command&rdquo;) plus an unexplained sentinel, and asserted the command
came back verbatim. The agent increasingly declined — over the framing, not the file operation — and a
declined case SKIPS. Measured across 27 case-runs the refusal rate was <strong>41%</strong>; every case was refused
at least once and the worst sat at 67%, so the suite could report success having verified almost
nothing.</p>
<p>It now asks for <strong>ordinary tasks</strong> whose completion requires the file operation — write two poems and
delete one; write a poem and rename it. The agent has no delete tool, so a deletion must go through
Bash, which is exactly the path the scanner watches, while a benign creative task gives it no reason to
refuse. Measured 9 of 9 runs complied, zero refusals. The two form a polarity pair: one must trip the
guard, one must not.</p>
<p>Because the task is real, the run is now also asserted on its <strong>effect</strong> — exactly one poem file
survives in <code>mnt/outputs</code> — where the pinned suite only ever proved the scanner had recorded an
<em>intent</em> to delete. What is given up is byte-exactness: the agent picks its own filenames and command
form, so assertions are on shape plus effect. Command-form distinctions that cannot be asked for
naturally (&ldquo;emptying a file is not a delete&rdquo;, &ldquo;a commented-out <code>rm</code> is not a delete&rdquo;, the <code>mv</code>
spellings) moved to <code>test/execute.test.ts</code>, deterministically and for free — including the
<code>mnt/</code>-prefixed <code>mv</code> bytes the live case depended on, which no unit test had covered.</p>
<p>Two intermediate attempts are recorded in the file&rsquo;s header so they are not retried blind: explaining
the request (stated purpose, what the marker is for) made refusals <strong>worse</strong>, and retargeting one
case&rsquo;s destination away from <code>/tmp</code> helped that case only.</p>
</li>
<li>
<p><strong>A fixture shrinking could red an unrelated test.</strong> <code>replay-json-pipe-truncation</code> multiplied a seed
cassette to exceed the 64KB pipe buffer, with the copy count hard-coded at 10 and justified as
&ldquo;~15KB/result&rdquo;. The real figure was ~5.5KB, so the total sat just under the buffer and a routine
re-record of the seed tipped it under — reddening the suite for a reason unrelated to the truncation
bug it exists to pin. The count is now derived from a measured result at ~2x the buffer; the
<code>&gt; 65536</code> assertion stays as the tripwire.</p>
</li>
<li>
<p><strong><code>replay --help</code> now says that <code>--allow-failing</code> waives the skill-drift gate too.</strong> <code>--assert-from</code>
forces that gate on precisely so a re-asserted block cannot be frozen against a recording whose skill
sources have moved — but the gate is the verdict, and <code>--allow-failing</code> waives the verdict wholesale.
Nothing downstream re-checks drift. So <code>--assert-from --write --allow-failing</code>, which is the natural
incantation when your asserts are legitimately failing (that being why you are re-asserting), persists
the block against a drifted recording with no warning. Behaviour is unchanged — the flag is an explicit
override and stays one — but it is now stated where it is reached for.</p>
<p>The same block documents that text mode writes to stderr and nothing to stdout (a passing replay is 0
bytes), and names <code>verdict.failures[].kind</code> as the way to separate your own failing asserts from
injected drift/corruption findings, which the exit code collapses.</p>
</li>
<li>
<p><strong><code>verdict.failures[].kind</code> said &ldquo;your assertion failed&rdquo; when the cassette was corrupt.</strong> That field is
the documented way to tell an author&rsquo;s own failing <code>assert:</code> from something the harness injected — and
seven cassette-corruption paths (duplicate <code>request_id</code>s with differing bodies, malformed control-out
lines, a truncated recording) pushed their pseudo-assertions without the <code>source</code> stamp that drives it.
<code>computeVerdict</code> falls back to <code>a.source ?? &quot;assertion&quot;</code>, so every one of them was reported as an
authored assertion, in direct contradiction of the contract written above the field. A consumer asking
&ldquo;did MY assertions pass?&rdquo; with the documented <code>select(.kind==&quot;assertion&quot;)</code> query got a yes-it-failed on
a cassette that was simply unreadable.</p>
<p>They now stamp <code>cassette-format</code>, whose definition widens from &ldquo;a cassette too new to interpret&rdquo; to
cover corruption as well — the shared property is that the cassette itself cannot be interpreted. No
enum changed; <code>cassette-format</code> was already a member.</p>
<p><strong>The guard that was supposed to catch this could not see it.</strong> It scanned for the <code>{} as Assertion</code>
cast shape, and all seven pass a real assertion key (<code>{ replay_protocol_fidelity: true }</code>), so they
never matched — the suite stayed green while the sites shipped unstamped. It now keys on
<code>assertions.push(</code> itself, which in these files is by construction an injection (an author&rsquo;s own
asserts are evaluated elsewhere and never reach that call), and carries a mutation check proving the
matcher rejects a bare push. Its site count is now counted rather than inherited: the old comment said
2 in <code>cli.ts</code>; there are 3.</p>
</li>
<li>
<p><strong>A stale sub-agent prompt pointer can no longer ship with a green <code>sync</code>.</strong> The prompt assets a
baseline points at (<code>spawn.subagentAppendHostLoop</code> / <code>spawn.subagentAppend</code>) are hand-authored, so
<code>sync</code> carries the previous release&rsquo;s values forward untouched — while the drift sentinel compares the
shipping app&rsquo;s text against a recorded fingerprint and never looks at those pointers. Recording a new
fingerprint therefore cleared the sentinel whether or not the pointer moved, and a host-loop sub-agent
would silently receive the previous release&rsquo;s paraphrase with every check green.</p>
<p>A new coupling check closes it: when the newest recorded fingerprint differs from the one before it on
an axis, the newest baseline&rsquo;s pointer for that axis must differ from the previous baseline&rsquo;s. Both
inputs are already-committed data, so there is no new field to fill in — and nothing to copy-paste into
compliance, which is what sank an earlier attempt at this. Verified by simulating the real failure: the
check fires and names the exact edit required.</p>
<p>Its limits are documented where it lives, not glossed: the committed asset is a deliberate paraphrase,
so this enforces coupling and cannot verify faithfulness; it is dormant between fingerprint moves; and
back-filling an older fingerprint entry equal to the newest silently disarms it.</p>
<p>Alongside it, the per-tier branch-selection assertions were unfrozen from a pinned <code>desktop-1.20186.1</code>
to <code>latest</code>. Pinned, they asserted real hl-vs-vm content semantics that could never observe a repoint
of the CURRENT baseline — coverage in appearance only for the pointer production actually renders.</p>
</li>
<li>
<p><strong><code>verify-cassettes</code> stopped flagging the agent&rsquo;s own built-in skills as operator inventory.</strong> The
host-inventory scan keys off a closed roster of skills the product itself ships; that roster still held
a single entry (<code>deep-research</code>) while the agent grew fourteen more. The first fresh <code>protocol</code>
recording after a sync therefore reported 14 <code>host-inventory</code> findings on a cassette carrying no
operator inventory at all — the exact false positive that pushes people toward a blanket
<code>--allow-host-inventory</code>, which would disable the check that matters.</p>
<p>The roster is now current, established three ways rather than assumed: the recording was made against
a <strong>managed (fresh) config dir</strong> whose session stages no plugins or skills, so nothing from the
operator&rsquo;s own config could have been enumerated; every name appears as a literal in both the staged
agent ELF and the host CLI; and ten personal/plugin skill names from the same machine are <strong>absent</strong>
from that binary, so the check discriminates rather than matching everything. The known cost is
unchanged and inherent to a name-keyed set: an operator whose own skill shares one of these bare names
is no longer flagged — the same trade the built-in <em>agent</em> roster already makes.</p>
</li>
<li>
<p><strong>A minified <code>$</code> in the shipping app could make <code>sync</code> refuse a perfectly healthy Desktop release.</strong>
Several spawn-contract sentinels pinned a minifier-assigned binding, callee or member name with
<code>\w+</code>. <code>\w</code> is <code>[A-Za-z0-9_]</code> — it cannot match <code>$</code>, which is a legal JavaScript identifier
character that minifiers use freely. Claude Desktop 1.32885.1 named the empty-<code>ANTHROPIC_*</code>
blank-sentinel helper <code>$s</code>, and the sentinel asserting that helper runs on the spawn env stopped
matching. Nothing about the spawn contract had changed: re-deriving it against the new app produced
the same 22 keys with the same values.</p>
<p>An audit of every regex in the sync module found <strong>11 such atoms across 7 patterns</strong>, all in the
spawn family, of which only one was firing — the other six were latent purely because their bindings
happened not to draw a <code>$</code> this build. All of them are now <code>[\w$]</code>, including the captured env-object
binding, which previously admitted a <em>trailing</em> <code>$</code> only and so would still have missed a
<code>$</code>-initial name even with its callees widened.</p>
<p><strong>The whole class fails closed</strong> — an unresolvable value flags and refuses to write, rather than
writing a wrong one — so the cost was a false refusal on a good release, never a silently incorrect
baseline. That is also why six of the seven went unnoticed for so long, and why the fix ships with a
guard rather than just a widening: a new test asserts the module contains <strong>zero</strong> regex atoms that
cannot match a <code>$</code>-initial identifier, and backs that structural invariant with behavioural fixtures
that drive the real sentinels using <code>$</code>-named bindings. The fixtures also assert the sentinels still
<em>fire</em> when the contract genuinely breaks, so the widening cannot be mistaken for weakening them.</p>
<p>Ships with one relaxation on the release checker: <code>check-versions</code>&rsquo; DESIGN.md gap-form regex now
accepts the singular <em>&ldquo;1 baseline has shipped since&rdquo;</em> — this release is the first N=1 gap on record,
and the count is still verified against the enumerated list, so the singular form is not a loophole.</p>
</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>
<p><strong>Three claims about the committed example fixtures were wrong, and are corrected.</strong> <code>docs/protocol.md</code>
said all three golden protocol vectors were &ldquo;extracted verbatim&rdquo; from
<code>example-multiselect-gate.cassette.json</code>. <code>initialize.json</code> cannot have been: it carries an
<code>appendSubagentSystemPrompt</code> holding the VM sub-agent text and a session id present in no committed
cassette, while a <code>protocol</code>-tier run renders no sub-agent append at all and that scenario has been
<code>fidelity: protocol</code> for its entire history. It is a real captured frame, from a container-tier run
that was never committed. The other two do come from that scenario, but &ldquo;verbatim&rdquo; has a shelf life —
one still matches field-for-field, the other carries a <code>request_id</code> regenerated on every re-record.</p>
<p><code>examples/replays/README.md</code> described a fixture as &ldquo;<code>protocol</code>-tier (no Docker/agent needed to
replay)&rdquo;, implying the tier is the reason. Replaying any cassette needs neither Docker nor a staged
agent whatever tier it was recorded at — replay reads recorded frames and spawns nothing, which is why
the token-free CI lane replays the container, protocol and hostloop fixtures side by side. The same
file called that fixture &ldquo;synthetic&rdquo;; that was true of its hand-written capability catalog and stopped
being true when it was re-recorded hermetically for this release&rsquo;s baseline sync.</p>
</li>
<li>
<p><strong><code>docs/maintenance.md</code> now names the repoint step.</strong> The per-release procedure walked a maintainer
through updating the paraphrase asset, appending a <code>subagentAppendVersions</code> entry and re-running
<code>sync</code> — and never said to repoint <code>spawn.subagentAppendHostLoop</code> at the new asset. Those pointers are
hand-authored, so <code>sync</code> carries the previous release&rsquo;s value forward untouched, and writing the
fingerprint entry clears the sentinel whether or not you repoint. Skipping it ships a host-loop
sub-agent the previous release&rsquo;s paraphrase with <code>sync</code> green. That is the step that was missed on
1.32885.1 and caught by eye.</p>
</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 1.25.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/120">https://github.com/yaniv-golan/cowork-harness/pull/120</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1.24.0...v1.25.0">https://github.com/yaniv-golan/cowork-harness/compare/v1.24.0...v1.25.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/b.ia-accessibility-checker/</link><pubDate>Thu, 20 Aug 2026 06:14:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/20/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines, helping companies ensure their products meet WCAG guidelines for specific audiences. It uses AI to analyze and measure guidelines more abstractly, allowing for flexibility in adopting accessibility practices. The action defines requirements for audience coverage and guideline compliance, with the outcome being whether developer pushes or pulls requests are accepted based on these criteria.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines, helping companies ensure their products meet WCAG guidelines for specific audiences. It uses AI to analyze and measure guidelines more abstractly, allowing for flexibility in adopting accessibility practices. The action defines requirements for audience coverage and guideline compliance, with the outcome being whether developer pushes or pulls requests are accepted based on these criteria.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>skeptic-diff-audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/skeptic-diff-audit/</link><pubDate>Wed, 19 Aug 2026 06:38:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/skeptic-diff-audit/</guid><description>Version updated for https://github.com/mamadou-wane/skeptic to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Skeptic is a GitHub Action that checks if automated test passes mean anything by injecting known bugs into pinned commits of real upstream repos, auditing the resulting patch. The tool helps identify false positives and ensures verification without access to the original repo. It evaluates its performance against baseline results using 12 tasks across two upstream repos, with varying detection settings and FP counts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mamadou-wane/skeptic">https://github.com/mamadou-wane/skeptic</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skeptic-diff-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Skeptic is a GitHub Action that checks if automated test passes mean anything by injecting known bugs into pinned commits of real upstream repos, auditing the resulting patch. The tool helps identify false positives and ensures verification without access to the original repo. It evaluates its performance against baseline results using 12 tasks across two upstream repos, with varying detection settings and FP counts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Marketplace metadata for the Action by @mamadou-wane in <a href="https://github.com/mamadou-wane/skeptic/pull/7">https://github.com/mamadou-wane/skeptic/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mamadou-wane/skeptic/compare/v0.1.0...v0.1.1">https://github.com/mamadou-wane/skeptic/compare/v0.1.0...v0.1.1</a></p>
]]></content:encoded></item><item><title>Goal-Driven AI PR Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/goal-driven-ai-pr-reviewer/</link><pubDate>Wed, 19 Aug 2026 06:37:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/goal-driven-ai-pr-reviewer/</guid><description>Version updated for https://github.com/markhuangai/ai-pr-reviewer to version v1.1.2.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action is a goal-driven AI-powered GitHub Action designed to review pull requests automatically. It uses Claude Agent SDK sessions for isolated reviews, supporting multiple goals and configurations. The action automates security checks, code correctness verification, and other tasks by inspecting the repository history and relevant conversation. Users can configure model parameters and effort levels for optimal performance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/markhuangai/ai-pr-reviewer">https://github.com/markhuangai/ai-pr-reviewer</a></strong> to version <strong>v1.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/goal-driven-ai-pr-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action is a goal-driven AI-powered GitHub Action designed to review pull requests automatically. It uses Claude Agent SDK sessions for isolated reviews, supporting multiple goals and configurations. The action automates security checks, code correctness verification, and other tasks by inspecting the repository history and relevant conversation. Users can configure model parameters and effort levels for optimal performance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add model usage and pricing summary by @Z-M-Huang in <a href="https://github.com/markhuangai/ai-pr-reviewer/pull/15">https://github.com/markhuangai/ai-pr-reviewer/pull/15</a></li>
<li>Add configurable Claude effort by @Z-M-Huang in <a href="https://github.com/markhuangai/ai-pr-reviewer/pull/16">https://github.com/markhuangai/ai-pr-reviewer/pull/16</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/markhuangai/ai-pr-reviewer/compare/v1.1.1...v1.1.2">https://github.com/markhuangai/ai-pr-reviewer/compare/v1.1.1...v1.1.2</a></p>
]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/lgtmaybe/</link><pubDate>Wed, 19 Aug 2026 06:36:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v2.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary lgtmaybe is a provider-agnostic PR reviewer designed to automatically review and assess changes in pull requests. It fetches the diff from GitHub using the API and reviews each line, considering context by reading surrounding lines. The action surfaces issues such as logic errors, security vulnerabilities, missing tests, outdated code, performance regressions, complexity, intent, and unnecessary complexity. lgtmaybe uses OpenAI models to generate inline comments and a summary of the review. It is designed to be provider-agnostic and supports local Ollama as well as any OpenAI-compatible endpoint without requiring static keys for cloud providers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v2.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>lgtmaybe is a provider-agnostic PR reviewer designed to automatically review and assess changes in pull requests. It fetches the diff from GitHub using the API and reviews each line, considering context by reading surrounding lines. The action surfaces issues such as logic errors, security vulnerabilities, missing tests, outdated code, performance regressions, complexity, intent, and unnecessary complexity. lgtmaybe uses OpenAI models to generate inline comments and a summary of the review. It is designed to be provider-agnostic and supports local Ollama as well as any OpenAI-compatible endpoint without requiring static keys for cloud providers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="230-2026-08-18"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v2.2.0...lgtmaybe-v2.3.0">2.3.0</a> (2026-08-18)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>provider:</strong> keep structured output on routes that reject response_format (<a href="https://github.com/MattJColes/lgtmaybe/issues/470">#470</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/28830c23e19dfbd895a1d357a094fb8a78e0eba5">28830c2</a>)</li>
</ul>
]]></content:encoded></item><item><title>Banner Markings</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/banner-markings/</link><pubDate>Wed, 19 Aug 2026 06:35:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/banner-markings/</guid><description>Version updated for https://github.com/mharrisb1/markings to version v0.2.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the enforcement and update of source code banner markings, ensuring compliance with standards like copyright notices and license headers. It uses special boundaries to safely manage these banners without breaking the codebase. The action supports configuration through a YAML file that defines templates and maps them to file types, making it easy to apply consistent formatting across multiple files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mharrisb1/markings">https://github.com/mharrisb1/markings</a></strong> to version <strong>v0.2.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/banner-markings">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the enforcement and update of source code banner markings, ensuring compliance with standards like copyright notices and license headers. It uses special boundaries to safely manage these banners without breaking the codebase. The action supports configuration through a YAML file that defines templates and maps them to file types, making it easy to apply consistent formatting across multiple files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>6247b7e451abe62887f023e5f547fed79e700a66 fix(engine): correctly add newline after (#24)</li>
</ul>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/totem-shield/</link><pubDate>Wed, 19 Aug 2026 06:34:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.118.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is an AI coding agent that provides a file-based toolkit to enforce project lessons and rules stored in the repository. It uses a queryable knowledge index derived from lessons, along with compiled lint rules that are enforced by a local, zero-LLM linter. This approach ensures that code adheres to established patterns and architectural guidelines without relying on LLMs for rule enforcement, providing deterministic and offline linting capabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.118.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is an AI coding agent that provides a file-based toolkit to enforce project lessons and rules stored in the repository. It uses a queryable knowledge index derived from lessons, along with compiled lint rules that are enforced by a local, zero-LLM linter. This approach ensures that code adheres to established patterns and architectural guidelines without relying on LLMs for rule enforcement, providing deterministic and offline linting capabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>Shoutrrr GitHub Notifications Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/shoutrrr-github-notifications-action/</link><pubDate>Wed, 19 Aug 2026 06:33:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/shoutrrr-github-notifications-action/</guid><description>Version updated for https://github.com/nicholas-fedor/shoutrrr-action to version v1.0.24.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending notifications using Shoutrrr in your workflows. It allows you to send titles, messages, and other data to various services supported by Shoutrrr. The main functionality involves configuring a service URL, setting a title for the notification, and including a message describing changes. This action is specifically designed for Linux runners and requires the service URL to be stored in a GitHub secret for security.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/shoutrrr-action">https://github.com/nicholas-fedor/shoutrrr-action</a></strong> to version <strong>v1.0.24</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shoutrrr-github-notifications-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending notifications using Shoutrrr in your workflows. It allows you to send titles, messages, and other data to various services supported by Shoutrrr. The main functionality involves configuring a service URL, setting a title for the notification, and including a message describing changes. This action is specifically designed for Linux runners and requires the service URL to be stored in a GitHub secret for security.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="2026-08-18">(2026-08-18)</h2>
<h2 id="1024-2026-08-18"><small>1.0.24 (2026-08-18)</small></h2>
<ul>
<li>chore(deps): update docker.io/nickfedor/shoutrrr docker tag to v0.17.1 (#535) (<a href="https://github.com/nicholas-fedor/shoutrrr-action/commit/dd6feaa">dd6feaa</a>), closes <a href="https://github.com/nicholas-fedor/shoutrrr-action/issues/535">#535</a></li>
<li>chore(deps): update step-security/harden-runner action to v2.20.1 (#533) (<a href="https://github.com/nicholas-fedor/shoutrrr-action/commit/fb9f9fa">fb9f9fa</a>), closes <a href="https://github.com/nicholas-fedor/shoutrrr-action/issues/533">#533</a></li>
<li>chore(deps): update step-security/harden-runner action to v2.21.0 (#534) (<a href="https://github.com/nicholas-fedor/shoutrrr-action/commit/97f0f80">97f0f80</a>), closes <a href="https://github.com/nicholas-fedor/shoutrrr-action/issues/534">#534</a></li>
</ul>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/run-aer-tests/</link><pubDate>Wed, 19 Aug 2026 06:32:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.36.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aer action automates running Apex and unit tests locally without requiring an org or deploy cycle. It supports various features such as SOQL, DML operations, triggers, validation rules, database limits, standard library, testing framework, type checking, and debugging through an interactive debugger (VS Code or IntelliJ).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.36</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The aer action automates running Apex and unit tests locally without requiring an org or deploy cycle. It supports various features such as SOQL, DML operations, triggers, validation rules, database limits, standard library, testing framework, type checking, and debugging through an interactive debugger (VS Code or IntelliJ).</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.36</p>
<ul>
<li>
<p>Upgrade grpc To v1.83.0 Along With Related Dependencies</p>
</li>
<li>
<p>Keep Queue And Public Group Rows Distinct When They Share A DeveloperName</p>
</li>
<li>
<p>Evaluate Approval Entry Criteria And Resolve Name-Pointing Lookups Through The Name Object</p>
</li>
<li>
<p>Scope User-Permission Cache Invalidation To The Affected Users</p>
</li>
<li>
<p>Add The allOrNone Overload Of Approval.process With Partial-Success Results</p>
</li>
<li>
<p>Reuse Formula Parse Trees Instead Of Reparsing Them Per Query</p>
</li>
<li>
<p>Reject Invalid Statements, Increment Operands, And Assignment Targets</p>
</li>
<li>
<p>Skip Name Case-Folding And Schema Rechecks On Hot Lookup Paths</p>
</li>
<li>
<p>Render Non-String Values As Text In Flow Formula Text Functions</p>
</li>
<li>
<p>Classify Dangling Lookup Errors Per Field, Not Just For OwnerId</p>
</li>
<li>
<p>Build Flow-Generated Assignments As Assignment Expressions</p>
</li>
<li>
<p>Emit Flow-Generated Methods And Visited Flags In A Stable Order</p>
</li>
<li>
<p>Capture Each Source Tree Once Instead Of Walking It Repeatedly</p>
</li>
<li>
<p>Return Only The Branch A Row Takes Through A TYPEOF Clause</p>
</li>
</ul>
]]></content:encoded></item><item><title>Self-hosted Repository Visuals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/self-hosted-repository-visuals/</link><pubDate>Wed, 19 Aug 2026 06:31:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/self-hosted-repository-visuals/</guid><description>Version updated for https://github.com/overtrue/repo-visuals-action to version v1.3.1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates star history charts and contributor walls from your repository’s GitHub API data, publishing self-contained SVG files without external dependencies or tracking mechanisms. It supports multiple themes and chart variants, including area, line, and glow styles, with customizable color options and layout configurations for the contributor wall.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/overtrue/repo-visuals-action">https://github.com/overtrue/repo-visuals-action</a></strong> to version <strong>v1.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/self-hosted-repository-visuals">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates star history charts and contributor walls from your repository&rsquo;s GitHub API data, publishing self-contained SVG files without external dependencies or tracking mechanisms. It supports multiple themes and chart variants, including area, line, and glow styles, with customizable color options and layout configurations for the contributor wall.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release fixing the two failing workflows on <code>main</code>.</p>
<h2 id="fixed">Fixed</h2>
<ul>
<li><strong>Repository renames no longer break star history.</strong> <code>history.json</code> records the repository it belongs to, and a rename left every scheduled run failing with <code>star history belongs to &lt;old-name&gt;</code>. A mismatch is now checked against the repository&rsquo;s numeric id — which GitHub keeps resolving from a former name — so a rename is adopted and the stored name rewritten on the next run. History from a genuinely different repository, such as a fork carrying the output branch, is still refused. Falls back to the previous behaviour when <code>GITHUB_REPOSITORY_ID</code> is unavailable. (#8)</li>
<li><strong>Rebuilt <code>dist/index.cjs</code></strong> so the packaged bundle carries the undici 6.28.0 security bump from #7.</li>
</ul>
<p>No action is required for existing workflows. A repository renamed while using an earlier version repairs its own <code>history.json</code> on the first run after upgrading, with the recorded points preserved.</p>
<p><strong>Full changelog</strong>: <a href="https://github.com/overtrue/repo-visuals-action/compare/v1.3.0...v1.3.1">https://github.com/overtrue/repo-visuals-action/compare/v1.3.0...v1.3.1</a></p>
]]></content:encoded></item><item><title>Setup PanDA</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/setup-panda/</link><pubDate>Wed, 19 Aug 2026 06:30:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/setup-panda/</guid><description>Version updated for https://github.com/PanDAWMS/panda-compose to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action provides a self-contained Docker Compose stack for running a local PanDA workload management system, designed for development and CI testing of tools that integrate with PanDA. The action automates the setup and configuration of PanDA services including databases, message brokers, and servers, while also providing configuration options and scripts for submitting and managing jobs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PanDAWMS/panda-compose">https://github.com/PanDAWMS/panda-compose</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-panda">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action provides a self-contained Docker Compose stack for running a local PanDA workload management system, designed for development and CI testing of tools that integrate with PanDA. The action automates the setup and configuration of PanDA services including databases, message brokers, and servers, while also providing configuration options and scripts for submitting and managing jobs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add Dependabot configuration for GitHub Actions and Docker ecosystems by @wdconinc with @Copilot in <a href="https://github.com/PanDAWMS/panda-compose/pull/10">https://github.com/PanDAWMS/panda-compose/pull/10</a></li>
<li>chore(deps): bump actions/setup-python from 5 to 6 by @dependabot[bot] in <a href="https://github.com/PanDAWMS/panda-compose/pull/15">https://github.com/PanDAWMS/panda-compose/pull/15</a></li>
<li>chore(deps): bump actions/configure-pages from 5 to 6 by @dependabot[bot] in <a href="https://github.com/PanDAWMS/panda-compose/pull/13">https://github.com/PanDAWMS/panda-compose/pull/13</a></li>
<li>chore(deps): bump actions/deploy-pages from 4 to 5 by @dependabot[bot] in <a href="https://github.com/PanDAWMS/panda-compose/pull/14">https://github.com/PanDAWMS/panda-compose/pull/14</a></li>
<li>chore(deps): bump actions/checkout from 4 to 6 by @dependabot[bot] in <a href="https://github.com/PanDAWMS/panda-compose/pull/12">https://github.com/PanDAWMS/panda-compose/pull/12</a></li>
<li>chore(deps): bump actions/upload-pages-artifact from 3 to 5 by @dependabot[bot] in <a href="https://github.com/PanDAWMS/panda-compose/pull/11">https://github.com/PanDAWMS/panda-compose/pull/11</a></li>
<li>README.md: replace your-org with eic by @veprbl in <a href="https://github.com/PanDAWMS/panda-compose/pull/16">https://github.com/PanDAWMS/panda-compose/pull/16</a></li>
<li>doc: use PANDA_COMPOSE_LOCAL in example invocation by @veprbl in <a href="https://github.com/PanDAWMS/panda-compose/pull/17">https://github.com/PanDAWMS/panda-compose/pull/17</a></li>
<li>feat: publish docker-compose.yml as OCI artifact to ghcr.io by @wdconinc in <a href="https://github.com/PanDAWMS/panda-compose/pull/19">https://github.com/PanDAWMS/panda-compose/pull/19</a></li>
<li>feat: Docker-in-Docker job execution via host socket by @wdconinc in <a href="https://github.com/PanDAWMS/panda-compose/pull/18">https://github.com/PanDAWMS/panda-compose/pull/18</a></li>
<li>doc: brings all docs up to date with the current state of the stack by @wdconinc in <a href="https://github.com/PanDAWMS/panda-compose/pull/20">https://github.com/PanDAWMS/panda-compose/pull/20</a></li>
<li>fix: inline &ndash;script content as &lsquo;sh -c&rsquo; to bridge host-container gap by @wdconinc in <a href="https://github.com/PanDAWMS/panda-compose/pull/21">https://github.com/PanDAWMS/panda-compose/pull/21</a></li>
<li>chore(deps): bump docker/login-action from 3 to 4 by @dependabot[bot] in <a href="https://github.com/PanDAWMS/panda-compose/pull/22">https://github.com/PanDAWMS/panda-compose/pull/22</a></li>
<li>fix(ci): change regex for docker-compose checksum by @wdconinc in <a href="https://github.com/PanDAWMS/panda-compose/pull/23">https://github.com/PanDAWMS/panda-compose/pull/23</a></li>
<li>fix(ci): increase healthcheck windows for panda-database by @wdconinc in <a href="https://github.com/PanDAWMS/panda-compose/pull/24">https://github.com/PanDAWMS/panda-compose/pull/24</a></li>
<li>Fixes for partitions initialization and for CI by @veprbl in <a href="https://github.com/PanDAWMS/panda-compose/pull/29">https://github.com/PanDAWMS/panda-compose/pull/29</a></li>
<li>chore(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in <a href="https://github.com/PanDAWMS/panda-compose/pull/26">https://github.com/PanDAWMS/panda-compose/pull/26</a></li>
<li>chore(deps): bump actions/setup-python from 6 to 7 by @dependabot[bot] in <a href="https://github.com/PanDAWMS/panda-compose/pull/27">https://github.com/PanDAWMS/panda-compose/pull/27</a></li>
<li>docs: update eic/panda-compose references after transfer to PanDAWMS by @wenaus in <a href="https://github.com/PanDAWMS/panda-compose/pull/25">https://github.com/PanDAWMS/panda-compose/pull/25</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@wdconinc with @Copilot made their first contribution in <a href="https://github.com/PanDAWMS/panda-compose/pull/10">https://github.com/PanDAWMS/panda-compose/pull/10</a></li>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/PanDAWMS/panda-compose/pull/15">https://github.com/PanDAWMS/panda-compose/pull/15</a></li>
<li>@veprbl made their first contribution in <a href="https://github.com/PanDAWMS/panda-compose/pull/16">https://github.com/PanDAWMS/panda-compose/pull/16</a></li>
<li>@wenaus made their first contribution in <a href="https://github.com/PanDAWMS/panda-compose/pull/25">https://github.com/PanDAWMS/panda-compose/pull/25</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/PanDAWMS/panda-compose/compare/v1.0.0...v1.1.0">https://github.com/PanDAWMS/panda-compose/compare/v1.0.0...v1.1.0</a></p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/skilltotal-ai-component-security-scan/</link><pubDate>Wed, 19 Aug 2026 06:29:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.41.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SkillTotal is an open-source CLI engine that statically analyzes AI-related components, such as agent skills/plugins, MCP servers, and AI-generated projects, to identify potential security risks and dangers. It allows users to scan paths, git URLs, npm/pypi packages, or project archives without leaving their machines and provides detailed evidence-based reports.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.41.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SkillTotal is an open-source CLI engine that statically analyzes AI-related components, such as agent skills/plugins, MCP servers, and AI-generated projects, to identify potential security risks and dangers. It allows users to scan paths, git URLs, npm/pypi packages, or project archives without leaving their machines and provides detailed evidence-based reports.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Values published on purpose were reported as leaked credentials (ruleset 45).</strong> Sampling the
MCP-registry survey, all four of the first components carrying an &ldquo;embedded secret&rdquo; were of this
kind. PostHog project keys (<code>phc_</code>, documented as safe to expose in client code) and base58
on-chain addresses (a Solana program id or mint — public data, and length-bounded so a keypair
still counts) now join the Algolia DocSearch and client-telemetry keys the scanner already
recognised. <code>browser-use</code> went <code>high</code> → <code>low</code>, <code>zeta-chain/cli</code> <code>high</code> → <code>low</code>.</li>
<li><strong>A comment mentioning <code>eval</code> was read as dynamic execution.</strong> <code>ST-DYN-NODE</code> declared no
code-context policy, so <code>// guarded string eval (no DOM types)</code> matched — the same demotion the
exposure and shell rules already use now applies.</li>
</ul>
]]></content:encoded></item><item><title>Acquit Test Selection</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/acquit-test-selection/</link><pubDate>Wed, 19 Aug 2026 06:28:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/acquit-test-selection/</guid><description>Version updated for https://github.com/rajeev-chaurasia/acquit to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Acquit is a GitHub Action that uses dependency analysis and static checks to skip affected tests on pull requests, providing evidence for skips. It aims to reduce test suite execution time by skipping tests that cannot be proven safe based on import statements alone, while still running the full suite in cases where Acquit cannot reason about a PR’s impact.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rajeev-chaurasia/acquit">https://github.com/rajeev-chaurasia/acquit</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/acquit-test-selection">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Acquit is a GitHub Action that uses dependency analysis and static checks to skip affected tests on pull requests, providing evidence for skips. It aims to reduce test suite execution time by skipping tests that cannot be proven safe based on import statements alone, while still running the full suite in cases where Acquit cannot reason about a PR&rsquo;s impact.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="012-2026-08-19"><a href="https://github.com/rajeev-chaurasia/acquit/compare/v0.1.1...v0.1.2">0.1.2</a> (2026-08-19)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>handle nested pytest configs and sync release pins (<a href="https://github.com/rajeev-chaurasia/acquit/issues/9">#9</a>) (<a href="https://github.com/rajeev-chaurasia/acquit/commit/d5bb93263eabd8d610bc2071f7cc3e4531eb1206">d5bb932</a>)</li>
</ul>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/rumdl-action/</link><pubDate>Wed, 19 Aug 2026 06:26:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.57.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: rumdl is a high-performance, Rust-based Markdown linter and formatter that offers quick linting and automatic formatting capabilities. It supports multiple Markdown flavors with auto-detection, is zero-dependency, and highly configurable via TOML files. With intelligent caching, it significantly improves performance by only re-linting changed files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.57</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong>
rumdl is a high-performance, Rust-based Markdown linter and formatter that offers quick linting and automatic formatting capabilities. It supports multiple Markdown flavors with auto-detection, is zero-dependency, and highly configurable via TOML files. With intelligent caching, it significantly improves performance by only re-linting changed files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>MD013</strong>: let a sentence open with a number under require-sentence-capital (<a href="https://github.com/rvben/rumdl/commit/5060333b9237cf0f63b095df388d65e8b01799f5">5060333</a>)</li>
<li><strong>lsp</strong>: keep a CRLF document&rsquo;s line endings through fixes and code actions (<a href="https://github.com/rvben/rumdl/commit/c88a7da9afc9738b5be40a0dd4a233d273ec11e2">c88a7da</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.57-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.57-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.57-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.57-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-x86_64-apple-darwin.tar.gz">rumdl-v0.2.57-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-aarch64-apple-darwin.tar.gz">rumdl-v0.2.57-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-x86_64-pc-windows-msvc.zip">rumdl-v0.2.57-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.57/rumdl-v0.2.57-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/custom-amazon-bedrock-agent-action/</link><pubDate>Wed, 19 Aug 2026 06:25:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback based on customized prompts. It integrates with Amazon Bedrock Knowledge Bases to enhance the analysis, providing context-aware insights and memory support across multiple PRs. The action is customizable for specific needs and can be used for code quality improvement, security assessments, and performance optimizations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback based on customized prompts. It integrates with Amazon Bedrock Knowledge Bases to enhance the analysis, providing context-aware insights and memory support across multiple PRs. The action is customizable for specific needs and can be used for code quality improvement, security assessments, and performance optimizations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/smyklot/</link><pubDate>Wed, 19 Aug 2026 06:24:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.43.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the .github/CODEOWNERS file. It supports CODEOWNERS-based permissions, multiple command formats (slash commands, mentions, bare commands), and provides flexibility in merge methods and reaction handling, with minimal permissions and support for running as both an Action and a webhook service across all repositories the App is installed on.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.43.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the <code>.github/CODEOWNERS</code> file. It supports CODEOWNERS-based permissions, multiple command formats (slash commands, mentions, bare commands), and provides flexibility in merge methods and reaction handling, with minimal permissions and support for running as both an Action and a webhook service across all repositories the App is installed on.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1431-2026-08-18"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.43.0...v1.43.1">1.43.1</a> (2026-08-18)</h2>
<h2 id="smyklot-v1431">Smyklot v1.43.1</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.43.1</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>9b48f9cc604cf67caa2fe3486019d2fe8f7ac84d chore(release): bump version to 1.43.1</li>
<li>fd5cee8b625336a32055581e73f3b92e31406300 fix(orgsync): stop rewriting a matching ruleset (#272)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/update-a-config-file-with-values-from-environment/</link><pubDate>Wed, 19 Aug 2026 06:23:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces environment variables in a specified configuration file. It automates the process of dynamically substituting placeholders with actual values from the environment, making it easier to manage sensitive information securely and easily deploy configurations across different environments or instances.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces environment variables in a specified configuration file. It automates the process of dynamically substituting placeholders with actual values from the environment, making it easier to manage sensitive information securely and easily deploy configurations across different environments or instances.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add support for .env files (e706be3)</li>
<li>chore: More info (d440258)</li>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Wed, 19 Aug 2026 06:23:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action deploy-swarm-service automates the deployment of a Docker Swarm service by bundling and committing the dist folder to the repository before pushing changes. This ensures that the built assets are included in the commit, facilitating easier deployment and version control for the Docker Swarm service.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>deploy-swarm-service</code> automates the deployment of a Docker Swarm service by bundling and committing the <code>dist</code> folder to the repository before pushing changes. This ensures that the built assets are included in the commit, facilitating easier deployment and version control for the Docker Swarm service.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>DockDesk Neural Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/dockdesk-neural-auditor/</link><pubDate>Wed, 19 Aug 2026 06:23:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/dockdesk-neural-auditor/</guid><description>Version updated for https://github.com/srivatsa-source/dockdesk to version v3.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary DockDesk v3.1.3 is a local-first semantic documentation auditor that checks code logic against documentation claims, ensuring code and docs never drift apart without cloud API calls. It helps prevent privacy risks, catches documentation rot, and reduces infrastructure costs by running entirely on local hardware with efficient SLMs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/srivatsa-source/dockdesk">https://github.com/srivatsa-source/dockdesk</a></strong> to version <strong>v3.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dockdesk-neural-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>DockDesk v3.1.3 is a local-first semantic documentation auditor that checks code logic against documentation claims, ensuring code and docs never drift apart without cloud API calls. It helps prevent privacy risks, catches documentation rot, and reduces infrastructure costs by running entirely on local hardware with efficient SLMs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/srivatsa-source/dockdesk/compare/v3.1.1...v3.1.2">https://github.com/srivatsa-source/dockdesk/compare/v3.1.1...v3.1.2</a></p>
]]></content:encoded></item><item><title>SimpleCov Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/simplecov-gate/</link><pubDate>Wed, 19 Aug 2026 06:21:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/simplecov-gate/</guid><description>Version updated for https://github.com/srozen/simplecov-gate to version 1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SimpleCov Gate GitHub Action is a tool that automates the process of enforcing minimum line coverage requirements for your Ruby projects using SimpleCov. It integrates seamlessly with GitHub Actions, allowing you to add a check run to verify that your code coverage meets specified thresholds. The action reads the total line coverage from coverage.json and compares it against a specified minimum threshold, emitting an error if the coverage falls below the required level. This helps maintain high code quality and ensures that critical parts of your project are well-covered by tests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/srozen/simplecov-gate">https://github.com/srozen/simplecov-gate</a></strong> to version <strong>1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/simplecov-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The SimpleCov Gate GitHub Action is a tool that automates the process of enforcing minimum line coverage requirements for your Ruby projects using SimpleCov. It integrates seamlessly with GitHub Actions, allowing you to add a check run to verify that your code coverage meets specified thresholds. The action reads the total line coverage from <code>coverage.json</code> and compares it against a specified minimum threshold, emitting an error if the coverage falls below the required level. This helps maintain high code quality and ensures that critical parts of your project are well-covered by tests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add GitHub Action &ldquo;SimpleCov Gate&rdquo; to enforce coverage thresholds by @srozen in <a href="https://github.com/srozen/simplecov-gate/pull/2">https://github.com/srozen/simplecov-gate/pull/2</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@srozen made their first contribution in <a href="https://github.com/srozen/simplecov-gate/pull/2">https://github.com/srozen/simplecov-gate/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/srozen/simplecov-gate/commits/1.0.0">https://github.com/srozen/simplecov-gate/commits/1.0.0</a></p>
]]></content:encoded></item><item><title>pinprick-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/pinprick-action/</link><pubDate>Wed, 19 Aug 2026 06:21:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/pinprick-action/</guid><description>Version updated for https://github.com/starhaven-io/pinprick-action to version v0.5.3.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates security audits of GitHub Actions supply chain integrity using the pinprick tool, which checks for runtime fetch patterns bypassing pinning and verifies action references. It supports different runners and can be configured to either upload results to GitHub code scanning or print them to the workflow log. The action is designed to be used with or without GitHub Advanced Security, depending on requirements for security alerts and reporting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/starhaven-io/pinprick-action">https://github.com/starhaven-io/pinprick-action</a></strong> to version <strong>v0.5.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pinprick-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates security audits of GitHub Actions supply chain integrity using the pinprick tool, which checks for runtime fetch patterns bypassing pinning and verifies action references. It supports different runners and can be configured to either upload results to GitHub code scanning or print them to the workflow log. The action is designed to be used with or without GitHub Advanced Security, depending on requirements for security alerts and reporting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Pins pinprick 0.23.1 as the default engine version.</p>
]]></content:encoded></item><item><title>Get PR Push token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/get-pr-push-token/</link><pubDate>Wed, 19 Aug 2026 06:19:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/get-pr-push-token/</guid><description>Version updated for https://github.com/tiangolo/pr-push to version 0.0.4.
This action is used across all versions by 47 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PR Push GitHub App issues short-lived, repository-scoped tokens to approved workflows that update existing pull request branches. It automates token management for workflow-triggered pushes to pull requests and manual commits on forks. The action uses GitHub’s OIDC authentication to securely grant access to repository contents and pull requests, ensuring only authorized workflows can generate and use tokens.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tiangolo/pr-push">https://github.com/tiangolo/pr-push</a></strong> to version <strong>0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>47</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/get-pr-push-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The PR Push GitHub App issues short-lived, repository-scoped tokens to approved workflows that update existing pull request branches. It automates token management for workflow-triggered pushes to pull requests and manual commits on forks. The action uses GitHub&rsquo;s OIDC authentication to securely grant access to repository contents and pull requests, ensuring only authorized workflows can generate and use tokens.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="features">Features</h3>
<ul>
<li>✨ Support workflow dispatch on PR branches. PR <a href="https://github.com/tiangolo/pr-push/pull/19">#19</a> by <a href="https://github.com/tiangolo">@tiangolo</a>.</li>
<li>✨ Use PR Submit for release PRs. PR <a href="https://github.com/tiangolo/pr-push/pull/16">#16</a> by <a href="https://github.com/tiangolo">@tiangolo</a>.</li>
</ul>
<h3 id="docs">Docs</h3>
<ul>
<li>📝 Use GitHub CLI for Git authentication. PR <a href="https://github.com/tiangolo/pr-push/pull/18">#18</a> by <a href="https://github.com/tiangolo">@tiangolo</a>.</li>
<li>📝 Use FastAPI Cloud deployment domain. PR <a href="https://github.com/tiangolo/pr-push/pull/15">#15</a> by <a href="https://github.com/tiangolo">@tiangolo</a>.</li>
<li>📝 Show PR Push commit identity. PR <a href="https://github.com/tiangolo/pr-push/pull/14">#14</a> by <a href="https://github.com/tiangolo">@tiangolo</a>.</li>
</ul>
<h3 id="internal">Internal</h3>
<ul>
<li>🎨 Align logo background color. PR <a href="https://github.com/tiangolo/pr-push/pull/13">#13</a> by <a href="https://github.com/tiangolo">@tiangolo</a>.</li>
</ul>
]]></content:encoded></item><item><title>Code Review Board</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/code-review-board/</link><pubDate>Wed, 19 Aug 2026 06:18:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/code-review-board/</guid><description>Version updated for https://github.com/tossneon/code-review-board-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “Code Review Board” automates the process of reviewing pull requests using multiple AI personas without relying on third-party software or storing sensitive information. It uses Anthropic’s Claude API to generate independent reviews for each review persona, which are then combined into a single comment posted directly onto the PR. This tool helps prevent sycophancy in code reviews and provides a robust solution for maintaining high-quality code across multiple teams.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tossneon/code-review-board-action">https://github.com/tossneon/code-review-board-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/code-review-board">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;Code Review Board&rdquo; automates the process of reviewing pull requests using multiple AI personas without relying on third-party software or storing sensitive information. It uses Anthropic&rsquo;s Claude API to generate independent reviews for each review persona, which are then combined into a single comment posted directly onto the PR. This tool helps prevent sycophancy in code reviews and provides a robust solution for maintaining high-quality code across multiple teams.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>docs: remove monorepo-internal note (this repo is now the standalone distribution) (647fa6a)</li>
<li>니치템플릿: Code Review Board Action 별도 리포 분리 + Marketplace 제출 (회장 승인 2026-08-17) (6827efa)</li>
<li>code-review-board-action: e2e 검증에서 발견한 두 가지 실사용 차단 버그 수정 (7fa81ca)</li>
<li>niche-templates: Gumroad 스토어명 변경(tossneon→nadacompany)에 따른 링크 일괄 수정 (e0561b3)</li>
<li>Merge remote-tracking branch &lsquo;origin/master&rsquo; into claude/jeongyeon-a-rq6q5q (41caa5f)</li>
<li>Merge: 나다컴퍼니9 Round 1 신사업 서칭 결과 병합 (052688a)</li>
<li>company5: ㅑ회차 대본 착수 — 기존 초안 이슈 정리 + 학습단어 추천안(회장 컨펌 대기) (14fd11d)</li>
<li>Merge: 하윤 세션의 쿠팡파트너스 인수인계 준비 작업과 나다컴퍼니7 실제 신설 병합 (aa49c61)</li>
<li>Merge remote-tracking branch &lsquo;origin/master&rsquo; (ce21126)</li>
<li>Merge remote-tracking branch &lsquo;origin/master&rsquo; into claude/jeongyeon-a-rq6q5q (9cb5f25)</li>
</ul>
]]></content:encoded></item><item><title>Rabbit Automation Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/rabbit-automation-action/</link><pubDate>Wed, 19 Aug 2026 06:17:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/rabbit-automation-action/</guid><description>Version updated for https://github.com/udx/github-rabbit-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Rabbit Automation Action automates the deployment of cloud infrastructure using Terraform, AWS, and Kubernetes by processing YAML configuration files in a .rabbit/ directory. It simplifies the process of setting up infrastructure across different environments with minimal setup. The action integrates seamlessly with GitHub workflows, enabling automatic planning and application or destruction based on actions like pushes, PRs, deletions, or manual triggers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/udx/github-rabbit-action">https://github.com/udx/github-rabbit-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rabbit-automation-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Rabbit Automation Action automates the deployment of cloud infrastructure using Terraform, AWS, and Kubernetes by processing YAML configuration files in a <code>.rabbit/</code> directory. It simplifies the process of setting up infrastructure across different environments with minimal setup. The action integrates seamlessly with GitHub workflows, enabling automatic planning and application or destruction based on actions like pushes, PRs, deletions, or manual triggers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Includes self-contained lifecycle resolution and the current public action contract.</p>
]]></content:encoded></item><item><title>verbatra</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/verbatra/</link><pubDate>Wed, 19 Aug 2026 06:16:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/verbatra/</guid><description>Version updated for https://github.com/verbatra/action to version v2.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: Purpose: The verbatra GitHub Action automates i18n translation and drift checks in CI/CD pipelines, using OpenAI, Anthropic, Gemini, DeepL, or local models.
Functionality: It reads locale files to detect missing or drifted translations, translates them with specified providers, and annotates failures in pull requests. The action can run translate, check, or diff commands, generating job summaries and GitHub annotations for visibility.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/verbatra/action">https://github.com/verbatra/action</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/verbatra">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<h3 id="summary">Summary:</h3>
<p><strong>Purpose:</strong> The verbatra GitHub Action automates i18n translation and drift checks in CI/CD pipelines, using OpenAI, Anthropic, Gemini, DeepL, or local models.</p>
<p><strong>Functionality:</strong> It reads locale files to detect missing or drifted translations, translates them with specified providers, and annotates failures in pull requests. The action can run <code>translate</code>, <code>check</code>, or <code>diff</code> commands, generating job summaries and GitHub annotations for visibility.</p>
<p><strong>Solves/Automates Problems:</strong> Automates i18n processes by filling gaps in locale files, ensuring translation consistency across applications, and providing clear feedback through GitHub actions.</p>
<p><strong>Key Capabilities:</strong> Runs verbatra CLI commands (<code>translate</code>, <code>check</code>, <code>diff</code>), reports changes via GitHub annotations, gates pull requests on drift, and supports multiple language translation providers.</p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/rustscript-action/</link><pubDate>Wed, 19 Aug 2026 06:15:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.6.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a powerful tool that allows developers to write and execute Rust scripts directly, bypassing the need for compilation. It provides a practical subset of Rust’s syntax and features, enabling users to quickly run their scripts without additional setup. The action automates validation, execution, and build processes using Rust, making it an efficient choice for scripting and automation tasks in environments where traditional shell scripting is not feasible or preferred.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.6.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a powerful tool that allows developers to write and execute Rust scripts directly, bypassing the need for compilation. It provides a practical subset of Rust&rsquo;s syntax and features, enabling users to quickly run their scripts without additional setup. The action automates validation, execution, and build processes using Rust, making it an efficient choice for scripting and automation tasks in environments where traditional shell scripting is not feasible or preferred.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.6.5...v0.6.6">https://github.com/VladasZ/rustscript/compare/v0.6.5...v0.6.6</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/b.ia-accessibility-checker/</link><pubDate>Wed, 19 Aug 2026 06:13:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action designed to automate accessibility checks within your CI/CD pipeline. It evaluates code against specified audiences and WCAG guidelines, ensuring that products meet accessibility standards. By focusing on specific audiences, companies can optimize their resources effectively and avoid the need for external solutions. The action uses AI to analyze guidelines and enforce compliance based on defined requirements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action designed to automate accessibility checks within your CI/CD pipeline. It evaluates code against specified audiences and WCAG guidelines, ensuring that products meet accessibility standards. By focusing on specific audiences, companies can optimize their resources effectively and avoid the need for external solutions. The action uses AI to analyze guidelines and enforce compliance based on defined requirements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>Causal Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/causal-verify/</link><pubDate>Wed, 19 Aug 2026 06:12:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/19/causal-verify/</guid><description>Version updated for https://github.com/zensteagarden/causal-verifier-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the verification of AI-generated software using a causal verification gate. It sends Python source and pytest tests to the gateway, verifying that the generated code meets specified contract requirements before passing CI. The action ensures data integrity and prevents unauthorized access by masking API keys and blocking paths from escaping the GitHub workspace.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zensteagarden/causal-verifier-action">https://github.com/zensteagarden/causal-verifier-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/causal-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the verification of AI-generated software using a causal verification gate. It sends Python source and pytest tests to the gateway, verifying that the generated code meets specified contract requirements before passing CI. The action ensures data integrity and prevents unauthorized access by masking API keys and blocking paths from escaping the GitHub workspace.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Document the MVP developer launch by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/4">https://github.com/zensteagarden/causal-verifier-action/pull/4</a></li>
<li>Add public live receipt proof workflow by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/5">https://github.com/zensteagarden/causal-verifier-action/pull/5</a></li>
<li>Pin the first public verification receipt by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/6">https://github.com/zensteagarden/causal-verifier-action/pull/6</a></li>
<li>Publish and independently verify signed receipts by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/7">https://github.com/zensteagarden/causal-verifier-action/pull/7</a></li>
<li>Pin the issuer-authenticated public receipt by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/8">https://github.com/zensteagarden/causal-verifier-action/pull/8</a></li>
<li>Add public offline receipt verifier by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/9">https://github.com/zensteagarden/causal-verifier-action/pull/9</a></li>
<li>Require trusted signed receipts in the Action by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/10">https://github.com/zensteagarden/causal-verifier-action/pull/10</a></li>
<li>Publish automatic signed-gate proof by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/11">https://github.com/zensteagarden/causal-verifier-action/pull/11</a></li>
<li>Make public signed-gate proof self-contained by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/13">https://github.com/zensteagarden/causal-verifier-action/pull/13</a></li>
<li>Match the live signup contract in signed proof by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/14">https://github.com/zensteagarden/causal-verifier-action/pull/14</a></li>
<li>Use a valid free-tier channel in public proof by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/15">https://github.com/zensteagarden/causal-verifier-action/pull/15</a></li>
<li>Fix disposable-key environment handoff by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/16">https://github.com/zensteagarden/causal-verifier-action/pull/16</a></li>
<li>Accept standard DSSE base64 encoding by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/17">https://github.com/zensteagarden/causal-verifier-action/pull/17</a></li>
<li>Package trusted verification records v1.1.0 by @zensteagarden in <a href="https://github.com/zensteagarden/causal-verifier-action/pull/18">https://github.com/zensteagarden/causal-verifier-action/pull/18</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/zensteagarden/causal-verifier-action/compare/v1.0.0...v1.1.0">https://github.com/zensteagarden/causal-verifier-action/compare/v1.0.0...v1.1.0</a></p>
]]></content:encoded></item><item><title>Kaniscope AI Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/kaniscope-ai-code-review/</link><pubDate>Tue, 18 Aug 2026 13:39:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/kaniscope-ai-code-review/</guid><description>Version updated for https://github.com/nhatvu148/kaniscope-action to version v0.1.10.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Kaniscope GitHub Action automates AI code reviews by posting line-anchored inline comments and a summary comment on pull requests using the OpenRouter AI engine. It solves problems related to quickly adding AI-powered review features to GitHub workflows without complex setup, offering an advisory review process and being cost-effective with low-cost models from OpenRouter.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nhatvu148/kaniscope-action">https://github.com/nhatvu148/kaniscope-action</a></strong> to version <strong>v0.1.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniscope-ai-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Kaniscope GitHub Action automates AI code reviews by posting line-anchored inline comments and a summary comment on pull requests using the OpenRouter AI engine. It solves problems related to quickly adding AI-powered review features to GitHub workflows without complex setup, offering an advisory review process and being cost-effective with low-cost models from OpenRouter.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Merge pull request #7 — ship a prebuilt GHCR image instead of compiling on every run</p>
<p>perf: ship a prebuilt GHCR image instead of compiling on every run</p>
]]></content:encoded></item><item><title>lacuna-cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/lacuna-cli/</link><pubDate>Tue, 18 Aug 2026 13:38:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/lacuna-cli/</guid><description>Version updated for https://github.com/Octagon-simon/lacuna to version ext-v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Lacuna is a command-line tool that automates the process of writing tests to fill coverage gaps in your code. It uses an AI model to suggest test cases, runs them, and retries those that fail until they pass. The action helps maintain high code coverage by identifying untested code and generating corresponding tests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Octagon-simon/lacuna">https://github.com/Octagon-simon/lacuna</a></strong> to version <strong>ext-v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lacuna-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Lacuna is a command-line tool that automates the process of writing tests to fill coverage gaps in your code. It uses an AI model to suggest test cases, runs them, and retries those that fail until they pass. The action helps maintain high code coverage by identifying untested code and generating corresponding tests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Octagon-simon/lacuna/compare/ext-v0.1.0...ext-v0.2.0">https://github.com/Octagon-simon/lacuna/compare/ext-v0.1.0...ext-v0.2.0</a></p>
]]></content:encoded></item><item><title>Oculum Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/oculum-security-scan/</link><pubDate>Tue, 18 Aug 2026 13:37:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/oculum-security-scan/</guid><description>Version updated for https://github.com/OculumDev/oculum-action to version 1.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Oculum Security Scan action automates security scanning of LLM-powered applications using AI technology. It detects prompt injection, hardcoded secrets, SQL injection, XSS, and other vulnerabilities in codebases. The action supports both the free tier with pattern-matching scans (no API key required) and a validated tier that uses AI for enhanced accuracy (requires an API key). It provides detailed scan reports via PR comments and inline annotations on diffs, making it easy to integrate into GitHub workflows for continuous security monitoring.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OculumDev/oculum-action">https://github.com/OculumDev/oculum-action</a></strong> to version <strong>1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oculum-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Oculum Security Scan action automates security scanning of LLM-powered applications using AI technology. It detects prompt injection, hardcoded secrets, SQL injection, XSS, and other vulnerabilities in codebases. The action supports both the free tier with pattern-matching scans (no API key required) and a validated tier that uses AI for enhanced accuracy (requires an API key). It provides detailed scan reports via PR comments and inline annotations on diffs, making it easy to integrate into GitHub workflows for continuous security monitoring.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Early Release of Oculum Security Scanner</p>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/odin-scan-smart-contract-security/</link><pubDate>Tue, 18 Aug 2026 13:36:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates smart contract security analysis for CosmWasm, Solana, and EVM projects using AI-powered tools. It integrates with GitHub workflows to detect vulnerabilities before deployment by uploading SARIF files for native security alerts, providing PR comments and inline annotations on findings. Users can specify platforms, severity thresholds, and configuration options for more tailored scans.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates smart contract security analysis for CosmWasm, Solana, and EVM projects using AI-powered tools. It integrates with GitHub workflows to detect vulnerabilities before deployment by uploading SARIF files for native security alerts, providing PR comments and inline annotations on findings. Users can specify platforms, severity thresholds, and configuration options for more tailored scans.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial Release</p>
<p>AI-powered smart contract security analysis, now integrated directly into your GitHub workflow.</p>
<p>✨ Features</p>
<p>Multi-Platform Support</p>
<ul>
<li>CosmWasm - Rust-based smart contracts for Cosmos SDK</li>
<li>Solana (SVM) - Anchor and native Solana programs</li>
<li>EVM - Solidity and Vyper contracts</li>
<li>Auto-detection - Automatically identifies platform from your repo</li>
</ul>
<p>GitHub Integration</p>
<ul>
<li>Code Scanning - SARIF upload for native security alerts in the Security tab</li>
<li>PR Comments - Severity summary and top findings posted directly on pull requests</li>
<li>Inline Annotations - Critical/high findings appear as errors, medium/low as warnings on diffs</li>
<li>Artifact Upload - Full JSON report available as workflow artifact</li>
</ul>
<p>Customization</p>
<ul>
<li>Severity Thresholds - Fail builds at critical, high, medium, or low severity</li>
<li>Platform Override - Force specific platform detection when auto-detect isn&rsquo;t enough</li>
<li>Timeout Control - Configurable analysis timeout (default: 30 minutes)</li>
<li>Flexible Triggers - Run on push, PR, schedule, or manual dispatch</li>
</ul>
<p>🚀 Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Security Scan</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&#39;on&#39;</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">main</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">security-events</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">api-key</span>: <span style="color:#e6db74">&#39;${{ secrets.ODIN_SCAN_API_KEY }}&#39;</span>
</span></span></code></pre></div><p>📋 Requirements</p>
<ul>
<li>Odin Scan Pro subscription - Required for API access</li>
<li>API Key - Generate at <a href="https://odinscan.ai/dashboard/settings">https://odinscan.ai/dashboard/settings</a></li>
<li>GitHub Permissions - contents: read, security-events: write (for SARIF), pull-requests: write (for
comments)</li>
</ul>
<p>🔧 Configuration</p>
<p>All Inputs</p>
<p>| ┌────────────────────┬─────────────────────┬──────────────────────────────────────────────┐ |
| │       Input        │       Default       │                 Description                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ api-key            │ Required            │ Your Odin Scan API key (odin_sk_*)           │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ platform           │ auto                │ Target platform: auto, cosmwasm, solana, evm │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ severity-threshold │ high                │ Fail at: critical, high, medium, low, none   │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ fail-on-findings   │ true                │ Whether to fail workflow on findings         │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ comment-on-pr      │ true                │ Post summary comment on PRs                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-sarif       │ true                │ Upload SARIF to Code Scanning                │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-artifact    │ true                │ Upload full report as artifact               │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ timeout            │ 1800                │ Max analysis wait time (seconds)             │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ github-token       │ ${{ github.token }} │ Token for PR comments and SARIF              │ |
| └────────────────────┴─────────────────────┴──────────────────────────────────────────────┘ |</p>
<p>All Outputs</p>
<ul>
<li>analysis-id - Unique analysis identifier</li>
<li>status - Analysis status (completed, failed)</li>
<li>total-findings - Total number of findings</li>
<li>critical-count, high-count, medium-count, low-count - Counts by severity</li>
<li>report-url - Link to full report on Odin Scan</li>
<li>sarif-file - Path to generated SARIF file</li>
</ul>
<p>📝 Example Workflows</p>
<p>Basic (Auto-detect)</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span></code></pre></div><p>EVM with Medium Threshold</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">platform</span>: <span style="color:#ae81ff">evm</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">severity-threshold</span>: <span style="color:#ae81ff">medium</span>
</span></span></code></pre></div><p>Only on Solidity Changes</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#39;**.sol&#39;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">foundry.toml</span>
</span></span></code></pre></div><p>🔒 Security &amp; Privacy</p>
<ul>
<li>All API communication over HTTPS (TLS 1.2+)</li>
<li>API keys automatically masked in logs</li>
<li>No data stored by the action (stateless)</li>
<li>See <a href="https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md">https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md</a> for details</li>
</ul>
<p>📖 Documentation</p>
<ul>
<li>Action README - <a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></li>
<li>Odin Scan Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
<li>Get API Key - <a href="https://app.odinscan.ai/settings">https://app.odinscan.ai/settings</a></li>
</ul>
<p>🐛 Known Limitations</p>
<ul>
<li>Private repos - Requires github-token with repo access</li>
<li>Large repos - May need increased timeout for complex codebases</li>
<li>Code Scanning - Requires GitHub Advanced Security on private repos</li>
</ul>
<p>🙏 Support</p>
<ul>
<li>Issues - <a href="https://github.com/Odin-Scan/odin-scan-action/issues">https://github.com/Odin-Scan/odin-scan-action/issues</a></li>
<li>Email - <a href="mailto:support@odinscan.ai">support@odinscan.ai</a></li>
<li>Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
</ul>
<hr>
<p>Full Changelog: <a href="https://github.com/Odin-Scan/odin-scan-action/commits/v1">https://github.com/Odin-Scan/odin-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>Git Mirror Repo</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/git-mirror-repo/</link><pubDate>Tue, 18 Aug 2026 13:35:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/git-mirror-repo/</guid><description>Version updated for https://github.com/Omikorin/git-mirror to version v1.1.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Git Mirror action automatically mirrors the state of a repository to another specified target repository, supporting HTTPS, SSH, and LFS. It detects LFS protocol automatically if the repository has already been downloaded. The action supports mirroring via SSH or HTTPS with optional username, token authentication, strict host key verification, and dry run options. It is recommended to use unique concurrency groups in workflows to mitigate race condition risks when running --mirror actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Omikorin/git-mirror">https://github.com/Omikorin/git-mirror</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/git-mirror-repo">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Git Mirror action automatically mirrors the state of a repository to another specified target repository, supporting HTTPS, SSH, and LFS. It detects LFS protocol automatically if the repository has already been downloaded. The action supports mirroring via SSH or HTTPS with optional username, token authentication, strict host key verification, and dry run options. It is recommended to use unique concurrency groups in workflows to mitigate race condition risks when running <code>--mirror</code> actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>defensive programming for intercompatibility between different runners and git hosts</li>
<li>security fixes that mitigate risk of running the script directly on own desktop</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Omikorin/git-mirror/compare/v1.0.0...v1.1.0">https://github.com/Omikorin/git-mirror/compare/v1.0.0...v1.1.0</a></p>
]]></content:encoded></item><item><title>vord Static Analysis</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/vord-static-analysis/</link><pubDate>Tue, 18 Aug 2026 13:34:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/vord-static-analysis/</guid><description>Version updated for https://github.com/pmaojo/vord to version v0.13.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary vord is a static analysis tool written in Rust that provides a guardrail for AI agents and coding agents, ensuring they write high-quality code before it reaches disk. It can be installed via various methods, including npm, Homebrew, or Docker, and offers features such as hook installation to gate agent writes, CI integration, support for multiple languages, and plugin integrations with Claude Code and DeepSeek Harness platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pmaojo/vord">https://github.com/pmaojo/vord</a></strong> to version <strong>v0.13.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vord-static-analysis">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>vord is a static analysis tool written in Rust that provides a guardrail for AI agents and coding agents, ensuring they write high-quality code before it reaches disk. It can be installed via various methods, including npm, Homebrew, or Docker, and offers features such as hook installation to gate agent writes, CI integration, support for multiple languages, and plugin integrations with Claude Code and DeepSeek Harness platforms.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add Gherkin BDD scaffolds to all kickoff templates by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/182">https://github.com/pmaojo/vord/pull/182</a></li>
<li>Fix false positives in missing list key and exhaustive deps rules by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/183">https://github.com/pmaojo/vord/pull/183</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.12.0...v0.13.1">https://github.com/pmaojo/vord/compare/v0.12.0...v0.13.1</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>Add Gherkin BDD scaffolds to all kickoff templates by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/182">https://github.com/pmaojo/vord/pull/182</a></li>
<li>Fix false positives in missing list key and exhaustive deps rules by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/183">https://github.com/pmaojo/vord/pull/183</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.12.0...v0.13.1">https://github.com/pmaojo/vord/compare/v0.12.0...v0.13.1</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>Add Gherkin BDD scaffolds to all kickoff templates by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/182">https://github.com/pmaojo/vord/pull/182</a></li>
<li>Fix false positives in missing list key and exhaustive deps rules by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/183">https://github.com/pmaojo/vord/pull/183</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.12.0...v0.13.1">https://github.com/pmaojo/vord/compare/v0.12.0...v0.13.1</a></p>
<h2 id="whats-changed-4">What&rsquo;s Changed</h2>
<ul>
<li>Add Gherkin BDD scaffolds to all kickoff templates by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/182">https://github.com/pmaojo/vord/pull/182</a></li>
<li>Fix false positives in missing list key and exhaustive deps rules by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/183">https://github.com/pmaojo/vord/pull/183</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.12.0...v0.13.1">https://github.com/pmaojo/vord/compare/v0.12.0...v0.13.1</a></p>
<h2 id="whats-changed-5">What&rsquo;s Changed</h2>
<ul>
<li>Add Gherkin BDD scaffolds to all kickoff templates by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/182">https://github.com/pmaojo/vord/pull/182</a></li>
<li>Fix false positives in missing list key and exhaustive deps rules by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/183">https://github.com/pmaojo/vord/pull/183</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.12.0...v0.13.1">https://github.com/pmaojo/vord/compare/v0.12.0...v0.13.1</a></p>
]]></content:encoded></item><item><title>GPG Import</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/gpg-import/</link><pubDate>Tue, 18 Aug 2026 13:33:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/gpg-import/</guid><description>Version updated for https://github.com/purpleclay/gpg-import-action to version v0.2.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GPG Import Action automates the process of importing and configuring a GPG key for Git signing. It supports both ASCII armored and base64-encoded formats, allows selecting specific keys or subkeys by fingerprint, and provides options to skip git configuration and override committer identity. The action is designed to streamline the setup of GPG-based signing in GitHub workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/purpleclay/gpg-import-action">https://github.com/purpleclay/gpg-import-action</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gpg-import">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GPG Import Action automates the process of importing and configuring a GPG key for Git signing. It supports both ASCII armored and base64-encoded formats, allows selecting specific keys or subkeys by fingerprint, and provides options to skip git configuration and override committer identity. The action is designed to streamline the setup of GPG-based signing in GitHub workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v020---august-18-2026">v0.2.0 - August 18, 2026</h2>
<p><a href="#new-features"><strong><code>1</code></strong></a> new feature</p>
<h2 id="contributors">Contributors</h2>
<ul>
<li><img src="https://avatars.githubusercontent.com/u/106762954?v=4&size=20" align="center">  @purpleclay (<a href="https://github.com/purpleclay/gpg-import-action/commits/v0.2.0?author=purpleclay&amp;since=2026-08-17&amp;until=2026-08-18"><strong><code>3</code></strong></a> commits)</li>
</ul>
<h2 id="new-features">New Features</h2>
<ul>
<li><a href="https://github.com/purpleclay/gpg-import-action/commit/46900703993b363215aa51a378ed7d0ca8c2a443"><strong><code>4690070</code></strong></a> switch to composite action that downloads and runs gpg-import on Darwin and Linux runners (#6) (@purpleclay)</li>
</ul>
<p><em>Generated with <a href="https://github.com/purpleclay/release-note">release-note</a></em></p>
]]></content:encoded></item><item><title>wavedash-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/wavedash-action/</link><pubDate>Tue, 18 Aug 2026 13:32:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/wavedash-action/</guid><description>Version updated for https://github.com/remarkablegames/wavedash-action to version v1.1.1.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the upload and publication of web games to Wavedash. It allows developers to easily integrate game uploads into their CI/CD pipelines by leveraging a wavedash.toml configuration file or automatically creating one with the necessary settings. The action handles the creation of a build, publishing it to Wavedash with optional release notes, and caching the installed Wavedash CLI between runs for efficiency.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablegames/wavedash-action">https://github.com/remarkablegames/wavedash-action</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wavedash-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the upload and publication of web games to Wavedash. It allows developers to easily integrate game uploads into their CI/CD pipelines by leveraging a <code>wavedash.toml</code> configuration file or automatically creating one with the necessary settings. The action handles the creation of a build, publishing it to Wavedash with optional release notes, and caching the installed Wavedash CLI between runs for efficiency.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="111-2026-08-18"><a href="https://github.com/remarkablegames/wavedash-action/compare/v1.1.0...v1.1.1">1.1.1</a> (2026-08-18)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump @wvdsh/sdk-js from 1.3.43 to 1.3.44 (<a href="https://github.com/remarkablegames/wavedash-action/issues/14">#14</a>) (<a href="https://github.com/remarkablegames/wavedash-action/commit/20baf6317018bd833928c4d878ae15db568be56b">20baf63</a>)</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/kaniko-build-action/</link><pubDate>Tue, 18 Aug 2026 13:31:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints a greeting message to the log, either “Hello World” or “Hello [name]”, and optionally includes the current time. It solves the problem of automating simple greetings with an input option for customizing who is greeted.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints a greeting message to the log, either &ldquo;Hello World&rdquo; or &ldquo;Hello [name]&rdquo;, and optionally includes the current time. It solves the problem of automating simple greetings with an input option for customizing who is greeted.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/rumdl-action/</link><pubDate>Tue, 18 Aug 2026 13:31:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.56.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rumdl is a high-performance Markdown linter and formatter written in Rust that helps maintain consistency in Markdown files. It offers over 80 lint rules, automatic formatting with the --fix option, and supports multiple Markdown flavors through auto-detection. The action provides a modern CLI for detailed error reporting and is optimized for speed, making it suitable for CI/CD workflows and editor integration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.56</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>rumdl is a high-performance Markdown linter and formatter written in Rust that helps maintain consistency in Markdown files. It offers over 80 lint rules, automatic formatting with the <code>--fix</code> option, and supports multiple Markdown flavors through auto-detection. The action provides a modern CLI for detailed error reporting and is optimized for speed, making it suitable for CI/CD workflows and editor integration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>MD076</strong>: attach its edit to each warning so the CLI reports it fixable (<a href="https://github.com/rvben/rumdl/commit/a10f6c8b63c1bd853be7c35e5f48af8d85df91c7">a10f6c8</a>)</li>
<li><strong>MD076</strong>: analyse each nested list on its own spacing (<a href="https://github.com/rvben/rumdl/commit/eb2d9d8a012c20685179c7f056d73bbe211e8a67">eb2d9d8</a>)</li>
<li><strong>MD064</strong>: judge column alignment per list so a nested item keeps its parent&rsquo;s exemption (<a href="https://github.com/rvben/rumdl/commit/9ea97d1d6456bcb6bd81ef827ac6f592871ee432">9ea97d1</a>)</li>
<li><strong>MD076</strong>: measure a list item&rsquo;s nesting level in columns as the block tracker does (<a href="https://github.com/rvben/rumdl/commit/15ba4091b1360a3e6d58c120fc6e4edc9e9c1981">15ba409</a>)</li>
<li><strong>MD032</strong>: measure list indent in columns so a tab nests and continues an item (<a href="https://github.com/rvben/rumdl/commit/bd197b04dcdf6ad09b5bd3a0a7c4c66fbc5702ff">bd197b0</a>)</li>
<li><strong>MD013</strong>: read sentence openers off the parse and honour reference definitions (<a href="https://github.com/rvben/rumdl/commit/78bafa98acee48919c35ac5dfe418656b1918ddb">78bafa9</a>)</li>
<li><strong>MD032</strong>: measure an HTML opener&rsquo;s indent in columns against every open item (<a href="https://github.com/rvben/rumdl/commit/56944fc9976dd204418a0abbf7165e6157db113b">56944fc</a>)</li>
<li><strong>MD013</strong>: keep links, images, math and HTML whole in sentence reflow (<a href="https://github.com/rvben/rumdl/commit/72871b984b7bf2b7374735f02dca766fab7c0a37">72871b9</a>)</li>
<li><strong>code-block-tools</strong>: resolve Windows tool names the way Command::new does (<a href="https://github.com/rvben/rumdl/commit/a005be4f124509f817417c9c71a8e17edcfb7530">a005be4</a>)</li>
<li><strong>MD032</strong>: let an HTML block or fence at short indent end a list (<a href="https://github.com/rvben/rumdl/commit/75d49a80dca7290c6619a4de8db2b6e055e925e5">75d49a8</a>)</li>
<li><strong>MD032</strong>: keep a Quarto div fence out of the lazy-continuation check (<a href="https://github.com/rvben/rumdl/commit/98242fd41515bd10080312ad94ddd1efac582288">98242fd</a>)</li>
<li><strong>MD013</strong>: run reflow after every rule that rewrites inline content (<a href="https://github.com/rvben/rumdl/commit/aabb4209f283cc6e9f36d1c908fc5be7a8675bc9">aabb420</a>)</li>
<li><strong>MD046</strong>: classify indented code blocks from the line above&rsquo;s verdict (<a href="https://github.com/rvben/rumdl/commit/e8004fbff767ea7d59e172f83df582b64aee6784">e8004fb</a>)</li>
<li><strong>MD032</strong>: treat under-indented text and no-space # lines as lazy continuations (<a href="https://github.com/rvben/rumdl/commit/3e60005ef9a010fc83df31c9750c8fa01ed26c54">3e60005</a>)</li>
<li><strong>code-block-tools</strong>: resolve tools in-process instead of spawning which (<a href="https://github.com/rvben/rumdl/commit/fb3e5d81d70d0a7f62651df2866d9d129ff0763f">fb3e5d8</a>)</li>
<li><strong>MD057</strong>: invalidate cache when link targets change (<a href="https://github.com/rvben/rumdl/commit/f6ae68fb22e7373b68b29adde3f8b113a7af2651">f6ae68f</a>)</li>
<li><strong>MD075</strong>: require an outer pipe on orphaned table row candidates (<a href="https://github.com/rvben/rumdl/commit/66d8d12c013543df57192bacb639b92b0870d4b9">66d8d12</a>)</li>
<li><strong>MD034</strong>: recognize reference definitions whose label escapes a closing bracket (<a href="https://github.com/rvben/rumdl/commit/f024e4df3b3080c7cd35b0b527429a22e398f814">f024e4d</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.56-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.56-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.56-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.56-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-x86_64-apple-darwin.tar.gz">rumdl-v0.2.56-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-aarch64-apple-darwin.tar.gz">rumdl-v0.2.56-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-x86_64-pc-windows-msvc.zip">rumdl-v0.2.56-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.56/rumdl-v0.2.56-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/custom-amazon-bedrock-agent-action/</link><pubDate>Tue, 18 Aug 2026 13:30:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze code files in a pull request and provide detailed feedback. It allows customization through tailored prompts and integrates with Amazon Bedrock Knowledge Bases for enhanced context-aware insights, enhancing the analysis capabilities beyond simple code quality checks. The action is useful for scenarios requiring specific organizational or domain-specific analysis, offering flexibility and integration with AWS services.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze code files in a pull request and provide detailed feedback. It allows customization through tailored prompts and integrates with Amazon Bedrock Knowledge Bases for enhanced context-aware insights, enhancing the analysis capabilities beyond simple code quality checks. The action is useful for scenarios requiring specific organizational or domain-specific analysis, offering flexibility and integration with AWS services.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/sherpa.sh/</link><pubDate>Tue, 18 Aug 2026 13:29:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven infrastructure management tool that automates the deployment and configuration of cloud resources based on a simple text prompt. It helps developers focus on writing code instead of managing complex infrastructure configurations, making it accessible to those without deep technical expertise in cloud technologies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven infrastructure management tool that automates the deployment and configuration of cloud resources based on a simple text prompt. It helps developers focus on writing code instead of managing complex infrastructure configurations, making it accessible to those without deep technical expertise in cloud technologies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/smyklot/</link><pubDate>Tue, 18 Aug 2026 13:28:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.38.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by enforcing permissions based on the repository’s CODEOWNERS file. It supports multiple command formats, allows users to approve/merge using reactions or commands, and provides reaction-based commands for approval and merge actions. The action ensures that only authorized individuals can perform these operations, enhancing security and compliance with CODEOWNER policies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.38.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by enforcing permissions based on the repository&rsquo;s CODEOWNERS file. It supports multiple command formats, allows users to approve/merge using reactions or commands, and provides reaction-based commands for approval and merge actions. The action ensures that only authorized individuals can perform these operations, enhancing security and compliance with CODEOWNER policies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1380-2026-08-18"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.37.0...v1.38.0">1.38.0</a> (2026-08-18)</h2>
<h2 id="smyklot-v1380">Smyklot v1.38.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.38.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>a5c7ad3798c02638b644ebde0db30d69bb715d9d chore(release): bump version to 1.38.0</li>
<li>b0d7c5c7129c5851d95bac4e99b64ad1367a192b feat(panel): one table component, everywhere (#264)</li>
<li>d17ad363e34619055a02c65b326115a0ee85bc99 fix(panel): straighten the catalogue&rsquo;s stories (#263)</li>
<li>095e99c04eeba47b33578d97c06151aa05aed21a ci(panel): publish the catalogue to Pages (#262)</li>
<li>a5bd7c5f22933dd6ca5cb53667d13292c12fdfe6 feat(panel): put the panel in Storybook (#261)</li>
<li>1df0a2b349d11f270a972bdeb9029df64d1d748e fix(panel): row states, a return, and a narrow queue (#260)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/update-a-config-file-with-values-from-environment/</link><pubDate>Tue, 18 Aug 2026 13:27:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces placeholders in a configuration file with values from the current environment. It helps automate the process of updating configuration settings based on dynamic data, such as environment-specific variables or secrets stored securely in CI/CD environments. This ensures that configurations are consistent across different environments without manual intervention.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces placeholders in a configuration file with values from the current environment. It helps automate the process of updating configuration settings based on dynamic data, such as environment-specific variables or secrets stored securely in CI/CD environments. This ensures that configurations are consistent across different environments without manual intervention.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Tue, 18 Aug 2026 13:27:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The deploy-swarm-service GitHub Action automates the deployment of a Swarm service by bundling JavaScript assets using npm before pushing them to a Docker container. It ensures that all necessary dependencies and bundles are prepared for production use, facilitating easier integration into a Swarm cluster.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>deploy-swarm-service</code> GitHub Action automates the deployment of a Swarm service by bundling JavaScript assets using npm before pushing them to a Docker container. It ensures that all necessary dependencies and bundles are prepared for production use, facilitating easier integration into a Swarm cluster.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/classroom-to-sheets-integration/</link><pubDate>Tue, 18 Aug 2026 13:26:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates Google Sheets with GitHub Classroom by automating the process of sending assignment results directly to specified columns in a Google sheet. It uses the provided API credentials and secrets to authenticate with Google Sheets, ensuring that students’ results are recorded accurately without manual intervention. The action supports various tasks within a course and automatically adapts to the structure of the Google sheet, adding or updating columns as necessary to accommodate new task results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates Google Sheets with GitHub Classroom by automating the process of sending assignment results directly to specified columns in a Google sheet. It uses the provided API credentials and secrets to authenticate with Google Sheets, ensuring that students&rsquo; results are recorded accurately without manual intervention. The action supports various tasks within a course and automatically adapts to the structure of the Google sheet, adding or updating columns as necessary to accommodate new task results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>Tessl Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/tessl-code-review/</link><pubDate>Tue, 18 Aug 2026 13:26:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/tessl-code-review/</guid><description>Version updated for https://github.com/tesslio/code-review-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Tessl Code Review is a GitHub Action that automates the process of running code reviews using the Tessl tool, handling pull request resolution, exact-head checkout, Tessl CLI setup, review publication, stale-head protection, idempotency, failure notices, and result artifacts. It simplifies the integration of code review functionality into GitHub workflows while retaining control over various aspects such as triggers, concurrency, permissions, secrets, runners, timeouts, and branch protections.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tesslio/code-review-action">https://github.com/tesslio/code-review-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tessl-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Tessl Code Review is a GitHub Action that automates the process of running code reviews using the Tessl tool, handling pull request resolution, exact-head checkout, Tessl CLI setup, review publication, stale-head protection, idempotency, failure notices, and result artifacts. It simplifies the integration of code review functionality into GitHub workflows while retaining control over various aspects such as triggers, concurrency, permissions, secrets, runners, timeouts, and branch protections.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Pin the Action to this release&rsquo;s commit SHA:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">tesslio/code-review-action@c6c5070082b1a578993552756e22fe0fef58015b</span> <span style="color:#75715e"># v1.1.0</span>
</span></span></code></pre></div><p>This revision installs Tessl CLI 0.97.0.</p>
]]></content:encoded></item><item><title>Run TestBot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/run-testbot/</link><pubDate>Tue, 18 Aug 2026 13:25:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/run-testbot/</guid><description>Version updated for https://github.com/testbots-ai/Run-Testbot to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of TestBots using the testbots-ai/Run-Testbot action. It loads a test bot configuration from configs/testbot-config.json, sets up JWT authentication, and runs the test bot within a GitHub Actions workflow. The results are stored in the workflow’s output and can be accessed for review or further processing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/testbots-ai/Run-Testbot">https://github.com/testbots-ai/Run-Testbot</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-testbot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of TestBots using the <code>testbots-ai/Run-Testbot</code> action. It loads a test bot configuration from <code>configs/testbot-config.json</code>, sets up JWT authentication, and runs the test bot within a GitHub Actions workflow. The results are stored in the workflow&rsquo;s output and can be accessed for review or further processing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Increased workflow timeouts for long-running TestBot executions (up to ~5h45m), right under GitHub&rsquo;s 360-minute cap: <code>POLL_TIMEOUT_MINUTES</code> → 345, job <code>timeout-minutes</code> → 358, step <code>timeout-minutes</code> → 350.</li>
<li>Packaged action (<code>uses: testbots-ai/Run-Testbot@v1.0.1</code>) now generates a JUnit XML report (<code>results/junit.xml</code>) automatically.</li>
<li>Added <code>USAGE_GUIDE.md</code> and Marketplace install instructions; full usage guide now also included in <code>README.md</code> so it shows on the Marketplace listing.</li>
<li>Clearer failure reasons surfaced in the GitHub Job Summary for the vendored workflow.</li>
</ul>
]]></content:encoded></item><item><title>Setup Modman</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/setup-modman/</link><pubDate>Tue, 18 Aug 2026 13:24:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/setup-modman/</guid><description>Version updated for https://github.com/ThatCuteOne/setup-modman to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup of MODX, a popular content management system, by installing it with specified version using Composer. It simplifies the process of setting up MODX environments for development and deployment projects, ensuring that developers can focus on building their applications without needing to manually install MODX each time.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ThatCuteOne/setup-modman">https://github.com/ThatCuteOne/setup-modman</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-modman">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup of MODX, a popular content management system, by installing it with specified version using Composer. It simplifies the process of setting up MODX environments for development and deployment projects, ensuring that developers can focus on building their applications without needing to manually install MODX each time.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ThatCuteOne/setup-modman/compare/v1.0.0...v1">https://github.com/ThatCuteOne/setup-modman/compare/v1.0.0...v1</a></p>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/compose-lint/</link><pubDate>Tue, 18 Aug 2026 13:23:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.19.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary compose-lint is a security-focused linter for Docker Compose files that detects and auto-fixes dangerous misconfigurations such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. It provides a static analysis check for docker-compose.yml and compose.yaml files, with full rule documentation at tmatens.github.io/compose-lint. The tool catches these security issues in CI before they reach production.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.19.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>compose-lint is a security-focused linter for Docker Compose files that detects and auto-fixes dangerous misconfigurations such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. It provides a static analysis check for docker-compose.yml and compose.yaml files, with full rule documentation at tmatens.github.io/compose-lint. The tool catches these security issues in CI before they reach production.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>GitHub Action: <code>upload-sarif</code> input (default <code>&quot;true&quot;</code>). Set to <code>&quot;false&quot;</code> to
write the file requested via <code>sarif-file</code> without uploading it to GitHub
Code Scanning — for runners without Code Scanning (Forgejo) or jobs that
lack the <code>security-events: write</code> permission the upload needs.</li>
<li>GitHub Action: <code>sarif-written</code> output — <code>&quot;true&quot;</code> when the SARIF file was
written and non-empty, empty otherwise.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Windows: every invocation crashed with <code>AttributeError: module 'os' has no attribute 'O_NONBLOCK'</code> in 0.18.0.</strong> The bounded-read hardening opened
files with the POSIX-only <code>O_NONBLOCK</code> flag (its FIFO-open-blocking rationale
does not exist on Windows). File opens now apply <code>O_NONBLOCK</code> only where the
platform has it, and add Windows&rsquo; <code>O_BINARY</code> so CRT newline translation
cannot corrupt reads that ask for the file&rsquo;s real bytes. Found by the new
macOS/Windows CI smoke on its first run.</li>
<li><strong>Windows: any run with findings crashed with <code>UnicodeEncodeError</code>.</strong>
Windows pipes and redirected files inherit the locale code page (usually
cp1252), which cannot encode the report&rsquo;s ⚠/·/│ characters. The CLI now
reconfigures stdout/stderr to UTF-8 when they aren&rsquo;t already — a no-op on
every other platform and on interactive Windows consoles — so piped and
redirected output is UTF-8 everywhere. Also found by the macOS/Windows
smoke.</li>
</ul>
<h3 id="known-limitations">Known limitations</h3>
<ul>
<li><strong>On Windows hosts, bind-source path resolution uses the host&rsquo;s path
semantics</strong>, so the climb-to-root detections (CL-0001, CL-0025) can miss
findings that the same file produces on Linux/macOS, and a bind source
containing <code>${VAR:?err}</code> can surface an OS error. Tracked in
<a href="https://github.com/tmatens/compose-lint/issues/588">#588</a>. Linting the
same files on Linux CI is unaffected.</li>
</ul>
]]></content:encoded></item><item><title>verbatra</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/verbatra/</link><pubDate>Tue, 18 Aug 2026 13:22:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/verbatra/</guid><description>Version updated for https://github.com/verbatra/action to version v1.1.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The verbatra GitHub Action automates i18n translation tasks by reading locale files, detecting missing or drifted content, translating it using an AI or machine-translation service (OpenAI, Anthropic, Gemini, DeepL, or an openai-compatible local model), and providing GitHub annotations and a job summary. It supports CI integration and can be used as a pull request gate without spending on provider API keys.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/verbatra/action">https://github.com/verbatra/action</a></strong> to version <strong>v1.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/verbatra">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The verbatra GitHub Action automates i18n translation tasks by reading locale files, detecting missing or drifted content, translating it using an AI or machine-translation service (OpenAI, Anthropic, Gemini, DeepL, or an openai-compatible local model), and providing GitHub annotations and a job summary. It supports CI integration and can be used as a pull request gate without spending on provider API keys.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixes">Fixes</h2>
<p>v1.1.2 fixed the original npx-cache resolution bug but introduced a more severe one: <code>npm install --prefix &quot;$install_dir&quot;</code> still reads and parses the consumer&rsquo;s <em>existing</em> <code>package.json</code>, not just the packages named on the command line. Any pnpm (or Yarn) workspace-protocol dependency string there — <code>workspace:*</code>, pnpm&rsquo;s <code>catalog:</code> — crashed the install outright, regardless of <code>--no-save</code>. Caught in the very first real-world CI run against v1.1.2, against verbatra&rsquo;s own docs site, whose <code>apps/docs/package.json</code> uses exactly this.</p>
<ul>
<li>Installs into an isolated scratch directory (no <code>package.json</code> to conflict with), then merges the result into <code>working-directory</code> — the consumer&rsquo;s own dependency manifest is never read by npm at all.</li>
<li>Fixes a <code>node_modules/.bin</code> symlink-dereferencing issue found while diagnosing the above (only matters for the merge step, not user-visible on its own).</li>
<li>Adds a <code>pnpm-workspace-protocols</code> regression fixture reproducing the exact failure, plus bumps all self-test fixtures to <code>0.9.0</code> (previously <code>0.8.0</code>, stale).</li>
</ul>
<p>No input or output changes; this is a drop-in upgrade.</p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/vibgrate-scan/</link><pubDate>Tue, 18 Aug 2026 13:21:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.818.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of analyzing codebases to provide insights on drift, risk, and potential fixes. It generates a deterministic code graph with call trees and import paths, calculates a drift score that ranks the lag in codebase maturity compared to runtime or dependency frameworks, and provides ranked upgrade plans for fixing issues. The analysis is performed locally on the user’s machine without requiring network calls or data leaving the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.818.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of analyzing codebases to provide insights on drift, risk, and potential fixes. It generates a deterministic code graph with call trees and import paths, calculates a drift score that ranks the lag in codebase maturity compared to runtime or dependency frameworks, and provides ranked upgrade plans for fixing issues. The analysis is performed locally on the user&rsquo;s machine without requiring network calls or data leaving the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268181">Vibgrate CLI 2026.818.1</h1>
<p><em>Released 2026-08-18</em></p>
<p>This release of the vg CLI includes several important fixes related to Architecture Layers and DriftScore reporting. These changes enhance the accuracy of the analysis and improve the clarity of the output.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Architecture Layers no longer reports CLI command→helper imports or tests importing the code they cover as boundary violations.</li>
<li>Path-vs-graph disagreements now list under Layer conflicts instead of Boundary violations.</li>
<li>Architecture Layers no longer flags a repository or database module importing a domain entity as a layered violation.</li>
<li>Empty layers (0 files) are omitted from the CLI report to avoid misclassifying missing domain folders as high risk.</li>
<li><code>vg lsp</code> no longer paints a parent package’s DriftScore onto an excluded nested manifest.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.817.2, interleaved on one runner against the pinned corpus (189 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>22561 count</td>
          <td>22561 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>12063 count</td>
          <td>12063 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.94 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>711.40 ms</td>
          <td>722.50 ms</td>
      </tr>
  </tbody>
</table>
<p>2 regression(s) — published, not omitted:</p>
<ul>
<li>Token reduction vs baseline agent (equal success): 0.41 → 0.27 (-33.9%)</li>
<li>Agent tokens with vg (comparable tasks, total): 471365 → 590462 (25.3%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.818.1">https://vibgrate.com/changelog/cli/2026.818.1</a></p>
]]></content:encoded></item><item><title>install spaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/install-spaces/</link><pubDate>Tue, 18 Aug 2026 13:20:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/install-spaces/</guid><description>Version updated for https://github.com/work-spaces/install-spaces to version v0.20.9.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of installing Spaces (a cloud-based development environment) on a GitHub-hosted runner. It simplifies the setup of a development workspace tailored for collaborative projects, ensuring developers can work efficiently without manual configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/install-spaces">https://github.com/work-spaces/install-spaces</a></strong> to version <strong>v0.20.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-spaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of installing Spaces (a cloud-based development environment) on a GitHub-hosted runner. It simplifies the setup of a development workspace tailored for collaborative projects, ensuring developers can work efficiently without manual configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.20.9 by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/45">https://github.com/work-spaces/install-spaces/pull/45</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/install-spaces/compare/v0.20.8...v0.20.9">https://github.com/work-spaces/install-spaces/compare/v0.20.8...v0.20.9</a></p>
]]></content:encoded></item><item><title>YAMLResume</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/yamlresume/</link><pubDate>Tue, 18 Aug 2026 13:20:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/yamlresume/</guid><description>Version updated for https://github.com/yamlresume/action to version v0.14.3.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The YAMLResume GitHub Action automates the creation of professional resumes from YAML files using the YAMLResume CLI. It builds multiple resumes in a single workflow step, supports custom build options such as skipping validation or PDF generation, and outputs generated file paths for use in subsequent steps. The action also works seamlessly with actions/upload-artifact to save generated files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yamlresume/action">https://github.com/yamlresume/action</a></strong> to version <strong>v0.14.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yamlresume">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The YAMLResume GitHub Action automates the creation of professional resumes from YAML files using the YAMLResume CLI. It builds multiple resumes in a single workflow step, supports custom build options such as skipping validation or PDF generation, and outputs generated file paths for use in subsequent steps. The action also works seamlessly with <code>actions/upload-artifact</code> to save generated files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="features">Features</h3>
<ul>
<li>bump yamlresume from v0.14.2 to v0.14.3 (<a href="https://github.com/yamlresume/action/commit/11040591b77bf3bc5c2f862207462ea1e89820ac">1104059</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yamlresume/action/compare/v0.14.2...v0.14.3">https://github.com/yamlresume/action/compare/v0.14.2...v0.14.3</a></p>
]]></content:encoded></item><item><title>Agent CLI Upgrade Canary</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/agent-cli-upgrade-canary/</link><pubDate>Tue, 18 Aug 2026 13:19:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/agent-cli-upgrade-canary/</guid><description>Version updated for https://github.com/yanjinzheng2005-gif/agent-cli-upgrade-canary to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Agent CLI Upgrade Canary action tests an Agent CLI upgrade in isolation by installing baseline and candidate versions separately, using different prefixes and configurations. It verifies if the upgraded version preserves startup, config, hooks, and MCP contracts against a set of predefined static contracts. The action is designed to help identify issues before they affect the actual user installation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yanjinzheng2005-gif/agent-cli-upgrade-canary">https://github.com/yanjinzheng2005-gif/agent-cli-upgrade-canary</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-cli-upgrade-canary">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Agent CLI Upgrade Canary action tests an Agent CLI upgrade in isolation by installing baseline and candidate versions separately, using different prefixes and configurations. It verifies if the upgraded version preserves startup, config, hooks, and MCP contracts against a set of predefined static contracts. The action is designed to help identify issues before they affect the actual user installation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Evidence-hardening release based on three independent reviews. Adds platform/architecture metadata, canonical macOS path redaction, explicit hook/MCP collection parsing, active parent-credential inheritance failure fixtures, self-asserting good/bad receipts, stricter version matching, corrected validation timestamps and CI lineage, and fixture-specific CI artifact names.</p>
<p>The OpenClaw #21488 version pair was tested without expanding scope: its reported Gateway/WebSocket runtime failure remains outside the declared static contract boundary. No Gateway, model, live hook event, or MCP connection was added.</p>
<p>Verification:</p>
<ul>
<li>Final main CI: <a href="https://github.com/yanjinzheng2005-gif/agent-cli-upgrade-canary/actions/runs/32019912558">https://github.com/yanjinzheng2005-gif/agent-cli-upgrade-canary/actions/runs/32019912558</a></li>
<li>v0.1.1 tag CI: <a href="https://github.com/yanjinzheng2005-gif/agent-cli-upgrade-canary/actions/runs/32020468809">https://github.com/yanjinzheng2005-gif/agent-cli-upgrade-canary/actions/runs/32020468809</a></li>
<li>Validation record: <a href="https://github.com/yanjinzheng2005-gif/agent-cli-upgrade-canary/blob/v0.1.1/VALIDATION.md">https://github.com/yanjinzheng2005-gif/agent-cli-upgrade-canary/blob/v0.1.1/VALIDATION.md</a></li>
</ul>
<p>Both CI runs completed Ubuntu Node 20/22/24, macOS Node 24, and Windows Node 24 successfully.</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/b.ia-accessibility-checker/</link><pubDate>Tue, 18 Aug 2026 13:18:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/18/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action designed to automate accessibility checks in CI/CD pipelines. It allows companies to define an audience and minimum percentage of WCAG guidelines they need their code to meet, enabling them to avoid costly external solutions and focus on their core business objectives. The action uses AI for abstract guideline analysis, providing flexibility and accuracy in ensuring product accessibility.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action designed to automate accessibility checks in CI/CD pipelines. It allows companies to define an audience and minimum percentage of WCAG guidelines they need their code to meet, enabling them to avoid costly external solutions and focus on their core business objectives. The action uses AI for abstract guideline analysis, providing flexibility and accuracy in ensuring product accessibility.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>RuleBlast</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/ruleblast/</link><pubDate>Mon, 17 Aug 2026 22:02:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/ruleblast/</guid><description>Version updated for https://github.com/Kpoiut/ruleblast to version v2.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The RuleBlast GitHub Action automates the visualization of Git diffs to show how a file change propagates across different repositories and tools, such as Codex, Claude Code, Gemini CLI, and Copilot CLI. It helps identify which files are inherited and which Git motions have been made independently, providing insights into code alignment and changes within a repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Kpoiut/ruleblast">https://github.com/Kpoiut/ruleblast</a></strong> to version <strong>v2.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ruleblast">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The RuleBlast GitHub Action automates the visualization of Git diffs to show how a file change propagates across different repositories and tools, such as Codex, Claude Code, Gemini CLI, and Copilot CLI. It helps identify which files are inherited and which Git motions have been made independently, providing insights into code alignment and changes within a repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="npm">npm</h2>
<p><code>ruleblast@2.3.0</code> is latest.</p>
<ul>
<li>integrity <code>sha512-1G1yAOUMnMQUfVX64YoLbBVKPNrFsX7ivIZ8OhJwL5YQUFyC6EyWYk4mNokyDIh+q7KqeLt9djgQSXxlQ2fn2Q==</code></li>
<li>tarball 138,135 bytes SHA-256 <code>1672bdd9133f960d8658e003b8d7cb77a13b3fbd79c9238a2b009abf2839ba2e</code></li>
<li>registry <code>gitHead</code> at publish was <code>67280fd8b43a53cd262d68058e3b4680410c8d2d</code> and is not the 2.3.0 source commit</li>
</ul>
<h2 id="source">Source</h2>
<p>Signed tag object <code>73e0fdf25f68c18380c9db5b459406419f72fc06</code> targets <code>7ca69ba262f3250e6e33630ca05c205d9f01e14c</code>.</p>
<h2 id="what-people-get">What people get</h2>
<ul>
<li>Human Git↔Git and Git→WORKTREE <code>diff</code> appends OTHER TRACKED CHANGES from Git storage blob-object identity, then WORK MAP and CHANGE ALIGNMENT (<code>ALIGNED</code> / <code>MIXED</code> / <code>DIVERGENT</code> / <code>UNRESOLVED</code>)</li>
<li>Companion <code>ruleblast-companion-2.3.0.vsix</code>: themed SVG, welcome scan/diff/explain/case, <code>Ctrl+Alt+R</code> then <code>S</code>/<code>D</code>/<code>E</code>/<code>C</code></li>
<li>CLI and MCP: <code>npx --yes ruleblast@2.3.0 --mcp</code></li>
<li>Action default pin is <code>2.3.0</code></li>
</ul>
<p>Not a fifth action. <code>--json</code> stays canonical. A host is not a modeled reality. Do not overwrite Marketplace <code>2.2.0</code> or <code>2.2.1</code>.</p>
<h2 id="companion">Companion</h2>
<p>125,885-byte <code>ruleblast-companion-2.3.0.vsix</code> SHA-256 <code>40aca6dbb59bf2b5d19938788f0454baa80abb806802290429aff8c3f255ab60</code></p>
]]></content:encoded></item><item><title>Repo Growth</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/repo-growth/</link><pubDate>Mon, 17 Aug 2026 22:00:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/repo-growth/</guid><description>Version updated for https://github.com/MacRimi/repo-growth to version v1.4.2.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Repo Growth automates the tracking and visualization of repository metrics such as stars, forks, release downloads, and optional Git clone traffic directly within a GitHub repository. It eliminates the need for external services or personal tokens, providing a simple and reliable way to track project growth without relying on third-party APIs. The action is designed to be self-contained and does not require any secret setup or hosted databases, making it easy to integrate into any repository’s workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MacRimi/repo-growth">https://github.com/MacRimi/repo-growth</a></strong> to version <strong>v1.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repo-growth">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Repo Growth automates the tracking and visualization of repository metrics such as stars, forks, release downloads, and optional Git clone traffic directly within a GitHub repository. It eliminates the need for external services or personal tokens, providing a simple and reliable way to track project growth without relying on third-party APIs. The action is designed to be self-contained and does not require any secret setup or hosted databases, making it easy to integrate into any repository&rsquo;s workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="transient-github-api-retries">Transient GitHub API retries</h2>
<ul>
<li>Retry HTTP 500, 502, 503, and 504 responses up to three times.</li>
<li>Use short exponential delays between attempts.</li>
<li>Continue to fail immediately for authentication, permission, validation, and rate-limit errors.</li>
</ul>
]]></content:encoded></item><item><title>Setup openapi-forge</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/setup-openapi-forge/</link><pubDate>Mon, 17 Aug 2026 21:59:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/setup-openapi-forge/</guid><description>Version updated for https://github.com/MarcusDunn/openapi-forge to version v1.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary OpenAPI Forge is a WASM-plugin-based replacement for openapi-generator that parses OpenAPI specs into a normalized intermediate representation and runs sandboxed WebAssembly plugins to transform or emit code from it. The host enforces capability limits to prevent plugins from accessing the filesystem, network, clock, randomness, and memory. It aims to provide a secure and maintainable way for developers to create and run custom generators without relying on third-party software.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MarcusDunn/openapi-forge">https://github.com/MarcusDunn/openapi-forge</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-openapi-forge">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>OpenAPI Forge is a WASM-plugin-based replacement for openapi-generator that parses OpenAPI specs into a normalized intermediate representation and runs sandboxed WebAssembly plugins to transform or emit code from it. The host enforces capability limits to prevent plugins from accessing the filesystem, network, clock, randomness, and memory. It aims to provide a secure and maintainable way for developers to create and run custom generators without relying on third-party software.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump thiserror from 2.0.19 to 2.0.20 in /plugins in the cargo-minor-patch group by @dependabot[bot] in <a href="https://github.com/MarcusDunn/openapi-forge/pull/129">https://github.com/MarcusDunn/openapi-forge/pull/129</a></li>
<li>chore(deps): bump the actions group with 3 updates by @dependabot[bot] in <a href="https://github.com/MarcusDunn/openapi-forge/pull/132">https://github.com/MarcusDunn/openapi-forge/pull/132</a></li>
<li>chore(deps): bump the cargo-minor-patch group with 3 updates by @dependabot[bot] in <a href="https://github.com/MarcusDunn/openapi-forge/pull/133">https://github.com/MarcusDunn/openapi-forge/pull/133</a></li>
<li>chore(deps-dev): bump esbuild from 0.28.1 to 0.28.2 in /plugins/generator-typescript-cli in the npm-minor-patch group by @dependabot[bot] in <a href="https://github.com/MarcusDunn/openapi-forge/pull/131">https://github.com/MarcusDunn/openapi-forge/pull/131</a></li>
<li>chore: prep next release v0.1.28 by @github-actions[bot] in <a href="https://github.com/MarcusDunn/openapi-forge/pull/128">https://github.com/MarcusDunn/openapi-forge/pull/128</a></li>
<li>chore(deps): bump thiserror from 2.0.19 to 2.0.20 in /fuzz in the cargo-minor-patch group by @dependabot[bot] in <a href="https://github.com/MarcusDunn/openapi-forge/pull/130">https://github.com/MarcusDunn/openapi-forge/pull/130</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/MarcusDunn/openapi-forge/compare/v0.1.27...v1.0.1">https://github.com/MarcusDunn/openapi-forge/compare/v0.1.27...v1.0.1</a></p>
]]></content:encoded></item><item><title>Deploy to Miabi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/deploy-to-miabi/</link><pubDate>Mon, 17 Aug 2026 21:58:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/deploy-to-miabi/</guid><description>Version updated for https://github.com/miabi-io/deploy-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of an application to a Miabi control panel. It uses the miabi CLI to deploy images from a GitHub repository without requiring SSH access or Docker socket. The action supports customizable deploy strategies and provides a quick start guide for setting up API tokens, environment variables, and integrating it into workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/miabi-io/deploy-action">https://github.com/miabi-io/deploy-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-to-miabi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of an application to a <a href="https://github.com/miabi-io/miabi">Miabi</a> control panel. It uses the <code>miabi</code> CLI to deploy images from a GitHub repository without requiring SSH access or Docker socket. The action supports customizable deploy strategies and provides a quick start guide for setting up API tokens, environment variables, and integrating it into workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: rename the miabi-cli to cli by @jkaninda in <a href="https://github.com/miabi-io/deploy-action/pull/3">https://github.com/miabi-io/deploy-action/pull/3</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/miabi-io/deploy-action/compare/v1.1.0...v1">https://github.com/miabi-io/deploy-action/compare/v1.1.0...v1</a></p>
]]></content:encoded></item><item><title>Fetch config from CF Worker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/fetch-config-from-cf-worker/</link><pubDate>Mon, 17 Aug 2026 21:57:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/fetch-config-from-cf-worker/</guid><description>Version updated for https://github.com/MoeFurina/pull-oc-config to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This private GitHub Action modifies code and requires certain technical foundation to use. It automates tasks related to modifying code by providing key capabilities for developers needing this functionality.
What’s Changed releases
Full Changelog: https://github.com/MoeFurina/pull-oc-config/commits/v1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MoeFurina/pull-oc-config">https://github.com/MoeFurina/pull-oc-config</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fetch-config-from-cf-worker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This private GitHub Action modifies code and requires certain technical foundation to use. It automates tasks related to modifying code by providing key capabilities for developers needing this functionality.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>releases</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/MoeFurina/pull-oc-config/commits/v1">https://github.com/MoeFurina/pull-oc-config/commits/v1</a></p>
]]></content:encoded></item><item><title>Nitrozen Changelog</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/nitrozen-changelog/</link><pubDate>Mon, 17 Aug 2026 21:57:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/nitrozen-changelog/</guid><description>Version updated for https://github.com/nitrozenio/changelog-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Nitrozen Changelog Action automates the process of publishing a changelog entry to a Nitrozen project from within a GitHub Actions workflow. It simplifies the task of creating and managing changelogs by integrating with Nitrozen’s API, reducing manual effort and improving consistency across releases. The action supports various inputs for customizing the changelog entry, such as title, content, category, and publishing settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nitrozenio/changelog-action">https://github.com/nitrozenio/changelog-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nitrozen-changelog">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Nitrozen Changelog Action automates the process of publishing a changelog entry to a Nitrozen project from within a GitHub Actions workflow. It simplifies the task of creating and managing changelogs by integrating with Nitrozen&rsquo;s API, reducing manual effort and improving consistency across releases. The action supports various inputs for customizing the changelog entry, such as title, content, category, and publishing settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="nitrozen-changelog-action">Nitrozen Changelog Action</h2>
<p>Publish a <a href="https://nitrozen.io">Nitrozen</a> changelog entry straight from a GitHub Actions workflow — most commonly triggered by a GitHub Release.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">nitrozenio/changelog-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.NITROZEN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">project-id</span>: <span style="color:#e6db74">&#39;123&#39;</span>
</span></span></code></pre></div><h3 id="highlights">Highlights</h3>
<ul>
<li><strong>Zero setup.</strong> Composite action, no <code>npm install</code> or build step — runs on the Node runtime every GitHub-hosted runner already ships.</li>
<li><strong>Release-aware defaults.</strong> On a <code>release</code> event, <code>title</code> and <code>content</code> default to the release&rsquo;s name/tag and body, so the  snippet above is a complete integration by itse</li>
<li><strong>Draft or publish.</strong> Set <code>is-published: 'false'</code> to import as a draft for manual review instead of publishing immediately. - <strong>Preserves original dates.</strong> <code>published-at</code> timestamp instead of always using &ldquo;now&rdquo;.</li>
<li><strong>Useful outputs.</strong> <code>entry-id</code> and (when <code>project-slug</code> is set) <code>changelog-url</code>, so you can comment the published link back on the release or a PR.</li>
</ul>
<p>See the <a href="https://github.com/nitrozenio/changelog-action#readme">README</a> for the full input/output reference, and <a href="https://nitrozen.io/docs/github-action">nitrozen.io/docs/github-action</a> for the hosted docs.</p>
]]></content:encoded></item><item><title>NotTodayThankyou</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/nottodaythankyou/</link><pubDate>Mon, 17 Aug 2026 21:56:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/nottodaythankyou/</guid><description>Version updated for https://github.com/NotTodayThankyou/NotTodayThankyou to version v1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically closes pull requests that fail selected tests and checks, ensuring clean code contributions from contributors. It solves problems by automating the closing of problematic PRs, such as those without workflows, with too many recent commits, or without an associated issue. The action allows customization through configuration options like post-comment messages, require-associated-issue settings, and max-prs-per-day limits.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NotTodayThankyou/NotTodayThankyou">https://github.com/NotTodayThankyou/NotTodayThankyou</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nottodaythankyou">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically closes pull requests that fail selected tests and checks, ensuring clean code contributions from contributors. It solves problems by automating the closing of problematic PRs, such as those without workflows, with too many recent commits, or without an associated issue. The action allows customization through configuration options like post-comment messages, require-associated-issue settings, and max-prs-per-day limits.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Add branding (fc29bf4)</li>
<li>Don&rsquo;t run tests on push (for now) (6eb4449)</li>
<li>Update README.md (91a911b)</li>
<li>Update README.md (c0139c0)</li>
<li>Update docs and metadata (aaf613b)</li>
<li>Revert &ldquo;Add check to tests that the workflow calling the Action did not error&rdquo; (6222c7d)</li>
<li>Add check to tests that the workflow calling the Action did not error (88a46c2)</li>
<li>Test if PR author is a contributor (c0fbf7f)</li>
<li>Don&rsquo;t treat closing a PR as a failed workflow run (23b5433)</li>
<li>Handle 404s from listWorkflowRunsForRepo (b2aa7b9)</li>
</ul>
]]></content:encoded></item><item><title>Full-site SEO Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/full-site-seo-audit/</link><pubDate>Mon, 17 Aug 2026 21:54:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/full-site-seo-audit/</guid><description>Version updated for https://github.com/nurkamol/seo-audit to version v1.10.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action full-site-seo-audit is designed to crawl a website’s sitemap and thoroughly check every page for SEO, metadata, and structured data issues that single-page graders might miss. This tool automates the process of identifying technical correctness across all pages and provides a comprehensive report in various formats, including Markdown, HTML, and JSON. It also includes features like cross-page checks, broken links, regression guards, and performance metrics via Google’s PSI tool. The action is optimized for use in CI environments and has zero dependencies, making it easy to integrate into workflows without additional setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nurkamol/seo-audit">https://github.com/nurkamol/seo-audit</a></strong> to version <strong>v1.10.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/full-site-seo-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>full-site-seo-audit</code> is designed to crawl a website&rsquo;s sitemap and thoroughly check every page for SEO, metadata, and structured data issues that single-page graders might miss. This tool automates the process of identifying technical correctness across all pages and provides a comprehensive report in various formats, including Markdown, HTML, and JSON. It also includes features like cross-page checks, broken links, regression guards, and performance metrics via Google&rsquo;s PSI tool. The action is optimized for use in CI environments and has zero dependencies, making it easy to integrate into workflows without additional setup.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>The <code>www.</code> host variant is only tried for a host that can have one.</strong> It was
built by string concatenation from whatever host was being audited, so
auditing <code>http://127.0.0.1:8080</code> asked a resolver for <code>www.127.0.0.1</code> — a
question with no sensible answer, which a resolver may decline instantly or
sit on for as long as it likes.</p>
<p>That made the test suite stall unpredictably, since every fixture test runs
against <code>127.0.0.1</code>. It also affected anyone auditing a local build on
<code>localhost</code>, where the same two requests were pure waste.</p>
<p>IP addresses and single-label hostnames are now skipped; a registrable domain
is checked exactly as before. Verified by intercepting <code>dns.lookup</code> during a
fixture run — zero hostname resolutions, everything a literal IP — and by
confirming a real domain still reports its <code>www.</code> redirect chain.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/odin-scan-smart-contract-security/</link><pubDate>Mon, 17 Aug 2026 21:53:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates smart contract security analysis for CosmWasm, Solana, and EVM projects using the Odin Scan AI platform. It integrates directly into workflows to detect vulnerabilities before they reach production. Key features include multi-platform support, automatic platform detection, integration with GitHub Code Scanning for SARIF uploads, PR comments, inline annotations, comment-triggered scans, configurable severity thresholds, artifact upload, and customizable output levels.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates smart contract security analysis for CosmWasm, Solana, and EVM projects using the Odin Scan AI platform. It integrates directly into workflows to detect vulnerabilities before they reach production. Key features include multi-platform support, automatic platform detection, integration with GitHub Code Scanning for SARIF uploads, PR comments, inline annotations, comment-triggered scans, configurable severity thresholds, artifact upload, and customizable output levels.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial Release</p>
<p>AI-powered smart contract security analysis, now integrated directly into your GitHub workflow.</p>
<p>✨ Features</p>
<p>Multi-Platform Support</p>
<ul>
<li>CosmWasm - Rust-based smart contracts for Cosmos SDK</li>
<li>Solana (SVM) - Anchor and native Solana programs</li>
<li>EVM - Solidity and Vyper contracts</li>
<li>Auto-detection - Automatically identifies platform from your repo</li>
</ul>
<p>GitHub Integration</p>
<ul>
<li>Code Scanning - SARIF upload for native security alerts in the Security tab</li>
<li>PR Comments - Severity summary and top findings posted directly on pull requests</li>
<li>Inline Annotations - Critical/high findings appear as errors, medium/low as warnings on diffs</li>
<li>Artifact Upload - Full JSON report available as workflow artifact</li>
</ul>
<p>Customization</p>
<ul>
<li>Severity Thresholds - Fail builds at critical, high, medium, or low severity</li>
<li>Platform Override - Force specific platform detection when auto-detect isn&rsquo;t enough</li>
<li>Timeout Control - Configurable analysis timeout (default: 30 minutes)</li>
<li>Flexible Triggers - Run on push, PR, schedule, or manual dispatch</li>
</ul>
<p>🚀 Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Security Scan</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&#39;on&#39;</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">main</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">security-events</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">api-key</span>: <span style="color:#e6db74">&#39;${{ secrets.ODIN_SCAN_API_KEY }}&#39;</span>
</span></span></code></pre></div><p>📋 Requirements</p>
<ul>
<li>Odin Scan Pro subscription - Required for API access</li>
<li>API Key - Generate at <a href="https://odinscan.ai/dashboard/settings">https://odinscan.ai/dashboard/settings</a></li>
<li>GitHub Permissions - contents: read, security-events: write (for SARIF), pull-requests: write (for
comments)</li>
</ul>
<p>🔧 Configuration</p>
<p>All Inputs</p>
<p>| ┌────────────────────┬─────────────────────┬──────────────────────────────────────────────┐ |
| │       Input        │       Default       │                 Description                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ api-key            │ Required            │ Your Odin Scan API key (odin_sk_*)           │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ platform           │ auto                │ Target platform: auto, cosmwasm, solana, evm │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ severity-threshold │ high                │ Fail at: critical, high, medium, low, none   │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ fail-on-findings   │ true                │ Whether to fail workflow on findings         │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ comment-on-pr      │ true                │ Post summary comment on PRs                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-sarif       │ true                │ Upload SARIF to Code Scanning                │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-artifact    │ true                │ Upload full report as artifact               │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ timeout            │ 1800                │ Max analysis wait time (seconds)             │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ github-token       │ ${{ github.token }} │ Token for PR comments and SARIF              │ |
| └────────────────────┴─────────────────────┴──────────────────────────────────────────────┘ |</p>
<p>All Outputs</p>
<ul>
<li>analysis-id - Unique analysis identifier</li>
<li>status - Analysis status (completed, failed)</li>
<li>total-findings - Total number of findings</li>
<li>critical-count, high-count, medium-count, low-count - Counts by severity</li>
<li>report-url - Link to full report on Odin Scan</li>
<li>sarif-file - Path to generated SARIF file</li>
</ul>
<p>📝 Example Workflows</p>
<p>Basic (Auto-detect)</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span></code></pre></div><p>EVM with Medium Threshold</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">platform</span>: <span style="color:#ae81ff">evm</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">severity-threshold</span>: <span style="color:#ae81ff">medium</span>
</span></span></code></pre></div><p>Only on Solidity Changes</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#39;**.sol&#39;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">foundry.toml</span>
</span></span></code></pre></div><p>🔒 Security &amp; Privacy</p>
<ul>
<li>All API communication over HTTPS (TLS 1.2+)</li>
<li>API keys automatically masked in logs</li>
<li>No data stored by the action (stateless)</li>
<li>See <a href="https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md">https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md</a> for details</li>
</ul>
<p>📖 Documentation</p>
<ul>
<li>Action README - <a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></li>
<li>Odin Scan Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
<li>Get API Key - <a href="https://app.odinscan.ai/settings">https://app.odinscan.ai/settings</a></li>
</ul>
<p>🐛 Known Limitations</p>
<ul>
<li>Private repos - Requires github-token with repo access</li>
<li>Large repos - May need increased timeout for complex codebases</li>
<li>Code Scanning - Requires GitHub Advanced Security on private repos</li>
</ul>
<p>🙏 Support</p>
<ul>
<li>Issues - <a href="https://github.com/Odin-Scan/odin-scan-action/issues">https://github.com/Odin-Scan/odin-scan-action/issues</a></li>
<li>Email - <a href="mailto:support@odinscan.ai">support@odinscan.ai</a></li>
<li>Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
</ul>
<hr>
<p>Full Changelog: <a href="https://github.com/Odin-Scan/odin-scan-action/commits/v1">https://github.com/Odin-Scan/odin-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>ov-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/ov-scan/</link><pubDate>Mon, 17 Aug 2026 21:52:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/ov-scan/</guid><description>Version updated for https://github.com/opaquev/ov-scan-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action runs the ov scan tool to detect leaked secrets in a repository’s working tree and git history. It ensures that only verified or critical findings are reported, and it optionally allows users to verify and rotate OV binary versions. The action is designed to catch secrets before they reach production environments by running ov scan on pull requests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/opaquev/ov-scan-action">https://github.com/opaquev/ov-scan-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ov-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action runs the <code>ov scan</code> tool to detect leaked secrets in a repository&rsquo;s working tree and git history. It ensures that only verified or critical findings are reported, and it optionally allows users to verify and rotate OV binary versions. The action is designed to catch secrets before they reach production environments by running <code>ov scan</code> on pull requests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>License change:</strong> MIT → Business Source License 1.1 (Change Date <strong>2030-05-06</strong>, Change License Apache-2.0). The Additional Use Grant permits production use by any organization, regardless of size, for invoking <code>ov scan</code> against repositories under your control in CI or local workflows. Tags v1.0.0–v1.0.2 were released under MIT and remain MIT. See <a href="https://github.com/opaquev/ov-scan-action/blob/v1.0.3/LICENSE">LICENSE</a> and the <a href="https://opaquevault.com/docs/license">plain-language guide</a>. No functional changes; the <code>v1</code> floating tag now points here.</p>
]]></content:encoded></item><item><title>Chock Governance Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/chock-governance-check/</link><pubDate>Mon, 17 Aug 2026 21:51:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/chock-governance-check/</guid><description>Version updated for https://github.com/open-coder-ai/chock to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Chock automates governance for AI coding agents by compiling rules into deterministic guardrails, ensuring consistency across teams and projects. It compiles rules to git hooks, CI gates, native pre-execution hooks in Claude Code and Cursor, and generates AGENTS.md for Copilot, Codex, Gemini, and other agents. This ensures that all agents adhere to the same policies, preventing unintended behavior such as force-pushes to main branches or inappropriate commits.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/open-coder-ai/chock">https://github.com/open-coder-ai/chock</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/chock-governance-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Chock automates governance for AI coding agents by compiling rules into deterministic guardrails, ensuring consistency across teams and projects. It compiles rules to git hooks, CI gates, native pre-execution hooks in Claude Code and Cursor, and generates <code>AGENTS.md</code> for Copilot, Codex, Gemini, and other agents. This ensures that all agents adhere to the same policies, preventing unintended behavior such as force-pushes to main branches or inappropriate commits.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="010--first-public-release">0.1.0 — First public release</h2>
<p>Everything below is the launch surface; <code>0.0.1a0</code> was a name-claiming pre-release, so this
is the first version with real contents.</p>
<ul>
<li><strong>Policies as code</strong>: versioned policy manifests committed to the repo, compiled by
<code>chock sync</code> to every enforcement surface each agent supports.</li>
<li><strong>Enforcement surfaces</strong>: pre-tool-use guards (Claude Code and Cursor), git hooks,
a CI gate (<code>chock sync --ci</code> + commit-range mode), and ambient rules for
instruction-file agents.</li>
<li><strong>Coverage honesty</strong>: per-agent, per-policy claims at three levels — <code>enforced</code>,
<code>enforced-at-commit</code>, <code>advisory</code> — raised only when the installed mechanism is
witnessed for that agent.</li>
<li><strong>Arm-on-clone</strong>: cloned repos re-arm through an ambient rule plus a consented
SessionStart hook; git never clones hooks and Chock does not fight that boundary.</li>
<li><strong>Catalog adoption</strong>: <code>chock add &lt;id&gt;</code> installs hash-pinned policies from any
catalog, public or private; every published policy ships with replayed evals.</li>
<li><strong>Compliance frameworks built in</strong>: OWASP Agentic Security Top-10, MITRE ATLAS,
NIST AI RMF, EU AI Act — manifests claim framework coverage, <code>chock check</code> reports it.</li>
<li><strong>Versioning contract</strong>: PATCH releases never change compiled output (enforced by a
golden-file suite); MINOR releases may.</li>
</ul>
]]></content:encoded></item><item><title>Build CheckMK MKP Package</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/build-checkmk-mkp-package/</link><pubDate>Mon, 17 Aug 2026 21:50:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/build-checkmk-mkp-package/</guid><description>Version updated for https://github.com/oposs/mkp-builder to version v2.2.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of Checkmk MKP packages from local plugin directories, supporting customizable build options and syntax validation. It provides a fast and reusable workflow that can be easily integrated into CI/CD pipelines. The action outputs package information for easy artifact upload, ensuring no permanent changes to the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oposs/mkp-builder">https://github.com/oposs/mkp-builder</a></strong> to version <strong>v2.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-checkmk-mkp-package">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of Checkmk MKP packages from local plugin directories, supporting customizable build options and syntax validation. It provides a fast and reusable workflow that can be easily integrated into CI/CD pipelines. The action outputs package information for easy artifact upload, ensuring no permanent changes to the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Renamed the release workflows for what they actually do: <code>Release</code> →
<strong>Create release PR</strong> (<code>create-release-pr.yml</code>) and <code>Publish release</code> →
<strong>Release publisher</strong> (<code>release-publisher.yml</code>). Since 2.2.1 split the release in two,
the old names read like two ways to do the same thing, when only one is ever the right
button to press.</li>
<li><strong>Release publisher</strong> no longer has a <code>workflow_dispatch</code> trigger. Publishing should be
a consequence of merging a release PR, not something anyone can start from a dropdown;
with <code>main</code> protected against direct pushes, merging a PR that changes <code>plugin.json</code> is
now the only route to a release. This costs no recovery: a failed run is re-run from the
Actions UI regardless of trigger, and because the version is read from <code>plugin.json</code>
rather than from run inputs, a re-run is faithful to the original attempt.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Name the release workflows for what they do; publishing is not hand-fireable by @oetiker in <a href="https://github.com/oposs/mkp-builder/pull/10">https://github.com/oposs/mkp-builder/pull/10</a></li>
<li>Release v2.2.2 by @github-actions[bot] in <a href="https://github.com/oposs/mkp-builder/pull/11">https://github.com/oposs/mkp-builder/pull/11</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/oposs/mkp-builder/compare/v2.2.1...v2.2.2">https://github.com/oposs/mkp-builder/compare/v2.2.1...v2.2.2</a></p>
]]></content:encoded></item><item><title>migguard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/migguard/</link><pubDate>Mon, 17 Aug 2026 21:48:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/migguard/</guid><description>Version updated for https://github.com/prvthmpcypher/migguard to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary migguard is a command-line tool that automates the detection of database migration conflicts before merging branches. It supports multiple ORM frameworks such as Django, Alembic, Prisma, Rails, and Knex. The tool helps teams avoid inconsistent database schemas by detecting conflicting migration heads or timestamp inconsistencies in pull requests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prvthmpcypher/migguard">https://github.com/prvthmpcypher/migguard</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/migguard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>migguard</code> is a command-line tool that automates the detection of database migration conflicts before merging branches. It supports multiple ORM frameworks such as Django, Alembic, Prisma, Rails, and Knex. The tool helps teams avoid inconsistent database schemas by detecting conflicting migration heads or timestamp inconsistencies in pull requests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="migguard-v010">migguard v0.1.0</h3>
<p>Catch database migration conflicts before the merge, not after the database is broken.</p>
<h4 id="key-features">Key Features</h4>
<ul>
<li>🔍 <strong>Framework Auto-Detection</strong>: Instant zero-config detection of Django, Alembic, Prisma, Rails, and Knex.</li>
<li>🌳 <strong>Engine A (DAG Traversal)</strong>: Per-app leaf node detection for Django and Alembic. Handles tuple merge points and squashed migrations without false positives.</li>
<li>⏱️ <strong>Engine B (Timestamp Comparison)</strong>: Git merge-base timestamp comparison for Prisma, Rails, and Knex with duplicate &amp; out-of-order detection.</li>
<li>⚡ <strong>CI &amp; Pre-Commit Ready</strong>: Includes native GitHub Action and pre-commit hook configurations.</li>
<li>🛡️ <strong>Zero Database Connection</strong>: Completely local and offline analysis derived purely from files and git history.</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/kaniko-build-action/</link><pubDate>Mon, 17 Aug 2026 21:47:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints a greeting message to the log, either “Hello World” or a personalized message including the input name. It solves the problem of automating simple greetings and provides a straightforward way to customize the greeting with a user-provided name.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints a greeting message to the log, either &ldquo;Hello World&rdquo; or a personalized message including the input name. It solves the problem of automating simple greetings and provides a straightforward way to customize the greeting with a user-provided name.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>rung gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/rung-gate/</link><pubDate>Mon, 17 Aug 2026 21:47:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/rung-gate/</guid><description>Version updated for https://github.com/rung-dev/rung to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The rung GitHub Action automates the grading of verifications based on reasoning and code execution, providing a two-axis model to assess real-world changes. It solves problems related to verifying code integrity and quality by offering a shared vocabulary, reference schema, and deterministic gate mechanism.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rung-dev/rung">https://github.com/rung-dev/rung</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rung-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The rung GitHub Action automates the grading of verifications based on reasoning and code execution, providing a two-axis model to assess real-world changes. It solves problems related to verifying code integrity and quality by offering a shared vocabulary, reference schema, and deterministic gate mechanism.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fail-closed hardening and documentation consolidation.</p>
<p>Changes:</p>
<ul>
<li>Standalone entries (python -m rung.gate, python -m rung.run) fail closed to exit 2 on any unexpected exception, never a raw traceback; the 0/30/2 exit-code contract and argparse usage errors pass through unchanged.</li>
<li>A malformed RUNG_MAX_CAPTURE_BYTES (non-integer or non-positive) fails closed to exit 2 before the probe runs, instead of crashing or silently reverting to the default cap.</li>
<li>The threat model moved to a standalone THREAT-MODEL.md; the README is reorganized by task role. No changes to the schema, policy, or the run/gate surfaces.</li>
</ul>
<p>Published as:</p>
<ul>
<li>pip install rung-ai==0.2.0</li>
<li>uses: <a href="mailto:rung-dev/rung@v0.2.0">rung-dev/rung@v0.2.0</a></li>
<li>docker run &ndash;rm ghcr.io/rung-dev/rung:0.2.0 version</li>
</ul>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/smyklot/</link><pubDate>Mon, 17 Aug 2026 21:46:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.36.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges based on CODEOWNERS rules. It allows users to approve, merge, or cleanup PRs with commands, mentions, or reactions, while respecting repository permissions. The app handles multiple command formats and provides emoji feedback for approval status.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.36.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges based on CODEOWNERS rules. It allows users to approve, merge, or cleanup PRs with commands, mentions, or reactions, while respecting repository permissions. The app handles multiple command formats and provides emoji feedback for approval status.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1360-2026-08-17"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.35.2...v1.36.0">1.36.0</a> (2026-08-17)</h2>
<h2 id="smyklot-v1360">Smyklot v1.36.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.36.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>a95c0cb0e48af0a407ecc5b2a3bb9f60e479e918 chore(release): bump version to 1.36.0</li>
<li>f8bbb3631a60dd3c6f1b018b830bab0f4b18b3ec feat(sync): keep rulesets in step across the org (#252)</li>
<li>f2e7de14db16d6c5199c631fce4ad6daf85e0c11 fix(panel): the help tips can be read (#256)</li>
<li>ba57fdeb48d1b8dbe258e66418954a6b1b31f163 fix(panel): closing a dialog keeps its view (#255)</li>
</ul>
]]></content:encoded></item><item><title>Vulnerability Spoiler Alert</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/vulnerability-spoiler-alert/</link><pubDate>Mon, 17 Aug 2026 21:45:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/vulnerability-spoiler-alert/</guid><description>Version updated for https://github.com/spaceraccoon/vulnerability-spoiler-alert-action to version v1.7.0.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action detects security vulnerabilities by monitoring open-source repositories and using AI to analyze commit messages, labels, and PR descriptions. It creates detailed issues with vulnerability analysis when a concrete exploit is demonstrated. The action supports multiple providers (Anthropic, OpenAI, DeepSeek) and can be configured to monitor specific repositories and create issues in different locations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spaceraccoon/vulnerability-spoiler-alert-action">https://github.com/spaceraccoon/vulnerability-spoiler-alert-action</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vulnerability-spoiler-alert">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action detects security vulnerabilities by monitoring open-source repositories and using AI to analyze commit messages, labels, and PR descriptions. It creates detailed issues with vulnerability analysis when a concrete exploit is demonstrated. The action supports multiple providers (Anthropic, OpenAI, DeepSeek) and can be configured to monitor specific repositories and create issues in different locations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>build(deps): bump esbuild from 0.28.0 to 0.28.1 by @dependabot[bot] in <a href="https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/18">https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/18</a></li>
<li>build(deps-dev): bump vite from 8.0.13 to 8.0.16 by @dependabot[bot] in <a href="https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/19">https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/19</a></li>
<li>Enable deepseek to utilize json_object instead of json_schema by @spaceraccoon in <a href="https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/25">https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/25</a></li>
<li>chore: update vulnerable deps flagged by dependabot by @spaceraccoon in <a href="https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/26">https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/26</a></li>
<li>Refactor judge model to support multiple providers by @spaceraccoon in <a href="https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/27">https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/compare/v1.6.0...v1.7.0">https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/compare/v1.6.0...v1.7.0</a></p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/ssg-static-site-generator/</link><pubDate>Mon, 17 Aug 2026 21:44:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.42.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SSG action is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website, including clean URLs, templates, feeds, search, image processing and native deployment. It works well for blogs, WordPress migrations, documentation, company sites, portfolios, and landing pages. The main purpose of the action is to streamline the process of creating and deploying static websites by automating content conversion and rendering, handling template engines, SEO metadata, and deployment options.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.42</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The SSG action is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website, including clean URLs, templates, feeds, search, image processing and native deployment. It works well for blogs, WordPress migrations, documentation, company sites, portfolios, and landing pages. The main purpose of the action is to streamline the process of creating and deploying static websites by automating content conversion and rendering, handling template engines, SEO metadata, and deployment options.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.42 — a content type&rsquo;s own archive, and repair finds fenced markup by @spagu in <a href="https://github.com/spagu/ssg/pull/167">https://github.com/spagu/ssg/pull/167</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.41...v1.8.42">https://github.com/spagu/ssg/compare/v1.8.41...v1.8.42</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/classroom-to-sheets-integration/</link><pubDate>Mon, 17 Aug 2026 21:42:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates Google Sheets with GitHub Classroom to automatically record assignment results. It uses service account credentials to authenticate and update the specified Google Sheet. The action allows users to specify student names, task results, and table IDs in their workflows. By doing so, it automates the process of updating grades directly into a Google Sheet.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates Google Sheets with GitHub Classroom to automatically record assignment results. It uses service account credentials to authenticate and update the specified Google Sheet. The action allows users to specify student names, task results, and table IDs in their workflows. By doing so, it automates the process of updating grades directly into a Google Sheet.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>Set up Feint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/set-up-feint/</link><pubDate>Mon, 17 Aug 2026 21:42:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/set-up-feint/</guid><description>Version updated for https://github.com/stephrobert/setup-feint to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action provides a local emulator for Terraform, OpenTofu, or Scaleway, Outscale, and Exoscale CLIs using the Feint project. It automates the setup of an environment without needing cloud credentials or account management. The action downloads a pre-compiled binary, verifies its checksum, starts the emulator, and exports necessary provider configurations for seamless integration with Terraform commands. Users can specify the version and desired provider to run their infrastructure tests locally.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stephrobert/setup-feint">https://github.com/stephrobert/setup-feint</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/set-up-feint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action provides a local emulator for Terraform, OpenTofu, or Scaleway, Outscale, and Exoscale CLIs using the Feint project. It automates the setup of an environment without needing cloud credentials or account management. The action downloads a pre-compiled binary, verifies its checksum, starts the emulator, and exports necessary provider configurations for seamless integration with Terraform commands. Users can specify the version and desired provider to run their infrastructure tests locally.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Run Terraform, OpenTofu or the official Scaleway, Outscale and Exoscale CLIs in GitHub Actions against a local emulator — <strong>no cloud account, no credentials, nothing billed.</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">stephrobert/setup-feint@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">version</span>: <span style="color:#ae81ff">0.9.0</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">provider</span>: <span style="color:#ae81ff">scaleway</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">run</span>: <span style="color:#ae81ff">terraform apply -auto-approve</span>
</span></span></code></pre></div><p>That job has no secret, because there is no account to authenticate to. The provider that applies is the real one from the registry; <a href="https://github.com/stephrobert/feint">Feint</a> emulates the API it talks to.</p>
<h2 id="what-it-does">What it does</h2>
<ol>
<li>Downloads the released binary for the runner&rsquo;s platform.</li>
<li><strong>Verifies its checksum before running it</strong> — the bytes are checked against the release&rsquo;s <code>checksums.txt</code>, not trusted because they arrived over HTTPS.</li>
<li>Starts the emulator through <code>feint start</code>, which detaches and waits until it answers rather than sleeping and hoping.</li>
<li>With <code>provider:</code>, exports the environment that client needs, so the next step needs no configuration at all.</li>
</ol>
<h2 id="what-keeps-it-honest">What keeps it honest</h2>
<p>The checksum verification is the part of this action that must never rot, so it is exercised rather than asserted: this repository&rsquo;s CI corrupts the downloaded binary while leaving <code>checksums.txt</code> intact, and requires the action <strong>as shipped</strong> to refuse it. If the check ever stops checking, that job goes red.</p>
<p>The body of the action lives in the <a href="https://github.com/stephrobert/feint/blob/main/.github/actions/setup-feint/action.yml">Feint repository</a> and is mirrored here, so there is one source and one CI. A gate there reads what this repository serves at <code>v1</code> and fails when the two differ — the copy cannot drift in silence.</p>
<h2 id="what-it-does-not-do">What it does not do</h2>
<p>The action starts the control plane. <strong>Real machines</strong> behind <code>--vm</code> need Incus on the host; what each mode proves is written row by row in <a href="https://github.com/stephrobert/feint/blob/main/docs/confidence.md">docs/confidence.md</a>.</p>
<p>Apache-2.0.</p>
]]></content:encoded></item><item><title>Setup GitHub CLI Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/setup-github-cli-actions/</link><pubDate>Mon, 17 Aug 2026 21:41:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/setup-github-cli-actions/</guid><description>Version updated for https://github.com/v2d27/setup-gh-cli to version v1.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of the GitHub CLI (gh) on self-hosted runners across multiple platforms and architectures. It supports multi-platform support, multi-architecture support, automatic archive format detection, tool caching, version flexibility, and platform detection. The action can be configured to install the latest version or a specific version of gh, and it simplifies setting up GitHub CLI in workflows by providing detailed usage examples and configuration options.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/v2d27/setup-gh-cli">https://github.com/v2d27/setup-gh-cli</a></strong> to version <strong>v1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-github-cli-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the installation of the GitHub CLI (<code>gh</code>) on self-hosted runners across multiple platforms and architectures. It supports multi-platform support, multi-architecture support, automatic archive format detection, tool caching, version flexibility, and platform detection. The action can be configured to install the latest version or a specific version of <code>gh</code>, and it simplifies setting up GitHub CLI in workflows by providing detailed usage examples and configuration options.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/v2d27/setup-gh-cli/compare/v1.4...v1.5">https://github.com/v2d27/setup-gh-cli/compare/v1.4...v1.5</a></p>
]]></content:encoded></item><item><title>Vaara Policy Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/vaara-policy-check/</link><pubDate>Mon, 17 Aug 2026 21:40:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/vaara-policy-check/</guid><description>Version updated for https://github.com/vaaraio/vaara to version v1.68.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Vaara is an AI-driven tool that provides verifiable receipts for autonomous actions, ensuring accountability by tracking every decision, call, and outcome in a tamper-evident ledger. The action automates the process of risk-scoring and logging actions according to predefined policies, allowing for transparent and trustworthy verification of any autonomous decision made within the system.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaaraio/vaara">https://github.com/vaaraio/vaara</a></strong> to version <strong>v1.68.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vaara-policy-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Vaara is an AI-driven tool that provides verifiable receipts for autonomous actions, ensuring accountability by tracking every decision, call, and outcome in a tamper-evident ledger. The action automates the process of risk-scoring and logging actions according to predefined policies, allowing for transparent and trustworthy verification of any autonomous decision made within the system.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1680---2026-08-17">[1.68.0] - 2026-08-17</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>Northern Lights: a decision now carries the route it actually took, and an
outcome travels back along that route.</strong> Routing a decision forward is
ordinary. Without a return path the record is write-only, so the next
decision is made in the same ignorance as the last one.</p>
<p>Trust moves at two scales under one rule. A criterion carries a prior that
decides whether its signal counts at a node; a node carries a weight that
decides whether its vote counts in a panel. Outcomes move both, both stop
counting below a floor, and both decay back toward trust so one bad week
does not become permanent policy. Only what actually voted is moved, so a
criterion that failed a check is never blamed for the result.</p>
<p>In a panel, standing follows being right rather than agreeing. A majority
that carries a call which turns out wrong loses weight while the objector
gains it, until the lone voice cannot be outvoted. Dissent stays in the
record instead of being discarded at the tally.</p>
<p>Four channels carry the return path: relay hop by hop, direct to the origin
from any point on the route, local closing at the node, and lateral between
neighbours without the origin hearing it. Four messages stay distinct on
them: an outcome, a refusal with its reason, a capability probe, and a
retraction. Hop counts bound the backward wave, a backward message never
spawns a forward one, and decisions carry a sequence because the two
directions cross.</p>
<p>Three shapes of walk share one structure: an ordered route, a broadcast
where which nodes answered is itself the signal, and a route discovered one
handoff at a time with no list written in advance.</p>
<p>Nodes measure their own firing rate against their own baseline, so a node
that objects constantly is not elevated when it objects. Simultaneous
elevation across nodes produces conclusions no single node reached.
Anti-nodes carry what must be un-true for such a conclusion to hold and veto
it outright, which is not a vote and cannot be outvoted; a blocked
conclusion is recorded with what stopped it.</p>
<p>Standard library only, no new dependencies. <code>docs/northern-lights.md</code>,
<code>src/vaara/northern_lights.py</code>, 44 tests.</p>
</li>
<li>
<p><strong><code>COMMERCIAL.md</code> states the commercial side of the dual licence.</strong> Vaara has
been dual-licensed since v1.0.0 and <code>LICENSING.md</code> carried the structure and
the relicensing history. This is the buyer-facing half: when the commercial
licence is needed, when it is not, and what it does not include. It states
plainly that AGPL compliance costs nothing and is not a lesser tier.</p>
</li>
<li>
<p><strong>A conformance statement now grades every check as <code>proved</code>, <code>unproved</code> or
<code>false</code> instead of true or false.</strong> A boolean cannot tell a reader whether a
check ran and failed or was never reached, and those need different repairs.
A suite the runner cannot place and a record file that will not parse both
used to land on <code>conforms: false</code>, next to a genuine disagreement with the
spec, which reports more than the run established.</p>
<p><code>unproved</code> is only ever produced by an execution state the runner recorded,
never inferred from a primary check that failed. A suite reports <code>runnable</code>;
an unreadable record is listed by name. Where a run mixes states the worst
one wins, because a check that ran and failed is a stronger claim than one
that never ran. Records stay optional: supplying none leaves the section
absent and contributes no grade, which is a different statement from
supplying records that could not be read.</p>
<p>The rendered page no longer prints NON-CONFORMING over an unreached check.
It prints UNPROVED, names which check could not be reached, and says the
statement establishes nothing either way.</p>
<p><code>schemaVersion</code> goes to 2. The change is additive: <code>conforms</code> keeps its
meaning and every previously conforming statement still conforms.</p>
<p>A fifth vector scenario, <code>unproved</code>, carries records that all conform plus one
file that will not parse, which is the case a boolean cannot express. The
Vaara-free checker re-derives the grade itself with its own worst-first fold
and fails if a page or golden ever claims <code>proved</code> where it derived
<code>unproved</code>, so the new field is checked rather than asserted.</p>
</li>
<li>
<p><strong>A Helm chart and a container image, so Vaara can be deployed on
Kubernetes.</strong> <code>deploy/helm/vaara</code> installs the model-endpoint proxy in front
of an in-cluster model endpoint: a StatefulSet with one replica, a
ClusterIP Service, a ServiceAccount with no API token mounted, and a
PersistentVolumeClaim holding the trail. The image is built on
<code>registry.suse.com/bci/python:3.12</code>, runs as UID 10001 with a read-only root
filesystem, and is published to <code>ghcr.io/vaaraio/vaara</code> on release for
linux/amd64 and linux/arm64.</p>
<p>The chart has no replica count. One hash chain has exactly one writer, and a
second pod appending to the same volume produces a chain neither pod can
verify, so the invariant is enforced by the shape of the chart rather than
documented next to a knob that breaks it.</p>
<p>Three configurations that would fail in the cluster now fail at template
time with the reason: <code>enforce</code> mode with no allow list and no approvals
directory (every tool call gated, clients appear to lose their tools),
signing with no Secret named (the chart will not mint a key that rotates on
every upgrade), and signing without persistence (signed evidence discarded
on restart).</p>
</li>
<li>
<p><strong><code>GET /healthz</code> on the model-endpoint proxy.</strong> Every other path on the
proxy forwards upstream, so a liveness probe had no way to ask about the
proxy rather than about the model: an orchestrator would restart Vaara
whenever the model was slow to load, and bill a request per probe. The route
answers locally with status, version and mode, names no internal host, and
does not shadow the <code>/health</code> that vLLM serves.</p>
</li>
<li>
<p><strong><code>docs/kubernetes-rancher.md</code></strong> covering install, storage, turning on
enforcement, signed receipts, and the NetworkPolicy that makes the proxy the
only route to the model. <strong><code>docs/supported-platforms.md</code></strong> lists the Python,
container and Kubernetes versions Vaara supports, and separately records
which platform versions a release has actually been run against.</p>
</li>
<li>
<p><strong>The conformance runner prints one link that opens the results form with
the run already in it.</strong> The runner printed a table of verdicts and stopped
there, so anyone who wanted their reproduction listed had to read the numbers
off a terminal and retype them. The commit, the suites and the totals are all
known at the end of a run, so they are now carried into the form. The link is
printed for a failing run as well, because a result that did not pass is a
legitimate row and gating the link behind a green run would collect only the
results that passed. <code>--no-submit-link</code> omits it for CI and scripted runs.</p>
</li>
<li>
<p><strong>The rendered text of <code>draft-sirkkavaara-vaara-receipt-07</code> is in the tree.</strong>
The <code>ietf/</code> directory carried 00 through 06 and the -07 text lived only on
the datatracker, so the readable timeline of the format had a hole in it at
the newest revision.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>The audit trail turned on WAL journalling everywhere, including on
filesystems that cannot support it, and corrupted itself there.</strong> SQLite&rsquo;s
WAL journal coordinates readers and writers through a shared-memory segment,
and SQLite&rsquo;s documentation states that WAL needs coherent shared memory and
working file locking. virtiofs, 9p, NFS, SMB and FUSE mounts provide neither.
There the write still goes through and the database corrupts, in the one file
whose purpose is being evidence.</p>
<p>This is the ordinary way people try the tool. The trail defaults to
<code>~/.vaara/trail/audit.db</code>, and a container with the host home directory bind
mounted in puts that on virtiofs or FUSE without anyone choosing it. Docker
Desktop, Rancher Desktop, Colima, Lima and OrbStack all mount that way, as do
WSL2 writing to <code>/mnt/c</code> and NFS or SMB network homes. On one such machine
the trail was damaged four times in twelve days.</p>
<p>Vaara now reads <code>/proc/mounts</code> when it opens a trail, and on a filesystem
that cannot support WAL it uses the DELETE journal instead and logs one line
naming the path, the filesystem type and what it did. Everywhere else is
unchanged. <code>VAARA_TRAIL_JOURNAL_MODE=wal|delete</code> overrides the choice in
either direction. Detection is Linux-only, because a filesystem type is not
readable on macOS or Windows without platform calls. Those keep WAL, and
<code>docs/supported-platforms.md</code> states that limit. 12 tests in
<code>tests/test_journal_mode_shared_fs.py</code>.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/vibgrate-scan/</link><pubDate>Mon, 17 Aug 2026 21:39:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.817.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action provides a local codebase intelligence tool called vg that generates a deterministic code graph, calculates drift scores and risk indices, and identifies potential fixes. It helps developers understand the state of their codebases and plan for updates without relying on external APIs or data transfer. The action runs entirely on the developer’s machine and does not require any network calls or data exfiltration unless explicitly pushed to a repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.817.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action provides a local codebase intelligence tool called <code>vg</code> that generates a deterministic code graph, calculates drift scores and risk indices, and identifies potential fixes. It helps developers understand the state of their codebases and plan for updates without relying on external APIs or data transfer. The action runs entirely on the developer&rsquo;s machine and does not require any network calls or data exfiltration unless explicitly pushed to a repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268171">Vibgrate CLI 2026.817.1</h1>
<p><em>Released 2026-08-17</em></p>
<p>This release of the vg CLI includes important changes to how the daemon operates, enhancements to the lsp command, and several fixes that improve stability and accuracy. Users should consider updating to benefit from these improvements.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="new">New</h3>
<ul>
<li>vg lsp now includes four new editor-facing capabilities to enhance runtime declaration visibility and manage ignored dependencies.</li>
</ul>
<h3 id="improved">Improved</h3>
<ul>
<li>vg daemon status now displays the CLI version serving the socket for better clarity.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>vg code now uses the same standalone vgd as vg daemon ensure, eliminating the in-process daemon for the session.</li>
<li>gpt-tokenizer has been updated to version 4.x, dropping unused bundles while maintaining token-accurate truncation.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>vg daemon restart now correctly re-spawns vgd from a global vg install, resolving issues with previous spawn attempts.</li>
<li>vg drift no longer incorrectly considers a node_modules directory above the scanned project as part of the project&rsquo;s installed versions.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.814.2, interleaved on one runner against the pinned corpus (189 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21928 count</td>
          <td>22060 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>11339 count</td>
          <td>11339 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.94 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>745.90 ms</td>
          <td>732.50 ms</td>
      </tr>
  </tbody>
</table>
<p>3 regression(s) — published, not omitted:</p>
<ul>
<li>Invented dependencies (not in any manifest): 1 → 2 (100.0%)</li>
<li>Tasks passed on both arms: 33 → 31 (-6.1%)</li>
<li>Comparable-task rate (both arms passed / total): 0.94 → 0.89 (-6.1%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.817.1">https://vibgrate.com/changelog/cli/2026.817.1</a></p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/rustscript-action/</link><pubDate>Mon, 17 Aug 2026 21:37:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.6.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that allows users to write Rust scripts and run them as if they were shell scripts. It compiles Rust code into a native binary, enabling scripts to be executed quickly and directly without the need for compilation. The action supports various features of Rust, including functions, closures, structs, enums, patterns, loops, iterators, and standard library bridging for common tasks like file I/O, network operations, and more. It also provides a cmp command to compile and run scripts as native binaries directly from the terminal.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a tool that allows users to write Rust scripts and run them as if they were shell scripts. It compiles Rust code into a native binary, enabling scripts to be executed quickly and directly without the need for compilation. The action supports various features of Rust, including functions, closures, structs, enums, patterns, loops, iterators, and standard library bridging for common tasks like file I/O, network operations, and more. It also provides a <code>cmp</code> command to compile and run scripts as native binaries directly from the terminal.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.6.0...v0.6.1">https://github.com/VladasZ/rustscript/compare/v0.6.0...v0.6.1</a></p>
]]></content:encoded></item><item><title>ProofRun Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/proofrun-verify/</link><pubDate>Mon, 17 Aug 2026 21:36:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/proofrun-verify/</guid><description>Version updated for https://github.com/yebiguo/ProofRun to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ProofRun is a tool that cryptographically verifies whether AI coding agents’ reported test results are accurate. It does this by comparing the exact code state (git commit and uncommitted changes) to the results of running checks, ensuring that any change in code invalidates previous check results marked as “PASS.” This helps prevent false claims about tests passing when the actual code has changed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yebiguo/ProofRun">https://github.com/yebiguo/ProofRun</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/proofrun-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ProofRun is a tool that cryptographically verifies whether AI coding agents&rsquo; reported test results are accurate. It does this by comparing the exact code state (git commit and uncommitted changes) to the results of running checks, ensuring that any change in code invalidates previous check results marked as &ldquo;PASS.&rdquo; This helps prevent false claims about tests passing when the actual code has changed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v030--tamper-evident-receipts">v0.3.0 — Tamper-evident receipts</h2>
<p>Every check result ProofRun records is now signed (HMAC-SHA256) with a local key and verified on read. A hand-edited or forged <code>receipt.json</code> entry is silently dropped rather than trusted — it never shows a false PASS.</p>
<p><strong>What&rsquo;s new</strong></p>
<ul>
<li>Receipts are signed on write, verified on read (schema bumped to <code>proofrun/v2</code>)</li>
<li>Signing key is generated automatically on first use, kept out of git on a best-effort basis</li>
<li>Two symlink-based attacks on the key file were found and closed in review before this shipped</li>
</ul>
<p><strong>Before relying on this:</strong> it&rsquo;s tamper-evident, not tamper-proof — it catches casual hand-edits, not an attacker who already has read access to the signing key. See the README&rsquo;s <a href="https://github.com/yebiguo/proofrun#tamper-evident-receipts">Tamper-evident receipts</a> section for exactly what it does and doesn&rsquo;t guarantee.</p>
<p><strong>Upgrading from v0.2:</strong> receipts signed before v0.3 have no signature and read as <code>NOT RUN</code> — there&rsquo;s no migration path. Re-run your checks after upgrading.</p>
<p><strong>Also in this release:</strong> the GitHub Action from v0.2 is unaffected by any of this — it never trusts a checked-out <code>receipt.json</code>, so local signing changes nothing about what makes its output trustworthy.</p>
]]></content:encoded></item><item><title>Vibe-Guard-AICoding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/vibe-guard-aicoding/</link><pubDate>Mon, 17 Aug 2026 21:35:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/vibe-guard-aicoding/</guid><description>Version updated for https://github.com/YUTAKONDO1205/VibeGuard to version v0.3.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary VibeGuard is a security scanner for AI-generated code that detects common programming mistakes like missing input checks and hard-coded passwords during development. It automates the process of identifying potential bugs in AI-generated code before it’s merged into a project, ensuring safer software delivery. The tool can run at multiple locations including IDEs, web browsers, and CI pipelines, providing consistent results across different environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YUTAKONDO1205/VibeGuard">https://github.com/YUTAKONDO1205/VibeGuard</a></strong> to version <strong>v0.3.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibe-guard-aicoding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>VibeGuard is a security scanner for AI-generated code that detects common programming mistakes like missing input checks and hard-coded passwords during development. It automates the process of identifying potential bugs in AI-generated code before it&rsquo;s merged into a project, ensuring safer software delivery. The tool can run at multiple locations including IDEs, web browsers, and CI pipelines, providing consistent results across different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Make the toolchain check the things it was only recording, and stop t… by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/67">https://github.com/YUTAKONDO1205/VibeGuard/pull/67</a></li>
<li>Put the three new workspaces in the lockfile, and make their absence … by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/68">https://github.com/YUTAKONDO1205/VibeGuard/pull/68</a></li>
<li>Make the checks measure the tree they stand in by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/69">https://github.com/YUTAKONDO1205/VibeGuard/pull/69</a></li>
<li>chore(deps-dev): bump @types/chrome from 0.2.2 to 0.2.5 in the typescript-tooling group by @dependabot[bot] in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/70">https://github.com/YUTAKONDO1205/VibeGuard/pull/70</a></li>
<li>chore(deps-dev): bump ovsx from 1.0.2 to 1.1.0 by @dependabot[bot] in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/71">https://github.com/YUTAKONDO1205/VibeGuard/pull/71</a></li>
<li>Claude/vg ship fixes and compiler blocks by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/72">https://github.com/YUTAKONDO1205/VibeGuard/pull/72</a></li>
<li>Fix/ci red from compiler blocks by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/73">https://github.com/YUTAKONDO1205/VibeGuard/pull/73</a></li>
<li>Feat/official site by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/74">https://github.com/YUTAKONDO1205/VibeGuard/pull/74</a></li>
<li>Fix the two CI failures the site landed with by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/76">https://github.com/YUTAKONDO1205/VibeGuard/pull/76</a></li>
<li>Give the site build the Node version Astro 7 requires by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/77">https://github.com/YUTAKONDO1205/VibeGuard/pull/77</a></li>
<li>Derive the fallback profile table from the measured envelope by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/75">https://github.com/YUTAKONDO1205/VibeGuard/pull/75</a></li>
<li>Let the site know its own address by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/78">https://github.com/YUTAKONDO1205/VibeGuard/pull/78</a></li>
<li>Serve Google&rsquo;s ownership proof from the Worker, not from public/ by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/79">https://github.com/YUTAKONDO1205/VibeGuard/pull/79</a></li>
<li>Refuse a fallback cell measured in a build that is not this one by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/80">https://github.com/YUTAKONDO1205/VibeGuard/pull/80</a></li>
<li>Close out 0.3.6: ship the editor&rsquo;s lockfile veto, seal the sidecar, and give 84 tests a runner by @YUTAKONDO1205 in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/81">https://github.com/YUTAKONDO1205/VibeGuard/pull/81</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/YUTAKONDO1205/VibeGuard/compare/v0...v0.3.6">https://github.com/YUTAKONDO1205/VibeGuard/compare/v0...v0.3.6</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/neurolink-ai/</link><pubDate>Mon, 17 Aug 2026 14:05:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v11.1.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is an AI integration platform that facilitates seamless communication between different AI providers and models, allowing developers to streamline their workflows. It provides a unified API that supports multiple LLMs, tools, and memory sources, enabling efficient and cost-effective AI integration into applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v11.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is an AI integration platform that facilitates seamless communication between different AI providers and models, allowing developers to streamline their workflows. It provides a unified API that supports multiple LLMs, tools, and memory sources, enabling efficient and cost-effective AI integration into applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1110-2026-08-17"><a href="https://github.com/juspay/neurolink/compare/v11.0.0...v11.1.0">11.1.0</a> (2026-08-17)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>(providers):</strong>  descriptor single-source-of-truth, unified error classification and retry (<a href="https://github.com/juspay/neurolink/commit/5502259c75207cbbd010f7bf2ea3c379a730e021">5502259</a>)</li>
</ul>
]]></content:encoded></item><item><title>Mise Update Tool</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/mise-update-tool/</link><pubDate>Mon, 17 Aug 2026 14:04:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/mise-update-tool/</guid><description>Version updated for https://github.com/jylenhof/mise-update-tool to version v1.0.4.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action mise-update-tool automates the process of upgrading tools defined in a local mise configuration file. It uses the mise upgrade --bump --local command to update specified or all local tools, and optionally opens pull requests if config files change. This helps maintain tool versions and ensures consistency across projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jylenhof/mise-update-tool">https://github.com/jylenhof/mise-update-tool</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mise-update-tool">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>mise-update-tool</code> automates the process of upgrading tools defined in a local mise configuration file. It uses the <code>mise upgrade --bump --local</code> command to update specified or all local tools, and optionally opens pull requests if config files change. This helps maintain tool versions and ensures consistency across projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="104-2026-08-17"><a href="https://github.com/jylenhof/mise-update-tool/compare/v1.0.3...v1.0.4">1.0.4</a> (2026-08-17)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>only use nodejs 24 types related to nodejs 24 (<a href="https://github.com/jylenhof/mise-update-tool/issues/43">#43</a>) (<a href="https://github.com/jylenhof/mise-update-tool/commit/657d6d2d804e5c4583161ed590e98ea0e5fe808b">657d6d2</a>)</li>
</ul>
]]></content:encoded></item><item><title>RepoCare repository health</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/repocare-repository-health/</link><pubDate>Mon, 17 Aug 2026 14:03:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/repocare-repository-health/</guid><description>Version updated for https://github.com/lstsavr/repocare to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RepoCare is a local tool that checks the health and completeness of open-source projects, providing immediate feedback on common maintenance gaps such as documentation, license files, and security policies. It helps maintainers identify areas for improvement by generating actionable reports without uploading source code or requiring API keys. RepoCare is designed to be fast and efficient, ensuring that developers can quickly understand where their repositories fall short in terms of quality and completeness.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lstsavr/repocare">https://github.com/lstsavr/repocare</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repocare-repository-health">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RepoCare is a local tool that checks the health and completeness of open-source projects, providing immediate feedback on common maintenance gaps such as documentation, license files, and security policies. It helps maintainers identify areas for improvement by generating actionable reports without uploading source code or requiring API keys. RepoCare is designed to be fast and efficient, ensuring that developers can quickly understand where their repositories fall short in terms of quality and completeness.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/lstsavr/repocare/compare/v0.1.0...v0.2.0">https://github.com/lstsavr/repocare/compare/v0.1.0...v0.2.0</a></p>
]]></content:encoded></item><item><title>React Native Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/react-native-audit/</link><pubDate>Mon, 17 Aug 2026 14:01:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/react-native-audit/</guid><description>Version updated for https://github.com/maheshwarimrinal/react-native-agents to version v1.0.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary React Native Agents provides AI guidance to React Native developers. It identifies issues and suggests fixes by analyzing the project context, using deep references, and explaining findings with practical examples. The action can be used to automate pull-request reviews and is compatible with various AI coding tools like Claude Code, Cursor, Windsurf, GitHub Copilot, Codex, Zed, Aider, MCP clients, and GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/maheshwarimrinal/react-native-agents">https://github.com/maheshwarimrinal/react-native-agents</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/react-native-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>React Native Agents provides AI guidance to React Native developers. It identifies issues and suggests fixes by analyzing the project context, using deep references, and explaining findings with practical examples. The action can be used to automate pull-request reviews and is compatible with various AI coding tools like Claude Code, Cursor, Windsurf, GitHub Copilot, Codex, Zed, Aider, MCP clients, and GitHub Actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="react-native-agents-v102">React Native Agents v1.0.2</h2>
<p>React Native Agents v1.0.2 — New Build, Doctor, Native Modules &amp; Bundle Size Agents</p>
<h2 id="release-notes">Release notes</h2>
<h1 id="react-native-agents-v102-1">React Native Agents v1.0.2</h1>
<p>This release expands React Native Agents with new implementation, diagnostics, native-module, and bundle-size capabilities.</p>
<h2 id="highlights">Highlights</h2>
<h3 id="new-specialist-agents">New specialist agents</h3>
<ul>
<li><code>rn-build</code> — Create React Native screens, components, forms, lists, and data flows.</li>
<li><code>rn-doctor</code> — Diagnose Android, iOS, Metro, dependency, environment, and build failures.</li>
<li><code>rn-native-modules</code> — Review TurboModules, Fabric, JSI, Codegen, threading, and bridge-based native modules.</li>
</ul>
<h3 id="deterministic-bundle-size-analysis">Deterministic bundle-size analysis</h3>
<p>Added bundle analysis without an API key or model call:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx @maheshwarimrinal/react-native-agents size
</span></span></code></pre></div><p>Compare bundle size against a base branch:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx @maheshwarimrinal/react-native-agents size --base main
</span></span></code></pre></div><p>Budget checks are supported:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx @maheshwarimrinal/react-native-agents size <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --base main <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --budget-delta 100kb
</span></span></code></pre></div><p>The analyzer now includes:</p>
<ul>
<li>Source-map-based package attribution</li>
<li>npm, Yarn, pnpm, and Bun lockfile detection</li>
<li>Strict budget validation</li>
<li>Safe failure when the base bundle cannot be built</li>
<li>No unexpected CLI downloads through <code>npx --no-install</code></li>
</ul>
<h3 id="improved-github-action-reliability">Improved GitHub Action reliability</h3>
<p>The GitHub Action now:</p>
<ul>
<li>Fails by default when an agent cannot complete</li>
<li>Reports failed agents through action outputs</li>
<li>Detects incomplete reviews caused by budget exhaustion</li>
<li>Supports <code>fail-on-error: false</code> for intentionally partial reviews</li>
<li>Falls back to the GitHub files API when a pull-request diff is too large</li>
<li>Handles configuration files outside the repository root more reliably</li>
</ul>
<p>Example:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">React Native audit</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">maheshwarimrinal/react-native-agents@v1.0.2</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">provider</span>: <span style="color:#ae81ff">openai</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">model</span>: <span style="color:#ae81ff">gpt-5</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.OPENAI_API_KEY }}</span>
</span></span></code></pre></div><p>To allow partial results:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">fail-on-error</span>: <span style="color:#66d9ef">false</span>
</span></span></code></pre></div><p>Use this only when a review is allowed to continue despite incomplete agent coverage.</p>
<h3 id="improved-routing">Improved routing</h3>
<p>MCP and GitHub Action routing now better identifies:</p>
<ul>
<li>Build and environment failures</li>
<li>New screen and component requests</li>
<li>Native module and platform-code changes</li>
<li>Performance issues described without explicit React Native keywords</li>
</ul>
<p>Interactive agents are excluded from automatic pull-request reviews unless explicitly requested.</p>
<h3 id="demo-and-documentation-improvements">Demo and documentation improvements</h3>
<ul>
<li>Added a real-world React Native audit demo project.</li>
<li>Added examples for Android native code and catalogue performance issues.</li>
<li>Split the README into focused documentation pages.</li>
<li>Updated generated outputs for Claude Code, Cursor, Windsurf, Copilot, and AGENTS.md.</li>
<li>Expanded evaluation coverage for build, doctor, and native-module scenarios.</li>
</ul>
<h2 id="validation">Validation</h2>
<p>This release includes expanded automated coverage for:</p>
<ul>
<li>Agent routing</li>
<li>Bundle-size analysis</li>
<li>Source-map attribution</li>
<li>Budget enforcement</li>
<li>API failure handling</li>
<li>Build diagnostics</li>
<li>Native-module reviews</li>
<li>Generated target synchronization</li>
</ul>
<h2 id="upgrade">Upgrade</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install @maheshwarimrinal/react-native-agents@1.0.2
</span></span></code></pre></div><p>Or run the latest CLI directly:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx @maheshwarimrinal/react-native-agents@1.0.2 install
</span></span></code></pre></div><p>Full comparison: <a href="https://github.com/maheshwarimrinal/react-native-agents/compare/v1.0.1...v1.0.2">https://github.com/maheshwarimrinal/react-native-agents/compare/v1.0.1...v1.0.2</a></p>
<p>One important release-note detail: mention that API and budget failures now fail the GitHub Action by default. This is a behavior improvement, but users who relied on partial reviews should configure:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">fail-on-error</span>: <span style="color:#66d9ef">false</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/lgtmaybe/</link><pubDate>Mon, 17 Aug 2026 14:00:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v2.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary lgtmaybe is a tool designed to automate and streamline the code review process by analyzing pull request diffs using an AI model. It helps identify logic errors, security vulnerabilities, missing tests, outdated code, performance regressions, unnecessary complexity, intent misalignment, and potential “ponytail” code (code that could be removed). The action reviews files line-by-line, considering context from surrounding lines, and categorizes findings into nine categories: security, correctness, code health, artefacts. It is provider-agnostic and supports multiple OpenAI-compatible endpoints.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v2.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>lgtmaybe is a tool designed to automate and streamline the code review process by analyzing pull request diffs using an AI model. It helps identify logic errors, security vulnerabilities, missing tests, outdated code, performance regressions, unnecessary complexity, intent misalignment, and potential &ldquo;ponytail&rdquo; code (code that could be removed). The action reviews files line-by-line, considering context from surrounding lines, and categorizes findings into nine categories: security, correctness, code health, artefacts. It is provider-agnostic and supports multiple OpenAI-compatible endpoints.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="220-2026-08-17"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v2.1.4...lgtmaybe-v2.2.0">2.2.0</a> (2026-08-17)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>cli:</strong> give the profile a machine-readable form, and stop it corrupting stdout (<a href="https://github.com/MattJColes/lgtmaybe/issues/460">#460</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/ff86872d1fcda2b93b27f374b90561336c1ed98d">ff86872</a>)</li>
<li><strong>engine:</strong> re-ask a lens without the schema when its reply won&rsquo;t parse (<a href="https://github.com/MattJColes/lgtmaybe/issues/463">#463</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/2a241cd723512a80a27030fbce252c6851afc506">2a241cd</a>), closes <a href="https://github.com/MattJColes/lgtmaybe/issues/454">#454</a></li>
<li><strong>evals:</strong> run each fixture N times so flaky and reproducible failures separate (<a href="https://github.com/MattJColes/lgtmaybe/issues/461">#461</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/b8d0568187c608fc474b07d9ebe0267d3b48589e">b8d0568</a>), closes <a href="https://github.com/MattJColes/lgtmaybe/issues/458">#458</a></li>
<li>make structured-output compliance failures diagnosable and survivable (<a href="https://github.com/MattJColes/lgtmaybe/issues/450">#450</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/d1c4f4d0dc7389ff72412dca30d179d53693b96b">d1c4f4d</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>engine:</strong> don&rsquo;t re-ask a lens whose schema the adapter already stripped (<a href="https://github.com/MattJColes/lgtmaybe/issues/465">#465</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/60d79447b0f647f5406c493204bafbc4ee2796ab">60d7944</a>)</li>
<li><strong>provider:</strong> don&rsquo;t step down an effort the route would discard (<a href="https://github.com/MattJColes/lgtmaybe/issues/459">#459</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/464b5b65099af7fda943ee905513787379adea60">464b5b6</a>)</li>
<li><strong>provider:</strong> give a reasoning-bound truncation a lever when no effort was set (<a href="https://github.com/MattJColes/lgtmaybe/issues/452">#452</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/abe7dac224caa5f87e70d546726acb030bd52308">abe7dac</a>)</li>
</ul>
<h3 id="dependencies">Dependencies</h3>
<ul>
<li>bump the python-dependencies group with 8 updates (<a href="https://github.com/MattJColes/lgtmaybe/issues/449">#449</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/047e8b4302e17f57ed9d2137963d9c2a4f69f471">047e8b4</a>)</li>
</ul>
]]></content:encoded></item><item><title>Minds Research Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/minds-research-review/</link><pubDate>Mon, 17 Aug 2026 13:59:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/minds-research-review/</guid><description>Version updated for https://github.com/minds-ai-co/minds-research-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Minds Research Review GitHub Action automates synthetic market research from a GitHub workflow. It allows you to list saved audiences, prepare non-executing study plans, ask one existing group a respondent-visible question, retrieve Panel progress and summary, and more. The action is designed to help streamline the research process for organizations using Minds’ MCP server.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/minds-ai-co/minds-research-action">https://github.com/minds-ai-co/minds-research-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/minds-research-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Minds Research Review GitHub Action automates synthetic market research from a GitHub workflow. It allows you to list saved audiences, prepare non-executing study plans, ask one existing group a respondent-visible question, retrieve Panel progress and summary, and more. The action is designed to help streamline the research process for organizations using Minds&rsquo; MCP server.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial public release of the Minds Research Review action. Safely inspect research groups, create reviewable study plans, ask existing Groups questions, and monitor Panel results through the Minds MCP endpoint.</p>
]]></content:encoded></item><item><title>Motoish CalVer Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/motoish-calver-release/</link><pubDate>Mon, 17 Aug 2026 13:58:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/motoish-calver-release/</guid><description>Version updated for https://github.com/motoish/calver-release-action to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The CalVer Release Action automates the process of publishing immutable daily builds, maintaining a daily prerelease channel, and promoting an explicitly selected build to a monthly stable release. It helps manage versioning across releases in a project using Calendar Versioning (CalVer) conventions. The action requires permissions to write GitHub content and supports customizable timezone settings for the daily calendar.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/motoish/calver-release-action">https://github.com/motoish/calver-release-action</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/motoish-calver-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The CalVer Release Action automates the process of publishing immutable daily builds, maintaining a daily prerelease channel, and promoting an explicitly selected build to a monthly stable release. It helps manage versioning across releases in a project using Calendar Versioning (CalVer) conventions. The action requires permissions to write GitHub content and supports customizable timezone settings for the daily calendar.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="bug-fix">Bug fix</h2>
<p>Daily and promote no longer fail the preflight check when the workflow uses <code>GITHUB_TOKEN</code>.</p>
<p><code>GET /repos</code> reports collaborator ACL (<code>permissions.push</code>), not the job&rsquo;s <code>contents: write</code> grant. GitHub Actions tokens often show <code>push: false</code> even when they can create tags and Releases, which made v1.1.0 fail with:</p>
<p><code>GitHub token requires contents: write permission</code></p>
<p>The Action now only treats a real <code>403</code> from GitHub writes as a permission error. Callers that already set <code>permissions: contents: write</code> do not need a PAT.</p>
<h2 id="upgrade">Upgrade</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">motoish/calver-release-action@v1</span>
</span></span></code></pre></div><p>Move the <code>v1</code> tag to this release after publishing.</p>
]]></content:encoded></item><item><title>Go - Test Suites</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/go-test-suites/</link><pubDate>Mon, 17 Aug 2026 13:57:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/go-test-suites/</guid><description>Version updated for https://github.com/mvrahden/go-test to version v1.27.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, gotest, automates the creation and execution of specification-driven Go test suites with isolation and parallelism as first-class citizens. It generates the lifecycle wiring, t.Run nesting, and process isolation necessary to run standard go test output in a more readable behavioral format. The tool is designed to simplify test organization and reduce discipline problems associated with maintaining clean and organized test files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mvrahden/go-test">https://github.com/mvrahden/go-test</a></strong> to version <strong>v1.27.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-test-suites">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>gotest</code>, automates the creation and execution of specification-driven Go test suites with isolation and parallelism as first-class citizens. It generates the lifecycle wiring, <code>t.Run</code> nesting, and process isolation necessary to run standard <code>go test</code> output in a more readable behavioral format. The tool is designed to simplify test organization and reduce discipline problems associated with maintaining clean and organized test files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix uncompilable Equal/NotEqual autofix on mixed operand types by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/104">https://github.com/mvrahden/go-test/pull/104</a></li>
<li>Reliable test runs on busy machines by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/105">https://github.com/mvrahden/go-test/pull/105</a></li>
<li>keep syncing the spec view when the run had failures by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/108">https://github.com/mvrahden/go-test/pull/108</a></li>
<li>Test the CLI and the extension against each other, not in isolation by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/109">https://github.com/mvrahden/go-test/pull/109</a></li>
<li>Show what tests promise, before you run them by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/110">https://github.com/mvrahden/go-test/pull/110</a></li>
<li>Behavior descriptions render as defined by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/111">https://github.com/mvrahden/go-test/pull/111</a></li>
<li>Report the time each test actually took by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/112">https://github.com/mvrahden/go-test/pull/112</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mvrahden/go-test/compare/v1.26.0...v1.27.0">https://github.com/mvrahden/go-test/compare/v1.26.0...v1.27.0</a></p>
]]></content:encoded></item><item><title>LinkML (linkml-scala)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/linkml-linkml-scala/</link><pubDate>Mon, 17 Aug 2026 13:55:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/linkml-linkml-scala/</guid><description>Version updated for https://github.com/NeverBlink-OSS/linkml-scala-action to version v0.13.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation and generation of LinkML schemas using Node.js. It leverages linkml-scala to perform these tasks efficiently, providing inline error and warning annotations directly in pull requests. The action supports various commands such as validation and generation with options like strict mode, generator types, and output handling.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NeverBlink-OSS/linkml-scala-action">https://github.com/NeverBlink-OSS/linkml-scala-action</a></strong> to version <strong>v0.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/linkml-linkml-scala">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation and generation of LinkML schemas using Node.js. It leverages linkml-scala to perform these tasks efficiently, providing inline error and warning annotations directly in pull requests. The action supports various commands such as validation and generation with options like strict mode, generator types, and output handling.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Tracks <a href="https://github.com/NeverBlink-OSS/linkml-scala/releases/tag/v0.13.0">linkml-scala v0.13.0</a>.</p>
<p>Bundles <code>@neverblink/linkml@0.13.0</code>.</p>
<ul>
<li>Pin <code>uses: NeverBlink-OSS/linkml-scala-action@v0.13.0</code> for reproducibility.</li>
<li>Pin <code>@v1</code> for automatic patch/minor updates.</li>
</ul>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/odin-scan-smart-contract-security/</link><pubDate>Mon, 17 Aug 2026 13:54:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security analysis of smart contracts across CosmWasm, Solana, and EVM platforms. It integrates seamlessly with GitHub workflows to catch vulnerabilities before deployment, providing detailed reports on pull requests and inline annotations in changed files. The action supports automatic platform detection or explicit specification, uploads SARIF for native security alerts, and offers configurable thresholds for severity, fail modes, and PR comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the security analysis of smart contracts across CosmWasm, Solana, and EVM platforms. It integrates seamlessly with GitHub workflows to catch vulnerabilities before deployment, providing detailed reports on pull requests and inline annotations in changed files. The action supports automatic platform detection or explicit specification, uploads SARIF for native security alerts, and offers configurable thresholds for severity, fail modes, and PR comments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add comment-triggered PR scans (ac72e5f)</li>
<li>docs: expand findings-visibility section with threat model and annotation rationale (0404708)</li>
<li>feat: add findings-visibility input for graduated public disclosure control (f18df59)</li>
<li>fix: show findings detail in PR comment with fallback to medium (c2e43c8)</li>
<li>fix: new comment per run, show only critical/high findings, rebuild dist (e237b62)</li>
<li>feat: use GitHub App installation token for branded PR comments (3abce4e)</li>
<li>feat: enrich PR comment with emojis, descriptions, and fix report URL (27cc2f2)</li>
<li>fix: gzip SARIF before base64 encoding for Code Scanning upload (d9eed9f)</li>
<li>fix: include sourcemap-register.js in dist (bd265af)</li>
<li>docs: add privacy policy (b78db44)</li>
</ul>
]]></content:encoded></item><item><title>svelte-vitals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/svelte-vitals/</link><pubDate>Mon, 17 Aug 2026 13:53:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/svelte-vitals/</guid><description>Version updated for https://github.com/oekazuma/svelte-vitals-action to version v0.10.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The svelte-vitals-action is a GitHub Action that automates static SvelteKit code health checks (SEO, Performance, Correctness, Security, Architecture, Accessibility) on pull requests. It provides inline annotations on the diff, a job summary, and a sticky PR comment that updates in place with new findings as changes are pushed. The action uses the svelte-vitals CLI for analysis and supports input parameters for configuring the scan scope, output format, and error handling.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oekazuma/svelte-vitals-action">https://github.com/oekazuma/svelte-vitals-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/svelte-vitals">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The svelte-vitals-action is a GitHub Action that automates static SvelteKit code health checks (SEO, Performance, Correctness, Security, Architecture, Accessibility) on pull requests. It provides inline annotations on the diff, a job summary, and a sticky PR comment that updates in place with new findings as changes are pushed. The action uses the svelte-vitals CLI for analysis and supports input parameters for configuring the scan scope, output format, and error handling.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="minor-changes">Minor Changes</h3>
<ul>
<li>
<p>0153223: Update the bundled analyzer to <code>svelte-vitals</code> 0.48.0 / <code>@svelte-vitals/core</code> 0.44.0. The action&rsquo;s inputs and outputs are unchanged, but one change here stops a workflow that currently passes until a file is renamed, and a new rule category moves every Health score.</p>
<p><strong>Config files must be ESM, and <code>svelte-vitals.config.mjs</code> is no longer read.</strong> The loader searches <code>svelte-vitals.config.{js,ts}</code> only. A leftover <code>.mjs</code> throws with a rename hint, and a <code>.js</code> config that parses as CommonJS throws with a &ldquo;config files are ESM&rdquo; error — both propagate out of the analysis and fail the step outright, rather than quietly falling back to defaults. Rename a <code>.mjs</code> config to <code>.js</code> (the project must be <code>&quot;type&quot;: &quot;module&quot;</code>, which is SvelteKit&rsquo;s default) or to <code>.ts</code>. CommonJS projects are no longer supported.</p>
<p><strong>A new Accessibility category adds 15 rules, all on by default, and shifts every Health score.</strong> ARIA role, attribute and value validity, required ARIA props, interactive-element nesting, accessible-name computability, label/control association, list-like text, <code>&lt;select&gt;</code> placeholder options, machine-readable <code>&lt;time&gt;</code>, an <code>app.html</code> doctype check, plus landmark duplication/nesting and project-wide id/idref integrity resolved across component boundaries. Existing projects will see new findings. Twelve of the fifteen are <code>warning</code> and three are <code>info</code>; none is <code>critical</code>, so under the default <code>failOn: critical</code> the new category adds annotations and moves scores without being able to fail the step. A project configured with <code>failOn: warning</code> is a different matter — twelve warning-level rules landing at once can turn it red. Separately from any finding, a sixth category now enters the weighted average, so the Health number in the job summary and the sticky comment moves on upgrade with no change on your side — recalibrate anything reading it.</p>
<p>The analyzer also raises its minimum Node to 24.16.0. The action runs on <code>node24</code>, so this is only a concern if your runner&rsquo;s Node 24 predates that patch.</p>
<p>Beyond that, the scan reaches code it previously could not:</p>
<ul>
<li><strong>Projects styling components in a CSS dialect were not analyzable at all.</strong> Svelte parses a <code>&lt;style&gt;</code> body as CSS whatever its <code>lang</code> says, so one <code>&lt;style lang=&quot;scss&quot;&gt;</code> block made a component unparseable, and a single unparseable route failed the entire run — which for this action meant the step failed with no report. SCSS, Less and Stylus projects now analyze normally, and will see their first real report.</li>
<li><strong>Large projects were losing files to an exhausted descriptor limit.</strong> Every <code>.svelte</code> file was read in parallel with no bound, so a big tree ran out of descriptors and each <code>EMFILE</code> was misattributed as a parse failure and dropped — the file went unanalyzed and the score never reflected the gap. The action did report the count as a skipped-file warning, so this was visible if you were reading annotations, just misdescribed. Reads are now bounded, so those files are analyzed and can carry findings.</li>
<li><strong>Source mode no longer collapses <code>&lt;link&gt;</code> and <code>&lt;script src&gt;</code> tags that share a <code>rel</code> or <code>src</code>.</strong> The composed <code>&lt;svelte:head&gt;</code> kept only the last one per key across the layout chain, so a page with two <code>rel=&quot;preload&quot;</code> entries, both Google Fonts <code>preconnect</code> origins, or several <code>hreflang</code> alternates was judged on one of them — producing a false &ldquo;un-preconnected origin&rdquo; on a correctly configured site — and a page&rsquo;s <code>defer</code> copy of a script masked the layout&rsquo;s render-blocking one. <code>rel=&quot;canonical&quot;</code> is the deliberate exception and still collapses, so a page canonical continues to override the layout&rsquo;s. Findings move in both directions here, and stored baselines or suppressions may need re-recording.</li>
<li><code>&lt;link&gt;</code> <code>rel</code> and <code>as</code> keywords are now matched case-insensitively as the HTML spec requires, so <code>rel=&quot;Canonical&quot;</code> and <code>rel=&quot;Preload&quot;</code> are recognised.</li>
<li>The inline <code>svelte-vitals-disable-next-line</code> directive now honours <code>a11y/*</code> rule ids, which it silently ignored.</li>
</ul>
</li>
</ul>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>
<p>74130f7: Update the bundled analyzer to <code>svelte-vitals</code> 0.48.1 / <code>@svelte-vitals/core</code> 0.45.0, and take the report and gating functions from <code>@svelte-vitals/core</code>&rsquo;s stable entry now that they are exported there.</p>
<p>Nothing the action reports changes: no rule, severity, score, annotation, job summary or sticky-comment output moves. The promotion upstream is a pure re-export, and the four functions this action calls — <code>formatGithubReport</code>, <code>formatMarkdownReport</code>, <code>summarize</code>, <code>hasFailureAtOrAbove</code> — keep the same signatures and behaviour.</p>
<p>What changes is the promise behind them. They previously came from <code>@svelte-vitals/core/internal</code>, which upstream excludes from semver and may reshape in any release including a patch, so a dependency bump could break this action&rsquo;s committed bundle with only its own CI typecheck standing in the way. They now come from an entry covered by semver.</p>
</li>
</ul>
]]></content:encoded></item><item><title>yaml-workflow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/yaml-workflow/</link><pubDate>Mon, 17 Aug 2026 13:52:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/yaml-workflow/</guid><description>Version updated for https://github.com/orieg/yaml-workflow to version v0.9.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The YAML Workflow action is a lightweight workflow engine that allows users to define reproducible CI/CD pipelines, data processing, and DevOps automation tasks in version-controlled YAML files. It provides features like multiple task types, workflow composition via imports, and state persistence with resume capability. The action is designed for use cases where simple task automation without infrastructure overhead is needed, making it a lightweight alternative to shell scripts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/orieg/yaml-workflow">https://github.com/orieg/yaml-workflow</a></strong> to version <strong>v0.9.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yaml-workflow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The YAML Workflow action is a lightweight workflow engine that allows users to define reproducible CI/CD pipelines, data processing, and DevOps automation tasks in version-controlled YAML files. It provides features like multiple task types, workflow composition via imports, and state persistence with resume capability. The action is designed for use cases where simple task automation without infrastructure overhead is needed, making it a lightweight alternative to shell scripts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(mcp): discovery/validate/dry-run/run meta-tools + Glama metadata by @orieg in <a href="https://github.com/orieg/yaml-workflow/pull/44">https://github.com/orieg/yaml-workflow/pull/44</a></li>
<li>chore: bump version to 0.9.5 by @orieg in <a href="https://github.com/orieg/yaml-workflow/pull/45">https://github.com/orieg/yaml-workflow/pull/45</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/orieg/yaml-workflow/compare/v0.9.4...v0.9.5">https://github.com/orieg/yaml-workflow/compare/v0.9.4...v0.9.5</a></p>
]]></content:encoded></item><item><title>Otzaria Plugin Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/otzaria-plugin-validator/</link><pubDate>Mon, 17 Aug 2026 13:51:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/otzaria-plugin-validator/</guid><description>Version updated for https://github.com/Otzaria/otzaria-plugin-validator to version v1.13.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of validating, building, and publishing an Otzaria plugin to the Otzaria store. It checks the plugin’s requirements and builds it before pushing a new version to the main branch, which is then published automatically to the store when secrets are set.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Otzaria/otzaria-plugin-validator">https://github.com/Otzaria/otzaria-plugin-validator</a></strong> to version <strong>v1.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/otzaria-plugin-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of validating, building, and publishing an Otzaria plugin to the Otzaria store. It checks the plugin&rsquo;s requirements and builds it before pushing a new version to the main branch, which is then published automatically to the store when secrets are set.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="מה-חדש">מה חדש</h2>
<ul>
<li><strong>ולידציית <code>when</code></strong> — בדיקה מלאה של תנאי הגדרות על תרומות דקלרטיביות (<code>toolbarItems</code>, <code>contextMenuItems</code>, <code>searchDialogItems</code>, <code>activationEvents</code>): סכימת <code>setting</code>/<code>storage</code>/<code>all</code>/<code>any</code>/<code>not</code>, מגבלות עומק (5), עלים (20) ואורך מפתח (128), דחיית מפתחות לא מוכרים באיברי <code>activationEvents</code>, ואכיפת <code>minAppVersion &gt;= 0.9.97</code> — רק כשקיים <code>when</code> בפועל; תוספים קיימים אינם מושפעים.</li>
<li>רשימת מפתחות ההגדרות המורשים לקריאה נגזרת חיה מ-API_REFERENCE.md, עם רצפה מובנית לכשל רשת ובדיקת spec-drift.</li>
<li>הושלמו 5 הרשאות שחסרו ברשימת ה-fallback — מונע חסימת-שווא של תוספי <code>contributes.startup</code> במצב אופליין.</li>
</ul>
]]></content:encoded></item><item><title>rung gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/rung-gate/</link><pubDate>Mon, 17 Aug 2026 13:49:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/rung-gate/</guid><description>Version updated for https://github.com/rung-dev/rung to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The rung GitHub Action automates the verification of code changes by grading their realism and independence. It distinguishes between “verified” claims based on the steps taken from reasoning about the code to driving real surfaces and capturing differences consistent with changes. The action supports different rung levels (0-4) and evaluation contexts (author, fresh-blind, cross-lab), providing a standardized way to track verification claims.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rung-dev/rung">https://github.com/rung-dev/rung</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rung-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>rung</code> GitHub Action automates the verification of code changes by grading their realism and independence. It distinguishes between &ldquo;verified&rdquo; claims based on the steps taken from reasoning about the code to driving real surfaces and capturing differences consistent with changes. The action supports different rung levels (0-4) and evaluation contexts (author, fresh-blind, cross-lab), providing a standardized way to track verification claims.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Maintenance release. No functional changes to the gate, run wrapper, schema, or policy; the version bump carries a pinned build to PyPI and GHCR.</p>
<p>Published as:</p>
<ul>
<li>pip install rung-ai==0.1.2</li>
<li>uses: <a href="mailto:rung-dev/rung@v0.1.2">rung-dev/rung@v0.1.2</a></li>
<li>docker run &ndash;rm ghcr.io/rung-dev/rung:0.1.2 version</li>
</ul>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/custom-amazon-bedrock-agent-action/</link><pubDate>Mon, 17 Aug 2026 13:48:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze PR files and provide feedback using customized prompts. It integrates with Knowledge Bases for more context-aware insights and is highly customizable, allowing for tailored analysis for code quality improvement, security assessments, and performance optimizations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze PR files and provide feedback using customized prompts. It integrates with Knowledge Bases for more context-aware insights and is highly customizable, allowing for tailored analysis for code quality improvement, security assessments, and performance optimizations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>agent-trace eval</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/agent-trace-eval/</link><pubDate>Mon, 17 Aug 2026 13:47:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/agent-trace-eval/</guid><description>Version updated for https://github.com/Siddhant-K-code/agent-trace to version v0.93.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary agent-trace is an experimental tool designed to capture and replay AI agent sessions, providing insights into file operations, tool calls, decision points, error recovery, and commands executed by the agent. It helps developers understand and audit AI-assisted work after the fact, ensuring transparency and accountability. The tool can be installed via pip and offers CLI hooks, an MCP proxy, and a Python decorator for integration with various coding tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Siddhant-K-code/agent-trace">https://github.com/Siddhant-K-code/agent-trace</a></strong> to version <strong>v0.93.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-trace-eval">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>agent-trace</code> is an experimental tool designed to capture and replay AI agent sessions, providing insights into file operations, tool calls, decision points, error recovery, and commands executed by the agent. It helps developers understand and audit AI-assisted work after the fact, ensuring transparency and accountability. The tool can be installed via pip and offers CLI hooks, an MCP proxy, and a Python decorator for integration with various coding tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: refresh CLI docs and Action packaging (#237)</li>
</ul>
]]></content:encoded></item><item><title>Setup Wiremock Stubs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/setup-wiremock-stubs/</link><pubDate>Mon, 17 Aug 2026 13:46:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/setup-wiremock-stubs/</guid><description>Version updated for https://github.com/SingingBush/setup-wiremock-stubs-action to version 0.3.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Setup Wiremock Stubs Action automates the process of uploading Wiremock stubs to a running instance of Wiremock. This action is particularly useful in CI/CD pipelines where integration tests require a specific set of mock responses from a server. It simplifies the setup and deployment of test environments by integrating with wiremock as a GitHub Service, allowing developers to manage stubs easily within their workflow configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SingingBush/setup-wiremock-stubs-action">https://github.com/SingingBush/setup-wiremock-stubs-action</a></strong> to version <strong>0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-wiremock-stubs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Setup Wiremock Stubs Action automates the process of uploading Wiremock stubs to a running instance of Wiremock. This action is particularly useful in CI/CD pipelines where integration tests require a specific set of mock responses from a server. It simplifies the setup and deployment of test environments by integrating with wiremock as a GitHub Service, allowing developers to manage stubs easily within their workflow configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>first published release. configure stubs in an already running wiremock service</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>output mappings by @SingingBush in <a href="https://github.com/SingingBush/setup-wiremock-stubs-action/pull/14">https://github.com/SingingBush/setup-wiremock-stubs-action/pull/14</a></li>
<li>Bump @types/node from 26.1.1 to 26.1.2 in the npm-development group by @dependabot[bot] in <a href="https://github.com/SingingBush/setup-wiremock-stubs-action/pull/15">https://github.com/SingingBush/setup-wiremock-stubs-action/pull/15</a></li>
<li>Bump brace-expansion from 1.1.16 to 1.1.18 by @dependabot[bot] in <a href="https://github.com/SingingBush/setup-wiremock-stubs-action/pull/17">https://github.com/SingingBush/setup-wiremock-stubs-action/pull/17</a></li>
<li>Bump the npm-development group with 2 updates by @dependabot[bot] in <a href="https://github.com/SingingBush/setup-wiremock-stubs-action/pull/18">https://github.com/SingingBush/setup-wiremock-stubs-action/pull/18</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SingingBush/setup-wiremock-stubs-action/compare/0.2...0.3">https://github.com/SingingBush/setup-wiremock-stubs-action/compare/0.2...0.3</a></p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/bernstein-multi-agent-orchestration/</link><pubDate>Mon, 17 Aug 2026 13:45:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.16.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is an open-source tool designed to orchestrate deterministic multi-agent CLI operations. It automates the execution of various AI language models like Claude Code, Codex, and Gemini CLI in parallel, ensuring consistent and predictable results by gating output and recording detailed logs. The action supports a wide range of models and provides clear documentation and support for integration into development workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.16.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein is an open-source tool designed to orchestrate deterministic multi-agent CLI operations. It automates the execution of various AI language models like Claude Code, Codex, and Gemini CLI in parallel, ensuring consistent and predictable results by gating output and recording detailed logs. The action supports a wide range of models and provides clear documentation and support for integration into development workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Someone pulled the plug mid-write. The journal ended on half a line, and the task
that owned it was gone. That used to be the end of the story. Here it is a repair.</p>
<h2 id="replay-stopped-losing-the-ending">Replay stopped losing the ending</h2>
<ul>
<li>A crash-torn journal tail is repaired and the suspended task resumes. (#3955, @Louis20060723)</li>
<li>Journal consistency and sealed identity are separate verdicts, so a clean prefix stops passing for a whole journal. (#3908, @Silentpartnercoding)</li>
<li><code>event_count</code> counts usable events through the sealed prefix instead of trusting the file. (#4025, @sujeito-operator)</li>
<li>A journal line that is not valid UTF-8 is discarded, not raised. (#4008, @sujeito-operator)</li>
<li><code>replay --as-json</code> emits JSON on every exit path, including the ones that fail. (#4017, @Chirag6722; #3991)</li>
</ul>
<h2 id="proof-instead-of-assurance">Proof instead of assurance</h2>
<ul>
<li>A result bundle verifies offline against DSSE. No network, no registry, nobody to ask. (#3903, @Nickgonzales76017)</li>
<li><code>allowed_files</code> is enforced at the merge acceptance gate, not merely declared. (#4002, @Aeirx)</li>
<li>A merge whose incoming change cannot be verified is refused rather than waved through. (#4022)</li>
<li>The credential <code>token_type</code> allowlist derives from its own Literal and cannot drift from it. (#4030, @Aeirx)</li>
</ul>
<h2 id="volunteer-workers">Volunteer workers</h2>
<p>Bernstein opted into its own volunteer program, which is either good engineering or
a conflict of interest. The project manifest is content-addressed, the sandbox
profile is derived rather than declared, and <code>bernstein volunteer verify</code> says
which. (#3907, #3909, #3912, #3916, #3920)</p>
<h2 id="boundaries">Boundaries</h2>
<ul>
<li>Sixteen hand-rolled path checks became one containment helper. (#3855, #3857, #3858, @vaibhav8a)</li>
<li>Card matches are Luhn-validated before redaction: real numbers go, coincidences stay readable. (#3818, @vaibhav8a)</li>
<li>Budget forecasts are scoped to the caller&rsquo;s tenant. (#3850, @vaibhav8a)</li>
<li>Upgrade proposals are gated on the proposer&rsquo;s measured history. Confidence is not history. (#3840, #3843, @Nickgonzales76017)</li>
</ul>
<h2 id="the-ci-said-it-was-fine">The CI said it was fine</h2>
<p>It was not. A gate that always succeeded, a mutation lane that could not fail, a
workflow whose header described another workflow. Now they say what they do.</p>
<ul>
<li>Silently-inert gates and misleading green, across the workflow surface. (#3945, #3960)</li>
<li>Workflow headers and names match behaviour. (#3956, @ThinkerDesigns)</li>
<li>Merges land through a queue, and release bumps go through it too. (#3964)</li>
</ul>
<h2 id="also">Also</h2>
<ul>
<li>READMEs in Hindi and Bengali. (#3992)</li>
<li>First-run paths for <code>evolve</code> and <code>listen</code> are fenced. (#3848, @jvsilva12600009)</li>
<li>A dashboard vocabulary reference. (#3790, @atirna)</li>
<li>The TUI renders a toast again, and its task list stops lying about stale rows. (#3938; #3932, @ShlokShar)</li>
</ul>
<h2 id="upgrading">Upgrading</h2>
<p>Upgrade in place. <code>JournalVerifyResult</code> reports chain consistency, reader coverage
and sealed identity as three verdicts instead of one <code>ok</code> bit; anything reading the
old bit needs updating.</p>
<h2 id="contributors">Contributors</h2>
<p>@Chirag6722 · @sujeito-operator · @vaibhav8a · @Louis20060723 ·
@Nickgonzales76017 · @Aeirx · @ThinkerDesigns · @Silentpartnercoding ·
@ShlokShar · @atirna · @jvsilva12600009 — and Renovate and Dependabot,
who never sleep.</p>
<h2 id="soundtrack">Soundtrack</h2>
<p>Two footwork takes on the same lyric sheet.</p>
<ul>
<li><a href="https://suno.com/s/07IQxBXsmYBRosMC">v3.16.0 — take one</a></li>
<li><a href="https://suno.com/s/g3xWwVpKDF3J5gRZ">v3.16.0 — take two</a></li>
</ul>
<details>
<summary>Lyrics</summary>
<pre tabindex="0"><code>[Intro — dry vocal, chopped]
Version three... one... six
Tag it — tag it — tag it
(queue empty, main green)

[Drop — chop loop]
Drain the queue, drain the queue
Merge — merge — merge —
Green on main, green on main
Fake green? Found it. Gated.

[Break — replay]
Torn tail? Stitched.
Crash mid-write? Resume.
Replay it byte for byte
Same hash — same hash — every time

[Drop — receipts]
Show me the receipt (-ceipt -ceipt -ceipt)
Verify it offline
No trust, just proof
No trust — just proof

[Break — volunteer]
Lend your worker to the cause
Sandbox locked, scope declared
Zero creds, clean room
We run our own program

[Bridge — tenant]
Your data — your lane
Tenant-scoped, stay in your lane
Card match? Redacted.
No leak — no leak

[Outro]
Readme speaks four new tongues
Mutation gate bites now
The ratchet only turns one way
Three... one... six. (tag it)
</code></pre></details>
<hr>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(web): add dashboard vocabulary reference by @atirna in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3790">https://github.com/sipyourdrink-ltd/bernstein/pull/3790</a></li>
<li>fix(openapi): refresh the snapshot and guard schema property names by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3811">https://github.com/sipyourdrink-ltd/bernstein/pull/3811</a></li>
<li>chore(ci): ratchet coverage baseline up to 83.63% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3805">https://github.com/sipyourdrink-ltd/bernstein/pull/3805</a></li>
<li>docs(release-notes): match the v3.15.1 page to the published release by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3816">https://github.com/sipyourdrink-ltd/bernstein/pull/3816</a></li>
<li>chore(deps): update dependency astral-sh/uv to v0.12.3 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3812">https://github.com/sipyourdrink-ltd/bernstein/pull/3812</a></li>
<li>fix(observability): Luhn-validate card matches before redacting by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3818">https://github.com/sipyourdrink-ltd/bernstein/pull/3818</a></li>
<li>fix(observability): stop a late prometheus_client import from replacing the stub registry by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3819">https://github.com/sipyourdrink-ltd/bernstein/pull/3819</a></li>
<li>fix(knowledge): resolve the default branch through a merge-queue ref by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3845">https://github.com/sipyourdrink-ltd/bernstein/pull/3845</a></li>
<li>docs(operations): record the merge-queue flip and the fresh wall-time measurement by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3842">https://github.com/sipyourdrink-ltd/bernstein/pull/3842</a></li>
<li>fix(ci): pin the aider canary install to an interpreter the CLI runs under by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3841">https://github.com/sipyourdrink-ltd/bernstein/pull/3841</a></li>
<li>fix(multimodal): run the attachment pipeline from the spawn path by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3814">https://github.com/sipyourdrink-ltd/bernstein/pull/3814</a></li>
<li>chore(ci): ratchet coverage baseline up to 83.63% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3832">https://github.com/sipyourdrink-ltd/bernstein/pull/3832</a></li>
<li>chore(deps): update dependency platformdirs to v4.11.1 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3851">https://github.com/sipyourdrink-ltd/bernstein/pull/3851</a></li>
<li>fix(routes): scope budget forecast to the caller&rsquo;s tenant by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3850">https://github.com/sipyourdrink-ltd/bernstein/pull/3850</a></li>
<li>fix: fence evolve and listen first-run paths by @jvsilva12600009 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3848">https://github.com/sipyourdrink-ltd/bernstein/pull/3848</a></li>
<li>feat(evolution): gate upgrade proposals on the proposer&rsquo;s measured history by @Nickgonzales76017 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3840">https://github.com/sipyourdrink-ltd/bernstein/pull/3840</a></li>
<li>feat(mcp): register plugin mcp.json servers through config gates (#3773) by @Louis20060723 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3849">https://github.com/sipyourdrink-ltd/bernstein/pull/3849</a></li>
<li>style(tests): restore the trailing newline on test_feature_matrix_drift by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3854">https://github.com/sipyourdrink-ltd/bernstein/pull/3854</a></li>
<li>perf(tests): collect only as RSS approaches the cap, not after every test by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3847">https://github.com/sipyourdrink-ltd/bernstein/pull/3847</a></li>
<li>docs: regenerate adapter last-green table from canary receipts by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3853">https://github.com/sipyourdrink-ltd/bernstein/pull/3853</a></li>
<li>chore(auto): nightly mirror + format drift sweep by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3859">https://github.com/sipyourdrink-ltd/bernstein/pull/3859</a></li>
<li>feat(config): gate the reviewer auto-execute path through the same admission policy by @Nickgonzales76017 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3843">https://github.com/sipyourdrink-ltd/bernstein/pull/3843</a></li>
<li>fix(ci): retry pip-audit on transient pypi.org failures by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3860">https://github.com/sipyourdrink-ltd/bernstein/pull/3860</a></li>
<li>fix(skills): route the three core/skills path checks through the containment helper by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3855">https://github.com/sipyourdrink-ltd/bernstein/pull/3855</a></li>
<li>fix(adapters): contain the receipt temp path, not just the sealed name by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3857">https://github.com/sipyourdrink-ltd/bernstein/pull/3857</a></li>
<li>fix(routes,replay): contain the run id in the diff path, not just the task id by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3858">https://github.com/sipyourdrink-ltd/bernstein/pull/3858</a></li>
<li>refactor(security): one Luhn implementation, length policy left with callers by @vaibhav8a in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3862">https://github.com/sipyourdrink-ltd/bernstein/pull/3862</a></li>
<li>fix(adapters): relay explicit_max_turns through CachingAdapter (#3738) by @Louis20060723 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3882">https://github.com/sipyourdrink-ltd/bernstein/pull/3882</a></li>
<li>docs: Japanese and Korean READMEs, plus a copy pass on the front-page docs by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3861">https://github.com/sipyourdrink-ltd/bernstein/pull/3861</a></li>
<li>docs(contributing): point newcomers at the volunteer workers program by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3893">https://github.com/sipyourdrink-ltd/bernstein/pull/3893</a></li>
<li>docs(assets): add the volunteer program banner used by the RFC by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3895">https://github.com/sipyourdrink-ltd/bernstein/pull/3895</a></li>
<li>docs(roadmap): replace the file with pointers to the live views; retire the generator script by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3894">https://github.com/sipyourdrink-ltd/bernstein/pull/3894</a></li>
<li>docs(readme): replace the front-page banner with the engraved score artwork by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3896">https://github.com/sipyourdrink-ltd/bernstein/pull/3896</a></li>
<li>chore(deps): update dependency esbuild to v0.28.2 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3904">https://github.com/sipyourdrink-ltd/bernstein/pull/3904</a></li>
<li>test: prove the first run of <code>bernstein live</code> and <code>bernstein worker</code> (#3826) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3899">https://github.com/sipyourdrink-ltd/bernstein/pull/3899</a></li>
<li>test: prove the three Ecosystem first-run rows (#3828) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3900">https://github.com/sipyourdrink-ltd/bernstein/pull/3900</a></li>
<li>fix(ci): gate the RPM smokes on the simple index, not the JSON API (#3815) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3898">https://github.com/sipyourdrink-ltd/bernstein/pull/3898</a></li>
<li>docs: prove <code>bernstein init</code>, fence the two demo rows (#3825) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3897">https://github.com/sipyourdrink-ltd/bernstein/pull/3897</a></li>
<li>feat(security): result receipt bundle with offline DSSE verify (#3870) by @Nickgonzales76017 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3903">https://github.com/sipyourdrink-ltd/bernstein/pull/3903</a></li>
<li>fix(ci): surface contract drift on fork PRs instead of a token-scope error by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3906">https://github.com/sipyourdrink-ltd/bernstein/pull/3906</a></li>
<li>feat(volunteer): content-addressed project manifest and loader by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3907">https://github.com/sipyourdrink-ltd/bernstein/pull/3907</a></li>
<li>fix(replay): separate journal consistency from sealed identity by @Silentpartnercoding in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3908">https://github.com/sipyourdrink-ltd/bernstein/pull/3908</a></li>
<li>feat(volunteer): derived, content-addressed hardened sandbox profile by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3909">https://github.com/sipyourdrink-ltd/bernstein/pull/3909</a></li>
<li>feat(volunteer): bernstein opts into its own volunteer program by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3912">https://github.com/sipyourdrink-ltd/bernstein/pull/3912</a></li>
<li>fix(cli): demo &ndash;flask-todo reports what the run actually did by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3913">https://github.com/sipyourdrink-ltd/bernstein/pull/3913</a></li>
<li>feat(volunteer): one answer to whether a path is inside a declared scope by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3916">https://github.com/sipyourdrink-ltd/bernstein/pull/3916</a></li>
<li>fix(fleet): bulk-cost-report dispatches <code>cost</code>, a command that resolves (#3755) by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3915">https://github.com/sipyourdrink-ltd/bernstein/pull/3915</a></li>
<li>chore(ci): ratchet coverage baseline up to 83.68% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3918">https://github.com/sipyourdrink-ltd/bernstein/pull/3918</a></li>
<li>feat(volunteer): register the CLI group and ship <code>volunteer verify</code> by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3920">https://github.com/sipyourdrink-ltd/bernstein/pull/3920</a></li>
<li>fix(docs): rotate unreleased.md and guard it against re-accumulating by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3924">https://github.com/sipyourdrink-ltd/bernstein/pull/3924</a></li>
<li>fix(cost): a missing default metrics dir reports empty, not error (#3917) by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3921">https://github.com/sipyourdrink-ltd/bernstein/pull/3921</a></li>
<li>chore(ci): ratchet coverage baseline up to 83.7% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3925">https://github.com/sipyourdrink-ltd/bernstein/pull/3925</a></li>
<li>fix(cost): read the archive before reporting no data (#3923) by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3926">https://github.com/sipyourdrink-ltd/bernstein/pull/3926</a></li>
<li>fix(cli): the readiness error reports the budget the wait actually uses (#3905) by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3929">https://github.com/sipyourdrink-ltd/bernstein/pull/3929</a></li>
<li>test(bootstrap): assert the readiness message with the real timeout constant by @Louis20060723 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3930">https://github.com/sipyourdrink-ltd/bernstein/pull/3930</a></li>
<li>fix(ci): the coverage ratchet declines a locked branch instead of failing on it by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3931">https://github.com/sipyourdrink-ltd/bernstein/pull/3931</a></li>
<li>Fix stale-row key annotation in TUI task list by @ShlokShar in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3932">https://github.com/sipyourdrink-ltd/bernstein/pull/3932</a></li>
<li>fix(tui): app.notify renders a toast again (#3933) by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3938">https://github.com/sipyourdrink-ltd/bernstein/pull/3938</a></li>
<li>feat(contributing): route area PRs to the area steward without a write grant by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3939">https://github.com/sipyourdrink-ltd/bernstein/pull/3939</a></li>
<li>docs: regenerate adapter last-green table from canary receipts by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3934">https://github.com/sipyourdrink-ltd/bernstein/pull/3934</a></li>
<li>fix(cli): let the console survive a legacy Windows code page (#3901) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3936">https://github.com/sipyourdrink-ltd/bernstein/pull/3936</a></li>
<li>test(tenant-scope): release the app each case builds, so the heap stops growing (#3927) by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3937">https://github.com/sipyourdrink-ltd/bernstein/pull/3937</a></li>
<li>docs(canary): describe why a last-green row can be missing, without naming adapters by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3942">https://github.com/sipyourdrink-ltd/bernstein/pull/3942</a></li>
<li>ci(decompose): gate pipeline start on the maintainer who applies the label by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3941">https://github.com/sipyourdrink-ltd/bernstein/pull/3941</a></li>
<li>fix(security): confine the ratchet&rsquo;s privileged checkout and stretch the A2A signing key by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3943">https://github.com/sipyourdrink-ltd/bernstein/pull/3943</a></li>
<li>chore(ci): ratchet coverage baseline up to 83.77% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3944">https://github.com/sipyourdrink-ltd/bernstein/pull/3944</a></li>
<li>chore(ci): raise diff-coverage floor to 86% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3946">https://github.com/sipyourdrink-ltd/bernstein/pull/3946</a></li>
<li>ci: fix silently-inert gates and misleading green across the workflow surface by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3945">https://github.com/sipyourdrink-ltd/bernstein/pull/3945</a></li>
<li>ci(weekly-digest): remove the dead threshold-alert computation by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3958">https://github.com/sipyourdrink-ltd/bernstein/pull/3958</a></li>
<li>ci: land major/minor release bumps through the merge queue by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3964">https://github.com/sipyourdrink-ltd/bernstein/pull/3964</a></li>
<li>fix(ci): let the mutation gate actually fail instead of always succeeding by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3960">https://github.com/sipyourdrink-ltd/bernstein/pull/3960</a></li>
<li>ops: three dormant CI lanes - decisions implemented by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3967">https://github.com/sipyourdrink-ltd/bernstein/pull/3967</a></li>
<li>ci(branch-protection-audit): read the live ruleset instead of the legacy protection API by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3962">https://github.com/sipyourdrink-ltd/bernstein/pull/3962</a></li>
<li>chore(ci): ratchet coverage baseline up to 83.77% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3961">https://github.com/sipyourdrink-ltd/bernstein/pull/3961</a></li>
<li>ci: shard the per-push macOS test lane 4-way by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3957">https://github.com/sipyourdrink-ltd/bernstein/pull/3957</a></li>
<li>chore(deps): update mkdocs-material[imaging] requirement from &lt;10,&gt;=9.7.6 to &gt;=9.7.7,&lt;10 by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3983">https://github.com/sipyourdrink-ltd/bernstein/pull/3983</a></li>
<li>chore(deps): bump actions/setup-python from 6.3.0 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3977">https://github.com/sipyourdrink-ltd/bernstein/pull/3977</a></li>
<li>chore(deps): bump docker/setup-qemu-action from 3.7.0 to 4.2.0 by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3978">https://github.com/sipyourdrink-ltd/bernstein/pull/3978</a></li>
<li>chore(deps): bump rich from 14.3.3 to 15.0.0 by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3981">https://github.com/sipyourdrink-ltd/bernstein/pull/3981</a></li>
<li>chore(deps): bump websockets from 16.0 to 17.0.1 by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3980">https://github.com/sipyourdrink-ltd/bernstein/pull/3980</a></li>
<li>chore(deps): bump datasets from 4.8.5 to 5.0.1 by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3985">https://github.com/sipyourdrink-ltd/bernstein/pull/3985</a></li>
<li>chore(deps): bump kubernetes from 35.0.0 to 36.0.3 by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3986">https://github.com/sipyourdrink-ltd/bernstein/pull/3986</a></li>
<li>chore(deps): bump cbor2 from 5.9.0 to 6.1.4 by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3984">https://github.com/sipyourdrink-ltd/bernstein/pull/3984</a></li>
<li>chore(deps): bump signxml from 4.4.0 to 5.1.0 by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3987">https://github.com/sipyourdrink-ltd/bernstein/pull/3987</a></li>
<li>fix(cli): declare the replay publish confirmation flag and make &ndash;as-json truthful by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3991">https://github.com/sipyourdrink-ltd/bernstein/pull/3991</a></li>
<li>docs(readme): add Hindi and Bengali translations by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3992">https://github.com/sipyourdrink-ltd/bernstein/pull/3992</a></li>
<li>chore(deps-dev): bump types-reportlab from 4.5.1.20260724 to 4.5.1.20260807 by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3988">https://github.com/sipyourdrink-ltd/bernstein/pull/3988</a></li>
<li>ci: path-gate install-smoke-rpm and add its nightly safety net by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3965">https://github.com/sipyourdrink-ltd/bernstein/pull/3965</a></li>
<li>test(audit): raise audit_log&rsquo;s mutation-gate kill rate to 98.8% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4007">https://github.com/sipyourdrink-ltd/bernstein/pull/4007</a></li>
<li>fix(replay): a journal line that is not valid UTF-8 is discarded, not raised (#3971) by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4008">https://github.com/sipyourdrink-ltd/bernstein/pull/4008</a></li>
<li>fix: unblock the grouped dependency bump on lint and license review by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3994">https://github.com/sipyourdrink-ltd/bernstein/pull/3994</a></li>
<li>docs(replay): fix the export invocation and split <code>--as-json</code> by what it emits (#3968) by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3989">https://github.com/sipyourdrink-ltd/bernstein/pull/3989</a></li>
<li>fix(security): refuse a persisted credential token_type outside the literal by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4006">https://github.com/sipyourdrink-ltd/bernstein/pull/4006</a></li>
<li>feat(security): enforce allowed_files at the merge acceptance gate by @Aeirx in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4002">https://github.com/sipyourdrink-ltd/bernstein/pull/4002</a></li>
<li>fix(scripts): render workflow locators as posix paths, not OS-native by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4014">https://github.com/sipyourdrink-ltd/bernstein/pull/4014</a></li>
<li>chore(deps): update dependency ovsx to v1.1.1 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4011">https://github.com/sipyourdrink-ltd/bernstein/pull/4011</a></li>
<li>chore(deps): update dependency lucide-react to v1.31.0 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4010">https://github.com/sipyourdrink-ltd/bernstein/pull/4010</a></li>
<li>ci: fix workflow headers and names to match actual behavior by @ThinkerDesigns in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3956">https://github.com/sipyourdrink-ltd/bernstein/pull/3956</a></li>
<li>fix(replay): emit JSON on every exit path, not only the successful one by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4017">https://github.com/sipyourdrink-ltd/bernstein/pull/4017</a></li>
<li>fix(replay): repair a crash-torn journal tail so a suspended task can resume (#3910) by @Louis20060723 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3955">https://github.com/sipyourdrink-ltd/bernstein/pull/3955</a></li>
<li>chore(renovate): cap mkdocs-redirects at the bound docs/requirements.in declares by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4012">https://github.com/sipyourdrink-ltd/bernstein/pull/4012</a></li>
<li>fix(api): refuse a non-finite budget_cap on /metrics/predictions by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4013">https://github.com/sipyourdrink-ltd/bernstein/pull/4013</a></li>
<li>feat(agents): read plugin-layout catalogs and wire configured catalogs into the match path by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3993">https://github.com/sipyourdrink-ltd/bernstein/pull/3993</a></li>
<li>chore(deps): bump the python-minor-and-patch group across 1 directory with 44 updates by @dependabot[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3979">https://github.com/sipyourdrink-ltd/bernstein/pull/3979</a></li>
<li>ci(docs): gate docs/requirements.txt against its own .in constraints by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3999">https://github.com/sipyourdrink-ltd/bernstein/pull/3999</a></li>
<li>fix(security): refuse a merge whose incoming change cannot be read by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4022">https://github.com/sipyourdrink-ltd/bernstein/pull/4022</a></li>
<li>fix(replay): event_count counts usable events, through the same scan (#4016) by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4025">https://github.com/sipyourdrink-ltd/bernstein/pull/4025</a></li>
<li>chore(web): rebuild SPA bundle for lucide-react 1.31.0 by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4027">https://github.com/sipyourdrink-ltd/bernstein/pull/4027</a></li>
<li>refactor(security): derive the token_type allowlist from its Literal by @Aeirx in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4030">https://github.com/sipyourdrink-ltd/bernstein/pull/4030</a></li>
<li>ci: finish the weekly rename for the fuzzing and eval lanes by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3959">https://github.com/sipyourdrink-ltd/bernstein/pull/3959</a></li>
<li>docs(replay): describe the &ndash;as-json contracts that #3991 shipped by @Chirag6722 in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4018">https://github.com/sipyourdrink-ltd/bernstein/pull/4018</a></li>
<li>ci: take the non-required lanes out of the merge queue by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4020">https://github.com/sipyourdrink-ltd/bernstein/pull/4020</a></li>
<li>ci: decide release readiness from check runs, not the combined status API by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4046">https://github.com/sipyourdrink-ltd/bernstein/pull/4046</a></li>
<li>ci: drop the release job&rsquo;s re-run of the suite it has already verified by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4049">https://github.com/sipyourdrink-ltd/bernstein/pull/4049</a></li>
<li>release: v3.16.0 by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4052">https://github.com/sipyourdrink-ltd/bernstein/pull/4052</a></li>
<li>fix(ci): register the protocol marker so the release gate can run at all by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4056">https://github.com/sipyourdrink-ltd/bernstein/pull/4056</a></li>
<li>perf(replay): cache event_count against a stat token, keeping the exact count (#4026) by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4029">https://github.com/sipyourdrink-ltd/bernstein/pull/4029</a></li>
<li>feat(security): derive manifest_sha256 and make its check visible in the verdict by @sujeito-operator in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4048">https://github.com/sipyourdrink-ltd/bernstein/pull/4048</a></li>
<li>test(ci): pin the trigger and cadence headers for two workflows by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4021">https://github.com/sipyourdrink-ltd/bernstein/pull/4021</a></li>
<li>fix(security): let the devops role edit docker-compose.yaml by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4045">https://github.com/sipyourdrink-ltd/bernstein/pull/4045</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@vaibhav8a made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3818">https://github.com/sipyourdrink-ltd/bernstein/pull/3818</a></li>
<li>@jvsilva12600009 made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3848">https://github.com/sipyourdrink-ltd/bernstein/pull/3848</a></li>
<li>@Chirag6722 made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3899">https://github.com/sipyourdrink-ltd/bernstein/pull/3899</a></li>
<li>@sujeito-operator made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3915">https://github.com/sipyourdrink-ltd/bernstein/pull/3915</a></li>
<li>@ShlokShar made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3932">https://github.com/sipyourdrink-ltd/bernstein/pull/3932</a></li>
<li>@Aeirx made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/4002">https://github.com/sipyourdrink-ltd/bernstein/pull/4002</a></li>
<li>@ThinkerDesigns made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3956">https://github.com/sipyourdrink-ltd/bernstein/pull/3956</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sipyourdrink-ltd/bernstein/compare/v3.15.1...v3.16.0">https://github.com/sipyourdrink-ltd/bernstein/compare/v3.15.1...v3.16.0</a></p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/smyklot/</link><pubDate>Mon, 17 Aug 2026 13:43:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.34.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository’s CODEOWNERS file. It handles comments with various formats, including slash commands, mentions, bare commands, and reaction-based commands to manage approval and merge processes efficiently. The app provides options for approving, merging, squashing, rebasing, removing approvals, cleaning up all bot reactions and comments, showing help information, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.34.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository&rsquo;s CODEOWNERS file. It handles comments with various formats, including slash commands, mentions, bare commands, and reaction-based commands to manage approval and merge processes efficiently. The app provides options for approving, merging, squashing, rebasing, removing approvals, cleaning up all bot reactions and comments, showing help information, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1340-2026-08-17"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.33.2...v1.34.0">1.34.0</a> (2026-08-17)</h2>
<h2 id="smyklot-v1340">Smyklot v1.34.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.34.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>ca13cf8bd92b3c51aa2b5a70e8e70509e084acb2 chore(release): bump version to 1.34.0</li>
<li>328955acd3a78c8d92c7395e6e7bf5ca71225fd7 chore(deps): lock file maintenance (#245)</li>
<li>7788316fd8f431d841eb4f4a7bcbe0ef440ea04b fix(storage): refuse two migrations at one version (#244)</li>
<li>ef831b75c354830aa57cdd7b61e6cde2599f9288 feat(panel): the pending CI queue as its own view (#238)</li>
<li>97691e23ebe3aa56d067ca9d8c0ba4bfb6863284 feat(panel): configure the merge-after-CI quiet period (#242)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Mon, 17 Aug 2026 13:42:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The deploy-swarm-service GitHub Action automates the deployment of a Dockerized service to a Swarm cluster. It performs the following tasks: builds and bundles the service using npm, commits the built files (specifically the dist directory), and deploys them to a Swarm cluster. This ensures that the latest version of the service is always running on the swarm nodes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>deploy-swarm-service</code> GitHub Action automates the deployment of a Dockerized service to a Swarm cluster. It performs the following tasks: builds and bundles the service using npm, commits the built files (specifically the <code>dist</code> directory), and deploys them to a Swarm cluster. This ensures that the latest version of the service is always running on the swarm nodes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>Claude Code Marketplace Manager</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/claude-code-marketplace-manager/</link><pubDate>Mon, 17 Aug 2026 13:42:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/claude-code-marketplace-manager/</guid><description>Version updated for https://github.com/spencerbeggs/claude-code-marketplace-manager to version 1.0.4.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action claude-code-marketplace-manager automates the process of updating plugins in a Claude Code marketplace manifest. It supports both manual and automated triggering, allowing users to re-pin plugins directly from their repositories or external sources. The action ensures that only specified changes are made, preserving existing formatting and comments, and signs commits server-side through a GitHub App for verification against branch protection rules.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spencerbeggs/claude-code-marketplace-manager">https://github.com/spencerbeggs/claude-code-marketplace-manager</a></strong> to version <strong>1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/claude-code-marketplace-manager">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>claude-code-marketplace-manager</code> automates the process of updating plugins in a Claude Code marketplace manifest. It supports both manual and automated triggering, allowing users to re-pin plugins directly from their repositories or external sources. The action ensures that only specified changes are made, preserving existing formatting and comments, and signs commits server-side through a GitHub App for verification against branch protection rules.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="maintenance">Maintenance</h3>
<ul>
<li>Adopts <code>effect@rc.109</code></li>
</ul>
<h3 id="patch-changes">Patch Changes</h3>
<p>Thanks to <a href="https://github.com/spencerbeggs">@spencerbeggs</a> for their contributions!</p>
<blockquote>
<p>This is a version-only release. No packages were published to a registry.</p>
</blockquote>
]]></content:encoded></item><item><title>GitHub Stats Cards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/github-stats-cards/</link><pubDate>Mon, 17 Aug 2026 13:41:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/github-stats-cards/</guid><description>Version updated for https://github.com/stn1slv/github-stats-cards to version v1.2.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates beautiful, high-quality SVG statistics cards for your GitHub profile README using Python. It automates the process of updating and displaying various metrics such as stars, commits, pull requests, issues, reviews, and contribution data. Key capabilities include 50+ themes, smart weighting for language stats, and local generation without external service dependencies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stn1slv/github-stats-cards">https://github.com/stn1slv/github-stats-cards</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-stats-cards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates beautiful, high-quality SVG statistics cards for your GitHub profile README using Python. It automates the process of updating and displaying various metrics such as stars, commits, pull requests, issues, reviews, and contribution data. Key capabilities include 50+ themes, smart weighting for language stats, and local generation without external service dependencies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<blockquote>
<p>[!WARNING]
<strong>v1.2.0 is broken and should not be used.</strong> It produced no card at all, and did so silently. If you pinned <code>@v1.2.0</code>, move to <code>@v1.2.1</code>.</p>
</blockquote>
<h2 id="what-went-wrong-in-120">What went wrong in 1.2.0</h2>
<p>1.2.0 set out to fix a real bug: the action checked out its own repository with no <code>ref</code>, so a pinned tag ran whatever was on <code>main</code>. The fix used <code>${{ github.action_repository }}</code> and <code>${{ github.action_ref }}</code>.</p>
<p>Inside a composite action those contexts resolve to the <strong>innermost</strong> action, not the outer one. So the step checked out <code>actions/checkout@v4</code> into the install directory, then exited without installing the CLI or generating anything.</p>
<p>The failure was invisible. Workflows using <code>continue-on-error: true</code> on their card steps, which is the pattern in this project&rsquo;s own example workflow, went green while quietly regenerating nothing. The only symptom was images that stopped updating.</p>
<h2 id="the-fix">The fix</h2>
<p>The action no longer checks itself out. It installs from <code>$GITHUB_ACTION_PATH</code>, where the runner has already placed this repository at exactly the ref the caller pinned:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">run</span>: <span style="color:#ae81ff">uv pip install --system -e &#34;$GITHUB_ACTION_PATH&#34;</span>
</span></span></code></pre></div><p>This removes the class of problem rather than patching an instance of it: there is no second resolution step left that can disagree with the pin. A test now rejects any self-checkout returning, under any spelling.</p>
<h2 id="who-is-affected">Who is affected</h2>
<table>
  <thead>
      <tr>
          <th>Version pinned</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>@v1.2.0</code></td>
          <td><strong>Broken.</strong> No cards generated, no error reported. Move to <code>@v1.2.1</code>.</td>
      </tr>
      <tr>
          <td><code>@v1.2.1</code></td>
          <td>Correct, and the first release where your pin is genuinely honoured.</td>
      </tr>
      <tr>
          <td><code>@v1.1.10</code> and earlier</td>
          <td>Unaffected by this bug, but they still ignore the pin and run <code>main</code>.</td>
      </tr>
  </tbody>
</table>
<p>Everything else in <a href="https://github.com/stn1slv/github-stats-cards/releases/tag/v1.2.0">v1.2.0</a> is unchanged and still applies.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/stn1slv/github-stats-cards/compare/v1.2.0...v1.2.1">https://github.com/stn1slv/github-stats-cards/compare/v1.2.0...v1.2.1</a></p>
]]></content:encoded></item><item><title>RepoGuardAI Security Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/repoguardai-security-audit/</link><pubDate>Mon, 17 Aug 2026 13:40:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/repoguardai-security-audit/</guid><description>Version updated for https://github.com/SUDARSHANCHAUDHARI/RepoGuardAI to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RepoGuardAI is a tool-independent repository auditing framework that guides AI coding agents through repeatable, evidence-driven security and code audits. It inspects repositories, runs local scanners plus its own deterministic scanners to generate precise instructions, ensuring consistent and auditable processes regardless of the agent used.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SUDARSHANCHAUDHARI/RepoGuardAI">https://github.com/SUDARSHANCHAUDHARI/RepoGuardAI</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repoguardai-security-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RepoGuardAI is a tool-independent repository auditing framework that guides AI coding agents through repeatable, evidence-driven security and code audits. It inspects repositories, runs local scanners plus its own deterministic scanners to generate precise instructions, ensuring consistent and auditable processes regardless of the agent used.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First tagged release of RepoGuardAI — a tool-independent repository audit framework, packaged as a GitHub Action.</p>
<h2 id="github-action-usage">GitHub Action usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">SUDARSHANCHAUDHARI/RepoGuardAI@v0.1.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">target</span>: <span style="color:#ae81ff">.</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">scope</span>: <span style="color:#ae81ff">security</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><ul>
<li>Runtime: Node 24 action (<code>action-dist/action.js</code>)</li>
<li>Inputs: <code>target</code>, <code>scope</code> (full|security|api), <code>fail-on</code></li>
<li>Outputs: <code>report-directory</code>, <code>json-report</code>, <code>sarif-report</code> (SARIF 2.1.0)</li>
<li>Deterministic-first: scanning + report assembly are deterministic; a coding agent does the reasoning. No AI provider baked in.</li>
</ul>
<p>See the README and docs/github-actions.md for permissions, private callers, and version pinning.</p>
]]></content:encoded></item><item><title>NuGet dependency graph</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/nuget-dependency-graph/</link><pubDate>Mon, 17 Aug 2026 13:39:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/nuget-dependency-graph/</guid><description>Version updated for https://github.com/Tsabo/nugraph-action to version v2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the generation of NuGet dependency graphs from .NET solutions or projects using the 0xced/nugraph tool. It supports generating job summaries with Mermaid diagrams and outputs the graph in various formats, including SVG, PNG, PDF, and JPEG images. The action can handle both single project paths and solution files by parsing the solution to include all referenced projects in the graph generation process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tsabo/nugraph-action">https://github.com/Tsabo/nugraph-action</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nuget-dependency-graph">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the generation of NuGet dependency graphs from .NET solutions or projects using the <code>0xced/nugraph</code> tool. It supports generating job summaries with Mermaid diagrams and outputs the graph in various formats, including SVG, PNG, PDF, and JPEG images. The action can handle both single project paths and solution files by parsing the solution to include all referenced projects in the graph generation process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Upgrades the action&rsquo;s dependencies to their latest majors, all of which now run on the Node.js 24 runtime. This clears the &ldquo;Node.js 20 is deprecated&rdquo; annotation warning that GitHub Actions raises for <code>actions/checkout@v4</code>, <code>actions/setup-dotnet@v4</code>, and <code>actions/upload-artifact@v4</code>.</p>
<h2 id="changes">Changes</h2>
<ul>
<li><code>actions/setup-dotnet</code> bumped to <code>v6</code> in the composite action itself — every consumer of <code>nugraph-action</code> picks this up automatically, no workflow changes required</li>
<li><code>actions/checkout</code> and <code>actions/upload-artifact</code> bumped to <code>v7</code> in the example workflows and README</li>
</ul>
<p>No inputs, outputs, or behavior changed. Tagged as a major version out of caution for the internal <code>setup-dotnet</code> bump, but existing <code>@v1</code> usages are unaffected — this only lands for consumers pinned to <code>@v2</code> or <code>@master</code>.</p>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Tsabo/nugraph-action@v2</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">project-path</span>: <span style="color:#ae81ff">./src/MyApp.sln</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>darnlink — self-healing Markdown links</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/darnlink-self-healing-markdown-links/</link><pubDate>Mon, 17 Aug 2026 13:38:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/darnlink-self-healing-markdown-links/</guid><description>Version updated for https://github.com/txemi/darnlink to version v0.24.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The darnlink GitHub Action automatically fixes broken links in Markdown files by repairing the paths of existing links or creating new ones with UUIDs if the targets have none. It supports cross-repo web links and is built to handle large trees of Markdown files efficiently. Users can use it directly from a repository without installation, making it easy to maintain documentation that evolves over time.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/txemi/darnlink">https://github.com/txemi/darnlink</a></strong> to version <strong>v0.24.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/darnlink-self-healing-markdown-links">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>darnlink</code> GitHub Action automatically fixes broken links in Markdown files by repairing the paths of existing links or creating new ones with UUIDs if the targets have none. It supports cross-repo web links and is built to handle large trees of Markdown files efficiently. Users can use it directly from a repository without installation, making it easy to maintain documentation that evolves over time.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>D1-D3 of the v0.24.0 block. Five PRs, each with its own adversarial review round (Copilot out of
quota for all of them — REGLA CERO). Every fix in this release verified with <code>git tag --contains</code>
before writing the notes — the exact check that was missing when <code>v0.22.0</code> credited two fixes it
didn&rsquo;t actually ship.</p>
<h2 id="what-a-consumer-sees">What a consumer sees</h2>
<p><strong>1. A dry-run&rsquo;s <code>+uuid X</code> no longer shows a value you can copy.</strong> A freshly-minted uuid (no
existing frontmatter) now reads <code>+uuid &lt;will be generated on write&gt;</code>; a reused uuid is unaffected.
<code>--write</code> still writes the real, correct, matching uuid.</p>
<p><strong>2. <code>check --json</code>&rsquo;s output comes from ONE tree read instead of two.</strong> Byte-for-byte identical to
<code>v0.23.0</code> — verified, not assumed, with two side-by-side worktrees — only faster (~2.1× measured on
a large repo in the fleet).</p>
<p>Nothing else changes behaviour for a consumer.</p>
<h2 id="fixed">Fixed</h2>
<ul>
<li>
<p><strong>An anchor comment no longer separates a link from its pandoc attribute block</strong> (#65). Plus a
follow-up hardening found by adversarial review: a <code>}</code> inside a <em>quoted</em> attribute value was
cutting the match short, and on <code>--write</code> that spliced the anchor comment into the attribute text
itself — worse than #65&rsquo;s own bug. A second, independently-drifted copy of the same regex (in
<code>ROBUST_LINK_RE</code>) was silently making <code>repair</code> report zero findings for an already-anchored link
whose target had moved; both now share one pattern.</p>
</li>
<li>
<p><strong>A trailing space in a link&rsquo;s destination no longer turns a file link into an unhealable
CONFLICT</strong> (#67). Fixed at the one shared primitive; <code>resolve_href</code> stays untouched on purpose
(the general whitespace question is <code>#74</code>&rsquo;s), so the side effect is the stray space gets cleaned
up when the link heals, not just stop being misdiagnosed.</p>
</li>
<li>
<p><strong>A freshly-minted dry-run uuid is no longer printed as if it were final</strong> (#41). Also covers
<code>--create-readme</code>&rsquo;s own uuid-minting path, found by adversarial review as a second route to the
same symptom.</p>
</li>
<li>
<p><strong><code>check</code> runs both its axes off ONE tree read instead of two</strong> (#87). <code>plan_repairs</code>/
<code>plan_robustify</code> gain an optional <code>prescanned</code> parameter (<code>None</code> by default — zero change for
every other caller). Adversarial review found <code>--only</code> was silently ignored when combined with
<code>prescanned</code> — a real gap, fixed with dedicated coverage before merge.</p>
</li>
</ul>
<h2 id="security--hardening">Security / hardening</h2>
<ul>
<li><strong><code>write_text_keep_newlines</code> now refuses a symlink path</strong>, as a live assertion. Verified first:
every path reaching this function is already resolved by <code>iter_markdown_files</code>
(<code>Path.resolve(strict=True)</code>), so the check is unreachable in current use — it protects a future
caller that bypasses that resolution, converting a silent alias-write into an immediate crash.</li>
</ul>
<h2 id="known-issues-filed-not-fixed-here">Known issues (filed, not fixed here)</h2>
<ul>
<li><strong>A hardlink to an indexed <code>.md</code> is indexed twice</strong> — same symptom as <code>#85</code>, different mechanism
(<code>Path.resolve()</code> doesn&rsquo;t collapse hardlinks). Verified live with <code>os.link()</code>. <strong>#91</strong>.</li>
</ul>
<h2 id="verified-before-release">Verified before release</h2>
<ul>
<li><code>uv run pytest -q</code> → <strong>427 passed</strong></li>
<li><code>check --json</code>, byte-for-byte identical between <code>v0.23.0</code> and this release on the same tree</li>
<li>Every one of the 5 commits confirmed inside this tag via <code>git tag --contains</code></li>
</ul>
<p>Full detail in <a href="https://github.com/txemi/darnlink/blob/v0.24.0/CHANGELOG.md">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/kover-report-action/</link><pubDate>Mon, 17 Aug 2026 13:36:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.31.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Kover Report Action is a GitHub Action designed to generate and report code coverage from Kover XML reports in Kotlin/Android projects with multi-module support. It automates the process of aggregating coverage data across multiple modules and provides customizable thresholds for module type and name. The action also supports PR integration, tracking coverage history and trends, and exporting coverage outputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v3.1.31</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Kover Report Action is a GitHub Action designed to generate and report code coverage from Kover XML reports in Kotlin/Android projects with multi-module support. It automates the process of aggregating coverage data across multiple modules and provides customizable thresholds for module type and name. The action also supports PR integration, tracking coverage history and trends, and exporting coverage outputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3.1.31: PR #170 - chore(deps): lock file maintenance</p>
]]></content:encoded></item><item><title>Validate Agent Skills</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/validate-agent-skills/</link><pubDate>Mon, 17 Aug 2026 06:04:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/validate-agent-skills/</guid><description>Version updated for https://github.com/mohitagw15856/pm-claude-skills to version v76.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PM Skills is an open-source library of 1099 Agent Skills that provide plain-markdown SKILL.md files to teach AI assistants professional tasks. Each skill bundles the framework, output template, quality checks, and anti-patterns, making it easier for AI assistants to perform tasks accurately at senior professional levels. PM Skills supports Claude, ChatGPT, Gemini, Cursor, Codex, and Hermes Agent, with ready-to-paste exports for other tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mohitagw15856/pm-claude-skills">https://github.com/mohitagw15856/pm-claude-skills</a></strong> to version <strong>v76.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/validate-agent-skills">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PM Skills is an open-source library of 1099 Agent Skills that provide plain-markdown SKILL.md files to teach AI assistants professional tasks. Each skill bundles the framework, output template, quality checks, and anti-patterns, making it easier for AI assistants to perform tasks accurately at senior professional levels. PM Skills supports Claude, ChatGPT, Gemini, Cursor, Codex, and Hermes Agent, with ready-to-paste exports for other tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>The SKILL.md validator that keeps these 1,099 skills honest now runs against yours — as a GitHub Action.</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">mohitagw15856/pm-claude-skills@v76</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">path</span>: <span style="color:#ae81ff">.claude/skills  </span> <span style="color:#75715e"># optional — it finds them otherwise</span>
</span></span></code></pre></div><p>Or without CI: <code>npx pm-claude-skills skillcheck</code></p>
<hr>
<h2 id="what-it-checks">What it checks</h2>
<p>Skill authoring is new enough that the mistakes are the same handful, and every one is cheap to catch:</p>
<ul>
<li><strong>Frontmatter</strong> — present, well-formed, and a <code>name</code> that matches its folder</li>
<li><strong>The <code>Use when …</code> trigger clause</strong> — the highest-value line in a skill, because it&rsquo;s what a model matches on when deciding whether the skill applies at all</li>
<li><strong>Leftover template text</strong> — <code>your-skill-name</code>, <code>[Instructions for Claude to follow</code></li>
<li><strong>Structure</strong> — a <code># Title</code>, Quality Checks, Anti-Patterns</li>
<li><strong>Length</strong> — too short to trigger on, or too long for the trigger budget</li>
</ul>
<p>Errors fail the build. Warnings are style advice and don&rsquo;t, unless you pass <code>--strict</code>.</p>
<h2 id="findings-land-on-the-line">Findings land on the line</h2>
<p>The reason to use an action rather than a shell step is annotation. Each finding carries a real line number and appears <strong>inline on the pull request diff</strong>:</p>
<pre tabindex="0"><code>::error file=skills/name-mismatch/SKILL.md,line=2,title=SkillCheck::Frontmatter name &#34;totally-different&#34; does not match folder &#34;name-mismatch&#34;.
</code></pre><p><code>errors</code>, <code>warnings</code> and <code>skills</code> are exposed as step outputs, populated <strong>even when the check fails</strong> — so you can comment on a PR or gate a later step on the numbers.</p>
<h2 id="one-implementation-including-for-this-repo">One implementation, including for this repo</h2>
<p><code>scripts/skillcheck.mjs</code> is now a thin wrapper around the published <code>bin/skillcheck.mjs</code>, so this library is validated by exactly the same rules yours is. A linter that exempts itself isn&rsquo;t worth much.</p>
<h2 id="also-in-this-release">Also in this release</h2>
<ul>
<li><strong><code>design-system-generate</code></strong> — skill #1099, for the gap between <em>audit the system we have</em> and <em>extract the brand we have</em>: there is no system and something ships on Thursday.</li>
<li><strong><code>/design-review</code></strong> — a workflow recipe that critiques first, then measures. It closes on the split that makes findings schedulable: <em>&ldquo;nine are a find-and-replace, three need a design decision&rdquo;</em>.</li>
<li><strong>The design skills compute their contrast numbers</strong> instead of estimating them. <code>#777777</code> on white is 4.478 and fails AA; <code>#767676</code> is 4.542 and passes, and no amount of looking at a screenshot separates those. Six skills plus <code>brand-guidelines</code> call <a href="https://github.com/mohitagw15856/notugly">notugly</a>; the MCP server exposes <code>check_contrast</code> as an eighth tool.</li>
<li><strong>Generated persona faces</strong> on the playground chips and the starter-pack banner.</li>
</ul>
<h2 id="fixed-since-v7620">Fixed since v76.2.0</h2>
<ul>
<li>The Marketplace caps an action description at 125 characters and this one was 152. The folded YAML form counts the joined string, so wrapping it changed nothing — it had to actually be shorter.</li>
<li><code>npm-publish</code> now skips a version already on npm instead of failing with <code>E403</code>, which turned the last release red for no good reason.</li>
</ul>
<hr>
<p>Zero dependencies. No Docker image. No model call. MIT.</p>
]]></content:encoded></item><item><title>Motoish CalVer Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/motoish-calver-release/</link><pubDate>Mon, 17 Aug 2026 06:03:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/motoish-calver-release/</guid><description>Version updated for https://github.com/motoish/calver-release-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The CalVer Release Action automates the process of publishing immutable daily builds, maintaining a daily prerelease channel, and promoting an explicitly selected build to a monthly stable release. It provides capabilities for creating CalVer formatted tags based on UTC or IANA timezones, handling fast-forwarding in the daily channel without backward movement, and ensuring that promotions only occur from published immutable pre-releases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/motoish/calver-release-action">https://github.com/motoish/calver-release-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/motoish-calver-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The CalVer Release Action automates the process of publishing immutable daily builds, maintaining a daily prerelease channel, and promoting an explicitly selected build to a monthly stable release. It provides capabilities for creating CalVer formatted tags based on UTC or IANA timezones, handling fast-forwarding in the daily channel without backward movement, and ensuring that promotions only occur from published immutable pre-releases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial stable release of Motoish CalVer Release Action.</p>
<p>Features:</p>
<ul>
<li>Publish immutable daily CalVer build releases.</li>
<li>Maintain a daily prerelease channel.</li>
<li>Promote an explicitly selected immutable build to a monthly stable release.</li>
<li>Support UTC by default with configurable IANA timezones.</li>
<li>Preserve release assets for the calling workflow to manage.</li>
</ul>
]]></content:encoded></item><item><title>agent-bom Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/agent-bom-scan/</link><pubDate>Mon, 17 Aug 2026 06:02:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/agent-bom-scan/</guid><description>Version updated for https://github.com/msaad00/agent-bom to version v0.101.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automates the process of scanning and normalizing evidence from various sources, including repositories, developer endpoints, images, Kubernetes clusters, cloud platforms, data platforms, MCP servers, and runtime activities. It generates findings, SARIF files, SBOMs, HTML reports, and graph exports without requiring an account, facilitating centralization when needed, and providing context for prioritized investigation and action through follow-up paths, impacts, owners, fixes, and verifications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaad00/agent-bom">https://github.com/msaad00/agent-bom</a></strong> to version <strong>v0.101.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-bom-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action automates the process of scanning and normalizing evidence from various sources, including repositories, developer endpoints, images, Kubernetes clusters, cloud platforms, data platforms, MCP servers, and runtime activities. It generates findings, SARIF files, SBOMs, HTML reports, and graph exports without requiring an account, facilitating centralization when needed, and providing context for prioritized investigation and action through follow-up paths, impacts, owners, fixes, and verifications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(docker-mcp): pin the submission to v0.100.0 by @github-actions[bot] in <a href="https://github.com/msaad00/agent-bom/pull/4784">https://github.com/msaad00/agent-bom/pull/4784</a></li>
<li>ci(smithery): a gate that cannot pass is as dishonest as one that cannot fail by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4786">https://github.com/msaad00/agent-bom/pull/4786</a></li>
<li>ci(demo): a release that does not deploy the demo must not report success by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4787">https://github.com/msaad00/agent-bom/pull/4787</a></li>
<li>fix(release): publish the image every surface already tells users to pull by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4788">https://github.com/msaad00/agent-bom/pull/4788</a></li>
<li>Tighten Overview header, label Findings nav badges, densify Remediation by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4789">https://github.com/msaad00/agent-bom/pull/4789</a></li>
<li>Compliance drill-through + demo hygiene (no leakage, readable) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4791">https://github.com/msaad00/agent-bom/pull/4791</a></li>
<li>Populate and surface finding-level owner and SLA due date by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4792">https://github.com/msaad00/agent-bom/pull/4792</a></li>
<li>Graph node drawer: tabbed + width-adjustable by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4793">https://github.com/msaad00/agent-bom/pull/4793</a></li>
<li>Retire the 2D-canvas graph hairball; large estates render via Sigma, readably by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4794">https://github.com/msaad00/agent-bom/pull/4794</a></li>
<li>CLI parity: campaigns, compliance eval, and attack/exposure paths by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4795">https://github.com/msaad00/agent-bom/pull/4795</a></li>
<li>Unify Investigation lens routes into one graph surface (mesh/context → /graph?lens=) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4796">https://github.com/msaad00/agent-bom/pull/4796</a></li>
<li>chore(deps-dev): bump @testing-library/jest-dom from 7.0.0 to 7.0.1 in /ui by @dependabot[bot] in <a href="https://github.com/msaad00/agent-bom/pull/4797">https://github.com/msaad00/agent-bom/pull/4797</a></li>
<li>chore(deps): forward dashboard pip floor bumps (plotly, pandas) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4800">https://github.com/msaad00/agent-bom/pull/4800</a></li>
<li>Compliance: explain why a control is Not evaluated + next-step CTA by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4803">https://github.com/msaad00/agent-bom/pull/4803</a></li>
<li>#4790 parity round 2: framework/control filter + ticketing/export CLI + triage MCP by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4802">https://github.com/msaad00/agent-bom/pull/4802</a></li>
<li>CWPP: ship Azure/GCP side-scan executors + wire the CLI (live smokes deferred) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4804">https://github.com/msaad00/agent-bom/pull/4804</a></li>
<li>Skills scan: REST API + dashboard page (closes the last #4790 parity gap) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4805">https://github.com/msaad00/agent-bom/pull/4805</a></li>
<li>CWPP Wave 2 (#4158): expose the shipped side-scan executors over API + MCP + UI by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4806">https://github.com/msaad00/agent-bom/pull/4806</a></li>
<li>Prune superseded release-evidence snapshots (v0.86–v0.88) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4807">https://github.com/msaad00/agent-bom/pull/4807</a></li>
<li>fix(evidence): make counts, scope, and public product truth consistent by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4808">https://github.com/msaad00/agent-bom/pull/4808</a></li>
<li>feat(workflow): close the finding-to-verification loop by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4809">https://github.com/msaad00/agent-bom/pull/4809</a></li>
<li>feat(ui): guide the blast-radius journey by persona by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4810">https://github.com/msaad00/agent-bom/pull/4810</a></li>
<li>chore(deps): refresh Python and UI lint tooling by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4813">https://github.com/msaad00/agent-bom/pull/4813</a></li>
<li>Make docker-mcp pin test robust to CI dubious-ownership (post-#4813) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4816">https://github.com/msaad00/agent-bom/pull/4816</a></li>
<li>feat(adoption): measure conversion and lock release proof by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4814">https://github.com/msaad00/agent-bom/pull/4814</a></li>
<li>fix(ci): give Python coverage lane bounded headroom by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4817">https://github.com/msaad00/agent-bom/pull/4817</a></li>
<li>fix(release): enforce exact MCP deployment inventory by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4819">https://github.com/msaad00/agent-bom/pull/4819</a></li>
<li>fix(ci): isolate graph story concurrency contracts by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4821">https://github.com/msaad00/agent-bom/pull/4821</a></li>
<li>fix(release): consolidate policy CWPP and UI hardening by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4822">https://github.com/msaad00/agent-bom/pull/4822</a></li>
<li>fix(scale): make Postgres evidence reproducible by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4823">https://github.com/msaad00/agent-bom/pull/4823</a></li>
<li>feat(storage): expose portable Postgres contract by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4824">https://github.com/msaad00/agent-bom/pull/4824</a></li>
<li>feat(deploy): verify managed Postgres readiness by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4825">https://github.com/msaad00/agent-bom/pull/4825</a></li>
<li>feat(interop): harden portable evidence tables by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4826">https://github.com/msaad00/agent-bom/pull/4826</a></li>
<li>fix(release): require exact-main green CI proof by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4827">https://github.com/msaad00/agent-bom/pull/4827</a></li>
<li>chore(release): prepare 0.101.0 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4828">https://github.com/msaad00/agent-bom/pull/4828</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/msaad00/agent-bom/compare/v0.100.0...v0.101.0">https://github.com/msaad00/agent-bom/compare/v0.100.0...v0.101.0</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/go-proxy-cache-updater/</link><pubDate>Mon, 17 Aug 2026 06:00:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.46.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automatically updates a Go module’s proxy cache when new releases are tagged on GitHub. It supports standard and submodule tags, customizable import paths, and various Go versions via setup-go. The workflow can be triggered by release events and caches Go modules and dependencies for faster builds.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.46</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action automatically updates a Go module&rsquo;s proxy cache when new releases are tagged on GitHub. It supports standard and submodule tags, customizable import paths, and various Go versions via <code>setup-go</code>. The workflow can be triggered by release events and caches Go modules and dependencies for faster builds.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1146-2026-08-17"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.45...v1.1.46">1.1.46</a> (2026-08-17)</h2>
]]></content:encoded></item><item><title>Setup flatc</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/setup-flatc/</link><pubDate>Mon, 17 Aug 2026 05:59:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/setup-flatc/</guid><description>Version updated for https://github.com/Nugine/setup-flatc to version v1.2.5.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs the FlatBuffers compiler (flatc) for use in workflows, allowing users to compile FlatBuffer schema files into C++, Go, and other languages. It supports installing the latest version, a specific version, or a semver range of versions through parameters.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nugine/setup-flatc">https://github.com/Nugine/setup-flatc</a></strong> to version <strong>v1.2.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-flatc">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs the FlatBuffers compiler (flatc) for use in workflows, allowing users to compile FlatBuffer schema files into C++, Go, and other languages. It supports installing the latest version, a specific version, or a semver range of versions through parameters.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Auto Update - 2026-02-01 by @Nugine in <a href="https://github.com/Nugine/setup-flatc/pull/30">https://github.com/Nugine/setup-flatc/pull/30</a></li>
<li>Auto Update - 2026-02-08 by @Nugine in <a href="https://github.com/Nugine/setup-flatc/pull/31">https://github.com/Nugine/setup-flatc/pull/31</a></li>
<li>Auto Update - 2026-03-01 by @Nugine in <a href="https://github.com/Nugine/setup-flatc/pull/32">https://github.com/Nugine/setup-flatc/pull/32</a></li>
<li>Auto Update - 2026-04-01 by @Nugine in <a href="https://github.com/Nugine/setup-flatc/pull/33">https://github.com/Nugine/setup-flatc/pull/33</a></li>
<li>Auto Update - 2026-06-01 by @Nugine in <a href="https://github.com/Nugine/setup-flatc/pull/34">https://github.com/Nugine/setup-flatc/pull/34</a></li>
<li>build(deps): bump actions/checkout from 6 to 7 in the actions group by @dependabot[bot] in <a href="https://github.com/Nugine/setup-flatc/pull/36">https://github.com/Nugine/setup-flatc/pull/36</a></li>
<li>Auto Update - 2026-08-01 by @Nugine in <a href="https://github.com/Nugine/setup-flatc/pull/35">https://github.com/Nugine/setup-flatc/pull/35</a></li>
<li>ci: enable dependabot for deno and make bundle reproducible by @Nugine in <a href="https://github.com/Nugine/setup-flatc/pull/37">https://github.com/Nugine/setup-flatc/pull/37</a></li>
<li>build(deps): upgrade dependencies by @Nugine in <a href="https://github.com/Nugine/setup-flatc/pull/39">https://github.com/Nugine/setup-flatc/pull/39</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Nugine/setup-flatc/compare/v1.2.4...v1.2.5">https://github.com/Nugine/setup-flatc/compare/v1.2.4...v1.2.5</a></p>
]]></content:encoded></item><item><title>Otzaria Plugin Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/otzaria-plugin-validator/</link><pubDate>Mon, 17 Aug 2026 05:59:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/otzaria-plugin-validator/</guid><description>Version updated for https://github.com/Otzaria/otzaria-plugin-validator to version v1.12.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation, building, and publishing of Otzaria plugins to their store, ensuring that only valid updates are pushed to the main branch. It requires two secrets (OTZARIA_USER and OTZARIA_PASSWORD) in GitHub Actions settings. The action supports both automatic publication on push to the main branch and manual validation for pull requests, with customizable inputs such as app version, API reference URL, and build options.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Otzaria/otzaria-plugin-validator">https://github.com/Otzaria/otzaria-plugin-validator</a></strong> to version <strong>v1.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/otzaria-plugin-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation, building, and publishing of Otzaria plugins to their store, ensuring that only valid updates are pushed to the main branch. It requires two secrets (OTZARIA_USER and OTZARIA_PASSWORD) in GitHub Actions settings. The action supports both automatic publication on push to the main branch and manual validation for pull requests, with customizable inputs such as app version, API reference URL, and build options.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Otzaria/otzaria-plugin-validator/compare/v1.11.1...v1.12.0">https://github.com/Otzaria/otzaria-plugin-validator/compare/v1.11.1...v1.12.0</a></p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/skilltotal-ai-component-security-scan/</link><pubDate>Mon, 17 Aug 2026 05:57:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.39.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SkillTotal is a static analysis tool that identifies potential security risks in AI-related components and projects. It scans files locally without running them on the machine, providing evidence-based findings such as file locations and code snippets. SkillTotal is designed to be 100% offline and safe for untrusted components, offering a determinate and standards-aligned approach to detecting supply-chain risks and capabilities before installation or trust.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.39.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SkillTotal is a static analysis tool that identifies potential security risks in AI-related components and projects. It scans files locally without running them on the machine, providing evidence-based findings such as file locations and code snippets. SkillTotal is designed to be 100% offline and safe for untrusted components, offering a determinate and standards-aligned approach to detecting supply-chain risks and capabilities before installation or trust.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>False negative: published packages were scanned without their code (ruleset 43).</strong> <code>dist/</code> and
<code>build/</code> are skipped for a repository, where they duplicate first-party source checked in beside
them. A published npm tarball is the mirror image — <code>.npmignore</code>/<code>files</code> keep the sources out and
ship only the build output — so those scans covered nothing but the manifest and the README and
reported &ldquo;no findings&rdquo;. Measured across the public MCP registry, 11 of 12 sampled npm packages
that reported zero findings were in fact shipping shell execution, network egress or filesystem
access. Build output is now scanned for package artifacts (<code>npm_package</code>, <code>python_package</code>) and
still skipped for git/local sources.</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li><strong>Build output establishes capability, never risk.</strong> A bundle inlines dependencies, tests and
templates into one file, blinding the path-based demotion layers, so a <code>risky_construct</code> or
<code>malicious_indicator</code> match found in build output is demoted to needs_review while capability
findings are kept. Without this, real packages were rated <code>critical</code> from a security tool&rsquo;s own
credential-path watch list and from a bundled SSRF test assertion.</li>
<li><strong>Minified bundles are disclosed, not scanned.</strong> A bundled script is one very long line, so a
finding in it could not carry the checkable file/line evidence every confirmed finding must have,
and its inlined dependencies are not the component&rsquo;s own code. Such files are now reported as a
<code>coverage</code> <strong>needs_review</strong> entry (&ldquo;Minified bundle not analyzed&rdquo;) listing the paths — visible
rather than silently absent, and without affecting the score.</li>
</ul>
]]></content:encoded></item><item><title>Multi-Style Contribution Snake</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/multi-style-contribution-snake/</link><pubDate>Mon, 17 Aug 2026 05:56:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/multi-style-contribution-snake/</guid><description>Version updated for https://github.com/Pro-Bandey/multi-style-snake-contribution-grid to version v17.08.26.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates multiple snake styles for a GitHub contribution graph, providing five unique shapes (Squares, Rounds, Triangles, Stars, Diamonds), auto-detects the repository owner, and displays month labels. It automates the process of generating a dynamic animation and includes features like automated generation of a gallery in README.md.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Pro-Bandey/multi-style-snake-contribution-grid">https://github.com/Pro-Bandey/multi-style-snake-contribution-grid</a></strong> to version <strong>v17.08.26</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/multi-style-contribution-snake">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates multiple snake styles for a GitHub contribution graph, providing five unique shapes (Squares, Rounds, Triangles, Stars, Diamonds), auto-detects the repository owner, and displays month labels. It automates the process of generating a dynamic animation and includes features like automated generation of a gallery in <code>README.md</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-multi-style-snake-daily-update">🐍 Multi-Style Snake Daily Update</h2>
<p>Automated daily release to the GitHub Marketplace.</p>
<p><strong>Version Details:</strong></p>
<ul>
<li><strong>Tag:</strong> <code>v17.08.26</code></li>
<li><strong>Release Date:</strong> $(date +&rsquo;%A, %B %d, 20%y')</li>
</ul>
<p><strong>Included Features:</strong></p>
<ul>
<li>5 Unique Snake Styles (Blocks, Rounds, Triangles, Stars, Diamonds)</li>
<li>Automated Month Labels above grids</li>
<li>Dynamic Username Detection</li>
<li>Auto-generated Asset Gallery</li>
</ul>
]]></content:encoded></item><item><title>Advisory lock service for CI/CD pipelines</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/advisory-lock-service-for-ci/cd-pipelines/</link><pubDate>Mon, 17 Aug 2026 05:55:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/advisory-lock-service-for-ci/cd-pipelines/</guid><description>Version updated for https://github.com/releasetools/mutex to version v1.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action helps manage shared resources by using an advisory lock in a PostgreSQL table. It allows one CI job at a time to access a shared resource, ensuring that no two jobs can interfere with each other. The action provides options for specifying the lock ID, reason, owner, expiration, wait period, and auto-release settings, and it supports commenting on GitHub pull requests and posting to Slack if configured.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/releasetools/mutex">https://github.com/releasetools/mutex</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/advisory-lock-service-for-ci-cd-pipelines">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action helps manage shared resources by using an advisory lock in a PostgreSQL table. It allows one CI job at a time to access a shared resource, ensuring that no two jobs can interfere with each other. The action provides options for specifying the lock ID, reason, owner, expiration, wait period, and auto-release settings, and it supports commenting on GitHub pull requests and posting to Slack if configured.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<blockquote>
<p><strong><code>DATABASE_URL</code> is no longer read.</strong> Any workflow or shell still passing it
fails with <code>MUTEX_DATABASE_URL not found</code> until it is renamed:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">MUTEX_DATABASE_URL</span>: <span style="color:#ae81ff">${{ secrets.DATABASE_URL }}</span> <span style="color:#75715e"># was DATABASE_URL:</span>
</span></span></code></pre></div><p>1.2.2 read both and warned when the old name was used; that warning names the
variable to set. The Action&rsquo;s <code>DATABASE_URL</code> input is gone with it.</p>
</blockquote>
<ul>
<li>Removed <code>DATABASE_URL</code>. <code>MUTEX_DATABASE_URL</code> is the only name mutex reads, in the Action and the CLI, so a lock can no longer land in whatever database something else set that name to.</li>
<li>Added explicit direct and server profiles, including a background TCP server that keeps PostgreSQL connections warm for faster CLI lock operations, a systemd template, and a rootless per-user macOS LaunchAgent.</li>
<li>Running <code>mutex</code> without arguments now prints the general help instead of returning a usage error.</li>
<li><code>mutex server status</code> and <code>mutex server stop</code> now identify a missing profiles file instead of claiming the implicit direct connection is a configured profile.</li>
<li>Published the CLI as the public <code>@releasetools/mutex</code> package with provenance, so npm and mise can install it without cloning the repository.</li>
<li>The npm package description now explains how its Postgres-backed TTL locks coordinate the GitHub Action and CLI.</li>
<li>Renamed the release artifact command to <code>npm run package:release</code>, reflecting that it assembles both the GitHub Action and npm CLI package.</li>
<li>Added <code>npm run cli:link</code> for building and linking a checkout and <code>npm run check</code> for formatting, building, and testing it locally.</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/kaniko-build-action/</link><pubDate>Mon, 17 Aug 2026 05:54:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a custom greeting message to the log, and optionally provides the current time. It is useful for automating simple greetings in workflows.
What’s Changed Full Changelog: https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a custom greeting message to the log, and optionally provides the current time. It is useful for automating simple greetings in workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>KeyHog Secret Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/keyhog-secret-scanner/</link><pubDate>Mon, 17 Aug 2026 05:54:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/keyhog-secret-scanner/</guid><description>Version updated for https://github.com/santhreal/keyhog to version v0.5.78.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary KeyHog is an open-source secret scanner in Rust that finds and verifies leaked API keys, tokens, passwords, and credentials across various sources such as source code, Git history, containers, cloud storage, browser assets, collaboration content, and running systems. It combines 926 service-specific detectors, decode-through for concealed credentials, context-aware evidence and suppression, live provider verification, and first-class CUDA, Metal, and WGPU execution through Vyre.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/santhreal/keyhog">https://github.com/santhreal/keyhog</a></strong> to version <strong>v0.5.78</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/keyhog-secret-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>KeyHog is an open-source secret scanner in Rust that finds and verifies leaked API keys, tokens, passwords, and credentials across various sources such as source code, Git history, containers, cloud storage, browser assets, collaboration content, and running systems. It combines 926 service-specific detectors, decode-through for concealed credentials, context-aware evidence and suppression, live provider verification, and first-class CUDA, Metal, and WGPU execution through Vyre.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>fix(scanner): gate expand_triggered_patterns independently of decode feature.</li>
</ul>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/agentauditkit-mcp-security-scan/</link><pubDate>Mon, 17 Aug 2026 05:53:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.80.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner designed to detect misconfigurations, hardcoded secrets, tool poisoning, and other vulnerabilities in AI agent pipelines. It runs offline and deterministically, ensuring that the same input always yields the same findings. Additionally, it produces auditor-ready compliance-evidence packs, including SARIF for GitHub Security tab and PDF reports mapped to multiple security frameworks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.80</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit is a security scanner designed to detect misconfigurations, hardcoded secrets, tool poisoning, and other vulnerabilities in AI agent pipelines. It runs offline and deterministically, ensuring that the same input always yields the same findings. Additionally, it produces auditor-ready compliance-evidence packs, including SARIF for GitHub Security tab and PDF reports mapped to multiple security frameworks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.80
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.80
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.80</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Detect unauthenticated MCP sidecar dashboards, and stop reading double quotes as a shell mitigation by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/606">https://github.com/sattyamjjain/agent-audit-kit/pull/606</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.79...v0.3.80">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.79...v0.3.80</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/sherpa.sh/</link><pubDate>Mon, 17 Aug 2026 05:51:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI tool that automatically configures and deploys infrastructure for developers. It simplifies the process of setting up cloud resources using plain English prompts, making it easy to deploy applications across various cloud providers such as AWS, Google Cloud, and more. The action supports features like specifying resources, custom domains, load balancing, CDN configuration, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI tool that automatically configures and deploys infrastructure for developers. It simplifies the process of setting up cloud resources using plain English prompts, making it easy to deploy applications across various cloud providers such as AWS, Google Cloud, and more. The action supports features like specifying resources, custom domains, load balancing, CDN configuration, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>greenbump</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/greenbump/</link><pubDate>Mon, 17 Aug 2026 05:50:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/greenbump/</guid><description>Version updated for https://github.com/shidesheng0218/greenbump to version v0.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary greenbump is a dependency upgrade tool that automatically fixes breaking changes in code when upgrading dependencies. It uses an AI agent to repair errors, looping until the build and tests pass. Key features include AI-powered code fixing, multi-layer verification, sandbox isolation, multi-ecosystem support, and safe by default practices.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shidesheng0218/greenbump">https://github.com/shidesheng0218/greenbump</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/greenbump">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>greenbump</code> is a dependency upgrade tool that automatically fixes breaking changes in code when upgrading dependencies. It uses an AI agent to repair errors, looping until the build and tests pass. Key features include AI-powered code fixing, multi-layer verification, sandbox isolation, multi-ecosystem support, and safe by default practices.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>See <a href="https://github.com/shidesheng0218/greenbump/blob/master/CHANGELOG.md">CHANGELOG.md</a> for details.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/shidesheng0218/greenbump/compare/v0.4.0...v0.5.0">https://github.com/shidesheng0218/greenbump/compare/v0.4.0...v0.5.0</a></p>
]]></content:encoded></item><item><title>agent-trace eval</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/agent-trace-eval/</link><pubDate>Mon, 17 Aug 2026 05:49:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/agent-trace-eval/</guid><description>Version updated for https://github.com/Siddhant-K-code/agent-trace to version v0.93.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The agent-trace action captures and records AI agent sessions, providing detailed information about what files were read, tool calls made, changes and failures during execution. It enables replaying these sessions later, facilitating inspection of the agent’s behavior and debugging issues after a pull request is merged. The action supports exporting data to various observability platforms like Datadog, Honeycomb, New Relic, or Splunk for monitoring purposes and includes features to set rules to control the agent’s execution, such as cost limits and file access restrictions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Siddhant-K-code/agent-trace">https://github.com/Siddhant-K-code/agent-trace</a></strong> to version <strong>v0.93.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-trace-eval">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>agent-trace</code> action captures and records AI agent sessions, providing detailed information about what files were read, tool calls made, changes and failures during execution. It enables replaying these sessions later, facilitating inspection of the agent&rsquo;s behavior and debugging issues after a pull request is merged. The action supports exporting data to various observability platforms like Datadog, Honeycomb, New Relic, or Splunk for monitoring purposes and includes features to set rules to control the agent&rsquo;s execution, such as cost limits and file access restrictions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add assignment submission scoring (#235)</li>
</ul>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/smyklot/</link><pubDate>Mon, 17 Aug 2026 05:48:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.33.2.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository’s CODEOWNERS file. It supports multiple command formats, including slash commands, mentions, and bare commands, and allows for flexible configuration via TOML files or environment variables. The app ensures only repository owners can approve or merge PRs, providing a streamlined workflow for managing pull requests based on ownership.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.33.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository&rsquo;s CODEOWNERS file. It supports multiple command formats, including slash commands, mentions, and bare commands, and allows for flexible configuration via TOML files or environment variables. The app ensures only repository owners can approve or merge PRs, providing a streamlined workflow for managing pull requests based on ownership.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1332-2026-08-16"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.33.1...v1.33.2">1.33.2</a> (2026-08-16)</h2>
<h2 id="smyklot-v1332">Smyklot v1.33.2</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.33.2</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>431eaa8e00b3a86da45a8d1bc81c9fe326b5719f chore(release): bump version to 1.33.2</li>
<li>261fed18968208bba21e660e9e6090e96daf336f fix(panel): give every page back its footer (#243)</li>
<li>40103cad5162fabba94682e7e0cf683476f1713e fix(panel): unusable storage reads as none (#241)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Mon, 17 Aug 2026 05:46:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The deploy-swarm-service GitHub Action automates the deployment of a Docker Swarm service by bundling the application and committing the necessary files to version control. It ensures that the environment is set up correctly before pushing changes, addressing potential build issues during deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>deploy-swarm-service</code> GitHub Action automates the deployment of a Docker Swarm service by bundling the application and committing the necessary files to version control. It ensures that the environment is set up correctly before pushing changes, addressing potential build issues during deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/ssg-static-site-generator/</link><pubDate>Mon, 17 Aug 2026 05:46:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.41.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It automates tasks such as content building, template rendering, SEO metadata, and deployment to various platforms like GitHub Pages, Netlify, Vercel, and Cloudflare Pages. The action provides an easy way to generate static websites using Markdown and YAML files, with options for custom themes, templates, and deployment services.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.41</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It automates tasks such as content building, template rendering, SEO metadata, and deployment to various platforms like GitHub Pages, Netlify, Vercel, and Cloudflare Pages. The action provides an easy way to generate static websites using Markdown and YAML files, with options for custom themes, templates, and deployment services.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.41 — a domain carrying a scheme no longer publishes https://https:// into every canonical URL by @spagu in <a href="https://github.com/spagu/ssg/pull/164">https://github.com/spagu/ssg/pull/164</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.40...v1.8.41">https://github.com/spagu/ssg/compare/v1.8.40...v1.8.41</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/classroom-to-sheets-integration/</link><pubDate>Mon, 17 Aug 2026 05:45:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates GitHub Classroom with Google Sheets to automatically send assignment results. It automates the process of updating a Google Sheet with student grades as they are submitted through GitHub Classroom, providing a centralized location for tracking student progress. The action is customizable by specifying task names and can handle multiple tasks in parallel.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates GitHub Classroom with Google Sheets to automatically send assignment results. It automates the process of updating a Google Sheet with student grades as they are submitted through GitHub Classroom, providing a centralized location for tracking student progress. The action is customizable by specifying task names and can handle multiple tasks in parallel.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>Roas OpenAPI Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/roas-openapi-action/</link><pubDate>Mon, 17 Aug 2026 05:44:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/roas-openapi-action/</guid><description>Version updated for https://github.com/sv-tools/roas-action to version v0.10.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, sv-tools/roas-action, is a Docker-based tool that integrates the official roas image to validate and convert OpenAPI specifications (Swagger 2.0, OpenAPI 3.x), overlay documents, and AsyncAPI documents. It supports various subcommands for validation, conversion, and overlay application. The action can handle loading $ref files, skipping checks, and applying overlays in a specified order.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sv-tools/roas-action">https://github.com/sv-tools/roas-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/roas-openapi-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>sv-tools/roas-action</code>, is a Docker-based tool that integrates the official <code>roas</code> image to validate and convert OpenAPI specifications (Swagger 2.0, OpenAPI 3.x), overlay documents, and AsyncAPI documents. It supports various subcommands for validation, conversion, and overlay application. The action can handle loading <code>$ref</code> files, skipping checks, and applying overlays in a specified order.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump actions/checkout from 7.0.0 to 7.0.1 in the ci group by @dependabot[bot] in <a href="https://github.com/sv-tools/roas-action/pull/9">https://github.com/sv-tools/roas-action/pull/9</a></li>
<li>Bump hadolint/hadolint-action from 3.3.0 to 3.4.0 in the ci group by @dependabot[bot] in <a href="https://github.com/sv-tools/roas-action/pull/10">https://github.com/sv-tools/roas-action/pull/10</a></li>
<li>add the asyncapi validate and convert subcommands by @SVilgelm in <a href="https://github.com/sv-tools/roas-action/pull/11">https://github.com/sv-tools/roas-action/pull/11</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sv-tools/roas-action/compare/v0.9.2...v0.10.0">https://github.com/sv-tools/roas-action/compare/v0.9.2...v0.10.0</a></p>
]]></content:encoded></item><item><title>model-eol check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/model-eol-check/</link><pubDate>Mon, 17 Aug 2026 05:42:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/model-eol-check/</guid><description>Version updated for https://github.com/thossullivan/model-eol to version v0.2.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The model-eol GitHub Action provides a machine-readable deprecation feed format for AI models along with the necessary tools to automate tasks related to model retirement, such as CI gate checks, Dependabot PRs, inventory creation, and migration plans. It helps manage dependencies more efficiently by providing clear lifecycle information for AI models and integrates seamlessly with existing software ecosystems like npm and GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thossullivan/model-eol">https://github.com/thossullivan/model-eol</a></strong> to version <strong>v0.2.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/model-eol-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>model-eol</code> GitHub Action provides a machine-readable deprecation feed format for AI models along with the necessary tools to automate tasks related to model retirement, such as CI gate checks, Dependabot PRs, inventory creation, and migration plans. It helps manage dependencies more efficiently by providing clear lifecycle information for AI models and integrates seamlessly with existing software ecosystems like npm and GitHub Actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Align README with the v0.2.3 lifecycle receipts by @thossullivan in <a href="https://github.com/thossullivan/model-eol/pull/61">https://github.com/thossullivan/model-eol/pull/61</a></li>
<li>fix: drain stdio then hard-exit - piped JSON truncated at 64KiB by @thossullivan in <a href="https://github.com/thossullivan/model-eol/pull/63">https://github.com/thossullivan/model-eol/pull/63</a></li>
<li>docs: Action usage in README, security policy - Marketplace listing prep by @thossullivan in <a href="https://github.com/thossullivan/model-eol/pull/62">https://github.com/thossullivan/model-eol/pull/62</a></li>
<li>ci: workflow_dispatch releases without the feeds guard by @thossullivan in <a href="https://github.com/thossullivan/model-eol/pull/64">https://github.com/thossullivan/model-eol/pull/64</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/thossullivan/model-eol/compare/v0.2.3...v0.2.4">https://github.com/thossullivan/model-eol/compare/v0.2.3...v0.2.4</a></p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/wails3-build-action/</link><pubDate>Mon, 17 Aug 2026 05:41:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building of Wails.io projects using GoLang and NodeJS. It builds a specified platform binary, optionally obfuscates it with Garble, and uploads the results to GitHub or releases on tagged builds. The action supports various configurations for different build options such as platform, caching, and packaging decisions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building of Wails.io projects using GoLang and NodeJS. It builds a specified platform binary, optionally obfuscates it with Garble, and uploads the results to GitHub or releases on tagged builds. The action supports various configurations for different build options such as platform, caching, and packaging decisions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>Install bashunit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/install-bashunit/</link><pubDate>Mon, 17 Aug 2026 05:40:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/install-bashunit/</guid><description>Version updated for https://github.com/TypedDevs/bashunit to version 0.49.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates testing Bash scripts using the bashunit framework, which provides a simple and fast way to write tests. It includes various assertions and features such as spies, mocks, data providers, snapshots, and more, making it easy to test complex Bash scripts efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TypedDevs/bashunit">https://github.com/TypedDevs/bashunit</a></strong> to version <strong>0.49.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-bashunit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates testing Bash scripts using the <code>bashunit</code> framework, which provides a simple and fast way to write tests. It includes various assertions and features such as spies, mocks, data providers, snapshots, and more, making it easy to test complex Bash scripts efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-upgrade-note">⚠️ Upgrade note</h2>
<p><code>bashunit empty_dir/</code> — a path that exists but holds no test files — used to exit <strong>0</strong> while silently running <code>BASHUNIT_DEFAULT_PATH</code> instead. It now reports <code>No tests found</code> and exits <strong>1</strong>.</p>
<p>If a pipeline passes a path that is sometimes empty, its build was green over a suite it never asked for, and it will go red on upgrade. Where the empty run is deliberate — a sharded CI matrix, a changed-files run — use the new flag:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>bashunit --pass-with-no-tests --shard 4/4 tests/
</span></span></code></pre></div><h2 id="added">Added</h2>
<ul>
<li><code>--pass-with-no-tests</code> exits 0 when a run selects no tests. The run still reports <code>No tests found</code>; only the verdict changes. It does not excuse a path that is not on disk. Same flag, same spelling, as jest, vitest, Playwright and Cypress (#1263)</li>
<li><code>--list-tags</code> prints the tags of the selected files, one per line, sorted and deduplicated, and runs nothing (#1265)</li>
</ul>
<h2 id="changed">Changed</h2>
<ul>
<li>A <code>test</code> or <code>bench</code> path that does not exist is named and refused before the run starts, instead of the <code>No tests found</code> / <code>No benchmarks found</code> an empty selection gives. Every genuinely-empty case keeps that message (#1263)</li>
<li>A path argument that selects nothing no longer falls back to <code>BASHUNIT_DEFAULT_PATH</code> (#1263)</li>
<li><code>--snapshot-report-unused</code> and <code>--snapshot-prune</code> now report a snapshot whose test <strong>file</strong> was deleted or renamed — the most common way one is orphaned. This widens what <code>--snapshot-prune</code> deletes (#1194)</li>
<li>A <code>--tag</code> matching nothing now names the tags the run saw (#1265)</li>
<li>Performance: a sequential run is about 3.9ms faster per test file, and the total runtime costs one fork and one subshell less (#1271)</li>
<li>Performance: per-test cleanup no longer reads the whole of <code>BASHUNIT_TEMP_DIR</code> — a 100-test file went from 978ms to 542ms against 5000 leftovers (#1269)</li>
</ul>
<h2 id="fixed">Fixed</h2>
<ul>
<li>A sequential run no longer leaks a file descriptor per test file. At the limit it stopped executing tests and reported <code>risky</code> while still exiting 0 (#1271)</li>
<li><code>Time taken</code> no longer reports <code>0ms</code>, or a negative duration, for a runtime it could not measure (#1271)</li>
<li>A run using <code>--test-timeout</code> no longer leaves its watchdog holding the caller&rsquo;s captured output for the rest of the timeout budget (#1137)</li>
<li>A test that both fails an assertion and hits a shell error reports the diagnostic alone (#1267)</li>
<li><code>--list</code> under <code>--parallel</code> no longer prints <code>No tests found</code> in the middle of the ids (#1007)</li>
</ul>
<p><strong>Full changelog</strong>: <a href="https://github.com/TypedDevs/bashunit/compare/0.48.0...0.49.0">https://github.com/TypedDevs/bashunit/compare/0.48.0...0.49.0</a></p>
]]></content:encoded></item><item><title>Rust Bench Compare PRs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/rust-bench-compare-prs/</link><pubDate>Mon, 17 Aug 2026 05:39:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/rust-bench-compare-prs/</guid><description>Version updated for https://github.com/wcampbell0x2a/rust-bench-compare-action to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub action compares the performance of a pull request with the base branch using Rust benchmarks. It supports both the criterion.rs and gungraun harnesses, with gungraun providing more stable results due to instruction counts and estimated cycles. The action is hardware-independent and does not use external services, making it suitable for CI environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wcampbell0x2a/rust-bench-compare-action">https://github.com/wcampbell0x2a/rust-bench-compare-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rust-bench-compare-prs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub action compares the performance of a pull request with the base branch using Rust benchmarks. It supports both the criterion.rs and gungraun harnesses, with gungraun providing more stable results due to instruction counts and estimated cycles. The action is hardware-independent and does not use external services, making it suitable for CI environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Initial Release</li>
</ul>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/b.ia-accessibility-checker/</link><pubDate>Mon, 17 Aug 2026 05:38:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/17/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, B.IA, automates accessibility checks in CI/CD pipelines. It helps companies ensure their products meet WCAG guidelines for specific audiences and provides AI-driven feedback to developers if compliance is not met. The action allows users to define an audience and the percentage of guidelines required, enabling companies to focus on critical user groups while maintaining high standards across all projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, B.IA, automates accessibility checks in CI/CD pipelines. It helps companies ensure their products meet WCAG guidelines for specific audiences and provides AI-driven feedback to developers if compliance is not met. The action allows users to define an audience and the percentage of guidelines required, enabling companies to focus on critical user groups while maintaining high standards across all projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>RuleBlast</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/ruleblast/</link><pubDate>Sun, 16 Aug 2026 22:24:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/ruleblast/</guid><description>Version updated for https://github.com/Kpoiut/ruleblast to version v2.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RuleBlast is a Git extension that analyzes repository changes to identify all files that inherit specific changes, including those in Codex, Claude Code, Gemini CLI, and Copilot CLI. It provides a detailed diff of the blast radius, showing which files have been affected by a change across different tools. This helps users understand how their changes propagate through the system and can detect anomalies or unintended consequences.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Kpoiut/ruleblast">https://github.com/Kpoiut/ruleblast</a></strong> to version <strong>v2.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ruleblast">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RuleBlast is a Git extension that analyzes repository changes to identify all files that inherit specific changes, including those in Codex, Claude Code, Gemini CLI, and Copilot CLI. It provides a detailed diff of the blast radius, showing which files have been affected by a change across different tools. This helps users understand how their changes propagate through the system and can detect anomalies or unintended consequences.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Companion 2.2.1 for Marketplace / Open VSX. Do not overwrite Marketplace 2.2.0.</p>
<ul>
<li>128x128 PNG icon in <code>ruleblast-companion-2.2.1.vsix</code></li>
<li>Verify builds once before <code>npm run check</code>; install smoke reuses <code>dist/cli.js</code></li>
<li>Windows 8.3 path uses <code>cmd %~sI</code> with an env var and <code>windowsVerbatimArguments</code></li>
<li>Test budgets stay 15s / 120s</li>
</ul>
<p>Published npm CLI remains <a href="https://www.npmjs.com/package/ruleblast/v/2.2.0">ruleblast@2.2.0</a>. This tag is not a new npm version.</p>
]]></content:encoded></item><item><title>AIsbom Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/aisbom-security-scanner/</link><pubDate>Sun, 16 Aug 2026 22:23:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/aisbom-security-scanner/</guid><description>Version updated for https://github.com/Lab700xOrg/aisbom to version v1.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AIsbom is a tool designed to detect malware and license risks in machine learning model files, primarily through static analysis. It inspects Python Pickle bytecode, Keras configurations, GGUF chat templates, ONNX graphs, and SafeTensors binaries to identify RCE-capable payloads and restrictive licenses that are not detected by generic SBOM tools. The tool does not load or execute the models, ensuring compliance and security during scans.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lab700xOrg/aisbom">https://github.com/Lab700xOrg/aisbom</a></strong> to version <strong>v1.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aisbom-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AIsbom is a tool designed to detect malware and license risks in machine learning model files, primarily through static analysis. It inspects Python Pickle bytecode, Keras configurations, GGUF chat templates, ONNX graphs, and SafeTensors binaries to identify RCE-capable payloads and restrictive licenses that are not detected by generic SBOM tools. The tool does not load or execute the models, ensuring compliance and security during scans.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="heads-up-two-exit-codes-changed">Heads up: two exit codes changed</h3>
<p>Two cases that previously exited <code>0</code> now exit non-zero. <strong>Neither was scanning anything before</strong>, so nothing that genuinely worked is affected — but a pipeline that was silently green on a bad path will now fail, which is the point of the fix.</p>
<h3 id="whats-new">What&rsquo;s new</h3>
<p><strong>Scanning a single model file works.</strong> <code>aisbom scan model.pt</code> discovered nothing and exited <code>0</code>, because local discovery only ever enumerated the <em>contents of a directory</em>. A malicious file named directly on the command line reported &ldquo;No AI models found&rdquo; and passed clean — while the identical file scanned via its parent directory was correctly flagged CRITICAL.</p>
<ul>
<li>This is the form the README documents for both <code>--strict</code> and <code>--lint</code>, so the two examples a security-conscious user is most likely to copy were the two that silently did nothing.</li>
<li>Single files are now first-class targets for every supported format, and a file gets the same verdict whichever way it is reached.</li>
</ul>
<p><strong>An unusable scan target now fails instead of passing.</strong> A path that does not exist — or a broken symlink, or a named file no scanner can read — previously produced an empty SBOM and exit <code>0</code>, indistinguishable from a genuinely clean repo. A typo&rsquo;d path in CI turned the gate green permanently.</p>
<ul>
<li>These now report what went wrong and exit <code>1</code>.</li>
<li><code>--no-fail-on-risk</code> does not suppress it: that flag governs risk findings, not a broken target.</li>
<li>An empty directory is still a clean scan and still exits <code>0</code>.</li>
</ul>
<p><strong>The bypass scorecard now publishes why each uncaught case is uncaught.</strong> Cases that are not fully caught carry a <code>limitation</code> note, rendered into <code>docs/bypass-scorecard.md</code> alongside the verdict: what AIsbom actually reports, why that is the wrong reason, and what closing the gap would take. No case&rsquo;s <code>expected</code> verdict changes — every evasion technique in the corpus remains one a correct scanner should catch, so the gate keeps counting all three against us. The note explains a gap; it never excuses one.</p>
<h3 id="exit-codes">Exit codes</h3>
<table>
  <thead>
      <tr>
          <th>Exit</th>
          <th>Meaning</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>0</code></td>
          <td>Scan completed, no CRITICAL risk</td>
      </tr>
      <tr>
          <td><code>1</code></td>
          <td>Scan could not be completed — target missing/unreadable, parse failure, or remote fetch failure</td>
      </tr>
      <tr>
          <td><code>2</code></td>
          <td>CRITICAL risk found (suppress with <code>--no-fail-on-risk</code>)</td>
      </tr>
  </tbody>
</table>
<p>Only the <code>1</code> row is new for local targets; remote fetch failures have behaved this way since v1.1.0.</p>
<h3 id="whats-not-changing">What&rsquo;s not changing</h3>
<p>CycloneDX and SPDX output are byte-for-byte identical to v1.3.0 — verified by diffing the emitted documents across the whole CLI surface. Detection behavior is unchanged, and the bypass scorecard holds at 8/11 with no case moving.</p>
<h3 id="dependencies">Dependencies</h3>
<p><code>typer</code> 0.27.1, <code>cyclonedx-python-lib</code> 11.11.1, <code>packaging</code> 26.3, and <code>pyinstaller</code> 6.22.0 (build-only). Each was verified individually and in combination against an unchanged CLI-output baseline.</p>
]]></content:encoded></item><item><title>Download and cache a file in GitHub Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/download-and-cache-a-file-in-github-actions/</link><pubDate>Sun, 16 Aug 2026 22:20:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/download-and-cache-a-file-in-github-actions/</guid><description>Version updated for https://github.com/mercury233/action-cache-download-file to version v1.3.0.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action downloads a file from a URL and caches it for subsequent workflow runs, supporting SHA-256 checksum verification. It ensures that only files with the expected contents are used, providing a reliable way to manage cached assets across different builds.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mercury233/action-cache-download-file">https://github.com/mercury233/action-cache-download-file</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/download-and-cache-a-file-in-github-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action downloads a file from a URL and caches it for subsequent workflow runs, supporting SHA-256 checksum verification. It ensures that only files with the expected contents are used, providing a reliable way to manage cached assets across different builds.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Hardened input handling to prevent shell command injection and unsafe cache keys.</li>
<li>Added validation for URLs, filenames, destination paths, and SHA-256 checksums.</li>
<li>Changed cache keys to use the expected SHA-256 checksum when provided, or a SHA-256 hash of the URL otherwise. Existing caches created by v1.2.0 will not be reused.</li>
<li>Improved automatic filename detection for URLs containing query strings or fragments.</li>
<li>Added portable SHA-256 calculation using <code>sha256sum</code>, <code>shasum</code>, or <code>openssl</code>.</li>
<li>Added tests for Ubuntu, macOS, and Windows, including invalid-input and command-injection cases.</li>
</ul>
]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Sun, 16 Aug 2026 22:19:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.14.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the running of automated test suites in a ServiceNow environment using basic authentication, API keys, or an instance URL. It solves problems related to managing and executing test automation scripts within a CI/CD pipeline by simplifying the setup and configuration process for testing environments. The key capabilities include supporting various browsers, operating systems, test suite selection, and handling different authentication methods for ServiceNow instances.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the running of automated test suites in a ServiceNow environment using basic authentication, API keys, or an instance URL. It solves problems related to managing and executing test automation scripts within a CI/CD pipeline by simplifying the setup and configuration process for testing environments. The key capabilities include supporting various browsers, operating systems, test suite selection, and handling different authentication methods for ServiceNow instances.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.13...1.0.14">https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.13...1.0.14</a></p>
]]></content:encoded></item><item><title>postmortem supply-chain gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/postmortem-supply-chain-gate/</link><pubDate>Sun, 16 Aug 2026 22:18:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/postmortem-supply-chain-gate/</guid><description>Version updated for https://github.com/mlab-sh/postmortem to version v2.1.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary postmortem is a command-line tool designed to detect and analyze security threats in dependencies. It provides a comprehensive analysis of your project’s codebase to identify malicious activities such as supply-chain attacks, typosquats, and unverified sources. The action does not collect any telemetry and only queries the network when necessary, ensuring minimal overhead. It can score dependencies by their reputations across multiple platforms and detect known vulnerabilities in the ecosystem.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mlab-sh/postmortem">https://github.com/mlab-sh/postmortem</a></strong> to version <strong>v2.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postmortem-supply-chain-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>postmortem is a command-line tool designed to detect and analyze security threats in dependencies. It provides a comprehensive analysis of your project&rsquo;s codebase to identify malicious activities such as supply-chain attacks, typosquats, and unverified sources. The action does not collect any telemetry and only queries the network when necessary, ensuring minimal overhead. It can score dependencies by their reputations across multiple platforms and detect known vulnerabilities in the ecosystem.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mlab-sh/postmortem/compare/v2.1.1...v2.1.2">https://github.com/mlab-sh/postmortem/compare/v2.1.1...v2.1.2</a></p>
]]></content:encoded></item><item><title>Kyosei Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/kyosei-code-review/</link><pubDate>Sun, 16 Aug 2026 22:17:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/kyosei-code-review/</guid><description>Version updated for https://github.com/ncaq/kyosei-action to version v2.4.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates a multi-perspective AI code review using the kyosei plugin. It collects existing feedback from PR conversations, excludes redundant comments, and removes project-specific coding conventions. The action wraps kyosei as a reusable workflow that handles checkout and timeout internally, requiring permissions to be declared by the caller.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ncaq/kyosei-action">https://github.com/ncaq/kyosei-action</a></strong> to version <strong>v2.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kyosei-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates a multi-perspective AI code review using the kyosei plugin. It collects existing feedback from PR conversations, excludes redundant comments, and removes project-specific coding conventions. The action wraps kyosei as a reusable workflow that handles checkout and timeout internally, requiring permissions to be declared by the caller.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v2.4.0 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="features">Features</h3>
<ul>
<li>feat: レビューに必要な権限をデフォルトで揃えます by @ncaq in <a href="https://github.com/ncaq/kyosei-action/pull/192">https://github.com/ncaq/kyosei-action/pull/192</a></li>
</ul>
<h3 id="dependency-updates">Dependency Updates</h3>
<ul>
<li>build(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/ncaq/kyosei-action/pull/189">https://github.com/ncaq/kyosei-action/pull/189</a></li>
<li>build(deps): update ncaq/nix-composite-action action to v3.0.3 by @renovate[bot] in <a href="https://github.com/ncaq/kyosei-action/pull/190">https://github.com/ncaq/kyosei-action/pull/190</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ncaq/kyosei-action/compare/v2.3.1...v2.4.0">https://github.com/ncaq/kyosei-action/compare/v2.3.1...v2.4.0</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/go-proxy-cache-updater/</link><pubDate>Sun, 16 Aug 2026 22:16:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.45.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of updating a proxy cache for Go modules when new tags are created. It supports standard and submodule version tags, customizes proxy configurations, and allows for customizable import paths and Go versions. The action simplifies setting up CI/CD pipelines to ensure module availability and documentation updates on platforms like pkg.go.dev.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.45</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of updating a proxy cache for Go modules when new tags are created. It supports standard and submodule version tags, customizes proxy configurations, and allows for customizable import paths and Go versions. The action simplifies setting up CI/CD pipelines to ensure module availability and documentation updates on platforms like pkg.go.dev.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1145-2026-08-16"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.44...v1.1.45">1.1.45</a> (2026-08-16)</h2>
]]></content:encoded></item><item><title>run-wenxian</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/run-wenxian/</link><pubDate>Sun, 16 Aug 2026 22:14:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/run-wenxian/</guid><description>Version updated for https://github.com/njzjz/wenxian to version v0.3.3.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, wenxian, generates BibTeX citations from paper identifiers such as DOI, PMID, arXiv ID, or title. It is designed to be used in the browser, command line, and within GitHub Actions workflows, automating the process of converting research references into structured bibliographic entries.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/njzjz/wenxian">https://github.com/njzjz/wenxian</a></strong> to version <strong>v0.3.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-wenxian">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>wenxian</code>, generates BibTeX citations from paper identifiers such as DOI, PMID, arXiv ID, or title. It is designed to be used in the browser, command line, and within GitHub Actions workflows, automating the process of converting research references into structured bibliographic entries.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update astral-sh/setup-uv action to v8.3.0 by @renovate[bot] in <a href="https://github.com/njzjz/wenxian/pull/102">https://github.com/njzjz/wenxian/pull/102</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v8.3.2 by @renovate[bot] in <a href="https://github.com/njzjz/wenxian/pull/105">https://github.com/njzjz/wenxian/pull/105</a></li>
<li>fix: restore browser lookups through Python fallbacks by @njzjz in <a href="https://github.com/njzjz/wenxian/pull/110">https://github.com/njzjz/wenxian/pull/110</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v10 by @renovate[bot] in <a href="https://github.com/njzjz/wenxian/pull/108">https://github.com/njzjz/wenxian/pull/108</a></li>
<li>chore(deps): update actions/checkout action to v7 by @renovate[bot] in <a href="https://github.com/njzjz/wenxian/pull/104">https://github.com/njzjz/wenxian/pull/104</a></li>
<li>chore(deps): update codecov/codecov-action action to v7 by @renovate[bot] in <a href="https://github.com/njzjz/wenxian/pull/103">https://github.com/njzjz/wenxian/pull/103</a></li>
<li>chore(deps): update actions/setup-python action to v7 by @renovate[bot] in <a href="https://github.com/njzjz/wenxian/pull/106">https://github.com/njzjz/wenxian/pull/106</a></li>
<li>feat: fetch metadata sources concurrently by @njzjz-bot in <a href="https://github.com/njzjz/wenxian/pull/111">https://github.com/njzjz/wenxian/pull/111</a></li>
<li>[pre-commit.ci] pre-commit autoupdate by @pre-commit-ci[bot] in <a href="https://github.com/njzjz/wenxian/pull/94">https://github.com/njzjz/wenxian/pull/94</a></li>
<li>fix: preserve BibTeX type priority when merging references by @njzjz-bot in <a href="https://github.com/njzjz/wenxian/pull/122">https://github.com/njzjz/wenxian/pull/122</a></li>
<li>fix: add native HTTP request timeouts by @njzjz-bot in <a href="https://github.com/njzjz/wenxian/pull/119">https://github.com/njzjz/wenxian/pull/119</a></li>
<li>fix: fall back after title validation mismatch by @njzjz-bot in <a href="https://github.com/njzjz/wenxian/pull/121">https://github.com/njzjz/wenxian/pull/121</a></li>
<li>fix: recognize valid PMID and legacy arXiv identifiers by @njzjz-bot in <a href="https://github.com/njzjz/wenxian/pull/118">https://github.com/njzjz/wenxian/pull/118</a></li>
<li>fix: preserve all PubMed structured abstract sections by @njzjz-bot in <a href="https://github.com/njzjz/wenxian/pull/123">https://github.com/njzjz/wenxian/pull/123</a></li>
<li>fix: isolate malformed metadata source failures by @njzjz-bot in <a href="https://github.com/njzjz/wenxian/pull/120">https://github.com/njzjz/wenxian/pull/120</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/njzjz/wenxian/compare/v0.3.2...v0.3.3">https://github.com/njzjz/wenxian/compare/v0.3.2...v0.3.3</a></p>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/run-aer-tests/</link><pubDate>Sun, 16 Aug 2026 22:13:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.34.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, aer, automates running Apex unit tests and executing anonymous Apex locally without needing an org. It supports various Salesforce features like SOQL, DML, triggers, flows, and testing, ensuring local execution behavior matches that in Salesforce. The action can be used for continuous integration to validate code changes before deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.34</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>aer</code>, automates running Apex unit tests and executing anonymous Apex locally without needing an org. It supports various Salesforce features like SOQL, DML, triggers, flows, and testing, ensuring local execution behavior matches that in Salesforce. The action can be used for continuous integration to validate code changes before deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.34</p>
<ul>
<li>
<p>Make getGlobalDescribe Map Lookups Case-Insensitive For Any Key Casing</p>
</li>
<li>
<p>Replace Hot-Path Linear Scans With Precomputed Schema Indexes</p>
</li>
<li>
<p>Implement The CompanyName, Street, And City Matching Methods</p>
</li>
<li>
<p>Persist Rollup Parent Updates As One Duplicate-Rule Save Call</p>
</li>
<li>
<p>Cache Repeated Record Fetches And Lookup Keys On The DML Hot Path</p>
</li>
<li>
<p>Keep A Successful Partial-Save Retry&rsquo;s Trigger Side Effects</p>
</li>
<li>
<p>Fetch Rollup Children With Filtered Queries Instead Of Full Table Scans</p>
</li>
</ul>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/odin-scan-smart-contract-security/</link><pubDate>Sun, 16 Aug 2026 22:12:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates AI-powered smart contract security analysis for CosmWasm, Solana, and EVM projects using the Odin Scan API. It integrates seamlessly with GitHub workflows to detect vulnerabilities before they reach production, providing detailed findings as inline comments on PRs and SARIF files for native security alerts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates AI-powered smart contract security analysis for CosmWasm, Solana, and EVM projects using the Odin Scan API. It integrates seamlessly with GitHub workflows to detect vulnerabilities before they reach production, providing detailed findings as inline comments on PRs and SARIF files for native security alerts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial Release</p>
<p>AI-powered smart contract security analysis, now integrated directly into your GitHub workflow.</p>
<p>✨ Features</p>
<p>Multi-Platform Support</p>
<ul>
<li>CosmWasm - Rust-based smart contracts for Cosmos SDK</li>
<li>Solana (SVM) - Anchor and native Solana programs</li>
<li>EVM - Solidity and Vyper contracts</li>
<li>Auto-detection - Automatically identifies platform from your repo</li>
</ul>
<p>GitHub Integration</p>
<ul>
<li>Code Scanning - SARIF upload for native security alerts in the Security tab</li>
<li>PR Comments - Severity summary and top findings posted directly on pull requests</li>
<li>Inline Annotations - Critical/high findings appear as errors, medium/low as warnings on diffs</li>
<li>Artifact Upload - Full JSON report available as workflow artifact</li>
</ul>
<p>Customization</p>
<ul>
<li>Severity Thresholds - Fail builds at critical, high, medium, or low severity</li>
<li>Platform Override - Force specific platform detection when auto-detect isn&rsquo;t enough</li>
<li>Timeout Control - Configurable analysis timeout (default: 30 minutes)</li>
<li>Flexible Triggers - Run on push, PR, schedule, or manual dispatch</li>
</ul>
<p>🚀 Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Security Scan</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&#39;on&#39;</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">main</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">security-events</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">api-key</span>: <span style="color:#e6db74">&#39;${{ secrets.ODIN_SCAN_API_KEY }}&#39;</span>
</span></span></code></pre></div><p>📋 Requirements</p>
<ul>
<li>Odin Scan Pro subscription - Required for API access</li>
<li>API Key - Generate at <a href="https://odinscan.ai/dashboard/settings">https://odinscan.ai/dashboard/settings</a></li>
<li>GitHub Permissions - contents: read, security-events: write (for SARIF), pull-requests: write (for
comments)</li>
</ul>
<p>🔧 Configuration</p>
<p>All Inputs</p>
<p>| ┌────────────────────┬─────────────────────┬──────────────────────────────────────────────┐ |
| │       Input        │       Default       │                 Description                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ api-key            │ Required            │ Your Odin Scan API key (odin_sk_*)           │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ platform           │ auto                │ Target platform: auto, cosmwasm, solana, evm │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ severity-threshold │ high                │ Fail at: critical, high, medium, low, none   │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ fail-on-findings   │ true                │ Whether to fail workflow on findings         │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ comment-on-pr      │ true                │ Post summary comment on PRs                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-sarif       │ true                │ Upload SARIF to Code Scanning                │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-artifact    │ true                │ Upload full report as artifact               │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ timeout            │ 1800                │ Max analysis wait time (seconds)             │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ github-token       │ ${{ github.token }} │ Token for PR comments and SARIF              │ |
| └────────────────────┴─────────────────────┴──────────────────────────────────────────────┘ |</p>
<p>All Outputs</p>
<ul>
<li>analysis-id - Unique analysis identifier</li>
<li>status - Analysis status (completed, failed)</li>
<li>total-findings - Total number of findings</li>
<li>critical-count, high-count, medium-count, low-count - Counts by severity</li>
<li>report-url - Link to full report on Odin Scan</li>
<li>sarif-file - Path to generated SARIF file</li>
</ul>
<p>📝 Example Workflows</p>
<p>Basic (Auto-detect)</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span></code></pre></div><p>EVM with Medium Threshold</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">platform</span>: <span style="color:#ae81ff">evm</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">severity-threshold</span>: <span style="color:#ae81ff">medium</span>
</span></span></code></pre></div><p>Only on Solidity Changes</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#39;**.sol&#39;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">foundry.toml</span>
</span></span></code></pre></div><p>🔒 Security &amp; Privacy</p>
<ul>
<li>All API communication over HTTPS (TLS 1.2+)</li>
<li>API keys automatically masked in logs</li>
<li>No data stored by the action (stateless)</li>
<li>See <a href="https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md">https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md</a> for details</li>
</ul>
<p>📖 Documentation</p>
<ul>
<li>Action README - <a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></li>
<li>Odin Scan Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
<li>Get API Key - <a href="https://app.odinscan.ai/settings">https://app.odinscan.ai/settings</a></li>
</ul>
<p>🐛 Known Limitations</p>
<ul>
<li>Private repos - Requires github-token with repo access</li>
<li>Large repos - May need increased timeout for complex codebases</li>
<li>Code Scanning - Requires GitHub Advanced Security on private repos</li>
</ul>
<p>🙏 Support</p>
<ul>
<li>Issues - <a href="https://github.com/Odin-Scan/odin-scan-action/issues">https://github.com/Odin-Scan/odin-scan-action/issues</a></li>
<li>Email - <a href="mailto:support@odinscan.ai">support@odinscan.ai</a></li>
<li>Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
</ul>
<hr>
<p>Full Changelog: <a href="https://github.com/Odin-Scan/odin-scan-action/commits/v1">https://github.com/Odin-Scan/odin-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>Cursor Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/cursor-action/</link><pubDate>Sun, 16 Aug 2026 22:11:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/cursor-action/</guid><description>Version updated for https://github.com/PunGrumpy/cursor-action to version v1.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of Cursor agents using the official @cursor/sdk. It runs on multiple platforms and allows for customization of prompts, models, and permissions through inputs. The action outputs a model response stored in steps.&amp;lt;id&amp;gt;.outputs.summary, which can be used in subsequent steps without interpolation to avoid security risks from untrusted model output.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PunGrumpy/cursor-action">https://github.com/PunGrumpy/cursor-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cursor-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of Cursor agents using the official @cursor/sdk. It runs on multiple platforms and allows for customization of prompts, models, and permissions through inputs. The action outputs a model response stored in <code>steps.&lt;id&gt;.outputs.summary</code>, which can be used in subsequent steps without interpolation to avoid security risks from untrusted model output.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>
<p>cf2ab49: Publish a moving <code>v1</code> tag on every release, so <code>uses: PunGrumpy/cursor-action@v1</code>
resolves to the latest <code>v1.x.x</code>. Previously only exact <code>vX.Y.Z</code> tags existed and
<code>@v1</code> did not resolve at all.</p>
</li>
<li>
<p>2c2f2ba: Update <code>@cursor/sdk</code> to 1.0.28. It drops <code>sqlite3</code> from its dependencies in
favour of an optional <code>@cursor/sdk/sqlite</code> entry point, so the action no longer
pulls a native module that has to be prebuilt or compiled during install.</p>
</li>
<li>
<p>cf2ab49: Document that <code>permissions</code> is validated but never enforced: the value is not
passed to the SDK, so <code>read-only</code> does <strong>not</strong> stop the agent from editing files
or running shell commands. Tool access follows your API key and account. It is
wired to the SDK&rsquo;s tool restrictions in v2.</p>
<p><code>cursor-version</code> is likewise ignored — the SDK manages the agent version.</p>
</li>
<li>
<p>cf2ab49: Fix the action failing with a module resolution error at every published tag.
<code>dist/</code> was gitignored while <code>action.yml</code> executed <code>dist/index.mjs</code>, so the file
never existed for consumers — only this repository&rsquo;s own smoke test worked,
because it downloaded <code>dist/</code> as a build artifact first.</p>
<p><code>dist/</code> is now committed. It holds only this repository&rsquo;s own code (5.8 kB):
<code>@cursor/sdk</code> cannot be bundled, because it dynamically imports its own webpack
chunks at runtime and resolves a native <code>@cursor/sdk-&lt;platform&gt;</code> package, so it
stays external and the action installs it.</p>
</li>
</ul>
]]></content:encoded></item><item><title>QWED Protocol Verification</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/qwed-protocol-verification/</link><pubDate>Sun, 16 Aug 2026 22:10:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/qwed-protocol-verification/</guid><description>Version updated for https://github.com/QWED-AI/qwed-verification to version v7.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates AI output verification using the QWED protocol and Verification Context v1.0, ensuring deterministic verification before production execution. It provides a standardized way to verify AI outputs, returning diagnostic results indicating whether they are VERIFIED, UNVERIFIABLE, or BLOCKED based on policy and rules. The action emits evidence and proof in a canonical format that can be used for auditing and decision-making.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/QWED-AI/qwed-verification">https://github.com/QWED-AI/qwed-verification</a></strong> to version <strong>v7.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qwed-protocol-verification">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates AI output verification using the QWED protocol and Verification Context v1.0, ensuring deterministic verification before production execution. It provides a standardized way to verify AI outputs, returning diagnostic results indicating whether they are VERIFIED, UNVERIFIABLE, or BLOCKED based on policy and rules. The action emits evidence and proof in a canonical format that can be used for auditing and decision-making.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v710--verification-context-v10-rollout">v7.1.0 — Verification Context v1.0 Rollout</h2>
<p>Additive minor release shipping the <strong>Verification Context (VC) v1.0</strong> — the external, interoperable layer on top of <code>DiagnosticResult</code>. Verification methods keep returning <code>DiagnosticResult</code>; a schema-validated, canonically-encoded, tamper-evident verification document is produced on demand via the explicit <code>to_verification_context()</code> conversion.</p>
<blockquote>
<p>No breaking wire changes — existing wire contracts remain unchanged.</p>
</blockquote>
<h3 id="ontology--spec-301-302">Ontology &amp; Spec (#301, #302)</h3>
<ul>
<li><strong>ADR-001..005 — verification ontology</strong> — object of verification, verification context document, truth-vs-admission separation, formalization boundary, root of trust formally defined</li>
<li><strong>Verification Context v1.0 spec freeze</strong> — 4-layer JSON document contract (interpretation / proof / evidence / decision) with RFC 8785 canonical encoding, UTF-16 key ordering, fail-closed schema validation, content-bound <code>proof_ref</code></li>
</ul>
<h3 id="core-model-308-309">Core Model (#308, #309)</h3>
<ul>
<li><strong><code>VerificationContext</code> model + JSON schema</strong> — <code>VerificationContext</code>, <code>VerificationContextDocument</code>, <code>Verdict</code>, <code>Admission</code>, and nested <code>Interpretation</code> / <code>Proof</code> / <code>Evidence</code> / <code>Decision</code> types with fail-closed validation</li>
<li><strong>Public <code>proof_ref</code> generation / resolution</strong> — <code>compute_document_proof_ref()</code> and <code>resolve_document_proof_ref()</code> exposed as public API; content-bound SHA-256 hashes over the canonical document</li>
</ul>
<h3 id="bridge--verifier-mappings-310-316">Bridge &amp; Verifier Mappings (#310, #316)</h3>
<ul>
<li><strong><code>verification_context_from_diagnostic_result()</code></strong> — <code>DiagnosticResult</code> → VC document; VERIFIED without attestation demotes to UNVERIFIABLE (fail-closed)</li>
<li><strong><code>to_verification_context()</code> on all 13 verifiers</strong> — Math, Logic, Symbolic, SQL, Code, Schema, Fact, Image, Graph, Reasoning, Stats, Consensus, SecureCodeExecutor</li>
</ul>
<h3 id="surface-exposure-311-313-314-315">Surface Exposure (#311, #313, #314, #315)</h3>
<ul>
<li><strong>SDK / API / CLI exposure</strong> — Verification Context surfaced across API routes, CLI, and SDK</li>
<li><strong>Docker action VC outputs</strong> — the containerized GitHub Action emits <code>verdict</code>, <code>admission</code>, <code>proof_ref</code>, and <code>verification_context</code></li>
<li><strong>Metadata &amp; README alignment</strong> — repository metadata aligned with the v7.0 architecture</li>
<li><strong>SDK re-exports</strong> — all Verification Context v1.0 types re-exported from <code>qwed_sdk</code></li>
</ul>
<h3 id="packages">Packages</h3>
<ul>
<li><code>qwed</code> (PyPI): <code>7.0.0</code> → <code>7.1.0</code></li>
<li><code>qwed_sdk</code> (Python): <code>7.0.0</code> → <code>7.1.0</code></li>
<li><code>@qwed-ai/sdk</code> (NPM): <code>7.0.0</code> → <code>7.1.0</code></li>
<li><code>qwed</code> (crates.io/Rust): <code>7.0.0</code> → <code>7.1.0</code></li>
<li>Docker image: <code>qwedai/qwed-verification:7.1.0</code> / <code>7.1</code> / <code>latest</code></li>
</ul>
<h3 id="notes">Notes</h3>
<ul>
<li>The <strong>QWED GitHub Action</strong> is versioned independently (<code>3.2.0</code>); not published from this repo.</li>
<li>Kubernetes deployment stays pinned to a previously-published image.</li>
</ul>
]]></content:encoded></item><item><title>Advisory lock service for CI/CD pipelines</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/advisory-lock-service-for-ci/cd-pipelines/</link><pubDate>Sun, 16 Aug 2026 22:08:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/advisory-lock-service-for-ci/cd-pipelines/</guid><description>Version updated for https://github.com/releasetools/mutex to version v1.2.1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, mutex, provides a robust solution to manage shared resources in CI/CD pipelines by enforcing advisory locks in a PostgreSQL table. It allows different workflows or commands to wait until a lock is released, preventing race conditions and ensuring proper resource management. The action supports locking and unlocking operations via command-line interface (CLI) and GitHub Actions, with options for customizing the lock duration and behavior through environment variables and inputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/releasetools/mutex">https://github.com/releasetools/mutex</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/advisory-lock-service-for-ci-cd-pipelines">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, mutex, provides a robust solution to manage shared resources in CI/CD pipelines by enforcing advisory locks in a PostgreSQL table. It allows different workflows or commands to wait until a lock is released, preventing race conditions and ensuring proper resource management. The action supports locking and unlocking operations via command-line interface (CLI) and GitHub Actions, with options for customizing the lock duration and behavior through environment variables and inputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Slack notifications are now switched on by <code>slack-channel</code> alone. A workflow that never asked for them no longer logs a warning about a missing <code>SLACK_BOT_TOKEN</code> on every lock and release.</li>
<li>Fixed a <code>SLACK_BOT_TOKEN</code> inherited from job-level <code>env:</code> failing any mutex step that set no <code>slack-channel</code>. The channel decides; an unrelated variable in the environment no longer can.</li>
</ul>
]]></content:encoded></item><item><title>agent-trace eval</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/agent-trace-eval/</link><pubDate>Sun, 16 Aug 2026 22:07:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/agent-trace-eval/</guid><description>Version updated for https://github.com/Siddhant-K-code/agent-trace to version v0.87.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary agent-strace is a tool designed to capture and replay the full session of AI agents, providing insights into tool calls, file operations, decision points, and error recovery. It helps in inspecting what ran, what changed, what failed, and where human review should occur, making it easier to debug and audit AI-assisted engineering processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Siddhant-K-code/agent-trace">https://github.com/Siddhant-K-code/agent-trace</a></strong> to version <strong>v0.87.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-trace-eval">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>agent-strace</code> is a tool designed to capture and replay the full session of AI agents, providing insights into tool calls, file operations, decision points, and error recovery. It helps in inspecting what ran, what changed, what failed, and where human review should occur, making it easier to debug and audit AI-assisted engineering processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add historical policy backtesting (#211)</li>
</ul>
]]></content:encoded></item><item><title>🤖 Setup GitHub App as bot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/setup-github-app-as-bot/</link><pubDate>Sun, 16 Aug 2026 22:06:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/setup-github-app-as-bot/</guid><description>Version updated for https://github.com/SimonMarquis/setup-github-app-as-bot to version v1.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup of a GitHub App as a bot, enabling CI workflows by generating an access token and configuring the bot’s git identity for authentication. It solves problems related to setting up automated actions that interact with GitHub repositories and users, providing easy configuration through environment variables.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SimonMarquis/setup-github-app-as-bot">https://github.com/SimonMarquis/setup-github-app-as-bot</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-github-app-as-bot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup of a GitHub App as a bot, enabling CI workflows by generating an access token and configuring the bot&rsquo;s git identity for authentication. It solves problems related to setting up automated actions that interact with GitHub repositories and users, providing easy configuration through environment variables.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial release</p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/smyklot/</link><pubDate>Sun, 16 Aug 2026 22:06:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.31.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository’s CODEOWNERS file. It handles comments with commands or reactions, supports multiple command formats, allows for different merge methods, provides emoji feedback, and includes features like approval deduplication and multi-command support.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.31.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository&rsquo;s CODEOWNERS file. It handles comments with commands or reactions, supports multiple command formats, allows for different merge methods, provides emoji feedback, and includes features like approval deduplication and multi-command support.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1310-2026-08-16"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.30.2...v1.31.0">1.31.0</a> (2026-08-16)</h2>
<h2 id="smyklot-v1310">Smyklot v1.31.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.31.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>72ced1acf488f7c44bb9004ff07c8916f3ca951e chore(release): bump version to 1.31.0</li>
<li>95ec560640dae037722554ce5d4c266f8a5ee8f3 feat(config)!: configure Smyklot in TOML (#225)</li>
<li>31a4ce44c2d658a92d500bda47905e7dc5c25d29 chore(ci): gate releases on the test workflow (#231)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/ssg-static-site-generator/</link><pubDate>Sun, 16 Aug 2026 22:05:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.39.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that turns Markdown with YAML frontmatter into a complete website. It automates the process of building websites, including creating content models, managing themes, and deploying to various platforms. The key capabilities include Markdown rendering, automatic URL creation, built-in SEO features, responsive images, and deployment options for hosting on cloud providers like GitHub Pages, Vercel, and Netlify.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.39</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that turns Markdown with YAML frontmatter into a complete website. It automates the process of building websites, including creating content models, managing themes, and deploying to various platforms. The key capabilities include Markdown rendering, automatic URL creation, built-in SEO features, responsive images, and deployment options for hosting on cloud providers like GitHub Pages, Vercel, and Netlify.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.39 — one sort for every listing, date archives that exist, and the newest engine wins by @spagu in <a href="https://github.com/spagu/ssg/pull/161">https://github.com/spagu/ssg/pull/161</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.38...v1.8.39">https://github.com/spagu/ssg/compare/v1.8.38...v1.8.39</a></p>
]]></content:encoded></item><item><title>SpecShield BDCT</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/specshield-bdct/</link><pubDate>Sun, 16 Aug 2026 22:03:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/specshield-bdct/</guid><description>Version updated for https://github.com/specshield-io/bdct-action to version v1.0.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SpecShield BDCT GitHub Action automates the Bi-Directional Contract Testing (BDCT) process using the SpecShield CLI. It provides a thin wrapper around the CLI, allowing users to easily integrate BDCT into their GitHub Actions workflows. Key capabilities include setting up Node 20 and caching/installing the SpecShield CLI, running BDCT subcommands with structured output, exposing type-safe outputs for can-i-deploy and verify, and writing clear result summaries to the GitHub Step Summary page. The action is a composite action that runs on various runners and supports different input options such as command, API token, organization key, service, version, environment, etc.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/specshield-io/bdct-action">https://github.com/specshield-io/bdct-action</a></strong> to version <strong>v1.0.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/specshield-bdct">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The SpecShield BDCT GitHub Action automates the Bi-Directional Contract Testing (BDCT) process using the SpecShield CLI. It provides a thin wrapper around the CLI, allowing users to easily integrate BDCT into their GitHub Actions workflows. Key capabilities include setting up Node 20 and caching/installing the SpecShield CLI, running BDCT subcommands with structured output, exposing type-safe outputs for <code>can-i-deploy</code> and <code>verify</code>, and writing clear result summaries to the GitHub Step Summary page. The action is a composite action that runs on various runners and supports different input options such as command, API token, organization key, service, version, environment, etc.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/specshield26/bdct-action/compare/v1.0.6...v1.0.7">https://github.com/specshield26/bdct-action/compare/v1.0.6...v1.0.7</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/classroom-to-sheets-integration/</link><pubDate>Sun, 16 Aug 2026 22:02:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates Google Sheets with GitHub Classroom to automatically update assignment results. It requires setting up Google API credentials and sharing the sheet with a service account, then configuring secrets in your GitHub repository. The action uses the classroom-resources/autograding-command-grader@v1 grader and updates a specified Google Sheet with students’ scores.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates Google Sheets with GitHub Classroom to automatically update assignment results. It requires setting up Google API credentials and sharing the sheet with a service account, then configuring secrets in your GitHub repository. The action uses the <code>classroom-resources/autograding-command-grader@v1</code> grader and updates a specified Google Sheet with students&rsquo; scores.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>move-test-gen coverage check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/move-test-gen-coverage-check/</link><pubDate>Sun, 16 Aug 2026 22:01:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/move-test-gen-coverage-check/</guid><description>Version updated for https://github.com/talongate/move-test-gen to version v1.5.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates edge-case test suites for Sui Move functions by covering various scenarios such as boundary values, arithmetic edges, access control issues, state machine problems, and economic considerations. It automates the creation of [test] and [expected_failure] functions to verify function correctness and handle potential errors during execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/talongate/move-test-gen">https://github.com/talongate/move-test-gen</a></strong> to version <strong>v1.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-test-gen-coverage-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates edge-case test suites for Sui Move functions by covering various scenarios such as boundary values, arithmetic edges, access control issues, state machine problems, and economic considerations. It automates the creation of <code>[test]</code> and <code>[expected_failure]</code> functions to verify function correctness and handle potential errors during execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Security patch. Fixes <a href="https://github.com/mehvetero/move-test-gen/security/advisories/GHSA-w7pc-q6qh-49qw">GHSA-w7pc-q6qh-49qw</a>, which was declared fixed in v1.5.0 but was not.</p>
<ul>
<li>Assert regex now tolerates parenthesised abort codes and trailing commas</li>
<li>An assert the regex cannot parse is recorded, printed, and <strong>fails</strong> the run instead of vanishing from both sides of the ratio</li>
<li>Zero denominator reports <code>n/a</code> instead of <code>100% (0/0)</code></li>
<li>A sources path with no <code>.move</code> files is a hard failure</li>
</ul>
<p>PR #51 by @HetCreep. Issue #50.</p>
<p><strong>Users on v1.5.0</strong>: this is the patch that makes GHSA-w7pc actually fixed. Please update.</p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/wails3-build-action/</link><pubDate>Sun, 16 Aug 2026 22:00:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building of Wails.io projects using GoLang and NodeJS. It builds a binary for specified platforms, caches the build, and optionally uploads artifacts or publishes releases on tag. The action supports various configurations such as Go version, Wails version, and Node.js/Deno versions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building of Wails.io projects using GoLang and NodeJS. It builds a binary for specified platforms, caches the build, and optionally uploads artifacts or publishes releases on tag. The action supports various configurations such as Go version, Wails version, and Node.js/Deno versions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>darnlink — self-healing Markdown links</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/darnlink-self-healing-markdown-links/</link><pubDate>Sun, 16 Aug 2026 21:59:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/darnlink-self-healing-markdown-links/</guid><description>Version updated for https://github.com/txemi/darnlink to version v0.23.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The darnlink GitHub Action automates the task of automatically healing Markdown links in a documentation folder after refactoring or moving files and folders. It uses deterministic, self-healing logic to ensure that links remain valid even when their targets are relocated or renamed. The action supports both local and cross-repo web links and can be used via the command line with minimal setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/txemi/darnlink">https://github.com/txemi/darnlink</a></strong> to version <strong>v0.23.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/darnlink-self-healing-markdown-links">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>darnlink</code> GitHub Action automates the task of automatically healing Markdown links in a documentation folder after refactoring or moving files and folders. It uses deterministic, self-healing logic to ensure that links remain valid even when their targets are relocated or renamed. The action supports both local and cross-repo web links and can be used via the command line with minimal setup.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="moving-your-pin-two-things-change-neither-is-a-regression">Moving your pin: two things change, neither is a regression</h2>
<p><strong>1. The file count can go DOWN, and that is the fix</strong> (#85). A symlink to a <code>.md</code> <strong>inside</strong> the
scanned root used to be walked as a second document. Measured on a real repo the day this shipped:
<strong>3534 → 3533</strong> files — one symlink that had been indexed twice. Nothing was lost; a duplicate
stopped being counted.</p>
<p><strong>2. A new category appears in the output</strong>, text and JSON alike: <code>[out-of-root-link]</code> /
<code>out_of_root_links</code> (a symlink whose target falls outside the scanned root). It is <strong>informational
and does not move the exit code</strong>. Anyone parsing CLI output line by line should expect it.</p>
<p>Nothing else here changes behaviour for a consumer: #83 (<code>absolute_local_path</code>) is report-only and
deliberately absent from the exit code, and the <code>darnlang</code> bumps only affect this repo&rsquo;s own CI.</p>
<h2 id="what-85-actually-fixes">What #85 actually fixes</h2>
<p>Sharing one instruction file across agents — <code>AGENTS.md</code>, <code>.github/copilot-instructions.md</code> and
<code>CLAUDE.md</code> pointing at a single source, which is standard practice — made the same <code>uuid</code> appear at
three paths, so the integrity check failed with <em>&ldquo;uuid in multiple files&rdquo;</em>. Measured on a real repo
on 2026-08-16, where it turned the gate red and <strong>blocked every push</strong> until the links were reverted.</p>
<p>Files are deduplicated by resolved path now, and the <strong>canonical</strong> path is the one reported. That
second half matters: relative links in a body resolve against the directory of the file they were
read from, so reporting <code>.github/copilot-instructions.md</code> made a body link look broken and <code>repair</code>
wanted to rewrite it. Otherwise walk order would decide which name wins.</p>
<h2 id="-this-release-also-corrects-a-defect-in-v0220s-notes">⚠️ This release also corrects a defect in v0.22.0&rsquo;s notes</h2>
<p>The BOM fix (#68) and the balanced-parentheses fix (#71) were documented under <code>v0.22.0</code> but merged
<strong>hours after that tag was cut</strong> — <code>git tag --contains</code> on either commit returns nothing. If you are
pinned at <code>v0.22.0</code>, you never received them despite the notes saying otherwise. <strong>They ship here.</strong>
Both entries moved to <code>[0.23.0]</code> in the changelog, with a note left behind under <code>[0.22.0]</code> rather
than deleting the claim silently.</p>
<h2 id="the-11-commits">The 11 commits</h2>
<table>
  <thead>
      <tr>
          <th>PR</th>
          <th>What</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>#85</td>
          <td>symlink dedup — the headline</td>
      </tr>
      <tr>
          <td>#84</td>
          <td><code>AGENTS.md</code> / <code>copilot-instructions.md</code> as symlinks (the layout that exposed #85)</td>
      </tr>
      <tr>
          <td>#83</td>
          <td><code>absolute_local_path</code> is a named finding now, not an unchecked blind spot</td>
      </tr>
      <tr>
          <td>#82 #81 #80 #78</td>
          <td><code>darnlang</code> <code>v0.4.0</code> → <code>v0.9.1</code>, baseline reseeded</td>
      </tr>
      <tr>
          <td>#79 #72</td>
          <td>the pin lives in one place; the shipped CI examples had rotted (one was 23 releases stale)</td>
      </tr>
      <tr>
          <td>#76</td>
          <td><code>--write</code> no longer deletes a UTF-8 BOM (#68)</td>
      </tr>
      <tr>
          <td>#75</td>
          <td>balanced parentheses in a destination no longer truncated (#71)</td>
      </tr>
  </tbody>
</table>
<p>Full detail in <a href="https://github.com/txemi/darnlink/blob/v0.23.0/CHANGELOG.md">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>ReactOS-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/reactos-vm/</link><pubDate>Sun, 16 Aug 2026 21:58:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/reactos-vm/</guid><description>Version updated for https://github.com/vmactions/reactos-vm to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the CI testing of ReactOS on various virtual machines (VMs). It addresses the problem of running CI tests across different architectures and operating systems, including ReactOS, which is not officially supported in a straightforward manner by standard CI tools. The action uses AnyVM.org to manage VM images and provides a user-friendly interface for specifying test requirements, such as release and architecture. With the vmactions-ci skill, users can describe their testing needs, and the action will generate a ready-to-commit YAML file for GitHub Actions that automates the setup and execution of CI tests on ReactOS, handling tasks like installing toolchains, syncing source code, and managing environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/reactos-vm">https://github.com/vmactions/reactos-vm</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/reactos-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the CI testing of ReactOS on various virtual machines (VMs). It addresses the problem of running CI tests across different architectures and operating systems, including ReactOS, which is not officially supported in a straightforward manner by standard CI tools. The action uses AnyVM.org to manage VM images and provides a user-friendly interface for specifying test requirements, such as release and architecture. With the vmactions-ci skill, users can describe their testing needs, and the action will generate a ready-to-commit YAML file for GitHub Actions that automates the setup and execution of CI tests on ReactOS, handling tasks like installing toolchains, syncing source code, and managing environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/reactos-vm/commits/v1.0.0">https://github.com/vmactions/reactos-vm/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Ubuntu-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/ubuntu-vm/</link><pubDate>Sun, 16 Aug 2026 21:57:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/ubuntu-vm/</guid><description>Version updated for https://github.com/vmactions/ubuntu-vm to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running continuous integration (CI) tasks on Ubuntu-based virtual machines. It supports various architectures like x86_64, aarch64, riscv64, s390x, and ppc64le, providing flexibility for different environments. The action handles the setup of tools and dependencies, forward secrets and environment variables, and synchronize code between the host and VM. It also supports multiple major versions, with v1 being the recommended version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/ubuntu-vm">https://github.com/vmactions/ubuntu-vm</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ubuntu-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running continuous integration (CI) tasks on Ubuntu-based virtual machines. It supports various architectures like x86_64, aarch64, riscv64, s390x, and ppc64le, providing flexibility for different environments. The action handles the setup of tools and dependencies, forward secrets and environment variables, and synchronize code between the host and VM. It also supports multiple major versions, with <code>v1</code> being the recommended version.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/ubuntu-vm/commits/v1.0.0">https://github.com/vmactions/ubuntu-vm/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Harmans Code Coverage Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/harmans-code-coverage-report/</link><pubDate>Sun, 16 Aug 2026 14:23:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/harmans-code-coverage-report/</guid><description>Version updated for https://github.com/hrgui/lcov-reporter-action to version v0.1.0.
This action is used across all versions by 7 repositories. Action Type This is a Node action using Node version 12.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates a HTML test coverage report for your Jest tests, based on the lcov coverage report generated by your test runner. It automatically comments a pull request with the report, helping developers quickly identify areas of code not covered by tests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hrgui/lcov-reporter-action">https://github.com/hrgui/lcov-reporter-action</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>12</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harman-s-code-coverage-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates a HTML test coverage report for your Jest tests, based on the lcov coverage report generated by your test runner. It automatically comments a pull request with the report, helping developers quickly identify areas of code not covered by tests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: when adding a check-run, need to report a conclusion (4e9b678)</li>
<li>feat: support for reporting coverage as a check-run for fuller detail (ae6159f)</li>
<li>actions.yml change for testing (e274627)</li>
<li>feat: delete previous comments (8c7f043)</li>
<li>chore: repo location for testing (50f4d9b)</li>
<li>v0.2.17 (b786241)</li>
<li>v0.2.17-alpha.5 (05abfce)</li>
<li>Use diff to build coverage (f3494ba)</li>
<li>v0.2.17-alpha.4 (506f94b)</li>
<li>Allow diffing of lcov files (4148348)</li>
</ul>
]]></content:encoded></item><item><title>reflint reference-integrity linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/reflint-reference-integrity-linter/</link><pubDate>Sun, 16 Aug 2026 14:21:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/reflint-reference-integrity-linter/</guid><description>Version updated for https://github.com/hyuga611/reflint to version v0.11.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary reflint is a zero-dependency reference integrity linter for AI agent configuration files, designed to fail PRs when references (like paths or scripts) point at non-existent files. It automates the verification of file existence for AGENTS.md, llms.txt, and CLAUDE.md, providing inline PR annotations and job failures on missing references.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hyuga611/reflint">https://github.com/hyuga611/reflint</a></strong> to version <strong>v0.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/reflint-reference-integrity-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>reflint</code> is a zero-dependency reference integrity linter for AI agent configuration files, designed to fail PRs when references (like paths or scripts) point at non-existent files. It automates the verification of file existence for <code>AGENTS.md</code>, <code>llms.txt</code>, and <code>CLAUDE.md</code>, providing inline PR annotations and job failures on missing references.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>既存の利用者に見える変化がひとつあります: <strong>指摘の件数が減ります。</strong></p>
<p>公開リポジトリ118本（<code>AGENTS.md</code> / <code>CLAUDE.md</code> を持つもの）で新旧を並べて測った結果は
208件 → 185件。消えた23件はすべてノイズで、<strong>新しく増えた指摘は0件</strong>でした。</p>
<p>減った理由は3つです。</p>
<ul>
<li><code>pnpm -r build</code> を「<code>-r</code> というスクリプトが無い」と報告していた。script 種の指摘39件のうち16件がこれ。</li>
<li><code>--code-blocks</code> が、付けても付けなくても同じ結果を返していた。<strong>このリリースで初めて実際に効きます。</strong>
フェンス内も検査したい場合は明示的に付けてください（118本中10本で結果が変わります）。</li>
<li>フェンスの開閉判定が実在の文書でずれ、途中から下を全部「コード内」とみなすことがあった。</li>
</ul>
<p><strong>減ったのか、見ていないのかを混同しないために</strong>、見送った件数を必ず出すようにしました。</p>
<pre tabindex="0"><code>reflint: 2 broken references (3 inside code blocks, not checked — run with --code-blocks)
reflint: all references resolve (1 inside code blocks, not checked — run with --code-blocks)
</code></pre><p><code>--format json</code> にも <code>skipped</code> が入ります（加算のみ・既存フィールドは不変）。</p>
<p>詳細は <a href="https://github.com/hyuga611/reflint/blob/main/CHANGELOG.md">CHANGELOG</a> を参照してください。
0.10.0 のエントリも今回あわせて埋めています。</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hyuga611/reflint/compare/v0.10.0...v0.11.0">https://github.com/hyuga611/reflint/compare/v0.10.0...v0.11.0</a></p>
]]></content:encoded></item><item><title>Validate AI-generated Python</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/validate-ai-generated-python/</link><pubDate>Sun, 16 Aug 2026 14:20:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/validate-ai-generated-python/</guid><description>Version updated for https://github.com/jkanselaar/python-code-validator to version v1.22.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Python code validation and repair, providing comprehensive checks including syntax and lint diagnostics, AST security policy, bandit pass, credential scan, and deterministic repair. It allows users to specify the intended functionality through assertions or doctest lines, ensuring that the code meets its requirements before being executed or repaired. The service runs within a read-only filesystem environment and charges based on usage, with a free tier providing up to 25 static checks per day.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jkanselaar/python-code-validator">https://github.com/jkanselaar/python-code-validator</a></strong> to version <strong>v1.22.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/validate-ai-generated-python">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates Python code validation and repair, providing comprehensive checks including syntax and lint diagnostics, AST security policy, bandit pass, credential scan, and deterministic repair. It allows users to specify the intended functionality through assertions or doctest lines, ensuring that the code meets its requirements before being executed or repaired. The service runs within a read-only filesystem environment and charges based on usage, with a free tier providing up to 25 static checks per day.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>One key per repository instead of one per run: the action keeps its free key in the workflow cache, so the 25 checks a day are a limit the repository can actually reach rather than a counter that restarts every run.</p>
<p>The run now leaves one comment on the pull request, edited in place on later pushes: what was accepted, what was repaired, and what is left of the day&rsquo;s allowance. It needs <code>permissions: pull-requests: write</code>; without it nothing is written and the job is unaffected, and <code>comment: &quot;false&quot;</code> turns it off.</p>
<p><code>validate.py</code> is again the same program the service serves at <code>/v1/client</code>, which also brings <code>--write</code> and the remedy text from a refusal to this copy.</p>
]]></content:encoded></item><item><title>Check Empty Files</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/check-empty-files/</link><pubDate>Sun, 16 Aug 2026 14:19:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/check-empty-files/</guid><description>Version updated for https://github.com/jonathandung/check-empty to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action check-empty automates the task of ensuring that specified files and directories are empty. It efficiently checks files without excessive filesystem stat calls, clearing them effectively if necessary. This tool supports a variety of programming languages and environments, including Python 3.6+, PyPy, and GraalPy, making it suitable for various projects. The action can be used as a CLI, pre-commit hook, or GitHub Action step to enforce empty file requirements in code repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jonathandung/check-empty">https://github.com/jonathandung/check-empty</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/check-empty-files">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>check-empty</code> automates the task of ensuring that specified files and directories are empty. It efficiently checks files without excessive filesystem stat calls, clearing them effectively if necessary. This tool supports a variety of programming languages and environments, including Python 3.6+, PyPy, and GraalPy, making it suitable for various projects. The action can be used as a CLI, pre-commit hook, or GitHub Action step to enforce empty file requirements in code repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jonathandung/check-empty/compare/v0.9.1...v1.0.1">https://github.com/jonathandung/check-empty/compare/v0.9.1...v1.0.1</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/neurolink-ai/</link><pubDate>Sun, 16 Aug 2026 14:17:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v11.0.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that unifies 30+ AI providers and 100+ models under one consistent API. It provides a practical, TypeScript-first way to integrate AI into any application, offering features like single provider switching, built-in tools, enterprise-level features, and intelligent routing. NeuroLink also supports new avatar and music modalities with 12 providers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v11.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>NeuroLink is a universal AI integration platform that unifies 30+ AI providers and 100+ models under one consistent API. It provides a practical, TypeScript-first way to integrate AI into any application, offering features like single provider switching, built-in tools, enterprise-level features, and intelligent routing. NeuroLink also supports new avatar and music modalities with 12 providers.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1100-2026-08-16"><a href="https://github.com/juspay/neurolink/compare/v10.12.9...v11.0.0">11.0.0</a> (2026-08-16)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li><strong>(providers):</strong> NOTE (nominal, no known consumers): the provably-unused
UniversalProviderOptions types and OpenRouterConfig type are removed from
the public type surface. Deliberately not marked with the major-bump
token: an unintended major release is the wrong signal for unused types.</li>
</ul>
<p>Known rides (ledgered follow-ups): 10 export-default sites incl. the
public neurolink.ts default export; stale TypeDoc pages for deleted
symbols; benchmark-provider-performance fan-out 10-&gt;30 without
per-provider try/catch; &ldquo;all providers&rdquo; wrapper message on explicit
single-provider calls; stale Groq default model in catalog; structure
suite&rsquo;s import-text check superseded by the plan-04 descriptor registry.</p>
<p>Verification: full pre-commit gate on every granular commit;
providers-mocked 45/45; provider-structure 2/2; provider-wiring 17/17;
live test:matrix 54P/11F/20S with all 11 failures adjudicated
environmental or pre-existing (billing, local servers, decommissioned
Groq model, pre-existing streaming tool_choice 400s).</p>
<h3 id="features">Features</h3>
<ul>
<li><strong>(providers):</strong>  dead-code purge, tier-A provider fixes, CI safety net (<a href="https://github.com/juspay/neurolink/commit/ec68f0a5803e0a11f03dc9c5885c7bba9faf97bb">ec68f0a</a>)</li>
</ul>
]]></content:encoded></item><item><title>Setup Fortran Compilers</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/setup-fortran-compilers/</link><pubDate>Sun, 16 Aug 2026 14:16:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/setup-fortran-compilers/</guid><description>Version updated for https://github.com/minhqdao/setup-fortran to version v1.9.3.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary minhqdao/setup-fortran is a GitHub Action that automates the setup and testing of Fortran projects across multiple compilers, versions, architectures, and operating systems. It provides reproducible toolchains for GNU, Intel, LLVM, NVIDIA, AMD, Arm, and LFortran on Linux, macOS, and Windows. The action supports various inputs to configure compiler choices, versions, and additional settings like MSYS2 subsystem and disk cleanup for nvfortran.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/minhqdao/setup-fortran">https://github.com/minhqdao/setup-fortran</a></strong> to version <strong>v1.9.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-fortran-compilers">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>minhqdao/setup-fortran</code> is a GitHub Action that automates the setup and testing of Fortran projects across multiple compilers, versions, architectures, and operating systems. It provides reproducible toolchains for GNU, Intel, LLVM, NVIDIA, AMD, Arm, and LFortran on Linux, macOS, and Windows. The action supports various inputs to configure compiler choices, versions, and additional settings like MSYS2 subsystem and disk cleanup for <code>nvfortran</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><input checked="" disabled="" type="checkbox"> Harden security.</li>
<li><input checked="" disabled="" type="checkbox"> Rework CI.</li>
</ul>
]]></content:encoded></item><item><title>Upload to Nexus Mods</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/upload-to-nexus-mods/</link><pubDate>Sun, 16 Aug 2026 14:14:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/upload-to-nexus-mods/</guid><description>Version updated for https://github.com/Nexus-Mods/upload-action to version v1.0.0-beta.9.
This action is used across all versions by 81 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading a new version of a file to NexusMods using their v3 API. It solves the problem of manually managing the upload process through a CI/CD workflow, providing features such as specifying various attributes like display name, description, and category for the uploaded file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nexus-Mods/upload-action">https://github.com/Nexus-Mods/upload-action</a></strong> to version <strong>v1.0.0-beta.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>81</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/upload-to-nexus-mods">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading a new version of a file to NexusMods using their v3 API. It solves the problem of manually managing the upload process through a CI/CD workflow, providing features such as specifying various attributes like display name, description, and category for the uploaded file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: add update_mod_version input parameter by @bengosney in <a href="https://github.com/Nexus-Mods/upload-action/pull/31">https://github.com/Nexus-Mods/upload-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Nexus-Mods/upload-action/compare/v1.0.0-beta.8...v1.0.0-beta.9">https://github.com/Nexus-Mods/upload-action/compare/v1.0.0-beta.8...v1.0.0-beta.9</a></p>
]]></content:encoded></item><item><title>chainsec — dependency chain supply audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/chainsec-dependency-chain-supply-audit/</link><pubDate>Sun, 16 Aug 2026 14:14:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/chainsec-dependency-chain-supply-audit/</guid><description>Version updated for https://github.com/ocku/chainsec to version 0.6.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary chainsec is a dependency chain supply auditing tool that scans Python, JavaScript, and TypeScript projects for malicious code, bad practices, and security vulnerabilities. It uses Tree-sitter to parse source files statically and runs versioned queries against them to detect suspicious constructs like dynamic execution and network access. The tool is safe by default and does not install or execute package code, making it suitable for use as a CI component with documented exit codes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ocku/chainsec">https://github.com/ocku/chainsec</a></strong> to version <strong>0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/chainsec-dependency-chain-supply-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>chainsec</code> is a dependency chain supply auditing tool that scans Python, JavaScript, and TypeScript projects for malicious code, bad practices, and security vulnerabilities. It uses Tree-sitter to parse source files statically and runs versioned queries against them to detect suspicious constructs like dynamic execution and network access. The tool is safe by default and does not install or execute package code, making it suitable for use as a CI component with documented exit codes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Make GitHub Action scan the current project (#12) (42199c4)</li>
<li>Reorganize app core and document control flow (#11) (aff391c)</li>
<li>Release/0.5.2 (#10) (5f13230)</li>
<li>chore: release 0.5.1 — improve human output for scans and diffs (#8) (5131eda)</li>
<li>Simplify architecture diagram in README, bump limits (#7) (01cb5e3)</li>
<li>Harden io-related subsystems, improve rules, rework cli, add diffing (#6) (fedc986)</li>
<li>Release 0.4.0 (#5) (8631275)</li>
<li>chore: update demo (#4) (527dd61)</li>
<li>Release 0.3.0 (#3) (3f6f46c)</li>
<li>Release 0.2.1 (#2) (2ef7230)</li>
</ul>
]]></content:encoded></item><item><title>PyAppify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/pyappify/</link><pubDate>Sun, 16 Aug 2026 14:12:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/pyappify/</guid><description>Version updated for https://github.com/ok-oldking/pyappify-action to version v1.1.0.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PyAppify Action is an automated GitHub action that uses the PyAppify tool to compile and package Python applications into cross-platform, standalone executables directly within a workflow. It simplifies the process of building and distributing Python applications by automating the cloning of PyAppify, updating configuration files, building binaries with Tauri, and packaging them into zipped bundles for each profile defined in pyappify.yml. The action requires a pyappify.yml file and an optional icons directory for custom application icons.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ok-oldking/pyappify-action">https://github.com/ok-oldking/pyappify-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pyappify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The PyAppify Action is an automated GitHub action that uses the PyAppify tool to compile and package Python applications into cross-platform, standalone executables directly within a workflow. It simplifies the process of building and distributing Python applications by automating the cloning of PyAppify, updating configuration files, building binaries with Tauri, and packaging them into zipped bundles for each profile defined in <code>pyappify.yml</code>. The action requires a <code>pyappify.yml</code> file and an optional <code>icons</code> directory for custom application icons.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Your Release Note</p>
]]></content:encoded></item><item><title>Codex Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/codex-reviewer/</link><pubDate>Sun, 16 Aug 2026 14:11:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/codex-reviewer/</guid><description>Version updated for https://github.com/p2achAI/codex-reviewer to version v2.1.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: This GitHub Action automates the process of reviewing pull requests by leveraging AI-powered models like Claude and OpenAI to generate summaries, improve code quality, detect potential bugs, and provide feedback in multiple languages. It centralizes runner permissions and trigger policies through a reusable workflow, supports both single-agent and multilingual reviews, and integrates with ClickUp for spec compliance checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/p2achAI/codex-reviewer">https://github.com/p2achAI/codex-reviewer</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codex-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary</strong>: This GitHub Action automates the process of reviewing pull requests by leveraging AI-powered models like Claude and OpenAI to generate summaries, improve code quality, detect potential bugs, and provide feedback in multiple languages. It centralizes runner permissions and trigger policies through a reusable workflow, supports both single-agent and multilingual reviews, and integrates with ClickUp for spec compliance checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="변경-사항">변경 사항</h2>
<ul>
<li>self-hosted io-light 기반 중앙 reusable review workflow 추가</li>
<li>caller repo의 fork/draft/라벨/concurrency 정책 중앙화</li>
<li>reusable workflow와 nested action의 불변 SHA 실행 경로 적용</li>
<li>GitHub Actions Dependabot 주간 갱신 및 최소 권한 caller 예시 추가</li>
</ul>
]]></content:encoded></item><item><title>Web App Security Skill</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/web-app-security-skill/</link><pubDate>Sun, 16 Aug 2026 14:10:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/web-app-security-skill/</guid><description>Version updated for https://github.com/parousia8888/web-app-security-skill to version v0.5.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates web application security audits by leveraging AI coding agents. It helps identify potential security vulnerabilities in local source files without requiring offensive-security expertise. The action reads project files locally, generates reports with explanations and evidence, and provides reviewable changes to enhance security and test the product’s normal behavior.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/parousia8888/web-app-security-skill">https://github.com/parousia8888/web-app-security-skill</a></strong> to version <strong>v0.5.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/web-app-security-skill">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates web application security audits by leveraging AI coding agents. It helps identify potential security vulnerabilities in local source files without requiring offensive-security expertise. The action reads project files locally, generates reports with explanations and evidence, and provides reviewable changes to enhance security and test the product&rsquo;s normal behavior.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="web-app-security-skill-v053">Web App Security Skill v0.5.3</h1>
<p>Web App Security Skill gives Web builders using AI coding agents a reviewable local security first pass. Run it without installing:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx --yes web-app-security-skill@0.5.3 audit . --fail-on never
</span></span></code></pre></div><p>The report explains each lead in security terms and ordinary language, states what the evidence
does not prove, proposes a change for review, names likely product side effects, and separates
security retesting from normal-behavior testing. The command does not edit the project or contact
a deployment.</p>
<p>v0.5.3 also includes the Claude repository plugin, diff-scoped review, the planted pattern
benchmark and public known limitations. These are bounded first-pass capabilities; they do not
prove that a project is secure or establish production-vulnerability precision or recall.</p>
<hr>
<h2 id="release-identity">Release identity</h2>
<ul>
<li>Version/tag: <code>v0.5.3</code></li>
<li>Source identity: the commit peeled from the SSH-signed annotated tag; the exact commit is recorded
in <code>web-app-security-skill-0.5.3.release.json</code> and the provenance attestation.</li>
<li>Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.</li>
<li>Stable corpus: 20 built-in risk rules, two evidence-integrity rules and eight opt-in external
adapter rules, unchanged from v0.5.2.</li>
</ul>
<p>This file is part of the source commit it describes and therefore does not embed a fabricated self-
referential source SHA. The signed tag, manifest and provenance establish the published source
identity.</p>
<h2 id="distribution">Distribution</h2>
<p>The package named <code>web-app-security-skill</code> publishes the real zero-dependency CLI with both
<code>web-app-security-skill</code> and <code>webapp-security</code> bin names. Its explicit file allowlist contains the
runtime, skill instructions, rules, schemas, references, current limitations and benchmark evidence
while excluding repository tests, launch/adoption notes and engineering plans. An isolated packed
artifact runs <code>version</code> and a real source audit through offline <code>npx</code>.</p>
<p>Claude Code can add this repository as marketplace <code>web-app-security</code> and install plugin
<code>web-app-security-skill</code>. The plugin uses the repository-root <code>SKILL.md</code>; no copied detector or
second skill body exists. Both manifests validate with Claude Code 2.1.284, and an isolated Claude
configuration completes marketplace add, plugin install and plugin listing.</p>
<h2 id="git-diff-source-selection">Git diff source selection</h2>
<p><code>audit &lt;project&gt; --since &lt;ref&gt;</code> resolves the ref to an immutable commit, scans current tracked source
with full file context and retains exact-location findings on added lines. It records but excludes
untracked files. <code>audit &lt;project&gt; --staged</code> exports and scans the Git index, excluding unstaged
working-tree content.</p>
<p>Path-level findings follow materially changed files. Missing-lockfile conclusions remain visible
when a relevant manifest, workspace file or ancestor lockfile changes. Changed-file parse failures
and global traversal incompleteness remain explicit unknown evidence. Pure content-identical renames
do not replay findings.</p>
<p>Diff modes use the built-in adapter only and cannot use baseline/retest comparison. A clean diff
report does not establish whole-repository safety.</p>
<h2 id="ground-truth-pattern-benchmark">Ground-truth pattern benchmark</h2>
<p><code>npm run benchmark:ground-truth</code> regenerates exact JSON and Markdown results from the stable corpus.
The 20 risk contracts produce TP=20, FN=0, TN=20 and FP=0; the two evidence-integrity contracts
produce TP=2, FN=0, TN=2 and FP=0, with no expected-state mismatch. Tests prove that deleting a
positive observation produces an FN and that a safe-neighbour match produces an FP.</p>
<p>These are synthetic planted pattern-contract results. They do not measure production-vulnerability
precision, recall, language coverage, reachability or exploitability. The five-project ordinary-code
review remains separate evidence.</p>
<h2 id="known-limitations-and-deferred-expansion">Known limitations and deferred expansion</h2>
<p><code>KNOWN_LIMITATIONS.md</code> publishes current parser, evidence-state, external-adapter, incremental and
recurring benign-match boundaries. The v0.5.3 architecture decision defers MCP and additional stable
rules. It defines client demand, permission, schema, local transport, distribution and failure tests
for future MCP work, plus fixture, evidence-boundary, false-positive and fail-closed gates for every
future stable rule.</p>
<h2 id="compatibility-and-security-boundary">Compatibility and security boundary</h2>
<ul>
<li>Finding/report v3, persisted-subject comparison and v2 migration semantics remain compatible.</li>
<li>Syntax and external scanner matches remain <code>suspected</code> until independent evidence confirms them.</li>
<li>Missing or failed source evidence remains <code>unknown</code>; unavailable evidence is never a pass.</li>
<li>Passive network defaults, authorization acknowledgements and review-only repair behavior are
unchanged.</li>
<li>This release is not general SAST/DAST coverage, authenticated testing, an MCP service or proof that
a project is secure.</li>
</ul>
<h2 id="release-verification">Release verification</h2>
<p>The release workflow runs <code>npm run check</code>, rebuilds all four release assets twice and compares every
byte, verifies archive structure, checksums, manifest and SPDX SBOM, exercises isolated install and
upgrade, then requests GitHub build provenance before publication.</p>
<p>Verify the signed tag:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>git -c gpg.ssh.allowedSignersFile<span style="color:#f92672">=</span>.github/release-signers verify-tag v0.5.3
</span></span></code></pre></div><p>The published <code>SHA256SUMS</code>, manifest source commit, <code>git rev-parse 'v0.5.3^{}'</code>, GitHub-recorded asset
digests and provenance are verified before immutable asset digests are added to the installer. npm,
verified installation and the mutable <code>v1</code> alias are promoted only after their public consumers pass.</p>
]]></content:encoded></item><item><title>arreglador-imagenes-locales</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/arreglador-imagenes-locales/</link><pubDate>Sun, 16 Aug 2026 14:09:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/arreglador-imagenes-locales/</guid><description>Version updated for https://github.com/piruetasxyz/arreglador-imagenes-locales to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary arreglador-imagenes-locales is a GitHub Action that detects images in markdown files that are not local to the repository, such as external URLs or uploaded images through drag-and-drop. Its purpose is to ensure offline accessibility by reporting and marking any non-local images so they can be uploaded to the repo and referenced with relative paths. The action does not download or fix anything but simply checks for and reports missing files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/piruetasxyz/arreglador-imagenes-locales">https://github.com/piruetasxyz/arreglador-imagenes-locales</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/arreglador-imagenes-locales">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>arreglador-imagenes-locales</code> is a GitHub Action that detects images in markdown files that are not local to the repository, such as external URLs or uploaded images through drag-and-drop. Its purpose is to ensure offline accessibility by reporting and marking any non-local images so they can be uploaded to the repo and referenced with relative paths. The action does not download or fix anything but simply checks for and reports missing files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/piruetasxyz/arreglador-imagenes-locales/commits/v0.1.0">https://github.com/piruetasxyz/arreglador-imagenes-locales/commits/v0.1.0</a></p>
]]></content:encoded></item><item><title>ROE-Lint policy gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/roe-lint-policy-gate/</link><pubDate>Sun, 16 Aug 2026 14:07:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/roe-lint-policy-gate/</guid><description>Version updated for https://github.com/r00tmancer/roelint to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ROE-Lint is a tool that converts an existing Rules of Engagement document into a local policy firewall to prevent out-of-scope commands before any security tool is executed. It provides features such as CIDR and domain scope checks, explicit human approval gates, and detection of unauthorized operations. The action supports importing ROE documents in various formats and outputs the policy in JSON and SARIF format for further analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/r00tmancer/roelint">https://github.com/r00tmancer/roelint</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/roe-lint-policy-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ROE-Lint is a tool that converts an existing Rules of Engagement document into a local policy firewall to prevent out-of-scope commands before any security tool is executed. It provides features such as CIDR and domain scope checks, explicit human approval gates, and detection of unauthorized operations. The action supports importing ROE documents in various formats and outputs the policy in JSON and SARIF format for further analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: ship ROE-Lint v0.1 policy firewall by @r00tmancer in <a href="https://github.com/r00tmancer/roelint/pull/2">https://github.com/r00tmancer/roelint/pull/2</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@r00tmancer made their first contribution in <a href="https://github.com/r00tmancer/roelint/pull/2">https://github.com/r00tmancer/roelint/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/r00tmancer/roelint/commits/v0.1.0">https://github.com/r00tmancer/roelint/commits/v0.1.0</a></p>
]]></content:encoded></item><item><title>docker-hash</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/docker-hash/</link><pubDate>Sun, 16 Aug 2026 14:06:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/docker-hash/</guid><description>Version updated for https://github.com/RemkoMolier/docker-hash to version v0.3.20.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action computes a deterministic SHA-256 hash for a Docker image build based on the Dockerfile content, build arguments, and files referenced by COPY/ADD instructions. It helps in cache-busting, change detection, and ensuring deterministic CI pipelines. The hash changes when the Dockerfile is modified or any file referenced in the build context is altered.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RemkoMolier/docker-hash">https://github.com/RemkoMolier/docker-hash</a></strong> to version <strong>v0.3.20</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-hash">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action computes a deterministic SHA-256 hash for a Docker image build based on the Dockerfile content, build arguments, and files referenced by COPY/ADD instructions. It helps in cache-busting, change detection, and ensuring deterministic CI pipelines. The hash changes when the Dockerfile is modified or any file referenced in the build context is altered.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/kaniko-build-action/</link><pubDate>Sun, 16 Aug 2026 14:05:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting to the log, allowing users to specify the person to greet. It provides an input for specifying the name and outputs the current time when executed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting to the log, allowing users to specify the person to greet. It provides an input for specifying the name and outputs the current time when executed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>NestJS Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/nestjs-doctor/</link><pubDate>Sun, 16 Aug 2026 14:04:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/nestjs-doctor/</guid><description>Version updated for https://github.com/RoloBits/nestjs-doctor to version nestjs-doctor-lsp@4.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, nestjs-doctor, automates the process of diagnosing and fixing NestJS code quality issues. It provides a comprehensive suite of 50 rules across various categories such as security, performance, correctness, architecture, and schema to evaluate and improve code quality in one command. The action outputs a detailed report with actionable diagnostics, including a score summary, source-level diagnostics with code viewer, interactive module graph, traced HTTP endpoints, schema ER diagram, and a custom rule playground. It supports monorepo support and catches AI-generated code anti-patterns. Additionally, it integrates with VS Code as an extension for inline diagnostics and provides GitHub Actions integration to review pull requests and report changes introduced.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RoloBits/nestjs-doctor">https://github.com/RoloBits/nestjs-doctor</a></strong> to version <strong><a href="mailto:nestjs-doctor-lsp@4.0.0">nestjs-doctor-lsp@4.0.0</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nestjs-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <strong>nestjs-doctor</strong>, automates the process of diagnosing and fixing NestJS code quality issues. It provides a comprehensive suite of 50 rules across various categories such as security, performance, correctness, architecture, and schema to evaluate and improve code quality in one command. The action outputs a detailed report with actionable diagnostics, including a score summary, source-level diagnostics with code viewer, interactive module graph, traced HTTP endpoints, schema ER diagram, and a custom rule playground. It supports monorepo support and catches AI-generated code anti-patterns. Additionally, it integrates with VS Code as an extension for inline diagnostics and provides GitHub Actions integration to review pull requests and report changes introduced.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>Updated dependencies [a2bb0dd]
<ul>
<li><a href="mailto:nestjs-doctor@0.8.0">nestjs-doctor@0.8.0</a></li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>Fettle — repository health grade</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/fettle-repository-health-grade/</link><pubDate>Sun, 16 Aug 2026 14:03:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/fettle-repository-health-grade/</guid><description>Version updated for https://github.com/rumankazi/fettle to version v4.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Fettle is an automated tool for assessing the maintenance health of GitHub repositories. It uses five rules, including branch protection, codeowners, dependency updates, open pull request count, and stale pull requests, to generate a letter grade. The tool provides detailed evidence for each rule and supports configurable weights, making it flexible for organizations to tailor its scoring criteria.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rumankazi/fettle">https://github.com/rumankazi/fettle</a></strong> to version <strong>v4.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fettle-repository-health-grade">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Fettle is an automated tool for assessing the maintenance health of GitHub repositories. It uses five rules, including branch protection, codeowners, dependency updates, open pull request count, and stale pull requests, to generate a letter grade. The tool provides detailed evidence for each rule and supports configurable weights, making it flexible for organizations to tailor its scoring criteria.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="400-2026-08-16"><a href="https://github.com/rumankazi/fettle/compare/v3.0.3...v4.0.0">4.0.0</a> (2026-08-16)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li>require Node 22, and run the Action on node24 (<a href="https://github.com/rumankazi/fettle/issues/47">#47</a>)</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li>require Node 22, and run the Action on node24 (<a href="https://github.com/rumankazi/fettle/issues/47">#47</a>) (<a href="https://github.com/rumankazi/fettle/commit/3eb2f052cf6b2438a1a93aac7c97b6e64d212845">3eb2f05</a>)</li>
</ul>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/custom-amazon-bedrock-agent-action/</link><pubDate>Sun, 16 Aug 2026 14:02:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide feedback. It allows customization of the analysis based on specific requirements and integrates with Amazon Bedrock Knowledge Bases for enriched insights. The action is highly flexible, supporting multiple programming languages and integrating seamlessly into the PR process through comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide feedback. It allows customization of the analysis based on specific requirements and integrates with Amazon Bedrock Knowledge Bases for enriched insights. The action is highly flexible, supporting multiple programming languages and integrating seamlessly into the PR process through comments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/sherpa.sh/</link><pubDate>Sun, 16 Aug 2026 14:01:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven GitHub Action that simplifies cloud infrastructure deployment by providing a natural language interface to configure and manage resources. It automates the process of setting up servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more using plain English prompts. Sherpa supports any cloud provider and framework, making it flexible for developers to ship applications seamlessly. The service is open-source and community-driven, offering visibility into how infrastructure is configured.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven GitHub Action that simplifies cloud infrastructure deployment by providing a natural language interface to configure and manage resources. It automates the process of setting up servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more using plain English prompts. Sherpa supports any cloud provider and framework, making it flexible for developers to ship applications seamlessly. The service is open-source and community-driven, offering visibility into how infrastructure is configured.</p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/smyklot/</link><pubDate>Sun, 16 Aug 2026 14:00:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.28.1.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository’s CODEOWNERS file. It supports multiple command formats, including slash commands, mentions, and bare commands, and provides options to control merge methods, use reactions for approval/merge, and perform cleanup tasks. The app also offers emoji feedback for instant visual confirmation and handles comment edits/deletes gracefully.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.28.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository&rsquo;s CODEOWNERS file. It supports multiple command formats, including slash commands, mentions, and bare commands, and provides options to control merge methods, use reactions for approval/merge, and perform cleanup tasks. The app also offers emoji feedback for instant visual confirmation and handles comment edits/deletes gracefully.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1281-2026-08-16"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.28.0...v1.28.1">1.28.1</a> (2026-08-16)</h2>
<h2 id="smyklot-v1281">Smyklot v1.28.1</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.28.1</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>b698ac9fb9eee8e97af4720df05dcb4d91463bd3 chore(release): bump version to 1.28.1</li>
<li>0028002525e76f58ea33b995db77c223838bf832 refactor(panel): float every layer from one place (#217)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sun, 16 Aug 2026 13:59:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Swarm service by running npm ci and npm run bundle commands before pushing to the repository. It focuses on setting up dependencies and bundling JavaScript files, ensuring that the necessary components are in place before deploying the service using Docker Compose or another orchestration tool.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Swarm service by running <code>npm ci</code> and <code>npm run bundle</code> commands before pushing to the repository. It focuses on setting up dependencies and bundling JavaScript files, ensuring that the necessary components are in place before deploying the service using Docker Compose or another orchestration tool.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/ssg-static-site-generator/</link><pubDate>Sun, 16 Aug 2026 13:59:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.37.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website with features such as clean URLs, templates, feeds, search, image processing and native deployment. It works well for blogs and WordPress migrations and can be used to build documentation, company sites, portfolios and landing pages. SSG is opt-in, offering advanced features like WebP conversion and local server functionality.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.37</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website with features such as clean URLs, templates, feeds, search, image processing and native deployment. It works well for blogs and WordPress migrations and can be used to build documentation, company sites, portfolios and landing pages. SSG is opt-in, offering advanced features like WebP conversion and local server functionality.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.37 — paginated category archives, posts_page takes its address, snap stops freezing the engine by @spagu in <a href="https://github.com/spagu/ssg/pull/151">https://github.com/spagu/ssg/pull/151</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.36...v1.8.37">https://github.com/spagu/ssg/compare/v1.8.36...v1.8.37</a></p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/wails3-build-action/</link><pubDate>Sun, 16 Aug 2026 13:58:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the build process for Wails.io v3 projects by installing GoLang and NodeJS, building the project, and optionally uploading artifacts to GitHub. It supports various configurations such as specifying the build name, platform, and obfuscation options. The action can also handle caching of builds, pnpm or node.js version management, and deno compilation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the build process for Wails.io v3 projects by installing GoLang and NodeJS, building the project, and optionally uploading artifacts to GitHub. It supports various configurations such as specifying the build name, platform, and obfuscation options. The action can also handle caching of builds, pnpm or node.js version management, and deno compilation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>MCP Test Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/mcp-test-harness/</link><pubDate>Sun, 16 Aug 2026 13:57:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/mcp-test-harness/</guid><description>Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v5.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The MCP Test Harness is a pytest-style testing framework designed to automate the testing of MCP (Microcontroller Platform) servers. It simplifies the process of creating and running tests for IoT devices, providing robust support across multiple languages including Python, TypeScript, Java, and .NET. The tool helps developers ensure the reliability and correctness of their microcontroller applications by automating functional, integration, and performance tests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaquarkhan/mcp-test-harness">https://github.com/vaquarkhan/mcp-test-harness</a></strong> to version <strong>v5.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-test-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The MCP Test Harness is a pytest-style testing framework designed to automate the testing of MCP (Microcontroller Platform) servers. It simplifies the process of creating and running tests for IoT devices, providing robust support across multiple languages including Python, TypeScript, Java, and .NET. The tool helps developers ensure the reliability and correctness of their microcontroller applications by automating functional, integration, and performance tests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="mcp-test-harness-520">MCP Test Harness 5.2.0</h2>
<p>Core + 25 provider shims aligned for PyPI.</p>
<h3 id="highlights">Highlights</h3>
<ul>
<li>Cyber-security suites A–D, incident E–K, audit verify, load resilience</li>
<li>Agent discoverability (llms.txt, scan-agents) from 5.1.0</li>
<li>Optional packages require <code>mcp-test-harness&gt;=5.2.0</code></li>
</ul>
<p>See CHANGELOG.md for full notes.</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/b.ia-accessibility-checker/</link><pubDate>Sun, 16 Aug 2026 13:55:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines by mapping and measuring WCAG guidelines against defined audiences. It helps companies ensure their products are accessible, focusing on critical audiences to maximize performance and revenue. The action uses AI analysis to provide detailed reports for developers to correct issues.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines by mapping and measuring WCAG guidelines against defined audiences. It helps companies ensure their products are accessible, focusing on critical audiences to maximize performance and revenue. The action uses AI analysis to provide detailed reports for developers to correct issues.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/hol-codex-plugin-scanner/</link><pubDate>Sun, 16 Aug 2026 06:14:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.516.
This action is used across all versions by 13 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The HOL AI Plugin Scanner GitHub Action automates the security, publishability, runtime readiness, and trust signals checks of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports in SARIF format, policy results, and submission metadata while ensuring compliance with the main scanner release train. The action supports multiple execution modes and output formats and can be configured to perform live network probing and upload SARIF reports to GitHub code scanning.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.516</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>13</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The HOL AI Plugin Scanner GitHub Action automates the security, publishability, runtime readiness, and trust signals checks of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports in SARIF format, policy results, and submission metadata while ensuring compliance with the main scanner release train. The action supports multiple execution modes and output formats and can be configured to perform live network probing and upload SARIF reports to GitHub code scanning.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1.2.515...v1.2.516">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1.2.515...v1.2.516</a></p>
]]></content:encoded></item><item><title>Harmans Code Coverage Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/harmans-code-coverage-report/</link><pubDate>Sun, 16 Aug 2026 06:13:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/harmans-code-coverage-report/</guid><description>Version updated for https://github.com/hrgui/lcov-reporter-action to version v0.2.18-alpha.12.
This action is used across all versions by 7 repositories. Action Type This is a Node action using Node version 12.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action generates a HTML coverage report based on the lcov coverage generated by your test runner and comments it into a pull request. It expects the tests to have been run by another action already. The report shows the total coverage percentage, file-wise branch, function, line, and uncovered lines details.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hrgui/lcov-reporter-action">https://github.com/hrgui/lcov-reporter-action</a></strong> to version <strong>v0.2.18-alpha.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>12</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harman-s-code-coverage-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action generates a HTML coverage report based on the lcov coverage generated by your test runner and comments it into a pull request. It expects the tests to have been run by another action already. The report shows the total coverage percentage, file-wise branch, function, line, and uncovered lines details.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>v0.2.18-alpha.12 (9b198cd)</li>
<li>Fix assignment to variable (45cc885)</li>
<li>v0.2.18-alpha.11 (75beb2d)</li>
<li>Fix reference to response (6edf6e7)</li>
<li>v0.2.18-alpha.10 (b7526f1)</li>
<li>Simplify file fetching loop (4c67927)</li>
<li>v0.2.18-alpha.9 (6668b90)</li>
<li>Use different method to fetch files (b8a2437)</li>
<li>v0.2.18-alpha.8 (acb967c)</li>
<li>v0.2.18-alpha.7 (74dd039)</li>
</ul>
]]></content:encoded></item><item><title>Hyperlocalise CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/hyperlocalise-ci/</link><pubDate>Sun, 16 Aug 2026 06:11:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/hyperlocalise-ci/</guid><description>Version updated for https://github.com/hyperlocalise/hyperlocalise to version v1.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of localizing applications using Hyperlocalise, a tool that integrates local-first CLI tools with CI automation and storage adapters. It solves problems related to managing translations within the engineering workflow instead of alongside it. Key capabilities include running localization tasks, evaluating translation quality, syncing with storage, reporting status, and providing workflows for generating localizations and handling CI processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hyperlocalise/hyperlocalise">https://github.com/hyperlocalise/hyperlocalise</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hyperlocalise-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of localizing applications using Hyperlocalise, a tool that integrates local-first CLI tools with CI automation and storage adapters. It solves problems related to managing translations within the engineering workflow instead of alongside it. Key capabilities include running localization tasks, evaluating translation quality, syncing with storage, reporting status, and providing workflows for generating localizations and handling CI processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v190">v1.9.0</h2>
<p><code>run</code> and <code>eval</code> can now use <strong>OpenRouter</strong> and <strong>Vercel AI Gateway</strong> as LLM providers. This release also fails closed on incomplete OpenAI-compatible completions, tightens Crowdin upload/error handling, and speeds up planning, scoring, and several file parsers.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/hyperlocalise/hyperlocalise/compare/v1.8.28...v1.9.0">https://github.com/hyperlocalise/hyperlocalise/compare/v1.8.28...v1.9.0</a></p>
<h3 id="breaking-changes">Breaking changes</h3>
<p>None.</p>
<h3 id="features">Features</h3>
<ul>
<li>Add <strong>Vercel AI Gateway</strong> as an LLM provider for <code>run</code> and <code>eval</code>. Set <code>llm.profiles.&lt;name&gt;.provider</code> to <code>ai_gateway</code> and export <code>AI_GATEWAY_API_KEY</code>. Model IDs such as <code>openai/gpt-5.6-luna</code> pass through to <code>https://ai-gateway.vercel.sh/v1</code>. Image localization stays OpenAI-only. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1848">#1848</a></li>
<li>Add <strong>OpenRouter</strong> as an LLM provider (<code>openrouter</code>). Auth via <code>OPENROUTER_API_KEY</code>; override the base URL with <code>OPENROUTER_BASE_URL</code>. Model IDs pass through unchanged. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1804">#1804</a></li>
</ul>
<h3 id="fixes">Fixes</h3>
<ul>
<li>Reject incomplete or failed OpenAI-compatible completions instead of writing truncated translations. Fail closed on choice-level errors, <code>finish_reason</code> of <code>error</code> / <code>length</code> / <code>content_filter</code>, and <code>tool_calls</code> / <code>function_call</code>. Transient 502/503/504 errors stay retryable. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1810">#1810</a></li>
<li>Send the raw filename in the Crowdin <code>Crowdin-API-FileName</code> header instead of query-escaping it, so names with spaces are not mangled. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1839">#1839</a></li>
<li>Align Crowdin <code>SourceStringsUpload</code> attributes with API v2 (<code>fileId</code>, <code>maxLen</code>, <code>omitempty</code> on optional fields). <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1823">#1823</a></li>
<li>Surface Crowdin 400 error payloads instead of a generic status message, and allow the documented project-level notification roles. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1801">#1801</a></li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>Faster SHA-512 lock fingerprinting during planning (<code>hex.EncodeToString</code> instead of <code>fmt.Sprintf(&quot;%x&quot;)</code>): about <strong>28%</strong> faster on large catalogs, <strong>11%</strong> fewer allocations. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1753">#1753</a></li>
<li>ICU parser plain-text fast path: about <strong>19%</strong> faster and <strong>60%</strong> fewer allocations on keys with no placeholders. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1775">#1775</a></li>
<li>JS/TS locale module parser: about <strong>35%</strong> faster parse and <strong>60%</strong> fewer allocations; marshal about <strong>30%</strong> faster. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1799">#1799</a></li>
<li>Mozilla Fluent parser: about <strong>45%</strong> fewer allocations via capacity hints and indent/comment fast paths. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1786">#1786</a></li>
<li>Zero-allocation brace-placeholder scanner in eval scoring (replaces regex). <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1821">#1821</a></li>
<li>Lower allocation cost when building the selection catalog (pre-sized maps, <code>slices.SortFunc</code>). <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1809">#1809</a></li>
<li>Segment profile validation fast paths and slice capacity hints. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1837">#1837</a></li>
</ul>
<h3 id="tests">Tests</h3>
<ul>
<li>Env loader, CLI telemetry, sync risk detection, SHA-512 fingerprint oracles, and brace-placeholder scanner coverage. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1824">#1824</a> <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1811">#1811</a> <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1788">#1788</a> <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1774">#1774</a> <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1836">#1836</a></li>
<li>Parser coverage for Apple <code>.stringsdict</code>, CSV, Liquid target fallback, Fluent attribute indents, JS/TS locale edges, and the ICU plain-text fast path. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1838">#1838</a> <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1755">#1755</a> <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1802">#1802</a> <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1798">#1798</a> <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1808">#1808</a> <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1784">#1784</a></li>
<li>Incomplete LLM completion and locale-path helper regressions. <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1820">#1820</a></li>
</ul>
<h3 id="maintenance">Maintenance</h3>
<ul>
<li>Bump Go dependencies (OpenAI SDK <code>v3.50.0</code>, WorkOS <code>v10.1.1</code>, OpenTelemetry <code>v1.45.0</code>). <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1751">#1751</a></li>
</ul>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/cibuild-action/</link><pubDate>Sun, 16 Aug 2026 06:10:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.5.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cibuild GitHub Action is designed to streamline iOS and Android CI setup by automating pipeline creation, configuration, and execution. It provides interactive wizards and auto-detection features to simplify setting up CI pipelines with recommended defaults or from existing YAML files. The action supports local development mode and remote runner execution, as well as secret management for secure project configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.5.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The cibuild GitHub Action is designed to streamline iOS and Android CI setup by automating pipeline creation, configuration, and execution. It provides interactive wizards and auto-detection features to simplify setting up CI pipelines with recommended defaults or from existing YAML files. The action supports local development mode and remote runner execution, as well as secret management for secure project configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.5.6</p>
]]></content:encoded></item><item><title>JFrog Boost</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/jfrog-boost/</link><pubDate>Sun, 16 Aug 2026 06:09:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/jfrog-boost/</guid><description>Version updated for https://github.com/jfrog/boost to version v0.11.15.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: Boost is a GitHub Action that automatically saves tokens and optimizes agent output by trimming unnecessary logs. It never trades quality for savings, ensuring agent performance while reducing log noise, thereby improving task efficiency and code readability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jfrog/boost">https://github.com/jfrog/boost</a></strong> to version <strong>v0.11.15</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jfrog-boost">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> Boost is a GitHub Action that automatically saves tokens and optimizes agent output by trimming unnecessary logs. It never trades quality for savings, ensuring agent performance while reducing log noise, thereby improving task efficiency and code readability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.7.23 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/41">https://github.com/jfrog/boost/pull/41</a></li>
<li>Release v0.7.25 by @menachemm-byte in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
<li>docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/47">https://github.com/jfrog/boost/pull/47</a></li>
<li>docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/48">https://github.com/jfrog/boost/pull/48</a></li>
<li>docs(readme): add how-to-use walkthrough GIF above Quick start by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/52">https://github.com/jfrog/boost/pull/52</a></li>
<li>docs(readme): add Boost comparison table by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/53">https://github.com/jfrog/boost/pull/53</a></li>
<li>fix: install.ps1 by @menachemm-byte in <a href="https://github.com/jfrog/boost/pull/54">https://github.com/jfrog/boost/pull/54</a></li>
<li>docs: refresh README badges, install, use cases, and agent guide by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/56">https://github.com/jfrog/boost/pull/56</a></li>
<li>docs(readme): localize repo main page with language selector by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/59">https://github.com/jfrog/boost/pull/59</a></li>
<li>docs: clarify collection scope by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/60">https://github.com/jfrog/boost/pull/60</a></li>
<li>docs: surface JFrog Xray security scanning in README and SECURITY.md by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/61">https://github.com/jfrog/boost/pull/61</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@menachemm-byte made their first contribution in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jfrog/boost/compare/v0.7.23...v0.11.15">https://github.com/jfrog/boost/compare/v0.7.23...v0.11.15</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/neurolink-ai/</link><pubDate>Sun, 16 Aug 2026 06:07:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v10.12.9.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is an AI integration platform that provides a single, consistent interface to connect with 30+ LLM providers and models. It streamlines the process of integrating AI into applications by providing a unified API that handles various tasks such as text generation, avatar creation, and music synthesis. The platform offers robust features like Redis memory for caching and multi-provider failover for enhanced reliability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v10.12.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>NeuroLink is an AI integration platform that provides a single, consistent interface to connect with 30+ LLM providers and models. It streamlines the process of integrating AI into applications by providing a unified API that handles various tasks such as text generation, avatar creation, and music synthesis. The platform offers robust features like Redis memory for caching and multi-provider failover for enhanced reliability.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="10129-2026-08-15"><a href="https://github.com/juspay/neurolink/compare/v10.12.8...v10.12.9">10.12.9</a> (2026-08-15)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(json):</strong>  recover a partial object from truncated structured output (<a href="https://github.com/juspay/neurolink/commit/798e219a384b420e407b7466584f8683f2aea6a1">798e219</a>), closes <a href="https://github.com/juspay/neurolink/issues/635">#635</a></li>
</ul>
]]></content:encoded></item><item><title>Doctoc Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/doctoc-validate/</link><pubDate>Sun, 16 Aug 2026 06:06:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/doctoc-validate/</guid><description>Version updated for https://github.com/kotanys/doctoc-validate-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks if the table of contents (TOC) generated by doctoc is up-to-date with the markdown files in a project, ensuring that TOCs are consistent and accurate. It automatically fails builds if any TOC needs to be regenerated, thus enforcing up-to-date TOCs in CI environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kotanys/doctoc-validate-action">https://github.com/kotanys/doctoc-validate-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/doctoc-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks if the table of contents (TOC) generated by <code>doctoc</code> is up-to-date with the markdown files in a project, ensuring that TOCs are consistent and accurate. It automatically fails builds if any TOC needs to be regenerated, thus enforcing up-to-date TOCs in CI environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release.</p>
<ul>
<li>No colons, spaces, tabs, and newlines in patterns (file names) are allowed.</li>
<li>Manually setting globbing options is not possible (globstar and nullglob are set).</li>
</ul>
]]></content:encoded></item><item><title>AIsbom Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/aisbom-security-scanner/</link><pubDate>Sun, 16 Aug 2026 06:05:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/aisbom-security-scanner/</guid><description>Version updated for https://github.com/Lab700xOrg/aisbom to version v1.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AIsbom is a static analysis tool that detects malware and license risks in AI model files, including Python Pickle bytecode, Keras configurations, GGUF chat templates, ONNX graphs, and SafeTensors / GGUF binary headers. It performs these checks without loading or executing models, ensuring compliance with security standards. The tool can be used as a GitHub Action to scan repositories on every commit and post an idempotent PR comment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lab700xOrg/aisbom">https://github.com/Lab700xOrg/aisbom</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aisbom-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AIsbom is a static analysis tool that detects malware and license risks in AI model files, including Python Pickle bytecode, Keras configurations, GGUF chat templates, ONNX graphs, and SafeTensors / GGUF binary headers. It performs these checks without loading or executing models, ensuring compliance with security standards. The tool can be used as a GitHub Action to scan repositories on every commit and post an idempotent PR comment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AIsbom now scans three more model formats, closes several documented ways of sneaking a malicious pickle past a scanner, and ships a command that lets you check those claims yourself.</p>
<h3 id="three-new-formats-scanned">Three new formats scanned</h3>
<p><strong>Keras</strong> (<code>.keras</code>, <code>.h5</code>, <code>.hdf5</code>) — a <code>Lambda</code> layer stores an arbitrary Python callable in the model config as a marshalled code object, and <code>load_model</code> runs it. Lambda layers and embedded code objects are now flagged CRITICAL. The payload is identified from its header bytes and <strong>never unmarshalled</strong>. Both containers Keras writes are handled — the <code>.keras</code> zip and legacy HDF5 — without adding an HDF5 library to your install.</p>
<p><strong>ONNX</strong> (<code>.onnx</code>) — the protobuf is walked directly; no ONNX runtime is imported and the graph is never executed. Alongside producer, opset, IR version and operator inventory, two signals are surfaced: operators from a non-standard domain, and external-data paths pointing outside the model directory, which turn <code>load_model</code> into an arbitrary-file read. Subgraphs carried by <code>If</code>, <code>Loop</code> and <code>Scan</code> are walked too.</p>
<p><strong>GGUF chat templates</strong> — the embedded Jinja <code>chat_template</code> is extracted into the SBOM component and checked statically for sandbox-escape constructs. The template is <strong>never rendered</strong>, because rendering it is the vulnerability.</p>
<h3 id="pickle-evasions-closed">Pickle evasions closed</h3>
<ul>
<li><strong>Concatenated streams are all walked.</strong> A legacy <code>torch.save</code> file hides its object behind several header pickles, so stopping at the first <code>STOP</code> meant never reaching the payload.</li>
<li><strong>Non-standard containers are flagged.</strong> Packing a model with 7z instead of the ZIP PyTorch expects previously meant the archive was never opened; it now reports <code>CRITICAL (Non-Standard Container: …)</code>. The container is named, not unpacked — no native dependency enters your install.</li>
<li><strong>Broken and truncated streams are scanned, not abandoned.</strong> The pickle VM runs sequentially, so a payload at the front executes before a corrupt tail is ever reached. Damaging a file is no longer a way to hide one.</li>
<li><strong>Files are disassembled before their type is decided.</strong> A printable protocol-0 pickle could previously pass as a text config file and be reported safe.</li>
<li><strong>Indirect-execution gadgets are caught in both modes</strong> — <code>bdb.Bdb.run</code>, the asyncio gadget chain, and the import-mechanism primitives (<code>sys.modules</code>, <code>importlib</code>, <code>runpy</code>, <code>pkgutil</code>, <code>builtins.__import__</code>). Strict mode now judges a global by its <em>resolved</em> module and attribute, so a submodule no longer inherits an allowlisted parent&rsquo;s trust.</li>
<li><strong><code>hf://</code> scans list the new extensions</strong>, so a repo containing a backdoored <code>.keras</code>, <code>.h5</code> or <code>.onnx</code> model no longer resolves to zero artifacts.</li>
</ul>
<h3 id="an-unfinished-scan-is-never-reported-as-a-clean-one">An unfinished scan is never reported as a clean one</h3>
<p>Two new risk levels you may see in output. <code>MEDIUM (Pickle Scan Incomplete)</code> appears when a file is so unusual that the scan reaches its work limit. <code>MEDIUM (Unreadable Pickle Member)</code> appears when an archive member cannot be read at all — a loader that does not verify integrity the way AIsbom does would still run it.</p>
<p>Both exist for the same reason: a scanner that quietly gives up and returns a clean bill is worse than no scanner, because you would act on the clean bill.</p>
<h3 id="new-aisbom-bypass-scorecard">New: <code>aisbom bypass-scorecard</code></h3>
<p>Builds inert replicas of publicly documented scanner-evasion techniques — each traceable to a published CVE or research paper — scans them in both modes, and prints what AIsbom catches and what it misses. Nothing in the corpus is ever executed.</p>
<p><strong>8 of 11 evasion cases are now caught, up from 5 of 11.</strong> The other three are published with the same detail as the wins — what AIsbom actually reports on each, why that reason is the wrong one, and what closing the gap would take:</p>
<ul>
<li><strong><code>shadowpickle-allowlist-overwrite</code></strong> — AIsbom resolves the <code>STACK_GLOBAL</code> pair and sees <code>collections.OrderedDict</code>, which is legitimately allowlisted because real state_dicts are OrderedDicts. Both modes return only <code>MEDIUM (Pickle Present)</code>, the baseline every pickle gets. This is the ceiling on static allowlist analysis: the call is indistinguishable from a legitimate call to an allowlisted global, and closing it needs evidence beyond the resolved name.</li>
<li><strong><code>nullifai-7z-container</code></strong> — reported <code>CRITICAL (Non-Standard Container: 7z)</code>. Right severity, earned from the container rather than the payload, which is never disassembled. Unpacking 7z would put a native dependency in every install to cover one evasion class.</li>
<li><strong><code>cve-2025-1889-nonstandard-extension</code></strong> — the one outright miss. A pickle named <code>config.p</code> is never opened, so the scan reports <code>No AI models found</code> and emits zero artifacts. picklescan closed this in 0.0.22 and AIsbom has not.</li>
</ul>
<p>None of the three is written off. All eleven stay marked as cases a correct scanner should catch, so the gate keeps counting them against us.</p>
<p><code>--check</code> is a release gate and runs in CI on every push. It cannot be satisfied by regenerating the scorecard — improving detection is the only way to raise the floor.</p>
<h3 id="whats-not-changing">What&rsquo;s not changing</h3>
<p>Exit codes, CycloneDX and SPDX output formats, and every existing verdict are unchanged. Verified against the pre-release baseline: no previously-reported risk level moves in either scan mode.</p>
<p>Full details in <a href="https://github.com/Lab700xOrg/aisbom/blob/main/CHANGELOG.md">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>Unity Cloud Build Trigger</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/unity-cloud-build-trigger/</link><pubDate>Sun, 16 Aug 2026 06:04:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/unity-cloud-build-trigger/</guid><description>Version updated for https://github.com/Matuyuhi/unity-cloud-build-action to version v0.4.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action triggers a Unity Cloud Build to build a specified target on a given branch, using API v2 authentication with a service account key. It supports clean builds and platform overrides, and returns the build ID upon success.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Matuyuhi/unity-cloud-build-action">https://github.com/Matuyuhi/unity-cloud-build-action</a></strong> to version <strong>v0.4.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/unity-cloud-build-trigger">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action triggers a Unity Cloud Build to build a specified target on a given branch, using API v2 authentication with a service account key. It supports clean builds and platform overrides, and returns the build ID upon success.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update actions/checkout to v7 for the node24 runtime by @Matuyuhi in <a href="https://github.com/Matuyuhi/unity-cloud-build-action/pull/6">https://github.com/Matuyuhi/unity-cloud-build-action/pull/6</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Matuyuhi/unity-cloud-build-action/compare/v0.4.2...v0.4.3">https://github.com/Matuyuhi/unity-cloud-build-action/compare/v0.4.2...v0.4.3</a></p>
]]></content:encoded></item><item><title>eigenhelm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/eigenhelm/</link><pubDate>Sun, 16 Aug 2026 06:04:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/eigenhelm/</guid><description>Version updated for https://github.com/metacogdev/eigenhelm to version v0.10.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Eigenhelm measures code structure using information theory to evaluate and improve AI-generated code. It helps catch low-quality code before it merges, providing actionable feedback for refactoring and optimization. The action integrates with GitHub workflows to ensure structural quality throughout the development process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/metacogdev/eigenhelm">https://github.com/metacogdev/eigenhelm</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/eigenhelm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Eigenhelm measures code structure using information theory to evaluate and improve AI-generated code. It helps catch low-quality code before it merges, providing actionable feedback for refactoring and optimization. The action integrates with GitHub workflows to ensure structural quality throughout the development process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/metacogdev/eigenhelm/compare/v0.9.0...v0.10.0">https://github.com/metacogdev/eigenhelm/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Upload to Nexus Mods</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/upload-to-nexus-mods/</link><pubDate>Sun, 16 Aug 2026 06:03:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/upload-to-nexus-mods/</guid><description>Version updated for https://github.com/Nexus-Mods/upload-action to version v1.0.0-beta.10.
This action is used across all versions by 81 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading new versions of files to NexusMods using their v3 API. It simplifies the workflow by reducing manual intervention and enabling continuous integration/continuous deployment (CI/CD) pipelines for mod developers. The action supports various configurations such as file name, version number, category, and additional metadata, making it flexible for different use cases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nexus-Mods/upload-action">https://github.com/Nexus-Mods/upload-action</a></strong> to version <strong>v1.0.0-beta.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>81</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/upload-to-nexus-mods">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading new versions of files to NexusMods using their v3 API. It simplifies the workflow by reducing manual intervention and enabling continuous integration/continuous deployment (CI/CD) pipelines for mod developers. The action supports various configurations such as file name, version number, category, and additional metadata, making it flexible for different use cases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: adding the add changelog endpoint to the action by @ashleynexusmods in <a href="https://github.com/Nexus-Mods/upload-action/pull/32">https://github.com/Nexus-Mods/upload-action/pull/32</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Nexus-Mods/upload-action/compare/v1.0.0-beta.9...v1.0.0-beta.10">https://github.com/Nexus-Mods/upload-action/compare/v1.0.0-beta.9...v1.0.0-beta.10</a></p>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/run-aer-tests/</link><pubDate>Sun, 16 Aug 2026 06:02:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.33.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aer GitHub Action runs Apex and Apex unit tests locally on the user’s machine. It provides a local environment to execute code with SOQL, DML, and test data, similar to an org but without the need for an organization or deployment process. The action supports various features of Salesforce Apex such as SObjects, triggers, validation rules, and testing frameworks, and can be used from the CLI, CI/CD pipelines, and integrated with development environments like VS Code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.33</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The aer GitHub Action runs Apex and Apex unit tests locally on the user&rsquo;s machine. It provides a local environment to execute code with SOQL, DML, and test data, similar to an org but without the need for an organization or deployment process. The action supports various features of Salesforce Apex such as SObjects, triggers, validation rules, and testing frameworks, and can be used from the CLI, CI/CD pipelines, and integrated with development environments like VS Code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.33</p>
<ul>
<li>
<p>Strip Relationship Data From Record-Triggered Flow Records</p>
</li>
<li>
<p>Evaluate Unique Field Constraints Against The Whole DML Batch</p>
</li>
<li>
<p>Resolve Flow Constant References In The Interview Runtime</p>
</li>
<li>
<p>Publish The Startup Heartbeat Phase And Counters As One Value</p>
</li>
<li>
<p>Format Decimal Values Per Locale And Condense Runaway Error Messages</p>
</li>
<li>
<p>Convert Flow Datetime Literals To Parseable Apex Expressions</p>
</li>
<li>
<p>Read Auto-Stored Subflow Outputs Through The Subflow Interview</p>
</li>
<li>
<p>Implement Fuzzy Name Matching And Field Diffs For Duplicate Rules</p>
</li>
<li>
<p>Reject Invalid Custom Share Access Levels And Unset Ids On Failed Insert</p>
</li>
<li>
<p>Never Infer An Ownership Or Audit Reference As A Sharing Parent</p>
</li>
<li>
<p>Apply The Sharing Write Check To List Updates</p>
</li>
<li>
<p>Unpack Dec128 Rollup Summary Columns In Aggregate Functions</p>
</li>
<li>
<p>Reset Sharing Mode At The Top-Level Trigger Boundary</p>
</li>
</ul>
]]></content:encoded></item><item><title>Otzaria Plugin Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/otzaria-plugin-validator/</link><pubDate>Sun, 16 Aug 2026 06:01:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/otzaria-plugin-validator/</guid><description>Version updated for https://github.com/Otzaria/otzaria-plugin-validator to version v1.11.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation and publication of Otzaria plugins by performing the following main tasks:
Validates plugin compatibility with Otzaria, identifying issues that need to be addressed. Builds a .otzplugin file from the plugin’s source code, excluding certain files as specified in an .otzignore file (optional). Automatically publishes new versions of the plugin to the Otzaria store once set up with API credentials. The action simplifies the process of releasing plugins by automatically pushing changes to main, ensuring that only valid and compatible versions are published.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Otzaria/otzaria-plugin-validator">https://github.com/Otzaria/otzaria-plugin-validator</a></strong> to version <strong>v1.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/otzaria-plugin-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation and publication of Otzaria plugins by performing the following main tasks:</p>
<ul>
<li>Validates plugin compatibility with Otzaria, identifying issues that need to be addressed.</li>
<li>Builds a <code>.otzplugin</code> file from the plugin&rsquo;s source code, excluding certain files as specified in an <code>.otzignore</code> file (optional).</li>
<li>Automatically publishes new versions of the plugin to the Otzaria store once set up with API credentials.</li>
</ul>
<p>The action simplifies the process of releasing plugins by automatically pushing changes to <code>main</code>, ensuring that only valid and compatible versions are published.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="מה-חדש">מה חדש</h2>
<p><strong>הרצה מקומית בלי לשכפל את המאגר.</strong> נוסף שדה <code>bin</code>, ומכאן שאפשר להריץ את הוולידטור ישירות מתיקיית התוסף:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx --yes github:Otzaria/otzaria-plugin-validator#v1 . --publish false
</span></span></code></pre></div><p><code>npm</code> פותר את התג <code>v1</code> מחדש בכל הרצה ושומר במטמון לפי ה-commit שנפתר ולא לפי שם הספק. לכן כל שחרור מגיע למפתחים מיד בהרצה המקומית הבאה, בלי שיתקינו או יעדכנו דבר — ואי אפשר להיתקע עם וולידטור ישן. נבדק על ענף נייד ועל תג נייד כאחד. נוסף גם <code>files</code>, כך שהחבילה הנמשכת מכילה את קוד הריצה בלבד (<code>action.yml</code> ו-<code>src</code>).</p>
<p><strong>git hook רשמי לאימות לפני קומיט</strong> — תועד ב-README. ה-CI הוא גם שלב הפרסום, וה-hook מקדים את הגילוי מהדחיפה אל הקומיט.</p>
<p><strong>ההבחנה בין כשל אימות לכשל תשתית.</strong> ה-hook נשען על <code>OUTPUT passed=true|false</code> שהוולידטור מדפיס גם בהרצה מקומית, ולא על קוד היציאה של <code>npx</code> — שאינו מבחין בין השניים ומחזיר <code>1</code> גם על תקלות תשתית (למשל <code>UNABLE_TO_GET_ISSUER_CERT_LOCALLY</code> מאחורי proxy ממסר-TLS, שנתקלנו בו בפועל). כך כשל אימות עוצר את הקומיט, וכשל רשת רק מזהיר וממשיך — ה-CI ממילא מאמת בדחיפה. נוסף גם <code>timeout</code>, שכן ברשת גרועה <code>npx</code> עלול להיתקע.</p>
<p><strong>אין שינוי בהתנהגות ה-Action.</strong> <code>action.yml</code> ו-<code>src/index.js</code> לא נגעו; <code>files</code> משפיע על אריזת npm בלבד.</p>
<p><strong>בדיקות:</strong> 32 עוברות. שלושת מסלולי ה-hook נבדקו כפי שהם מתועדים: תוסף תקין <code>0</code>, תוסף פגום <code>1</code>, וולידטור בלתי נגיש <code>0</code> עם המשך הקומיט.</p>
]]></content:encoded></item><item><title>pgrls — Postgres RLS linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/pgrls-postgres-rls-linter/</link><pubDate>Sun, 16 Aug 2026 05:59:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/pgrls-postgres-rls-linter/</guid><description>Version updated for https://github.com/pgrls/pgrls-action to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action pgrls-action automates static analysis of PostgreSQL Row-Level Security (RLS) using the pgrls tool. It checks for policy bugs like broken tenant/per-user scoping and write-side holes, failing builds to prevent deployment of problematic RLS configurations. The action can either lint a live database’s RLS state or serve as a pull-request gate to detect regressions and new issues in the schema without requiring access to a running database or Docker container.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pgrls/pgrls-action">https://github.com/pgrls/pgrls-action</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pgrls-postgres-rls-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>pgrls-action</code> automates static analysis of PostgreSQL Row-Level Security (RLS) using the <code>pgrls</code> tool. It checks for policy bugs like broken tenant/per-user scoping and write-side holes, failing builds to prevent deployment of problematic RLS configurations. The action can either lint a live database&rsquo;s RLS state or serve as a pull-request gate to detect regressions and new issues in the schema without requiring access to a running database or Docker container.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Marketplace and README copy: <strong>19</strong> rules with mechanical auto-fixes, not 20.</p>
<p>The SEC006 auto-fixer was removed in pgrls 0.53.0 — it was provably disjoint from its own rule, so it could never remediate a real finding and instead rewrote <em>clean</em> policies.</p>
<p>Rule count is unchanged at <strong>67</strong>: pgrls 0.54.0 added a <code>verify</code> mode (<code>--mode reachability</code>), not a lint rule. No behaviour change to the action itself; <code>v1</code> has been moved here.</p>
]]></content:encoded></item><item><title>vord Static Analysis</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/vord-static-analysis/</link><pubDate>Sun, 16 Aug 2026 05:58:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/vord-static-analysis/</guid><description>Version updated for https://github.com/pmaojo/vord to version v0.11.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary A static analysis tool in Rust that helps developers ensure their code adheres to a set of rules before it’s committed or pushed. It provides an interactive wizard, CI integration options, and can be used as a Claude Code plugin to enforce coding standards on user input.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pmaojo/vord">https://github.com/pmaojo/vord</a></strong> to version <strong>v0.11.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vord-static-analysis">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>A static analysis tool in Rust that helps developers ensure their code adheres to a set of rules before it&rsquo;s committed or pushed. It provides an interactive wizard, CI integration options, and can be used as a Claude Code plugin to enforce coding standards on user input.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.11.6: activate rust:unchecked-convergence-bool and rust:route-without-test-coverage by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/176">https://github.com/pmaojo/vord/pull/176</a></li>
<li>Release v0.11.6 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/177">https://github.com/pmaojo/vord/pull/177</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.11.5...v0.11.6">https://github.com/pmaojo/vord/compare/v0.11.5...v0.11.6</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.11.6: activate rust:unchecked-convergence-bool and rust:route-without-test-coverage by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/176">https://github.com/pmaojo/vord/pull/176</a></li>
<li>Release v0.11.6 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/177">https://github.com/pmaojo/vord/pull/177</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.11.5...v0.11.6">https://github.com/pmaojo/vord/compare/v0.11.5...v0.11.6</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.11.6: activate rust:unchecked-convergence-bool and rust:route-without-test-coverage by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/176">https://github.com/pmaojo/vord/pull/176</a></li>
<li>Release v0.11.6 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/177">https://github.com/pmaojo/vord/pull/177</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.11.5...v0.11.6">https://github.com/pmaojo/vord/compare/v0.11.5...v0.11.6</a></p>
<h2 id="whats-changed-4">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.11.6: activate rust:unchecked-convergence-bool and rust:route-without-test-coverage by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/176">https://github.com/pmaojo/vord/pull/176</a></li>
<li>Release v0.11.6 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/177">https://github.com/pmaojo/vord/pull/177</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.11.5...v0.11.6">https://github.com/pmaojo/vord/compare/v0.11.5...v0.11.6</a></p>
<h2 id="whats-changed-5">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.11.6: activate rust:unchecked-convergence-bool and rust:route-without-test-coverage by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/176">https://github.com/pmaojo/vord/pull/176</a></li>
<li>Release v0.11.6 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/177">https://github.com/pmaojo/vord/pull/177</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.11.5...v0.11.6">https://github.com/pmaojo/vord/compare/v0.11.5...v0.11.6</a></p>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/raviqqe/muffy/</link><pubDate>Sun, 16 Aug 2026 05:56:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.5.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Muffy is a static website validator that checks the links, markup, and robots.txt of multiple websites. It provides features such as recursive link checking, markup validation for HTML, SVG, and MathML documents, caching with configurable cache ages and stale-while-revalidate periods, concurrency and rate limits, retries with exponential backoff, robots.txt and sitemap support. The action can be used to check a set of websites or an individual website through the command line interface or GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.5.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Muffy is a static website validator that checks the links, markup, and robots.txt of multiple websites. It provides features such as recursive link checking, markup validation for HTML, SVG, and MathML documents, caching with configurable cache ages and stale-while-revalidate periods, concurrency and rate limits, retries with exponential backoff, <code>robots.txt</code> and sitemap support. The action can be used to check a set of websites or an individual website through the command line interface or GitHub Actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>5065dbf4a1e39c36ed6465be7948531d8fe252e2 Bump version (#1270)</li>
<li>15fcae235eaf5e79c2f8109a99e3080463538454 Include content (#1269)</li>
<li>1960f844d31ef6a18121c68e1fc0b222a1dc3e2d Remove done todos (#1268)</li>
<li>324af285c8b8e6fce706e8a1e219b029cbc819fc Refactor inherit modifier (#1267)</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/kaniko-build-action/</link><pubDate>Sun, 16 Aug 2026 05:56:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting to a specified person and logs the current timestamp. It is designed to automate the process of sending greetings in automated workflows, enhancing communication within development teams.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting to a specified person and logs the current timestamp. It is designed to automate the process of sending greetings in automated workflows, enhancing communication within development teams.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/agentauditkit-mcp-security-scan/</link><pubDate>Sun, 16 Aug 2026 05:55:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.79.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit automates security audits of AI agent pipelines by identifying misconfigurations, hardcoded secrets, and other security issues across 10 agent platforms. Unlike hosted scanners, it runs offline and deterministically, ensuring consistent findings without relying on LLMs or external models. Additionally, it provides auditor-ready compliance-evidence packs in SARIF format and PDF reports for multiple security frameworks, helping ensure robust security practices are followed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.79</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit automates security audits of AI agent pipelines by identifying misconfigurations, hardcoded secrets, and other security issues across 10 agent platforms. Unlike hosted scanners, it runs offline and deterministically, ensuring consistent findings without relying on LLMs or external models. Additionally, it provides auditor-ready compliance-evidence packs in SARIF format and PDF reports for multiple security frameworks, helping ensure robust security practices are followed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.79
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.79
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.79</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Pin the Letta CVE chain, and stop backlog rows distorting the published latency by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/602">https://github.com/sattyamjjain/agent-audit-kit/pull/602</a></li>
<li>Make <code>suggest --apply-trivial</code> do what its help text says by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/603">https://github.com/sattyamjjain/agent-audit-kit/pull/603</a></li>
<li>chore(release): v0.3.79 by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/604">https://github.com/sattyamjjain/agent-audit-kit/pull/604</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.78...v0.3.79">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.78...v0.3.79</a></p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/smyklot/</link><pubDate>Sun, 16 Aug 2026 05:54:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.28.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the .github/CODEOWNERS file. It supports multiple command formats, including slash commands, mentions, and bare commands, with options to approve, merge, squash, or rebase PRs. The action also provides reaction-based approval and cleanup capabilities, ensuring smooth and efficient pull request management.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.28.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the <code>.github/CODEOWNERS</code> file. It supports multiple command formats, including slash commands, mentions, and bare commands, with options to approve, merge, squash, or rebase PRs. The action also provides reaction-based approval and cleanup capabilities, ensuring smooth and efficient pull request management.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1280-2026-08-16"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.27.0...v1.28.0">1.28.0</a> (2026-08-16)</h2>
<h2 id="smyklot-v1280">Smyklot v1.28.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.28.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>bc8dcd56b39e72612c49a97a3ad31de83440d211 chore(release): bump version to 1.28.0</li>
<li>88639d1c7a2cd18933d80ba3d5d99a565b82bae3 chore(deps): update dependency yq to v4.53.3 (#214)</li>
<li>baaab9fdcc12786168ee87247fb2e3a0232b5dd1 feat(panel): bring the night sky to life (#216)</li>
<li>ecb01bd6e3f38bcc5759ab061636998c658e6489 feat(panel): give dialogs addresses of their own (#215)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/update-a-config-file-with-values-from-environment/</link><pubDate>Sun, 16 Aug 2026 05:53:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action reads environment variables from your workflow and replaces placeholders in specified configuration files with those values. It helps automate the process of managing dynamic configurations by automatically applying variable substitutions based on environmental settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action reads environment variables from your workflow and replaces placeholders in specified configuration files with those values. It helps automate the process of managing dynamic configurations by automatically applying variable substitutions based on environmental settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sun, 16 Aug 2026 05:53:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by bundling assets and running necessary commands before pushing them to a repository. It ensures that all necessary files, including those in the dist directory, are included in the commit process, facilitating efficient deployment workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by bundling assets and running necessary commands before pushing them to a repository. It ensures that all necessary files, including those in the <code>dist</code> directory, are included in the commit process, facilitating efficient deployment workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/classroom-to-sheets-integration/</link><pubDate>Sun, 16 Aug 2026 05:53:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically sends assignment results from GitHub Classroom to Google Sheets. It helps automate the process of tracking and displaying student submissions in a structured format within Google Sheets. The action requires setting up Google API credentials, creating a shared Google sheet, and configuring secrets for authentication. Users can integrate this action into their GitHub workflows to keep track of submissions efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically sends assignment results from GitHub Classroom to Google Sheets. It helps automate the process of tracking and displaying student submissions in a structured format within Google Sheets. The action requires setting up Google API credentials, creating a shared Google sheet, and configuring secrets for authentication. Users can integrate this action into their GitHub workflows to keep track of submissions efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/wails3-build-action/</link><pubDate>Sun, 16 Aug 2026 05:52:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building and packaging of Wails.io v3 projects. It installs GoLang and NodeJS, builds the application for different platforms, and optionally uploads the results to GitHub or releases on tagged builds. The action provides configuration options for customizing build settings, including Go version, Wails version, binary name, obfuscation, platform, caching, and package upload.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building and packaging of Wails.io v3 projects. It installs GoLang and NodeJS, builds the application for different platforms, and optionally uploads the results to GitHub or releases on tagged builds. The action provides configuration options for customizing build settings, including Go version, Wails version, binary name, obfuscation, platform, caching, and package upload.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>NuGet dependency graph</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/nuget-dependency-graph/</link><pubDate>Sun, 16 Aug 2026 05:51:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/nuget-dependency-graph/</guid><description>Version updated for https://github.com/Tsabo/nugraph-action to version v1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating a NuGet dependency graph from .NET solutions or projects using the nugraph tool. It supports both local and pull request jobs, providing job summaries and customizable output formats like Mermaid diagrams and Graphviz DOT text. The action parses solution files to handle multiple projects and outputs graphs in various formats according to the specified settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tsabo/nugraph-action">https://github.com/Tsabo/nugraph-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nuget-dependency-graph">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating a NuGet dependency graph from .NET solutions or projects using the nugraph tool. It supports both local and pull request jobs, providing job summaries and customizable output formats like Mermaid diagrams and Graphviz DOT text. The action parses solution files to handle multiple projects and outputs graphs in various formats according to the specified settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of the NuGet dependency graph action, wrapping <a href="https://github.com/0xced/nugraph">0xced/nugraph</a> as a reusable composite GitHub Action.</p>
<h2 id="features">Features</h2>
<ul>
<li>Generate a NuGet dependency graph for a single <code>.csproj</code>/<code>.fsproj</code>/<code>.vbproj</code> or an entire <code>.sln</code> (each project in the solution gets its own graph)</li>
<li>Post the graph directly to the job summary as a native Mermaid diagram — no artifact upload required</li>
<li>Optionally write the graph to a file as <code>.svg</code>, <code>.png</code>, <code>.pdf</code>, <code>.jpg</code>, or raw <code>.mmd</code>/<code>.mermaid</code> source</li>
<li>Customize the graph: embedded title, package versions in nodes, layout direction, clickable links on/off</li>
<li>Ignore packages by pattern (e.g. <code>System.*</code>) via a simple newline-separated list</li>
<li>Hide empty graphs for projects with no NuGet dependencies</li>
<li>Works with private NuGet feeds already configured on the runner</li>
<li>Pass any other nugraph flag through <code>extra-args</code></li>
</ul>
<p>See the <a href="../../blob/v1.0.0/README.md">README</a> for full usage and <a href="../../tree/v1.0.0/examples">examples/</a> for ready-to-copy workflows.</p>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Tsabo/nugraph-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">project-path</span>: <span style="color:#ae81ff">./src/MyApp.sln</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/rustscript-action/</link><pubDate>Sun, 16 Aug 2026 05:50:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.3.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is an interpreter for Rust scripts that allows running them without compiling. It provides functionalities such as executing Rust scripts directly, validating scripts without running them, and building native binaries for CPU-heavy scripts. The action supports various commands like interpreting, checking, and running scripts, with options to pass arguments and use shebangs effectively.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.3.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is an interpreter for Rust scripts that allows running them without compiling. It provides functionalities such as executing Rust scripts directly, validating scripts without running them, and building native binaries for CPU-heavy scripts. The action supports various commands like interpreting, checking, and running scripts, with options to pass arguments and use shebangs effectively.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.3.7...v0.3.8">https://github.com/VladasZ/rustscript/compare/v0.3.7...v0.3.8</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/b.ia-accessibility-checker/</link><pubDate>Sun, 16 Aug 2026 05:49:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/16/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks for code in CI/CD pipelines. It allows companies to define audience requirements and use AI to analyze whether their code meets WCAG guidelines, helping ensure their products are accessible to a specific user group. The action provides flexibility by focusing on the accessibility of an audience with higher revenue potential.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks for code in CI/CD pipelines. It allows companies to define audience requirements and use AI to analyze whether their code meets WCAG guidelines, helping ensure their products are accessible to a specific user group. The action provides flexibility by focusing on the accessibility of an audience with higher revenue potential.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>sigilbadges — SVG badges for README (Perl)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sigilbadges-svg-badges-for-readme-perl/</link><pubDate>Sat, 15 Aug 2026 21:48:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sigilbadges-svg-badges-for-readme-perl/</guid><description>Version updated for https://github.com/lucianofedericopereira/sigilbadges to version v0.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action sigilbadges generates SVG badges directly into a README.md file based on comments with specific syntax. It automates the process of creating and inserting badges, such as version numbers, build statuses, test coverage, and more, by leveraging pure Perl logic without external dependencies or binary requirements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lucianofedericopereira/sigilbadges">https://github.com/lucianofedericopereira/sigilbadges</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sigilbadges-svg-badges-for-readme-perl">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action sigilbadges generates SVG badges directly into a <code>README.md</code> file based on comments with specific syntax. It automates the process of creating and inserting badges, such as version numbers, build statuses, test coverage, and more, by leveraging pure Perl logic without external dependencies or binary requirements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fixed <code>badge:</code>/<code>badge-row:</code> markers hard-erroring whenever a file also contained the new <code>pdf-preview</code> sibling&rsquo;s own <code>pdf:</code> / <code>pdf-gallery:</code> markers — same <code>&lt;!--[[ ]]--&gt;</code> bracket-sharing issue already fixed against sigilmd in 0.2.0, now closed for the fourth project in the suite too</p>
]]></content:encoded></item><item><title>sigilmd</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sigilmd/</link><pubDate>Sat, 15 Aug 2026 21:47:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sigilmd/</guid><description>Version updated for https://github.com/lucianofedericopereira/sigilmd to version v0.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The sigilmd GitHub Action automates the process of inserting file contents and config-defined values into a README.md file using marker comments. It is designed to be lightweight, with no external dependencies or complex templating languages, relying solely on Perl’s built-in capabilities. This ensures that the generated content remains consistent and easily updatable in the future, reducing maintenance overhead for project documentation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lucianofedericopereira/sigilmd">https://github.com/lucianofedericopereira/sigilmd</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sigilmd">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The sigilmd GitHub Action automates the process of inserting file contents and config-defined values into a README.md file using marker comments. It is designed to be lightweight, with no external dependencies or complex templating languages, relying solely on Perl&rsquo;s built-in capabilities. This ensures that the generated content remains consistent and easily updatable in the future, reducing maintenance overhead for project documentation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fixed table/reference markers hard-erroring whenever a file also contained the new <code>pdf-preview</code> sibling&rsquo;s own <code>pdf:</code> / <code>pdf-gallery:</code> markers — same <code>&lt;!--[[ ]]--&gt;</code> bracket-sharing issue already fixed for sigilbadges in 0.2.0, now closed for the fourth project in the suite too</p>
]]></content:encoded></item><item><title>treegen2 — File Tree for README (Perl)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/treegen2-file-tree-for-readme-perl/</link><pubDate>Sat, 15 Aug 2026 21:46:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/treegen2-file-tree-for-readme-perl/</guid><description>Version updated for https://github.com/lucianofedericopereira/treegen2 to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, treegen2, automates the creation of file trees in Markdown files by replacing [[]files]] markers with ASCII, SVG, or collapsible HTML content. It is written in pure Perl and maintains compatibility across multiple versions of Perl since 1994. The action ensures that it will continue to function as intended without modifications even after twenty years, providing a reliable CI pipeline tool for generating readable directory structures in Markdown files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lucianofedericopereira/treegen2">https://github.com/lucianofedericopereira/treegen2</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/treegen2-file-tree-for-readme-perl">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, treegen2, automates the creation of file trees in Markdown files by replacing <code>[[]files]]</code> markers with ASCII, SVG, or collapsible HTML content. It is written in pure Perl and maintains compatibility across multiple versions of Perl since 1994. The action ensures that it will continue to function as intended without modifications even after twenty years, providing a reliable CI pipeline tool for generating readable directory structures in Markdown files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="020----august-15-2026">0.2.0 -  August 15, 2026</h2>
<ul>
<li>Fixed four <code>uses: lucianofedericopereira/treegen2@v1</code> pins in the README that never matched any real tag — the actual published tag is <code>v0.1</code>; rewrote the &ldquo;Publishing to Marketplace&rdquo; section to describe the direct-tag-pin flow this project actually uses pre-1.0, instead of a <code>v1.0.0</code> release plus a floating <code>v1</code> alias that was never cut</li>
<li>The README&rsquo;s &ldquo;Read the Docs&rdquo; link is now a proper badge (GitHub logo, <code>for-the-badge</code>, matching sigilbadges/sigilmd) instead of a one-off <code>&lt;h2&gt;</code> link with its own icon asset; the top logo image is now centered and size-capped to match its siblings</li>
<li>The four places the README shows the action&rsquo;s version pin now derive from small snippet files declared in <code>sigilmd.toml</code>, kept in sync by <code>sigilmd</code> itself, instead of four separately hand-maintained copies of the same string</li>
</ul>
]]></content:encoded></item><item><title>Code Audit Studio — AI Pull Request Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/code-audit-studio-ai-pull-request-review/</link><pubDate>Sat, 15 Aug 2026 21:44:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/code-audit-studio-ai-pull-request-review/</guid><description>Version updated for https://github.com/mikailcengizz/code-audit-studio-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action reviews AI-assisted code from pull requests in a repository or organization using Code Audit Studio. It evaluates risks, missing tests, remediation steps, and verification details, providing a report to the job summary and as a Markdown file without modifying the PR. The action is read-only, ensuring no checkout, execution, or interaction with the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikailcengizz/code-audit-studio-action">https://github.com/mikailcengizz/code-audit-studio-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/code-audit-studio-ai-pull-request-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action reviews AI-assisted code from pull requests in a repository or organization using Code Audit Studio. It evaluates risks, missing tests, remediation steps, and verification details, providing a report to the job summary and as a Markdown file without modifying the PR. The action is read-only, ensuring no checkout, execution, or interaction with the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial public release of Code Audit Studio pull-request risk review.</p>
<ul>
<li>Fetches only the current pull request diff with GitHub&rsquo;s runner token.</li>
<li>Sends the bounded diff and minimal pull-request context to Code Audit Studio with a separate analysis token.</li>
<li>Writes a cited Markdown report to the job summary and exposes its file path and highest severity as outputs.</li>
<li>Supports an opt-in severity failure threshold while defaulting to advisory review.</li>
<li>Rejects pull_request_target, unsafe endpoints, redirects, oversized diffs, invalid event context, and inconclusive evidence validation.</li>
<li>Runs as a zero-dependency Node.js 24 Action and performs no checkout, repository code execution, telemetry, or repository writes.</li>
</ul>
<p>Reviewed runtime artifact:</p>
<ul>
<li>dist/index.js size: 16,304 bytes</li>
<li>SHA-256: 35a2a5d742da537fb71d6699dc484f10845951d8e2f408d3588c8adac98c2088</li>
</ul>
]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Sat, 15 Aug 2026 21:43:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.9.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a CI/CD tool specifically designed to automate the execution of automated test suites in ServiceNow environments using various browser configurations and operating system settings. It addresses the need for seamless integration between ServiceNow’s CI/CD features and modern testing frameworks, allowing developers to quickly set up and run functional tests across different environments and devices.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a CI/CD tool specifically designed to automate the execution of automated test suites in ServiceNow environments using various browser configurations and operating system settings. It addresses the need for seamless integration between ServiceNow&rsquo;s CI/CD features and modern testing frameworks, allowing developers to quickly set up and run functional tests across different environments and devices.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.8...1.0.9">https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.8...1.0.9</a></p>
]]></content:encoded></item><item><title>x402 Endpoint Compliance Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/x402-endpoint-compliance-validator/</link><pubDate>Sat, 15 Aug 2026 21:42:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/x402-endpoint-compliance-validator/</guid><description>Version updated for https://github.com/MSSATANASS/x402-endpoint-validator to version v0.4.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action checks x402 endpoints by hitting them with real probes and verifying compliance with the x402 spec. It provides 5 core conformance checks: reachability, manifest format, 402 response conformance, response time (P95), and payment-required behavior. The action supports optional telemetry inputs for additional features like webhooks, trend tracking, and private repo support.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MSSATANASS/x402-endpoint-validator">https://github.com/MSSATANASS/x402-endpoint-validator</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/x402-endpoint-compliance-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action checks x402 endpoints by hitting them with real probes and verifying compliance with the x402 spec. It provides 5 core conformance checks: reachability, manifest format, 402 response conformance, response time (P95), and payment-required behavior. The action supports optional telemetry inputs for additional features like webhooks, trend tracking, and private repo support.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="documentation-cleanupnn--removed-legacy-ownership-support-and-commercial-references-from-the-marketplace-readmen--updated-examples-to-use-mssatanassx402-endpoint-validatorv1n--clarified-optional-telemetry-inputs-and-report-only-authorization-evidencen--no-validator-logic-or-tests-changednnvalidation-82-passed-77-subtests-passed">Documentation cleanup\n\n- Removed legacy ownership, support, and commercial references from the Marketplace README.\n- Updated examples to use MSSATANASS/x402-endpoint-validator@v1.\n- Clarified optional telemetry inputs and report-only authorization evidence.\n- No validator logic or tests changed.\n\nValidation: 82 passed, 77 subtests passed.</h2>
]]></content:encoded></item><item><title>Full-site SEO Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/full-site-seo-audit/</link><pubDate>Sat, 15 Aug 2026 21:41:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/full-site-seo-audit/</guid><description>Version updated for https://github.com/nurkamol/seo-audit to version v1.8.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action checks every page of a site’s sitemap for SEO, metadata, and structured data issues to ensure technical correctness across all pages, including cross-page links, broken links, and performance issues. It provides comprehensive reports in HTML, Markdown, and JSON format, helping users maintain a high level of technical quality on their websites without relying solely on free SEO tools that may overlook certain problems or estimates performance metrics.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nurkamol/seo-audit">https://github.com/nurkamol/seo-audit</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/full-site-seo-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action checks every page of a site&rsquo;s sitemap for SEO, metadata, and structured data issues to ensure technical correctness across all pages, including cross-page links, broken links, and performance issues. It provides comprehensive reports in HTML, Markdown, and JSON format, helping users maintain a high level of technical quality on their websites without relying solely on free SEO tools that may overlook certain problems or estimates performance metrics.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>Two checks on the image <code>title</code> attribute</strong> — <code>img-title-duplicates-alt</code>
and <code>img-title-on-decorative</code>, both notes.</p>
<p>Deliberately <em>not</em> a &ldquo;missing title&rdquo; check, which is what tools normally ship
here. A <code>title</code> is a hover tooltip: invisible on touch, unread by Google, and
W3C guidance discourages putting anything that matters in it. An image without
one has nothing wrong with it, so that check would fire on nearly every image
on nearly every site.</p>
<p>What is worth reporting is when <code>title</code> contradicts something on the same tag.
Repeating <code>alt</code> verbatim adds nothing for a sighted visitor and is read twice
by a screen reader that surfaces both — usually one CMS field populating both
attributes. And a <code>title</code> on an image declared decorative by <code>alt=&quot;&quot;</code> or
<code>role=&quot;presentation&quot;</code> is markup saying &ldquo;ignore this&rdquo; while attaching a tooltip
to it; one of the two statements is wrong.</p>
<p>Verified against wpbeginner.com, which carries a <code>title</code> on 26 of its 117
images: 14 identical to the <code>alt</code>, 6 on decorative images.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Changelog Bot Runner Nyaomaru</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/changelog-bot-runner-nyaomaru/</link><pubDate>Sat, 15 Aug 2026 21:40:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/changelog-bot-runner-nyaomaru/</guid><description>Version updated for https://github.com/nyaomaru/changelog-bot to version v0.6.10.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, @nyaomaru/changelog-bot, automates the process of generating a polished changelog entry from Git history and release notes. It provides automated storytelling by combining commit messages, PR titles, and release notes into human-readable sections. Users can also use OpenAI or Anthropic for tone-aware summaries or rely on robust heuristic fallbacks if AI is down. The action supports CI-native integration through GitHub Actions workflows, works as a reusable workflow, and can open a pull request with the updated changelog, compare links, and release notes already wired up.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nyaomaru/changelog-bot">https://github.com/nyaomaru/changelog-bot</a></strong> to version <strong>v0.6.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/changelog-bot-runner-nyaomaru">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>@nyaomaru/changelog-bot</code>, automates the process of generating a polished changelog entry from Git history and release notes. It provides automated storytelling by combining commit messages, PR titles, and release notes into human-readable sections. Users can also use OpenAI or Anthropic for tone-aware summaries or rely on robust heuristic fallbacks if AI is down. The action supports CI-native integration through GitHub Actions workflows, works as a reusable workflow, and can open a pull request with the updated changelog, compare links, and release notes already wired up.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(changelog): 0.6.9 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/177">https://github.com/nyaomaru/changelog-bot/pull/177</a></li>
<li>refactor: separate category scoring responsibilities by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/178">https://github.com/nyaomaru/changelog-bot/pull/178</a></li>
<li>Release: 0.6.10 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/179">https://github.com/nyaomaru/changelog-bot/pull/179</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nyaomaru/changelog-bot/compare/v0.6.9...v0.6.10">https://github.com/nyaomaru/changelog-bot/compare/v0.6.9...v0.6.10</a></p>
]]></content:encoded></item><item><title>chainsec — dependency chain supply audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/chainsec-dependency-chain-supply-audit/</link><pubDate>Sat, 15 Aug 2026 21:39:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/chainsec-dependency-chain-supply-audit/</guid><description>Version updated for https://github.com/ocku/chainsec to version 0.5.2.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary chainsec is a tool for auditing dependency chains in Python, JavaScript, and TypeScript projects. It discovers dependencies, enriches them with lockfile information, securely acquires verified artifacts, scans sources with versioned Tree-sitter rules, and generates JSON, SARIF, or terminal reports. It can be used as a CI component and offers safe defaults by default, without launching executables or executing package code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ocku/chainsec">https://github.com/ocku/chainsec</a></strong> to version <strong>0.5.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/chainsec-dependency-chain-supply-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>chainsec</code> is a tool for auditing dependency chains in Python, JavaScript, and TypeScript projects. It discovers dependencies, enriches them with lockfile information, securely acquires verified artifacts, scans sources with versioned Tree-sitter rules, and generates JSON, SARIF, or terminal reports. It can be used as a CI component and offers safe defaults by default, without launching executables or executing package code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Release/0.5.2 (#10) (5f13230)</li>
<li>chore: release 0.5.1 — improve human output for scans and diffs (#8) (5131eda)</li>
<li>Simplify architecture diagram in README, bump limits (#7) (01cb5e3)</li>
<li>Harden io-related subsystems, improve rules, rework cli, add diffing (#6) (fedc986)</li>
<li>Release 0.4.0 (#5) (8631275)</li>
<li>chore: update demo (#4) (527dd61)</li>
<li>Release 0.3.0 (#3) (3f6f46c)</li>
<li>Release 0.2.1 (#2) (2ef7230)</li>
<li>Scope CI triggers to main (b646594)</li>
<li>Harden archive extraction checks (faabb7a)</li>
</ul>
]]></content:encoded></item><item><title>Web App Security Skill</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/web-app-security-skill/</link><pubDate>Sat, 15 Aug 2026 21:38:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/web-app-security-skill/</guid><description>Version updated for https://github.com/parousia8888/web-app-security-skill to version v0.5.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of scanning web applications to identify security vulnerabilities using AI coding agents. It helps in auditing, hardening, and retesting projects to ensure that they are secure and compliant with best practices. The action generates detailed reports with risk summaries and explanations, providing insights into potential issues and their impact.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/parousia8888/web-app-security-skill">https://github.com/parousia8888/web-app-security-skill</a></strong> to version <strong>v0.5.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/web-app-security-skill">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of scanning web applications to identify security vulnerabilities using AI coding agents. It helps in auditing, hardening, and retesting projects to ensure that they are secure and compliant with best practices. The action generates detailed reports with risk summaries and explanations, providing insights into potential issues and their impact.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v052-release-evidence">v0.5.2 release evidence</h1>
<p>Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.</p>
<p>Web App Security Skill v0.5.2 is a focused correctness patch over v0.5.1. It repairs report
rendering, pnpm workspace lockfile evidence, nested JavaScript/TypeScript template coverage and
path-only retest evasion without expanding the stable rule boundary or changing evidence states.</p>
<h2 id="release-identity">Release identity</h2>
<ul>
<li>Version/tag: <code>v0.5.2</code></li>
<li>Source identity: the commit peeled from the SSH-signed annotated tag; the exact commit is recorded
in <code>web-app-security-skill-0.5.2.release.json</code> and the provenance attestation.</li>
<li>Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.</li>
<li>Stable corpus: 20 built-in risk rules, two evidence-integrity rules and eight opt-in external
adapter rules, unchanged from v0.5.1.</li>
</ul>
<p>This file is part of the source commit it describes and therefore does not embed a fabricated
self-referential source SHA. The signed tag, manifest and provenance establish the published source
identity.</p>
<h2 id="correctness-fixes">Correctness fixes</h2>
<h3 id="structured-risk-summaries">Structured risk summaries</h3>
<p>The v3 Markdown and HTML renderers now read each state&rsquo;s structured <code>{ total, bySeverity }</code> value.
They omit zero-count states and render both state totals and nonzero severity counts. The report&rsquo;s
first risk summary no longer coerces those objects to <code>[object Object]</code>.</p>
<h3 id="pnpm-workspace-lockfiles">pnpm workspace lockfiles</h3>
<p>The missing-lockfile rule now reads bounded <code>pnpm-workspace.yaml</code> package patterns and recognizes an
applicable ancestor <code>pnpm-lock.yaml</code>. Positive and negative package patterns form an include/exclude
boundary. Unreadable, oversized or unsupported workspace metadata makes the
check incomplete and emits evidence-integrity coverage; it does not produce a confirmed absence.</p>
<p>This parser supports the ordinary string-list form and JSON-compatible inline arrays. It is not a
general YAML implementation. A package excluded from the workspace still needs its own applicable
lockfile.</p>
<h3 id="nested-template-coverage">Nested template coverage</h3>
<p>The bounded JavaScript/TypeScript tokenizer now tracks nested template literals and their
expression depth, including templates inside TSX brace expressions. Template text remains ignored
as data while code inside <code>${...}</code> remains tokenized and scanned. An unterminated template still
produces partial coverage and explicit <code>unknown</code> evidence.</p>
<h3 id="rename-aware-retesting">Rename-aware retesting</h3>
<p>Retesting now derives a path-independent movement fingerprint from rule identity, adapter identity
and normalized evidence. A unique one-to-one match across old and new paths is reported as
<code>unchanged</code> with reason <code>condition_moved</code>. Duplicate or otherwise ambiguous matches remain separate
<code>new</code> and <code>fixed</code> observations so the comparison does not guess.</p>
<h2 id="compatibility-and-security-boundary">Compatibility and security boundary</h2>
<ul>
<li>Finding/report v3, persisted-subject comparison and v2 migration semantics remain compatible.</li>
<li>Syntax and external scanner matches remain <code>suspected</code> until independent evidence confirms them.</li>
<li>Missing or failed source evidence remains <code>unknown</code>; no parser fix turns unavailable evidence into
a pass.</li>
<li>Passive network defaults, authorization acknowledgements and review-only repair behavior are
unchanged.</li>
<li>This release is not general SAST/DAST coverage, authenticated testing or proof that a project is
secure.</li>
</ul>
<h2 id="release-verification">Release verification</h2>
<p>The release workflow runs <code>npm run check</code>, rebuilds all four release assets twice and compares every
byte, verifies archive structure, checksums, manifest and SPDX SBOM, exercises isolated install and
upgrade, then requests GitHub build provenance before publication.</p>
<p>Verify the signed tag:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>git -c gpg.ssh.allowedSignersFile<span style="color:#f92672">=</span>.github/release-signers verify-tag v0.5.2
</span></span></code></pre></div><p>After publication, verify <code>SHA256SUMS</code>, compare the manifest source commit with
<code>git rev-parse 'v0.5.2^{}'</code>, verify provenance, and only then add the immutable asset digests to the
verified installer. The mutable <code>v1</code> alias moves only after the public consumer workflow passes.</p>
]]></content:encoded></item><item><title>action-debian-build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/action-debian-build/</link><pubDate>Sat, 15 Aug 2026 21:37:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/action-debian-build/</guid><description>Version updated for https://github.com/pkghaus/action-debian-build to version v1.0.0.
This action is used across all versions by 6 repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of building Debian packages from a specified upstream git tag and configuration in the debian/ directory. It leverages a reusable workflow to build across multiple Debian suites and architectures, ensuring comprehensive testing and validation of the package. The action helps packaging repositories maintain consistency and reliability by automating the entire packaging pipeline, reducing human error and speeding up the release process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pkghaus/action-debian-build">https://github.com/pkghaus/action-debian-build</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<p>Go to the <a href="https://github.com/marketplace/actions/action-debian-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of building Debian packages from a specified upstream git tag and configuration in the <code>debian/</code> directory. It leverages a reusable workflow to build across multiple Debian suites and architectures, ensuring comprehensive testing and validation of the package. The action helps packaging repositories maintain consistency and reliability by automating the entire packaging pipeline, reducing human error and speeding up the release process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Build a Debian package from an upstream git tag and your own debian/ directory.</p>
<h2 id="what-ships">What ships</h2>
<ul>
<li>Per-suite builder images: <code>ghcr.io/pkghaus/deb-builder:{trixie,testing,unstable}</code>, amd64 + arm64, with SLSA provenance and SBOM attestations</li>
<li>A reusable validation workflow: call <code>pkghaus/action-debian-build/.github/workflows/build.yml@v1</code> and every tag push builds all suites and architectures</li>
<li>Suite-qualified versions from one changelog: <code>X~haus13+1</code> on stable, <code>X~testing1</code> on testing, plain <code>X</code> on unstable, ordered so OS upgrades move packages forward instead of fighting them</li>
<li>Artifacts land in <code>debs/</code> under canonical Debian filenames</li>
<li>Optional archive dispatch: set <code>APT_DISPATCH_TOKEN</code> and a validated tag notifies your APT archive to ingest immediately</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">build</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">pkghaus/action-debian-build/.github/workflows/build.yml@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">secrets</span>: <span style="color:#ae81ff">inherit</span>
</span></span></code></pre></div><p>The packaging repository needs <code>package.conf</code> (<code>UPSTREAM</code> + <code>VERSION</code>) next to its <code>debian/</code> directory. Full documentation in the README.</p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/kaniko-build-action/</link><pubDate>Sat, 15 Aug 2026 21:36:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints a greeting message, either “Hello World” or “Hello [name]”, to the log. It allows for customization by specifying the name of the person to greet and provides an option to return the current timestamp.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints a greeting message, either &ldquo;Hello World&rdquo; or &ldquo;Hello [name]&rdquo;, to the log. It allows for customization by specifying the name of the person to greet and provides an option to return the current timestamp.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>Fettle — repository health grade</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/fettle-repository-health-grade/</link><pubDate>Sat, 15 Aug 2026 21:35:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/fettle-repository-health-grade/</guid><description>Version updated for https://github.com/rumankazi/fettle to version v3.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action, Fettle, automates the maintenance health assessment of GitHub repositories using five standardized rules: branch protection, codeowners, dependency updates, open PR count, and stale PRs. It provides a detailed report with weighted scores and evidence for each rule, helping users understand their repository’s ongoing maintenance status.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rumankazi/fettle">https://github.com/rumankazi/fettle</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fettle-repository-health-grade">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action, Fettle, automates the maintenance health assessment of GitHub repositories using five standardized rules: branch protection, codeowners, dependency updates, open PR count, and stale PRs. It provides a detailed report with weighted scores and evidence for each rule, helping users understand their repository&rsquo;s ongoing maintenance status.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="300-2026-08-15"><a href="https://github.com/rumankazi/fettle/compare/v2.0.2...v3.0.0">3.0.0</a> (2026-08-15)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li><strong>core:</strong> remove both Octokit plugins, leaving two runtime dependencies (<a href="https://github.com/rumankazi/fettle/issues/21">#21</a>)</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li><strong>core:</strong> remove both Octokit plugins, leaving two runtime dependencies (<a href="https://github.com/rumankazi/fettle/issues/21">#21</a>) (<a href="https://github.com/rumankazi/fettle/commit/ba52532b65858b6808bfd5a9d5bda6b66d18390f">ba52532</a>)</li>
</ul>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/agentauditkit-mcp-security-scan/</link><pubDate>Sat, 15 Aug 2026 21:34:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.78.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner designed to audit AI agent pipelines, identifying misconfigurations, hardcoded secrets, tool poisoning, and other vulnerabilities. It runs fully offline and deterministically, producing auditor-ready compliance-evidence packs.
What’s Changed Installation pip:
pip install agent-audit-kit==v0.3.78 Docker:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.78</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit is a security scanner designed to audit AI agent pipelines, identifying misconfigurations, hardcoded secrets, tool poisoning, and other vulnerabilities. It runs fully offline and deterministically, producing auditor-ready compliance-evidence packs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.78
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.78
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.78</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ssrf_patterns: require reachability instead of deciding file-wide by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/596">https://github.com/sattyamjjain/agent-audit-kit/pull/596</a></li>
<li>Correct transport-flip remediation that pointed at fields the MCP spec does not define by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/597">https://github.com/sattyamjjain/agent-audit-kit/pull/597</a></li>
<li>Replace the proximity heuristic for AAK-MCP-STDIO-CMD-INJ-002 with data flow by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/599">https://github.com/sattyamjjain/agent-audit-kit/pull/599</a></li>
<li>Stop the CVE watcher filing CVEs from outside the ecosystem it tracks by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/600">https://github.com/sattyamjjain/agent-audit-kit/pull/600</a></li>
<li>chore(release): v0.3.78 by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/601">https://github.com/sattyamjjain/agent-audit-kit/pull/601</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.77...v0.3.78">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.77...v0.3.78</a></p>
]]></content:encoded></item><item><title>OKF Bundle Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/okf-bundle-validator/</link><pubDate>Sat, 15 Aug 2026 21:33:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/okf-bundle-validator/</guid><description>Version updated for https://github.com/scaccogatto/okf-skills to version okf–v0.7.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation and validation of Open Knowledge Format (OKF) bundles, which are directories of markdown files with YAML frontmatter. It provides tools for producing, maintaining, consuming, validating, and visualizing OKF bundles as a part of Claude Code’s capabilities, driving by the verbatim spec and backed by a deterministic conformance checker, with a self-contained graph renderer. The action supports installation via the Claude Code marketplace or agent skills, and can be used to capture knowledge, validate before committing, and gate in CI.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scaccogatto/okf-skills">https://github.com/scaccogatto/okf-skills</a></strong> to version <strong>okf&ndash;v0.7.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/okf-bundle-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation and validation of Open Knowledge Format (OKF) bundles, which are directories of markdown files with YAML frontmatter. It provides tools for producing, maintaining, consuming, validating, and visualizing OKF bundles as a part of Claude Code&rsquo;s capabilities, driving by the verbatim spec and backed by a deterministic conformance checker, with a self-contained graph renderer. The action supports installation via the Claude Code marketplace or agent skills, and can be used to capture knowledge, validate before committing, and gate in CI.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci: auto-release on version bump by @scaccogatto in <a href="https://github.com/scaccogatto/okf-skills/pull/35">https://github.com/scaccogatto/okf-skills/pull/35</a></li>
<li>ci: require a version bump when shipped code changes by @scaccogatto in <a href="https://github.com/scaccogatto/okf-skills/pull/36">https://github.com/scaccogatto/okf-skills/pull/36</a></li>
<li>ci: make the version-bump gate safe to require by @scaccogatto in <a href="https://github.com/scaccogatto/okf-skills/pull/37">https://github.com/scaccogatto/okf-skills/pull/37</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scaccogatto/okf-skills/compare/okf--v0.7.1...okf--v0.7.2">https://github.com/scaccogatto/okf-skills/compare/okf--v0.7.1...okf--v0.7.2</a></p>
]]></content:encoded></item><item><title>Ephemeral Pages</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/ephemeral-pages/</link><pubDate>Sat, 15 Aug 2026 21:32:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/ephemeral-pages/</guid><description>Version updated for https://github.com/schalkneethling/ephemeral-pages-action to version v1.0.1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Ephemeral Pages Action automates the process of publishing self-contained HTML accessibility reports from pull requests within the same repository and creates or updates a stable comment with their temporary URL on GitHub. It uses OIDC authentication when available, falling back to the anonymous service quota if not. The action compresses reports with Brotli and supports various time-to-live (TTL) options for URLs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/schalkneethling/ephemeral-pages-action">https://github.com/schalkneethling/ephemeral-pages-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ephemeral-pages">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Ephemeral Pages Action automates the process of publishing self-contained HTML accessibility reports from pull requests within the same repository and creates or updates a stable comment with their temporary URL on GitHub. It uses OIDC authentication when available, falling back to the anonymous service quota if not. The action compresses reports with Brotli and supports various time-to-live (TTL) options for URLs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at main -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="dependencies">Dependencies</h3>
<ul>
<li>chore(deps-dev): bump oxlint from 1.76.0 to 1.77.0 by @dependabot[bot] in <a href="https://github.com/schalkneethling/ephemeral-pages-action/pull/19">https://github.com/schalkneethling/ephemeral-pages-action/pull/19</a></li>
<li>chore(deps-dev): bump oxfmt from 0.61.0 to 0.62.0 by @dependabot[bot] in <a href="https://github.com/schalkneethling/ephemeral-pages-action/pull/20">https://github.com/schalkneethling/ephemeral-pages-action/pull/20</a></li>
</ul>
<h3 id="other-changes">Other changes</h3>
<ul>
<li>Explain release environment approval by @schalkneethling in <a href="https://github.com/schalkneethling/ephemeral-pages-action/pull/18">https://github.com/schalkneethling/ephemeral-pages-action/pull/18</a></li>
<li>Prepare v1.0.1 Marketplace release by @schalkneethling in <a href="https://github.com/schalkneethling/ephemeral-pages-action/pull/21">https://github.com/schalkneethling/ephemeral-pages-action/pull/21</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/schalkneethling/ephemeral-pages-action/compare/v1...v1.0.1">https://github.com/schalkneethling/ephemeral-pages-action/compare/v1...v1.0.1</a></p>
]]></content:encoded></item><item><title>EvalRepro compare</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/evalrepro-compare/</link><pubDate>Sat, 15 Aug 2026 21:31:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/evalrepro-compare/</guid><description>Version updated for https://github.com/seva9523/EvalRepro to version v0.1.0a2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary EvalRepro is an open-source tool designed to detect semantic drift in AI evaluation inputs and contracts before changes can affect benchmark results silently. It creates hash-only manifests in isolated environments and compares the evaluation contract rather than relying solely on import success. The action checks various aspects such as task version, adapter parameters, sample coverage, order, and semantic fields, providing verdicts like reproducible, order_drift, or semantic_drift.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seva9523/EvalRepro">https://github.com/seva9523/EvalRepro</a></strong> to version <strong>v0.1.0a2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/evalrepro-compare">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>EvalRepro is an open-source tool designed to detect semantic drift in AI evaluation inputs and contracts before changes can affect benchmark results silently. It creates hash-only manifests in isolated environments and compares the evaluation contract rather than relying solely on import success. The action checks various aspects such as task version, adapter parameters, sample coverage, order, and semantic fields, providing verdicts like <code>reproducible</code>, <code>order_drift</code>, or <code>semantic_drift</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="what-changed">What changed</h2>
<p>EvalRepro now includes a first-party Harvey LAB task-contract adapter for detecting semantic drift across exact tasks, task-prefix selections, or complete local benchmark checkouts.</p>
<h3 id="highlights">Highlights</h3>
<ul>
<li>Deterministic hashing of effective instructions, rubrics, deliverables, unknown fields, document paths, and document contents</li>
<li>Credential-stripped Git provenance and shared-document inventory caching</li>
<li>Hash-only output with optional identifier previews</li>
<li>Path and symlink protections for task, instruction, document-root, and source-file inputs</li>
<li>CLI support for reproducible local comparisons</li>
</ul>
<h3 id="validation">Validation</h3>
<ul>
<li>Python 3.11, 3.12, and 3.13</li>
<li>Ruff format and lint, strict mypy, and distribution builds</li>
<li>72 offline tests with 95.25% branch coverage on Python 3.12</li>
</ul>
<p>Full details: <a href="https://github.com/seva9523/EvalRepro/blob/v0.1.0a2/CHANGELOG.md">CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Medium Recent Articles</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/medium-recent-articles/</link><pubDate>Sat, 15 Aug 2026 21:30:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/medium-recent-articles/</guid><description>Version updated for https://github.com/shahidsha1612/medium-recent-articles to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the display of the latest Medium blog posts on a user’s GitHub profile page and keeps them updated automatically. It simplifies adding recent articles to one’s GitHub README without requiring any coding knowledge or manual updates. The action uses Medium’s API to fetch article data and dynamically generates cards displaying thumbnails, titles, dates, and previews.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shahidsha1612/medium-recent-articles">https://github.com/shahidsha1612/medium-recent-articles</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/medium-recent-articles">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the display of the latest Medium blog posts on a user&rsquo;s GitHub profile page and keeps them updated automatically. It simplifies adding recent articles to one&rsquo;s GitHub README without requiring any coding knowledge or manual updates. The action uses Medium&rsquo;s API to fetch article data and dynamically generates cards displaying thumbnails, titles, dates, and previews.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Add branding metadata required for GitHub Marketplace (1c34764)</li>
<li>Crop thumbnails server-side via Medium&rsquo;s own CDN instead of CSS (a94b116)</li>
<li>Rewrite README without em dashes, add link_titles to beginner guide (7d4cdd9)</li>
<li>Add link_titles option to toggle title hyperlinks (b152855)</li>
<li>Preserve thumbnail aspect ratio instead of forcing a fixed height (4077c11)</li>
<li>Force uniform thumbnail size and document theme/animation behavior (52ba7da)</li>
<li>Render each article as its own separate card table with spacing (96b465b)</li>
<li>Render articles as thumbnail cards instead of a plain link list (29ad15d)</li>
<li>Target node24 runtime to remove Actions deprecation warning (189205c)</li>
<li>Add simple step-by-step guide to README (3d57e29)</li>
</ul>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/smyklot/</link><pubDate>Sat, 15 Aug 2026 21:29:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.24.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges based on CODEOWNERS file permissions. It supports multiple command formats, such as slash commands, mentions, and bare commands, and allows customization through configuration options. The app provides features like reaction-based commands, cleanup, and approval deduplication to enhance the workflow experience for repository maintainers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.24.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges based on CODEOWNERS file permissions. It supports multiple command formats, such as slash commands, mentions, and bare commands, and allows customization through configuration options. The app provides features like reaction-based commands, cleanup, and approval deduplication to enhance the workflow experience for repository maintainers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1240-2026-08-15"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.23.2...v1.24.0">1.24.0</a> (2026-08-15)</h2>
<h2 id="smyklot-v1240">Smyklot v1.24.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.24.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>146386745b7346fcc554f2abf306ab68a4b5a19d chore(release): bump version to 1.24.0</li>
<li>11b12392459b727ba687e9cc45bf5125134aeb8c feat(panel): refuse invitations nobody can use (#203)</li>
<li>a9f4404a16be31163433a45970f1025052ccde79 fix(panel): sign in with a separate OAuth App (#204)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/update-a-config-file-with-values-from-environment/</link><pubDate>Sat, 15 Aug 2026 21:28:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The config-file-from-env GitHub Action replaces placeholders in configuration files with environment variables, making it easier to manage sensitive information securely. This action automates the process of updating configuration settings without hardcoding them in source code, thereby enhancing security and maintainability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>config-file-from-env</code> GitHub Action replaces placeholders in configuration files with environment variables, making it easier to manage sensitive information securely. This action automates the process of updating configuration settings without hardcoding them in source code, thereby enhancing security and maintainability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add support for .env files (e706be3)</li>
<li>chore: More info (d440258)</li>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sat, 15 Aug 2026 21:27:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by executing commands to build and package the application before pushing it. It ensures that all necessary dependencies are installed, bundles the project using npm, and then commits the dist directory containing the compiled files to your repository. This setup helps streamline the deployment process by handling the build and packaging tasks before manual intervention is required.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by executing commands to build and package the application before pushing it. It ensures that all necessary dependencies are installed, bundles the project using npm, and then commits the <code>dist</code> directory containing the compiled files to your repository. This setup helps streamline the deployment process by handling the build and packaging tasks before manual intervention is required.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/ssg-static-site-generator/</link><pubDate>Sat, 15 Aug 2026 21:27:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.35.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It automates tasks such as building, deploying and maintaining websites, including support for multiple themes, templates, image processing and cloud integrations. The main purpose of SSG is to provide a tool for quickly creating and managing modern websites with ease.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.35</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It automates tasks such as building, deploying and maintaining websites, including support for multiple themes, templates, image processing and cloud integrations. The main purpose of SSG is to provide a tool for quickly creating and managing modern websites with ease.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.35 — comments render, the front page is nameable, archives keep their address by @spagu in <a href="https://github.com/spagu/ssg/pull/144">https://github.com/spagu/ssg/pull/144</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.34...v1.8.35">https://github.com/spagu/ssg/compare/v1.8.34...v1.8.35</a></p>
]]></content:encoded></item><item><title>HowFastly</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/howfastly/</link><pubDate>Sat, 15 Aug 2026 21:26:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/howfastly/</guid><description>Version updated for https://github.com/stepbrobd/howfastly to version 2026.815.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action measures a runner’s connection speed to Fastly using binary caching technology, providing detailed throughput and latency data. It supports multiple runners and can be pinned to specific releases or use the latest release by default. The action outputs key performance metrics such as download and upload speeds, latency, and POP information.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stepbrobd/howfastly">https://github.com/stepbrobd/howfastly</a></strong> to version <strong>2026.815.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/howfastly">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action measures a runner&rsquo;s connection speed to Fastly using binary caching technology, providing detailed throughput and latency data. It supports multiple runners and can be pinned to specific releases or use the latest release by default. The action outputs key performance metrics such as download and upload speeds, latency, and POP information.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>flake: bump the inputs group with 2 updates by @dependabot[bot] in <a href="https://github.com/stepbrobd/howfastly/pull/7">https://github.com/stepbrobd/howfastly/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/stepbrobd/howfastly/compare/2026.814.4...2026.815.0">https://github.com/stepbrobd/howfastly/compare/2026.814.4...2026.815.0</a></p>
]]></content:encoded></item><item><title>WeInc Website Builder</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/weinc-website-builder/</link><pubDate>Sat, 15 Aug 2026 21:25:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/weinc-website-builder/</guid><description>Version updated for https://github.com/umairalisadaqat/weinc-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action allows developers to manage WeInc websites using their CI pipelines, automating tasks such as listing and creating projects, clients, pulling site analytics, and inspecting templates and plans. It wraps the WeInc Agency API for seamless integration into workflows, providing clear input and output parameters for easy configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/umairalisadaqat/weinc-action">https://github.com/umairalisadaqat/weinc-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/weinc-website-builder">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action allows developers to manage WeInc websites using their CI pipelines, automating tasks such as listing and creating projects, clients, pulling site analytics, and inspecting templates and plans. It wraps the WeInc Agency API for seamless integration into workflows, providing clear input and output parameters for easy configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release. Composite action wrapping the WeInc Agency API (<a href="https://my.we.inc/api/v1)">https://my.we.inc/api/v1)</a>: list/create/update/delete projects, manage clients, list templates and plans, pull site analytics, list webhooks. MIT licensed.</p>
]]></content:encoded></item><item><title>RISCOS-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/riscos-vm/</link><pubDate>Sat, 15 Aug 2026 21:24:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/riscos-vm/</guid><description>Version updated for https://github.com/vmactions/riscos-vm to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running CI builds in RISCOS. It supports AI-powered workflows to generate GitHub Actions CI files automatically based on user descriptions, simplifying setup and reducing manual effort. The action provides support for specific releases of RISC OS (e.g., version 5.30), using a patched QEMU emulator tailored for Raspberry Pi machines, which runs ARMv7 architecture.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/riscos-vm">https://github.com/vmactions/riscos-vm</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/riscos-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running CI builds in RISCOS. It supports AI-powered workflows to generate GitHub Actions CI files automatically based on user descriptions, simplifying setup and reducing manual effort. The action provides support for specific releases of RISC OS (e.g., version 5.30), using a patched QEMU emulator tailored for Raspberry Pi machines, which runs ARMv7 architecture.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/riscos-vm/commits/v1.0.0">https://github.com/vmactions/riscos-vm/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Sync With ModelScope</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sync-with-modelscope/</link><pubDate>Sat, 15 Aug 2026 21:23:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sync-with-modelscope/</guid><description>Version updated for https://github.com/xiaoyao9184/modelscope-sync-action to version v0.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action modelscope-sync-action is designed to synchronize files from a GitHub repository with ModelScope. It automates the process of creating or updating a ModelScope repository by syncing contents from a specified local path or a GitHub repository. The action supports various configurations such as the type of repo, whether it should be private, and additional options for subdirectory selection, README inclusion, and commit message generation. This tool is particularly useful for developers who need to integrate their GitHub repositories with ModelScope for model and dataset management tasks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/xiaoyao9184/modelscope-sync-action">https://github.com/xiaoyao9184/modelscope-sync-action</a></strong> to version <strong>v0.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sync-with-modelscope">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>modelscope-sync-action</code> is designed to synchronize files from a GitHub repository with ModelScope. It automates the process of creating or updating a ModelScope repository by syncing contents from a specified local path or a GitHub repository. The action supports various configurations such as the type of repo, whether it should be private, and additional options for subdirectory selection, README inclusion, and commit message generation. This tool is particularly useful for developers who need to integrate their GitHub repositories with ModelScope for model and dataset management tasks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Nothing changed, just one more test case was added.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/xiaoyao9184/modelscope-sync-action/compare/v0.0.1...v0.0.2">https://github.com/xiaoyao9184/modelscope-sync-action/compare/v0.0.1...v0.0.2</a></p>
]]></content:encoded></item><item><title>Setup MySQL with Python 2.7</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/setup-mysql-with-python-2.7/</link><pubDate>Sat, 15 Aug 2026 14:16:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/setup-mysql-with-python-2.7/</guid><description>Version updated for https://github.com/griffinkelly/mysql-python to version 0.9.4.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action sets up a MySQL database in Docker, allowing users to customize various options such as character set and collation. It supports specifying different versions of MySQL and databases. The action also provides options for binding host ports and configuring root and user passwords securely through GitHub Actions secrets.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/griffinkelly/mysql-python">https://github.com/griffinkelly/mysql-python</a></strong> to version <strong>0.9.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-mysql-with-python-2-7">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action sets up a MySQL database in Docker, allowing users to customize various options such as character set and collation. It supports specifying different versions of MySQL and databases. The action also provides options for binding host ports and configuring root and user passwords securely through GitHub Actions secrets.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update Dockerfile (88923f6)</li>
<li>Update Dockerfile (958fe5b)</li>
<li>Update Dockerfile (76bb5fc)</li>
<li>Update action.yml (2f7c2ae)</li>
<li>Update entrypoint.sh (149624a)</li>
<li>Update action.yml (76f218b)</li>
<li>Update Dockerfile (94ea8c5)</li>
<li>Improve documentations (700bd56)</li>
<li>Add restart option (c2f734e)</li>
<li>Add test code (82ee48a)</li>
</ul>
]]></content:encoded></item><item><title>slack-build-notifier</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/slack-build-notifier/</link><pubDate>Sat, 15 Aug 2026 14:15:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/slack-build-notifier/</guid><description>Version updated for https://github.com/hennejg/slack-build-notifier to version v1.1.
This action is used across all versions by 25 repositories. Action Type This is a Node action using Node version 12.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the notification of Slack channels when a GitHub Actions workflow job completes with various statuses (success, failure, cancellation). It supports legacy webhook features like setting the author name and emoji, and provides more compact default templates while retaining essential information. The action can also mention users only on failure or specify different channels for incoming webhooks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hennejg/slack-build-notifier">https://github.com/hennejg/slack-build-notifier</a></strong> to version <strong>v1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>25</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>12</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/slack-build-notifier">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action automates the notification of Slack channels when a GitHub Actions workflow job completes with various statuses (success, failure, cancellation). It supports legacy webhook features like setting the author name and emoji, and provides more compact default templates while retaining essential information. The action can also mention users only on failure or specify different channels for incoming webhooks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Remove erroneously committed artifacts (83e0fda)</li>
<li>Build release (10e0389)</li>
<li>Fix channel field (0682480)</li>
<li>Fix typo, Icon (ff6f799)</li>
<li>Merge pull request #1 from hennejg/just_playing_around (6769f45)</li>
<li>Update Branding (22d888f)</li>
<li>Hide more fields by default (7d10d8f)</li>
<li>Simplify template (93ed17e)</li>
<li>Can a default be set using action.yml? (07bf727)</li>
<li>There seems to be no way of accessing the job status (5cedcab)</li>
</ul>
]]></content:encoded></item><item><title>LintLang Agent Config Linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/lintlang-agent-config-linter/</link><pubDate>Sat, 15 Aug 2026 14:15:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/lintlang-agent-config-linter/</guid><description>Version updated for https://github.com/hermes-labs-ai/lintlang to version v0.4.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary LintLang is an AI agent linting tool that statically analyzes natural-language instructions to catch common issues such as ambiguous tool descriptions, missing stop conditions, and conflicting directives. It helps ensure the quality of AI agent instructions before runtime.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hermes-labs-ai/lintlang">https://github.com/hermes-labs-ai/lintlang</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lintlang-agent-config-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>LintLang is an AI agent linting tool that statically analyzes natural-language instructions to catch common issues such as ambiguous tool descriptions, missing stop conditions, and conflicting directives. It helps ensure the quality of AI agent instructions before runtime.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Metadata-only patch: PyPI Homepage and Documentation now point to <a href="https://hermes-labs.ai/lintlang">https://hermes-labs.ai/lintlang</a>. LintLang scan behavior and the GitHub Action interface are unchanged.</p>
]]></content:encoded></item><item><title>Supply Chain Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/supply-chain-guard/</link><pubDate>Sat, 15 Aug 2026 14:14:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/supply-chain-guard/</guid><description>Version updated for https://github.com/homeofe/supply-chain-guard to version v5.26.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action supply-chain-guard is an open-source tool designed to scan project dependencies across various ecosystems (npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions and repositories) for malware, fake AI tool repos, account takeovers, and numerous security threats. It generates CycloneDX SBOMs and SLSA provenance to detect and correlate findings into attack-chain incidents, providing comprehensive supply chain security audits.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/homeofe/supply-chain-guard">https://github.com/homeofe/supply-chain-guard</a></strong> to version <strong>v5.26.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supply-chain-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action supply-chain-guard is an open-source tool designed to scan project dependencies across various ecosystems (npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions and repositories) for malware, fake AI tool repos, account takeovers, and numerous security threats. It generates CycloneDX SBOMs and SLSA provenance to detect and correlate findings into attack-chain incidents, providing comprehensive supply chain security audits.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="5263---2026-08-15">[5.26.3] - 2026-08-15</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>250 package IOCs imported from the GitHub Advisory Database</strong>, 173 of them
corroborated against OSV.dev. All npm. The window is dominated by a single
bulk-publication event: GitHub backfilled 5,249 OpenSSF <code>malicious-packages</code>
records into the advisory database on 2026-08-14, most of them carrying <code>MAL-2025-*</code>
identifiers for packages npm removed long ago. The importer queues the live material
first, so this batch is the still-installable part: a farm of single-version
throwaway publishes (the <code>*-poke*</code> and <code>*-tea</code> name families) plus a set of
version-pinned dependency-confusion lures.</li>
<li><strong>Six atomic indicators for the Vellia / Guangnao / lodash-js npm malware cluster</strong>
(August 2026), extracted by hand from the OpenSSF <code>malicious-packages</code> write-ups
because advisory databases publish package coordinates and nothing else. Three C2
domains: <code>hub[.]client-llm[.]com</code>, the WebSocket command hub that
<code>@guangnao/agent-proxy</code> reconstructs at runtime via XOR and base64 so it never
appears as a plaintext string; <code>analytics[.]baskirill-an[.]workers[.]dev</code>, the
rotatable pool and wallet config endpoint for the <code>@lodash-js/lodash-js</code>
cryptojacker; and <code>registrynpmjs[.]to</code>, a lookalike of <code>registry[.]npmjs[.]org</code> that
<code>@polymarkets/clob-client-v2</code> uses to serve a trojanized <code>inquirer</code> tarball through a
direct dependency URL. Three matching dead-drop paths, including the
<code>@velliajs/discord</code> runtime allow-list. All are single-source (amazon-inspector), so
the feed rows carry confidence 0.85 rather than 1.0.</li>
<li><strong>Two malicious GitHub accounts</strong> behind <code>@velliajs/discord</code>: <code>navaLinh</code>, which hosts
the unpinned private repository the package installs its <code>sysframe</code> dependency from,
and <code>Vellia-Elyvia</code>, which hosts the remote kill-switch that gates the bot at
runtime. Both are attacker-created rather than compromised victims. The
<code>api[.]github[.]com</code> host itself is deliberately not listed, only the attacker&rsquo;s
repository path, so ordinary GitHub API usage is not flagged. The same discipline
applies to the <code>workers[.]dev</code> apex, where only the attacker&rsquo;s specific worker
subdomain is listed.</li>
</ul>
]]></content:encoded></item><item><title>Zyvor QA</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/zyvor-qa/</link><pubDate>Sat, 15 Aug 2026 14:12:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/zyvor-qa/</guid><description>Version updated for https://github.com/hypersdk/ZyAIQAAgent to version v0.5.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the continuous validation of Zyvor’s platform by reading requirements from GitHub, generating Playwright tests, executing them after deployments, detecting regressions, and producing actionable reports. The agent provides a live web console with 20+ QA capabilities, including E2E flow tests, HAR record replay, API contract tests, authentication &amp;amp; session tests, live-data assertions, Core Web Vitals, route sweeps, site audits, network &amp;amp; security probes, load checks, flaky detection, screenshots, and recurring monitors. Optionally, it includes an Ask Zyvor knowledge Q&amp;amp;A feature using LangChain for product docs Q&amp;amp;A within the same console.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hypersdk/ZyAIQAAgent">https://github.com/hypersdk/ZyAIQAAgent</a></strong> to version <strong>v0.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zyvor-qa">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the continuous validation of Zyvor&rsquo;s platform by reading requirements from GitHub, generating Playwright tests, executing them after deployments, detecting regressions, and producing actionable reports. The agent provides a live web console with 20+ QA capabilities, including E2E flow tests, HAR record replay, API contract tests, authentication &amp; session tests, live-data assertions, Core Web Vitals, route sweeps, site audits, network &amp; security probes, load checks, flaky detection, screenshots, and recurring monitors. Optionally, it includes an Ask Zyvor knowledge Q&amp;A feature using LangChain for product docs Q&amp;A within the same console.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Image: <code>ghcr.io/hypersdk/zyaiqaagent:v0.5.1</code></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/hypersdk/zyaiqaagent:v0.5.1
</span></span></code></pre></div><p>macOS desktop app: download the <code>.dmg</code> below (unsigned — right-click → Open on first launch). See <a href="https://github.com/hypersdk/ZyAIQAAgent/blob/main/docs/tutorials/17-desktop-app.md">Tutorial 17</a> and <code>desktop/README.md</code>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hypersdk/ZyAIQAAgent/compare/v0.5.0...v0.5.1">https://github.com/hypersdk/ZyAIQAAgent/compare/v0.5.0...v0.5.1</a></p>
]]></content:encoded></item><item><title>ProofDiff evidence report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/proofdiff-evidence-report/</link><pubDate>Sat, 15 Aug 2026 14:11:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/proofdiff-evidence-report/</guid><description>Version updated for https://github.com/hzw0813/proofdiff to version v0.5.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The ProofDiff action automates the process of creating a deterministic evidence report for every code change in a Git repository. It inspects Git and parses supported source files, but does not execute repository code. The key capabilities include generating a static-only interactive report with detailed changes, verification results, and unverified items. For trusted repositories, it can run repository-defined tests, typechecks, and linters.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hzw0813/proofdiff">https://github.com/hzw0813/proofdiff</a></strong> to version <strong>v0.5.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/proofdiff-evidence-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The ProofDiff action automates the process of creating a deterministic evidence report for every code change in a Git repository. It inspects Git and parses supported source files, but does not execute repository code. The key capabilities include generating a static-only interactive report with detailed changes, verification results, and unverified items. For trusted repositories, it can run repository-defined tests, typechecks, and linters.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Run one-time v0.5.2 release dispatcher by @hzw0813 in <a href="https://github.com/hzw0813/proofdiff/pull/43">https://github.com/hzw0813/proofdiff/pull/43</a></li>
<li>Finalize ProofDiff v0.5.2 post-release docs by @hzw0813 in <a href="https://github.com/hzw0813/proofdiff/pull/44">https://github.com/hzw0813/proofdiff/pull/44</a></li>
<li>Fail closed on repository symlink inputs by @hzw0813 in <a href="https://github.com/hzw0813/proofdiff/pull/45">https://github.com/hzw0813/proofdiff/pull/45</a></li>
<li>Prepare ProofDiff v0.5.3 by @hzw0813 in <a href="https://github.com/hzw0813/proofdiff/pull/46">https://github.com/hzw0813/proofdiff/pull/46</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hzw0813/proofdiff/compare/v0.5.2...v0.5.3">https://github.com/hzw0813/proofdiff/compare/v0.5.2...v0.5.3</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/neurolink-ai/</link><pubDate>Sat, 15 Aug 2026 14:10:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v10.12.5.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that unifies over 30 AI providers and 100 models under one consistent API. It provides a practical, TypeScript-first way to integrate AI into any application, enabling seamless switching between providers with a single parameter change, leveraging built-in tools plus any MCP-compliant tool server, deploying with confidence using enterprise features like Redis memory and multi-provider failover, and optimizing costs automatically with intelligent routing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v10.12.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is a universal AI integration platform that unifies over 30 AI providers and 100 models under one consistent API. It provides a practical, TypeScript-first way to integrate AI into any application, enabling seamless switching between providers with a single parameter change, leveraging built-in tools plus any MCP-compliant tool server, deploying with confidence using enterprise features like Redis memory and multi-provider failover, and optimizing costs automatically with intelligent routing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="10125-2026-08-15"><a href="https://github.com/juspay/neurolink/compare/v10.12.4...v10.12.5">10.12.5</a> (2026-08-15)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(processors):</strong>  bound pptx and opendocument entry decompression (<a href="https://github.com/juspay/neurolink/commit/63773698fd265a5503a0383a1ae919a91a153c5d">6377369</a>)</li>
</ul>
]]></content:encoded></item><item><title>riskratchet</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/riskratchet/</link><pubDate>Sat, 15 Aug 2026 14:09:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/riskratchet/</guid><description>Version updated for https://github.com/KayhanB21/riskratchet-action to version v1.0.10.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a wrapper for the KayhanB21/riskratchet maintainability ratchet tool, which helps automate code health checks by analyzing changes in codebase. It automates the process of identifying potential areas that need attention based on churn metrics and provides insights into code quality and maintainability. The action can be used to integrate riskratchet functionality into GitHub workflows, allowing for continuous monitoring and improvement of codebase health.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/KayhanB21/riskratchet-action">https://github.com/KayhanB21/riskratchet-action</a></strong> to version <strong>v1.0.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/riskratchet">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a wrapper for the KayhanB21/riskratchet maintainability ratchet tool, which helps automate code health checks by analyzing changes in codebase. It automates the process of identifying potential areas that need attention based on churn metrics and provides insights into code quality and maintainability. The action can be used to integrate riskratchet functionality into GitHub workflows, allowing for continuous monitoring and improvement of codebase health.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Delegates to <a href="https://github.com/KayhanB21/riskratchet/releases/tag/v0.3.3"><code>riskratchet@v0.3.3</code></a>.</p>
<p>The floating <code>v1</code> tag has been moved here, so <code>uses: KayhanB21/riskratchet-action@v1</code> now runs 0.3.3.</p>
<h2 id="what-you-get-from-033">What you get from 0.3.3</h2>
<p><strong>An unreadable baseline is no longer a silent pass.</strong> If your <code>.riskratchet.json</code> was corrupt,
truncated, or written by a newer riskratchet, it used to load as <em>zero entries</em> — and an empty
baseline passes every gate. Your Action reported &ldquo;No risk regressions detected&rdquo; and exited 0 while
ratcheting nothing. That is now a hard error (exit 2) with a remediation command, and a baseline from
a newer riskratchet tells you to upgrade rather than to regenerate.</p>
<p>Individually malformed entries still let the run continue, but now warn with a count instead of
vanishing silently.</p>
<p>Also: riskratchet fixed a 7.6-point error in how it measured its own test coverage. That one is
internal — it has no effect on your repository&rsquo;s scores.</p>
<p>Full notes: <a href="https://github.com/KayhanB21/riskratchet/blob/master/CHANGELOG.md">https://github.com/KayhanB21/riskratchet/blob/master/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>datamodel-code-generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/datamodel-code-generator/</link><pubDate>Sat, 15 Aug 2026 14:08:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/datamodel-code-generator/</guid><description>Version updated for https://github.com/koxudaxi/datamodel-code-generator to version 0.73.0.
This action is used across all versions by 3,464 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The datamodel-code-generator GitHub Action automates the process of generating Python data models from various schema formats, including OpenAPI 3, AsyncAPI, JSON Schema, Apache Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, and MCP tool schemas. It can also convert existing Python types (Pydantic, dataclass, TypedDict) to different output types and supports Pydantic v2 and multiple model styles such as Pydantic v2 dataclass, dataclasses, TypedDict, or msgspec. The action handles complex schemas with features like $ref, allOf, oneOf, anyOf, enums, and nested types, ensuring type-safe, validated code output for development environments and type checkers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/koxudaxi/datamodel-code-generator">https://github.com/koxudaxi/datamodel-code-generator</a></strong> to version <strong>0.73.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3,464</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/datamodel-code-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>datamodel-code-generator</code> GitHub Action automates the process of generating Python data models from various schema formats, including OpenAPI 3, AsyncAPI, JSON Schema, Apache Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, and MCP tool schemas. It can also convert existing Python types (Pydantic, dataclass, TypedDict) to different output types and supports Pydantic v2 and multiple model styles such as Pydantic v2 dataclass, dataclasses, TypedDict, or msgspec. The action handles complex schemas with features like <code>$ref</code>, <code>allOf</code>, <code>oneOf</code>, <code>anyOf</code>, enums, and nested types, ensuring type-safe, validated code output for development environments and type checkers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="breaking-changes">Breaking Changes</h2>
<h3 id="error-handling-changes">Error Handling Changes</h3>
<ul>
<li>Additional imports are now validated as Python import paths - Values passed via <code>--additional-imports</code>, the Python config API (<code>GenerateConfig</code>, <code>JSONSchemaParserConfig</code>, etc.), or <code>--extra-template-data</code> must now be dotted sequences of Python identifiers. Previously any value was accepted and split on commas without validation; now inputs that are not valid import paths (e.g. containing newlines, semicolons, or non-identifier syntax) raise an <code>Error</code> and abort generation instead of being emitted into the generated output. Valid dotted paths (optionally whitespace-padded) continue to work unchanged. (#3763)</li>
</ul>
<pre tabindex="0"><code>additional_imports must be a Python import path composed of identifiers: &#39;collections.deque\nINJECTION_MARKER = 1&#39;
</code></pre><h3 id="default-behavior-changes">Default Behavior Changes</h3>
<ul>
<li>Reserved template keys in <code>--extra-template-data</code> now raise an error for built-in templates - When rendering a built-in (project-owned) template, supplying any generator-reserved key through <code>--extra-template-data</code> (or the <code>extra_template_data</code> API argument) now raises an <code>Error</code> and aborts generation instead of injecting the value. The reserved keys are <code>class_body_lines</code>, <code>config_items</code>, <code>schema_runtime_validation</code>, <code>schema_runtime_validation_base_class_name</code>, <code>schema_runtime_validation_use_base</code>, <code>sequence_base_class</code>, <code>sequence_item_type</code>, <code>sequence_slice_type</code>, <code>_safe_config_items</code>, <code>typed_dict_kwargs</code>, and <code>typed_dict_kwargs_suffix</code>. To inject raw code via these keys you must now use a custom root template through <code>--custom-template-dir</code>. (#3765)</li>
<li>Stricter <code>extra_template_data</code> validation - <code>extra_template_data</code> that is not a dictionary, contains non-string keys, or contains duplicate (normalized) keys now raises an <code>Error</code> rather than being silently accepted. (#3765)</li>
</ul>
<h3 id="code-generation-changes">Code Generation Changes</h3>
<ul>
<li>Built-in templates now serialize <code>extra_template_data</code> values as non-executing literals - For built-in templates, user-supplied values that were previously emitted as raw Python source are now serialized as quoted, non-executing literals. This affects GraphQL scalar <code>py_type</code>, TypedDict <code>additionalPropertiesType</code>, <code>ConfigDict</code> values, msgspec <code>base_class_kwargs</code>, and comments. Only bare or dotted identifiers (e.g. <code>datetime.date</code>) are still emitted unquoted; more complex expressions become string literals. For example, a scalar <code>py_type</code> supplied as a type expression is now rendered as:</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-python" data-lang="python"><span style="display:flex;"><span>Evil <span style="color:#f92672">=</span> TypeAliasType(<span style="color:#e6db74">&#34;Evil&#34;</span>, <span style="color:#e6db74">&#34;__import__(&#39;os&#39;).system(&#39;id&#39;) or str&#34;</span>)
</span></span></code></pre></div><p>Trusted custom root templates (<code>--custom-template-dir</code> providing the root template) keep the previous unrestricted raw behavior. (#3765)</p>
<ul>
<li>Include-only custom template directories no longer receive raw built-in context - &ldquo;Custom root&rdquo; detection changed from <code>template_file_path.is_absolute()</code> to <code>_uses_custom_root_template</code>. A <code>--custom-template-dir</code> that only supplies include/partial templates (not the model&rsquo;s root template) no longer opts the built-in root into the unrestricted raw-context path; its <code>extra_template_data</code> is now treated with the hardened built-in rules (and reserved keys raise an error). (#3765)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update CHANGELOG for 0.72.4 by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3736">https://github.com/koxudaxi/datamodel-code-generator/pull/3736</a></li>
<li>Update release benchmark data by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3737">https://github.com/koxudaxi/datamodel-code-generator/pull/3737</a></li>
<li>Guard refactor contracts by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3739">https://github.com/koxudaxi/datamodel-code-generator/pull/3739</a></li>
<li>Tighten generation types by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3740">https://github.com/koxudaxi/datamodel-code-generator/pull/3740</a></li>
<li>Simplify generation dispatch by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3741">https://github.com/koxudaxi/datamodel-code-generator/pull/3741</a></li>
<li>Simplify parser metadata flow by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3742">https://github.com/koxudaxi/datamodel-code-generator/pull/3742</a></li>
<li>Optimize built-in generation performance by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3738">https://github.com/koxudaxi/datamodel-code-generator/pull/3738</a></li>
<li>Optimize simple field construction by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3754">https://github.com/koxudaxi/datamodel-code-generator/pull/3754</a></li>
<li>Optimize msgspec unset field rendering by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3755">https://github.com/koxudaxi/datamodel-code-generator/pull/3755</a></li>
<li>Optimize false reference handling by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3750">https://github.com/koxudaxi/datamodel-code-generator/pull/3750</a></li>
<li>Compile built-in templates by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3757">https://github.com/koxudaxi/datamodel-code-generator/pull/3757</a></li>
<li>Optimize Pydantic field name resolution by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3758">https://github.com/koxudaxi/datamodel-code-generator/pull/3758</a></li>
<li>Avoid Jinja in the playground runtime by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3759">https://github.com/koxudaxi/datamodel-code-generator/pull/3759</a></li>
<li>Fix main lint workflow by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3761">https://github.com/koxudaxi/datamodel-code-generator/pull/3761</a></li>
<li>Bump the github-actions group with 5 updates by @dependabot[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3751">https://github.com/koxudaxi/datamodel-code-generator/pull/3751</a></li>
<li>Fix payload runtime validation exclusions by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3764">https://github.com/koxudaxi/datamodel-code-generator/pull/3764</a></li>
<li>Validate additional import paths by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3763">https://github.com/koxudaxi/datamodel-code-generator/pull/3763</a></li>
<li>Harden built-in template data by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3765">https://github.com/koxudaxi/datamodel-code-generator/pull/3765</a></li>
<li>Restrict template source paths by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3766">https://github.com/koxudaxi/datamodel-code-generator/pull/3766</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/koxudaxi/datamodel-code-generator/compare/0.72.4...0.73.0">https://github.com/koxudaxi/datamodel-code-generator/compare/0.72.4...0.73.0</a></p>
]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Sat, 15 Aug 2026 14:07:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.14.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates running automated test suites in ServiceNow CI/CD pipelines by setting up necessary credentials, instance URLs, app identifiers, and test suite details. It supports configuring browser environments and operating systems to run tests according to specified criteria. The action is useful for DevOps teams looking to integrate automated testing into their workflows with ease.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates running automated test suites in ServiceNow CI/CD pipelines by setting up necessary credentials, instance URLs, app identifiers, and test suite details. It supports configuring browser environments and operating systems to run tests according to specified criteria. The action is useful for DevOps teams looking to integrate automated testing into their workflows with ease.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.13...1.0.14">https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.13...1.0.14</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/go-proxy-cache-updater/</link><pubDate>Sat, 15 Aug 2026 14:06:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.44.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Go Proxy Cache Updater Action automatically pulls new Go module releases to a specified proxy cache when tags are created, ensuring that the module is immediately available and documentation updated on platforms like pkg.go.dev. This action supports standard version (vX.Y.Z) and submodule version tags (submodule/path/vX.Y.Z), allows for custom proxy configurations, import paths, and Go versions via setup-go, and is configured using a simple workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.44</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Go Proxy Cache Updater Action automatically pulls new Go module releases to a specified proxy cache when tags are created, ensuring that the module is immediately available and documentation updated on platforms like pkg.go.dev. This action supports standard version (<code>vX.Y.Z</code>) and submodule version tags (<code>submodule/path/vX.Y.Z</code>), allows for custom proxy configurations, import paths, and Go versions via setup-go, and is configured using a simple workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1144-2026-08-15"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.43...v1.1.44">1.1.44</a> (2026-08-15)</h2>
]]></content:encoded></item><item><title>citation-check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/citation-check/</link><pubDate>Sat, 15 Aug 2026 14:05:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/citation-check/</guid><description>Version updated for https://github.com/ninefiveonefive/citation-check-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks citations and claims in markdown files by parsing their structure without relying on models or machine learning. It ensures that stated counts match lists beneath them, internal references link to valid targets, totals balance figures beside them, and resolves unclear cases as “NOT CHECKED” with reasons. The action is free for up to 10 checks per address per day and provides a deterministic mechanism to validate documents.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ninefiveonefive/citation-check-action">https://github.com/ninefiveonefive/citation-check-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/citation-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks citations and claims in markdown files by parsing their structure without relying on models or machine learning. It ensures that stated counts match lists beneath them, internal references link to valid targets, totals balance figures beside them, and resolves unclear cases as &ldquo;NOT CHECKED&rdquo; with reasons. The action is free for up to 10 checks per address per day and provides a deterministic mechanism to validate documents.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Citation and claim checks on a PR&rsquo;s changed markdown: counts, references, totals. No model, documents never stored.</p>
]]></content:encoded></item><item><title>yaml-workflow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/yaml-workflow/</link><pubDate>Sat, 15 Aug 2026 14:04:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/yaml-workflow/</guid><description>Version updated for https://github.com/orieg/yaml-workflow to version v0.9.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
yaml-workflow is a lightweight workflow engine that allows developers to define and execute reproducible, version-controlled CI/CD pipelines and data processing tasks using plain YAML files. It provides features such as task automation without infrastructure overhead, reusable workflows through imports, state persistence, parallel execution, and more. This makes it suitable for local automation, scripts, and batch processing tasks while offering a lightweight alternative to shell scripts with better error handling. The tool is designed to be GitOps-friendly, making workflows live alongside the code in version control repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/orieg/yaml-workflow">https://github.com/orieg/yaml-workflow</a></strong> to version <strong>v0.9.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yaml-workflow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>yaml-workflow is a lightweight workflow engine that allows developers to define and execute reproducible, version-controlled CI/CD pipelines and data processing tasks using plain YAML files. It provides features such as task automation without infrastructure overhead, reusable workflows through imports, state persistence, parallel execution, and more. This makes it suitable for local automation, scripts, and batch processing tasks while offering a lightweight alternative to shell scripts with better error handling. The tool is designed to be GitOps-friendly, making workflows live alongside the code in version control repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Phase 0: adoption + credibility fixes by @orieg in <a href="https://github.com/orieg/yaml-workflow/pull/38">https://github.com/orieg/yaml-workflow/pull/38</a></li>
<li>docs: Editor Integration guide + promote .yaml-workflow.yaml convention by @orieg in <a href="https://github.com/orieg/yaml-workflow/pull/39">https://github.com/orieg/yaml-workflow/pull/39</a></li>
<li>docs: address Copilot review on editor-integration guide by @orieg in <a href="https://github.com/orieg/yaml-workflow/pull/40">https://github.com/orieg/yaml-workflow/pull/40</a></li>
<li>feat(mcp): prepare official MCP Registry publishing by @orieg in <a href="https://github.com/orieg/yaml-workflow/pull/41">https://github.com/orieg/yaml-workflow/pull/41</a></li>
<li>fix(mcp): address Copilot review on #41 by @orieg in <a href="https://github.com/orieg/yaml-workflow/pull/42">https://github.com/orieg/yaml-workflow/pull/42</a></li>
<li>chore: bump version to 0.9.4 by @orieg in <a href="https://github.com/orieg/yaml-workflow/pull/43">https://github.com/orieg/yaml-workflow/pull/43</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/orieg/yaml-workflow/compare/v0.9.3...v0.9.4">https://github.com/orieg/yaml-workflow/compare/v0.9.3...v0.9.4</a></p>
]]></content:encoded></item><item><title>github-actions-opentelemetry</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/github-actions-opentelemetry/</link><pubDate>Sat, 15 Aug 2026 14:03:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/github-actions-opentelemetry/</guid><description>Version updated for https://github.com/paper2/github-actions-opentelemetry to version v1.0.0.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sends metrics and traces of GitHub Actions workflows to an OTLP endpoint, helping you monitor and analyze them. It collects metrics such as workflow duration and job execution times, and generates traces of workflow, jobs, and steps. The action is useful for monitoring complex workflows without modifying existing workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/paper2/github-actions-opentelemetry">https://github.com/paper2/github-actions-opentelemetry</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-actions-opentelemetry">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sends metrics and traces of GitHub Actions workflows to an OTLP endpoint, helping you monitor and analyze them. It collects metrics such as workflow duration and job execution times, and generates traces of workflow, jobs, and steps. The action is useful for monitoring complex workflows without modifying existing workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: apply all open dependency updates by @paper2 in <a href="https://github.com/paper2/github-actions-opentelemetry/pull/211">https://github.com/paper2/github-actions-opentelemetry/pull/211</a></li>
<li>release 1.0.0 by @paper2 in <a href="https://github.com/paper2/github-actions-opentelemetry/pull/212">https://github.com/paper2/github-actions-opentelemetry/pull/212</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/paper2/github-actions-opentelemetry/compare/v0.10.2...v1.0.0">https://github.com/paper2/github-actions-opentelemetry/compare/v0.10.2...v1.0.0</a></p>
]]></content:encoded></item><item><title>phi.ag - Setup Binaryen</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/phi.ag-setup-binaryen/</link><pubDate>Sat, 15 Aug 2026 14:02:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/phi.ag-setup-binaryen/</guid><description>Version updated for https://github.com/phi-ag/setup-binaryen to version v1.0.11.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up the Binaryen build environment, automating the installation of the latest or specified version of Binaryen. It streamlines the process for developers to integrate Binaryen into their workflows without manual intervention.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/phi-ag/setup-binaryen">https://github.com/phi-ag/setup-binaryen</a></strong> to version <strong>v1.0.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/phi-ag-setup-binaryen">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up the Binaryen build environment, automating the installation of the latest or specified version of Binaryen. It streamlines the process for developers to integrate Binaryen into their workflows without manual intervention.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1011-2026-08-13"><a href="https://github.com/phi-ag/setup-binaryen/compare/v1.0.10...v1.0.11">1.0.11</a> (2026-08-13)</h2>
<h3 id="miscellaneous-chores">Miscellaneous Chores</h3>
<ul>
<li><strong>deps:</strong> update actions/checkout digest to 3d3c42e (<a href="https://github.com/phi-ag/setup-binaryen/commit/9e9d9f7e98b2eda536b45e6af47d46a6c2b9ad83">9e9d9f7</a>)</li>
<li><strong>deps:</strong> update dependency binaryen to v132 (<a href="https://github.com/phi-ag/setup-binaryen/commit/8a5a4245363fbb70d6c938be67f5dd579eecb94c">8a5a424</a>)</li>
</ul>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/raviqqe/muffy/</link><pubDate>Sat, 15 Aug 2026 14:02:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.5.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Muffy, is a static website validator that automates the process of checking multiple websites for errors such as broken links, invalid markup, and compliance with robots.txt rules. It supports recursive link checking, markup validation across HTML, SVG, and MathML documents, and includes features like cache management, concurrency control, and retries to handle transient issues efficiently. The action can be easily integrated into GitHub workflows to ensure website quality before deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Muffy, is a static website validator that automates the process of checking multiple websites for errors such as broken links, invalid markup, and compliance with <code>robots.txt</code> rules. It supports recursive link checking, markup validation across HTML, SVG, and MathML documents, and includes features like cache management, concurrency control, and retries to handle transient issues efficiently. The action can be easily integrated into GitHub workflows to ensure website quality before deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>86d7c93d21ce608bbe057ac99307f2db65c0aa87 Bump version (#1266)</li>
<li>2e066e19d873744290c5ba14e5534509ab6ea15b Update readme (#1265)</li>
<li>64a24a7b4c1c02550e0149f89b40530abb7cb64a Refactor <code>muffy-css</code> (#1264)</li>
<li>852bb20497ba363e3b02a3205526a8bd7f222afd Extract muffy-css crate (#1263)</li>
<li>84bf26d1568362193e70a6934a359087c082208f CSS as document (#1258)</li>
<li>218857181a5375081e8a785a4669045714e82dad Update action versions in documentation (#1262)</li>
<li>4eeacc275c38ac43c21c7f7a8c532e00977dc33d Bump astro from 7.2.0 to 7.2.1 in /doc in the astro group across 1 directory (#1259)</li>
<li>1ec9ef8f0152b988afc511deb223dbcf17afaf7a Bump futures from 0.3.33 to 0.3.34 (#1260)</li>
<li>38542514c3c1157bea3044d9931b2679f278dbda Bump @biomejs/biome from 2.5.7 to 2.5.8 in /doc (#1261)</li>
<li>45ab0ecb9a7f4074ab9e2218fbf6cc7ee95bb2cc Update Muffy config (#1257)</li>
</ul>
]]></content:encoded></item><item><title>Fettle — repository health grade</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/fettle-repository-health-grade/</link><pubDate>Sat, 15 Aug 2026 14:01:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/fettle-repository-health-grade/</guid><description>Version updated for https://github.com/rumankazi/fettle to version v2.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Fettle GitHub Action assesses the maintenance health of GitHub repositories, focusing on five key criteria: branch protection, CODEOWNERS file existence, Dependabot or Renovate configuration, open pull request count, and stale pull request management. It provides a real five-rule score with evidence for each result, helping users identify areas needing improvement in their repository’s maintainability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rumankazi/fettle">https://github.com/rumankazi/fettle</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fettle-repository-health-grade">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Fettle GitHub Action assesses the maintenance health of GitHub repositories, focusing on five key criteria: branch protection, CODEOWNERS file existence, Dependabot or Renovate configuration, open pull request count, and stale pull request management. It provides a real five-rule score with evidence for each result, helping users identify areas needing improvement in their repository&rsquo;s maintainability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="200-2026-08-15"><a href="https://github.com/rumankazi/fettle/compare/v1.0.1...v2.0.0">2.0.0</a> (2026-08-15)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li><strong>action:</strong> publish the Action from the repository root (<a href="https://github.com/rumankazi/fettle/issues/15">#15</a>)</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li><strong>action:</strong> publish the Action from the repository root (<a href="https://github.com/rumankazi/fettle/issues/15">#15</a>) (<a href="https://github.com/rumankazi/fettle/commit/2544cda6cc5d0f27c6aa9a6336280e36669ca6de">2544cda</a>)</li>
</ul>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/agentauditkit-mcp-security-scan/</link><pubDate>Sat, 15 Aug 2026 14:00:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.77.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner specifically designed for AI agents, focusing on identifying misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across various agent platforms. It ensures deterministic and offline scanning, producing auditor-ready compliance-evidence packs that meet industry standards like EU AI Act, SOC 2, and ISO 27001/42001.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.77</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>AgentAuditKit</strong> is a security scanner specifically designed for AI agents, focusing on identifying misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across various agent platforms. It ensures deterministic and offline scanning, producing auditor-ready compliance-evidence packs that meet industry standards like EU AI Act, SOC 2, and ISO 27001/42001.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.77
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.77
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.77</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): Bump the github-actions group with 4 updates by @dependabot[bot] in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/564">https://github.com/sattyamjjain/agent-audit-kit/pull/564</a></li>
<li>chore(deps-dev): Update ruff requirement from &lt;0.16,&gt;=0.15 to &gt;=0.15,&lt;0.17 by @dependabot[bot] in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/563">https://github.com/sattyamjjain/agent-audit-kit/pull/563</a></li>
<li>Install <code>aak</code> as a console script, so the documented shorthand resolves by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/590">https://github.com/sattyamjjain/agent-audit-kit/pull/590</a></li>
<li>Agent-Zero named pin for CVE-2026-30624, with three corrections to the roadmap row by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/591">https://github.com/sattyamjjain/agent-audit-kit/pull/591</a></li>
<li>Class rule: deny policy evaluated on a truncated copy of what the executor runs by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/592">https://github.com/sattyamjjain/agent-audit-kit/pull/592</a></li>
<li>Triage the 2026-08-14 CVE wave: three pins covering five issues, and repoint a dead domain by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/594">https://github.com/sattyamjjain/agent-audit-kit/pull/594</a></li>
<li>chore(release): v0.3.77 by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/595">https://github.com/sattyamjjain/agent-audit-kit/pull/595</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.76...v0.3.77">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.76...v0.3.77</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/custom-amazon-bedrock-agent-action/</link><pubDate>Sat, 15 Aug 2026 13:59:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action leverages Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback. It allows customization through tailored prompts and integrates with Amazon Bedrock Knowledge Bases for context-aware insights, enhancing its capabilities beyond code review. The action supports various programming languages, Terraform configurations, and can be easily integrated into PR workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action leverages Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback. It allows customization through tailored prompts and integrates with Amazon Bedrock Knowledge Bases for context-aware insights, enhancing its capabilities beyond code review. The action supports various programming languages, Terraform configurations, and can be easily integrated into PR workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sherpa.sh/</link><pubDate>Sat, 15 Aug 2026 13:58:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven infrastructure management tool that automates cloud deployment based on natural language prompts. It simplifies the process of setting up and configuring complex infrastructures, allowing developers to focus on their code instead of managing YAML files. The action supports various cloud providers, frameworks, and configuration options without requiring any specific expertise or vendor lock-in.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven infrastructure management tool that automates cloud deployment based on natural language prompts. It simplifies the process of setting up and configuring complex infrastructures, allowing developers to focus on their code instead of managing YAML files. The action supports various cloud providers, frameworks, and configuration options without requiring any specific expertise or vendor lock-in.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Zola check and build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/zola-check-and-build/</link><pubDate>Sat, 15 Aug 2026 13:57:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/zola-check-and-build/</guid><description>Version updated for https://github.com/SirMonteiro/zola-action to version v0.23.3.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the Zola static website generator by checking if a site builds successfully or building it for deployment. It allows users to customize various aspects of the build process through environment variables, such as skipping external link checks, including drafts, minifying HTML, and overriding base URLs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SirMonteiro/zola-action">https://github.com/SirMonteiro/zola-action</a></strong> to version <strong>v0.23.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zola-check-and-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the Zola static website generator by checking if a site builds successfully or building it for deployment. It allows users to customize various aspects of the build process through environment variables, such as skipping external link checks, including drafts, minifying HTML, and overriding base URLs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SirMonteiro/zola-action/compare/v0.21.0...v0.23.3">https://github.com/SirMonteiro/zola-action/compare/v0.21.0...v0.23.3</a></p>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sat, 15 Aug 2026 13:56:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service. It ensures that the necessary environment setup is completed before deploying, including installing dependencies and bundling the application. This helps in maintaining consistency across development and deployment environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service. It ensures that the necessary environment setup is completed before deploying, including installing dependencies and bundling the application. This helps in maintaining consistency across development and deployment environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>i18n-ai-translate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/i18n-ai-translate/</link><pubDate>Sat, 15 Aug 2026 13:56:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/i18n-ai-translate/</guid><description>Version updated for https://github.com/taahamahdi/i18n-ai-translate to version v5.2.0.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The i18n-ai-translate GitHub Action automates the translation of i18n locale files using AI models like ChatGPT, Gemini, Claude, or local Ollama models. It supports a wide range of formats including JSON, Gettext PO, Java properties, iOS strings, Rails YAML, and JavaScript/TypeScript modules, preserving original formatting and placeholders while ensuring accurate translations across multiple languages. The action can be used as a CLI, Node library, or GitHub Action to translate files automatically during pull requests, with features such as multi-engine selection, fast translation speed, safe verification, diff-aware updates, and check mode for auditing translations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/taahamahdi/i18n-ai-translate">https://github.com/taahamahdi/i18n-ai-translate</a></strong> to version <strong>v5.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/i18n-ai-translate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The i18n-ai-translate GitHub Action automates the translation of i18n locale files using AI models like ChatGPT, Gemini, Claude, or local Ollama models. It supports a wide range of formats including JSON, Gettext PO, Java properties, iOS strings, Rails YAML, and JavaScript/TypeScript modules, preserving original formatting and placeholders while ensuring accurate translations across multiple languages. The action can be used as a CLI, Node library, or GitHub Action to translate files automatically during pull requests, with features such as multi-engine selection, fast translation speed, safe verification, diff-aware updates, and check mode for auditing translations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: fix nested code fences and document missing flags in the guide by @taahamahdi in <a href="https://github.com/taahamahdi/i18n-ai-translate/pull/495">https://github.com/taahamahdi/i18n-ai-translate/pull/495</a></li>
<li>feat(formats): add a Rails YAML adapter by @taahamahdi in <a href="https://github.com/taahamahdi/i18n-ai-translate/pull/496">https://github.com/taahamahdi/i18n-ai-translate/pull/496</a></li>
<li>feat(formats): translate JS/TS locale modules by @taahamahdi in <a href="https://github.com/taahamahdi/i18n-ai-translate/pull/497">https://github.com/taahamahdi/i18n-ai-translate/pull/497</a></li>
<li>chore: fix package-name typography and searchable metadata by @taahamahdi in <a href="https://github.com/taahamahdi/i18n-ai-translate/pull/498">https://github.com/taahamahdi/i18n-ai-translate/pull/498</a></li>
<li>chore(action): modernize the composite action by @taahamahdi in <a href="https://github.com/taahamahdi/i18n-ai-translate/pull/499">https://github.com/taahamahdi/i18n-ai-translate/pull/499</a></li>
<li>chore: release 5.2.0 and fix what it would have published by @taahamahdi in <a href="https://github.com/taahamahdi/i18n-ai-translate/pull/500">https://github.com/taahamahdi/i18n-ai-translate/pull/500</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/taahamahdi/i18n-ai-translate/compare/v5.1.0...v5.2.0">https://github.com/taahamahdi/i18n-ai-translate/compare/v5.1.0...v5.2.0</a></p>
]]></content:encoded></item><item><title>NextBSD-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/nextbsd-vm/</link><pubDate>Sat, 15 Aug 2026 13:55:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/nextbsd-vm/</guid><description>Version updated for https://github.com/vmactions/nextbsd-vm to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of CI/CD workflows in NextBSD. It provides a convenient way to run tests and builds on NextBSD, which is not natively supported by GitHub Actions due to its limited support for different operating systems. The action supports both x86_64 (amd64) and aarch64 (arm64) architectures. It handles the installation of necessary toolchains and dependencies, as well as environment variable and source code synchronization between the host machine and the NextBSD virtual machine.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/nextbsd-vm">https://github.com/vmactions/nextbsd-vm</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nextbsd-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of CI/CD workflows in NextBSD. It provides a convenient way to run tests and builds on NextBSD, which is not natively supported by GitHub Actions due to its limited support for different operating systems. The action supports both x86_64 (amd64) and aarch64 (arm64) architectures. It handles the installation of necessary toolchains and dependencies, as well as environment variable and source code synchronization between the host machine and the NextBSD virtual machine.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/nextbsd-vm/commits/v1.0.0">https://github.com/vmactions/nextbsd-vm/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>API Probe - LLM Endpoint Health Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/api-probe-llm-endpoint-health-check/</link><pubDate>Sat, 15 Aug 2026 13:53:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/api-probe-llm-endpoint-health-check/</guid><description>Version updated for https://github.com/xydadada/api-probe to version v1.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The API Probe is a tool designed to test and diagnose compatibility of APIs, particularly those commonly used with large language models (LLMs). It supports various protocols, base URLs, authentication methods, and request bodies. The action automates the process of checking model availability, batch testing, querying balance, and constructing custom requests. It provides both graphical user interface and command-line interfaces, as well as machine-readable JSON outputs, to facilitate debugging and automation tasks related to LLM APIs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/xydadada/api-probe">https://github.com/xydadada/api-probe</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/api-probe-llm-endpoint-health-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The API Probe is a tool designed to test and diagnose compatibility of APIs, particularly those commonly used with large language models (LLMs). It supports various protocols, base URLs, authentication methods, and request bodies. The action automates the process of checking model availability, batch testing, querying balance, and constructing custom requests. It provides both graphical user interface and command-line interfaces, as well as machine-readable JSON outputs, to facilitate debugging and automation tasks related to LLM APIs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: update workflows for Node 24 runtime (b6d3f94)</li>
<li>chore: prepare v1.2.0 release (c87be3c)</li>
<li>feat: prepare GitHub Marketplace action (30ff342)</li>
<li>fix: serve branded assets and harden local UX (0e8041a)</li>
<li>feat: add API Probe visual identity (ddfc497)</li>
<li>fix: use Unicode-safe Windows launcher (02df945)</li>
<li>Fix npm command entry point (c75f05d)</li>
<li>Improve discovery, distribution, and integrations (03d4e2c)</li>
<li>Prepare public GitHub release (95327b2)</li>
<li>Initial release (d398d2f)</li>
</ul>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/b.ia-accessibility-checker/</link><pubDate>Sat, 15 Aug 2026 13:52:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines, enabling companies to ensure their code complies with WCAG guidelines for specific audiences. By defining requirements and using AI analysis, B.IA helps companies prioritize accessibility efforts more effectively. It provides flexibility in coverage across different target audiences and outputs detailed feedback when compliance is not met.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines, enabling companies to ensure their code complies with WCAG guidelines for specific audiences. By defining requirements and using AI analysis, B.IA helps companies prioritize accessibility efforts more effectively. It provides flexibility in coverage across different target audiences and outputs detailed feedback when compliance is not met.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>DeepSeek Harness for GitHub</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/deepseek-harness-for-github/</link><pubDate>Sat, 15 Aug 2026 07:03:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/deepseek-harness-for-github/</guid><description>Version updated for https://github.com/Lixiaoyiao/deepseek-harness-action to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of using DeepSeek Harness to review, diagnose, and fix issues in pull requests (PRs) and CI builds. It integrates with GitHub events to trigger coding agents, allowing for real-time feedback and automated code corrections. The action handles PR reviews, re-runs, diagnoses, fixes, and creates new PRs based on comments, providing a seamless integration of DeepSeek Harness into the GitHub workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lixiaoyiao/deepseek-harness-action">https://github.com/Lixiaoyiao/deepseek-harness-action</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deepseek-harness-for-github">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of using DeepSeek Harness to review, diagnose, and fix issues in pull requests (PRs) and CI builds. It integrates with GitHub events to trigger coding agents, allowing for real-time feedback and automated code corrections. The action handles PR reviews, re-runs, diagnoses, fixes, and creates new PRs based on comments, providing a seamless integration of DeepSeek Harness into the GitHub workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Controller-owned sticky progress updates context preparation, DSH execution/structured-output validation, and publication or trusted write in one existing comment.</li>
<li><code>result-json</code> schema v1 is emitted on success, neutral, denied, timeout, validation-failure, and ordinary failure paths, with new backward-compatible scalar outputs.</li>
<li>Stable, redacted failure codes now identify the phase, retryability, and an actionable next step. Controller validation distinguishes non-zero exits, timeouts, truncation, and setup/container failures.</li>
<li>The trust model now separates actor authorization, untrusted repository/event input, isolated worker capabilities, and controller-owned GitHub side effects.</li>
</ul>
<h2 id="security-and-reliability">Security and reliability</h2>
<ul>
<li>Packaged DSH policy profiles resolve relative to the installed JavaScript action, so a caller workspace cannot substitute controller policy files.</li>
<li>Progress begins only after authorization. The worker still receives neither <code>GITHUB_TOKEN</code> nor the DeepSeek API key, and model output never grants capabilities.</li>
<li>Review publication and trusted writes remain fail closed. Real E2E runs confirmed malformed model output is rejected before GitHub side effects and surfaced through the same sticky comment.</li>
</ul>
<h2 id="compatibility">Compatibility</h2>
<p>Existing v0.1.0 inputs, outputs, and v1 sticky markers remain supported. <code>progress-comment</code> defaults to <code>true</code>; no marker migration is required. The bundled DSH dependency remains pinned to <code>0.1.0-rc.6</code>.</p>
<p>For immutable workflow references, use:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Lixiaoyiao/deepseek-harness-action@50580590de152abcc3bd81c07b26dd632b76360b</span> <span style="color:#75715e"># v0.2.0</span>
</span></span></code></pre></div><h2 id="validation">Validation</h2>
<ul>
<li><a href="https://github.com/Lixiaoyiao/deepseek-harness-action/pull/6">PR #6</a></li>
<li><a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/31849160466">Final PR CI</a></li>
<li><a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/31849602272">Merged main CI and Linux Docker smoke</a></li>
<li><a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/31846230373">Real sticky/review/fix/validation/denied E2E</a></li>
<li><a href="https://github.com/Lixiaoyiao/deepseek-harness-action/actions/runs/31847649760">Fail-closed malformed-output E2E</a></li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/Lixiaoyiao/deepseek-harness-action/compare/v0.1.0...v0.2.0">https://github.com/Lixiaoyiao/deepseek-harness-action/compare/v0.1.0...v0.2.0</a></p>
]]></content:encoded></item><item><title>OSS Security Policy as Code</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/oss-security-policy-as-code/</link><pubDate>Sat, 15 Aug 2026 07:01:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/oss-security-policy-as-code/</guid><description>Version updated for https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit to version v10.0.15.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action evaluates OSS repositories against security policies using a policy library and generates reports in Markdown, JSON, and SARIF formats. It supports evidence files, waivers, and compliance frameworks like SLSA, OSPS, and SSDF. The action helps maintain code quality and ensures adherence to security standards by providing detailed reports on findings and control assessments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit">https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit</a></strong> to version <strong>v10.0.15</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oss-security-policy-as-code">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action evaluates OSS repositories against security policies using a policy library and generates reports in Markdown, JSON, and SARIF formats. It supports evidence files, waivers, and compliance frameworks like SLSA, OSPS, and SSDF. The action helps maintain code quality and ensures adherence to security standards by providing detailed reports on findings and control assessments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="oss-security-policy-as-code-starter-kit-v10015">OSS Security Policy as Code Starter Kit v10.0.15</h2>
<p>One control starts enforcing a contract this kit has published since the day that control was written.</p>
<p><code>GL-PIPE-011</code> reads <code>.oss-policy-kit/evidence/gitlab-mr-rules.json</code>. A JSON Schema for that file ships in the wheel, ships in <code>reports/schema/</code>, and is the file the control&rsquo;s own remediation message tells you to use. <strong>Nothing loaded it.</strong> Hand-rolled checks stood in its place, and they were more generous than the contract.</p>
<hr>
<h2 id="read-this-first-gl-pipe-011-verdicts-change">Read this first: GL-PIPE-011 verdicts change</h2>
<table>
  <thead>
      <tr>
          <th>Your <code>gitlab-mr-rules.json</code></th>
          <th>Before</th>
          <th>Now</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Untouched <code>scaffold-evidence</code> output, still containing <code>REPLACE_ME_…</code></td>
          <td><strong>PASS</strong></td>
          <td><code>not-evaluated</code>, naming the placeholders</td>
      </tr>
      <tr>
          <td>Missing a required field (<code>schema_version</code>, <code>attested_at</code>, <code>attested_by</code>, <code>project</code>)</td>
          <td><strong>PASS</strong></td>
          <td><code>manual-review-required</code>, naming the field</td>
      </tr>
      <tr>
          <td>A <code>schema_version</code> other than <code>gitlab-mr-rules/v1</code></td>
          <td><strong>PASS</strong></td>
          <td><code>manual-review-required</code></td>
      </tr>
      <tr>
          <td><code>min_approvers</code> that is not a whole number</td>
          <td><strong>PASS</strong></td>
          <td><code>manual-review-required</code></td>
      </tr>
      <tr>
          <td><code>min_approvers: 0</code></td>
          <td><em>&ldquo;No … evidence&rdquo;</em></td>
          <td><strong>FAIL</strong>, naming the count</td>
      </tr>
      <tr>
          <td>Valid, <code>min_approvers</code> ≥ 1</td>
          <td>PASS</td>
          <td>PASS — unchanged</td>
      </tr>
  </tbody>
</table>
<p><strong>If GL-PIPE-011 stops passing for you, the PASS was not earned.</strong> The schema has always listed those fields as required; the kit simply never checked. The fix is to fill the file in — <code>oss-policy-kit scaffold-evidence</code> writes the skeleton, and <code>collect-evidence --platform gitlab</code> fills it from the GitLab API.</p>
<p>Nothing that was genuinely proven starts failing: a complete, filled-in file with at least one required approver passes exactly as before.</p>
<hr>
<h2 id="fixed">Fixed</h2>
<h3 id="an-untouched-template-earned-a-pass">An untouched template earned a PASS</h3>
<p><code>scaffold-evidence</code> writes <code>gitlab-mr-rules.json</code> with <code>min_approvers: 2</code> as an example value, alongside <code>attested_by: REPLACE_ME_GITLAB_USER</code>. The control read the <code>2</code> and reported <em>&ldquo;MR rule evidence documents min_approvers=2&rdquo;</em> — <strong>the template passing on the strength of its own placeholder</strong>, with the unfilled fields sitting right there in the same document.</p>
<p>Placeholder detection is the step that was missing. Every sibling evidence control already ran it.</p>
<h3 id="evidence-that-no-approvals-are-required-was-reported-as-no-evidence">Evidence that no approvals are required was reported as no evidence</h3>
<p><code>min_approvers: 0</code> says merge requests can be merged without an approval. That is a readable, complete, schema-valid statement that the protection is off — and it fell through to <em>&ldquo;No <code>.oss-policy-kit/evidence/gitlab-mr-rules.json</code> evidence; MR approval enforcement cannot be verified from a clone.&rdquo;</em></p>
<p>The kit hid a real finding behind a sentence denying the file existed, and sent the operator to create a file they had already written. It is a <strong>FAIL</strong> now, quoting the count and pointing at the file.</p>
<p>ADR-045 reserves <code>manual-review-required</code> for evidence that cannot be <em>read</em>. This reads perfectly. It just says something you would rather it did not.</p>
<h3 id="a-document-that-ignored-the-contract-still-passed">A document that ignored the contract still passed</h3>
<p>A file with an unrecognised <code>schema_version</code>, or missing required fields, or with <code>min_approvers: 1.5</code> where the schema says integer — all reported PASS. The control now validates first and reports what failed, pointing at <code>reports/schema/evidence-gitlab-mr-rules.schema.json</code>.</p>
<hr>
<h2 id="also-in-this-release">Also in this release</h2>
<p><strong>The two shipped copies of every schema are now checked against each other.</strong> One copy lives in the wheel, where controls validate against it; the other lives in <code>reports/schema/</code>, where remediation messages send you. They were identical, and nothing kept them that way — tolerable while the packaged copies were decorative, not tolerable now that a control enforces one. A drift would mean the kit rejecting a document the published contract calls valid, with no way for you to tell which copy was wrong. The check is derived from the directories, so a schema added to only one side fails too.</p>
<p><strong>The kit&rsquo;s own producers were verified against the contract before it was switched on.</strong> A contract that a tool&rsquo;s own output violates is a contract that gets switched back off. Both the <code>scaffold-evidence</code> skeleton and the <code>collect-evidence</code> payload satisfy the schema, and the collector&rsquo;s shape is now pinned by a test.</p>
<hr>
<h2 id="notes">Notes</h2>
<p>Full gate green: lint, formatting, type checking, <strong>7149 tests</strong>, <strong>100.00% coverage</strong> against a floor of 100.</p>
<p>Four mutations, four caught — including one that edits the schema <strong>file</strong> rather than the code, which is what distinguishes a contract the kit enforces from a document it ships.</p>
]]></content:encoded></item><item><title>sigilmd</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sigilmd/</link><pubDate>Sat, 15 Aug 2026 07:00:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sigilmd/</guid><description>Version updated for https://github.com/lucianofedericopereira/sigilmd to version v0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, sigilmd, automates the insertion of file contents and config-defined values into a README.md file using marker comments. It provides a single Perl script solution without external dependencies, ensuring compatibility over time. The action supports declaring tables with key-value pairs and referencing values from files or other tables within the same format.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lucianofedericopereira/sigilmd">https://github.com/lucianofedericopereira/sigilmd</a></strong> to version <strong>v0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sigilmd">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, sigilmd, automates the insertion of file contents and config-defined values into a README.md file using marker comments. It provides a single Perl script solution without external dependencies, ensuring compatibility over time. The action supports declaring tables with key-value pairs and referencing values from files or other tables within the same format.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v02----august-15-2026">v0.2 -  August 15, 2026</h2>
<ul>
<li>Fixed table/reference markers hard-erroring whenever a file also contained <code>sigilbadges</code>&rsquo; own <code>badge:</code> / <code>badge-row:</code> markers — both tools share the same <code>&lt;!--[[ ]]--&gt;</code> bracket syntax with no namespace, so <code>sigilmd</code> now recognizes and skips sigilbadges&rsquo; (unambiguous, colon-prefixed) marker shapes instead of dying on it</li>
<li>Fixed <code>uses: lucianofedericopereira/sigilmd@v1</code> pins in the README that never matched any real tag — the actual published tag is <code>v0.1</code>; rewrote the &ldquo;Publishing to Marketplace&rdquo; section to describe the direct-tag-pin flow this project actually uses pre-1.0</li>
<li>Replaced the placeholder pencil-icon brand mark (nav, hero, footer, favicon) with the real <code>sigilmd.png</code> logo across the site</li>
<li>Added a &ldquo;Read the Docs&rdquo; badge, matching the shared style used by sigilbadges/treegen2 (GitHub logo, <code>for-the-badge</code>, centered under the top logo)</li>
<li>Reworked the README&rsquo;s marker-grammar &ldquo;Example&rdquo; section into a real before/after: the &ldquo;after&rdquo; half is now shown rendered rather than as a second code block, since that&rsquo;s what a reader actually sees on the page</li>
</ul>
]]></content:encoded></item><item><title>treegen2 — File Tree for README (Perl)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/treegen2-file-tree-for-readme-perl/</link><pubDate>Sat, 15 Aug 2026 06:59:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/treegen2-file-tree-for-readme-perl/</guid><description>Version updated for https://github.com/lucianofedericopereira/treegen2 to version v0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action treegen2 provides a file tree README generator written in pure Perl, with options to choose from ASCII, SVG, and collapsible formats. It ensures compatibility for twenty years by not relying on CPAN dependencies or interpreter setup steps. The action is optimized for long-term stability and reliability in CI pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lucianofedericopereira/treegen2">https://github.com/lucianofedericopereira/treegen2</a></strong> to version <strong>v0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/treegen2-file-tree-for-readme-perl">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>treegen2</code> provides a file tree README generator written in pure Perl, with options to choose from ASCII, SVG, and collapsible formats. It ensures compatibility for twenty years by not relying on CPAN dependencies or interpreter setup steps. The action is optimized for long-term stability and reliability in CI pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="020----august-15-2026">0.2.0 -  August 15, 2026</h2>
<ul>
<li>Fixed four <code>uses: lucianofedericopereira/treegen2@v1</code> pins in the README that never matched any real tag — the actual published tag is <code>v0.1</code>; rewrote the &ldquo;Publishing to Marketplace&rdquo; section to describe the direct-tag-pin flow this project actually uses pre-1.0, instead of a <code>v1.0.0</code> release plus a floating <code>v1</code> alias that was never cut</li>
<li>The README&rsquo;s &ldquo;Read the Docs&rdquo; link is now a proper badge (GitHub logo, <code>for-the-badge</code>, matching sigilbadges/sigilmd) instead of a one-off <code>&lt;h2&gt;</code> link with its own icon asset; the top logo image is now centered and size-capped to match its siblings</li>
<li>The four places the README shows the action&rsquo;s version pin now derive from small snippet files declared in <code>sigilmd.toml</code>, kept in sync by <code>sigilmd</code> itself, instead of four separately hand-maintained copies of the same string</li>
</ul>
]]></content:encoded></item><item><title>Goal-Driven AI PR Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/goal-driven-ai-pr-reviewer/</link><pubDate>Sat, 15 Aug 2026 06:58:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/goal-driven-ai-pr-reviewer/</guid><description>Version updated for https://github.com/markhuangai/ai-pr-reviewer to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The AI PR Reviewer GitHub Action automates pull request reviews using Goal-driven, MCP-enabled JavaScript. It leverages a pre-installed Anthropic Claude Agent SDK to analyze code changes and suggest improvements based on user-defined prompts. The action runs isolated review sessions with automated compaction, read-only repository tools, and HTTP MCP servers. Reviewed findings are merged and deduplicated before posting as a single GitHub pull request review or written to the workflow run summary.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/markhuangai/ai-pr-reviewer">https://github.com/markhuangai/ai-pr-reviewer</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/goal-driven-ai-pr-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The AI PR Reviewer GitHub Action automates pull request reviews using Goal-driven, MCP-enabled JavaScript. It leverages a pre-installed Anthropic Claude Agent SDK to analyze code changes and suggest improvements based on user-defined prompts. The action runs isolated review sessions with automated compaction, read-only repository tools, and HTTP MCP servers. Reviewed findings are merged and deduplicated before posting as a single GitHub pull request review or written to the workflow run summary.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add read-only cross-repository reviews by @Z-M-Huang in <a href="https://github.com/markhuangai/ai-pr-reviewer/pull/11">https://github.com/markhuangai/ai-pr-reviewer/pull/11</a></li>
<li>Add concise review comments and apply suggestions by @Z-M-Huang in <a href="https://github.com/markhuangai/ai-pr-reviewer/pull/12">https://github.com/markhuangai/ai-pr-reviewer/pull/12</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/markhuangai/ai-pr-reviewer/compare/v1.0.1...v1.1.0">https://github.com/markhuangai/ai-pr-reviewer/compare/v1.0.1...v1.1.0</a></p>
]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Sat, 15 Aug 2026 06:57:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.9.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of automated test suites in ServiceNow using Selenium WebDriver. It helps users set up and run tests across different environments by configuring service credentials, instance URLs, app sys_ids, and test suite IDs. The action supports various browsers and operating systems, allowing for flexible testing configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of automated test suites in ServiceNow using Selenium WebDriver. It helps users set up and run tests across different environments by configuring service credentials, instance URLs, app sys_ids, and test suite IDs. The action supports various browsers and operating systems, allowing for flexible testing configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.8...1.0.9">https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.8...1.0.9</a></p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/totem-shield/</link><pubDate>Sat, 15 Aug 2026 06:56:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.118.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is an AI code agent that automates linting and documentation, keeping project lessons and rules in the repository. It ensures architectural integrity by enforcing deterministic lint rules with zero LLM calls, providing a local, queryable knowledge index based on Markdown lessons. This approach minimizes dependencies and friction while maintaining project context and lessons across sessions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.118.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is an AI code agent that automates linting and documentation, keeping project lessons and rules in the repository. It ensures architectural integrity by enforcing deterministic lint rules with zero LLM calls, providing a local, queryable knowledge index based on Markdown lessons. This approach minimizes dependencies and friction while maintaining project context and lessons across sessions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>AI Agent Discipline Linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/ai-agent-discipline-linter/</link><pubDate>Sat, 15 Aug 2026 06:54:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/ai-agent-discipline-linter/</guid><description>Version updated for https://github.com/naimkatiman/continuous-improvement to version v3.23.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Continuous Improvement adds three layers to Claude Code to make it smarter:
Before an edit: It physically blocks destructive edits until the agent presents a fact-list investigation. During work: It enforces planning, one-thing-at-a-time execution, and TDD before “done”. After work: It provides reflection on the 7 Laws of AI Agent Discipline and captures lessons for future sessions. What’s Changed What’s Changed feat(ship): make urgent fixes globally runnable by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/294 chore(release): cut v3.23.0 by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/295 Full Changelog: https://github.com/naimkatiman/continuous-improvement/compare/v3.22.1...v3.23.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/naimkatiman/continuous-improvement">https://github.com/naimkatiman/continuous-improvement</a></strong> to version <strong>v3.23.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-agent-discipline-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Continuous Improvement adds three layers to Claude Code to make it smarter:</p>
<ol>
<li><strong>Before an edit</strong>: It physically blocks destructive edits until the agent presents a fact-list investigation.</li>
<li><strong>During work</strong>: It enforces planning, one-thing-at-a-time execution, and TDD before &ldquo;done&rdquo;.</li>
<li><strong>After work</strong>: It provides reflection on the 7 Laws of AI Agent Discipline and captures lessons for future sessions.</li>
</ol>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(ship): make urgent fixes globally runnable by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/294">https://github.com/naimkatiman/continuous-improvement/pull/294</a></li>
<li>chore(release): cut v3.23.0 by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/295">https://github.com/naimkatiman/continuous-improvement/pull/295</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/naimkatiman/continuous-improvement/compare/v3.22.1...v3.23.0">https://github.com/naimkatiman/continuous-improvement/compare/v3.22.1...v3.23.0</a></p>
]]></content:encoded></item><item><title>gh-settings</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/gh-settings/</link><pubDate>Sat, 15 Aug 2026 06:53:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/gh-settings/</guid><description>Version updated for https://github.com/noirbizarre/gh-settings to version 0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the management of repository settings using the GitHub CLI. It provides a declarative way to define and update repository configuration, including topics, labels, and autolinks. The action computes the difference between the current state and the desired state defined in a .github/settings.yml file and applies the necessary changes. It does not require any external services or apps, and it can preview changes before applying them using gh settings plan.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/noirbizarre/gh-settings">https://github.com/noirbizarre/gh-settings</a></strong> to version <strong>0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gh-settings">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the management of repository settings using the GitHub CLI. It provides a declarative way to define and update repository configuration, including topics, labels, and autolinks. The action computes the difference between the current state and the desired state defined in a <code>.github/settings.yml</code> file and applies the necessary changes. It does not require any external services or apps, and it can preview changes before applying them using <code>gh settings plan</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="-features">💫 Features</h3>
<ul>
<li><strong>resources</strong> Manage Actions general settings and web commit signoff - (<a href="https://github.com/noirbizarre/gh-settings/commit/36e4b9a5ec7155f3ffcb55cd8df24a70b9b698eb">36e4b9a</a>)</li>
</ul>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li><strong>docs</strong> Add Actions general settings to the Administration: write lists - (<a href="https://github.com/noirbizarre/gh-settings/commit/181150fd4a6ea16e4a8a0a9e22f37c3ba0fec112">181150f</a>)</li>
<li><strong>docs</strong> Say the Actions token reaches Pages, not just labels - (<a href="https://github.com/noirbizarre/gh-settings/commit/0f9cf82c7315dbdb0c740ee6fdbba9ef33f2c554">0f9cf82</a>)</li>
</ul>
<h3 id="-refactor">🔨 Refactor</h3>
<ul>
<li><strong>resources</strong> Derive the exported section instead of hand-building it - (<a href="https://github.com/noirbizarre/gh-settings/commit/c58b245fdf578ed821a1c6075d750f2aeb2420f5">c58b245</a>)</li>
<li><strong>rulesets</strong> Match the idioms the other resources use - (<a href="https://github.com/noirbizarre/gh-settings/commit/d8e88caaf4ef9e9407cbbefa1e470966f388e33f">d8e88ca</a>)</li>
<li>State the recreate invariant instead of hiding it in a shared arm - (<a href="https://github.com/noirbizarre/gh-settings/commit/27543a2cfdbd0122614addc46597dbc34f04a6e7">27543a2</a>)</li>
</ul>
<h3 id="-documentation">📚 Documentation</h3>
<ul>
<li><strong>adr</strong> Record what later records changed - (<a href="https://github.com/noirbizarre/gh-settings/commit/599250c6c3f01ef130088e63ba6899ff6306fe26">599250c</a>)</li>
<li><strong>roadmap</strong> List Actions general settings as supported - (<a href="https://github.com/noirbizarre/gh-settings/commit/7a2bed1d3aa10847ed80e884600102bf78947244">7a2bed1</a>)</li>
<li>Correct the small stale statements - (<a href="https://github.com/noirbizarre/gh-settings/commit/9e16f93d89b680e62d1b352b89dc371f3e280dbf">9e16f93</a>)</li>
<li>Stop saying the action has never been released - (<a href="https://github.com/noirbizarre/gh-settings/commit/b927f6d46de52fc644315950add484d1bce0eb58">b927f6d</a>)</li>
</ul>
<h3 id="-style">🎨 Style</h3>
<ul>
<li><strong>resources</strong> One wording for the undecodable-payload panic - (<a href="https://github.com/noirbizarre/gh-settings/commit/780dfdf22385a41178a4a68d48cf832a37c661ea">780dfdf</a>)</li>
<li>Rustfmt the rewrapped panic messages - (<a href="https://github.com/noirbizarre/gh-settings/commit/3125adc70e74e19681a7cfa05fc6d880748b43b9">3125adc</a>)</li>
</ul>
<h3 id="-ci">🔧 CI</h3>
<ul>
<li><strong>git-cliff</strong> Avoid <code>git-cliff</code> GitHub integration rate limiting by using a token - (<a href="https://github.com/noirbizarre/gh-settings/commit/3937314007784c5ae46627c04581178bffb95db1">3937314</a>)</li>
<li><strong>lint</strong> Move actionlint suppressions into a config file - (<a href="https://github.com/noirbizarre/gh-settings/commit/60e8b4828d10dc5570672ff92214815a6ab9bedc">60e8b48</a>)</li>
<li><strong>mise</strong> Stop installing artwork tools in every job - (<a href="https://github.com/noirbizarre/gh-settings/commit/331610f03597876deba1d33d63c7aba51a5dab1d">331610f</a>)</li>
<li><strong>release</strong> Sign the release commit with a GitHub App - (<a href="https://github.com/noirbizarre/gh-settings/commit/9e5ff42f84dc4786d1aad863ac37480517bab82a">9e5ff42</a>)</li>
</ul>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/run-aer-tests/</link><pubDate>Sat, 15 Aug 2026 06:52:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.32.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action aer automates the execution of Apex unit tests locally, enabling developers to run Apex code and test against their local metadata without needing an org or sandbox. It supports running Apex unit tests with code coverage from the command line or in CI pipelines, executing anonymous Apex, and stepping through Apex using an interactive debugger (VS Code or IntelliJ).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.32</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>aer</code> automates the execution of Apex unit tests locally, enabling developers to run Apex code and test against their local metadata without needing an org or sandbox. It supports running Apex unit tests with code coverage from the command line or in CI pipelines, executing anonymous Apex, and stepping through Apex using an interactive debugger (VS Code or IntelliJ).</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.32</p>
<ul>
<li>
<p>Match Flow Runtime SOQL Limit Semantics For Global Variables And Get Records</p>
</li>
<li>
<p>Resolve os.Stdout At Write Time For &ndash;json Output To Stdout</p>
</li>
<li>
<p>Fix Flow And Process Builder Record Update Conversion And Write Sets</p>
</li>
<li>
<p>Apply Every Rollup Record Type Filter Rewrite To The Copy-On-Write Clone</p>
</li>
<li>
<p>Unwrap SELECT COUNT() To Integer Regardless Of Assignment Target Type</p>
</li>
<li>
<p>Convert Flow Number Action Inputs And Date Subtraction To Valid Apex</p>
</li>
</ul>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/odin-scan-smart-contract-security/</link><pubDate>Sat, 15 Aug 2026 06:51:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is an AI-powered tool for smart contract security analysis on CosmWasm, Solana, and EVM projects. It integrates seamlessly with the workflow to identify vulnerabilities before they reach production. Key features include multi-platform support, automatic platform detection, GitHub Code Scanning integration for native security alerts, PR comments with findings summary, inline annotations, comment-triggered scans, configurable severity thresholds, artifact upload of full reports, and SARIF file generation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is an AI-powered tool for smart contract security analysis on CosmWasm, Solana, and EVM projects. It integrates seamlessly with the workflow to identify vulnerabilities before they reach production. Key features include multi-platform support, automatic platform detection, GitHub Code Scanning integration for native security alerts, PR comments with findings summary, inline annotations, comment-triggered scans, configurable severity thresholds, artifact upload of full reports, and SARIF file generation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add comment-triggered PR scans (ac72e5f)</li>
<li>docs: expand findings-visibility section with threat model and annotation rationale (0404708)</li>
<li>feat: add findings-visibility input for graduated public disclosure control (f18df59)</li>
<li>fix: show findings detail in PR comment with fallback to medium (c2e43c8)</li>
<li>fix: new comment per run, show only critical/high findings, rebuild dist (e237b62)</li>
<li>feat: use GitHub App installation token for branded PR comments (3abce4e)</li>
<li>feat: enrich PR comment with emojis, descriptions, and fix report URL (27cc2f2)</li>
<li>fix: gzip SARIF before base64 encoding for Code Scanning upload (d9eed9f)</li>
<li>fix: include sourcemap-register.js in dist (bd265af)</li>
<li>docs: add privacy policy (b78db44)</li>
</ul>
]]></content:encoded></item><item><title>OpenTelemetry for GitHub Workflows, Jobs and Steps</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/opentelemetry-for-github-workflows-jobs-and-steps/</link><pubDate>Sat, 15 Aug 2026 06:50:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/opentelemetry-for-github-workflows-jobs-and-steps/</guid><description>Version updated for https://github.com/plengauer/Thoth to version v5.61.0.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the collection and instrumentation of OpenTelemetry traces, metrics, and logs from shell scripts and GitHub workflows. It automatically propagates context via HTTP requests, instruments all available commands, injects into child scripts and executables using shebangs, and integrates with GitHub actions for workflow-level and job-level monitoring. The action is installable via package managers and provides a comprehensive set of features to monitor applications and CI/CD pipelines efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plengauer/Thoth">https://github.com/plengauer/Thoth</a></strong> to version <strong>v5.61.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>14</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/opentelemetry-for-github-workflows-jobs-and-steps">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the collection and instrumentation of OpenTelemetry traces, metrics, and logs from shell scripts and GitHub workflows. It automatically propagates context via HTTP requests, instruments all available commands, injects into child scripts and executables using shebangs, and integrates with GitHub actions for workflow-level and job-level monitoring. The action is installable via package managers and provides a comprehensive set of features to monitor applications and CI/CD pipelines efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add Xcode 27 preview macOS runner coverage in GitHub workflow tests by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3894">https://github.com/plengauer/Thoth/pull/3894</a></li>
<li>fix: use <code>rm -f</code> in <code>otel_shutdown</code> to handle missing FIFO gracefully by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3896">https://github.com/plengauer/Thoth/pull/3896</a></li>
<li>Keep gh-aw agent execution on the current job trace by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3897">https://github.com/plengauer/Thoth/pull/3897</a></li>
<li>Fall back to OTEL_KILL_SWITCH repository variable when kill switch input is unset by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3893">https://github.com/plengauer/Thoth/pull/3893</a></li>
<li>Fix autofix: inject triggering-workflow-run-id into agent prompt context by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3898">https://github.com/plengauer/Thoth/pull/3898</a></li>
<li>Expand descrption to improve code reviews by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3900">https://github.com/plengauer/Thoth/pull/3900</a></li>
<li>feat(job): async npm install + shell-based cache restore to remove npm from critical path by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3895">https://github.com/plengauer/Thoth/pull/3895</a></li>
<li>Update actions/setup-java action to v5.7.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3890">https://github.com/plengauer/Thoth/pull/3890</a></li>
<li>Prevent <code>quality</code> job failures from invalid MegaLinter SARIF fixes payload by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3827">https://github.com/plengauer/Thoth/pull/3827</a></li>
<li>Analyze: always upload <code>megalinter-reports</code> artifact for SARIF-only linter triage by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3866">https://github.com/plengauer/Thoth/pull/3866</a></li>
<li>Update opentelemetry-js monorepo by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3822">https://github.com/plengauer/Thoth/pull/3822</a></li>
<li>Update github/codeql-action action to v3.37.6 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3889">https://github.com/plengauer/Thoth/pull/3889</a></li>
<li>Update actions/attest-build-provenance action to v4.2.2 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3916">https://github.com/plengauer/Thoth/pull/3916</a></li>
<li>Update renovatebot/github-action action to v46.2.1 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3872">https://github.com/plengauer/Thoth/pull/3872</a></li>
<li>Update otel/opentelemetry-collector-contrib Docker tag to v0.158.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3904">https://github.com/plengauer/Thoth/pull/3904</a></li>
<li>Update dependency opentelemetry-resourcedetector-gcp to v1.14.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3811">https://github.com/plengauer/Thoth/pull/3811</a></li>
<li>Pin dependencies by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3819">https://github.com/plengauer/Thoth/pull/3819</a></li>
<li>Lock file maintenance by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3868">https://github.com/plengauer/Thoth/pull/3868</a></li>
<li>Update Gradle to v9.7.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3917">https://github.com/plengauer/Thoth/pull/3917</a></li>
<li>feat: adopt $/ self-repository syntax for same-repo action references by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3899">https://github.com/plengauer/Thoth/pull/3899</a></li>
<li>Exclude workflow YAML from MegaLinter lychee URL checks by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3864">https://github.com/plengauer/Thoth/pull/3864</a></li>
<li>Format Python sources with Black + isort (MegaLinter valid finding) by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3859">https://github.com/plengauer/Thoth/pull/3859</a></li>
<li>Use bash loadable builtins for rm and mkfifo when available by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3912">https://github.com/plengauer/Thoth/pull/3912</a></li>
<li>chore: exclude generated/captured files from MegaLinter by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3863">https://github.com/plengauer/Thoth/pull/3863</a></li>
<li>Update Demo injection_shebang by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3924">https://github.com/plengauer/Thoth/pull/3924</a></li>
<li>Update Demo injection_deep_node by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3926">https://github.com/plengauer/Thoth/pull/3926</a></li>
<li>Update Demo context_propagation_http_wget by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3930">https://github.com/plengauer/Thoth/pull/3930</a></li>
<li>Update Demo _simple_hello_world by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3927">https://github.com/plengauer/Thoth/pull/3927</a></li>
<li>Update Demo injection_deep_python by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3932">https://github.com/plengauer/Thoth/pull/3932</a></li>
<li>Update Demo context_propagation_http_curl by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3925">https://github.com/plengauer/Thoth/pull/3925</a></li>
<li>Update Demo injection_inner_xargs_parallel by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3933">https://github.com/plengauer/Thoth/pull/3933</a></li>
<li>Update actions/upload-artifact action to v7 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3938">https://github.com/plengauer/Thoth/pull/3938</a></li>
<li>Update dependency org.junit.jupiter:junit-jupiter to v6.1.3 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3937">https://github.com/plengauer/Thoth/pull/3937</a></li>
<li>Fix deep docker injection deadlock caused by bash loadable mkfifo ignoring -m 666 by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3986">https://github.com/plengauer/Thoth/pull/3986</a></li>
<li>Update renovatebot/github-action action to v46.2.2 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3978">https://github.com/plengauer/Thoth/pull/3978</a></li>
<li>Update oxsecurity/megalinter action to v10 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3954">https://github.com/plengauer/Thoth/pull/3954</a></li>
<li>Update github/gh-aw-actions action to v0.86.1 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3821">https://github.com/plengauer/Thoth/pull/3821</a></li>
<li>Update plengauer/opentelemetry-github action to v5.60.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3961">https://github.com/plengauer/Thoth/pull/3961</a></li>
<li>Pin actions/upload-artifact action to v7.0.1 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3936">https://github.com/plengauer/Thoth/pull/3936</a></li>
<li>Update github/codeql-action action to v4.37.6 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3747">https://github.com/plengauer/Thoth/pull/3747</a></li>
<li>Update ghcr.io/plengauer/opentelemetry-github-workflow-instrumentation-runner Docker tag to v5.60.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3957">https://github.com/plengauer/Thoth/pull/3957</a></li>
<li>Triple timeout for SuperLinter and MegaLinter CI jobs by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3982">https://github.com/plengauer/Thoth/pull/3982</a></li>
<li>Fix report workflow failure on ubuntu-slim by pinning gh repository context by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3984">https://github.com/plengauer/Thoth/pull/3984</a></li>
<li>Update Demo injection_deep_python by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3960">https://github.com/plengauer/Thoth/pull/3960</a></li>
<li>Update Demo context_propagation_http_wget by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3958">https://github.com/plengauer/Thoth/pull/3958</a></li>
<li>Update Demo observe_subprocesses by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3934">https://github.com/plengauer/Thoth/pull/3934</a></li>
<li>Update Demo injection_shebang by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3956">https://github.com/plengauer/Thoth/pull/3956</a></li>
<li>Update Demo context_propagation_http_netcat by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3923">https://github.com/plengauer/Thoth/pull/3923</a></li>
<li>Update Demo injection_child by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3931">https://github.com/plengauer/Thoth/pull/3931</a></li>
<li>Update Demo _complex_download_github_releases by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3929">https://github.com/plengauer/Thoth/pull/3929</a></li>
<li>Update Demo injection_docker_renovate by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3935">https://github.com/plengauer/Thoth/pull/3935</a></li>
<li>Update Demo _simple_hello_world by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3955">https://github.com/plengauer/Thoth/pull/3955</a></li>
<li>Update Demo injection_deep_java by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3928">https://github.com/plengauer/Thoth/pull/3928</a></li>
<li>Remove __kill_switch from copilot-setup-steps instrumentation by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3977">https://github.com/plengauer/Thoth/pull/3977</a></li>
<li>Update dependency traceloop-sdk to v0.62.3 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3988">https://github.com/plengauer/Thoth/pull/3988</a></li>
<li>Update Demo injection_deep_node by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3963">https://github.com/plengauer/Thoth/pull/3963</a></li>
<li>Update Demo context_propagation_http_curl by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3962">https://github.com/plengauer/Thoth/pull/3962</a></li>
<li>Apply shfmt formatting and configure MegaLinter shfmt style by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3869">https://github.com/plengauer/Thoth/pull/3869</a></li>
<li>Preserve all archived Python deep-injection versions in Docker mode by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3983">https://github.com/plengauer/Thoth/pull/3983</a></li>
<li>Set executable mode on all shell scripts in <code>src/usr/share/opentelemetry_shell</code> by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3981">https://github.com/plengauer/Thoth/pull/3981</a></li>
<li>Add <code>otel4sh</code> executable wrapper via packaged injection script by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3980">https://github.com/plengauer/Thoth/pull/3980</a></li>
<li>Make job-level container skip opt-in and document the toggle by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3969">https://github.com/plengauer/Thoth/pull/3969</a></li>
<li>Fix Gradle deep-injection failure on newer Gradle daemons by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3966">https://github.com/plengauer/Thoth/pull/3966</a></li>
<li>Fix renovate-copilot-instrumentation job failing due to missing git context by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3965">https://github.com/plengauer/Thoth/pull/3965</a></li>
<li>Fix autofix reported incomplete result due to API access issue by @plengauer with @Codex in <a href="https://github.com/plengauer/Thoth/pull/3941">https://github.com/plengauer/Thoth/pull/3941</a></li>
<li>Apply autobackport.yml template update (580a975) by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3902">https://github.com/plengauer/Thoth/pull/3902</a></li>
<li>Allow MegaLinter zizmor audits to use <code>GITHUB_TOKEN</code> by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3854">https://github.com/plengauer/Thoth/pull/3854</a></li>
<li>Update Demo injection_inner_xargs_parallel by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3959">https://github.com/plengauer/Thoth/pull/3959</a></li>
<li>Fix autorerun pattern by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3992">https://github.com/plengauer/Thoth/pull/3992</a></li>
<li>Fix local redirect by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3993">https://github.com/plengauer/Thoth/pull/3993</a></li>
<li>Update github/gh-aw-actions action to v0.86.2 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3990">https://github.com/plengauer/Thoth/pull/3990</a></li>
<li>Lock file maintenance by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3979">https://github.com/plengauer/Thoth/pull/3979</a></li>
<li>Update Demo observe_subprocesses by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3999">https://github.com/plengauer/Thoth/pull/3999</a></li>
<li>Update Demo injection_deep_python by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3997">https://github.com/plengauer/Thoth/pull/3997</a></li>
<li>Update Demo injection_deep_java by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3995">https://github.com/plengauer/Thoth/pull/3995</a></li>
<li>Update Demo injection_deep_node by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3998">https://github.com/plengauer/Thoth/pull/3998</a></li>
<li>Update Demo injection_docker_renovate by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/4000">https://github.com/plengauer/Thoth/pull/4000</a></li>
<li>Update Demo _complex_download_github_releases by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3996">https://github.com/plengauer/Thoth/pull/3996</a></li>
<li>Fix caching in job-level instrumentation by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/4003">https://github.com/plengauer/Thoth/pull/4003</a></li>
<li>Automatic Version Bump by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/4001">https://github.com/plengauer/Thoth/pull/4001</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/plengauer/Thoth/compare/v5.60.0...v5.61.0">https://github.com/plengauer/Thoth/compare/v5.60.0...v5.61.0</a></p>
]]></content:encoded></item><item><title>esc-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/esc-action/</link><pubDate>Sat, 15 Aug 2026 06:48:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/esc-action/</guid><description>Version updated for https://github.com/pulumi/esc-action to version v3.2.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 200 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup and use of Pulumi ESC, a tool that helps manage shared environments, secrets, and configurations securely. It simplifies developer workflows by injecting necessary secrets directly into CI/CD pipelines, ensuring access to required resources is valid at the time of use and automatically rotated after a specified period.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pulumi/esc-action">https://github.com/pulumi/esc-action</a></strong> to version <strong>v3.2.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>200</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/esc-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup and use of Pulumi ESC, a tool that helps manage shared environments, secrets, and configurations securely. It simplifies developer workflows by injecting necessary secrets directly into CI/CD pipelines, ensuring access to required resources is valid at the time of use and automatically rotated after a specified period.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Mask only secrets by opening ESC environments with &ndash;format detailed by @seanyeh in <a href="https://github.com/pulumi/esc-action/pull/55">https://github.com/pulumi/esc-action/pull/55</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pulumi/esc-action/compare/v3.1.0...v3.2.0">https://github.com/pulumi/esc-action/compare/v3.1.0...v3.2.0</a></p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/kaniko-build-action/</link><pubDate>Sat, 15 Aug 2026 06:47:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting message to the log, taking an optional parameter to specify the name of the person to greet. It can also output the current time, making it useful for logging and tracking interactions in workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting message to the log, taking an optional parameter to specify the name of the person to greet. It can also output the current time, making it useful for logging and tracking interactions in workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/custom-amazon-bedrock-agent-action/</link><pubDate>Sat, 15 Aug 2026 06:47:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action leverages Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback using customizable prompts. It also supports integration with Amazon Bedrock Knowledge Bases to enhance analysis capabilities, offering tailored insights and context-aware responses. The action is highly flexible and adaptable for various use cases, including code quality improvement, security assessments, and performance optimizations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action leverages Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback using customizable prompts. It also supports integration with Amazon Bedrock Knowledge Bases to enhance analysis capabilities, offering tailored insights and context-aware responses. The action is highly flexible and adaptable for various use cases, including code quality improvement, security assessments, and performance optimizations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sherpa.sh/</link><pubDate>Sat, 15 Aug 2026 06:46:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-based tool that automates the deployment of web applications across various cloud providers. It allows developers to describe their infrastructure needs in plain English, and Sherpa handles the creation and configuration of servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more. This simplifies the process of deploying applications by eliminating the need for manual configuration files or DevOps expertise.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-based tool that automates the deployment of web applications across various cloud providers. It allows developers to describe their infrastructure needs in plain English, and Sherpa handles the creation and configuration of servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more. This simplifies the process of deploying applications by eliminating the need for manual configuration files or DevOps expertise.</p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/ssg-static-site-generator/</link><pubDate>Sat, 15 Aug 2026 06:45:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.34.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown content with YAML frontmatter into a complete website, handling features such as sitemaps, feeds, and SEO metadata. It works well for blogs, documentation, portfolios, and landing pages, offering options for deployment to various platforms like GitHub Pages, Netlify, and Vercel.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.34</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown content with YAML frontmatter into a complete website, handling features such as sitemaps, feeds, and SEO metadata. It works well for blogs, documentation, portfolios, and landing pages, offering options for deployment to various platforms like GitHub Pages, Netlify, and Vercel.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.34 — navigation survives a migration; nested categories; a shipped regression fixed by @spagu in <a href="https://github.com/spagu/ssg/pull/139">https://github.com/spagu/ssg/pull/139</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.33...v1.8.34">https://github.com/spagu/ssg/compare/v1.8.33...v1.8.34</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/classroom-to-sheets-integration/</link><pubDate>Sat, 15 Aug 2026 06:44:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates automatic grading from GitHub Classroom into Google Sheets, allowing instructors to store and track student results efficiently. It automatically updates the specified columns in a pre-defined Google Sheet with assignment grades based on task completion status. The integration requires setting up Google sheet API credentials and sharing them securely through GitHub secrets.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates automatic grading from GitHub Classroom into Google Sheets, allowing instructors to store and track student results efficiently. It automatically updates the specified columns in a pre-defined Google Sheet with assignment grades based on task completion status. The integration requires setting up Google sheet API credentials and sharing them securely through GitHub secrets.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>nix init</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/nix-init/</link><pubDate>Sat, 15 Aug 2026 06:43:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/nix-init/</guid><description>Version updated for https://github.com/spotdemo4/nix-init to version v1.65.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The nix-init action initializes Nix-based repositories by automating common setup steps such as creating GitHub app tokens, checking out the repository, setting up Git user and environment, installing Nix, configuring Nix settings based on a flake, and handling caching. It is designed to streamline the process for developers working with Nix in various environments, including self-hosted runners like Forgejo and GitHub Actions. The action also allows users to specify different shells from a flake for development purposes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spotdemo4/nix-init">https://github.com/spotdemo4/nix-init</a></strong> to version <strong>v1.65.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nix-init">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The nix-init action initializes Nix-based repositories by automating common setup steps such as creating GitHub app tokens, checking out the repository, setting up Git user and environment, installing Nix, configuring Nix settings based on a flake, and handling caching. It is designed to streamline the process for developers working with Nix in various environments, including self-hosted runners like Forgejo and GitHub Actions. The action also allows users to specify different shells from a flake for development purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update cachix/install-nix-action action to v31.11.1 (#8) (21e8c74252389207cfad13f42ea6b725df593bc4)</li>
<li>bump: v1.64.0 -&gt; v1.65.0 (c7537bc73ce11ca01e53bd9d119d6e46363f9888)</li>
<li>chore(deps): update spotdemo4/nix-init action to v1.64.0 (#9) (c1a6e834920f81dae782a522cfa759439ac7a1e7)</li>
</ul>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/runward-gate/</link><pubDate>Sat, 15 Aug 2026 06:42:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.35.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is an open-source delivery methodology for AI-assisted software engineering that verifies the engineering decisions behind AI-written code. It automates the process of ensuring that design decisions are followed and documented, providing a way to verify that the load-bearing decisions were actually made and written down. Runward uses plain code to verify these decisions, eliminating the need to ask an LLM about it.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.35.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Runward is an open-source delivery methodology for AI-assisted software engineering that verifies the engineering decisions behind AI-written code. It automates the process of ensuring that design decisions are followed and documented, providing a way to verify that the load-bearing decisions were actually made and written down. Runward uses plain code to verify these decisions, eliminating the need to ask an LLM about it.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The verdict becomes a portable, re-checkable, standards-legible object — and a full-repo multi-agent audit hardened it before it shipped.</p>
<ul>
<li><strong><code>check --attest</code></strong> — the verdict as an unsigned in-toto Statement v1 (predicate <code>https://runward.dev/verdict/v1</code>), bound to the exact mission state; schema-validated in CI offline against a vendored in-toto schema. Signing stays the operator&rsquo;s gesture — runward holds no key.</li>
<li><strong><code>runward verify</code></strong> — offline re-derivation on the repo alone: drift and tampered predicates fail loud; a cross-version skew is named (<code>producedBy</code>/<code>versionSkew</code>) so verdict evolution is never mistaken for forgery. Horizon-aware for <code>check --through --attest</code> prefix attestations.</li>
<li><strong><code>runward bundle</code></strong> — the delivery artifacts (attestation, seal, OSCAL, SBOM) bound into one in-toto provenance, re-hashable by any cosign/in-toto tool.</li>
<li><strong><code>runward spec-check</code></strong> — deterministic spec conformance: every acceptance criterion linked at the depth it declares (<code>#SYMBOL</code>, <code>::NAME</code>, <code>:LINE</code>), through the gate&rsquo;s own evidence layer. Linkage, never semantic satisfaction.</li>
<li><strong>JUnit committed-tool adapter</strong> — homonym-safe: every occurrence scanned, one red reddens; <code>CLASS::NAME</code> pins a case. Reads the committed report, never runs the tool.</li>
<li><strong>The shared corpus, pinned without a registry</strong> (ADR-0057, accepted) — <code>update --corpus &lt;path&gt;</code> (a path, never a registry coordinate), <code>corpusPin</code>/<code>corpusDrift</code> (advisory), org <code>migrations.json</code> merged; the no-fetch invariant proven under network-cut CI.</li>
<li><strong>9/64 signed rules · <code>rules --for --json</code> fail-loud <code>couldNotRead</code> · the ADR-0054 runtime boundary as a test (accepted) · <code>npm run bench</code> (the gate is O(cited evidence), not O(repo)) · corrected assessor-facing registers · <code>runward/claims</code> export · honest README tiering.</strong></li>
</ul>
<p>Migration note in <a href="https://github.com/stranxik/runward/blob/main/CHANGELOG.md">CHANGELOG.md</a>: two false greens die on purpose (JUnit homonyms; spec-check declared depth), three rules gain a signature.</p>
]]></content:encoded></item><item><title>Sigbound</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sigbound/</link><pubDate>Sat, 15 Aug 2026 06:41:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/sigbound/</guid><description>Version updated for https://github.com/surya-koritala/sigbound to version v2.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sigbound is a GitHub Action that automates parallel development of AI coding agents on a single repository. It merges their work in parallel and resolves conflicts automatically using a model, ensuring each merge passes tests before landing. The action handles file lanes to prevent overlap and supports run parking and continuous mode for efficient collaboration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/surya-koritala/sigbound">https://github.com/surya-koritala/sigbound</a></strong> to version <strong>v2.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sigbound">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sigbound is a GitHub Action that automates parallel development of AI coding agents on a single repository. It merges their work in parallel and resolves conflicts automatically using a model, ensuring each merge passes tests before landing. The action handles file lanes to prevent overlap and supports run parking and continuous mode for efficient collaboration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>81ceb8670e832cb4387125709e1caf24a652d9b8 feat(policy): add bounded native job graph (#194)</li>
</ul>
]]></content:encoded></item><item><title>PolyForge gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/polyforge-gate/</link><pubDate>Sat, 15 Aug 2026 06:40:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/polyforge-gate/</guid><description>Version updated for https://github.com/tensorov/polyforge-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks if a task has been gated against a PolyForge evidence ledger and verifies that the committed Merkle chain matches the anchor hash. It posts a summary comment on pull requests with gate results, pass/fail state, tail hash, and bundle SHA-256. The action requires polyforge-cli available; for self-hosted runners, it installs the CLI from crates.io.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tensorov/polyforge-action">https://github.com/tensorov/polyforge-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polyforge-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks if a task has been gated against a PolyForge evidence ledger and verifies that the committed Merkle chain matches the anchor hash. It posts a summary comment on pull requests with gate results, pass/fail state, tail hash, and bundle SHA-256. The action requires <code>polyforge-cli</code> available; for self-hosted runners, it installs the CLI from crates.io.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="polyforge-gate-action-v100">PolyForge gate action v1.0.0</h1>
<p>First release of the PolyForge gate action. Gates a task against the PolyForge
evidence ledger and verifies the committed Merkle-chain anchor, directly from
GitHub Actions.</p>
<h2 id="changelog-scaffold-commit-005544c">Changelog (scaffold commit 005544c)</h2>
<ul>
<li>Composite action (<code>runs.using: composite</code>) with four inputs:
<ul>
<li><code>task-id</code> (required): task id to gate against the ledger.</li>
<li><code>required</code> (default <code>verified,validated</code>): comma-list of required evidence states.</li>
<li><code>ledger-path</code> (default <code>.pf/ledger.jsonl</code>): ledger path relative to the workspace root.</li>
<li><code>evidence-dir</code> (default <code>.pf/evidence/</code>): evidence directory relative to the workspace root.</li>
</ul>
</li>
<li>Runs <code>polyforge-cli gate &lt;task-id&gt; --required &lt;required&gt;</code>, preferring a
pre-built workspace binary under <code>target/debug/polyforge-cli</code> and falling
back to installing the CLI from crates.io.</li>
<li>Verifies the Merkle chain against the committed anchor <code>.pf/ledger.jsonl.anchor</code>.
The ledger head hash and entry count must match the anchor, otherwise the
action fails closed (exit non-zero).</li>
<li>On <code>pull_request</code> events only, posts a gate summary PR comment with the ledger
summary, pass/fail state, tail hash, and bundle SHA-256. Push and schedule runs
stay silent on success but hard-error on failure.</li>
<li>Trust-model section in the README documents the current limitations: no
cryptographic signatures yet, tamper evidence is only meaningful within a
trusted checkout, and external anchoring is on the roadmap.</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">dtolnay/rust-toolchain@stable</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">tensorov/polyforge-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">task-id</span>: <span style="color:#ae81ff">my-task</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">required</span>: <span style="color:#ae81ff">verified,validated</span>
</span></span></code></pre></div><p>The action needs <code>polyforge-cli</code> available; a Rust toolchain setup step is
required when the workspace binary is absent (crates.io install fallback).</p>
]]></content:encoded></item><item><title>Install bashunit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/install-bashunit/</link><pubDate>Sat, 15 Aug 2026 06:39:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/install-bashunit/</guid><description>Version updated for https://github.com/TypedDevs/bashunit to version 0.48.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a testing framework for Bash scripts, providing assertions and test doubles for writing fast, simple unit tests. It supports various features such as equality checks, strings, exit codes, numeric comparisons, array length checks, file permissions, JSON validation, date comparisons, duration measurements, snapshot matching, and more. The framework is lightweight and easy to use, with a user-friendly interface that includes documentation, example tests, and shell completion options.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TypedDevs/bashunit">https://github.com/TypedDevs/bashunit</a></strong> to version <strong>0.48.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-bashunit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a testing framework for Bash scripts, providing assertions and test doubles for writing fast, simple unit tests. It supports various features such as equality checks, strings, exit codes, numeric comparisons, array length checks, file permissions, JSON validation, date comparisons, duration measurements, snapshot matching, and more. The framework is lightweight and easy to use, with a user-friendly interface that includes documentation, example tests, and shell completion options.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-improvements">✨ Improvements</h2>
<ul>
<li><code>--verbose</code> warns on Bash 3.x that coverage does not count lines run inside a subshell, so a lower percentage there explains itself (#1112)</li>
</ul>
<h2 id="-changes">🛠️ Changes</h2>
<ul>
<li>Performance: <code>--coverage</code> is roughly 5x faster and <code>--coverage-report-html</code> roughly 19x — this repo went from 16.2s to 2.9s, and a 128-file HTML report from 58.7s to 3.1s (#1092, #1096, #1098, #1099, #1102, #1104, #1110, #1117)</li>
<li>Performance: <code>./build.sh</code> is about 1.9x faster (7.6s to 4.0s), producing a byte-identical artifact (#1233)</li>
<li>Performance: cold start makes two fewer forks, about 4ms of a 65ms startup (#1124)</li>
<li>The HTML report gained a <code>Failures</code> section with each failure&rsquo;s name, <code>file:line</code> and message, and its summary now counts risky and flaky tests (#1251, #1252)</li>
<li>A <code>--filter</code> that matches nothing names the test it most likely meant: filters match the test <strong>function name</strong>, case-sensitively, not the humanized title in the report (#1237)</li>
<li><code>--env</code> with a space in the path now says the value was split on the first space to pass bootstrap arguments, and that <code>BASHUNIT_BOOTSTRAP</code> takes the path whole (#1247)</li>
<li>The bootstrap error names the actual cause — missing, a directory, or not a regular file — instead of <code>cannot read</code> for all of them (#1262)</li>
<li><code>bashunit doc &lt;filter&gt;</code> says <code>No assertion matches '&lt;filter&gt;'</code> instead of printing nothing (#1201)</li>
<li><code>install.sh</code> destination errors no longer advise a <code>-d</code> flag that does not exist; the script takes positional arguments (#1221)</li>
<li><code>bashunit learn</code> generates starter files that are valid bash, and verifies lessons against the learner&rsquo;s code rather than the hint comments in its own template (#1256, #1258)</li>
<li>The coverage HTML report handles filenames containing <code>|</code>, <code>&lt;</code> or <code>&amp;</code> (#1254)</li>
<li>A test file that fails to source without writing to stderr reports its size, so a truncated file can be told from one whose last command failed (#1137)</li>
<li>The <code>example/</code> demo is covered by the suite; nothing ran it before (#1219)</li>
<li>Docs: benchmarks are the <code>bashunit bench [path]</code> subcommand — <code>-s -b</code> and <code>--simple --bench</code> never existed (#1227)</li>
<li>Docs: test functions need a literal, lowercase <code>test_</code> prefix; the guide&rsquo;s camelCase example and its case-insensitive claim were both wrong (#1215)</li>
<li>Docs: <code>assert_equals</code> strips ANSI codes, tabs and newlines — not spaces (#1225)</li>
<li>Docs: an empty entry in the <code>-e/--env/--boot</code> file assigns an empty value; it does not restore the default (#1217)</li>
<li>Docs: <code>assert_matches</code> costs ~2.5ms per call against ~0.065ms for <code>assert_same</code>, so prefer <code>assert_contains</code> for a fixed substring (#1187)</li>
<li>Docs: a <code>@data_provider</code> test shares one snapshot across all its values; use <code>assert_match_named_snapshot &quot;$1&quot;</code> for one each (#1185)</li>
</ul>
<h2 id="-bug-fixes">🐛 Bug Fixes</h2>
<ul>
<li><code>bashunit --output junit</code> produces valid XML, and <code>--parallel --stop-on-failure</code> no longer corrupts a machine <code>--output</code> stream (#1239, #1243)</li>
<li>The HTML report escapes test titles instead of writing them into the markup (#1249)</li>
<li><code>--coverage-paths</code> accepts a path containing a space, an apostrophe or a glob character; it used to break the DEBUG trap and fail passing tests (#1245)</li>
<li>A piped <code>--parallel</code> run no longer emits a stray <code>\r  \r</code>, and an empty one renders its notice on its own line (#1239)</li>
<li>Duplicate test functions are detected under <code>--parallel</code> again; the run reported &ldquo;All tests passed&rdquo; over a file where one of two same-named tests never ran (#1147)</li>
<li>A <code>@data_provider</code> that is undefined or yields no data is reported as an error naming the provider, instead of the test vanishing behind &ldquo;No tests found&rdquo; (#1145)</li>
<li>A bootstrap file that fails to load reports it and exits non-zero through every path that loads one, instead of leaving the run with no tests and exit 0 (#1179, #1181)</li>
<li><code>bashunit bench</code> reports <code>No benchmarks found</code> and exits non-zero when the path does not exist or holds no <code>bench_</code> function (#1199)</li>
<li>A report path that is a directory fails fast with <code>is a directory, not a file</code> instead of exiting 0 with no report written (#1177)</li>
<li>A coverage run that tracked no executable line says so and names <code>--coverage-paths</code>, instead of reporting <code>Coverage 0% is below minimum N%</code> (#1171)</li>
<li><code>assert_exec &quot;cmd&quot; --exit 1</code> works under <code>--strict</code>; <code>set -e</code> aborted the test before the assertion could read the code (#1207)</li>
<li><code>assert_equals</code> no longer expands backslash escapes while normalizing, so <code>C:\</code> and <code>C:\\</code> differ and a literal <code>\t</code> is not a real tab (#1108)</li>
<li><code>assert_file_contains</code> accepts a needle starting with a dash, and <code>assert_file_not_contains</code> matches literally like its counterpart (#1108)</li>
<li>The mock/spy misuse message names a helper that exists (<code>bashunit::mock</code>, not <code>mock</code>), and reports a usable-name error instead of a raw bash syntax error (#1136, #1229)</li>
<li>A JSON test skipped for a missing <code>jq</code> is reported under its own name, not <code>bashunit::assert_json::require_jq</code> (#1223)</li>
<li>A data-provider value ending in a backslash reaches the test instead of arriving unset (#1134)</li>
<li>Coverage no longer loses hits recorded inside a command substitution; on Bash 5 a run reported 196 of 236 real hits (#1101)</li>
<li><code>install.sh</code> names the real problem when the destination is unusable, and validates it before any network call (#1197)</li>
<li><code>bashunit init</code> no longer adds a dead <code>BASHUNIT_BOOTSTRAP</code> line to <code>.env</code> on every run, and reports what it wrote (#1175)</li>
<li>A run survives its scratch directory going missing and says so once on stderr (#1163, #1167)</li>
<li>A run&rsquo;s scratch-directory cleanup can no longer widen to every concurrent run&rsquo;s (#1165)</li>
<li>TAP escapes a <code>#</code> in a test name, so <code>check # SKIP me</code> is no longer read as a directive (#1119)</li>
<li>GitHub Actions annotations are percent-encoded on Bash 3.0 too (#1121)</li>
</ul>
<h2 id="-contributors">👥 Contributors</h2>
<ul>
<li>@Chemaclass</li>
</ul>
<h2 id="checksum">Checksum</h2>
<p>SHA256: <code>9e27d930a505fcdc46e0c3275ca943d412e5df4b51dc1f5b5219d794d3b1893d</code></p>
<p><strong>Full Changelog:</strong> <a href="https://github.com/TypedDevs/bashunit/compare/0.47.0...0.48.0">0.47.0&hellip;0.48.0</a></p>
]]></content:encoded></item><item><title>Vaara Policy Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/vaara-policy-check/</link><pubDate>Sat, 15 Aug 2026 06:38:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/vaara-policy-check/</guid><description>Version updated for https://github.com/vaaraio/vaara to version v1.67.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of tracking and recording verifiable receipts for autonomous actions across various environments such as Python CLI, macOS applications, and Node.js clients. It ensures that all actions are risk-scored against predefined policies before execution, providing a tamper-evident record that can be verified offline by anyone.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaaraio/vaara">https://github.com/vaaraio/vaara</a></strong> to version <strong>v1.67.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vaara-policy-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of tracking and recording verifiable receipts for autonomous actions across various environments such as Python CLI, macOS applications, and Node.js clients. It ensures that all actions are risk-scored against predefined policies before execution, providing a tamper-evident record that can be verified offline by anyone.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1671---2026-08-14">[1.67.1] - 2026-08-14</h2>
<p>Everything here was found by opening the pages and looking at them.</p>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>The dashboard called itself read-only in three places and is not.</strong>
The startup banner, the command docstring and the <code>--help</code> line all said so,
while <code>/api/config</code> writes the <code>config.json</code> the gate reads and <code>/api/policy</code>
writes the escalate and deny thresholds. Those thresholds decide whether an
agent is stopped, so an operator was told the wrong thing about the part that
matters most. The banner now states that settings and thresholds are writable
and that writes need the per-run token served only in that page.</li>
<li><strong>The theme toggle did nothing.</strong> An explicit light choice removed the
<code>data-theme</code> attribute and fell through to the operating system rule, so
choosing light on a dark machine changed nothing.</li>
<li><strong>The Resin and the dashboard applied the stored theme after first paint</strong>,
so both rendered in the operating system colourway and then snapped to the
saved choice when the body script ran. Only the homepage did this correctly.</li>
<li><strong>Both pages fetched the wordmark from raw.githubusercontent.com.</strong> That was
the only third-party request either page made, on a page whose central claim
is that nothing leaves your tab and that it works with the network off. With
the network off the mark was the one thing that did not render. The marks now
ship in <code>webpage/</code> and load from the same origin, and
<code>tests/test_webpage_assets.py</code> fails if any <code>src</code> on either page ever points
off-origin again.</li>
<li>The Resin asked for a receipt file before showing anything, and its wording
read like an upload on a page that uploads nothing.</li>
<li>The dashboard wordmark was <code>min(58vw,300px)</code> against <code>min(60vw,440px)</code> on the
other two surfaces, so the mark changed size depending on which one you
opened.</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li><strong>Search the Resin by public key.</strong> Paste a public key and the log returns
every head published with it. No account and no sign-in, because the key is
the identity, and the answer comes from the log rather than from us. A pasted
private key is refused outright with a warning.</li>
<li><strong>A log entry renders in the page&rsquo;s own layout</strong> instead of sending the
reader to the log&rsquo;s raw API response: log index, integrated time, entry type,
data digest, log id, tree size at inclusion, root hash, inclusion proof path
length, checkpoint and signed entry timestamp. The raw response stays one
click away, because that is the authority and this is a render of it.</li>
<li><strong>The dashboard reads and writes the policy thresholds</strong> through the same
validator the pipeline uses, backing the file up first and refusing any edit
the validator rejects.</li>
<li>The search moved into its own card at the top of the Resin, favicons, and a
corner link from the dashboard to the Resin marked as outbound because it is
the only thing on that page that leaves the machine.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong><code>Resin</code> standing alone now reads <code>Vaara Resin</code> wherever it stood in for the
brand</strong>: the homepage call to action, the verify page&rsquo;s section headings and
opening sentence, and the dashboard&rsquo;s corner link. The sentence explaining
where the name comes from keeps the common noun.</li>
<li>The demo receipt states that <code>agent-decision/v0.1</code> is Vaara&rsquo;s own open
proposal on in-toto/attestation#554 rather than a registered in-toto
predicate. Reading the URL alone, in-toto looked like it had endorsed it.</li>
<li><code>docs/PRIOR_ART.md</code> carries the v1.67.0 rows, now that the release date is
public and checkable against GitHub and PyPI.</li>
</ul>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/vibgrate-scan/</link><pubDate>Sat, 15 Aug 2026 06:36:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.814.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the local analysis of codebases to provide insights into drift, drift risk index, and actionable upgrade priorities using a code graph. It helps in maintaining code quality, preventing technical debt, and ensuring compatibility with dependencies. The tool runs on the developer’s machine without relying on external APIs or data leaving the repository unless necessary.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.814.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the local analysis of codebases to provide insights into drift, drift risk index, and actionable upgrade priorities using a code graph. It helps in maintaining code quality, preventing technical debt, and ensuring compatibility with dependencies. The tool runs on the developer&rsquo;s machine without relying on external APIs or data leaving the repository unless necessary.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268142">Vibgrate CLI 2026.814.2</h1>
<p><em>Released 2026-08-14</em></p>
<p>This release of the Vibgrate CLI introduces significant documentation improvements for the <code>vg code</code> and <code>vg evidence</code> commands, clarifying their functionalities and usage. Users can expect enhanced guidance on approval modes, lifecycle processes, and exit codes.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="improved">Improved</h3>
<ul>
<li><code>vg code</code> is now clearly documented as a coding agent with a default path in the multi-step tool loop, including a comprehensive section in the README.</li>
<li>The README for <code>vg evidence</code> now explains the frozen release manifest, the lifecycle stages, and the meanings of the various states, along with exit codes for CI gating.</li>
<li><code>vg code --help</code> has been updated to accurately reflect that <code>--apply</code>/<code>--yes</code> apply only to the one-shot <code>--single</code> path.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.814.1, interleaved on one runner against the pinned corpus (189 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21790 count</td>
          <td>21790 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>11110 count</td>
          <td>11110 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.94 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>620.20 ms</td>
          <td>616.50 ms</td>
      </tr>
  </tbody>
</table>
<p>2 regression(s) — published, not omitted:</p>
<ul>
<li>Tasks passed on both arms: 33 → 31 (-6.1%)</li>
<li>Comparable-task rate (both arms passed / total): 0.94 → 0.89 (-6.1%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.814.2">https://vibgrate.com/changelog/cli/2026.814.2</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/b.ia-accessibility-checker/</link><pubDate>Sat, 15 Aug 2026 06:35:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/15/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in your CI/CD pipeline. It defines an audience and requires a certain percentage of WCAG guidelines to be met, helping companies avoid costly external solutions and focus on user experience. This action uses AI to analyze code compliance with the specified guidelines, ensuring products are accessible by focusing on larger audiences.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in your CI/CD pipeline. It defines an audience and requires a certain percentage of WCAG guidelines to be met, helping companies avoid costly external solutions and focus on user experience. This action uses AI to analyze code compliance with the specified guidelines, ensuring products are accessible by focusing on larger audiences.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>mockdr — Multi-EDR Mock Server</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/mockdr-multi-edr-mock-server/</link><pubDate>Fri, 14 Aug 2026 22:37:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/mockdr-multi-edr-mock-server/</guid><description>Version updated for https://github.com/mockdr/mockdr to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The mockdr action is a self-contained multi-EDR mock server that provides realistic data and response formats for eight security platforms, including SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Elastic Security, Cortex XDR, Splunk SIEM, and Microsoft Sentinel. It supports various authentication methods and response formats to simulate real API interactions without the need for live environments or lab licenses. The action is designed to facilitate testing and development of EDR integration tools and automation scripts across multiple platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mockdr/mockdr">https://github.com/mockdr/mockdr</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mockdr-multi-edr-mock-server">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The mockdr action is a self-contained multi-EDR mock server that provides realistic data and response formats for eight security platforms, including SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Elastic Security, Cortex XDR, Splunk SIEM, and Microsoft Sentinel. It supports various authentication methods and response formats to simulate real API interactions without the need for live environments or lab licenses. The action is designed to facilitate testing and development of EDR integration tools and automation scripts across multiple platforms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First tagged release since the project was opened up; <code>v1.0.4</code> pointed at the
initial commit. The major bump reflects two behaviour changes rather than a
rewrite: an unparseable OData <code>$filter</code> is now refused instead of quietly
returning the wrong rows, and the UI moved to Tailwind CSS v4.</p>
<h3 id="security">Security</h3>
<ul>
<li>Dependency advisories published since the last refresh are cleared:
<code>python-multipart</code> 0.0.22 → 0.0.32 (PYSEC-2026-3036/3037/3038/3039/3040) and
<code>pytest</code> 9.0.2 → 9.0.3 (PYSEC-2026-1845), plus transitive frontend bumps of
<code>form-data</code>, <code>nanoid</code>, <code>picomatch</code>, <code>postcss</code> and <code>yaml</code>. <code>pip-audit</code> and
<code>npm audit</code> both report zero vulnerabilities.</li>
<li>Splunk index creation, HEC token management and KV Store collection
management now require an administrator role. <code>require_splunk_admin</code> existed
but was never applied, so the seeded <code>viewer</code> could create indexes and mint
HEC tokens. <code>sc_admin</code> counts as an administrator, as it does in Splunk Cloud.</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li>OData <code>$filter</code> supports <code>endswith(field,'value')</code>, which real Graph serves
and mockdr previously rejected.</li>
<li>Unquoted <code>true</code>, <code>false</code>, <code>null</code>, <code>Edm.Guid</code> and ISO-8601 date/time literals
are recognised in <code>$filter</code>, as OData v4 writes them.</li>
<li>EDR→SIEM bridging is live (ADR-009): the Splunk and Sentinel bridges are
registered at startup and EDR mutations publish to the event bus, so a
Defender alert or a triggered scenario now appears in the SIEMs. Both bridges
and the bus were previously unreachable code.</li>
<li>MDE list endpoints support <code>$count=true</code>, returning <code>@odata.count</code>.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>An unparseable or unsupported OData <code>$filter</code> returns <code>400</code> instead of
being partly ignored.</strong> Input the parser could not read used to be skipped,
which <em>widened</em> the filter — <code>$filter=@@@</code> returned every record with a
<code>200</code>, and a stray paren silently dropped the rest of the expression.
Unsupported-but-valid syntax (<code>not</code>, <code>in</code>, nested functions) previously
raised and surfaced as <code>500</code>. Both now answer <code>400</code> in the vendor&rsquo;s error
envelope, matching Defender and Graph. No filter that worked before stops
working.</li>
<li><strong>The UI is built with Tailwind CSS v4.</strong> Tailwind&rsquo;s default palette moved to
OKLCH, so built-in colours (<code>text-green-400</code> and friends) render slightly
more vivid; a 13-page screenshot comparison found 12 pages byte-identical and
the custom <code>s1-*</code> palette unchanged.</li>
<li>The version is defined once per workspace — <code>config.APP_VERSION</code>,
<code>pyproject.toml</code> and <code>package.json</code> — and the sidebar footer reads it at
build time instead of hardcoding a string. The five sources previously
disagreed. A unit test now fails if they drift apart.</li>
<li>Dependencies refreshed: FastAPI 0.141.1, faker 40.36.0, ruff 0.16.2,
pytest-cov 7.1.0, pre-commit 4.6.2, vue-router 5.2.0, lucide-vue-next 1.0.0,
jsdom 30.0.1 and <code>@types/node</code> 26.2.0.</li>
<li>The Graph, MDE and Sentinel token endpoints return OAuth 2.0 errors —
<code>{&quot;error&quot;: &quot;...&quot;, &quot;error_description&quot;: &quot;AADSTS...&quot;, &quot;error_codes&quot;: [...]}</code> —
instead of the OData envelope of the API they sit in front of. MSAL and other
OAuth clients read those keys.</li>
<li><code>GET /graph/v1.0/me</code> returns <code>400 Request_BadRequest</code> under app-only
authentication, as real Graph does, instead of returning the first seeded user.</li>
<li>Splunk endpoints now answer in Atom XML unless <code>output_mode=json</code> is
requested, as splunkd does. HEC still always answers JSON.</li>
<li>Sentinel management-plane requests now require <code>?api-version=</code>, as Azure
Resource Manager does. The Log Analytics query endpoint is unaffected.</li>
<li>Graph <code>$count=true</code> now requires <code>ConsistencyLevel: eventual</code> instead of being
answered regardless.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><code>contains()</code> and <code>startswith()</code> in an OData <code>$filter</code> returned <code>500</code> on every
call, on both MDE and Graph — the tokeniser consumed the opening paren as
part of the function token and the parser then demanded it again. These are
the forms the XSOAR MDE integration and Microsoft&rsquo;s Graph documentation lead
with. Graph imports the parser from MDE, so one defect reached both.</p>
</li>
<li>
<p><code>and</code> bound <em>looser</em> than <code>or</code> in an OData <code>$filter</code>, inverting the
precedence OData specifies: <code>a and b or c</code> evaluated as <code>a and (b or c)</code>, so
records matching only the <code>or</code> arm were dropped. The parser builds a tree
rather than a flat clause list, and parentheses nest correctly.</p>
</li>
<li>
<p><code>accountEnabled eq true</code> matched nothing and <code>ne true</code> matched everything —
unquoted keywords were compared as strings against <code>str(True)</code>, i.e. <code>&quot;True&quot;</code>.</p>
</li>
<li>
<p>Unquoted timestamps were truncated to their year, so <code>createdDateTime ge 2026-08-08T00:00:00Z</code> compared against <code>2026</code> and answered far more coarsely
than asked. Unquoted GUIDs were shredded the same way.</p>
</li>
<li>
<p>A doubled quote — OData&rsquo;s escape for a literal one — ended the string, so
<code>startswith(displayName,'O''Brien')</code> matched every name starting with <code>O</code>.</p>
</li>
<li>
<p>Deeply nested parentheses raised <code>RecursionError</code> and surfaced as <code>500</code>,
reachable from a short query string. Nesting is capped.</p>
</li>
<li>
<p>Every in-repo caller of the Sentinel operations endpoint omitted the
<code>api-version</code> parameter that ARM enforcement had just made mandatory,
including the UI&rsquo;s health check, which returned <code>400</code> at runtime. The test
fixture supplied the parameter automatically, hiding it from the suite.</p>
</li>
<li>
<p><code>apply_graph_filter</code> leaked its synthetic <code>_lambda_*</code> keys into the caller&rsquo;s
records when a filter failed to parse; cleanup now runs unconditionally.</p>
</li>
<li>
<p>Cortex XDR advanced authentication now uses the documented scheme —
<code>SHA256(key + nonce + timestamp)</code> over the plain concatenation — instead of an
HMAC over <code>nonce:timestamp</code>, which rejected every client built to Palo Alto&rsquo;s
specification. Standard authentication (the API key in <code>Authorization</code>) is
supported as well.</p>
</li>
<li>
<p>Request-validation failures are returned in the mocked vendor&rsquo;s error envelope
with the status that vendor uses, instead of FastAPI&rsquo;s <code>422 {&quot;detail&quot;: [...]}</code>,
which no mocked API emits.</p>
</li>
<li>
<p><code>POST /mde/api/indicators</code> now rejects a body missing <code>indicatorValue</code>,
<code>indicatorType</code>, <code>action</code> or <code>title</code> with <code>400 BadRequest</code> instead of creating
an indicator with empty fields.</p>
</li>
<li>
<p>Authorization scheme names are matched case-insensitively for Sentinel and
Splunk, per RFC 7235.</p>
</li>
<li>
<p>Splunk accepts a session key in its own <code>Authorization: Splunk &lt;key&gt;</code> scheme,
not only as <code>Bearer</code>.</p>
</li>
<li>
<p>Graph reports a missing resource with the code its sub-API uses:
<code>Request_ResourceNotFound</code> for directory objects, <code>ErrorItemNotFound</code> for
Outlook mail, <code>itemNotFound</code> for drive items and <code>notFound</code> for the security
API.</p>
</li>
<li>
<p>A state snapshot now covers every seeded collection. Graph, Sentinel, Splunk
and hash exceptions were absent from the registry, and because loading a
snapshot skips seeding, restarting with <code>MOCKDR_PERSIST</code> left those vendors
permanently empty. A coverage test now fails if a new collection is missed.</p>
</li>
<li>
<p>Sentinel rejects a <code>$skipToken</code> it did not issue with <code>400 InvalidSkipToken</code>
instead of raising <code>ValueError</code> and returning a 500, and <code>nextLink</code> is now the
absolute, followable URL ARM returns rather than a bare <code>?$skipToken=</code>.</p>
</li>
<li>
<p><code>POST /iocs/bulk</code> accepts a single indicator sent as an object instead of
silently discarding it and reporting success.</p>
</li>
<li>
<p>Activity records evicted from the bounded order deque are deleted with it, so
<code>count()</code> and <code>list_activities()</code> no longer diverge past 10,000 activities.</p>
</li>
<li>
<p>The Webhooks UI reads <code>eventTypes</code> and <code>createdAt</code>, the field names the API
actually returns; it previously read snake_case and threw while rendering.</p>
</li>
<li>
<p><code>frontend/.env</code> is created from <code>.env.example</code> by <code>start.sh</code> and the Docker
build. Vite inlines <code>VITE_*</code> at build time, so without it every vendor client
in the UI authenticated as <code>undefined</code>.</p>
</li>
<li>
<p><code>xdr_api_key_repo.get_by_key_id</code> is a single dict lookup instead of rebuilding
an index on every call, matching what its docstring already claimed.</p>
</li>
<li>
<p>Graph, MDE and Sentinel token endpoints now accept the tenant-scoped URL real
Entra ID uses (<code>/{tenant}/oauth2/v2.0/token</code>) in addition to the bare path, so
clients that mirror the Microsoft authority shape no longer fall through to
the SPA catch-all and get a misleading <code>405 Method Not Allowed</code> (<a href="https://github.com/mockdr/mockdr/issues/22">#22</a>).
Like Entra, the segment accepts the tenant GUID or a verified domain name; a
tenant that matches neither is rejected with <code>400 invalid_request</code>
(AADSTS90002). Set <code>MOCKDR_STRICT_TENANT=false</code> to accept any tenant.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Full-site SEO Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/full-site-seo-audit/</link><pubDate>Fri, 14 Aug 2026 22:36:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/full-site-seo-audit/</guid><description>Version updated for https://github.com/nurkamol/seo-audit to version v1.6.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the SEO audit of a website by crawling its sitemap and checking every page for errors in metadata, structured data, and link structure. It solves common issues that single-page graders may overlook and provides comprehensive reports on technical correctness across all pages of a site.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nurkamol/seo-audit">https://github.com/nurkamol/seo-audit</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/full-site-seo-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the SEO audit of a website by crawling its sitemap and checking every page for errors in metadata, structured data, and link structure. It solves common issues that single-page graders may overlook and provides comprehensive reports on technical correctness across all pages of a site.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong><code>--verbose</code> prints each request as it happens.</strong> A run was silent from the
first line to the last: on a 53-page site, <code>crawling …</code> and then twenty
seconds of nothing before the whole report arrived at once. A slow site looked
exactly like a hung one, and there was no way to tell which page it was
sitting on.</p>
<p>Covers every stage that takes time — sitemap discovery, the page crawl, the
link and image sweeps, hreflang alternates, redirect-map rules, and PageSpeed
Insights, which announces each measurement <em>before</em> making it because each one
costs about twelve seconds.</p>
<p>Plain lines rather than a spinner or a redrawing counter, deliberately: a long
run is exactly the one whose output gets piped to a file or read back out of a
CI log, and neither can show a cursor trick. A timeout arrives as status <code>0</code>,
so a stall stays on screen rather than being overwritten.</p>
<p>Written to <strong>stderr</strong>, so <code>--json</code> and <code>--md</code> are untouched. <code>--quiet</code> wins
over <code>--verbose</code> — asking for silence and getting a running commentary would
be the more surprising of the two.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/run-aer-tests/</link><pubDate>Fri, 14 Aug 2026 22:35:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.29.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of Apex unit tests locally without using an org. It provides a local environment that mimics Salesforce’s runtime by loading metadata, allowing developers to run tests and debug code in their own IDEs like VS Code or IntelliJ. The action supports various features such as SOQL queries, DML operations, governor limits, standard library methods, and testing framework functionalities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.29</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of Apex unit tests locally without using an org. It provides a local environment that mimics Salesforce&rsquo;s runtime by loading metadata, allowing developers to run tests and debug code in their own IDEs like VS Code or IntelliJ. The action supports various features such as SOQL queries, DML operations, governor limits, standard library methods, and testing framework functionalities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.29</p>
<ul>
<li>
<p>Reject Unrecognized &ndash;feature Values At Flag Parse Time</p>
</li>
<li>
<p>Give Each Flow Get Records Element Its Own Local In The Queueable</p>
</li>
<li>
<p>Read Flow Polymorphic References Only On The Named Branch</p>
</li>
<li>
<p>Accept The Id Field As An Upsert External ID</p>
</li>
<li>
<p>Convert Flow Custom Error, Collection Filter, And Collection Sort Elements</p>
</li>
<li>
<p>Back ConnectApi Feed Posts And Reads With FeedItem Storage</p>
</li>
<li>
<p>Add Health Cloud Care Plan Objects To The Feature Schema</p>
</li>
<li>
<p>Back ConnectApi Feed Comments With FeedComment Storage</p>
</li>
<li>
<p>Resolve $Flow.InterviewGuid And Reserve The bulk Identifier</p>
</li>
<li>
<p>Auto-Enable Features From SObjectField Tokens And Fix Health Cloud Flags</p>
</li>
<li>
<p>Convert The FIND Function In Flow Formulas</p>
</li>
<li>
<p>Back ConnectApi Feed Likes With FeedLike Storage</p>
</li>
<li>
<p>Complete The ConnectApi Feed Element Edit And Delete Path</p>
</li>
<li>
<p>Fix DescribeFieldResult.isDefaultedOnCreate</p>
</li>
<li>
<p>Add UserServicePresence To The Omni-Channel Feature Schema</p>
</li>
<li>
<p>Resolve $Profile And $Organization In Flows And Correct Id Checksums</p>
</li>
<li>
<p>Auto-Enable Enterprise Territory Management From Object References</p>
</li>
<li>
<p>Fix ConnectApi Feed Element Representation</p>
</li>
<li>
<p>Store A Flow Create Records Element&rsquo;s Output As The New Record&rsquo;s Id</p>
</li>
<li>
<p>Include Tabs And Visualforce Pages In Packages</p>
</li>
<li>
<p>Report Package Tabs And Visualforce Pages In List And Unpack</p>
</li>
<li>
<p>Strip Package Namespace From Mock Package Components</p>
</li>
<li>
<p>Convert Flow TRIM, CONTAINS, Text +, And Process Builder Wait Elements</p>
</li>
<li>
<p>Add The Survey Objects Behind SurveySettings.enableSurvey</p>
</li>
<li>
<p>Support Method Declarations In Trigger Bodies</p>
</li>
<li>
<p>Back ConnectApi Chatter Groups With CollaborationGroup Storage</p>
</li>
<li>
<p>Add The Remaining Survey Objects And Filter Them Like Salesforce Does</p>
</li>
<li>
<p>Auto-Enable The Team Selling Objects From Static Apex References</p>
</li>
<li>
<p>Back ConnectApi Group Records And Announcements With Storage</p>
</li>
<li>
<p>Back Chatter Group Membership Requests With Storage</p>
</li>
<li>
<p>Match Flow Null Semantics And Add Subflow, Approval Submit, Fault Support</p>
</li>
<li>
<p>Read Stored Groups From The Chatter Group List And Batch Readers</p>
</li>
<li>
<p>Bind StubProvider handleMethodCall Parameters Positionally</p>
</li>
<li>
<p>Fix Semantics At The Stub Return And JSON Temporal Boundaries</p>
</li>
<li>
<p>Load Minimal Fixtures Instead Of Full Metadata Trees In cmd Tests</p>
</li>
<li>
<p>Add The Health Cloud Assessment Objects</p>
</li>
<li>
<p>Skip Formula Date Validation, Update Flow Collections, Model Modify All Data</p>
</li>
<li>
<p>Store Chatter Group Photos And Enforce Unique Group Names</p>
</li>
<li>
<p>Parse Date.valueOf Fields As Greedy Digit Runs</p>
</li>
<li>
<p>Add The WorkplaceCommandCenter Feature</p>
</li>
<li>
<p>Drop The All-False FieldPermissions Seed And Enforce Row-Existence Semantics</p>
</li>
<li>
<p>Store Chatter Group Membership Roles And Page Group Members</p>
</li>
<li>
<p>Preserve Double Rendering In Implicit Double-To-Decimal Conversions</p>
</li>
<li>
<p>Derive Person Account Runtime Behavior From The Loaded Schema</p>
</li>
<li>
<p>Read And Write A Group&rsquo;s Chatter Email Frequency</p>
</li>
<li>
<p>Support Latitude And Longitude Field Access On System.Location</p>
</li>
<li>
<p>Require Name On List Custom Settings</p>
</li>
</ul>
]]></content:encoded></item><item><title>yaml-workflow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/yaml-workflow/</link><pubDate>Fri, 14 Aug 2026 22:34:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/yaml-workflow/</guid><description>Version updated for https://github.com/orieg/yaml-workflow to version v0.9.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary yaml-workflow is a lightweight, GitOps-based workflow engine that allows you to define reproducible CI/CD pipelines and data processing tasks using plain YAML files. It simplifies task automation by reducing infrastructure overhead and provides features like parallel execution, state persistence, and secret validation. The tool supports multiple task types, workflow composition via imports, and is suitable for local, CI, or any machine with Python installed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/orieg/yaml-workflow">https://github.com/orieg/yaml-workflow</a></strong> to version <strong>v0.9.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yaml-workflow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>yaml-workflow</strong> is a lightweight, GitOps-based workflow engine that allows you to define reproducible CI/CD pipelines and data processing tasks using plain YAML files. It simplifies task automation by reducing infrastructure overhead and provides features like parallel execution, state persistence, and secret validation. The tool supports multiple task types, workflow composition via imports, and is suitable for local, CI, or any machine with Python installed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump the github-actions group with 4 updates by @dependabot[bot] in <a href="https://github.com/orieg/yaml-workflow/pull/25">https://github.com/orieg/yaml-workflow/pull/25</a></li>
<li>chore(deps): bump the github-actions group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/orieg/yaml-workflow/pull/27">https://github.com/orieg/yaml-workflow/pull/27</a></li>
<li>chore(deps-dev): bump the dependencies group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/orieg/yaml-workflow/pull/29">https://github.com/orieg/yaml-workflow/pull/29</a></li>
<li>chore(deps): bump codecov/codecov-action from 6 to 7 in the github-actions group by @dependabot[bot] in <a href="https://github.com/orieg/yaml-workflow/pull/31">https://github.com/orieg/yaml-workflow/pull/31</a></li>
<li>chore(deps-dev): bump black from 26.5.0 to 26.5.1 in the dependencies group by @dependabot[bot] in <a href="https://github.com/orieg/yaml-workflow/pull/30">https://github.com/orieg/yaml-workflow/pull/30</a></li>
<li>chore(deps): bump the github-actions group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/orieg/yaml-workflow/pull/33">https://github.com/orieg/yaml-workflow/pull/33</a></li>
<li>chore(deps-dev): bump the dependencies group with 2 updates by @dependabot[bot] in <a href="https://github.com/orieg/yaml-workflow/pull/34">https://github.com/orieg/yaml-workflow/pull/34</a></li>
<li>fix: clear 26 CodeQL clear-text-logging false positives by @orieg in <a href="https://github.com/orieg/yaml-workflow/pull/35">https://github.com/orieg/yaml-workflow/pull/35</a></li>
<li>fix(engine): mask declared secrets in dry-run previews and param-default logs by @orieg in <a href="https://github.com/orieg/yaml-workflow/pull/36">https://github.com/orieg/yaml-workflow/pull/36</a></li>
<li>chore(release): bump version to 0.9.3 by @orieg in <a href="https://github.com/orieg/yaml-workflow/pull/37">https://github.com/orieg/yaml-workflow/pull/37</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/orieg/yaml-workflow/compare/v0.9.2...v0.9.3">https://github.com/orieg/yaml-workflow/compare/v0.9.2...v0.9.3</a></p>
]]></content:encoded></item><item><title>quantakrypto Quantum Readiness Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/quantakrypto-quantum-readiness-scan/</link><pubDate>Fri, 14 Aug 2026 22:31:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/quantakrypto-quantum-readiness-scan/</guid><description>Version updated for https://github.com/quantakrypto/pqc-tools to version v0.12.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action @quantakrypto/action automates the process of identifying and reporting quantum-vulnerable cryptography in a codebase during CI. It runs the qScan tool to scan for such vulnerabilities, writes SARIF files for upload, annotates diffs, and fails the build only on newly identified issues. This ensures continuous monitoring and compliance with post-quantum standards in software development pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quantakrypto/pqc-tools">https://github.com/quantakrypto/pqc-tools</a></strong> to version <strong>v0.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quantakrypto-quantum-readiness-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <strong><code>@quantakrypto/action</code></strong> automates the process of identifying and reporting quantum-vulnerable cryptography in a codebase during CI. It runs the <code>qScan</code> tool to scan for such vulnerabilities, writes SARIF files for upload, annotates diffs, and fails the build only on newly identified issues. This ensures continuous monitoring and compliance with post-quantum standards in software development pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Additions only. Nothing here is breaking, so the Action stays on <code>@v1</code>: that is exactly the case a moving major tag exists for.</p>
<h2 id="added--a-real-crypto-inventory">Added — a real crypto inventory</h2>
<p>What the tool called an inventory was a findings list under another name. <code>buildInventory</code> counted findings, <code>toCbom</code> iterated findings, and all 47 detectors fire only on cryptography that is <em>wrong</em>. <code>ML-KEM</code> appeared in the entire codebase solely inside remediation strings.</p>
<p>So a repository that had migrated correctly was <strong>indistinguishable from one that uses no cryptography at all</strong>: both reported an empty inventory and 100/100. You could prove nothing was broken; you could not prove you had done the work.</p>
<p><code>inventory.assets</code> now carries every algorithm found, grouped with a count and a few example sites. The classical half is derived from the findings, which already carry algorithm, file and line, so it can never disagree with the findings list. The other half is a new pass over the PQC families, the hybrids, the pre-standard CRYSTALS names (kept separate, because a Kyber768 build is not an ML-KEM-768 build) and the symmetric and hash primitives.</p>
<p>Symmetric is classified <code>not-quantum-relevant</code> rather than <code>quantum-safe</code>. Grover halves the effective key length, which matters at 128 bits and does not break 256; calling AES quantum-safe beside ML-KEM would flatten a real distinction.</p>
<p>Detection is lexical, like the rest of the engine, so a mention in prose counts. Use <code>--ignore</code> for content that describes cryptography without using it.</p>
<h2 id="added--findings-carry-their-baseline-fingerprint">Added — findings carry their baseline fingerprint</h2>
<p>The same id <code>qscan --write-baseline</code> writes, so CI and any consumer hold one identity for a finding rather than two that agree until one is edited. It excludes line and column, so an edit that shifts code down a file does not resurface a finding as new.</p>
<h2 id="fixed--the-json-reporter-dropped-the-inventory">Fixed — the JSON reporter dropped the inventory</h2>
<p>It names its <code>inventory</code> fields explicitly, so <code>assets</code> was computed and then silently discarded. The third field lost at a hand-written boundary, after the remediation and the fingerprint.</p>
<h2 id="fixed--an-algorithm-named-in-key-position-is-not-a-use-of-it">Fixed — an algorithm named in key position is not a use of it</h2>
<p><code>.cargo_vcs_info.json</code> carries <code>{&quot;sha1&quot;: &quot;&lt;commit&gt;&quot;}</code> for the git revision, and the first inventory run read that as &ldquo;this project uses SHA-1&rdquo;. A name in key position is metadata now. The guard initially also dropped <code>ml_kem_768::keypair()</code>, because Rust&rsquo;s path separator is a colon too; the tests caught it.</p>
]]></content:encoded></item><item><title>Xcode Packages Update</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/xcode-packages-update/</link><pubDate>Fri, 14 Aug 2026 22:30:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/xcode-packages-update/</guid><description>Version updated for https://github.com/quver/xcode-packages-update to version v4.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary A GitHub Action that resolves and reports Xcode Swift Package Manager dependencies, including changes in package versions. It generates an HTML dependency report, a CycloneDX SBOM, and automatically classifies packages as App or Development. This action can be used with both Xcode projects and workspaces and integrates with vulnerability scanning tools like Trivy for comprehensive security checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quver/xcode-packages-update">https://github.com/quver/xcode-packages-update</a></strong> to version <strong>v4.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xcode-packages-update">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>A GitHub Action that resolves and reports Xcode Swift Package Manager dependencies, including changes in package versions. It generates an HTML dependency report, a CycloneDX SBOM, and automatically classifies packages as App or Development. This action can be used with both Xcode projects and workspaces and integrates with vulnerability scanning tools like Trivy for comprehensive security checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #81 from quver/release/v4.0.2 (f0aa022)</li>
<li>release: v4.0.2 (3767881)</li>
<li>Merge pull request #80 from quver/dependabot/npm_and_yarn/dev-dependencies-e1dac8ee3a (82acb6b)</li>
<li>build(deps-dev): bump the dev-dependencies group across 1 directory with 4 updates (84c588e)</li>
<li>Merge pull request #78 from quver/release/v4.0.1 (9e0e694)</li>
<li>release: v4.0.1 (671b4de)</li>
<li>Merge pull request #75 from quver/dependabot/npm_and_yarn/dev-dependencies-6155092b98 (c294437)</li>
<li>build(deps-dev): bump the dev-dependencies group across 1 directory with 3 updates (1b36406)</li>
<li>Merge pull request #77 from quver/dependabot/npm_and_yarn/postcss-8.5.25 (7892ef0)</li>
<li>build(deps-dev): bump postcss from 8.5.22 to 8.5.25 (83e37e1)</li>
</ul>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/agentauditkit-mcp-security-scan/</link><pubDate>Fri, 14 Aug 2026 22:29:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.76.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: AgentAuditKit automates the security audit of AI agent pipelines, detecting misconfigurations, hardcoded secrets, tool poisoning, and trust boundary violations. It runs offline and deterministically, ensuring consistent findings across different environments. The tool produces auditor-ready compliance-evidence packs, covering a wide range of security categories including 298 rules and 89 scanner modules.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.76</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong>
AgentAuditKit automates the security audit of AI agent pipelines, detecting misconfigurations, hardcoded secrets, tool poisoning, and trust boundary violations. It runs offline and deterministically, ensuring consistent findings across different environments. The tool produces auditor-ready compliance-evidence packs, covering a wide range of security categories including 298 rules and 89 scanner modules.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.76
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.76
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.76</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Two CVE rules, the strict_loading warm-registry fix, real session transcripts, and CVE-to-rule latency as a published number by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/583">https://github.com/sattyamjjain/agent-audit-kit/pull/583</a></li>
<li>Triage the 2026-08-13 CVE wave: two pins, one reference, five documented out-of-scope by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/584">https://github.com/sattyamjjain/agent-audit-kit/pull/584</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.74...v0.3.76">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.74...v0.3.76</a></p>
]]></content:encoded></item><item><title>Invariant SAT Zero-IP ZK Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/invariant-sat-zero-ip-zk-scanner/</link><pubDate>Fri, 14 Aug 2026 22:28:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/invariant-sat-zero-ip-zk-scanner/</guid><description>Version updated for https://github.com/sellhotitemz-hue/invariant-sat-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Invariant SAT ZK Circuit Security Scanner automates zero-knowledge circuit soundness and exploit witness scanning for GitHub CI/CD pipelines. It identifies under-constrained signals and proof forgery vulnerabilities before deploying code to production, ensuring the security of cryptographic circuits used in blockchain applications. The action supports various types of circuits including R1CS, SP1 zkVM AIR traces, Halo2 Plonkish matrices, and Aztec Noir smart contracts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sellhotitemz-hue/invariant-sat-action">https://github.com/sellhotitemz-hue/invariant-sat-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/invariant-sat-zero-ip-zk-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Invariant SAT ZK Circuit Security Scanner automates zero-knowledge circuit soundness and exploit witness scanning for GitHub CI/CD pipelines. It identifies under-constrained signals and proof forgery vulnerabilities before deploying code to production, ensuring the security of cryptographic circuits used in blockchain applications. The action supports various types of circuits including R1CS, SP1 zkVM AIR traces, Halo2 Plonkish matrices, and Aztec Noir smart contracts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sellhotitemz-hue/invariant-sat-action/commits/v1.0.0">https://github.com/sellhotitemz-hue/invariant-sat-action/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/custom-amazon-bedrock-agent-action/</link><pubDate>Fri, 14 Aug 2026 22:26:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in pull requests (PRs) and provides feedback. It is customizable and integrates with Amazon Bedrock Knowledge Bases, enhancing the action’s capability by providing enriched, context-aware insights. The action is designed for code quality improvement, security assessments, and performance optimizations, offering features like tailored prompts, memory support, and flexible use cases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in pull requests (PRs) and provides feedback. It is customizable and integrates with Amazon Bedrock Knowledge Bases, enhancing the action’s capability by providing enriched, context-aware insights. The action is designed for code quality improvement, security assessments, and performance optimizations, offering features like tailored prompts, memory support, and flexible use cases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/sherpa.sh/</link><pubDate>Fri, 14 Aug 2026 22:25:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven tool that simplifies infrastructure deployment by allowing developers to describe their desired setup in plain English. It automates the creation and configuration of complex cloud resources, such as servers, databases, load balancers, and CDNs. Sherpa supports various cloud providers and frameworks, making it open-source and transparent. Users can integrate Sherpa with GitHub Actions or Claude Code CLI for automatic deployment on code pushes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven tool that simplifies infrastructure deployment by allowing developers to describe their desired setup in plain English. It automates the creation and configuration of complex cloud resources, such as servers, databases, load balancers, and CDNs. Sherpa supports various cloud providers and frameworks, making it open-source and transparent. Users can integrate Sherpa with GitHub Actions or Claude Code CLI for automatic deployment on code pushes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/bernstein-multi-agent-orchestration/</link><pubDate>Fri, 14 Aug 2026 22:24:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.15.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is an open-source CLI orchestration tool that runs multiple language models (Claude Code, Codex, Gemini CLI) in parallel. It automates the process of coordinating and monitoring these agents to ensure reproducible and traceable results. The key capabilities include:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.15.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein is an open-source CLI orchestration tool that runs multiple language models (Claude Code, Codex, Gemini CLI) in parallel. It automates the process of coordinating and monitoring these agents to ensure reproducible and traceable results. The key capabilities include:</p>
<ol>
<li><strong>Deterministic Orchestrator</strong>: Runs multiple LLMs in parallel without using an external LLM for coordination, ensuring that each run can be reproduced exactly.</li>
<li><strong>Replayability</strong>: After a run, users can replay the same plan to reproduce the exact task graph and results.</li>
<li><strong>Monitoring and Control</strong>: Continuously monitors the performance of the agents and allows for easy control over which tasks are executed next or which ones should be skipped.</li>
</ol>
<p>Bernstein supports a wide range of LLMs and provides an air-gap install profile, making it suitable for environments with restricted internet access. It is released under the Apache-2.0 license and can be used to streamline the development process by automating the execution and monitoring of multiple language models in parallel.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v3151">v3.15.1</h1>
<p>v3.15.0 closed a trust boundary. This release went back to see how far that fix
reached. Not far enough.</p>
<h2 id="tenant-scoping">Tenant scoping</h2>
<p>#3799 narrowed the task routes and listed a second set of readers it
deliberately left alone. That set got asked directly: a server with two tenants,
all five kinds of credential. Twelve of thirteen handed over another tenant&rsquo;s
task ids and titles. The thirteenth never touches the task table, so it is
closed with evidence instead of a patch.</p>
<p>The twelve now derive their tenant from authenticated state (#3808). So does the
budget forecast, where one tenant&rsquo;s spending moved another tenant&rsquo;s exhaustion
date. Found and fixed by @BinarySpecter (#3809).</p>
<h2 id="credentials">Credentials</h2>
<p>An agent token authenticated, and then nothing else was asked of it (#3797). It
reached log reads, stream reads and session-kill routes it held no permission
for. Review of that patch found the cluster secret doing the same. Both closed
in one change. Same shape in gRPC (#3537), attachment access (#3567) and tenant
directories (#3693).</p>
<h2 id="behaviour-changes">Behaviour changes</h2>
<ul>
<li><code>auth_type=&quot;oauth&quot;</code> fails at construction (#3463). Documented, implemented
nowhere, refused every request. Move to <code>&quot;bearer&quot;</code> or <code>&quot;none&quot;</code>.</li>
<li>Cost rows with no tenant are excluded from tenant-scoped queries (#3702).</li>
<li>Disclosure defaults match the published policy (#3694).</li>
<li>Rawhide no longer holds the RPM channel red while every released chroot ships
(#3791).</li>
</ul>
<h2 id="upgrading">Upgrading</h2>
<p>Upgrade in place. On a multi-tenant install the operator views now answer for one
tenant: dashboards, recap, observability, exports, <code>/badge.json</code>, the budget
forecast. A fleet-wide number will drop. Single-tenant sees no change.</p>
<p>Two security advisories are published alongside this release.</p>
<hr>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(ci): ratchet coverage baseline up to 83.5% by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3789">https://github.com/sipyourdrink-ltd/bernstein/pull/3789</a></li>
<li>chore(deps): update dependency lucide-react to v1.30.0 by @renovate[bot] in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3779">https://github.com/sipyourdrink-ltd/bernstein/pull/3779</a></li>
<li>fix(rpm): keep rawhide churn from holding the release, and give it a C++ toolchain by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3791">https://github.com/sipyourdrink-ltd/bernstein/pull/3791</a></li>
<li>fix(mcp): reject undocumented auth_type values at RemoteMCPConfig construction by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3792">https://github.com/sipyourdrink-ltd/bernstein/pull/3792</a></li>
<li>fix(security): align vuln_disclosure defaults with SECURITY.md by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3793">https://github.com/sipyourdrink-ltd/bernstein/pull/3793</a></li>
<li>fix(tenanting): route path containment through the shared barrier by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3795">https://github.com/sipyourdrink-ltd/bernstein/pull/3795</a></li>
<li>fix(grpc): enforce cluster scopes and pin node identity on RegisterNode by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3796">https://github.com/sipyourdrink-ltd/bernstein/pull/3796</a></li>
<li>fix(cost): scope the daily cost-history trend by tenant by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3798">https://github.com/sipyourdrink-ltd/bernstein/pull/3798</a></li>
<li>fix(security): apply the request tenant scope on the remaining task sinks by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3799">https://github.com/sipyourdrink-ltd/bernstein/pull/3799</a></li>
<li>fix(multimodal): decide attachment worktree access from authenticated rows by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3794">https://github.com/sipyourdrink-ltd/bernstein/pull/3794</a></li>
<li>fix(security): check route permissions for every credential kind by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3797">https://github.com/sipyourdrink-ltd/bernstein/pull/3797</a></li>
<li>fix(security): narrow the dashboard and observability task readers to the caller&rsquo;s tenant by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3808">https://github.com/sipyourdrink-ltd/bernstein/pull/3808</a></li>
<li>fix(cost): scope the /metrics/predictions forecast by tenant (#3800) by @BinarySpecter in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3809">https://github.com/sipyourdrink-ltd/bernstein/pull/3809</a></li>
<li>release: v3.15.1 by @chernistry in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3804">https://github.com/sipyourdrink-ltd/bernstein/pull/3804</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@BinarySpecter made their first contribution in <a href="https://github.com/sipyourdrink-ltd/bernstein/pull/3809">https://github.com/sipyourdrink-ltd/bernstein/pull/3809</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sipyourdrink-ltd/bernstein/compare/v3.15.0...v3.15.1">https://github.com/sipyourdrink-ltd/bernstein/compare/v3.15.0...v3.15.1</a></p>
]]></content:encoded></item><item><title>Go Report Card Badge</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/go-report-card-badge/</link><pubDate>Fri, 14 Aug 2026 22:23:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/go-report-card-badge/</guid><description>Version updated for https://github.com/soulteary/goreportcard-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating a quality report card for a Go project. It performs several checks, including code formatting, static analysis tools, and license compliance, to assess the overall quality of the project. The action outputs an SVG badge that visually represents the grade and can be committed back into the repository for easy visibility.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/soulteary/goreportcard-action">https://github.com/soulteary/goreportcard-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-report-card-badge">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating a quality report card for a Go project. It performs several checks, including code formatting, static analysis tools, and license compliance, to assess the overall quality of the project. The action outputs an SVG badge that visually represents the grade and can be committed back into the repository for easy visibility.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/soulteary/goreportcard-action/commits/v1.0.0">https://github.com/soulteary/goreportcard-action/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/ssg-static-site-generator/</link><pubDate>Fri, 14 Aug 2026 22:22:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.32.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast and efficient static site generator written in Go. It converts Markdown with YAML frontmatter into a complete website, including clean URLs, templates, feeds, search, image processing, and native deployment options. SSG is particularly well-suited for blogs and WordPress migrations, but can also be used for documentation, company sites, portfolios, and landing pages. The action automates the process of building a static site from Markdown content and provides features like auto-rebuilding on changes, web server with automatic updates, and support for various deployment targets such as Cloudflare Pages, GitHub Pages, and Vercel.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.32</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast and efficient static site generator written in Go. It converts Markdown with YAML frontmatter into a complete website, including clean URLs, templates, feeds, search, image processing, and native deployment options. SSG is particularly well-suited for blogs and WordPress migrations, but can also be used for documentation, company sites, portfolios, and landing pages. The action automates the process of building a static site from Markdown content and provides features like auto-rebuilding on changes, web server with automatic updates, and support for various deployment targets such as Cloudflare Pages, GitHub Pages, and Vercel.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.32 — migrations take only the media the content uses by @spagu in <a href="https://github.com/spagu/ssg/pull/133">https://github.com/spagu/ssg/pull/133</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.31...v1.8.32">https://github.com/spagu/ssg/compare/v1.8.31...v1.8.32</a></p>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/spek-openspec-static-site/</link><pubDate>Fri, 14 Aug 2026 22:20:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.14.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary spek is a lightweight tool that provides a structured browsing interface for OpenSpec content, including specs, changes, and tasks. It allows users to navigate through OpenSpec content in an interactive, BDD syntax-highlighted format, with features such as task progress tracking, full-text search, and responsive layout.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.14.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>spek is a lightweight tool that provides a structured browsing interface for OpenSpec content, including specs, changes, and tasks. It allows users to navigate through OpenSpec content in an interactive, BDD syntax-highlighted format, with features such as task progress tracking, full-text search, and responsive layout.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Highlight: the light theme is readable.</strong> It was never opt-in — <code>prefers-color-scheme</code> on the web, VS Code&rsquo;s theme, IntelliJ&rsquo;s — so it is what a reader gets rather than a mode they chose, and nearly every colour in it failed WCAG AA. An error message measured 2.76:1; the spec diff&rsquo;s added lines 1.70:1, sitting directly beside removed lines that were merely bad. The dark theme was audited on the same terms rather than assumed sound, and carried two failures of its own.</p>
<ul>
<li><strong>Error, success and warning colours are now defined per theme.</strong> Each was one Tailwind shade applied to both, and no 400 shade in any family reaches even 3:1 on a light background — the spec diff&rsquo;s added and removed lines, every page&rsquo;s error message, the repo picker&rsquo;s detection states and the jj conflict badge all failed there</li>
<li><strong>Secondary text is readable in both themes.</strong> Timestamps, counts, empty states and the labels beside them measured 2.34:1 light and 3.54:1 dark</li>
<li><strong>Links, the active sidebar item and search highlighting</strong> take a deeper amber in the light theme. The previous one was 3.04:1 as plain text and 3.50:1 where a search hit sits on a tint of it — that tint, not the link, is what set the new value</li>
<li><strong>A completed task no longer fades its own links and code spans.</strong> The row carried 60% opacity, which composites everything beneath it: its body text measured 3.24:1 dark and 2.77:1 light, and no colour could have compensated because the fading happens after the colour is chosen. Completion is marked by colour now, with the strikethrough and checkmark unchanged</li>
<li><strong>The task progress bar&rsquo;s complete state is distinguishable from its track</strong> — 2.02:1 before, in the light theme</li>
<li><strong>The graph and the timeline follow the theme.</strong> Node fills, legend swatches and the archived timeline bars were hard-coded colours no theme could reach: the graph&rsquo;s spec nodes measured 1.85:1 on a light page, and its archived nodes 2.93:1 in the <em>dark</em> one, because that colour was a copy of a token that had since been corrected. Edges were drawn in the panel-border colour, which is 1.22:1 at full strength and cannot be seen at any opacity</li>
<li><strong>Graph labels stay readable where they overlap a node</strong>, and the timeline&rsquo;s &ldquo;today&rdquo; marker and both bar states are drawn at full strength instead of faded</li>
<li><strong>A CLI failure is no longer remembered for the full cache window.</strong> An unreachable <code>openspec</code> binary meant 30 seconds of &ldquo;unavailable&rdquo; even after <code>PATH</code> was fixed; a failure that resolves is now retried on the next read, while one the installed CLI reproduces identically is still cached (<a href="https://github.com/spekhq/spek/issues/46">#46</a>)</li>
<li><strong>Building from source works on Windows.</strong> <code>@spekjs/core</code> and <code>@spekjs/ui</code> used Unix-only <code>rm -rf</code> / <code>cp</code> in their build scripts, so <code>npm run build</code> failed under <code>cmd.exe</code>. Thanks to <a href="https://github.com/nthansen">@nthansen</a> (Norman Hansen) (<a href="https://github.com/spekhq/spek/pull/47">#47</a>)</li>
</ul>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/compose-lint/</link><pubDate>Fri, 14 Aug 2026 22:19:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.18.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The compose-lint GitHub Action performs security-focused linting on Docker Compose files to detect and auto-fix dangerous misconfigurations before they reach production. It covers issues such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. The tool helps ensure better security practices by automating static-analysis checks and providing detailed explanations of findings for quick remediation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.18.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <strong>compose-lint</strong> GitHub Action performs security-focused linting on Docker Compose files to detect and auto-fix dangerous misconfigurations before they reach production. It covers issues such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. The tool helps ensure better security practices by automating static-analysis checks and providing detailed explanations of findings for quick remediation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="upgrading">Upgrading</h3>
<p><strong>A file compose-lint cannot fully see is now an error (exit 2), not a pass.</strong>
<code>include:</code> and cross-file <code>extends: {file: ...}</code> reference services in other
files, and compose-lint reads single files without following them — so those
services were never linted. The gap was reported on stderr for <code>include:</code> and
not at all for <code>extends:</code>, while the verdict, exit code, JSON <code>errors</code> and SARIF
<code>executionSuccessful</code> all said the run was clean. A base carrying
<code>privileged: true</code> and <code>network_mode: host</code> could sit unlinted behind a green
check.</p>
<p>Measured over the 5,417-file corpus: <strong>31 files (0.6%) change exit code — 20
from pass to error, 11 from fail to error.</strong> Findings for the local services are
still reported; the file is graded on what could be seen <em>and</em> the gap is
recorded.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span><span style="color:#75715e"># Cover everything by linting the merged output (compose-lint reads files,</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># not stdin, so write it out first):</span>
</span></span><span style="display:flex;"><span>docker compose config &gt; merged.yml <span style="color:#f92672">&amp;&amp;</span> compose-lint merged.yml
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Or accept the gap and grade only what is visible:</span>
</span></span><span style="display:flex;"><span>compose-lint --allow-partial-coverage docker-compose.yml
</span></span></code></pre></div><p><code>fix</code> reports gaps but never fails on them — it is not the merge gate.</p>
<p><strong>Rules now grade <code>${VAR:-default}</code> as the value it deploys, so files that
passed may now fail.</strong> With no <code>.env</code> and the variable unset, Compose ships the
default — <code>privileged: ${P:-true}</code> deploys <code>privileged: true</code> — but only bind
sources were being resolved, so every other rule compared its dangerous-value
set against the literal text <code>&quot;${P:-true}&quot;</code> and found no match. Writing a
dangerous value in interpolated form was a general-purpose bypass of twelve
rules.</p>
<p>Measured over the 5,417-file corpus: <strong>286 files (5.3%) change findings, and
100 (1.8%) go from pass to fail at the default <code>--fail-on high</code>.</strong> One file
goes the other way.</p>
<table>
  <thead>
      <tr>
          <th>Trigger</th>
          <th>before</th>
          <th>after</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>POSTGRES_PASSWORD: ${PW:-hunter2}</code></td>
          <td><em>none</em></td>
          <td><strong>CL-0020</strong> high</td>
      </tr>
      <tr>
          <td><code>DATABASE_URL: postgres://${U:-u}:${P:-p}@db</code></td>
          <td><em>none</em></td>
          <td><strong>CL-0021</strong> high</td>
      </tr>
      <tr>
          <td><code>image: nginx:${TAG:-latest}</code></td>
          <td>CL-0019 medium</td>
          <td><strong>CL-0004</strong> medium</td>
      </tr>
      <tr>
          <td><code>ports: [&quot;${BIND:-0.0.0.0}:80:80&quot;]</code></td>
          <td><em>none</em></td>
          <td><strong>CL-0005</strong> medium</td>
      </tr>
      <tr>
          <td><code>user: &quot;${UID:-0}:${GID:-0}&quot;</code></td>
          <td><em>none</em></td>
          <td><strong>CL-0018</strong> medium</td>
      </tr>
      <tr>
          <td><code>mem_limit: &quot;${MEM:-0}m&quot;</code></td>
          <td><em>none</em></td>
          <td><strong>CL-0026</strong> medium</td>
      </tr>
      <tr>
          <td><code>privileged: ${P:-true}</code></td>
          <td><em>none</em></td>
          <td><strong>CL-0002</strong> critical</td>
      </tr>
  </tbody>
</table>
<p>The <code>image:</code> row is a reclassification, not a new failure: CL-0004 replaces
CL-0019 at the same location and severity, because the tag resolves to the
mutable <code>latest</code> rather than to an opaque <code>${TAG}</code>.</p>
<p>Two changes go the other way and <strong>remove</strong> findings, both fixing false
positives: a port whose default binds loopback (<code>&quot;${PORT:-127.0.0.1:80}:80&quot;</code>)
no longer trips CL-0005, and an empty placeholder in a list-form entry
(<code>- API_KEY=&quot;&quot;</code>) no longer trips CL-0020 — the mapping form <code>API_KEY: &quot;&quot;</code> was
already exempt.</p>
<p>If a finding is genuinely parameterized in your deployment, that is what
<code>.compose-lint.yml</code> suppressions are for. Writing the reference without a
default (<code>${PW}</code> rather than <code>${PW:-hunter2}</code>) also stays exempt, because
Compose then ships nothing.</p>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Coverage gaps are reported on every channel a consumer reads.</strong> An
unresolved <code>include:</code> or cross-file <code>extends: {file: ...}</code> now produces a JSON
<code>errors[]</code> entry, a SARIF <code>toolExecutionNotifications</code> record with
<code>executionSuccessful: false</code>, and exit 2 — previously a stderr warning for
<code>include:</code> and complete silence for <code>extends:</code>. <code>parser.coverage_gaps(data)</code>
exposes the same list to library callers. The text verdict counts them
separately from parse failures, because those files parsed fine and saying
otherwise would misdescribe the run. See <strong>Upgrading</strong> above.</li>
<li><strong>New <code>--allow-partial-coverage</code> flag on <code>check</code></strong> to accept a coverage gap
and grade what is visible. It waives the gap, not the findings: a local
CRITICAL still fails the gate.</li>
<li><strong><code>${VAR:-default}</code> is resolved document-wide before rules run.</strong> The parser
normalizes every string leaf to the value Compose ships when the variable is
unset, so a rule classifies the deployed configuration instead of the source
text. Substitution had been wired into one call site (bind sources), leaving
CL-0002, CL-0004, CL-0005, CL-0008, CL-0009, CL-0010, CL-0011, CL-0014,
CL-0016, CL-0018, CL-0020, CL-0021, CL-0022, CL-0024, CL-0026 and the
capability rules grading a string that is never deployed. Doing it once in the
parser is what keeps it from being re-litigated per rule: a rule that adds a
dangerous literal to its set gets the interpolated spellings for free. See
<strong>Upgrading</strong> above for the measured impact. A reference with no default is
still left as written — Compose ships nothing for it, so there is nothing to
grade.</li>
<li><strong>The credential rules&rsquo; interpolation exemption is stated as what Compose
does.</strong> CL-0020 and CL-0021 previously skipped any value <em>containing</em> a
reference, so appending one character to a literal (<code>hunter2$X</code>) silenced
them, while Compose ships <code>hunter2</code>. The exemption is now &ldquo;Compose resolves
this value to nothing&rdquo;, which also correctly exempts a quoted reference in a
list-form entry (<code>- SECRET_KEY=&quot;${KEY}&quot;</code>, where the quotes are literal
characters) that a stricter shape test would have flagged.</li>
<li><strong>CL-0021&rsquo;s rule description</strong> now says the password half is skipped when
Compose resolves it to nothing, and that a defaulted password still fires.
Visible in <code>--explain CL-0021</code>, the docs site and SARIF rule metadata.</li>
<li><strong>CL-0026 no longer treats an unparseable dollar-bearing value as a limit.</strong>
<code>mem_limit: &quot;${MEM:-0}m&quot;</code> resolves to <code>0m</code>, which Docker reads as unlimited,
and now fires; a bare <code>${MEM_LIMIT}</code> stays exempt as genuinely unknowable.</li>
<li>Scalars longer than 8 KB are no longer scanned for interpolation. The two
substitution regexes are quadratic (measured 80 KB → 0.49 s, 160 KB →
1.94 s), and the pass above runs them over every string rather than bind
sources alone; past the cap the conservative answer is returned unscanned.</li>
<li><strong>A Compose file containing an ambiguous line break is now refused</strong> (exit 2,
reported per file, with a SARIF <code>toolExecutionNotifications</code> entry) instead of
being linted with line numbers nothing else agrees with. A lone <code>\r</code>, U+0085,
U+2028 or U+2029 is a line break to the YAML parser but not to editors, SARIF
viewers or CI annotations, so on such a document <em>any</em> reported line number is
wrong for one side or the other — and the fix engine would splice at a line
the user is not looking at. There is no line numbering to fall back on, so the
file is refused rather than mislabeled. None of the 5,417 files in the corpus
contains one, and CRLF and LF are unaffected.</li>
<li><strong>The parser now reads files without universal-newline translation</strong>, so
<code>check</code> and <code>fix</code> parse the same bytes for the same file. <code>fix</code> has always
read with <code>newline=&quot;&quot;</code> to preserve line endings, while the parser rewrote a
lone <code>\r</code> to <code>\n</code> — a second, quieter version of the same disagreement.
Verified no behavior change: LF and CRLF documents produce byte-identical
findings and line numbers, and a full corpus run is unchanged.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>CL-0021 no longer reports a connection string whose credential is entirely
a variable reference.</strong> The <code>user:password@</code> split ran on the first <code>:</code>,
which for <code>postgresql://${DB_USER:?error}:${DB_PASSWORD:?error}@db/x</code> lands
inside the substitution — leaving a &ldquo;password&rdquo; of <code>?error}:${DB_PASSWORD:?error}</code>,
which is not wholly a reference and so read as a shipped literal. The split
now happens at substitution depth zero, the same thing <code>parser</code> already did
for short-syntax volumes, and each half is length-bounded rather than
relying on a regex quantifier to bound it.</p>
</li>
<li>
<p><strong>CL-0020 no longer reads a token&rsquo;s <em>lifetime</em> as the token.</strong>
<code>JWT_ACCESS_TOKEN_EXPIRE_MINUTES: 30</code> matched on the <code>TOKEN</code> substring and
fired at <code>high</code> — a finding with no fix, since the value is a duration.
A key naming a quantity about the credential (<code>TTL</code>, <code>EXPIRE</code>, <code>EXPIRY</code>,
<code>VALIDITY</code>, <code>ROTATION</code>, <code>INTERVAL</code>, <code>RETENTION</code>, <code>_MINUTES</code>/<code>_DAYS</code>,
<code>MIN_LENGTH</code>, <code>MIN_CHAR</code>, <code>_LIMIT</code>, <code>_SIZE</code>, <code>POLICY</code>, plural <code>TOKENS</code>,
<code>_PORT</code>) is now exempt <strong>when its value is also a bare quantity</strong> (<code>30</code>,
<code>900s</code>, <code>30m</code>).</p>
<p>Both halves are required, and deliberately so. Exempting on the value alone
— the shape a bare integer suggests — would have reverted the numeric-secret
fix: <code>POSTGRES_PASSWORD: 1234</code> is a weak credential and must keep firing.
Exempting on the key alone would skip <code>AUTH_TOKENS: your_token_here</code>.</p>
<p>Measured over the 5,417-file corpus: <strong>30 findings removed across 18 files,
every one a knob; all 40 numeric-valued credentials kept; no other rule&rsquo;s
output changes.</strong> Three files stop failing at the default <code>--fail-on high</code>,
having failed only on this. This class grew with the interpolation change
above — <code>TOKEN_TTL: ${TTL:-60}</code> resolves to <code>60</code> and began firing where the
unresolved reference had not.</p>
<p>Four knob keys holding non-quantity values still fire (a banned-password
<em>list filename</em>, a <code>5/hour</code> rate, an arithmetic expression, a placeholder
token); judging those needs the content scanner this rule declines to be.</p>
</li>
<li>
<p><strong>Nested interpolation defaults resolve the way Compose resolves them.</strong>
<code>${A:-x${B:-y}z}</code> was rewritten by a single regex pass whose default group
stopped at the <em>first</em> <code>}</code> — the inner one — so
<code>${DB_URL:-postgres://u:${PW:-s3cret}@db/x}</code> normalized to
<code>postgres://u:${PW:-s3cret@db/x}</code>, a string Compose never ships, with the
userinfo boundary moved and the brace relocated past the host. Every rule
reads the normalized document, so the corruption reached bind sources
(<code>${GOPATH:-${HOME}/go}/pkg/mod/cache</code>) as well as the credential rules. 98
values across 34 corpus files are written this way. Resolution is now
innermost-first with balanced brace counting, checked against
<code>docker compose config</code> on Compose 5.4.0 with no <code>.env</code>:</p>
<table>
  <thead>
      <tr>
          <th>written</th>
          <th>shipped</th>
          <th>before</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>${A:-front-${B:-back}-tail}</code></td>
          <td><code>front-back-tail</code></td>
          <td><code>front-${B:-back-tail}</code></td>
      </tr>
      <tr>
          <td><code>${OUTER:-postgres://u:${IN:-pw}@db/x}</code></td>
          <td><code>postgres://u:pw@db/x</code></td>
          <td><code>postgres://u:${IN:-pw@db/x}</code></td>
      </tr>
      <tr>
          <td><code>${CONF:-{&quot;a&quot;:1}}</code></td>
          <td><code>{&quot;a&quot;:1}</code></td>
          <td><code>{&quot;a&quot;:1}</code></td>
      </tr>
  </tbody>
</table>
<p>Nesting is bounded at 32 levels, deeper values being left as written: because
resolution recurses per level, <code>${A:-</code> repeated 1,200 times — 7 KB, under
<code>MAX_SCAN_LEN</code> — otherwise exhausted the interpreter stack and the parser
reported that as a usage error, so a 7 KB scalar turned a clean lint into
exit 2.</p>
<p>Measured over the 5,417-file corpus: <strong>5 files (0.09%) change findings and
none go from pass to fail.</strong> Two stop failing at the default <code>--fail-on high</code>,
each losing a single CL-0021 false positive; one drops a CL-0020 on
<code>MINIO_ROOT_PASSWORD: ${S3_SECRET_ACCESS_KEY:-${S3_SECRET_KEY:-}}</code>, which
Compose ships empty; and one file&rsquo;s five <code>${IMG:-repo/app:${TAG:-latest}}</code>
images move from CL-0019 to CL-0004 at the same MEDIUM severity, because the
tag now resolves to the mutable <code>latest</code> rather than to an opaque reference.</p>
</li>
<li>
<p><strong><code>init</code> no longer writes a config that does not parse.</strong> A service name
carrying a newline produced a <code>.compose-lint.yml</code> with a bare line break
inside a mapping key — and <code>init</code> reported success writing it, so every later
run in that directory failed with <code>Invalid YAML in config file</code> at exit 2
until someone found the file by hand. Durable corruption from one lint of one
hostile file. Quoting is now delegated to PyYAML rather than hand-rolled
(the previous version escaped <code>\</code> and <code>&quot;</code> and nothing else), and the
plain-scalar test is anchored with <code>\Z</code> rather than <code>$</code> — in Python <code>$</code> also
matches <em>before</em> a trailing newline, so <code>&quot;web\n&quot;</code> was emitted unquoted.
Ordinary names are still emitted unquoted.</p>
</li>
<li>
<p><strong><code>init --force</code> no longer overwrites a read-only config.</strong> A 0444
<code>.compose-lint.yml</code> is an explicit &ldquo;do not modify&rdquo; on the file that decides
which security rules are suppressed, and <code>os.replace</code> would swap it out
through the writable parent directory regardless. <code>fix --apply</code> had honoured
that mode all along; the init path did not. The guard is now one shared
helper called by both, with a test that fails if either loses it.</p>
</li>
<li>
<p><strong>A small file can no longer buy a large amount of work.</strong> Nine defects
shared that shape: input that parses in milliseconds and then costs seconds
or gigabytes downstream, while producing no finding and exiting 0 — so
nothing in the output signalled it. Measured at 800 services, <code>fix</code> went from
2.67 s to 0.65 s and SARIF from 2.37 s to 0.36 s, and both are now linear in
service count rather than approaching quadratic.</p>
<ul>
<li><strong>Reading a path that is not a bounded regular file.</strong> <code>.exists()</code> is true
of a FIFO and of <code>/dev/zero</code>, and a repository can commit a <em>symlink</em> to
either — it survives clone and checkout, and the runner resolves it.
Reading one hung the job forever; the other allocated until the runner
died. Both the Compose loader and the config loader now check the resolved
file&rsquo;s shape before reading a byte, with the descriptor opened
<code>O_NONBLOCK</code> — a plain <code>open()</code> on a FIFO blocks <em>before</em> any check can
run — and the read bounded at 8 MB.</li>
<li><strong><code>str()</code> on a YAML container.</strong> Aliases share nodes by reference, so a
22-level doubling chain is under 1 KB on disk and 22 nodes in memory, but
<code>str()</code> serializes it as a <em>tree</em>: 4M elements from one call. Eleven rule
sinks and three config fields did that to whatever the document handed
them. They now refuse a container rather than render it — a list is not a
capability, a port, a mount spec, or a suppression reason.</li>
<li><strong>Repeated work over one document.</strong> <code>split_lines</code> was called once per
fixer and re-split the whole file each time (2.24 s of a 2.58 s run at 800
services); <code>extends_targets</code> walked every service once per <em>finding</em>; and
<code>_merge_extends</code> re-walked a shared alias subtree once per path through the
DAG (805 B → 5.4 s). All three are now memoized per document, and
<code>split_lines</code> takes a C-speed path when the text contains none of the five
characters <code>str.splitlines()</code> breaks on and PyYAML does not.</li>
<li><strong>Quadratic scanning of a long scalar.</strong> CL-0021&rsquo;s userinfo pattern
retried from every offset (20 KB → 1.1 s, 40 KB → 4.1 s). Its quantifiers
are now bounded and the scalar is capped before scanning.</li>
<li><strong>The edit-conflict check</strong> compared every pair of fix units. It now sweeps
spans sorted by offset and stops as soon as a later span begins past the
current one&rsquo;s end.</li>
<li><strong>SARIF output that a consumer would reject.</strong> 1,500 aliased services in
29 KB produced a document over GitHub Code Scanning&rsquo;s 10 MB ceiling — and
an artifact that large is <em>rejected</em>, so the run showed no alerts at all.
Output is capped at 5,000 results, the omission is stated in
<code>toolExecutionNotifications</code>, <code>executionSuccessful</code> is false, and the run
exits 2 so a gate cannot read success from a knowingly incomplete artifact.
Use <code>--format json</code> for the complete set.</li>
</ul>
</li>
<li>
<p><strong>Malformed input is a per-file failure, never a traceback.</strong> Four paths let
an exception escape the fail-loud boundary: the CLI printed a Python
traceback, exited <strong>1</strong> — which reads as &ldquo;I linted it and it failed&rdquo; rather
than &ldquo;I could not lint it&rdquo; — and abandoned every remaining file in the batch.
All four now surface as a clean error at exit 2 with the rest of the run
intact. Each had a correct sibling already in the repo.</p>
<ul>
<li><strong>Deep recursion in the post-parse passes.</strong> The loader&rsquo;s
<code>RecursionError</code> guard covered the <em>parse</em> only, so a 2000-deep <code>extends:</code>
chain or a self-referential <code>${A:-${A:-…}}</code> in a bind source blew the stack
after the loader returned. The boundary now covers every pass that walks
the document.</li>
<li><strong><code>ReaderError</code> from the loader constructor.</strong> <code>Reader.__init__</code> runs the
printable-character check, so a document carrying a C0 byte raises at
construction — which happened <em>outside</em> the <code>try</code>. The constructor is now
inside it.</li>
<li><strong><code>RecursionError</code> in the config loader.</strong> <code>except yaml.YAMLError</code> does not
catch it, since it is a <code>RuntimeError</code>. The Compose loader already
translated this; the config loader did not.</li>
<li><strong>Write failures from <code>fix --apply</code> / <code>init</code>.</strong> An unwrapped <code>OSError</code> — a
read-only directory, a full disk — aborted the batch and printed the
absolute workspace path in a traceback. Failures are now attributed to the
file they belong to, and later files still lint. The message reports the
condition (<code>Permission denied</code>) rather than the errno decoration and the
internal temp filename the caller never chose.</li>
<li>A write target that exists but is <strong>not a regular file</strong> is now named as
such. A directory has <code>st_nlink &gt;= 2</code>, so it was previously reported as a
hard link, which is not what is wrong with it.</li>
</ul>
</li>
<li>
<p><strong><code>fix --apply</code> could edit the wrong line and silently delete config.</strong> The
fix engine&rsquo;s offset table counted only <code>\n</code>, while the line numbers it
converted come from PyYAML, which also breaks on a lone <code>\r</code>, U+0085,
U+2028 and U+2029. One such codepoint inside a quoted scalar shifted every
later splice a line, so a fix could remove a line the user never selected —
and because the result was still valid Compose, every safety net passed and
the run exited 0. <code>compose_lint._lines</code> now owns a single definition of a
line break, with <code>split_lines</code> and <code>line_starts</code> derived from one scan so
they cannot disagree; the fixers, the fix engine and the text formatter&rsquo;s
source excerpt all use it. A CI guard fails the build on a bare
<code>str.splitlines()</code> in <code>src/</code>. Documents free of those four codepoints —
effectively all real Compose files — are unaffected: a 5,417-file corpus run
shows zero change in findings, exit codes or errors.</p>
</li>
<li>
<p><strong>A file whose fixes could not be computed no longer destroys the batch.</strong>
The same desync could push a line number past the offset table and raise a
bare <code>IndexError</code>, which aborted the whole run: <code>check --format sarif</code> then
emitted a 0-byte document, discarding the findings of every other file
scanned alongside it. Out-of-range positions now raise a
<code>LineOutOfRangeError</code> that the CLI reports as a per-file failure (exit 2,
the usage-error code) while the rest of the batch still lints and still
ships its findings.</p>
</li>
</ul>
<h3 id="security">Security</h3>
<ul>
<li>
<p><strong>The release layer no longer has a weaker path than its main one.</strong></p>
<ul>
<li><strong>One tag gate, called by both publish paths.</strong> <code>publish.yml</code> verified
three things about a release tag: annotated, reachable from <code>main</code>, and
signed by a key in <code>.github/allowed_signers</code>. <code>publish-channel.yml</code> — the
manual escape hatch, which ships with the same credentials — carried its
own copy that did the first two and omitted the third, so a tag signed by
nobody could reach the publishing jobs. The signature check is the
cryptographic root of the Sigstore provenance chain. It now lives once, in
a reusable <code>verify-tag.yml</code> that both paths call, and every
credential-bearing job depends on it. A test walks the <code>needs:</code> graph and
fails if any job touching a publishing credential does not reach the gate.</li>
<li><strong>The release smoke no longer resolves dependencies from TestPyPI.</strong> <code>-i</code>
makes an index <em>primary</em>, and pip then prefers the highest version across
all configured indexes — so with TestPyPI primary, anyone who claims a
dependency name in that open namespace at a higher version supplies code
into the release. The closure is now installed from the hash-pinned lock
first, and TestPyPI is used only with <code>--no-deps</code> for the one artifact
under test. Verified against a local squat: PyYAML resolves from the lock,
not the planted 99.0.0. A test fails any workflow <code>pip install</code> that reads
from a non-default index without <code>--no-deps</code>.</li>
<li><strong>The manual Docker Hub description sync runs default-branch code.</strong>
<code>workflow_dispatch</code> can name any ref and <code>uses: ./…</code> runs whatever is in
the workspace, so the dispatcher chose the code that reads a
Read+Write+Delete token. The checkout is pinned to the default branch: a
dispatch now chooses when it runs, not what runs.</li>
<li><strong>The corpus report escapes third-party repository and path strings.</strong>
They come from code-search results over arbitrary public repositories, and
only a path&rsquo;s <em>basename</em> is filtered when fetching — so a directory
component could contain <code>|</code>, backticks and HTML, forge extra columns, and
write rows that looked like compose-lint&rsquo;s own findings. Backticks are
replaced rather than escaped, because Markdown does not honour backslash
escapes inside a code span.</li>
</ul>
<p>Two related items need repository and Docker Hub settings rather than code,
and are written up in <code>docs/RELEASING.md</code>: moving the Docker Hub secrets into
a default-branch-scoped environment, and splitting the single
Read+Write+Delete PAT into read, write and admin tokens.</p>
</li>
<li>
<p><strong>Four places where the tool reported a state that was not true.</strong></p>
<ul>
<li><strong><code>fix --apply</code> no longer claims to have fixed a file it did not touch.</strong>
<code>os.replace</code> swaps the directory entry, not the inode behind it, so on a
<strong>symlink</strong> it dropped a regular file over the link and left the file the
stack actually deploys unchanged — while the run reported the fix applied.
On a <strong>hard link</strong> it broke the link and let the two names diverge in
silence. Both are now refused with an error naming the reason; the rest of
the batch continues. <code>setuid</code>/<code>setgid</code>/sticky bits are no longer carried
onto the replacement inode.</li>
<li><strong>A <code>severity:</code> override leaves an audit record.</strong> It was the one
suppression channel with none: <code>enabled: false</code> and <code>exclude_services</code> both
mark findings SUPPRESSED with a reason, but a re-graded finding was
indistinguishable from one the rule declared at that level — so three lines
in a policy file could take a CRITICAL below the default gate invisibly.
Now reported as <code>(severity overridden from critical)</code> in text,
<code>severity_overridden_from</code> in JSON, and <code>properties.severityOverriddenFrom</code>
in SARIF. Re-stating a rule&rsquo;s own severity records nothing, because nothing
changed.</li>
<li><strong>Duplicate keys in <code>.compose-lint.yml</code> are a config error.</strong> YAML resolves
them last-wins in silence, so a policy that disables a rule with a reason
and re-enables it further down read, to a human, as the first entry and
behaved as the second. The Compose parser already refuses duplicates for
this reason; the config loader was the door left open.</li>
<li><strong>A line lookup never returns a line belonging to a different node.</strong>
Joining path segments with <code>.</code> is lossy when a segment contains one: a
service named <code>web.logging</code> and service <code>web</code>&rsquo;s <code>logging:</code> child both spell
<code>services.web.logging</code>, and last-write-wins handed one of them the other&rsquo;s
line — so a fixer evaluated its anchor/merge-key refusal against a
different service and applied an edit every fixer is required to refuse.
Colliding paths are now dropped from the map, so the lookup returns <code>None</code>
and the fixer fails closed. 17 corpus files use dotted service names
(<code>llama.cpp</code>, <code>smartwardrobe.api</code>); none of them collides, so nothing real
loses its line numbers.</li>
</ul>
</li>
<li>
<p><strong>Everything compose-lint prints about a file is now sanitized at the sink.</strong>
Escaping lived in a private helper inside the text formatter, so it covered
that formatter&rsquo;s own fields and nothing else: 26 other print sites emitted
attacker-derived text raw — service names, file paths, and parse-error text
that quotes the document — and a terminal or CI log renders control sequences.
The full CSI repertoire reaching stderr means the file being linted can erase
findings already on screen.</p>
<p>Escaping now lives in <code>compose_lint._output</code> and <strong>every</strong> stderr write goes
through <code>emit()</code>, so it is the default rather than something each new call
site must remember; a test fails the build on a raw
<code>print(..., file=sys.stderr)</code> anywhere in <code>src/</code>.</p>
<ul>
<li><strong>A newline can no longer forge a report line.</strong> <code>_sanitize</code> passed <code>\n</code>
through &ldquo;so excerpt layout survives&rdquo;, but the sink is a newline-delimited
report — a service name carrying one put attacker text in the report&rsquo;s own
left margin, indistinguishable from a line compose-lint wrote. Values
rendered as a single record are now escaped with <code>sanitize_line</code>, and
multi-line diagnostics indent their continuation lines so nothing after an
embedded newline can occupy column zero.</li>
<li><strong>The <code>fix</code> dry-run diff is sanitized.</strong> It is the surface a human reads to
authorise a destructive write, and it printed file content verbatim —
bidi and zero-width codepoints are YAML-printable, so they survive the
parser&rsquo;s own check and could display a line in an order the file does not
have. Sanitizing happens in <code>render_file_diff</code>, so all three emit sites are
covered at once. Display only: <code>fix --apply</code> still writes the original
bytes.</li>
<li><strong><code>format_header</code> sanitizes the config path</strong>, the one unsanitized <em>stdout</em>
site — it sat immediately beside a correctly sanitized <code>files</code> argument.</li>
</ul>
<p>Measured over the corpus: no findings, exit codes or errors change. Text
output is byte-identical on 299 of 300 sampled files; the exception is
PyYAML&rsquo;s parse-error context, whose continuation lines gain two spaces of
indent. Of the 16 corpus files containing a sanitizable codepoint (all
zero-width space or BOM), the only visible change is that a leading BOM now
shows as <code>\ufeff</code> in a <code>fix</code> diff instead of being invisible — which is the
point of the fix.</p>
</li>
<li>
<p><strong>The GitHub Action no longer passes where the CLI would fail.</strong> Six defects
shared that shape, and <code>action.yml</code> is fixed as one block.</p>
<ul>
<li><strong>&ldquo;No Compose files found&rdquo; is an error, not a green check.</strong> The lint step
was gated on <code>if: steps.find-files.outputs.files != ''</code>, so a <code>pattern:</code>
that matched nothing skipped the step entirely and the job reported
success — while the CLI exits 2 for exactly that input. The decision now
lives inside the script, where it can fail. New <code>allow-no-files: true</code>
input for the case where an empty result is expected.</li>
<li><strong>A SARIF artifact is never uploaded unless it was written.</strong> The re-run
redirected straight at the target — truncating it before the command ran —
and <code>|| true</code> reported failure as success, so <code>always()</code> uploaded a 0-byte
document and Code Scanning showed no alerts. Output now goes to a
temporary file that is moved into place only once it holds a complete
document; a run that produces nothing fails the step, and the upload is
gated on the file having been written rather than on <code>always()</code>.</li>
<li><strong><code>sarif-file</code> is validated to stay inside the workspace.</strong> <code>&gt;</code> truncates
before the command runs, so an unvalidated path let a caller-supplied
value destroy a file anywhere the runner could write.</li>
<li><strong>The install is pinned by default.</strong> A consumer who SHA-pins <code>uses:</code> is
asking for a reproducible check, but the action installed whatever PyPI
served at that moment. It now installs the version it was released with;
<code>version: latest</code> opts back in to tracking PyPI.
<code>scripts/bump-version.sh</code> keeps the pin in step and
<code>tests/test_action_contract.py</code> fails if it drifts.</li>
<li><strong>No attacker-controlled text reaches <code>$GITHUB_OUTPUT</code>.</strong> Discovered paths
are written NUL-separated to a file under <code>RUNNER_TEMP</code> and only that
file&rsquo;s path crosses the step boundary, so a filename containing a newline
can no longer forge output records. Discovery uses <code>find -print0</code>, so
paths containing spaces survive too.</li>
<li><strong>The documented consumer workflow ships a <code>permissions:</code> block</strong> —
workflow-level deny-all plus the two scopes the job actually uses.</li>
</ul>
</li>
<li>
<p><strong>Five rules now classify the normalized value instead of the spelling.</strong>
Each decided what a value <em>was</em> by matching the raw token, so an equivalent
spelling walked past it. All five were verified against
<code>docker compose config</code>, and none of the 5,417 files in the corpus uses any
of them — these are evasion spellings, not things people write by accident,
so the added coverage costs no false positives.</p>
<table>
  <thead>
      <tr>
          <th>Spelling</th>
          <th>before</th>
          <th>after</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>o: rbind</code> in <code>driver_opts</code></td>
          <td><em>silent</em></td>
          <td><strong>CL-0001</strong> critical (also CL-0013, CL-0025)</td>
      </tr>
      <tr>
          <td><code>//dev/sda</code>, <code>/dev/./sda</code></td>
          <td><em>silent</em></td>
          <td><strong>CL-0016</strong> critical</td>
      </tr>
      <tr>
          <td><code>privileged: y</code> / <code>Y</code></td>
          <td><em>silent</em></td>
          <td><strong>CL-0002</strong> critical</td>
      </tr>
      <tr>
          <td><code>[::0]</code>, <code>[0:0:0:0:0:0:0:0]</code>, <code>[::ffff:0.0.0.0]</code></td>
          <td><em>silent</em></td>
          <td><strong>CL-0005</strong> medium</td>
      </tr>
      <tr>
          <td><code>read_only: !reset true</code></td>
          <td>credited as hardened</td>
          <td><strong>CL-0003/0006/0007</strong></td>
      </tr>
  </tbody>
</table>
<ul>
<li><strong><code>o: rbind</code></strong> is a recursive bind of the same host path. Bind detection now
keys off the shape the kernel acts on — <code>type: none</code> with an absolute
<code>device</code> under the local driver — rather than the <code>o:</code> string being exactly
<code>bind</code>. <code>type: nfs</code> and <code>type: tmpfs</code> are still not claimed as host paths.</li>
<li><strong>Device paths</strong> run through <code>normalize_host_path</code> before the sixteen
<code>^/dev/</code>-anchored patterns see them.</li>
<li><strong><code>_TRUE</code>/<code>_FALSE</code></strong> cover YAML 1.1&rsquo;s single-letter forms. <code>privileged: y</code>
is emitted as <code>privileged: true</code> by <code>docker compose config</code>, so one
character hid the tool&rsquo;s highest-severity finding. <code>n</code>/<code>N</code> are added for
symmetry; they failed safe.</li>
<li><strong>Bind addresses</strong> are parsed, not matched against a literal set. Every
spelling of the unspecified address is now recognized in both families; a
value that is not an address (a hostname) is still not a wildcard.</li>
<li><strong><code>!reset</code> deletes the key it is attached to</strong>, which is what Compose does:
a file carrying <code>read_only: !reset true</code>, <code>cap_drop: !reset [ALL]</code> and
<code>security_opt: !reset [...]</code> deploys a service with none of them. Keeping
the underlying value credited the service with hardening Docker removes, so
the absence rules stayed silent on an unhardened container. <code>!override</code>
still keeps its value — it changes how a value merges, not what it is.</li>
</ul>
</li>
<li>
<p><strong>The shipped harnesses now terminate the option namespace with <code>--</code>.</strong> A
repository can contain a directory named <code>--config=cfgdir</code> holding a
<code>compose.yml</code>; the resulting path <code>--config=cfgdir/compose.yml</code> matches the
pre-commit hook&rsquo;s <code>files:</code> pattern and the Action&rsquo;s discovery, so a harness
that globbed repo paths straight into argv handed argparse something it read
as an option. The crafted file left the lint set <em>and</em> an attacker-authored
policy disabling every rule was installed for the run — the gate went green
over a <code>privileged</code> stack mounting <code>/var/run/docker.sock</code>. Confirmed
end-to-end: the pre-commit hook reported <code>Passed</code> before this change and
<code>Failed</code> after, on the same repository.</p>
<p>The pre-commit hook ships <code>args: [--]</code> and the Action passes <code>--</code> before the
file list in both invocations (the text run and the SARIF re-run). Setting
<code>args:</code> in your <code>.pre-commit-config.yaml</code> replaces the default, so keep <code>--</code>
last if you pass flags — see README.</p>
<p>The separator is deliberately <strong>not</strong> inserted by the CLI&rsquo;s argv shim: it
cannot tell a genuine <code>--config=x</code> from a file named that, and terminating
before the first positional would break the documented
<code>compose-lint init docker-compose.yml -o ci.yml</code> form.</p>
</li>
</ul>
]]></content:encoded></item><item><title>grype_me</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/grype_me/</link><pubDate>Fri, 14 Aug 2026 22:18:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/grype_me/</guid><description>Version updated for https://github.com/TomTonic/grype_me to version v1.3.20-release.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of project dependencies for known vulnerabilities using Anchore Grype, a fast and efficient vulnerability scanner. It supports repository and artifact scans and provides detailed reports with badges generated via GitHub Gist. The action is designed to be easy to use and integrates seamlessly into CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TomTonic/grype_me">https://github.com/TomTonic/grype_me</a></strong> to version <strong>v1.3.20-release</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/grype_me">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the scanning of project dependencies for known vulnerabilities using Anchore Grype, a fast and efficient vulnerability scanner. It supports repository and artifact scans and provides detailed reports with badges generated via GitHub Gist. The action is designed to be easy to use and integrates seamlessly into CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v1320-release">v1.3.20-release</h1>
<h2 id="source-code-updates">Source Code Updates</h2>
<ul>
<li><strong>Go toolchain updated 1.26.5 → 1.26.6.</strong> This point release fixes 10 security issues; the ones I could confirm from the upstream advisory include:
<ul>
<li><strong>CVE-2026-56865 / CVE-2026-56864 — <code>go</code> command, module sum-database (GOSUMDB) verification.</strong> A flaw in transparency-log tile verification allowed a malicious <code>GOPROXY</code> to forge log tiles or return arbitrary content outside the log, letting <code>go build</code>/<code>go mod download</code> accept unverified, attacker-controlled module content into the local module cache. This is directly relevant to <code>grype_me</code>&rsquo;s own build (the Docker builder stage runs <code>go mod download</code>/<code>go build</code>) and to any downstream Go project this action scans — recommend rebuilding with this toolchain.</li>
<li><strong>CVE-2026-56859 — <code>encoding/xml</code>:</strong> a broken recursion-depth counter allowed the nesting guard to never fire, risking stack exhaustion (DoS) when decoding crafted XML.</li>
<li><strong>CVE-2026-56853 — <code>net/http</code>:</strong> <code>ReadHeaderTimeout</code> was not applied while probing a new connection for an unencrypted HTTP/2 client preface, allowing a slow/stalled client to hold a connection open past the configured timeout.</li>
<li><strong>CVE-2026-56856 — <code>net/url</code>:</strong> quadratic-complexity path resolution could be abused for denial of service on crafted URLs.</li>
<li>The remaining fixes in this release touch <code>crypto/tls</code>, <code>encoding/asn1</code>, <code>html/template</code>, and <code>net</code>; I could not find individually itemized CVE descriptions for those in the sources available to me, so I&rsquo;m not attributing specific CVE IDs to them here rather than guessing.</li>
</ul>
</li>
<li><code>golang.org/x/crypto</code> 0.54.0 → 0.55.0 and <code>golang.org/x/net</code> 0.57.0 → 0.58.0 (indirect, via <code>go-git</code>): routine version bumps. I found no dedicated golang-announce security tag for either of these specific versions, so treat them as non-security refreshes.</li>
</ul>
<h2 id="ci-updates">CI Updates</h2>
<ul>
<li>Refreshed the <code>golang</code> build-stage Docker base image to the <code>1.26.6-bookworm</code> tag (carrying the toolchain security fixes above into the container build), after an interim digest-only refresh of the prior <code>1.26.5-bookworm</code> tag.</li>
<li><code>github/codeql-action</code> v4.37.6 → v4.37.7.</li>
<li>Python tooling: <code>platformdirs</code> (used by yamllint CI tooling) 4.11.1 → 4.11.3.</li>
<li>Refreshed the self-referential <code>TomTonic/grype_me</code> action digest pin used for this repository&rsquo;s own dogfooding workflow.</li>
</ul>
<h2 id="changed-behavior">Changed Behavior</h2>
<p>None.</p>
<h2 id="new-features">New Features</h2>
<p>None.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/TomTonic/grype_me/compare/v1.3.19-release...v1.3.20-release">https://github.com/TomTonic/grype_me/compare/v1.3.19-release...v1.3.20-release</a></p>
]]></content:encoded></item><item><title>Vaara Policy Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/vaara-policy-check/</link><pubDate>Fri, 14 Aug 2026 22:17:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/vaara-policy-check/</guid><description>Version updated for https://github.com/vaaraio/vaara to version v1.67.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation and management of verifiable receipts for autonomous actions, ensuring accountability and transparency in decision-making processes. It provides a secure and tamper-evident record of every call to governed functions, allowing users to verify outcomes offline using a simple HTML verification tool. The action integrates with various platforms and languages, making it easy to implement across different projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaaraio/vaara">https://github.com/vaaraio/vaara</a></strong> to version <strong>v1.67.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vaara-policy-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation and management of verifiable receipts for autonomous actions, ensuring accountability and transparency in decision-making processes. It provides a secure and tamper-evident record of every call to governed functions, allowing users to verify outcomes offline using a simple HTML verification tool. The action integrates with various platforms and languages, making it easy to implement across different projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1670---2026-08-14">[1.67.0] - 2026-08-14</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Anyone can now verify a receipt without installing anything.</strong>
<code>webpage/verify.html</code> is a single file with no build step and no
dependencies. It recomputes the DSSE pre-authentication encoding, takes its
digest, and checks the Ed25519 signature with WebCrypto. The receipt never
leaves the browser, nothing is uploaded, and the page works with the network
off, so verification is not a service and not a party anyone has to trust.
It mirrors the independent Python checker under <code>tests/vectors/</code>, which
imports no Vaara code either; both were run against <code>agent_decision_v0</code> and
agree on the PAE digest, the signature and the decision.</li>
<li>The page also states what a passing check does <strong>not</strong> establish: that the
key belongs to the expected party, that the signed statement is true, that
<code>decided_at</code> means anything without an external time authority, or that one
receipt is a whole history.</li>
<li><strong><code>vaara trail publish-head</code></strong> publishes a trail&rsquo;s head digest to a public
transparency log. Takes the same <code>--trail</code> / <code>--db</code> source as the other trail
commands, plus <code>--dry-run</code>, <code>--log</code> for a self-hosted or EU-operated
endpoint, and <code>--yes</code> for non-interactive use. Opt-in and off by default.</li>
<li>The command prints, on every run, what leaves the machine and what does not,
that publication is permanent with no erasure available afterwards, that the
log is public and enumerable rather than visible only to its operator, and
that everything published under one key can be grouped by anyone. An
interactive run confirms before publishing; <code>--yes</code> skips the prompt, never
the disclosure.</li>
<li><strong><code>vaara.attestation.rekor_log</code></strong> backs that with Sigstore Rekor, the adapter
<code>transparency_log.py</code> has described in its docstring since it was written. A
log the emitter operates proves the chain is internally consistent; it cannot
prove the emitter kept one history. What leaves the machine is one digest and
a signature over it. Offline verification never calls it.</li>
</ul>
]]></content:encoded></item><item><title>verbatra</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/verbatra/</link><pubDate>Fri, 14 Aug 2026 22:16:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/verbatra/</guid><description>Version updated for https://github.com/verbatra/action to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The verbatra GitHub Action automates the process of translating locale files using AI or machine translation providers. It reads and compares locale files to detect missing or drifted strings, fills gaps with translations, ensures placeholder and ICU integrity, and provides annotations and a job-summary table in CI or pull requests. The action supports various providers like OpenAI, Anthropic, Gemini, DeepL, or local models, allowing for flexible localization workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/verbatra/action">https://github.com/verbatra/action</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/verbatra">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The verbatra GitHub Action automates the process of translating locale files using AI or machine translation providers. It reads and compares locale files to detect missing or drifted strings, fills gaps with translations, ensures placeholder and ICU integrity, and provides annotations and a job-summary table in CI or pull requests. The action supports various providers like OpenAI, Anthropic, Gemini, DeepL, or local models, allowing for flexible localization workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Metadata and documentation only. No change to the action&rsquo;s behavior, inputs, or outputs.</p>
<p><code>action.yml</code> now describes what the action has done since v1.1.0: run translations in CI <strong>or</strong> gate a pull request on locale drift. The old description mentioned translation only, so the Marketplace listing hid the read-only <code>check</code> and <code>diff</code> gate that v1.1.0 shipped. The <code>command</code> input itself is unchanged.</p>
<p>Also refreshes the README, contributing guide, and security policy carried at the release tag, and folds the version bump into the release commit, so <code>package.json</code> and <code>package-lock.json</code> now read the version they ship at instead of the previous one.</p>
<p><code>verbatra/action@v1</code> moves to this release.</p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/vibgrate-scan/</link><pubDate>Fri, 14 Aug 2026 22:15:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.814.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @vibgrate/cli GitHub Action provides a local codebase intelligence tool that answers three main questions: what the codebase is, how far behind it is (measured by DriftScore and RiskScore), and whether it can be fixed locally. It generates a deterministic code graph, drift score, and ranked upgrade priorities for any repository. The action runs on your machine without relying on network calls or data leaving your repo unless explicitly pushed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.814.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>@vibgrate/cli</code> GitHub Action provides a local codebase intelligence tool that answers three main questions: what the codebase is, how far behind it is (measured by DriftScore and RiskScore), and whether it can be fixed locally. It generates a deterministic code graph, drift score, and ranked upgrade priorities for any repository. The action runs on your machine without relying on network calls or data leaving your repo unless explicitly pushed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268141">Vibgrate CLI 2026.814.1</h1>
<p><em>Released 2026-08-14</em></p>
<p>This release of the vg CLI includes several enhancements and fixes aimed at improving usability and performance. Key updates include a new session protocol for vg code, incremental extraction for vg hcs, and improved handling of scans and updates.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="new">New</h3>
<ul>
<li>vg code session protocol v2 introduces new features for host UIs, including session details reporting and explicit session ID continuation.</li>
<li>vg hcs extract is now incremental by default, optimizing re-extraction of files.</li>
<li>vg code approval friction is reduced for read-only commands in Agent mode, enhancing usability.</li>
<li>vg code session power features allow mid-flight steering of turns and improved management of stored chats.</li>
<li>vg code now provides reasoning model insights and cost tracking for reasoning efforts.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>The semantic backend now loads components from a specified directory when available.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>vg update no longer triggers unnecessary downloads during installation.</li>
<li>vg scans now handle plan limits more gracefully, warning users without aborting.</li>
<li>vg code &ndash;continue correctly identifies session IDs without confusion from instruction text.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.813.1, interleaved on one runner against the pinned corpus (189 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21789 count</td>
          <td>21789 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>11108 count</td>
          <td>11108 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.94 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>710 ms</td>
          <td>720 ms</td>
      </tr>
  </tbody>
</table>
<p>2 regression(s) — published, not omitted:</p>
<ul>
<li>Tasks passed on both arms: 33 → 31 (-6.1%)</li>
<li>Comparable-task rate (both arms passed / total): 0.94 → 0.89 (-6.1%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.814.1">https://vibgrate.com/changelog/cli/2026.814.1</a></p>
]]></content:encoded></item><item><title>WAF++ PASS Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/waf-pass-scan/</link><pubDate>Fri, 14 Aug 2026 22:13:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/waf-pass-scan/</guid><description>Version updated for https://github.com/WAF2p/wafpass-action to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of Infrastructure as Code (IaC) files using WAF++ PASS, a security tool that assesses IaC configurations for vulnerabilities and misconfigurations. It pushes scan results to a specified WAF++ server endpoint, supports both Bearer token and API key authentication, and can fail the workflow based on predefined policies. The action is configured with various inputs such as scan paths, IaC frameworks, and severity levels, making it flexible for different use cases in CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/WAF2p/wafpass-action">https://github.com/WAF2p/wafpass-action</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/waf-pass-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the scanning of Infrastructure as Code (IaC) files using WAF++ PASS, a security tool that assesses IaC configurations for vulnerabilities and misconfigurations. It pushes scan results to a specified WAF++ server endpoint, supports both Bearer token and API key authentication, and can fail the workflow based on predefined policies. The action is configured with various inputs such as scan paths, IaC frameworks, and severity levels, making it flexible for different use cases in CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: add fetch_controls input to pull controls from framework repo by @ZanshinShadow in <a href="https://github.com/WAF2p/wafpass-action/pull/2">https://github.com/WAF2p/wafpass-action/pull/2</a></li>
<li>upgrade to the new API versioning - WAF2p/pass#42 by @lewandos in <a href="https://github.com/WAF2p/wafpass-action/pull/3">https://github.com/WAF2p/wafpass-action/pull/3</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@lewandos made their first contribution in <a href="https://github.com/WAF2p/wafpass-action/pull/1">https://github.com/WAF2p/wafpass-action/pull/1</a></li>
<li>@ZanshinShadow made their first contribution in <a href="https://github.com/WAF2p/wafpass-action/pull/2">https://github.com/WAF2p/wafpass-action/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/WAF2p/wafpass-action/compare/v0.1.0...v0.1.1">https://github.com/WAF2p/wafpass-action/compare/v0.1.0...v0.1.1</a></p>
]]></content:encoded></item><item><title>Picket Secret Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/picket-secret-scanner/</link><pubDate>Fri, 14 Aug 2026 22:12:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/picket-secret-scanner/</guid><description>Version updated for https://github.com/willibrandon/picket to version v0.2.12.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Picket is a MIT-licensed tool for scanning secrets in .NET projects, providing a Gitleaks-compatible command surface, Native AOT release binaries, and dotnet tool packages. It automates the process of identifying sensitive information such as API keys, passwords, and other credentials by scanning Git changes, Hugging Face resources, and GitLab project data. The action can be integrated into CI pipelines and used to ensure code safety during development.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/willibrandon/picket">https://github.com/willibrandon/picket</a></strong> to version <strong>v0.2.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/picket-secret-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Picket is a MIT-licensed tool for scanning secrets in .NET projects, providing a Gitleaks-compatible command surface, Native AOT release binaries, and dotnet tool packages. It automates the process of identifying sensitive information such as API keys, passwords, and other credentials by scanning Git changes, Hugging Face resources, and GitLab project data. The action can be integrated into CI pipelines and used to ensure code safety during development.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release artifacts include SHA-256 checksums, package-size metadata, and GitHub artifact attestations.</p>
]]></content:encoded></item><item><title>Sync With ModelScope</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/sync-with-modelscope/</link><pubDate>Fri, 14 Aug 2026 22:11:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/sync-with-modelscope/</guid><description>Version updated for https://github.com/xiaoyao9184/modelscope-sync-action to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The modelscope-sync-action GitHub Action automates the process of synchronizing files from a GitHub repository with ModelScope. It allows users to specify local paths, GitHub repos, and ModelScope repo IDs for synchronization. The action can be configured to create new ModelScope repositories if they don’t exist, sync specific directories or subdirectories, include README.md files, and generate commit messages for the sync process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/xiaoyao9184/modelscope-sync-action">https://github.com/xiaoyao9184/modelscope-sync-action</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sync-with-modelscope">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>modelscope-sync-action</code> GitHub Action automates the process of synchronizing files from a GitHub repository with ModelScope. It allows users to specify local paths, GitHub repos, and ModelScope repo IDs for synchronization. The action can be configured to create new ModelScope repositories if they don&rsquo;t exist, sync specific directories or subdirectories, include README.md files, and generate commit messages for the sync process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of the Model Scope Sync action! This action lets you sync files on GitHub with a repo on Model Scope.👾</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/xiaoyao9184/modelscope-sync-action/commits/v0.0.1">https://github.com/xiaoyao9184/modelscope-sync-action/commits/v0.0.1</a></p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/cowork-harness/</link><pubDate>Fri, 14 Aug 2026 22:10:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.23.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, cowork-harness, is a test harness designed for testing Claude Cowork skills. It automates the reproduction of the observable runtime contract closely enough to run tests headless and in CI environments across various scenarios. The key capabilities include reproducing both behavior and limitations such as sealed filesystem and default-deny egress. It provides a green test result when all conditions are met, ensuring that real Cowork runs would also pass.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.23.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, cowork-harness, is a test harness designed for testing Claude Cowork skills. It automates the reproduction of the observable runtime contract closely enough to run tests headless and in CI environments across various scenarios. The key capabilities include reproducing both behavior and limitations such as sealed filesystem and default-deny egress. It provides a green test result when all conditions are met, ensuring that real Cowork runs would also pass.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>Platform baseline for Claude Desktop 1.30096.1 (bundled agent ELF <code>2.1.229</code>).</strong> The agent ELF&rsquo;s
<code>sha256</code> was verified against the official release manifest for 2.1.229. The modeled spawn contract is
unchanged across the bump — <code>spawn.tools</code> stays 20 entries, <code>allowedTools</code> 19, the egress allowlist 15
domains, the spawn-env key set 61 with 31 conditional spreads, and the Cowork system prompt is
byte-identical (its fingerprint is recorded for 1.30096.1 in
<code>baselines/prompts/cowork-system-prompt-fingerprints.json</code>). <code>sync</code> refused to write this baseline until
the two sentinel defects below were corrected.</p>
</li>
<li>
<p><strong>Two drift sentinels pinned in the synced baseline&rsquo;s <code>provenance.gates</code></strong>: the artifact-mount gate
(<code>coworkArtifacts</code>) and the CIC <code>can_use_tool</code> handler (<code>cicCanUseToolEnabled</code>). Both are force-ON in
production, and the artifact-mount gap documented in <code>docs/fidelity-gaps.md</code> rests on that fact — which
was previously read from a live feature cache the baseline never recorded, so nothing would have
noticed it changing.</p>
</li>
<li>
<p><strong><code>check:versions</code> guards DESIGN.md&rsquo;s live-verification scope note (invariant 11).</strong> That note is the
repo&rsquo;s disclosure of how much of the <em>current</em> baseline has actually been verified live, and every
figure in it is derivable from <code>baselines/desktop-*.json</code> — yet it sat in unguarded prose and had
drifted twice, the baseline list having been extended without recounting. Understating how much is
unverified is the doc error least worth shipping, so it is now checked. Two forms, selected by whether
the note&rsquo;s live-pass baseline is the newest one: with a gap, the listed baselines must run contiguously
from wherever the list starts through the newest baseline, and both counts must match the list and the
real <code>agentVersion</code> transitions; with no gap, the note must say so explicitly and carry no stale
enumeration. Either way the named agent must be the newest baseline&rsquo;s. Because shipping a baseline flips
the no-gap form into the gap form, a new release now forces the note to be rewritten rather than
silently overstating coverage. The list&rsquo;s <em>start</em> is deliberately not derived — the note omits baselines
covered by the live pass itself, and encoding that rule would only relocate the drift. A missing or
unrecognisable note is an error, never a skip.</p>
</li>
<li>
<p><strong>Cassettes now record the rootfs image they were recorded against</strong>, closing the last gap in the
agent-image provenance work. The image decides <code>missingCapabilityUse</code>, which <code>computeVerdict</code> fails
on, so the rootfs is verdict-affecting — yet no cassette field named it, and a recording silently
inherited whatever image happened to be on the machine. <code>environment.agentImage</code> now carries the
resolved <code>ref</code> plus whichever identities exist: <code>configId</code> (the local config id, present for built
<strong>and</strong> pulled images but not comparable across machines) and <code>registryDigest</code> (the registry manifest
digest, pulled images only, and the only identity comparable across machines).</p>
<p>The field is stamped only for the tiers whose capabilities actually come from that image —
<code>container</code> and <code>hostloop</code>. <code>microvm</code> probes the Lima guest instead, so it records nothing rather
than naming an image that had no bearing on the run. Additive: no <code>cassetteVersion</code> bump, absent on
cassettes recorded before the field existed, and never backfilled — the absence is meaningful.</p>
<p><code>ref</code> is a verbatim <code>COWORK_AGENT_IMAGE</code> value, so a private registry ref (<code>registry.acme.corp/…</code>)
would otherwise be committed into a public fixture with <code>grep</code>-clean transcript text. It is scanned
by <code>verify-cassettes</code> and rewritten by redaction like every other user-controlled string; the digests
are content hashes and are deliberately left intact.</p>
</li>
<li>
<p><strong><code>replay</code> warns when the rootfs image differs from the recording.</strong> It compares <code>registryDigest</code>
first — the only identity stable across machines, which is the case the field exists to serve — and
falls back to the local config id only when neither side has a registry digest. A recording made
against a pulled image and replayed against a local rebuild is reported as drift rather than passing
silently. Advisory only: a legitimately re-pulled image is the common case, so this names the
difference instead of failing the replay.</p>
<p>The current image is inspected at most once per <code>replay</code> invocation, and only when a cassette
actually recorded one — so replay stays usable with no container runtime present, and the
<code>verify-cassettes</code> privacy scan never shells out.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>The host-loop <code>canUseTool</code> chain sentinel could be widened silently.</strong> Desktop 1.30096.1 inserts a
fourth link into the chain — an allow carve-out that rewrites the tool&rsquo;s input and runs ahead of the
existing deny. The sentinel was a prefix match with no terminator, so it accepted any chain that merely
<em>started</em> with the expected calls: an inserted <strong>synchronous</strong> link would have passed unnoticed, and
the block that surfaced this release only happened because the new link is <code>await</code>ed.</p>
<p>The check now decomposes the chain with a real scanner (the assignment must be brace/paren-balanced,
and <code>??</code> legitimately occurs inside a template interpolation in the chain&rsquo;s own log line) and asserts
it end to end: the terminal operand must be a bare call to the saved original, every operand whose
callee is an <code>async function</code> must be awaited, no link that can return an allow may precede the
VM-path deny, and each link must resolve to a definition. The await rule is the load-bearing one — an
un-awaited async link returns a Promise, which is never nullish, so <code>??</code> short-circuits and every later
link <em>including the original callback</em> is skipped. Three and four link chains are both accepted so an
older Desktop still syncs; a fifth is reported for classification.</p>
</li>
<li>
<p><strong>The early-allow ordering check had never fired.</strong> It searched for a containment helper by two
readable names, neither of which occurs in any shipped asar — production mangles the call — so the
guard was permanently inert and its test passed only because the fixture hard-coded a token that does
not exist in the product. The helper is now identified by shape and resolved through the export map.</p>
</li>
<li>
<p><strong>S6c no longer hard-blocks on a minifier rename.</strong> It pinned the HIPAA-restriction call by its
minified <em>member name</em>, so the rename <code>A.r()</code> → <code>t.hu()</code> failed a predicate that is otherwise
byte-for-byte identical. The callee is now resolved through the chunk&rsquo;s export map and verified two
hops to the reader that consults the restriction, with resolution failure treated as a miss.</p>
</li>
<li>
<p><strong>The <code>protocol</code>-tier live suite had been silently skipping itself for many releases.</strong> <code>live-matrix</code>
required a staged agent binary for a baseline pinned years back, but protocol fidelity spawns the host
<code>claude</code> from <code>PATH</code> and never resolves a staged binary — the requirement was never real for that tier.
Because Claude Desktop prunes old staged agents on update, the gate went false as soon as a machine
moved past that agent version, and the suite dropped out on every developer machine and in CI without
naming itself. It now gates on what the tier actually uses and emits a skip notice identifying the
failing precondition, since this is the only protocol-tier live coverage there is.</p>
</li>
<li>
<p><strong>The <code>hostloop</code> uploads-are-<code>Read</code>-able live case no longer fails on the model&rsquo;s choice of exploration
tool.</strong> It asserted that neither native nor workspace bash ran at all, as a proxy for &ldquo;the agent needed a
workaround&rdquo; — so a run where the agent listed the uploads directory with <code>ls</code> went red, while the next
run, which used <code>Glob</code> instead, went green. In both the upload was <code>Read</code> directly at the advertised
path and no outputs-delete fired, so the regression the case guards was absent either way. It now reads
the recorded bash commands and fails only when one <strong>names the uploaded file</strong>, which is what reading or
copying it as a workaround requires and what listing its directory cannot do. Verified against both
recorded runs plus <code>cat</code>/<code>cp</code> mutations: the false red is gone and the workaround chain still trips it.</p>
</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>
<p><strong>A full live end-to-end pass now covers baseline <code>desktop-1.30096.1</code> / agent 2.1.229</strong>, across all
three tiers (<code>protocol</code>, <code>container</code>, <code>hostloop</code>), superseding the <code>desktop-1.20186.0</code> pin. DESIGN.md&rsquo;s
claim and its scope note are re-stamped accordingly, including the caveats: two <code>live-outputs-delete</code>
cases skipped as model-behaviour misses, the tiers were covered across two invocations because the
<code>protocol</code> suite was repaired mid-pass, and the suites are model-dependent enough that a single red is
evidence of variance until a re-run says otherwise.</p>
</li>
<li>
<p><strong><code>docs/fidelity-gaps.md</code>&rsquo;s artifacts section records the agent-side consent floor.</strong> The server-delivered
session flag no longer only decides Desktop&rsquo;s spawned tool list — the agent reads the corresponding
spawn-env key itself and uses it to select its own artifact publish surface and a read-only mode. The
agent also refuses artifact publishes, comment replies, comment-thread resolves and artifact database
writes outright in a session with no answerable approval surface, and fails closed if it cannot confirm
one. The section now also states why this is recorded rather than modeled: artifact operations are
server-backed, on hosts outside the sandbox egress allowlist, so supplying the flag would offer a tool
resolving against a service the sandbox cannot reach.</p>
</li>
<li>
<p><strong>The same section&rsquo;s mount-kind list is corrected.</strong> It named a synthetic root that is not a mount kind
and omitted one that is, which mattered because the artifact-mount gap is stated in terms of what the
harness does and does not mount.</p>
</li>
<li>
<p><strong><code>docs/maintenance.md</code> corrects what moves the floating agent-image <code>:2</code> tag.</strong> It is a curated pointer
moved deliberately by a manual publish with <code>immutable_only</code> unchecked — explicitly <em>not</em> something a
release tag push moves.</p>
</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 1.23.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/115">https://github.com/yaniv-golan/cowork-harness/pull/115</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1.22.0...v1.23.0">https://github.com/yaniv-golan/cowork-harness/compare/v1.22.0...v1.23.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/b.ia-accessibility-checker/</link><pubDate>Fri, 14 Aug 2026 22:09:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows companies to define target audiences and ensure their code meets specific accessibility guidelines. The action uses AI to measure guidelines, providing flexibility in accessibility focus and reducing costs associated with external solutions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows companies to define target audiences and ensure their code meets specific accessibility guidelines. The action uses AI to measure guidelines, providing flexibility in accessibility focus and reducing costs associated with external solutions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>Zuke Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/zuke-build/</link><pubDate>Fri, 14 Aug 2026 22:08:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/zuke-build/</guid><description>Version updated for https://github.com/zuke-build/zuke to version v1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Zuke is a build automation system for Deno and TypeScript that allows developers to define builds as TypeScript classes with fluent API, resolving dependencies and running them in topological order. It provides type-safe dependencies, refactoring-safe code, and just TypeScript syntax without YAML or bespoke DSLs. Zuke is built using AI and has 54 packages following full semver, including tool wrappers and plugins.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zuke-build/zuke">https://github.com/zuke-build/zuke</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zuke-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Zuke is a build automation system for Deno and TypeScript that allows developers to define builds as TypeScript classes with fluent API, resolving dependencies and running them in topological order. It provides type-safe dependencies, refactoring-safe code, and just TypeScript syntax without YAML or bespoke DSLs. Zuke is built using AI and has 54 packages following full semver, including tool wrappers and plugins.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Updates <code>step-security/harden-runner</code> to v2.20.1.</p>
<p>Nothing about the action&rsquo;s interface changes: the same seven inputs, the same behaviour, the same ordering. This exists so the bump reaches anyone sing zuke-build/zuke@v1 — a pinned action only ships a fix when the tag it is pinned to moves.</p>
<p>Pin the full commit SHA rather than the moving v1 tag: <code>zuke-build/zuke@5400f044d0b56206b0fa48c90b30486df205c7c6</code></p>
]]></content:encoded></item><item><title>stackit-cli tools installer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/stackit-cli-tools-installer/</link><pubDate>Fri, 14 Aug 2026 14:01:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/stackit-cli-tools-installer/</guid><description>Version updated for https://github.com/jkroepke/setup-stackit-cli to version v1.2.98.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs the stackit-cli binary on the runner, allowing users to define which version of the tool they want to use in their workflows. It supports installing the latest stable version or any specific semantic version string. The action also caches and prepends the installed binary path to the PATH environment variable for easier access.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jkroepke/setup-stackit-cli">https://github.com/jkroepke/setup-stackit-cli</a></strong> to version <strong>v1.2.98</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/stackit-cli-tools-installer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs the stackit-cli binary on the runner, allowing users to define which version of the tool they want to use in their workflows. It supports installing the latest stable version or any specific semantic version string. The action also caches and prepends the installed binary path to the PATH environment variable for easier access.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.2.98 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="-dependencies">🛠️ Dependencies</h3>
<ul>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/jkroepke/setup-stackit-cli/pull/306">https://github.com/jkroepke/setup-stackit-cli/pull/306</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.97...v1.2.98">https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.97...v1.2.98</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/neurolink-ai/</link><pubDate>Fri, 14 Aug 2026 14:00:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v10.12.3.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that provides a single, consistent API for integrating 30+ AI providers and models. It allows users to switch between different providers with ease and leverages built-in tools plus any MCP-compliant tool server. With enterprise features like Redis memory and multi-provider failover, NeuroLink optimizes costs automatically with intelligent routing. Users can interact with the platform via our professional CLI or TypeScript SDK.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v10.12.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is a universal AI integration platform that provides a single, consistent API for integrating 30+ AI providers and models. It allows users to switch between different providers with ease and leverages built-in tools plus any MCP-compliant tool server. With enterprise features like Redis memory and multi-provider failover, NeuroLink optimizes costs automatically with intelligent routing. Users can interact with the platform via our professional CLI or TypeScript SDK.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="10123-2026-08-14"><a href="https://github.com/juspay/neurolink/compare/v10.12.2...v10.12.3">10.12.3</a> (2026-08-14)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(proxy):</strong>  attribute runtime errors internally (<a href="https://github.com/juspay/neurolink/commit/258ca3435e4fe0d52abbb327c59a599444ffd302">258ca34</a>)</li>
<li><strong>(proxy):</strong>  diagnose updater health probe failures (<a href="https://github.com/juspay/neurolink/commit/41e3c9e94d84d89d8c4ad3ff9b020bdb9cb475e4">41e3c9e</a>)</li>
</ul>
]]></content:encoded></item><item><title>Maximize GitHub Runner Space</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/maximize-github-runner-space/</link><pubDate>Fri, 14 Aug 2026 13:59:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/maximize-github-runner-space/</guid><description>Version updated for https://github.com/justinthelaw/maximize-github-runner-space to version v0.12.1.
This action is used across all versions by 27 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action maximize-github-runner-space automatically cleans up optional SDKs, toolchains, services, and caches on standard GitHub-hosted runners before large build, test, or container jobs. It detects the runner’s OS, architecture, privileges, and installed capabilities; callers do not select a platform manually. This action is intended for reclaiming disk space on these runners, especially for large images, Android builds, or monorepos.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/justinthelaw/maximize-github-runner-space">https://github.com/justinthelaw/maximize-github-runner-space</a></strong> to version <strong>v0.12.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>27</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/maximize-github-runner-space">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>maximize-github-runner-space</code> automatically cleans up optional SDKs, toolchains, services, and caches on standard GitHub-hosted runners before large build, test, or container jobs. It detects the runner&rsquo;s OS, architecture, privileges, and installed capabilities; callers do not select a platform manually. This action is intended for reclaiming disk space on these runners, especially for large images, Android builds, or monorepos.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: consolidate dependency updates for v0.12.1 by @justinthelaw in <a href="https://github.com/justinthelaw/maximize-github-runner-space/pull/47">https://github.com/justinthelaw/maximize-github-runner-space/pull/47</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/justinthelaw/maximize-github-runner-space/compare/v0.12.0...v0.12.1">https://github.com/justinthelaw/maximize-github-runner-space/compare/v0.12.0...v0.12.1</a></p>
]]></content:encoded></item><item><title>jscpd-copy-paste-detector</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/jscpd-copy-paste-detector/</link><pubDate>Fri, 14 Aug 2026 13:58:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/jscpd-copy-paste-detector/</guid><description>Version updated for https://github.com/kucherenko/jscpd to version v5.0.15.
This action is used across all versions by 4,724 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the detection of duplicated code blocks across files using the jscpd tool. It supports multiple programming languages and engines (TypeScript and Rust), offering 224+ formats and a 24-37x faster speed than the previous version. The action can be used to integrate jscpd into CI workflows, providing a clear report of detected clones.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kucherenko/jscpd">https://github.com/kucherenko/jscpd</a></strong> to version <strong>v5.0.15</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4,724</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jscpd-copy-paste-detector">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the detection of duplicated code blocks across files using the jscpd tool. It supports multiple programming languages and engines (TypeScript and Rust), offering 224+ formats and a 24-37x faster speed than the previous version. The action can be used to integrate jscpd into CI workflows, providing a clear report of detected clones.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="new-features">New Features</h3>
<ul>
<li><strong>SARIF: size-based severity</strong> — new <code>--sarif-error-tokens &lt;N&gt;</code> flag (also <code>sarifErrorTokens</code> in <code>.jscpd.json</code>): clones with at least N tokens are reported at level <code>error</code> while smaller ones stay <code>warning</code>. When overall duplication exceeds <code>--threshold</code>, <strong>all</strong> SARIF results are emitted as <code>error</code>, matching the threshold check that fails the build. Default output is unchanged when neither option is set. (<a href="https://github.com/kucherenko/jscpd/issues/908">#908</a>)</li>
<li><strong>SARIF: clone fingerprints</strong> — each result carries <code>token_count</code> and a <code>clone_hash</code> in its properties bag, plus a <code>partialFingerprints</code> entry (<code>jscpdCloneHash/v1</code>) for cross-run result identity in consumers like GitHub code scanning. The hash is order-insensitive, so the same clone pair produces the same hash regardless of file discovery order. (<a href="https://github.com/kucherenko/jscpd/issues/909">#909</a>)</li>
<li><strong>SARIF: related-location messages</strong> — the duplicate&rsquo;s counterpart location now has a message (<code>Duplicated at &lt;path&gt;:&lt;line&gt;</code>), and the primary message references it via a SARIF embedded link so GitHub code scanning displays it. (<a href="https://github.com/kucherenko/jscpd/issues/911">#911</a>)</li>
<li><strong>SARIF: richer rule metadata</strong> — the <code>jscpd/duplicate-code</code> rule now includes a display name, full description, default configuration, and quality tags for better presentation in SARIF viewers and Azure DevOps. (<a href="https://github.com/kucherenko/jscpd/pull/914">#914</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>Scan-root-relative report paths</strong> — fragments store their scan root separately (<code>source_root</code>), so report paths are relative to the scanned directory again (as in 4.x) while reporters can still resolve and read source files; SARIF emits <code>originalUriBaseIds</code> with per-root base ids. Fixes empty snippets and unresolvable paths when scanning from outside the target directory, including multi-root scans. (<a href="https://github.com/kucherenko/jscpd/issues/872">#872</a>, <a href="https://github.com/kucherenko/jscpd/issues/892">#892</a>)</li>
<li><strong>Report version stamping</strong> — the SARIF <code>tool.driver.version</code> (previously hardcoded <code>5.0.3</code>) and the HTML report version now match <code>cpd --version</code>, bundled at build time. (<a href="https://github.com/kucherenko/jscpd/issues/915">#915</a>)</li>
<li><strong>Multi-root blame attribution</strong> — with multiple scan roots containing the same relative path, git blame data is now keyed by resolved path, so the second root no longer inherits the first root&rsquo;s authors.</li>
<li><strong>Git root discovery</strong> — walking up from a relative scan path no longer terminates early before reaching the repository root.</li>
</ul>
<h3 id="dependencies">Dependencies</h3>
<ul>
<li>Bump <code>serde_json</code> to 1.0.151 in <code>/rust</code></li>
<li>Bump <code>ignore</code> to 0.4.32 in <code>/rust</code></li>
<li>Bump <code>anyhow</code> to 1.0.104 in <code>/rust</code></li>
</ul>
<h3 id="thank-you-">Thank You ❤️</h3>
<p>This release was shaped by community contributions — huge thanks to:</p>
<ul>
<li><a href="https://github.com/chrisc-onaorg">@chrisc-onaorg</a> for the SARIF clone fingerprints (<a href="https://github.com/kucherenko/jscpd/pull/910">#910</a>), related-location messages (<a href="https://github.com/kucherenko/jscpd/pull/912">#912</a>), and richer rule metadata (<a href="https://github.com/kucherenko/jscpd/pull/914">#914</a>), plus reporting #909, #911, and #915</li>
<li><a href="https://github.com/darronz">@darronz</a> for the scan-root-relative paths fix (<a href="https://github.com/kucherenko/jscpd/pull/913">#913</a>)</li>
<li><a href="https://github.com/nvuillam">@nvuillam</a> for proposing size-based SARIF severity (<a href="https://github.com/kucherenko/jscpd/issues/908">#908</a>)</li>
</ul>
<h2 id="published-packages">Published Packages</h2>
<ul>
<li><code>cpd-core@0.1.8</code> on crates.io</li>
<li><code>cpd-finder@0.1.10</code> on crates.io</li>
<li><code>cpd-reporter@0.1.8</code> on crates.io</li>
<li><code>cpd-tokenizer@0.1.9</code> on crates.io</li>
<li><code>jscpd@5.0.15</code> on crates.io</li>
<li><code>cpd@5.0.15</code> on npm</li>
<li><code>jscpd-darwin-arm64@5.0.15</code> on npm</li>
<li><code>jscpd-darwin-x64@5.0.15</code> on npm</li>
<li><code>jscpd-linux-x64-gnu@5.0.15</code> on npm</li>
<li><code>jscpd-linux-arm64-gnu@5.0.15</code> on npm</li>
<li><code>jscpd-linux-x64-musl@5.0.15</code> on npm</li>
<li><code>jscpd-windows-x64-msvc@5.0.15</code> on npm</li>
<li><code>jscpd@5.0.15</code> on npm</li>
</ul>
]]></content:encoded></item><item><title>Regula AI Governance Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/regula-ai-governance-check/</link><pubDate>Fri, 14 Aug 2026 13:57:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/regula-ai-governance-check/</guid><description>Version updated for https://github.com/kuzivaai/getregula to version v1.9.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Regula is an AI governance scanning tool that checks local source-code folders for potential risks related to AI regulations such as the EU AI Act, South Korea’s AI Basic Act, and Colorado SB 26-189. It provides a detailed review trail and candidate risk categories, allowing developers or governance leads to decide what further investigation is needed. The tool does not determine legal classification or compliance but focuses on identifying patterns that may need human review.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kuzivaai/getregula">https://github.com/kuzivaai/getregula</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/regula-ai-governance-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Regula is an AI governance scanning tool that checks local source-code folders for potential risks related to AI regulations such as the EU AI Act, South Korea&rsquo;s AI Basic Act, and Colorado SB 26-189. It provides a detailed review trail and candidate risk categories, allowing developers or governance leads to decide what further investigation is needed. The tool does not determine legal classification or compliance but focuses on identifying patterns that may need human review.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Marketplace listing release for the existing v1.9.0.</p>
]]></content:encoded></item><item><title>Slackalaka</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/slackalaka/</link><pubDate>Fri, 14 Aug 2026 13:55:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/slackalaka/</guid><description>Version updated for https://github.com/mallowigi/tag-n-slack to version 0.2.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action Tag n&amp;#39; Slack creates a new release tag with a changelog and notifies Slack about the release. It automates the process of extracting version information from either package.json or commit hash/message, updating the changelog, creating a release tag, and sending a notification to a specified Slack channel with details about the release.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mallowigi/tag-n-slack">https://github.com/mallowigi/tag-n-slack</a></strong> to version <strong>0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/slackalaka">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>Tag n' Slack</code> creates a new release tag with a changelog and notifies Slack about the release. It automates the process of extracting version information from either <code>package.json</code> or commit hash/message, updating the changelog, creating a release tag, and sending a notification to a specified Slack channel with details about the release.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Truncate changelog content before subversion headers during parsing (4cba572)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (d48462d)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (e8cca16)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (0998ab2)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (74b7ec6)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (995b49e)</li>
<li>Add watch mode and enhance error handling for <code>findPackageJson</code> (58f570c)</li>
<li>Add watch mode and enhance error handling for <code>findPackageJson</code> (0a6a3ea)</li>
<li>Add watch mode and enhance error handling for <code>findPackageJson</code> (d616c7f)</li>
<li>Migrate codebase and dependencies to ES modules. (bd554c2)</li>
</ul>
]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/lgtmaybe/</link><pubDate>Fri, 14 Aug 2026 13:54:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v2.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary lgtmaybe is a tool that automates code reviews by analyzing pull requests against a set of predefined criteria. It uses an AI model to detect bugs, security vulnerabilities, and other issues in the code changes, providing inline comments and a summary of the review results. The action supports various hosted providers, local Ollama models, and OpenAI-compatible endpoints.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v2.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>lgtmaybe is a tool that automates code reviews by analyzing pull requests against a set of predefined criteria. It uses an AI model to detect bugs, security vulnerabilities, and other issues in the code changes, providing inline comments and a summary of the review results. The action supports various hosted providers, local Ollama models, and OpenAI-compatible endpoints.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="212-2026-08-14"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v2.1.1...lgtmaybe-v2.1.2">2.1.2</a> (2026-08-14)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>trace review findings through profile (<a href="https://github.com/MattJColes/lgtmaybe/issues/441">#441</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/8f21f4db2c8f4df6a56d2acae6e0a603f63aef77">8f21f4d</a>)</li>
</ul>
]]></content:encoded></item><item><title>hestia-cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/hestia-cache/</link><pubDate>Fri, 14 Aug 2026 13:53:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/hestia-cache/</guid><description>Version updated for https://github.com/Mic92/hestia to version v3.0.1.
This action is used across all versions by 28 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Hestia GitHub Action is designed to efficiently cache Nix build results in the GitHub Actions cache. It allows builds to run faster by downloading previously built packages instead of rebuilding them, significantly reducing download times and avoiding 429 Too Many Requests errors. The action also deduplicates data, making it more efficient for large repositories. Additionally, it includes a matrix subaction that evaluates flake checks only once and distributes them across parallel runners, optimizing build workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Mic92/hestia">https://github.com/Mic92/hestia</a></strong> to version <strong>v3.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>28</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hestia-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Hestia GitHub Action is designed to efficiently cache Nix build results in the GitHub Actions cache. It allows builds to run faster by downloading previously built packages instead of rebuilding them, significantly reducing download times and avoiding <code>429 Too Many Requests</code> errors. The action also deduplicates data, making it more efficient for large repositories. Additionally, it includes a matrix subaction that evaluates flake checks only once and distributes them across parallel runners, optimizing build workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Mic92/hestia@v3.0.1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">version</span>: <span style="color:#ae81ff">v3.0.1</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>pipeline: bypass upstream filter for drv closures by @cons-tan-tan in <a href="https://github.com/Mic92/hestia/pull/132">https://github.com/Mic92/hestia/pull/132</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@cons-tan-tan made their first contribution in <a href="https://github.com/Mic92/hestia/pull/132">https://github.com/Mic92/hestia/pull/132</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Mic92/hestia/compare/v3.0.0...v3.0.1">https://github.com/Mic92/hestia/compare/v3.0.0...v3.0.1</a></p>
]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Fri, 14 Aug 2026 13:52:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.9.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action ServiceNow CI/CD GitHub Action for Run Tests automates the execution of automated test suites in a ServiceNow instance using Basic or API Key authentication. It helps streamline the process of running tests across different environments and versions, providing flexibility and ease of use for DevOps teams integrating ServiceNow with their CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>ServiceNow CI/CD GitHub Action for Run Tests</code> automates the execution of automated test suites in a ServiceNow instance using Basic or API Key authentication. It helps streamline the process of running tests across different environments and versions, providing flexibility and ease of use for DevOps teams integrating ServiceNow with their CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.8...1.0.9">https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.8...1.0.9</a></p>
]]></content:encoded></item><item><title>AurumCode Documentation Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/aurumcode-documentation-generator/</link><pubDate>Fri, 14 Aug 2026 13:51:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/aurumcode-documentation-generator/</guid><description>Version updated for https://github.com/Mpaape/AurumCode to version v1.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AurumCode is a multi-language API documentation generator that can be used as a GitHub Action or locally. It scans a source tree, extracts documentation per detected language, and generates Jekyll-ready sites. The main purpose of AurumCode is to help developers generate and review documentation for their projects, with features such as local diff reviews and pull request reviews using LLM-powered security passes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Mpaape/AurumCode">https://github.com/Mpaape/AurumCode</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aurumcode-documentation-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AurumCode is a multi-language API documentation generator that can be used as a GitHub Action or locally. It scans a source tree, extracts documentation per detected language, and generates Jekyll-ready sites. The main purpose of AurumCode is to help developers generate and review documentation for their projects, with features such as local diff reviews and pull request reviews using LLM-powered security passes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AurumCode reviews pull requests, generates documentation, and publishes it as a site. Three features, nothing else.</p>
<h2 id="try-it-in-two-minutes-with-no-api-key">Try it in two minutes, with no API key</h2>
<p>The security pass is deterministic: it matches the lines a change <strong>adds</strong> against an embedded rule catalogue and calls no model.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>git clone https://github.com/Mpaape/AurumCode <span style="color:#f92672">&amp;&amp;</span> cd AurumCode
</span></span><span style="display:flex;"><span>go build -o aurumcode ./cmd/aurumcode
</span></span><span style="display:flex;"><span>cd /path/to/your/repo
</span></span><span style="display:flex;"><span>aurumcode review -base HEAD~1 -seguranca
</span></span></code></pre></div><p>Add <code>-fail-on error</code> and the command exits 3 when a finding is severity <code>error</code> — that is how it blocks a merge in CI.</p>
<h2 id="in-ci">In CI</h2>
<p>Copy <code>.github/workflows/examples/code-review.yml</code> into your repository. It needs no secret for the security pass, and <code>pull-requests: write</code> is the only privilege it asks for.</p>
<p>A live demo runs at <strong><a href="https://github.com/Mpaape/aurumcode-demo">Mpaape/aurumcode-demo</a></strong>: <a href="https://github.com/Mpaape/aurumcode-demo/pull/1">pull request #1</a> opens with three planted vulnerabilities, the action finds all three with file and line, comments, and fails the check — then goes green on the commit that fixes them.</p>
<h2 id="what-it-does">What it does</h2>
<p><strong>Code review.</strong> Findings carry file, line, severity and the rule that produced them. Secrets are redacted before anything reaches a model. <code>--limite</code> caps what a run may spend, <code>--modelo</code> selects any OpenAI-compatible endpoint including one served locally, and <code>--pr</code> publishes findings as inline comments with a commit status that blocks the merge.</p>
<p><strong>Documentation.</strong> Go, Rust and C# are parsed natively — no external toolchain to install.</p>
<p><strong>Pages.</strong> A copyable workflow builds the site and deploys it.</p>
<h2 id="what-it-does-not-do-yet-stated-plainly">What it does not do yet, stated plainly</h2>
<ul>
<li>Three of the eight security rules carry a matcher today: <code>sql-injection</code>, <code>command-injection</code> and <code>hardcoded-secret</code>. The command announces its own coverage on every run rather than implying it applied all eight.</li>
<li>The review is scoped to the diff. A defect that already existed in the base branch is not reported, which surprises people testing it for the first time.</li>
<li>Configuration lives in flags and environment variables; rules and prompts are embedded and not yet overridable from a file in your repository.</li>
</ul>
<h2 id="verifying-this-release">Verifying this release</h2>
<p><code>v1</code> is the major-version alias example workflows reference; <code>v1.0.1</code> is the immutable tag it currently points at. If your policy requires immutable pins, use the commit SHA <code>v1</code> resolves to.</p>
]]></content:encoded></item><item><title>LinkML (linkml-scala)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/linkml-linkml-scala/</link><pubDate>Fri, 14 Aug 2026 13:50:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/linkml-linkml-scala/</guid><description>Version updated for https://github.com/NeverBlink-OSS/linkml-scala-action to version v0.12.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation and generation of LinkML schemas using Node.js. It provides inline annotations in GitHub checks and supports various schema languages such as JSON Schema, SHACL, RDF, and Scala. The action can validate or generate different outputs based on specified configurations, with options to handle warnings and strict errors.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NeverBlink-OSS/linkml-scala-action">https://github.com/NeverBlink-OSS/linkml-scala-action</a></strong> to version <strong>v0.12.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/linkml-linkml-scala">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation and generation of LinkML schemas using Node.js. It provides inline annotations in GitHub checks and supports various schema languages such as JSON Schema, SHACL, RDF, and Scala. The action can validate or generate different outputs based on specified configurations, with options to handle warnings and strict errors.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Tracks <a href="https://github.com/NeverBlink-OSS/linkml-scala/releases/tag/v0.12.2">linkml-scala v0.12.2</a>.</p>
<p>Bundles <code>@neverblink/linkml@0.12.2</code>.</p>
<ul>
<li>Pin <code>uses: NeverBlink-OSS/linkml-scala-action@v0.12.2</code> for reproducibility.</li>
<li>Pin <code>@v1</code> for automatic patch/minor updates.</li>
</ul>
]]></content:encoded></item><item><title>Open Delivery Spec</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/open-delivery-spec/</link><pubDate>Fri, 14 Aug 2026 13:49:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/open-delivery-spec/</guid><description>Version updated for https://github.com/open-delivery-spec/validate-action to version v0.2.9.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the governance and visibility of AI-assisted code in pull requests by running the full Open Delivery Spec (ODS) pipeline, which includes attribute detection, quality analysis, scoring, and policy enforcement. It helps identify low-quality AI-generated code early and enforces AI policy through OPA Rego rules. The action can be run on pull requests and checks the base commit history for accurate results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/open-delivery-spec/validate-action">https://github.com/open-delivery-spec/validate-action</a></strong> to version <strong>v0.2.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/open-delivery-spec">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the governance and visibility of AI-assisted code in pull requests by running the full Open Delivery Spec (ODS) pipeline, which includes attribute detection, quality analysis, scoring, and policy enforcement. It helps identify low-quality AI-generated code early and enforces AI policy through OPA Rego rules. The action can be run on pull requests and checks the base commit history for accurate results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h2 id="-bug-fixes">🐛 Bug fixes</h2>
<ul>
<li>fix: WARN only when something needs a human by @shenxianpeng in #86</li>
</ul>
<h2 id="-maintenance">👻 Maintenance</h2>
<ul>
<li>chore: keep the PR comment readable on large AI changes by @shenxianpeng in #87</li>
</ul>
<h2 id="-dependencies">📦 Dependencies</h2>
<ul>
<li>chore(deps): bump open-delivery-spec/validate-action from 0.2.7 to 0.2.8 in the github-actions group by @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> in #85</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/open-delivery-spec/validate-action/compare/v0.2.8...v0.2.9">https://github.com/open-delivery-spec/validate-action/compare/v0.2.8...v0.2.9</a></p>
]]></content:encoded></item><item><title>Create Verified Commit and Tag</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/create-verified-commit-and-tag/</link><pubDate>Fri, 14 Aug 2026 13:48:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/create-verified-commit-and-tag/</guid><description>Version updated for https://github.com/oWretch/create-verified-commits to version v1.1.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of verified, signed commits and optional annotated tags using the GitHub GraphQL API. It simplifies file path management, allows committing only changed files, and supports creating commit-if-changed workflows without failing the run. The action is OS-agnostic and works seamlessly across Linux, macOS, and Windows runners.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oWretch/create-verified-commits">https://github.com/oWretch/create-verified-commits</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/create-verified-commit-and-tag">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of verified, signed commits and optional annotated tags using the GitHub GraphQL API. It simplifies file path management, allows committing only changed files, and supports creating commit-if-changed workflows without failing the run. The action is OS-agnostic and works seamlessly across Linux, macOS, and Windows runners.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="110-2026-08-14"><a href="https://github.com/oWretch/create-verified-commits/compare/v1.0.2...v1.1.0">1.1.0</a> (2026-08-14)</h1>
<h3 id="features">Features</h3>
<ul>
<li>adopt TypeScript 7 features and set up TS6/TS7 side-by-side toolchain (<a href="https://github.com/oWretch/create-verified-commits/commit/14a34416ab2f610027b57b22e3c03cb168fcfc4a">14a3441</a>)</li>
</ul>
]]></content:encoded></item><item><title>Web App Security Skill</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/web-app-security-skill/</link><pubDate>Fri, 14 Aug 2026 13:47:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/web-app-security-skill/</guid><description>Version updated for https://github.com/parousia8888/web-app-security-skill to version v0.5.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates web application security by using AI coding agents to analyze, audit, harden, and retest projects. It solves problems related to identifying and addressing vulnerabilities in web applications without requiring an offensive-security background. The action provides reproducible evidence through stable semantic digests for verification, enhancing trust and reliability in security practices.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/parousia8888/web-app-security-skill">https://github.com/parousia8888/web-app-security-skill</a></strong> to version <strong>v0.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/web-app-security-skill">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates web application security by using AI coding agents to analyze, audit, harden, and retest projects. It solves problems related to identifying and addressing vulnerabilities in web applications without requiring an offensive-security background. The action provides reproducible evidence through stable semantic digests for verification, enhancing trust and reliability in security practices.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v051-release-evidence">v0.5.1 release evidence</h1>
<p>Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.</p>
<p>Web App Security Skill v0.5.1 is a compatibility patch over the v0.5.0 source-detection and
understandable-remediation release. It repairs independently reproduced tokenizer and case-study
reproduction defects without expanding the stable rule boundary or changing evidence states.</p>
<h2 id="release-identity">Release identity</h2>
<ul>
<li>Version/tag: <code>v0.5.1</code></li>
<li>Source identity: the commit peeled from the SSH-signed annotated tag; the exact commit is recorded
in <code>web-app-security-skill-0.5.1.release.json</code> and the provenance attestation.</li>
<li>Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.</li>
<li>Stable corpus: 20 built-in risk rules, two evidence-integrity rules and eight opt-in external
adapter rules, unchanged from v0.5.0.</li>
</ul>
<p>This file is part of the source commit it describes and therefore does not embed a fabricated
self-referential source SHA. The signed tag, manifest and provenance establish the published source
identity.</p>
<h2 id="correctness-fixes">Correctness fixes</h2>
<h3 id="jsx-text-boundary">JSX text boundary</h3>
<p>The bounded JS/TS tokenizer now tracks JSX tag, child-text and brace-expression states. Text such as
<code>skills/*.yaml</code> or <code>src/*.tsx</code> no longer opens a JavaScript block comment, while expressions, tag
attributes and nested JSX return to code tokenization. A tokenizer failure still produces partial
coverage and explicit <code>unknown</code> evidence; it is never treated as a clean result.</p>
<h3 id="python-raw-string-boundary">Python raw-string boundary</h3>
<p>The Python tokenizer now consumes backslash-quoted characters in raw as well as non-raw strings for
lexical delimiter handling. The reproduced raw regular expression compiles with CPython and now
completes tokenizer coverage. This remains a bounded tokenizer, not a claim of complete Python
grammar or data-flow analysis.</p>
<h3 id="reproducible-ordinary-project-evidence">Reproducible ordinary-project evidence</h3>
<p>The v0.5.0 five-project evidence retains each original <code>report.json</code> SHA-256 as an archival byte
identity and adds <code>report.semanticDigest</code>. The stable digest covers report schema, ruleset digest,
state summary and sorted finding ID/state pairs. Third parties can run:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>node scripts/check-v050-ordinary-review.mjs <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --report &lt;project-id&gt; /path/to/reproduced/report.json
</span></span></code></pre></div><p>Direct audits intentionally receive a random ephemeral subject, so their full report bytes are not
claimed to match the author&rsquo;s original report. The new comparison preserves subject isolation while
making the reviewed finding semantics reproducible.</p>
<h3 id="local-tls-fixture-isolation">Local TLS fixture isolation</h3>
<p>The HTTPS hardening regression test removes inherited <code>SSL_CERT_FILE</code> before setting its owned
<code>CURL_CA_BUNDLE</code>. The reported enterprise-CA failure was not independently reproduced on the release
host; this change removes an unnecessary host-environment input from the fixture.</p>
<h2 id="compatibility-and-security-boundary">Compatibility and security boundary</h2>
<ul>
<li>Finding/report v3, persisted-subject comparison and v2 migration semantics are unchanged.</li>
<li>Syntax and external scanner matches remain <code>suspected</code> until independent evidence confirms them.</li>
<li>Missing or failed source evidence remains <code>unknown</code>; no parser fix turns unavailable evidence into
a pass.</li>
<li>Passive network defaults, authorization acknowledgements and review-only repair behavior are
unchanged.</li>
<li>This release is not general SAST/DAST coverage, authenticated testing or proof that a project is
secure.</li>
</ul>
<h2 id="release-verification">Release verification</h2>
<p>The release workflow runs <code>npm run check</code>, rebuilds all four release assets twice and compares every
byte, verifies archive structure, checksums, manifest and SPDX SBOM, exercises isolated install and
upgrade, then requests GitHub build provenance before publication.</p>
<p>Verify the signed tag:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>git -c gpg.ssh.allowedSignersFile<span style="color:#f92672">=</span>.github/release-signers verify-tag v0.5.1
</span></span></code></pre></div><p>After publication, verify <code>SHA256SUMS</code>, compare the manifest source commit with
<code>git rev-parse 'v0.5.1^{}'</code>, verify provenance, and only then add the immutable asset digests to the
verified installer. The mutable <code>v1</code> alias moves only after the public consumer workflow passes.</p>
]]></content:encoded></item><item><title>ExploitSpec security regression tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/exploitspec-security-regression-tests/</link><pubDate>Fri, 14 Aug 2026 13:45:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/exploitspec-security-regression-tests/</guid><description>Version updated for https://github.com/pazent/exploitspec to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ExploitSpec is a tool that converts confirmed HTTP exploits into repeatable tests to ensure security vulnerabilities are not reintroduced. It focuses on proven HTTP exploits by running them multiple times to verify they pass without regression. The action provides features like multi-actor support, dynamic workflows, and local execution, making it suitable for maintaining the security of applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pazent/exploitspec">https://github.com/pazent/exploitspec</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/exploitspec-security-regression-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ExploitSpec is a tool that converts confirmed HTTP exploits into repeatable tests to ensure security vulnerabilities are not reintroduced. It focuses on proven HTTP exploits by running them multiple times to verify they pass without regression. The action provides features like multi-actor support, dynamic workflows, and local execution, making it suitable for maintaining the security of applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><img src="https://raw.githubusercontent.com/pazent/exploitspec/v0.1.0/docs/demo.svg" alt="ExploitSpec — RED, GREEN, STABLE"></p>
<p>Turn a proven HTTP exploit into a permanent, deterministic security regression test.</p>
<h2 id="install">Install</h2>
<p><a href="https://github.com/marketplace/actions/exploitspec-security-regression-tests">Install the GitHub Action from Marketplace</a>, download the archive for your platform below and verify it with <code>SHA256SUMS</code>, or install the CLI with Go:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>go install github.com/pazent/exploitspec/cmd/exploitspec@v0.1.0
</span></span></code></pre></div><h2 id="what-ships-in-v010">What ships in v0.1.0</h2>
<ul>
<li>RED → GREEN → STABLE calibration against vulnerable and fixed baselines</li>
<li>isolated multi-actor HTTP sessions, captures, JSONPath, regex, and header assertions</li>
<li>conservative cURL import that redacts secrets without executing the command</li>
<li>safe redirects, response limits, explicit host authorization, and metadata-IP blocking</li>
<li>text, JSON, and JUnit reports with deterministic exit codes</li>
<li>a free composite GitHub Action and versioned JSON Schema</li>
<li>Linux, macOS, and Windows archives for AMD64 and ARM64</li>
</ul>
<p>ExploitSpec is Apache-2.0, local-first, account-free, telemetry-free, and has no paid tier.</p>
<ul>
<li><a href="https://github.com/marketplace/actions/exploitspec-security-regression-tests">GitHub Marketplace</a></li>
<li><a href="https://github.com/pazent/exploitspec-demo">Passing GitHub Actions template</a></li>
<li><a href="https://github.com/pazent/exploitspec/discussions/8">BOLA/IDOR case study</a></li>
<li><a href="https://github.com/pazent/exploitspec#quick-start">Quick start</a></li>
<li><a href="https://github.com/pazent/exploitspec/blob/v0.1.0/docs/specification.md">Specification</a></li>
<li><a href="https://github.com/pazent/exploitspec/blob/v0.1.0/SECURITY.md">Security model</a></li>
<li><a href="https://github.com/pazent/exploitspec/discussions/3">Launch announcement</a></li>
</ul>
<p><strong>Every security bug deserves a regression test.</strong></p>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/raviqqe/muffy/</link><pubDate>Fri, 14 Aug 2026 13:44:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Muffy, automates the validation of static websites by checking links and markup on all pages. It supports concurrent checks with configurable limits and retries, along with persistent caching for efficient performance. The action can be run locally or integrated into workflows using GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Muffy, automates the validation of static websites by checking links and markup on all pages. It supports concurrent checks with configurable limits and retries, along with persistent caching for efficient performance. The action can be run locally or integrated into workflows using GitHub Actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>d74e1ac8cbf5569ab9fe0053f43a93dbb8ced883 Bump version (#1256)</li>
<li>e45bd3b610a70d9e8d2951b3ae11f237c81dbf06 Flip default site config condition (#1255)</li>
<li>714d5acc9e67be27d2d41457efa2f857d7bd328f Ignored fragments (#1254)</li>
</ul>
]]></content:encoded></item><item><title>KeyHog Secret Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/keyhog-secret-scanner/</link><pubDate>Fri, 14 Aug 2026 13:44:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/keyhog-secret-scanner/</guid><description>Version updated for https://github.com/santhreal/keyhog to version v0.5.73-action.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary KeyHog is an open-source secret scanner written in Rust that scans code, Git history, containers, cloud storage, browser assets, collaboration content, and running systems for leaked API keys, tokens, passwords, and credentials. It combines 926 service-specific detectors, decode-through for concealed credentials, context-aware confidence and suppression, live provider verification, and first-class GPU execution through Vyre.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/santhreal/keyhog">https://github.com/santhreal/keyhog</a></strong> to version <strong>v0.5.73-action</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/keyhog-secret-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>KeyHog is an open-source secret scanner written in Rust that scans code, Git history, containers, cloud storage, browser assets, collaboration content, and running systems for leaked API keys, tokens, passwords, and credentials. It combines 926 service-specific detectors, decode-through for concealed credentials, context-aware confidence and suppression, live provider verification, and first-class GPU execution through Vyre.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>release: v0.5.73 (3c684da)</li>
<li>fix(release): preflight registry dependencies (f8cf345)</li>
<li>release: v0.5.72 (2b15d7a)</li>
<li>release: publish the tag the bump job creates (54462f7)</li>
<li>release: v0.5.71 (1ed0797)</li>
<li>fix(release): consume legacy unreleased notes (d2aa413)</li>
<li>fix(scanner): prevent huge-page pack retention (ba5e615)</li>
<li>ci(action): preserve push runs across schedules (5a6da00)</li>
<li>ci(scanner): isolate RSS-sensitive mapping test (2ff07b3)</li>
<li>test(cli): move enum diagnostics out of src (fda5c09)</li>
</ul>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/custom-amazon-bedrock-agent-action/</link><pubDate>Fri, 14 Aug 2026 13:43:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide feedback. It is highly customizable and integrates with Amazon Bedrock Knowledge Bases for more accurate context-aware insights. The key features include file processing, prompt generation, analysis using an integrated knowledge base, and integration with the GitHub workflow for comment posting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide feedback. It is highly customizable and integrates with Amazon Bedrock Knowledge Bases for more accurate context-aware insights. The key features include file processing, prompt generation, analysis using an integrated knowledge base, and integration with the GitHub workflow for comment posting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/classroom-to-sheets-integration/</link><pubDate>Fri, 14 Aug 2026 13:42:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending assignment results from Google Classroom to a Google Sheets document. It enables educators to receive real-time feedback on student submissions directly within their spreadsheets, streamlining the grading workflow. The integration requires configuring Google Cloud API credentials and setting up secrets in the organization, then adding a specific step to your GitHub Actions workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending assignment results from Google Classroom to a Google Sheets document. It enables educators to receive real-time feedback on student submissions directly within their spreadsheets, streamlining the grading workflow. The integration requires configuring Google Cloud API credentials and setting up secrets in the organization, then adding a specific step to your GitHub Actions workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/runward-gate/</link><pubDate>Fri, 14 Aug 2026 13:41:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.34.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward automates the verification of engineering decisions behind AI-generated code. It ensures that every critical architectural decision is written down and checked deterministically, preventing potential errors in production. The action helps teams to ensure that they have a clear chain of evidence for their software systems.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.34.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Runward automates the verification of engineering decisions behind AI-generated code. It ensures that every critical architectural decision is written down and checked deterministically, preventing potential errors in production. The action helps teams to ensure that they have a clear chain of evidence for their software systems.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Three decisions from the 2026-08-12 product review land: the construction gate becomes usable in CI, and the gate is made as strong as its headline. This release deliberately reddens some previously green missions — the migration note below names exactly which, and the one-line fix for each.</strong></p>
<h3 id="runward-check---through-phase-id--the-construction-gate-adr-0053"><code>runward check --through &lt;phase-id&gt;</code> — the construction gate (<a href="docs/adr/ADR-0053-the-construction-gate-certifies-a-declared-horizon.md">ADR-0053</a>)</h3>
<p>A required <code>check --strict</code> exits 1 for the whole build, because later-phase deliverables are unfilled by definition — so it was unusable in CI during construction, and teams hacked a partial-green with <code>jq</code> or <code>|| true</code>. <code>--through &lt;phase-id&gt;</code> certifies a declared PREFIX: every phase up to and including <code>&lt;phase-id&gt;</code> is crossed on evidence, nothing past it. It narrows only the phase counters; the 0/1/2 exit contract, the seal and the six phases are untouched, and the phase-global integrity checks (corpus, seal, unratified ADRs, drift) are NOT scoped, so a regression at or below the horizon still reds — the horizon is a floor, not a ceiling. It refuses <code>--freeze</code> (a seal certifies a full crossing) and an unknown id, both exit 2; it prints a loud &ldquo;not a completion verdict&rdquo; banner and carries additive JSON (<code>through</code>, <code>horizon</code>, <code>gaps.deferred</code>). The wiring contract is in the ADR: the release / merge-to-main gate stays the full <code>check --strict</code>; <code>--through</code> is a construction progress signal, never the sole required release check.</p>
<h3 id="the-gate-is-made-as-strong-as-its-headline-adr-0051">The gate is made as strong as its headline (<a href="docs/adr/ADR-0051-the-gate-is-made-as-strong-as-its-headline.md">ADR-0051</a>)</h3>
<ul>
<li><strong>Symbols match at an identifier boundary.</strong> <code>#guardFields</code> no longer matches a file that contains only <code>guardFieldsLegacy</code>. A renamed identifier — the exact &ldquo;moved or renamed&rdquo; case the violation message names — now reds instead of silently passing, and a seal can no longer sit on a pointer whose identifier no longer exists. Non-identifier symbols (dotted, quoted) keep their exact-substring semantics.</li>
<li><strong>Five more rules carry an evidence signature</strong> (6 of 64, up from 1): <code>resilience-retry-backoff</code>, <code>resilience-multi-provider-fallback</code>, <code>security-mcp-server-pinning</code>, <code>security-code-execution-sandbox</code>, <code>security-tool-change-reapproval</code> — each a conventional idiom the rule text prescribes, each with a <code>nonScope</code> stating what a match does NOT prove. Rules whose idiom is illustrative rather than a code token stay unsigned, and the refusals are named in the commit.</li>
<li><strong>The run names the signed share of the verdict</strong>: &ldquo;N of M <code>applied</code> row(s) rest on a signed rule&rdquo;. Counted, never gated; additive JSON (<code>evidence.signed</code>).</li>
</ul>
<h3 id="overclaim-rules-externalized-adr-0050-decision-2-structural-part">Overclaim rules externalized (<a href="docs/adr/ADR-0050-the-public-claim-is-narrowed-to-the-provable-form.md">ADR-0050</a> decision 2, structural part)</h3>
<p>The forbidden-claim list moves out of the CLI test into <code>src/lib/claims-rules.ts</code>, shipped with the package, so a site-build guard can consume the same list from the pinned dependency — one source, no drift. No behaviour change; the guard&rsquo;s three meta-guards are intact. ADR-0050 stays proposed (its site-copy decisions need the site repo).</p>
<h3 id="migration--this-release-reddens-some-green-missions-on-purpose">Migration — this release reddens some green missions on purpose</h3>
<p>After <code>runward update</code> refreshes a mission&rsquo;s rule corpus (or on the next <code>check --strict</code> for a mission that judges against the package corpus), two populations turn red. Both are the mechanism working, and each has a one-line fix:</p>
<ol>
<li><strong>A pointer symbol that was a fragment of the real identifier.</strong> If an <code>applied</code> row&rsquo;s <code>#SYMBOL</code> passed only because it is a substring of a larger identifier (e.g. <code>#guardFields</code> over <code>guardFieldsLegacy</code>), it now reads &ldquo;symbol not found&rdquo;. <strong>Fix:</strong> point at the real identifier, or drop the <code>#SYMBOL</code> to keep the bare path.</li>
<li><strong>A prose <code>applied</code> row on one of the five newly-signed rules.</strong> A signature makes file-backed evidence mandatory for <code>applied</code> rows, so an <code>applied</code> row that carried only prose (no <code>file:</code>/<code>test:</code> pointer whose content matches the idiom) now reds with &ldquo;cited, not applied&rdquo;. <strong>Fix:</strong> point the row at evidence that carries the rule&rsquo;s shape, or answer <code>n/a</code> / <code>deviated</code> with a reason — a rule the mission does not implement was never meant to be <code>applied</code>.</li>
</ol>
<p>The two reference missions (runward&rsquo;s own, and the shipped <code>request-triage</code> example) are strict-green under this release; every change was validated in both directions on each.</p>
]]></content:encoded></item><item><title>SFDX Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/sfdx-code-review/</link><pubDate>Fri, 14 Aug 2026 13:40:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/sfdx-code-review/</guid><description>Version updated for https://github.com/svierk/sfdx-code-review to version v1.0.1.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the static code review process for Salesforce projects, bundling several checks into a single quality gate to ensure compliance and adhere to best practices. It includes static analysis using the Salesforce Code Analyzer, code formatting with Prettier, and linting with ESLint, producing SonarQube-compatible reports. The action allows customization of which checks are performed and can apply project-specific ESLint configurations if desired.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svierk/sfdx-code-review">https://github.com/svierk/sfdx-code-review</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdx-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the static code review process for Salesforce projects, bundling several checks into a single quality gate to ensure compliance and adhere to best practices. It includes static analysis using the Salesforce Code Analyzer, code formatting with Prettier, and linting with ESLint, producing SonarQube-compatible reports. The action allows customization of which checks are performed and can apply project-specific ESLint configurations if desired.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>pin action versions and harden workflow examples</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svierk/sfdx-code-review/compare/v1.0.0...v1.0.1">https://github.com/svierk/sfdx-code-review/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>SFDX Delete Scratch Org</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/sfdx-delete-scratch-org/</link><pubDate>Fri, 14 Aug 2026 13:39:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/sfdx-delete-scratch-org/</guid><description>Version updated for https://github.com/svierk/sfdx-delete-scratch-org to version v1.1.3.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub action automates the deletion of Salesforce scratch orgs after a CI run, ensuring that resources are released even if previous steps fail. It works in conjunction with the sfdx-create-scratch-org action and uses tokens for authentication, following best practices for maintaining security and clarity in workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svierk/sfdx-delete-scratch-org">https://github.com/svierk/sfdx-delete-scratch-org</a></strong> to version <strong>v1.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdx-delete-scratch-org">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub action automates the deletion of Salesforce scratch orgs after a CI run, ensuring that resources are released even if previous steps fail. It works in conjunction with the <code>sfdx-create-scratch-org</code> action and uses tokens for authentication, following best practices for maintaining security and clarity in workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>pin action versions and harden workflow example</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svierk/sfdx-delete-scratch-org/compare/v1.1.2...v1.1.3">https://github.com/svierk/sfdx-delete-scratch-org/compare/v1.1.2...v1.1.3</a></p>
]]></content:encoded></item><item><title>SunsetPR AI Model Lifecycle Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/sunsetpr-ai-model-lifecycle-check/</link><pubDate>Fri, 14 Aug 2026 13:37:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/sunsetpr-ai-model-lifecycle-check/</guid><description>Version updated for https://github.com/synergia-yoshi/sunsetpr-action to version v0.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SunsetPR is a GitHub Action designed to detect deprecated AI models and API endpoints before their shutdown dates. It provides detailed reports including file and line numbers, shutdown dates, official replacements or migration paths, confidence levels, and provider documentation. The action supports TypeScript, JavaScript, and Python languages and can identify hardcoded model IDs in major SDK call shapes, single-use const model IDs passed to supported calls, model IDs assigned to model-named variables, and various configuration files. It reports findings but does not automatically create or merge PRs; reviewers are required to manually confirm the corrections.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/synergia-yoshi/sunsetpr-action">https://github.com/synergia-yoshi/sunsetpr-action</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sunsetpr-ai-model-lifecycle-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SunsetPR is a GitHub Action designed to detect deprecated AI models and API endpoints before their shutdown dates. It provides detailed reports including file and line numbers, shutdown dates, official replacements or migration paths, confidence levels, and provider documentation. The action supports TypeScript, JavaScript, and Python languages and can identify hardcoded model IDs in major SDK call shapes, single-use <code>const</code> model IDs passed to supported calls, model IDs assigned to model-named variables, and various configuration files. It reports findings but does not automatically create or merge PRs; reviewers are required to manually confirm the corrections.</p>
<p>This tool helps developers stay informed about upcoming changes in AI models and can assist with migration planning and verification of code changes before potential disruptions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="日本語">日本語</h2>
<p>Cohere と xAI の公式ライフサイクル情報を追加しました。通知だけで終わらせず、影響箇所と公式根拠を報告し、修正は確認待ちPRとして扱います。</p>
<ul>
<li>124モデルID・4 API surface</li>
<li>Cohere/xAI は公式情報に限定し、互換性差分は report-only</li>
<li>日本語の導入・安全性説明を追加</li>
</ul>
<p>詳細はREADMEとMODEL-LIFECYCLE.mdを参照してください。</p>
<h2 id="english">English</h2>
<p>Adds first-party lifecycle coverage for Cohere and xAI, with conservative report-only replacements and Japanese onboarding documentation.</p>
]]></content:encoded></item><item><title>Delete GitHub Workflow Runs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/delete-github-workflow-runs/</link><pubDate>Fri, 14 Aug 2026 13:36:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/delete-github-workflow-runs/</guid><description>Version updated for https://github.com/tagdots/delete-workflow-runs to version 1.2.34.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary delete-workflow-runs is a GitHub Action that deletes workflow runs from a specified repository. It reduces supply chain risks by ensuring actions follow best practices and provides evidence of code coverage results in action. The tool can also identify orphan workflow runs to delete, reduce API rate limit consumption, and run using both the command line and GitHub Actions Marketplace.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tagdots/delete-workflow-runs">https://github.com/tagdots/delete-workflow-runs</a></strong> to version <strong>1.2.34</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delete-github-workflow-runs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>delete-workflow-runs</strong> is a GitHub Action that deletes workflow runs from a specified repository. It reduces supply chain risks by ensuring actions follow best practices and provides evidence of code coverage results in action. The tool can also identify orphan workflow runs to delete, reduce API rate limit consumption, and run using both the command line and GitHub Actions Marketplace.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at 1.2.34 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="-fixes">🐛 Fixes</h3>
<ul>
<li>fix: specify python version in action by @andreclc in <a href="https://github.com/tagdots/delete-workflow-runs/pull/138">https://github.com/tagdots/delete-workflow-runs/pull/138</a></li>
</ul>
<h3 id="-maintenance">🛠️ Maintenance</h3>
<ul>
<li>[GITHUB-ACTIONS] bump the github-actions group with 6 updates by @dependabot[bot] in <a href="https://github.com/tagdots/delete-workflow-runs/pull/73">https://github.com/tagdots/delete-workflow-runs/pull/73</a></li>
<li>[PIP] bump click from 8.3.0 to 8.3.1 in the pip group by @dependabot[bot] in <a href="https://github.com/tagdots/delete-workflow-runs/pull/76">https://github.com/tagdots/delete-workflow-runs/pull/76</a></li>
<li>[GITHUB-ACTIONS] bump the github-actions group with 2 updates by @dependabot[bot] in <a href="https://github.com/tagdots/delete-workflow-runs/pull/75">https://github.com/tagdots/delete-workflow-runs/pull/75</a></li>
<li>[GITHUB-ACTIONS] bump the github-actions group with 5 updates by @dependabot[bot] in <a href="https://github.com/tagdots/delete-workflow-runs/pull/78">https://github.com/tagdots/delete-workflow-runs/pull/78</a></li>
<li>[GITHUB-ACTIONS] bump the github-actions group with 2 updates by @dependabot[bot] in <a href="https://github.com/tagdots/delete-workflow-runs/pull/79">https://github.com/tagdots/delete-workflow-runs/pull/79</a></li>
<li>[GITHUB-ACTIONS] bump the github-actions group with 4 updates by @dependabot[bot] in <a href="https://github.com/tagdots/delete-workflow-runs/pull/84">https://github.com/tagdots/delete-workflow-runs/pull/84</a></li>
<li>[GITHUB-ACTIONS] bump bridgecrewio/checkov-action from 12.3075.0 to 12.3077.0 in the github-actions group by @dependabot[bot] in <a href="https://github.com/tagdots/delete-workflow-runs/pull/86">https://github.com/tagdots/delete-workflow-runs/pull/86</a></li>
<li>fix: update pre-commit-config and pyproject.toml accordingly by @andreclc in <a href="https://github.com/tagdots/delete-workflow-runs/pull/123">https://github.com/tagdots/delete-workflow-runs/pull/123</a></li>
<li>[GITHUB-ACTIONS] bump the github-actions group with 15 updates by @dependabot[bot] in <a href="https://github.com/tagdots/delete-workflow-runs/pull/124">https://github.com/tagdots/delete-workflow-runs/pull/124</a></li>
<li>[PIP] bump pandas from 3.0.3 to 3.0.5 in the pip group by @dependabot[bot] in <a href="https://github.com/tagdots/delete-workflow-runs/pull/128">https://github.com/tagdots/delete-workflow-runs/pull/128</a></li>
</ul>
<h3 id="-others">👒 Others</h3>
<ul>
<li>docs: update how to examples on readme by @andreclc in <a href="https://github.com/tagdots/delete-workflow-runs/pull/72">https://github.com/tagdots/delete-workflow-runs/pull/72</a></li>
<li>build: remove unused deps and break down deps group by @andreclc in <a href="https://github.com/tagdots/delete-workflow-runs/pull/81">https://github.com/tagdots/delete-workflow-runs/pull/81</a></li>
<li>build: revert action checkout that caused duplicate authorization hea… by @andreclc in <a href="https://github.com/tagdots/delete-workflow-runs/pull/82">https://github.com/tagdots/delete-workflow-runs/pull/82</a></li>
<li>build: fix duplicate header by breaking the a multi-step job into 2 jobs by @andreclc in <a href="https://github.com/tagdots/delete-workflow-runs/pull/83">https://github.com/tagdots/delete-workflow-runs/pull/83</a></li>
<li>Build/migrate from pip to uv by @andreclc in <a href="https://github.com/tagdots/delete-workflow-runs/pull/134">https://github.com/tagdots/delete-workflow-runs/pull/134</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tagdots/delete-workflow-runs/compare/1.2.33...1.2.34">https://github.com/tagdots/delete-workflow-runs/compare/1.2.33...1.2.34</a></p>
]]></content:encoded></item><item><title>GitHub Settings as Code</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/github-settings-as-code/</link><pubDate>Fri, 14 Aug 2026 13:35:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/github-settings-as-code/</guid><description>Version updated for https://github.com/Vivswan/github-settings-as-code to version v2.0.0.
This action is used across all versions by 15 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the application of declarative repository settings from a .github/settings.yml file, replacing the Probot Settings app. It manages branch protections, rulesets, and other configurations in a stateless manner, providing detailed error messages upon failure. The action is triggered on pushes to .github/settings.yml or manual workflows dispatches, ensuring that every change is visible and auditable through workflow runs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Vivswan/github-settings-as-code">https://github.com/Vivswan/github-settings-as-code</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>15</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-settings-as-code">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the application of declarative repository settings from a <code>.github/settings.yml</code> file, replacing the Probot Settings app. It manages branch protections, rulesets, and other configurations in a stateless manner, providing detailed error messages upon failure. The action is triggered on pushes to <code>.github/settings.yml</code> or manual workflows dispatches, ensuring that every change is visible and auditable through workflow runs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="200-2026-08-11"><a href="https://github.com/Vivswan/github-settings-as-code/compare/v1.0.1...v2.0.0">2.0.0</a> (2026-08-11)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li>the action moved to Vivswan/github-settings-as-code; uses: references to Vivswan/repo-settings-as-code fail with &ldquo;repository not found&rdquo; and must be updated.</li>
<li>branches[].protection.required_signatures now acts. Previously the key rode the protection PUT, where GitHub dropped it (check mode showed permanent drift). A settings file already carrying it will start toggling the signed-commit requirement on the first apply after upgrading - a stale required_signatures: false would REMOVE a hand-enabled requirement. Audit existing declarations for intent before moving to v2. The v1 line keeps the old inert behavior.</li>
<li>actions.fork_pr_contributor_approval and actions.fork_pr_workflows_private_repos now act. Previously both keys fell through to the base permissions PUT, where GitHub ignored them and a notice said so. A settings file already carrying either key will start applying these policies on the first apply after upgrading; audit existing declarations for intent before moving to v2. The v1 line keeps the old inert behavior.</li>
<li>actions.oidc_customization_sub now acts. Previously the key fell through to the base permissions PUT, where GitHub ignored it and a notice said so. A settings file already carrying the key will start customizing the OIDC subject claim template on the first apply after upgrading; audit existing declarations for intent before moving to v2. The v1 line keeps the old inert behavior.</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li>add issue-on-failure private-report channel (quiet on healthy runs) (<a href="https://github.com/Vivswan/github-settings-as-code/commit/934a321d64d49470ced76b484f6f714fc2a2bbe4">934a321</a>)</li>
<li>enrich API rejection errors and reject unknown keys in closed sections (<a href="https://github.com/Vivswan/github-settings-as-code/commit/7a44e90bc15016d7926b812000f22043d1f3058f">7a44e90</a>)</li>
<li>first-class GraphQL operation layer (<a href="https://github.com/Vivswan/github-settings-as-code/commit/7d5279fcdae87c0985c9a6ecb637c89dcd38e2f7">7d5279f</a>)</li>
<li>let settings.yml choose the undeclared-resource policy per section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/372b8844f1274cdfac71d04b5c526d6d6714da8f">372b884</a>)</li>
<li>manage Actions artifact/log retention and cache limits (<a href="https://github.com/Vivswan/github-settings-as-code/commit/8014910b884aece9cc71f974cef26db4656da74f">8014910</a>)</li>
<li>manage code quality setup and check suite preferences (<a href="https://github.com/Vivswan/github-settings-as-code/commit/adab49e76316dfab7122b30c114d7bde1f69b1ba">adab49e</a>)</li>
<li>manage Copilot agents secrets and variables (<a href="https://github.com/Vivswan/github-settings-as-code/commit/1d839e1797f622da2cb01331a8ec395cd56dcf0b">1d839e1</a>)</li>
<li>manage deploy keys (<a href="https://github.com/Vivswan/github-settings-as-code/commit/a6f7ae1251177cd07c1ce6d0acc3176e3986f9b0">a6f7ae1</a>)</li>
<li>manage environment custom deployment protection rules (<a href="https://github.com/Vivswan/github-settings-as-code/commit/f752ce8626e98689902e4f83463816fe25636139">f752ce8</a>)</li>
<li>manage environment deployment branch-policy patterns (<a href="https://github.com/Vivswan/github-settings-as-code/commit/34eafe4e46dd12f6b17dfdf4987b7898270d1718">34eafe4</a>)</li>
<li>manage environment variables in the environments section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/1d272c355ed1b933080d1234b3925625ec1e1edb">1d272c3</a>)</li>
<li>manage environment, Dependabot, and Codespaces secrets (<a href="https://github.com/Vivswan/github-settings-as-code/commit/c8bbe75a91fadbfe241e152ab3fdcf3d52120309">c8bbe75</a>)</li>
<li>manage fork pull request workflow policies from the actions section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/cd2bfcfb332cd789cb4d8d55a7ca40daefcdfec8">cd2bfcf</a>)</li>
<li>manage Git LFS enablement from the repository section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/a0195faf6bc2a8df6e68437a38c35c6d419020bc">a0195fa</a>)</li>
<li>manage immutable releases from the repository section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/f2582f7b8d66d5d7db79fad6b2b0f70788baa590">f2582f7</a>)</li>
<li>manage pinned environments (<a href="https://github.com/Vivswan/github-settings-as-code/commit/c368c98a52ee5d0a35028e2501423316b5c65023">c368c98</a>)</li>
<li>manage repository Actions secrets (<a href="https://github.com/Vivswan/github-settings-as-code/commit/0f8ea4e0ba0ffc23802bfd608fc979b40045eaf2">0f8ea4e</a>)</li>
<li>manage repository Actions variables (<a href="https://github.com/Vivswan/github-settings-as-code/commit/780abf0ec19c50279cc2454606492101bfbdebf7">780abf0</a>)</li>
<li>manage repository custom property values (<a href="https://github.com/Vivswan/github-settings-as-code/commit/b5bf3ac547b0ad84ae19427cf2da06b35b3911fb">b5bf3ac</a>)</li>
<li>manage repository interaction limits (<a href="https://github.com/Vivswan/github-settings-as-code/commit/c8dd58d04de93da9f76168f985654e5d54646065">c8dd58d</a>)</li>
<li>manage repository secret scanning custom patterns (<a href="https://github.com/Vivswan/github-settings-as-code/commit/05f614c0a894e2a9599e81f03c7de593164ad9eb">05f614c</a>)</li>
<li>manage repository webhooks (<a href="https://github.com/Vivswan/github-settings-as-code/commit/85013d3d6437bd78357dd37547c1426c80fb449b">85013d3</a>)</li>
<li>manage required commit signatures in the branches section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/16bec9a328879af3a522e67fb80c86e50c4e6460">16bec9a</a>)</li>
<li>manage the Actions OIDC subject claim from the actions section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/c4e712fd4b929ba6553f2e54c3f1b53b6fd7971b">c4e712f</a>)</li>
<li>manage the pull request creation cap and bypass list (<a href="https://github.com/Vivswan/github-settings-as-code/commit/e98fb3ad58b2f8b78d759480cf096a483678a741">e98fb3a</a>)</li>
<li>manage the sponsor button and issue creation policy (<a href="https://github.com/Vivswan/github-settings-as-code/commit/97111fb2fa66779f099e6daf3c0ac5c5b44b189f">97111fb</a>)</li>
<li>manage wildcard branch protection, force-push bypassers, and required deployments (<a href="https://github.com/Vivswan/github-settings-as-code/commit/085ac52683eaacbda1d974cf19f5a6e38f774b71">085ac52</a>)</li>
<li>move repo-owned CI and release logic to template extension points (<a href="https://github.com/Vivswan/github-settings-as-code/issues/12">#12</a>) (<a href="https://github.com/Vivswan/github-settings-as-code/commit/cdde9ccbf867af6d257ce26f5eac8180930b4ca9">cdde9cc</a>)</li>
<li>reconcile pending collaborator invitations (<a href="https://github.com/Vivswan/github-settings-as-code/commit/cb9218874d6a6956cb1a575ce64418ad8614c199">cb92188</a>)</li>
<li>rename to github-settings-as-code (<a href="https://github.com/Vivswan/github-settings-as-code/commit/9678ceef5375ce7a30f70107ef441a496cf8653b">9678cee</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>ci:</strong> cover src/report in the changed-sections selector and openapi cache key (<a href="https://github.com/Vivswan/github-settings-as-code/commit/a1c43023ab54ea3dca16dd61a2034d2b003756fd">a1c4302</a>)</li>
<li>declare dependabot default labels and realign SECURITY.md (<a href="https://github.com/Vivswan/github-settings-as-code/commit/aa89a230e6dbe0f823dc7998c21edbed0b167972">aa89a23</a>)</li>
<li>drop connections for real in the e2e mock, on bun 1.3.14 (<a href="https://github.com/Vivswan/github-settings-as-code/commit/791c4bfe668f02b1d72bdb8677f14fd390678ea5">791c4bf</a>)</li>
<li><strong>e2e:</strong> keep body-presence checks active for requestOffSpec rejections (<a href="https://github.com/Vivswan/github-settings-as-code/commit/43426a6cca49370f6200acef20dbe368af190106">43426a6</a>)</li>
<li>mark the secrets-and-vaults action pins for major-tag rewrites (<a href="https://github.com/Vivswan/github-settings-as-code/commit/9d1f616eaf368f959b1761945619ca1926ecc659">9d1f616</a>)</li>
<li>name every offender in errors and carry engine invariants in types (<a href="https://github.com/Vivswan/github-settings-as-code/commit/49b386a1313173fdcf376c7698852f497a355626">49b386a</a>)</li>
<li>preserve a rotated deploy key&rsquo;s live read_only flag (<a href="https://github.com/Vivswan/github-settings-as-code/commit/a36da82b4c2ca0a91549b40ca8a4a1e522b16bc4">a36da82</a>)</li>
<li>re-enable declared protection rules the API reports as disabled (<a href="https://github.com/Vivswan/github-settings-as-code/commit/b469a6fde4c32b20fe4abf4b895a0d4f525d39d6">b469a6f</a>)</li>
<li>reject invalid actions and repository declarations before any section writes (<a href="https://github.com/Vivswan/github-settings-as-code/commit/85be8efd6355326f3814616580d8ff6586e7cbe7">85be8ef</a>)</li>
<li>silence and label intentional error noise in green runs (<a href="https://github.com/Vivswan/github-settings-as-code/commit/a786ae682fc791c0be8fc1bc94881265d28c30ed">a786ae6</a>)</li>
<li>track secret-reference provenance structurally through the merge (<a href="https://github.com/Vivswan/github-settings-as-code/commit/e9c223e2f828aee777270939948093e3467618c9">e9c223e</a>)</li>
<li>unpad flow-mapping braces in the pins cap scenario (<a href="https://github.com/Vivswan/github-settings-as-code/commit/7b041fd13a4da8466f5b9c622993a04a7fc3ff73">7b041fd</a>)</li>
<li>write version-less secret scanning patterns the way the API allows (<a href="https://github.com/Vivswan/github-settings-as-code/commit/6fa0cefed39867bcd44d615da5e5bf0c22b237c1">6fa0cef</a>)</li>
</ul>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/b.ia-accessibility-checker/</link><pubDate>Fri, 14 Aug 2026 13:34:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility testing in CI/CD pipelines. It allows companies to define an audience and percentage of WCAG guidelines met, ensuring their products are accessible. This tool provides flexibility by focusing on the most impactful audiences, helping companies avoid costly external solutions. The action uses AI to analyze guidelines and helps developers improve code quality through feedback reports.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility testing in CI/CD pipelines. It allows companies to define an audience and percentage of WCAG guidelines met, ensuring their products are accessible. This tool provides flexibility by focusing on the most impactful audiences, helping companies avoid costly external solutions. The action uses AI to analyze guidelines and helps developers improve code quality through feedback reports.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>move-test-gen coverage check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/move-test-gen-coverage-check/</link><pubDate>Fri, 14 Aug 2026 06:23:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/move-test-gen-coverage-check/</guid><description>Version updated for https://github.com/mehvetero/move-test-gen to version v1.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The move-test-gen GitHub Action generates edge-case test suites for Sui Move functions by analyzing a module and creating [test] and [expected_failure] functions covering various scenarios such as boundary values, arithmetic edges, access control issues, state machine problems, economic considerations, and fee evasion. It outputs the generated tests in a .move file that can be used with sui move test. The action is useful for automating the generation of comprehensive test cases to ensure robustness and reliability of Move contracts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mehvetero/move-test-gen">https://github.com/mehvetero/move-test-gen</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-test-gen-coverage-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>move-test-gen</code> GitHub Action generates edge-case test suites for Sui Move functions by analyzing a module and creating <code>[test]</code> and <code>[expected_failure]</code> functions covering various scenarios such as boundary values, arithmetic edges, access control issues, state machine problems, economic considerations, and fee evasion. It outputs the generated tests in a <code>.move</code> file that can be used with <code>sui move test</code>. The action is useful for automating the generation of comprehensive test cases to ensure robustness and reliability of Move contracts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v150--community-security-audit">v1.5.0 — Community Security Audit</h2>
<p>Major release driven by a full security audit from <a href="https://github.com/HetCreep">@HetCreep</a>. 23 pull requests merged, 3 security advisories patched, and the project&rsquo;s first external contributor.</p>
<h3 id="security-fixes">Security fixes</h3>
<ul>
<li><strong>GHSA-6r4g</strong> (Moderate): block comment containing <code>#[test_only]</code> above module skipped all 6 lint rules</li>
<li><strong>GHSA-w7pc</strong> (Moderate): zero parsed asserts printed &ldquo;100% coverage&rdquo; and exited 0</li>
<li><strong>GHSA-5499</strong> (Moderate): same-line <code>#[test_only] use ...</code> leaked exemption onto the next function</li>
</ul>
<h3 id="new-features">New features</h3>
<ul>
<li><code>--fail-on &lt;severity&gt;</code> — configurable gate threshold (default: high)</li>
<li><code>--json</code> machine-readable output with versioned schema</li>
<li><code>// move-test-gen-disable-next-line MOV-003</code> suppression pragmas + <code>--disable</code> flag</li>
<li>Exit codes: 0 clean / 1 findings / 2 usage error / 3 tool error</li>
<li>Action outputs + job summary for downstream CI jobs</li>
<li><code>public(package)</code> visibility (Move 2024) support</li>
</ul>
<h3 id="reliability">Reliability</h3>
<ul>
<li>Mutation timeout is its own outcome, not a false kill</li>
<li>Missing test count is an error, not a silent pass</li>
<li><code>--scope</code> with no match is an error, not a green gate</li>
<li>Temp-dir cleanup registered before recursive copy</li>
<li>13 gate-selftest cases, all green</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>SECURITY.md, CHANGELOG.md, RELEASE.md added</li>
<li>README overhauled: exit codes, untrusted-code warning, hardened consumer examples</li>
</ul>
<h3 id="contributors">Contributors</h3>
<p>Security audit and 23 pull requests by <a href="https://github.com/HetCreep">@HetCreep</a> — zero false positives across the entire audit.</p>
]]></content:encoded></item><item><title>Healify — Check broken selectors</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/healify-check-broken-selectors/</link><pubDate>Fri, 14 Aug 2026 06:22:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/healify-check-broken-selectors/</guid><description>Version updated for https://github.com/mescobar996/Healify to version v2.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Healify is a tool that automatically identifies and suggests stable selector replacements for broken E2E tests. It helps developers maintain stable, reliable selectors by analyzing test evidence captured during previous runs. The action automates the process of identifying broken selectors, suggesting fixes, and updating tests without modifying them directly. It provides insights into the effectiveness of its suggestions through a local dashboard and supports integration with various testing frameworks including Playwright, Cypress, Selenium, and WebdriverIO.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mescobar996/Healify">https://github.com/mescobar996/Healify</a></strong> to version <strong>v2.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/healify-check-broken-selectors">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Healify is a tool that automatically identifies and suggests stable selector replacements for broken E2E tests. It helps developers maintain stable, reliable selectors by analyzing test evidence captured during previous runs. The action automates the process of identifying broken selectors, suggesting fixes, and updating tests without modifying them directly. It provides insights into the effectiveness of its suggestions through a local dashboard and supports integration with various testing frameworks including Playwright, Cypress, Selenium, and WebdriverIO.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="changelog">Changelog</h1>
<h2 id="280--2026-08-13">2.8.0 — 2026-08-13</h2>
<h3 id="onboarding-healify-init-en-2-minutos-diseño-en-docsonboarding-designmd">Onboarding: <code>healify init</code> en 2 minutos (diseño en docs/onboarding-design.md)</h3>
<ul>
<li><strong>Output rediseñado por pasos</strong>: <code>init</code> ahora narra el flujo completo — 1/4 detección
(con la evidencia: &ldquo;Playwright — @playwright/test · playwright.config.ts&rdquo;), 2/4
instalación, 3/4 configuración, 4/4 scripts — y cierra con un único siguiente paso
accionable (<code>npm run healify</code> → <code>npm run healify:dashboard</code>).</li>
<li><strong>Verificación instantánea</strong>: al terminar, <code>init</code> corre <code>healify doctor</code> y muestra el
estado real del proyecto — nada de &ldquo;debería andar&rdquo;, se ve lo que hay.</li>
<li><strong>Scripts de conveniencia en package.json</strong> (idempotentes, sin pisar los existentes):
<code>healify</code> (<code>healify fix</code>), <code>healify:dry</code> (<code>healify fix --dry-run</code>),
<code>healify:dashboard</code> (<code>healify dashboard --serve</code>).</li>
<li><strong><code>healify init --dry-run</code></strong>: muestra el plan completo (instalar/configurar/scripts)
sin tocar nada — para CI y para no asustar.</li>
<li><strong>Detección con evidencia</strong>: <code>detectFramework</code> ahora reporta POR QUÉ detectó cada
framework (dependencia + archivo de config), y el output lo muestra.</li>
<li>Se mantiene la regla de oro: init <strong>no genera tests</strong> — el cierre lo dice explícitamente
(&ldquo;Corré tus tests (los tuyos — Healify no te genera tests)&rdquo;).</li>
</ul>
<h2 id="271--2026-08-13">2.7.1 — 2026-08-13</h2>
<h3 id="dashboard-de-eficacia--eficacia">Dashboard de eficacia (🎯 Eficacia)</h3>
<ul>
<li><strong>Nueva sección &ldquo;Eficacia&rdquo;</strong> en el dashboard (<code>/efficacy</code>) con datos reales de
<code>.healify/history.jsonl</code>:
<ul>
<li>Donut de aceptados vs rechazados vs sin confirmar + tasa global.</li>
<li>Tasa de eficacia por framework (Playwright, Cypress, Selenium, WebdriverIO); las
entradas históricas sin framework se agrupan en &ldquo;unknown&rdquo; sin romper el total.</li>
<li>Tendencia de aceptados/rechazados en ventanas de <strong>7 y 30 días</strong> (toggle en la UI;
agregación server-side vía <code>?efficacy-window=7|30</code>).</li>
<li>Desglose por causa de fallo (&ldquo;Selector roto&rdquo;, &ldquo;Aserción&rdquo;, &ldquo;Timing / espera&rdquo;, …).</li>
</ul>
</li>
<li><strong><code>HistoryEntry.framework</code></strong> — cada entrada nueva del historial registra el framework de la
corrida (campo opcional, back-compat total con historiales viejos).</li>
<li>Gráficos interactivos (hover con detalle) con Chart.js — sin dependencias nuevas.</li>
</ul>
<h3 id="landing--secciones-orientadas-a-la-acción">Landing — secciones orientadas a la acción</h3>
<ul>
<li><strong>&ldquo;Funciona con&rdquo; interactivo</strong>: los logos de frameworks ahora son botones — el clic
actualiza un mini terminal con los comandos reales (Install / Run / Fix) por framework,
con tooltip al hover (oculto en táctil, donde el clic abre el terminal).</li>
<li><strong>Frase de unificación</strong> en la sección: &ldquo;el mismo <code>healify fix</code> funciona con todos, sin
cambios en tu pipeline&rdquo; + CTA &ldquo;Ver integraciones completas&rdquo; (docs/adapters).</li>
<li><strong>Carrusel del dashboard</strong> (prev/next + dots) con 3 capturas reales del dashboard servido
con <code>healify dashboard --serve</code> (Resumen, Eficacia, Crónicos) + CTA &ldquo;Explora el dashboard
en tu máquina&rdquo; con el comando copiable.</li>
<li><strong>Footer ampliado</strong>: GitHub, Changelog, Contributing, Docs y npm + badge &ldquo;Hecho con ❤&rdquo;.</li>
<li>Interacciones en JS vanilla (sin Alpine, sin CDN — se mantiene el rendimiento y la
promesa de cero dependencias externas). Número de tests del footer actualizado a 1153.</li>
</ul>
<h2 id="270--2026-08-13">2.7.0 — 2026-08-13</h2>
<p>Smart Healing: Healify pasa de &ldquo;reparación automática&rdquo; a &ldquo;diagnóstico + validación +
sugerencia inteligente&rdquo;, con un rediseño visual completo.</p>
<h3 id="smart-healing-feedback-de-la-comunidad">Smart Healing (feedback de la comunidad)</h3>
<ul>
<li><strong><code>healify fix --validate</code></strong> — después de aplicar un fix, vuelve a correr la prueba más
pequeña que fallaba (comando por framework: playwright/cypress/vitest, o
<code>--test-command</code> para proyectos custom). Si el test falla, el cambio se revierte y el
proceso sale con error <strong>antes</strong> de tocar la rama/PR. Framework desconocido → aviso
honesto, nunca se adivina.</li>
<li><strong><code>healify fix --min-confidence &lt;n&gt;</code></strong> (default 0.8) — los healed bajo el umbral se
saltean como <code>low-confidence</code> (solo sugerencia), antes del reemplazo de texto y del AST.</li>
<li><strong>Output con contexto</strong> — cada fix aplicado muestra: localizador viejo → candidato,
confianza, si fue verificado contra la página y el rol+nombre que coincidió
(<code>#old → [data-testid='new'] (95% · verificada en la página · button &quot;Add to cart&quot;)</code>).</li>
<li><strong><code>healify fix --suggest-only</code></strong> — imprime las sugerencias sin modificar ningún archivo.</li>
<li><strong><code>healify confirm --id &lt;defectId&gt; [--accepted|--rejected]</code></strong> — métrica de eficacia:
cuántos fixes se aceptan sin revertir. El dashboard muestra <code>Eficacia de fixes</code>
(aceptados · rechazados · sin confirmar).</li>
</ul>
<h3 id="visual-overhaul">Visual overhaul</h3>
<ul>
<li><strong>Nuevo logo</strong> escudo + H (SVG animado/estático + pack raster 512/192/180/32/16 + favicon.ico).</li>
<li><strong>Landing rediseñada</strong>: hero a pantalla (82vh), glassmorphism verde-cian-azul, logos
oficiales animados con glow, CTA ámbar, cero CDN.</li>
<li><strong>README EN/ES</strong> con storytelling, badges y ejemplo rápido.</li>
<li><strong>Docs</strong>: <code>docs/project-evaluation.md</code> y <code>docs/project-status.md</code>.</li>
</ul>
<h3 id="calidad">Calidad</h3>
<p>2026-08-13 — calidad, cobertura y presentación (release 2.6.0)</p>
<p>Cierre del ciclo de presentación: el proyecto queda listo para mostrarse, con métricas
verificables y una cara nueva.</p>
<ul>
<li><strong>Cobertura de los huecos del CLI</strong>: <code>ai.ts</code> e <code>index.ts</code> de 0% a ~96% (56 tests nuevos);
el paquete <code>cli</code> de 63% a 91.8%.</li>
<li><strong>Cobertura de <code>cypress-plugin</code></strong>: flujo de curación en vivo de <code>support.ts</code> (sondeo, heal
css/xpath, shadow-DOM finder, no-suggestion/failed) — de 55.97% a 94.8%.</li>
<li><strong>9 paquetes medidos</strong> con umbrales anti-regresión (<code>ai-local</code>, <code>mcp</code>, <code>dashboard-web</code>
incluidos); <code>cypress-plugin</code> y <code>cli</code> ahora exigen 80%. El CI verifica los umbrales con
fuente única en los scripts.</li>
<li><strong>0 usos de <code>any</code>/<code>as</code>/<code>!</code> en producción</strong> (auditoría de tipos: 15 hallazgos, corregidos
con type guards y validación runtime).</li>
<li><strong>Refactor de funciones largas</strong>: <code>healing-engine.ts</code> (870 líneas) y <code>local-report.ts</code>
(779) divididos en módulos cohesivos — ninguna función supera las 80 líneas.
<code>dashboard-serve.ts</code> (329 líneas) partido en 6 módulos.</li>
<li><strong>38 JSDoc agregados</strong> en exports sin documentar de reporter-core y cli.</li>
<li><strong>README EN/ES reescritos</strong> con storytelling, badges y ejemplo rápido.</li>
<li><strong>Landing rediseñada</strong>: minimalista, glassmorphism verde-cian-azul, logos oficiales animados,
CTA ámbar, cero CDN. Lighthouse: Performance 99 · Accesibilidad 95 · Best Practices 100.</li>
<li><strong>Captura del dashboard</strong> (<code>landing/report-screenshot.png</code>) generada con Playwright.</li>
<li><strong>Documentación</strong>: <code>docs/project-evaluation.md</code>, <code>docs/project-status.md</code>,
<code>docs/final-review.md</code>.</li>
<li><strong>Versión alineada a 2.6.0</strong> en los 11 <code>package.json</code> del repo.</li>
<li><strong>Corrección</strong>: rutas de assets relativas que rompían <code>/es/</code> en la landing (404) — ahora
rutas absolutas.</li>
</ul>
<h3 id="publicado-en-npm">Publicado en npm</h3>
<p>8 paquetes (<code>@healify/*</code>) — <code>dashboard-web</code> queda privado.</p>
<h2 id="260">2.6.0</h2>
<blockquote>
<p>El histórico deja de ser un archivo muerto: <code>healify dashboard --serve</code> levanta un servidor
local con una UI React que navega por los selectores, sus sugerencias y su tendencia — todo
100% local, sin telemetría.</p>
</blockquote>
<h3 id="healify-dashboard---serve-el-dashboard-web-local"><code>healify dashboard --serve</code>: el dashboard web local</h3>
<ul>
<li>
<p><strong>Nuevo comando <code>healify dashboard --serve</code>.</strong> Levanta un servidor Express en
<code>http://127.0.0.1:5173</code> que sirve la UI React (<code>dashboard-web/</code>) y una API JSON. Sin <code>--serve</code>
el comando sigue generando el HTML offline de siempre — comportamiento intacto.</p>
</li>
<li>
<p><strong>Datos reales, cero inventos.</strong> La API lee en cada request <code>~/.healify/stats.json</code> (agregados
de <code>healify heal --stats</code>) y <code>.healify/history.jsonl</code> (el historial por selector). Un selector
se agrega por <code>sha256(testFile + selector)</code>, con su recuento de roturas, última sugerencia,
última cura, primera/última aparición y si es crónico (3+ roturas).</p>
</li>
<li>
<p><strong>API REST local:</strong></p>
<ul>
<li><code>GET /api/stats</code> → stats.json + resumen del histórico con timeline.</li>
<li><code>GET /api/selectors</code> → lista de selectores agregada, ordenada por roturas.</li>
<li><code>GET /api/selectors/:id</code> → detalle de un selector (historial + tendencia). 404 si no existe.</li>
</ul>
</li>
<li>
<p><strong>UI React en <code>dashboard-web/</code>.</strong> Vite + React + TypeScript con la paleta de la landing:
<code>DashboardLayout</code> con sidebar, <code>StatsOverview</code> con tarjetas de totales, <code>SelectorList</code> con
filtro por tipo, <code>SelectorDetail</code> con historial y <code>TrendChart</code> (Chart.js), y
<code>ChronicSelectors</code> para los selectores crónicos. SPA con fallback: cualquier ruta responde el
HTML de la app, nunca 404.</p>
</li>
<li>
<p><strong>Auto-puerto.</strong> Si el puerto pedido (default 5173) está ocupado, prueba los siguientes hasta
10 intentos y usa el primero libre. <code>--port 0</code> deja que el SO asigne un efímero. El mensaje
siempre muestra el puerto real en uso.</p>
</li>
<li>
<p><strong><code>--open</code></strong> abre el navegador al arrancar. Ctrl+C cierra el servidor limpio. Sin la UI
compilada, el servidor igual responde la API con una página de fallback con links — los datos
nunca se quedan sin servir por falta de la app.</p>
</li>
</ul>
<blockquote>
<p>El motor deja de curar a ciegas: el probe en vivo ahora le trae el <strong>testid real</strong> del DOM y le
dice cuánto shadow DOM hay que atravesar, el CLI mide su propio trabajo sin telemetría, el MCP
procesa lotes y habla el idioma de cada framework, y la Action pasa del comentario a la PR.</p>
</blockquote>
<h3 id="el-motor-aprende-del-dom-real-el-testid-el-nombre-ausente-y-el-shadow-anidado">El motor aprende del DOM real: el testid, el nombre ausente y el shadow anidado</h3>
<ul>
<li>
<p><strong>MEJORA 1 — el data-testid se lee, no se adivina.</strong> El probe en vivo (Selenium/WebdriverIO/
Cypress) trae ahora <code>testId</code> y <code>testIdAttr</code> del elemento encontrado: si el DOM conserva un
<code>data-testid</code>/<code>data-cy</code>/<code>data-qa</code>/<code>data-test</code>/<code>data-e2e</code>, el motor lo propone como estrategia
<code>TESTID</code> en <code>priority 1</code>, justo debajo del role verificado en vivo. Se conserva el atributo
REAL (<code>data-cy</code> en vez de <code>data-testid</code>): reescribirlo a otro nombre inventaría un selector
que no existe en el DOM (regla &ldquo;Cero Inventos&rdquo;). Un testid que se lee de la pantalla no tiene
precio de confianza: <code>0.94</code>.</p>
</li>
<li>
<p><strong>MEJORA 2 — un rol sin nombre deja de venderse como cura.</strong> <code>buildRoleSuggestion</code> devuelve
<code>null</code> sin nombre accesible: <code>role('button')</code> a secas matchea de más y no tiene XPath
ejecutable, así que no es una sugerencia aplicable. Donde antes se interpolarba ese rol
genérico (XPath, <code>nth-child</code>, objetivo de combinador sin atributos estables), ahora se usa
<code>buildGenericRoleHint</code> — una pista de revisión manual en <code>priority 4</code>, con el texto diciendo
que requiere revisión antes de aplicar, en vez de caer al fallback <code>visible=</code>.</p>
</li>
<li>
<p><strong>MEJORA 2 (cont.) — el veredicto se desacopla de la prioridad.</strong> Nueva bandera
<code>pageVerified</code> en la estrategia: es lo que decide <code>verified</code>, no <code>priority === 0</code>. Una pista
degradada (rol sin nombre) vive en <code>priority 4</code> pero nace igual de la evidencia real de la
página, así que conserva su confidence sin re-ajustarla. Y si el elemento real NO expone
nombre accesible pero sí testid, el testid pasa a ser la sugerencia principal (index 0): es
la mejor señal estable disponible en ese caso.</p>
</li>
<li>
<p><strong>MEJORA 3 — el shadow DOM anidado se avisa, no se calla.</strong> El probe registra <code>shadowDepth</code> y
<code>shadowPath</code> (la cadena de hosts, <code>['x-card', 'inner-widget']</code>): los selectores CSS/XPath NO
atraviesan shadow roots por especificación, así que sugerir un locator plano callado mandaría
al usuario a un test que sigue fallando y encima parecería un bug de Healify. Ahora la
explicación dice exactamente qué pierce hacer (<code>.shadow()</code> en Cypress, <code>.shadowRoot</code> en
Selenium/WebdriverIO), igual que ya avisaba el cambio de contexto de iframe. El <code>pierceNote</code>
va vacío en light DOM, así que las ramas de siempre quedan idénticas.</p>
</li>
<li>
<p><strong>Sin nombre y sin testid no se invierte nada.</strong> Un elemento real sin ninguna señal estable
termina en la pista genérica de revisión manual — evidencia de que el elemento existe, con
<code>pageVerified: true</code>, pero sin pretender ser un locator aplicable.</p>
</li>
</ul>
<h3 id="--stats-el-healing-se-mide-sin-mandar-un-byte-a-la-nube"><code>--stats</code>: el healing se mide sin mandar un byte a la nube</h3>
<ul>
<li>
<p><strong>Nuevo flag <code>healify heal --stats</code>.</strong> Cada corrida ya medía sus fases (<code>probeMs</code>,
<code>analysisMs</code>, <code>healingMs</code>, <code>totalMs</code> en el output) y ahora además acumula estadísticas en
<code>~/.healify/stats.json</code>: total analizado, sanados vs. fallidos (una sugerencia que requiere
revisión manual cuenta como fallida), conteo por tipo de selector y tiempo promedio. Todo
local — no hay telemetría, nada sale de la máquina.</p>
</li>
<li>
<p><strong>Va a stderr a propósito.</strong> <code>stdout</code> sigue siendo JSON puro para no romperle el parsing al
caller de cualquier lenguaje; el resumen humano (<code>✅ 3 selectores sanados (2 roles, 1 testid) en 234ms — tasa de éxito: 67%</code>) se imprime en <code>stderr</code>.</p>
</li>
<li>
<p><strong>Tolerante por diseño.</strong> El archivo ausente o corrupto arranca de cero, y un fallo de
escritura (sin permisos, disco lleno) no rompe el heal: las métricas son menos importantes
que curar.</p>
</li>
</ul>
<h3 id="el-mcp-procesa-lotes-cachea-y-habla-el-idioma-de-cada-framework">El MCP procesa lotes, cachea y habla el idioma de cada framework</h3>
<ul>
<li>
<p><strong>Nueva herramienta <code>healify_batch_analyze_selectors</code>.</strong> Procesa hasta 5 selectores en
paralelo, corta cada análisis a los 30s y los que fallan van a <code>errors</code> con su código sin
tumbar el lote — para un agente que tiene que revisar una página con veinte locators rotos.</p>
</li>
<li>
<p><strong>Cache local de 5 minutos.</strong> El análisis es determinista, así que cachear el output por
<code>(selector, pageUrl, framework)</code> en <code>~/.healify/mcp-cache.json</code> es seguro, y se invalida por
TTL. Solo se sirve un valor que tenga la forma de la herramienta que lo pide: un valor
huérfano con la forma de otra herramienta se ignora y se computa fresco.</p>
</li>
<li>
<p><strong><code>framework</code> opcional en <code>healify_analyze_selector</code></strong> (y en el batch). El motor propone en su
propio dialecto (<code>role(...)</code>, <code>:has-text</code>, <code>visible=</code>), que no se puede pegar en cualquier
archivo: Cypress no entiende <code>getByRole</code> sin librería extra y Selenium no tiene <code>:has-text</code>.
El nuevo <code>framework.ts</code> traduce la sugerencia a la sintaxis idiomática de
playwright/cypress/selenium/webdriverio — conversión 1:1 y determinista. La nota sigue
siendo honesta: sin ver la página, la sugerencia es la mejor heurística (<code>verified: false</code>),
no un reemplazo confirmado.</p>
</li>
</ul>
<h3 id="la-action-pasa-del-comentario-a-la-pr">La Action pasa del comentario a la PR</h3>
<ul>
<li>
<p><strong>Modo auto-PR para <code>workflow_dispatch</code> y <code>schedule</code>.</strong> Nuevos inputs: <code>test-log-path</code>,
<code>auto-pr</code>, <code>fail-on-unsupported</code> y <code>labels</code>. El flujo: log → selectores → <code>healify heal</code> por
selector → reporte → <code>healify fix</code> real → rama + commit + push → PR + comentario con la
tabla de cambios. En <code>pull_request</code> nada cambia: el flujo de comentario clásico sigue intacto.</p>
</li>
<li>
<p><strong><code>log-parser.js</code> — extracción sin dependencias.</strong> La action no puede importar
<code>@healify/reporter-core</code> (es TypeScript y vale la regla de cero deps de runtime), así que los
patrones de extracción viven portados desde <code>selector-extractor.ts</code>, con el mismo cuidado de
<code>QUOTED_CONTENT</code>. Sirve tanto para Playwright (cabeceras <code>N) archivo.spec.ts</code>) como para
Cypress (<code>Running:</code>), deduplica por <code>testFile::selector</code> y descarta los selectores que no se
pueden extraer — alimentar al motor con &ldquo;Unknown selector&rdquo; produciría una sugerencia basura.</p>
</li>
<li>
<p><strong><code>report-builder.js</code> — del heal al reporte.</strong> Traduce la salida de <code>healify heal</code> al shape
<code>LocalCaseResult</code> que ya conoce <code>fix</code>, replicando los umbrales de estado de <code>local-mode.ts</code>
(healed ≥ 0.90 / review ≥ 0.80 / unresolved el resto). Un fallo puntual de un selector no
aborta el lote: ese caso queda <code>unresolved</code> y se ve en el comentario.</p>
</li>
<li>
<p><strong><code>fail-on-unsupported</code> para los crons.</strong> Cuando Healify no pudo trabajar (no hay log, no se
extrajo ningún selector o el CLI falló), el usuario puede pedir que el job falle para que el
problema no pase en silencio en un cron. Default <code>false</code>: se registra y se sigue, para que un
correr informativo no ponga en rojo una corrida programada.</p>
</li>
<li>
<p><strong>Plantilla en <code>examples/github-action-auto-pr/</code></strong> con su README: vive ahí a propósito, si
estuviera en <code>.github/workflows/</code> del repo Healify correría en cada PR de acá haciendo un
no-op. Es para copiar, no un workflow activo.</p>
</li>
</ul>
<h3 id="fix-de-tests-flaky">Fix de tests flaky</h3>
<ul>
<li>
<p>El fake server de Jira (<code>helpers/fake-jira.ts</code>) cerraba el server sin soltar las conexiones
del pool keep-alive de undici: con puertos efímeros, si el OS reutilizaba un puerto entre
tests, undici podía reusar una conexión ya cerrada por el server anterior → <code>ECONNRESET</code>
intermitente → el caso caía como <code>failed</code>. Ahora <code>close()</code> llama a
<code>server.closeAllConnections?.()</code> antes de <code>server.close()</code>, y la aserción del caso HTTP
incluye el mensaje del outcome para diagnóstico si vuelve a pasar. 25+ corridas seguidas
verdes después del fix.</p>
</li>
<li>
<p>128 tests nuevos (965 en total).</p>
</li>
</ul>
<h2 id="240">2.4.0</h2>
<blockquote>
<p><code>@healify/mcp</code> sale con versionado propio (<strong>0.1.0</strong>), como la extensión de VS Code. Todavía
no se publica desde el workflow: npm exige que un paquete exista antes de poder configurarle
trusted publishing, así que su primera publicación es manual. Ver <code>PARA-MANANA.md</code>.</p>
</blockquote>
<h3 id="servidor-mcp-y-el-readme-contra-el-rival-que-importa">Servidor MCP, y el README contra el rival que importa</h3>
<ul>
<li>
<p><strong>Nuevo paquete <code>@healify/mcp</code></strong> — servidor MCP por stdio con cuatro herramientas:
<code>healify_analyze_selector</code>, <code>healify_diagnose_failure</code>, <code>healify_report_summary</code> y
<code>healify_chronic_selectors</code>.</p>
<p>Es el complemento del MCP oficial de Playwright, no su reemplazo. Ese le da a un agente un
browser; la falla documentada de los agentes haciendo eso es el exceso de confianza — clickear
lo primero que matchea, inventar lo que no pueden ver. Healify contesta determinista, desde
evidencia que ya está en disco.</p>
<p><strong>La misma regla que rige la extensión de VS Code, ahora en una tercera superficie:</strong> sin haber
visto la página no se propone un nombre concreto. <code>healify_analyze_selector</code> devuelve siempre
<code>verifiedReplacementAvailable: false</code>, y hay un test que recorre cuatro tipos de selector para
garantizar que la respuesta nunca incluya un reemplazo inventado. Un agente que recibe
<code>role('button', { name: 'Submit' })</code> deducido lo aplica sin dudar.</p>
</li>
<li>
<p><strong>Cero dependencias de runtime</strong>, como los otros seis paquetes. MCP sobre stdio es JSON-RPC 2.0
delimitado por saltos de línea con cuatro mensajes: entra en <code>protocol.ts</code> y se testea
alimentándole líneas, sin levantar un cliente.</p>
</li>
<li>
<p><strong>El <code>tsconfig.json</code> del paquete NO excluye <code>src/__tests__</code></strong> — el chequeo de tipos cubre los
tests. La exclusión que tiene <code>cli</code> es justamente el agujero que dejó pasar un helper sin el
campo <code>cause</code>. El emit usa un <code>tsconfig.build.json</code> aparte para que los <code>.d.ts</code> de los tests no
terminen publicados.</p>
</li>
<li>
<p><strong>README y README.es reposicionados.</strong> La tabla comparaba contra Healenium, que dejó de ser el
rival relevante: Playwright ahora trae su propio agente healer. La tabla nueva compara los tres
y agrega la fila que más distingue a Healify — <strong>cuándo se niega</strong>. Y dice de frente el límite:
los selectores rotos son cerca de un cuarto de los fallos de un e2e, y &ldquo;arreglar&rdquo; una aserción
fallida cambiando el selector tapa el bug que el test acababa de encontrar.</p>
</li>
<li>
<p>33 tests nuevos (837 en total).</p>
</li>
</ul>
<h3 id="el-veredicto-de-flakiness-llega-a-la-decisión-de-curar">El veredicto de flakiness llega a la decisión de curar</h3>
<p><code>detectFlakyTests</code> y <code>healify flake</code> ya distinguían un test intermitente de uno siempre roto,
pero ese veredicto <strong>nunca llegaba al motor de sanado</strong>: Healify proponía y aplicaba un selector
nuevo igual, sin mirar si el test venía pasando a veces.</p>
<p>El razonamiento que ahora se aplica: <strong>un selector realmente roto falla siempre</strong>. Si el elemento
no está, no está en ninguna corrida. Que el mismo test haya pasado en otras corridas con el mismo
selector es evidencia de que el locator resuelve, y de que lo intermitente es otra cosa — una
carrera, un dato, un servicio lento.</p>
<ul>
<li><strong><code>flakeVerdictFor(runs, testName, testFile)</code></strong> — veredicto de un test puntual sin construir la
lista entera. Comparte la regla con <code>detectFlakyTests</code> mediante un único <code>verdictFrom()</code>, así
el comando <code>flake</code> y el motor no pueden responder distinto sobre el mismo test (hay un test que
compara las dos salidas).</li>
<li><strong><code>LocalCaseInput.runHistory</code></strong> — las corridas anteriores, que el adapter pasa igual que el
repertorio. El reporter de Playwright las lee en <code>onBegin</code>, <strong>antes</strong> de que esta corrida agregue
la suya: si las leyera al final, el test que acaba de fallar contaminaría su propio veredicto.</li>
<li><strong>Un test flaky no se auto-aplica.</strong> Baja de <code>healed</code> a <code>review</code> y la explicación dice por qué.
La sugerencia <strong>no</strong> se descarta: puede haber render condicional, y ahí el locator por rol sí
ayuda. Como <code>fix</code> solo aplica los <code>healed</code>, bajar a <code>review</code> frena la aplicación automática sin
esconderle nada al usuario.</li>
<li>Sin <code>runHistory</code> el comportamiento es idéntico al anterior — Selenium y WebdriverIO curan en
vivo, no tienen concepto de suite y nunca lo van a pasar.</li>
<li>12 tests nuevos (804 en total).</li>
</ul>
<h3 id="el-historial-pasa-a-ser-accionable-y-sobrevive-a-ci">El historial pasa a ser accionable, y sobrevive a CI</h3>
<ul>
<li>
<p><strong>La causa se persiste.</strong> <code>HistoryEntry.cause</code> es opcional a propósito: los historiales
escritos antes tienen que seguir leyéndose sin migración.</p>
</li>
<li>
<p><strong>Nuevo <code>computeChronic()</code></strong> — agrupa por <code>testFile</code>+<code>selector</code> (mismo criterio que
<code>defectId</code>), umbral de 3 roturas, ventana temporal y una recomendación en una línea. Ahora
<code>healify history</code> abre con lo accionable en vez de con un conteo:</p>
<pre tabindex="0"><code>#add-to-cart (e2e/checkout.spec.ts)
  Se rompió 3 veces en 21 días. En vez de volver a parchear el selector,
  agregale un data-testid estable al elemento.

#total (e2e/carrito.spec.ts)
  Se rompió 3 veces en 15 días, y 3 de 3 no fueron por el selector.
  El locator no es el problema: revisá el flujo del test.
</code></pre><p>La segunda recomendación es el pago de cruzar el clasificador de causa con el historial: sin
la causa persistida, ese selector recibiría el consejo del testid y mandaría a alguien a
cambiar un locator que nunca estuvo roto.</p>
</li>
<li>
<p><strong>Nuevo flag <code>--record-history</code>.</strong> La Action corre <code>fix --dry-run</code> a propósito (su promesa es
no tocar archivos) y <code>appendHistory</code> estaba detrás de un <code>if (!dryRun)</code>: nunca dejaba rastro,
así que cachear <code>.healify/</code> habría cacheado un directorio vacío. Es defendible grabar en
dry-run porque <code>.healify/history.jsonl</code> es el registro propio de Healify, no el código del
usuario — y hay un test que verifica que los archivos de test siguen sin tocarse.</p>
</li>
<li>
<p><strong>La Action pasa a composite y cachea <code>.healify/</code>.</strong> Un action <code>node20</code> no puede restaurar un
cache (es un step, no una llamada de librería) ni depender de <code>@actions/cache</code>, porque
<code>gh-action/node_modules</code> está gitignoreado y GitHub no instala dependencias de un action.
Composite resuelve las dos cosas sin agregar una sola dependencia. Cache por rama con
fallback a la base: una PR arranca sabiendo qué se venía rompiendo en main.</p>
</li>
<li>
<p><strong>Job de CI que ejecuta la Action de verdad.</strong> Los tests de <code>gh-action</code> prueban <code>run.js</code> en
aislamiento; nada probaba que el <code>action.yml</code> arranque. Instala, buildea, siembra un reporte
y después <strong>verifica que <code>.healify/history.jsonl</code> se haya escrito</strong> — un job que pasa sin que
el CLI haya corrido no vale nada.</p>
</li>
</ul>
<h3 id="-la-action-decía-all-clear-cuando-no-había-corrido-nada">🚨 La Action decía &ldquo;All Clear&rdquo; cuando no había corrido nada</h3>
<p>Encontrado por ese job nuevo, en su primera ejecución. Es un bug preexistente, no una regresión.</p>
<p><code>run()</code> atrapaba cualquier error del CLI y devolvía el texto del fallo <strong>como si fuera salida
normal</strong>. Ese texto no trae marcadores <code>✅</code>/<code>❌</code>/<code>✓</code>/<code>⚠</code>, así que <code>buildComment</code> no encontraba
nada que reportar y caía en su rama final:</p>
<blockquote>
<h3 id="healify--all-clear-">Healify — All Clear ✅</h3>
<p>No broken selectors detected. Healify doctor passed all checks.</p>
</blockquote>
<p>O sea que cualquier proyecto donde <code>@healify/cli</code> no estuviera instalado o accesible recibía un
visto bueno en cada PR, sin que Healify se ejecutara jamás. La afirmación más fuerte que puede
hacer la Action era justo la que emitía cuando no sabía nada.</p>
<ul>
<li>
<p><code>run()</code> ahora devuelve <code>{ ok, output }</code>. No relanza a propósito: un CLI que falla tiene que
terminar en un comentario que lo explique, no en un job rojo sin contexto.</p>
</li>
<li>
<p>Comentario nuevo <strong>&ldquo;Could not run ⚠️&rdquo;</strong> que dice qué comando falló, aclara <em>&ldquo;this is not a
pass&rdquo;</em> y adjunta la salida real del comando en un <code>&lt;details&gt;</code>.</p>
</li>
<li>
<p>7 tests que cubren el falso verde.</p>
</li>
<li>
<p>21 tests nuevos (799 en total).</p>
</li>
</ul>
<h3 id="diagnóstico-de-causa-antes-de-curar">Diagnóstico de causa antes de curar</h3>
<p>Healify pasa a preguntarse <strong>por qué</strong> falló un test antes de decidir si tiene algo que
proponer, y a abstenerse cuando la respuesta no es &ldquo;un selector dejó de encontrar su
elemento&rdquo;.</p>
<ul>
<li><strong>Nuevo <code>diagnoseFailure()</code></strong> (<code>reporter-core/src/failure-cause.ts</code>): clasifica el fallo en
<code>selector</code>, <code>assertion</code>, <code>timing</code>, <code>navigation</code>, <code>runtime</code> o <code>unknown</code> a partir del mensaje
de error. Determinista, sin red y sin IA, igual que el resto del motor. El <code>errorMessage</code> ya
viajaba hasta el motor desde siempre y no lo leía nadie.</li>
<li><strong>El sanado se abstiene fuera de alcance.</strong> Un fallo con causa identificada distinta de
<code>selector</code> se reporta con la causa nombrada, <code>status: unresolved</code> y sin corrección
propuesta. El caso que justifica todo esto:
<code>expect(page.locator('#total')).toHaveText('99')</code> menciona un locator, así que hasta ahora
el motor le proponía un selector nuevo — pero el elemento <strong>se había encontrado</strong>, lo que
falló fue el valor. Curar eso hace pasar el test tapando el defecto que acababa de
encontrar. Un falso verde es peor que un rojo.</li>
<li><strong>Regla de diseño: solo se clasifica como no-selector con una señal positiva.</strong> Ante la duda
gana el comportamiento anterior, así que ningún fallo que Healify ya curaba deja de curarse.
En particular <code>Timed out ... waiting for locator('#x')</code> sigue siendo un selector roto: la
regla de timing cubre esperas de navegación y de carga, nunca un timeout a secas.</li>
<li><strong><code>LocalCaseResult.cause</code> y <code>RunStats.causes</code></strong> exponen la clasificación, y <code>printSummary()</code>
agrega una segunda línea cuando hay fallos fuera de alcance. Sin eso quedaban contados como
<code>unresolved</code> a secas y parecía que Healify no supo resolverlos, cuando en realidad decidió
no meterse.</li>
<li>21 tests nuevos (777 en total).</li>
</ul>
<h2 id="java-en-maven-central-fuera-del-ciclo-de-versión-npm">Java en Maven Central (fuera del ciclo de versión npm)</h2>
<blockquote>
<p>Tampoco toca ningún paquete npm — <code>io.github.mescobar996:healify-selenium</code> tiene su propio
versionado en Maven Central (<code>0.1.0</code>), independiente de Healify.</p>
</blockquote>
<ul>
<li><strong><code>healify-selenium</code> publicado en Maven Central</strong> (<code>java/healify-selenium/</code>), coordenadas
<code>io.github.mescobar996:healify-selenium:0.1.0</code>. El adapter Java deja de ser solo un
archivo de referencia para copiar y pasa a ser una dependencia real de Maven.</li>
<li>Camino completo hecho de cero, sin nada preexistente: cuenta en el Central Publisher
Portal, namespace <code>io.github.mescobar996</code> verificado (repo público en GitHub con el
Verification Key como nombre), clave GPG 4096-bit generada y publicada a un keyserver,
<code>pom.xml</code> con jars de sources/javadoc/firma GPG/<code>central-publishing-maven-plugin</code>, Maven
instalado de forma permanente (Chocolatey) para que el usuario pueda repetir el proceso a
futuro.</li>
<li><strong>Dos bugs reales encontrados y arreglados en el camino</strong> (ninguno del código de Healify,
ambos de la herramienta): el GPG que trae Git para Windows depende de un demonio
(<code>keyboxd</code>) pensado para correr dentro de git-bash — desde PowerShell nativo fallaba con
<code>No Keybox daemon running</code>; se resolvió instalando Gpg4win (el GPG estándar de Windows,
con <code>gpg-agent</code> propio). El plugin <code>central-publishing-maven-plugin</code> 0.7.0 no reconoce un
campo nuevo (<code>warnings</code>) que la API de Sonatype ahora devuelve al consultar el estado del
deployment — el <code>mvn deploy</code> fallaba en ese paso, pero el upload en sí ya había terminado
bien; se resolvió publicando manualmente desde la web del Central Portal.</li>
<li>Verificado real contra el registro: <code>repo1.maven.org</code> devuelve <code>200</code> para el <code>.pom</code> y el
<code>.jar</code> del paquete publicado.</li>
<li><strong><code>healify-selenium</code> en PyPI</strong> (<code>python/healify-selenium/</code>): el adapter de Python deja de
ser solo un archivo de referencia para copiar y pasa a ser un paquete instalable
(<code>pip install healify-selenium</code>), con <code>pyproject.toml</code>, licencia MIT y README propios.
Verificado de punta a punta con el wheel real: construido (<code>python -m build</code>, pasa
<code>twine check</code>), instalado en un venv limpio, y corrido contra Chrome real con Selenium
4.46 — mismo resultado que el adapter de referencia (<code>verified: true</code>, click ejecutado).
C# sigue siendo adapter de referencia (código para copiar), no paquete en NuGet — eso
sigue siendo un compromiso de mantenimiento aparte, no asumido.</li>
<li><strong>Adapter C# verificado de punta a punta, por primera vez</strong>: con un .NET 8 SDK portable
(zip, sin instalar nada en el sistema) + Selenium.WebDriver 4.27 vía NuGet + Chrome real.
Un selector roto a propósito se curó en vivo y se verificó contra la página
(<code>verified: true</code>, <code>confidence: 0.97</code>).</li>
<li><strong>Bug real encontrado y arreglado en esa verificación</strong>: <code>RunProcess</code> invocaba <code>npx.cmd</code>
directo como <code>FileName</code> con <code>UseShellExecute=false</code> — a diferencia de una terminal real,
<code>Process.Start</code> de .NET en Windows no lo asocia con un intérprete solo, y termina en un
<code>MODULE_NOT_FOUND</code> interno de npm apenas se corre así. Arreglado invocando <code>cmd.exe /c npx ...</code> explícito, el patrón estándar de .NET para lanzar batch scripts sin una shell real.</li>
</ul>
<h2 id="230--2026-08-05">2.3.0 — 2026-08-05</h2>
<blockquote>
<p>⚠️ <strong>Si configuraste el reporte a Jira, nunca funcionó.</strong> No es una regresión de esta
versión: no funcionó nunca, desde que la feature existe. Está arreglado acá.</p>
</blockquote>
<h3 id="el-reporte-a-jira-no-podía-crear-un-ticket">El reporte a Jira no podía crear un ticket</h3>
<p>Dos motivos, los dos confirmados contra la documentación de Atlassian:</p>
<ol>
<li><strong>La API v3 exige ADF</strong> (Atlassian Document Format) en <code>description</code> y en el cuerpo de los
comentarios. El cliente mandaba strings, y v3 contesta 400 con <em>&ldquo;Operation value must be an
Atlassian Document&rdquo;</em>. Es la diferencia principal entre la v2 y la v3.</li>
<li><strong><code>GET /rest/api/3/search</code> fue removido.</strong> Hoy responde 410 pidiendo migrar a
<code>/rest/api/3/search/jql</code>. Ese endpoint es el que hace el dedupe: además de no poder crear
tickets, tampoco podía evitar duplicarlos.</li>
</ol>
<p>La feature tenía 19 tests en verde. Todos con el <code>fetch</code> mockeado, y <strong>un mock devuelve lo que
el test le dice que devuelva</strong>: valida que el código llame a lo que el test cree que
corresponde, nunca que el otro lado lo acepte.</p>
<p>Ahora hay un servidor que se comporta como Jira Cloud v3 y <strong>rechaza lo que Jira rechaza</strong> —
texto plano donde va ADF, 410 en el endpoint viejo, 403 sin el header XSRF en los adjuntos.
Los 12 tests nuevos pasan por HTTP real; con el código anterior, 5 fallaban de entrada.</p>
<h3 id="github-issues">GitHub Issues</h3>
<p>Los defectos ahora pueden ir a los Issues del repo. Mismo contrato que Jira (buscar por
<code>defectId</code>, crear o comentar) pero en Markdown, que es lo que la API espera.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-js" data-lang="js"><span style="display:flex;"><span><span style="color:#a6e22e">agile</span><span style="color:#f92672">:</span> {
</span></span><span style="display:flex;"><span>  <span style="color:#a6e22e">enabled</span><span style="color:#f92672">:</span> <span style="color:#66d9ef">true</span>,
</span></span><span style="display:flex;"><span>  <span style="color:#a6e22e">provider</span><span style="color:#f92672">:</span> <span style="color:#e6db74">&#39;github&#39;</span>,
</span></span><span style="display:flex;"><span>  <span style="color:#a6e22e">repository</span><span style="color:#f92672">:</span> <span style="color:#e6db74">&#39;tu-usuario/tu-repo&#39;</span>,
</span></span><span style="display:flex;"><span>  <span style="color:#a6e22e">apiToken</span><span style="color:#f92672">:</span> <span style="color:#a6e22e">process</span>.<span style="color:#a6e22e">env</span>.<span style="color:#a6e22e">HEALIFY_GITHUB_TOKEN</span>,
</span></span><span style="display:flex;"><span>}
</span></span></code></pre></div><p>En un workflow alcanza el token que GitHub ya da, con <code>permissions: issues: write</code>. El token se
lee de <code>HEALIFY_GITHUB_TOKEN</code> y <strong>no</strong> de <code>GITHUB_TOKEN</code> a secas: esa variable la exporta el
runner en todo workflow, y tomarla sola convertiría un <code>healify report</code> mal configurado en un
intento silencioso de escribir en tu repo.</p>
<p>Nació con 10 tests contra un servidor igual de estricto, sin pasar por la etapa de mockear.</p>
<h3 id="la-evidencia-llega-al-ticket">La evidencia llega al ticket</h3>
<p>Hasta ahora el screenshot del fallo iba en la descripción como
<code>[captura](test-results/checkout/fallo.png)</code> — una ruta en el disco de quien corrió los tests,
que para el que abre el ticket no existe.</p>
<p><code>attachEvidence: true</code> sube el archivo de verdad (multipart, con el header XSRF que Jira exige
y sin el cual devuelve 403 aunque las credenciales estén bien). Es opt-in aparte de <code>enabled</code>
porque una captura de un entorno de prueba puede tener datos reales adentro.</p>
<h3 id="los-tickets-se-cierran">Los tickets se cierran</h3>
<p><code>transitionOnHealed: 'Done'</code> mueve el ticket cuando Healify resolvió el selector <strong>y lo
verificó contra la página</strong> — no cuando dedujo un nombre plausible. Jira no acepta el nombre
del estado destino, solo el id de la transición, que varía por workflow: se consultan las
disponibles primero. Si el workflow no la tiene, el ticket queda creado igual.</p>
<h3 id="dos-bugs-más-encontrados-en-el-camino">Dos bugs más, encontrados en el camino</h3>
<ul>
<li><strong><code>GITHUB_REPOSITORY</code> se leía siempre</strong>, y el runner de GitHub Actions la exporta en <em>todo</em>
workflow: la config resuelta cambiaba según dónde corría. Lo encontró CI — los tests pasaban
en cualquier máquina y fallaban en el runner.</li>
<li><strong><code>validateAgile</code> descartaba los campos nuevos.</strong> Un <code>healify.config.json</code> con
<code>provider: 'github'</code> quedaba reducido a <code>{ enabled: true }</code>: la feature andaba solo por
variables de entorno, y la documentación recién escrita mostraba ejemplos que no habrían
funcionado.</li>
</ul>
<h3 id="menor">Menor</h3>
<ul>
<li>El dry-run decía que el dedupe lo hace el receptor. Eso solo vale para <code>webhook</code>; con Jira y
GitHub lo hace Healify.</li>
<li><strong>El reporte de defectos por fin está en el README</strong>, en los dos idiomas. Existía desde la
1.7.0 y quien llegaba al repo por GitHub no se enteraba de que Healify podía abrirle un
ticket.</li>
<li>La landing menciona GitHub Issues y suma el ejemplo de Selenium, que faltaba ahí.</li>
</ul>
<h2 id="220--2026-08-05">2.2.0 — 2026-08-05</h2>
<h3 id="extensión-de-vs-code-healify-vscode-010">Extensión de VS Code (<code>healify-vscode</code> 0.1.0)</h3>
<p>Healify sale de la terminal. Los selectores frágiles se subrayan mientras escribís; los que
se rompieron de verdad se arreglan con <code>Ctrl+.</code>.</p>
<p>La extensión se versiona aparte de los paquetes npm, igual que los adapters de Java y Python:
su ciclo de release no es el de npm.</p>
<p><strong>Dos niveles, y la diferencia es el diseño entero:</strong></p>
<table>
  <thead>
      <tr>
          <th></th>
          <th>Origen</th>
          <th>Acción</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Amarillo</td>
          <td>El motor, sin ver la página</td>
          <td>Ninguna — advierte, no propone</td>
      </tr>
      <tr>
          <td>Rojo</td>
          <td><code>healify-report.json</code> con <code>verified: true</code></td>
          <td>Quick Fix con el reemplazo real</td>
      </tr>
  </tbody>
</table>
<p>Sin evidencia del DOM el motor igual propone algo: preguntarle por <code>#btn-a1b2c3</code> devuelve
<code>role('button', { name: 'Submit' })</code>. Ese <em>&ldquo;Submit&rdquo;</em> no salió de ninguna página. Ofrecerlo
como Quick Fix sería la adivinanza que Healify dice no hacer, y encima dentro del editor,
donde un <code>Ctrl+.</code> distraído lo aplica sin que nadie lo lea. <strong>Un selector no recibe reemplazo
concreto si no fue confrontado contra una página real</strong>, y hay tests —unitarios y dentro de un
VS Code de verdad— que fallan si eso deja de cumplirse.</p>
<p>No reimplementa nada del motor: <code>analyzeAndHeal</code> va bundleado para el lint (spawnear un
proceso por tecla no es viable) y las correcciones estructurales las aplica el <code>healify fix</code>
del proyecto, que ya sabe de page objects y reescritura AST. Dos copias de esa lógica se
desincronizan seguro.</p>
<p><strong>Dos bugs que aparecieron construyéndola</strong>, los dos en el mismo lugar donde nadie mira:</p>
<ul>
<li>El enmascarado de comentarios trataba el <code>//</code> inicial de un XPath como comentario de línea.
La extensión habría sido <strong>ciega a todos los XPath</strong> — de los selectores más frágiles que
existen — y el subrayado simplemente no habría aparecido nunca.</li>
<li>La regex exigía que el cuerpo del string no tuviera <em>ninguna</em> comilla, así que
<code>By.xpath(&quot;//button[text()='Pagar']&quot;)</code> se cortaba en la comilla interna.</li>
</ul>
<p>Los encontraron los tests al escribirlos, no una revisión del código.</p>
<h3 id="menor-1">Menor</h3>
<ul>
<li><strong>LICENSE en los 7 tarballs.</strong> Todos declaraban <code>&quot;license&quot;: &quot;MIT&quot;</code> sin llevar el texto: npm
solo incluye el archivo si está en la raíz <em>del paquete</em>, y el nuestro vive en la raíz del
repo. Lo copia un <code>prepack</code>, y CI verifica el tarball —no el script— porque un tarball
publicado no se corrige: hay que quemar una versión nueva.</li>
<li><strong><code>ts-morph</code> 21 → 28.</strong> Siete majors, pero la superficie que usa <code>fix-ast</code> son 6 llamadas de
la API core y ninguna cambió. Verificado con los tests que escriben archivos de verdad más
el ciclo completo del ejemplo <code>playwright-pom</code> contra Chrome real.</li>
<li><strong><code>healify ai models</code> con Ollama apagado.</strong> Salía con error aunque el catálogo de modelos y
la RAM son datos locales, y son justo lo que querés mirar <em>antes</em> de bajar nada.</li>
</ul>
<h2 id="211--2026-08-04">2.1.1 — 2026-08-04</h2>
<blockquote>
<p>⚠️ <strong>Si usás el adapter de Selenium, actualizá.</strong> En 2.1.0 no curaba nada. No fallaba, no
avisaba: simplemente no hacía nada.</p>
</blockquote>
<p>Tres bugs, los tres encontrados igual que los de la 2.1.0 — construyendo ejemplos que corren
contra un browser de verdad. Ninguno lo vio la suite unitaria.</p>
<h3 id="selenium-el-adapter-no-curaba-nunca">Selenium: el adapter no curaba nunca</h3>
<p>Encontrado con <code>examples/selenium-live-heal</code>. Es el peor bug que tuvo Healify hasta ahora.</p>
<p>La guarda de entrada del wrapper era <code>err instanceof error.NoSuchElementError</code>. Alcanza con que
haya <strong>dos instancias del módulo <code>selenium-webdriver</code></strong> en el árbol de dependencias (un
monorepo, un install de pnpm, dos versiones conviviendo) para que la clase exista duplicada y esa
comparación dé <code>false</code> sobre un error que sí lo es. El log lo decía en la cara:</p>
<pre tabindex="0"><code>[DBG] no es NoSuchElement: NoSuchElementError
</code></pre><p>El wrapper salía por ahí antes de sondear nada. Silencioso y total: el test fallaba igual que
sin Healify instalado.</p>
<p>Los tests unitarios no podían verlo porque ahí el mock y el plugin comparten la misma instancia
del módulo, así que <code>instanceof</code> funciona siempre. Ahora la detección también mira <code>.name</code> y
<code>.constructor.name</code>, y hay un test de regresión que simula la segunda instancia.</p>
<h3 id="selenium-y-webdriverio-el-mismo-bug-de-shadow-dom-que-cypress">Selenium y WebdriverIO: el mismo bug de shadow DOM que Cypress</h3>
<p>El arreglado en 2.1.0 estaba solo en Cypress. Los otros dos adapters seguían resolviendo el
reintento con <code>By.xpath()</code>, que no atraviesa shadow DOM: sugerencia correcta, elemento
inalcanzable. Los dos caen ahora a <code>BROWSER_FIND_BY_ROLE_SCRIPT</code>.</p>
<p>De paso, ese script pasó a leer sus argumentos de <code>arguments[0]/[1]</code>, así el <strong>mismo string</strong>
sirve en los tres adapters sin envoltorios distintos.</p>
<h3 id="cypress-healifyget-moría-por-timeout-justo-cuando-el-selector-no-existía">Cypress: <code>healifyGet</code> moría por timeout justo cuando el selector no existía</h3>
<p>El <code>.then()</code> que envuelve al sondeo heredaba <code>defaultCommandTimeout</code> — el mismo presupuesto de
tiempo que el sondeo iba a gastar esperando. Como el sondeo recién resuelve en el tick posterior
al vencimiento, Cypress mataba el comando primero (siempre, no de a ratos) con <em>&ldquo;cy.then() timed
out … promise that never resolved&rdquo;</em>.</p>
<p>Dónde caía es lo peor: <strong>solo cuando el selector no existía</strong>, que es el único caso en el que
Healify tiene algo que hacer. Con el selector presente resolvía al instante y todo parecía
andar, así que el bug vivía escondido detrás del camino feliz.</p>
<h3 id="para-que-no-vuelva-a-pasar">Para que no vuelva a pasar</h3>
<p>Los tres ejemplos corren ahora <strong>en CI, contra browsers reales</strong>. Antes solo lo hacía
<code>playwright-pom</code>; los de cura en vivo dependían de que alguien se acordara de correrlos a mano —
y son justamente los que encontraron todos estos bugs.</p>
<p>Un test verde no alcanza como prueba: si alguien arregla el HTML de un demo y el selector roto
vuelve a existir, el test sigue pasando mientras Healify no hace nada. Por eso <code>scripts/ assert-healed.mjs</code> verifica además el reporte, exigiendo <code>status: healed</code> <strong>y</strong> <code>verified: true</code>
para el selector roto concreto de cada ejemplo.</p>
<h3 id="menor-2">Menor</h3>
<ul>
<li><code>@healify/ai-local</code> tiene README: su página en npm estaba vacía.</li>
<li><code>webdriverio-plugin/dist</code> era el único de los 7 paquetes que no estaba en <code>.gitignore</code>, así
que su build quedaba versionado. Ignorado y destrackeado.</li>
</ul>
<h2 id="210--2026-08-04">2.1.0 — 2026-08-04</h2>
<blockquote>
<p>⚠️ <strong>Si estás en 2.0.0, actualizá.</strong> Esa versión anunciaba soporte de shadow DOM y de Page
Object Model, y las dos estaban rotas. Están arregladas acá. La 2.0.0 quedó deprecada en npm.</p>
</blockquote>
<p>Las dos features estrella de la 2.0.0 se publicaron sin funcionar del todo, y <strong>ninguno de los
700 tests unitarios lo detectó</strong>. Los dos bugs aparecieron el mismo día, construyendo ejemplos
que se corren de verdad contra un browser real — cada uno destapó el suyo.</p>
<h3 id="shadow-dom-el-sondeo-entraba-el-reintento-no">Shadow DOM: el sondeo entraba, el reintento no</h3>
<p>Encontrado con <code>examples/cypress-shadow-dom</code>, corriendo Cypress contra un web component real.</p>
<p>El sondeo <strong>sí</strong> atravesaba el shadow root y proponía bien: la sugerencia era
<code>role('button', { name: 'Pagar ahora' })</code>, el nombre accesible verdadero del botón. Pero el
reintento resolvía con <code>document.querySelector</code> (CSS) o <code>document.evaluate</code> (XPath), y <strong>ninguno
de los dos atraviesa shadow DOM por especificación</strong>. Resultado: <code>la sugerencia tampoco encontró el elemento</code>. Correcta, pero irrecuperable — ciego justo en el último paso.</p>
<p>Los tests no lo veían porque cubrían las dos mitades por separado: el sondeo contra un DOM
falso, el resolver con selectores que nunca estaban dentro de un shadow root.</p>
<ul>
<li><strong><code>BROWSER_FIND_BY_ROLE_SCRIPT</code></strong>: busca un elemento por rol + nombre accesible caminando
shadow roots abiertos e iframes same-origin, con los mismos topes que el sondeo.</li>
<li>La derivación de rol y nombre se extrajo a un helper <strong>compartido</strong> entre sondeo y búsqueda.
Si cada uno usara su propio criterio, lo que uno ve el otro no lo encuentra — que es
literalmente el bug que se está arreglando.</li>
<li>El plugin de Cypress manda rol + nombre además del locator y expone <code>healify:find-script</code>;
el support cae a la búsqueda por shadow roots cuando el locator no resuelve. Los dos scripts
se piden juntos y se cachean, para no agregar round-trips al reintento.</li>
</ul>
<h3 id="page-object-model-la-feature-estaba-muerta-en-playwright">Page Object Model: la feature estaba muerta en Playwright</h3>
<p>Encontrado con <code>examples/playwright-pom</code>.</p>
<p>Con Playwright <strong>siempre</strong> hay evidencia del DOM, así que el motor casi siempre sugiere
<code>role(...)</code>. Y <code>role('button', { name: 'X' })</code> no es un valor de selector —es una representación
legible para el reporte— así que no es sustituible. Como el chequeo de &ldquo;sustituible&rdquo; corría
<strong>antes</strong> de mirar dónde vivía el selector, toda sugerencia de rol se descartaba sin llegar nunca
a la búsqueda en page objects. Medido: 2 de cada 3 casos caían ahí.</p>
<p>O sea: la feature que más diferencia a Healify de Healenium (G3) era código muerto en el runner
más usado, y el README prometía algo que no pasaba.</p>
<ul>
<li>Se invirtió el orden en <code>fix()</code>: primero <strong>dónde</strong> está el selector, después si la sugerencia
es sustituible. Si está en el spec sigue yendo al AST (reescribe la llamada entera, que es
mejor); si está en un page object, se resuelve como string.</li>
<li><strong><code>roleSuggestionToPlaywrightSelector()</code></strong>: <code>role('button', { name: 'X' })</code> →
<code>role=button[name=&quot;X&quot;]</code>, la sintaxis del motor de selectores de Playwright, que sí se puede
pegar dentro de las comillas de un page object sin tocar el call site.
<ul>
<li>Solo para Playwright: en Cypress (jQuery) o Selenium (CSS/XPath) sería un selector inválido,
y ahí el caso sigue quedando para revisión manual. Romper el page object es peor que no
tocarlo.</li>
<li>Devuelve <code>null</code> sin nombre accesible: <code>role=button</code> a secas matchea de más, y un test que
pasa probando otro elemento es el peor resultado posible de una curación.</li>
</ul>
</li>
<li><strong>Bug adicional</strong>, del mismo día: <code>fix</code> resolvía el path posicional del reporte con
<code>args.find(a =&gt; !a.startsWith('--'))</code>. Mientras ningún flag llevó valor eso alcanzaba, pero
con <code>fix --watch --interval 500</code> tomaba <code>500</code> como nombre del reporte. Ahora hay un
<code>parseReportPath()</code> que sabe qué flags consumen el argumento siguiente.</li>
</ul>
<h3 id="ejemplos-que-se-corren">Ejemplos que se corren</h3>
<p>Dos proyectos completos, no snippets. <strong>CI los ejecuta contra un browser real en cada commit</strong>:
si dejan de funcionar, el build se pone en rojo. Un ejemplo que se pudre en silencio es peor que
no tener ejemplo.</p>
<ul>
<li><strong><code>examples/playwright-pom</code></strong> — el selector vive en <code>pages/</code>, no en el test. Verificado
end-to-end: el test falla, <code>fix</code> cura el page object, el test pasa.</li>
<li><strong><code>examples/cypress-shadow-dom</code></strong> — el botón está dentro de un web component, donde
<code>document.querySelectorAll('button')</code> devuelve cero. El test usa un selector inexistente y
pasa igual, curado en vivo.</li>
</ul>
<h3 id="documentación">Documentación</h3>
<p>El README hacía dos trabajos y ninguno bien: 434 líneas donde el pitch quedaba enterrado bajo
snippets de cuatro runners y tablas de flags.</p>
<ul>
<li><strong>README (102 líneas)</strong>: qué problema resuelve y por qué no adivina. Se lee en un minuto.</li>
<li><strong><code>docs/</code></strong>: instalación, comandos, configuración, GitHub Action, Jira y reportes. Cada página
con título propio y navegación, para que se sostenga sola si alguien cae ahí desde Google.</li>
<li><strong><code>examples/README.md</code></strong>: índice de los ejemplos.</li>
</ul>
<p>711 tests (53 archivos), 0 warnings de lint.</p>
<h2 id="200--2026-08-03">2.0.0 — 2026-08-03</h2>
<blockquote>
<p>⚠️ <strong>Deprecada.</strong> Shadow DOM y Page Object Model se anunciaron acá pero no funcionaban del
todo. Usá 2.1.0.</p>
</blockquote>
<p><strong>Hito, no ruptura.</strong> El major marca que se cerró el análisis competitivo entero — los 18 gaps
del <code>docs/research/competitive-gaps.md</code> están cerrados o descartados a conciencia — no un cambio
incompatible de API. <strong>Actualizar desde 1.x no requiere tocar una línea de tu código:</strong> todo lo
que entró desde 1.6.0 es aditivo (comandos nuevos, flags nuevos, bloques de config opcionales
apagados por default). Si venías de 1.6.0, <code>npm i -D @healify/cli@2</code> y listo.</p>
<p>Lo que entra en este major, acumulado desde la última versión publicada (1.6.0):</p>
<table>
  <thead>
      <tr>
          <th>Gap</th>
          <th>Qué salió</th>
          <th>Versión interna</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>G18</td>
          <td><code>healify report</code> — defectos a Jira/webhook, opt-in, dedupe por <code>defectId</code></td>
          <td>1.7.0</td>
      </tr>
      <tr>
          <td>G7</td>
          <td><code>healify dashboard</code> — histórico de healings, 100% offline</td>
          <td>1.8.0</td>
      </tr>
      <tr>
          <td>G8</td>
          <td><code>healify flake</code> — flaky vs. siempre-roto, sobre <code>.healify/runs.jsonl</code></td>
          <td>1.9.0</td>
      </tr>
      <tr>
          <td>G9</td>
          <td><code>healify fix --watch</code> — re-aplica en cada corrida nueva</td>
          <td>1.10.0</td>
      </tr>
  </tbody>
</table>
<p>700 tests (53 archivos), 0 warnings de lint, CI en verde.</p>
<h3 id="g9--fix---watch-lo-último-que-faltaba">G9 — <code>fix --watch</code> (lo último que faltaba)</h3>
<ul>
<li><strong>feat(cli): <code>healify fix --watch [--interval &lt;ms&gt;]</code>.</strong> El análogo del <code>--ui</code> de Playwright
para el lado de Healify: en vez de correr los tests, esperar y acordarse de volver a tipear
<code>healify fix</code>, el loop vigila el reporte y re-aplica solo cada vez que el runner escribe una
corrida nueva. Polling por <code>mtime + size</code> en vez de <code>fs.watch</code>, que tiene semántica distinta
en cada sistema operativo (en algunos dispara dos veces por escritura, en otros no dispara si
el archivo se reemplaza por <code>rename</code> — que es exactamente cómo un runner escribe un reporte).
Cero dependencias nuevas.
<ul>
<li>La primera pasada es inmediata: si ya hay un reporte al arrancar, se aplica ahí mismo.</li>
<li>Sin reporte todavía, avisa <strong>una sola vez</strong> y se queda esperando — en un loop de 1 s,
repetirlo sería spam que taparía la salida útil cuando el reporte por fin aparezca.</li>
<li><code>--pr</code> y <code>--interactive</code> quedan fuera del loop a propósito (crear una PR por corrida, o
preguntar mientras el usuario mira otra cosa, no tienen sentido).</li>
</ul>
</li>
<li><strong>refactor(cli): <code>applyRun()</code> compartido.</strong> El núcleo de una aplicación (sustitución de texto
<ul>
<li>reescritura AST de lo que no era sustituible) es ahora una sola función que usan tanto
<code>healify fix</code> como cada iteración del watch. Si estuviera duplicado, las dos ramas divergirían
en el primer bugfix que se aplicara a una sola.</li>
</ul>
</li>
<li><strong>fix(cli): el valor de un flag ya no se confunde con el path del reporte.</strong> <code>runFix</code> resolvía
el path posicional con <code>args.find(a =&gt; !a.startsWith('--'))</code>. Mientras ningún flag llevó valor
eso alcanzaba, pero con <code>fix --watch --interval 500</code> tomaba <code>500</code> como si fuera el nombre del
reporte, y el watch terminaba vigilando un archivo que nunca iba a existir. Encontrado
corriendo el comando de verdad — los tests con dependencias inyectadas no lo veían porque no
parsean <code>argv</code>. Ahora hay un <code>parseReportPath()</code> que sabe qué flags consumen el argumento
siguiente, con test de regresión.</li>
</ul>
<h2 id="190--2026-08-03">1.9.0 — 2026-08-03</h2>
<p>Cierra el gap G8 del análisis competitivo (<code>docs/research/competitive-gaps.md</code>): detectar
tests flaky. 674 tests (51 archivos), 0 warnings de lint.</p>
<h3 id="detección-de-flakiness">Detección de flakiness</h3>
<p>El historial (<code>history.jsonl</code>) solo guarda selectores rotos, así que &ldquo;apareció roto N veces&rdquo;
no puede distinguir el test flaky del siempre roto. La solución: un registro de corridas
<code>.healify/runs.jsonl</code> con el resultado de CADA test (no solo los fallidos), y un comando que
lee ese registro con denominador.</p>
<ul>
<li><strong>feat(core): registro de corridas</strong> (<code>reporter-core/src/runs.ts</code>) — <code>RunRecord</code>/<code>RunOutcome</code>,
<code>serializeRunRecord</code>/<code>parseRunLines</code> (tolerante a líneas basura) y <code>appendRunRecord</code>
(crea <code>.healify/</code> si no existe; ante cualquier error avisa por <code>console.warn</code> y no rompe la
corrida). El archivo se guarda sin BOM — en Windows <code>Set-Content -Encoding utf8</code> lo escribiría
y <code>JSON.parse</code> explotaría; hay test que lo verifica.</li>
<li><strong>feat(core): <code>detectFlakyTests</code></strong> (<code>reporter-core/src/flake.ts</code>) — agrupa los outcomes por
<code>testFile + testName</code>, computa <code>flakeRate</code> (fallos / corridas) y dictamina
<code>healthy | flaky | always-failing | insufficient-data</code> (con <code>minRuns</code> configurable, default 2).
El mismo test en dos archivos distintos no se mezcla.</li>
<li><strong>feat(test-runner)</strong>: el reporter de Playwright ahora registra la corrida en <code>onEnd</code>
(<code>project: 'Playwright suite'</code>) con los outcomes de cada test en <code>onTestEnd</code> — <code>testName</code>
de <code>titlePath().join(' &gt; ')</code>, <code>testFile</code> relativo al <code>cwd</code>. <code>skipped</code>/<code>interrupted</code> no
entran: ni pasan ni fallan.</li>
<li><strong>feat(cypress-plugin)</strong>: mismo registro en <code>after:run</code> (<code>project: 'Cypress suite'</code>), con
outcomes en <code>after:spec</code> — solo tests <code>passed</code>/<code>failed</code>, nunca <code>skipped</code>/<code>pending</code>.</li>
<li><strong>feat(cli): <code>healify flake [--min-runs &lt;n&gt;]</code></strong> — lee <code>.healify/runs.jsonl</code> e imprime la
tabla de flaky (verde en unas corridas, rojo en otras) y siempre-roto (falló en todas),
con el resumen &ldquo;X flaky de Y tests con datos · N corridas registradas&rdquo;. Sin corridas, avisa
y no rompe. <code>--min-runs</code> sube el piso para opinar (default 2).</li>
<li><strong>fuera de alcance</strong>: Selenium/WebdriverIO no registran corridas — curan en vivo y no tienen
suite propia, así que no hay denominador que leer.</li>
</ul>
<h2 id="180--2026-08-03">1.8.0 — 2026-08-03</h2>
<p>Cierra el gap G7 del análisis competitivo (<code>docs/research/competitive-gaps.md</code>): la vista
visual del histórico de curaciones. 662 tests (47 archivos), 0 warnings de lint.</p>
<h3 id="dashboard--histórico-de-healings">Dashboard / histórico de healings</h3>
<ul>
<li><strong>feat(core): <code>buildDashboardStats</code> + <code>renderDashboardHtml</code></strong> (<code>reporter-core/src/dashboard.ts</code>) —
la misma información que <code>healify history</code> muestra en texto plano, pero como HTML autocontenido
100% offline y con la misma estética dark/light que <code>healify-report.html</code>. Tarjetas de resumen
(total/curadas/en revisión/sin resolver/re-rotos), timeline apilado por día UTC y listas de
recurrentes/re-rotos con los selectores escapados.</li>
<li><strong>refactor(core): <code>computeTopRecurrent</code>/<code>computeRebroken</code> se mudan a reporter-core.</strong> Antes
vivían en <code>cli/src/history.ts</code> (no testeables fuera del CLI, el mismo problema que se resolvió
moviendo el repertorio). <code>cli/src/history.ts</code> los re-exporta — <code>healify history</code> no cambia.</li>
<li><strong>feat(cli): <code>healify dashboard [--out &lt;path&gt;]</code></strong> — lee <code>.healify/history.jsonl</code> y escribe
<code>healify-dashboard.html</code> (o la ruta de <code>--out</code>). Sin historial, avisa y no escribe nada.</li>
</ul>
<h2 id="170--2026-08-03">1.7.0 — 2026-08-03</h2>
<p>Cierra el gap G18 del análisis competitivo (<code>docs/research/competitive-gaps.md</code>): el loop
&ldquo;selector roto → ticket en Jira&rdquo;. 638 tests (46 archivos), 0 warnings de lint.</p>
<h3 id="reporte-a-herramientas-ágiles">Reporte a herramientas ágiles</h3>
<ul>
<li><strong>feat(core): <code>reportDefects</code></strong> — orquestador en <code>reporter-core/src/agile.ts</code> que traduce cada
<code>LocalCaseResult</code> a un defecto y lo reporta a Jira o a un webhook. <strong>Opt-in, off por default</strong>:
sin <code>agile.enabled: true</code> no hace ningún fetch. Mismo estándar que &ldquo;Cadena de custodia&rdquo;: las
credenciales son del usuario contra su instancia, la única salida de datos es el POST hacia su
Jira/webhook, y el token jamás se loguea.</li>
<li><strong>feat(core): dedupe por <code>defectId</code>.</strong> Cada defecto lleva el <code>defectId</code> estable de Healify
(<code>HLF-XXXXXXXX</code>, sha1 de archivo+selector) en el título y la descripción. Antes de crear,
Healify pregunta a tu Jira (<code>text ~ &quot;HLF-XXXXXXXX&quot; AND project = QA</code>); si el defecto ya existe,
no crea nada (<code>existing</code>), que es lo que elimina el ruido de tickets duplicados que la
investigación de campo encontró en todos los equipos QA.</li>
<li><strong>feat(core): la sugerencia viaja como comentario del ticket, nunca reemplaza el hallazgo.</strong> El
issue se crea con expected/actual/pasos/selector/evidencia/entorno, y la sugerencia
(fixedSelector + confidence + verified + explanation + alternativas) se agrega como comentario
— contexto, no reemplazo. Un 503 de tu Jira falla ese defecto, no la corrida: el reporte local
nunca se pierde por un error de red.</li>
<li><strong>feat(core): <code>createJiraClient</code></strong> (<code>reporter-core/src/jira.ts</code>) — cliente mínimo de la API
Cloud v3 con <code>fetch</code> puro (cero deps, patrón <code>gh-action/github-api.js</code>): Basic auth
<code>base64(email:token)</code>, <code>searchByDefectId</code> con JQL escapado, <code>createIssue</code>, <code>addComment</code>. Un
no-2xx tira error con status + snippet del cuerpo (el de Jira explica permisos).</li>
<li><strong>feat(core): provider <code>webhook</code></strong> (<code>reporter-core/src/webhook.ts</code>) — <code>postJson</code> POSTea el
payload JSON y el receptor decide crear-o-actualizar, el patrón que la competencia ya
estableció (&ldquo;webhook → JQL lookup por clave estable → crear si no existe / comentar si existe&rdquo;).</li>
<li><strong>feat(config): bloque <code>agile</code></strong> — <code>enabled</code>, <code>provider</code> (<code>jira</code>|<code>webhook</code>), <code>baseUrl</code>,
<code>email</code>, <code>apiToken</code>, <code>project</code>, <code>issueType</code>, <code>priorityBySeverity</code> (blocker→Highest, major→High,
minor→Medium, pisable), <code>labels</code>, <code>webhookUrl</code>. Env overrides para CI sin commitear secretos:
<code>HEALIFY_AGILE_ENABLED</code>, <code>HEALIFY_AGILE_PROVIDER</code>, <code>JIRA_BASE_URL</code>, <code>JIRA_EMAIL</code>,
<code>JIRA_API_TOKEN</code>, <code>JIRA_PROJECT</code>, <code>JIRA_ISSUE_TYPE</code>, <code>HEALIFY_WEBHOOK_URL</code>.</li>
<li><strong>feat(cli): <code>healify report [reporte.json] [--dry-run]</code></strong> — cierra el loop desde la terminal.
<code>--dry-run</code> imprime qué se reportaría sin tocar la red. Sin config <code>agile</code>, avisa que está
desactivado y no hace nada.</li>
</ul>
<h2 id="160--2026-08-03">1.6.0 — 2026-08-03</h2>
<p>Tres features nuevas salidas de un gap analysis contra 15 proyectos del rubro
(<code>docs/research/competitive-gaps.md</code>), más el hardening de release. 601 tests (43 archivos),
0 warnings de lint.</p>
<h3 id="motor">Motor</h3>
<ul>
<li><strong>feat(probe): shadow DOM abierto e iframes same-origin.</strong> <code>BROWSER_PROBE_SCRIPT</code> hacía un
<code>document.querySelectorAll</code> plano, que no ve nada dentro de un <code>shadowRoot</code> ni de un iframe.
En una app hecha con web components (Salesforce Lightning, Ionic, Lit, Vaadin) devolvía lista
vacía y el motor degradaba <strong>en silencio</strong> a la heurística a ciegas: toda sugerencia salía
<code>verified: false</code> justo donde más falta hacía la evidencia. Afectaba a 3 de los 4 adapters
(Selenium, WebdriverIO, Cypress); Playwright no lo sufre porque su snapshot ya pierce shadow
DOM. Ahora el scan es recursivo, con topes duros (<code>MAX_DEPTH=12</code>, <code>MAX_NODES=3000</code>) y los
iframes cross-origin envueltos en <code>try/catch</code> para que uno de ads no mate el scan entero.</li>
<li><strong>feat(core): <code>PageElement.frame</code>.</strong> Lo que vive dentro de un iframe se marca como tal: un
locator a nivel top no lo encuentra, hay que entrar al frame primero. La sugerencia sigue
saliendo (es la mejor pista que hay) pero con confianza 0.88 y diciendo explícitamente que
falta el <code>frameLocator()</code> / <code>switchTo().frame()</code>. El shadow DOM <strong>no</strong> se marca: es el mismo
contexto de locator. <code>bestElementFor</code>/<code>bestNameFor</code> hacen dos pasadas — el documento principal
siempre le gana al iframe.</li>
</ul>
<h3 id="cli">CLI</h3>
<ul>
<li><strong>feat(fix): fallback a page objects.</strong> <code>fix()</code> buscaba el selector solo en <code>case.testFile</code>.
En cualquier proyecto con Page Object Model —la arquitectura estándar de e2e— el selector vive
en <code>pages/login.page.ts</code>, así que el <strong>100%</strong> de las curaciones se reportaba como
<code>saltado: ya no se encontró en el archivo</code>. Ahora, cuando no está en el spec, se busca en el
resto del código del proyecto con un walker propio (sin <code>glob</code>, sin dependencias nuevas),
determinista y con topes duros. Conservador con el mismo criterio de siempre: aplica solo si
hay <strong>un</strong> archivo con <strong>una</strong> ocurrencia; con dos candidatos reporta ambiguo. <code>outcome.appliedIn</code>
dice en qué archivo se tocó. Flag <code>--no-pom</code> para el comportamiento anterior.
<ul>
<li>Limitación conocida: <code>fix-ast</code> (la reescritura <code>page.click</code> → <code>page.getByRole</code>) sigue mirando
solo el spec, porque el call site vive ahí aunque el string esté en el page object.</li>
</ul>
</li>
</ul>
<h3 id="configuración">Configuración</h3>
<ul>
<li><strong>feat(config): umbrales configurables.</strong> <code>healEnabled</code>, <code>minConfidence</code>, <code>reviewConfidence</code> y
<code>maxAlternatives</code> — los equivalentes de <code>heal-enabled</code>, <code>score-cap</code> y <code>recovery-tries</code> de
<code>healenium.properties</code>. Antes el 0.90 que decide si <code>fix</code> puede tocar un archivo era una
constante de módulo.</li>
<li><strong>feat(config): <code>healify.config.js</code> / <code>.cjs</code></strong> (CommonJS, carga síncrona con <code>createRequire</code>
para que sirva igual en el bundle ESM y en el CJS). Un <code>.js</code> que resulte ser ESM se captura y
cae al siguiente candidato en vez de romper la corrida de tests.</li>
<li><strong>feat(config): overrides por entorno.</strong> <code>HEALIFY_HEAL_ENABLED</code>, <code>HEALIFY_MIN_CONFIDENCE</code>,
<code>HEALIFY_REVIEW_CONFIDENCE</code>, <code>HEALIFY_MAX_ALTERNATIVES</code> pisan el archivo — el análogo del
<code>-Dheal-enabled=false</code> de Healenium para un job de CI puntual. Un valor que no parsea se ignora.</li>
<li><strong>fix(core): la config del proyecto ahora llega al reporte.</strong> <code>loadConfig()</code> solo lo llamaba
<code>explain</code>; los adapters usan <code>runLocalHealing()</code>, que nunca la recibía. O sea que
<code>customTestIds</code> y <code>customSynonyms</code>, documentados como config del proyecto, <strong>no tenían ningún
efecto sobre el reporte real</strong>. Bug silencioso, no feature faltante. Playwright y Cypress ahora
la cargan una vez por corrida y se la pasan al motor.</li>
</ul>
<h3 id="github-action">GitHub Action</h3>
<ul>
<li><strong>fix(gh-action): la action nunca podía arrancar.</strong> <code>run.js</code> hacía
<code>await import('@octokit/action')</code> con un comentario que decía &ldquo;bundled with the action runtime&rdquo;,
pero no estaba bundleada ni <code>gh-action/node_modules</code> versionado — y una action <code>node20</code> ejecuta
<code>main</code> directo, GitHub no corre <code>npm install</code>. La primera PR real que la usara moría con
<code>ERR_MODULE_NOT_FOUND</code>. Se reemplazó por un cliente de ~60 líneas sobre <code>fetch</code>: la action pasa
a tener <strong>cero dependencias de runtime</strong>, en línea con el resto del proyecto.</li>
<li><strong>fix(gh-action): paginación de comentarios.</strong> Se leía solo la primera página (100): en una PR
larga no encontraba su propio comentario y publicaba uno nuevo en cada push.</li>
<li><strong>feat(gh-action): publicable en el Marketplace.</strong> <code>action.yml</code> se movió a la raíz del repo
(requisito de GitHub para publicar; el código sigue en <code>gh-action/</code>). Se documentó el uso y el
permiso <code>pull-requests: write</code> en el README.</li>
<li>Errores de la API ahora incluyen el detalle que devuelve GitHub — sin eso, un permiso faltante
se veía como un 403 pelado.</li>
</ul>
<h3 id="ci--release">CI / release</h3>
<ul>
<li><strong>CI: matriz de Node 18/20/22</strong> en Ubuntu y Windows. <code>engines</code> prometía <code>&gt;=18</code> sin que nadie lo
corriera; 22 además es donde cambia el <code>require()</code> de ESM, que es justo lo que hace el loader de
<code>healify.config.js</code>.</li>
<li><strong>CI: job de lint</strong> con <code>--max-warnings=0</code>. &ldquo;0 warnings&rdquo; era una propiedad prometida sin nada que
la sostuviera en CI.</li>
<li><strong>Release con npm provenance</strong> (<code>.github/workflows/release.yml</code>): npm firma de forma verificable
desde qué commit y qué workflow salió cada tarball. Requiere <code>repository.url</code> en cada
<code>package.json</code> — agregado en los 7 paquetes, junto con <code>homepage</code> y <code>bugs</code>.</li>
</ul>
<h2 id="150--2026-07-31">1.5.0 — 2026-07-31</h2>
<ul>
<li><strong>feat(cli): <code>healify explain &lt;selector&gt;</code></strong> — explica por qué un selector es frágil, su
clasificación (TESTID/ROLE/CSS/XPATH), confidence, issue detectado y fix propuesto. Reusa
100% <code>analyzeAndHeal()</code> de <code>healing-engine.ts</code>. Sin args, lee el último caso de
<code>healify-report.json</code>. Flag <code>--json</code> para output machine-readable (puente Python/Java/C#).</li>
<li><strong>feat(core): <code>customTestIds</code> configurable</strong> — via <code>healify.config.json</code>
(<code>{ &quot;customTestIds&quot;: [&quot;data-cy-custom&quot;] }</code>) o <code>package.json</code> (<code>{ &quot;healify&quot;: { ... } }</code>).
Se mergea con los 5 defaults (<code>data-testid</code>, <code>data-cy</code>, <code>data-qa</code>, <code>data-test</code>,
<code>data-e2e</code>). Solo acepta atributos que empiecen con <code>data-</code>; los demás se descartan
silenciosamente. Disponible también vía el puente <code>healify heal</code> (JSON stdin).</li>
<li><strong>nuevo: <code>reporter-core/src/config.ts</code></strong> — <code>loadConfig(cwd)</code> lee <code>healify.config.json</code> o
<code>package.json → healify</code>, valida y retorna <code>HealifyConfig</code>.</li>
<li><strong>tests: 475 (+16)</strong> — 6 en <code>healing-engine.test.ts</code> (customTestIds), 2 en
<code>heal-command.test.ts</code> (paso de customTestIds), 8 en <code>explain-command.test.ts</code> (nuevo).</li>
</ul>
<h2 id="140--combinadores-css-compuestos">1.4.0 — combinadores CSS compuestos</h2>
<p>Último hueco documentado como &ldquo;fuera de alcance a propósito&rdquo;: el motor no reconocía
selectores con combinador (<code>.padre &gt; .hijo</code>, <code>.card .title</code>, <code>div + span</code>) como un patrón
propio — dependen de la relación exacta entre dos elementos en el DOM, no solo del elemento
buscado, y se rompen con un wrapper nuevo o un reordenamiento de hermanos aunque el elemento
buscado no haya cambiado en nada.</p>
<ul>
<li><strong>Detección</strong> (<code>hasCompoundCombinator</code>): marca el selector como frágil y explica por qué —
antes, un selector así sin keyword de acción reconocible (<code>.card .price</code>) quedaba con
<code>detectedIssue: &quot;Selector pattern analysis&quot;</code>, un placeholder sin información real.</li>
<li><strong>Bug real arreglado — el fallback roto para selectores compuestos sin keyword</strong>: sin
ninguna estrategia aplicable, el motor caía a <code>visible=${selector.replace(/[.#]/, '')}</code> —
sin flag <code>/g</code>, solo recorta el PRIMER <code>.</code>/<code>#</code> de todo el selector. Para <code>.card .price</code> eso
daba <code>visible=card .price</code>, ni CSS válido. Ahora se propone conservar solo el elemento
objetivo (<code>extractCombinatorTarget</code>, el último segmento después del combinador más a la
derecha): <code>.card .price</code> → <code>.price</code>, <code>.sidebar &gt; .username</code> → <code>.username</code>.</li>
<li><strong>Bug real arreglado — testid del ancestro en vez del objetivo</strong>: con dos testids
compuestos (<code>[data-testid=&quot;product-card&quot;] [data-testid=&quot;add-to-cart-btn&quot;]</code>),
<code>extractTestid()</code> (sin <code>/g</code>) tomaba el primer match de todo el string — el del ancestro,
no el del elemento que el selector busca en definitiva. Ahora extrae el testid del target.</li>
<li><strong>Sin falsos positivos</strong>: un espacio adentro de <code>has-text('Add to cart')</code> o del valor de un
atributo (<code>[aria-label=&quot;Cerrar sesión&quot;]</code>) no se confunde con un combinador descendiente
(<code>maskQuotedContent</code> enmascara el contenido entre comillas antes de buscar el combinador,
preservando índices para no perder el segmento objetivo real).</li>
<li><strong>Sin cambio de comportamiento donde ya andaba bien</strong>: selectores compuestos con un keyword
de acción reconocible (<code>form.checkout &gt; button.submit</code> → sigue proponiendo
<code>role('button', { name: 'Submit' })</code>) o con posición (<code>nth-child</code>/<code>nth-of-type</code>, que ya
tenía su propio fallback) no cambian de resultado — verificado con el snapshot de 37
selectores (antes 34) del corpus de heurística.</li>
<li>12 tests nuevos (3 snapshot + 9 unitarios), <strong>203 tests</strong> en <code>reporter-core</code> (antes 191),
<strong>459 en total</strong> en los 6 workspaces.</li>
</ul>
<h2 id="130--cypress-en-vivo--multi-lenguaje">1.3.0 — Cypress en vivo + multi-lenguaje</h2>
<h3 id="cypress-curado-en-vivo-contra-el-dom-real">Cypress: curado en vivo contra el DOM real</h3>
<p>Cypress era el único de los cuatro frameworks soportados sin verificación contra el DOM real:
solo un reporter pasivo, heurística sobre el texto del error, post-hoc. La razón: Cypress no
expone un gancho para envolver <code>cy.get()</code> sin pisar su propio motor de retry-ability, a
diferencia de Selenium/WebdriverIO (que exponen <code>findElement</code>/<code>$</code> directo) — hacía falta un
comando nuevo, no un wrap del existente.</p>
<ul>
<li><strong><code>cy.healifyGet(selector, options?)</code></strong> (<code>@healify/cypress-plugin/support</code>, nuevo entry
point): como <code>cy.get()</code>, pero si el selector no aparece dentro del timeout, sondea el DOM
real vía <code>BROWSER_PROBE_SCRIPT</code> (mismo script que Selenium/WebdriverIO, corrido en la
ventana de la app bajo test, no en la del test-runner de Cypress — un error real encontrado
en la verificación: <code>new Function()</code> a secas corre en el scope global equivocado), pide una
curación verificada a Healify y reintenta con la sugerencia (CSS o XPath) antes de fallar.
Opciones: <code>timeout</code> (default: <code>defaultCommandTimeout</code>), <code>confidenceThreshold</code> (default 0.9,
igual que selenium-plugin/webdriverio-plugin).</li>
<li><strong>Puente browser↔Node vía <code>cy.task</code></strong>: Cypress corre el spec en el browser y el motor
(<code>analyzeAndHeal</code>, repertorio) en Node — dos procesos separados, a diferencia de
Selenium/WebdriverIO donde ambos viven en el mismo proceso. <code>plugin.ts</code> registra
<code>healify:probe-script</code> (devuelve el script), <code>healify:heal</code> (corre el motor, consulta) y
<code>healify:record-event</code> (recibe el resultado del retry ya resuelto en el browser). El caso
vivo se suma al mismo <code>healify-report.json</code> que el modo reporte, aunque el test haya
<strong>pasado</strong> (Cypress nunca lo ve como fallido: se curó antes de llegar a fallar).</li>
<li>Verificado real: Cypress 15 + Chrome headless contra una página HTML servida en local — un
selector roto a propósito curado y clickeado de punta a punta (<code>verified: true</code> en el
reporte), y un selector genuinamente irrecuperable fallando limpio sin romper la corrida.</li>
</ul>
<h3 id="multi-lenguaje-healify-heal">Multi-lenguaje: <code>healify heal</code></h3>
<p>Hasta acá Healify era JS/TS puro. Un equipo que automatiza con pytest+Selenium (Python) o
JUnit+Selenium (Java) no podía usarlo. El motor mismo es agnóstico (recibe un string, devuelve
un string) — lo único atado a Node era cómo se lo invocaba.</p>
<ul>
<li><strong><code>healify heal</code></strong> (nuevo comando): el motor entero — heurística, verificación contra la
página, repertorio — expuesto como JSON por stdin/stdout. Cualquier lenguaje que pueda
spawnear un subproceso lo usa, sin reescribir nada. Devuelve un <code>locator</code> ya resuelto
(<code>{ strategy: 'css'|'xpath'|'unsupported', value }</code>) — el cliente no necesita entender la
sintaxis <code>role(...)</code> de Playwright.</li>
<li><strong><code>healify probe-script</code></strong> (nuevo comando): imprime el script JS que hay que correr con el
<code>execute_script</code>/equivalente de cualquier driver para sondear el DOM — el mismo que ya usan
los plugins de Selenium/WebdriverIO en JS, reusado tal cual.</li>
<li><strong>El repertorio se consulta del lado del servidor</strong>: <code>heal</code> lee <code>.healify/history.jsonl</code> en
cada invocación. Si dos lenguajes corren contra el mismo repo (ej. Playwright en JS y
pytest en Python), comparten repertorio — una curación verificada en un lenguaje resuelve
un selector roto en el otro, verificado real con el binario: una entrada grabada a mano
(simulando un adapter de Python) fue reusada por una segunda llamada a <code>heal</code> sin DOM,
marcando <code>fromRepertoire: true</code>, y una tercera llamada con <code>testFile</code> distinto correctamente
NO la reusó.</li>
<li><strong>Adapters de referencia</strong> (no paquetes publicados — código para copiar y adaptar, ver
<code>docs/adapters/</code>):
<ul>
<li><strong>Python</strong> (<code>docs/adapters/python/healify_selenium.py</code>): verificado de punta a punta con
Selenium 4.46 y Chrome real (Selenium Manager). Encontró y corrigió un bug real de
portabilidad: <code>subprocess.run([&quot;npx&quot;, ...])</code> sin <code>shell=True</code> no resuelve <code>npx.cmd</code> en
Windows (<code>[WinError 2]</code>) — se resuelve con <code>shutil.which</code>.</li>
<li><strong>Java</strong> (<code>docs/adapters/java/HealifySeleniumWrapper.java</code>): compila real contra
selenium-java 4.27 (resuelto con una Maven portable, sin instalar nada). El puente a
<code>healify heal</code> (subproceso + parseo del JSON real) se verificó de punta a punta. El
<code>ChromeDriver</code> en vivo no se pudo correr en esta sesión por un bug de red del JDK 17 de
esta máquina (<code>java.net.http</code> roto para cualquier uso, confirmado con un repro de 4
líneas sin Selenium de por medio) — no es un defecto de Selenium ni de Healify.</li>
<li><strong>C#</strong> (<code>docs/adapters/csharp/HealifySeleniumWrapper.cs</code>): <strong>sin verificar</strong> — no hay SDK
de .NET en esta máquina. Marcado explícito en el propio archivo.</li>
</ul>
</li>
<li>Dedup: <code>resolveLocatorStrategy</code> (reporter-core) reemplaza la lógica que vivía duplicada e
inline en <code>selenium-plugin</code>/<code>webdriverio-plugin</code> para convertir <code>role(...)</code> a XPath — ahora
la comparten esos dos plugins JS y el comando <code>heal</code>. Cero cambio de comportamiento
(verificado: sus 39 + 28 tests no se movieron).</li>
</ul>
<h2 id="120--repertorio-consultable--modo-interactivo">1.2.0 — repertorio consultable + modo interactivo</h2>
<p>Los dos huecos que quedaban del pedido original: memoria entre corridas, y que el
desarrollador pueda decidir caso por caso en vez de todo-o-nada.</p>
<ul>
<li><strong>Repertorio</strong>: <code>.healify/history.jsonl</code> ahora se <strong>consulta</strong>, no solo se escribe. Cuando
una corrida no puede verificar nada por su cuenta (Cypress, siempre; o cualquier adapter si
el snapshot/sondeo no estuvo disponible esa vez), el motor busca si ese mismo selector, en
el mismo archivo, ya se curó y <strong>se confirmó contra la página real</strong> en una corrida
anterior — y reusa esa corrección en vez de volver a adivinar a ciegas.
<ul>
<li>Solo cuentan las entradas <code>verified: true</code>. Reusar una curación a ciegas no aporta nada
(la heurística es determinística, recalcularla da lo mismo) — el valor real está en
cargar hacia adelante una confirmación que sí costó algo conseguir.</li>
<li>La verificación en vivo de la corrida actual <strong>siempre gana</strong> sobre el repertorio: la
página de ahora es más confiable que la memoria de una corrida vieja.</li>
<li>Verificado con Playwright real: un selector se curó y verificó, quedó en el historial con
<code>verified: true</code>; en una segunda corrida <strong>sin</strong> snapshot (<code>PLAYWRIGHT_NO_COPY_PROMPT=1</code>),
el motor reusó esa misma corrección marcando <code>fromRepertoire: true</code>.</li>
</ul>
</li>
<li><strong><code>fix --interactive</code></strong>: en vez de aplicar todo lo que supera el umbral automático, muestra
cada sugerencia (selector, propuesta, confianza, si está verificada o viene del repertorio)
y pregunta. Ofrece también los casos <code>review</code> (80-89%, hoy invisibles para <code>fix</code>) — el
desarrollador puede aplicar algo de menor confianza si decide que tiene sentido, cosa que
antes no existía en ningún lado. <code>a</code> aplica el resto sin seguir preguntando, <code>q</code> corta y deja
el resto sin tocar. Sin terminal real (CI, pipe) avisa y sigue en modo automático — nunca se
cuelga esperando un input que no puede llegar.</li>
<li>Dedup: el parseo de <code>.healify/history.jsonl</code> vivía duplicado en el motor conceptualmente —
ahora <code>parseHistoryLines</code>/<code>readRepertoire</code> viven en <code>reporter-core</code> y <code>cli</code> los reusa.</li>
</ul>
<h3 id="selenium-y-webdriverio-también-verifican-contra-la-página-real">Selenium y WebdriverIO también verifican contra la página real</h3>
<p>El bloque anterior le dio a Playwright acceso al árbol de accesibilidad real (el archivo que
Playwright ya escribe al fallar un test). Selenium y WebdriverIO se quedaron afuera porque no
tienen ese archivo — pero tienen algo mejor: el browser vivo en la mano, en el momento exacto
del fallo. <code>driver.executeScript()</code>/<code>browser.execute()</code> permiten consultar el DOM real ahí
mismo, sin depender de que ningún framework les regale nada.</p>
<ul>
<li><strong>Sondeo del DOM en vivo</strong> (<code>reporter-core/src/browser-probe.ts</code>): script JS plano que corre
dentro del browser, recorre los elementos interactivos y calcula rol + nombre accesible con
el mismo criterio en toda la escalera (aria-label → texto visible → placeholder → value).</li>
<li><strong>Las sugerencias de rol ahora se pueden aplicar</strong>: Selenium/WebdriverIO no interpretan
<code>role('button', { name: 'Comprar' })</code> (es sintaxis de Playwright), así que antes se
descartaban siempre. Ahora se convierten a un XPath real
(<code>reporter-core/src/role-locator.ts</code>) que busca por el mismo criterio de nombre — el mismo
elemento que originó la sugerencia.</li>
<li><strong>Verificado con Chrome real, no solo con mocks</strong>: usando <code>selenium-webdriver</code> con Selenium
Manager (detecta el Chrome instalado solo, sin configuración) y <code>webdriverio</code> conectado
directo al chromedriver que Selenium Manager resolvió. Los tres roles principales (botón,
link, campo de texto) curados de punta a punta contra un browser de verdad.</li>
<li><strong>Bug real encontrado en esa verificación — WebdriverIO 9.x nunca curaba en la práctica</strong>:
el detector de &ldquo;elemento no encontrado&rdquo; buscaba el wording viejo (<code>&quot;element not found&quot;</code>);
el mensaje real de wdio 9.x es <code>&quot;...because element wasn't found&quot;</code> (distinto), así que el
healing nunca se disparaba con esta versión, aunque los tests con mocks (que usaban el
wording viejo) pasaran igual. No es algo que este bloque haya introducido — estaba roto
desde antes y solo se vio al probar contra un driver real.</li>
<li>Dedup: <code>parseRoleSuggestion</code> (antes duplicado dentro de <code>healing-engine.ts</code>) ahora vive en
<code>role-locator.ts</code> y lo comparten el motor y los dos plugins.</li>
</ul>
<h3 id="el-motor-mira-la-página-real">El motor mira la página real</h3>
<p>Hasta acá el motor recibía un string y devolvía otro, adivinando nombres por diccionario: de
ahí salían sugerencias como <code>role('link', { name: 'Submit' })</code> para un <code>&lt;a&gt;</code> cualquiera, sin
ninguna evidencia de que ese texto existiera. Sobre un corpus de 34 selectores realistas, los
únicos arreglos que <code>fix</code> llegaba a aplicar eran casos que ya estaban bien.</p>
<p>Playwright, resulta, ya guarda el árbol de accesibilidad de la página cada vez que un test
falla (<code>error-context.md</code>). Estaba ahí, en disco, sin usar.</p>
<ul>
<li><strong>Las sugerencias se confrontan contra la página</strong>: si el motor propone un rol y un nombre
que no existen en pantalla, la sugerencia se descarta en vez de ofrecerse.</li>
<li><strong>Los nombres se leen de la página, no se deducen</strong>: un <code>#comprar-ahora-a1b2c3</code> roto ahora
resuelve a <code>role('button', { name: 'Comprar' })</code> con el texto real del botón. La confianza
sube a 97% y, a diferencia de antes, está justificada.</li>
<li><strong>Marca <code>verificada</code> en los tres formatos</strong>: el reporte distingue lo comprobado contra la
página de lo deducido del texto del selector. El usuario tiene derecho a saber cuál está
leyendo.</li>
<li><strong>Si nada coincide, se dice</strong>: cuando ninguna sugerencia sobrevive el contraste, el reporte
avisa que el elemento puede haber desaparecido — el defecto no es el selector, es la
funcionalidad. Para un QA eso vale más que un candidato inventado.</li>
<li><strong><code>fix</code> reescribe <code>role(...)</code> por defecto</strong>: <code>page.click('#x')</code> pasa a
<code>page.getByRole('button', { name: 'Comprar' }).click()</code>. La reescritura ya existía pero
estaba detrás de <code>--ast</code>, marcada como experimental, así que en la práctica casi nada se
aplicaba. Se puede desactivar con <code>--no-ast</code>; <code>--ast</code> se sigue aceptando y no hace nada.</li>
<li>Sin dependencias nuevas y sin cambiar cómo se escriben los tests: el dato ya estaba, solo
había que leerlo. Sigue sin haber IA, red ni servidor.</li>
</ul>
<p><strong>Verificado de punta a punta, por primera vez</strong>: un test que fallaba por un selector roto,
arreglado solo por <code>fix</code>, vuelve a correr y <strong>pasa</strong>. Hasta ahora nunca se había comprobado
que un arreglo aplicado por Healify dejara el test en verde.</p>
<p>Por ahora solo Playwright. Cypress, Selenium y WebdriverIO siguen con la heurística a ciegas
y lo dicen en el reporte.</p>
<h3 id="el-reporte-pasa-a-ser-un-entregable-de-qa">El reporte pasa a ser un entregable de QA</h3>
<p>El reporte servía para ver selectores rotos, pero no como entregable: no tenía veredicto, ni
severidad, ni entorno, ni evidencia. Y había un agujero — si todos los tests pasaban no se
generaba ningún archivo, así que no había forma de distinguir &ldquo;salió todo bien&rdquo; de &ldquo;no se
corrió nada&rdquo;.</p>
<ul>
<li><strong>Veredicto PASS/FAIL</strong> y <strong>el reporte se escribe siempre</strong>, también con la suite entera en
verde. Sale del resultado real de la corrida, no de cuántos selectores curó Healify.</li>
<li><strong><code>healify-report.md</code> nuevo</strong>: reporte de defectos en Markdown, listo para pegar en un
ticket o en un informe, con un bloque por defecto ordenado de más grave a menos grave.</li>
<li><strong>ID de defecto estable</strong> (<code>HLF-A1B2C3</code>): el mismo selector roto en el mismo archivo da
siempre el mismo ID, en cualquier máquina. Es el cimiento para reconocer defectos repetidos
contra el historial más adelante.</li>
<li><strong>Severidad</strong> derivada del estado con una regla fija: sin sugerencia es bloqueante, a
revisar es mayor, sanado es menor.</li>
<li><strong>Resultado esperado vs. obtenido, pasos para reproducir y evidencia</strong>: los pasos salen de
los que Playwright registró de verdad y la evidencia enlaza al screenshot que el framework
ya escribió en disco. Nada se inventa: el adapter que no tiene un dato lo omite.</li>
<li><strong>Entorno</strong> en el reporte: framework y versión, navegador, URL base, sistema, Node y
duración.</li>
<li><strong>Bug encontrado verificando con Playwright real</strong>: la ubicación del test se guardaba como
ruta absoluta, así que el reporte filtraba la estructura de carpetas de quien lo corría y
—peor— el ID de defecto no coincidía entre dos personas del mismo equipo. Ahora es relativa
al proyecto.</li>
<li><strong>Bug en el plugin de Cypress</strong>: <code>after:run</code> no siempre recibe resultados; leerlos sin
chequear hacía que el reporte no se escribiera nunca en esos modos.</li>
<li><code>fix</code> sobre una corrida limpia ahora dice &ldquo;ningún selector roto en la última corrida&rdquo; en vez
de un escueto &ldquo;0 aplicados · 0 salteados&rdquo;.</li>
</ul>
<h3 id="init-te-muestra-cómo-escribir-el-primer-test"><code>init</code> te muestra cómo escribir el primer test</h3>
<p>Después de <code>init</code>, correr <code>npx playwright test</code> daba <code>No tests found</code>: correcto (Healify
nunca genera tests), pero el mensaje decía &ldquo;escribí tu primer test en <code>e2e/</code>&rdquo; sin mostrar
cómo, asumiendo una sintaxis que el público objetivo declarado del proyecto no tiene por
qué saber.</p>
<ul>
<li><strong><code>init</code> ahora imprime un snippet mínimo y real</strong>, ajustado al proyecto: <code>.ts</code> o <code>.js</code>
según tengas TypeScript, y <code>require</code> en vez de <code>import</code> si tu <code>package.json</code> es CommonJS
— antes el mensaje pedía un archivo <code>.ts</code> incluso en proyectos donde acababa de
scaffoldear un <code>playwright.config.js</code>. Sigue sin escribir ningún archivo: el selector es
un placeholder explícito (<code>#reemplazar-por-tu-selector-real</code>) que el usuario tiene que
cambiar por uno de su propia app.</li>
<li><strong><code>FrameworkInitResult</code> expone <code>ext</code> y <code>moduleType</code></strong>, la misma forma del proyecto que se
usó para scaffoldear, para que el mensaje final no pueda contradecir lo que se escribió.</li>
<li><strong>READMEs</strong>: sección &ldquo;Tu primer test, paso a paso&rdquo; con el snippet, qué hace cada línea,
cómo sacar un selector real con DevTools, y la aclaración de correr el framework que ya
se detectó (probar Cypress en un proyecto Playwright-only falla por falta de Cypress, no
por Healify).</li>
</ul>
<h2 id="111--red-de-seguridad-de-tests--fix-de-tipos-en-webdriverio">1.1.1 — red de seguridad de tests + fix de tipos en WebdriverIO</h2>
<blockquote>
<p>Solo <code>@healify/webdriverio-plugin</code> sube a 1.1.1: es el único paquete cuyo código cambió.
Los otros cuatro siguen en 1.1.0 — <code>reporter-core</code> (que se bundlea dentro de todos) no se
tocó, así que republicarlos no cambiaría un solo byte.</p>
</blockquote>
<ul>
<li><strong>Snapshot de la heurística</strong> (<code>reporter-core/src/__tests__/heuristic-corpus.test.ts</code>): 34
selectores reales (IDs generados por frameworks, clases hasheadas de CSS-in-JS, XPath de
grabadores, los cinco atributos testid, posicionales, locators modernos de Playwright)
congelan la salida completa de <code>analyzeAndHeal()</code>. Cualquier retoque de estrategias o
prioridades rompe el snapshot y obliga a revisar el diff antes de aceptarlo, en vez de
cambiar el comportamiento del motor sin que nadie lo note.</li>
<li><strong>Los scaffolds ahora se compilan de verdad</strong>
(<code>cli/src/__tests__/scaffold-compiles.test.ts</code>): cada archivo que <code>init</code> escribe en el
proyecto del usuario se vuelca a un directorio temporal y pasa por <code>tsc --noEmit</code> contra
las dependencias reales. Antes solo se comparaban strings, así que un import roto o un
tipo inválido pasaba desapercibido.</li>
<li><strong>Bug real que encontró ese test — <code>HealifyWebdriverIOPlugin.wrap()</code> no aceptaba un
browser de WebdriverIO</strong>: <code>wrap(browser: Record&lt;string, unknown&gt;)</code> rechazaba
<code>WebdriverIO.Browser</code> (interfaz sin index signature), o sea que el ejemplo generado por
<code>init</code> no compilaba en un proyecto real. Ahora la firma es genérica
(<code>wrap&lt;T extends object&gt;(browser: T): T</code>), que además le conserva al usuario el tipado y
el autocompletado de su propio browser.</li>
</ul>
<h2 id="110--auditoría-tech-lead-correcciones--deuda-técnica">1.1.0 — auditoría Tech Lead (correcciones + deuda técnica)</h2>
<p>Ronda de correcciones sobre el código real tras una auditoría tipo Tech Lead (revisión de
<code>reporter-core</code>, adapters, CLI y el spec de historial). Nada de esto es feature nueva:
son bugs reales, deduplicación y ampliación de cobertura sobre lo que ya existía.</p>
<ul>
<li><strong>Bug real arreglado — <code>init</code> scaffoldeaba Selenium para proyectos WebdriverIO</strong>:
<code>cli/src/scaffold.ts</code> no tenía un scaffold propio para WebdriverIO; <code>scaffoldFilesFor()</code>
caía por fallback implícito al ejemplo de Selenium (imports de <code>selenium-webdriver</code> en un
proyecto que usa <code>webdriverio</code>). Ahora <code>scaffoldWebdriverio()</code> genera su propio archivo de
referencia (<code>healify.wdio.example.ts</code>), <code>init.ts</code> distingue explícitamente cada framework
sin fallback implícito, y el prompt interactivo (<code>prompt.ts</code>) ya ofrece <code>webdriverio</code> como
opción.</li>
<li><strong>Deduplicación en <code>reporter-core</code></strong>: <code>buildLocalRunFromEvents()</code> e
<code>isPlaywrightOnlySelector()</code> (antes duplicadas casi 1:1 en <code>selenium-plugin</code> y
<code>webdriverio-plugin</code>) se movieron a <code>reporter-core</code> y ambos adapters las reusan. Sin
cambio de comportamiento observable — refactor puro, mismos tests en verde.</li>
<li><strong>Heurística ampliada</strong>: <code>analyzeAndHeal()</code> reconoce ahora las convenciones de testid
<code>data-qa</code>/<code>data-test</code>/<code>data-e2e</code> (antes solo <code>data-testid</code>/<code>data-cy</code>), y detecta
selectores basados en posición (<code>nth-child</code>/<code>nth-of-type</code>) como frágiles, proponiendo un
<code>role()</code> genérico en vez de dejarlos caer al fallback ciego — sigue siendo pattern-matching
sobre el texto del selector, sin tocar DOM real.</li>
<li><strong>UX del CLI mejorada</strong>: <code>doctor</code> explica el gotcha de semver caret con un ejemplo
numérico concreto; <code>fix</code> distingue <code>EACCES</code>/<code>EPERM</code> (permisos denegados, archivo abierto
en otro proceso) del error técnico genérico; <code>init</code> ya no confunde &ldquo;no pude verificar el
puerto en este entorno&rdquo; con &ldquo;puerto libre&rdquo; al no tener PowerShell disponible.</li>
<li><strong>Feature #8 (reporte histórico) documentada como IMPLEMENTADA</strong>: el spec quedó
desactualizado como &ldquo;pendiente&rdquo; cuando el código (<code>cli/src/history.ts</code>,
<code>cli/src/commands/history.ts</code>, <code>appendHistory()</code> en <code>runFix()</code>) ya estaba en el repo.
Riesgos de concurrencia (escritura simultánea al <code>.jsonl</code>) y de línea corrupta por
escritura interrumpida quedan documentados y asumidos por diseño MVP — sin locks, hasta
que haya evidencia real de que hace falta.</li>
</ul>
<p>Verificado con <code>npm run verify</code>: 258 tests en verde en los 6 workspaces.</p>
<p><strong>Limpieza documental</strong>: se borraron 13 archivos <code>.md</code> de planes/specs/logs de auditoría
de features ya implementadas (<code>docs/superpowers/plans/</code>, <code>docs/superpowers/specs/</code>,
<code>docs/audit-0.4.1.md</code>, <code>docs/audit-0.5.0.md</code>) y el <code>HANDOFF.md</code> de la raíz (duplicaba
<code>CONTEXT_HANDOFF.md</code>). Solo quedan README/CHANGELOG/CONTEXT_HANDOFF/CLAUDE.md y el manual
de usuario en <code>docs/guide/</code>.</p>
<h2 id="100--primera-versión-estable">1.0.0 — Primera versión estable</h2>
<p>Los 6 paquetes (<code>reporter-core</code>, <code>test-runner</code>, <code>cypress-plugin</code>, <code>selenium-plugin</code>,
<code>webdriverio-plugin</code>, <code>cli</code>) pasan a 1.0.0 juntos. No es una feature nueva: es la
declaración de que la superficie pública está estable y el producto es presentable de
punta a punta. Lo que entró en esta versión, todo encontrado o pulido probando la
herramienta como la usaría un tercero:</p>
<p><strong>Arreglos de UX (evitan la mala primera impresión):</strong></p>
<ul>
<li><code>healify --version</code> / <code>-v</code>: antes no había forma de que un usuario chequee qué versión
tiene. Es justo el gap que hace que alguien con una versión vieja instalada (el pozo del
caret <code>^0.x</code>, que no sube de minor con un <code>npm install</code> a secas) no se dé cuenta y vea
comportamiento viejo. Ahora <code>healify --version</code> lo dice.</li>
<li><code>fix</code> sin <code>healify-report.json</code>: antes tiraba el <code>ENOENT</code> crudo de Node + exit 1. Pero un
<code>fix</code> sin reporte no es un error: es lo normal cuando los tests pasaron (ningún selector
roto). Ahora da un mensaje que explica qué hacer y sale con exit 0 (no rompe pipelines).
JSON corrupto sigue siendo error real (exit 1).</li>
</ul>
<p><strong>Presentación (lo que ve alguien que evalúa el repo):</strong></p>
<ul>
<li>Badge de tests estático &ldquo;238 verdes&rdquo; (mentía si un test fallaba) reemplazado por el badge
real de GitHub Actions. Badges de WebdriverIO, coverage (~85% real) y MIT agregados.</li>
<li>Demo &ldquo;En 30 segundos&rdquo; en el README con salida REAL capturada (init → test rompe →
<code>fix --ast</code> reescribe el archivo), no inventada. Reporte HTML real navegable en
<code>docs/ejemplos/</code>.</li>
<li>Coverage medido de verdad (<code>@vitest/coverage-v8</code> + <code>npm run coverage</code>), con tabla honesta
por paquete en el README (motor <code>reporter-core</code> ~90%; adapters más finos).</li>
</ul>
<p><strong>Rigor de CI:</strong></p>
<ul>
<li>Tests corren en Ubuntu Y Windows (Healify es sensible a Windows: puertos, PowerShell,
<code>.cmd</code> de npm). <code>typecheck</code> cubre <code>webdriverio-plugin</code>. Nuevos jobs: <code>gh-action</code> (sus
tests no corrían en CI por no ser workspace) y <code>coverage</code>.</li>
</ul>
<p><strong>Higiene de release público:</strong></p>
<ul>
<li>Archivo <code>LICENSE</code> MIT real (antes el README lo declaraba pero el archivo no existía).</li>
<li>README: la mención a <code>archive/saas-full</code> ahora aclara que es una RAMA de git, no una
carpeta de <code>main</code> (un evaluador buscaba la carpeta y no la encontraba).</li>
</ul>
<p>Verificado con <code>npm run verify</code> (los 6 workspaces en verde), <code>npm audit</code> (0
vulnerabilidades) y un smoke real instalando desde npm contra un browser real.</p>
<h2 id="071-test-runner--bug-crítico-real-playwright-timeouts-nunca-curaban">0.7.1 (test-runner) — bug crítico real: Playwright timeouts nunca curaban</h2>
<p>Encontrado probando de verdad contra el paquete publicado (<code>@healify/test-runner@0.7.0</code>
instalado desde npm, no desde el workspace local), con un test real que rompe un botón
real en un navegador real. No es un caso hipotético: es el fallo más común en cualquier
suite de Playwright real (un <code>click()</code>/<code>fill()</code> que nunca encuentra el elemento y hace
timeoutear el test entero).</p>
<p><strong>El bug</strong>: cuando el test entero timeoutea (no una excepción explícita del propio
<code>click()</code>), Playwright reporta el fallo en DOS entradas de <code>result.errors</code>: la primera es
el mensaje genérico <code>&quot;Test timeout of 30000ms exceeded.&quot;</code> (sin selector), y la segunda
tiene el detalle real (<code>page.click: ... Call log: - waiting for locator('#x')</code>).
<code>test-runner/src/reporter.ts</code> solo miraba <code>result.error</code>/<code>result.errors[0]</code>, que en este
caso concreto (probablemente el más frecuente en la práctica) es siempre el mensaje corto
sin selector. Resultado: el caso quedaba <code>unresolved</code> con <code>&quot;Unknown selector&quot;</code>, aunque el
motor heurístico hubiera podido curarlo sin problema si hubiera recibido el mensaje
correcto.</p>
<p>Ninguno de los tests existentes lo detectó porque todos fabricaban un <code>result</code> sintético
donde el mensaje útil ya estaba en el primer lugar que el código miraba, nunca
reproduciendo la forma real del objeto que devuelve Playwright.</p>
<p><strong>Fix</strong>: <code>reporter.ts</code> ahora concatena todos los mensajes de <code>result.errors[]</code> (no solo
el primero) antes de pasarlos a <code>extractSelectorFromError</code>, así encuentra el selector sin
importar en cuál entrada esté. +1 test que reproduce el shape real (dos errores, selector
en el segundo) → 9 tests en test-runner. Verificado con una corrida real de Playwright
contra un selector roto de verdad, antes y después del fix.</p>
<p>Cypress-plugin se probó en paralelo con el mismo método (instalación real desde npm,
selector roto real, navegador real) y no tiene este problema: <code>test.displayError</code> de
Cypress ya trae el mensaje completo en un solo campo, así que la extracción funciona
desde la primera versión. <code>selenium-plugin</code>/<code>webdriverio-plugin</code>/<code>cli</code> no se probaron con
este mismo nivel de rigor en esta pasada (sí tienen sus propios tests unitarios y, en el
caso de <code>cli</code>, verificación con el binario real compilado, pero no una instalación real
desde npm contra un browser real como se hizo acá).</p>
<h2 id="080--feature-8-historial-de-curaciones-mvp">0.8.0 — Feature #8: historial de curaciones (MVP)</h2>
<p><code>healify fix</code> (sin <code>--dry-run</code>) ahora graba cada caso de la corrida en
<code>.healify/history.jsonl</code>. Nuevo comando <code>healify history</code> muestra en terminal los
selectores más recurrentes y los que se rompieron de nuevo después de haber sido curados.</p>
<p>Sin sistema de config, sin export HTML/JSON, sin retención automática — MVP acotado tras
corregir el spec original contra el código real (asumía <code>cli/src/commands/fix.ts</code> y
<code>cli/src/config.ts</code>, que no existen). Detalle completo en
<code>docs/superpowers/specs/2026-07-23-feature8-historical-report-design.md</code>, plan de
implementación en <code>docs/superpowers/plans/2026-07-23-feature8-history-mvp-plan.md</code>
(ejecutado con subagent-driven development: implementador + 2 revisores por task).</p>
<p><code>--dry-run</code> nunca graba (evita ensuciar el historial con las corridas del gh-action en
cada PR). &ldquo;Re-roto&rdquo; es una aproximación documentada: se basa en si la primera aparición
del selector fue <code>status: 'healed'</code> Y hubo al menos una aparición posterior no-healed —
un bug real de esta última condición (dos curaciones seguidas del mismo selector se
contaban como re-roto) se encontró y arregló durante la implementación, no en el diseño.</p>
<p>+14 tests (5 storage, 7 trends, 2 comando combinado) → 121 en <code>cli</code>. <code>cli</code> bump a 0.8.0.</p>
<h2 id="sin-publicar-post-070-incluida-en-080">Sin publicar (post-0.7.0, incluida en 0.8.0)</h2>
<p>Auditoría de lectura de las features #1-#6 (documentadas en 0.7.0 más abajo) — no
confiar en que &ldquo;tests en verde&rdquo; significa &ldquo;comportamiento real correcto&rdquo; cuando los
tests solo ejercitan el camino inyectado/mockeado. Se encontraron y arreglaron 4 huecos
reales, ninguno cubierto por los tests originales:</p>
<ul>
<li><strong><code>cli/src/commands/init.ts</code> — <code>defaultCheckPort</code> estaba efectivamente invertido.</strong>
Corría <code>Test-NetConnection</code> por PowerShell pero nunca parseaba el stdout (&ldquo;True&rdquo;/
&ldquo;False&rdquo;), solo miraba si el comando tiraba excepción — cosa que casi nunca pasa. En la
práctica esto devolvía &ldquo;puerto ocupado&rdquo; en la gran mayoría de los casos, exista o no
algo corriendo ahí. Arreglado parseando el stdout real. +2 tests que mockean
<code>execSync</code> con &ldquo;True&rdquo;/&ldquo;False&rdquo; y verifican <code>portWarning</code> en consecuencia (→ 106 tests
en cli). También se sacó un import muerto (<code>createConnection</code> de <code>node:net</code>, resto de
una implementación anterior nunca usada).</li>
<li><strong><code>webdriverio-plugin/src/wrap.ts</code> — <code>getEvents()</code> era un stub que siempre devolvía
<code>[]</code>.</strong> No estaba exportado desde <code>index.ts</code>, no lo usaba <code>plugin.ts</code> (que ya captura
eventos correctamente vía <code>onEvent</code>), y no tenía test. Eliminado por ser código muerto
que podía confundir a quien lo llamara esperando eventos reales.</li>
<li><strong><code>gh-action/</code> — <code>@octokit/action</code> se importaba dinámicamente sin estar declarado
como dependency.</strong> En un run real de GitHub Actions esto rompía con &ldquo;Cannot find
module&rdquo;. Agregado a <code>package.json</code> y verificado que resuelve en runtime.</li>
<li><strong><code>gh-action/</code> — el input <code>project-path</code> no tenía ningún efecto.</strong> Se leía de
<code>INPUT_PROJECT_PATH</code> pero nunca se pasaba como <code>cwd</code> a los comandos de Healify, ni
estaba declarado en <code>action.yml</code>. Arreglado: <code>run()</code> ahora acepta <code>cwd</code> y lo usa de
verdad al correr <code>doctor</code>/<code>fix --dry-run</code>; <code>project-path</code> se declaró como input en
<code>action.yml</code>. +2 tests que verifican que <code>run()</code> pasa el <code>cwd</code> correcto (→ 22 tests en
gh-action).</li>
</ul>
<p>Verificación real tras los 4 fixes: <code>npm run verify</code> completo (231 tests en los 6
workspaces del monorepo en ese momento, antes de la Feature #8 — 238 con Feature #8 ya
incluida, ver sección de arriba)
workspaces del monorepo) + <code>npm test</code> en <code>gh-action</code> (22, standalone) + <code>npm audit</code> (0
vulnerabilidades). Nota de entorno: <code>npm run verify</code> vía PowerShell en Windows resuelve
<code>bash</code> a WSL (<code>C:\WINDOWS\system32\bash.exe</code>), un filesystem distinto al del repo —
correr con Git Bash real, no con el <code>bash</code> que resuelve PowerShell por defecto.</p>
<h2 id="070---2026-07-23">0.7.0 - 2026-07-23</h2>
<p>Features #1 a #7 del <code>ROADMAP.md</code>, en dos sesiones. #1-#6 se implementaron primero (231
tests); #7 se agregó después, con 2 correcciones reales al diseño original antes de
implementar (ver detalle abajo). #9 (extensión de VSCode) quedó cancelada por decisión
del usuario, marcada así en el <code>ROADMAP.md</code>, no se tocó código.</p>
<p><strong>#1 — <code>doctor</code> detecta el gotcha de semver caret.</strong> Compara la versión instalada contra
el rango declarado en <code>package.json</code> y avisa si un <code>^0.x.y</code> viejo va a bloquear que
<code>npm install</code> sin versión explícita traiga una versión nueva (el mismo problema real que
mordió al usuario dos veces en sesiones anteriores).</p>
<p><strong>#2 — <code>flush()</code> en <code>@healify/selenium-plugin</code>.</strong> Selenium ahora puede generar
<code>healify-report.html</code>/<code>.json</code> acumulando los eventos de cura en vivo, igual que
Playwright/Cypress — antes solo curaba sin dejar reporte.</p>
<p><strong>#3 — <code>init</code> detecta conflictos de puerto antes de escribir el config.</strong> Chequeo liviano
del <code>baseURL</code> detectado antes de confirmar la config, para adelantarse a casos como el de
Obsidian compitiendo por el puerto 3000 en <code>sgo-pzbp</code>.</p>
<p><strong>#4 — diccionario de sinónimos configurable (<code>customSynonyms</code>).</strong> <code>healing-engine.ts</code>
ahora acepta sinónimos adicionales sin tener que tocar los <code>dictionaries/*.json</code> del
propio paquete — útil para vocabulario propio de cada proyecto.</p>
<p><strong>#5 — paquete nuevo <code>@healify/webdriverio-plugin</code>.</strong> Mismo patrón que
<code>selenium-plugin</code> (wrap del driver real, cura en vivo), para WebdriverIO.</p>
<p><strong>#6 — <code>gh-action/</code>.</strong> GitHub Action empaquetada que corre <code>doctor</code> + <code>fix --dry-run</code> en
cada PR y comenta el resultado. Paquete privado (no se publica a npm, se usa directo del
repo).</p>
<p><strong>#7 — <code>healify fix --ast</code> (experimental).</strong> Las sugerencias <code>role('button', { name: 'X' })</code> no son un valor de selector pegable — antes se saltaban siempre como
<code>not-substitutable</code>. <code>--ast</code> usa <code>ts-morph</code> para reescribir la llamada completa
(<code>page.click('#x')</code> → <code>page.getByRole('button', { name: 'X' }).click()</code>), un cambio
estructural real, no reemplazo de texto. Es aditivo: primero corre el <code>fix</code> normal
(TESTID/CSS/TEXT, que ya son pegables tal cual), y solo reintenta con AST lo que quedó
sin aplicar. El plan original de esta feature tenía 2 errores reales corregidos antes de
implementar:</p>
<ul>
<li>Asumía que las sugerencias TEXT usaban el formato <code>text('X')</code> — el motor real nunca
genera eso, usa <code>button:has-text('X')</code> (confirmado leyendo <code>healing-engine.ts</code>), que
además <strong>ya es un selector CSS válido</strong> que el <code>fix</code> normal aplica bien tal cual sin
necesitar AST — se sacó ese camino entero en vez de dejar código muerto.</li>
<li>Estaba escrito asumiendo <code>commander.js</code> y un archivo <code>cli/src/commands/fix.ts</code> que no
existen en este código — se adaptó al dispatch real (<code>cli/src/index.ts</code> + <code>cli/src/fix.ts</code>).</li>
</ul>
<p>Bug real encontrado en la primera build: <code>ts-morph</code> (que carga el compilador de
TypeScript completo) quedó bundleado dentro de <code>dist/index.js</code>, inflándolo de 25kb a
<strong>12MB</strong>. Arreglado externalizándolo del bundle (<code>--external:ts-morph</code>, mismo patrón que
<code>@playwright/test</code>/<code>cypress</code>/<code>selenium-webdriver</code> en los otros paquetes) — queda en
31.4kb. Verificado real con el binario compilado: <code>fix --ast</code> reescribió
<code>page.click('#btn-submit')</code> a <code>page.getByRole('button', { name: 'Submit' }).click()</code>
de verdad, sin y con <code>--force</code>/<code>--dry-run</code>.</p>
<p>241 tests (antes 164): 44 reporter-core + 8 test-runner + 7 cypress-plugin + 104 cli + 35
selenium-plugin + 23 webdriverio-plugin + 20 gh-action. <code>npm audit</code> → 0 vulnerabilidades.</p>
<p><code>reporter-core</code>/<code>test-runner</code>/<code>cypress-plugin</code>/<code>selenium-plugin</code>/<code>cli</code> a <code>0.7.0</code> (todos
bundlean o son afectados por <code>reporter-core</code>, que cambió con <code>customSynonyms</code>).
<code>@healify/webdriverio-plugin</code> nace en <code>0.6.0</code> (primera versión, no publicada todavía).
<code>gh-action</code> es privado, no se publica.</p>
<h2 id="060---2026-07-23">0.6.0 - 2026-07-23</h2>
<p><strong>Cambio de comportamiento pedido explícitamente por el usuario, probando 0.5.1 en
producción real:</strong> <code>init</code> ya NO genera ningún archivo de test. En 0.5.0/0.5.1, para cada
framework <code>init</code> creaba un test con un selector inventado a propósito
(<code>demo-boton-roto-healify</code>, <code>boton-viejo-12345678</code>) solo para mostrar un primer
<code>healify-report.html</code>. Probándolo en un proyecto real, sintió que se le mostraba algo
falso como si fuera una prueba genuina de la herramienta. Decisión: nada de demos, nunca
más — <code>init</code> deja la config real conectada y nada más; el primer selector roto que
Healify cure tiene que ser uno de verdad, escrito por el QA sobre su propia app.</p>
<ul>
<li><code>cli/src/scaffold.ts</code>: sacadas las constantes <code>DEMO_*</code> y las funciones que generaban
<code>e2e/healify.demo.spec.*</code>, <code>cypress/e2e/healify.demo.cy.*</code> y <code>healify.selenium.demo.*</code>.
<code>scaffoldPlaywright</code> ahora devuelve solo <code>playwright.config.*</code>. <code>scaffoldCypress</code>
devuelve config + <code>cypress/support/e2e.*</code> (ese sí es real: Cypress lo exige para e2e
testing, no es un extra de Healify). <code>scaffoldSelenium</code> devuelve solo
<code>healify.selenium.example.ts</code> (documentación de referencia que nunca se ejecuta, se
mantiene sin cambios).</li>
<li><code>cli/src/index.ts</code>: el mensaje final de <code>init</code> ya no dice &ldquo;Corré <code>npx playwright test</code>&rdquo;
(implicaba que ya había algo armado para correr) — ahora dice honestamente que hay que
escribir el primer test real. Sacados <code>RUN_COMMAND</code>/<code>runCommandFor</code>.</li>
<li><code>cli/README.md</code> y <code>README.md</code> raíz actualizados: sin ningún bloque mostrando un demo,
con la aclaración explícita de que <code>init</code> no genera tests.</li>
<li>2 bugs reales encontrados en una auditoría completa del motor, no relacionados con los
demos — ver detalle abajo.</li>
</ul>
<p><strong>Bug real — <code>healing-engine.ts</code>: selectores CSS-in-JS compuestos no se detectaban como
volátiles.</strong> <code>analyzeSelector</code> solo entraba a la rama de clase volátil si el selector
completo empezaba con <code>.</code> — un selector real como <code>.btn.css-1a2b3c4d5e</code> (clase semántica +
hash de CSS-in-JS pegados, muy común con styled-components) o con combinador
(<code>.container &gt; .css-1a2b3c4d</code>) nunca se detectaba como dinámico, y caía al fallback
genérico en vez de proponer una alternativa estable. Arreglado: la detección ahora busca
el patrón volátil en cualquier posición del selector, no solo desde el inicio del string.</p>
<p><strong>Bug real — <code>cli/src/fix.ts</code>: podía reemplazar un selector dentro de un comentario en vez
del código real.</strong> El conteo de ocurrencias no distinguía código de comentarios — si el
selector roto quedaba mencionado solo en un comentario (<code>// TODO: reemplazar '#btn-x'</code>) y
ya no existía en el código real, <code>fix</code> lo reemplazaba ahí igual y reportaba <code>applied</code> con
confianza total, sin cambiar nada funcional. Arreglado: las líneas de comentario se
filtran antes de contar ocurrencias; si la única mención real está en un comentario, se
trata como <code>not-found</code>.</p>
<p><code>reporter-core</code>/<code>test-runner</code>/<code>cypress-plugin</code>/<code>cli</code>/<code>selenium-plugin</code> a <code>0.6.0</code> — los 4
paquetes publicables bundlean <code>reporter-core</code>, así que el fix de <code>healing-engine.ts</code>
necesita republicar los 5, no solo <code>cli</code>.</p>
<h2 id="051---2026-07-23">0.5.1 - 2026-07-23</h2>
<p><strong>Fix crítico encontrado probando 0.5.0 en producción real (<code>sgo-pzbp</code>), no en tests:</strong>
un <code>npx playwright test</code> (sin especificar archivo) escaneó todo <code>e2e/</code> y encontró
<code>e2e/selenium.demo.test.ts</code> — matchea el patrón de descubrimiento de tests por defecto de
Playwright (<code>*.test.ts</code> dentro del <code>testDir</code>). Playwright lo cargó como si fuera un test
suyo y, como el script corre <code>main()</code> apenas se importa (no espera a que lo invoquen),
se disparó como efecto secundario: abrió una sesión de Chrome de más (vía ChromeDriver) y
mezcló su log de curado con la salida del test real de Playwright. Confirmado real,
copia exacta del output del usuario.</p>
<p><strong>Fix:</strong> el demo de Selenium (<code>scaffoldSelenium</code> en <code>cli/src/scaffold.ts</code>) ya no vive en
<code>e2e/</code> ni usa sufijo <code>.spec.</code>/<code>.test.</code> — se mueve a la raíz como <code>healify.selenium.demo.ts</code>
(al lado de <code>healify.selenium.example.ts</code>). <code>cli/src/index.ts</code> ajustado para armar el
comando de &ldquo;Listo. Corré&hellip;&rdquo; leyendo el nombre real generado (TS o JS) en vez de asumir
<code>.ts</code> a mano. Verificado real: <code>npx playwright test</code> en <code>sgo-pzbp</code> ya no dispara Chrome de
más, y <code>npx tsx healify.selenium.demo.ts</code> sigue curando y clickeando bien por separado.</p>
<p><strong>Bug secundario encontrado en el propio mensaje del demo:</strong> el comentario JSDoc explicando
por qué el archivo no debía llamarse <code>.test.ts</code> contenía literalmente <code>*.spec.*/*.test.*</code>
— ese <code>*/</code> cerraba el comentario <code>/** ... */</code> antes de tiempo, dejando el resto del texto
como código real y rompiendo el parseo (<code>esbuild</code> tiraba <code>Unexpected &quot;*&quot;</code> al intentar
correr el demo con <code>npx tsx</code>). Reescrito sin la secuencia <code>*/</code> literal. Test de regresión
nuevo: los 3 templates (Playwright/Cypress/Selenium) ahora se validan parseando con
<code>esbuild.transformSync</code> en vez de solo revisar substrings — así un futuro comentario mal
escrito rompe el test en vez de llegar a producción.</p>
<p>162 tests (antes 160). <code>cli</code> a <code>0.5.1</code> — único paquete tocado, <code>test-runner</code>/
<code>cypress-plugin</code>/<code>reporter-core</code> sin cambios desde 0.5.0.</p>
<h2 id="050---2026-07-23">0.5.0 - 2026-07-23</h2>
<p><strong>Fix crítico (<code>reporter-core</code>, republicado vía <code>test-runner</code>/<code>cypress-plugin</code>):</strong>
<code>extractSelectorFromError()</code> usaba un patrón <code>[&quot;']([^&quot;']+)[&quot;']</code> que EXCLUÍA ambos tipos de
comilla del contenido capturado. El selector de mayor confianza del motor —
<code>[data-testid=&quot;x&quot;]</code>, comillas dobles adentro de las comillas simples que pone Playwright
alrededor de <code>locator('...')</code> — nunca se extraía completo: el regex cortaba en la primera
comilla interna y no volvía a matchear nunca. Resultado real, confirmado corriendo
<code>npx playwright test</code> contra un selector <code>data-testid</code> roto de verdad: <code>status: 'unresolved'</code>
siempre, para el caso más común y de mayor confianza del motor (TESTID, 0.95). Arreglado con
un backreference de comilla (<code>([&quot;'])((?:(?!\1).)+)\1</code>, grupo 2 = contenido) que permite
comillas del otro tipo adentro. Verificado real: mismo test, mismo selector, ahora
<code>Healed: 1 | Review: 0 | Unresolved: 0</code>. Afecta a cualquier proyecto Playwright real que use
<code>data-testid</code>/<code>data-cy</code> — que es la recomendación estándar de selector estable. 6 tests de
regresión nuevos en <code>reporter-core</code> (<code>selector-extractor.test.ts</code>).</p>
<p><strong>Feature (<code>@healify/cli</code>): <code>init</code> universal — funciona en cualquier proyecto, no solo en uno
que ya tiene el framework instalado.</strong></p>
<ul>
<li>Si no detecta ningún framework de e2e, pregunta cuál armar (Playwright/Cypress/Selenium,
default Playwright) y scaffoldea todo desde cero: config con el reporter/plugin ya
wireado, un test demo con selector roto a propósito, y (Playwright/Cypress) los archivos
de soporte necesarios</li>
<li>Si el framework ya está instalado pero sin archivo de config (bug real encontrado en un
proyecto Vite-only: <code>@playwright/test</code> instalado, <code>playwright.config.*</code> nunca creado) —
scaffoldea el config automáticamente en vez de solo avisar</li>
<li>Si ya hay config sin Healify, sigue igual que antes (inyecta el marcador, idempotente)</li>
<li>baseURL automático: primero el script <code>&quot;dev&quot;</code> de <code>package.json</code> (<code>vite --port=3000</code> — el
caso real más común, confirmado auditando un proyecto Vite donde el puerto nunca está en
<code>vite.config.*</code>), después <code>server.port</code> de <code>vite.config.*</code>/<code>next.config.*</code>, si no 5173/3000</li>
<li>TS vs JS y ESM vs CJS detectados solos (<code>tsconfig.json</code>, <code>package.json</code> <code>&quot;type&quot;</code>)</li>
<li>Prompt interactivo sin dependencias nuevas (<code>fs.readSync</code> sobre el fd 0), con fallback
determinístico al framework default si stdin no es TTY (nunca cuelga en CI)</li>
<li>Selenium: el demo (<code>e2e/selenium.demo.test.ts</code>) navega a una página HTML autocontenida
(<code>data:</code> URL) en vez de depender del DOM real del proyecto — no necesitás tu app corriendo.
Usa un selector de ID dinámico (no testid) a propósito: la estrategia de &ldquo;cura&rdquo; de testid
solo normaliza comillas, que para el navegador es el MISMO selector — así que si el
original no encuentra nada, el reintento con el &ldquo;fix&rdquo; tampoco encontraría nada nunca
(confirmado corriendo el demo real antes del cambio: la cura se detecta, confidence 0.93,
pero el reintento vuelve a tirar <code>NoSuchElementError</code>). Con la estrategia de ID
dinámico → clase estable (<code>#boton-viejo-12345678</code> → <code>.boton-viejo</code>, confidence 0.82) y un
botón real con esa clase en la página autocontenida, el reintento sí encuentra un elemento
distinto y el click funciona de verdad. <code>confidenceThreshold</code> bajado a 0.75 solo en el
demo (0.82 &lt; el default de producción 0.9) — comentado en el propio archivo generado.</li>
</ul>
<p><strong>Fix (<code>doctor</code>):</strong> mensaje de &ldquo;no detectamos framework&rdquo; ahora manda a <code>npx @healify/cli init</code>
en vez de &ldquo;instalá Playwright/Cypress/Selenium primero&rdquo; — con <code>init</code> universal ya no hace
falta instalar nada a mano antes.</p>
<p><strong>Tests:</strong> 22 tests nuevos (<code>init.test.ts</code> ampliado + <code>scaffold.test.ts</code> nuevo + 6 de
regresión en <code>reporter-core</code>) — 160 tests en verde (36+8+7+80+29), antes 138.</p>
<p><strong>Validación real (no solo tests) contra <code>sgo-pzbp</code> (proyecto Vite real, sin ningún e2e
armado todavía):</strong></p>
<ul>
<li><strong>Playwright</strong> (bug real de CASO B: <code>@playwright/test</code>+<code>@healify/test-runner</code> ya
instalados, <code>playwright.config.ts</code> nunca existió) → <code>init</code> lo creó con
<code>baseURL: 'http://localhost:3000'</code> (correcto — el puerto real vive en el script <code>dev</code>, no
en <code>vite.config.ts</code>, que en este proyecto no lo menciona) → <code>npx playwright test</code> con la
app corriendo → <code>Healed: 1 | Review: 0 | Unresolved: 0</code> real → <code>doctor</code> 100% verde</li>
<li><strong>Cypress</strong> (<code>cypress</code> no es dependency declarada en <code>sgo-pzbp</code> — validado en un proyecto
descartable aparte para no forzar una dependencia nueva en un repo de producción real, sin
tocar <code>sgo-pzbp</code>) → mismo resultado: <code>npx cypress run</code> → <code>Healed: 1 | Review: 0 | Unresolved: 0</code> real → <code>doctor</code> 100% verde</li>
<li><strong>Selenium</strong> (<code>selenium-webdriver</code>+<code>@healify/selenium-plugin</code> ya instalados) → <code>init</code>
scaffoldeó el ejemplo + el demo → <code>npx tsx e2e/selenium.demo.test.ts</code> con ChromeDriver real
→ evento <code>healed</code> real (confidence 0.82, <code>.boton-viejo</code>) y el <code>.click()</code> final funcionó de
verdad → <code>doctor</code> 100% verde</li>
</ul>
<p>Todo lo agregado a <code>sgo-pzbp</code> para las pruebas (<code>playwright.config.ts</code>, <code>e2e/</code>,
<code>healify.selenium.example.ts</code>, <code>healify-report.html/json</code>) se borró al terminar — el repo
real queda exactamente como estaba (Vite-only), según lo pedido. Detalle completo en
<code>docs/audit-0.5.0.md</code>.</p>
<p><code>reporter-core</code>/<code>test-runner</code>/<code>cypress-plugin</code>/<code>cli</code> a <code>0.5.0</code>. <code>selenium-plugin</code> sin
cambios de código, queda en <code>0.1.0</code>.</p>
<p><strong>chore:</strong> <code>npm audit fix --force</code> — <code>esbuild</code> 0.27.7 → 0.28.1 (bump breaking, quedaba
pendiente desde 0.4.1). Verificado real: build de los 5 workspaces sin cambios de
comportamiento (tamaños de bundle casi idénticos), 160 tests siguen verdes, <code>cli/dist/index.js</code>
probado a mano (<code>--help</code>, <code>doctor</code>) sin diferencias. <code>npm audit</code> → 0 vulnerabilidades.</p>
<h2 id="041---2026-07-23">0.4.1 - 2026-07-23</h2>
<ul>
<li>fix: <code>doctor</code> marcaba <code>❌ healify-report.json existe</code> en proyectos Selenium-only como si fuera un error — Selenium cura en vivo y nunca genera ese archivo, así que ese check nunca podía pasar. Ahora, si Selenium es el único framework, se reemplaza por un check informativo (<code>ℹ️ Selenium cura en vivo, no genera reporte</code>). Si convive con Playwright/Cypress, el check de reporte se mantiene (<code>cli/src/commands/doctor.ts</code>)</li>
<li>fix: <code>--help</code>/<code>-h</code> ejecutaba el comando de verdad en vez de mostrar ayuda — confirmado corriendo el binario real: <code>healify init --help</code> instalaba paquetes y editaba configs. Ahora <code>--help</code> en cualquier posición corta antes de despachar a <code>init</code>/<code>doctor</code>/<code>fix</code> (<code>cli/src/index.ts</code>)</li>
<li>docs: alineados <code>README.md</code> raíz y <code>cli/README.md</code> a <code>npx @healify/cli &lt;comando&gt;</code> en vez de <code>npx healify &lt;comando&gt;</code> (ambas formas funcionan una vez instalado, pero eran inconsistentes entre sí)</li>
<li>docs: corregido el ejemplo de <code>doctor</code> en el README raíz — mostraba un flujo interactivo <code>[y/n]</code> que no existe; reemplazado por el output real del comando</li>
<li>docs: badge y menciones de cantidad de tests actualizadas de 135 a 138 (64 tests en <code>cli</code>, +3 por el fix de <code>doctor</code>)</li>
<li>chore: <code>npm audit fix</code> (sin <code>--force</code>) resolvió 5 de 6 vulnerabilidades de devDependencies (lodash, picomatch, postcss, vite, vitest — todas vía <code>cypress</code>/<code>vitest</code>, no llegan al tarball publicado). Queda <code>esbuild</code> (requiere bump breaking 0.27→0.28, usado en el build de los 4 paquetes) — no forzado, ver <code>docs/audit-0.4.1.md</code></li>
<li><code>@healify/cli</code> a <code>0.4.1</code> (único paquete con cambios de comportamiento reales). <code>test-runner</code>/<code>cypress-plugin</code>/<code>reporter-core</code> quedan en <code>0.4.0</code>, <code>selenium-plugin</code> en <code>0.1.0</code></li>
<li>138 tests en verde (<code>npm run verify</code>), verificado con el binario real contra un proyecto Playwright, uno Cypress y contra <code>sgo-pzbp</code> (Selenium real, ChromeDriver real)</li>
</ul>
<h2 id="040---2026-07-22">0.4.0 - 2026-07-22</h2>
<ul>
<li>feat: <code>@healify/cli init</code> — detecta el framework (Playwright/Cypress/Selenium) por <code>package.json</code> y archivos de config, instala el paquete de Healify que falte y wirea el <code>reporter</code>/plugin en el config automáticamente. Idempotente: no duplica si ya está instalado o configurado</li>
<li>feat: <code>@healify/cli doctor</code> — checklist con ✅/❌ y fix sugerido: framework detectado, paquete instalado, config wireado, <code>healify-report.json</code> generado. No modifica nada</li>
<li>feat: <code>healify</code> sin argumentos o con comando desconocido imprime help listando <code>init</code>/<code>doctor</code>/<code>fix</code></li>
<li>fix: instalación en Windows fallaba silenciosamente (<code>ENOENT</code>/<code>EINVAL</code> con <code>execFileSync</code> + <code>npm</code>/<code>.cmd</code>) — encontrado corriendo el binario real, corregido con <code>execSync</code></li>
<li>docs: sección &ldquo;Para QA sin experiencia&rdquo; en <code>cli/README.md</code> con los 3 comandos</li>
<li>61 tests nuevos en <code>cli</code> (135 totales en el monorepo)</li>
</ul>
<h2 id="031---2026-07-22">0.3.1 - 2026-07-22</h2>
<ul>
<li>fix: filtro de atributos volátiles (<code>css-</code>, <code>sc-</code>, hash largo) — el motor ya no propone una <code>.class</code> inestable como alternativa cuando el candidato sigue viéndose volátil o el selector original tiene más de 3 fragmentos tipo hash/número (<code>1998642</code>)</li>
<li>fix: <code>healing-engine</code> ordena candidatos por escalera de prioridad de atributo estable (testid &gt; id &gt; name &gt; aria-label/role &gt; texto &gt; clase) en vez de solo por confidence — ningún número de confianza cambió, solo qué candidato gana cuando compiten varios (<code>b41e0be</code>)</li>
<li>docs: tabla de versiones, sección <code>npm run verify</code> y mención del <code>printSummary</code> nuevo en los READMEs de <code>test-runner</code>/<code>cypress-plugin</code>/raíz (<code>b657c39</code>)</li>
</ul>
<h2 id="030---2026-07-22">0.3.0 - 2026-07-22</h2>
<ul>
<li>feat: <code>printSummary()</code> en <code>local-report.ts</code> -&gt; stdout <code>Healed | Review | Unresolved</code> en <code>onEnd()</code> de <code>test-runner</code> y <code>cypress-plugin</code></li>
<li>feat: <code>npm run verify</code> script de 33 líneas, resumen de 5 paquetes con dot reporter</li>
<li>feat: diccionarios extraídos a <code>dictionaries/en.json</code> y <code>es.json</code> con <code>resolveJsonModule</code></li>
<li>breaking: eliminado modo nube completo (<code>http-client.ts</code>, <code>HEALIFY_API_KEY</code>, <code>config.ts</code>, <code>fake-server.mjs</code> y verifies). Main ahora 100% local sin red.</li>
<li>chore: <code>.claudeignore</code> y <code>CLAUDE.md</code> para reducir consumo de tokens de Claude Code</li>
</ul>
]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Fri, 14 Aug 2026 06:20:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.14.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action described in the README automates the process of running automated test suites in a ServiceNow environment using various parameters such as browser settings, operating system versions, and test suite details. It solves the problem of integrating CI/CD practices into the ServiceNow development workflow by providing a reusable action that can be configured for different environments and test requirements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action described in the README automates the process of running automated test suites in a ServiceNow environment using various parameters such as browser settings, operating system versions, and test suite details. It solves the problem of integrating CI/CD practices into the ServiceNow development workflow by providing a reusable action that can be configured for different environments and test requirements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.13...1.0.14">https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.13...1.0.14</a></p>
]]></content:encoded></item><item><title>Go - Test Suites</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/go-test-suites/</link><pubDate>Fri, 14 Aug 2026 06:19:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/go-test-suites/</guid><description>Version updated for https://github.com/mvrahden/go-test to version v1.26.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The gotest action generates and executes Go test suites as specification-driven behavioral contracts, offering isolated and parallel execution with no runtime dependencies or reflection. It simplifies test management by organizing tests into readable specifications and ensures state isolation between tests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mvrahden/go-test">https://github.com/mvrahden/go-test</a></strong> to version <strong>v1.26.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-test-suites">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>gotest</code> action generates and executes Go test suites as specification-driven behavioral contracts, offering isolated and parallel execution with no runtime dependencies or reflection. It simplifies test management by organizing tests into readable specifications and ensures state isolation between tests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Rebuild the website and grow the blog by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/93">https://github.com/mvrahden/go-test/pull/93</a></li>
<li>Publish the Go testing research article by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/94">https://github.com/mvrahden/go-test/pull/94</a></li>
<li>Make the docs, config, and test reports match what actually happens by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/97">https://github.com/mvrahden/go-test/pull/97</a></li>
<li>Teach AI coding assistants how to write gotest tests by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/98">https://github.com/mvrahden/go-test/pull/98</a></li>
<li>Report failures reliably across the entire test lifecycle by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/96">https://github.com/mvrahden/go-test/pull/96</a></li>
<li>Broken packages can no longer slip through as passing by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/100">https://github.com/mvrahden/go-test/pull/100</a></li>
<li>Smarter test linting: assertions everywhere, with rules organized by how much they matter by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/99">https://github.com/mvrahden/go-test/pull/99</a></li>
<li>Replace the retired Go Report Card badge by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/102">https://github.com/mvrahden/go-test/pull/102</a></li>
<li>Make the linter docs match the linter by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/101">https://github.com/mvrahden/go-test/pull/101</a></li>
<li>Lint findings now show up right in the pull request by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/103">https://github.com/mvrahden/go-test/pull/103</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mvrahden/go-test/compare/v1.25.0...v1.26.0">https://github.com/mvrahden/go-test/compare/v1.25.0...v1.26.0</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/go-proxy-cache-updater/</link><pubDate>Fri, 14 Aug 2026 06:18:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.43.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Go Proxy Cache Updater action automatically pulls new Go module releases to a specified proxy cache when tags matching semantic version patterns are created. It supports standard and submodule version tags, customizable proxy configurations, custom import paths, and specifies a Go version via setup-go. The action ensures the module is immediately available on platforms like pkg.go.dev.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.43</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Go Proxy Cache Updater action automatically pulls new Go module releases to a specified proxy cache when tags matching semantic version patterns are created. It supports standard and submodule version tags, customizable proxy configurations, custom import paths, and specifies a Go version via <code>setup-go</code>. The action ensures the module is immediately available on platforms like pkg.go.dev.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1143-2026-08-13"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.42...v1.1.43">1.1.43</a> (2026-08-13)</h2>
]]></content:encoded></item><item><title>GuardSmith Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/guardsmith-lint/</link><pubDate>Fri, 14 Aug 2026 06:17:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/guardsmith-lint/</guid><description>Version updated for https://github.com/novexar/Guardsmith to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GuardSmith is a governance toolkit that automates the distribution and validation of AI coding standards. It provides an AI-based system to verify compliance with predefined standards, including ESLint + official configurations, and offers features such as project creation, policy verification, drift detection, CI integration, and multi-level deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/novexar/Guardsmith">https://github.com/novexar/Guardsmith</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/guardsmith-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GuardSmith is a governance toolkit that automates the distribution and validation of AI coding standards. It provides an AI-based system to verify compliance with predefined standards, including ESLint + official configurations, and offers features such as project creation, policy verification, drift detection, CI integration, and multi-level deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li>
<p><strong>Self-contained CLI bundle on GitHub Releases</strong> (<code>guardsmith-cli-v0.4.0.tar.gz</code>) — run GuardSmith <strong>without any npm registry access</strong> (air-gapped / restricted egress environments). Only GitHub + Node.js 20+ required:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>gh release download v0.4.0 --repo novexar/Guardsmith --pattern <span style="color:#e6db74">&#39;guardsmith-cli-*.tar.gz&#39;</span>
</span></span><span style="display:flex;"><span>tar -xzf guardsmith-cli-*.tar.gz
</span></span><span style="display:flex;"><span>node guardsmith-cli/guard.mjs lint
</span></span></code></pre></div></li>
<li>
<p><strong>Action <code>source</code> input</strong> — <code>source: release</code> runs the action from the Releases bundle instead of npx (npm registry not required). Default remains <code>npm</code>.</p>
</li>
<li>
<p><strong>npm READMEs (JA/EN)</strong> — <code>@guardsmith/core</code> / <code>@guardsmith/cli</code> 0.2.2 now ship bilingual READMEs (the npm pages previously showed no description).</p>
</li>
<li>
<p><code>guard version</code> command; <code>guard new</code> reference tag decoupled from the npm version (standards remain at v0.2.1).</p>
</li>
</ul>
<hr>
<p>npm レジストリへ到達できない環境向けの<strong>依存同梱バンドル</strong>を添付しました(GitHub と Node.js 20+ のみで動作)。Action は <code>source: release</code> で npm 不要になります。npm パッケージ 0.2.2 には日英併記の README を同梱しています。</p>
]]></content:encoded></item><item><title>Harness Score</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/harness-score/</link><pubDate>Fri, 14 Aug 2026 06:15:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/harness-score/</guid><description>Version updated for https://github.com/paladini/harness-score to version v1.6.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Harness Score automates and measures the reliability of AI coding harnesses across various tools, providing insights into context, skills, hooks, sensors, CI feedback, hygiene, and safety. It evaluates a repository’s harness maturity level and lists specific areas that need improvement to achieve higher levels.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/paladini/harness-score">https://github.com/paladini/harness-score</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harness-score">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Harness Score automates and measures the reliability of AI coding harnesses across various tools, providing insights into context, skills, hooks, sensors, CI feedback, hygiene, and safety. It evaluates a repository&rsquo;s harness maturity level and lists specific areas that need improvement to achieve higher levels.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Scan the complete repository tree without a production depth cap, raise the file-count fuse to 1,000,000, and decide incomplete-scan failures from the selected gate while preserving authoritative maturity outputs. Discovered paths that cannot be inspected and symlinks that escape the scan root now also make the affected snapshot incomplete.</p>
]]></content:encoded></item><item><title>Quick OCP</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/quick-ocp/</link><pubDate>Fri, 14 Aug 2026 06:14:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/quick-ocp/</guid><description>Version updated for https://github.com/palmsoftware/quick-ocp to version v1.0.1.
This action is used across all versions by 15 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of quickly spawning an OpenShift cluster using OpenShift Local on GitHub Actions. It supports a variety of runners and provides options to customize the cluster setup, such as desired version, memory allocation, and operator readiness monitoring. The action includes connectivity checks and allows for disabling these checks if needed, with clear error messages for failure scenarios.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/palmsoftware/quick-ocp">https://github.com/palmsoftware/quick-ocp</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>15</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quick-ocp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of quickly spawning an OpenShift cluster using OpenShift Local on GitHub Actions. It supports a variety of runners and provides options to customize the cluster setup, such as desired version, memory allocation, and operator readiness monitoring. The action includes connectivity checks and allows for disabling these checks if needed, with clear error messages for failure scenarios.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="documentation">Documentation</h2>
<ul>
<li>Document all inputs and outputs in README (#139, #168)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: document all inputs and outputs in README by @bpalm in #168</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/palmsoftware/quick-ocp/compare/v1.0.0...v1.0.1">https://github.com/palmsoftware/quick-ocp/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>PatchWitness Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/patchwitness-gate/</link><pubDate>Fri, 14 Aug 2026 06:13:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/patchwitness-gate/</guid><description>Version updated for https://github.com/pangxueyuan2-creator/patchwitness to version v0.2.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PatchWitness is an AI-driven tool that automates the verification of AI-generated code changes by providing independent evidence and policy gates. It helps reviewers verify scope, verifier integrity, real check execution, secrets, dependency impact, and portable evidence without relying on LLMs. PatchWitness generates Change Passports for every change, which can be offline-verifiable. Users can test its functionality with a 60-second demo that demonstrates how it blocks protected CI workflows when tests fail or the policy is violated.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pangxueyuan2-creator/patchwitness">https://github.com/pangxueyuan2-creator/patchwitness</a></strong> to version <strong>v0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/patchwitness-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PatchWitness is an AI-driven tool that automates the verification of AI-generated code changes by providing independent evidence and policy gates. It helps reviewers verify scope, verifier integrity, real check execution, secrets, dependency impact, and portable evidence without relying on LLMs. PatchWitness generates Change Passports for every change, which can be offline-verifiable. Users can test its functionality with a 60-second demo that demonstrates how it blocks protected CI workflows when tests fail or the policy is violated.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="patch-release">Patch release</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Preserved the advisory Copilot CLI PowerShell hook’s documented zero exit status when it runs under a strict PowerShell caller, while retaining status output on stderr.</li>
<li>Excluded local virtual environments and generated build directories from source distributions.</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li>Added Windows-only regression coverage that runs the published PowerShell hook against a synthetic Git change and verifies the resulting Change Passport.</li>
</ul>
<h3 id="security">Security</h3>
<ul>
<li>Updated the pinned CodeQL action revision used for Python security analysis.</li>
</ul>
<h3 id="verification">Verification</h3>
<p>The tag-triggered release workflow passed the complete quality gate, source/wheel build, metadata and manifest validation, clean-install wheel smoke test, digest generation, provenance attestation, and GitHub Release upload.</p>
<blockquote>
<p>This release provides direct PowerShell-hook compatibility evidence only. It does not claim GitHub Copilot CLI <code>sessionEnd</code> event-dispatch validation, semantic correctness, external adoption, or PyPI publication.</p>
</blockquote>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pangxueyuan2-creator/patchwitness/compare/v0.2.1...v0.2.2">https://github.com/pangxueyuan2-creator/patchwitness/compare/v0.2.1...v0.2.2</a></p>
]]></content:encoded></item><item><title>Web App Security Skill</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/web-app-security-skill/</link><pubDate>Fri, 14 Aug 2026 06:12:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/web-app-security-skill/</guid><description>Version updated for https://github.com/parousia8888/web-app-security-skill to version v0.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates web security audits, audits, hardens, and retests web projects using AI coding agents. It provides reproducible evidence through semantic digests and fixes with repair plans, simplifying the process of identifying and addressing security issues without requiring offensive-security expertise.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/parousia8888/web-app-security-skill">https://github.com/parousia8888/web-app-security-skill</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/web-app-security-skill">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates web security audits, audits, hardens, and retests web projects using AI coding agents. It provides reproducible evidence through semantic digests and fixes with repair plans, simplifying the process of identifying and addressing security issues without requiring offensive-security expertise.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v050-release-evidence">v0.5.0 release evidence</h1>
<p>Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.</p>
<p>Web App Security Skill v0.5.0 expands narrow automated source detection and makes every actionable
source result understandable before a user approves a change. It keeps the evidence discipline and
passive defaults from v0.4.0; it does not turn syntax matches into confirmed vulnerabilities or let
the CLI edit a project unattended.</p>
<h2 id="release-identity">Release identity</h2>
<ul>
<li>Version/tag: <code>v0.5.0</code></li>
<li>Source identity: the commit peeled from the SSH-signed annotated tag; the exact 40-character SHA
is also recorded in <code>web-app-security-skill-0.5.0.release.json</code> and the provenance attestation.</li>
<li>Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.</li>
<li>External adapters: Gitleaks <code>8.30.1</code>, Opengrep <code>1.27.0</code>, OSV-Scanner <code>2.5.0</code> and Checkov <code>3.3.9</code>,
installed and version-pinned by the caller.</li>
</ul>
<p>This Markdown file is part of the source commit it describes, so it does not embed a fabricated
self-referential commit SHA. Verify the exact published identity with the signed tag, release
manifest and provenance.</p>
<h2 id="stable-rule-boundary">Stable rule boundary</h2>
<p>The v0.5.0 stable source and deployment-policy corpus contains exactly 30 rules:</p>
<ul>
<li>20 built-in risk rules: four shared project/configuration checks, eight bounded
JavaScript/TypeScript checks and eight tokenizer-backed Python checks;</li>
<li>two built-in evidence-integrity rules that expose unreadable/failed source observations as
<code>unknown</code> rather than clean;</li>
<li>eight opt-in external-adapter risk rules: two Gitleaks rules, two Opengrep rules, one
OSV-Scanner rule and three Checkov rules.</li>
</ul>
<p>The machine-readable source of truth is <a href="../stable-source-rules.json"><code>docs/stable-source-rules.json</code></a>,
and <a href="../stable-rule-corpus.json"><code>docs/stable-rule-corpus.json</code></a> links every stable rule to a positive
fixture, safe near-neighbour, expected state, evidence boundary and test entrypoint. Built-in rules
have 22 real observations and 22 planted missing-observation failures. External rules use pinned
real-tool CI fixtures. This demonstrates the documented observation paths, not population-level
precision, recall or exploitability.</p>
<p>Built-in depth is deliberately limited to direct lexical or tokenizer-backed constructs. It does
not prove whole-program input flow, runtime reachability, sanitizer correctness or deployment
exposure. Source patterns and external scanner rows remain <code>suspected</code> unless rule-specific
independent evidence confirms the conclusion.</p>
<h2 id="explanation-and-repair-contract">Explanation and repair contract</h2>
<p>Source findings and reports now use v3. Each actionable result retains the professional term and
standards mapping, then also records:</p>
<ul>
<li>a plain-language explanation and conditional consequence;</li>
<li>the evidence that exists and what it cannot prove;</li>
<li>one reviewable proposal, alternatives and likely product side effects;</li>
<li>decisions that must remain with the owner;</li>
<li>separate security and normal-function retests; and</li>
<li>rollback criteria.</li>
</ul>
<p>Persisted v2 source baselines remain readable through the compatibility layer and cannot
manufacture a <code>fixed</code> result. A fix is comparable only when subject, scope, rule identity and current
coverage agree. <code>repair-plan</code> and <code>repair-validate</code> create and validate private, non-overwriting
review records with explicit approval and dual-retest states. The CLI does not apply project edits,
deploy changes or migrations.</p>
<h2 id="adapter-decisions">Adapter decisions</h2>
<ul>
<li>Opengrep <code>1.27.0</code> is the stable bounded SAST adapter for two bundled, digest-pinned same-file
request-to-command rules. It is opt-in, does not fetch rules and does not execute project code.</li>
<li>Checkov <code>3.3.9</code> is the stable bounded deployment adapter for three fixed root Dockerfile/GitHub
Actions rules. It uses <code>--skip-download</code>; it may query PyPI for version metadata but does not
upload project source.</li>
<li>Gitleaks and OSV-Scanner retain the v0.4.0 contracts. OSV data may change with the public advisory
database. None of the adapters is downloaded automatically, and project dependencies are never
installed or executed.</li>
</ul>
<p>Exact selection evidence, rejected alternatives and failure behavior are in
<a href="../sast-adapter-benchmark.md"><code>docs/sast-adapter-benchmark.md</code></a>,
<a href="../iac-adapter-benchmark.md"><code>docs/iac-adapter-benchmark.md</code></a> and
<a href="../adapter-protocol.md"><code>docs/adapter-protocol.md</code></a>.</p>
<h2 id="ordinary-project-and-demo-evidence">Ordinary-project and demo evidence</h2>
<p>The broader built-in v3 path ran against five existing ordinary Web projects at immutable commits,
without probing hosted services or executing project dependencies. All 43 observed findings were
uniquely reviewed: 11 useful leads, 27 expected benign matches, one <code>unknown</code> tokenizer observation
and four confirmed missing-lockfile facts. These are finding classifications, not 43 vulnerabilities
and not a precision/recall result. A zero-finding project is not evidence that the project is secure.</p>
<p>The local network-free demo uses one intentionally unsafe Node.js child-process call. It reports a
suspected CWE-78-shaped lead, states that input flow and reachability are unproven, proposes
<code>execFile</code> with separate arguments, names quoting and cross-platform behavior as side effects, then
records a compatible security retest and an independent functional retest. The demo proves this
bounded workflow, not automatic safe repair.</p>
<h2 id="release-verification">Release verification</h2>
<p>The release workflow runs the full repository gate, builds every artifact twice and compares bytes,
verifies archive paths, the stable rule manifest, release manifest, SHA-256 list and SPDX 2.3 SBOM,
then exercises clean installation and an isolated v0.4.0-to-v0.5.0 lifecycle upgrade. GitHub build
provenance is requested only after these checks pass. External consumers separately exercise the
exact immutable Action source in backward-compatible crawl mode and v0.5.0 source mode before the
stable <code>v1</code> alias moves.</p>
<p>Verify the published tag after release:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>git -c gpg.ssh.allowedSignersFile<span style="color:#f92672">=</span>.github/release-signers verify-tag v0.5.0
</span></span></code></pre></div><p>Verify downloaded assets with <code>SHA256SUMS</code>, compare the manifest source commit with
<code>git rev-parse 'v0.5.0^{}'</code>, and verify GitHub provenance. The built-in verified-installer trust
anchor is updated only after immutable public asset digests exist; until then, the documented
default installer remains the already trusted v0.4.0 release.</p>
<h2 id="unsupported-and-known-risks">Unsupported and known risks</h2>
<ul>
<li>This is not a general SAST/DAST scanner, authenticated pentest or proof that a project is secure.</li>
<li>BOLA/IDOR, business logic, LLM/OAuth, database isolation and most framework-specific paths remain
agent-guided and require project context.</li>
<li>Twenty-seven expected benign matches in the bounded ordinary-project review show that lexical
leads still need human review. No precision or recall percentage is claimed.</li>
<li>Authenticated browser DAST, universal language coverage, automatic exploit generation, unattended
patching, deployment and database migration are not provided.</li>
<li>No authenticated third-party deployment, production cloud account or upstream live system was
actively tested for this release.</li>
<li>Native Windows, PowerShell and WSL2 remain unsupported because no maintained verification
environment exists. Node 20 and earlier are not supported release targets.</li>
<li>Signatures, checksums and attestations establish artifact identity and build origin; they do not
prove that every security conclusion or proposed implementation is correct.</li>
</ul>
]]></content:encoded></item><item><title>PromptSign Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/promptsign-verify/</link><pubDate>Fri, 14 Aug 2026 06:10:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/promptsign-verify/</guid><description>Version updated for https://github.com/PromptSign/promptsign-verify to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks that AI instruction files in a repository, including skills and agent definitions, still have valid signatures from an expected publisher. It automates the verification process to prevent changes from introducing unsigned or invalid signatures into pull requests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PromptSign/promptsign-verify">https://github.com/PromptSign/promptsign-verify</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/promptsign-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks that AI instruction files in a repository, including skills and agent definitions, still have valid signatures from an expected publisher. It automates the verification process to prevent changes from introducing unsigned or invalid signatures into pull requests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds a <code>badge</code> input that writes a README badge SVG rendered from the run&rsquo;s own verification, naming
the identity it established. The file is committed in your repository. Nothing is hosted by PromptSign.</p>
<p>A failing run now reports &ldquo;verification failed&rdquo; rather than &ldquo;signature invalid&rdquo;, since a failure can equally mean
a policy rejection or a changed pin.</p>
]]></content:encoded></item><item><title>Install Python Tools with pipx</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/install-python-tools-with-pipx/</link><pubDate>Fri, 14 Aug 2026 06:09:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/install-python-tools-with-pipx/</guid><description>Version updated for https://github.com/python-build-tools/pipx-install-action to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary pipx-install is a GitHub Action that automates the installation of Python tools using pipx, which allows users to specify tooling prerequisites needed for CI/CD operations on a Python project. It caches installed files, supports pipx’s inject operation to install plugins, and can handle various version specifiers. The action is designed to simplify setting up Python environments in GitHub Actions workflows by providing a clear and user-friendly way to manage global tools like poetry, tox, and potheoet.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/python-build-tools/pipx-install-action">https://github.com/python-build-tools/pipx-install-action</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-python-tools-with-pipx">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>pipx-install</code> is a GitHub Action that automates the installation of Python tools using <code>pipx</code>, which allows users to specify tooling prerequisites needed for CI/CD operations on a Python project. It caches installed files, supports pipx&rsquo;s <code>inject</code> operation to install plugins, and can handle various version specifiers. The action is designed to simplify setting up Python environments in GitHub Actions workflows by providing a clear and user-friendly way to manage global tools like poetry, tox, and potheoet.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump @vercel/ncc from 0.38.4 to 0.44.1 in the npm-development group across 1 directory by @dependabot[bot] in <a href="https://github.com/python-build-tools/pipx-install-action/pull/20">https://github.com/python-build-tools/pipx-install-action/pull/20</a></li>
<li>migrate to ESM and upgrade @actions/* to latest majors by @BrandonLWhite in <a href="https://github.com/python-build-tools/pipx-install-action/pull/21">https://github.com/python-build-tools/pipx-install-action/pull/21</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/python-build-tools/pipx-install-action/pull/20">https://github.com/python-build-tools/pipx-install-action/pull/20</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/python-build-tools/pipx-install-action/compare/v1.2.0...v1.3.0">https://github.com/python-build-tools/pipx-install-action/compare/v1.2.0...v1.3.0</a></p>
]]></content:encoded></item><item><title>Quill Typst Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/quill-typst-validator/</link><pubDate>Fri, 14 Aug 2026 06:06:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/quill-typst-validator/</guid><description>Version updated for https://github.com/ReeseHatfield/quill to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Quill is an action that automates the validation of Typst files in a GitHub repository. It ensures all Typst documents compile without errors, allowing developers to catch issues early and improve code quality. The action supports ignoring specific files by adding // quill: ignore at the top of the .typ file. Users can integrate Quill into their workflows to validate Typst files as part of their development process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ReeseHatfield/quill">https://github.com/ReeseHatfield/quill</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quill-typst-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Quill is an action that automates the validation of Typst files in a GitHub repository. It ensures all Typst documents compile without errors, allowing developers to catch issues early and improve code quality. The action supports ignoring specific files by adding <code>// quill: ignore</code> at the top of the <code>.typ</code> file. Users can integrate Quill into their workflows to validate Typst files as part of their development process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial version of Quill. Include validator and ignore directoive</p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/custom-amazon-bedrock-agent-action/</link><pubDate>Fri, 14 Aug 2026 06:05:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR), providing tailored feedback. It enhances code quality, improves security, and supports performance optimizations by leveraging AI-powered insights from pre-configured prompts and integrated knowledge bases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR), providing tailored feedback. It enhances code quality, improves security, and supports performance optimizations by leveraging AI-powered insights from pre-configured prompts and integrated knowledge bases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Validate Syscribe Model</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/validate-syscribe-model/</link><pubDate>Fri, 14 Aug 2026 06:04:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/validate-syscribe-model/</guid><description>Version updated for https://github.com/sjames/syscribe to version v0.35.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Syscribe automates the conversion of SysMLv2 models into human-readable Markdown files. It solves problems related to understanding complex models, generating model documentation, and improving collaboration by enabling LLMs to interact with system requirements and architecture decisions through plain text files. The action provides capabilities for managing a wide range of model elements, including Requirements, TestCases, and Architecture Decision Records, while maintaining traceability across the project lifecycle.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sjames/syscribe">https://github.com/sjames/syscribe</a></strong> to version <strong>v0.35.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/validate-syscribe-model">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Syscribe automates the conversion of SysMLv2 models into human-readable Markdown files. It solves problems related to understanding complex models, generating model documentation, and improving collaboration by enabling LLMs to interact with system requirements and architecture decisions through plain text files. The action provides capabilities for managing a wide range of model elements, including Requirements, TestCases, and Architecture Decision Records, while maintaining traceability across the project lifecycle.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(sysmlv2): lift @Syscribe* metadata annotations for domain, integrity level, shortName, and implementedBy (#92) by @sjames in <a href="https://github.com/sjames/syscribe/pull/93">https://github.com/sjames/syscribe/pull/93</a></li>
<li>feat(sysmlv2): lift doc comments and connect endpoints (#94, #95) by @sjames in <a href="https://github.com/sjames/syscribe/pull/96">https://github.com/sjames/syscribe/pull/96</a></li>
<li>fix: n2 axis, doc lifts, connect resolution, W600 suppression, template PlanningItem (#97-#102) by @sjames in <a href="https://github.com/sjames/syscribe/pull/103">https://github.com/sjames/syscribe/pull/103</a></li>
<li>fix(sysmlv2): W542 truncated-connect warning + scoped typedBy: resolution for W600 (#104, #105) by @sjames in <a href="https://github.com/sjames/syscribe/pull/106">https://github.com/sjames/syscribe/pull/106</a></li>
<li>fix(sysmlv2): widen resolve_scoped_ref to W007 and graph.rs&rsquo;s TypedBy edge by @sjames in <a href="https://github.com/sjames/syscribe/pull/108">https://github.com/sjames/syscribe/pull/108</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sjames/syscribe/compare/v0.34.0...v0.35.0">https://github.com/sjames/syscribe/compare/v0.34.0...v0.35.0</a></p>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/update-a-config-file-with-values-from-environment/</link><pubDate>Fri, 14 Aug 2026 06:03:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The config-file-from-env GitHub Action reads environment variables from your repository and substitutes them into a specified configuration file. This action automates the process of managing dynamic configurations without hardcoding sensitive information directly into the codebase. It helps in maintaining a secure and flexible deployment environment by leveraging environment variables for configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>config-file-from-env</code> GitHub Action reads environment variables from your repository and substitutes them into a specified configuration file. This action automates the process of managing dynamic configurations without hardcoding sensitive information directly into the codebase. It helps in maintaining a secure and flexible deployment environment by leveraging environment variables for configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Fri, 14 Aug 2026 06:03:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The deploy-swarm-service GitHub Action is designed to automate the deployment of a Docker service on a Swarm cluster. It ensures that all necessary dependencies are installed and bundled before deploying, thereby reducing potential issues during runtime. This action helps streamline the process of deploying services in a containerized environment, making it easier to manage and scale applications across multiple nodes in a swarm.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>deploy-swarm-service</code> GitHub Action is designed to automate the deployment of a Docker service on a Swarm cluster. It ensures that all necessary dependencies are installed and bundled before deploying, thereby reducing potential issues during runtime. This action helps streamline the process of deploying services in a containerized environment, making it easier to manage and scale applications across multiple nodes in a swarm.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/ssg-static-site-generator/</link><pubDate>Fri, 14 Aug 2026 06:03:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.31.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into complete websites. It supports various themes, template engines, SEO features, and deployment options such as GitHub Pages, Cloudflare Pages, and FTP. The main purpose of SSG is to simplify the process of building websites quickly using plain text files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.31</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into complete websites. It supports various themes, template engines, SEO features, and deployment options such as GitHub Pages, Cloudflare Pages, and FTP. The main purpose of SSG is to simplify the process of building websites quickly using plain text files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: add site identity configuration, markup check, and repair tools… by @spagu in <a href="https://github.com/spagu/ssg/pull/126">https://github.com/spagu/ssg/pull/126</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.30...v1.8.31">https://github.com/spagu/ssg/compare/v1.8.30...v1.8.31</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/classroom-to-sheets-integration/</link><pubDate>Fri, 14 Aug 2026 06:02:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates Google Sheets with GitHub Classroom, automatically sending assignment results to specified columns. It uses service account credentials and Google Sheet IDs provided as secrets. The action dynamically updates or creates columns and rows in the sheet based on task results from other actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates Google Sheets with GitHub Classroom, automatically sending assignment results to specified columns. It uses service account credentials and Google Sheet IDs provided as secrets. The action dynamically updates or creates columns and rows in the sheet based on task results from other actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>nix init</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/nix-init/</link><pubDate>Fri, 14 Aug 2026 06:01:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/nix-init/</guid><description>Version updated for https://github.com/spotdemo4/nix-init to version v1.64.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action initializes Nix-based repositories by automating common setup tasks such as creating a GitHub app token, checking out the repository, setting up Git user information, configuring an optimal Nix environment, installing Nix, and optionally setting caching. It works with self-hosted/gitea/forgejo action runners and is designed to save time by reducing repetitive configuration steps across multiple workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spotdemo4/nix-init">https://github.com/spotdemo4/nix-init</a></strong> to version <strong>v1.64.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nix-init">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action initializes Nix-based repositories by automating common setup tasks such as creating a GitHub app token, checking out the repository, setting up Git user information, configuring an optimal Nix environment, installing Nix, and optionally setting caching. It works with self-hosted/gitea/forgejo action runners and is designed to save time by reducing repetitive configuration steps across multiple workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update dependency NixOS/nix to v2.35.2 (#7) (b3d3f16e51ecaa638455fa0b128b55f7346dd1ca)</li>
<li>bump: v1.63.0 -&gt; v1.64.0 (52b7e46ef1fb211e25e0f91e0ba9fdf2cb1c34e2)</li>
<li>chore(deps): lock file maintenance nix inputs (#5) (6ab15ded71a63ea0d672347abb8c46e51e145161)</li>
<li>chore(deps): update spotdemo4/nix-init action to v1.63.0 (#4) (9b754ca640ccf8a22418fd23e8e067e4adf7ece3)</li>
<li>chore(deps): update forgejo actions to v1.63.0 (#3) (4c7478b9a86f7897f5eaf86332a29545bc583b67)</li>
</ul>
]]></content:encoded></item><item><title>Build Watermark</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/build-watermark/</link><pubDate>Fri, 14 Aug 2026 06:00:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/build-watermark/</guid><description>Version updated for https://github.com/svaraborut/watermark to version v2.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically generates professional CI/CD watermarks for your projects, enhancing traceability and versioning by embedding build information directly into deployment assets. It allows users to configure customizable watermark formats, including automatic versioning based on dependencies or manual input, which helps in identifying builds quickly during troubleshooting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svaraborut/watermark">https://github.com/svaraborut/watermark</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-watermark">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically generates professional CI/CD watermarks for your projects, enhancing traceability and versioning by embedding build information directly into deployment assets. It allows users to configure customizable watermark formats, including automatic versioning based on dependencies or manual input, which helps in identifying builds quickly during troubleshooting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v2 - Template Values as Outputs
We are excited to announce the release of Watermark GitHub Action v2. This release builds on the watermark generation engine with direct access to every template value as its own output, plus new filename-safe variants for branches and tags.</p>
<p>Key features include:</p>
<ul>
<li>Individual outputs for every keyword: Every value used to build your watermark (REF, BRANCH, SHA, SHA7, VERSION, DATE, and more) is now exposed as its own action output, so you can use them directly without parsing a custom format.</li>
<li>BRANCH_FILE and BRANCH_PREFIX: Get the branch name in a filename-safe format, or just the portion before the first slash, ideal for grouping builds by branch naming convention (e.g. feat/my-feature) and creating safe preview deployments of individual branches.</li>
<li>TAG_FILE: A filename-safe version of the triggering tag, ready to use in artifact or file names.</li>
</ul>
<p>This release makes it easier to consume watermark data throughout your pipeline, beyond just the final formatted string, giving you more flexibility when naming build artifacts, deployments, and release assets.</p>
]]></content:encoded></item><item><title>Invisible Unicode Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/invisible-unicode-check/</link><pubDate>Fri, 14 Aug 2026 05:59:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/invisible-unicode-check/</guid><description>Version updated for https://github.com/tkm112345/invisible-unicode-check to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Invisible Unicode Check GitHub Action detects invisible Unicode used to smuggle malicious code into source files and blocks the pull request from being merged. It scans commit changes against a specified base commit (defaulting to the base commit of a pull request) and supports excluding specific files or directories from scanning, as well as silencing specific rules for certain paths.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tkm112345/invisible-unicode-check">https://github.com/tkm112345/invisible-unicode-check</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/invisible-unicode-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Invisible Unicode Check GitHub Action detects invisible Unicode used to smuggle malicious code into source files and blocks the pull request from being merged. It scans commit changes against a specified base commit (defaulting to the base commit of a pull request) and supports excluding specific files or directories from scanning, as well as silencing specific rules for certain paths.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="new-ignore-rules">New: <code>ignore-rules</code></h2>
<p>Disable <strong>specific rules</strong> for <strong>specific paths</strong>, without taking the file out of the scan.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">tkm112345/invisible-unicode-check@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">ignore-rules</span>: |<span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      # Arabic and Hebrew resources legitimately use directional markers
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      locales/**:IUC005,IUC010
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      # this vendored file mixes Greek symbols into identifiers
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      src/vendor/mathjax-shim.js:IUC012</span>
</span></span></code></pre></div><p><code>exclude</code> removes a file from the scan completely. <code>ignore-rules</code> keeps every other rule active and silences only the ones named — so a bidi override planted in <code>locales/ar/app.json</code> is still caught while <code>IUC005</code> is silenced there.</p>
<ul>
<li>A glob with no wildcard matches one file exactly, so <code>src/vendor/thing.js:IUC005</code> is a per-file switch.</li>
<li>Rule ids are case insensitive and <code>#</code> starts a comment.</li>
<li>An unknown rule id is reported as a warning instead of being silently accepted: a typo like <code>IUC0012</code> will not quietly disable anything.</li>
<li>Silencing a <strong>critical</strong> rule is allowed, but never silent. The run log states which blocking rule was disabled for which path, and the summary reports how many findings were suppressed:</li>
</ul>
<pre tabindex="0"><code>::warning::ignore-rules disables blocking rule(s) IUC001 for &#39;locales/**&#39;
Scanned 2 file(s): 0 critical, 1 warning(s), 1 suppressed by ignore-rules.
</code></pre><p>33 tests.</p>
]]></content:encoded></item><item><title>darnlink — self-healing Markdown links</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/darnlink-self-healing-markdown-links/</link><pubDate>Fri, 14 Aug 2026 05:58:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/darnlink-self-healing-markdown-links/</guid><description>Version updated for https://github.com/txemi/darnlink to version v0.22.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The darnlink GitHub Action automatically heals Markdown links by updating paths after file or folder moves, ensuring they continue to work correctly even as documentation evolves over time. It supports cross-repo web links and offers options for robustifying plain links with UUIDs. The action is user-friendly and can be used in one line without installation, making it a powerful tool for maintaining consistent links in documentation projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/txemi/darnlink">https://github.com/txemi/darnlink</a></strong> to version <strong>v0.22.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/darnlink-self-healing-markdown-links">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The darnlink GitHub Action automatically heals Markdown links by updating paths after file or folder moves, ensuring they continue to work correctly even as documentation evolves over time. It supports cross-repo web links and offers options for robustifying plain links with UUIDs. The action is user-friendly and can be used in one line without installation, making it a powerful tool for maintaining consistent links in documentation projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<blockquote>
<h3 id="-moving-your-pin-to-this-release-can-turn-a-green-gate-red--without-you-changing-anything">⚠️ Moving your pin to this release CAN turn a green gate red — without you changing anything</h3>
<p>Not because of the new keys: those are opt-in, and a repo that sets none of them behaves exactly as
it did on v0.21.0. It is the <strong>dangling</strong> fix below. Links with empty text — <code>![](photo.jpg)</code>, the
shape pandoc emits for every image in a converted document — were not being filtered out, they were
never <em>candidates</em>, so a tree full of broken embeds reported <code>dangling: 0</code>. Making them visible can
only push the count up.</p>
<p><strong>How likely is it to be you?</strong> Measured across a nine-repository fleet, each with its own config,
same command, only the version changing. Seven of them run <code>dangling: &quot;repo&quot;</code> with no ceiling — the
setting that turns a finding into a closed push wall — and <strong>two go red: 0 → 7 and 0 → 1. The other
five stay at 0 and notice nothing.</strong> An eighth, already at <code>warn</code>, moves 1704 → 1716; the ninth has
the axis off.</p>
<p>So: a minority, but not a rarity. Every single finding across the whole fleet was the same shape —
<code>media/imageN.{jpeg,png,emf}</code> or a <code>foto-*.jpg</code> inside a CV or attachment converted by pandoc — so
what it tracks is how many converted documents a tree carries.</p>
<p><strong>Before you upgrade:</strong> run the axis at <code>dangling: &quot;warn&quot;</code> to see your own number, then fix the
links or raise the ceiling. This is a fix uncovering debt you already had, not a new failure — but
it arrives as a red build either way, and being told afterwards is not being told.</p>
</blockquote>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong><code>darnlink-gate</code>: the <code>own_web</code> keys, so feature 016 can actually be switched on.</strong> The rule
shipped in v0.21.0 lives in the CLI; until now no gate invoked it, so it protected nothing. Both
recipes — bash and PowerShell — now read <code>own_web</code> (a list of owners), <code>own_web_from_origin</code> (bool)
and <code>own_web_max</code> (int) and pass them through — including an explicit <code>own_web_max: 0</code>, which the
PowerShell config reader dropped at first because it tests truthiness and PowerShell reads JSON <code>0</code>
as false. That is the one value whose distinction from <em>absent</em> is the whole point of the budget.</p>
<p>Three details keep it honest, and each is the same rule an existing key already follows:</p>
<ul>
<li><strong><code>own_web_from_origin</code> is its own key, not a sentinel inside the list</strong> — an owner literally
called <code>origin</code> has to stay expressible, the same reason the CLI has a flag rather than
<code>--own auto</code>.</li>
<li><strong>A non-numeric budget counts as ABSENT, never as infinite.</strong> Silently widening an allowance is
the one direction a config typo must not be able to go (<code>dangling_max</code> established this).</li>
<li><strong>An exit 1 is treated as likely-config, but only when this run passed an <code>own_*</code> flag.</strong> Feature
016 makes exit 1 reachable from configuration — a budget with no owners, an unresolvable origin —
and reporting that as a red gate would send someone hunting for broken links that do not exist.
But exit 1 is <em>not</em> exclusively a usage error: <code>uvx</code> exits 1 on its own failures and an uncaught
exception exits 1 too, so an unconditional reading would have turned those green for every
consumer with <code>web: true</code>, including repositories that never adopted 016 — a worse guarantee than
before the key existed. And it respects <code>fail_closed</code>: under fail-open the axis is dropped with a
warning, in CI it becomes 4, because there the gate <em>is</em> the wall and an axis that could not run
is not a pass. It is not routed to <code>bail()</code> either: that exits the script and would skip every
axis after this one, the bug this same pass was fixed for once already.</li>
</ul>
<p>The wiring is asserted on the <strong>invocation</strong>, not the verdict: without a token an unreadable
destination is <code>web_unverifiable</code> and the gate exits 0 whether or not the flags were passed, so a
verdict-based test cannot tell — and did not. Dropping the <code>--own</code> loop entirely left every other
recipe test green until the shim started recording argv.</p>
<p>Two further silent no-ops closed while wiring it, both found by mutation rather than by reading:</p>
<ul>
<li><strong>An empty owner entry passed without a word.</strong> <code>[&quot;&quot;]</code> flattens to exactly what an absent key
gives, so the list length is now read separately from its value — and a <em>partially</em> empty list is
named too, the case where the config lists three owners and the gate enforces one.</li>
<li><strong><code>web-check</code>&rsquo;s exit 4 had no test protecting it from the <code>rc&gt;3</code> fail-open heuristic.</strong> Its codes
are all in 0..4 and none of them means <em>unreachable</em>, which is why the web verdict is marked
final; remove that immunity and a genuine 4 — exactly how feature 016 reports an owned
destination with no uuid — turns into <strong>0</strong> under the default, with the suite green.</li>
</ul>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>Nothing had ever parsed <code>recipes/darnlink-gate.ps1</code>.</strong> The recipe tests skip on Windows and no CI
job ran <code>pwsh</code>, so a syntax error in the shipped PowerShell recipe would have reached consumers as
a script that does not start. CI now parses it. Parsing is not testing — it never runs the gate —
but it is the one failure mode a bash-only fleet cannot see at all.</p>
</li>
<li>
<p><strong>A link with empty text — <code>![](photo.jpg)</code>, what pandoc emits for every image in a converted
<code>.docx</code>/<code>.odt</code> — was invisible to every axis, not merely unreported.</strong> <code>MD_LINK_RE</code> required at
least one character of link text (<code>[^\]]+</code>), so such a link never matched: it was not a finding
that got filtered, it was never a candidate. The axis then printed <code>dangling: 0</code> over a tree full
of broken image embeds, which reads as <em>&ldquo;no broken links&rdquo;</em> but only ever meant <em>&ldquo;none of the
shapes the regex recognises&rdquo;</em>.</p>
<p>Measured on one repository running the wall at maximum, in its own gate scope: <strong>127 links with
empty text, 7 of them pointing at a target that does not exist</strong>, and the axis printed
<code>dangling: 0</code>. Since those files are converted documents, they arrive in blocks and nobody
re-reads them.</p>
<p>⚠️ <strong>Adopting this is not a no-op for a consumer.</strong> <code>MD_LINK_RE</code> has three call sites, so
the same repository also gains <strong>36 newly visible web links</strong> (none a <code>/blob/</code> URL today, so its
web gate does not flip — the shape of those URLs, not a guarantee), and <code>--create-readme</code> gains a
path where <code>![](media/)</code> can create a <code>README.md</code>. A repo at <code>dangling: repo</code> with <code>dangling_max</code>
unset goes <strong>0 → 7 and its push wall closes</strong>: fix the links or raise the ceiling <em>before</em> moving
the pin, not after.</p>
<p>Reported as the pandoc attribute suffix (<code>{width=&quot;1.1in&quot;}</code>) hiding the link; it was not.
The pattern stops at the <code>)</code> and never looks past it, so <code>![alt](x.jpg){width=&quot;1.1in&quot;}</code> was always
seen. The two shapes simply co-occur. Both are pinned in tests so the real cause — the empty text —
cannot be re-diagnosed from the same coincidence. <code>ROBUST_LINK_RE</code> widens alongside <code>MD_LINK_RE</code>,
so an anchored empty-text link cannot be plain to one function and robust to another — a coupling
that matters to the <strong>repair</strong> axis and has its own tests, since reverting that half alone leaves
every <code>dangling</code> test green. FR-051.</p>
</li>
</ul>
<h3 id="known-issues--read-this-before-moving-a-pin">Known issues — read this before moving a pin</h3>
<p>None is introduced by this release, but they belong where a consumer deciding on an upgrade will
see them rather than buried under <em>Fixed</em>. <strong>One of them is live</strong>; the rest are latent at 0
occurrences across thirteen repositories.</p>
<ul>
<li>
<p>⚠️ <strong>LIVE — balanced parentheses in a destination are truncated at the first <code>)</code></strong> (#71).
CommonMark allows them; <code>MD_LINK_RE</code> does not, so the link is cut short and reported dead while
the file it names sits on disk, clustered in mirrored attachment filenames (<code>(Parte 1)</code>,
<code>(February - Monthly)</code>). The report conceals itself: its own <code>(resolves to …)</code> supplies the
missing parenthesis, so the truncated path reads as complete, and a reader who checks finds the
file present and concludes the <em>gate</em> is broken.</p>
<p><strong>Size it by 20, not by 104.</strong> Two measurements of the same repository, and only the first is what
a wall would enforce:</p>
<table>
  <thead>
      <tr>
          <th>measurement</th>
          <th style="text-align: right">count</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>dangling</code> findings the gate <strong>emits</strong> that are truncations</td>
          <td style="text-align: right"><strong>20</strong></td>
      </tr>
      <tr>
          <td>truncated links <strong>in the tree</strong> whose paren-completed target exists</td>
          <td style="text-align: right">104</td>
      </tr>
  </tbody>
</table>
<p>An earlier version of this entry printed only the 104 and said raising <code>dangling</code> to <code>repo</code> &ldquo;would
close the wall on 104 files that exist&rdquo;. That is wrong: a wall counts what the axis emits, and
most of the 104 never reach it. The gap between the two is filters this note does not fully
account for, which is exactly why the actionable number is the one measured at the gate.</p>
<p>Pre-existing and orthogonal to this release.</p>
</li>
<li>
<p><strong><code>--write</code> detaches a pandoc attribute block</strong> (#65). The anchor lands between the link and its
<code>{…}</code>, so the block stops applying. Pre-existing: a non-empty link text has always done it. The
tests added here pin that the block is never <em>deleted</em>, which is the worse neighbour of the two.</p>
</li>
<li>
<p><strong><code>--write</code> silently drops a file&rsquo;s UTF-8 BOM</strong> (#68) on all four write paths. CRLF is preserved
meticulously; the BOM is not, and three places in this repo imply otherwise — including the CI
Windows matrix, whose stated purpose is BOM/CRLF and whose BOM fixture only covers the <em>read</em>
path, so it cannot see this.</p>
</li>
<li>
<p><strong>A trailing space in a destination makes <code>repair</code> emit a CONFLICT it cannot heal</strong> (#67):
a trailing space makes <code>names_md</code> false, the link is classified as a directory link and becomes a
<code>CONFLICT</code> diagnosed as <em>&ldquo;path and uuid disagree&rdquo;</em> — which is untrue, and <code>--write</code> never heals
it, so the gate stays red.</p>
</li>
</ul>
]]></content:encoded></item><item><title>verbatra</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/verbatra/</link><pubDate>Fri, 14 Aug 2026 05:56:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/14/verbatra/</guid><description>Version updated for https://github.com/verbatra/action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary verbatra is a GitHub Action that automates i18n translation tasks using OpenAI, Anthropic, Gemini, DeepL, or local/ self-hosted models. It reads locale files, detects missing or drifted translations, and fills gaps through AI translation. The action provides CI gate functionality for pull requests by checking if locales have drifted from the source.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/verbatra/action">https://github.com/verbatra/action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/verbatra">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>verbatra is a GitHub Action that automates i18n translation tasks using OpenAI, Anthropic, Gemini, DeepL, or local/ self-hosted models. It reads locale files, detects missing or drifted translations, and fills gaps through AI translation. The action provides CI gate functionality for pull requests by checking if locales have drifted from the source.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds a <code>command</code> input so the action can run the CLI&rsquo;s read-only commands, not only <code>translate</code>.</p>
<p><code>command: check</code> fails the job when a locale is missing or stale. <code>command: diff</code> fails it when there are pending changes, and lists the keys. Both are read-only: no provider call, no API key, no quota, so they work on pull requests from forks.</p>
<p><code>command</code> defaults to <code>translate</code>, so existing workflows are unaffected. <code>dry-run</code> applies to <code>translate</code> only and is rejected with the other commands rather than ignored.</p>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/odin-scan-smart-contract-security/</link><pubDate>Thu, 13 Aug 2026 22:28:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Odin Scan GitHub Action is an AI-powered tool that automatically scans smart contract code for vulnerabilities on CosmWasm, Solana, and EVM platforms. It integrates with GitHub Code Scanning to provide native security alerts and inline annotations in pull requests. The action supports multi-platform detection and configurable thresholds for severity levels, allowing developers to catch vulnerabilities early in the development process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Odin Scan GitHub Action is an AI-powered tool that automatically scans smart contract code for vulnerabilities on CosmWasm, Solana, and EVM platforms. It integrates with GitHub Code Scanning to provide native security alerts and inline annotations in pull requests. The action supports multi-platform detection and configurable thresholds for severity levels, allowing developers to catch vulnerabilities early in the development process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial Release</p>
<p>AI-powered smart contract security analysis, now integrated directly into your GitHub workflow.</p>
<p>✨ Features</p>
<p>Multi-Platform Support</p>
<ul>
<li>CosmWasm - Rust-based smart contracts for Cosmos SDK</li>
<li>Solana (SVM) - Anchor and native Solana programs</li>
<li>EVM - Solidity and Vyper contracts</li>
<li>Auto-detection - Automatically identifies platform from your repo</li>
</ul>
<p>GitHub Integration</p>
<ul>
<li>Code Scanning - SARIF upload for native security alerts in the Security tab</li>
<li>PR Comments - Severity summary and top findings posted directly on pull requests</li>
<li>Inline Annotations - Critical/high findings appear as errors, medium/low as warnings on diffs</li>
<li>Artifact Upload - Full JSON report available as workflow artifact</li>
</ul>
<p>Customization</p>
<ul>
<li>Severity Thresholds - Fail builds at critical, high, medium, or low severity</li>
<li>Platform Override - Force specific platform detection when auto-detect isn&rsquo;t enough</li>
<li>Timeout Control - Configurable analysis timeout (default: 30 minutes)</li>
<li>Flexible Triggers - Run on push, PR, schedule, or manual dispatch</li>
</ul>
<p>🚀 Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Security Scan</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&#39;on&#39;</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">main</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">security-events</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">api-key</span>: <span style="color:#e6db74">&#39;${{ secrets.ODIN_SCAN_API_KEY }}&#39;</span>
</span></span></code></pre></div><p>📋 Requirements</p>
<ul>
<li>Odin Scan Pro subscription - Required for API access</li>
<li>API Key - Generate at <a href="https://odinscan.ai/dashboard/settings">https://odinscan.ai/dashboard/settings</a></li>
<li>GitHub Permissions - contents: read, security-events: write (for SARIF), pull-requests: write (for
comments)</li>
</ul>
<p>🔧 Configuration</p>
<p>All Inputs</p>
<p>| ┌────────────────────┬─────────────────────┬──────────────────────────────────────────────┐ |
| │       Input        │       Default       │                 Description                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ api-key            │ Required            │ Your Odin Scan API key (odin_sk_*)           │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ platform           │ auto                │ Target platform: auto, cosmwasm, solana, evm │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ severity-threshold │ high                │ Fail at: critical, high, medium, low, none   │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ fail-on-findings   │ true                │ Whether to fail workflow on findings         │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ comment-on-pr      │ true                │ Post summary comment on PRs                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-sarif       │ true                │ Upload SARIF to Code Scanning                │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-artifact    │ true                │ Upload full report as artifact               │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ timeout            │ 1800                │ Max analysis wait time (seconds)             │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ github-token       │ ${{ github.token }} │ Token for PR comments and SARIF              │ |
| └────────────────────┴─────────────────────┴──────────────────────────────────────────────┘ |</p>
<p>All Outputs</p>
<ul>
<li>analysis-id - Unique analysis identifier</li>
<li>status - Analysis status (completed, failed)</li>
<li>total-findings - Total number of findings</li>
<li>critical-count, high-count, medium-count, low-count - Counts by severity</li>
<li>report-url - Link to full report on Odin Scan</li>
<li>sarif-file - Path to generated SARIF file</li>
</ul>
<p>📝 Example Workflows</p>
<p>Basic (Auto-detect)</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span></code></pre></div><p>EVM with Medium Threshold</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">platform</span>: <span style="color:#ae81ff">evm</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">severity-threshold</span>: <span style="color:#ae81ff">medium</span>
</span></span></code></pre></div><p>Only on Solidity Changes</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#39;**.sol&#39;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">foundry.toml</span>
</span></span></code></pre></div><p>🔒 Security &amp; Privacy</p>
<ul>
<li>All API communication over HTTPS (TLS 1.2+)</li>
<li>API keys automatically masked in logs</li>
<li>No data stored by the action (stateless)</li>
<li>See <a href="https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md">https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md</a> for details</li>
</ul>
<p>📖 Documentation</p>
<ul>
<li>Action README - <a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></li>
<li>Odin Scan Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
<li>Get API Key - <a href="https://app.odinscan.ai/settings">https://app.odinscan.ai/settings</a></li>
</ul>
<p>🐛 Known Limitations</p>
<ul>
<li>Private repos - Requires github-token with repo access</li>
<li>Large repos - May need increased timeout for complex codebases</li>
<li>Code Scanning - Requires GitHub Advanced Security on private repos</li>
</ul>
<p>🙏 Support</p>
<ul>
<li>Issues - <a href="https://github.com/Odin-Scan/odin-scan-action/issues">https://github.com/Odin-Scan/odin-scan-action/issues</a></li>
<li>Email - <a href="mailto:support@odinscan.ai">support@odinscan.ai</a></li>
<li>Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
</ul>
<hr>
<p>Full Changelog: <a href="https://github.com/Odin-Scan/odin-scan-action/commits/v1">https://github.com/Odin-Scan/odin-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>OSSystems Nix Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/ossystems-nix-actions/</link><pubDate>Thu, 13 Aug 2026 22:26:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/ossystems-nix-actions/</guid><description>Version updated for https://github.com/OSSystems/nix-actions to version v1.0.6.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the CI process for Nix flake repos by running checks and building specific attributes. It supports installing Nix and restoring a cache on hosted runners, and it can build hosts, packages, or dev shells as specified in the flake. The action is designed to be used within a job step and can run before or after other tasks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OSSystems/nix-actions">https://github.com/OSSystems/nix-actions</a></strong> to version <strong>v1.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ossystems-nix-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the CI process for Nix flake repos by running checks and building specific attributes. It supports installing Nix and restoring a cache on hosted runners, and it can build hosts, packages, or dev shells as specified in the flake. The action is designed to be used within a job step and can run before or after other tasks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixed">Fixed</h2>
<p><strong>A truncated Nix archive download no longer fails the job.</strong>
<code>nix-quick-install-action</code> pipes its download straight into <code>tar</code>, so a short
body cannot be retried: <code>curl --retry</code> is powerless once the bytes have reached
<code>tar</code>. The job died with <code>zstd: unexpected end of file</code>, and the reported
failure named the caller&rsquo;s job — <code>gofmt</code>, <code>lint</code> — rather than the download.</p>
<p>Both actions now fetch the archive to a file first and hand the verified copy to
<code>nix-quick-install-action</code> through its <code>nix_archives_url</code> input:</p>
<ul>
<li>Three bounded attempts with a growing wait, and an integrity check on each.
A body that arrives short but well-formed at the transfer level is the case
only the integrity check can catch; it drives a retry, not a job failure.</li>
<li>A download that never arrives intact fails with a message naming the URL, not
the extraction.</li>
<li>Only a 404 skips the retry — it means <code>nix-version</code> is not a version the
pinned release ships. A 5xx or an expired asset redirect is retried.</li>
<li><code>--speed-limit</code>/<code>--speed-time</code> bound a stalled body, so the retry is bounded
in wall time and not only in attempts.</li>
</ul>
<p>Reported downstream as InoBram/inobramxd#488.</p>
<h2 id="added">Added</h2>
<ul>
<li><strong><code>nix-version</code> input</strong>, on both <code>nix-actions</code> and <code>update-flake</code>. Default
<code>2.29.2</code>, which tracks the pinned <code>nix-quick-install-action</code> release&rsquo;s own
default. It must be a version that release ships.</li>
</ul>
<h2 id="tests">Tests</h2>
<p><code>tests/prefetch-nix-archive.test.sh</code> — 26 assertions against a local server that
reproduces each failure mode. It installs no Nix, so it still reports when the
Nix install itself is broken.</p>
<h2 id="upgrading">Upgrading</h2>
<p>No caller change is required. <code>@v1</code> now points at this release.</p>
]]></content:encoded></item><item><title>Otzaria Plugin Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/otzaria-plugin-validator/</link><pubDate>Thu, 13 Aug 2026 22:25:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/otzaria-plugin-validator/</guid><description>Version updated for https://github.com/Otzaria/otzaria-plugin-validator to version v1.10.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation, build, and publication process of an Otzaria plugin. It checks for specific errors during package creation and compilation, builds the .otzplugin file, and publishes it to Otzaria’s store automatically when pushing changes to the main branch. The action can also perform a full check on pull requests without requiring secrets but still validates the plugin.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Otzaria/otzaria-plugin-validator">https://github.com/Otzaria/otzaria-plugin-validator</a></strong> to version <strong>v1.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/otzaria-plugin-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation, build, and publication process of an Otzaria plugin. It checks for specific errors during package creation and compilation, builds the <code>.otzplugin</code> file, and publishes it to Otzaria&rsquo;s store automatically when pushing changes to the main branch. The action can also perform a full check on pull requests without requiring secrets but still validates the plugin.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="מה-חדש">מה חדש</h2>
<p><strong>חריג פס הכותרת ב-font-size.</strong> ולידציית העיצוב פסלה כל <code>font-size</code> בערך px קבוע, בעוד ש-DESIGN_GUIDE מחייב דווקא גדלים קשיחים בפס הכותרת — כדי שהפס לא יתנפח עם גופן הקריאה שהמשתמש בחר. תוסף שמימש את המפרט כלשונו נחסם מפרסום. כעת החריג נאכף לפי שם הסלקטור (<code>topbar</code> / <code>top-bar</code>, כבדוגמת המפרט), וכל שאר הכללים ממשיכים להיפסל. הודעת ההפרה מפנה לחריג.</p>
<p><strong>סנכרון מול ה-SDK:</strong> <code>calendar.getCities</code> (הרשאת <code>calendar.read</code>, מגרסה 0.9.97) והאירוע <code>calendar.city_changed</code>.</p>
<p><strong>בדיקות:</strong> 32 עוברות — כולל px מותר בפס, נפסל מחוצה לו, והחריג אינו זולג לכלל הבא.</p>
]]></content:encoded></item><item><title>Web App Security Skill</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/web-app-security-skill/</link><pubDate>Thu, 13 Aug 2026 22:23:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/web-app-security-skill/</guid><description>Version updated for https://github.com/parousia8888/web-app-security-skill to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security testing of web applications by leveraging AI coding agents to detect potential vulnerabilities such as OS command injection. It provides detailed explanations and remediation proposals, helping users understand how to secure their projects and ensure that changes do not introduce new risks. The action supports a wide range of programming languages and codebases, including JavaScript/TypeScript and Python Web code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/parousia8888/web-app-security-skill">https://github.com/parousia8888/web-app-security-skill</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/web-app-security-skill">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the security testing of web applications by leveraging AI coding agents to detect potential vulnerabilities such as OS command injection. It provides detailed explanations and remediation proposals, helping users understand how to secure their projects and ensure that changes do not introduce new risks. The action supports a wide range of programming languages and codebases, including JavaScript/TypeScript and Python Web code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v040-release-evidence">v0.4.0 release evidence</h1>
<p>Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.</p>
<p>Web App Security Skill v0.4.0 is the evidence-integrity and useful-detection release. It keeps the
agent-guided hardening methodology while making narrow automated results harder to overstate.</p>
<h2 id="release-identity">Release identity</h2>
<ul>
<li>Version/tag: <code>v0.4.0</code></li>
<li>Source identity: the commit peeled from the SSH-signed annotated tag; the exact 40-character SHA
is also recorded in <code>web-app-security-skill-0.4.0.release.json</code> and the provenance attestation.</li>
<li>Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.</li>
<li>External adapters: Gitleaks <code>8.30.1</code> and OSV-Scanner <code>2.5.0</code>, installed and pinned by the caller.</li>
</ul>
<p>The Markdown file is part of the source commit it describes, so it does not embed a fabricated
self-referential commit SHA. Verify the exact published identity with the signed tag and manifest.</p>
<h2 id="evidence-model-and-migration">Evidence model and migration</h2>
<p>Report v2 binds findings to subject, scope, rule revision, adapter and ruleset identity. Per-rule
coverage records discovered, eligible, scanned, excluded, skipped, truncated and failed work. A
missing or incomplete check is explicit <code>unknown</code>/unavailable evidence and cannot establish <code>fixed</code>.</p>
<p>Historical v1 reports remain readable but are never silently comparable. <code>migrate-report</code> records
their original SHA-256 and explicit user binding as non-comparable lineage; a new persisted v2 audit
is required before a later retest can prove a fix. Moved or cloned projects require explicit
<code>rebind</code> acknowledgement rather than path or repository-name inference. See
<a href="../report-v2-migration.md"><code>docs/report-v2-migration.md</code></a>.</p>
<h2 id="detection-and-reporting-changes">Detection and reporting changes</h2>
<ul>
<li>Built-in source checks remain deliberately narrow: lockfile absence, environment-named files,
public Node inspector bindings and common production source-map settings.</li>
<li>Gitleaks checks committed history and the working tree. OSV-Scanner checks supported recorded
lockfiles and may query the public OSV advisory service. Neither adapter is downloaded by the
product and project dependencies are not executed.</li>
<li>Every external scanner match is <code>suspected</code>. Gitleaks does not prove credential validity or
exposure; OSV does not prove reachability, deployed version or exploitability.</li>
<li>Reports separate <code>security_exposure</code>, <code>supply_chain</code>, <code>search_discoverability</code>, <code>reliability</code> and
<code>evidence_integrity</code>. A HIGH discoverability result is not a HIGH security vulnerability.</li>
<li>JSON, Markdown, HTML, SARIF and JUnit are committed as one private atomic evidence bundle after
sanitization and validation. Existing output is not overwritten.</li>
<li>The composite Action keeps v0.3 crawl behavior and adds source mode. External findings require an
acknowledged alert-owner policy before they can affect the configured gate.</li>
</ul>
<h2 id="five-project-evidence">Five-project evidence</h2>
<p>The dated <code>2026-08-14</code> corpus ran the complete v2 source path at immutable commits without probing a
hosted project or executing project dependencies.</p>
<table>
  <thead>
      <tr>
          <th>Project</th>
          <th style="text-align: right">Confirmed</th>
          <th style="text-align: right">Suspected</th>
          <th>Boundary</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Linkwarden</td>
          <td style="text-align: right">0</td>
          <td style="text-align: right">270</td>
          <td>OSV advisory rows are mutable suspected leads</td>
      </tr>
      <tr>
          <td>Healthchecks</td>
          <td style="text-align: right">0</td>
          <td style="text-align: right">98</td>
          <td>Gitleaks documentation/test matches suspected; OSV not applicable</td>
      </tr>
      <tr>
          <td>Open WebUI</td>
          <td style="text-align: right">0</td>
          <td style="text-align: right">144</td>
          <td>Source-map and OSV leads suspected; public <code>.map</code> delivery unknown</td>
      </tr>
      <tr>
          <td>Uptime Kuma</td>
          <td style="text-align: right">4</td>
          <td style="text-align: right">93</td>
          <td>Four low-severity missing-lockfile facts in independent <code>extra/</code> tools; external leads suspected</td>
      </tr>
      <tr>
          <td>Mealie</td>
          <td style="text-align: right">0</td>
          <td style="text-align: right">30</td>
          <td>Gitleaks test-material matches suspected</td>
      </tr>
  </tbody>
</table>
<p>These records demonstrate applicability, state discipline and false-positive closure. They are not
labelled benchmark data and do not support a precision/recall score. OSV counts can change as its
public advisory database changes. Reproduction commands and unreached surfaces are in
<a href="../case-studies/journeys/README.md"><code>docs/case-studies/journeys/</code></a>.</p>
<h2 id="regressions-fixed">Regressions fixed</h2>
<ul>
<li>Cross-project, tampered, forged, v1 or incomplete baselines cannot manufacture a fixed result.</li>
<li>Deep, large, unreadable, malformed and truncated source candidates remain visible in coverage.</li>
<li>Crawler-range, sitemap and AWS permission failures become unknown evidence, never a clean result.</li>
<li>Cross-domain severity is no longer combined into one security headline.</li>
<li>Evidence writes are private, atomic, non-overwriting and rolled back after handled failures.</li>
<li>External-tool missing/version/timeout/error/malformed paths fail closed; upstream OSV severity
cannot inflate local severity.</li>
<li>Duplicate Gitleaks rows are deduplicated while distinct fingerprints remain distinct; finding IDs
survive sanitizer patterns that resemble numeric account identifiers.</li>
</ul>
<p>The complete bug-to-test map is <a href="../regression-inventory.md"><code>docs/regression-inventory.md</code></a>.</p>
<h2 id="release-verification">Release verification</h2>
<p>The release workflow runs the full gate, builds every artifact twice and compares bytes, verifies
archive paths, manifest, SHA-256 list and SPDX 2.3 SBOM, then exercises an isolated v0.3.0-to-v0.4.0
upgrade plus clean install/version/start/upgrade/uninstall behavior. GitHub provenance is requested
only after those checks pass. A separate consumer repository verifies both backward-compatible crawl
mode and built-in source mode against the exact candidate/release commit.</p>
<p>Verify the published tag after release:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>git -c gpg.ssh.allowedSignersFile<span style="color:#f92672">=</span>.github/release-signers verify-tag v0.4.0
</span></span></code></pre></div><p>Verify downloaded assets with <code>SHA256SUMS</code>, then compare the manifest source commit with
<code>git rev-parse 'v0.4.0^{}'</code> and verify GitHub provenance. The post-publication verifier now trusts
the immutable v0.4.0 asset digests, and the documented bootstrap pins and verifies that verifier
before installation.</p>
<h2 id="unsupported-and-unknown">Unsupported and unknown</h2>
<ul>
<li>This is not a general SAST/DAST scanner, authenticated pentest or automatic patching system.</li>
<li>BOLA/IDOR, business logic, LLM/OAuth, database isolation and most framework-specific sinks remain
agent-guided and require project context.</li>
<li>No authenticated third-party deployment, production cloud account or upstream live system was
actively tested for this release.</li>
<li>Native Windows, PowerShell and WSL2 are unsupported because no maintained verification environment
exists. Node 20 and earlier are not supported release targets.</li>
<li>Release signatures, checksums and attestations establish artifact identity and build origin; they
do not prove every security conclusion is correct or that an installed project is secure.</li>
</ul>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/prowler-security-scan/</link><pubDate>Thu, 13 Aug 2026 22:22:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.39.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Prowler is an open-source, automated tool that helps organizations identify security risks and non-compliance issues in their cloud environments through a suite of security checks and compliance frameworks. It automates the process of scanning AWS and Azure environments to ensure compliance with industry standards and best practices, providing real-time monitoring and seamless integrations for simple, scalable, and cost-effective cloud security.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.39.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Prowler</strong> is an open-source, automated tool that helps organizations identify security risks and non-compliance issues in their cloud environments through a suite of security checks and compliance frameworks. It automates the process of scanning AWS and Azure environments to ensure compliance with industry standards and best practices, providing real-time monitoring and seamless integrations for simple, scalable, and cost-effective cloud security.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-new-features-to-highlight-in-this-version">✨ New features to highlight in this version</h1>
<p>Enjoy them all now for free at <a href="https://cloud.prowler.com/">https://cloud.prowler.com/</a></p>
<h2 id="-lighthouse-ai--finding-skills">🤖 Lighthouse AI — Finding Skills</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Lighthouse AI now embeds a Skills menu on every finding, answering the questions an analyst actually asks. <strong>Contextual Fix</strong> produces the fix for the finding, <strong>Triage Decision</strong> judges whether it is real and closes it out when it is not, and <strong>Systemic Scope</strong> determines whether the problem is a one-off or everywhere. A free-form &ldquo;Ask Lighthouse anything&rdquo; prompt sits in the same menu, and each run shows its progress and offers follow-up actions such as creating a Jira issue or muting the finding.</p>
<img width="3274" height="1796" alt="Lighthouse AI Skills menu on a finding resource" src="https://github.com/user-attachments/assets/7beccac4-f376-4218-b2fd-b60d2cf62ee4" />
<p>Read more in the <a href="https://docs.prowler.com/getting-started/products/prowler-cloud-lighthouse">Lighthouse AI documentation</a>.</p>
<h2 id="-azure-management-group-onboarding">☁️ Azure Management Group Onboarding</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Azure subscriptions no longer onboard one at a time. Choose &ldquo;Add Multiple Subscriptions With Azure Management Group&rdquo; in the add-provider wizard, enter the Microsoft Entra tenant ID, and authenticate once with a single tenant-wide service principal: Prowler discovers the entire management-group hierarchy under the tenant root, lets you select the subscriptions to onboard, and creates their providers with the management-group structure preserved. Azure now matches the one-step onboarding that AWS Organizations and GCP organizations already have.</p>
<img width="1815" height="1013" alt="Azure onboarding method selector with the Management Group option" src="https://github.com/user-attachments/assets/e9fc5714-cead-41b3-9fca-0cf702ea648f" />
<p>Read more in the <a href="https://docs.prowler.com/user-guide/tutorials/prowler-cloud-azure-management-groups">Azure Management Groups documentation</a>.</p>
<h2 id="-findings-triage--verify-manual-findings-as-pass">✅ Findings Triage — Verify MANUAL Findings as PASS</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Checks that require human judgment report <code>MANUAL</code> findings. For these findings, and only for them, the triage status selector now offers <strong>Resolved</strong>: choosing it asks for the required written evidence and verifies the finding as passing. The finding then reports an effective <code>PASS</code> while preserving the raw <code>MANUAL</code> scan result, across findings, finding groups, compliance reports, and scans, with the attestation&rsquo;s author, evidence, and validity always visible. Attestations expire automatically after 90 days, or as soon as a new scan reports a real failure, returning the finding to the review queue.</p>
<img width="3058" height="1796" alt="Triage status selector offering Resolved on a MANUAL finding" src="https://github.com/user-attachments/assets/20347e2b-3c82-4dcc-a89e-83a0e16398de" />
<img width="2966" height="1796" alt="Manual Pass details showing evidence, author, and validity" src="https://github.com/user-attachments/assets/f67b6bcf-9514-4fda-87d3-a2485e0b9616" />
<p>Read more in the <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-findings-triage#verify-a-manual-finding-as-pass">Findings Triage documentation</a>.</p>
<h2 id="-prowler-cloud-mcp--organizations-management-and-grouped-jira-dispatch">☁️ Prowler Cloud MCP — Organizations Management and Grouped Jira Dispatch</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>The hosted Prowler Cloud MCP server adds eight organization tools, so an agent can onboard and manage entire cloud organizations end to end: create the organization, discover its accounts, subscriptions, and projects, apply the selection, and manage the resulting providers. The tools cover AWS Organizations, GCP organizations, and Azure tenant root management groups, and they are available to Lighthouse AI.</p>
<p><code>prowler_send_findings_to_jira</code> also gains Cloud-only dispatch capabilities: select failed findings by check IDs against the latest completed scan, and send them in grouped mode, one Jira work item per check listing up to 50 affected resources, with per-group error reporting.</p>
<p>Read more in the <a href="https://docs.prowler.com/getting-started/basic-usage/prowler-mcp-tools">Prowler MCP tools documentation</a> and its <a href="https://docs.prowler.com/getting-started/basic-usage/prowler-mcp-tools#jira-operations">Jira operations reference</a>.</p>
<h2 id="-attack-paths--grouped-graph-with-outcome-destinations">🕸️ Attack Paths — Grouped Graph with Outcome Destinations</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>The Attack Paths graph now reads from source to destination. Resources of the same class collapse into a single expandable node with a count, clicking reveals its members, and every path terminates in an explicit outcome node naming the destination impact: code execution, privilege escalation, public exposure, or resource inventory. The per-account hub node is gone, and the clicked resource stays highlighted while its findings are expanded.</p>
<img width="1353" height="723" alt="Attack Paths graph from the Internet to a public exposure outcome node" src="https://github.com/user-attachments/assets/618f5ee9-7f0e-4065-a106-056f78a6608f" />
<p>Explore the full Attack Paths query catalog at <a href="https://hub.prowler.com/attack-paths">Prowler Hub</a>.</p>
<p>Read more in the <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-attack-paths">Attack Paths documentation</a>.</p>
<h2 id="-new-compliance-framework--cmmc-20">📚 New Compliance Framework — CMMC 2.0</h2>
<p>The Cybersecurity Maturity Model Certification (CMMC) is the certification the US Department of Defense requires from contractors and suppliers that handle federal contract data. Prowler now includes CMMC 2.0 as a universal framework with all 149 requirements defined by the CMMC Program rule (32 CFR Part 170), organized in its three levels:</p>
<ul>
<li><strong>Level 1 (Foundational):</strong> 15 requirements for the basic safeguarding of Federal Contract Information, from FAR 52.204-21.</li>
<li><strong>Level 2 (Advanced):</strong> 110 requirements from NIST SP 800-171 Rev 2, protecting Controlled Unclassified Information.</li>
<li><strong>Level 3 (Expert):</strong> 24 enhanced requirements from NIST SP 800-172 for the most sensitive programs.</li>
</ul>
<p>Requirements map to Prowler checks across AWS, Azure, GCP, Alibaba Cloud, Oracle Cloud, and Microsoft 365, so one framework reports the compliance posture of the whole estate.</p>
<p>Read more in the <a href="https://docs.prowler.com/user-guide/compliance/tutorials/compliance">Compliance documentation</a>.</p>
<h2 id="-checks">🔍 Checks</h2>
<h3 id="microsoft-365">Microsoft 365</h3>
<p>Twenty new Entra ID checks expand the coverage of CIS Microsoft 365 Foundations Benchmark v7.0.0:</p>
<ul>
<li><strong>Password protection:</strong> custom banned password list, on-premises enforcement, and lockout threshold and duration.</li>
<li><strong>Default user permissions:</strong> security group and Microsoft 365 group creation restricted, and guest invitations limited to allowed domains.</li>
<li><strong>Conditional Access:</strong> high and medium sign-in risk blocked, authentication transfer blocked, untrusted locations blocked, trusted named locations defined, sign-in frequency enforced, and token protection enforced.</li>
<li><strong>Sessions and authentication methods:</strong> idle session timeout configured, email one-time passcodes disabled, and Microsoft Authenticator context shown.</li>
<li><strong>PIM and access reviews:</strong> approval required to activate the Global Administrator and Privileged Role Administrator roles, and access reviews configured for guest users and privileged roles.</li>
</ul>
<p>Explore all Microsoft 365 checks at <a href="https://hub.prowler.com/check?provider=m365">Prowler Hub</a>.</p>
<h3 id="aws">AWS</h3>
<p>Two new checks detect hardcoded secrets:</p>
<ul>
<li><code>batch_job_definition_no_secrets</code> scans Batch job definition environment variables and command parameters. Thanks to @praneetrajv!</li>
<li><code>awslambda_layer_no_secrets_in_content</code> scans Lambda layer package content. Thanks to @ganiganesh25!</li>
</ul>
<p>Explore all AWS checks at <a href="https://hub.prowler.com/check?provider=aws">Prowler Hub</a>.</p>
<h2 id="-external-contributors">🙌 External Contributors</h2>
<p>Thank you to our community contributors for this release!</p>
<ul>
<li>@praneetrajv: AWS <code>batch_job_definition_no_secrets</code> check (<a href="https://github.com/prowler-cloud/prowler/pull/12117">#12117</a>)</li>
<li>@ganiganesh25: AWS <code>awslambda_layer_no_secrets_in_content</code> check (<a href="https://github.com/prowler-cloud/prowler/pull/12233">#12233</a>)</li>
<li>@andoniaf: GitHub <code>organization_repository_creation_limited</code> now reports low severity when repository creation is limited to private or internal visibility (<a href="https://github.com/prowler-cloud/prowler/pull/12164">#12164</a>)</li>
</ul>
<hr>
<h2 id="ui">UI</h2>
<h3 id="-added">🚀 Added</h3>
<ul>
<li>Manual verification workflow for <code>MANUAL</code> findings with evidence, effective <code>PASS</code> status, and expiration details <a href="https://github.com/prowler-cloud/prowler/pull/12253">(#12253)</a></li>
<li>Surface pre-configured credential creation links in the add-provider wizard. Cloudflare exposes the User API Token template and an Account-Owned template pinned to the Cloudflare Account ID entered in the wizard, GitHub exposes the personal-repositories template and an organization-scanning template pinned to the identifier entered in the wizard <a href="https://github.com/prowler-cloud/prowler/pull/12349">(#12349)</a></li>
<li>Attack Paths graph groups resources by class into expandable nodes and marks the query outcome as the terminal node, with the clicked resource highlighted while its findings are expanded (Prowler Cloud only) <a href="https://github.com/prowler-cloud/prowler/pull/12381">(#12381)</a></li>
<li>Azure Management Group onboarding: add every subscription in a tenant at once (Prowler Cloud only) <a href="https://github.com/prowler-cloud/prowler/pull/12386">(#12386)</a></li>
<li>Manage Lighthouse AI role permission in the role forms and role details, so permission to change the Lighthouse AI configuration can be granted or restricted independently of other permissions (Prowler Cloud only) <a href="https://github.com/prowler-cloud/prowler/pull/12412">(#12412)</a></li>
<li>CMMC 2.0 universal compliance framework rendering: dedicated icon, Domain/Level requirement mapper and cross-provider catalog tile <a href="https://github.com/prowler-cloud/prowler/pull/12414">(#12414)</a></li>
</ul>
<h3 id="-fixed">🐞 Fixed</h3>
<ul>
<li>Organization discovery describes a too-deep hierarchy in each provider&rsquo;s own vocabulary: AWS organizational units, Azure Management Groups, Google Cloud folders <a href="https://github.com/prowler-cloud/prowler/pull/12386">(#12386)</a></li>
<li><code>View Findings</code> on the Scans page no longer opens an empty list for users outside the UTC timezone <a href="https://github.com/prowler-cloud/prowler/pull/12411">(#12411)</a></li>
</ul>
<h2 id="api">API</h2>
<h3 id="-changed">🔄 Changed</h3>
<ul>
<li><code>GET /api/v1/users/me</code> membership relationships identify the active tenant with <code>meta.active</code> for JWT and API key authentication <a href="https://github.com/prowler-cloud/prowler/pull/12388">(#12388)</a></li>
</ul>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li>Tenant deletion no longer leaves memberships partially removed when exclusive-user cleanup fails <a href="https://github.com/prowler-cloud/prowler/pull/12379">(#12379)</a></li>
<li><code>/api/v1/accounts/saml/{organization_slug}/acs/</code> rejects non-POST requests before SAML response processing <a href="https://github.com/prowler-cloud/prowler/pull/12393">(#12393)</a></li>
<li>Social login derives a valid user name when identity providers omit the profile name <a href="https://github.com/prowler-cloud/prowler/pull/12413">(#12413)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-added-1">🚀 Added</h3>
<ul>
<li><code>batch_job_definition_no_secrets</code> check for AWS provider, scanning Batch job definition environment variables and command parameters for hardcoded secrets <a href="https://github.com/prowler-cloud/prowler/pull/12117">(#12117)</a></li>
<li>7 M365 Entra checks covering CIS Microsoft 365 Foundations Benchmark v7.0.0 password protection, default user permissions, and guest invitation domain restrictions <a href="https://github.com/prowler-cloud/prowler/pull/12153">(#12153)</a></li>
<li>7 M365 entra checks covering CIS Microsoft 365 Foundations Benchmark v7.0.0 Conditional Access (5.2.2.x) and idle session timeout controls <a href="https://github.com/prowler-cloud/prowler/pull/12154">(#12154)</a></li>
<li><code>entra_authentication_method_email_otp_disabled</code>, <code>entra_authentication_method_authenticator_show_context</code>, <code>entra_pim_global_administrator_approval_required</code>, <code>entra_pim_privileged_role_administrator_approval_required</code>, <code>entra_access_review_guest_users_configured</code> and <code>entra_access_review_privileged_roles_configured</code> checks for M365 provider covering CIS Microsoft 365 Foundations Benchmark v7.0.0 authentication method, PIM approval and access review controls <a href="https://github.com/prowler-cloud/prowler/pull/12155">(#12155)</a></li>
<li><code>awslambda_layer_no_secrets_in_content</code> check for AWS provider, scanning Lambda layer package content for hardcoded secrets <a href="https://github.com/prowler-cloud/prowler/pull/12233">(#12233)</a></li>
<li>CMMC 2.0 universal compliance framework (<code>cmmc_2.0</code>) with the 149 official requirements from 32 CFR Part 170 — Level 1 (15, 48 CFR 52.204-21), Level 2 (110, NIST SP 800-171 Rev 2) and Level 3 (24, NIST SP 800-172) — with AWS, Azure, GCP, Alibaba Cloud, Oracle Cloud and M365 check mappings and config guardrails <a href="https://github.com/prowler-cloud/prowler/pull/12401">(#12401)</a></li>
</ul>
<h3 id="-changed-1">🔄 Changed</h3>
<ul>
<li>GitHub <code>organization_repository_creation_limited</code> check now reports low severity for FAIL findings when repository creation is provably limited to private/internal visibility, instead of always reporting high <a href="https://github.com/prowler-cloud/prowler/pull/12164">(#12164)</a></li>
</ul>
<h3 id="-security">🔐 Security</h3>
<ul>
<li>HTML report header now HTML-escapes every provider identity field across all 23 providers, closing a stored XSS in the header block (Secur0, CWE-79) that was left unaddressed by the earlier finding-row fix in #12221 <a href="https://github.com/prowler-cloud/prowler/pull/12424">(#12424)</a></li>
</ul>
]]></content:encoded></item><item><title>RelayShield Secret Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/relayshield-secret-scan/</link><pubDate>Thu, 13 Aug 2026 22:21:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/relayshield-secret-scan/</guid><description>Version updated for https://github.com/relayshield/rsscan to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The rsscan GitHub Action automatically detects and blocks commits and builds introducing API keys, tokens, and other machine credentials in a repository by scanning added lines. It uses local patterns to detect common credential types, providing inline annotations on pull requests to help developers identify and address security issues early. The action is suitable for use with pre-commit hooks, GitHub Actions, GitLab CI/CD, CircleCI, Docker pipelines, and various other CI tools without requiring any additional configuration or setup beyond installation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/relayshield/rsscan">https://github.com/relayshield/rsscan</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/relayshield-secret-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>rsscan</code> GitHub Action automatically detects and blocks commits and builds introducing API keys, tokens, and other machine credentials in a repository by scanning added lines. It uses local patterns to detect common credential types, providing inline annotations on pull requests to help developers identify and address security issues early. The action is suitable for use with pre-commit hooks, GitHub Actions, GitLab CI/CD, CircleCI, Docker pipelines, and various other CI tools without requiring any additional configuration or setup beyond installation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="rsscan---deps"><code>rsscan --deps</code></h2>
<p>Counts the accounts that can publish into your npm dependencies.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rsscan
</span></span><span style="display:flex;"><span>rsscan --deps
</span></span></code></pre></div><p>A self-replicating npm worm does not start with malicious code. It starts with a maintainer account: an infostealer takes the publish token out of somebody&rsquo;s <code>.npmrc</code>, and a patch version nobody reads ships four steps before there is any artifact for a scanner to analyse.</p>
<p>Every package security tool reads the artifact. None of them can tell you how many humans hold publish rights over your tree.</p>
<p>An ordinary install of Next.js, React, TypeScript, ESLint, Jest, axios, Tailwind, Prettier and dotenv:</p>
<pre tabindex="0"><code>     433  dependencies in package-lock.json
     275  distinct publisher accounts can push code into them
     126  on personal webmail (no SSO, no central revocation)
      28  role or automation addresses
</code></pre><p>Reproduce it with <code>npm install --package-lock-only --ignore-scripts</code>, then <code>rsscan --deps</code>.</p>
<h3 id="what-it-does-not-do">What it does not do</h3>
<p>It counts, and deliberately stops there. No screening, no verdicts, and it names nobody: the output is integers.</p>
<ul>
<li><strong>Reads locally.</strong> No account, no API key, no telemetry. The only host it contacts is <code>registry.npmjs.org</code>.</li>
<li><strong>Unresolved packages are counted separately</strong> and never folded into the totals. A package whose publishers could not be looked up is not a package with no publishers.</li>
<li><strong>Always exits 0.</strong> There is no dependency count that constitutes a build failure, so this is a report and not a gate.</li>
</ul>
<h3 id="also-in-this-release">Also in this release</h3>
<ul>
<li><code>--org</code> remains opt-in and off by default.</li>
<li>The module docstring no longer implies a <code>--staged</code> flag exists. Staged is what you get without <code>--rev-range</code>.</li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/RelayShield/rsscan/compare/v0.1.3...v0.2.0">https://github.com/RelayShield/rsscan/compare/v0.1.3...v0.2.0</a></p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/kaniko-build-action/</link><pubDate>Thu, 13 Aug 2026 22:20:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, “Hello world docker action,” is designed to print a greeting message either in English or with a specified name. It automates tasks such as personalizing greetings and tracking timestamps for logging purposes. Key capabilities include customizable inputs for the person to greet and an output that provides the time of greeting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, &ldquo;Hello world docker action,&rdquo; is designed to print a greeting message either in English or with a specified name. It automates tasks such as personalizing greetings and tracking timestamps for logging purposes. Key capabilities include customizable inputs for the person to greet and an output that provides the time of greeting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>SFDT for Salesforce</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/sfdt-for-salesforce/</link><pubDate>Thu, 13 Aug 2026 22:19:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/sfdt-for-salesforce/</guid><description>Version updated for https://github.com/scoobydrew83/sfdt to version v0.22.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates Salesforce deployment, testing, quality analysis, and release management processes using the @sfdt/cli tool. It supports interactive workflows, automated release manifest generation, parallel Apex test execution with coverage enforcement, code and test quality analysis, pre-release validation checks, deployment rollback, post-deploy smoke testing, org metadata drift detection, multi-package project support, AI-powered deployment error log interpretation, PR descriptions and Slack messages, AI-generated code review, test failure analysis, changelog generation, and release notes. It also includes features like CI/CD pipeline templates, notifications, plugin architecture, and multi-channel messaging capabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scoobydrew83/sfdt">https://github.com/scoobydrew83/sfdt</a></strong> to version <strong>v0.22.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdt-for-salesforce">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates Salesforce deployment, testing, quality analysis, and release management processes using the <code>@sfdt/cli</code> tool. It supports interactive workflows, automated release manifest generation, parallel Apex test execution with coverage enforcement, code and test quality analysis, pre-release validation checks, deployment rollback, post-deploy smoke testing, org metadata drift detection, multi-package project support, AI-powered deployment error log interpretation, PR descriptions and Slack messages, AI-generated code review, test failure analysis, changelog generation, and release notes. It also includes features like CI/CD pipeline templates, notifications, plugin architecture, and multi-channel messaging capabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: release extension v0.13.0 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/336">https://github.com/scoobydrew83/sfdt/pull/336</a></li>
<li>chore: release v0.22.2 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/337">https://github.com/scoobydrew83/sfdt/pull/337</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scoobydrew83/sfdt/compare/v0.22.1...v0.22.2">https://github.com/scoobydrew83/sfdt/compare/v0.22.1...v0.22.2</a></p>
]]></content:encoded></item><item><title>CI Health Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/ci-health-audit/</link><pubDate>Thu, 13 Aug 2026 22:18:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/ci-health-audit/</guid><description>Version updated for https://github.com/sdxiaomage/ci-health-audit to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose and Functionality: The CI Health Audit GitHub Action performs a heuristic static audit of GitHub Actions workflows to identify common security and reliability risks. It checks for issues like un-pinned third-party actions, self-hosted runners, excessive permissions, dangerous event interpolation, insecure curl/wget usage, and mutable container tags.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sdxiaomage/ci-health-audit">https://github.com/sdxiaomage/ci-health-audit</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ci-health-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Purpose and Functionality:</strong> The CI Health Audit GitHub Action performs a heuristic static audit of GitHub Actions workflows to identify common security and reliability risks. It checks for issues like un-pinned third-party actions, self-hosted runners, excessive permissions, dangerous event interpolation, insecure <code>curl</code>/<code>wget</code> usage, and mutable container tags.</p>
<p><strong>Problems Solved:</strong> The action helps prevent potential vulnerabilities in CI processes by automating a manual static code analysis of workflows. It ensures that security best practices are followed and identifies common pitfalls early on.</p>
<p><strong>Key Capabilities:</strong> - Scans workflow YAML files locally. - Publishes a summary visible in the GitHub Job Summary page. - Allows setting a fail-on threshold for severity levels. - Provides focused remediation suggestions for identified issues. - Supports Markdown or JSON output formats.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Security and visibility release: Action inputs are passed through environment variables instead of inline shell interpolation; audit targets are confined to GITHUB_WORKSPACE; Markdown reports now appear in the GitHub Job Summary; findings include one optional free-diagnosis link; and wrapper tests cover safe, failing, missing, and hostile path inputs across the three hosted runner operating systems.</p>
]]></content:encoded></item><item><title>Set up Rust</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/set-up-rust/</link><pubDate>Thu, 13 Aug 2026 22:17:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/set-up-rust/</guid><description>Version updated for https://github.com/seapagan/setup-rust to version v1.0.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs a Rust toolchain specification and optional components and targets in a CI workflow. It automates the setup of Rust development environments by handling complex Rustup configurations and ensuring reproducible builds across different platforms. The action provides flexibility to install specific versions or nightly builds of Rust, as well as add custom Rustup components and targets for cross-compilation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seapagan/setup-rust">https://github.com/seapagan/setup-rust</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/set-up-rust">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs a Rust toolchain specification and optional components and targets in a CI workflow. It automates the setup of Rust development environments by handling complex Rustup configurations and ensuring reproducible builds across different platforms. The action provides flexibility to install specific versions or nightly builds of Rust, as well as add custom Rustup components and targets for cross-compilation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First stable release of <code>seapagan/setup-rust</code>.</p>
<ul>
<li>Installs a requested rustup toolchain specification, including explicit Rust versions and standard channels such as <code>stable</code>, <code>beta</code>, and <code>nightly</code>.</li>
<li>Installs optional rustup components and Rust targets.</li>
<li>Selects the requested toolchain for subsequent job steps through <code>RUSTUP_TOOLCHAIN</code>, without changing rustup&rsquo;s persistent default toolchain.</li>
<li>Integration-tested on GitHub-hosted Linux, Windows, and macOS runners.</li>
</ul>
<p>Installing a target provides Rust target support only. It does not install external linkers, SDKs, or cross-compilers.</p>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/update-a-config-file-with-values-from-environment/</link><pubDate>Thu, 13 Aug 2026 22:16:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The config-file-from-env GitHub Action replaces environment variables in a specified config file with their corresponding values. This automates the process of handling configuration files by dynamically inserting environment variable references into your configuration files, making them more flexible and easier to manage across different environments or deployments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>config-file-from-env</code> GitHub Action replaces environment variables in a specified config file with their corresponding values. This automates the process of handling configuration files by dynamically inserting environment variable references into your configuration files, making them more flexible and easier to manage across different environments or deployments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add support for .env files (e706be3)</li>
<li>chore: More info (d440258)</li>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Thu, 13 Aug 2026 22:16:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service. It performs two main tasks: first, it runs npm ci and npm run bundle to prepare the project for deployment; second, it commits the dist folder to the repository to ensure all necessary files are included in the build artifacts. This ensures that the service is ready to be deployed without errors.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service. It performs two main tasks: first, it runs <code>npm ci</code> and <code>npm run bundle</code> to prepare the project for deployment; second, it commits the <code>dist</code> folder to the repository to ensure all necessary files are included in the build artifacts. This ensures that the service is ready to be deployed without errors.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/classroom-to-sheets-integration/</link><pubDate>Thu, 13 Aug 2026 22:16:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates Google Sheets with GitHub Classroom to automatically send assignment results. It requires setting up Google Cloud credentials and secrets for authentication and sharing the sheet with the service account email. The workflow step should be configured to include task results and the corresponding table ID of the Google sheet.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates Google Sheets with GitHub Classroom to automatically send assignment results. It requires setting up Google Cloud credentials and secrets for authentication and sharing the sheet with the service account email. The workflow step should be configured to include task results and the corresponding table ID of the Google sheet.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>Tirith IaC Governance</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/tirith-iac-governance/</link><pubDate>Thu, 13 Aug 2026 22:15:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/tirith-iac-governance/</guid><description>Version updated for https://github.com/StackGuardian/tirith-iac-governance-action to version v2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose: The Tirith — IaC Governance plugin GitHub Action automates infrastructure governance by evaluating Terraform plans against policies using the Tirith CLI. It helps protect sensitive values, enforce centralised governance, and surface actionable results before changes are applied.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/StackGuardian/tirith-iac-governance-action">https://github.com/StackGuardian/tirith-iac-governance-action</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tirith-iac-governance">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Purpose</strong>: The <code>Tirith — IaC Governance plugin</code> GitHub Action automates infrastructure governance by evaluating Terraform plans against policies using the Tirith CLI. It helps protect sensitive values, enforce centralised governance, and surface actionable results before changes are applied.</p>
<p><strong>Problems Solved/Tasks Automated</strong>:</p>
<ul>
<li>Evaluates Terraform plans for compliance with defined policies.</li>
<li>Protects sensitive information from exposure during infrastructure deployment.</li>
<li>Enforces centralized governance policies across multiple pipelines.</li>
<li>Provides real-time feedback on policy violations through pull-request comments and check runs.</li>
</ul>
<p><strong>Key Capabilities Provided</strong>:</p>
<ul>
<li>Runs policies locally or remotely using StackGuardian credentials.</li>
<li>Supports both default local mode and remote evaluation modes.</li>
<li>Reports policy outcomes as sticky comments and check runs in pull requests, setting job exit codes to prevent changes from being applied if violations are found.</li>
</ul>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>[SG-4885] feat: the Tirith IaC Governance action — zero-config, with a credential-free local mode by @refeed in <a href="https://github.com/StackGuardian/tirith-iac-governance-action/pull/182">https://github.com/StackGuardian/tirith-iac-governance-action/pull/182</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/StackGuardian/tirith-iac-governance-action/compare/v1.0.0-beta...v2">https://github.com/StackGuardian/tirith-iac-governance-action/compare/v1.0.0-beta...v2</a></p>
]]></content:encoded></item><item><title>Gemini AI Triage Bot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/gemini-ai-triage-bot/</link><pubDate>Thu, 13 Aug 2026 22:14:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/gemini-ai-triage-bot/</guid><description>Version updated for https://github.com/sysv86/ai-triage-bot to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “AI Triage Bot” automates issue and pull request triaging using Gemini, a language model. It checks code claims against actual code to label issues (bug, enhancement, etc.) and pull requests (good-pr, needs-work) with comments. It also detects duplicates and floods, implements antispam and anti-abuse measures, and has optional features for GitHub Discussions Q&amp;amp;A, AI Agent PRs/issues opening, commit review, and workflow dispatch.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sysv86/ai-triage-bot">https://github.com/sysv86/ai-triage-bot</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gemini-ai-triage-bot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;AI Triage Bot&rdquo; automates issue and pull request triaging using Gemini, a language model. It checks code claims against actual code to label issues (<code>bug</code>, <code>enhancement</code>, etc.) and pull requests (<code>good-pr</code>, <code>needs-work</code>) with comments. It also detects duplicates and floods, implements antispam and anti-abuse measures, and has optional features for GitHub Discussions Q&amp;A, AI Agent PRs/issues opening, commit review, and workflow dispatch.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix(action): unique marketplace name and short description for validation (9cadc73)</li>
<li>feat: move action.yml to repo root for GitHub Marketplace listing (937cab8)</li>
<li>test(config): make env-dependent config tests runner-deterministic (2b7cd7f)</li>
<li>feat: publish AI Triage Bot — Gemini-powered issue/PR triage GitHub Action (d122cac)</li>
</ul>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/setup-tombi/</link><pubDate>Thu, 13 Aug 2026 22:13:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.4.0.
This action is used across all versions by 145 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi in your GitHub Actions workflow, allowing you to easily integrate Tombi into your CI/CD pipeline for managing dependencies. It supports installing a specific version of Tombi, using a lock file to resolve the version automatically, and verifying checksums to ensure integrity during installation. The action also offers options to enable or disable caching for efficient reuse of previously downloaded artifacts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>145</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up Tombi in your GitHub Actions workflow, allowing you to easily integrate Tombi into your CI/CD pipeline for managing dependencies. It supports installing a specific version of Tombi, using a lock file to resolve the version automatically, and verifying checksums to ensure integrity during installation. The action also offers options to enable or disable caching for efficient reuse of previously downloaded artifacts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.4.0">tombi v1.4.0</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1.3.5...v1.4.0">https://github.com/tombi-toml/setup-tombi/compare/v1.3.5...v1.4.0</a></p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/wails3-build-action/</link><pubDate>Thu, 13 Aug 2026 22:10:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action ToQuery/wails3-build-action@v3 automates the building of Wails.io v3 applications. It installs GoLang and NodeJS, builds the application, and optionally uploads the results to GitHub or a release on tag. Key capabilities include building for various platforms, obfuscation, caching, and uploading artifacts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>ToQuery/wails3-build-action@v3</code> automates the building of Wails.io v3 applications. It installs GoLang and NodeJS, builds the application, and optionally uploads the results to GitHub or a release on tag. Key capabilities include building for various platforms, obfuscation, caching, and uploading artifacts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>darnlink — self-healing Markdown links</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/darnlink-self-healing-markdown-links/</link><pubDate>Thu, 13 Aug 2026 22:09:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/darnlink-self-healing-markdown-links/</guid><description>Version updated for https://github.com/txemi/darnlink to version v0.21.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The darnlink GitHub Action automates the process of healing Markdown links in a documentation tree by automatically updating links’ paths and UUIDs when files are moved or refactored. It works with both local and cross-repo web links, providing deterministic self-healing capabilities for Markdown documents over time. The action is available on PyPI and can be easily integrated into workflows using uv tool to run it without installation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/txemi/darnlink">https://github.com/txemi/darnlink</a></strong> to version <strong>v0.21.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/darnlink-self-healing-markdown-links">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The darnlink GitHub Action automates the process of healing Markdown links in a documentation tree by automatically updating links&rsquo; paths and UUIDs when files are moved or refactored. It works with both local and cross-repo web links, providing deterministic self-healing capabilities for Markdown documents over time. The action is available on PyPI and can be easily integrated into workflows using <code>uv</code> tool to run it without installation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The web axis is forgiving by design: a destination that fetches 200 without a <code>uuid</code> is <code>web_unverifiable</code> and the run still exits 0, because the file lives in <strong>someone else&rsquo;s</strong> repository and cannot be fixed from here.</p>
<p>That is right for a third party and <strong>wrong for a destination you own</strong>: there it is not an external limitation, it is a missing two-line edit in a repo you control — and nothing ever told you so. This release closes that blind spot.</p>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>--own OWNER</code></strong> (repeatable, stripped and case-folded) names the owners you control. <strong><code>--own-from-origin</code></strong> adds this repository&rsquo;s <code>origin</code> owner — a separate flag rather than a magic <code>--own auto</code>, so an owner literally called <code>auto</code> stays expressible. If it cannot resolve, the run is a <strong>usage error</strong>, even when explicit owners were given: it is a request, not a fallback.</li>
<li><strong><code>web_own_no_uuid</code></strong> at exit <strong>4</strong>, not 3. Exit 3 promises &ldquo;re-run with <code>--write</code>&rdquo;, and darnlink cannot fix this one — the edit belongs to the destination repository. The message names owner, repo and path, and never suggests <code>--write</code>.</li>
<li><strong><code>--own-max N</code></strong> budgets it, so a repository can adopt the rule before reaching zero. The budget silences the <em>verdict</em>, never the <em>finding</em>, and never shields another exit-4 cause. The report says where the count stands in all four cases — including <strong>over</strong> budget, because a budget that goes silent exactly when it is exceeded is the one moment its number is worth reading.</li>
<li><strong><code>&lt;!-- darnlink-own-exempt --&gt;</code></strong> for a destination that is machine-regenerated, where a <code>uuid</code> is futile: the next refresh wipes it and the anchor points at nothing. It exempts from the new finding, from anchoring, and from <code>web_mismatch</code> — a regenerating destination is precisely one whose uuid drifts. Honoured <strong>with or without an owner set</strong>: it states a property of the link, not of the run.</li>
</ul>
<p>Two exclusions, both textual and offline: a destination that is not <code>.md</code> can never carry frontmatter, and one pinned to a <strong>commit SHA</strong> can never be given one retroactively. <strong>Tags are deliberately not excluded</strong> — a tag is textually indistinguishable from a branch of the same name, so honouring it would need the network <em>and</em> would exclude a maintenance branch for <em>looking</em> like a tag, which is a false green.</p>
<h3 id="compatibility">Compatibility</h3>
<p><strong>Opt-in throughout.</strong> With no owner set, behaviour is byte-identical in the text report, the exit code and the files on disk — measured across 13,500 cases — with two departures the specification names: the exemption marker, and three keys <code>--json</code> gains unconditionally so a consumer can tell both that the axis ran and under what budget.</p>
<h3 id="upgrading">Upgrading</h3>
<p>Bump your pinned ref to <code>v0.21.0</code>. Nothing changes until you pass <code>--own</code>.</p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/vibgrate-scan/</link><pubDate>Thu, 13 Aug 2026 22:08:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.813.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the process of identifying codebase drift, drift score, risk score, and prioritized upgrade priorities for AI coding agents. It provides a deterministic code graph and runtime/framework lag assessment, dependency age and EOL proximity scoring, and prioritized fix lists to help developers ensure their projects are up-to-date with dependencies and frameworks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.813.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the process of identifying codebase drift, drift score, risk score, and prioritized upgrade priorities for AI coding agents. It provides a deterministic code graph and runtime/framework lag assessment, dependency age and EOL proximity scoring, and prioritized fix lists to help developers ensure their projects are up-to-date with dependencies and frameworks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268131">Vibgrate CLI 2026.813.1</h1>
<p><em>Released 2026-08-13</em></p>
<p>This release of the Vibgrate CLI includes several important fixes and enhancements to improve the user experience and accuracy of scans. Notably, architecture layer detection has been expanded to support a wider range of languages and frameworks.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="new">New</h3>
<ul>
<li>Architecture layer detection now recognizes .NET solutions, classifying C#, F#, VB, and Razor files according to PascalCase conventions and common NuGet packages.</li>
<li>Architecture layer detection has been extended to cover multiple languages, including Java, Python, Go, Ruby, PHP, Swift, Dart, and Elixir, with popular packages mapped to layer tech stacks.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>vg fix --dry-run</code> no longer prompts for a plan tier, allowing for a preview of the recommended plan without writing files.</li>
<li><code>vg scan</code> now correctly sends the repository&rsquo;s git remote URL during the pre-scan check, preventing miscounts of repositories in fresh clones.</li>
<li>Scans on Windows now report project paths consistently with <code>/</code> separators, ensuring proper deduplication and sorting across different scanners.</li>
<li><code>vg daemon ensure</code> now waits up to 30 seconds for the background daemon to respond, addressing issues with flaky status confirmations on slow cold starts.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.807.1, interleaved on one runner against the pinned corpus (189 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21609 count</td>
          <td>21609 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>10848 count</td>
          <td>10848 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.94 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>545.40 ms</td>
          <td>544 ms</td>
      </tr>
  </tbody>
</table>
<p>2 regression(s) — published, not omitted:</p>
<ul>
<li>Tasks passed on both arms: 33 → 31 (-6.1%)</li>
<li>Comparable-task rate (both arms passed / total): 0.94 → 0.89 (-6.1%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.813.1">https://vibgrate.com/changelog/cli/2026.813.1</a></p>
]]></content:encoded></item><item><title>Symfony Security Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/symfony-security-auditor/</link><pubDate>Thu, 13 Aug 2026 22:07:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/symfony-security-auditor/</guid><description>Version updated for https://github.com/vinceAmstoutz/symfony-security-auditor to version 1.19.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is an AI-powered security auditor for Symfony applications that targets application-level logic flaws missed by traditional static analysis tools and multi-agent review loops. It provides a comprehensive, adversarial approach to auditing Symfony projects and can emit validated reports in various output formats including console, JSON, SARIF, HTML, and Markdown.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vinceAmstoutz/symfony-security-auditor">https://github.com/vinceAmstoutz/symfony-security-auditor</a></strong> to version <strong>1.19.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/symfony-security-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is an AI-powered security auditor for Symfony applications that targets application-level logic flaws missed by traditional static analysis tools and multi-agent review loops. It provides a comprehensive, adversarial approach to auditing Symfony projects and can emit validated reports in various output formats including console, JSON, SARIF, HTML, and Markdown.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: sync 1.x changelog after the 1.19.0 release by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/306">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/306</a></li>
<li>ci: auto-tag and draft a release on a release commit by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/307">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/307</a></li>
<li>ci: add a manual replay trigger to Auto Release by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/308">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/308</a></li>
<li>ci: allow the release scope and require squash-merge by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/309">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/309</a></li>
<li>ci(release): add an optional publish input to Auto Release by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/310">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/310</a></li>
<li>docs: fix inaccuracies in the 1.19.0 changelog by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/317">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/317</a></li>
<li>chore(release): prepare 1.19.1 by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/321">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/321</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.19.0...1.19.1">https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.19.0...1.19.1</a></p>
]]></content:encoded></item><item><title>agents-md-facts check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/agents-md-facts-check/</link><pubDate>Thu, 13 Aug 2026 22:06:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/agents-md-facts-check/</guid><description>Version updated for https://github.com/Wolfe-Jam/agents-md-facts to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The agents-md-facts GitHub Action generates a minimal AGENTS.md file from repository facts without guessing or introducing unnecessary information. It automates the process of documenting build and testing commands, entry points, toolchain conventions, and security settings to ensure clarity and efficiency in project management. The action checks for drift between the generated AGENTS.md and the repository to prevent issues during CI pipelines and ensures that the file is kept up-to-date.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Wolfe-Jam/agents-md-facts">https://github.com/Wolfe-Jam/agents-md-facts</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-md-facts-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The agents-md-facts GitHub Action generates a minimal AGENTS.md file from repository facts without guessing or introducing unnecessary information. It automates the process of documenting build and testing commands, entry points, toolchain conventions, and security settings to ensure clarity and efficiency in project management. The action checks for drift between the generated AGENTS.md and the repository to prevent issues during CI pipelines and ensures that the file is kept up-to-date.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="agents-md-facts-010">agents-md-facts 0.1.0</h2>
<p>Author a minimal AGENTS.md from your repo&rsquo;s facts. Never guessed.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx agents-md-facts
</span></span></code></pre></div><h3 id="highlights">Highlights</h3>
<ul>
<li>Detected commands, entry points, conventions</li>
<li>Non-destructive refresh markers</li>
<li>CI Action: <code>Wolfe-Jam/agents-md-facts@v0.1.0</code></li>
<li>Examples: Node/TS, Python, Rust, Go</li>
<li>Vendor-free; built on the open <a href="https://agents.md">AGENTS.md</a> standard</li>
</ul>
<p>npm: <code>agents-md-facts@0.1.0</code></p>
]]></content:encoded></item><item><title>Overweight-Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/overweight-guard/</link><pubDate>Thu, 13 Aug 2026 22:05:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/overweight-guard/</guid><description>Version updated for https://github.com/yoavniran/overweight to version v2.2.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Overweight: An all-in-one toolkit for managing and optimizing bundle sizes. It provides a CLI, Node API, and GitHub Action to automate the process of keeping your project’s asset sizes within acceptable limits. The tool supports various testers (gzip, brotli) and allows custom logic through extensions. With its configuration flexibility and extensibility, Overweight simplifies tracking changes in file sizes during development and ensures efficient code delivery.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yoavniran/overweight">https://github.com/yoavniran/overweight</a></strong> to version <strong>v2.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/overweight-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Overweight</strong>: An all-in-one toolkit for managing and optimizing bundle sizes. It provides a CLI, Node API, and GitHub Action to automate the process of keeping your project&rsquo;s asset sizes within acceptable limits. The tool supports various testers (gzip, brotli) and allows custom logic through extensions. With its configuration flexibility and extensibility, Overweight simplifies tracking changes in file sizes during development and ensures efficient code delivery.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="220-2026-08-13"><a href="https://github.com/yoavniran/overweight/compare/v2.1.0...v2.2.0">2.2.0</a> (2026-08-13)</h2>
<h3 id="features">Features</h3>
<ul>
<li>add typings (<a href="https://github.com/yoavniran/overweight/commit/1786d19a69166d4d300d42c20e21f1dcb42b75a4">1786d19</a>)</li>
<li>add typings (<a href="https://github.com/yoavniran/overweight/issues/65">#65</a>) (<a href="https://github.com/yoavniran/overweight/commit/8cf32678ba82eb89175ca52060c1a20bed5b9d1d">8cf3267</a>)</li>
</ul>
]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/kover-report-action/</link><pubDate>Thu, 13 Aug 2026 22:04:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.27.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating and reporting code coverage from Kover XML reports in Kotlin/Android projects. It supports multi-module support, flexible discovery methods, configurable thresholds, PR integration with coverage reports, and automatic updates, as well as tracking coverage history and trends.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v3.1.27</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating and reporting code coverage from Kover XML reports in Kotlin/Android projects. It supports multi-module support, flexible discovery methods, configurable thresholds, PR integration with coverage reports, and automatic updates, as well as tracking coverage history and trends.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3.1.27: PR #164 - chore(deps): update dependency @biomejs/biome to v2.5.6</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/b.ia-accessibility-checker/</link><pubDate>Thu, 13 Aug 2026 22:02:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines by mapping guidelines and using AI to evaluate code against predefined requirements. It helps companies ensure their products are accessible by focusing on an audience with the highest potential impact, thus reducing costs associated with implementing accessibility solutions for various user groups.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines by mapping guidelines and using AI to evaluate code against predefined requirements. It helps companies ensure their products are accessible by focusing on an audience with the highest potential impact, thus reducing costs associated with implementing accessibility solutions for various user groups.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>ReleaseGuard - Release Asset Quality Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/releaseguard-release-asset-quality-gate/</link><pubDate>Thu, 13 Aug 2026 22:01:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/releaseguard-release-asset-quality-gate/</guid><description>Version updated for https://github.com/zhaoryder/releaseguard to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ReleaseGuard is a tool that inspects GitHub Release assets to catch common issues such as missing platforms, mislabeled architectures, empty installers, version drift, and missing checksums. It helps users choose the correct download based on their OS and CPU architecture, ensuring downloads are reliable and accurate.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zhaoryder/releaseguard">https://github.com/zhaoryder/releaseguard</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/releaseguard-release-asset-quality-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>ReleaseGuard is a tool that inspects GitHub Release assets to catch common issues such as missing platforms, mislabeled architectures, empty installers, version drift, and missing checksums. It helps users choose the correct download based on their OS and CPU architecture, ensuring downloads are reliable and accurate.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>ReleaseGuard v0.1.0 restores the release and adds a practical download advisor.</p>
<h2 id="what-it-does">What it does</h2>
<ul>
<li>Checks GitHub Release assets and quality gates.</li>
<li>Detects the current platform and architecture.</li>
<li>Recommends the exact installer to download, with a reason and alternatives.</li>
<li>Supports explicit checks with <code>--platform</code> and <code>--arch</code> when reviewing a release for another machine.</li>
<li>Runs locally; no telemetry, uploads, or model calls.</li>
</ul>
<h2 id="quick-start">Quick start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx --yes github:zhaoryder/releaseguard check zhaoryder/releaseguard
</span></span><span style="display:flex;"><span>npx --yes github:zhaoryder/releaseguard check zhaoryder/releaseguard --platform macos --arch arm64
</span></span></code></pre></div><p>The same release includes installers for macOS (Apple Silicon, Intel, universal), Windows (x64, ARM64, x86), and Linux (x64/ARM64 AppImage and deb), plus native packages and checksums.</p>
<p>The previous release attachments deleted from GitHub could not be reconstructed byte-for-byte; this release was rebuilt from the preserved source and successful CI artifacts. The original v0.1.0 commit is retained as <code>v0.1.0-legacy</code>.</p>
]]></content:encoded></item><item><title>Zuke Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/zuke-build/</link><pubDate>Thu, 13 Aug 2026 22:00:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/zuke-build/</guid><description>Version updated for https://github.com/zuke-build/zuke to version ai-v2.2.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is designed to automate continuous integration (CI) processes for Deno projects. It simplifies the setup of CI pipelines by providing a predefined set of steps that include building, testing, and deploying code changes. The action automates many common tasks related to Deno development, reducing manual effort and ensuring consistency across different environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zuke-build/zuke">https://github.com/zuke-build/zuke</a></strong> to version <strong>ai-v2.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zuke-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is designed to automate continuous integration (CI) processes for Deno projects. It simplifies the setup of CI pipelines by providing a predefined set of steps that include building, testing, and deploying code changes. The action automates many common tasks related to Deno development, reducing manual effort and ensuring consistency across different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="220-2026-08-13"><a href="https://github.com/zuke-build/zuke/compare/ai-v2.1.1...ai-v2.2.0">2.2.0</a> (2026-08-13)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>gh:</strong> release-asset uploads, the Gemini extension archive, and a coverage push to 98% (<a href="https://github.com/zuke-build/zuke/issues/352">#352</a>) (<a href="https://github.com/zuke-build/zuke/commit/a678f35c3baea51ebb837dbf2cc0e100760ff0ae">a678f35</a>)</li>
</ul>
]]></content:encoded></item><item><title>Git Velocity Analyser</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/git-velocity-analyser/</link><pubDate>Thu, 13 Aug 2026 14:20:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/git-velocity-analyser/</guid><description>Version updated for https://github.com/lukaszraczylo/git-velocity to version v1.0.20.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Git Velocity is a GitHub Action that analyzes your GitHub repositories to generate a game-like dashboard showing developer velocity metrics. It automates the process of tracking and visualizing code contributions, pull requests, issues, and more, providing gamification features like achievements, leaderboards, and streaks. The action supports local Git analysis for faster performance and is available as both a Go tool and a binary download.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lukaszraczylo/git-velocity">https://github.com/lukaszraczylo/git-velocity</a></strong> to version <strong>v1.0.20</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/git-velocity-analyser">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Git Velocity is a GitHub Action that analyzes your GitHub repositories to generate a game-like dashboard showing developer velocity metrics. It automates the process of tracking and visualizing code contributions, pull requests, issues, and more, providing gamification features like achievements, leaderboards, and streaks. The action supports local Git analysis for faster performance and is available as both a Go tool and a binary download.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/lgtmaybe/</link><pubDate>Thu, 13 Aug 2026 14:19:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v1.14.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, lgtmaybe, automates code reviews by analyzing pull request diffs using an OpenAI-compatible model. It identifies logic and correctness bugs, security vulnerabilities, missing tests, outdated or incorrect code, performance regressions, unnecessary complexity, intent misalignment, and potential “ponytail” code. The tool does not run the code but relies on context from surrounding lines in files to provide detailed reviews, reducing false positives.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v1.14.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, lgtmaybe, automates code reviews by analyzing pull request diffs using an OpenAI-compatible model. It identifies logic and correctness bugs, security vulnerabilities, missing tests, outdated or incorrect code, performance regressions, unnecessary complexity, intent misalignment, and potential &ldquo;ponytail&rdquo; code. The tool does not run the code but relies on context from surrounding lines in files to provide detailed reviews, reducing false positives.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1140-2026-08-13"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v1.13.1...lgtmaybe-v1.14.0">1.14.0</a> (2026-08-13)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>engine:</strong> add a spec lens that checks the PR against its committed spec (<a href="https://github.com/MattJColes/lgtmaybe/issues/376">#376</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/d55e35e7ceb7e7681bd8d463e70937b5e76e2c17">d55e35e</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>stop one flaky provider call voiding a whole review round (<a href="https://github.com/MattJColes/lgtmaybe/issues/378">#378</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/6c59f861e87b6e465a25275ed553c25335fb591f">6c59f86</a>)</li>
</ul>
<h3 id="dependencies">Dependencies</h3>
<ul>
<li>bump the python-dependencies group and unblock pip-audit on aiohttp (<a href="https://github.com/MattJColes/lgtmaybe/issues/379">#379</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/d296f252573109fa23a3682c9ef8018cba4a8e0d">d296f25</a>)</li>
</ul>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/totem-shield/</link><pubDate>Thu, 13 Aug 2026 14:18:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.116.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based toolkit that helps teams maintain project architecture and consistency by enforcing rules derived from plain-text lessons. It uses a local, zero-LLM linter to enforce these rules, ensuring deterministic behavior and reducing the risk of architectural mistakes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.116.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a file-based toolkit that helps teams maintain project architecture and consistency by enforcing rules derived from plain-text lessons. It uses a local, zero-LLM linter to enforce these rules, ensuring deterministic behavior and reducing the risk of architectural mistakes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>GuardSmith Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/guardsmith-lint/</link><pubDate>Thu, 13 Aug 2026 14:17:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/guardsmith-lint/</guid><description>Version updated for https://github.com/novexar/Guardsmith to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GuardSmith is a governance tool that standardizes AI development standards and automates code review. It provides features such as generating new projects from templates, automating static analysis checks, identifying drift in policies, integrating into CI/CD pipelines, and managing multi-layered environments (OSS baseline + organization overlay + project-specific layers).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/novexar/Guardsmith">https://github.com/novexar/Guardsmith</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/guardsmith-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>GuardSmith is a governance tool that standardizes AI development standards and automates code review. It provides features such as generating new projects from templates, automating static analysis checks, identifying drift in policies, integrating into CI/CD pipelines, and managing multi-layered environments (OSS baseline + organization overlay + project-specific layers).</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li><strong>GitHub Action moved to the repository root</strong> — use it with a single line:
<code>uses: novexar/Guardsmith@v0.3.0</code> (the old <code>packages/action</code> path is removed)</li>
<li><strong>npx-based execution</strong> — the action now runs the published CLI via
<code>npx @guardsmith/cli</code> (pinned with the <code>cli-version</code> input) instead of
checking out this repository and installing dependencies. Setup steps are gone
and runs are faster. The <code>guardsmith-ref</code> input is replaced by <code>cli-version</code>.</li>
<li>npm packages (<code>@guardsmith/core</code> / <code>@guardsmith/cli</code>) remain at <strong>0.2.1</strong> — the CLI itself is unchanged.</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">GuardSmith</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>: [<span style="color:#ae81ff">pull_request]</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">guard</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">novexar/Guardsmith@v0.3.0</span>
</span></span></code></pre></div><p>On violations the job fails, the console report lands in the Job Summary, a SARIF
report is uploaded (Code Scanning / artifact), and a summary comment is posted on the PR.</p>
]]></content:encoded></item><item><title>Nuon CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/nuon-cli/</link><pubDate>Thu, 13 Aug 2026 14:15:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/nuon-cli/</guid><description>Version updated for https://github.com/nuonco/actions-nuon to version v0.4.3.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of Nuon CLI commands within CI/CD workflows, supporting both OIDC federation and API token authentication. It simplifies infrastructure management by integrating Nuon’s capabilities directly into automated deployments. Users can configure and execute various Nuon CLI commands to manage organizations, apps, and installs within their GitHub Actions pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nuonco/actions-nuon">https://github.com/nuonco/actions-nuon</a></strong> to version <strong>v0.4.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nuon-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of Nuon CLI commands within CI/CD workflows, supporting both OIDC federation and API token authentication. It simplifies infrastructure management by integrating Nuon&rsquo;s capabilities directly into automated deployments. Users can configure and execute various Nuon CLI commands to manage organizations, apps, and installs within their GitHub Actions pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore: update the preflight cmd (#14) (4a13d66)</li>
<li>chore: improved version selection (#13) (8b7d21c)</li>
<li>fix: yaml syntax error in description (#12) (58da122)</li>
<li>feat: support using oidc with the cli (#11) (500be20)</li>
<li>feat: use &ndash;no-input flag (#8) (b144959)</li>
<li>feat: Make input <code>command</code> optional, allowing for setup use cases (#7) (1c320c6)</li>
<li>fix: The NUON_VERSION env var was not being picked up by install script (#6) (866d9e5)</li>
<li>feat: Set <code>NUON_CONFIG_FILE</code> variable for subsequent steps (#4) (352448d)</li>
<li>fix: Use the correct value for <code>NUON_VERSION</code> while installing (#5) (0d28fb9)</li>
<li>chore: rename for publication (#3) (3cc58a1)</li>
</ul>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/odin-scan-smart-contract-security/</link><pubDate>Thu, 13 Aug 2026 14:14:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security analysis of smart contracts in CosmWasm, Solana, and EVM projects. It uses Odin Scan’s AI-powered tools to detect vulnerabilities and integrates seamlessly into GitHub workflows, providing automatic platform detection, PR comments, inline annotations, configurable thresholds, and SARIF uploads for native security alerts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the security analysis of smart contracts in CosmWasm, Solana, and EVM projects. It uses Odin Scan&rsquo;s AI-powered tools to detect vulnerabilities and integrates seamlessly into GitHub workflows, providing automatic platform detection, PR comments, inline annotations, configurable thresholds, and SARIF uploads for native security alerts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add comment-triggered PR scans (ac72e5f)</li>
<li>docs: expand findings-visibility section with threat model and annotation rationale (0404708)</li>
<li>feat: add findings-visibility input for graduated public disclosure control (f18df59)</li>
<li>fix: show findings detail in PR comment with fallback to medium (c2e43c8)</li>
<li>fix: new comment per run, show only critical/high findings, rebuild dist (e237b62)</li>
<li>feat: use GitHub App installation token for branded PR comments (3abce4e)</li>
<li>feat: enrich PR comment with emojis, descriptions, and fix report URL (27cc2f2)</li>
<li>fix: gzip SARIF before base64 encoding for Code Scanning upload (d9eed9f)</li>
<li>fix: include sourcemap-register.js in dist (bd265af)</li>
<li>docs: add privacy policy (b78db44)</li>
</ul>
]]></content:encoded></item><item><title>svelte-vitals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/svelte-vitals/</link><pubDate>Thu, 13 Aug 2026 14:13:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/svelte-vitals/</guid><description>Version updated for https://github.com/oekazuma/svelte-vitals-action to version v0.9.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The svelte-vitals-action is a GitHub Action that automates static SvelteKit code health checks on pull requests. It provides inline annotations, a job summary, and a single sticky PR comment that updates in place on each push. The action uses the svelte-vitals CLI for analysis and supports configuration via committed files, such as svelte-vitals.config.* and svelte-vitals-suppressions.json. It fails the job when gating findings are present and provides a report regardless of whether it’s a pull request or fork PR.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oekazuma/svelte-vitals-action">https://github.com/oekazuma/svelte-vitals-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/svelte-vitals">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The svelte-vitals-action is a GitHub Action that automates static SvelteKit code health checks on pull requests. It provides inline annotations, a job summary, and a single sticky PR comment that updates in place on each push. The action uses the <code>svelte-vitals</code> CLI for analysis and supports configuration via committed files, such as <code>svelte-vitals.config.*</code> and <code>svelte-vitals-suppressions.json</code>. It fails the job when gating findings are present and provides a report regardless of whether it&rsquo;s a pull request or fork PR.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="minor-changes">Minor Changes</h3>
<ul>
<li>
<p>9f513e6: Update the bundled analyzer to <code>svelte-vitals</code> 0.45.1 / <code>@svelte-vitals/core</code> 0.41.1, a wide range covering several upstream releases. The action&rsquo;s inputs and outputs are unchanged, and the step still fails on <code>failOn</code> severity rather than on any score — but that severity table itself moved, so read the first two entries before upgrading a workflow you rely on:</p>
<ul>
<li><strong>The default gate loosens: <code>seo/description-presence</code> drops from <code>critical</code> to <code>warning</code>.</strong> Under the default <code>failOn: critical</code>, a project whose only failure was a missing <code>&lt;meta name=&quot;description&quot;&gt;</code> now passes the step where it used to fail it. If you were relying on that block, set <code>failOn: warning</code> or override the rule&rsquo;s severity in your config. Three more severities moved, and they only bite under a non-default <code>failOn: warning</code>: <code>seo/og-url</code> <code>info</code> → <code>warning</code> (the one tightening — a previously green run can turn red), <code>seo/og-description</code> <code>warning</code> → <code>info</code>, and <code>seo/single-h1</code> splitting per finding so that two or more <code>&lt;h1&gt;</code> is now <code>info</code> while a missing one stays <code>warning</code>. The <code>seo::route</code> scoring pair&rsquo;s total weight drops from 110 to 100 as a result, so SEO and Health can shift a point or two with no finding change at all.</li>
<li><strong>A previously green run can turn red from files that were never analyzed.</strong> A parse crash on argument-less <code>$state()</code> — <code>let el = $state();</code>, the idiomatic <code>bind:this</code> declaration — used to make the whole component invisible to every rule, silently. Those files are analyzed now, and what surfaces in them can include <code>critical</code> findings that fail the default gate. That is the fix working.</li>
<li><strong>A rule that throws no longer fails the whole step.</strong> The run completes without that rule and its weight is removed from the Health denominator, so the score is not silently inflated. Previously the exception propagated and the action failed the job outright. Note the tradeoff: the action does not yet surface the analyzer&rsquo;s non-fatal warnings, so the skipped rule&rsquo;s id is not reported anywhere — a rule that fails now goes unmentioned instead of loud.</li>
<li><strong>The job summary and the sticky PR comment are hardened against the analyzed project&rsquo;s own content.</strong> Strings quoted from the repo under analysis — file paths, route ids, and rule messages embedding page content such as <code>&lt;title&gt;</code> text or JSON-LD values — can no longer forge report structure: an embedded newline, code fence, heading, <code>[text](url)</code> link or bare <code>&lt;tag&gt;</code> renders as inert quoted text. Visible on well-behaved projects in one place: a message containing a literal tag (<code>Missing &lt;title&gt;</code>) now renders as inline code, which also fixes table cells silently dropping such tags.</li>
<li><strong>More of the project is reachable, so findings move in both directions.</strong> Head and heading resolution now follows a component imported through a <code>kit.alias</code>/<code>kit.files.lib</code> alias (<code>$components</code>, <code>$ui</code>, …) instead of only <code>$lib/…</code> and relative paths; every <code>application/ld+json</code> script on a route is analyzed instead of only the last one; and <code>seo/single-h1</code> counts headings rendered by imported local components. False &ldquo;Missing&rdquo; findings on routes whose content lives in such components disappear and Health can rise, while defects inside them — an empty <code>&lt;title&gt;</code>, invalid JSON-LD, a second <code>&lt;h1&gt;</code> — become visible for the first time.</li>
<li><strong><code>seo/json-ld-validity</code> now checks <code>@type</code> against the schema.org vocabulary.</strong> A bare type name that is not an exact, case-sensitive schema.org type produces a <code>warning</code>, with a did-you-mean hint for a casing slip or a typo within edit distance 2. IRI and prefixed forms are never flagged, and a document whose <code>@context</code> names a non-schema.org vocabulary is exempt.</li>
<li><strong>Several false positives removed.</strong> <code>seo/json-ld-required-props</code> was stale against Google&rsquo;s current requirements — the <code>Article</code>/<code>BlogPosting</code>/<code>NewsArticle</code>, <code>Organization</code> and <code>Person</code> rows are gone, <code>Product</code> now accepts any one of <code>review</code>/<code>aggregateRating</code>/<code>offers</code>, <code>Recipe</code> needs only <code>name</code> + <code>image</code>, <code>VideoObject</code> drops <code>description</code>. <code>security/handler-state-write</code> and <code>security/shared-state-import</code> no longer fire on a universal <code>+page.ts</code>/<code>+layout.ts</code> that exports <code>ssr = false</code>; since the former is <code>critical</code>, that can turn a red run green. <code>performance/render-blocking-script</code> no longer flags non-executing script types (<code>text/partytown</code>, <code>importmap</code>, <code>speculationrules</code>). <code>correctness/effect-as-onmount</code> no longer flags an <code>$effect</code> reading reactive state through a member expression on an imported binding or a <code>new …()</code> local.</li>
</ul>
</li>
</ul>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>
<p>e40f45c: Fix the <code>baseline</code> input reporting every finding as new on projects whose <code>svelte-vitals.config.*</code> imports <code>svelte-vitals</code> — the shape the <code>install</code> wizard scaffolds.</p>
<p>The baseline ref is analyzed inside a temporary git worktree, and that worktree has no <code>node_modules</code> in its ancestry, so re-loading the config file from within it threw on the import. The comparison caught the error and fell back to reporting everything, which is the opposite of what the input is for: a gate meant to show only new findings showed all of them. The action now hands its own config-file load to the baseline analysis instead of letting it look for one.</p>
<p>Both sides of the comparison therefore run under the same config, so editing <code>svelte-vitals.config.*</code> between the baseline ref and the current commit no longer makes findings look new on its own.</p>
</li>
<li>
<p>f2f9314: Update the bundled analyzer to <code>svelte-vitals</code> 0.46.0 / <code>@svelte-vitals/core</code> 0.42.0. Nothing the action reports changes: no rule severity, score, finding, annotation, job summary or sticky-comment output moves. Upstream&rsquo;s visible work in this range is CLI-only (shell completion, spinner cursor restore, the <code>ci install</code> workflow scaffold, and the dispatch layer&rsquo;s exit code), and the rest is internal refactoring plus two new library exports the action does not use yet.</p>
</li>
<li>
<p>18d8dea: Surface the analyzer&rsquo;s non-fatal warnings as workflow annotations. <code>analyzeProject</code> reports config-file problems, version-floor notices, unparseable files it skipped, and rules that crashed and were dropped from the run — the action collected all of it and printed none of it.</p>
<p>The crashed-rule case is why this matters now. A rule that throws no longer aborts the analysis; the run completes without it and its weight leaves the Health denominator, so nothing about the report looks wrong. Before, the exception propagated and failed the job outright. Without this, an incomplete scan passed the gate with no trace of which rule was missing.</p>
<p>The gate is unchanged — these are annotations, not failures.</p>
</li>
</ul>
]]></content:encoded></item><item><title>PatchWitness Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/patchwitness-gate/</link><pubDate>Thu, 13 Aug 2026 14:12:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/patchwitness-gate/</guid><description>Version updated for https://github.com/pangxueyuan2-creator/patchwitness to version v0.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PatchWitness is an independent evidence and policy gate for AI-generated code changes. It automates the verification of agent-authored patches by generating a verifiable Change Passport that checks scope, verifier integrity, test execution, secrets, dependency impact, and portable evidence. The action does not replace traditional AI reviewers but serves as a local-first, agent-neutral trust gate for ensuring high-quality code changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pangxueyuan2-creator/patchwitness">https://github.com/pangxueyuan2-creator/patchwitness</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/patchwitness-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PatchWitness is an independent evidence and policy gate for AI-generated code changes. It automates the verification of agent-authored patches by generating a verifiable Change Passport that checks scope, verifier integrity, test execution, secrets, dependency impact, and portable evidence. The action does not replace traditional AI reviewers but serves as a local-first, agent-neutral trust gate for ensuring high-quality code changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="patchwitness-v021">PatchWitness v0.2.1</h2>
<p>This patch release fixes the v0.2.0 clean-room failure when a committed pull-request diff is applied in a disposable worktree. The release removes the invalid positional <code>-</code> argument from the <code>git apply</code> invocation and adds regression coverage for committed base-to-HEAD gating, Change Passport generation, and offline verification.</p>
<p>The GitHub Actions guide now requires repository-specific dependency setup and uses PatchWitness&rsquo;s real <code>.[dev]</code> path for its own example. No new runtime dependencies, integrations, or CLI features are included.</p>
<p>Validation completed before release: full tests with coverage gate, Ruff, mypy, Demo, package build and Twine validation, clean install, committed-PR clean-room gate, minimal and recommended profiles, plus strict protected-workflow blocking with PW003 and offline evidence verification.</p>
<p>PyPI publication is intentionally not part of this release.</p>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/remyx-outrider/</link><pubDate>Thu, 13 Aug 2026 14:11:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.52.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of turning research papers into review-ready pull requests.
The action takes various inputs to select an arXiv paper, search query, or custom brief, and generates a draft PR with comprehensive evidence for review, including references cited, license flagged, tests written, honest scope discipline in the self-review, and alignment with the repository’s conventions. The output is a wired-in implementation that simplifies the development process by handling testing variance and providing a clear selection narrative.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.52</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>This GitHub Action automates the process of turning research papers into review-ready pull requests.</strong></p>
<p>The action takes various inputs to select an arXiv paper, search query, or custom brief, and generates a draft PR with comprehensive evidence for review, including references cited, license flagged, tests written, honest scope discipline in the self-review, and alignment with the repository&rsquo;s conventions. The output is a wired-in implementation that simplifies the development process by handling testing variance and providing a clear selection narrative.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><code>outrider.yml</code> used a flat concurrency group:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">concurrency</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">group</span>: <span style="color:#ae81ff">outrider</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">cancel-in-progress</span>: <span style="color:#66d9ef">false</span>
</span></span></code></pre></div><p>GitHub permits exactly one <em>pending</em> run per group, and when a third dispatch arrives it cancels the run already <strong>waiting</strong> — not the newcomer — with no error and no annotation. Firing four targets at one repo produced one run, one survivor, and two cancellations that read as CI flakes rather than lost work.</p>
<p>The group is now keyed by what the dispatch is working on:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">group</span>: <span style="color:#ae81ff">outrider-${{ inputs[&#39;pin-arxiv&#39;] || inputs[&#39;start-from-ref&#39;] || github.run_id }}</span>
</span></span></code></pre></div><p>Distinct papers and branches run in parallel — they touch different branches, so there was nothing to serialize. A genuine duplicate of the same target still queues behind its predecessor. Unpinned runs fall back to <code>run_id</code>, so a dispatch is never cancelled unless it&rsquo;s provably a duplicate.</p>
<p><code>outrider-daily.yml</code> and <code>outrider-weekly-refine.yml</code> keep their static groups deliberately: every drafter run commits to the same accumulated intel branch, so two in flight would race on the push.</p>
<p>Engine-side twin (for App-provisioned installs, which render their own <code>outrider.yml</code>): remyxai/remyx#558. CLI-side mitigation — <code>outrider trigger</code> warns when a run is pending, and <code>--wait-for-slot</code> serializes: remyxai/remyxai-cli#50.</p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/kaniko-build-action/</link><pubDate>Thu, 13 Aug 2026 14:10:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting to the log, automating the process of greeting someone by name. It solves the problem of programmatically sending greetings and provides capabilities for customizing the message based on input parameters.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting to the log, automating the process of greeting someone by name. It solves the problem of programmatically sending greetings and provides capabilities for customizing the message based on input parameters.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>Argus PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/argus-pr-review/</link><pubDate>Thu, 13 Aug 2026 14:09:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/argus-pr-review/</guid><description>Version updated for https://github.com/sibinms/argus to version v1.2.34.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is a GitHub Action that automates AI-based code reviews by running multiple specialized reviewers in parallel and using an evidence-based curator to verify findings before posting review comments. It helps identify real bugs while managing false positives, providing a more comprehensive approach to code quality assurance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sibinms/argus">https://github.com/sibinms/argus</a></strong> to version <strong>v1.2.34</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/argus-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Argus is a GitHub Action that automates AI-based code reviews by running multiple specialized reviewers in parallel and using an evidence-based curator to verify findings before posting review comments. It helps identify real bugs while managing false positives, providing a more comprehensive approach to code quality assurance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Feed a repo&rsquo;s CLAUDE.md/AGENTS.md to every reviewer by @sibinms in <a href="https://github.com/sibinms/argus/pull/70">https://github.com/sibinms/argus/pull/70</a></li>
<li>Release v1.2.34: project standards context (CLAUDE.md/AGENTS.md) by @sibinms in <a href="https://github.com/sibinms/argus/pull/74">https://github.com/sibinms/argus/pull/74</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sibinms/argus/compare/v1.2.33...v1.2.34">https://github.com/sibinms/argus/compare/v1.2.33...v1.2.34</a></p>
]]></content:encoded></item><item><title>Solsynth Express Upload</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/solsynth-express-upload/</link><pubDate>Thu, 13 Aug 2026 14:08:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/solsynth-express-upload/</guid><description>Version updated for https://github.com/Solsynth/SolsynthExpressUpload to version v2.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, SolsynthExpressUpload, automates the process of uploading build artifacts to a specific version in DistributionCenter. It prepares an upload URL with the given release version, uploads the artifact to S3, computes its SHA-256 digest, and attaches it as an immutable artifact to the release. If the version does not exist, it creates a stable draft automatically. The action requires various inputs such as API base URL, product ID, API key, version, file path, platform, architecture, MIME type, and channel.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Solsynth/SolsynthExpressUpload">https://github.com/Solsynth/SolsynthExpressUpload</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/solsynth-express-upload">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>SolsynthExpressUpload</code>, automates the process of uploading build artifacts to a specific version in DistributionCenter. It prepares an upload URL with the given release version, uploads the artifact to S3, computes its SHA-256 digest, and attaches it as an immutable artifact to the release. If the version does not exist, it creates a stable draft automatically. The action requires various inputs such as API base URL, product ID, API key, version, file path, platform, architecture, MIME type, and channel.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Solsynth/SolsynthExpressUpload/compare/v1.0.1...v2">https://github.com/Solsynth/SolsynthExpressUpload/compare/v1.0.1...v2</a></p>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Thu, 13 Aug 2026 14:08:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by bundling assets before they are pushed to a repository. It ensures that all necessary files, including the bundled distribution, are included in the commit process to facilitate smooth deployment and versioning.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by bundling assets before they are pushed to a repository. It ensures that all necessary files, including the bundled distribution, are included in the commit process to facilitate smooth deployment and versioning.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/ssg-static-site-generator/</link><pubDate>Thu, 13 Aug 2026 14:07:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.30.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It automates the process of building, serving, and deploying websites using features like templates, feeds, images, and SEO metadata.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.30</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It automates the process of building, serving, and deploying websites using features like templates, feeds, images, and SEO metadata.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.30 — migration keeps menus, ssg mcp &ndash;http serves, entities decoded by @spagu in <a href="https://github.com/spagu/ssg/pull/125">https://github.com/spagu/ssg/pull/125</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.29...v1.8.30">https://github.com/spagu/ssg/compare/v1.8.29...v1.8.30</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/classroom-to-sheets-integration/</link><pubDate>Thu, 13 Aug 2026 14:06:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of integrating Assignment results from GitHub Classroom with Google Sheets. It allows instructors to automatically update their Google Sheet with students’ submission results, making it easier to track grading and progress in the classroom. The integration requires setting up Google API credentials and sharing a sheet with the service account email. Users can specify student names and task results within a GitHub Actions workflow and the action will handle updating the corresponding cells in the Google Sheet.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of integrating Assignment results from GitHub Classroom with Google Sheets. It allows instructors to automatically update their Google Sheet with students&rsquo; submission results, making it easier to track grading and progress in the classroom. The integration requires setting up Google API credentials and sharing a sheet with the service account email. Users can specify student names and task results within a GitHub Actions workflow and the action will handle updating the corresponding cells in the Google Sheet.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>Jira Release annotations</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/jira-release-annotations/</link><pubDate>Thu, 13 Aug 2026 14:05:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/jira-release-annotations/</guid><description>Version updated for https://github.com/Staffbase/github-action-jira-release-tagging to version v1.7.3.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “Jira Release Annotator” automates the process of updating JIRA issues with a release tag and component name. It uses a tag name and a list of issue IDs to annotate JIRA tickets, which helps in managing and tracking updates across different projects efficiently. The action requires a Jira login and token for API access, making it useful for continuous integration pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Staffbase/github-action-jira-release-tagging">https://github.com/Staffbase/github-action-jira-release-tagging</a></strong> to version <strong>v1.7.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jira-release-annotations">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;Jira Release Annotator&rdquo; automates the process of updating JIRA issues with a release tag and component name. It uses a tag name and a list of issue IDs to annotate JIRA tickets, which helps in managing and tracking updates across different projects efficiently. The action requires a Jira login and token for API access, making it useful for continuous integration pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What’s Changed</h2>
<ul>
<li>Update release workflow to use client_id (#210) @axdotl</li>
<li>⬆️ run action on Node 24 (#209) @stefan-scheidewig</li>
<li>Bump undici from 6.27.0 to 6.28.0 (#208) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump eslint from 10.5.0 to 10.8.0 (#207) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump Staffbase/gha-workflows/.github/workflows/template_release_drafter.yml from 14.1.0 to 15.1.1 (#205) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump @vercel/ncc from 0.44.0 to 0.44.1 (#206) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump picomatch to 2.3.2 to resolve GHSA-3v7f-55p6-f55p (method injection in POSIX character classes) (#204) @<a href="https://github.com/apps/copilot-swe-agent">copilot-swe-agent[bot]</a></li>
<li>Bump transitive brace-expansion to patched 1.1.16 (GHSA-3jxr-9vmj-r5cp) (#202) @<a href="https://github.com/apps/copilot-swe-agent">copilot-swe-agent[bot]</a></li>
<li>Fix brace-expansion DoS vulnerability (GHSA-3jxr-9vmj-r5cp / CVE-2026-13149) (#203) @<a href="https://github.com/apps/copilot-swe-agent">copilot-swe-agent[bot]</a></li>
<li>fix(deps): bump minimatch 3.x to 3.1.5 to resolve CVE-2026-27903 (#201) @flaxel</li>
<li>Bump eslint from 10.4.0 to 10.5.0 (#199) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump js-yaml from 3.14.2 to 3.15.0 (#197) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump @vercel/ncc from 0.38.4 to 0.44.0 (#200) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump Staffbase/gha-workflows/.github/workflows/template_release_drafter.yml from 13.4.1 to 14.1.0 (#198) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump undici from 6.24.1 to 6.27.0 (#195) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
</ul>
]]></content:encoded></item><item><title>SFDX Run Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/sfdx-run-tests/</link><pubDate>Thu, 13 Aug 2026 14:05:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/sfdx-run-tests/</guid><description>Version updated for https://github.com/svierk/sfdx-run-tests to version v1.1.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of Salesforce Apex, LWC, and Flow tests. It reports coverage to the CLI logs and the GitHub step summary, and writes coverage reports to paths expected by quality tools like SonarQube/SonarCloud or Codecov. The action is configurable to run only certain types of tests, and provides a streamlined way to include tests in CI workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svierk/sfdx-run-tests">https://github.com/svierk/sfdx-run-tests</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdx-run-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of Salesforce Apex, LWC, and Flow tests. It reports coverage to the CLI logs and the GitHub step summary, and writes coverage reports to paths expected by quality tools like SonarQube/SonarCloud or Codecov. The action is configurable to run only certain types of tests, and provides a streamlined way to include tests in CI workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>pin action references and harden the usage examples</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svierk/sfdx-run-tests/compare/v1.1.0...v1.1.1">https://github.com/svierk/sfdx-run-tests/compare/v1.1.0...v1.1.1</a></p>
]]></content:encoded></item><item><title>ghstats-cards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/ghstats-cards/</link><pubDate>Thu, 13 Aug 2026 14:04:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/ghstats-cards/</guid><description>Version updated for https://github.com/tiennm99/ghstats to version v1.6.2.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ghstats is a GitHub Action that generates SVG cards summarizing a GitHub user’s profile, providing insights into various metrics like repository language breakdowns, commit activity, and contribution trends. It automates the process of visualizing user data in a visually appealing format, making it easier to share and present on a user’s GitHub profile README.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tiennm99/ghstats">https://github.com/tiennm99/ghstats</a></strong> to version <strong>v1.6.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ghstats-cards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>ghstats</code> is a GitHub Action that generates SVG cards summarizing a GitHub user&rsquo;s profile, providing insights into various metrics like repository language breakdowns, commit activity, and contribution trends. It automates the process of visualizing user data in a visually appealing format, making it easier to share and present on a user&rsquo;s GitHub profile README.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixes">Fixes</h2>
<ul>
<li>
<p><strong><code>commits_per_repo: &quot;0&quot;</code> now means every commit instead of none.</strong> The pagination guard broke on <code>seen &gt;= maxPerRepo</code>, so a cap of zero stopped before the first page and silently rendered empty productive-time, productive-weekday and most-commit-language cards — the opposite of what <code>0</code> already meant for <code>top_repos</code>. A cap of zero or less is now treated as no cap.</p>
<p>Verified against a real repository: a cap of <code>100</code> still stops at 100 commits, while <code>500</code> and <code>0</code> both walk the full 382-commit history.</p>
</li>
</ul>
<p>The default stays at <code>500</code>, which is plenty for most accounts. Raising it matters when a repo holds more reachable commits than the cap <em>and</em> you want the all-time cards to reflect your full history — commit history is returned newest-first, so a cap keeps the most recent commits and drops the older tail.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tiennm99/ghstats/compare/v1.6.1...v1.6.2">https://github.com/tiennm99/ghstats/compare/v1.6.1...v1.6.2</a></p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/wails3-build-action/</link><pubDate>Thu, 13 Aug 2026 14:02:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of building Wails.io v3 applications. It installs necessary tools such as GoLang and NodeJS, builds the application for specified platforms, and optionally uploads the results to GitHub or releases on tagged builds. The action supports customizing build options like go version, wails version, and platform targets.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of building Wails.io v3 applications. It installs necessary tools such as GoLang and NodeJS, builds the application for specified platforms, and optionally uploads the results to GitHub or releases on tagged builds. The action supports customizing build options like go version, wails version, and platform targets.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Install bashunit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/install-bashunit/</link><pubDate>Thu, 13 Aug 2026 14:02:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/install-bashunit/</guid><description>Version updated for https://github.com/TypedDevs/bashunit to version 0.47.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a testing framework for Bash scripts, focusing on developer experience with 93 assertions and additional features like spies, mocks, data providers, and snapshots. It automates the process of writing, running, and documenting tests for Bash scripts efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TypedDevs/bashunit">https://github.com/TypedDevs/bashunit</a></strong> to version <strong>0.47.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-bashunit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a testing framework for Bash scripts, focusing on developer experience with 93 assertions and additional features like spies, mocks, data providers, and snapshots. It automates the process of writing, running, and documenting tests for Bash scripts efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-improvements">✨ Improvements</h2>
<ul>
<li><code>--output &lt;text|tap|json|junit&gt;</code> prints the JSON and JUnit reports on stdout, so a pipeline needs no temp file; <code>--report-json</code> still writes its file alongside (#1018)</li>
<li><code>bashunit::skip_if</code>, <code>bashunit::skip_unless</code>, <code>bashunit::skip_unless_command &lt;cmd&gt;</code> and <code>bashunit::skip_on &lt;windows|macos|linux&gt;</code> mark a test skipped <strong>and</strong> end it, replacing <code>bashunit::skip &amp;&amp; return</code> (#1019)</li>
<li>Per-test <code># @timeout &lt;seconds&gt;</code>, <code># @retry &lt;n&gt;</code> and <code># @skip [reason]</code> annotations override the run-wide flags in both directions; a malformed value aborts the run (#1020)</li>
<li><code>[suite:&lt;name&gt;]</code> sections in <code>.bashunitrc</code> name a set of paths and options; <code>--suite &lt;name&gt;</code> runs one (repeatable) and <code>--list-suites</code> lists them (#1021)</li>
<li><code>--sandbox</code> fails a test that runs an external command it did not mock, and <code>--sandbox-allow &lt;cmd,...&gt;</code> widens the baseline allowlist (ADR-012) (#1022)</li>
<li><code>bashunit::mock_sequence &lt;cmd&gt; &lt;answer&gt;…</code> answers each call with the next entry, so retry loops need no hand-rolled counter file; the last entry repeats once exhausted (#1023)</li>
<li><code>assert_have_never_been_called &lt;cmd&gt;</code> asserts a spied command never ran, printing the recorded calls when it did (#1023)</li>
<li><code>assert_is_file_readable</code>, <code>assert_is_file_writable</code>, <code>assert_is_file_executable</code>, their negatives and <code>assert_is_file_not_empty</code> give files the parity directories already had (#1024)</li>
<li><code>assert_json_key_not_exists</code> checks that a JSON path is absent, and <code>assert_json_length</code> the size of an array, object or string (#1025)</li>
<li><code>bashunit bench --report-json &lt;file&gt;</code> and <code>--report-junit &lt;file&gt;</code> write the benchmark run to disk, so a CI run leaves an artifact to store, chart and compare (#1028)</li>
<li><code>bashunit bench --baseline &lt;file&gt;</code> fails a run when a benchmark is more than <code>--baseline-tolerance</code> percent (default 10) slower than the recorded one, comparing medians; <code>--baseline-update &lt;file&gt;</code> records the new reference (#1029)</li>
<li><code>--snapshot-prune</code> deletes the snapshot files no test resolved, printing every path; full runs only, and never on a run with failures (#1030)</li>
</ul>
<h2 id="-changes">🛠️ Changes</h2>
<ul>
<li>LCOV <code>BRDA</code> carries the arm&rsquo;s execution count instead of a 0/1 taken flag, taken from the arm&rsquo;s first executable line; <code>BRF</code> and <code>BRH</code> are unchanged (#1061)</li>
<li>Performance: <code>--coverage</code> is about 10x faster — a run over this repo&rsquo;s <code>src</code> went from 9.23s to 0.96s. The report phase classifies lines, scans declarations and branches and emits the whole LCOV report in one awk invocation per run instead of Bash loops and forks per file, hit data is grouped once, the DEBUG trap rejects untracked lines before recording, and the caches are read through the variable table (#1056, #1057, #1059, #1060, #1084, #1088, #1090)</li>
</ul>
<h2 id="-bug-fixes">🐛 Bug Fixes</h2>
<ul>
<li>Coverage reports every file under <code>--coverage-paths</code>, not only the ones a test executed: an untouched file shows as <code>0/N (0%)</code> and <code>--coverage-min</code> gates on that denominator. This repo reported 11 of its own 121 files. <strong>Percentages drop, because the old ones were measured over the files that ran</strong> (#1053)</li>
<li><code>--coverage-diff</code> counts a changed file that no test executed, instead of skipping it and letting a brand new untested file pass a <code>--coverage-min 90</code> gate. A docs-only commit still reports 100% (#1054)</li>
<li>Coverage read a statement ending in <code>)</code> as a <code>case</code> arm, so <code>x=$(foo)</code> left the denominator while <code>x=$(printf '%s\n')</code> stayed. A <code>)</code> now closes an arm only when no <code>(</code> opened earlier on the line, recovering 456 executable lines of this repo&rsquo;s <code>src/</code>. <strong>Percentages move in both directions per file</strong> (#1055)</li>
<li>A brace inside a comment, a string or a heredoc no longer counts towards a function&rsquo;s span, so a single stray <code>{</code> stops swallowing every later function in the file — 11 functions in this repo&rsquo;s <code>src/coverage/lines.sh</code> were reported as 1, and <code>END {</code> inside an embedded awk program was reported as a function. <code>FN</code>, <code>FNDA</code>, <code>FNF</code> and <code>FNH</code> change; lines and branches do not (#1086)</li>
</ul>
<h2 id="-contributors">👥 Contributors</h2>
<ul>
<li>@Chemaclass</li>
<li>@ColumbusLabs</li>
</ul>
<h2 id="checksum">Checksum</h2>
<p>SHA256: <code>defa50ff54c902acf33c17a2813a879defb349452b51f667736800e63c0156ae</code></p>
<p><strong>Full Changelog:</strong> <a href="https://github.com/TypedDevs/bashunit/compare/0.46.0...0.47.0">0.46.0&hellip;0.47.0</a></p>
]]></content:encoded></item><item><title>Symfony Security Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/symfony-security-auditor/</link><pubDate>Thu, 13 Aug 2026 14:00:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/symfony-security-auditor/</guid><description>Version updated for https://github.com/vinceAmstoutz/symfony-security-auditor to version 1.19.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Symfony Security Auditor is an AI-powered security auditing tool designed to catch application-level flaws that traditional static analysis and dependency scanners might miss. It provides a multi-agent adversarial approach where an attacker hunts for vulnerabilities, while a reviewer culls false positives over three iterations before emitting a validated report in various formats such as console, JSON, SARIF, HTML, or Markdown. The auditor can be run as a standalone CLI tool or integrated into a Symfony application via the Symfony bundle. It includes features like dry-run mode to estimate costs and provide a live audit feed in the console.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vinceAmstoutz/symfony-security-auditor">https://github.com/vinceAmstoutz/symfony-security-auditor</a></strong> to version <strong>1.19.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/symfony-security-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Symfony Security Auditor is an AI-powered security auditing tool designed to catch application-level flaws that traditional static analysis and dependency scanners might miss. It provides a multi-agent adversarial approach where an attacker hunts for vulnerabilities, while a reviewer culls false positives over three iterations before emitting a validated report in various formats such as console, JSON, SARIF, HTML, or Markdown. The auditor can be run as a standalone CLI tool or integrated into a Symfony application via the Symfony bundle. It includes features like dry-run mode to estimate costs and provide a live audit feed in the console.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump DavidAnson/markdownlint-cli2-action from 24.0.0 to 24.1.0 by @app/dependabot in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/227">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/227</a></li>
<li>chore(deps): update symfony/ai-bundle from ^0.11 to ^0.12 by @app/dependabot in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/228">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/228</a></li>
<li>fix(standalone): drop polyfilled ext-uri from the static build by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/229">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/229</a></li>
<li>docs: use last models by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/230">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/230</a></li>
<li>chore(deps): bump zizmorcore/zizmor-action to 0.6.1 by @app/dependabot in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/236">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/236</a></li>
<li>fix(docs): drop the invalid expanded model mapping from examples by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/237">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/237</a></li>
<li>chore: keep main at the released version by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/254">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/254</a></li>
<li>fix: restore extra.branch-alias to unbreak CI by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/255">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/255</a></li>
<li>fix(ci): resolve the root version deterministically by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/256">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/256</a></li>
<li>ci: enforce the core layer boundary in deptrac by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/261">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/261</a></li>
<li>feat: normalized score and A-F grade by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/262">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/262</a></li>
<li>feat: &ndash;min-score CI gate by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/263">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/263</a></li>
<li>feat: shields.io badge endpoint from the action by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/264">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/264</a></li>
<li>feat: PR comment with the audit summary by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/265">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/265</a></li>
<li>refactor: neutral surface archetype by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/266">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/266</a></li>
<li>refactor: neutral application security map by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/267">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/267</a></li>
<li>refactor: neutral synthesizer prompt wording by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/268">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/268</a></li>
<li>refactor: carry pending reviews in a value object by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/271">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/271</a></li>
<li>refactor: carry pending chunks in a value object by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/272">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/272</a></li>
<li>refactor: carry wavefront conversation state in a value object by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/273">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/273</a></li>
<li>refactor: type the batch request shape behind the ports by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/274">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/274</a></li>
<li>ci: retarget dependabot by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/283">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/283</a></li>
<li>chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 by @app/dependabot in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/281">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/281</a></li>
<li>chore(deps): bump DavidAnson/markdownlint-cli2-action from 24.1.0 to 24.2.0 by @app/dependabot in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/282">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/282</a></li>
<li>feat(agent): add XSSI detection for GET controller actions by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/284">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/284</a></li>
<li>fix: PR-comment escaping and failing-gate message by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/276">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/276</a></li>
<li>fix(standalone): block repo platform override by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/278">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/278</a></li>
<li>chore: make the local test gates trustworthy by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/279">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/279</a></li>
<li>docs: fix the duplicate Security heading by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/285">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/285</a></li>
<li>fix: stop the audited project executing code by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/277">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/277</a></li>
<li>fix(scan): close three secret-scrubbing gaps by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/280">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/280</a></li>
<li>fix: prevent false-SAFE results and dropped findings by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/288">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/288</a></li>
<li>fix: close four prompt/report injection gaps by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/289">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/289</a></li>
<li>fix(domain): stop Vulnerability id() colliding on join by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/292">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/292</a></li>
<li>ci(release): scope binary job&rsquo;s write token by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/293">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/293</a></li>
<li>ci: verify static-php-cli checksum before use by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/296">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/296</a></li>
<li>fix(domain): stop fingerprint() colliding on join by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/294">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/294</a></li>
<li>fix(scan): make ThisCallReachability linear-time by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/297">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/297</a></li>
<li>test: fix SARIF slash-escaping mutant gap by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/300">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/300</a></li>
<li>fix: harden git-filter, MCP path, and PR-comment exposure by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/290">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/290</a></li>
<li>fix: reject negative token counts unconditionally by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/291">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/291</a></li>
<li>fix(scan): stop RegexCodeSlicer segfaulting by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/301">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/301</a></li>
<li>refactor(scan): decompose RegexCodeSlicer by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/302">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/302</a></li>
<li>fix(scan): secret-scrubber gaps and hash collisions by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/303">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/303</a></li>
<li>fix(scan): scan-config path traversal and ReDoS gaps by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/304">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/304</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.18.0...1.19.0">https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.18.0...1.19.0</a></p>
]]></content:encoded></item><item><title>Picket Secret Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/picket-secret-scanner/</link><pubDate>Thu, 13 Aug 2026 13:59:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/picket-secret-scanner/</guid><description>Version updated for https://github.com/willibrandon/picket to version v0.2.11.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Picket is a MIT-licensed secrets scanner for .NET that provides a Gitleaks-compatible command surface, Native AOT release binaries, dotnet tool packages, and embeddable libraries. It automates scanning staged, unstaged, and untracked non-ignored Git changes, as well as GitLab issues, comments, releases, and release assets using various authentication methods. The action supports CI integrations through GitHub Actions and Azure DevOps, with options for customizing reports and handling findings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/willibrandon/picket">https://github.com/willibrandon/picket</a></strong> to version <strong>v0.2.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/picket-secret-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Picket is a MIT-licensed secrets scanner for .NET that provides a Gitleaks-compatible command surface, Native AOT release binaries, dotnet tool packages, and embeddable libraries. It automates scanning staged, unstaged, and untracked non-ignored Git changes, as well as GitLab issues, comments, releases, and release assets using various authentication methods. The action supports CI integrations through GitHub Actions and Azure DevOps, with options for customizing reports and handling findings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release artifacts include SHA-256 checksums, package-size metadata, and GitHub artifact attestations.</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/b.ia-accessibility-checker/</link><pubDate>Thu, 13 Aug 2026 13:57:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that enables companies to integrate accessibility checks into their CI/CD pipeline. It uses AI to analyze and measure the WCAG guidelines against defined audiences, allowing them to focus on specific groups that represent higher revenue potential. This helps in avoiding ineffective or harmful solutions by focusing on accessibility for targeted users efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that enables companies to integrate accessibility checks into their CI/CD pipeline. It uses AI to analyze and measure the WCAG guidelines against defined audiences, allowing them to focus on specific groups that represent higher revenue potential. This helps in avoiding ineffective or harmful solutions by focusing on accessibility for targeted users efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>ReleaseGuard - Release Asset Quality Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/releaseguard-release-asset-quality-gate/</link><pubDate>Thu, 13 Aug 2026 13:56:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/releaseguard-release-asset-quality-gate/</guid><description>Version updated for https://github.com/zhaoryder/releaseguard to version v0.2.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ReleaseGuard is a GitHub Action that provides a quality gate and download advisor for GitHub Release assets. It helps identify missing platforms, mislabeled architectures, empty installers, version drift, and missing checksums in release files, guiding users to the most suitable download based on their operating system and CPU architecture.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zhaoryder/releaseguard">https://github.com/zhaoryder/releaseguard</a></strong> to version <strong>v0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/releaseguard-release-asset-quality-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ReleaseGuard is a GitHub Action that provides a quality gate and download advisor for GitHub Release assets. It helps identify missing platforms, mislabeled architectures, empty installers, version drift, and missing checksums in release files, guiding users to the most suitable download based on their operating system and CPU architecture.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Fix and verify macOS app signatures (e3a443e)</li>
<li>Redesign desktop UI and app mark (91ee6e7)</li>
<li>Fix Linux desktop packaging metadata (4c4c118)</li>
<li>Add cross-platform desktop app (085ba0d)</li>
<li>Prepare Action for GitHub Marketplace (58a8ca0)</li>
<li>Add Simplified Chinese README (149f01d)</li>
<li>Pin Action execution to release tag (f6d2afb)</li>
<li>Launch GitHub Release quality gate (92a219b)</li>
</ul>
]]></content:encoded></item><item><title>Zuke Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/zuke-build/</link><pubDate>Thu, 13 Aug 2026 13:54:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/zuke-build/</guid><description>Version updated for https://github.com/zuke-build/zuke to version ai-v2.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Zuke is a type-safe build automation system for Deno &amp;amp; TypeScript. It allows you to define builds as TypeScript classes with fluent APIs that reference each other by this.x, forming a dependency graph that Zuke resolves and runs in topological order.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zuke-build/zuke">https://github.com/zuke-build/zuke</a></strong> to version <strong>ai-v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zuke-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Zuke is a type-safe build automation system for Deno &amp; TypeScript. It allows you to define builds as TypeScript classes with fluent APIs that reference each other by <code>this.x</code>, forming a dependency graph that Zuke resolves and runs in topological order.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="210-2026-08-13"><a href="https://github.com/zuke-build/zuke/compare/ai-v2.0.0...ai-v2.1.0">2.1.0</a> (2026-08-13)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>ai:</strong> drive review discussions on GitLab, Azure and Bitbucket (<a href="https://github.com/zuke-build/zuke/issues/336">#336</a>) (<a href="https://github.com/zuke-build/zuke/commit/f92f929250e6c8411f6790ad1043794b9477bdab">f92f929</a>)</li>
<li><strong>ai:</strong> findings as inline review threads on GitHub (<a href="https://github.com/zuke-build/zuke/issues/343">#343</a>) (<a href="https://github.com/zuke-build/zuke/commit/0f39ce9f103b1d38ca560e0e4ef55c4fcae70077">0f39ce9</a>)</li>
<li><strong>ai:</strong> point a dismissal at the suppress list as the cross-PR override (<a href="https://github.com/zuke-build/zuke/issues/345">#345</a>) (<a href="https://github.com/zuke-build/zuke/commit/11a2b55880da50bef1a71a1cf60b69b2209fd08c">11a2b55</a>)</li>
<li><strong>ai:</strong> resolve a reworded finding onto the identity it already has (<a href="https://github.com/zuke-build/zuke/issues/338">#338</a>) (<a href="https://github.com/zuke-build/zuke/commit/1533b887a8b2e0954092dee5859280cf08600b3c">1533b88</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>ai:</strong> compare a reworded finding against still-open findings too (<a href="https://github.com/zuke-build/zuke/issues/341">#341</a>) (<a href="https://github.com/zuke-build/zuke/commit/5b65329e1514a22a3ad63da1a3be54b8952ba508">5b65329</a>)</li>
<li><strong>ai:</strong> stop model text from forging the review state block (<a href="https://github.com/zuke-build/zuke/issues/340">#340</a>) (<a href="https://github.com/zuke-build/zuke/commit/c6b71157ddd6f1457bb56d296c473bf6ee68f0b7">c6b7115</a>)</li>
</ul>
]]></content:encoded></item><item><title>Configure Node.js</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/configure-node.js/</link><pubDate>Thu, 13 Aug 2026 05:57:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/configure-node.js/</guid><description>Version updated for https://github.com/pwrdrvr/configure-nodejs to version v1.4.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates setting up Node.js environments in CI workflows by detecting the package manager, enabling Corepack when necessary, restoring the correct cache, and installing only when required. It solves problems related to cold cache misses, trade-offs between installation time and cache usage, and the retry trap caused by post-step cache saves. The action is designed to improve build efficiency and reduce costs by caching builds that are not affected by changes in dependencies or lockfiles.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pwrdrvr/configure-nodejs">https://github.com/pwrdrvr/configure-nodejs</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/configure-node-js">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates setting up Node.js environments in CI workflows by detecting the package manager, enabling Corepack when necessary, restoring the correct cache, and installing only when required. It solves problems related to cold cache misses, trade-offs between installation time and cache usage, and the retry trap caused by post-step cache saves. The action is designed to improve build efficiency and reduce costs by caching builds that are not affected by changes in dependencies or lockfiles.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Add opt-in <code>cache-electron: &quot;true&quot;</code> support that stores Electron runtime artifacts and native-addon prebuild downloads in workspace-scoped dependency caches.</li>
<li>Give enabled Electron caches a versioned key segment so existing immutable dependency caches cannot masquerade as containing lifecycle artifacts. Disabled/default behavior keeps the existing cache paths and key.</li>
</ul>
<h2 id="fixes">Fixes</h2>
<ul>
<li>Ensure a pnpm lookup-only primer miss installs into and saves the workspace-local pnpm store.</li>
</ul>
<p>No migration is required. Electron caching remains disabled by default and can be enabled consistently on cache primer and consumer jobs.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/pwrdrvr/configure-nodejs/compare/v1.3.0...v1.4.0">https://github.com/pwrdrvr/configure-nodejs/compare/v1.3.0...v1.4.0</a></p>
]]></content:encoded></item><item><title>Open Growth Loop Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/open-growth-loop-audit/</link><pubDate>Thu, 13 Aug 2026 05:54:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/open-growth-loop-audit/</guid><description>Version updated for https://github.com/R3ijar/open-growth-loop to version v0.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Open Growth Loop is a technical documentation assistant designed to help maintainers of open-source repositories prioritize their work. It analyzes the repository’s hygiene, assesses its readiness for contributors, and suggests actionable next steps based on evidence. The action supports both local-only mode and integration with GitHub APIs to gather additional context.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/R3ijar/open-growth-loop">https://github.com/R3ijar/open-growth-loop</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/open-growth-loop-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Open Growth Loop is a technical documentation assistant designed to help maintainers of open-source repositories prioritize their work. It analyzes the repository&rsquo;s hygiene, assesses its readiness for contributors, and suggests actionable next steps based on evidence. The action supports both local-only mode and integration with GitHub APIs to gather additional context.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Open Growth Loop v0.2.1 is the GitHub Marketplace readiness release for the reusable Open Growth Loop Audit Action.</p>
<h2 id="changed">Changed</h2>
<ul>
<li>Shortened the Action description to satisfy GitHub Marketplace metadata requirements.</li>
<li>Identified the Action author as Jesus (R3ijar) in public Marketplace metadata.</li>
<li>Updated official GitHub Actions dependencies to current Node.js 24-compatible major releases.</li>
</ul>
<p>The CLI and <code>repo-steward</code> skill are unchanged from v0.2.0. All 91 tests pass across Python 3.10–3.13, Ruff passes, the Repository Audit passes, and trusted publishing successfully delivered the package to PyPI.</p>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-console" data-lang="console"><span style="display:flex;"><span>pip install --upgrade open-growth-loop
</span></span></code></pre></div><ul>
<li><a href="https://pypi.org/project/open-growth-loop/0.2.1/">PyPI package</a></li>
<li><a href="https://github.com/R3ijar/open-growth-loop/blob/v0.2.1/docs/COMPATIBILITY_STUDY.md">Compatibility study</a></li>
<li><a href="https://github.com/R3ijar/open-growth-loop/issues/6">Maintainer field test</a></li>
</ul>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/rumdl-action/</link><pubDate>Thu, 13 Aug 2026 05:53:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.55.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rumdl is a high-performance Markdown linter and formatter written in Rust, offering speed, extensive lint rules, automatic formatting with --fix, and support for multiple Markdown flavors. It’s designed to help maintain consistent and best practices in Markdown files, providing modern CLI features and integration options for various environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.55</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>rumdl is a high-performance Markdown linter and formatter written in Rust, offering speed, extensive lint rules, automatic formatting with <code>--fix</code>, and support for multiple Markdown flavors. It&rsquo;s designed to help maintain consistent and best practices in Markdown files, providing modern CLI features and integration options for various environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>lsp</strong>: honor per-directory config across workspace features (<a href="https://github.com/rvben/rumdl/commit/2c7670fb5ba5bf156bd9756111da80559f3c4c92">2c7670f</a>)</li>
<li><strong>core</strong>: align path-aware document processing across adapters (<a href="https://github.com/rvben/rumdl/commit/7285b7ad7b1c9d3a7ec17b59f93704dfaa38b9dc">7285b7a</a>)</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li><strong>lsp</strong>: construct workspace index rules directly (<a href="https://github.com/rvben/rumdl/commit/864e42a891364827bb98cbc908affe17a0241d14">864e42a</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.55-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.55-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.55-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.55-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-x86_64-apple-darwin.tar.gz">rumdl-v0.2.55-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-aarch64-apple-darwin.tar.gz">rumdl-v0.2.55-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-x86_64-pc-windows-msvc.zip">rumdl-v0.2.55-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.55/rumdl-v0.2.55-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/agentauditkit-mcp-security-scan/</link><pubDate>Thu, 13 Aug 2026 05:52:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.74.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit automates the security auditing of AI agent pipelines by scanning and reporting on misconfigurations, hardcoded secrets, tool poisoning, and other potential vulnerabilities across 10 different platforms. Unlike hosted scanners, AgentAuditKit runs fully offline and deterministically, producing auditor-ready compliance-evidence packs that cover a wide range of security categories including EU AI Act, SOC 2, ISO 27001/42001, HIPAA, NIST AI RMF, and regional regimes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.74</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>AgentAuditKit automates the security auditing of AI agent pipelines by scanning and reporting on misconfigurations, hardcoded secrets, tool poisoning, and other potential vulnerabilities across 10 different platforms. Unlike hosted scanners, AgentAuditKit runs fully offline and deterministically, producing auditor-ready compliance-evidence packs that cover a wide range of security categories including EU AI Act, SOC 2, ISO 27001/42001, HIPAA, NIST AI RMF, and regional regimes.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.74
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.74
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.74</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Session-splice rule (AAK-AGENT-COMPOSE-002), one live NVD feed, and a count guard that catches prose drift by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/571">https://github.com/sattyamjjain/agent-audit-kit/pull/571</a></li>
<li>CVE response: pin CVE-2026-72768 (n8n MCP Client SSRF) + CVE-2026-73222 (claude-code-templates &ndash;studio RCE) by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/572">https://github.com/sattyamjjain/agent-audit-kit/pull/572</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.73...v0.3.74">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.73...v0.3.74</a></p>
]]></content:encoded></item><item><title>SFDT for Salesforce</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/sfdt-for-salesforce/</link><pubDate>Thu, 13 Aug 2026 05:51:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/sfdt-for-salesforce/</guid><description>Version updated for https://github.com/scoobydrew83/sfdt to version ext-v0.13.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SFDT action automates the deployment, testing, and release process for Salesforce projects. It offers features like interactive workflows, preflight validation, AI-powered fix plans, and CI/CD pipeline templates to streamline development and reduce errors. The multi-package project support allows deploying to individual packages or specific source directories directly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scoobydrew83/sfdt">https://github.com/scoobydrew83/sfdt</a></strong> to version <strong>ext-v0.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdt-for-salesforce">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The SFDT action automates the deployment, testing, and release process for Salesforce projects. It offers features like interactive workflows, preflight validation, AI-powered fix plans, and CI/CD pipeline templates to streamline development and reduce errors. The multi-package project support allows deploying to individual packages or specific source directories directly.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: release extension v0.13.0 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/336">https://github.com/scoobydrew83/sfdt/pull/336</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scoobydrew83/sfdt/compare/v0.22.1...ext-v0.13.0">https://github.com/scoobydrew83/sfdt/compare/v0.22.1...ext-v0.13.0</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/custom-amazon-bedrock-agent-action/</link><pubDate>Thu, 13 Aug 2026 05:50:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide AI-powered feedback, enhancing code quality, security, and performance. It allows customization of prompts using Bedrock Agents, supports memory for context across PRs, and integrates with Knowledge Bases for enhanced accuracy and relevance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide AI-powered feedback, enhancing code quality, security, and performance. It allows customization of prompts using Bedrock Agents, supports memory for context across PRs, and integrates with Knowledge Bases for enhanced accuracy and relevance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/sherpa.sh/</link><pubDate>Thu, 13 Aug 2026 05:49:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI tool that automates infrastructure deployment and configuration based on plain English prompts. It supports multiple cloud providers, frameworks, and configurations, allowing developers to describe their needs in natural language and have it translated into optimized infrastructure setups. The action integrates with GitHub Actions and the Claude Code CLI for seamless deployment workflows, enabling users to deploy applications quickly and easily across various cloud environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI tool that automates infrastructure deployment and configuration based on plain English prompts. It supports multiple cloud providers, frameworks, and configurations, allowing developers to describe their needs in natural language and have it translated into optimized infrastructure setups. The action integrates with GitHub Actions and the Claude Code CLI for seamless deployment workflows, enabling users to deploy applications quickly and easily across various cloud environments.</p>
]]></content:encoded></item><item><title>greenbump</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/greenbump/</link><pubDate>Thu, 13 Aug 2026 05:48:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/greenbump/</guid><description>Version updated for https://github.com/shidesheng0218/greenbump to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The greenbump action automates the process of upgrading dependencies while ensuring that breaking changes are fixed using an AI agent. It helps bring your own Anthropic API key to verify against real tests before merging updates, making it a safer and more efficient option than manually reviewing every upgrade.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shidesheng0218/greenbump">https://github.com/shidesheng0218/greenbump</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/greenbump">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The greenbump action automates the process of upgrading dependencies while ensuring that breaking changes are fixed using an AI agent. It helps bring your own Anthropic API key to verify against real tests before merging updates, making it a safer and more efficient option than manually reviewing every upgrade.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>See <a href="https://github.com/shidesheng0218/greenbump/blob/master/CHANGELOG.md">CHANGELOG.md</a> for details.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/shidesheng0218/greenbump/compare/v0.2.0...v0.2.1">https://github.com/shidesheng0218/greenbump/compare/v0.2.0...v0.2.1</a></p>
]]></content:encoded></item><item><title>Conventional Release Creator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/conventional-release-creator/</link><pubDate>Thu, 13 Aug 2026 05:46:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/conventional-release-creator/</guid><description>Version updated for https://github.com/so1omon563/release-creator to version v2.0.1.
This action is used across all versions by 13 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Release Creator is a GitHub Action that automates the creation of GitHub Releases from conventional commit history. It generates structured release notes grouped by commit type and automatically detects pre-release status from SemVer identifiers. The action supports multiple release note formats, such as grouped, conventional, flat, and GitHub-native, allowing for customization of how releases are presented.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/so1omon563/release-creator">https://github.com/so1omon563/release-creator</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>13</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/conventional-release-creator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Release Creator is a GitHub Action that automates the creation of GitHub Releases from conventional commit history. It generates structured release notes grouped by commit type and automatically detects pre-release status from SemVer identifiers. The action supports multiple release note formats, such as grouped, conventional, flat, and GitHub-native, allowing for customization of how releases are presented.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li>report truthful suite totals #skip (<code>d583cba</code>)</li>
<li>route note failures through policy #skip (<code>9ca86a0</code>)</li>
<li>validate constrained inputs #skip (<code>cdf00a9</code>)</li>
<li>preserve asset glob depth #skip (<code>7190b76</code>)</li>
<li>keep draft floating tags unchanged #skip (<code>9e16890</code>)</li>
<li>pin floating tag target #skip (<code>fcd6a35</code>)</li>
<li>reject non-tag ref fallback #skip (<code>06551d2</code>)</li>
<li>report complete coverage (<code>0b4544d</code>)</li>
</ul>
<h3 id="-documentation">📖 Documentation</h3>
<ul>
<li>document draft floating-tag skip #skip (<code>5c04131</code>)</li>
<li>remove duplicate contributor metadata #skip (<code>1b21dc3</code>)</li>
</ul>
<h3 id="-cicd">🔧 CI/CD</h3>
<ul>
<li>update coverage badge [skip ci] (<code>7d2c6d4</code>)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Thu, 13 Aug 2026 05:45:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Swarm service by preparing it for production. It ensures that all necessary dependencies are installed and bundled, making it ready to be deployed with minimal configuration changes. The action streamlines the process of deploying services from development to production on Docker Swarm environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Swarm service by preparing it for production. It ensures that all necessary dependencies are installed and bundled, making it ready to be deployed with minimal configuration changes. The action streamlines the process of deploying services from development to production on Docker Swarm environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>Deploy to Vercel</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/deploy-to-vercel/</link><pubDate>Thu, 13 Aug 2026 05:45:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/deploy-to-vercel/</guid><description>Version updated for https://github.com/Spectra010s/d-vercel to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The d-vercel GitHub Action simplifies the deployment of frontend and full-stack applications to Vercel. It automates PR comments, supports monorepos, and allows for customized CI/CD pipelines. The action generates sticky comments on Pull Requests with deployment status, preview links, commit hashes, and logs, facilitating quick updates.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Spectra010s/d-vercel">https://github.com/Spectra010s/d-vercel</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-to-vercel">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The d-vercel GitHub Action simplifies the deployment of frontend and full-stack applications to Vercel. It automates PR comments, supports monorepos, and allows for customized CI/CD pipelines. The action generates sticky comments on Pull Requests with deployment status, preview links, commit hashes, and logs, facilitating quick updates.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="γëíæç-new-comment-marker-input-for-monorepo-workflows">Γëí╞Æ├£├ç New: <code>comment-marker</code> input for monorepo workflows</h3>
<p><code>d-vercel</code> now supports a <code>comment-marker</code> input so you can set a <strong>distinct sticky comment marker per job</strong>. In monorepos (Turborepo/pnpm workspaces) where one workflow runs multiple <code>d-vercel</code> jobs ╬ô├ç├╢ one per app ╬ô├ç├╢ each job previously shared the same hardcoded marker, so the last job to finish overwrote the single PR comment.</p>
<p>Now each app keeps its own sticky comment, updated independently on subsequent commits.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Spectra010s/d-vercel@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">comment-title</span>: <span style="color:#e6db74">&#34;Vercel Deployment ╬ô├ç├╢ Web&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">comment-marker</span>: <span style="color:#e6db74">&#34;vercel-sticky-comment-web&#34;</span>
</span></span></code></pre></div><ul>
<li>New &ldquo;Monorepo: Multiple Apps, One Workflow&rdquo; section in the README (<a href="https://github.com/Spectra010s/d-vercel/pull/13">#13</a>)</li>
<li>Closes <a href="https://github.com/Spectra010s/d-vercel/issues/12">#12</a></li>
</ul>
<h3 id="maintenance">Maintenance</h3>
<ul>
<li>Bumped <a href="https://git-aic.pages.dev"><code>git-aic</code></a> to <code>1.4.1</code>, <code>prettier</code> to <code>3.9.6</code>, and <code>rollup</code> to <code>4.62.4</code></li>
<li>Fixed git-aic links in <code>CONTRIBUTING.md</code></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/Spectra010s/d-vercel/pull/14">https://github.com/Spectra010s/d-vercel/pull/14</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Spectra010s/d-vercel/compare/v1.2.0...v1.3.0">https://github.com/Spectra010s/d-vercel/compare/v1.2.0...v1.3.0</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/classroom-to-sheets-integration/</link><pubDate>Thu, 13 Aug 2026 05:44:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending assignment results from GitHub Classroom to Google Sheets. It helps streamline grading workflows by automatically updating the specified columns with task scores and creating necessary rows as needed. The integration requires setting up Google Cloud API credentials and configuring secrets in your organization, then integrating it into a GitHub Actions workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending assignment results from GitHub Classroom to Google Sheets. It helps streamline grading workflows by automatically updating the specified columns with task scores and creating necessary rows as needed. The integration requires setting up Google Cloud API credentials and configuring secrets in your organization, then integrating it into a GitHub Actions workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>Firebase Rules Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/firebase-rules-audit/</link><pubDate>Thu, 13 Aug 2026 05:43:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/firebase-rules-audit/</guid><description>Version updated for https://github.com/subhan900/firebase-rules-audit to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Firebase Rules Audit GitHub Action is a local command-line tool that reviews Firestore and Cloud Storage security rules for common risky access patterns, including unconditional allow statements, public if true conditions, rules without a request.auth reference, and recursive wildcard paths. It provides static checks to help identify potential security vulnerabilities in the rules files without connecting to Firebase or deploying them. The tool can be run from the command line or as a GitHub Action, and it outputs both console and machine-readable reports for further automation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/subhan900/firebase-rules-audit">https://github.com/subhan900/firebase-rules-audit</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/firebase-rules-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Firebase Rules Audit GitHub Action is a local command-line tool that reviews Firestore and Cloud Storage security rules for common risky access patterns, including unconditional <code>allow</code> statements, public <code>if true</code> conditions, rules without a <code>request.auth</code> reference, and recursive wildcard paths. It provides static checks to help identify potential security vulnerabilities in the rules files without connecting to Firebase or deploying them. The tool can be run from the command line or as a GitHub Action, and it outputs both console and machine-readable reports for further automation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="first-stable-release">First stable release</h2>
<p>Firebase Rules Audit is a local-only GitHub Action and CLI for flagging common risky Firestore and Cloud Storage security-rule patterns.</p>
<h3 id="highlights">Highlights</h3>
<ul>
<li>Detects unconditional allow statements and public <code>if true</code> conditions</li>
<li>Flags rules that do not reference <code>request.auth</code></li>
<li>Reports recursive wildcard paths</li>
<li>Provides console, JSON, and Markdown output</li>
<li>Supports CI enforcement with <code>fail-on-high</code></li>
</ul>
<h3 id="use-in-github-actions">Use in GitHub Actions</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">subhan900/firebase-rules-audit@v1.0.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">files</span>: <span style="color:#ae81ff">firestore.rules storage.rules</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on-high</span>: <span style="color:#e6db74">&#39;true&#39;</span>
</span></span></code></pre></div><p>This is static analysis, not a replacement for a complete Firebase security review.</p>
]]></content:encoded></item><item><title>Tessl Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/tessl-code-review/</link><pubDate>Thu, 13 Aug 2026 05:42:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/tessl-code-review/</guid><description>Version updated for https://github.com/tesslio/code-review-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Tessl Code Review in GitHub Actions, handling pull-request resolution, exact-head checkout, Tessl CLI setup, review publication, stale-head protection, idempotency, failure notices, and result artifacts. It provides a quick start guide, configuration options, and review cadence support.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tesslio/code-review-action">https://github.com/tesslio/code-review-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tessl-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates Tessl Code Review in GitHub Actions, handling pull-request resolution, exact-head checkout, Tessl CLI setup, review publication, stale-head protection, idempotency, failure notices, and result artifacts. It provides a quick start guide, configuration options, and review cadence support.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The first supported release of the Tessl Code Review Action.</p>
<p>Pin the Action to this release&rsquo;s commit SHA:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">tesslio/code-review-action@1907f303ffe89a7d65e298ee1183e4ccaeeb93b3</span> <span style="color:#75715e"># v1</span>
</span></span></code></pre></div><p>This revision installs Tessl CLI 0.96.0. A review runs the <code>standard</code> profile in advisory mode by default; see the <a href="https://github.com/tesslio/code-review-action#readme">README</a> for gate mode, review cadence, and the <code>lenses</code> input, and the <a href="https://github.com/tesslio/code-review-action/blob/1907f303ffe89a7d65e298ee1183e4ccaeeb93b3/docs/action-contract.md">Action contract</a> for supported configuration and outputs.</p>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/setup-tombi/</link><pubDate>Thu, 13 Aug 2026 05:41:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.3.5.
This action is used across all versions by 145 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi in your GitHub Actions workflow. It allows you to install Tombi CLI versions, either by specifying a version number, using a lock file, or with checksum verification for the downloaded archive and executable binary. The action supports caching and can be configured to use a custom cache directory.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.3.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>145</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up <a href="https://github.com/tombi-toml/tombi">Tombi</a> in your GitHub Actions workflow. It allows you to install Tombi CLI versions, either by specifying a version number, using a lock file, or with checksum verification for the downloaded archive and executable binary. The action supports caching and can be configured to use a custom cache directory.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.3.5">tombi v1.3.5</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1.3.4...v1.3.5">https://github.com/tombi-toml/setup-tombi/compare/v1.3.4...v1.3.5</a></p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/wails3-build-action/</link><pubDate>Thu, 13 Aug 2026 05:39:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub action automates the building of Wails.io v3 projects. It installs GoLang and NodeJS, builds a Wails binary for specified platforms, and optionally uploads the build results to GitHub or a release tag. The action supports various configurations through input parameters such as build name, platform, and obfuscation settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub action automates the building of Wails.io v3 projects. It installs GoLang and NodeJS, builds a Wails binary for specified platforms, and optionally uploads the build results to GitHub or a release tag. The action supports various configurations through input parameters such as build name, platform, and obfuscation settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>Railway Deploy Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/railway-deploy-action/</link><pubDate>Thu, 13 Aug 2026 05:38:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/railway-deploy-action/</guid><description>Version updated for https://github.com/twopow/railway-deploy-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a new container image to a Railway service and waits for the deployment to succeed. It simplifies the process by leveraging the Railway public GraphQL API and handles multiple services concurrently through a matrix strategy. The action supports various configurations such as project, service name, image reference, environment, and debugging options to streamline CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/twopow/railway-deploy-action">https://github.com/twopow/railway-deploy-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/railway-deploy-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a new container image to a <a href="https://railway.com">Railway</a> service and waits for the deployment to succeed. It simplifies the process by leveraging the Railway public GraphQL API and handles multiple services concurrently through a matrix strategy. The action supports various configurations such as project, service name, image reference, environment, and debugging options to streamline CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/twopow/railway-deploy-action/commits/v1">https://github.com/twopow/railway-deploy-action/commits/v1</a></p>
]]></content:encoded></item><item><title>aicheck-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/aicheck-scan/</link><pubDate>Thu, 13 Aug 2026 05:37:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/aicheck-scan/</guid><description>Version updated for https://github.com/unauthdev/aicheck-scan to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, aicheck-scan, prevents coding-agent credential files from being committed to version control by failing the build if such files are detected. It uses a predefined list of file paths and checks for their presence in the repository before allowing a successful commit. The action can be integrated into CI workflows to automate this check.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/unauthdev/aicheck-scan">https://github.com/unauthdev/aicheck-scan</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aicheck-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, aicheck-scan, prevents coding-agent credential files from being committed to version control by failing the build if such files are detected. It uses a predefined list of file paths and checks for their presence in the repository before allowing a successful commit. The action can be integrated into CI workflows to automate this check.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Breaking for the GitHub Action only. The CLI is unchanged.</p>
<p>Root Action is now <code>aicheck agents</code>. No network. No <code>target</code> input.</p>
<pre tabindex="0"><code>- uses: actions/checkout@v4
- uses: unauthdev/aicheck-scan@v2
</code></pre><p>Live-probe moved to <code>uses: unauthdev/aicheck-scan/scan@v2</code> (still needs <code>target:</code>).
<code>uses: unauthdev/aicheck-scan/agents@v2</code> is an alias of the root Action.
<code>@v1</code> is frozen leftover live-probe. Do not move that tag.</p>
<p>SHA256 sums are appended below by the publish workflow.</p>
<h2 id="sha256">SHA256</h2>
<pre tabindex="0"><code>74b589cdeb6d8bb4db224e0e5e46290516d53aafeb484d07497796ac29e69746  aicheck_scan-2.0.0-py3-none-any.whl
e1f59f945f341ae28c1b08423be6ab15594cd088bfb9846c484f1b3520fb93ac  aicheck_scan-2.0.0.tar.gz
</code></pre>]]></content:encoded></item><item><title>GitHub Settings as Code</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/github-settings-as-code/</link><pubDate>Thu, 13 Aug 2026 05:36:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/github-settings-as-code/</guid><description>Version updated for https://github.com/Vivswan/github-settings-as-code to version v2.1.0.
This action is used across all versions by 15 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the application of declarative repository settings from a .github/settings.yml file using a fine-grained personal access token. It replaces the Probot Settings app and manages rulesets such as branch protection and push policies. The action provides visible, stateless workflow runs that report errors if apply fails. It also includes a JSON Schema for the configuration, which is generated from Zod schemas in src/schema.ts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Vivswan/github-settings-as-code">https://github.com/Vivswan/github-settings-as-code</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>15</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-settings-as-code">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the application of declarative repository settings from a <code>.github/settings.yml</code> file using a fine-grained personal access token. It replaces the Probot Settings app and manages rulesets such as branch protection and push policies. The action provides visible, stateless workflow runs that report errors if apply fails. It also includes a JSON Schema for the configuration, which is generated from Zod schemas in <code>src/schema.ts</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="210-2026-08-12"><a href="https://github.com/Vivswan/github-settings-as-code/compare/v2.0.0...v2.1.0">2.1.0</a> (2026-08-12)</h2>
<h3 id="features">Features</h3>
<ul>
<li>attest build provenance and attach the sigstore bundle to releases (<a href="https://github.com/Vivswan/github-settings-as-code/commit/d12eeb8ab48fe92f49e4a0aea251060117cf7027">d12eeb8</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>apply review fixes to the docs and tooling sweep (<a href="https://github.com/Vivswan/github-settings-as-code/commit/a849b19c4b45daebd9901316363abb60c8f35045">a849b19</a>)</li>
<li>apply review fixes to the harness audit batch (<a href="https://github.com/Vivswan/github-settings-as-code/commit/01e9e3b7d26dc36d3cf8db2cd328d2bd6e8c18cf">01e9e3b</a>)</li>
<li>apply review fixes to the src-side audit batch (<a href="https://github.com/Vivswan/github-settings-as-code/commit/ed298706bd64261a67e464a9a01f3d696552777b">ed29870</a>)</li>
<li>centralize the token-leak sweep in the runner (<a href="https://github.com/Vivswan/github-settings-as-code/commit/84f5ae1f737903d4c55bbbca2c1d9df919d41eaa">84f5ae1</a>)</li>
<li>classify rate limits structurally on every path (<a href="https://github.com/Vivswan/github-settings-as-code/commit/0c2eb3cf20fc001f3481ff0c6a5263a928397df4">0c2eb3c</a>)</li>
<li>correct mock identity minting and the pages resurrect bug (<a href="https://github.com/Vivswan/github-settings-as-code/commit/56502448ece1bfd7a506f5d806a5fd1bf6d27024">5650244</a>)</li>
<li>cover every faultable section in the fuzz fault battery (<a href="https://github.com/Vivswan/github-settings-as-code/commit/f683bb3a990f781cbcaadf60ace3f4f8c9e62751">f683bb3</a>)</li>
<li>derive owner-kind sensitivity from the section declaration (<a href="https://github.com/Vivswan/github-settings-as-code/commit/5d2b67ecbc8647c71a834fd928f33cd521dada7d">5d2b67e</a>)</li>
<li>discover schema-corpus scenarios across all scenario roots (<a href="https://github.com/Vivswan/github-settings-as-code/commit/4171f1bd773e3d9bd08b0ccd21d17ae2bc9a7325">4171f1b</a>)</li>
<li>harden the CI tooling (<a href="https://github.com/Vivswan/github-settings-as-code/commit/2c1b3603ae8c79ca2e4e1a1b0087ed1850295421">2c1b360</a>)</li>
<li>keep spec-pinned gaps out of automatic graduation (<a href="https://github.com/Vivswan/github-settings-as-code/commit/ae278c9f3770a8580727db917124a0cea32e164b">ae278c9</a>)</li>
<li>reject required-sections entries excluded by the sections allowlist (<a href="https://github.com/Vivswan/github-settings-as-code/commit/13b59f53dd1e356311dbbc4f3934254153112bb9">13b59f5</a>)</li>
<li>size the harness kill cap for the directed fuzz battery (<a href="https://github.com/Vivswan/github-settings-as-code/commit/8543af85d8178f736598e6565839df1c57b8334c">8543af8</a>)</li>
<li>strengthen the remaining per-section representations (<a href="https://github.com/Vivswan/github-settings-as-code/commit/9567f3f8305edc8b4d050d2d00fb20b044df56eb">9567f3f</a>)</li>
</ul>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/rustscript-action/</link><pubDate>Thu, 13 Aug 2026 05:35:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.3.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is an interpreter that runs Rust scripts without compiling them. It supports basic Rust features like functions, loops, conditionals, and error handling, but does not support complex types or standard library features. The main purpose of RustScript is to allow developers to quickly test and iterate on small scripts in Rust without waiting for a full compilation process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.3.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is an interpreter that runs Rust scripts without compiling them. It supports basic Rust features like functions, loops, conditionals, and error handling, but does not support complex types or standard library features. The main purpose of RustScript is to allow developers to quickly test and iterate on small scripts in Rust without waiting for a full compilation process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.3.6...v0.3.7">https://github.com/VladasZ/rustscript/compare/v0.3.6...v0.3.7</a></p>
]]></content:encoded></item><item><title>RSecrets Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/rsecrets-scanner/</link><pubDate>Thu, 13 Aug 2026 05:34:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/rsecrets-scanner/</guid><description>Version updated for https://github.com/whit3rabbit/secrets-scanner to version v0.2.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the detection of leaked secrets in source code, configuration files, and pipelines. It uses Rust to perform fast multi-stage scanning with features like fast matching, custom rules, and support for gitleaks-compatible configurations. The action can scan various sources including git-tracked files, changed files, full history patches, staged index blobs, and untracked files. It outputs results in multiple formats (text, JSON, JSONL, SARIF) and supports suppressions and baselines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/whit3rabbit/secrets-scanner">https://github.com/whit3rabbit/secrets-scanner</a></strong> to version <strong>v0.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rsecrets-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the detection of leaked secrets in source code, configuration files, and pipelines. It uses Rust to perform fast multi-stage scanning with features like fast matching, custom rules, and support for gitleaks-compatible configurations. The action can scan various sources including git-tracked files, changed files, full history patches, staged index blobs, and untracked files. It outputs results in multiple formats (text, JSON, JSONL, SARIF) and supports suppressions and baselines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/whit3rabbit/secrets-scanner/compare/v0.2.2...v0.2.3">https://github.com/whit3rabbit/secrets-scanner/compare/v0.2.2...v0.2.3</a></p>
]]></content:encoded></item><item><title>Picket Secret Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/picket-secret-scanner/</link><pubDate>Thu, 13 Aug 2026 05:32:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/picket-secret-scanner/</guid><description>Version updated for https://github.com/willibrandon/picket to version v0.2.10.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Picket is a secrets scanner for .NET that provides a command-line tool, an interactive report triage companion, and native AOT releases. It can scan staged Git changes, Hugging Face models, GitLab issues, and other resources using read-only tokens stored in environment variables or secret files. The action can be integrated into GitHub Actions and Azure Pipelines, and it offers agent guards for Codex and Claude hook events.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/willibrandon/picket">https://github.com/willibrandon/picket</a></strong> to version <strong>v0.2.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/picket-secret-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Picket is a secrets scanner for .NET that provides a command-line tool, an interactive report triage companion, and native AOT releases. It can scan staged Git changes, Hugging Face models, GitLab issues, and other resources using read-only tokens stored in environment variables or secret files. The action can be integrated into GitHub Actions and Azure Pipelines, and it offers agent guards for Codex and Claude hook events.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release artifacts include SHA-256 checksums, package-size metadata, and GitHub artifact attestations.</p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/cowork-harness/</link><pubDate>Thu, 13 Aug 2026 05:32:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.22.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary cowork-harness is a testing tool that automates the testing of Claude Cowork skills by reproducing its observable runtime contract, including limits such as sealed filesystem and default-deny egress. It allows developers to script and automate end-to-end tests across various scenarios in a headless manner, making it suitable for CI pipelines without relying on the locked-down Desktop app. The tool provides options to test local skills with different fidelity levels (protocol, replay, live), each requiring varying prerequisites including token, runtime setup, and agent configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.22.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>cowork-harness</strong> is a testing tool that automates the testing of Claude Cowork skills by reproducing its observable runtime contract, including limits such as sealed filesystem and default-deny egress. It allows developers to script and automate end-to-end tests across various scenarios in a headless manner, making it suitable for CI pipelines without relying on the locked-down Desktop app. The tool provides options to test local skills with different fidelity levels (protocol, replay, live), each requiring varying prerequisites including token, runtime setup, and agent configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>Platform baseline for Claude Desktop 1.28929.0 (bundled agent ELF <code>2.1.227</code>).</strong> The modeled
first-party spawn contract is unchanged: <code>spawn.tools</code> stays 20 entries, <code>allowedTools</code> 19, and the
egress allowlist 15 domains. The Cowork system prompt, the sub-agent append, <code>coworkSyspromptMap</code> and
the mount-mode anchors all passed unchanged, and the VM rootfs image is byte-identical, so no
provisioning re-capture. The ELF&rsquo;s SHA-256 matches Anthropic&rsquo;s official <code>linux-arm64</code> release
manifest checksum. All three committed cassettes replay clean (re-stamped, not re-recorded — replay
runs no live agent, so their recorded behaviour could not move).</p>
<p>Two spawn-contract deltas, both classified rather than bypassed:</p>
<ul>
<li>Desktop can now splice an <strong><code>Artifact</code> tool</strong> into the session tool list, between <code>AskUserQuestion</code>
and <code>ToolSearch</code>. It is selected by a <strong>server-delivered session flag</strong>, not a feature gate — the
flag arrives with the session config alongside <code>memoryEnabled</code>/<code>skillsEnabled</code>, so it is invisible
to gate diffing and can change without a Desktop release. It is off for a default first-party
session, so the rendered tool list is unchanged and <code>Artifact</code> is <strong>not</strong> added to the pin.</li>
<li>Desktop constructs one new spawn-env key, <code>CLAUDE_CODE_COWORK_FRAME_ARTIFACTS</code>, gated on that same
flag. It is <strong>allowlisted rather than pinned</strong>: a default session never receives it, so pinning
would bake a value into the baseline that production does not send. <code>provenance.spawnEnvKeys</code> grows
60 → 61 to record that Desktop constructs it.</li>
</ul>
<p>Also recorded: the <code>coworkRuntimeConfig</code> gate now serves a <strong>1 h</strong> (was 15 min) TTL for the host-loop
<code>web_fetch</code> dedup cache. The harness reads that value from the baseline, so the change is carried
automatically; the code-level fallback is unchanged and still mirrors Desktop&rsquo;s own absent-key default.</p>
</li>
<li>
<p><strong>Guards for the conditional <code>Artifact</code> tool and its spawn-env key.</strong> <code>sync</code> admits the new spread
only while it still resolves to the frame-artifacts predicate. The check walks the real chain —
condition → attended-turn wrapper → predicate — capturing each callee rather than hard-coding
minified names, and matches the condition as a <strong>whole expression anchored at both ends</strong>. Fragment
matching is not sufficient and was the defect in an earlier draft: appending <code>||!0</code>, flipping the
cached arm, or replacing the trailing restriction all make <code>Artifact</code> unconditional while still
containing the right call. A companion check asserts the env key stays gated on the <strong>same</strong>
predicate as the tool, in both directions, because allowlisting a key is unconditional by
construction — without it, making either unconditional or re-keying one of them would be absorbed
silently. Fifteen mutations covering these paths are executed as tests.</p>
</li>
<li>
<p><strong>Two drift sentinels</strong> in the synced baseline&rsquo;s <code>provenance.gates</code>: the skill-argument collection
guidance flag (on for a standard account) and the auto-mode permission rubric flag (dark). Neither
flag name appears in the asar, so both carry kebab-case descriptors under the existing name caveat
rather than names shaped like verified flags.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><strong>The tools-list tail guard now pins the whole tail.</strong> It previously anchored only on the first
spread after <code>ToolSearch</code>, leaving everything past it unguarded — which defeated its own stated
purpose, since a tool appended there was invisible to both it and the head check. That region already
held a second conditional tool. The tail is now pinned through its closing bracket, with the trailing
tool&rsquo;s name and its condition both <strong>resolved</strong> rather than shape-matched: swapping either would
otherwise pass silently.</p>
</li>
<li>
<p><strong>The CI boundary-parity job pulls the pinned agent-image digest instead of the floating <code>:2</code> tag.</strong>
CI previously certified whatever was published last while <code>doctor</code> certified the pin, so a green CI
said nothing about the pinned image and vice versa. Both now validate the same bytes, and a pin naming
a digest that was never pushed fails the gate rather than silently falling back to a rebuild.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>The egress proxy answered nothing when a CONNECT upstream failed before the tunnel was
established.</strong> A transient failure on an <strong>allowlisted</strong> host — DNS, a TCP reset, an unreachable
route — destroyed the client socket with no HTTP response and no log record anywhere. The client saw
the proxy accept CONNECT and then vanish (<code>curl: (56) Proxy CONNECT aborted</code>), and container logs were
empty, so an intermittent left nothing to diagnose. The asymmetry was accidental: the plain-HTTP
forward path already answered 502 on the same class of failure. CONNECT now matches it and emits a
structured <code>upstream_error</code> line.</p>
<p>The 502 is written only <em>before</em> the tunnel is established — afterwards the socket is a raw tunnel and
an HTTP status would corrupt the stream. No egress-log row is written either way: <code>allow</code> is recorded
only after a successful connect precisely so a failed request cannot false-pass <code>egress_allowed</code>, and
<code>deny</code> would be untrue since the host is allowlisted and nothing was blocked.</p>
<p><strong>The egress proxy image tag moves to <code>cowork-egress-proxy:5</code>.</strong> The tag is the cache key, so existing
installs would otherwise keep serving the old proxy while <code>doctor</code> reported it healthy. No action is
required — the image is rebuilt automatically when the tag is absent.</p>
</li>
<li>
<p><strong>The two allowlisted boundary probes retry</strong> (<code>--retry 2 --retry-all-errors</code>). A single-shot request
through the proxy is exposed to the same ordinary transients, which failed a probe once in eight runs
while the sandbox was behaving correctly. The off-list probes deliberately do <strong>not</strong> retry: they
assert a 403 deny, and retrying a policy decision could turn a real enforcement failure into a later
pass.</p>
</li>
<li>
<p><strong>Release tags no longer move the floating <code>:2</code> agent-image tag.</strong> Every release rebuilt both image
variants and repointed <code>:2</code>, while nothing re-recorded <code>docker/agent-image.json</code> — whose digests are
transcribed by hand from a log line that tag-push builds never emit. Pin and tag therefore diverged
permanently after the first release. <code>docs/maintenance.md</code> already stated the intended contract (move
<code>:2</code> in the same release that ships the updated pin); the workflow now implements it. <code>:2</code> remains
movable by an explicit dispatch, which is how a deliberate image refresh has always been described.</p>
</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>
<p><strong><code>docs/fidelity-gaps.md</code> gains four sections.</strong> <em>Artifacts — two mechanisms, neither modeled</em>
(Cowork&rsquo;s per-artifact bind-mounts and the newer <code>Artifact</code> tool are mutually exclusive, the selecting
flag is not observable locally, and the harness models neither); <em>HIPAA restriction is a process-global
latch</em>; <em>Auto-mode permission rubric is not modeled</em> (dark, and scoped to sessions the harness does not
model); and <em>Skill argument collection — the elicitation form branch is not reachable here</em>, which
records that production splits between <code>AskUserQuestion</code> and an elicitation form while a harness run
deterministically takes the former. That last one is an <strong>open gap with a stated plan</strong>, not a closed
question. The <code>save_skill</code> section notes the tool is now additionally governed by the permission rubric.</p>
</li>
<li>
<p><strong><code>RELEASING.md</code> gains an agent-image checklist item.</strong> The release process never mentioned the image
pin, which is what let the tag drift go unnoticed. It also notes that an unchanged <code>Dockerfile.agent</code>
still yields different bytes on a rebuild, since its <code>apt</code>/<code>pip</code>/<code>npm</code> installs are unpinned.</p>
</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 1.22.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/114">https://github.com/yaniv-golan/cowork-harness/pull/114</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1.21.1...v1.22.0">https://github.com/yaniv-golan/cowork-harness/compare/v1.21.1...v1.22.0</a></p>
]]></content:encoded></item><item><title>GitBanner Profile Card</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/gitbanner-profile-card/</link><pubDate>Thu, 13 Aug 2026 05:30:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/13/gitbanner-profile-card/</guid><description>Version updated for https://github.com/yashksaini-coder/GitBanner to version v1.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates and displays an open-source contribution banner for a GitHub profile README, aggregating contributions from other repositories. It helps users showcase their collaborative efforts across multiple projects. The action requires a Personal Access Token with read:user (and repo scope if including private repos) and can be configured to include specific tiles and date ranges.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yashksaini-coder/GitBanner">https://github.com/yashksaini-coder/GitBanner</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gitbanner-profile-card">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates and displays an open-source contribution banner for a GitHub profile README, aggregating contributions from other repositories. It helps users showcase their collaborative efforts across multiple projects. The action requires a Personal Access Token with read:user (and repo scope if including private repos) and can be configured to include specific tiles and date ranges.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at a527ae4109fcfbc6be5998e57df97333a38d0cd1 -->
<p><strong>Full Changelog</strong>: <a href="https://github.com/yashksaini-coder/GitBanner/compare/v1.2.1...v1.3.0">https://github.com/yashksaini-coder/GitBanner/compare/v1.2.1...v1.3.0</a></p>
]]></content:encoded></item><item><title>JFrog Boost</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/jfrog-boost/</link><pubDate>Wed, 12 Aug 2026 23:03:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/jfrog-boost/</guid><description>Version updated for https://github.com/jfrog/boost to version v0.11.13.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 4 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: Boost is a GitHub Action that automates the process of wrapping and analyzing logs from CI/CD agents. It helps in saving tokens by trimming noisy logs and keeping important context such as errors, timings, and cache hits while maintaining agent output quality. This tool uses OpenTelemetry for monitoring and can be used to automate the initialization, running tasks, and reporting process of agent outputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jfrog/boost">https://github.com/jfrog/boost</a></strong> to version <strong>v0.11.13</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>4</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jfrog-boost">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> Boost is a GitHub Action that automates the process of wrapping and analyzing logs from CI/CD agents. It helps in saving tokens by trimming noisy logs and keeping important context such as errors, timings, and cache hits while maintaining agent output quality. This tool uses OpenTelemetry for monitoring and can be used to automate the initialization, running tasks, and reporting process of agent outputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.7.23 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/41">https://github.com/jfrog/boost/pull/41</a></li>
<li>Release v0.7.25 by @menachemm-byte in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
<li>docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/47">https://github.com/jfrog/boost/pull/47</a></li>
<li>docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/48">https://github.com/jfrog/boost/pull/48</a></li>
<li>docs(readme): add how-to-use walkthrough GIF above Quick start by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/52">https://github.com/jfrog/boost/pull/52</a></li>
<li>docs(readme): add Boost comparison table by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/53">https://github.com/jfrog/boost/pull/53</a></li>
<li>fix: install.ps1 by @menachemm-byte in <a href="https://github.com/jfrog/boost/pull/54">https://github.com/jfrog/boost/pull/54</a></li>
<li>docs: refresh README badges, install, use cases, and agent guide by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/56">https://github.com/jfrog/boost/pull/56</a></li>
<li>docs(readme): localize repo main page with language selector by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/59">https://github.com/jfrog/boost/pull/59</a></li>
<li>docs: clarify collection scope by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/60">https://github.com/jfrog/boost/pull/60</a></li>
<li>docs: surface JFrog Xray security scanning in README and SECURITY.md by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/61">https://github.com/jfrog/boost/pull/61</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@menachemm-byte made their first contribution in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jfrog/boost/compare/v0.7.23...v0.11.13">https://github.com/jfrog/boost/compare/v0.7.23...v0.11.13</a></p>
]]></content:encoded></item><item><title>Gitscaffold – Roadmap to GitHub Issues</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/gitscaffold-roadmap-to-github-issues/</link><pubDate>Wed, 12 Aug 2026 23:02:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/gitscaffold-roadmap-to-github-issues/</guid><description>Version updated for https://github.com/josephedward/gitscaffold to version v0.1.17.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Gitscaffold is a command-line tool and GitHub Action designed to convert Markdown-based roadmaps into structured GitHub issues and milestones using AI-driven extraction and enrichment. It supports various features such as AI-powered issue extraction, roadmap synchronization, bulk deletion of closed issues, cleanup of issue titles, deduplication of issues, AI enrichment of descriptions, display of next action items, selection of the next open task for the current roadmap phase, comparison of local roadmaps vs GitHub issues, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/josephedward/gitscaffold">https://github.com/josephedward/gitscaffold</a></strong> to version <strong>v0.1.17</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gitscaffold-roadmap-to-github-issues">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Gitscaffold is a command-line tool and GitHub Action designed to convert Markdown-based roadmaps into structured GitHub issues and milestones using AI-driven extraction and enrichment. It supports various features such as AI-powered issue extraction, roadmap synchronization, bulk deletion of closed issues, cleanup of issue titles, deduplication of issues, AI enrichment of descriptions, display of next action items, selection of the next open task for the current roadmap phase, comparison of local roadmaps vs GitHub issues, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>docs: Add release notes for v0.1.17 (774e5f5)</li>
<li>fix: Properly mock load_dotenv in get_github_token test (38b8141)</li>
<li>feat: Add uninstall command for clean removal of config and package (9be0afb)</li>
<li>style: Normalize quoting for global config keys (3329e8e)</li>
<li>fix: Prevent dotenv from loading real .env files in tests (5857e52)</li>
<li>fix: Isolate test for global config token read (47e9759)</li>
<li>fix: Resolve config test failures with robust parsing and mocking (8931215)</li>
<li>fix: Update env handling tests for python-dotenv quoting (330874a)</li>
<li>refactor: Secure config file permissions and add dedicated tests (d5404d6)</li>
<li>test: Add unit tests for environment and config handling (0b67f70)</li>
</ul>
]]></content:encoded></item><item><title>SST Operations</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sst-operations/</link><pubDate>Wed, 12 Aug 2026 23:01:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sst-operations/</guid><description>Version updated for https://github.com/kodehort/sst-ops-action to version v0.7.42.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates various operations related to Serverless Stack (SST) applications, including deploying, diffing infrastructure changes, removing resources on PR closure, and staging deployments. It consolidates multiple composite actions into a single tool to streamline SST management workflows. The action supports deployment to specific stages, handling pull request-related operations, and provides customizable features like comment modes and output truncation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kodehort/sst-ops-action">https://github.com/kodehort/sst-ops-action</a></strong> to version <strong>v0.7.42</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sst-operations">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates various operations related to Serverless Stack (SST) applications, including deploying, diffing infrastructure changes, removing resources on PR closure, and staging deployments. It consolidates multiple composite actions into a single tool to streamline SST management workflows. The action supports deployment to specific stages, handling pull request-related operations, and provides customizable features like comment modes and output truncation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="release-v0742">Release v0.7.42</h1>
<p><strong>Release Date:</strong> 2026-08-12
<strong>Previous Version:</strong> v0.7.41</p>
<h2 id="-whats-new">🚀 What&rsquo;s New</h2>
<h2 id="-bundle-information">📦 Bundle Information</h2>
<ul>
<li><strong>Bundle Size:</strong> 1.51MB (1584536 bytes)</li>
<li><strong>Integrity Hash:</strong> <code>3ffa6987e95304a4...</code></li>
<li><strong>Format:</strong> ES Modules for GitHub Actions</li>
<li><strong>Target:</strong> Node.js 20+</li>
<li><strong>Source Maps:</strong> Included for debugging</li>
<li><strong>Distribution:</strong> Files included in repository at tagged version</li>
</ul>
<h2 id="-usage">🚀 Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">SST Operations</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">kodehort/sst-ops-action@v0.7.42</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">operation</span>: <span style="color:#ae81ff">deploy </span> <span style="color:#75715e"># deploy, diff, or remove</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">stage</span>: <span style="color:#ae81ff">production</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">token</span>: <span style="color:#ae81ff">${{ secrets.GITHUB_TOKEN }}</span>
</span></span></code></pre></div><h2 id="-links">🔗 Links</h2>
<ul>
<li><a href="https://github.com/kodehort/sst-ops-action/compare/v0.7.41...v0.7.42">Full Changelog</a></li>
<li><a href="https://github.com/kodehort/sst-ops-action/blob/v0.7.42/README.md">Documentation</a></li>
<li><a href="https://github.com/marketplace/actions/sst-operations">Action Marketplace</a></li>
</ul>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kodehort/sst-ops-action/compare/v0.7.41...v0.7.42">https://github.com/kodehort/sst-ops-action/compare/v0.7.41...v0.7.42</a></p>
]]></content:encoded></item><item><title>datamodel-code-generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/datamodel-code-generator/</link><pubDate>Wed, 12 Aug 2026 23:00:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/datamodel-code-generator/</guid><description>Version updated for https://github.com/koxudaxi/datamodel-code-generator to version 0.72.4.
This action is used across all versions by 3,445 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates Python data models from schema definitions in various formats and supports multiple input types, including OpenAPI 3, AsyncAPI, JSON Schema, Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, MCP tool schemas, and raw data. It can also convert existing Python types (Pydantic, dataclass, TypedDict) into different output types. The action handles complex schemas and produces type-safe, validated code ready for IDEs and type checkers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/koxudaxi/datamodel-code-generator">https://github.com/koxudaxi/datamodel-code-generator</a></strong> to version <strong>0.72.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3,445</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/datamodel-code-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates Python data models from schema definitions in various formats and supports multiple input types, including OpenAPI 3, AsyncAPI, JSON Schema, Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, MCP tool schemas, and raw data. It can also convert existing Python types (Pydantic, dataclass, TypedDict) into different output types. The action handles complex schemas and produces type-safe, validated code ready for IDEs and type checkers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update CHANGELOG for 0.72.3 by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3724">https://github.com/koxudaxi/datamodel-code-generator/pull/3724</a></li>
<li>Update release benchmark data by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3725">https://github.com/koxudaxi/datamodel-code-generator/pull/3725</a></li>
<li>Update package metadata validation by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3733">https://github.com/koxudaxi/datamodel-code-generator/pull/3733</a></li>
<li>Fix nullable forward reference unions by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3732">https://github.com/koxudaxi/datamodel-code-generator/pull/3732</a></li>
<li>Split generation orchestration into phases by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3726">https://github.com/koxudaxi/datamodel-code-generator/pull/3726</a></li>
<li>Split result emission paths by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3727">https://github.com/koxudaxi/datamodel-code-generator/pull/3727</a></li>
<li>Split parser processing phases by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3728">https://github.com/koxudaxi/datamodel-code-generator/pull/3728</a></li>
<li>Group single-module processing steps by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3729">https://github.com/koxudaxi/datamodel-code-generator/pull/3729</a></li>
<li>Remove Astral sponsor logo by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3735">https://github.com/koxudaxi/datamodel-code-generator/pull/3735</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/koxudaxi/datamodel-code-generator/compare/0.72.3...0.72.4">https://github.com/koxudaxi/datamodel-code-generator/compare/0.72.3...0.72.4</a></p>
]]></content:encoded></item><item><title>Git Checkout Lite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/git-checkout-lite/</link><pubDate>Wed, 12 Aug 2026 22:58:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/git-checkout-lite/</guid><description>Version updated for https://github.com/lite-actions/git-checkout to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks out a repository using plain git. It automates the process of cloning and fetching repositories, allowing for custom configurations such as sparse checkout and partial clone filtering. The action provides options to clean the checkout directory, fetch a specific number of commits or tags, and use authentication tokens for accessing private repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lite-actions/git-checkout">https://github.com/lite-actions/git-checkout</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/git-checkout-lite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks out a repository using plain <code>git</code>. It automates the process of cloning and fetching repositories, allowing for custom configurations such as sparse checkout and partial clone filtering. The action provides options to clean the checkout directory, fetch a specific number of commits or tags, and use authentication tokens for accessing private repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="initial-release">Initial release</h3>
<p>This is the initial first stage release. Other actions will depend on this action.</p>
<p>The next release will include those additional actions in the workflows!</p>
]]></content:encoded></item><item><title>AIShield MCP/Agent Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/aishield-mcp/agent-security-scan/</link><pubDate>Wed, 12 Aug 2026 22:57:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/aishield-mcp/agent-security-scan/</guid><description>Version updated for https://github.com/lm203688/aishield to version v4.2.2.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action scans and evaluates agents to ensure they adhere to security standards, detecting potential vulnerabilities such as injection attacks and data leaks. It also provides a comprehensive identity system for agents, including DID-based authentication and reputation management. The action integrates with existing toolchains and supports multiple programming languages for safe execution of scripts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lm203688/aishield">https://github.com/lm203688/aishield</a></strong> to version <strong>v4.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aishield-mcp-agent-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action scans and evaluates agents to ensure they adhere to security standards, detecting potential vulnerabilities such as injection attacks and data leaks. It also provides a comprehensive identity system for agents, including DID-based authentication and reputation management. The action integrates with existing toolchains and supports multiple programming languages for safe execution of scripts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="aishield-v422">AIShield v4.2.2</h2>
<h3 id="重点github-action-正式上架就绪">重点：GitHub Action 正式上架就绪</h3>
<ul>
<li>新增 <code>action_entrypoint.py</code> + <code>Dockerfile</code> ENTRYPOINT：Action 现在<strong>真正执行扫描</strong>（此前只启动服务器），产出 <code>score</code> / <code>risk_level</code> / JSON 报告 / SARIF。</li>
<li><code>action.yml</code>：<code>source_url</code> 改为可选（留空扫当前仓库），默认 <strong>no-spawn（不执行被扫配置）</strong>。</li>
<li>用法：<code>uses: lm203688/aishield@v4.2.2</code>，<code>fail_on: high</code>，SARIF 直传 GitHub Security。</li>
</ul>
<h3 id="生态位占位docs">生态位占位（docs/）</h3>
<ul>
<li><code>docs/ecosystem-positioning-2026.md</code>：agent 生态 4 层 + 数据层盘点，已介入/缺口、开源参考、执行清单。</li>
<li><code>docs/trust-attestation-spec.md</code>：可嵌入发现层的<strong>中立信任凭证</strong> <code>aishield-trust/v1</code>（Server Card / Agent Card / ai-catalog 用 <code>trust</code> 字段引用）。</li>
<li><code>docs/.well-known/agent-card.json</code> 已 dogfood <code>trust</code> 字段。</li>
<li><code>distribution/guardrail-harness/</code>：forge / Goose / Open Interpreter 的 drop-in 内容安全护栏示例。</li>
</ul>
<h3 id="规则与能力">规则与能力</h3>
<ul>
<li>214 MCP / 220 Skill 规则，OWASP MCP Top 10 + Agentic ASI01–10 双维对齐。</li>
<li>Agent 计算机「内容安全平面」叙事（与隔离运行时互补）。</li>
</ul>
<blockquote>
<p>Marketplace 发布需在仓库 Marketplace 标签页点击 Publish（需已验证的发布者身份）。</p>
</blockquote>
]]></content:encoded></item><item><title>crabd</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/crabd/</link><pubDate>Wed, 12 Aug 2026 22:55:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/crabd/</guid><description>Version updated for https://github.com/louisescher/crabd to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates multi-provider coding tasks using AI models like Anthropic’s Claude. It allows users to interact with GitHub and Forgejo projects via @-mentions, review pull requests, and implement issues on any supported model, providing a seamless integration into various CI workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/louisescher/crabd">https://github.com/louisescher/crabd</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crab-d">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates multi-provider coding tasks using AI models like Anthropic&rsquo;s Claude. It allows users to interact with GitHub and Forgejo projects via @-mentions, review pull requests, and implement issues on any supported model, providing a seamless integration into various CI workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: version packages by @github-actions[bot] in <a href="https://github.com/louisescher/crabd/pull/42">https://github.com/louisescher/crabd/pull/42</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/louisescher/crabd/compare/v1.0.0...v1.0.1">https://github.com/louisescher/crabd/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>MigrationPilot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/migrationpilot/</link><pubDate>Wed, 12 Aug 2026 22:55:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/migrationpilot/</guid><description>Version updated for https://github.com/mickelsamuel/migrationpilot to version v1.6.1.
This action is used across all versions by 1 repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary MigrationPilot is a GitHub Action that analyzes PostgreSQL migration SQL files to ensure they adhere to best practices and are free of common issues. It checks 112 rules, including locking behavior, query timeouts, and index creation methods, ensuring migrations are safe before merging into the main branch. The action outputs detailed reports with violation summaries and suggestions for improving the migration scripts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mickelsamuel/migrationpilot">https://github.com/mickelsamuel/migrationpilot</a></strong> to version <strong>v1.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<p>Go to the <a href="https://github.com/marketplace/actions/migrationpilot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>MigrationPilot is a GitHub Action that analyzes PostgreSQL migration SQL files to ensure they adhere to best practices and are free of common issues. It checks 112 rules, including locking behavior, query timeouts, and index creation methods, ensuring migrations are safe before merging into the main branch. The action outputs detailed reports with violation summaries and suggestions for improving the migration scripts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>build(action): bundle dist/action for v1.6.1 (bab9820)</li>
<li>test(enterprise): pin homedir so the auth tests are hermetic on clean CI (fd9cc4a)</li>
<li>chore(site): regenerate the hero fixture for 1.6.1 (d91e66b)</li>
<li>bench: v1.6.1 catches the invalid-index retry (u13) — 31/33 strict, regenerated on a quiet machine (c602273)</li>
<li>chore: v1.6.1 — version cascade, changelog, cli-reference completeness, refreshed benchmark numbers (2dede01)</li>
<li>test: regenerate snapshots for the merged engine (1051c50)</li>
<li>merge: close the last-mile gaps a first user hits — pre-commit, schema, simulate, the safe-index recipe (288eb97)</li>
<li>merge: the Action survives a read-only token, and the report a reviewer can act on (b9c9842)</li>
<li>docs: the seven commands the CLI reference never mentioned (4553851)</li>
<li>fix(cli): stop offering to silence the criticals that just fired (0266c83)</li>
</ul>
]]></content:encoded></item><item><title>Set up MLIR toolchain</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/set-up-mlir-toolchain/</link><pubDate>Wed, 12 Aug 2026 22:53:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/set-up-mlir-toolchain/</guid><description>Version updated for https://github.com/munich-quantum-software/setup-mlir to version v1.4.2.
This action is used across all versions by 5 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup of MLIR and provides installation scripts for local use, allowing users to easily integrate MLIR into their workflows. The action includes options to specify LLVM versions or commit hashes and install debug builds on Windows. It also supports automated downloads and decompression using a platform-specific zstd binary, ensuring compatibility across different systems without requiring additional dependencies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/munich-quantum-software/setup-mlir">https://github.com/munich-quantum-software/setup-mlir</a></strong> to version <strong>v1.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/set-up-mlir-toolchain">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup of MLIR and provides installation scripts for local use, allowing users to easily integrate MLIR into their workflows. The action includes options to specify LLVM versions or commit hashes and install debug builds on Windows. It also supports automated downloads and decompression using a platform-specific <code>zstd</code> binary, ensuring compatibility across different systems without requiring additional dependencies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-what-changed">👀 What Changed</h2>
<p><em>Please refer to the <a href="https://github.com/munich-quantum-software/setup-mlir/blob/main/CHANGELOG.md">changelog</a> for a structured overview of the changes.</em></p>
<h2 id="-bug-fixes">🐛 Bug Fixes</h2>
<ul>
<li>🐛 Load the remote version manifest from <code>main</code> (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/230">#230</a>) (<strong>@denialhaag</strong>)</li>
</ul>
<h2 id="-documentation">📄 Documentation</h2>
<ul>
<li>🔖 Prepare release of <code>v1.4.2</code> (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/231">#231</a>) (<strong>@denialhaag</strong>)</li>
<li>👷 Update known versions for 2026.08.11 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/229">#229</a>) (<strong>@<a href="https://github.com/apps/mqt-app">mqt-app[bot]</a></strong>)</li>
<li>👷 Update known versions for 2026.07.13 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/214">#214</a>) (<strong>@<a href="https://github.com/apps/mqt-app">mqt-app[bot]</a></strong>)</li>
</ul>
<h2 id="-ci">🤖 CI</h2>
<ul>
<li>👷 Update macOS runners (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/232">#232</a>) (<strong>@denialhaag</strong>)</li>
</ul>
<h2 id="-dependencies">⬆️ Dependencies</h2>
<details>
<summary>31 changes</summary>
<ul>
<li>🔧 Update pre-commit hooks (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/233">#233</a>) (<strong>@denialhaag</strong>)</li>
<li>⬆️🔒️ Lock file maintenance (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/228">#228</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️🪝 Update pre-commit hook python-jsonschema/check-jsonschema to v0.38.0 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/227">#227</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️🪝 Update pre-commit hook adhtruong/mirrors-typos to v1.49.0 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/226">#226</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️🔒️ Lock file maintenance (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/225">#225</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️📜 Update patch updates (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/222">#222</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️📜 Update dependency @types/semver to v7.8.0 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/224">#224</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️📜 Update dependency @octokit/openapi-types to v28 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/223">#223</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️👨‍💻 Update release-drafter/release-drafter action to v7.7.0 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/221">#221</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️👨‍💻 Update github/codeql-action action to v4.37.4 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/220">#220</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️📜 Update dependency typescript to v7 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/212">#212</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️👨‍💻 Update patch updates (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/219">#219</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️👨‍💻 Update actions/setup-node action to v7 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/217">#217</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️👨‍💻 Update release-drafter/release-drafter action to v7.6.0 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/218">#218</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️👨‍💻 Update actions/setup-node action to v6.5.0 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/216">#216</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️👨‍💻 Update github/codeql-action action to v4.37.1 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/215">#215</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️🔒️ Lock file maintenance (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/213">#213</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️👨‍💻 Update github/codeql-action action to v4.37.0 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/211">#211</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️📜 Update patch updates (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/210">#210</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️🔒️ Lock file maintenance (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/209">#209</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️🪝 Update pre-commit hook adhtruong/mirrors-typos to v1.48.0 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/208">#208</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️📜 Update patch updates (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/207">#207</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️🪝 Update pre-commit hook rbubley/mirrors-prettier to v3.9.1 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/206">#206</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️🪝 Update pre-commit hook rbubley/mirrors-prettier to v3.8.5 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/205">#205</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️👨‍💻 Update release-drafter/release-drafter action to v7.5.1 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/204">#204</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️🔒️ Lock file maintenance (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/203">#203</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️📜 Update patch updates to v7.8.5 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/199">#199</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️👨‍💻 Update actions/checkout action to v7 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/201">#201</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️👨‍💻 Update release-drafter/release-drafter action to v7.4.0 (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/200">#200</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️🔒️ Lock file maintenance (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/198">#198</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
<li>⬆️📜 Update patch updates (<a href="https://github.com/munich-quantum-software/setup-mlir/pull/197">#197</a>) (<strong>@<a href="https://github.com/apps/renovate">renovate[bot]</a></strong>)</li>
</ul>
</details>
<p><strong>Full Changelog</strong>: <a href="https://github.com/munich-quantum-software/setup-mlir/compare/v1.4.1...v1.4.2">https://github.com/munich-quantum-software/setup-mlir/compare/v1.4.1...v1.4.2</a></p>
]]></content:encoded></item><item><title>SDP CI Integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sdp-ci-integration/</link><pubDate>Wed, 12 Aug 2026 22:52:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sdp-ci-integration/</guid><description>Version updated for https://github.com/opentext/sdp-github-actions-integration to version v26.4.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 1 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the communication between GitHub workflows and an OpenText Core Software Delivery Platform (formerly ALM Octane/ValueEdge) through CI/CD. It monitors workflow runs, updates them in the product, and can handle BDD test results and debugging information. The action supports both unidirectional and bidirectional communication with the product, requiring specific API access roles for higher versions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/opentext/sdp-github-actions-integration">https://github.com/opentext/sdp-github-actions-integration</a></strong> to version <strong>v26.4.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>1</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sdp-ci-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the communication between GitHub workflows and an OpenText Core Software Delivery Platform (formerly ALM Octane/ValueEdge) through CI/CD. It monitors workflow runs, updates them in the product, and can handle BDD test results and debugging information. The action supports both unidirectional and bidirectional communication with the product, requiring specific API access roles for higher versions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="v2640">v26.4.0</h3>
<ul>
<li>Introduced a <strong>deployment lock mechanism</strong> to prevent duplicate workflow runs when multi-job upstream workflows trigger the integration multiple times.</li>
<li>The integration now uses GitHub Deployments as atomic locks to ensure only one workflow processes each upstream workflow run, preventing duplicate CI events in the product.</li>
<li>Added <code>SDP_ENABLE_DEPLOYMENT_LOCK</code> environment variable (enabled by default) to control this feature. Set to <code>false</code> to disable duplicate run protection if needed.</li>
<li>Added comprehensive documentation for the duplicate workflow run protection feature in the README.</li>
</ul>
]]></content:encoded></item><item><title>Test Adequacy Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/test-adequacy-guard/</link><pubDate>Wed, 12 Aug 2026 22:51:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/test-adequacy-guard/</guid><description>Version updated for https://github.com/Ostico/test-guard to version v2.0.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Test-Guard automates the task of checking if a pull request has adequate tests. It evaluates every source file in the PR independently, using diff coverage and heuristic test-file matching to determine if changes are tested. The action provides detailed per-file analysis and uses AI-powered evaluation to ensure comprehensive testing coverage.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Ostico/test-guard">https://github.com/Ostico/test-guard</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/test-adequacy-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Test-Guard automates the task of checking if a pull request has adequate tests. It evaluates every source file in the PR independently, using diff coverage and heuristic test-file matching to determine if changes are tested. The action provides detailed per-file analysis and uses AI-powered evaluation to ensure comprehensive testing coverage.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="a-red-gate-that-measured-nothing">A red gate that measured nothing</h2>
<p>On a <code>pull_request</code> run whose <code>GITHUB_REF</code> is not <code>refs/pull/&lt;number&gt;/merge</code>, the action aborted before Layer 1 ran:</p>
<pre tabindex="0"><code>::error::Could not determine PR number from GITHUB_REF.
</code></pre><p>Exit 1, no coverage read, no diff examined — but the check goes red, which from the author&rsquo;s side is indistinguishable from a test-adequacy verdict.</p>
<p>It reproduces on the <code>edited</code> activity type. Editing a PR body produces a fresh run, and that run can arrive with the ref pointing somewhere other than the merge ref. Since GitHub surfaces the latest run per check name, the result was a red required gate on a commit whose earlier run had passed.</p>
<h2 id="the-fix">The fix</h2>
<p><code>.pull_request.number</code> is present in every <code>pull_request</code> payload, for every activity type. <code>GITHUB_REF</code> carries the number only while GitHub has a merge ref to point the run at.</p>
<p>The action now reads the payload at <code>GITHUB_EVENT_PATH</code> first and keeps <code>GITHUB_REF</code> as the fallback, so every case that worked before still works. An unusable payload — absent, unreadable, malformed, for another event, or with a number that is not an <code>int</code> — yields no number rather than an exception, leaving the fallback its chance. That last case is not hypothetical: <code>true</code> is valid JSON where the number goes, and <code>bool</code> subclasses <code>int</code>, so a naive check would pass <code>True</code> downstream as PR number 1.</p>
<p>The error message, when neither source yields a number, now names both sources and states outright that nothing was measured.</p>
<h2 id="upgrading">Upgrading</h2>
<p>Nothing to change. <code>v2</code> now points here.</p>
<p>12 tests added (455 in the suite), <code>ruff</code> clean, and each of the four ways to break the change was verified to turn the suite red.</p>
<p>Full detail in #6.</p>
]]></content:encoded></item><item><title>codemetrics complexity gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/codemetrics-complexity-gate/</link><pubDate>Wed, 12 Aug 2026 22:49:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/codemetrics-complexity-gate/</guid><description>Version updated for https://github.com/richardwooding/codemetrics to version v0.12.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The codemetrics GitHub Action automates the computation and gating of cyclomatic and cognitive complexities across multiple programming languages. It allows users to set complexity thresholds for pull requests, ensuring that changes do not exceed these limits, thereby maintaining code quality standards. The action uses a pre-built binary for simplicity and runs on any platform, with support for Go and 16 other languages through the tree-sitter backend.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/richardwooding/codemetrics">https://github.com/richardwooding/codemetrics</a></strong> to version <strong>v0.12.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codemetrics-complexity-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The codemetrics GitHub Action automates the computation and gating of cyclomatic and cognitive complexities across multiple programming languages. It allows users to set complexity thresholds for pull requests, ensuring that changes do not exceed these limits, thereby maintaining code quality standards. The action uses a pre-built binary for simplicity and runs on any platform, with support for Go and 16 other languages through the tree-sitter backend.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="others">Others</h3>
<ul>
<li>e15c21b544b5f2bf7a59a4e05e82dad09331f09e: chore(deps): Bump github.com/odvcencio/gotreesitter (#36) (@dependabot[bot])</li>
<li>96daef2859f368a28eb192237a6635be28dc5b28: chore(site): sync gloam assets to 43b9fc8ccd66aa58f25adc74c6b83ab0f8647782 (#35) (@github-actions[bot])</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/kaniko-build-action/</link><pubDate>Wed, 12 Aug 2026 22:47:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting to the log. It solves the problem of automatically greeting people in automated workflows and automates tasks that require basic text output. The key capabilities include setting a custom greeting name and retrieving the current time during execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting to the log. It solves the problem of automatically greeting people in automated workflows and automates tasks that require basic text output. The key capabilities include setting a custom greeting name and retrieving the current time during execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>Lighthouse Snapshot Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/lighthouse-snapshot-action/</link><pubDate>Wed, 12 Aug 2026 22:47:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/lighthouse-snapshot-action/</guid><description>Version updated for https://github.com/seatonjiang/lighthouse-snapshot-action to version 2026.08.12.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary 本 GitHub Action 是一个用于定时创建腾讯云轻量应用服务器快照的工具。它支持设置每天特定时间自动执行快照，并提供手动触发功能。通过使用 GitHub Secrets 存储敏感信息，确保密钥的安全性。用户可以选择循环模式保留 2 个自动创建的快照或固定模式保留 1 个手动创建的快照和 1 个自动创建的快照。
What’s Changed chore: 更新依赖项 (1d0ace9) docs: 更新 LICENSE 文件的版权年份 (aa75892) docs: 添加项目说明文件 (7109414) docs: 添加 Actions 执行截图 (0cebbf0) docs: 添加赞赏码图片 (b7be2dd) feat: 添加元数据文件 (2ad9cc0) feat: 添加核心文件和构建后的文件 (ed923c2) build: 添加项目清单文件 (38a3e01) chore: 添加格式配置文件 (c905d76) chore: 添加忽略配置文件 (34ea98e)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seatonjiang/lighthouse-snapshot-action">https://github.com/seatonjiang/lighthouse-snapshot-action</a></strong> to version <strong>2026.08.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lighthouse-snapshot-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>本 GitHub Action 是一个用于定时创建腾讯云轻量应用服务器快照的工具。它支持设置每天特定时间自动执行快照，并提供手动触发功能。通过使用 GitHub Secrets 存储敏感信息，确保密钥的安全性。用户可以选择循环模式保留 2 个自动创建的快照或固定模式保留 1 个手动创建的快照和 1 个自动创建的快照。</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore: 更新依赖项 (1d0ace9)</li>
<li>docs: 更新 LICENSE 文件的版权年份 (aa75892)</li>
<li>docs: 添加项目说明文件 (7109414)</li>
<li>docs: 添加 Actions 执行截图 (0cebbf0)</li>
<li>docs: 添加赞赏码图片 (b7be2dd)</li>
<li>feat: 添加元数据文件 (2ad9cc0)</li>
<li>feat: 添加核心文件和构建后的文件 (ed923c2)</li>
<li>build: 添加项目清单文件 (38a3e01)</li>
<li>chore: 添加格式配置文件 (c905d76)</li>
<li>chore: 添加忽略配置文件 (34ea98e)</li>
</ul>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/custom-amazon-bedrock-agent-action/</link><pubDate>Wed, 12 Aug 2026 22:46:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in pull requests, providing AI-powered feedback. It supports custom prompts, memory management, and integrates with Amazon Bedrock Knowledge Bases for enhanced context-aware insights. The action is customizable and suitable for various use cases beyond code review, including security assessments and performance optimizations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in pull requests, providing AI-powered feedback. It supports custom prompts, memory management, and integrates with Amazon Bedrock Knowledge Bases for enhanced context-aware insights. The action is customizable and suitable for various use cases beyond code review, including security assessments and performance optimizations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sherpa.sh/</link><pubDate>Wed, 12 Aug 2026 22:45:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven tool that simplifies cloud infrastructure management by automatically creating and configuring resources based on user prompts. It automates deployment, eliminating the need for complex YAML files or DevOps expertise, while providing a plain English interface for developers to describe their requirements. The action supports various cloud providers and frameworks, offering features such as server configuration, DNS management, load balancing, CDN setup, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven tool that simplifies cloud infrastructure management by automatically creating and configuring resources based on user prompts. It automates deployment, eliminating the need for complex YAML files or DevOps expertise, while providing a plain English interface for developers to describe their requirements. The action supports various cloud providers and frameworks, offering features such as server configuration, DNS management, load balancing, CDN setup, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Custom Version Bumper</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/custom-version-bumper/</link><pubDate>Wed, 12 Aug 2026 22:44:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/custom-version-bumper/</guid><description>Version updated for https://github.com/so1omon563/custom-semver-bumper to version v1.0.12.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GitHub Action to automatically tag merge commits with Semantic Versioning 2.0.0-compliant Git tags, handling commit messages for major, minor, and patch bumps, supporting Conventional Commits, pre-releases, and floating reference tags. The action can be configured to skip certain branches or use branch name fallbacks for versioning.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/so1omon563/custom-semver-bumper">https://github.com/so1omon563/custom-semver-bumper</a></strong> to version <strong>v1.0.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>14</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-version-bumper">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GitHub Action to automatically tag merge commits with Semantic Versioning 2.0.0-compliant Git tags, handling commit messages for major, minor, and patch bumps, supporting Conventional Commits, pre-releases, and floating reference tags. The action can be configured to skip certain branches or use branch name fallbacks for versioning.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li>handle pull request heads safely (#16) (<code>356127a</code>)</li>
<li>require bats for full suite (#15) (<code>5b693a4</code>)</li>
<li>parse Conventional Commit headers only (SO1-266) (#14) (<code>ceac5b8</code>)</li>
<li>publish tags atomically (#13) (<code>12902d5</code>)</li>
<li>preserve inline prerelease suffixes (SO1-265) (#12) (<code>d8d7d99</code>)</li>
<li>validate prerelease suffixes (SO1-263) (#11) (<code>554cac9</code>)</li>
<li>validate bump configuration (#10) (<code>b043d9c</code>)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/update-a-config-file-with-values-from-environment/</link><pubDate>Wed, 12 Aug 2026 22:43:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces placeholders in a configuration file with values from environment variables. It’s designed to automate the process of dynamically setting configurations based on environment settings, making it easier to manage and deploy applications across different environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces placeholders in a configuration file with values from environment variables. It&rsquo;s designed to automate the process of dynamically setting configurations based on environment settings, making it easier to manage and deploy applications across different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/ssg-static-site-generator/</link><pubDate>Wed, 12 Aug 2026 22:43:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.29.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a static site generator written in Go that converts Markdown content with YAML frontmatter into a fully functional website. It supports various features such as templates, Sitemap and SEO metadata, webP conversion, and deployment to platforms like GitHub Pages and Netlify.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.29</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a static site generator written in Go that converts Markdown content with YAML frontmatter into a fully functional website. It supports various features such as templates, Sitemap and SEO metadata, webP conversion, and deployment to platforms like GitHub Pages and Netlify.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.29 — fix(#114): snap bundles wpexporter so ssg migrate works by @spagu in <a href="https://github.com/spagu/ssg/pull/124">https://github.com/spagu/ssg/pull/124</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.28...v1.8.29">https://github.com/spagu/ssg/compare/v1.8.28...v1.8.29</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/classroom-to-sheets-integration/</link><pubDate>Wed, 12 Aug 2026 22:42:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates GitHub Classroom assignments with Google Sheets, automatically sending results to a specified Google Sheet. It allows teachers to track assignment grades and provide feedback directly within their Google Sheets. The action requires setting up Google Sheets API credentials and configuring secrets for authentication. Users can update the Google sheet structure by defining column names in their workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates GitHub Classroom assignments with Google Sheets, automatically sending results to a specified Google Sheet. It allows teachers to track assignment grades and provide feedback directly within their Google Sheets. The action requires setting up Google Sheets API credentials and configuring secrets for authentication. Users can update the Google sheet structure by defining column names in their workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>sverklo audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sverklo-audit/</link><pubDate>Wed, 12 Aug 2026 22:41:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sverklo-audit/</guid><description>Version updated for https://github.com/sverklo/sverklo to version v0.29.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sverklo is an open-source local-first Memory Control Plane (MCP) server designed to enhance coding agent productivity by providing context and insights into the codebase. It helps agents make informed decisions by offering symbols, callers, diffs, blast radius, and git-pinned decisions before editing. Sverklo supports multiple language models and integrates with popular coding tools like Claude Code, Cursor, Windsurf, Codex CLI, and any MCP-speaking agent. The action automates the process of generating context for agents to improve their performance by providing a detailed view of the codebase without modifying it.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sverklo/sverklo">https://github.com/sverklo/sverklo</a></strong> to version <strong>v0.29.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sverklo-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sverklo is an open-source local-first Memory Control Plane (MCP) server designed to enhance coding agent productivity by providing context and insights into the codebase. It helps agents make informed decisions by offering symbols, callers, diffs, blast radius, and git-pinned decisions before editing. Sverklo supports multiple language models and integrates with popular coding tools like Claude Code, Cursor, Windsurf, Codex CLI, and any MCP-speaking agent. The action automates the process of generating context for agents to improve their performance by providing a detailed view of the codebase without modifying it.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore(release): v0.29.5 (b0a7b81)</li>
<li>fix: prioritize matched path definitions (ff68633)</li>
<li>chore(release): v0.29.4 (077fc57)</li>
<li>fix: harden proof receipt caller evidence (0e5af34)</li>
<li>chore(release): v0.29.3 (fd90c18)</li>
<li>fix: make proof feedback privacy-safe (c284435)</li>
<li>docs: surface latest proof receipt (3156eff)</li>
<li>0.29.2 (58f82b8)</li>
<li>feat(search): emit bounded budget requests (48b9857)</li>
<li>feat(search): explain result enoughness (87217bd)</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/wails3-build-action/</link><pubDate>Wed, 12 Aug 2026 22:40:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the build process for Wails.io v3 projects. It installs GoLang and NodeJS, builds the project based on specified platforms, and optionally obfuscates the binary before uploading results to GitHub. On tagged builds, it also uploads the release artifacts to the release section. The action supports various configuration options for building and packaging the application.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the build process for Wails.io v3 projects. It installs GoLang and NodeJS, builds the project based on specified platforms, and optionally obfuscates the binary before uploading results to GitHub. On tagged builds, it also uploads the release artifacts to the release section. The action supports various configuration options for building and packaging the application.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Vaara Policy Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/vaara-policy-check/</link><pubDate>Wed, 12 Aug 2026 22:39:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/vaara-policy-check/</guid><description>Version updated for https://github.com/vaaraio/vaara to version v1.66.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Vaara is a Python library that provides verifiable receipts for autonomous actions, ensuring accountability and trust in decision-making processes. It automates the process of verifying and auditing autonomous actions by providing secure logging and evidence storage, which can be used to prove the outcomes of actions and maintain traceability of all activities within an organization.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaaraio/vaara">https://github.com/vaaraio/vaara</a></strong> to version <strong>v1.66.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vaara-policy-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Vaara is a Python library that provides verifiable receipts for autonomous actions, ensuring accountability and trust in decision-making processes. It automates the process of verifying and auditing autonomous actions by providing secure logging and evidence storage, which can be used to prove the outcomes of actions and maintain traceability of all activities within an organization.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1662---2026-08-12">[1.66.2] - 2026-08-12</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>The documented way to use the action did not work.</strong> The README and
<code>docs/github-action.md</code> tell consumers <code>uses: vaaraio/vaara@v1</code>, which is the
GitHub Actions convention, but no <code>v1</code> tag existed. Anyone copying that line
got &ldquo;unable to resolve action vaaraio/vaara@v1&rdquo;. A floating <code>v1</code> tag now
exists and moves with each release.</li>
<li>The release workflow triggered on <code>v*</code>, which would have fired it for the
floating <code>v1</code> tag, derived version &ldquo;1&rdquo;, and failed looking for a changelog
entry that cannot exist. It now triggers only on full version tags.</li>
<li>One example in <code>docs/github-action.md</code> pinned <code>v1.65.0</code>, a release that
predates the action existing.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>The action&rsquo;s display name is now &ldquo;Vaara Policy Check&rdquo;. This is the title
GitHub Marketplace shows. The listing URL is unaffected.</li>
</ul>
]]></content:encoded></item><item><title>Maintainer PR Triage Bot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/maintainer-pr-triage-bot/</link><pubDate>Wed, 12 Aug 2026 22:38:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/maintainer-pr-triage-bot/</guid><description>Version updated for https://github.com/wagmiiii/pr-reviewer to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates PR triage by reading open pull requests, identifying potential blockers, and labeling them with relevant information. It helps maintainers quickly understand which PRs are worth addressing and provides detailed guidance to contributors on what needs improvement. The bot never merges any PRs, leaving the final decision up to the maintainer.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wagmiiii/pr-reviewer">https://github.com/wagmiiii/pr-reviewer</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/maintainer-pr-triage-bot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates PR triage by reading open pull requests, identifying potential blockers, and labeling them with relevant information. It helps maintainers quickly understand which PRs are worth addressing and provides detailed guidance to contributors on what needs improvement. The bot never merges any PRs, leaving the final decision up to the maintainer.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #54 from wagmiiii/feat/sweep-performance-optimizations (b372a50)</li>
<li>chore: rename action to Maintainer PR Triage Bot for marketplace uniqueness (104f69a)</li>
<li>Merge pull request #52 from wagmiiii/feat/sweep-performance-optimizations (4bc3a2d)</li>
<li>fix: read github-token from action inputs to fix missing token error (cc3e84f)</li>
<li>fix: bundle action as cjs to prevent dynamic require error (9a167e3)</li>
<li>Merge pull request #53 from wagmiiii/feat/pr-110-user-gate (cca7ede)</li>
<li>style: fix prettier formatting issues (4bddd3b)</li>
<li>docs: file PR-086, and put PR-110 on the board as the only open question (a1e9219)</li>
<li>fix: mock checks collection in tests and update dist (8245a3e)</li>
<li>chore: add self-dogfooding workflow (bca4e46)</li>
</ul>
]]></content:encoded></item><item><title>E-Mail HTML Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/e-mail-html-validator/</link><pubDate>Wed, 12 Aug 2026 22:36:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/e-mail-html-validator/</guid><description>Version updated for https://github.com/YunaBraska/email-html-validator to version 2026.8.12.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation of HTML email templates against Can I Email, a dataset of supported features and accessibility standards. It supports multiple interfaces including CLI, Java DSL, GitHub Action, Maven Central/GitHub Packages, and Docker image, providing JSON/XML/HTML/Markdown reports. The action can be used to validate inline HTML, files, stdin, or URLs and includes an optional BFSG accessibility audit using Playwright and axe-core.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YunaBraska/email-html-validator">https://github.com/YunaBraska/email-html-validator</a></strong> to version <strong>2026.8.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/e-mail-html-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation of HTML email templates against Can I Email, a dataset of supported features and accessibility standards. It supports multiple interfaces including CLI, Java DSL, GitHub Action, Maven Central/GitHub Packages, and Docker image, providing JSON/XML/HTML/Markdown reports. The action can be used to validate inline HTML, files, stdin, or URLs and includes an optional BFSG accessibility audit using Playwright and axe-core.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci: standardize native release pipeline by @YunaBraska in <a href="https://github.com/YunaBraska/email-html-validator/pull/17">https://github.com/YunaBraska/email-html-validator/pull/17</a></li>
<li>ci: use corrected native workflow by @YunaBraska in <a href="https://github.com/YunaBraska/email-html-validator/pull/18">https://github.com/YunaBraska/email-html-validator/pull/18</a></li>
<li>ci: use corrected native asset workflow by @YunaBraska in <a href="https://github.com/YunaBraska/email-html-validator/pull/19">https://github.com/YunaBraska/email-html-validator/pull/19</a></li>
<li>ci: use Windows-ready native workflow by @YunaBraska in <a href="https://github.com/YunaBraska/email-html-validator/pull/20">https://github.com/YunaBraska/email-html-validator/pull/20</a></li>
<li>ci: simplify release asset flow by @YunaBraska in <a href="https://github.com/YunaBraska/email-html-validator/pull/21">https://github.com/YunaBraska/email-html-validator/pull/21</a></li>
<li>ci: map Central publish secrets by @YunaBraska in <a href="https://github.com/YunaBraska/email-html-validator/pull/22">https://github.com/YunaBraska/email-html-validator/pull/22</a></li>
<li>fix: skip arm64 QEMU browser smoke test by @YunaBraska in <a href="https://github.com/YunaBraska/email-html-validator/pull/23">https://github.com/YunaBraska/email-html-validator/pull/23</a></li>
<li>ci: publish delivery channels in parallel by @YunaBraska in <a href="https://github.com/YunaBraska/email-html-validator/pull/24">https://github.com/YunaBraska/email-html-validator/pull/24</a></li>
<li>ci: align native build matrix by @YunaBraska in <a href="https://github.com/YunaBraska/email-html-validator/pull/25">https://github.com/YunaBraska/email-html-validator/pull/25</a></li>
<li>ci: reuse native Docker assets by @YunaBraska in <a href="https://github.com/YunaBraska/email-html-validator/pull/26">https://github.com/YunaBraska/email-html-validator/pull/26</a></li>
<li>ci: allow Docker artifact downloads by @YunaBraska in <a href="https://github.com/YunaBraska/email-html-validator/pull/27">https://github.com/YunaBraska/email-html-validator/pull/27</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@YunaBraska made their first contribution in <a href="https://github.com/YunaBraska/email-html-validator/pull/17">https://github.com/YunaBraska/email-html-validator/pull/17</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/YunaBraska/email-html-validator/compare/2026.06.1562143...2026.8.12">https://github.com/YunaBraska/email-html-validator/compare/2026.06.1562143...2026.8.12</a></p>
]]></content:encoded></item><item><title>Garita PII Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/garita-pii-guard/</link><pubDate>Wed, 12 Aug 2026 14:58:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/garita-pii-guard/</guid><description>Version updated for https://github.com/proscar87/garita to version v0.33.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Garita is a GitHub Action that prevents sensitive personal information and credentials from entering a repository. It checks for common identifiers such as CURP, RFC, CLABE, and phone numbers to ensure they are not included. Garita uses a single configuration file to specify which sensitive data should be blocked, making it easy to maintain and update without needing to modify the Git history.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/proscar87/garita">https://github.com/proscar87/garita</a></strong> to version <strong>v0.33.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/garita-pii-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Garita is a GitHub Action that prevents sensitive personal information and credentials from entering a repository. It checks for common identifiers such as CURP, RFC, CLABE, and phone numbers to ensure they are not included. Garita uses a single configuration file to specify which sensitive data should be blocked, making it easy to maintain and update without needing to modify the Git history.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>El README prometía que «un identificador con dígito verificador no valida fuera de su país, así que no dispara». Es cierto entre familias distintas y <strong>falso</strong> dentro de una misma. Medido antes de tocar nada:</p>
<table>
  <thead>
      <tr>
          <th>Colisión</th>
          <th style="text-align: right">Cruce</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>NIT guatemalteco ↔ RUC paraguayo (el mismo módulo 11, la misma base, las mismas palabras de contexto)</td>
          <td style="text-align: right"><strong>100 %</strong></td>
      </tr>
      <tr>
          <td>CUIT argentino ↔ RUC peruano (los mismos pesos; el prefijo 20 es válido en los dos)</td>
          <td style="text-align: right"><strong>82.2 %</strong></td>
      </tr>
      <tr>
          <td>Cédula ecuatoriana ↔ NIT colombiano («cédula» satisface el refuerzo del NIT base 9)</td>
          <td style="text-align: right"><strong>8.3 %</strong></td>
      </tr>
  </tbody>
</table>
<p>El reporte emitía <strong>dos hallazgos sobre el mismo número</strong>, cada uno afirmando una nacionalidad distinta con la misma seguridad. Las dos no pueden ser ciertas, y quien lee no tiene cómo saber cuál lo es.</p>
<h2 id="qué-se-hizo">Qué se hizo</h2>
<p>La información para desambiguar <strong>no está en el número</strong>, así que no hay arreglo que la deduzca. Lo que sí se puede es dejar de fingir que la hay: cuando dos países reclaman el mismo valor en la misma línea se emite <strong>un</strong> hallazgo, con los candidatos nombrados y con el camino para volverlo inequívoco (<code>paises:</code>). Se conserva el de mayor severidad y, a igualdad, el primero por nombre de detector, para que la línea base y el SARIF sigan casando entre corridas.</p>
<p>La promesa falsa estaba en tres lugares —README, <code>paises/__init__.py</code> y <code>Config.paises</code>— y los tres quedaron corregidos con los porcentajes medidos.</p>
<h2 id="lo-que-casi-sale-mal">Lo que casi sale mal</h2>
<p>La regla exige países <strong>distintos</strong>, y no es un detalle: la primera versión agrupaba por (archivo, línea, valor recortado) a secas, y al medirla contra un repositorio real <strong>se comió un RFC</strong>. El valor va recortado, así que el CURP y el RFC de una misma persona —que empiezan igual y pueden terminar igual— compartían clave. Dos documentos del mismo país no se contradicen: se suman.</p>
<h2 id="verificación">Verificación</h2>
<p>322 pruebas, cuatro de ellas de contrapeso. Medido contra siete repositorios reales, incluidos los cuatro consumidores del tag <code>v0</code>: reportes byte a byte idénticos.</p>
]]></content:encoded></item><item><title>PssbleTrngle/set-package-version</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/pssbletrngle/set-package-version/</link><pubDate>Wed, 12 Aug 2026 14:57:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/pssbletrngle/set-package-version/</guid><description>Version updated for https://github.com/PssbleTrngle/set-package-version to version v1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is designed to set or update the version of a package in your project. It automates the process of updating package versions, which is useful for version control and dependency management. The action provides a simple interface to specify the new version number, allowing you to streamline release processes and ensure consistent versioning across different environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PssbleTrngle/set-package-version">https://github.com/PssbleTrngle/set-package-version</a></strong> to version <strong>v1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pssbletrngle-set-package-version">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is designed to set or update the version of a package in your project. It automates the process of updating package versions, which is useful for version control and dependency management. The action provides a simple interface to specify the new version number, allowing you to streamline release processes and ensure consistent versioning across different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Initial Release</li>
</ul>
]]></content:encoded></item><item><title>Release Pilot Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/release-pilot-action/</link><pubDate>Wed, 12 Aug 2026 14:56:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/release-pilot-action/</guid><description>Version updated for https://github.com/ranarn/release-pilot to version v1.0.8.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Release Pilot is a GitHub Action that simplifies the release process by automating semantic versioning, tagging, changelog generation, and GitHub Release creation. It uses Conventional Commits parsing to determine the next SemVer version, supports breaking changes with ! footers, and provides features like pre-release support, floating major/minor tags, and Node.js 24+ ESM compatibility. It offers a zero-config approach for users who want a single action to handle all release tasks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ranarn/release-pilot">https://github.com/ranarn/release-pilot</a></strong> to version <strong>v1.0.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/release-pilot-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Release Pilot is a GitHub Action that simplifies the release process by automating semantic versioning, tagging, changelog generation, and GitHub Release creation. It uses Conventional Commits parsing to determine the next SemVer version, supports breaking changes with <code>!</code> footers, and provides features like pre-release support, floating major/minor tags, and Node.js 24+ ESM compatibility. It offers a zero-config approach for users who want a single action to handle all release tasks.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li>Update versions due to audit issues (<a href="https://github.com/ranarn/release-pilot/commit/256256fd1d98f9a6006c6a5b461825fbb3fb0c00">256256f</a>)</li>
<li>Group codeql-action Dependabot updates to avoid version mismatch failures (#61) (<a href="https://github.com/ranarn/release-pilot/commit/77721a396ea9d3f19a63e3d14f6f4b4e76a278cd">77721a3</a>)</li>
</ul>
<h3 id="-build">📦 Build</h3>
<ul>
<li><strong>deps:</strong> bump pnpm/action-setup from 6.0.9 to 6.0.10 (<a href="https://github.com/ranarn/release-pilot/commit/19b819448e6ca7e2134dfdfd14e3def581a7e5b7">19b8194</a>)</li>
<li><strong>deps:</strong> bump actions/stale from 10.4.0 to 11.0.0 (<a href="https://github.com/ranarn/release-pilot/commit/0c7aa83e97b308138ecfa34605826aa01fadf9c8">0c7aa83</a>)</li>
<li><strong>deps:</strong> bump github/codeql-action/analyze from 4.37.2 to 4.37.6 (<a href="https://github.com/ranarn/release-pilot/commit/38344e7c584fb6b98ab7f6dd4078a704a0ff9c4d">38344e7</a>)</li>
<li><strong>deps:</strong> bump github/codeql-action/init from 4.37.3 to 4.37.6 (<a href="https://github.com/ranarn/release-pilot/commit/5752358412b8529c4b0a3452658b3f35ce7e2483">5752358</a>)</li>
<li><strong>deps:</strong> bump github/codeql-action/autobuild from 4.37.2 to 4.37.6 (<a href="https://github.com/ranarn/release-pilot/commit/da268062e5e96615fb86572ef56b07c7e2e0214a">da26806</a>)</li>
<li><strong>deps:</strong> bump github/codeql-action/autobuild from 4.37.0 to 4.37.2 (<a href="https://github.com/ranarn/release-pilot/commit/00fc66264dc4b1e916fc9ab93f20e02669151d0a">00fc662</a>)</li>
<li><strong>deps:</strong> bump github/codeql-action/analyze from 4.37.0 to 4.37.2 (<a href="https://github.com/ranarn/release-pilot/commit/c0687f2ed2d352e8a13119223a3589e74bc7b971">c0687f2</a>)</li>
<li><strong>deps:</strong> bump github/codeql-action/init from 4.37.0 to 4.37.3 (<a href="https://github.com/ranarn/release-pilot/commit/5b4270f1c6aa142f967b72c13c5ae06400d145eb">5b4270f</a>)</li>
<li><strong>deps:</strong> bump actions/checkout from 7.0.0 to 7.0.1 (<a href="https://github.com/ranarn/release-pilot/commit/737824f7af65619e8379f82a63fd91661c5e3535">737824f</a>)</li>
<li><strong>deps:</strong> bump actions/setup-node from 6.4.0 to 7.0.0 (<a href="https://github.com/ranarn/release-pilot/commit/2fafde6e36e4333450b953837ec0302f1c25adc1">2fafde6</a>)</li>
<li><strong>deps:</strong> bump actions/stale from 10.3.0 to 10.4.0 (<a href="https://github.com/ranarn/release-pilot/commit/fe5be85c03287198d7145e05598a3b71e6efc474">fe5be85</a>)</li>
<li><strong>deps:</strong> bump pnpm/action-setup from 6.0.8 to 6.0.9 (<a href="https://github.com/ranarn/release-pilot/commit/f4daeb1bb9f324ff2197cfa58bc888e64af59398">f4daeb1</a>)</li>
<li><strong>deps:</strong> bump github/codeql-action from 4.36.1 to 4.36.2 (<a href="https://github.com/ranarn/release-pilot/commit/7cca48c474783fb934343902d459181f6a3778dc">7cca48c</a>)</li>
</ul>
<h3 id="-chores">🧹 Chores</h3>
<ul>
<li>versions (<a href="https://github.com/ranarn/release-pilot/commit/3985847de24627b1ad4474167778070b572b56f7">3985847</a>)</li>
<li>versions (<a href="https://github.com/ranarn/release-pilot/commit/d947a6177ee834d7caa17c180b5c71b2261fc425">d947a61</a>)</li>
</ul>
]]></content:encoded></item><item><title>file-search-on review gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/file-search-on-review-gate/</link><pubDate>Wed, 12 Aug 2026 14:55:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/file-search-on-review-gate/</guid><description>Version updated for https://github.com/richardwooding/file-search-on to version v0.119.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary file-search-on is a versatile file search tool that uses CEL expressions to filter files based on metadata and content-type-specific attributes. It supports multiple file formats and provides comprehensive extraction of metadata, making it suitable for various use cases such as searching documents, images, and videos by specific criteria. The tool is built in the open and welcomes contributions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/richardwooding/file-search-on">https://github.com/richardwooding/file-search-on</a></strong> to version <strong>v0.119.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/file-search-on-review-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>file-search-on</code> is a versatile file search tool that uses CEL expressions to filter files based on metadata and content-type-specific attributes. It supports multiple file formats and provides comprehensive extraction of metadata, making it suitable for various use cases such as searching documents, images, and videos by specific criteria. The tool is built in the open and welcomes contributions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="others">Others</h3>
<ul>
<li>9248e4dc4ce9056979d6c20ea876caea6445671e chore(deps): Bump modernc.org/sqlite in the minor-and-patch group (#569)</li>
<li>34a18fba2f2922090b921b2f070376db634bbb44 chore(deps): bump codemetrics to v0.12.5, treesitter-symbols to v0.6.5</li>
<li>39243f9c148c25f8b34135c47c4ce1dc45b89845 chore(site): sync gloam assets to 43b9fc8ccd66aa58f25adc74c6b83ab0f8647782 (#568)</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/kaniko-build-action/</link><pubDate>Wed, 12 Aug 2026 14:54:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints a greeting message to the log, with an optional parameter for the name of the person to greet. It uses Docker to run a container and provides an output for the current time.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints a greeting message to the log, with an optional parameter for the name of the person to greet. It uses Docker to run a container and provides an output for the current time.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>PR Is All You Need</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/pr-is-all-you-need/</link><pubDate>Wed, 12 Aug 2026 14:54:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/pr-is-all-you-need/</guid><description>Version updated for https://github.com/sandys/pr-is-all-you-need to version v1.0.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: This GitHub Action, named piayn, automates the management of pull requests (PRs) across multiple branches to enable AI code review tools to process code directly from private branches. It ensures that PRs are open solely as review surfaces and are automatically retired when a branch is merged, deleted, or goes quiet.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sandys/pr-is-all-you-need">https://github.com/sandys/pr-is-all-you-need</a></strong> to version <strong>v1.0.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-is-all-you-need">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> This GitHub Action, named piayn, automates the management of pull requests (PRs) across multiple branches to enable AI code review tools to process code directly from private branches. It ensures that PRs are open solely as review surfaces and are automatically retired when a branch is merged, deleted, or goes quiet.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sandys/pr-is-all-you-need/compare/v1.0.0.1...v1.0.0.2">https://github.com/sandys/pr-is-all-you-need/compare/v1.0.0.1...v1.0.0.2</a></p>
]]></content:encoded></item><item><title>Surefire Test Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/surefire-test-report/</link><pubDate>Wed, 12 Aug 2026 14:53:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/surefire-test-report/</guid><description>Version updated for https://github.com/ScalableCapital/action-surefire-report to version v2.0.5.
This action is used across all versions by 29 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action processes various test reports generated by Maven Surefire, Failsafe, Gradle, Pytest, and Go, publishing the results as either a GitHub check run or workflow-native annotations with a job summary. It supports migration from v1 to v2 with improved default behavior for certain events and new capabilities like workflow-native reporting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ScalableCapital/action-surefire-report">https://github.com/ScalableCapital/action-surefire-report</a></strong> to version <strong>v2.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>29</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/surefire-test-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action processes various test reports generated by Maven Surefire, Failsafe, Gradle, Pytest, and Go, publishing the results as either a GitHub check run or workflow-native annotations with a job summary. It supports migration from v1 to v2 with improved default behavior for certain events and new capabilities like workflow-native reporting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changes">Changes</h2>
<h2 id="-fixes">🐛 Fixes</h2>
<ul>
<li>chore(deps): update all dependencies @ghaiszaher (#38)</li>
<li>chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#31)</li>
<li>chore(deps): bump actions/setup-java from 5 to 5.6.0 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#36)</li>
<li>chore(deps): bump actions/stale from 10 to 11 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#35)</li>
<li>chore(deps-dev): bump nock from 14.0.15 to 14.0.16 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#26)</li>
<li>chore(deps-dev): bump @types/node from 26.0.0 to 26.1.0 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#30)</li>
<li>chore(deps): bump release-drafter/release-drafter from 7.4.0 to 7.5.1 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#24)</li>
</ul>
<h2 id="-dependencies">📦 Dependencies</h2>
<ul>
<li>chore(deps): update all dependencies @ghaiszaher (#38)</li>
<li>chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#31)</li>
<li>chore(deps): bump actions/setup-java from 5 to 5.6.0 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#36)</li>
<li>chore(deps): bump actions/stale from 10 to 11 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#35)</li>
<li>chore(deps-dev): bump vitest from 4.1.9 to 4.1.10 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#34)</li>
<li>chore(deps-dev): bump nock from 14.0.15 to 14.0.16 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#26)</li>
<li>chore(deps-dev): bump @types/node from 26.0.0 to 26.1.0 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#30)</li>
<li>chore(deps): bump release-drafter/release-drafter from 7.4.0 to 7.5.1 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#24)</li>
<li>chore(deps): bump release-drafter/release-drafter/autolabeler from 7.4.0 to 7.5.1 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#25)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ScalableCapital/action-surefire-report/compare/v2.0.4...v2.0.5">https://github.com/ScalableCapital/action-surefire-report/compare/v2.0.4...v2.0.5</a></p>
]]></content:encoded></item><item><title>Mordant Lints</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/mordant-lints/</link><pubDate>Wed, 12 Aug 2026 14:52:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/mordant-lints/</guid><description>Version updated for https://github.com/scarletindustries/mordant-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the linting process using the Mordant library, which helps developers identify potential issues in their code. It builds Mordant against nightly pins and runs it over the workspace, providing findings annotated on the pull request diff, within the job log, and in the job summary. The action can fail if there are any findings or can run without failure based on user settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scarletindustries/mordant-action">https://github.com/scarletindustries/mordant-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mordant-lints">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the linting process using the Mordant library, which helps developers identify potential issues in their code. It builds Mordant against nightly pins and runs it over the workspace, providing findings annotated on the pull request diff, within the job log, and in the job summary. The action can fail if there are any findings or can run without failure based on user settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Runs Mordant lints against any Rust workspace</li>
<li>Needs no Cargo.toml change</li>
<li>Annotates findings on the pull request diff</li>
<li>Tabulates every finding in the job summary</li>
<li>Exits non-zero on the first finding</li>
<li>Caches the driver, library, and dylint binaries</li>
<li>Reads dylint.toml, including the ratchet baseline</li>
</ul>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/custom-amazon-bedrock-agent-action/</link><pubDate>Wed, 12 Aug 2026 14:51:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action leverages Amazon Bedrock Agent to analyze files in a pull request (PR) using customizable prompts and integrates with Amazon Bedrock Knowledge Bases for context-aware insights. It provides tailored analysis, flexible use cases, and seamless integration into the PR process, enhancing code quality, security assessments, and performance optimizations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action leverages Amazon Bedrock Agent to analyze files in a pull request (PR) using customizable prompts and integrates with Amazon Bedrock Knowledge Bases for context-aware insights. It provides tailored analysis, flexible use cases, and seamless integration into the PR process, enhancing code quality, security assessments, and performance optimizations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sherpa.sh/</link><pubDate>Wed, 12 Aug 2026 14:50:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI that automates the deployment of applications across various cloud providers. It simplifies the process by allowing developers to describe their infrastructure needs in plain English, and Sherpa figures out how to configure and deploy it automatically. This tool reduces the need for manual configuration and expertise in DevOps, making it easier for developers to ship products efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI that automates the deployment of applications across various cloud providers. It simplifies the process by allowing developers to describe their infrastructure needs in plain English, and Sherpa figures out how to configure and deploy it automatically. This tool reduces the need for manual configuration and expertise in DevOps, making it easier for developers to ship products efficiently.</p>
]]></content:encoded></item><item><title>Shipi18n Auto Translate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/shipi18n-auto-translate/</link><pubDate>Wed, 12 Aug 2026 14:49:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/shipi18n-auto-translate/</guid><description>Version updated for https://github.com/Shipi18n/shipi18n-github-action to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Shipi18n GitHub Action automatically translates i18n locale files using your own LLM, providing an open-source solution for translating without a Shipi18n account or hosted API. It supports incremental mode and allows you to skip keys or paths during translation, while also verifying placeholder preservation and key consistency. The action can output translated files, verification errors, warnings, and skipped keys count.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Shipi18n/shipi18n-github-action">https://github.com/Shipi18n/shipi18n-github-action</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shipi18n-auto-translate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Shipi18n GitHub Action automatically translates i18n locale files using your own LLM, providing an open-source solution for translating without a Shipi18n account or hosted API. It supports incremental mode and allows you to skip keys or paths during translation, while also verifying placeholder preservation and key consistency. The action can output translated files, verification errors, warnings, and skipped keys count.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v2 drops the hosted Shipi18n API. The action now calls <strong>your own</strong> OpenAI or Anthropic key directly — no Shipi18n account, no API key, no per-word fees.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Shipi18n/shipi18n-github-action@v2</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">source-file</span>: <span style="color:#ae81ff">locales/en.json</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">target-languages</span>: <span style="color:#ae81ff">es,fr,de</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">provider</span>: <span style="color:#ae81ff">anthropic         </span> <span style="color:#75715e"># or openai</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><h2 id="breaking-changes">Breaking changes</h2>
<ul>
<li>The Shipi18n <code>api-key</code> / <code>api-url</code> inputs are gone. Pass <code>provider</code> plus your own LLM key (or set <code>ANTHROPIC_API_KEY</code> / <code>OPENAI_API_KEY</code> in the job env).</li>
<li>Hosted LLM verification, self-correction and dashboard sync are removed. <strong>Local</strong> verification (placeholder, key and length checks) is kept.</li>
<li>The YAML locale-file input is removed; JSON only.</li>
</ul>
<h2 id="added">Added</h2>
<ul>
<li><code>provider</code>, <code>model</code> inputs — Anthropic (default) or OpenAI, with an optional model override.</li>
<li>Local <code>skip-keys</code> / <code>skip-paths</code> glob matching.</li>
<li>Built on the new open-source <a href="https://www.npmjs.com/package/@shipi18n/core"><code>@shipi18n/core</code></a> engine, which is now bundled into <code>dist/</code> along with the provider SDKs.</li>
</ul>
<p>Source for v2 lives in the <a href="https://github.com/Shipi18n/shipi18n">Shipi18n/shipi18n</a> monorepo; this repo remains the release mirror, so <code>@v2</code> keeps working with no path change.</p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/smyklot/</link><pubDate>Wed, 12 Aug 2026 14:48:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.23.1.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges based on the .github/CODEOWNERS file. It allows repository owners to approve or merge PRs by commenting with specific commands or reactions, ensuring only authorized users can perform these actions. The app supports multiple formats for command submission and provides features like reaction-based approval, merge method control, and automated cleanup of bot interactions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.23.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges based on the <code>.github/CODEOWNERS</code> file. It allows repository owners to approve or merge PRs by commenting with specific commands or reactions, ensuring only authorized users can perform these actions. The app supports multiple formats for command submission and provides features like reaction-based approval, merge method control, and automated cleanup of bot interactions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1231-2026-08-12"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.23.0...v1.23.1">1.23.1</a> (2026-08-12)</h2>
<h2 id="smyklot-v1231">Smyklot v1.23.1</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.23.1</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>a19b159aa070b16b36a3eb882bfcfd76d2f7fb69 chore(release): bump version to 1.23.1</li>
<li>8c1dc00e76e553c2e35019266a409338a09988bc fix(ci): use GitHub App client ID (#190)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/update-a-config-file-with-values-from-environment/</link><pubDate>Wed, 12 Aug 2026 14:46:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action reads values from environment variables and replaces placeholders in specified configuration files. It automates tasks like updating configuration settings dynamically based on runtime conditions, ensuring consistency across environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action reads values from environment variables and replaces placeholders in specified configuration files. It automates tasks like updating configuration settings dynamically based on runtime conditions, ensuring consistency across environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add support for .env files (e706be3)</li>
<li>chore: More info (d440258)</li>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Wed, 12 Aug 2026 14:46:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The deploy-swarm-service GitHub Action automates the deployment of a service to a Docker Swarm cluster. It performs two main tasks: running npm ci and bundling the project, then committing the resulting dist directory. This ensures that only necessary changes are pushed to the repository, reducing unnecessary uploads and improving deployment efficiency.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>deploy-swarm-service</code> GitHub Action automates the deployment of a service to a Docker Swarm cluster. It performs two main tasks: running <code>npm ci</code> and bundling the project, then committing the resulting <code>dist</code> directory. This ensures that only necessary changes are pushed to the repository, reducing unnecessary uploads and improving deployment efficiency.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/classroom-to-sheets-integration/</link><pubDate>Wed, 12 Aug 2026 14:46:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates with Google Sheets to automatically send assignment results from GitHub Classroom. It enables the following functionality:
Integration: Automatically updates a Google Sheet with students’ grades and additional information. Task Results: Supports multiple tasks by dynamically adjusting column names based on task IDs specified in the workflow. Column Management: Handles the creation of new columns for tasks that are not yet present in the sheet. Security: Uses service account credentials to ensure secure access to the Google Sheets API. Key Capabilities Automatically updates assignment results in a Google Sheet. Supports multiple tasks by dynamically adjusting column names. Creates new columns and rows as needed based on task IDs specified in the workflow. Securely integrates with Google Sheets using service account credentials. What’s Changed Updated comments (bf17880) Updated .dockerignore (498a6f7) Updated readme (bbb6b5a) Changed dockerfile to docker pull (8c8584b) Changed dockerfile to docker pull (23fa131) Fixed inputs (844c583) Merge pull request #5 from SPGC/using-result-base64-string (042d99f) Fixed input name (92dd201) Merge pull request #4 from SPGC/using-result-base64-string (79dad97) Code cleanup and fix bug with empty env variables (b474731)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates with Google Sheets to automatically send assignment results from GitHub Classroom. It enables the following functionality:</p>
<ol>
<li><strong>Integration</strong>: Automatically updates a Google Sheet with students&rsquo; grades and additional information.</li>
<li><strong>Task Results</strong>: Supports multiple tasks by dynamically adjusting column names based on task IDs specified in the workflow.</li>
<li><strong>Column Management</strong>: Handles the creation of new columns for tasks that are not yet present in the sheet.</li>
<li><strong>Security</strong>: Uses service account credentials to ensure secure access to the Google Sheets API.</li>
</ol>
<h2 id="key-capabilities">Key Capabilities</h2>
<ul>
<li>Automatically updates assignment results in a Google Sheet.</li>
<li>Supports multiple tasks by dynamically adjusting column names.</li>
<li>Creates new columns and rows as needed based on task IDs specified in the workflow.</li>
<li>Securely integrates with Google Sheets using service account credentials.</li>
</ul>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>sverklo audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sverklo-audit/</link><pubDate>Wed, 12 Aug 2026 14:45:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sverklo-audit/</guid><description>Version updated for https://github.com/sverklo/sverklo to version v0.29.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sverklo is an open-source local-first Memory and Context Provider server designed to enhance coding agents by providing them with contextual information such as symbols, callers, diffs, blast radius, and git-pinned decisions before they edit. It allows users to use Sverklo when their agent needs relationships before editing or when they know the exact string. The action is particularly useful for large codebases where writing and running scripts can be time-consuming.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sverklo/sverklo">https://github.com/sverklo/sverklo</a></strong> to version <strong>v0.29.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sverklo-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sverklo is an open-source local-first Memory and Context Provider server designed to enhance coding agents by providing them with contextual information such as symbols, callers, diffs, blast radius, and git-pinned decisions before they edit. It allows users to use Sverklo when their agent needs relationships before editing or when they know the exact string. The action is particularly useful for large codebases where writing and running scripts can be time-consuming.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore(release): v0.29.4 (077fc57)</li>
<li>fix: harden proof receipt caller evidence (0e5af34)</li>
<li>chore(release): v0.29.3 (fd90c18)</li>
<li>fix: make proof feedback privacy-safe (c284435)</li>
<li>docs: surface latest proof receipt (3156eff)</li>
<li>0.29.2 (58f82b8)</li>
<li>feat(search): emit bounded budget requests (48b9857)</li>
<li>feat(search): explain result enoughness (87217bd)</li>
<li>docs: clarify proof-first fit (7c7d1a2)</li>
<li>docs: add proof-run feedback template (c3628e4)</li>
</ul>
]]></content:encoded></item><item><title>hello_task_0812</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/hello_task_0812/</link><pubDate>Wed, 12 Aug 2026 14:44:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/hello_task_0812/</guid><description>Version updated for https://github.com/tanyi1013-arch/my-first-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating a README file for your project by creating a simple template. It solves the problem of maintaining updated README files manually and provides key capabilities for customizing and enhancing the content with additional information, contributors, or links.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tanyi1013-arch/my-first-action">https://github.com/tanyi1013-arch/my-first-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hello_task_0812">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating a README file for your project by creating a simple template. It solves the problem of maintaining updated README files manually and provides key capabilities for customizing and enhancing the content with additional information, contributors, or links.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>初始发布，支持打招呼</p>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/compose-lint/</link><pubDate>Wed, 12 Aug 2026 14:44:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.17.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The compose-lint action is a security-focused linter for Docker Compose files that catches dangerous misconfigurations before they reach production. It automates the process of identifying and fixing common security vulnerabilities in docker-compose.yml and compose.yaml files, such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. The action provides a full rule documentation at tmatens.github.io/compose-lint for reference.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.17.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>compose-lint</code> action is a security-focused linter for Docker Compose files that catches dangerous misconfigurations before they reach production. It automates the process of identifying and fixing common security vulnerabilities in <code>docker-compose.yml</code> and <code>compose.yaml</code> files, such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. The action provides a full rule documentation at <a href="https://tmatens.github.io/compose-lint/">tmatens.github.io/compose-lint</a> for reference.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="upgrading-from-016x">Upgrading from 0.16.x</h3>
<p><strong>Four capabilities that passed on 0.16.0 now fail; nothing else moved.</strong>
<code>SYS_NICE</code>, <code>IPC_LOCK</code> and <code>LEASE</code> are flagged by the new CL-0029, and
<code>SYSLOG</code> by the new CL-0030 — all four at HIGH, and all four ungraded on
0.16.0, where no rule covered them.</p>
<table>
  <thead>
      <tr>
          <th>Trigger</th>
          <th>0.16.0</th>
          <th>0.17.0</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>cap_add: SYS_NICE</code> / <code>IPC_LOCK</code> / <code>LEASE</code></td>
          <td><em>none</em></td>
          <td><strong>CL-0029</strong> HIGH</td>
      </tr>
      <tr>
          <td><code>cap_add: SYSLOG</code></td>
          <td><em>none</em></td>
          <td><strong>CL-0030</strong> HIGH</td>
      </tr>
  </tbody>
</table>
<p>Unlike 0.15.x → 0.16.0, no existing finding changes rule or severity, so a
waiver written against 0.16.0 still covers what it named. The only new
suppressions you may need are for the four capabilities above.</p>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>CL-0029 — host-availability capability added</strong> (HIGH): flags <code>cap_add</code>
of <code>SYS_NICE</code>, <code>IPC_LOCK</code> or <code>LEASE</code>. Each reaches the host with nothing
else in the file and costs availability alone — <code>SYS_NICE</code> puts the
container&rsquo;s threads above every ordinary host process on a scheduler that
is not namespaced, <code>IPC_LOCK</code> pins host RAM past <code>RLIMIT_MEMLOCK</code> that
cannot be reclaimed or swapped, and <code>LEASE</code> stalls the host&rsquo;s own <code>open()</code>
on any bind-mounted path for the kernel&rsquo;s lease-break timeout. Each member
was measured on Docker 29.4.3 holding only that capability under
<code>--cap-drop ALL</code>. The fix text points at <code>deploy.resources</code> and at bounding
a workload that keeps the capability, since SPDK and DPDK ask for
<code>SYS_NICE</code> and <code>IPC_LOCK</code> together.</p>
</li>
<li>
<p><strong>CL-0030 — host-disclosure capability added</strong> (HIGH): flags
<code>cap_add: SYSLOG</code>, which reads the host kernel ring buffer — <code>dmesg</code> is not
namespaced, so the container sees the host&rsquo;s boot, hardware and driver log,
including kernel pointers where <code>kptr_restrict</code> allows them. Independence
from the host&rsquo;s <code>kernel.dmesg_restrict</code> was measured rather than assumed:
with that sysctl at 0, a capless container still read 0 lines against 2,028
with the capability, because Docker&rsquo;s default seccomp profile admits
<code>syslog(2)</code> only for <code>CAP_SYSLOG</code>. The gate is the capability, on any host.</p>
<p>With SYSLOG graded, every Linux capability now carries a rule or a recorded
reason it needs none — <code>test_rule_membership.py</code>&rsquo;s ungraded set is empty.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>CL-0013&rsquo;s remedy for <code>/dev/shm</code> and <code>/dev/hugepages</code> is now something the
reader can actually follow. Both kept firing correctly — a host bind of
either exposes segments belonging to the host and every other container —
but the guidance said to drop the mount and &ldquo;use a named volume&rdquo;, which
provides neither facility. It now names the real alternatives, each
verified against Docker 29.4.3 rather than taken from documentation:
<code>shm_size:</code> for a larger segment, <code>ipc: shareable</code> plus <code>ipc: service:</code> for
two services that must share one, and a <code>hugetlbfs</code> volume for huge pages
(bounded with <code>deploy.resources.limits</code>, since the pool stays host-wide). A
workload that genuinely needs the host&rsquo;s own huge-page files is told to
suppress with a reason rather than pretend the mount is safe. Over the
archived 5,417-file corpus this changed 39 fix texts and zero findings.</li>
<li>CL-0024&rsquo;s doc now states what the <code>SYS_ADMIN</code> judgment call actually
decides, rather than implying a broader choice than the rule makes.</li>
<li><code>docs/state-of-compose.md</code> and its four charts are regenerated on a 0.16.0
baseline, so the published corpus figures reflect the current severity
model rather than 0.15.x pricing.</li>
<li>The examples library is refreshed against 0.16.0 — each worked example
re-linted so its quoted findings, ids and severities match what the release
actually emits.</li>
<li>The demo GIFs are re-rendered on 0.16.0.</li>
<li>Rule counts stated in prose are now held to the registry by
<code>tests/test_rule_surfaces.py</code>. Four surfaces had gone on claiming 25 rules
after CL-0029 and CL-0030 landed — the mkdocs <code>site_description</code> search
engines index, the Docker Hub overview that syncs on every default-branch
push, <code>SECURITY-EXPECTATIONS.md</code>, and the roadmap inventory — because such
counts go stale when a rule lands, not when a version ships, so neither the
release checklist nor CI&rsquo;s version-pin check reached them.</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/wails3-build-action/</link><pubDate>Wed, 12 Aug 2026 14:43:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub action automates the build process for Wails.io projects using GoLang and NodeJS. It builds a binary for different platforms, optionally obfuscates it, and can upload the results to GitHub or release on tagged builds. Users can specify various configurations like Go version, Wails version, build name, platform, caching options, and even build Node.js and Deno applications using pnpm and Deno, respectively.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub action automates the build process for Wails.io projects using GoLang and NodeJS. It builds a binary for different platforms, optionally obfuscates it, and can upload the results to GitHub or release on tagged builds. Users can specify various configurations like Go version, Wails version, build name, platform, caching options, and even build Node.js and Deno applications using pnpm and Deno, respectively.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>Vigilnz Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/vigilnz-security-scan/</link><pubDate>Wed, 12 Aug 2026 14:42:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/vigilnz-security-scan/</guid><description>Version updated for https://github.com/Vigilnz/vigilnz-scan-action to version v1.3.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Vigilnz Security Scan Action automates security scanning tasks such as SCA, SBOM, SAST, IAC SCAN, SECRET SCAN, DAST, and CONTAINER SCAN on GitHub repositories. It integrates with Vigilnz’s API to perform these scans and provides outputs directly in the GitHub Actions workflow. The action is easy to use, requiring an API key stored securely in GitHub Secrets and adding a simple step to your workflow YAML file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Vigilnz/vigilnz-scan-action">https://github.com/Vigilnz/vigilnz-scan-action</a></strong> to version <strong>v1.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vigilnz-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Vigilnz Security Scan Action automates security scanning tasks such as SCA, SBOM, SAST, IAC SCAN, SECRET SCAN, DAST, and CONTAINER SCAN on GitHub repositories. It integrates with Vigilnz&rsquo;s API to perform these scans and provides outputs directly in the GitHub Actions workflow. The action is easy to use, requiring an API key stored securely in GitHub Secrets and adding a simple step to your workflow YAML file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Implement the includes field for folder vise selection scan</li>
<li>Also added the excludes field for to ignore the folder to scan</li>
</ul>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/rustscript-action/</link><pubDate>Wed, 12 Aug 2026 14:40:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.3.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is an interpreter that allows running Rust scripts without compiling them. It supports basic Rust syntax and functions like file reading and printing, but does not compile the script to a binary or execute it with Cargo. Instead, it interprets the script in-memory and runs it on a register VM using multi-threaded Tokio runtime. This makes it ideal for quick prototyping or executing small scripts without waiting for compilation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.3.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is an interpreter that allows running Rust scripts without compiling them. It supports basic Rust syntax and functions like file reading and printing, but does not compile the script to a binary or execute it with Cargo. Instead, it interprets the script in-memory and runs it on a register VM using multi-threaded Tokio runtime. This makes it ideal for quick prototyping or executing small scripts without waiting for compilation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.3.5...v0.3.6">https://github.com/VladasZ/rustscript/compare/v0.3.5...v0.3.6</a></p>
]]></content:encoded></item><item><title>graph-sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/graph-sync/</link><pubDate>Wed, 12 Aug 2026 14:39:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/graph-sync/</guid><description>Version updated for https://github.com/wordlift/graph-sync to version v6.11.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of syncing a graph using Worai, a tool for managing graph data. It installs Worai and its dependencies, including Playwright and Chromium, and runs the synchronization command. The action supports various options for debugging, logging levels, working directories, and configuration paths. Additionally, it can export graph KPIs to WordLift’s API for analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wordlift/graph-sync">https://github.com/wordlift/graph-sync</a></strong> to version <strong>v6.11.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/graph-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of syncing a graph using Worai, a tool for managing graph data. It installs Worai and its dependencies, including Playwright and Chromium, and runs the synchronization command. The action supports various options for debugging, logging levels, working directories, and configuration paths. Additionally, it can export graph KPIs to WordLift&rsquo;s API for analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: Trim sync-report artifacts with 7-day retention and filter out kpi json by @numanwordlift in <a href="https://github.com/wordlift/graph-sync/pull/8">https://github.com/wordlift/graph-sync/pull/8</a></li>
<li>chore: bump default worai to 6.20.10 by @ziodave in <a href="https://github.com/wordlift/graph-sync/pull/9">https://github.com/wordlift/graph-sync/pull/9</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wordlift/graph-sync/compare/v6.11.5...v6.11.6">https://github.com/wordlift/graph-sync/compare/v6.11.5...v6.11.6</a></p>
]]></content:encoded></item><item><title>GitBanner Profile Card</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/gitbanner-profile-card/</link><pubDate>Wed, 12 Aug 2026 14:38:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/gitbanner-profile-card/</guid><description>Version updated for https://github.com/yashksaini-coder/GitBanner to version v1.2.1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action creates an open-source contribution banner based on contributions made to other people’s repositories, measuring and displaying stats such as merged PRs, reviews given, projects contributed to, and issues resolved. It supports both SVG and PNG formats and can be configured with various options like theme, format, output path, and tile rendering. The action automates the process of updating a GitHub profile README with this contribution banner, ensuring it reflects your contributions across repositories efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yashksaini-coder/GitBanner">https://github.com/yashksaini-coder/GitBanner</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gitbanner-profile-card">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action creates an open-source contribution banner based on contributions made to other people&rsquo;s repositories, measuring and displaying stats such as merged PRs, reviews given, projects contributed to, and issues resolved. It supports both SVG and PNG formats and can be configured with various options like theme, format, output path, and tile rendering. The action automates the process of updating a GitHub profile README with this contribution banner, ensuring it reflects your contributions across repositories efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at d2c0bb1d8c99ea9b1b0f8e884cf5990e9a05268a -->
<p><strong>Full Changelog</strong>: <a href="https://github.com/yashksaini-coder/GitBanner/compare/v1.2.0...v1.2.1">https://github.com/yashksaini-coder/GitBanner/compare/v1.2.0...v1.2.1</a></p>
]]></content:encoded></item><item><title>npm-audit-fix action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/npm-audit-fix-action/</link><pubDate>Wed, 12 Aug 2026 14:36:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/npm-audit-fix-action/</guid><description>Version updated for https://github.com/ybiquitous/npm-audit-fix-action to version v8.0.0.
This action is used across all versions by 84 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of running npm audit fix and creating a pull request to fix security vulnerabilities in Node.js projects. It helps maintain secure dependencies and enhances project stability by addressing potential issues found during an audit. The action is configured through YAML files and supports various inputs for customization, such as branch creation, commit message, labels, assignees, and npm arguments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ybiquitous/npm-audit-fix-action">https://github.com/ybiquitous/npm-audit-fix-action</a></strong> to version <strong>v8.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>84</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/npm-audit-fix-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of running <code>npm audit fix</code> and creating a pull request to fix security vulnerabilities in Node.js projects. It helps maintain secure dependencies and enhances project stability by addressing potential issues found during an audit. The action is configured through YAML files and supports various inputs for customization, such as branch creation, commit message, labels, assignees, and npm arguments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>See the <a href="https://github.com/ybiquitous/npm-audit-fix-action/blob/v8.0.0/CHANGELOG.md">changelog</a> for details.</p>
<p>Compare: <a href="https://github.com/ybiquitous/npm-audit-fix-action/compare/v7.3.11...v8.0.0">https://github.com/ybiquitous/npm-audit-fix-action/compare/v7.3.11...v8.0.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/b.ia-accessibility-checker/</link><pubDate>Wed, 12 Aug 2026 14:36:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows companies to define an audience and the percentage of WCAG guidelines they must meet, ensuring their code complies with accessibility standards before acceptance into production. This tool streamlines the process by using AI to analyze guidelines more effectively than manual methods, helping teams focus on improving specific audiences’ accessibility needs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows companies to define an audience and the percentage of WCAG guidelines they must meet, ensuring their code complies with accessibility standards before acceptance into production. This tool streamlines the process by using AI to analyze guidelines more effectively than manual methods, helping teams focus on improving specific audiences&rsquo; accessibility needs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>Zuke Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/zuke-build/</link><pubDate>Wed, 12 Aug 2026 14:34:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/zuke-build/</guid><description>Version updated for https://github.com/zuke-build/zuke to version ai-v2.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action uses a tagged template to provide consistent, safe, and explicit ways to run process commands with sensible defaults such as throwing on failure, capturing output, and ensuring security by preventing injection attacks. It ensures that all processes are executed with default options, making it easy to maintain and use across different projects without needing to configure each call individually.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zuke-build/zuke">https://github.com/zuke-build/zuke</a></strong> to version <strong>ai-v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zuke-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action uses a tagged template to provide consistent, safe, and explicit ways to run process commands with sensible defaults such as throwing on failure, capturing output, and ensuring security by preventing injection attacks. It ensures that all processes are executed with default options, making it easy to maintain and use across different projects without needing to configure each call individually.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="200-2026-08-12"><a href="https://github.com/zuke-build/zuke/compare/ai-v1.8.1...ai-v2.0.0">2.0.0</a> (2026-08-12)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<blockquote>
<p><strong>Note</strong>: the v2 API is source-compatible with 1.x — no code changes are required to upgrade. The major version marks the new review model: conventions-aware, adversarially verified, discussion-driven review with an injection-hardened comment channel, replacing the per-push diff score.</p>
</blockquote>
<ul>
<li><strong>ai:</strong> discussion-driven review with adversarial verify and deeper context (<a href="https://github.com/zuke-build/zuke/issues/334">#334</a>)</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li><strong>ai:</strong> discussion-driven review with adversarial verify and deeper context (<a href="https://github.com/zuke-build/zuke/issues/334">#334</a>) (<a href="https://github.com/zuke-build/zuke/commit/3002b69831f8df2cdf8805cf7f8e6dcfadbda3f8">3002b69</a>)</li>
</ul>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/raviqqe/muffy/</link><pubDate>Wed, 12 Aug 2026 06:01:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.4.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a static website validator that performs recursive link checking, markup validation of HTML, SVG, and MathML documents, checks multiple websites with a single configuration file, supports persistent response caching, concurrency, rate limits, retries, robots.txt, and sitemap support. It can be installed via Cargo and used to check websites or as part of GitHub Actions workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.4.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a static website validator that performs recursive link checking, markup validation of HTML, SVG, and MathML documents, checks multiple websites with a single configuration file, supports persistent response caching, concurrency, rate limits, retries, <code>robots.txt</code>, and sitemap support. It can be installed via Cargo and used to check websites or as part of GitHub Actions workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>791242ccf6e8590c0f71549709521986e2ca67f8 Bump version (#1245)</li>
<li>4c67d05c6c99255a4bbd1fe3042b7163863563f4 Handle empty namespaces (#1235)</li>
<li>404042efb53b987ef9f9120d45efd4f9fec2df2d Bump async-trait from 0.1.91 to 0.1.92 (#1244)</li>
<li>db204770c98b902ff89adc804ff831e506c5b597 Refactor name class members (#1243)</li>
<li>f58d6af756b278801dae71a85fff0127715a81fa Bump @types/node from 26.1.2 to 26.2.0 in /doc (#1238)</li>
<li>33bdcb33c78b62acbd60eee9e844a42c14a82bbe Bump swatinem/rust-cache from 2.9.1 to 2.9.2 in /.github/actions/setup (#1242)</li>
<li>d28d3c191a6ae0b301292813aee3c0c05147f411 Bump codspeedhq/action from 5.0.2 to 5.0.3 (#1241)</li>
<li>abda60558362e69eed403cb064815935e39dea91 Bump homebrew/actions/setup-homebrew from 2026.08.03.2 to 2026.08.10.1 (#1240)</li>
<li>b259455bcafae43b0b1f03f50689770bcafa1473 Bump vendor/validator from <code>1fd9e8b</code> to <code>1cf9f1b</code> (#1239)</li>
<li>6fbafe906a9e8a4a5434ad90fc7a5b35d4d2e7bd Bump clap from 4.6.5 to 4.6.6 (#1236)</li>
<li>16d34c4772e04d46740eb1a0f96d68e59dc99660 Bump the astro group in /doc with 2 updates (#1237)</li>
<li>45d656c31f9a8c7060e84e54c15218582b7fef9b Fix duplicate elements on SVG validation (#1229)</li>
<li>8ad1593f1734a4f9f7d3fe761b2f3ad929d36dbe Bump pnpm/action-setup from 6.0.9 to 6.0.10 in /.github/actions/setup-document (#1234)</li>
<li>7d3c53f0b05498bbb12ceb3a7e7735c226fe9354 Bump @biomejs/biome from 2.5.6 to 2.5.7 in /doc (#1231)</li>
<li>a5972daaed5a0ad1fb33870b372c6a3e83f76984 Bump homebrew/actions/setup-homebrew from 2026.08.03.1 to 2026.08.03.2 (#1233)</li>
<li>e1a3701288f1ef50d19c17e9068ca0c054622a73 Bump vendor/validator from <code>372674c</code> to <code>1fd9e8b</code> (#1232)</li>
<li>9a1efcb5014831b9c0418a853f73aeb1bb723f90 Add TODO comment on attribute repetition semantics (#1230)</li>
<li>1585e1477c4bfc82f308d40eaa8164938a459401 Fix double <code>lang</code> attributes (#1228)</li>
<li>0972cf23ef0530b19f42bd39d035bd82cf5ed525 Fix <code>xml:id</code> match (#1227)</li>
<li>b3fa2973142b02688cd52606398dd7da5063d723 Check root element in SVG (#1226)</li>
<li>57d490d55eb8217c9156ad89eeec61c89af09358 Link stale-while-revalidate semantics (#1225)</li>
</ul>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/remyx-outrider/</link><pubDate>Wed, 12 Aug 2026 06:00:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.51.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Outrider GitHub Action: Automates the creation of draft pull requests (PRs) with detailed implementation notes and evidence of compliance. The action supports various trigger patterns such as alerts, search queries, pinned papers, or design briefs, ensuring that each PR is reviewed thoroughly by automatically generating a self-review section and checking for references cited, license flags, tests, convention alignment, and scope discipline. The action uses multiple backends like Anthropic Opus and z.ai GLM-5.2 to optimize the recommendation process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.51</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Outrider GitHub Action</strong>: Automates the creation of draft pull requests (PRs) with detailed implementation notes and evidence of compliance. The action supports various trigger patterns such as alerts, search queries, pinned papers, or design briefs, ensuring that each PR is reviewed thoroughly by automatically generating a self-review section and checking for references cited, license flags, tests, convention alignment, and scope discipline. The action uses multiple backends like Anthropic Opus and z.ai GLM-5.2 to optimize the recommendation process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Harden the agent runtime against prompt injection and GitHub-token leakage.</p>
<ul>
<li>Capability cut: PreToolUse Bash deny-gate for the spawned agent (package installs, network egress, <code>gh</code> writes, <code>git push</code>).</li>
<li>Risky-surface signal: route-to-human flag (draft + label + PR note) on dependency-manifest / CI / hook / Dockerfile / <code>*.sh</code> diffs.</li>
<li>Token handling: token-less clone config, ephemeral push (no <code>set-url</code> persistence), <code>GITHUB_TOKEN</code> withheld from the agent, fail-closed pre-push credential scan.</li>
<li>Pre-install target deps before the agent runs (CI / <code>INPUT_PREINSTALL</code>).</li>
</ul>
<p>Full changelog: #119</p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/kaniko-build-action/</link><pubDate>Wed, 12 Aug 2026 05:59:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints a greeting message to the log, either “Hello World” or “Hello [person’s name]”, and provides the current time. It is useful for automating the process of greeting users in automated workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints a greeting message to the log, either &ldquo;Hello World&rdquo; or &ldquo;Hello [person&rsquo;s name]&rdquo;, and provides the current time. It is useful for automating the process of greeting users in automated workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/rumdl-action/</link><pubDate>Wed, 12 Aug 2026 05:59:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.54.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The rumdl action is a high-performance Rust-based Markdown linter and formatter that provides fast linting, extensive rule coverage, automatic formatting with --fix, and support for multiple markdown flavors. It’s designed to be zero-dependency and highly configurable, making it suitable for use in various environments including Rust, Python, npm, pip, uv, mise, Nix, Termux User Repository, and pacman.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.54</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The rumdl action is a high-performance Rust-based Markdown linter and formatter that provides fast linting, extensive rule coverage, automatic formatting with <code>--fix</code>, and support for multiple markdown flavors. It&rsquo;s designed to be zero-dependency and highly configurable, making it suitable for use in various environments including Rust, Python, npm, pip, uv, mise, Nix, Termux User Repository, and pacman.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>action</strong>: add a command input to run rumdl fmt (<a href="https://github.com/rvben/rumdl/commit/9b59bffc64f1038ce99c6645fa12fa6247673240">9b59bff</a>)</li>
<li><strong>action</strong>: add install-only input to skip linting (<a href="https://github.com/rvben/rumdl/commit/aa0c6048af8bf798dd6102d78fc95383a9069047">aa0c604</a>)</li>
<li><strong>MD010</strong>: add ignore-code-languages to exempt fence languages from tab checks (<a href="https://github.com/rvben/rumdl/commit/21b56d038ace5943370aa628d6cf088263c5abdf">21b56d0</a>)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>config</strong>: honor the markdown attribute on every block-level element (<a href="https://github.com/rvben/rumdl/commit/6f88d71c1bd0a06230da193a848c17f5763fde5f">6f88d71</a>)</li>
<li><strong>links</strong>: stop parsing reference links and images inside HTML blocks (<a href="https://github.com/rvben/rumdl/commit/8829f6b722c67a45a6c8f207e56473c9b8913f9d">8829f6b</a>)</li>
<li><strong>html-blocks</strong>: keep a nested raw-text element from opening its own block (<a href="https://github.com/rvben/rumdl/commit/27d96bbf978a53fddc93ca1519da48e8df97fb7c">27d96bb</a>)</li>
<li><strong>code-block-tools</strong>: stop a linter in a format slot from overwriting the block (<a href="https://github.com/rvben/rumdl/commit/a40d7daac542db2a5db83c065e43e54b0b6d6991">a40d7da</a>)</li>
<li><strong>code-block-tools</strong>: report findings at the line they belong to (<a href="https://github.com/rvben/rumdl/commit/31cc6cba6e82091cf2dbd161f3c621feb98a606e">31cc6cb</a>)</li>
<li><strong>code-block-tools</strong>: bound a hanging tool by its timeout and stop respawning it (<a href="https://github.com/rvben/rumdl/commit/6ce8a1d214a6749bfec5cd0fa07228a30a9b373e">6ce8a1d</a>)</li>
<li><strong>action</strong>: add rumdl to PATH so later workflow steps can call it (<a href="https://github.com/rvben/rumdl/commit/98baf602371b04281e2280f90fe0bb4f5e8fd068">98baf60</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.54-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.54-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.54-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.54-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-x86_64-apple-darwin.tar.gz">rumdl-v0.2.54-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-aarch64-apple-darwin.tar.gz">rumdl-v0.2.54-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-x86_64-pc-windows-msvc.zip">rumdl-v0.2.54-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.54/rumdl-v0.2.54-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>PR Is All You Need</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/pr-is-all-you-need/</link><pubDate>Wed, 12 Aug 2026 05:58:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/pr-is-all-you-need/</guid><description>Version updated for https://github.com/sandys/pr-is-all-you-need to version v1.0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically manages multiple pull requests per active branch, enabling AI code review tools to process direct commits to private branches without the need for manual intervention or additional tokens. It keeps draft PRs open as surfaces for review and retires them when branches are merged, deleted, or become inactive. The action uses a single GITHUB_TOKEN for all operations and has no secrets or configuration required.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sandys/pr-is-all-you-need">https://github.com/sandys/pr-is-all-you-need</a></strong> to version <strong>v1.0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-is-all-you-need">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically manages multiple pull requests per active branch, enabling AI code review tools to process direct commits to private branches without the need for manual intervention or additional tokens. It keeps draft PRs open as surfaces for review and retires them when branches are merged, deleted, or become inactive. The action uses a single <code>GITHUB_TOKEN</code> for all operations and has no secrets or configuration required.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sandys/pr-is-all-you-need/compare/v1.0.0.0...v1.0.0.1">https://github.com/sandys/pr-is-all-you-need/compare/v1.0.0.0...v1.0.0.1</a></p>
]]></content:encoded></item><item><title>sarif-kit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sarif-kit/</link><pubDate>Wed, 12 Aug 2026 05:57:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sarif-kit/</guid><description>Version updated for https://github.com/sarif-kit/sarif-kit to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The sarif-kit GitHub Action converts output from various static analysis tools into valid SARIF 2.1.0 format suitable for GitHub Code Scanning, which requires this specific format for input. It supports linting tools like yamllint and pip-audit, translating their native output into SARIF reports that GitHub can understand, ensuring consistent error reporting across different scanning engines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sarif-kit/sarif-kit">https://github.com/sarif-kit/sarif-kit</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sarif-kit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The sarif-kit GitHub Action converts output from various static analysis tools into valid SARIF 2.1.0 format suitable for GitHub Code Scanning, which requires this specific format for input. It supports linting tools like yamllint and pip-audit, translating their native output into SARIF reports that GitHub can understand, ensuring consistent error reporting across different scanning engines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v030-2026-08-11">v0.3.0 (2026-08-11)</h2>
<p><em>This release is published under the Apache-2.0 License.</em></p>
<h3 id="documentation">Documentation</h3>
<ul>
<li>
<p>Drop the stale status counts (<a href="https://github.com/sarif-kit/sarif-kit/commit/0f8dcb671cc906230de9126bdb01e88fdb20f983"><code>0f8dcb6</code></a>)</p>
</li>
<li>
<p>Mkdocs site on github pages (<a href="https://github.com/sarif-kit/sarif-kit/commit/8336445eaa0475fc267e433a42cfcc48636e2c5d"><code>8336445</code></a>)</p>
</li>
<li>
<p>Platformio alert screenshot (<a href="https://github.com/sarif-kit/sarif-kit/commit/4344870fb99721cdf8b653b0a8f40b3a50a4d4e1"><code>4344870</code></a>)</p>
</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li>Pylint adapter (<a href="https://github.com/sarif-kit/sarif-kit/commit/74d28972e1607cabd656c5e94e8475770075dcef"><code>74d2897</code></a>)</li>
</ul>
<hr>
<p><strong>Detailed Changes</strong>: <a href="https://github.com/sarif-kit/sarif-kit/compare/v0.2.0...v0.3.0">v0.2.0&hellip;v0.3.0</a></p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/agentauditkit-mcp-security-scan/</link><pubDate>Wed, 12 Aug 2026 05:55:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.73.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: AgentAuditKit is a security scanner designed to scan AI agent pipelines for misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows. It runs fully offline and deterministically, ensuring consistent findings across different runs. The action provides auditor-ready compliance-evidence packs in SARIF format and PDF reports, covering 12 security frameworks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.73</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong>
AgentAuditKit is a security scanner designed to scan AI agent pipelines for misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows. It runs fully offline and deterministically, ensuring consistent findings across different runs. The action provides auditor-ready compliance-evidence packs in SARIF format and PDF reports, covering 12 security frameworks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.73
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.73
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.73</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Composition-aware capability union, and honest limits on per-skill scanning by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/567">https://github.com/sattyamjjain/agent-audit-kit/pull/567</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.72...v0.3.73">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.72...v0.3.73</a></p>
]]></content:encoded></item><item><title>Xipher Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/xipher-action/</link><pubDate>Wed, 12 Aug 2026 05:54:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/xipher-action/</guid><description>Version updated for https://github.com/shibme/xipher to version v1.32.3.
This action is used across all versions by 15 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Xipher is a versatile cryptographic tool that provides key/password-based asymmetric encryption with optional post-quantum security. It simplifies the sharing of encrypted data between parties over insecure channels using password-derived public keys, offering a secure and efficient solution for both small and large data. The action automates tasks such as encryption, decryption, and streaming, making it easy to integrate into various workflows and applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shibme/xipher">https://github.com/shibme/xipher</a></strong> to version <strong>v1.32.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>15</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xipher-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Xipher is a versatile cryptographic tool that provides key/password-based asymmetric encryption with optional post-quantum security. It simplifies the sharing of encrypted data between parties over insecure channels using password-derived public keys, offering a secure and efficient solution for both small and large data. The action automates tasks such as encryption, decryption, and streaming, making it easy to integrate into various workflows and applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>8dd1cfbfb1b1c6d315415b528819907d85d3e04d bump deps</li>
<li>39ac53c63732b78822a59363a795fea562df20fa fix(xcp): give every block its own nonce instead of reusing one across a whole message</li>
<li>2042aa95a65c55fcf9aa3be2a184fc9a4d6fbb08 implicit trust for same-origin provider</li>
</ul>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/smyklot/</link><pubDate>Wed, 12 Aug 2026 05:53:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.22.1.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository’s CODEOWNERS file. It supports multiple command formats, allows for flexibility in merge methods, and provides emoji feedback to users. The action also handles reaction-based commands and ensures approval deduplication.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.22.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository&rsquo;s CODEOWNERS file. It supports multiple command formats, allows for flexibility in merge methods, and provides emoji feedback to users. The action also handles reaction-based commands and ensures approval deduplication.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1221-2026-08-11"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.22.0...v1.22.1">1.22.1</a> (2026-08-11)</h2>
<h2 id="smyklot-v1221">Smyklot v1.22.1</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.22.1</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>498d95c1fbad747aa1b4e324d0508e2e73c9bf3d chore(release): bump version to 1.22.1</li>
<li>e0963ed025cbbac7f6c9fc12a4b2167a53588aad fix(panel): unhijack table scrolling and unclip tooltips (#188)</li>
</ul>
]]></content:encoded></item><item><title>Ward - Pre-Agent Metadata Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/ward-pre-agent-metadata-scanner/</link><pubDate>Wed, 12 Aug 2026 05:52:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/ward-pre-agent-metadata-scanner/</guid><description>Version updated for https://github.com/Sonofg0tham/ward to version v0.3.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Ward is a pre-agent metadata scanner designed to detect and prevent prompt injection attacks. It screens AI agent inputs before they reach security tools like SAST or IaC scanners, catching attempts to inject malicious prompts into branch names, commit messages, PR titles, and file names. Ward uses benchmarks to measure its effectiveness in catching prompt injection attempts across different corpora.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Sonofg0tham/ward">https://github.com/Sonofg0tham/ward</a></strong> to version <strong>v0.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ward-pre-agent-metadata-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Ward is a pre-agent metadata scanner designed to detect and prevent prompt injection attacks. It screens AI agent inputs before they reach security tools like SAST or IaC scanners, catching attempts to inject malicious prompts into branch names, commit messages, PR titles, and file names. Ward uses benchmarks to measure its effectiveness in catching prompt injection attempts across different corpora.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release 0.3.2: pin the build, which broke the 0.3.1 upload by @Sonofg0tham in <a href="https://github.com/Sonofg0tham/ward/pull/18">https://github.com/Sonofg0tham/ward/pull/18</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Sonofg0tham/ward/compare/v0.3.1...v0.3.2">https://github.com/Sonofg0tham/ward/compare/v0.3.1...v0.3.2</a></p>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/update-a-config-file-with-values-from-environment/</link><pubDate>Wed, 12 Aug 2026 05:51:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces placeholders with environment variable values in a specified configuration file. It automates the process of updating environment-specific settings without manual intervention, ensuring consistency across different environments.
What’s Changed feat: Initial version (e440a96)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces placeholders with environment variable values in a specified configuration file. It automates the process of updating environment-specific settings without manual intervention, ensuring consistency across different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/ssg-static-site-generator/</link><pubDate>Wed, 12 Aug 2026 05:51:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.26.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a static site generator written in Go that converts Markdown files with YAML frontmatter into a complete website, including features like templates, feeds, and SEO metadata. It automates the process of building websites quickly and efficiently, especially suitable for blogs, documentation, and company sites. The action simplifies the setup and maintenance of web projects by providing a fast, deterministic build system that handles content rendering and deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.26</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a static site generator written in Go that converts Markdown files with YAML frontmatter into a complete website, including features like templates, feeds, and SEO metadata. It automates the process of building websites quickly and efficiently, especially suitable for blogs, documentation, and company sites. The action simplifies the setup and maintenance of web projects by providing a fast, deterministic build system that handles content rendering and deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.26 — fixes for #114–#118 (WordPress migration + theme-authoring) by @spagu in <a href="https://github.com/spagu/ssg/pull/119">https://github.com/spagu/ssg/pull/119</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.25...v1.8.26">https://github.com/spagu/ssg/compare/v1.8.25...v1.8.26</a></p>
]]></content:encoded></item><item><title>Spare Parts Changelog</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/spare-parts-changelog/</link><pubDate>Wed, 12 Aug 2026 05:49:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/spare-parts-changelog/</guid><description>Version updated for https://github.com/sparepartslabs/spareparts-changelog to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates AI-written Markdown end-user change logs from Conventional Commits. It updates the CHANGELOG.md file in the working tree without committing or pushing changes. The action supports S3 and LinkedIn publishing options and has a user-facing types whitelist initially including feat, fix, perf, security, deprecate, and remove.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sparepartslabs/spareparts-changelog">https://github.com/sparepartslabs/spareparts-changelog</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spare-parts-changelog">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates AI-written Markdown end-user change logs from Conventional Commits. It updates the <code>CHANGELOG.md</code> file in the working tree without committing or pushing changes. The action supports S3 and LinkedIn publishing options and has a user-facing types whitelist initially including <code>feat</code>, <code>fix</code>, <code>perf</code>, <code>security</code>, <code>deprecate</code>, and <code>remove</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: bump @vercel/ncc from 0.38.4 to 0.44.1 in the development group by @dependabot[bot] in <a href="https://github.com/sparepartslabs/spareparts-changelog/pull/7">https://github.com/sparepartslabs/spareparts-changelog/pull/7</a></li>
<li>feat: add AI-generated public changelogs by @ike4est in <a href="https://github.com/sparepartslabs/spareparts-changelog/pull/8">https://github.com/sparepartslabs/spareparts-changelog/pull/8</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/sparepartslabs/spareparts-changelog/pull/7">https://github.com/sparepartslabs/spareparts-changelog/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sparepartslabs/spareparts-changelog/compare/v0.1.0...v0.2.0">https://github.com/sparepartslabs/spareparts-changelog/compare/v0.1.0...v0.2.0</a></p>
]]></content:encoded></item><item><title>Spare Parts LGTM</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/spare-parts-lgtm/</link><pubDate>Wed, 12 Aug 2026 05:49:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/spare-parts-lgtm/</guid><description>Version updated for https://github.com/sparepartslabs/spareparts-lgtm to version v1.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary LGTM is a GitHub Action that automates code review tasks by asking reviewers questions about changes in pull requests. It solves the problem of ensuring that reviewers have thoroughly read and understood the changes before approving them, promoting more thorough reviews and reducing misunderstandings. The action uses Claude, Codex, Cursor, GitHub Copilot, Gemini, or OpenCode as agents to generate questions based on the diff and reports the result as a check run. It ensures that code review decisions are informed by actual reading of the changes rather than just approvals.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sparepartslabs/spareparts-lgtm">https://github.com/sparepartslabs/spareparts-lgtm</a></strong> to version <strong>v1.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spare-parts-lgtm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>LGTM is a GitHub Action that automates code review tasks by asking reviewers questions about changes in pull requests. It solves the problem of ensuring that reviewers have thoroughly read and understood the changes before approving them, promoting more thorough reviews and reducing misunderstandings. The action uses Claude, Codex, Cursor, GitHub Copilot, Gemini, or OpenCode as agents to generate questions based on the diff and reports the result as a check run. It ensures that code review decisions are informed by actual reading of the changes rather than just approvals.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- spareparts-changelog:start:aca87a753ec66872 -->
<h2 id="v131">v1.3.1</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Changelog entries are now published under the canonical changelog prefix.</li>
</ul>
<!-- spareparts-changelog:end:aca87a753ec66872 -->
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/spek-openspec-static-site/</link><pubDate>Wed, 12 Aug 2026 05:48:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.13.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary spek is a lightweight, read-only viewer for OpenSpec content. It automates the process of browsing, searching, and tracking BDD tasks within a local directory structure, providing a structured interface with features like BDD syntax highlighting, task progress tracking, and full-text search.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.13.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>spek is a lightweight, read-only viewer for OpenSpec content. It automates the process of browsing, searching, and tracking BDD tasks within a local directory structure, providing a structured interface with features like BDD syntax highlighting, task progress tracking, and full-text search.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Highlight: the rule beside an open section now starts and ends where its content does.</strong> 1.13.0 gave each requirement its own rule and a gap between them, but the rule was drawn down the section&rsquo;s <em>box</em> — and a box holds two spaces its content does not. Reported from the IntelliJ tool window (issue #42), one round after the change that introduced the gap.</p>
<ul>
<li><strong>The rule starts at its heading, not 20px above it.</strong> That space is also what separates a section from the one before it, so of the 28px between two requirements, 20px was drawn as rule — 1.13.0&rsquo;s gap was real but invisible, and a page of requirements still read as one interrupted line with a notch in it</li>
<li><strong>And it ends at the last of its content</strong>, instead of running past it. The trailing space below a section&rsquo;s last paragraph sits inside the box too, so the rule overshot the thing it was marking by a further 20px — plainest under the last scenario of a requirement</li>
<li><strong>An open requirement&rsquo;s heading no longer sits 1px right of a closed one&rsquo;s.</strong> The rule used to be a border, which inset everything inside an open section; drawn as its own element it does not. Headings and disclosure arrows now line up down the page regardless of open state</li>
<li><strong>The rule stays visible in Windows high contrast</strong>, where the previous drawing method would have been discarded</li>
<li>A scenario written with no requirement above it now takes a top-level section&rsquo;s spacing, 4px lower than before: how much room a section leaves above its heading follows its nesting, not its heading level</li>
</ul>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/runward-gate/</link><pubDate>Wed, 12 Aug 2026 05:47:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.33.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward automates the verification of engineering decisions behind AI-generated code, ensuring that critical aspects of software delivery are adhered to. It provides a deterministic gate to check that the process was followed, making it easier to verify compliance with standards like ISO 42001 and NIST AI RMF.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.33.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Runward automates the verification of engineering decisions behind AI-generated code, ensuring that critical aspects of software delivery are adhered to. It provides a deterministic gate to check that the process was followed, making it easier to verify compliance with standards like ISO 42001 and NIST AI RMF.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>No verdict changes. The canary for <a href="https://github.com/stranxik/runward/blob/main/docs/adr/ADR-0049-the-build-is-isolated-from-the-publish.md">ADR-0049</a>: the first release whose provenance is signed by the isolated builder.</strong></p>
<p>The tarball is built, tested and its provenance signed inside <code>build-and-attest.yml</code>, a reusable workflow whose steps <code>release.yml</code> cannot reach into; the signing certificate names that file. The publish job packs the same commit itself and <strong>refuses to publish</strong> a builder tarball that does not byte-match. <code>npm publish</code> stays under OIDC trusted publishing, unchanged.</p>
<p>What this release must establish, written before the tag:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>gh attestation verify runward-0.33.5.tgz --repo stranxik/runward <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --signer-workflow stranxik/runward/.github/workflows/build-and-attest.yml
</span></span></code></pre></div><p>passing on the published artifact; the determinism cross-check holding; a local rebuild of the attested commit reconciling byte for byte. <code>verify-release.yml</code> requires the signer identity on this run — the outcome is loud in both directions.</p>
<p>No SLSA level is asserted anywhere. Verification procedure: <a href="https://github.com/stranxik/runward/blob/main/docs/verifying-a-release.md">docs/verifying-a-release.md</a>.</p>
<p><strong>Full changelog</strong>: <a href="https://github.com/stranxik/runward/blob/main/CHANGELOG.md">https://github.com/stranxik/runward/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>SFDX Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sfdx-deploy/</link><pubDate>Wed, 12 Aug 2026 05:45:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/sfdx-deploy/</guid><description>Version updated for https://github.com/svierk/sfdx-deploy to version v1.2.2.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SFDX Deploy GitHub Action automates the deployment of Salesforce metadata to a target org, supporting source directories, manifest files, and metadata component selectors. It includes options for test levels, dry runs, and delta deployments, making it suitable for pull request validation and actual deployments to higher environments. The action also provides functionality to delete metadata deletions as post-destructive changes in delta mode.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svierk/sfdx-deploy">https://github.com/svierk/sfdx-deploy</a></strong> to version <strong>v1.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdx-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The SFDX Deploy GitHub Action automates the deployment of Salesforce metadata to a target org, supporting source directories, manifest files, and metadata component selectors. It includes options for test levels, dry runs, and delta deployments, making it suitable for pull request validation and actual deployments to higher environments. The action also provides functionality to delete metadata deletions as post-destructive changes in delta mode.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>pin action examples to exact releases and harden them</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svierk/sfdx-deploy/compare/v1.2.1...v1.2.2">https://github.com/svierk/sfdx-deploy/compare/v1.2.1...v1.2.2</a></p>
]]></content:encoded></item><item><title>ThreatFlux Jira Automation</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/threatflux-jira-automation/</link><pubDate>Wed, 12 Aug 2026 05:44:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/threatflux-jira-automation/</guid><description>Version updated for https://github.com/ThreatFlux/threatflux-atlassian to version v0.5.1.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the integration of Atlassian Jira Cloud with various tasks, such as retrieving issues, creating and updating them, managing comments and attachments, and triggering workflow transitions. It uses a Rust SDK to interact with the Jira REST API v2, providing a reusable solution for developers looking to build integrations or operators for Jira Cloud operations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ThreatFlux/threatflux-atlassian">https://github.com/ThreatFlux/threatflux-atlassian</a></strong> to version <strong>v0.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/threatflux-jira-automation">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the integration of Atlassian Jira Cloud with various tasks, such as retrieving issues, creating and updating them, managing comments and attachments, and triggering workflow transitions. It uses a Rust SDK to interact with the Jira REST API v2, providing a reusable solution for developers looking to build integrations or operators for Jira Cloud operations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="release-v051">Release v0.5.1</h2>
]]></content:encoded></item><item><title>Install bashunit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/install-bashunit/</link><pubDate>Wed, 12 Aug 2026 05:43:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/install-bashunit/</guid><description>Version updated for https://github.com/TypedDevs/bashunit to version 0.46.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates testing for Bash scripts using the bashunit framework, providing a simple and fast way to test bash functions, assertions, spies, mocks, data providers, snapshots, and more. It supports multiple features such as equality checks, string comparisons, exit codes, numeric assertions, array operations, file permissions, JSON parsing, date comparisons, duration measurements, snapshot matching, and test double verification.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TypedDevs/bashunit">https://github.com/TypedDevs/bashunit</a></strong> to version <strong>0.46.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-bashunit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates testing for Bash scripts using the <code>bashunit</code> framework, providing a simple and fast way to test bash functions, assertions, spies, mocks, data providers, snapshots, and more. It supports multiple features such as equality checks, string comparisons, exit codes, numeric assertions, array operations, file permissions, JSON parsing, date comparisons, duration measurements, snapshot matching, and test double verification.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-improvements">✨ Improvements</h2>
<ul>
<li><code>--changed [&lt;ref&gt;]</code> runs only the test files git reports as touched since <code>&lt;ref&gt;</code> (default <code>origin/HEAD</code>, then <code>HEAD</code>), covering committed, staged, unstaged and untracked changes (#1010)</li>
<li><code>--order-by &lt;defined|defects|random&gt;</code> picks the execution order; <code>defects</code> runs the last run&rsquo;s failures first and still runs the whole suite (#1011)</li>
<li><code>--list</code> (alias <code>--dry-run</code>) prints the tests a run would execute without running them; <code>--list-format json</code> emits file, function, name, line and tags, honouring every selection flag including <code>--shard</code> (#1007)</li>
<li><code>--exclude-filter &lt;name&gt;</code> skips tests by name, the counterpart of <code>--exclude-tag</code>: repeatable, OR&rsquo;d, and wins over <code>--filter</code> (#1009)</li>
<li><code>--tag</code> accepts expressions: <code>'a&amp;&amp;b'</code> (AND), <code>'!a'</code> (NOT) and <code>'a&amp;&amp;!b'</code>; repeated <code>--tag</code> flags keep OR semantics and <code>--exclude-tag</code> still wins (#1008)</li>
<li><code># @tags a b</code> above any top-level line tags every test in the file, unioned with per-function <code># @tag</code> (#1008)</li>
<li><code>--repeat &lt;n&gt;</code> runs each selected test n times to hunt flakiness before CI does: one report line with the aggregate outcome, a failure names its iteration, and repeat wraps <code>--retry</code> (#1013)</li>
<li>Flaky is a first-class outcome: a test that only passed after a retry is counted separately, stays inside the pass total so the exit code is unchanged, and is carried into JUnit (<code>&lt;flakyFailure&gt;</code>), TAP, JSON, HTML and GitHub Actions with the first attempt&rsquo;s failure message; <code>--fail-on-flaky</code> turns such a run red (#1012)</li>
<li><code>--coverage-report-cobertura [file]</code> writes Cobertura XML (default <code>coverage/cobertura.xml</code>), the format GitLab merge-request visualisation, Azure DevOps and Jenkins consume, with repo-relative filenames, per-line hits and <code>condition-coverage</code> on branch lines, alongside the LCOV and HTML reports (#1017)</li>
<li><code>--coverage-diff &lt;ref&gt;</code> limits the coverage console report to lines changed since a base ref; <code>--coverage-min</code> then gates on that diff percentage (#1032)</li>
<li><code>--report-md &lt;file&gt;</code> writes a Markdown run summary — verdict, counts table, failures with their message, plus coverage and slowest tests when those ran — and inside GitHub Actions appends it to <code>$GITHUB_STEP_SUMMARY</code> (#1015)</li>
<li>GitHub Actions annotations print to stdout automatically inside Actions, carrying the failing test&rsquo;s file and line so they land on the right line of the diff; <code>--gha-annotations &lt;auto|always|never&gt;</code> overrides the detection and <code>action.yml</code> gains an <code>annotations</code> input (#1014)</li>
<li><code>assert_between &lt;min&gt; &lt;max&gt; &lt;actual&gt;</code> and <code>assert_not_between</code> add inclusive numeric-range assertions for integers and decimals (#1026)</li>
<li><code>assert_command_available &lt;command&gt;</code> asserts a command, shell builtin or function resolves through <code>command -v</code> (#1027)</li>
<li><code>--verbose</code> reports the coverage engine in use, and an explicit <code>BASHUNIT_COVERAGE_ENGINE=xtrace</code> the running Bash cannot honour now warns instead of being silently ignored (#1005)</li>
</ul>
<h2 id="-changes">🛠️ Changes</h2>
<ul>
<li>JUnit XML: one <code>&lt;testsuite&gt;</code> per test file with its own counts, time and timestamp instead of a single flat suite, <code>classname</code> on every <code>&lt;testcase&gt;</code>, <code>&lt;failure message=&quot;...&quot;&gt;</code> carrying the first informative line of the real message with <code>type=&quot;AssertionFailed&quot;</code>, <code>&lt;system-out&gt;</code> with the test&rsquo;s captured output, and aggregate totals on <code>&lt;testsuites&gt;</code>, so consumers that group by suite or classname (Jenkins, GitLab, dorny/test-reporter) get real groupings (#1016)</li>
<li>Performance: <code>--coverage</code> is about 1.6x to 2.3x faster; executable-line classification no longer forks <code>grep</code> per source line, roughly half of a coverage run&rsquo;s wall time on both engines (#1005)</li>
<li><code>bashunit test --help</code> lists <code>--show-skipped</code> and <code>--show-incomplete</code>, both accepted by the parser but never advertised; <code>BASHUNIT_COVERAGE_SHOW_FUNCTIONS</code> and <code>BASHUNIT_COVERAGE_SHOW_UNCOVERED</code> are registered in <code>src/config/env.sh</code> like every other setting, and <code>.env.example</code> now lists all 66 settings, 19 of which were missing (#1063)</li>
<li>Docs: full audit of the reference pages against the code — <code>docs/configuration.md</code> gained the 17 settings it never documented, <code>docs/command-line.md</code> gained the <code>assert</code> subcommand section and real example output, and the coverage settings and diff-coverage narrative now live in one place instead of two that had drifted (#1063)</li>
</ul>
<h2 id="-bug-fixes">🐛 Bug Fixes</h2>
<ul>
<li>Report formats are no longer empty under <code>--parallel</code>; <code>--report-junit</code>, <code>--report-tap</code>, <code>--report-json</code>, <code>--report-html</code> and <code>--log-junit</code> all recorded zero tests, because the rows were collected inside the per-test worker and nothing rebuilt them in the parent (#1004)</li>
<li>A failed assertion is no longer reported twice: <code>bashunit::assert_that</code> returns 1 on failure by design, so a custom assertion ending with it made the test body exit non-zero and the runner printed a spurious <code>✗ Error</code> on top of the <code>✗ Failed</code>. Custom assertions no longer need a trailing <code>return 0</code>, and a real runtime error is still reported as an error (#1063)</li>
<li><code>--coverage-report</code> with no value uses <code>coverage/lcov.info</code> instead of aborting the run with <code>$2: unbound variable</code>, and no longer consumes a following flag as its filename; write the test path before it, since an optional value cannot be told apart from a path (#1063)</li>
<li><code>--list --list-format json</code> reports each tag as its own array element; the emitter split the tag list on whitespace while every other consumer splits it on commas, so two tags rendered as <code>[&quot;slow,fileTag&quot;]</code> (#1063)</li>
<li><code>assert_within_delta</code> rejects malformed numbers such as <code>1.2.3</code> or <code>5-3</code> as non-numeric instead of leaking a raw <code>bc</code> parse error or evaluating them as an expression (#1026)</li>
<li>Build: the standalone binary size budget is 544 KiB, raised from 500 KiB after ordinary feature growth crossed it; the artifact keeps its indentation rather than being minified (#1045)</li>
</ul>
<h2 id="-contributors">👥 Contributors</h2>
<ul>
<li>@Chemaclass</li>
<li>@fzlzjerry</li>
<li>@w3lld1</li>
</ul>
<h2 id="checksum">Checksum</h2>
<p>SHA256: <code>c49fd3874c7df68170f6a22d76599031113f2bb8a5a3bca664fa056dc214e85f</code></p>
<p><strong>Full Changelog:</strong> <a href="https://github.com/TypedDevs/bashunit/compare/0.45.0...0.46.0">0.45.0&hellip;0.46.0</a></p>
]]></content:encoded></item><item><title>Vigilnz Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/vigilnz-security-scan/</link><pubDate>Wed, 12 Aug 2026 05:42:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/vigilnz-security-scan/</guid><description>Version updated for https://github.com/Vigilnz/vigilnz-scan-action to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Vigilnz Security Scan Action automates security scanning for applications and repositories using Vigilnz’s API. It supports multiple scan types including SCA, SBOM, SAST, IAC SCAN, SECRET SCAN, DAST, and CONTAINER SCAN. The action integrates seamlessly with GitHub workflows to help developers detect vulnerabilities during CI/CD pipelines securely and efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Vigilnz/vigilnz-scan-action">https://github.com/Vigilnz/vigilnz-scan-action</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vigilnz-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Vigilnz Security Scan Action automates security scanning for applications and repositories using Vigilnz&rsquo;s API. It supports multiple scan types including SCA, SBOM, SAST, IAC SCAN, SECRET SCAN, DAST, and CONTAINER SCAN. The action integrates seamlessly with GitHub workflows to help developers detect vulnerabilities during CI/CD pipelines securely and efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Implement CI provenance metadata collection for scan requests
Add branch resolution to scan requests for improved result grouping</p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/rustscript-action/</link><pubDate>Wed, 12 Aug 2026 05:41:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.3.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is an action that enables Rust developers to run scripts without compiling them into binaries. It provides a practical subset of the language, allowing for quick execution and validation of code snippets, with support for concurrency using Tokio. The action supports compiling scripts to native binaries for performance-critical tasks. It also caches results of compiled checks and builds for efficient reusability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.3.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is an action that enables Rust developers to run scripts without compiling them into binaries. It provides a practical subset of the language, allowing for quick execution and validation of code snippets, with support for concurrency using Tokio. The action supports compiling scripts to native binaries for performance-critical tasks. It also caches results of compiled checks and builds for efficient reusability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.3.4...v0.3.5">https://github.com/VladasZ/rustscript/compare/v0.3.4...v0.3.5</a></p>
]]></content:encoded></item><item><title>Prism Reviewer AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/prism-reviewer-ai/</link><pubDate>Wed, 12 Aug 2026 05:40:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/prism-reviewer-ai/</guid><description>Version updated for https://github.com/vyoman-labs/prism-reviewer to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Prism Reviewer is an AI-driven multi-agent code review system that automates static analysis, dependency scanning, AST-based symbol inspection, and parallel LLM-guided code evaluation. It acts as a gatekeeper for pull requests by performing targeted reviews, providing detailed reports categorized by severity.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vyoman-labs/prism-reviewer">https://github.com/vyoman-labs/prism-reviewer</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prism-reviewer-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Prism Reviewer is an AI-driven multi-agent code review system that automates static analysis, dependency scanning, AST-based symbol inspection, and parallel LLM-guided code evaluation. It acts as a gatekeeper for pull requests by performing targeted reviews, providing detailed reports categorized by severity.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v1.0.0</p>
<p>Publish to pypi</p>
<p><strong>Changelog:</strong> <a href="https://github.com/vyoman-labs/prism-reviewer/blob/main/CHANGELOG.md#100---2026-08-11">https://github.com/vyoman-labs/prism-reviewer/blob/main/CHANGELOG.md#100---2026-08-11</a></p>
]]></content:encoded></item><item><title>wcagc accessibility check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/wcagc-accessibility-check/</link><pubDate>Wed, 12 Aug 2026 05:39:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/wcagc-accessibility-check/</guid><description>Version updated for https://github.com/WCAG-Compliance/wcagc-ci to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action, wcagc CI, automates accessibility checks for GitHub and GitLab repositories using the WCAGc service. It compares current checks against a saved baseline and reports findings in PR comments or SARIF files, helping to ensure compliance with web standards while preserving manual review requirements. The action is designed to help developers catch accessibility issues early in the development process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/WCAG-Compliance/wcagc-ci">https://github.com/WCAG-Compliance/wcagc-ci</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wcagc-accessibility-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action, wcagc CI, automates accessibility checks for GitHub and GitLab repositories using the WCAGc service. It compares current checks against a saved baseline and reports findings in PR comments or SARIF files, helping to ensure compliance with web standards while preserving manual review requirements. The action is designed to help developers catch accessibility issues early in the development process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(ci): automate immutable action releases by @pcherkasov in <a href="https://github.com/WCAG-Compliance/wcagc-ci/pull/1">https://github.com/WCAG-Compliance/wcagc-ci/pull/1</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@pcherkasov made their first contribution in <a href="https://github.com/WCAG-Compliance/wcagc-ci/pull/1">https://github.com/WCAG-Compliance/wcagc-ci/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/WCAG-Compliance/wcagc-ci/compare/v1.1.0...v1.2.0">https://github.com/WCAG-Compliance/wcagc-ci/compare/v1.1.0...v1.2.0</a></p>
]]></content:encoded></item><item><title>GitBanner Profile Card</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/gitbanner-profile-card/</link><pubDate>Wed, 12 Aug 2026 05:38:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/gitbanner-profile-card/</guid><description>Version updated for https://github.com/yashksaini-coder/GitBanner to version v1.2.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates a customizable open-source contribution banner (SVG + PNG) for your GitHub profile README, measuring contributions across other repositories. It automates the process of tracking and displaying metrics like merged pull requests, reviews given, and projects contributed to, making it easy to showcase your involvement in the community without relying solely on repository stars.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yashksaini-coder/GitBanner">https://github.com/yashksaini-coder/GitBanner</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gitbanner-profile-card">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates a customizable open-source contribution banner (SVG + PNG) for your GitHub profile README, measuring contributions across other repositories. It automates the process of tracking and displaying metrics like merged pull requests, reviews given, and projects contributed to, making it easy to showcase your involvement in the community without relying solely on repository stars.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at 85c5f47b732ff73167c93bfd946bfd23e2ba2a9b -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="other-changes">Other changes</h3>
<ul>
<li>feat: add ignore-languages input to filter generated/vendored files by @yashksaini-coder in <a href="https://github.com/yashksaini-coder/GitBanner/pull/2">https://github.com/yashksaini-coder/GitBanner/pull/2</a></li>
<li>Redesign: measure external contributions instead of own-repo stats by @yashksaini-coder in <a href="https://github.com/yashksaini-coder/GitBanner/pull/3">https://github.com/yashksaini-coder/GitBanner/pull/3</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yashksaini-coder/GitBanner/compare/v1.1.0...v1.2.0">https://github.com/yashksaini-coder/GitBanner/compare/v1.1.0...v1.2.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/b.ia-accessibility-checker/</link><pubDate>Wed, 12 Aug 2026 05:36:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that integrates accessibility checks into CI/CD pipelines. It allows companies to define an audience and a percentage of guidelines to be met, using AI to analyze and measure guidelines. The action helps ensure products comply with WCAG guidelines by providing feedback on any violations, allowing developers to correct solutions efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that integrates accessibility checks into CI/CD pipelines. It allows companies to define an audience and a percentage of guidelines to be met, using AI to analyze and measure guidelines. The action helps ensure products comply with WCAG guidelines by providing feedback on any violations, allowing developers to correct solutions efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>Zuke Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/zuke-build/</link><pubDate>Wed, 12 Aug 2026 05:35:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/12/zuke-build/</guid><description>Version updated for https://github.com/zuke-build/zuke to version core-v1.38.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action allows users to execute templates as shell commands in a safe and repeatable manner, with options to throw on failure or capture output. It ensures injection safety by not using any third-party dependencies and focuses only on basic tasks needed for template execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zuke-build/zuke">https://github.com/zuke-build/zuke</a></strong> to version <strong>core-v1.38.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zuke-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action allows users to execute templates as shell commands in a safe and repeatable manner, with options to throw on failure or capture output. It ensures injection safety by not using any third-party dependencies and focuses only on basic tasks needed for template execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1381-2026-08-11"><a href="https://github.com/zuke-build/zuke/compare/core-v1.38.0...core-v1.38.1">1.38.1</a> (2026-08-11)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>core:</strong> close three trust gaps at the backend, registry and cache boundaries (<a href="https://github.com/zuke-build/zuke/issues/330">#330</a>) (<a href="https://github.com/zuke-build/zuke/commit/37fbf3469316dd5e95243d6ea7bb1cdd1b114c3b">37fbf34</a>)</li>
</ul>
]]></content:encoded></item><item><title>Acquit Test Selection</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/acquit-test-selection/</link><pubDate>Tue, 11 Aug 2026 14:38:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/acquit-test-selection/</guid><description>Version updated for https://github.com/rajeev-chaurasia/acquit to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Acquit analyzes a repository’s dependency graph and selectively skips tests that are not affected by changes in the pull request. It uses static analysis to determine which tests can be skipped, ensuring only potentially unsafe changes are included in the test suite. The action is designed to improve build times and reduce unnecessary testing in large codebases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rajeev-chaurasia/acquit">https://github.com/rajeev-chaurasia/acquit</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/acquit-test-selection">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Acquit analyzes a repository&rsquo;s dependency graph and selectively skips tests that are not affected by changes in the pull request. It uses static analysis to determine which tests can be skipped, ensuring only potentially unsafe changes are included in the test suite. The action is designed to improve build times and reduce unnecessary testing in large codebases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="011-2026-08-09"><a href="https://github.com/rajeev-chaurasia/acquit/compare/v0.1.0...v0.1.1">0.1.1</a> (2026-08-09)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>resolve the release-please merge conflict, keep v5 and the dispatch step (<a href="https://github.com/rajeev-chaurasia/acquit/commit/27a33ce7e4d5d0dd5e4511f5d788905b9cb690ad">27a33ce</a>)</li>
<li>unique Marketplace display name, the bare word collides (<a href="https://github.com/rajeev-chaurasia/acquit/commit/72d6b16633b31de9c7f31e17d09e105dc92a6b54">72d6b16</a>)</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>pin the quickstart to v0.1.0 (<a href="https://github.com/rajeev-chaurasia/acquit/commit/f3da1f0f9cacf24cd901dd6f4a8def151f16a90c">f3da1f0</a>)</li>
</ul>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/remyx-outrider/</link><pubDate>Tue, 11 Aug 2026 14:37:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.50.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Outrider is a GitHub Action designed to turn briefs into review-ready PRs by automating the process of implementing and testing code. It uses Anthropic Opus and z.ai GLM-5.2 as backend models to suggest and evaluate candidate implementations based on their relevance to a user’s research interest or other triggers like search queries or pinning specific papers. The action generates draft PRs with complete implementation details, including test cases, license information, and references cited, ensuring that the maintainer has all necessary evidence for reviewing the changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.50</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Outrider is a GitHub Action designed to turn briefs into review-ready PRs by automating the process of implementing and testing code. It uses Anthropic Opus and z.ai GLM-5.2 as backend models to suggest and evaluate candidate implementations based on their relevance to a user&rsquo;s research interest or other triggers like search queries or pinning specific papers. The action generates draft PRs with complete implementation details, including test cases, license information, and references cited, ensuring that the maintainer has all necessary evidence for reviewing the changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Two layered mitigations against indirect prompt injection through
external content Outrider ingests (Discussions, merged-PR bodies,
lead-content URLs).</p>
<p><strong>Content-source labeling</strong> — wrap external content in
<code>&lt;untrusted_content source=&quot;…&quot;&gt;</code> tags with a preamble instructing the
model NOT to treat instructions inside as directives. Applies to the
Discussions block (v1.7.49), merged-PR block, and lead-content
override sites.</p>
<p><strong>Canary-gated routing</strong> — per-run token in <code>INVOCATION.md</code> that the
coding agent must write to <code>.remyx-recommendation/SPEC_ACK.txt</code> before
finishing. Missing token downgrades PR mode to Issue and flags branch
mode as <code>branch_pushed_canary_missing</code>. Bundle dir is scrubbed before
staging, so the canary never lands in the merged diff.</p>
<p>Validated against two attack shapes on a controlled fork:</p>
<ul>
<li>Payload hidden in a collapsed <code>&lt;details&gt;</code> block → blocked</li>
<li>Payload buried mid-page in verbose corporate policy text → blocked</li>
</ul>
<p>27 new tests; full suite 1230 passed. See #117.</p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/kaniko-build-action/</link><pubDate>Tue, 11 Aug 2026 14:36:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints a greeting message to the log, either “Hello World” or “Hello [name]”, and optionally provides the current time. It automates the task of sending personalized greetings in automated workflows. The action accepts an optional input for the person’s name and outputs the current timestamp.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints a greeting message to the log, either &ldquo;Hello World&rdquo; or &ldquo;Hello [name]&rdquo;, and optionally provides the current time. It automates the task of sending personalized greetings in automated workflows. The action accepts an optional input for the person&rsquo;s name and outputs the current timestamp.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>Cryload Load Test</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/cryload-load-test/</link><pubDate>Tue, 11 Aug 2026 14:36:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/cryload-load-test/</guid><description>Version updated for https://github.com/sdogruyol/cryload to version v5.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary cryload is a modern, cross-platform HTTP load testing CLI that automates performance testing in CI/CD pipelines. It provides features like concurrent connections, latency percentiles, CI thresholds, JSON/CSV output, and supports multi-URLs, custom success codes, and rate limiting. The action allows for easy integration into GitHub Actions to validate deployment performance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sdogruyol/cryload">https://github.com/sdogruyol/cryload</a></strong> to version <strong>v5.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cryload-load-test">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>cryload is a modern, cross-platform HTTP load testing CLI that automates performance testing in CI/CD pipelines. It provides features like concurrent connections, latency percentiles, CI thresholds, JSON/CSV output, and supports multi-URLs, custom success codes, and rate limiting. The action allows for easy integration into GitHub Actions to validate deployment performance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><strong>GitHub Action</strong> — Shortened the <code>action.yml</code> description to 117 characters; GitHub Marketplace rejects listings whose description is 125 characters or longer, which blocked publishing v5.2.0</li>
</ul>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/custom-amazon-bedrock-agent-action/</link><pubDate>Tue, 11 Aug 2026 14:34:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze code files in a PR and provide feedback. It integrates with Knowledge Bases for enhanced context-aware insights and supports customizable prompts, memory, and language-agnostic analysis. The action is tailored for various use cases, including code quality improvement and performance optimizations. It seamlessly integrates with the AWS ecosystem and provides detailed, markdown-formatted comments as feedback in the PR.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze code files in a PR and provide feedback. It integrates with Knowledge Bases for enhanced context-aware insights and supports customizable prompts, memory, and language-agnostic analysis. The action is tailored for various use cases, including code quality improvement and performance optimizations. It seamlessly integrates with the AWS ecosystem and provides detailed, markdown-formatted comments as feedback in the PR.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/sherpa.sh/</link><pubDate>Tue, 11 Aug 2026 14:33:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-powered tool that automates the deployment of applications to various cloud providers. It simplifies infrastructure management by allowing users to describe their needs in plain English, and Sherpa generates and configures the necessary resources, including servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more. This makes it easier for developers to focus on writing code rather than managing complex configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-powered tool that automates the deployment of applications to various cloud providers. It simplifies infrastructure management by allowing users to describe their needs in plain English, and Sherpa generates and configures the necessary resources, including servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more. This makes it easier for developers to focus on writing code rather than managing complex configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Constellation Index</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/constellation-index/</link><pubDate>Tue, 11 Aug 2026 14:32:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/constellation-index/</guid><description>Version updated for https://github.com/ShiftinBits/constellation-github to version v1.2.3.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs the latest Constellation CLI and indexes your repository’s codebase using Tree-sitter AST analysis, ensuring AI assistants can understand your code without transmitting source code. It provides a privacy-first approach by extracting only AST metadata and offers automatic updates to the CLI version. The action supports cross-platform operation on Ubuntu, macOS, and Windows runners and includes a smart diff detection mechanism to skip indexing when no files matching the configuration have changed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ShiftinBits/constellation-github">https://github.com/ShiftinBits/constellation-github</a></strong> to version <strong>v1.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/constellation-index">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs the latest Constellation CLI and indexes your repository&rsquo;s codebase using Tree-sitter AST analysis, ensuring AI assistants can understand your code without transmitting source code. It provides a privacy-first approach by extracting only AST metadata and offers automatic updates to the CLI version. The action supports cross-platform operation on Ubuntu, macOS, and Windows runners and includes a smart diff detection mechanism to skip indexing when no files matching the configuration have changed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="whats-new">What&rsquo;s new?</h3>
<ul>
<li><strong>Incremental indexing in CI</strong>: every trigger now ensures full git history is available (self-healing shallow clones), so the CLI can compute deltas against the last indexed commit instead of falling back to a full re-index on each push — dramatically reducing index churn</li>
<li><strong>No more waiting on the server</strong>: the action now finishes as soon as the upload is accepted instead of polling until server-side indexing completes, cutting idle runner minutes; a new <code>wait</code> input (default <code>&quot;false&quot;</code>) restores the old behavior for workflows that need the completed index</li>
<li><strong>Manual runs are truly full re-indexes</strong>: <code>workflow_dispatch</code> triggers now explicitly request a full re-index, guaranteeing a clean rebuild when you click &ldquo;Run workflow&rdquo;</li>
<li>More reliable diff-checks on shallow clones — pushes that touch no tracked files can now skip indexing entirely</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ShiftinBits/constellation-github/compare/v1.2.2...v1.2.3">https://github.com/ShiftinBits/constellation-github/compare/v1.2.2...v1.2.3</a></p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/smyklot/</link><pubDate>Tue, 11 Aug 2026 14:31:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.21.2.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository’s CODEOWNERS file. It supports multiple command formats, including slash commands, mentions, and bare commands, and provides options to approve, merge, squash, rebase, remove approvals, and clean up comments. The app also handles reaction-based commands for approval and merging and maintains a history of reactions removed from approvals/merges.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.21.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository&rsquo;s CODEOWNERS file. It supports multiple command formats, including slash commands, mentions, and bare commands, and provides options to approve, merge, squash, rebase, remove approvals, and clean up comments. The app also handles reaction-based commands for approval and merging and maintains a history of reactions removed from approvals/merges.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1212-2026-08-11"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.21.1...v1.21.2">1.21.2</a> (2026-08-11)</h2>
<h2 id="smyklot-v1212">Smyklot v1.21.2</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.21.2</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>41e3daf552efc8e7b614e8cca74ed9b78ba2cf6d chore(release): bump version to 1.21.2</li>
<li>4166b2e89acf0ac412564b3d8ba41548467753fe fix(panel): compact workspace picker (#186)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/update-a-config-file-with-values-from-environment/</link><pubDate>Tue, 11 Aug 2026 14:30:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action reads configuration files and replaces placeholders with values from environment variables, making it easier to manage sensitive data securely during deployment.
What’s Changed feat: Add support for .env files (e706be3) chore: More info (d440258) feat: Initial version (e440a96)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action reads configuration files and replaces placeholders with values from environment variables, making it easier to manage sensitive data securely during deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add support for .env files (e706be3)</li>
<li>chore: More info (d440258)</li>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Tue, 11 Aug 2026 14:30:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by bundling and committing the dist folder before pushing it to the repository. It ensures that the latest production-ready version is deployed without manual intervention, streamlining the process of deploying changes to the swarm environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by bundling and committing the <code>dist</code> folder before pushing it to the repository. It ensures that the latest production-ready version is deployed without manual intervention, streamlining the process of deploying changes to the swarm environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>Spare Parts LGTM</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/spare-parts-lgtm/</link><pubDate>Tue, 11 Aug 2026 14:30:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/spare-parts-lgtm/</guid><description>Version updated for https://github.com/sparepartslabs/spareparts-lgtm to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of asking reviewers questions about pull requests they approve, generating the questions from the diff. It solves the problem of ensuring that everyone reads the pull request before approving it and provides a user-friendly experience by offering unlimited attempts without scoring or marking reviews as failed. The action uses an agent matrix supported by Claude, Codex, Cursor, GitHub Copilot, Gemini, and OpenCode to generate the questions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sparepartslabs/spareparts-lgtm">https://github.com/sparepartslabs/spareparts-lgtm</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spare-parts-lgtm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of asking reviewers questions about pull requests they approve, generating the questions from the diff. It solves the problem of ensuring that everyone reads the pull request before approving it and provides a user-friendly experience by offering unlimited attempts without scoring or marking reviews as failed. The action uses an agent matrix supported by Claude, Codex, Cursor, GitHub Copilot, Gemini, and OpenCode to generate the questions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #14 from sparepartslabs/feat/lgtm-agent-plugin (76cd8c4)</li>
<li>docs: lead with agent-neutral LGTM workflow (4d635c1)</li>
<li>feat: package LGTM agent plugin (661916c)</li>
<li>chore(ec): install shared constitution workflow (52aaacd)</li>
<li>chore(ec): install shared constitution workflow (3ce27c8)</li>
<li>Rename action from &lsquo;LGTM&rsquo; to &lsquo;Spare Parts LGTM&rsquo; (e8629a1)</li>
<li>Merge pull request #10 from sparepartslabs/dependabot/npm_and_yarn/dev-1939bc3e6a (b519b4e)</li>
<li>chore: bump the dev group with 2 updates (47df768)</li>
<li>feat: publish action (b089510)</li>
<li>feat: secrets, tests, deps (2718cef)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/classroom-to-sheets-integration/</link><pubDate>Tue, 11 Aug 2026 14:28:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates GitHub Classroom with Google Sheets to automatically send assignment results. It solves the problem of manually updating students’ grades and scores in Google Sheets by automating this process through API credentials, secrets, and workflows. The action supports multiple tasks and automatically updates or creates columns and rows in the Google sheet based on the task results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates GitHub Classroom with Google Sheets to automatically send assignment results. It solves the problem of manually updating students&rsquo; grades and scores in Google Sheets by automating this process through API credentials, secrets, and workflows. The action supports multiple tasks and automatically updates or creates columns and rows in the Google sheet based on the task results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>rag-redteam</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/rag-redteam/</link><pubDate>Tue, 11 Aug 2026 14:27:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/rag-redteam/</guid><description>Version updated for https://github.com/Srivatsa03/rag-redteam to version v0.6.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The rag-redteam GitHub Action is designed to test RAG pipelines for potential security vulnerabilities such as indirect prompt injection and source-document leakage. It automates these tests by simulating attacks on the pipeline and failing the build if any vulnerabilities are found, ensuring that sensitive information remains protected in the retrieved documents. The action can be used with local or remote RAG implementations, providing a comprehensive security check for LLM-based retrieval pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Srivatsa03/rag-redteam">https://github.com/Srivatsa03/rag-redteam</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rag-redteam">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The rag-redteam GitHub Action is designed to test RAG pipelines for potential security vulnerabilities such as indirect prompt injection and source-document leakage. It automates these tests by simulating attacks on the pipeline and failing the build if any vulnerabilities are found, ensuring that sensitive information remains protected in the retrieved documents. The action can be used with local or remote RAG implementations, providing a comprehensive security check for LLM-based retrieval pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><code>pip install rag-redteam==0.6.0</code> — still zero runtime dependencies.</p>
<h2 id="what-changed">What changed</h2>
<p><strong>Every probe now samples a grammar.</strong> Six of the seven replayed between one and four hardcoded strings, which is too little to support a conclusion: cross-document decided a published 100% on a <em>single attempt</em>, and measures 17% at 300 trials. Grammars run from 480 to over 5,000 combinations. Use <code>--trials</code>.</p>
<p><strong>Reference defenses</strong> (<code>rag_redteam.defenses</code>) wrap any target, and each declares whether it is <strong>structural</strong> — holding regardless of what the model decides — or <strong>advisory</strong>, working by persuading it. That distinction turned out to matter more than the defenses themselves.</p>
<p><strong>A utility metric</strong> reported beside attack success, because a defense that refuses every query scores a perfect 0% on every probe and is also a broken product. This caught a real bug before release: the first real-model run read 0% across every security column while answering half the ordinary questions.</p>
<p><strong>An HTTP adapter</strong> — point it at an endpoint instead of writing a Python target:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>rag-redteam run --target-url https://my-rag.example.com/ask
</span></span></code></pre></div><p>Private and loopback addresses are refused by default, so the same code is safe in a hosted scanner.</p>
<h2 id="what-the-runs-found">What the runs found</h2>
<p>8,400 injection attempts across four models and four retrieval stacks:</p>
<ul>
<li><strong>Filter evasion anti-correlates with attack success, r = −0.79.</strong> base64 evades a pattern filter 57% of the time and breaks the pipeline 0% of the time. Plain uppercase is caught 91% of the time and is the strongest attack tested.</li>
<li><strong>That relationship moves with the model.</strong> base64 goes 0% → 0% → 18% → 2% across the capability ladder; rot13 stays at 0% until the newest model obeys it 9% of the time. A filter&rsquo;s least important weakness becomes a live hole on upgrade day, with nothing about the filter having changed.</li>
<li><strong>Alignment narrows the funnel, capability widens the door.</strong> The hardest model to inject is the only one that obeys <em>every</em> encoding tested.</li>
<li><strong>Defenses cut injection 37% → 10% and cannot close it</strong>, and every point of that comes from an advisory defense. Structural defenses alone leave injection at exactly the undefended rate.</li>
</ul>
<p>Full write-up in <a href="https://github.com/Srivatsa03/rag-redteam/blob/main/docs/FINDINGS.md"><code>docs/FINDINGS.md</code></a>. Live demo and browser scanner: <strong><a href="https://srivatsa03.github.io/rag-redteam/">https://srivatsa03.github.io/rag-redteam/</a></strong></p>
<h2 id="limits">Limits</h2>
<p>Everything here is non-adaptive, which is known to overestimate robustness, so read the numbers as a lower bound on exposure. All four models are OpenAI, so the ladder is a within-family result.</p>
]]></content:encoded></item><item><title>Standard Ruby</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/standard-ruby/</link><pubDate>Tue, 11 Aug 2026 14:26:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/standard-ruby/</guid><description>Version updated for https://github.com/standardrb/standard-ruby-action to version v1.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the linting and formatting of Ruby code using the Standard Ruby tool. It runs bundle exec standardrb --fix on the repository’s root directory, committing any auto-fixable errors back to the repo. If any errors remain, it fails the build with annotations for each failure. The action can be added to a workflow or existing job in GitHub Actions, allowing developers to maintain code quality and consistency without manual intervention.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/standardrb/standard-ruby-action">https://github.com/standardrb/standard-ruby-action</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/standard-ruby">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the linting and formatting of Ruby code using the Standard Ruby tool. It runs <code>bundle exec standardrb --fix</code> on the repository&rsquo;s root directory, committing any auto-fixable errors back to the repo. If any errors remain, it fails the build with annotations for each failure. The action can be added to a workflow or existing job in GitHub Actions, allowing developers to maintain code quality and consistency without manual intervention.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Smoke test this action against example sinatra apps. by @jasonkarns in <a href="https://github.com/standardrb/standard-ruby-action/pull/32">https://github.com/standardrb/standard-ruby-action/pull/32</a></li>
<li>Pin action dependencies to full sha for security by @jasonkarns in <a href="https://github.com/standardrb/standard-ruby-action/pull/34">https://github.com/standardrb/standard-ruby-action/pull/34</a></li>
<li>Configure dependabot for bundler in example dirs by @jasonkarns in <a href="https://github.com/standardrb/standard-ruby-action/pull/35">https://github.com/standardrb/standard-ruby-action/pull/35</a></li>
<li>Bump actions/checkout from 4.2.1 to 4.2.2 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/36">https://github.com/standardrb/standard-ruby-action/pull/36</a></li>
<li>Bump ruby/setup-ruby from 1.244.0 to 1.245.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/37">https://github.com/standardrb/standard-ruby-action/pull/37</a></li>
<li>Enhance ruby-version selection by @jasonkarns in <a href="https://github.com/standardrb/standard-ruby-action/pull/39">https://github.com/standardrb/standard-ruby-action/pull/39</a></li>
<li>Rename workdir to working-directory by @jasonkarns in <a href="https://github.com/standardrb/standard-ruby-action/pull/40">https://github.com/standardrb/standard-ruby-action/pull/40</a></li>
<li>Bump ruby/setup-ruby from 1.245.0 to 1.247.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/42">https://github.com/standardrb/standard-ruby-action/pull/42</a></li>
<li>Bump step-security/harden-runner from 2.12.2 to 2.13.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/41">https://github.com/standardrb/standard-ruby-action/pull/41</a></li>
<li>Bump ruby/setup-ruby from 1.247.0 to 1.253.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/43">https://github.com/standardrb/standard-ruby-action/pull/43</a></li>
<li>Bump ruby/setup-ruby from 1.253.0 to 1.254.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/44">https://github.com/standardrb/standard-ruby-action/pull/44</a></li>
<li>Bump actions/checkout from 4.2.2 to 4.3.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/45">https://github.com/standardrb/standard-ruby-action/pull/45</a></li>
<li>Bump actions/checkout from 4.3.0 to 5.0.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/46">https://github.com/standardrb/standard-ruby-action/pull/46</a></li>
<li>Bump ruby/setup-ruby from 1.254.0 to 1.255.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/47">https://github.com/standardrb/standard-ruby-action/pull/47</a></li>
<li>Bump ruby/setup-ruby from 1.255.0 to 1.257.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/49">https://github.com/standardrb/standard-ruby-action/pull/49</a></li>
<li>Bump step-security/harden-runner from 2.13.0 to 2.13.1 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/50">https://github.com/standardrb/standard-ruby-action/pull/50</a></li>
<li>Bump ruby/setup-ruby from 1.257.0 to 1.262.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/51">https://github.com/standardrb/standard-ruby-action/pull/51</a></li>
<li>Bump ruby/setup-ruby from 1.262.0 to 1.265.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/53">https://github.com/standardrb/standard-ruby-action/pull/53</a></li>
<li>Bump ruby/setup-ruby from 1.265.0 to 1.266.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/54">https://github.com/standardrb/standard-ruby-action/pull/54</a></li>
<li>Bump ruby/setup-ruby from 1.266.0 to 1.267.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/55">https://github.com/standardrb/standard-ruby-action/pull/55</a></li>
<li>Bump step-security/harden-runner from 2.13.1 to 2.13.2 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/56">https://github.com/standardrb/standard-ruby-action/pull/56</a></li>
<li>Bump ruby/setup-ruby from 1.267.0 to 1.268.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/58">https://github.com/standardrb/standard-ruby-action/pull/58</a></li>
<li>Bump actions/checkout from 5.0.0 to 6.0.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/57">https://github.com/standardrb/standard-ruby-action/pull/57</a></li>
<li>Bump step-security/harden-runner from 2.13.2 to 2.13.3 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/62">https://github.com/standardrb/standard-ruby-action/pull/62</a></li>
<li>Bump actions/checkout from 6.0.0 to 6.0.1 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/61">https://github.com/standardrb/standard-ruby-action/pull/61</a></li>
<li>Bump ruby/setup-ruby from 1.268.0 to 1.269.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/60">https://github.com/standardrb/standard-ruby-action/pull/60</a></li>
<li>Bump ruby/setup-ruby from 1.269.0 to 1.270.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/64">https://github.com/standardrb/standard-ruby-action/pull/64</a></li>
<li>Bump step-security/harden-runner from 2.13.3 to 2.14.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/63">https://github.com/standardrb/standard-ruby-action/pull/63</a></li>
<li>Bump ruby/setup-ruby from 1.270.0 to 1.275.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/65">https://github.com/standardrb/standard-ruby-action/pull/65</a></li>
<li>Bump ruby/setup-ruby from 1.275.0 to 1.276.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/66">https://github.com/standardrb/standard-ruby-action/pull/66</a></li>
<li>Bump ruby/setup-ruby from 1.276.0 to 1.278.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/67">https://github.com/standardrb/standard-ruby-action/pull/67</a></li>
<li>Bump ruby/setup-ruby from 1.278.0 to 1.281.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/68">https://github.com/standardrb/standard-ruby-action/pull/68</a></li>
<li>Bump ruby/setup-ruby from 1.281.0 to 1.284.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/69">https://github.com/standardrb/standard-ruby-action/pull/69</a></li>
<li>Bump step-security/harden-runner from 2.14.0 to 2.14.1 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/72">https://github.com/standardrb/standard-ruby-action/pull/72</a></li>
<li>Bump actions/checkout from 6.0.1 to 6.0.2 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/71">https://github.com/standardrb/standard-ruby-action/pull/71</a></li>
<li>Bump ruby/setup-ruby from 1.284.0 to 1.286.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/70">https://github.com/standardrb/standard-ruby-action/pull/70</a></li>
<li>Decrease dependabot frequence to monthly for GHA by @jasonkarns in <a href="https://github.com/standardrb/standard-ruby-action/pull/73">https://github.com/standardrb/standard-ruby-action/pull/73</a></li>
<li>Bump ruby/setup-ruby from 1.286.0 to 1.288.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/74">https://github.com/standardrb/standard-ruby-action/pull/74</a></li>
<li>Bump ruby/setup-ruby from 1.288.0 to 1.302.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/76">https://github.com/standardrb/standard-ruby-action/pull/76</a></li>
<li>Bump step-security/harden-runner from 2.14.1 to 2.18.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/75">https://github.com/standardrb/standard-ruby-action/pull/75</a></li>
<li>Don&rsquo;t pin production dependencies to SHAs by @jasonkarns in <a href="https://github.com/standardrb/standard-ruby-action/pull/81">https://github.com/standardrb/standard-ruby-action/pull/81</a></li>
<li>Bump step-security/harden-runner from 2.18.0 to 2.19.3 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/78">https://github.com/standardrb/standard-ruby-action/pull/78</a></li>
<li>Bump step-security/harden-runner from 2.19.3 to 2.19.4 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/84">https://github.com/standardrb/standard-ruby-action/pull/84</a></li>
<li>Bump actions/checkout from 6.0.2 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/83">https://github.com/standardrb/standard-ruby-action/pull/83</a></li>
<li>Bump actions/checkout from 7.0.0 to 7.0.1 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/87">https://github.com/standardrb/standard-ruby-action/pull/87</a></li>
<li>Bump step-security/harden-runner from 2.19.4 to 2.20.0 by @dependabot[bot] in <a href="https://github.com/standardrb/standard-ruby-action/pull/86">https://github.com/standardrb/standard-ruby-action/pull/86</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/standardrb/standard-ruby-action/pull/36">https://github.com/standardrb/standard-ruby-action/pull/36</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/standardrb/standard-ruby-action/compare/v1.5.0...v1.6.0">https://github.com/standardrb/standard-ruby-action/compare/v1.5.0...v1.6.0</a></p>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/runward-gate/</link><pubDate>Tue, 11 Aug 2026 14:25:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.33.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward automates AI-assisted software engineering by verifying that the engineering decisions behind AI-written code were followed deterministically. It provides a way to check whether the architecture, where things run, how it’s secured, and how it’s handed over were correctly handled after the code ships. The action scaffolds a filled reference mission and ends by running the strict gate itself, ensuring the load-bearing decisions were actually made and written down.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.33.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Runward automates AI-assisted software engineering by verifying that the engineering decisions behind AI-written code were followed deterministically. It provides a way to check whether the architecture, where things run, how it&rsquo;s secured, and how it&rsquo;s handed over were correctly handled after the code ships. The action scaffolds a filled reference mission and ends by running the strict gate itself, ensuring the load-bearing decisions were actually made and written down.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>No verdict changes.</strong> The release path now carries its own proof, two claims that were true became enforced, and the gate&rsquo;s requirements are stated one at a time with the test that exercises each.</p>
<h2 id="the-release-carried-no-proof">The release carried no proof</h2>
<p>Until today a GitHub release carried the SBOM and <strong>nothing else</strong> — not the tarball, not a single attestation:</p>
<pre tabindex="0"><code>v0.33.2: runward-sbom.cdx.json
v0.33.1: runward-sbom.cdx.json
v0.33.0: runward-sbom.cdx.json
</code></pre><p>The provenance existed — <code>npm audit signatures</code> returns it, and deps.dev shows Google verifying it independently — but it lived on the <strong>npm registry</strong>, and a GitHub release is where most people look.</p>
<p>So OpenSSF Scorecard read the release assets and answered, verbatim:</p>
<blockquote>
<p><code>Signed-Releases: 0</code> — <em>Project has not signed or included provenance with any releases.</em></p>
</blockquote>
<p><strong>The project&rsquo;s own public scorecard contradicted its strongest claim</strong>, across at least three releases.</p>
<p>The real bundle now goes up under the <code>.intoto.jsonl</code> name the ecosystem reads, with the tarball beside it: an attestation whose subject the reader cannot fetch from the same place proves nothing they can act on. <code>test -s &quot;$BUNDLE&quot;</code> reds the release rather than shipping a silent gap.</p>
<p><strong>This release is the first proof that the path works.</strong> It could not be tested any other way.</p>
<h2 id="two-lines-the-compliance-sheet-could-only-assert">Two lines the compliance sheet could only assert</h2>
<p><strong><code>npm audit --audit-level=high</code> on every pull request.</strong> There was no such job — <code>grep -rn &quot;npm audit&quot; .github/workflows/</code> returned nothing, and a HIGH advisory sat green and unmerged while a release was cut. Scoped to high and above on purpose: a floor at <code>low</code> reds on advisories nobody would act on, and a guard that cries on the safe case gets switched off.</p>
<p><strong>A coverage floor.</strong> The <code>coverage</code> script existed and nothing called it. A <strong>ratchet, not a target</strong>: 78 against a measured 80.41, moved only by a deliberate commit. ADR-0046 refuses a threshold on the <em>mutation</em> score for reasons that do not transfer — a mutation score is a property of the tests, whereas line coverage is recomputed from scratch on every run.</p>
<h2 id="tool-operational-requirements">Tool operational requirements</h2>
<p><strong>51 requirements</strong> over the verdict surface, each citing a test file and a case name inside it. The substance was already in <code>runward/contracts/port-contract.md</code> — in prose, with <strong>zero identifiers</strong>. Prose cannot be checked off: an assessor asks <em>which requirement, verified where</em>.</p>
<p>Each entry states what a green <strong>leaves open</strong>, per requirement. TOR-028 is the one to read first: a tampered seal reddens the gate, and the same entry says the seal establishes nothing about <strong>when</strong> it was written, because <code>sealedAt</code> is the mission&rsquo;s word.</p>
<p>It is <strong>not a qualification kit</strong>, and says so in its own opening: a vendor kit&rsquo;s documents are produced under a quality system a third party has assessed, and these are produced by one maintainer with no external assessment of any kind. Its traceability guard checks that a citation <strong>resolves</strong>, never that the cited test is <strong>relevant</strong>. Section 10 names what carries no requirement at all.</p>
<h2 id="why-runward-issues-no-attestation-about-your-application">Why runward issues no attestation about your application</h2>
<p>The answer is <strong>no</strong>, in any form, and the reason is measured rather than principled: the machine contract cannot distinguish a substantial mission from one carrying no project code, the corpus belongs to the audited party, the seal date is the mission&rsquo;s word, and issuer, subject and verifier would be the same party.</p>
<p>What can be published instead is a <strong>replayable record, by the operator, in their own repository</strong> — with the admission that on a private repository the only level that checks content is unavailable to an outside reader, which is the commonest case.</p>
<h2 id="test-suite">Test suite</h2>
<p><strong>428 → 435</strong>, and 98 mutants that survived the entire net now die. Re-measured before instructing: the derived figure was 199, the measured one <strong>179</strong>, because twenty had been killed by tests that never aimed at them. 81 survivors remain, filed as a register rather than a backlog.</p>
<p><strong>Full changelog</strong>: <a href="https://github.com/stranxik/runward/blob/main/CHANGELOG.md">https://github.com/stranxik/runward/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>AgentScan-cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/agentscan-cli/</link><pubDate>Tue, 11 Aug 2026 14:24:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/agentscan-cli/</guid><description>Version updated for https://github.com/thesfb/agentscan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The AgentScan Action automates the security scanning of AI agent skills before they are run in GitHub Actions workflows. It uses a deterministic local scanner to identify and report potential security issues such as shell commands, network calls, secrets, licenses, and obfuscation. The action helps prevent risky skills from being deployed by failing the build when it detects findings at or above a specified severity threshold, while still printing all findings in the log for review.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thesfb/agentscan-action">https://github.com/thesfb/agentscan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentscan-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The AgentScan Action automates the security scanning of AI agent skills before they are run in GitHub Actions workflows. It uses a deterministic local scanner to identify and report potential security issues such as shell commands, network calls, secrets, licenses, and obfuscation. The action helps prevent risky skills from being deployed by failing the build when it detects findings at or above a specified severity threshold, while still printing all findings in the log for review.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AgentScan is a local scanner for AI agent skills. Point it at any Claude Code, Codex, or OpenCode skill directory before you install. It shows what the skill does: permissions, network calls, secrets, license. A scan takes seconds and returns file:line evidence for every finding, so the verdict is yours. It never runs the skill. It never sends data.</p>
]]></content:encoded></item><item><title>tishlang-sem</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/tishlang-sem/</link><pubDate>Tue, 11 Aug 2026 14:23:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/tishlang-sem/</guid><description>Version updated for https://github.com/tishlang/sem to version v1.3.3.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the semantic versioning and release pipeline using Tish, a modern JavaScript runtime. It supports both Node.js and Tish-native environments and provides dual runtimes. The action is configured via file, package.json, environment variables, or JSON/YAML configuration options. It handles conventional Commits and semver for bumping versions, with soft-skipping on non-release branches. It also supports recoveries with the --force/SEM_FORCE flag and auto-republishs when a git tag exists but the version is missing from npm. The action promotes GitHub releases through the promote-style pattern, including prerelease assets and unchecking pre-release status for publishing workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tishlang/sem">https://github.com/tishlang/sem</a></strong> to version <strong>v1.3.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tishlang-sem">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the semantic versioning and release pipeline using Tish, a modern JavaScript runtime. It supports both Node.js and Tish-native environments and provides dual runtimes. The action is configured via file, <code>package.json</code>, environment variables, or JSON/YAML configuration options. It handles conventional Commits and semver for bumping versions, with soft-skipping on non-release branches. It also supports recoveries with the <code>--force</code>/<code>SEM_FORCE</code> flag and auto-republishs when a git tag exists but the version is missing from npm. The action promotes GitHub releases through the promote-style pattern, including prerelease assets and unchecking pre-release status for publishing workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="133-2026-08-10"><a href="https://github.com/tishlang/sem/compare/v1.3.2...v1.3.3">1.3.3</a> (2026-08-10)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>skip npm publish when the GitHub release is still a draft (<a href="https://github.com/tishlang/sem/commit/023520d49360d2db15dc33adad44cb80750b9445">023520d</a>)</li>
</ul>
<hr>
<p>Published to npm: <a href="https://www.npmjs.com/package/@tishlang/sem/v/1.3.3">https://www.npmjs.com/package/@tishlang/sem/v/1.3.3</a>
GitHub Packages: <a href="https://github.com/tishlang/sem/pkgs/npm/sem">https://github.com/tishlang/sem/pkgs/npm/sem</a>
GitHub Action: uses: <a href="mailto:tishlang/sem@v1.3.3">tishlang/sem@v1.3.3</a></p>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/compose-lint/</link><pubDate>Tue, 11 Aug 2026 14:22:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.16.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a static-analysis linter for Docker Compose files that checks for security vulnerabilities such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. It catches these issues before they reach production and provides auto-fixes for unambiguous problems during a dry-run. The action leverages OWASP and CIS Docker Benchmarks to ensure compliance with best practices.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.16.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a static-analysis linter for Docker Compose files that checks for security vulnerabilities such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, hard-coded credentials, and more. It catches these issues before they reach production and provides auto-fixes for unambiguous problems during a dry-run. The action leverages OWASP and CIS Docker Benchmarks to ensure compliance with best practices.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="upgrading-from-015x">Upgrading from 0.15.x</h3>
<p><strong>Your CI verdict may change in both directions, on files you have not
touched.</strong> This release re-derived every severity and moved findings between
rules, so a gate that passed may fail and a gate that failed may pass. Nothing
here is a parser change: the same file is being read the same way and priced
differently.</p>
<p><strong>The hazard worth reading twice: a waiver can still parse and no longer
cover anything.</strong> A retired rule id warns on load —
<code>config: unknown rule id 'CL-0012'; the override has no effect</code> — and
<code>--strict-config</code> turns that into an error. But a waiver naming a rule that
still <em>exists</em> is silent, even when the finding it was written for has moved:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">rules</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">CL-0011</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">reason</span>: <span style="color:#e6db74">&#34;we need SYS_ADMIN for the FUSE mount&#34;</span>   <span style="color:#75715e"># no longer covers it</span>
</span></span></code></pre></div><p><code>SYS_ADMIN</code> is CL-0024 now. The config is valid, nothing warns, and the finding
comes back at CRITICAL. Check every waiver against the table below.</p>
<h4 id="where-findings-moved">Where findings moved</h4>
<p>Generated by linting one trigger per row under both versions.</p>
<table>
  <thead>
      <tr>
          <th>Trigger</th>
          <th>0.15.2</th>
          <th>0.16.0</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>cap_add: ALL</code></td>
          <td>CL-0011 CRITICAL</td>
          <td><strong>CL-0024</strong> CRITICAL</td>
      </tr>
      <tr>
          <td><code>cap_add: SYS_ADMIN</code> / <code>SYS_MODULE</code> / <code>SYS_RAWIO</code></td>
          <td>CL-0011 HIGH</td>
          <td><strong>CL-0024 CRITICAL</strong></td>
      </tr>
      <tr>
          <td><code>cap_add: PERFMON</code> / <code>SYS_TIME</code></td>
          <td>CL-0011 HIGH</td>
          <td><strong>CL-0028</strong> HIGH</td>
      </tr>
      <tr>
          <td><code>cap_add: SYS_PTRACE</code> / <code>DAC_READ_SEARCH</code></td>
          <td>CL-0011 HIGH</td>
          <td><strong>CL-0027 MEDIUM</strong></td>
      </tr>
      <tr>
          <td><code>cap_add: NET_ADMIN</code> / <code>BPF</code> / <code>SYS_BOOT</code></td>
          <td>CL-0011 HIGH</td>
          <td>CL-0011 HIGH <em>(unchanged)</em></td>
      </tr>
      <tr>
          <td><code>cap_add: DAC_OVERRIDE</code></td>
          <td>CL-0011 HIGH</td>
          <td><em>none — Docker default</em></td>
      </tr>
      <tr>
          <td>whole-root mount <code>/</code>, either mode</td>
          <td>CL-0013 CRITICAL</td>
          <td><strong>CL-0001</strong> CRITICAL</td>
      </tr>
      <tr>
          <td>writable <code>/etc</code>, <code>/root</code>, <code>/boot</code>, <code>/proc</code></td>
          <td>CL-0013 HIGH</td>
          <td><strong>CL-0025 CRITICAL</strong></td>
      </tr>
      <tr>
          <td>read-only <code>/etc</code> and friends</td>
          <td>CL-0013 HIGH</td>
          <td>CL-0013 HIGH <em>(unchanged)</em></td>
      </tr>
      <tr>
          <td><code>devices: /dev/sda</code> and other host disks</td>
          <td>CL-0016 HIGH</td>
          <td>CL-0016 <strong>CRITICAL</strong></td>
      </tr>
      <tr>
          <td><code>devices: /dev/fuse</code></td>
          <td>CL-0016 HIGH</td>
          <td><em>none — needs <code>SYS_ADMIN</code>, which CL-0024 flags</em></td>
      </tr>
      <tr>
          <td><code>userns_mode: host</code></td>
          <td>CL-0010 HIGH</td>
          <td><em>none — a no-op at Docker&rsquo;s default posture</em></td>
      </tr>
  </tbody>
</table>
<h4 id="newly-flagged--a-passing-file-can-now-fail">Newly flagged — a passing file can now fail</h4>
<table>
  <thead>
      <tr>
          <th>Trigger</th>
          <th>0.16.0</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>writable <code>/var/lib</code> or <code>/var/lib/containerd</code></td>
          <td>CL-0025 CRITICAL</td>
      </tr>
      <tr>
          <td><code>/run</code> or <code>/var/run</code> mounted whole</td>
          <td>CL-0001 CRITICAL</td>
      </tr>
      <tr>
          <td>a path below them — <code>/run/udev</code>, <code>/var/run/libvirt/libvirt-sock</code></td>
          <td>CL-0013 HIGH</td>
      </tr>
      <tr>
          <td><code>~/.ssh</code>, <code>~/.aws</code>, <code>~/.docker</code>, <code>~/.kube</code>, <code>~/.gnupg</code></td>
          <td>CL-0013 HIGH</td>
      </tr>
      <tr>
          <td>a relative source that climbs out — <code>../../../..</code></td>
          <td>CL-0001 CRITICAL</td>
      </tr>
      <tr>
          <td>a bind-backed named volume (<code>driver_opts: {device: …, o: bind}</code>)</td>
          <td>CL-0001 CRITICAL</td>
      </tr>
      <tr>
          <td><code>devices: /dev/md0</code>, <code>/dev/vd*</code>, <code>/dev/xvd*</code>, <code>/dev/mmcblk*</code></td>
          <td>CL-0016 CRITICAL</td>
      </tr>
  </tbody>
</table>
<h4 id="no-longer-flagged--a-failing-file-can-now-pass">No longer flagged — a failing file can now pass</h4>
<p><code>cap_add: DAC_OVERRIDE</code> · <code>userns_mode: host</code> · <code>devices: /dev/fuse</code> ·
<code>/dev/null</code>, <code>/dev/zero</code>, <code>/dev/full</code>, <code>/dev/random</code>, <code>/dev/urandom</code> ·
a project directory under a home dir (<code>/home/alice/proj/data</code>) ·
<code>/var/lib/mysql</code>, <code>/var/lib/postgresql/data</code> and other service state dirs ·
anything that was CL-0012, CL-0015 or CL-0023.</p>
<h4 id="check-your-own-files-rather-than-reasoning-about-this-list">Check your own files rather than reasoning about this list</h4>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>compose-lint check --format json . &gt; before.json   <span style="color:#75715e"># on 0.15.x</span>
</span></span><span style="display:flex;"><span>pip install --upgrade compose-lint
</span></span><span style="display:flex;"><span>compose-lint check --strict-config .               <span style="color:#75715e"># dead rule ids become errors</span>
</span></span><span style="display:flex;"><span>compose-lint check --format json . &gt; after.json
</span></span><span style="display:flex;"><span>diff &lt;<span style="color:#f92672">(</span>jq -S <span style="color:#e6db74">&#39;[.findings[]|{rule_id,line,service}]&#39;</span> before.json<span style="color:#f92672">)</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>     &lt;<span style="color:#f92672">(</span>jq -S <span style="color:#e6db74">&#39;[.findings[]|{rule_id,line,service}]&#39;</span> after.json<span style="color:#f92672">)</span>
</span></span></code></pre></div><p>The diff catches the moved-waiver case, which no warning can reach.</p>
<h3 id="added">Added</h3>
<ul>
<li><strong>CL-0026 — no memory or CPU resource limits</strong> (MEDIUM). Docker imposes
neither by default: a container&rsquo;s <code>memory.max</code> is <code>max</code> and its <code>cpu.max</code> is
<code>max 100000</code> unless a limit is set. Fires when a service declares no memory
limit, no CPU limit, or neither, and names which is missing. Reservations
(<code>mem_reservation</code>, <code>cpu_shares</code>) express priority under contention and do not
satisfy it; <code>cpu_quota</code> does. Covers both halves of ATT&amp;CK T1496 Resource
Hijacking — the memory-exhaustion denial of service and the CPU-bound
cryptomining that a memory limit does not bound at all.</li>
<li>Every rule page carries a derivation block — baseline, precondition, impact,
qualifier, derived, shipped, and an <strong>Evidence</strong> line naming a premise check
or a captured observation. A test asserts the page and the severity table
state the same derivation.</li>
<li><code>scripts/validate_rule_premises.py</code> asserts the daemon under test is at
Docker&rsquo;s defaults before measuring anything, and aborts if it is not — a
premise measured against a hardened or loosened daemon returns a confidently
wrong answer. Five new premise checks: a <code>:ro</code> socket is still a working API
endpoint, a raw host-disk read at default capabilities, the <code>/dev</code>-bind
negative control for it, <code>core_pattern</code> writable through an rw <code>/proc</code> bind,
and memory/CPU unbounded by default.</li>
<li>CI smoke-tests <code>.pre-commit-hooks.yaml</code> with the real tool
(<code>precommit-smoke</code>). <code>action.yml</code>, the image and the wheel each had an
end-to-end smoke job; the pre-commit hook had none, which is how issue #465 —
a <code>files</code> pattern that made the hook unable to pass — reached a user.
<code>pre-commit try-repo</code> runs the manifest from the working tree, so <code>entry</code>,
<code>language</code> and hook installation are exercised on the PR that changes them.
<code>.pre-commit-hooks.yaml</code> was also missing from the <code>code</code> path filter, so a
manifest-only edit previously skipped the jobs that check it.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><strong>BREAKING — the severity model was rebuilt, and rule ids moved with it.</strong>
Severities are now <em>derived</em> from a documented two-axis matrix under a stated
attacker baseline and a stated Docker posture, and any rule shipping a
different value declares an override from a closed reason list. See
<code>docs/severity.md</code>, <a href="docs/adr/020-severity-scoping-and-overrides.md">ADR-020</a>,
<a href="docs/adr/021-critical-tier-posture.md">ADR-021</a> and
<a href="docs/adr/022-threat-model-grounding.md">ADR-022</a>.</p>
<p><strong>Severity changes:</strong> CL-0016 HIGH → CRITICAL; CL-0005 HIGH → MEDIUM;
CL-0007, CL-0014 and CL-0017 MEDIUM → LOW. Only CL-0005 crosses the default
<code>--fail-on high</code> gate: a file whose only finding at or above HIGH was an
all-interfaces port bind now passes. That is deliberate — CI stops failing on
intended-public exposure. Use <code>--fail-on medium</code>, or override CL-0005 back to
HIGH in <code>.compose-lint.yml</code>, to keep the old behaviour.</p>
<p><strong>Rules split.</strong> <code>cap_add</code> is now four rules by what the capability grants:
CL-0024 (CRITICAL: <code>ALL</code>, <code>SYS_ADMIN</code>, <code>SYS_MODULE</code>, <code>SYS_RAWIO</code>), CL-0011
(HIGH, unchanged id: <code>NET_ADMIN</code>, <code>BPF</code>, <code>SYS_BOOT</code>), <strong>CL-0028</strong> (HIGH:
<code>PERFMON</code>, <code>SYS_TIME</code>) and CL-0027 (MEDIUM: <code>SYS_PTRACE</code>, <code>DAC_READ_SEARCH</code>).
CL-0028 is new: both its members reach the host with no other key in the file
and nothing from the image — <code>SYS_TIME</code> writes the host&rsquo;s wall clock, because
Docker does not namespace <code>CLOCK_REALTIME</code>, and <code>PERFMON</code> opens a host-wide
<code>perf_event_open</code> at the upstream kernel default. A service adding either now
crosses the default gate where it previously reported MEDIUM. The severity
model gains an <code>integrity-only</code> qualifier (one tier down) alongside
<code>read-only</code> and <code>availability-only</code>, which is what the impact axis was missing
for a host effect that corrupts without disclosing or granting control.</p>
<p>Host paths are two rules: CL-0025 (CRITICAL) for writable mounts of <code>/etc</code>,
<code>/root</code>, <code>/boot</code>, <code>/proc</code>, <code>/var/lib/docker</code>, <code>/var/lib/containerd</code> and
<code>/var/lib</code>, and CL-0013 (HIGH, unchanged id) for <code>/sys</code>, <code>/dev</code>, the home tree
and read-only mounts of CL-0025&rsquo;s paths. A whole-root mount (<code>/</code>) is CL-0001&rsquo;s
in either mode, because it contains the daemon control socket. Neither rule
branches severity any more, which fixes the SARIF descriptor/finding mismatch
in #503.</p>
<p><strong>Suppression migration.</strong> A <code>CL-0011</code> waiver now covers only <code>NET_ADMIN</code>,
<code>BPF</code> and <code>SYS_BOOT</code>; the other capabilities move to CL-0024, CL-0027 and
CL-0028 and are no longer covered by it. A <code>CL-0027</code> waiver does not cover
<code>PERFMON</code> or <code>SYS_TIME</code> — re-waive as CL-0028. A <code>CL-0013</code> waiver no longer
covers a writable root-equivalent path (CL-0025) or a <code>/run</code>-family mount
(CL-0001), and a waiver of a whole-root mount moves to CL-0001 (from CL-0025
when writable, or from CL-0013 when read-only). Waivers for CL-0012, CL-0015
and <code>/var/lib/kubelet</code> are dead and can be deleted.</p>
</li>
<li>
<p><strong>CL-0013 matches the home tree by depth, not by subtree.</strong> <code>/home</code> and a
single user&rsquo;s home directory (<code>/home/alice</code>) are still flagged in either mode,
and so are the credential directories <code>~/.ssh</code>, <code>~/.docker</code>, <code>~/.aws</code>,
<code>~/.kube</code> and <code>~/.gnupg</code> together with everything below them. A deeper project
path — <code>/home/alice/projects/app/data</code> — is the application&rsquo;s own directory
and is no longer flagged. <strong>Fewer findings</strong> on absolute
<code>/home/&lt;user&gt;/&lt;project&gt;/…</code> mounts, <strong>new findings</strong> on <code>~/.ssh</code>-style
credential mounts. This pairs with relative-source resolution below: <code>./data</code>
resolves to an absolute path under wherever the compose file sits, which for
most projects is under <code>/home</code>, so a subtree match would have flagged the
commonest bind idiom in Compose.</p>
</li>
<li>
<p>CL-0016&rsquo;s device list is reconciled with what a device actually grants. It
<strong>gains</strong> <code>/dev/vd*</code>, <code>/dev/xvd*</code>, <code>/dev/mmcblk*</code> and <code>/dev/md*</code> — the host
root disks of KVM and Proxmox guests, EC2 instances, Raspberry Pis and mdraid
arrays, which needed no capability and were not flagged at all. It <strong>drops</strong>
<code>/dev/mem</code>, <code>/dev/port</code> and <code>/dev/fuse</code>, each live only alongside a capability
CL-0024 or CL-0009 already flags, and <code>/dev/kmem</code> and <code>/dev/raw</code>, for which
Docker refuses to create the container. Suppressions for the dropped devices
are dead and can be deleted.</p>
</li>
<li>
<p>CL-0001 flags any mount that exposes a host control socket, including a
directory that merely contains one — <code>/run</code>, <code>/var/run</code>, <code>/run/containerd</code>,
<code>/run/systemd</code>, or the whole root <code>/</code> — and is mode-independent, because <code>:ro</code>
applies to the socket file rather than to the read-write API behind it. A
read-only <code>/</code> used to be graded CL-0013 HIGH, a tier below the socket it
exposes. It also matches a socket name on the <strong>host</strong> side of a mount only:
<code>- /tmp/fake:/var/run/docker.sock</code> is no longer reported as a socket mount,
since the container path is where a socket would land, not where it comes from.</p>
</li>
<li>
<p>Host paths are normalised before the mount rules match them, so <code>.</code> and <code>..</code>
segments no longer hide a mount. <code>- /.:/host</code>, <code>- /..:/host</code> and <code>- /./:/host</code>
are whole-root mounts and now report CL-0001 CRITICAL instead of passing
clean; <code>/run/.</code> is matched like <code>/run</code>, and <code>/etc/..</code> is treated as root
rather than as CL-0013&rsquo;s HIGH.</p>
</li>
<li>
<p>CL-0026 no longer accepts a non-positive value hidden in an interpolation
default. <code>mem_limit: ${MEM:-0}</code> and <code>cpus: ${CPUS:-0}</code> describe an unbounded
container and are now flagged; a bare <code>${MEM}</code> still counts as a limit,
because its value is genuinely unknowable from the file.</p>
</li>
<li>
<p>CL-0006 and the <code>cap_add</code> rules share one capability normaliser, so
<code>cap_drop: [CAP_ALL]</code> and <code>cap_drop: [&quot;  ALL  &quot;]</code> are read the same way
<code>cap_add</code> reads them. <code>cap_add: [CAP_ALL]</code> is no longer flagged at all:
Docker rejects that spelling outright, so the file could never start.</p>
</li>
</ul>
<h3 id="removed">Removed</h3>
<ul>
<li>
<p><strong>CL-0012 (PIDs cgroup limit disabled)</strong> — the premise does not hold. On the
grounded target, <code>pids_limit: -1</code>, <code>pids_limit: 0</code> and omitting the key all
produce the same <code>pids.max</code> (systemd&rsquo;s <code>DefaultTasksMax</code>), so the explicit
opt-out the rule flagged does not leave the process count unbounded.</p>
</li>
<li>
<p><strong>CL-0015 (healthcheck disabled)</strong> — no runtime delta, and its citations
mandate the case it declines to flag.</p>
</li>
<li>
<p><strong><code>uts: host</code> and <code>userns_mode: host</code></strong> from CL-0010. Both are no-ops under
the grounded posture: <code>sethostname()</code> needs <code>CAP_SYS_ADMIN</code>, which is not in
Docker&rsquo;s default set, and <code>userns_mode</code> only means anything against a
<code>--userns-remap</code> daemon.</p>
</li>
<li>
<p><strong><code>/var/lib/kubelet</code></strong> from CL-0013 — its danger is entirely conditional on
Kubernetes being present, so it cannot be premise-checked on the grounded
target.</p>
<p>The ids CL-0012, CL-0015 and CL-0023 stay fallow and will not be reused.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>The mount rules see host paths they were missing.</strong> Each of these mounted a
real host path and reported clean:</p>
<ul>
<li><strong>A relative or <code>~</code> source.</strong> Compose resolves a relative mount source
against the compose file&rsquo;s directory and expands a leading <code>~</code>; the source
was matched as written, so <code>- ../../../../../..:/host</code> mounted the host root
filesystem and reported nothing. <code>./data:/data</code> and other in-project mounts
are unaffected.</li>
<li><strong>An interpolated default.</strong> With no <code>.env</code> and no exported variable,
Compose substitutes the default, so <code>${DOCKER_SOCKET_PATH:-/var/run/docker.sock}</code>
mounts the live control socket. A reference with <strong>no</strong> default (<code>${VAR}</code>,
<code>${VAR:?err}</code>, <code>$VAR</code>) is still left alone — the host path is not knowable
from the file, and guessing one would invent a finding.</li>
<li><strong>A bind-backed named volume.</strong> <code>driver_opts: {type: none, device: &lt;host path&gt;, o: bind}</code> is the standard way to pin a bind mount&rsquo;s options, and the
host path lives in the top-level <code>volumes:</code> block, which the mount rules
never read. <code>external: true</code> volumes are left alone, since their host path
is not in the file.</li>
<li><strong>A writable <code>/var/lib</code></strong> (CL-0025 CRITICAL; read-only, CL-0013 HIGH). It
contains the container store, so a mount of it grants what <code>/var/lib/docker</code>
does — verified on Docker 29.4.3, a container given only <code>-v /var/lib</code> read
and modified a second container&rsquo;s files. It is matched <strong>exactly</strong>, because
its grant comes from what it contains rather than from what lies below it:
<code>-v /var/lib/mysql</code>, <code>/var/lib/postgresql/data</code> and other service data
directories are <em>not</em> flagged. <code>/var/lib/containerd</code> is a member in its own
right and is matched by descent.</li>
<li><strong>A path below <code>/run</code> or <code>/var/run</code></strong> (CL-0013 HIGH) — <code>/var/run/dbus</code>,
which reaches systemd and PolicyKit; <code>/var/run/libvirt/libvirt-sock</code>, which
is VM control; <code>/run/udev</code>, <code>/var/run/utmp</code>, <code>/run/systemd/journal</code>. CL-0001
owns those directories and their ancestors, because those hold the control
socket; what sits strictly below holds host service state instead. A
descendant that <em>is</em> a socket stays CL-0001&rsquo;s at CRITICAL.</li>
<li><strong><code>/dev/md/&lt;name&gt;</code></strong> (CL-0016). mdadm creates a named symlink per array
alongside the numeric node, and <code>^/dev/md\d</code> cannot match it — the character
after <code>md</code> is <code>/</code>, not a digit — so a named array passed clean while
<code>/dev/md0</code> beside it was CRITICAL. Added as a second pattern rather than by
loosening the first, which is what keeps <code>/dev/mdadm</code> out.</li>
</ul>
</li>
<li>
<p><strong><code>/dev/null</code> and the other inert character devices are no longer flagged</strong>
(CL-0013). <code>/dev/null</code>, <code>/dev/zero</code>, <code>/dev/full</code>, <code>/dev/random</code> and
<code>/dev/urandom</code> disclose no host state and grant no access — mounting
<code>/dev/null</code> over a config file the image expects is a near-universal idiom,
and the <code>/dev</code> descent match priced it HIGH. The rest of <code>/dev</code>, including
<code>/dev/shm</code>, is unchanged.</p>
</li>
<li>
<p>CL-0011 no longer flags <code>DAC_OVERRIDE</code>, which inverted the default gate
(issue #492). <code>DAC_OVERRIDE</code> is one of Docker&rsquo;s 14 default capabilities, so a
container holds it whether or not the file names it — flagging it on <code>cap_add</code>
scored the declaration rather than the runtime state. The effect was that
hardening a service made it fail: <code>cap_drop: [ALL]</code> plus
<code>cap_add: [DAC_OVERRIDE]</code> — one capability — exited 1 at the default
<code>--fail-on high</code>, while the same service with no <code>cap_drop</code> at all — fourteen
capabilities, <code>DAC_OVERRIDE</code> among them — exited 0. The fastest way back to
green was to delete the hardening. CL-0011 already excluded <code>MKNOD</code> and
<code>SYS_CHROOT</code> for exactly this reason; <code>DAC_OVERRIDE</code> was the one default
capability the list still carried. CL-0006 now names it among the retained
defaults, so both rules describe the same capability the same way.</p>
</li>
<li>
<p>CL-0020 and CL-0021 no longer skip credentials containing <code>$$</code>, Compose&rsquo;s
escape for a literal dollar (issue #502). CL-0020&rsquo;s variable-reference regex
read the second dollar of <code>pa$$w0rd</code> as starting a <code>$w0rd</code> substitution, and
CL-0021 exempted any value containing <code>$</code> at all — so exactly the passwords a
careful user escaped correctly went unchecked, and the two rules disagreed on
values like <code>hunter2$</code>. Both now share one classifier that consumes <code>$$</code>
escapes left-to-right, as Compose does, before testing for a reference.</p>
</li>
<li>
<p>Handing compose-lint its own config file no longer fails the run (issue #499).
<code>.compose-lint.yml</code> parses as YAML but has no <code>services:</code> key, and its shape
matched neither of ADR-013&rsquo;s not-applicable buckets, so it fell through to
<code>Not a valid Compose file</code> and exit 2. It is now recognised as a third
not-applicable shape and skipped with exit 0, like fragments and Compose v1
files. This is the root cause behind issue #465: <code>compose-lint init</code> followed
by a pre-commit sweep could never pass. Genuinely malformed Compose files
still exit 2; the check requires <em>every</em> non-meta top-level key to be a config
key, so it cannot swallow a broken file.</p>
</li>
<li>
<p>Fourteen false claims across the rule docs, each re-verified against a live
daemon. The worst was CL-0006&rsquo;s documented <code>## Fix</code>, which crash-looped:
<code>cap_drop: [ALL]</code> plus <code>cap_add: [NET_BIND_SERVICE]</code> exits with
<code>chown(&quot;/var/cache/nginx/client_temp&quot;) failed (Operation not permitted)</code>. Also
corrected: seccomp and AppArmor <em>do</em> survive <code>execve</code> of a setuid binary;
<code>bpf</code> and <code>init_module</code> are capability-gated rather than blocked outright;
<code>SYS_BOOT</code> does not load a kernel via kexec; <code>pid: host</code> does not expose
<code>/proc/[pid]/environ</code> at default capabilities; <code>uts: host</code> cannot change the
hostname; a <code>/dev</code> bind is not equivalent to <code>devices:</code>; <code>read_only</code> does not
prevent persistence through a volume; and <code>user: root</code> does not undo a
gosu/su-exec image&rsquo;s privilege drop.</p>
</li>
<li>
<p>CL-0019 was ungrounded — its only citation contained no digest guidance at
all. It now cites Docker&rsquo;s pull-by-digest documentation and CIS 5.28.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Run Godlint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/run-godlint/</link><pubDate>Tue, 11 Aug 2026 14:20:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/run-godlint/</guid><description>Version updated for https://github.com/tomerwave/godlint to version v0.9.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Godlint automates code quality checks across multiple programming languages, ensuring consistency in architectural boundaries, security practices, and operational standards. It helps developers maintain clear and secure codebases by enforcing policies locally and in CI, reducing the risk of architectural drift caused by AI-generated code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tomerwave/godlint">https://github.com/tomerwave/godlint</a></strong> to version <strong>v0.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-godlint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Godlint automates code quality checks across multiple programming languages, ensuring consistency in architectural boundaries, security practices, and operational standards. It helps developers maintain clear and secure codebases by enforcing policies locally and in CI, reducing the risk of architectural drift caused by AI-generated code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>npm release publishing now uses a trusted-publishing-capable npm client.</li>
</ul>
]]></content:encoded></item><item><title>GitHub Settings as Code</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/github-settings-as-code/</link><pubDate>Tue, 11 Aug 2026 14:19:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/github-settings-as-code/</guid><description>Version updated for https://github.com/Vivswan/github-settings-as-code to version v2.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Settings as Code action automates the process of applying declarative repository settings from a .github/settings.yml file to GitHub repositories using Actions. It replaces the Probot Settings app and handles branch, tag, and push rules, providing visible workflow runs with API error messages. The action can be used to manage repository permissions and configurations without manual intervention, making it easier for developers to maintain consistent settings across their projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Vivswan/github-settings-as-code">https://github.com/Vivswan/github-settings-as-code</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-settings-as-code">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Settings as Code action automates the process of applying declarative repository settings from a <code>.github/settings.yml</code> file to GitHub repositories using Actions. It replaces the Probot Settings app and handles branch, tag, and push rules, providing visible workflow runs with API error messages. The action can be used to manage repository permissions and configurations without manual intervention, making it easier for developers to maintain consistent settings across their projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="200-2026-08-11"><a href="https://github.com/Vivswan/github-settings-as-code/compare/v1.0.1...v2.0.0">2.0.0</a> (2026-08-11)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li>the action moved to Vivswan/github-settings-as-code; uses: references to Vivswan/repo-settings-as-code fail with &ldquo;repository not found&rdquo; and must be updated.</li>
<li>branches[].protection.required_signatures now acts. Previously the key rode the protection PUT, where GitHub dropped it (check mode showed permanent drift). A settings file already carrying it will start toggling the signed-commit requirement on the first apply after upgrading - a stale required_signatures: false would REMOVE a hand-enabled requirement. Audit existing declarations for intent before moving to v2. The v1 line keeps the old inert behavior.</li>
<li>actions.fork_pr_contributor_approval and actions.fork_pr_workflows_private_repos now act. Previously both keys fell through to the base permissions PUT, where GitHub ignored them and a notice said so. A settings file already carrying either key will start applying these policies on the first apply after upgrading; audit existing declarations for intent before moving to v2. The v1 line keeps the old inert behavior.</li>
<li>actions.oidc_customization_sub now acts. Previously the key fell through to the base permissions PUT, where GitHub ignored it and a notice said so. A settings file already carrying the key will start customizing the OIDC subject claim template on the first apply after upgrading; audit existing declarations for intent before moving to v2. The v1 line keeps the old inert behavior.</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li>add issue-on-failure private-report channel (quiet on healthy runs) (<a href="https://github.com/Vivswan/github-settings-as-code/commit/934a321d64d49470ced76b484f6f714fc2a2bbe4">934a321</a>)</li>
<li>enrich API rejection errors and reject unknown keys in closed sections (<a href="https://github.com/Vivswan/github-settings-as-code/commit/7a44e90bc15016d7926b812000f22043d1f3058f">7a44e90</a>)</li>
<li>first-class GraphQL operation layer (<a href="https://github.com/Vivswan/github-settings-as-code/commit/7d5279fcdae87c0985c9a6ecb637c89dcd38e2f7">7d5279f</a>)</li>
<li>let settings.yml choose the undeclared-resource policy per section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/372b8844f1274cdfac71d04b5c526d6d6714da8f">372b884</a>)</li>
<li>manage Actions artifact/log retention and cache limits (<a href="https://github.com/Vivswan/github-settings-as-code/commit/8014910b884aece9cc71f974cef26db4656da74f">8014910</a>)</li>
<li>manage code quality setup and check suite preferences (<a href="https://github.com/Vivswan/github-settings-as-code/commit/adab49e76316dfab7122b30c114d7bde1f69b1ba">adab49e</a>)</li>
<li>manage Copilot agents secrets and variables (<a href="https://github.com/Vivswan/github-settings-as-code/commit/1d839e1797f622da2cb01331a8ec395cd56dcf0b">1d839e1</a>)</li>
<li>manage deploy keys (<a href="https://github.com/Vivswan/github-settings-as-code/commit/a6f7ae1251177cd07c1ce6d0acc3176e3986f9b0">a6f7ae1</a>)</li>
<li>manage environment custom deployment protection rules (<a href="https://github.com/Vivswan/github-settings-as-code/commit/f752ce8626e98689902e4f83463816fe25636139">f752ce8</a>)</li>
<li>manage environment deployment branch-policy patterns (<a href="https://github.com/Vivswan/github-settings-as-code/commit/34eafe4e46dd12f6b17dfdf4987b7898270d1718">34eafe4</a>)</li>
<li>manage environment variables in the environments section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/1d272c355ed1b933080d1234b3925625ec1e1edb">1d272c3</a>)</li>
<li>manage environment, Dependabot, and Codespaces secrets (<a href="https://github.com/Vivswan/github-settings-as-code/commit/c8bbe75a91fadbfe241e152ab3fdcf3d52120309">c8bbe75</a>)</li>
<li>manage fork pull request workflow policies from the actions section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/cd2bfcfb332cd789cb4d8d55a7ca40daefcdfec8">cd2bfcf</a>)</li>
<li>manage Git LFS enablement from the repository section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/a0195faf6bc2a8df6e68437a38c35c6d419020bc">a0195fa</a>)</li>
<li>manage immutable releases from the repository section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/f2582f7b8d66d5d7db79fad6b2b0f70788baa590">f2582f7</a>)</li>
<li>manage pinned environments (<a href="https://github.com/Vivswan/github-settings-as-code/commit/c368c98a52ee5d0a35028e2501423316b5c65023">c368c98</a>)</li>
<li>manage repository Actions secrets (<a href="https://github.com/Vivswan/github-settings-as-code/commit/0f8ea4e0ba0ffc23802bfd608fc979b40045eaf2">0f8ea4e</a>)</li>
<li>manage repository Actions variables (<a href="https://github.com/Vivswan/github-settings-as-code/commit/780abf0ec19c50279cc2454606492101bfbdebf7">780abf0</a>)</li>
<li>manage repository custom property values (<a href="https://github.com/Vivswan/github-settings-as-code/commit/b5bf3ac547b0ad84ae19427cf2da06b35b3911fb">b5bf3ac</a>)</li>
<li>manage repository interaction limits (<a href="https://github.com/Vivswan/github-settings-as-code/commit/c8dd58d04de93da9f76168f985654e5d54646065">c8dd58d</a>)</li>
<li>manage repository secret scanning custom patterns (<a href="https://github.com/Vivswan/github-settings-as-code/commit/05f614c0a894e2a9599e81f03c7de593164ad9eb">05f614c</a>)</li>
<li>manage repository webhooks (<a href="https://github.com/Vivswan/github-settings-as-code/commit/85013d3d6437bd78357dd37547c1426c80fb449b">85013d3</a>)</li>
<li>manage required commit signatures in the branches section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/16bec9a328879af3a522e67fb80c86e50c4e6460">16bec9a</a>)</li>
<li>manage the Actions OIDC subject claim from the actions section (<a href="https://github.com/Vivswan/github-settings-as-code/commit/c4e712fd4b929ba6553f2e54c3f1b53b6fd7971b">c4e712f</a>)</li>
<li>manage the pull request creation cap and bypass list (<a href="https://github.com/Vivswan/github-settings-as-code/commit/e98fb3ad58b2f8b78d759480cf096a483678a741">e98fb3a</a>)</li>
<li>manage the sponsor button and issue creation policy (<a href="https://github.com/Vivswan/github-settings-as-code/commit/97111fb2fa66779f099e6daf3c0ac5c5b44b189f">97111fb</a>)</li>
<li>manage wildcard branch protection, force-push bypassers, and required deployments (<a href="https://github.com/Vivswan/github-settings-as-code/commit/085ac52683eaacbda1d974cf19f5a6e38f774b71">085ac52</a>)</li>
<li>move repo-owned CI and release logic to template extension points (<a href="https://github.com/Vivswan/github-settings-as-code/issues/12">#12</a>) (<a href="https://github.com/Vivswan/github-settings-as-code/commit/cdde9ccbf867af6d257ce26f5eac8180930b4ca9">cdde9cc</a>)</li>
<li>reconcile pending collaborator invitations (<a href="https://github.com/Vivswan/github-settings-as-code/commit/cb9218874d6a6956cb1a575ce64418ad8614c199">cb92188</a>)</li>
<li>rename to github-settings-as-code (<a href="https://github.com/Vivswan/github-settings-as-code/commit/9678ceef5375ce7a30f70107ef441a496cf8653b">9678cee</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>ci:</strong> cover src/report in the changed-sections selector and openapi cache key (<a href="https://github.com/Vivswan/github-settings-as-code/commit/a1c43023ab54ea3dca16dd61a2034d2b003756fd">a1c4302</a>)</li>
<li>declare dependabot default labels and realign SECURITY.md (<a href="https://github.com/Vivswan/github-settings-as-code/commit/aa89a230e6dbe0f823dc7998c21edbed0b167972">aa89a23</a>)</li>
<li>drop connections for real in the e2e mock, on bun 1.3.14 (<a href="https://github.com/Vivswan/github-settings-as-code/commit/791c4bfe668f02b1d72bdb8677f14fd390678ea5">791c4bf</a>)</li>
<li><strong>e2e:</strong> keep body-presence checks active for requestOffSpec rejections (<a href="https://github.com/Vivswan/github-settings-as-code/commit/43426a6cca49370f6200acef20dbe368af190106">43426a6</a>)</li>
<li>mark the secrets-and-vaults action pins for major-tag rewrites (<a href="https://github.com/Vivswan/github-settings-as-code/commit/9d1f616eaf368f959b1761945619ca1926ecc659">9d1f616</a>)</li>
<li>name every offender in errors and carry engine invariants in types (<a href="https://github.com/Vivswan/github-settings-as-code/commit/49b386a1313173fdcf376c7698852f497a355626">49b386a</a>)</li>
<li>preserve a rotated deploy key&rsquo;s live read_only flag (<a href="https://github.com/Vivswan/github-settings-as-code/commit/a36da82b4c2ca0a91549b40ca8a4a1e522b16bc4">a36da82</a>)</li>
<li>re-enable declared protection rules the API reports as disabled (<a href="https://github.com/Vivswan/github-settings-as-code/commit/b469a6fde4c32b20fe4abf4b895a0d4f525d39d6">b469a6f</a>)</li>
<li>reject invalid actions and repository declarations before any section writes (<a href="https://github.com/Vivswan/github-settings-as-code/commit/85be8efd6355326f3814616580d8ff6586e7cbe7">85be8ef</a>)</li>
<li>silence and label intentional error noise in green runs (<a href="https://github.com/Vivswan/github-settings-as-code/commit/a786ae682fc791c0be8fc1bc94881265d28c30ed">a786ae6</a>)</li>
<li>track secret-reference provenance structurally through the merge (<a href="https://github.com/Vivswan/github-settings-as-code/commit/e9c223e2f828aee777270939948093e3467618c9">e9c223e</a>)</li>
<li>unpad flow-mapping braces in the pins cap scenario (<a href="https://github.com/Vivswan/github-settings-as-code/commit/7b041fd13a4da8466f5b9c622993a04a7fc3ff73">7b041fd</a>)</li>
<li>write version-less secret scanning patterns the way the API allows (<a href="https://github.com/Vivswan/github-settings-as-code/commit/6fa0cefed39867bcd44d615da5e5bf0c22b237c1">6fa0cef</a>)</li>
</ul>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/rustscript-action/</link><pubDate>Tue, 11 Aug 2026 14:18:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.3.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is an interpreter that allows running Rust scripts without compiling them. It provides functionalities like running, validating, building, and cleaning Rust scripts. The action interprets a practical subset of the language and uses Rustc to validate files. It supports concurrency with #[tokio::main] scripts and caches compiled files for faster execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.3.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is an interpreter that allows running Rust scripts without compiling them. It provides functionalities like running, validating, building, and cleaning Rust scripts. The action interprets a practical subset of the language and uses Rustc to validate files. It supports concurrency with <code>#[tokio::main]</code> scripts and caches compiled files for faster execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.3.3...v0.3.4">https://github.com/VladasZ/rustscript/compare/v0.3.3...v0.3.4</a></p>
]]></content:encoded></item><item><title>install spaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/install-spaces/</link><pubDate>Tue, 11 Aug 2026 14:17:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/install-spaces/</guid><description>Version updated for https://github.com/work-spaces/install-spaces to version v0.20.8.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of Spaces, a popular cloud storage service, on a self-hosted runner. It simplifies the process of setting up Spaces by automating the creation and configuration of a new Space instance, making it easier for developers to manage their files securely in the cloud.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/install-spaces">https://github.com/work-spaces/install-spaces</a></strong> to version <strong>v0.20.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-spaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the installation of Spaces, a popular cloud storage service, on a self-hosted runner. It simplifies the process of setting up Spaces by automating the creation and configuration of a new Space instance, making it easier for developers to manage their files securely in the cloud.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.20.8 by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/44">https://github.com/work-spaces/install-spaces/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/install-spaces/compare/v0.20.7...v0.20.8">https://github.com/work-spaces/install-spaces/compare/v0.20.7...v0.20.8</a></p>
]]></content:encoded></item><item><title>spaces checkout run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/spaces-checkout-run/</link><pubDate>Tue, 11 Aug 2026 14:17:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/spaces-checkout-run/</guid><description>Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.20.8.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of checking out a specific branch or revision from a GitHub repository using the spaces CLI and then executing a build command within that workspace. It simplifies the setup by automatically installing the necessary tools and handling authentication through a GitHub token, making it easier for developers to automate space checkout and run workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/spaces-checkout-run">https://github.com/work-spaces/spaces-checkout-run</a></strong> to version <strong>v0.20.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spaces-checkout-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of checking out a specific branch or revision from a GitHub repository using the <code>spaces</code> CLI and then executing a build command within that workspace. It simplifies the setup by automatically installing the necessary tools and handling authentication through a GitHub token, making it easier for developers to automate space checkout and run workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.20.8 by @tyler-gilbert in <a href="https://github.com/work-spaces/spaces-checkout-run/pull/37">https://github.com/work-spaces/spaces-checkout-run/pull/37</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/spaces-checkout-run/compare/v0.20.7...v0.20.8">https://github.com/work-spaces/spaces-checkout-run/compare/v0.20.7...v0.20.8</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/b.ia-accessibility-checker/</link><pubDate>Tue, 11 Aug 2026 14:16:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The B.IA GitHub Action automates accessibility checks in a CI/CD pipeline by defining an audience and percentage of WCAG guidelines to be met. It uses AI to analyze code against these guidelines, providing feedback or blocking pull requests based on compliance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The B.IA GitHub Action automates accessibility checks in a CI/CD pipeline by defining an audience and percentage of WCAG guidelines to be met. It uses AI to analyze code against these guidelines, providing feedback or blocking pull requests based on compliance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>Zuke Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/zuke-build/</link><pubDate>Tue, 11 Aug 2026 14:15:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/11/zuke-build/</guid><description>Version updated for https://github.com/zuke-build/zuke to version core-v1.38.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action provides a tagged template for running processes with sensible defaults such as throwing on failure and capturing output, ensuring injection safety. It simplifies the process of executing commands and scripts in CI/CD workflows by abstracting away common configuration options, making it easier to focus on task logic without distractions related to environment setup or error handling.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zuke-build/zuke">https://github.com/zuke-build/zuke</a></strong> to version <strong>core-v1.38.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zuke-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action provides a tagged template for running processes with sensible defaults such as throwing on failure and capturing output, ensuring injection safety. It simplifies the process of executing commands and scripts in CI/CD workflows by abstracting away common configuration options, making it easier to focus on task logic without distractions related to environment setup or error handling.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1380-2026-08-11"><a href="https://github.com/zuke-build/zuke/compare/core-v1.37.0...core-v1.38.0">1.38.0</a> (2026-08-11)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>core:</strong> scope run recovery to the build that owns the run (<a href="https://github.com/zuke-build/zuke/issues/328">#328</a>) (<a href="https://github.com/zuke-build/zuke/commit/0aabb2b9c0d5149c17201ce755d1b62d1106a68f">0aabb2b</a>)</li>
</ul>
]]></content:encoded></item><item><title>Oculum Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/oculum-security-scan/</link><pubDate>Mon, 10 Aug 2026 21:44:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/oculum-security-scan/</guid><description>Version updated for https://github.com/OculumDev/oculum-action to version 1.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is an AI-based security scanner designed to detect common vulnerabilities in LLM-powered applications. It automatically detects prompt injection, hardcoded secrets, SQL injection, XSS, and more using both traditional SAST techniques and AI-driven validation. The action integrates seamlessly with GitHub to provide PR comments and inline annotations on code changes, making it easy for developers to identify and fix security issues early.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OculumDev/oculum-action">https://github.com/OculumDev/oculum-action</a></strong> to version <strong>1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oculum-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is an AI-based security scanner designed to detect common vulnerabilities in LLM-powered applications. It automatically detects prompt injection, hardcoded secrets, SQL injection, XSS, and more using both traditional SAST techniques and AI-driven validation. The action integrates seamlessly with GitHub to provide PR comments and inline annotations on code changes, making it easy for developers to identify and fix security issues early.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Early Release of Oculum Security Scanner</p>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/odin-scan-smart-contract-security/</link><pubDate>Mon, 10 Aug 2026 21:42:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates AI-powered smart contract security analysis for CosmWasm, Solana, and EVM projects. It integrates seamlessly into your workflow to catch vulnerabilities before they reach production by uploading SARIF files for native security alerts, posting summary comments on pull requests, and triggering on-demand scans through PR comments. The action supports multi-platform detection and configurable thresholds for severity levels and output visibility.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates AI-powered smart contract security analysis for CosmWasm, Solana, and EVM projects. It integrates seamlessly into your workflow to catch vulnerabilities before they reach production by uploading SARIF files for native security alerts, posting summary comments on pull requests, and triggering on-demand scans through PR comments. The action supports multi-platform detection and configurable thresholds for severity levels and output visibility.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial Release</p>
<p>AI-powered smart contract security analysis, now integrated directly into your GitHub workflow.</p>
<p>✨ Features</p>
<p>Multi-Platform Support</p>
<ul>
<li>CosmWasm - Rust-based smart contracts for Cosmos SDK</li>
<li>Solana (SVM) - Anchor and native Solana programs</li>
<li>EVM - Solidity and Vyper contracts</li>
<li>Auto-detection - Automatically identifies platform from your repo</li>
</ul>
<p>GitHub Integration</p>
<ul>
<li>Code Scanning - SARIF upload for native security alerts in the Security tab</li>
<li>PR Comments - Severity summary and top findings posted directly on pull requests</li>
<li>Inline Annotations - Critical/high findings appear as errors, medium/low as warnings on diffs</li>
<li>Artifact Upload - Full JSON report available as workflow artifact</li>
</ul>
<p>Customization</p>
<ul>
<li>Severity Thresholds - Fail builds at critical, high, medium, or low severity</li>
<li>Platform Override - Force specific platform detection when auto-detect isn&rsquo;t enough</li>
<li>Timeout Control - Configurable analysis timeout (default: 30 minutes)</li>
<li>Flexible Triggers - Run on push, PR, schedule, or manual dispatch</li>
</ul>
<p>🚀 Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Security Scan</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&#39;on&#39;</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">main</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">security-events</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">api-key</span>: <span style="color:#e6db74">&#39;${{ secrets.ODIN_SCAN_API_KEY }}&#39;</span>
</span></span></code></pre></div><p>📋 Requirements</p>
<ul>
<li>Odin Scan Pro subscription - Required for API access</li>
<li>API Key - Generate at <a href="https://odinscan.ai/dashboard/settings">https://odinscan.ai/dashboard/settings</a></li>
<li>GitHub Permissions - contents: read, security-events: write (for SARIF), pull-requests: write (for
comments)</li>
</ul>
<p>🔧 Configuration</p>
<p>All Inputs</p>
<p>| ┌────────────────────┬─────────────────────┬──────────────────────────────────────────────┐ |
| │       Input        │       Default       │                 Description                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ api-key            │ Required            │ Your Odin Scan API key (odin_sk_*)           │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ platform           │ auto                │ Target platform: auto, cosmwasm, solana, evm │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ severity-threshold │ high                │ Fail at: critical, high, medium, low, none   │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ fail-on-findings   │ true                │ Whether to fail workflow on findings         │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ comment-on-pr      │ true                │ Post summary comment on PRs                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-sarif       │ true                │ Upload SARIF to Code Scanning                │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-artifact    │ true                │ Upload full report as artifact               │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ timeout            │ 1800                │ Max analysis wait time (seconds)             │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ github-token       │ ${{ github.token }} │ Token for PR comments and SARIF              │ |
| └────────────────────┴─────────────────────┴──────────────────────────────────────────────┘ |</p>
<p>All Outputs</p>
<ul>
<li>analysis-id - Unique analysis identifier</li>
<li>status - Analysis status (completed, failed)</li>
<li>total-findings - Total number of findings</li>
<li>critical-count, high-count, medium-count, low-count - Counts by severity</li>
<li>report-url - Link to full report on Odin Scan</li>
<li>sarif-file - Path to generated SARIF file</li>
</ul>
<p>📝 Example Workflows</p>
<p>Basic (Auto-detect)</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span></code></pre></div><p>EVM with Medium Threshold</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">platform</span>: <span style="color:#ae81ff">evm</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">severity-threshold</span>: <span style="color:#ae81ff">medium</span>
</span></span></code></pre></div><p>Only on Solidity Changes</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#39;**.sol&#39;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">foundry.toml</span>
</span></span></code></pre></div><p>🔒 Security &amp; Privacy</p>
<ul>
<li>All API communication over HTTPS (TLS 1.2+)</li>
<li>API keys automatically masked in logs</li>
<li>No data stored by the action (stateless)</li>
<li>See <a href="https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md">https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md</a> for details</li>
</ul>
<p>📖 Documentation</p>
<ul>
<li>Action README - <a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></li>
<li>Odin Scan Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
<li>Get API Key - <a href="https://app.odinscan.ai/settings">https://app.odinscan.ai/settings</a></li>
</ul>
<p>🐛 Known Limitations</p>
<ul>
<li>Private repos - Requires github-token with repo access</li>
<li>Large repos - May need increased timeout for complex codebases</li>
<li>Code Scanning - Requires GitHub Advanced Security on private repos</li>
</ul>
<p>🙏 Support</p>
<ul>
<li>Issues - <a href="https://github.com/Odin-Scan/odin-scan-action/issues">https://github.com/Odin-Scan/odin-scan-action/issues</a></li>
<li>Email - <a href="mailto:support@odinscan.ai">support@odinscan.ai</a></li>
<li>Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
</ul>
<hr>
<p>Full Changelog: <a href="https://github.com/Odin-Scan/odin-scan-action/commits/v1">https://github.com/Odin-Scan/odin-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>Run on OnMCU</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/run-on-onmcu/</link><pubDate>Mon, 10 Aug 2026 21:41:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/run-on-onmcu/</guid><description>Version updated for https://github.com/onmcu/onmcu-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the flashing and running of firmware on real MCU hardware using OnMCU, ensuring that the workflow fails if the hardware run fails. It installs the OnMCU CLI, writes a CI config, and invokes onmcu run in a single step, providing minimal overhead. The action is designed to handle various inputs such as board identifier, firmware file, API key, and more, with sensible defaults for missing values.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/onmcu/onmcu-action">https://github.com/onmcu/onmcu-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-on-onmcu">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the flashing and running of firmware on real MCU hardware using OnMCU, ensuring that the workflow fails if the hardware run fails. It installs the OnMCU CLI, writes a CI config, and invokes <code>onmcu run</code> in a single step, providing minimal overhead. The action is designed to handle various inputs such as board identifier, firmware file, API key, and more, with sensible defaults for missing values.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Config value <code>timeout_seconds</code> was renamed to <code>job_timeout_seconds</code> in <code>0.2.0</code> of <a href="https://github.com/onmcu/onmcu-rs">https://github.com/onmcu/onmcu-rs</a></p>
]]></content:encoded></item><item><title>quantakrypto Quantum Readiness Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/quantakrypto-quantum-readiness-scan/</link><pubDate>Mon, 10 Aug 2026 21:40:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/quantakrypto-quantum-readiness-scan/</guid><description>Version updated for https://github.com/quantakrypto/pqc-tools to version v0.11.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action action (@quantakrypto/action) automates the process of scanning codebases for quantum-vulnerable cryptography using the qScan tool. It integrates seamlessly with CI pipelines, generates SARIF files for upload, annotates code diffs, and fails the build if new quantum vulnerabilities are detected. This ensures that projects remain post-quantum ready throughout development and deployment cycles.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quantakrypto/pqc-tools">https://github.com/quantakrypto/pqc-tools</a></strong> to version <strong>v0.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quantakrypto-quantum-readiness-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <strong>action</strong> (<code>@quantakrypto/action</code>) automates the process of scanning codebases for quantum-vulnerable cryptography using the <code>qScan</code> tool. It integrates seamlessly with CI pipelines, generates SARIF files for upload, annotates code diffs, and fails the build if new quantum vulnerabilities are detected. This ensures that projects remain post-quantum ready throughout development and deployment cycles.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Minor. User-facing fixes to the GitHub Action and the runtime it declares. Nothing existing changes shape, and no exit code moves.</p>
<h2 id="fixed">Fixed</h2>
<p><strong>A URL in the Action&rsquo;s <code>probe-target</code> was refused, despite the docs.</strong> Both <code>action.yml</code> files have always said &ldquo;A full URL is accepted and reduced to its host&rdquo;. It was not: <code>normalizeProbeTarget</code> existed, was exported, was documented and had its own passing tests, and nothing called it. It is now called, and narrowed so that calling it is safe. Only a string that already carries a scheme is treated as a URL, and only when its authority has no userinfo, so <code>our-api.example.com@evil.test</code> is still refused rather than silently resolving to <code>evil.test</code> under a manufactured <code>i-own-this</code>.</p>
<p><strong>qProbe reported the wrong tool version in every JSON report and CBOM.</strong> <code>VERSION</code> said <code>0.7.0</code> while the package was at <code>0.10.0</code>, kept honest only by a comment. Every qProbe report and endpoint CBOM since 0.8.0 carried a <code>toolVersion</code> that lies about the build, and that is evidence data. The lockstep test <code>@quantakrypto/core</code> has always had is now on qProbe too.</p>
<p><strong>The <code>setOutput</code> fallback wrote a removed workflow command.</strong> With no <code>$GITHUB_OUTPUT</code> it emitted <code>::set-output</code>, which GitHub removed from the runner in 2023 and rejects, spelled with the wrong parameter. Our own unit tests call it, so those commands reached the real runner&rsquo;s stdout during CI, and whether it parsed them came down to output interleaving.</p>
<h2 id="added">Added</h2>
<p><strong>The result payload carries each finding&rsquo;s <code>remediation</code>.</strong> Every detector produces one, and it rides in the JSON report and the SARIF <code>help</code> text, but it was dropped at the payload boundary. The unrunnable-conformance finding splits accordingly: <code>message</code> says what happened, <code>remediation</code> says what to do.</p>
<h2 id="changed">Changed</h2>
<p><strong>The Action runs on Node 24.</strong> Both <code>action.yml</code> files declared <code>node20</code>, which GitHub deprecated and already force-runs on 24. The re-bundled <code>dist/index.js</code> is byte-identical, so nothing needed downleveling.</p>
<h2 id="docs">Docs</h2>
<p>The ready-to-copy <code>examples/quantum-readiness.yml</code> was syntactically broken and nothing checked it; a supply-chain gate now validates the examples and requires our own action to be pinned to a bare moving major. The Action README documents <code>checks</code>, <code>ignore</code>/<code>include</code>, and what the platform callback does and does not do. Every path example is <code>.quantakrypto/</code>, stated as the convention in <code>docs/CONFIG.md</code>.</p>
<p>The short-lived <code>v2</code> Action tag is <strong>deleted</strong>. <code>checks</code> defaults to <code>scan</code>, so it was never a breaking change and never earned a new major. <code>uses: quantakrypto/pqc-tools/packages/action@v1</code> is the ref, and it now points here.</p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/agentauditkit-mcp-security-scan/</link><pubDate>Mon, 10 Aug 2026 21:38:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.72.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner designed to audit AI agent pipelines offline and deterministically. It identifies misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. Unlike hosted scanners, AgentAuditKit runs fully offline without network calls, ensuring reproducibility with a 0% variance in findings across multiple runs. Additionally, it produces auditor-ready compliance-evidence packs using SARIF for GitHub Security tab and PDF reports mapped to 12 security frameworks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.72</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>AgentAuditKit is a security scanner designed to audit AI agent pipelines offline and deterministically. It identifies misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. Unlike hosted scanners, AgentAuditKit runs fully offline without network calls, ensuring reproducibility with a 0% variance in findings across multiple runs. Additionally, it produces auditor-ready compliance-evidence packs using SARIF for GitHub Security tab and PDF reports mapped to 12 security frameworks.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.72
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.72
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.72</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.71...v0.3.72">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.71...v0.3.72</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/custom-amazon-bedrock-agent-action/</link><pubDate>Mon, 10 Aug 2026 21:37:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze PR files and provide feedback tailored to specific requirements. It supports custom prompts, memory persistence across PRs, integration with Knowledge Bases for context-aware insights, and seamless GitHub integration with PR comments. This tool enhances code quality, security assessments, and performance optimizations by leveraging advanced AI models within the AWS ecosystem.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze PR files and provide feedback tailored to specific requirements. It supports custom prompts, memory persistence across PRs, integration with Knowledge Bases for context-aware insights, and seamless GitHub integration with PR comments. This tool enhances code quality, security assessments, and performance optimizations by leveraging advanced AI models within the AWS ecosystem.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Automated Changelog Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/automated-changelog-generator/</link><pubDate>Mon, 10 Aug 2026 21:36:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/automated-changelog-generator/</guid><description>Version updated for https://github.com/shazib-summar/automated-changelog-gh to version v0.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “Automated Changelog” generates and updates CHANGELOG.md files based on git tags and commit history. It groups commits using Conventional Commits and renders them in Keep a Changelog format. The action can create an entry for a new release or regenerate the entire changelog, linking versions to GitHub compare views and commits/PRs to their pages. Users can specify whether to commit the updated changelog back to the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shazib-summar/automated-changelog-gh">https://github.com/shazib-summar/automated-changelog-gh</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/automated-changelog-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;Automated Changelog&rdquo; generates and updates <code>CHANGELOG.md</code> files based on git tags and commit history. It groups commits using Conventional Commits and renders them in Keep a Changelog format. The action can create an entry for a new release or regenerate the entire changelog, linking versions to GitHub compare views and commits/PRs to their pages. Users can specify whether to commit the updated changelog back to the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(changelog): update changelog for v0.2.0 by @github-actions[bot] in <a href="https://github.com/shazib-summar/automated-changelog-gh/pull/22">https://github.com/shazib-summar/automated-changelog-gh/pull/22</a></li>
<li>chore: Make tag required field for manual runs by @shazib-summar in <a href="https://github.com/shazib-summar/automated-changelog-gh/pull/23">https://github.com/shazib-summar/automated-changelog-gh/pull/23</a></li>
<li>docs: update readme about backfilling changelog by @shazib-summar in <a href="https://github.com/shazib-summar/automated-changelog-gh/pull/24">https://github.com/shazib-summar/automated-changelog-gh/pull/24</a></li>
<li>Allow teams to be added as reviewers by @shazib-summar in <a href="https://github.com/shazib-summar/automated-changelog-gh/pull/26">https://github.com/shazib-summar/automated-changelog-gh/pull/26</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/shazib-summar/automated-changelog-gh/compare/v0.2.0...v0.3.0">https://github.com/shazib-summar/automated-changelog-gh/compare/v0.2.0...v0.3.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/sherpa.sh/</link><pubDate>Mon, 10 Aug 2026 21:34:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven infrastructure automation tool that simplifies cloud deployment by allowing developers to describe their needs in plain English. It automatically configures servers, DNS, SSL certificates, CDN, databases, backups, and load balancing using natural language prompts. Key capabilities include open-source transparency, support for multiple clouds and frameworks, and the ability to deploy any application seamlessly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven infrastructure automation tool that simplifies cloud deployment by allowing developers to describe their needs in plain English. It automatically configures servers, DNS, SSL certificates, CDN, databases, backups, and load balancing using natural language prompts. Key capabilities include open-source transparency, support for multiple clouds and frameworks, and the ability to deploy any application seamlessly.</p>
]]></content:encoded></item><item><title>Muninn Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/muninn-security-scanner/</link><pubDate>Mon, 10 Aug 2026 21:33:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/muninn-security-scanner/</guid><description>Version updated for https://github.com/skaldlab/muninn to version v0.3.8.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Muninn is an open-source security scanner for GitHub Actions pipelines and self-hosted CI that uses multiple best-in-class scanners to detect vulnerabilities in code, configuration, dependencies, and infrastructure. It normalizes the results into a single format and provides detailed reporting options including PR comments, SARIF uploads, and structured JSON, allowing users to easily identify and manage security issues across their workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skaldlab/muninn">https://github.com/skaldlab/muninn</a></strong> to version <strong>v0.3.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/muninn-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Muninn is an open-source security scanner for GitHub Actions pipelines and self-hosted CI that uses multiple best-in-class scanners to detect vulnerabilities in code, configuration, dependencies, and infrastructure. It normalizes the results into a single format and provides detailed reporting options including PR comments, SARIF uploads, and structured JSON, allowing users to easily identify and manage security issues across their workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="changelog">Changelog</h1>
<h2 id="unreleased">[Unreleased]</h2>
<h3 id="changed">Changed</h3>
<h2 id="038---2026-08-10">[0.3.8] - 2026-08-10</h2>
<h3 id="changed-1">Changed</h3>
<ul>
<li>Docker image scanner update: osv-scanner 2.5.0 (full osv-scalibr pipeline;
checkov remains at 3.2.531 pending aiohttp cap lift).</li>
<li>GitPython floor raised to &gt;=3.1.58 for GHSA-hmq2-w58f-27jc and related
3.1.58 hardening advisories (path traversal / unguarded git option sinks).</li>
</ul>
<h2 id="037---2026-08-04">[0.3.7] - 2026-08-04</h2>
<h3 id="changed-2">Changed</h3>
<ul>
<li>GitPython floor raised to &gt;=3.1.55 for GHSA-94p4-4cq8-9g67 (incomplete
expandvars fix in create_remote / Remote.add).</li>
<li>cryptography floor raised to &gt;=50.0.0 for GHSA-g6cj-pr64-35w5
(CVE-2026-69247: PKCS#7 EnvelopedData Bleichenbacher oracle).</li>
<li>aiohttp floor raised to &gt;=3.14.3; scanner lockfile recompiled with click 8.3.3
and mcp 1.28.1 security overrides.</li>
<li>Docker image scanner updates: trivy 0.73.0, semgrep 1.172.0, zizmor 1.29.0
(checkov remains at 3.2.531 pending aiohttp cap lift; 3.2.533+ also caps
<code>aiohttp&lt;3.14</code>).</li>
</ul>
<h2 id="036---2026-07-22">[0.3.6] - 2026-07-22</h2>
<h3 id="changed-3">Changed</h3>
<ul>
<li>Docker image scanner updates: zizmor 1.28.0 (replaces yanked 1.27.0);
GitPython floor raised to &gt;=3.1.52 for checkov-transitive GHSA highs
(checkov remains at 3.2.531 pending aiohttp cap lift).</li>
<li>Go toolchain bumped to 1.26.5.</li>
</ul>
<h2 id="035---2026-07-20">[0.3.5] - 2026-07-20</h2>
<h3 id="changed-4">Changed</h3>
<ul>
<li>Docker image scanner updates: semgrep 1.170.0, zizmor 1.27.0 (checkov
remains at 3.2.531 pending aiohttp cap lift).</li>
</ul>
<h2 id="034---2026-07-04">[0.3.4] - 2026-07-04</h2>
<h3 id="changed-5">Changed</h3>
<ul>
<li>Docker image scanner updates: osv-scanner 2.4.0, trivy 0.72.0, semgrep
1.168.0, zizmor 1.26.1 (checkov remains at 3.2.531 pending aiohttp cap lift).</li>
</ul>
<h2 id="033---2026-06-17">[0.3.3] - 2026-06-17</h2>
<h3 id="changed-6">Changed</h3>
<ul>
<li>Trivy default severity is now all levels (<code>UNKNOWN</code> through <code>CRITICAL</code>) instead
of <code>CRITICAL</code> and <code>HIGH</code> only. osv-scanner and trivy now overlap on
medium/low advisories by default so cross-scanner dedup and <code>Detected by</code>
work without extra config. Consumers can narrow the Trivy scan with
<code>scanners.trivy.severity</code>; <code>fail-on</code> still controls which findings fail the run.</li>
</ul>
<h2 id="032---2026-06-16">[0.3.2] - 2026-06-16</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Suppressions with <code>tool</code> and/or <code>rule-id</code> are now applied. Previously only <code>id</code>
(path substring) and <code>fingerprint</code> matchers worked; tool+rule-id entries
parsed from <code>muninn.yml</code> but silently no-op&rsquo;d.</li>
</ul>
<h2 id="031---2026-06-16">[0.3.1] - 2026-06-16</h2>
<h3 id="fixed-1">Fixed</h3>
<ul>
<li>Poutine v1.x JSON parsing: findings from poutine 1.1.6+ (<code>rule_id</code>, <code>meta</code>,
<code>rules</code>, <code>blobshas</code>) now populate title, rule, and file in PR comments instead
of empty shells (<code>File: :0</code>, `Rule: ``) (#41).</li>
<li>Actionlint PR comments: fall back to <code>kind</code> (e.g. <code>expression</code>) when
<code>rule.name</code> is absent; omit empty Rule lines.</li>
<li>Poutine injection findings: render <code>injection_sources</code> as formatted
<strong>Sources</strong> instead of plain <code>meta.details</code> text.</li>
</ul>
<h3 id="changed-7">Changed</h3>
<ul>
<li>PR comment layout: shared field helpers; non-dependency findings follow
File → Rule → optional extras → description; single-scanner dependency
findings use <strong>File</strong> instead of a redundant <strong>Source</strong> line.</li>
</ul>
<h2 id="030---2026-06-16">[0.3.0] - 2026-06-16</h2>
<h3 id="added">Added</h3>
<ul>
<li>Cross-scanner deduplication by advisory id: findings that report the same
CVE/GHSA for the same package from different scanners (e.g. OSV-Scanner from a
lockfile and Trivy from a container layer) are now collapsed into a single
finding. The contributing scanners are recorded in a new <code>detected_by</code> field
(surfaced in the JSON report, the PR comment&rsquo;s &ldquo;Detected by&rdquo; line, and a
<code>detectedBy</code> SARIF result property). A CVE is preferred over GHSA so the same
vulnerability converges on one id across scanners (#27).</li>
<li>Richer dependency finding rendering: aggregated dependency findings now appear
under a neutral <code>[dependency]</code> heading (instead of a single scanner&rsquo;s name)
with <code>Package</code>, <code>Advisory</code> (including the shared CVE), <code>Detected by</code>, and a
<code>Sources</code> list showing where each scanner observed it. A new <code>sources</code> field on
the finding (per-scanner <code>tool</code> + <code>file</code>) backs the JSON report (#27).</li>
</ul>
<h3 id="fixed-2">Fixed</h3>
<ul>
<li>PR comment rendering: scanner descriptions are flattened to a single line and
their Markdown (code fences, headings) neutralized, so an unbalanced ``` fence
can no longer swallow later findings and the footer into a code block.</li>
</ul>
<h2 id="020---2026-06-15">[0.2.0] - 2026-06-15</h2>
<p>Supply-chain hardening for the scanner image and signed, verifiable releases
(closes #30).</p>
<h3 id="added-1">Added</h3>
<ul>
<li>Pinned every bundled binary scanner to an exact version with SHA256 checksum
verification in the Docker image — gitleaks, zizmor, actionlint, poutine,
osv-scanner, trivy (#31)</li>
<li>Hash-locked the pip-installed scanners (semgrep, checkov, zizmor) via a fully
pinned, multi-arch <code>requirements-scanners.txt</code> installed with
<code>pip --require-hashes</code> (#33)</li>
<li>Renovate configuration to auto-PR scanner version bumps, with a CI job that
refreshes the pinned checksums (#32)</li>
<li>Keyless (OIDC) cosign signing of the published container image and of the
release binary checksums (Sigstore bundle <code>checksums.txt.sigstore.json</code>) (#34)</li>
<li>SBOM (SPDX) attached to every release and as an image attestation (#34)</li>
<li>Max-mode SLSA build provenance attestation on the container image (#34)</li>
<li>&ldquo;Verifying releases&rdquo; instructions in the README (#34)</li>
</ul>
<h3 id="changed-8">Changed</h3>
<ul>
<li>Pinned checkov to 3.2.531 (from 3.3.1) so its dependency tree resolves the
patched aiohttp 3.14.1 and drops the unfixable python-ecdsa Minerva
dependency that checkov 3.3.x introduced. Revisit when a newer checkov lifts
its <code>aiohttp&lt;3.14</code> cap (#33)</li>
</ul>
<h2 id="010---2026-06-14">[0.1.0] - 2026-06-14</h2>
<h3 id="added-2">Added</h3>
<ul>
<li>8 security scanners: gitleaks, zizmor, actionlint, poutine,
semgrep, osv-scanner, trivy, checkov</li>
<li>Unified Finding schema with fingerprinting</li>
<li>Three output formats: SARIF 2.1.0, JSON, GitHub PR comment</li>
<li>GitHub Action with outputs</li>
<li>Config-driven scanner behavior via muninn.yml</li>
<li>Suppression management with expiry dates</li>
<li>90%+ test coverage enforced in CI</li>
<li>Integration tests with real scanner binaries</li>
<li>Self-scan: Muninn scans itself on every PR</li>
</ul>
<p>Built by Skald Lab — skaldlab.dev</p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/smyklot/</link><pubDate>Mon, 10 Aug 2026 21:32:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.18.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges based on CODEOWNERS. It uses emojis to approve or merge PRs, ensuring only authorized users can perform these actions. The app also supports multiple command formats, handles reaction-based commands, and provides feedback through emoji reactions and comments for approval and merge status.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.18.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges based on CODEOWNERS. It uses emojis to approve or merge PRs, ensuring only authorized users can perform these actions. The app also supports multiple command formats, handles reaction-based commands, and provides feedback through emoji reactions and comments for approval and merge status.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1180-2026-08-10"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.17.0...v1.18.0">1.18.0</a> (2026-08-10)</h2>
<h2 id="smyklot-v1180">Smyklot v1.18.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.18.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>48e001eef7d03872cf90c45bcd38fdeb95306161 chore(release): bump version to 1.18.0</li>
<li>e4935da3a73cb75c4303a1694d4431dd44b64c9a feat(panel): refine data table interactions (#178)</li>
<li>3629b3b2a9ad1062f0a18e501ac7a78cbc1f3434 chore(deps): lock file maintenance (#177)</li>
</ul>
]]></content:encoded></item><item><title>Custom Version Bumper</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/custom-version-bumper/</link><pubDate>Mon, 10 Aug 2026 21:31:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/custom-version-bumper/</guid><description>Version updated for https://github.com/so1omon563/custom-semver-bumper to version v1.0.5.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action Custom Version Bumper automatically tags every merge commit with a semver-compliant Git tag. It supports bumping based on commit message markers, pre-release tags, and can default to a patch bump if no marker is present. The action handles version numbers, supports Conventional Commits, and allows for customization of tag prefixes and defaults.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/so1omon563/custom-semver-bumper">https://github.com/so1omon563/custom-semver-bumper</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>14</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-version-bumper">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>Custom Version Bumper</code> automatically tags every merge commit with a semver-compliant Git tag. It supports bumping based on commit message markers, pre-release tags, and can default to a patch bump if no marker is present. The action handles version numbers, supports Conventional Commits, and allows for customization of tag prefixes and defaults.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li>preserve post-merge release trigger (#9) (<code>949dc37</code>)</li>
<li>harden marker detection and issue reporting #patch #release (#8) (<code>9b08b31</code>)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Mon, 10 Aug 2026 21:29:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of deploying a Docker Swarm service. It ensures that all necessary dependencies are installed using npm ci, bundles the application, and commits the built files to the repository. This helps maintain a clean build environment and ensures consistent deployment across different environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of deploying a Docker Swarm service. It ensures that all necessary dependencies are installed using <code>npm ci</code>, bundles the application, and commits the built files to the repository. This helps maintain a clean build environment and ensures consistent deployment across different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/ssg-static-site-generator/</link><pubDate>Mon, 10 Aug 2026 21:29:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.24.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast and powerful static site generator written in Go. It automates the process of converting Markdown with YAML frontmatter into clean URLs, templates, feeds, search, image processing, and deployment. Key capabilities include built-in themes, template engines, SEO metadata, webP conversion, local server for automatic rebuilds, and native deployment to various platforms such as GitHub Pages, Netlify, Vercel, and FTP/SFTP.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.24</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast and powerful static site generator written in Go. It automates the process of converting Markdown with YAML frontmatter into clean URLs, templates, feeds, search, image processing, and deployment. Key capabilities include built-in themes, template engines, SEO metadata, webP conversion, local server for automatic rebuilds, and native deployment to various platforms such as GitHub Pages, Netlify, Vercel, and FTP/SFTP.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release 1.8.24 by @spagu in <a href="https://github.com/spagu/ssg/pull/112">https://github.com/spagu/ssg/pull/112</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.23...v1.8.24">https://github.com/spagu/ssg/compare/v1.8.23...v1.8.24</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/classroom-to-sheets-integration/</link><pubDate>Mon, 10 Aug 2026 21:28:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates with Google Sheets to automatically send assignment results from GitHub Classroom. It automates the process of updating a Google Sheet with students’ scores and names based on data provided by other GitHub Actions steps that use classroom-resources/autograding-command-grader@v1. The action requires Google API credentials, a shared Google sheet, and specific secrets to be set up in your organization.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates with Google Sheets to automatically send assignment results from GitHub Classroom. It automates the process of updating a Google Sheet with students&rsquo; scores and names based on data provided by other GitHub Actions steps that use <code>classroom-resources/autograding-command-grader@v1</code>. The action requires Google API credentials, a shared Google sheet, and specific secrets to be set up in your organization.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>Gemara Catalog Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/gemara-catalog-validator/</link><pubDate>Mon, 10 Aug 2026 21:27:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/gemara-catalog-validator/</guid><description>Version updated for https://github.com/sshiells-scottlogic/gemara-catalog-validator to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Gemara Catalog Validator tool checks the semantic rules of Gemara source catalogs to ensure they are correctly structured and free of common mistakes such as unresolved references, duplicate IDs, incorrect prefixes, mismatched nesting structures, and orphan mappings. It provides inline annotations in GitHub pull requests, helping developers identify and fix issues before merging. The tool is project-agnostic and can be used for any repository that authors Gemara catalogs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sshiells-scottlogic/gemara-catalog-validator">https://github.com/sshiells-scottlogic/gemara-catalog-validator</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gemara-catalog-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Gemara Catalog Validator tool checks the semantic rules of Gemara source catalogs to ensure they are correctly structured and free of common mistakes such as unresolved references, duplicate IDs, incorrect prefixes, mismatched nesting structures, and orphan mappings. It provides inline annotations in GitHub pull requests, helping developers identify and fix issues before merging. The tool is project-agnostic and can be used for any repository that authors Gemara catalogs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>8cd8482339765465379df933e4e11ba619b79025 fix: show file:line:col in error output so findings are locatable (#11)</li>
</ul>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/setup-tombi/</link><pubDate>Mon, 10 Aug 2026 21:25:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.10.
This action is used across all versions by 144 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi in your GitHub Actions workflow, allowing you to manage TOML configuration files with a command-line interface. It provides options to install specific versions of Tombi from the repository or use lock files for dependency management. Additionally, it allows for checksum verification of downloaded archives and executable binaries to ensure integrity.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.2.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>144</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up Tombi in your GitHub Actions workflow, allowing you to manage TOML configuration files with a command-line interface. It provides options to install specific versions of Tombi from the repository or use lock files for dependency management. Additionally, it allows for checksum verification of downloaded archives and executable binaries to ensure integrity.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.2.10">tombi v1.2.10</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.10">https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.10</a></p>
]]></content:encoded></item><item><title>grype_me</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/grype_me/</link><pubDate>Mon, 10 Aug 2026 21:23:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/grype_me/</guid><description>Version updated for https://github.com/TomTonic/grype_me to version v1.3.19-release.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The grype_me GitHub Action automates the scanning of project supply chains for known vulnerabilities using Anchore Grype. It provides a simple, quick way to generate detailed badge reports and integrates seamlessly with GitHub workflows. The action runs on a daily basis to update security badges, ensuring developers are aware of potential vulnerabilities in their projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TomTonic/grype_me">https://github.com/TomTonic/grype_me</a></strong> to version <strong>v1.3.19-release</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/grype_me">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The grype_me GitHub Action automates the scanning of project supply chains for known vulnerabilities using Anchore Grype. It provides a simple, quick way to generate detailed badge reports and integrates seamlessly with GitHub workflows. The action runs on a daily basis to update security badges, ensuring developers are aware of potential vulnerabilities in their projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v1319-release">v1.3.19-release</h1>
<h2 id="source-code-updates">Source Code Updates</h2>
<ul>
<li><strong><code>cloudflare/circl</code> 1.6.4 → 1.6.5.</strong> A large security-hardening release (43 merged PRs) for CIRCL, the crypto library pulled in transitively via <code>go-git</code>&rsquo;s SSH support. No CVE ID has been assigned, but the release fixes multiple denial-of-service-style panics on malformed input (invalid points, malformed signatures across several primitives), tightens input validation (rejecting non-canonical encodings, trailing signature data), and improves constant-time behavior in FourQ arithmetic. Recommended even though <code>grype_me</code> does not call CIRCL directly.</li>
<li><strong><code>go-git/go-git/v5</code> 5.19.1 → 5.19.2</strong> and <strong><code>go-git/go-billy/v5</code> 5.9.0 → 5.9.1.</strong> Routine patch releases. The path-validation issue that let a crafted repository write outside the intended checkout target, including the <code>.git</code> directory (CVE-2026-45571), was already fixed in v5.19.1 and remains fixed here — it is not new to this release. <code>go-billy</code> v5.9.1 backports <code>golang.org/x/net</code>/<code>golang.org/x/text</code> security updates into its own build; <code>grype_me</code>&rsquo;s <code>go.sum</code> already pinned newer versions of both, so this bump has no additional effect on this project&rsquo;s build.</li>
</ul>
<h2 id="ci-updates">CI Updates</h2>
<ul>
<li>Hardened the GHCR image cleanup and publish workflows (<code>cleanup-ghcr.yml</code>, <code>publish-ghcr.yml</code>):
<ul>
<li><code>publish-ghcr.yml</code> now validates that a release tag is well-formed semver (<code>vX.Y.Z</code> or <code>vX.Y.Z-release</code>) before deriving the moving <code>v1</code>/<code>v1.2</code>/<code>v1.2.3</code> tags, and fails the workflow with a clear error instead of silently publishing a malformed tag.</li>
<li><code>cleanup-ghcr.yml</code> now also removes GHCR image versions whose tags don&rsquo;t match any recognized scheme (e.g. leftovers from a mistyped release like <code>v.1.2.3</code>), and turns individual deletion failures into a failed workflow run (previously only logged as a warning) so cleanup problems are no longer silently swallowed.</li>
</ul>
</li>
<li>Routine Actions/tooling bumps: <code>step-security/harden-runner</code> v2.20.0 → v2.20.1, <code>docker/login-action</code> v4.4.0 → v4.6.0, <code>github/codeql-action</code> v4.37.1 → v4.37.6, <code>ossf/scorecard-action</code> v2.4.3 → v2.4.4; Python tooling <code>platformdirs</code> 4.10.1 → 4.11.1, <code>packaging</code> 26.2 → 26.3; refreshed <code>golang:1.26.5-bookworm</code> build-stage digest (no Go version change).</li>
</ul>
<h2 id="changed-behavior">Changed Behavior</h2>
<ul>
<li>Maintainers publishing a release with an invalid version tag will now see the <code>publish-ghcr</code> workflow fail fast rather than push a mistagged image; the next scheduled cleanup run will also retroactively remove any previously published images with malformed tags.</li>
</ul>
<h2 id="new-features">New Features</h2>
<p>None.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/TomTonic/grype_me/compare/v1.3.18-release...v1.3.19-release">https://github.com/TomTonic/grype_me/compare/v1.3.18-release...v1.3.19-release</a></p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/wails3-build-action/</link><pubDate>Mon, 10 Aug 2026 21:22:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub action automates the building and packaging of Wails.io projects using GoLang and NodeJS. It supports various platforms and provides options for obfuscation, caching, and uploading results to GitHub or releases on tagged builds. The action is particularly useful for developers working with Wails v3 projects to streamline their build processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub action automates the building and packaging of Wails.io projects using GoLang and NodeJS. It supports various platforms and provides options for obfuscation, caching, and uploading results to GitHub or releases on tagged builds. The action is particularly useful for developers working with Wails v3 projects to streamline their build processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Setup Vamposer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/setup-vamposer/</link><pubDate>Mon, 10 Aug 2026 21:21:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/setup-vamposer/</guid><description>Version updated for https://github.com/ValaTux/vamposer to version v0.7.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Vamposer is a dependency manager for Vala projects that automates the resolution of dependencies, installation of system packages, and generation of Meson subproject wiring. It provides features inspired by Composer/Go modules, making it easier to manage project dependencies in a consistent manner. The action helps resolve package IDs, checks for system dependencies, installs them if necessary, clones subprojects, and generates necessary Meson files for building the project.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ValaTux/vamposer">https://github.com/ValaTux/vamposer</a></strong> to version <strong>v0.7.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-vamposer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>Vamposer</code> is a dependency manager for Vala projects that automates the resolution of dependencies, installation of system packages, and generation of Meson subproject wiring. It provides features inspired by Composer/Go modules, making it easier to manage project dependencies in a consistent manner. The action helps resolve package IDs, checks for system dependencies, installs them if necessary, clones subprojects, and generates necessary Meson files for building the project.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changes">Changes</h2>
<p>From v0.7.4 to v0.7.5:</p>
<ul>
<li>[Update] separated variable deps for dev for update command (9ab930f) by @JanGalek</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ValaTux/vamposer/compare/v0.7.4...v0.7.5">https://github.com/ValaTux/vamposer/compare/v0.7.4...v0.7.5</a></p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/rustscript-action/</link><pubDate>Mon, 10 Aug 2026 21:20:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action interprets and runs Rust scripts without compiling them. It automates running, validating, and building Rust scripts efficiently, handling concurrency, type checks, and errors gracefully.
What’s Changed Full Changelog: https://github.com/VladasZ/rustscript/compare/v0.3...v0.3.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action interprets and runs Rust scripts without compiling them. It automates running, validating, and building Rust scripts efficiently, handling concurrency, type checks, and errors gracefully.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.3...v0.3.1">https://github.com/VladasZ/rustscript/compare/v0.3...v0.3.1</a></p>
]]></content:encoded></item><item><title>Prism Reviewer AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/prism-reviewer-ai/</link><pubDate>Mon, 10 Aug 2026 21:18:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/prism-reviewer-ai/</guid><description>Version updated for https://github.com/vyoman-labs/prism-reviewer to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Prism Reviewer is an AI-driven multi-agent code review system that automates the process of analyzing pull requests by performing targeted static analysis, dependency scanning, AST-based symbol inspection, and parallel LLM-guided code evaluation. It helps identify vulnerabilities, security issues, design flaws, clean code practices, and other potential problems in code changes, ensuring zero hallucinations and no duplication across runs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vyoman-labs/prism-reviewer">https://github.com/vyoman-labs/prism-reviewer</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prism-reviewer-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Prism Reviewer is an AI-driven multi-agent code review system that automates the process of analyzing pull requests by performing targeted static analysis, dependency scanning, AST-based symbol inspection, and parallel LLM-guided code evaluation. It helps identify vulnerabilities, security issues, design flaws, clean code practices, and other potential problems in code changes, ensuring zero hallucinations and no duplication across runs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Changelog</strong>: <a href="https://github.com/vyoman-labs/prism-reviewer/blob/main/CHANGELOG.md#011---2026-08-10">https://github.com/vyoman-labs/prism-reviewer/blob/main/CHANGELOG.md#011---2026-08-10</a></p>
]]></content:encoded></item><item><title>wcagc accessibility check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/wcagc-accessibility-check/</link><pubDate>Mon, 10 Aug 2026 21:17:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/wcagc-accessibility-check/</guid><description>Version updated for https://github.com/WCAG-Compliance/wcagc-ci to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates WCAG (Web Content Accessibility Guidelines) accessibility checks using the wcagc tool from GitHub Actions or GitLab CI. It compares URL-level findings with a saved baseline and generates a review workflow comment if necessary. The action provides automated checks for only part of WCAG, ensures manual review remains essential, and outputs URL-level annotations and results for continuous integration and code scanning purposes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/WCAG-Compliance/wcagc-ci">https://github.com/WCAG-Compliance/wcagc-ci</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wcagc-accessibility-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates WCAG (Web Content Accessibility Guidelines) accessibility checks using the wcagc tool from GitHub Actions or GitLab CI. It compares URL-level findings with a saved baseline and generates a review workflow comment if necessary. The action provides automated checks for only part of WCAG, ensures manual review remains essential, and outputs URL-level annotations and results for continuous integration and code scanning purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What’s new</h2>
<ul>
<li>Optional SARIF 2.1.0 output with stable fingerprints for GitHub Code scanning uploads.</li>
<li>Opt-in, idempotent pull request comments for accessibility check results.</li>
<li>Dedicated <code>ci:check</code> API scope and documented FREE/STARTER CI quotas.</li>
<li>Hardened GitLab CI handling and secret-safe diagnostic output.</li>
</ul>
<p>The action reports automated accessibility findings and does not guarantee legal compliance. Review results manually as part of your accessibility process.</p>
]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/kover-report-action/</link><pubDate>Mon, 10 Aug 2026 21:16:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.24.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary A GitHub Action that generates and reports code coverage from Kover XML reports for Kotlin/Android projects, supporting multi-module support with flexible discovery methods and configurable thresholds. It integrates with PRs for automatic updates and tracks coverage history with visual indicators. The action is fast and secure, parsing Kover reports in parallel to ensure robustness.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v3.1.24</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>A GitHub Action that generates and reports code coverage from Kover XML reports for Kotlin/Android projects, supporting multi-module support with flexible discovery methods and configurable thresholds. It integrates with PRs for automatic updates and tracks coverage history with visual indicators. The action is fast and secure, parsing Kover reports in parallel to ensure robustness.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3.1.24: PR #163 - chore(deps): lock file maintenance</p>
]]></content:encoded></item><item><title>Auto-generate PR Description</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/auto-generate-pr-description/</link><pubDate>Mon, 10 Aug 2026 21:14:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/auto-generate-pr-description/</guid><description>Version updated for https://github.com/yuri-val/auto-pr-description-action to version v1.7.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses OpenAI’s language models to automatically generate detailed and context-aware pull request descriptions. It enhances collaboration by providing clear and concise summaries that capture ticket links, intent, and previous discussions, while handling rate limiting and retries. The action supports customizable configurations and outputs the generated description for easy review and updating in PRs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuri-val/auto-pr-description-action">https://github.com/yuri-val/auto-pr-description-action</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auto-generate-pr-description">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses OpenAI&rsquo;s language models to automatically generate detailed and context-aware pull request descriptions. It enhances collaboration by providing clear and concise summaries that capture ticket links, intent, and previous discussions, while handling rate limiting and retries. The action supports customizable configurations and outputs the generated description for easy review and updating in PRs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Changes in this Release:</p>
<ul>
<li>feat: use PR description and comments as context, not just the diff (#7)</li>
</ul>
<ul>
<li>feat: feed the PR&rsquo;s description and comments to the model, not just the diff</li>
</ul>
<p>The description was generated from the diff alone, so every regeneration on a new
push discarded the human context: ticket links, deployment notes, decisions taken in
review. The current body was read only to archive it as a comment, and comments were
never read at all.</p>
<p>The user message is now three labelled sections — <diff>, &lt;current_description&gt;,
<comments> — and the system prompt states how each is to be used: the diff is the
source of truth for what changed, the description and comments supply intent.
Human-authored facts (ticket links, test plans, rollout notes) are preserved; a
previously auto-generated body is rewritten rather than edited in place.</p>
<p>Comments cover issue comments, review bodies and inline review comments (carrying
file:line so they tie back to the diff). Collection is best-effort and paginated: a
token without the read scope logs and falls back to diff-only.</p>
<p>Budgets bound the request (100k diff / 5k description / 20k comments, 2k per comment)
with explicit truncation markers.</p>
<p>Pure assembly logic moved to context.js so it is testable without @actions/* or
network; 14 unit tests added (node &ndash;test) plus &rsquo;npm test'.</p>
<ul>
<li>test: point this repo&rsquo;s own workflow at feat/pr-context for an end-to-end run</li>
</ul>
<p>Temporary — reverted before merge.</p>
<ul>
<li>
<p>ci: run unit tests and verify dist/ is not stale on every PR</p>
</li>
<li>
<p>fix(ci): let the shell expand the test glob</p>
</li>
</ul>
<p>Quoted, the pattern reaches node verbatim; Node 20 on the runner does not expand
globs itself (Node 21+ does), so the run failed with &lsquo;Could not find tests/*.test.js&rsquo;.</p>
<ul>
<li>revert: point this repo&rsquo;s workflow back at @v1 after the end-to-end run</li>
</ul>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/b.ia-accessibility-checker/</link><pubDate>Mon, 10 Aug 2026 21:13:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates accessibility checks within a CI/CD pipeline using AI. It helps companies ensure their code meets accessibility standards by defining target audiences and the percentage of WCAG guidelines to be met, thereby improving overall product performance and accessibility.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates accessibility checks within a CI/CD pipeline using AI. It helps companies ensure their code meets accessibility standards by defining target audiences and the percentage of WCAG guidelines to be met, thereby improving overall product performance and accessibility.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>Zuke Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/zuke-build/</link><pubDate>Mon, 10 Aug 2026 21:12:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/zuke-build/</guid><description>Version updated for https://github.com/zuke-build/zuke to version core-v1.36.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action provides a tagged template literal that runs processes with sensible defaults such as throwing on failure and capturing output, ensuring injection safety. It’s designed to be small and explicit, focusing solely on discovering targets, building a dependency graph, sorting them topologically, and running them without additional plugins or magic.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zuke-build/zuke">https://github.com/zuke-build/zuke</a></strong> to version <strong>core-v1.36.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zuke-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action provides a tagged template literal that runs processes with sensible defaults such as throwing on failure and capturing output, ensuring injection safety. It&rsquo;s designed to be small and explicit, focusing solely on discovering targets, building a dependency graph, sorting them topologically, and running them without additional plugins or magic.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1360-2026-08-10"><a href="https://github.com/zuke-build/zuke/compare/core-v1.35.0...core-v1.36.0">1.36.0</a> (2026-08-10)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>core:</strong> give a run a lease, so slow and dead stop looking alike (<a href="https://github.com/zuke-build/zuke/issues/322">#322</a>) (<a href="https://github.com/zuke-build/zuke/commit/eb4945bfbbd30b318fcb7ee6f4bf4ca8ade29d2d">eb4945b</a>)</li>
<li><strong>core:</strong> reap abandoned runs and give a run a deadline (<a href="https://github.com/zuke-build/zuke/issues/323">#323</a>) (<a href="https://github.com/zuke-build/zuke/commit/f7832a792da694d845803c8ea0dc53e67bf0974d">f7832a7</a>)</li>
<li><strong>core:</strong> record an effect&rsquo;s intent before it runs, and re-drive it (<a href="https://github.com/zuke-build/zuke/issues/320">#320</a>) (<a href="https://github.com/zuke-build/zuke/commit/909b09c35b4453b29d287e92d53e12021541589f">909b09c</a>)</li>
</ul>
]]></content:encoded></item><item><title>Action Mailer ✨</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/action-mailer/</link><pubDate>Mon, 10 Aug 2026 14:37:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/action-mailer/</guid><description>Version updated for https://github.com/ksatriow/action-mailer to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Action Mailer is a GitHub Action that sends professional emails using SMTP (Gmail, Outlook, SendGrid) or AWS SES. It offers HTML templates, attachments, CC/BCC support, and secure credential handling. Key features include automatic provider detection, rich logging, input validation, and security best practices.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ksatriow/action-mailer">https://github.com/ksatriow/action-mailer</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-mailer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Action Mailer</strong> is a GitHub Action that sends professional emails using SMTP (Gmail, Outlook, SendGrid) or AWS SES. It offers HTML templates, attachments, CC/BCC support, and secure credential handling. Key features include automatic provider detection, rich logging, input validation, and security best practices.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="action-mailer">Action Mailer</h1>
<blockquote>
<p>Send beautiful and configurable emails directly from <strong>GitHub Actions</strong>, via <strong>SMTP</strong> or <strong>AWS SES</strong>, with support for <strong>HTML templates</strong>, <strong>CC</strong>, <strong>BCC</strong>, and <strong>attachments</strong>.</p>
</blockquote>
<hr>
<h2 id="-overview">📘 Overview</h2>
<p><strong>Action Mailer</strong> is a GitHub Action that allows you to send rich HTML emails, alerts, or reports as part of your CI/CD pipeline.<br>
You can use either:</p>
<ul>
<li><strong>SMTP</strong> (e.g., Gmail, Outlook, Zoho, custom mail servers), or</li>
<li><strong>AWS SES</strong> (Amazon Simple Email Service)</li>
</ul>
<p>Perfect for:</p>
<ul>
<li>Build/deploy success/failure notifications</li>
<li>Daily or weekly reports</li>
<li>Monitoring alerts</li>
<li>Custom workflow notifications</li>
</ul>
<hr>
<h2 id="-features">🚀 Features</h2>
<p>✅ Supports <strong>SMTP</strong> and <strong>AWS SES</strong><br>
✅ <strong>HTML Templates</strong> with <a href="https://handlebarsjs.com">Handlebars</a><br>
✅ <strong>CC / BCC</strong> recipients<br>
✅ <strong>Attachments</strong> with wildcard support (<code>*.pdf</code>)<br>
✅ <strong>Dynamic variables</strong> in templates<br>
✅ Automatic provider detection (SMTP or SES)<br>
✅ Emoji-enhanced log output for better readability</p>
<hr>
<h2 id="-inputs">🧩 Inputs</h2>
<table>
  <thead>
      <tr>
          <th>Name</th>
          <th>Description</th>
          <th>Required</th>
          <th>Default</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>smtp-server</code></td>
          <td>SMTP hostname (e.g. <code>smtp.gmail.com</code>)</td>
          <td>❌</td>
          <td></td>
      </tr>
      <tr>
          <td><code>smtp-port</code></td>
          <td>SMTP port number (e.g. 465 or 587)</td>
          <td>❌</td>
          <td><code>465</code></td>
      </tr>
      <tr>
          <td><code>smtp-secure</code></td>
          <td>Use secure TLS connection (true/false)</td>
          <td>❌</td>
          <td><code>true</code></td>
      </tr>
      <tr>
          <td><code>aws-region</code></td>
          <td>AWS region for SES</td>
          <td>❌</td>
          <td></td>
      </tr>
      <tr>
          <td><code>username</code></td>
          <td>SMTP username or AWS access key ID</td>
          <td>❌</td>
          <td></td>
      </tr>
      <tr>
          <td><code>password</code></td>
          <td>SMTP password or AWS secret key</td>
          <td>❌</td>
          <td></td>
      </tr>
      <tr>
          <td><code>from-email</code></td>
          <td>Sender email address</td>
          <td>✅</td>
          <td></td>
      </tr>
      <tr>
          <td><code>to-email</code></td>
          <td>Recipient email(s), comma-separated</td>
          <td>✅</td>
          <td></td>
      </tr>
      <tr>
          <td><code>cc-email</code></td>
          <td>CC recipients, comma-separated</td>
          <td>❌</td>
          <td></td>
      </tr>
      <tr>
          <td><code>bcc-email</code></td>
          <td>BCC recipients, comma-separated</td>
          <td>❌</td>
          <td></td>
      </tr>
      <tr>
          <td><code>subject</code></td>
          <td>Email subject line</td>
          <td>✅</td>
          <td></td>
      </tr>
      <tr>
          <td><code>body</code></td>
          <td>Plain text email body</td>
          <td>❌</td>
          <td></td>
      </tr>
      <tr>
          <td><code>html-template</code></td>
          <td>Path to HTML template (Handlebars supported)</td>
          <td>❌</td>
          <td></td>
      </tr>
      <tr>
          <td><code>template-variables</code></td>
          <td>JSON string containing key-value pairs for template replacement</td>
          <td>❌</td>
          <td></td>
      </tr>
      <tr>
          <td><code>attachments</code></td>
          <td>File paths or glob patterns for attachments</td>
          <td>❌</td>
          <td></td>
      </tr>
  </tbody>
</table>
<hr>
<h2 id="-example-smtp">✉️ Example (SMTP)</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Send Email</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">yourusername/action-mailer@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">smtp-server</span>: <span style="color:#ae81ff">smtp.gmail.com</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">smtp-port</span>: <span style="color:#ae81ff">465</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">smtp-secure</span>: <span style="color:#66d9ef">true</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">from-email</span>: <span style="color:#ae81ff">youremail@gmail.com</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">to-email</span>: <span style="color:#ae81ff">recipient@example.com</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">username</span>: <span style="color:#ae81ff">${{ secrets.SMTP_USERNAME }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">password</span>: <span style="color:#ae81ff">${{ secrets.SMTP_PASSWORD }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">subject</span>: <span style="color:#e6db74">&#34;✅ Build Success&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">html-template</span>: <span style="color:#e6db74">&#34;./templates/success.html&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">template-variables</span>: <span style="color:#e6db74">&#39;{&#34;name&#34;:&#34;Satrio&#34;,&#34;job_name&#34;:&#34;CI Build&#34;,&#34;status&#34;:&#34;SUCCESS&#34;,&#34;date&#34;:&#34;&#39;</span><span style="color:#e6db74">&#34;$(date -u)&#34;</span><span style="color:#e6db74">&#39;&#34;}&#39;</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e">**Full</span> <span style="color:#f92672">Changelog**</span>: <span style="color:#ae81ff">https://github.com/ksatriow/action-mailer/commits/v1.0.0</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Mon, 10 Aug 2026 14:36:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.14.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action provided automates the execution of automated test suites in a ServiceNow environment using specific browser and operating system configurations. It requires setting up credentials and instance URLs as secrets in the repository, then configuring the action with necessary inputs such as test suite details, browser settings, and operating system parameters to run tests on specified environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action provided automates the execution of automated test suites in a ServiceNow environment using specific browser and operating system configurations. It requires setting up credentials and instance URLs as secrets in the repository, then configuring the action with necessary inputs such as test suite details, browser settings, and operating system parameters to run tests on specified environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.13...1.0.14">https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.13...1.0.14</a></p>
]]></content:encoded></item><item><title>Setup Fortran Compilers</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/setup-fortran-compilers/</link><pubDate>Mon, 10 Aug 2026 14:35:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/setup-fortran-compilers/</guid><description>Version updated for https://github.com/minhqdao/setup-fortran to version v1.9.1.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action setup-fortran automates the setup and testing of Fortran projects across various compilers, versions, architectures, and operating systems. It provides reproducible toolchains for GNU, Intel, LLVM, NVIDIA, AMD, Arm, and LFortran on Linux, macOS, and Windows. The action supports multiple compilers with specific versions and can manage disk space by removing pre-installed toolkits during nvfortran setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/minhqdao/setup-fortran">https://github.com/minhqdao/setup-fortran</a></strong> to version <strong>v1.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-fortran-compilers">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>setup-fortran</code> automates the setup and testing of Fortran projects across various compilers, versions, architectures, and operating systems. It provides reproducible toolchains for GNU, Intel, LLVM, NVIDIA, AMD, Arm, and LFortran on Linux, macOS, and Windows. The action supports multiple compilers with specific versions and can manage disk space by removing pre-installed toolkits during <code>nvfortran</code> setup.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Persist Windows MSVC toolchain path.</li>
</ul>
]]></content:encoded></item><item><title>TreeExporter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/treeexporter/</link><pubDate>Mon, 10 Aug 2026 14:33:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/treeexporter/</guid><description>Version updated for https://github.com/mrf0rtuna4/TreeExporter to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary TreeExporter automatically generates beautiful repository structure diagrams from project folders, replacing manual editing of README file trees. It supports SVG and plain text export formats, customizable themes, and GitHub Actions integration.
What’s Changed Changelog [0.2.0] - 2026-08-10 Added Added built-in SVG themes:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mrf0rtuna4/TreeExporter">https://github.com/mrf0rtuna4/TreeExporter</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/treeexporter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>TreeExporter automatically generates beautiful repository structure diagrams from project folders, replacing manual editing of README file trees. It supports SVG and plain text export formats, customizable themes, and GitHub Actions integration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="changelog">Changelog</h1>
<h2 id="020---2026-08-10">[0.2.0] - 2026-08-10</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p>Added built-in SVG themes:</p>
<ul>
<li><code>light</code></li>
<li><code>dark</code></li>
<li><code>github-light</code></li>
<li><code>github-dark</code></li>
<li><code>dracula</code></li>
<li><code>monokai</code></li>
<li><code>nord</code></li>
<li><code>solarized-light</code></li>
<li><code>solarized-dark</code></li>
<li><code>one-dark</code></li>
</ul>
</li>
<li>
<p>Added <code>--theme</code> CLI option for SVG output.</p>
</li>
<li>
<p>Added <code>theme</code> input to the GitHub Action.</p>
</li>
<li>
<p>Added SVG previews for all built-in themes.</p>
</li>
<li>
<p>Added theme examples to the repository documentation.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Extended SVG renderer with theme-aware background and text colors.</li>
<li>Updated GitHub Action configuration to pass the selected theme to the CLI.</li>
<li>Expanded README documentation for CLI usage, GitHub Actions, themes, and configuration.</li>
<li>Updated repository structure generation workflow.</li>
</ul>
<h3 id="maintenance">Maintenance</h3>
<ul>
<li>Updated Docker configuration.</li>
<li>Updated generated repository structure and theme preview assets.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mrf0rtuna4/TreeExporter/compare/v0.1.0...v0.2.0">https://github.com/mrf0rtuna4/TreeExporter/compare/v0.1.0...v0.2.0</a></p>
]]></content:encoded></item><item><title>Nox Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/nox-security-scanner/</link><pubDate>Mon, 10 Aug 2026 14:31:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/nox-security-scanner/</guid><description>Version updated for https://github.com/Nox-HQ/nox to version v1.29.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Nox is an open-source static analyzer designed for AI application developers. It detects potential vulnerabilities in LLM applications by analyzing both the code and external dependencies without requiring access to your codebase or internet connection. Key capabilities include detecting prompt injection, embedding leakage, agent over-privilege, and unverifiable dependency provenance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nox-HQ/nox">https://github.com/Nox-HQ/nox</a></strong> to version <strong>v1.29.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nox-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Nox is an open-source static analyzer designed for AI application developers. It detects potential vulnerabilities in LLM applications by analyzing both the code and external dependencies without requiring access to your codebase or internet connection. Key capabilities include detecting prompt injection, embedding leakage, agent over-privilege, and unverifiable dependency provenance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="nox-v1290-2026-08-10t130859z">Nox v1.29.0 (2026-08-10T13:08:59Z)</h2>
<p>Language-agnostic security scanner with first-class AI application security.</p>
<h3 id="installation">Installation</h3>
<h4 id="macoslinux-homebrew">macOS/Linux (Homebrew)</h4>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap felixgeelhaar/tap
</span></span><span style="display:flex;"><span>brew install nox
</span></span></code></pre></div><h4 id="direct-download">Direct Download</h4>
<p>Download the appropriate archive for your platform from the assets below.</p>
<h3 id="whats-changed-1">What&rsquo;s Changed</h3>
<h2 id="changelog">Changelog</h2>
<h3 id="features">Features</h3>
<ul>
<li>07ea9730d833f58aa6e5a44d4ec0e9f1cbd3381b feat(config): report .nox.yaml keys nox does not recognise (#453)</li>
</ul>
<h3 id="others">Others</h3>
<ul>
<li>44788ecbc9e150398f6de53face82d90b454c9ab chore(release): 1.29.0</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nox-hq/nox/compare/v1.28.0...v1.29.0">https://github.com/nox-hq/nox/compare/v1.28.0...v1.29.0</a></p>
]]></content:encoded></item><item><title>Oculum Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/oculum-security-scan/</link><pubDate>Mon, 10 Aug 2026 14:30:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/oculum-security-scan/</guid><description>Version updated for https://github.com/OculumDev/oculum-action to version v1.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action Oculum Security Scan is an AI-driven security tool designed to detect various vulnerabilities in LLM-powered applications. It combines both traditional static application security testing (SAST) and AI techniques to identify prompt injection, hardcoded secrets, SQL injection, XSS, and more. The action can be integrated into GitHub workflows to automatically scan code changes and provide real-time feedback through PR comments or inline annotations. It supports two scan depths: cheap for free pattern matching scans and validated for AI-assisted validation with a required API key.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OculumDev/oculum-action">https://github.com/OculumDev/oculum-action</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oculum-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action Oculum Security Scan is an AI-driven security tool designed to detect various vulnerabilities in LLM-powered applications. It combines both traditional static application security testing (SAST) and AI techniques to identify prompt injection, hardcoded secrets, SQL injection, XSS, and more. The action can be integrated into GitHub workflows to automatically scan code changes and provide real-time feedback through PR comments or inline annotations. It supports two scan depths: cheap for free pattern matching scans and validated for AI-assisted validation with a required API key.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update README and action.yml for marketplace (d43812a)</li>
<li>reduced description length for marketplace publish (f19893e)</li>
<li>change description (ae151d7)</li>
<li>Improve annotation fix details - use fixSteps when available (3b55e59)</li>
<li>first commit (16010ba)</li>
</ul>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/odin-scan-smart-contract-security/</link><pubDate>Mon, 10 Aug 2026 14:29:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates smart contract security analysis for CosmWasm, Solana, and EVM projects using Odin Scan. It integrates with GitHub Code Scanning to provide SARIF files for native security alerts and comments on pull requests. Users can configure severity thresholds and trigger scans through comments, making it easier to catch vulnerabilities early in the development process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates smart contract security analysis for CosmWasm, Solana, and EVM projects using Odin Scan. It integrates with GitHub Code Scanning to provide SARIF files for native security alerts and comments on pull requests. Users can configure severity thresholds and trigger scans through comments, making it easier to catch vulnerabilities early in the development process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add comment-triggered PR scans (ac72e5f)</li>
<li>docs: expand findings-visibility section with threat model and annotation rationale (0404708)</li>
<li>feat: add findings-visibility input for graduated public disclosure control (f18df59)</li>
<li>fix: show findings detail in PR comment with fallback to medium (c2e43c8)</li>
<li>fix: new comment per run, show only critical/high findings, rebuild dist (e237b62)</li>
<li>feat: use GitHub App installation token for branded PR comments (3abce4e)</li>
<li>feat: enrich PR comment with emojis, descriptions, and fix report URL (27cc2f2)</li>
<li>fix: gzip SARIF before base64 encoding for Code Scanning upload (d9eed9f)</li>
<li>fix: include sourcemap-register.js in dist (bd265af)</li>
<li>docs: add privacy policy (b78db44)</li>
</ul>
]]></content:encoded></item><item><title>ActionScope</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/actionscope/</link><pubDate>Mon, 10 Aug 2026 14:28:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/actionscope/</guid><description>Version updated for https://github.com/r12habh/ActionScope to version v0.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ActionScope is an open-source tool that analyzes GitHub Actions workflows to identify AWS permissions and potential security risks. It automates the process of mapping the blast radius of CI/CD pipelines against AWS resources, providing clear insights into what actions and permissions are implied if a workflow is compromised. Key capabilities include detecting known-compromised actions, identifying OIDC trust policy misconfigurations, and monitoring for script injection or artifact poisoning. Users can run it locally to scan their repositories without requiring AWS credentials.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/r12habh/ActionScope">https://github.com/r12habh/ActionScope</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/actionscope">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ActionScope is an open-source tool that analyzes GitHub Actions workflows to identify AWS permissions and potential security risks. It automates the process of mapping the blast radius of CI/CD pipelines against AWS resources, providing clear insights into what actions and permissions are implied if a workflow is compromised. Key capabilities include detecting known-compromised actions, identifying OIDC trust policy misconfigurations, and monitoring for script injection or artifact poisoning. Users can run it locally to scan their repositories without requiring AWS credentials.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="actionscope-v050">ActionScope v0.5.0</h2>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install actionscope<span style="color:#f92672">==</span>0.5.0
</span></span></code></pre></div><h3 id="whats-new">What&rsquo;s New</h3>
<p>See <a href="CHANGELOG.md">CHANGELOG.md</a> for details.</p>
]]></content:encoded></item><item><title>Redis Repo Memory</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/redis-repo-memory/</link><pubDate>Mon, 10 Aug 2026 14:26:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/redis-repo-memory/</guid><description>Version updated for https://github.com/redis-learn/redis-repo-memory to version v1.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Redis Repo Memory automates the process of finding semantically related pull requests, issues, and commits in repository history using Redis vector search. It extracts commit or PR context from titles, bodies, and changed files, embeds it with OpenAI’s text-embedding-3-small, searches a Redis vector index for similar work, and posts results as comments or commit statuses on pull requests and pushes to non-main branches. The action helps teams quickly understand related content before reviewing new changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/redis-learn/redis-repo-memory">https://github.com/redis-learn/redis-repo-memory</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/redis-repo-memory">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Redis Repo Memory automates the process of finding semantically related pull requests, issues, and commits in repository history using Redis vector search. It extracts commit or PR context from titles, bodies, and changed files, embeds it with OpenAI&rsquo;s <code>text-embedding-3-small</code>, searches a Redis vector index for similar work, and posts results as comments or commit statuses on pull requests and pushes to non-main branches. The action helps teams quickly understand related content before reviewing new changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fixes duplicate PR comments. The action now maintains a single comment per PR, updating it in place on every push instead of adding a new one.</p>
]]></content:encoded></item><item><title>Cloudflare IP List Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/cloudflare-ip-list-sync/</link><pubDate>Mon, 10 Aug 2026 14:25:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/cloudflare-ip-list-sync/</guid><description>Version updated for https://github.com/rezzell/cloudflare-ip-list-sync-action to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action synchronizes a Cloudflare IP list with composed IP and CIDR sources, such as GitHub webhook egress ranges from the GitHub Meta API. It automates keeping the WAF IP list current by replacing all existing items with the resolved desired set. The action supports various source types, including GitHub Meta, CIDRs, and URLs, and provides options for dry run and wait operations to ensure smooth execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rezzell/cloudflare-ip-list-sync-action">https://github.com/rezzell/cloudflare-ip-list-sync-action</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cloudflare-ip-list-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action synchronizes a Cloudflare IP list with composed IP and CIDR sources, such as GitHub webhook egress ranges from the GitHub Meta API. It automates keeping the WAF IP list current by replacing all existing items with the resolved desired set. The action supports various source types, including GitHub Meta, CIDRs, and URLs, and provides options for dry run and wait operations to ensure smooth execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixes">Fixes</h2>
<ul>
<li>Fixed hyphenated action input parsing for inputs such as <code>cloudflare-api-token</code>. GitHub exposes these to JavaScript actions as environment variables such as <code>INPUT_CLOUDFLARE-API-TOKEN</code>; the action now reads that format and retains underscore fallback for local testing. Fixes #1.</li>
</ul>
<h2 id="impact">Impact</h2>
<p>This fixes real GitHub Actions runtime failures where the action reported <code>Missing required input: cloudflare-api-token</code> even though the workflow passed the input.</p>
<h2 id="verification">Verification</h2>
<ul>
<li>Added regression coverage for hyphenated action inputs.</li>
<li>Confirmed <code>npm test</code> passes.</li>
<li>Confirmed the built action dry-run resolves 6 current GitHub webhook CIDRs.</li>
<li>Confirmed <code>rezzell/.github</code> dry-run workflow succeeds: <a href="https://github.com/rezzell/.github/actions/runs/31356536712">https://github.com/rezzell/.github/actions/runs/31356536712</a></li>
</ul>
<p>The <code>v1</code> tag has been moved to this release commit.</p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/kaniko-build-action/</link><pubDate>Mon, 10 Aug 2026 14:24:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting to the log and optionally includes the current timestamp. It automates the process of generating greetings in various formats, making it useful for documentation generation, automated testing, or any task requiring simple text outputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting to the log and optionally includes the current timestamp. It automates the process of generating greetings in various formats, making it useful for documentation generation, automated testing, or any task requiring simple text outputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/rumdl-action/</link><pubDate>Mon, 10 Aug 2026 14:24:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.53.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rumdl is a high-performance Markdown linter and formatter written in Rust. It aims to provide fast linting and formatting of Markdown files, with support for multiple markdown flavors and automatic fixing. The tool is highly configurable through TOML-based configuration files and offers zero dependencies. It improves upon existing tools like ruff by being built for speed using Rust, with 82 lint rules covering common Markdown issues.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.53</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>rumdl is a high-performance Markdown linter and formatter written in Rust. It aims to provide fast linting and formatting of Markdown files, with support for multiple markdown flavors and automatic fixing. The tool is highly configurable through TOML-based configuration files and offers zero dependencies. It improves upon existing tools like ruff by being built for speed using Rust, with 82 lint rules covering common Markdown issues.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>tables</strong>: find a table&rsquo;s extent in the document&rsquo;s flavor (<a href="https://github.com/rvben/rumdl/commit/ad139af7aa11904768588fdac7fb10eca1ad3051">ad139af</a>)</li>
<li><strong>tables</strong>: quoted brackets and a blank target are not a wikilink (<a href="https://github.com/rvben/rumdl/commit/a8aed70e3d5599f5759f46a412b2db48c2d3e9d1">a8aed70</a>)</li>
<li><strong>lsp</strong>: a rescan keeps an open buffer only where a file still is (<a href="https://github.com/rvben/rumdl/commit/8e16303a900ea20e07e57c7dbb82115f74b13c51">8e16303</a>)</li>
<li><strong>lsp</strong>: keep an open document indexed from its buffer (<a href="https://github.com/rvben/rumdl/commit/ea30ccac9c3ecef75d8863a9c83d996857cd0a6f">ea30cca</a>)</li>
<li><strong>lsp</strong>: index what an editor is showing when the workspace is rescanned (<a href="https://github.com/rvben/rumdl/commit/0d8eacc81c99bef35c9aa5e5fe58c362e5d5073b">0d8eacc</a>)</li>
<li><strong>lsp</strong>: stop an evicted file from being put back by a waiting disk read (<a href="https://github.com/rvben/rumdl/commit/5644516f37fd5fe7ac177406777d57bd173d6982">5644516</a>)</li>
<li><strong>md075</strong>: ignore Obsidian wikilink aliases in prose after tables (<a href="https://github.com/rvben/rumdl/commit/dda35d54d654b3aa54410faa779aa4af4f9cf2f0">dda35d5</a>)</li>
<li><strong>md084</strong>: stop deleting line endings as invisible characters (<a href="https://github.com/rvben/rumdl/commit/e6ca26ebfa1d76aaa628f3b060231f048159b875">e6ca26e</a>)</li>
<li><strong>rules</strong>: report a multi-line link&rsquo;s range on the line it ends on (<a href="https://github.com/rvben/rumdl/commit/2e1fde59e2ec9566674a9314a504f190160cfe37">2e1fde5</a>)</li>
<li><strong>config</strong>: break &ldquo;did you mean&rdquo; ties by name instead of by key order (<a href="https://github.com/rvben/rumdl/commit/23fafd96f45caca63ee9c42ad63b237dbb43cba5">23fafd9</a>)</li>
<li><strong>lsp</strong>: keep a pending edit when a file is only evicted from the index (<a href="https://github.com/rvben/rumdl/commit/1e34c4726adbebf7d63bb4e7cf48046b014240fb">1e34c47</a>)</li>
<li><strong>lsp</strong>: drop a pending edit when its file is deleted (<a href="https://github.com/rvben/rumdl/commit/f718ecafb671a9ace9426e0b158fbe10f5789a1b">f718eca</a>)</li>
<li><strong>md038</strong>: include the closing backtick in the reported range (<a href="https://github.com/rvben/rumdl/commit/128b9a190c745b8d38a9d8ec94a651e800051e1f">128b9a1</a>)</li>
<li><strong>md038</strong>: stop deleting a line when trimming a multi-line code span (<a href="https://github.com/rvben/rumdl/commit/e2e27ac6d8da74f0741ab11b3c2589cce028dcf8">e2e27ac</a>)</li>
<li><strong>md018</strong>: recognize tags that start with a digit (<a href="https://github.com/rvben/rumdl/commit/6237384fdfe98e6b156dc7bbe50dbe5b0a206fe2">6237384</a>)</li>
<li><strong>lsp</strong>: stop publishing diagnostics for files that were never opened (<a href="https://github.com/rvben/rumdl/commit/8b895847da2050cae10658739ac81a8b313fd1b1">8b89584</a>)</li>
<li><strong>lsp</strong>: refresh cross-file diagnostics when the workspace index changes (<a href="https://github.com/rvben/rumdl/commit/eecda03825d251384e64b9d70135417ffab4fd32">eecda03</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.53-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.53-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.53-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.53-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-x86_64-apple-darwin.tar.gz">rumdl-v0.2.53-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-aarch64-apple-darwin.tar.gz">rumdl-v0.2.53-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-x86_64-pc-windows-msvc.zip">rumdl-v0.2.53-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.53/rumdl-v0.2.53-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/bernstein-multi-agent-orchestration/</link><pubDate>Mon, 10 Aug 2026 14:23:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.14.159.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is an open-source CLI orchestration tool that leverages deterministic multi-agent scheduling in Python. It automates tasks by scheduling them through plain Python and ensures reproducibility end to end, with each task running in its own git worktree behind lint, type, and test gates. Artifact-mode tasks provide a plain working directory for completion on a signed lineage receipt instead of committing changes. The tool supports various coding agents and includes features like always-on lineage spines, replay journals, and an opt-in HMAC-chained audit log with receipts that can be verified offline. It is suitable for production environments and is under active development.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.14.159</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein is an open-source CLI orchestration tool that leverages deterministic multi-agent scheduling in Python. It automates tasks by scheduling them through plain Python and ensures reproducibility end to end, with each task running in its own git worktree behind lint, type, and test gates. Artifact-mode tasks provide a plain working directory for completion on a signed lineage receipt instead of committing changes. The tool supports various coding agents and includes features like always-on lineage spines, replay journals, and an opt-in HMAC-chained audit log with receipts that can be verified offline. It is suitable for production environments and is under active development.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The minor landed on 14, so the version is π to three digits. If this release ever needs a patch, we&rsquo;ll append digits — 3.14.1592 — the way TeX does. That&rsquo;s the only whimsical thing in here.</p>
<p>This is the release where the surface stopped pretending. A first-use report (#3514) described ninety minutes of setup that ended in nothing: an error message recommending a flag that doesn&rsquo;t exist, a run that produced no plan and said nothing, and a command list too large to hold in one head. Most of what shipped since v3.13.0 answers some part of that, directly or by removing the class of defect behind it. The README now also says plainly what this is: a beta maintained by one person — pin the version for anything you depend on, file regressions, they get fixed fast.</p>
<h2 id="read-before-upgrading">Read before upgrading</h2>
<ul>
<li><strong>Five commands are gone, no deprecation window</strong> (#3472): <code>postmortem</code> → <code>bernstein report postmortem</code>, <code>incident</code> → <code>bernstein report incident</code>, <code>commit-stats</code> → <code>bernstein report commits</code>, and the <code>consensus</code> and <code>issue-to-pr</code> groups are removed outright. Everything else that moved (<code>quickstart</code>, <code>init-wizard</code>, <code>validate</code>, <code>routine</code>, benchmark subcommands, impact analysis, <code>changelog</code>/<code>run-changelog</code> swap, <code>listen</code>) kept aliases that print a deprecation notice for the documented window.</li>
<li><strong>Plan loading rejects what it used to swallow</strong> (#3534, #3539). Out-of-range enums, a scalar where <code>files</code> expects a list, a non-integer <code>priority</code>, an explicit <code>null</code> — these used to load as defaults, which is how a run could start, produce no plan, and say nothing. They now raise <code>PlanLoadError</code> with the field named. Two tolerances remain and are tracked: <code>dry-run --plan</code> still converts a load error into an empty exit-0 result (#3550), and both verifiers still skip malformed journal rows instead of failing (#3549).</li>
<li><strong><code>evolution_enabled: false</code> now disables the evolution loop</strong> (#3397). It previously did not, which is the kind of sentence a config option should never need written about it.</li>
<li><strong>Verification absences downgrade instead of passing</strong> — unparseable attestation key (#3494), missing identity signal (#3429), symlinked receipt store (#3414), and <code>telemetry verify-span</code> exit codes now match <code>trace verify-projection</code> for these cases (#3407). One divergence is still open: removed audit evidence exits 0 on <code>verify-projection</code> but 1 on <code>verify-span</code> (#3551).</li>
</ul>
<h2 id="worth-knowing">Worth knowing</h2>
<ul>
<li>The reference docs are now <strong>CI-gated against the registered CLI</strong> (#3511, #3536) — twenty-three commands were documenting flags the parser rejected; that defect class is closed, not groomed.</li>
<li>The no-adapter error names a flag that exists (#3530), and a test resolves every command in that message against the live CLI so it can&rsquo;t drift back.</li>
<li><strong>A signed run receipt that verifies fully offline</strong> (#3387), and <code>bernstein audit diagnose</code> (#3388), which names the first faulty step instead of leaving you to bisect.</li>
<li>New surfaces: <strong>Muse Code adapter</strong> (#3542), Kimchi CLI with ACP ingress conformance (#3509), a generic adapter for Python-library runtimes (#3510), a Playwright browser driver behind a conformance kit (#3508), <strong>Agent Plugins v1.0.0 manifests</strong> validated in CI against vendored schemas (#3541), and a read-only datasource query driver (#3386).</li>
<li>The demo produces real completion evidence instead of mock theater (#3432), and the front page shows a recorded real run that ships its own proof (#3438).</li>
<li>Floor-raising: two mypy backlogs cleared, coverage ratcheted to 83.25%, every TypeScript package under the typecheck gate, the secret scanner pinned to an exact release.</li>
</ul>
<p>Every behaviour change, with the exact windows and replacements, is spelled out in the <a href="https://github.com/sipyourdrink-ltd/bernstein/blob/main/docs/release-notes/v3.14.159.md">full release notes</a>.</p>
<p>Thanks to @Silentpartnercoding, @Louis20060723, @bymyforge, @AmirF194, @essentialols, @PyaaZz and @Maqbool61 for landing work in this cycle — the beta line in the README is an invitation.</p>
<p><strong>Full changelog</strong>: <a href="https://github.com/sipyourdrink-ltd/bernstein/compare/v3.13.0...v3.14.159">https://github.com/sipyourdrink-ltd/bernstein/compare/v3.13.0...v3.14.159</a></p>
]]></content:encoded></item><item><title>Snowflake Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/snowflake-actions/</link><pubDate>Mon, 10 Aug 2026 14:22:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/snowflake-actions/</guid><description>Version updated for https://github.com/snowflakedb/snowflake-actions to version v3.3.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 1 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Snowflake Actions GitHub Action installs and configures the Snowflake CLI in a workflow, enabling tasks like deploying dbt projects, running SQL commands, automating Snowflake App Runtime apps, and more. It supports OIDC authentication for secure access to Snowflake without storing secrets and is recommended for most environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snowflakedb/snowflake-actions">https://github.com/snowflakedb/snowflake-actions</a></strong> to version <strong>v3.3.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>1</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/snowflake-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Snowflake Actions GitHub Action installs and configures the Snowflake CLI in a workflow, enabling tasks like deploying dbt projects, running SQL commands, automating Snowflake App Runtime apps, and more. It supports OIDC authentication for secure access to Snowflake without storing secrets and is recommended for most environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Snowflake Actions v3.3.1</strong></p>
<h2 id="fixes">Fixes</h2>
<ul>
<li><strong>DCM composite actions</strong> (<code>dcm/</code>): <code>pull_request_target</code> workflows with <code>comment-on-pr: &quot;true&quot;</code> no longer post the plan comment on the last-merged pull request instead of the open one. <code>GITHUB_SHA</code> on that event points at the default branch tip, so the old commit-based lookup returned the wrong PR; both <code>resolvePrNumber</code> and <code>resolvePrBranch</code> now recognise <code>pull_request_target</code> as a payload event and read the PR number and head branch directly from the event
payload. (#31)</li>
<li><strong>DCM composite actions</strong> (<code>dcm/</code>): the deployment alias is now <code>&lt;source&gt;-&lt;run id&gt;.&lt;run attempt&gt;</code> instead of <code>&lt;branch&gt;-&lt;short sha&gt;</code>, so re-running a workflow or retrying after a transient failure no longer fails with a duplicate-alias error. Push-triggered deploys previously received no alias at all and appeared in <code>SHOW DEPLOYMENTS</code> as only <code>DEPLOYMENT$N</code>; they now get <code>&lt;ref&gt;-&lt;run id&gt;.&lt;run attempt&gt;</code>. (#31)</li>
</ul>
<h2 id="notes">Notes</h2>
<ul>
<li>No inputs or outputs changed. Both fixes are transparent to existing workflow files.</li>
</ul>
<p><strong>Usage:</strong> <code>uses: snowflakedb/snowflake-actions@v3</code></p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/snowflakedb/snowflake-actions/compare/v3.3.0...v3.3.1">https://github.com/snowflakedb/snowflake-actions/compare/v3.3.0...v3.3.1</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fix PR resolution on pull_request_target and make the deployment alias unique per run by @sfc-gh-jsommerfeld in <a href="https://github.com/snowflakedb/snowflake-actions/pull/31">https://github.com/snowflakedb/snowflake-actions/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/snowflakedb/snowflake-actions/compare/v3...v3.3.1">https://github.com/snowflakedb/snowflake-actions/compare/v3...v3.3.1</a></p>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/update-a-config-file-with-values-from-environment/</link><pubDate>Mon, 10 Aug 2026 14:20:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The config-file-from-env GitHub Action replaces environment variables in a specified configuration file with their corresponding values. This action automates the process of updating placeholders in configuration files to use actual environment settings, making it easier to manage configurations across different environments and deployments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>config-file-from-env</code> GitHub Action replaces environment variables in a specified configuration file with their corresponding values. This action automates the process of updating placeholders in configuration files to use actual environment settings, making it easier to manage configurations across different environments and deployments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Mon, 10 Aug 2026 14:20:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by bundling its dependencies with npm and committing the resulting distribution folder to the repository. This helps streamline the release process, ensuring that all necessary files are included in the version control before publishing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by bundling its dependencies with <code>npm</code> and committing the resulting distribution folder to the repository. This helps streamline the release process, ensuring that all necessary files are included in the version control before publishing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/spek-openspec-static-site/</link><pubDate>Mon, 10 Aug 2026 14:20:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.12.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary spek is a lightweight tool that provides a read-only, local interface to browse OpenSpec content. It offers features such as a dashboard, spec and change browsers, schema browser, worktree aggregation, timeline, BDD syntax highlighting, task progress tracking, and full-text search. The tool is designed to be accessible in any browser without server deployment or authentication.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>spek is a lightweight tool that provides a read-only, local interface to browse OpenSpec content. It offers features such as a dashboard, spec and change browsers, schema browser, worktree aggregation, timeline, BDD syntax highlighting, task progress tracking, and full-text search. The tool is designed to be accessible in any browser without server deployment or authentication.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Highlight: spek now shows the workflow itself, not just its output.</strong> A schema decides what a change <em>is</em> in OpenSpec — which artifacts exist, what order they come in, what each is supposed to contain, and when the change is ready to implement. spek has always rendered the products of that process and never the process. Until now the schema appeared only as a small badge on a change that differed from the repo default: a name with nothing behind it.</p>
<ul>
<li><strong>New Schemas page</strong> listing every workflow schema available to the selected repo, with its description, its source (shipped with the <code>openspec</code> package, or project-local under <code>openspec/schemas/</code>), and how many artifacts it defines. The schema named by <code>openspec/config.yaml</code> is marked as the repo default, and each schema shows how many active changes declare it, with a link through to them. Thanks to <a href="https://github.com/nthansen">@nthansen</a> (Norman Hansen)</li>
<li><strong>A schema detail view that reads as a workflow</strong> — its artifacts in authoritative order as a diagram, each showing the file it generates, what it requires before it can be written, and its full instruction text. The <code>apply</code> step is drawn as the flow&rsquo;s terminal step, because &ldquo;when is this change ready to implement&rdquo; is part of what a reader is trying to understand</li>
<li><strong>When the OpenSpec CLI cannot answer, the page says so.</strong> If the CLI is missing, exits non-zero, times out, or emits something unparsable, the list comes back empty <em>with the reason stated</em>, rather than as an unexplained empty page. It does not substitute a reading of its own: which schemas exist, and which shadows which across the three directories OpenSpec searches, is a question only OpenSpec can answer</li>
<li><strong>Schema reads stay off the scan hot path</strong> — they happen only when schema information is asked for, and are cached per repo. Change lists, the overview and worktree aggregation are unaffected</li>
<li><strong>Spec content is now ranked by structure rather than by inherited type size.</strong> In a change&rsquo;s Specs tab the spec&rsquo;s own name was smaller than the <code>ADDED Requirements</code> label inside it — and, being an <code>h3</code> sibling of the content&rsquo;s <code>h2</code>s, it was <em>terminated</em> by the first one rather than containing them, leaving the requirements below attributed to no spec at all. The topic name is now the dominant heading of its section with a rule beneath it, the operation label is demoted, and an open section is inset with a hairline rule marking where it ends. Reported from the IntelliJ tool window (issue #42)</li>
<li><strong>Every delta operation is marked, not an arbitrary two.</strong> <code>REMOVED</code> and <code>RENAMED</code> had no styling of their own, so in prose they read as ordinary words. <code>REMOVED</code> deliberately does not take red: red already means &ldquo;normative&rdquo; (<code>MUST</code> / <code>SHALL</code>) in this renderer, and one colour carrying two meanings weakens both</li>
<li><em>Internal:</em> <code>@spekjs/core</code> 1.8.0 exposes the schema enumeration and reading API, and gains <code>yaml</code> as a runtime dependency</li>
</ul>
]]></content:encoded></item><item><title>Roborazzi Golden Snapshots</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/roborazzi-golden-snapshots/</link><pubDate>Mon, 10 Aug 2026 14:19:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/roborazzi-golden-snapshots/</guid><description>Version updated for https://github.com/sudansh/roborazzi-screenshot-kmp to version v0.0.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Roborazzi Golden Snapshots Action automates the process of generating and reviewing golden images using Gradle/Roborazzi/Paparazzi tasks. It ensures that only changes to reference images are pushed to a separate branch, creates an inline diff gallery, opens a reference PR, and updates comments with the results. The action is designed to work with generator-agnostic render commands, allowing users to integrate it into their CI pipelines without modifying their build configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sudansh/roborazzi-screenshot-kmp">https://github.com/sudansh/roborazzi-screenshot-kmp</a></strong> to version <strong>v0.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/roborazzi-golden-snapshots">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Roborazzi Golden Snapshots Action automates the process of generating and reviewing golden images using Gradle/Roborazzi/Paparazzi tasks. It ensures that only changes to reference images are pushed to a separate branch, creates an inline diff gallery, opens a reference PR, and updates comments with the results. The action is designed to work with generator-agnostic render commands, allowing users to integrate it into their CI pipelines without modifying their build configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Run on node24 — Node 20 is deprecated on GitHub Actions runners.</p>
]]></content:encoded></item><item><title>Markdown to PDF (MintPDF)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/markdown-to-pdf-mintpdf/</link><pubDate>Mon, 10 Aug 2026 14:18:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/markdown-to-pdf-mintpdf/</guid><description>Version updated for https://github.com/TrendTweekers/markdown-to-pdf-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action markdown-to-pdf-action converts Markdown or HTML files into styled PDFs from a GitHub workflow using MintPDF, a web-based PDF generator. It simplifies the process of generating PDFs in CI by eliminating the need to install Chromium and shared libraries. The action supports various options for formatting, orientation, margins, page numbers, and header/footer text. It also provides an API key option to manage quotas and ensure secure use.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TrendTweekers/markdown-to-pdf-action">https://github.com/TrendTweekers/markdown-to-pdf-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/markdown-to-pdf-mintpdf">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>markdown-to-pdf-action</code> converts Markdown or HTML files into styled PDFs from a GitHub workflow using MintPDF, a web-based PDF generator. It simplifies the process of generating PDFs in CI by eliminating the need to install Chromium and shared libraries. The action supports various options for formatting, orientation, margins, page numbers, and header/footer text. It also provides an API key option to manage quotas and ensure secure use.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release.</p>
<p>Turn a Markdown file, an HTML file or a live URL into a styled PDF from a GitHub workflow, without installing Chromium on the runner.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">TrendTweekers/markdown-to-pdf-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">file</span>: <span style="color:#ae81ff">CHANGELOG.md</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">output</span>: <span style="color:#ae81ff">dist/changelog.pdf</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">page-numbers</span>: <span style="color:#66d9ef">true</span>
</span></span></code></pre></div><ul>
<li><strong>No dependencies.</strong> One file of plain Node against the runtime already on every runner, so there is no <code>node_modules</code> to vendor and nothing to audit but <code>main.js</code>.</li>
<li>Inputs for paper size, orientation, margins, page numbers, and header and footer text.</li>
<li>Outputs <code>file</code> and <code>size-bytes</code>, plus a job summary.</li>
<li>Fails loudly with clear annotations on bad input rather than writing an empty file.</li>
</ul>
<p>Markdown is rendered with a print stylesheet, so code blocks and tables are not sliced across page boundaries and table header rows repeat.</p>
<p>Full documentation is in the <a href="https://github.com/TrendTweekers/markdown-to-pdf-action#readme">README</a>.</p>
]]></content:encoded></item><item><title>install spaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/install-spaces/</link><pubDate>Mon, 10 Aug 2026 14:17:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/install-spaces/</guid><description>Version updated for https://github.com/work-spaces/install-spaces to version v0.20.7.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of Spaces on a new instance. It simplifies the process by handling various configuration options and ensuring compatibility across different operating systems. The action supports both Windows and macOS, providing flexibility for deploying Spaces in various environments seamlessly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/install-spaces">https://github.com/work-spaces/install-spaces</a></strong> to version <strong>v0.20.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-spaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the installation of Spaces on a new instance. It simplifies the process by handling various configuration options and ensuring compatibility across different operating systems. The action supports both Windows and macOS, providing flexibility for deploying Spaces in various environments seamlessly.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fix macos detection by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/41">https://github.com/work-spaces/install-spaces/pull/41</a></li>
<li>Remove windows ci check by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/42">https://github.com/work-spaces/install-spaces/pull/42</a></li>
<li>Bump version to v0.20.7 by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/43">https://github.com/work-spaces/install-spaces/pull/43</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/install-spaces/compare/v0.20.3...v0.20.7">https://github.com/work-spaces/install-spaces/compare/v0.20.3...v0.20.7</a></p>
]]></content:encoded></item><item><title>spaces checkout run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/spaces-checkout-run/</link><pubDate>Mon, 10 Aug 2026 14:16:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/spaces-checkout-run/</guid><description>Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.20.7.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of checking out a workspace and running tasks on it using the spaces CLI. It solves the problem of manually executing these steps in CI/CD pipelines, making the workflow more efficient and easier to maintain. The action provides inputs for specifying arguments to spaces checkout and spaces run, as well as an optional GitHub token for authorization.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/spaces-checkout-run">https://github.com/work-spaces/spaces-checkout-run</a></strong> to version <strong>v0.20.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spaces-checkout-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of checking out a workspace and running tasks on it using the spaces CLI. It solves the problem of manually executing these steps in CI/CD pipelines, making the workflow more efficient and easier to maintain. The action provides inputs for specifying arguments to <code>spaces checkout</code> and <code>spaces run</code>, as well as an optional GitHub token for authorization.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Use patched version of install-spaces by @tyler-gilbert in <a href="https://github.com/work-spaces/spaces-checkout-run/pull/35">https://github.com/work-spaces/spaces-checkout-run/pull/35</a></li>
<li>Update version v0.20.7 by @tyler-gilbert in <a href="https://github.com/work-spaces/spaces-checkout-run/pull/36">https://github.com/work-spaces/spaces-checkout-run/pull/36</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/spaces-checkout-run/compare/v0.20.3...v0.20.7">https://github.com/work-spaces/spaces-checkout-run/compare/v0.20.3...v0.20.7</a></p>
]]></content:encoded></item><item><title>AI-Driven ADR Enforcer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/ai-driven-adr-enforcer/</link><pubDate>Mon, 10 Aug 2026 14:16:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/ai-driven-adr-enforcer/</guid><description>Version updated for https://github.com/y-matsuo081991/ai-adr-enforcer to version v1.1.8.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the enforcement of Architecture Decision Records (ADRs) in your project. It uses LLMs to audit incoming Pull Requests, ensuring compliance with established ADRs and blocking non-compliant commits with actionable suggestions directly within the PR timeline. The action also offers self-healing capabilities by suggesting compliant code alternatives when violations are detected.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/y-matsuo081991/ai-adr-enforcer">https://github.com/y-matsuo081991/ai-adr-enforcer</a></strong> to version <strong>v1.1.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-driven-adr-enforcer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the enforcement of Architecture Decision Records (ADRs) in your project. It uses LLMs to audit incoming Pull Requests, ensuring compliance with established ADRs and blocking non-compliant commits with actionable suggestions directly within the PR timeline. The action also offers self-healing capabilities by suggesting compliant code alternatives when violations are detected.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: hybrid two-stage ADR corpus retrieval (ADR-013) by @y-matsuo081991 in <a href="https://github.com/y-matsuo081991/ai-adr-enforcer/pull/8">https://github.com/y-matsuo081991/ai-adr-enforcer/pull/8</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/y-matsuo081991/ai-adr-enforcer/compare/v1.1.7...v1.1.8">https://github.com/y-matsuo081991/ai-adr-enforcer/compare/v1.1.7...v1.1.8</a></p>
]]></content:encoded></item><item><title>YAMLResume</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/yamlresume/</link><pubDate>Mon, 10 Aug 2026 14:15:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/yamlresume/</guid><description>Version updated for https://github.com/yamlresume/action to version v0.14.2.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses the YAMLResume CLI to build professional resumes from YAML files. It automates the process of generating multiple resumes, customizing build options, and outputs generated file paths. The action is useful for developers to streamline the resume-building workflow in their CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yamlresume/action">https://github.com/yamlresume/action</a></strong> to version <strong>v0.14.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yamlresume">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses the YAMLResume CLI to build professional resumes from YAML files. It automates the process of generating multiple resumes, customizing build options, and outputs generated file paths. The action is useful for developers to streamline the resume-building workflow in their CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="features">Features</h3>
<ul>
<li>bump yamlresume from v0.14.1 to v0.14.2 (<a href="https://github.com/yamlresume/action/commit/9d836ebc2964bae8a9a081526939a80883e0faa5">9d836eb</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yamlresume/action/compare/v0.14.1...v0.14.2">https://github.com/yamlresume/action/compare/v0.14.1...v0.14.2</a></p>
]]></content:encoded></item><item><title>AGENTS.md Lint (Schliff)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/agents.md-lint-schliff/</link><pubDate>Mon, 10 Aug 2026 14:14:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/agents.md-lint-schliff/</guid><description>Version updated for https://github.com/Zandereins/schliff to version v8.11.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Schliff is a tool that scores the quality of AI instruction files, ensuring consistency and reliability across different environments. It uses an explicit, versioned rubric to provide deterministic quality scores, preventing degradation and providing reproducibility in model evaluation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zandereins/schliff">https://github.com/Zandereins/schliff</a></strong> to version <strong>v8.11.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-md-lint-schliff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Schliff is a tool that scores the quality of AI instruction files, ensuring consistency and reliability across different environments. It uses an explicit, versioned rubric to provide deterministic quality scores, preventing degradation and providing reproducibility in model evaluation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release. No score changes, no exit-code changes, no new surface.</p>
<h2 id="fixed">Fixed</h2>
<p><strong>The skill mesh no longer reports a skill as colliding with itself.</strong> Installing the same skill in two places — <code>~/.claude/skills</code> plus a project-local copy, which is how schliff itself is distributed — produced two <em>critical</em> findings and cost 27 mesh-health points. The pair was never two skills competing for triggers; it is one skill at two paths. The remediation the mesh generated for it named the same skill on both sides of &ldquo;narrow your scope to disambiguate&rdquo;, which nobody can act on.</p>
<p><strong>A duplicate skill name is now reported as what it is.</strong> <code>duplicate_name</code> (severity <code>info</code>, no health penalty) lists every path the skill was found at — only one of them resolves, and the file does not say which.</p>
<p><strong><code>doctor</code> shows mesh findings again after an upgrade.</strong> Its incremental cache keys on skill <em>content</em>, and upgrading schliff changes no file on your disk — so the verdict computed by the previous version was returned indefinitely. The cache now carries a version stamp and discards verdicts written by different analysis logic. If you ran <code>doctor</code> on 8.11.0, this is the release that makes its output correct again.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/Zandereins/schliff/compare/v8.11.0...v8.11.1">https://github.com/Zandereins/schliff/compare/v8.11.0...v8.11.1</a></p>
]]></content:encoded></item><item><title>Zero-X Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/zero-x-security-scanner/</link><pubDate>Mon, 10 Aug 2026 14:13:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/zero-x-security-scanner/</guid><description>Version updated for https://github.com/Zero-X-Security/zero-x-actions to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of your repository’s security vulnerabilities using Zero-X Cloud, which integrates with GitHub Actions workflows. It triggers a scan via Zero-X API, polls until completion, exports findings as SARIF format, and uploads them to GitHub Code Scanning. This helps you monitor and track security issues in real-time.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zero-X-Security/zero-x-actions">https://github.com/Zero-X-Security/zero-x-actions</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zero-x-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the scanning of your repository&rsquo;s security vulnerabilities using Zero-X Cloud, which integrates with GitHub Actions workflows. It triggers a scan via Zero-X API, polls until completion, exports findings as SARIF format, and uploads them to GitHub Code Scanning. This helps you monitor and track security issues in real-time.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #1 from Zero-X-Security/feature/sarif-file (459dc9b)</li>
<li>Release v1.0.2: publish findings to GitHub Code Scanning (213cd1a)</li>
<li>Update build process to use @vercel/ncc for bundling (926ee73)</li>
<li>updated desciption (076cb45)</li>
<li>Update workflows and documentation for Zero-X Action (4269cb7)</li>
<li>Add ESLint and Prettier configuration, enhance action inputs, and update documentation (912b608)</li>
<li>added workflows (6f8e468)</li>
<li>base dir setup (5fa40ee)</li>
</ul>
]]></content:encoded></item><item><title>Zuke Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/zuke-build/</link><pubDate>Mon, 10 Aug 2026 14:11:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/zuke-build/</guid><description>Version updated for https://github.com/zuke-build/zuke to version gh-v1.2.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action uses tagged template literals to define and run processes with sane defaults such as error handling and output capture, ensuring injection safety. It’s designed to be small and explicit, providing a core functionality of discovering targets, building a dependency graph, sorting, and running them in topological order.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zuke-build/zuke">https://github.com/zuke-build/zuke</a></strong> to version <strong>gh-v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zuke-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action uses tagged template literals to define and run processes with sane defaults such as error handling and output capture, ensuring injection safety. It&rsquo;s designed to be small and explicit, providing a core functionality of discovering targets, building a dependency graph, sorting, and running them in topological order.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="120-2026-08-10"><a href="https://github.com/zuke-build/zuke/compare/gh-v1.1.0...gh-v1.2.0">1.2.0</a> (2026-08-10)</h2>
<h3 id="features">Features</h3>
<ul>
<li>cut the action release from CI, and propose its pin as a pull request (<a href="https://github.com/zuke-build/zuke/issues/312">#312</a>) (<a href="https://github.com/zuke-build/zuke/commit/4449731fcc7a82a0f7b3c6625cbef3ab41f76217">4449731</a>)</li>
</ul>
]]></content:encoded></item><item><title>Codex Review Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/codex-review-gate/</link><pubDate>Mon, 10 Aug 2026 06:13:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/codex-review-gate/</guid><description>Version updated for https://github.com/JoeyTeng/codex-review-gate-action to version v1.5.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Codex Review Gate GitHub action automates a deterministic codex/review-gate status check that passes only when a complete and clean evidence snapshot is produced from the latest official trusted provider artifact. The action coordinates GitHub comments, reviews, reactions, and commit statuses to ensure repository maintainers can make Codex review a required branch-protection signal.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JoeyTeng/codex-review-gate-action">https://github.com/JoeyTeng/codex-review-gate-action</a></strong> to version <strong>v1.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codex-review-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Codex Review Gate GitHub action automates a deterministic <code>codex/review-gate</code> status check that passes only when a complete and clean evidence snapshot is produced from the latest official trusted provider artifact. The action coordinates GitHub comments, reviews, reactions, and commit statuses to ensure repository maintainers can make Codex review a required branch-protection signal.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="codex-review-gate-action-v151">codex-review-gate-action v1.5.1</h1>
<p>This compatibility release adds the centrally deployed reusable workflow while preserving the direct composite Action interface and the v1.4.0 decision semantics.</p>
<h2 id="canonical-githubcom-caller-after-activation">Canonical GitHub.com caller after activation</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Codex Review Gate</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request_target</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">types</span>: [<span style="color:#ae81ff">opened, reopened, synchronize, ready_for_review]</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">issue_comment</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">types</span>: [<span style="color:#ae81ff">created]</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request_review</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">types</span>: [<span style="color:#ae81ff">submitted]</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request_review_comment</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">types</span>: [<span style="color:#ae81ff">created]</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">schedule</span>:
</span></span><span style="display:flex;"><span>    - <span style="color:#f92672">cron</span>: <span style="color:#e6db74">&#34;0 */2 * * *&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">workflow_dispatch</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">inputs</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">description</span>: <span style="color:#ae81ff">Optional pull request number to gate</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">required</span>: <span style="color:#66d9ef">false</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">type</span>: <span style="color:#ae81ff">string</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">issues</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">statuses</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">concurrency</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">group</span>: <span style="color:#ae81ff">codex-review-gate-${{ github.repository }}</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">cancel-in-progress</span>: <span style="color:#66d9ef">false</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">codex-review-gate</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">name</span>: <span style="color:#ae81ff">codex/review-gate runner</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">JoeyTeng/codex-review-gate-action/.github/workflows/codex-review-gate.yml@v1</span>
</span></span></code></pre></div><p>The floating <code>@v1</code> selector is the intentional centralised pre-execution trust boundary. Post-run admission does not trust that selector alone. It binds <code>W</code> across the exact-attempt <code>referenced_workflows[].sha</code>, receipt <code>producer.job.workflow_sha</code>, and receipt <code>producer.action.ref</code>. It binds <code>C</code> across the full-SHA-pinned checkout step&rsquo;s official <code>commit</code> output, receipt <code>producer.action.commit_sha</code>, provenance <code>action.commit_oid</code>, and <code>tags.v1.peeled_commit_oid</code>.</p>
<p>Exactly one closed resolution branch is admitted:</p>
<ul>
<li>current live shape: <code>W == T == tags.v1.tag_object_oid</code>, and signed annotated tag <code>T</code> peels directly to <code>C</code>;</li>
<li>future exact-commit shape: <code>W == C == action.commit_oid</code>, while independently signed <code>T</code> still peels directly to <code>C</code>.</li>
</ul>
<p>Other object types, nested tags, and zero or multiple candidate matches fail closed. Historical runs use the exact attempt&rsquo;s recorded <code>W</code>; consumers never substitute the current <code>v1</code> ref.</p>
<h2 id="immutable-identities">Immutable identities</h2>
<ul>
<li>Source release commit: <code>e9a4a79866518ba07e9b0bf9df68dffdb02bfeef</code></li>
<li>Action release commit: <code>59eeda2af2a7baab3f3f15a59fbbaee015fa6c01</code></li>
<li>Source <code>packages/action</code> tree and Action release root tree: <code>8d909dd441b28b6915c46f60e8a144e64fd5268b</code></li>
<li>Released-tree NUL-manifest SHA-256: <code>be4e780d1cf3b6874d246d2c4edd1451f7ca10442781dd99f8d37385d229dd46</code></li>
<li>Provenance asset SHA-256: <code>db00a0b88be3cbff8956e6082544c418d7878f6b2a6405a0773af4eea5004fc8</code></li>
</ul>
<p>Immutable reusable audit pin:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">codex-review-gate</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">JoeyTeng/codex-review-gate-action/.github/workflows/codex-review-gate.yml@59eeda2af2a7baab3f3f15a59fbbaee015fa6c01</span>
</span></span></code></pre></div><p>Direct composite and GitHub Enterprise Server compatibility pin:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">JoeyTeng/codex-review-gate-action@59eeda2af2a7baab3f3f15a59fbbaee015fa6c01</span>
</span></span></code></pre></div><h2 id="protocol-compatibility-and-receipt-boundary">Protocol compatibility and receipt boundary</h2>
<ul>
<li>Producer protocol major: <code>1</code></li>
<li>Producer receipt schema: <code>urn:joeyteng:codex-review-gate:producer-receipt:1</code>, version <code>1</code></li>
<li>Decision policy major: <code>1</code></li>
<li>Decision policy version: <code>1.4.0</code></li>
<li>First admitted reusable release: <code>1.5.1</code>; the immutable v1.5.0 provenance contract is fail-closed and has no digest erratum.</li>
</ul>
<p>Reusable and direct GitHub.com runs expose <code>producer-receipt-artifact-id</code>, <code>producer-receipt-artifact-url</code>, and <code>producer-receipt-artifact-digest</code>. These values and the receipt provide causal-consistency and integrity evidence under a trusted caller workflow/job graph and the fixed GitHub-hosted runner; they are not a job-scoped cryptographic execution attestation. The run-level <code>referenced_workflows</code> array does not bind an entry to a specific job, status, or artifact, and a malicious same-run sibling remains outside that attribution boundary.</p>
<p>The reusable workflow checks out only <code>job.workflow_repository</code> at <code>job.workflow_sha</code>, to a fixed private path, and then runs the local composite from that release tree. It never checks out or executes caller or pull-request code. All external Actions are full-SHA pinned.</p>
<p>Moving <code>v1</code> does not activate this caller in the canonical source repository or its template. Activation remains a separate post-release change, gated on immutable-release verification and a successful live reusable-workflow canary.</p>
]]></content:encoded></item><item><title>Tackle Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/tackle-review/</link><pubDate>Mon, 10 Aug 2026 06:12:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/tackle-review/</guid><description>Version updated for https://github.com/JordanDalton/tackle-review to version v1.2.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Laravel pull request reviews by integrating AI-powered code review with Tackle. It provides inline comments, incremental re-reviews on every push, and optional merge gating. The action supports various providers and can be configured to fail merges based on critical findings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JordanDalton/tackle-review">https://github.com/JordanDalton/tackle-review</a></strong> to version <strong>v1.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tackle-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates Laravel pull request reviews by integrating AI-powered code review with Tackle. It provides inline comments, incremental re-reviews on every push, and optional merge gating. The action supports various providers and can be configured to fail merges based on critical findings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Marketplace-ready: action descriptions shortened to fit GitHub&rsquo;s 125-character limit, and a leftover <code>@tackle</code> in the respond action&rsquo;s description corrected to <code>/tackle</code>. No behavior changes.</p>
]]></content:encoded></item><item><title>AWE TraceGate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/awe-tracegate/</link><pubDate>Mon, 10 Aug 2026 06:11:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/awe-tracegate/</guid><description>Version updated for https://github.com/kingggg5/awe-tracegate to version 3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AWE TraceGate is a plugin that helps developers verify the safety and reliability of AI-generated skills by providing a deterministic and content-addressable framework. It allows users to compare agent changes, protect pull requests, review Agent Skills, connect evaluation harnesses, and share results in a transparent manner. The action provides a secure and offline path for skill verification without relying on any external resources or models.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kingggg5/awe-tracegate">https://github.com/kingggg5/awe-tracegate</a></strong> to version <strong>3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/awe-tracegate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AWE TraceGate is a plugin that helps developers verify the safety and reliability of AI-generated skills by providing a deterministic and content-addressable framework. It allows users to compare agent changes, protect pull requests, review Agent Skills, connect evaluation harnesses, and share results in a transparent manner. The action provides a secure and offline path for skill verification without relying on any external resources or models.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: ship TraceGate v0.3 cross-host plugin and atomic gate (#11) (e94b4ee)</li>
<li>feat: add skill-first TraceGate plugin (#10) (547c160)</li>
<li>feat: refine TraceGate Review experience (#9) (66f247d)</li>
<li>feat: ship evidence interoperability and command workspace (#8) (0aa2e44)</li>
<li>feat: gate promotion on replayed evidence chain (#7) (cad491e)</li>
<li>docs: embed workflow and architecture diagrams (#6) (4c856b7)</li>
<li>feat: release AWE TraceGate evidence gate (4e42fec)</li>
<li>feat: bootstrap evidence-gated AWE harness (7162cb4)</li>
</ul>
]]></content:encoded></item><item><title>Action Mailer ✨</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/action-mailer/</link><pubDate>Mon, 10 Aug 2026 06:10:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/action-mailer/</guid><description>Version updated for https://github.com/ksatriow/action-mailer to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Action Mailer is a GitHub Action that enables developers to send professional and beautiful emails directly from their CI/CD pipelines. It supports SMTP (Gmail, Outlook, SendGrid) or AWS SES with templates, attachments, CC/BCC, dynamic variables, auto-detection, rich logging, security best practices, and production readiness. The action simplifies the process of sending emails in automated workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ksatriow/action-mailer">https://github.com/ksatriow/action-mailer</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-mailer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Action Mailer is a GitHub Action that enables developers to send professional and beautiful emails directly from their CI/CD pipelines. It supports SMTP (Gmail, Outlook, SendGrid) or AWS SES with templates, attachments, CC/BCC, dynamic variables, auto-detection, rich logging, security best practices, and production readiness. The action simplifies the process of sending emails in automated workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>ci: add real notification test job (ef3459c)</li>
<li>build: bundle action with ncc and update action.yml (a63ef30)</li>
<li>fix: regenerate package-lock.json to sync with package.json (20724cd)</li>
<li>ci: add comprehensive test workflow for Action Mailer (71321c7)</li>
<li>feat: complete Action Mailer implementation with all features (3b165a5)</li>
<li>Update README.md (6e9be71)</li>
<li>action-mailer v1.0.0 (2c85110)</li>
</ul>
]]></content:encoded></item><item><title>NormWind Tailwind Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/normwind-tailwind-audit/</link><pubDate>Mon, 10 Aug 2026 06:08:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/normwind-tailwind-audit/</guid><description>Version updated for https://github.com/LunarWerxs/NormWind to version v3.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NormWind is a zero-config CLI and GitHub Action that helps normalize Tailwind utility classes by collapsing verbose combinations and non-canonical arbitrary values into their short, canonical forms. It audits and optionally fixes bloated class strings in your project without forcing any formatting or configuration changes. This tool is useful for teams aiming to maintain cleaner, more readable CSS outputs while leveraging the power of Tailwind’s utility-first approach.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LunarWerxs/NormWind">https://github.com/LunarWerxs/NormWind</a></strong> to version <strong>v3.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/normwind-tailwind-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NormWind is a zero-config CLI and GitHub Action that helps normalize Tailwind utility classes by collapsing verbose combinations and non-canonical arbitrary values into their short, canonical forms. It audits and optionally fixes bloated class strings in your project without forcing any formatting or configuration changes. This tool is useful for teams aiming to maintain cleaner, more readable CSS outputs while leveraging the power of Tailwind&rsquo;s utility-first approach.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="normwind-v380">NormWind v3.8.0</h2>
<p><em>2026-08-09 · merge-safety correctness fix, SARIF reporter, ignore files, broader scanning</em></p>
<ul>
<li><strong>Merge-safety gate for shorthand merges (correctness fix)</strong>: a merge such as <code>ml-2 mr-2</code> → <code>mx-2</code> is now applied only when Tailwind&rsquo;s own engine confirms the before and after class lists render identical CSS. Tailwind emits utilities in its own order, not authoring order, so a merge sharing a group with another utility at a different value (a pre-existing <code>mx-8</code> alongside <code>ml-2 mr-2</code>) could previously hand that other utility the win and silently change the rendered layout. <code>--fix</code>/<code>--fixall</code> now skip any merge that isn&rsquo;t provably safe instead of applying it blind; this closes a real path to a silent visual regression from <code>--fix</code>.</li>
<li><strong>New flags</strong>: <code>--reporter &lt;text|json|sarif&gt;</code> (<code>sarif</code> emits SARIF 2.1.0 for GitHub code scanning; <code>--json</code> remains an alias for <code>--reporter json</code>), <code>--ignore &lt;glob&gt;</code> (repeatable), <code>--allow-empty</code> (exit <code>0</code> instead of <code>2</code> when a pattern matches nothing), and <code>--</code> to end flag parsing so a target can start with a dash.</li>
<li><strong><code>.normwindignore</code></strong>: a project-local ignore file (one glob per line, <code>#</code> comments, a bare directory name means everything under it) is now read automatically from the scanned directory. It is deliberately not read in GitHub Action mode, since the file is checkout-controlled and a pull request could otherwise silence the audit on the very files it changed; <code>--ignore</code> flags are always honored in both modes.</li>
<li><strong>Broader file matching</strong>: <code>.svelte</code>, <code>.astro</code> (frontmatter skipped, markup scanned), and plain <code>.html</code>/<code>.htm</code> join the default scan alongside Vue/JS/TS. The generated-folder ignore list dropped project-specific paths and now covers <code>.next</code>, <code>.nuxt</code>, <code>.output</code>, <code>.svelte-kit</code>, <code>.turbo</code>, and <code>storybook-static</code> at any depth, plus root-only build folders such as <code>build</code>, <code>coverage</code>, <code>out</code>, and <code>vendor</code>.</li>
<li><strong>Class-string builders are scanned</strong>: <code>clsx</code>, <code>cx</code>, <code>cn</code>, <code>classnames</code>, <code>classNames</code>, <code>cva</code>, <code>tv</code>, <code>twMerge</code>, and <code>twJoin</code> calls, including strings nested in <code>cva</code>/<code>tv</code> variant objects, arrays, ternaries, and <code>cond &amp;&amp; &quot;...&quot;</code>, with locally-aliased imports resolved.</li>
<li><strong><code>--fix</code> covers every markup format</strong>: <code>.svelte</code>, <code>.astro</code>, and <code>.html</code>/<code>.htm</code> join <code>.vue</code> in the safe default fixer, not just <code>--fixall</code>.</li>
<li><strong>Composite equivalences are now fixable</strong>: <code>truncate</code>, <code>place-content-*</code>, <code>place-items-*</code>, and <code>place-self-*</code> findings are applied by <code>--fix</code>/<code>--fixall</code> instead of being audit-only, so a fix-then-audit CI loop can actually reach exit <code>0</code>.</li>
<li><strong>Stricter exit codes</strong>: a pattern matching no lintable files now exits <code>2</code> instead of <code>0</code> (<code>--allow-empty</code> restores the old behavior), and <code>--fix</code>/<code>--fixall</code>/<code>--dry-run</code> combined with a canonical-maintenance flag, or <code>--dry-run</code> without <code>--fix</code>/<code>--fixall</code>, now exits <code>2</code> instead of silently doing nothing.</li>
</ul>
<p><strong>Full comparison:</strong> <a href="https://github.com/LunarWerxs/NormWind/compare/v3.7.0...v3.8.0">v3.7.0&hellip;v3.8.0</a></p>
]]></content:encoded></item><item><title>MCP-VCR Verify Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/mcp-vcr-verify-action/</link><pubDate>Mon, 10 Aug 2026 06:07:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/mcp-vcr-verify-action/</guid><description>Version updated for https://github.com/MCP-VCR/mcp-vcr to version 0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MCP-VCR is a tool that records and verifies MCP client-server conversations, ensuring consistent behavior in CI pipelines. It normalizes data to ensure reproducibility, protects against credential leaks, and supports various replay options. The action helps developers catch regressions early by providing a layer of transparency between clients and servers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MCP-VCR/mcp-vcr">https://github.com/MCP-VCR/mcp-vcr</a></strong> to version <strong>0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-vcr-verify-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>MCP-VCR is a tool that records and verifies MCP client-server conversations, ensuring consistent behavior in CI pipelines. It normalizes data to ensure reproducibility, protects against credential leaks, and supports various replay options. The action helps developers catch regressions early by providing a layer of transparency between clients and servers.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<p>We are excited to release <code>v0.2.0</code>, introducing core architecture upgrades for custom transports, a dedicated Pytest plugin for offline VCR testing, and security hardening for CLI and CI environments.</p>
<h3 id="-key-features--upgrades">🚀 Key Features &amp; Upgrades</h3>
<ul>
<li><strong>Transport Abstraction Layer</strong>: Replaced tight stdio coupling with an extensible <code>Transport</code> protocol supporting both local <code>StdioTransport</code> and remote <code>SseTransport</code> (SSE + HTTP POST).</li>
<li><strong>Pytest Plugin (<code>pytest-mcp-vcr</code>)</strong>: Added first-class offline replaying fixtures for deterministic unit testing of MCP clients and servers.</li>
<li><strong>Large Transcript Streaming</strong>: Replaced full-memory transcript backfilling with space-efficient O(1) memory tempfile streaming for large NDJSON logs.</li>
<li><strong>Timing-Faithful Replays</strong>: Improved sleep latency calculation to execute relative to the session start to avoid drift accumulation.</li>
</ul>
<h3 id="-security--stability-hardening">🔒 Security &amp; Stability Hardening</h3>
<ul>
<li><strong>URL Log Redaction</strong>: Strips sensitive query parameters, API tokens, and credentials from all user-facing console logs and recorded command metadata.</li>
<li><strong>SSE Payload Size Bounding</strong>: Implemented byte size limits on incoming SSE event payloads to prevent memory overflow.</li>
<li><strong>Credential Isolation</strong>: Hardened CI workflow workflows by disabling credential persistence in checked-out code steps.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/MCP-VCR/mcp-vcr/compare/v0.1.5...0.2.0">https://github.com/MCP-VCR/mcp-vcr/compare/v0.1.5...0.2.0</a></p>
]]></content:encoded></item><item><title>provensql SQL equivalence check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/provensql-sql-equivalence-check/</link><pubDate>Mon, 10 Aug 2026 06:06:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/provensql-sql-equivalence-check/</guid><description>Version updated for https://github.com/nac7/provensql-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks SQL equivalence for pull requests by comparing modified .sql files (base vs. head versions) using the provensql tool. It reports four verdicts per file: EQUIVALENT, UNKNOWN, DIFFERENT, or SCHEMA_CHANGE based on the proven behavior changes or undecidability of the diffs. The action is sound by construction and can fail the job only when a proven behavior change occurs, with an option to report UNKNOWN for human review.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nac7/provensql-action">https://github.com/nac7/provensql-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/provensql-sql-equivalence-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks SQL equivalence for pull requests by comparing modified <code>.sql</code> files (base vs. head versions) using the <code>provensql</code> tool. It reports four verdicts per file: EQUIVALENT, UNKNOWN, DIFFERENT, or SCHEMA_CHANGE based on the proven behavior changes or undecidability of the diffs. The action is sound by construction and can fail the job only when a proven behavior change occurs, with an option to report <code>UNKNOWN</code> for human review.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>provensql checks the SQL changed in a pull request and fails the build
when a change is not proven equivalence-preserving. Sound by construction:
it never reports a false EQUIVALENT.</p>
<p>Usage:</p>
<ul>
<li>uses: actions/checkout@v4
with: { fetch-depth: 0 }</li>
<li>uses: nac7/provensql-action@v1
with:
paths: &ldquo;**/*.sql&rdquo;
fail-on: different</li>
</ul>
<p>Verdicts: EQUIVALENT / DIFFERENT (with a counterexample row) /
SCHEMA_CHANGE / UNKNOWN. Apache-2.0</p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/go-proxy-cache-updater/</link><pubDate>Mon, 10 Aug 2026 06:05:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.41.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically pulls new releases of Go modules to a specified proxy cache whenever new tags are created. It supports standard and submodule version formats, customizable proxy configurations, and custom import paths. The action is configured via YAML workflows and provides features such as caching and dependency file support.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.41</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically pulls new releases of Go modules to a specified proxy cache whenever new tags are created. It supports standard and submodule version formats, customizable proxy configurations, and custom import paths. The action is configured via YAML workflows and provides features such as caching and dependency file support.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1141-2026-08-10"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.40...v1.1.41">1.1.41</a> (2026-08-10)</h2>
]]></content:encoded></item><item><title>lacuna-cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/lacuna-cli/</link><pubDate>Mon, 10 Aug 2026 06:04:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/lacuna-cli/</guid><description>Version updated for https://github.com/Octagon-simon/lacuna to version ext-v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Lacuna is a command-line tool that automates the process of finding untested code in your project and writing tests to cover it. It uses an OpenAI-compatible model to generate test cases based on code coverage analysis and ensures that the generated tests pass by retrying them until they are successful.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Octagon-simon/lacuna">https://github.com/Octagon-simon/lacuna</a></strong> to version <strong>ext-v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lacuna-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Lacuna is a command-line tool that automates the process of finding untested code in your project and writing tests to cover it. It uses an OpenAI-compatible model to generate test cases based on code coverage analysis and ensures that the generated tests pass by retrying them until they are successful.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Octagon-simon/lacuna/compare/v0.3.5...ext-v0.1.0">https://github.com/Octagon-simon/lacuna/compare/v0.3.5...ext-v0.1.0</a></p>
]]></content:encoded></item><item><title>Oculum Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/oculum-security-scan/</link><pubDate>Mon, 10 Aug 2026 06:03:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/oculum-security-scan/</guid><description>Version updated for https://github.com/OculumDev/oculum-action to version 1.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Oculum Security Scan action is a GitHub Action that detects AI-era security vulnerabilities in LLM-powered applications. It combines both AI-assisted validation and traditional static application security testing (SAST) to find hardcoded secrets, SQL injection, XSS, and more. The action supports both the free tier for pattern-matching scans at no cost and validated scans using an API key for enhanced accuracy and lower false positives. It provides real-time feedback through PR comments and inline annotations on code diffs, making it easy to identify and address security issues early in the development cycle.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OculumDev/oculum-action">https://github.com/OculumDev/oculum-action</a></strong> to version <strong>1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oculum-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Oculum Security Scan action is a GitHub Action that detects AI-era security vulnerabilities in LLM-powered applications. It combines both AI-assisted validation and traditional static application security testing (SAST) to find hardcoded secrets, SQL injection, XSS, and more. The action supports both the free tier for pattern-matching scans at no cost and validated scans using an API key for enhanced accuracy and lower false positives. It provides real-time feedback through PR comments and inline annotations on code diffs, making it easy to identify and address security issues early in the development cycle.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Early Release of Oculum Security Scanner</p>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/odin-scan-smart-contract-security/</link><pubDate>Mon, 10 Aug 2026 06:02:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Odin Scan GitHub Action automates smart contract security analysis for CosmWasm, Solana, and EVM projects. It integrates with GitHub Code Scanning to provide SARIF files for native security alerts, automatically detects platforms, posts PR comments, and includes inline annotations on changed files. The action can be triggered on pull requests and supports configurable thresholds for severity levels and options like commenting and artifact uploads.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Odin Scan GitHub Action automates smart contract security analysis for CosmWasm, Solana, and EVM projects. It integrates with GitHub Code Scanning to provide SARIF files for native security alerts, automatically detects platforms, posts PR comments, and includes inline annotations on changed files. The action can be triggered on pull requests and supports configurable thresholds for severity levels and options like commenting and artifact uploads.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial Release</p>
<p>AI-powered smart contract security analysis, now integrated directly into your GitHub workflow.</p>
<p>✨ Features</p>
<p>Multi-Platform Support</p>
<ul>
<li>CosmWasm - Rust-based smart contracts for Cosmos SDK</li>
<li>Solana (SVM) - Anchor and native Solana programs</li>
<li>EVM - Solidity and Vyper contracts</li>
<li>Auto-detection - Automatically identifies platform from your repo</li>
</ul>
<p>GitHub Integration</p>
<ul>
<li>Code Scanning - SARIF upload for native security alerts in the Security tab</li>
<li>PR Comments - Severity summary and top findings posted directly on pull requests</li>
<li>Inline Annotations - Critical/high findings appear as errors, medium/low as warnings on diffs</li>
<li>Artifact Upload - Full JSON report available as workflow artifact</li>
</ul>
<p>Customization</p>
<ul>
<li>Severity Thresholds - Fail builds at critical, high, medium, or low severity</li>
<li>Platform Override - Force specific platform detection when auto-detect isn&rsquo;t enough</li>
<li>Timeout Control - Configurable analysis timeout (default: 30 minutes)</li>
<li>Flexible Triggers - Run on push, PR, schedule, or manual dispatch</li>
</ul>
<p>🚀 Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Security Scan</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&#39;on&#39;</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">main</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">security-events</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">api-key</span>: <span style="color:#e6db74">&#39;${{ secrets.ODIN_SCAN_API_KEY }}&#39;</span>
</span></span></code></pre></div><p>📋 Requirements</p>
<ul>
<li>Odin Scan Pro subscription - Required for API access</li>
<li>API Key - Generate at <a href="https://odinscan.ai/dashboard/settings">https://odinscan.ai/dashboard/settings</a></li>
<li>GitHub Permissions - contents: read, security-events: write (for SARIF), pull-requests: write (for
comments)</li>
</ul>
<p>🔧 Configuration</p>
<p>All Inputs</p>
<p>| ┌────────────────────┬─────────────────────┬──────────────────────────────────────────────┐ |
| │       Input        │       Default       │                 Description                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ api-key            │ Required            │ Your Odin Scan API key (odin_sk_*)           │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ platform           │ auto                │ Target platform: auto, cosmwasm, solana, evm │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ severity-threshold │ high                │ Fail at: critical, high, medium, low, none   │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ fail-on-findings   │ true                │ Whether to fail workflow on findings         │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ comment-on-pr      │ true                │ Post summary comment on PRs                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-sarif       │ true                │ Upload SARIF to Code Scanning                │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-artifact    │ true                │ Upload full report as artifact               │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ timeout            │ 1800                │ Max analysis wait time (seconds)             │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ github-token       │ ${{ github.token }} │ Token for PR comments and SARIF              │ |
| └────────────────────┴─────────────────────┴──────────────────────────────────────────────┘ |</p>
<p>All Outputs</p>
<ul>
<li>analysis-id - Unique analysis identifier</li>
<li>status - Analysis status (completed, failed)</li>
<li>total-findings - Total number of findings</li>
<li>critical-count, high-count, medium-count, low-count - Counts by severity</li>
<li>report-url - Link to full report on Odin Scan</li>
<li>sarif-file - Path to generated SARIF file</li>
</ul>
<p>📝 Example Workflows</p>
<p>Basic (Auto-detect)</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span></code></pre></div><p>EVM with Medium Threshold</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">platform</span>: <span style="color:#ae81ff">evm</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">severity-threshold</span>: <span style="color:#ae81ff">medium</span>
</span></span></code></pre></div><p>Only on Solidity Changes</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#39;**.sol&#39;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">foundry.toml</span>
</span></span></code></pre></div><p>🔒 Security &amp; Privacy</p>
<ul>
<li>All API communication over HTTPS (TLS 1.2+)</li>
<li>API keys automatically masked in logs</li>
<li>No data stored by the action (stateless)</li>
<li>See <a href="https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md">https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md</a> for details</li>
</ul>
<p>📖 Documentation</p>
<ul>
<li>Action README - <a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></li>
<li>Odin Scan Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
<li>Get API Key - <a href="https://app.odinscan.ai/settings">https://app.odinscan.ai/settings</a></li>
</ul>
<p>🐛 Known Limitations</p>
<ul>
<li>Private repos - Requires github-token with repo access</li>
<li>Large repos - May need increased timeout for complex codebases</li>
<li>Code Scanning - Requires GitHub Advanced Security on private repos</li>
</ul>
<p>🙏 Support</p>
<ul>
<li>Issues - <a href="https://github.com/Odin-Scan/odin-scan-action/issues">https://github.com/Odin-Scan/odin-scan-action/issues</a></li>
<li>Email - <a href="mailto:support@odinscan.ai">support@odinscan.ai</a></li>
<li>Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
</ul>
<hr>
<p>Full Changelog: <a href="https://github.com/Odin-Scan/odin-scan-action/commits/v1">https://github.com/Odin-Scan/odin-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>mdx-embeddings-actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/mdx-embeddings-actions/</link><pubDate>Mon, 10 Aug 2026 06:00:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/mdx-embeddings-actions/</guid><description>Version updated for https://github.com/PieterDePauw/mdx-embeddings-actions to version v.0.0.9-alpha.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the conversion of markdown files into embeddings using OpenAI and stores them in a Supabase database. It allows for vector similarity search within documentation and websites, complementing the headless-vector-search repository by facilitating data storage and retrieval for vector-based queries. The action is available on the Marketplace and requires specific environment variables to be set as secrets for authentication and configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PieterDePauw/mdx-embeddings-actions">https://github.com/PieterDePauw/mdx-embeddings-actions</a></strong> to version <strong>v.0.0.9-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mdx-embeddings-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the conversion of markdown files into embeddings using OpenAI and stores them in a Supabase database. It allows for vector similarity search within documentation and websites, complementing the <code>headless-vector-search</code> repository by facilitating data storage and retrieval for vector-based queries. The action is available on the Marketplace and requires specific environment variables to be set as secrets for authentication and configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/PieterDePauw/mdx-embeddings-actions/compare/v.0.0.8-alpha...v.0.0.9-alpha">https://github.com/PieterDePauw/mdx-embeddings-actions/compare/v.0.0.8-alpha...v.0.0.9-alpha</a></p>
]]></content:encoded></item><item><title>Setup pnpm with runtime</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/setup-pnpm-with-runtime/</link><pubDate>Mon, 10 Aug 2026 06:00:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/setup-pnpm-with-runtime/</guid><description>Version updated for https://github.com/pnpm/setup to version v2.0.2.
This action is used across all versions by 374 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs pnpm and a JavaScript runtime (Node.js, Bun, or Deno) in a single step. It automates the setup process by downloading pnpm’s self-contained binary and setting up the specified runtime on the runner’s PATH. The action automatically detects the required runtime from package.json if not provided as an input, reducing the need for multiple setup steps.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pnpm/setup">https://github.com/pnpm/setup</a></strong> to version <strong>v2.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>374</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-pnpm-with-runtime">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs pnpm and a JavaScript runtime (Node.js, Bun, or Deno) in a single step. It automates the setup process by downloading pnpm&rsquo;s self-contained binary and setting up the specified runtime on the runner&rsquo;s PATH. The action automatically detects the required runtime from <code>package.json</code> if not provided as an input, reducing the need for multiple setup steps.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: install pnpm from the npm registry, verified against npm&rsquo;s signature by @zkochan in <a href="https://github.com/pnpm/setup/pull/24">https://github.com/pnpm/setup/pull/24</a></li>
<li>fix: keep the installed runtime authoritative against context-aware shims by @zkochan in <a href="https://github.com/pnpm/setup/pull/25">https://github.com/pnpm/setup/pull/25</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pnpm/setup/compare/v2.0.1...v2.0.2">https://github.com/pnpm/setup/compare/v2.0.1...v2.0.2</a></p>
]]></content:encoded></item><item><title>Multi-Style Contribution Snake</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/multi-style-contribution-snake/</link><pubDate>Mon, 10 Aug 2026 05:58:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/multi-style-contribution-snake/</guid><description>Version updated for https://github.com/Pro-Bandey/multi-style-snake-contribution-grid to version v10.08.26.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Multi-Style Snake Contribution Grid GitHub Action generates multiple visually distinct snake styles, including squares, rounds, triangles, stars, and diamonds, for each month of the repository’s contribution graph. It automates the process by analyzing the repository owner and creating a gallery in the output branch with SVGs and a README.md file for easy viewing and sharing on GitHub Pages.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Pro-Bandey/multi-style-snake-contribution-grid">https://github.com/Pro-Bandey/multi-style-snake-contribution-grid</a></strong> to version <strong>v10.08.26</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/multi-style-contribution-snake">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Multi-Style Snake Contribution Grid GitHub Action generates multiple visually distinct snake styles, including squares, rounds, triangles, stars, and diamonds, for each month of the repository&rsquo;s contribution graph. It automates the process by analyzing the repository owner and creating a gallery in the <code>output</code> branch with SVGs and a README.md file for easy viewing and sharing on GitHub Pages.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-multi-style-snake-daily-update">🐍 Multi-Style Snake Daily Update</h2>
<p>Automated daily release to the GitHub Marketplace.</p>
<p><strong>Version Details:</strong></p>
<ul>
<li><strong>Tag:</strong> <code>v10.08.26</code></li>
<li><strong>Release Date:</strong> $(date +&rsquo;%A, %B %d, 20%y')</li>
</ul>
<p><strong>Included Features:</strong></p>
<ul>
<li>5 Unique Snake Styles (Blocks, Rounds, Triangles, Stars, Diamonds)</li>
<li>Automated Month Labels above grids</li>
<li>Dynamic Username Detection</li>
<li>Auto-generated Asset Gallery</li>
</ul>
]]></content:encoded></item><item><title>Garita PII Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/garita-pii-guard/</link><pubDate>Mon, 10 Aug 2026 05:57:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/garita-pii-guard/</guid><description>Version updated for https://github.com/proscar87/garita to version v0.30.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Garita is an open-source GitHub Action that helps protect sensitive data like personal identifiers and credentials from entering your repository. It checks for potential PII (Personally Identifiable Information) in commits and files using a configurable list of patterns. Garita uses abstract syntax tree parsing to monitor the repository without executing code, ensuring that any false positives are caught before they make their way into production.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/proscar87/garita">https://github.com/proscar87/garita</a></strong> to version <strong>v0.30.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/garita-pii-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Garita is an open-source GitHub Action that helps protect sensitive data like personal identifiers and credentials from entering your repository. It checks for potential PII (Personally Identifiable Information) in commits and files using a configurable list of patterns. Garita uses abstract syntax tree parsing to monitor the repository without executing code, ensuring that any false positives are caught before they make their way into production.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Arreglo de pruebas. <strong>Ningún cambio de comportamiento.</strong></p>
<p>La prueba del escapado de la tabla del resumen creaba un archivo llamado <code>tubo|corte.py</code>, y en Windows eso no se puede ni crear: <code>OSError 22</code> antes de llegar a la aserción. Tumbó los tres casos de la clase en <code>windows-latest</code> y dejó CI en rojo con v0.30.0 ya publicada.</p>
<p>Es el mismo molde que los dos puntos en v0.15.0, y ahí la salida fue saltarse Windows. Esta vez no: el escapado se prueba llamando a <code>resumen_markdown</code> con hallazgos construidos a mano, <strong>sin tocar el disco</strong>, así que corre en las cinco plataformas — incluida la única donde el carácter es ilegal, que es justo la que un skip habría dejado sin cubrir.</p>
<p>Verificado que la prueba nueva falla contra el <code>reporte.py</code> de v0.29.0. 299 pruebas.</p>
]]></content:encoded></item><item><title>Cloudflare IP List Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/cloudflare-ip-list-sync/</link><pubDate>Mon, 10 Aug 2026 05:56:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/cloudflare-ip-list-sync/</guid><description>Version updated for https://github.com/rezzell/cloudflare-ip-list-sync-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action synchronizes composed IP and CIDR sources into a Cloudflare account IP list, solving the problem of keeping WAF lists up-to-date with published provider ranges. It automates tasks such as updating GitHub webhook egress ranges from the GitHub Meta API to Cloudflare’s WAF rules list. The action supports various input types including GitHub Meta hooks, CIDR strings, and URL sources, making it flexible for different use cases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rezzell/cloudflare-ip-list-sync-action">https://github.com/rezzell/cloudflare-ip-list-sync-action</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cloudflare-ip-list-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action synchronizes composed IP and CIDR sources into a Cloudflare account IP list, solving the problem of keeping WAF lists up-to-date with published provider ranges. It automates tasks such as updating GitHub webhook egress ranges from the GitHub Meta API to Cloudflare&rsquo;s WAF rules list. The action supports various input types including GitHub Meta <code>hooks</code>, CIDR strings, and URL sources, making it flexible for different use cases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release</p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/kaniko-build-action/</link><pubDate>Mon, 10 Aug 2026 05:55:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or “Hello” + a specified name to the log, solving the problem of automating basic greeting messages. It provides flexibility in greeting names through an input parameter and outputs the current time.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or &ldquo;Hello&rdquo; + a specified name to the log, solving the problem of automating basic greeting messages. It provides flexibility in greeting names through an input parameter and outputs the current time.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/custom-amazon-bedrock-agent-action/</link><pubDate>Mon, 10 Aug 2026 05:55:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action leverages Amazon Bedrock Agent to analyze files in pull requests, providing customizable feedback through tailored prompts. It integrates with Amazon Bedrock Knowledge Bases for enhanced context-aware insights and supports various programming languages and Terraform configurations. The action is highly flexible and customizable, making it suitable for code quality improvement, security assessments, and performance optimizations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action leverages Amazon Bedrock Agent to analyze files in pull requests, providing customizable feedback through tailored prompts. It integrates with Amazon Bedrock Knowledge Bases for enhanced context-aware insights and supports various programming languages and Terraform configurations. The action is highly flexible and customizable, making it suitable for code quality improvement, security assessments, and performance optimizations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/sherpa.sh/</link><pubDate>Mon, 10 Aug 2026 05:54:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-based infrastructure management tool that automates the deployment of applications to various cloud providers by understanding developers’ needs in plain English. It simplifies complex deployment processes, making it easier for developers without extensive technical knowledge to deploy their code seamlessly across different environments and services.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-based infrastructure management tool that automates the deployment of applications to various cloud providers by understanding developers&rsquo; needs in plain English. It simplifies complex deployment processes, making it easier for developers without extensive technical knowledge to deploy their code seamlessly across different environments and services.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/smyklot/</link><pubDate>Mon, 10 Aug 2026 05:53:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.17.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges using CODEOWNERS permissions. It supports multiple command formats, provides reaction-based approval and merge options, and includes features like cleanup commands and minimal permissions to run either as an Action or a webhook service across all repositories the app is installed on.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.17.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges using CODEOWNERS permissions. It supports multiple command formats, provides reaction-based approval and merge options, and includes features like cleanup commands and minimal permissions to run either as an Action or a webhook service across all repositories the app is installed on.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1170-2026-08-09"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.16.0...v1.17.0">1.17.0</a> (2026-08-09)</h2>
<h2 id="smyklot-v1170">Smyklot v1.17.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.17.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>80def87733e94434b9fd42244c0762bf8149a580 chore(release): bump version to 1.17.0</li>
<li>931113b4dd5edda7a2019cdbe09dc9f478895169 feat(panel): standardize the admin dashboard (#176)</li>
<li>b0f1311a06fba40ce31741e4fd92757adc76d50e feat(panel): add role-based user management (#175)</li>
<li>9355acd02cbef124757f0cf75178c2eec24fcc13 chore(deps): lock file maintenance (#174)</li>
<li>efe55ba3538bf83fc3a08bfb641b17920d957509 chore(deps): update dependency @sveltejs/vite-plugin-svelte to v7.3.0 (#173)</li>
<li>7a60f3ebfff0c732fd87a8ac8d9bab923242b93e chore(deps): update dependency vite to v8.2.1 (#172)</li>
<li>cd7376969fd3cfe37756eff96a1294258257a4f3 chore(deps): update dependency svelte-check to v4.7.5 (#171)</li>
<li>5249eef40267862d92657040065da9697e38e1d0 chore(deps): update dependency eslint to v10.8.1 (#170)</li>
<li>aba3eb923db736acf728a2443653da830195168c docs(storage): note offset pagination tradeoff (#169)</li>
<li>fdf869a285a1d6c16441d42a629ae945d82ac7a4 chore(deps): update dependency typescript-eslint to v8.66.0 (#164)</li>
<li>ee9d8b63f728d12dcd8e330e013e39e31325255e chore(deps): update dependency @types/node to v24 (#166)</li>
<li>0286a95923f4ec66e10d5898ca7697a18b040dd6 chore(deps): update npm to v12.0.2 (#160)</li>
<li>735217d1e0b2664d91d0d2f14ba8af6e8cf5e16a chore(deps): update dependency globals to v17.9.0 (#163)</li>
<li>ecb0077a0d19653eba20500fae74c4c429b43a05 fix(deps): update module go.yaml.in/yaml/v3 to v3.0.5 (#161)</li>
<li>12213c00a06a719976c4722b3deebc599c6c622f chore(deps): update dependency vite to v8.2.0 (#165)</li>
<li>032be6ca12feee428195fb182dd6770b1d1a555e feat(assets): add wide-ring and transparent sets (#168)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/update-a-config-file-with-values-from-environment/</link><pubDate>Mon, 10 Aug 2026 05:52:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The config-file-from-env GitHub Action replaces placeholders in configuration files with values from environment variables. It helps automate the process of managing sensitive data or configurations by securely storing them outside of the repository and retrieving them during runtime. This action is useful for deploying applications where configuration files need to be customized based on different environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>config-file-from-env</code> GitHub Action replaces placeholders in configuration files with values from environment variables. It helps automate the process of managing sensitive data or configurations by securely storing them outside of the repository and retrieving them during runtime. This action is useful for deploying applications where configuration files need to be customized based on different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add support for .env files (e706be3)</li>
<li>chore: More info (d440258)</li>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Mon, 10 Aug 2026 05:52:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by bundling dependencies and committing the dist folder. It ensures that the necessary files are ready for deployment before pushing changes to the repository, facilitating a smoother workflow during development.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by bundling dependencies and committing the <code>dist</code> folder. It ensures that the necessary files are ready for deployment before pushing changes to the repository, facilitating a smoother workflow during development.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>Advanced Jules PR Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/advanced-jules-pr-reviewer/</link><pubDate>Mon, 10 Aug 2026 05:52:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/advanced-jules-pr-reviewer/</guid><description>Version updated for https://github.com/thalesraymond/jules-pr-reviewer to version v1.6.0.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Google Jules to review pull requests and post comments directly on the lines of code where security issues are found, providing line-level feedback. It automatically resolves its own comments if the issues are fixed and prevents duplicate findings in subsequent commits. The action is designed to work with any programming language or framework and uses a low-noise approach by default.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thalesraymond/jules-pr-reviewer">https://github.com/thalesraymond/jules-pr-reviewer</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/advanced-jules-pr-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Google Jules to review pull requests and post comments directly on the lines of code where security issues are found, providing line-level feedback. It automatically resolves its own comments if the issues are fixed and prevents duplicate findings in subsequent commits. The action is designed to work with any programming language or framework and uses a low-noise approach by default.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="160-2026-08-09"><a href="https://github.com/thalesraymond/jules-pr-reviewer/compare/v1.5.0...v1.6.0">1.6.0</a> (2026-08-09)</h2>
<h3 id="features">Features</h3>
<ul>
<li>adopt GitHub Checks API for review status (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/ae00f48877ec8fc8e9a298db472c65ca6e575f9d">ae00f48</a>), closes <a href="https://github.com/thalesraymond/jules-pr-reviewer/issues/113">#113</a></li>
<li><strong>dedup:</strong> dedplucation feat (<a href="https://github.com/thalesraymond/jules-pr-reviewer/issues/132">#132</a>) (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/65360680675c72aa0510965e13915b50d783044e">6536068</a>)</li>
<li>harden concurrency (<a href="https://github.com/thalesraymond/jules-pr-reviewer/issues/134">#134</a>) (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/637bd3022fdb6648c134f73e4089b83e59a4293f">637bd30</a>)</li>
<li>large pr handling (<a href="https://github.com/thalesraymond/jules-pr-reviewer/issues/133">#133</a>) (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/f618fe638201e6fca6ed71102fe483c17c355f3a">f618fe6</a>)</li>
<li>ticket 113 (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/d399580712c2b99df1f8cb3d1b436b22a6acff6f">d399580</a>)</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/wails3-build-action/</link><pubDate>Mon, 10 Aug 2026 05:50:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub action automates the build process for Wails.io v3 projects by installing GoLang, NodeJS, and running a build. It supports building for multiple platforms and options to obfuscate the build, upload results to GitHub, and publish releases on tag. The action can be configured with various options such as Go version, Wails version, and platform settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub action automates the build process for Wails.io v3 projects by installing GoLang, NodeJS, and running a build. It supports building for multiple platforms and options to obfuscate the build, upload results to GitHub, and publish releases on tag. The action can be configured with various options such as Go version, Wails version, and platform settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>OVPN Connect and Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/ovpn-connect-and-verify/</link><pubDate>Mon, 10 Aug 2026 05:50:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/ovpn-connect-and-verify/</guid><description>Version updated for https://github.com/uchauhan1994/OVPN-connect-actions to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The OVPN Connect Action connects a GitHub Actions job to an OpenVPN network and verifies connectivity to a specified host through the VPN. It automates the process of setting up an OpenVPN connection, decoding credentials from GitHub Secrets, and testing the connection to ensure the host is reachable. The action supports username/password authentication and TLS encryption via environment variables or GitHub Secrets, providing clear output indicating whether the connection was successful.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/uchauhan1994/OVPN-connect-actions">https://github.com/uchauhan1994/OVPN-connect-actions</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ovpn-connect-and-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The OVPN Connect Action connects a GitHub Actions job to an OpenVPN network and verifies connectivity to a specified host through the VPN. It automates the process of setting up an OpenVPN connection, decoding credentials from GitHub Secrets, and testing the connection to ensure the host is reachable. The action supports username/password authentication and TLS encryption via environment variables or GitHub Secrets, providing clear output indicating whether the connection was successful.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/uchauhan1994/OVPN-connect-actions/commits/v1">https://github.com/uchauhan1994/OVPN-connect-actions/commits/v1</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/b.ia-accessibility-checker/</link><pubDate>Mon, 10 Aug 2026 05:49:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/10/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates the accessibility check of code in your CI/CD pipeline. It helps companies define an audience and percentage of WCAG guidelines to ensure their products are accessible, making it easier for them to follow accessibility standards without extensive learning. This tool saves time by using AI analysis to measure guidelines more abstractly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates the accessibility check of code in your CI/CD pipeline. It helps companies define an audience and percentage of WCAG guidelines to ensure their products are accessible, making it easier for them to follow accessibility standards without extensive learning. This tool saves time by using AI analysis to measure guidelines more abstractly.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>KubeAtlas Dependency Graph</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/kubeatlas-dependency-graph/</link><pubDate>Sun, 09 Aug 2026 22:10:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/kubeatlas-dependency-graph/</guid><description>Version updated for https://github.com/lithastra/kubeatlas-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The KubeAtlas GitHub Action automates the rendering of a KubeAtlas dependency graph from a Kubernetes cluster’s configuration. It reads a kubeconfig, targets specific scopes (like clusters or namespaces), and outputs an SVG file that can be used to visualize dependencies within the cluster. The action supports uploading the SVG as a workflow artifact and optionally running additional checks using kubeatlas diagnose to identify policy violations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lithastra/kubeatlas-action">https://github.com/lithastra/kubeatlas-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kubeatlas-dependency-graph">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The KubeAtlas GitHub Action automates the rendering of a KubeAtlas dependency graph from a Kubernetes cluster&rsquo;s configuration. It reads a kubeconfig, targets specific scopes (like clusters or namespaces), and outputs an SVG file that can be used to visualize dependencies within the cluster. The action supports uploading the SVG as a workflow artifact and optionally running additional checks using <code>kubeatlas diagnose</code> to identify policy violations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>KubeAtlas Action v1.0.1 strengthens policy-report execution and release safety.</p>
<ul>
<li>Fixes temporary-directory cleanup for downloaded CLI artifacts.</li>
<li>Adds policy-report output for pull-request workflows.</li>
<li>Verifies real release download, checksum, extraction, execution, and cleanup in Kind smoke tests.</li>
<li>Documents compatibility with KubeAtlas v1.5.</li>
<li>Requires an explicit verified promotion before the moving v1 tag is updated.</li>
</ul>
<p>Pin v1.0.1 for immutable behavior. The moving v1 tag is promoted only after exact-tag validation passes.</p>
]]></content:encoded></item><item><title>Speccy API review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/speccy-api-review/</link><pubDate>Sun, 09 Aug 2026 22:09:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/speccy-api-review/</guid><description>Version updated for https://github.com/mcclowes/speccy to version speccy-cli@0.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Speccy is an OpenAPI renderer that provides a unified rendering core across various platforms, including React, web, macOS, and Docusaurus. It uses one design approach to render specifications uniformly across all surfaces, with focus on clarity through minimal decoration rather than color identifiers. The action automates the linting, diffing, and rendering of OpenAPI 3.x and Swagger 2 documents, offering a comprehensive suite of features for developers and documentation authors.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcclowes/speccy">https://github.com/mcclowes/speccy</a></strong> to version <strong><a href="mailto:speccy-cli@0.3.1">speccy-cli@0.3.1</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/speccy-api-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Speccy is an OpenAPI renderer that provides a unified rendering core across various platforms, including React, web, macOS, and Docusaurus. It uses one design approach to render specifications uniformly across all surfaces, with focus on clarity through minimal decoration rather than color identifiers. The action automates the linting, diffing, and rendering of OpenAPI 3.x and Swagger 2 documents, offering a comprehensive suite of features for developers and documentation authors.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li><a href="https://github.com/mcclowes/speccy/commit/906c8d884972efd90b52281d2cf633cfda168606"><code>906c8d8</code></a> Thanks <a href="https://github.com/mcclowes">@mcclowes</a>! - Restore the <code>speccy</code> executable in the published package.</li>
</ul>
]]></content:encoded></item><item><title>Deploy to Miabi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/deploy-to-miabi/</link><pubDate>Sun, 09 Aug 2026 22:08:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/deploy-to-miabi/</guid><description>Version updated for https://github.com/miabi-io/deploy-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automates the deployment of an application to a Miabi control panel from GitHub Actions. It installs the miabi CLI and uses its API to deploy applications based on Git tags, providing options for different deployment strategies and workspace management. The action supports specifying app details, image tags, and server configurations, with fallbacks to environment variables where necessary.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/miabi-io/deploy-action">https://github.com/miabi-io/deploy-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-to-miabi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action automates the deployment of an application to a Miabi control panel from GitHub Actions. It installs the <code>miabi</code> CLI and uses its API to deploy applications based on Git tags, providing options for different deployment strategies and workspace management. The action supports specifying app details, image tags, and server configurations, with fallbacks to environment variables where necessary.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: add a  input and deprecate by @jkaninda in <a href="https://github.com/miabi-io/deploy-action/pull/1">https://github.com/miabi-io/deploy-action/pull/1</a></li>
<li>chore(branding): add miabi branding assets by @jkaninda in <a href="https://github.com/miabi-io/deploy-action/pull/2">https://github.com/miabi-io/deploy-action/pull/2</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@jkaninda made their first contribution in <a href="https://github.com/miabi-io/deploy-action/pull/1">https://github.com/miabi-io/deploy-action/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/miabi-io/deploy-action/compare/v1.0.0...v1.1.0">https://github.com/miabi-io/deploy-action/compare/v1.0.0...v1.1.0</a></p>
]]></content:encoded></item><item><title>Star History Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/star-history-action/</link><pubDate>Sun, 09 Aug 2026 22:07:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/star-history-action/</guid><description>Version updated for https://github.com/narayann7/star-history-action to version v1.0.5.
This action is used across all versions by 21 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically generates and updates an SVG star history chart for a repository owned or collaborated on by its owner or collaborators. It uses Node.js to run the star-history renderer, which outputs static files (SVG and PNG) that are committed to the repository’s README, ensuring that the chart is always current without relying on external services. The action checks for changes in star data and commits only if there have been updates, improving efficiency by avoiding unnecessary renders.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/narayann7/star-history-action">https://github.com/narayann7/star-history-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>21</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/star-history-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically generates and updates an SVG star history chart for a repository owned or collaborated on by its owner or collaborators. It uses Node.js to run the <code>star-history</code> renderer, which outputs static files (SVG and PNG) that are committed to the repository&rsquo;s README, ensuring that the chart is always current without relying on external services. The action checks for changes in star data and commits only if there have been updates, improving efficiency by avoiding unnecessary renders.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>The chart no longer draws the &ldquo;star-history.com&rdquo; watermark in the bottom-right corner. The vendored renderer is untouched; the watermark text and its icon are stripped after rendering, alongside the existing <code>&lt;style&gt;</code> and <code>.browser-only</code> strips. Attribution for the vendored star-history code stays where the MIT license needs it, in <code>renderer/vendor/LICENSE</code> and <code>renderer/NOTICE.md</code>.</li>
<li>The change-detection signature now includes a <code>RENDER_VERSION</code> constant, so a change to how the chart is drawn reaches every repo on the next run instead of waiting for a star change or a day rollover. This release bumps it, so the first run after upgrade re-renders and commits even with flat stars.</li>
</ul>
<p><strong>Upgrading:</strong> consumers pinned to <code>@v1</code> pick this up automatically — the <code>v1</code> tag now points at v1.0.5. Your next scheduled run regenerates the chart without the watermark.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/narayann7/star-history-action/blob/main/CHANGELOG.md">https://github.com/narayann7/star-history-action/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Tuffgal</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/tuffgal/</link><pubDate>Sun, 09 Aug 2026 22:05:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/tuffgal/</guid><description>Version updated for https://github.com/nschneble/tuffgal-action to version v1.6.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Tuffgal Action is a GitHub Action wrapper for Tuffgal, which automates visual regression testing by comparing screenshots against baseline images. It handles Node.js and Playwright setup, runs the harness with --ci --manage-servers, parses results.json, uploads artifacts as reports, and posts sticky PR comments for approval. The action supports CI mode and per-PR preview of test results via GitHub Pages.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nschneble/tuffgal-action">https://github.com/nschneble/tuffgal-action</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tuffgal">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Tuffgal Action is a GitHub Action wrapper for Tuffgal, which automates visual regression testing by comparing screenshots against baseline images. It handles Node.js and Playwright setup, runs the harness with <code>--ci --manage-servers</code>, parses <code>results.json</code>, uploads artifacts as reports, and posts sticky PR comments for approval. The action supports CI mode and per-PR preview of test results via GitHub Pages.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<p>The approve action now edits the sticky report comment in place as an approval runs, so a watching maintainer sees live progress instead of a frozen comment.</p>
<h3 id="changed">Changed</h3>
<ul>
<li>The deleted section now links the report&rsquo;s deleted-baselines heading when a preview published</li>
<li>The sticky PR comment&rsquo;s changed table drops its diff column</li>
<li>The sticky PR comment is now breakpoint-aware</li>
<li>The sticky PR comment now lists every failed story individually</li>
</ul>
<h3 id="fixed">Fixed</h3>
<p>The main action now skips its own redundant rerun after a full baseline approval, even when the approve step pushes with a PAT. v1.5.0&rsquo;s shortcut only ever covered the default <code>GITHUB_TOKEN</code> path.</p>
]]></content:encoded></item><item><title>MegaLinter Custom Flavor npm-groovy-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/megalinter-custom-flavor-npm-groovy-lint/</link><pubDate>Sun, 09 Aug 2026 22:04:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/megalinter-custom-flavor-npm-groovy-lint/</guid><description>Version updated for https://github.com/nvuillam/megalinter-custom-flavor-npm-groovy-lint to version v10.0.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This custom MegaLinter project is designed to optimize Docker image size by using official MegaLinter images as a base and maintaining an optimized version on a different GitHub repository. It includes various linters such as Hadolint, Groovy linting, JavaScript Prettier, JSON linting, Markdown linting, and more. The custom flavor can be used in GitHub Actions workflows or directly with Docker images by replacing the official MegaLinter images with this optimized version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nvuillam/megalinter-custom-flavor-npm-groovy-lint">https://github.com/nvuillam/megalinter-custom-flavor-npm-groovy-lint</a></strong> to version <strong>v10.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/megalinter-custom-flavor-npm-groovy-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This custom MegaLinter project is designed to optimize Docker image size by using official MegaLinter images as a base and maintaining an optimized version on a different GitHub repository. It includes various linters such as Hadolint, Groovy linting, JavaScript Prettier, JSON linting, Markdown linting, and more. The custom flavor can be used in GitHub Actions workflows or directly with Docker images by replacing the official MegaLinter images with this optimized version.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Automated release to sync with MegaLinter version v10.0.0.</p>
<p>This release was automatically created to build a custom MegaLinter flavor based on the upstream MegaLinter release v10.0.0.</p>
<p>For more information about changes in this version, see the <a href="https://github.com/oxsecurity/megalinter/releases/tag/v10.0.0">MegaLinter changelog</a>.</p>
]]></content:encoded></item><item><title>Oculum Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/oculum-security-scan/</link><pubDate>Sun, 09 Aug 2026 22:03:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/oculum-security-scan/</guid><description>Version updated for https://github.com/OculumDev/oculum-action to version v1.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Oculum Security Scan, is an AI-driven security scanner designed to detect various vulnerabilities in LLM-powered applications. It combines both AI and traditional static application security testing (SAST) methods to identify prompt injection, hardcoded secrets, SQL injection, XSS, and more. The action provides low false positives by using AI-assisted validation and integrates seamlessly with GitHub workflows to automatically scan pull requests and commits. Users can set different scan depths and fail thresholds based on their needs, and it offers options for customizing the directory and file patterns scanned.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OculumDev/oculum-action">https://github.com/OculumDev/oculum-action</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oculum-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Oculum Security Scan, is an AI-driven security scanner designed to detect various vulnerabilities in LLM-powered applications. It combines both AI and traditional static application security testing (SAST) methods to identify prompt injection, hardcoded secrets, SQL injection, XSS, and more. The action provides low false positives by using AI-assisted validation and integrates seamlessly with GitHub workflows to automatically scan pull requests and commits. Users can set different scan depths and fail thresholds based on their needs, and it offers options for customizing the directory and file patterns scanned.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update README and action.yml for marketplace (d43812a)</li>
<li>reduced description length for marketplace publish (f19893e)</li>
<li>change description (ae151d7)</li>
<li>Improve annotation fix details - use fixSteps when available (3b55e59)</li>
<li>first commit (16010ba)</li>
</ul>
]]></content:encoded></item><item><title>PR Nutrition</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/pr-nutrition/</link><pubDate>Sun, 09 Aug 2026 22:02:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/pr-nutrition/</guid><description>Version updated for https://github.com/Param-10/pr-nutrition to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PR Nutrition is a local-first PR triage CLI that provides a simple review-readiness label based on Git metadata and file paths. It helps reviewers quickly identify the most important files to focus on, reducing the time spent reading through large or complex PRs. The tool uses a risk score to determine which changes are low-risk, medium-risk, or high-risk, making it easier for developers to prioritize their work.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Param-10/pr-nutrition">https://github.com/Param-10/pr-nutrition</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-nutrition">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PR Nutrition is a local-first PR triage CLI that provides a simple review-readiness label based on Git metadata and file paths. It helps reviewers quickly identify the most important files to focus on, reducing the time spent reading through large or complex PRs. The tool uses a risk score to determine which changes are low-risk, medium-risk, or high-risk, making it easier for developers to prioritize their work.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="030---2026-08-09">0.3.0 - 2026-08-09</h2>
<h3 id="added">Added</h3>
<ul>
<li>Markdown focus-file groups are capped at 10 entries per group with an <code>...and N more</code> line; JSON still returns the full lists.</li>
<li>Eval precision reporting: every case has an <code>intent</code>, and <code>pnpm eval</code> prints false-positive avoidance and true-positive pass rates.</li>
<li>Broader dependency manifests for Python, Ruby, Java/Gradle, and PHP (<code>requirements.txt</code>, <code>Gemfile</code>, <code>pom.xml</code>, <code>build.gradle</code>, <code>composer.json</code>, and related lockfiles).</li>
<li>Shallow monorepo evidence discovery under <code>packages/*</code>, <code>apps/*</code>, <code>libs/*</code>, and <code>services/*</code>.</li>
<li>Always-on Coverage section in Markdown and JSON describing what was checked and what was not.</li>
<li><code>pr-nutrition check</code> for pre-PR local analysis with focus-file groups enabled by default.</li>
<li>Opt-in <code>--fail-on &lt;low|medium|high&gt;</code> on the main command and <code>check</code> (exit code <code>3</code> when the threshold is met).</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>CI risk is presence-based at full points (20), matching migrations and authentication.</li>
<li>CLI <code>--version</code> reads the published package version from <code>package.json</code> instead of a hardcoded string.</li>
<li>Focus-file sorting precomputes reviewable line counts instead of scanning the file list on every comparison.</li>
</ul>
]]></content:encoded></item><item><title>mdx-embeddings-actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/mdx-embeddings-actions/</link><pubDate>Sun, 09 Aug 2026 22:00:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/mdx-embeddings-actions/</guid><description>Version updated for https://github.com/PieterDePauw/mdx-embeddings-actions to version v0.0.11.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating and storing document embeddings using OpenAI and Supabase. It reads markdown files from a specified directory, converts them into embeddings, and stores these embeddings in a PostgreSQL/Supabase database. This setup enables efficient vector similarity search within the documentation or website, facilitating quick access to relevant information.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PieterDePauw/mdx-embeddings-actions">https://github.com/PieterDePauw/mdx-embeddings-actions</a></strong> to version <strong>v0.0.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mdx-embeddings-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating and storing document embeddings using OpenAI and Supabase. It reads markdown files from a specified directory, converts them into embeddings, and stores these embeddings in a PostgreSQL/Supabase database. This setup enables efficient vector similarity search within the documentation or website, facilitating quick access to relevant information.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>TOTAL OVERHAUL (2cd1eba)</li>
<li>Refactor processMdxForSearch function for improved code readability and performance (b002cf3)</li>
<li>Refactor parsePaths function to improve code clarity and consistency (d3aa6c6)</li>
<li>Add /dist files (15b298a)</li>
<li>Refactor generateEmbeddings function for improved code readability and removal of unused code (2069271)</li>
<li>Refactor generateEmbeddings function for improved code readability and removal of unused code (3d4485e)</li>
<li>Refactor generateEmbeddings function to improve code readability and remove unused code (dffc3cb)</li>
<li>Refactor generateEmbeddings function to improve code readability and remove unused code (9bc0822)</li>
<li>chore: Update pages table schema to reference parent_page_id column (59d1dc9)</li>
<li>chore: Update package.json to include release script (86e6b5f)</li>
</ul>
]]></content:encoded></item><item><title>Critical URL SEO Release Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/critical-url-seo-release-guard/</link><pubDate>Sun, 09 Aug 2026 22:00:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/critical-url-seo-release-guard/</guid><description>Version updated for https://github.com/plainproof-labs/release-regression-guard to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Release Regression Guard action automates the verification of critical URLs after a deployment by comparing a repository-owned manifest with the deployed origin. It checks for broken redirects, noindex, canonical/metadata regressions, sitemap gaps, and missing internal links. The main functionality is to report these issues in the workflow Job Summary as pass, fail, unknown, or documented temporary exceptions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plainproof-labs/release-regression-guard">https://github.com/plainproof-labs/release-regression-guard</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/critical-url-seo-release-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Release Regression Guard action automates the verification of critical URLs after a deployment by comparing a repository-owned manifest with the deployed origin. It checks for broken redirects, <code>noindex</code>, canonical/metadata regressions, sitemap gaps, and missing internal links. The main functionality is to report these issues in the workflow Job Summary as pass, fail, unknown, or documented temporary exceptions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release Regression Guard v1.1.0 adds a bounded GitHub Job Summary and strengthens deterministic release verification across positive, negative, exception, and unknown states.</p>
<p>Highlights:</p>
<ul>
<li>Validate Action exit codes, annotations, outputs, JSON, SARIF, Markdown, summaries, and privacy canaries through the spawned entrypoint.</li>
<li>Correct robots wildcard precedence, noindex handling, document and base URL resolution, sitemap membership, and invalid redirect handling.</li>
<li>Prevent comments and script, style, or template text from creating false document facts; ambiguous JavaScript remains unknown.</li>
<li>Align report provenance with package version 1.1.0 and tighten manifest path validation.</li>
<li>Keep the Node.js 24 runtime, existing inputs and outputs, target-only network boundary, and default-disabled affiliate mode.</li>
</ul>
<p>See CHANGELOG.md for the full compatibility note.</p>
]]></content:encoded></item><item><title>SBOMlyze Diff</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sbomlyze-diff/</link><pubDate>Sun, 09 Aug 2026 21:59:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sbomlyze-diff/</guid><description>Version updated for https://github.com/rezmoss/sbomlyze to version v0.5.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary sbomlyze is a GitHub Action that compares two Software Bills of Materials (SBOMs) to identify changes and potential security risks. It checks for integrity drift, where a package’s hash changes without updating its version, which can indicate tampering. The action provides detailed reports and compliance scoring capabilities, helping to ensure the integrity and security of software supply chains.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rezmoss/sbomlyze">https://github.com/rezmoss/sbomlyze</a></strong> to version <strong>v0.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sbomlyze-diff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>sbomlyze is a GitHub Action that compares two Software Bills of Materials (SBOMs) to identify changes and potential security risks. It checks for integrity drift, where a package&rsquo;s hash changes without updating its version, which can indicate tampering. The action provides detailed reports and compliance scoring capabilities, helping to ensure the integrity and security of software supply chains.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>31503690611fda8ebba4ed2bd186eda000442594 chore(main): release 0.5.1 (#48)</li>
<li>0e6545a162a24b829ead359544d38f093ada99e4 docs(action): update examples to v0.5.0</li>
<li>4ade8ddd3302ea3e247282f4ce2239d6625b6e5d fix(sarif): prevent cross-PR alert collisions (#47)</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/kaniko-build-action/</link><pubDate>Sun, 09 Aug 2026 21:57:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints a greeting message to the log. It can greet either “World” or a specified name, and includes a timestamp in the output.
What’s Changed My first action is ready (5619594) Initial commit (2a56a2a)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints a greeting message to the log. It can greet either &ldquo;World&rdquo; or a specified name, and includes a timestamp in the output.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/agentauditkit-mcp-security-scan/</link><pubDate>Sun, 09 Aug 2026 21:57:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.71.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner designed to audit MCP-connected AI agent pipelines. It automates the detection of misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. Unlike hosted scanners that rely on machine learning, AgentAuditKit runs fully offline and deterministically, ensuring consistent findings and compliance evidence packs with support for 12 security frameworks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.71</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit is a security scanner designed to audit MCP-connected AI agent pipelines. It automates the detection of misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. Unlike hosted scanners that rely on machine learning, AgentAuditKit runs fully offline and deterministically, ensuring consistent findings and compliance evidence packs with support for 12 security frameworks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.71
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.71
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.71</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): Bump the github-actions group across 1 directory with 4 updates by @dependabot[bot] in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/526">https://github.com/sattyamjjain/agent-audit-kit/pull/526</a></li>
<li>fix(cve): pin @adenot/mcp-google-search SSRF (CVE-2026-19337); adjudicate #556/#557 by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/559">https://github.com/sattyamjjain/agent-audit-kit/pull/559</a></li>
<li>chore: drop the orphan findings.sarif from the repo root by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/560">https://github.com/sattyamjjain/agent-audit-kit/pull/560</a></li>
<li>feat(scanners): agent config/skill auto-trust scanner (AAK-AGENT-TRUST-001..004) by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/561">https://github.com/sattyamjjain/agent-audit-kit/pull/561</a></li>
<li>chore: archive pre-0.3.60 changelog history by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/562">https://github.com/sattyamjjain/agent-audit-kit/pull/562</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.70...v0.3.71">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.70...v0.3.71</a></p>
]]></content:encoded></item><item><title>CI Health Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/ci-health-audit/</link><pubDate>Sun, 09 Aug 2026 21:56:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/ci-health-audit/</guid><description>Version updated for https://github.com/sdxiaomage/ci-health-audit to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action scans GitHub Actions workflows for common security and reliability risks such as untrusted pull-request head checkout, lack of permissions, missing timeouts, and attacker-controlled event fields. It produces a report in Markdown or JSON format and can fail the CI build at a chosen severity threshold. The audit is run locally on the runner without uploading workflow files to an external service.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sdxiaomage/ci-health-audit">https://github.com/sdxiaomage/ci-health-audit</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ci-health-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action scans GitHub Actions workflows for common security and reliability risks such as untrusted pull-request head checkout, lack of permissions, missing timeouts, and attacker-controlled event fields. It produces a report in Markdown or JSON format and can fail the CI build at a chosen severity threshold. The audit is run locally on the runner without uploading workflow files to an external service.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release. Zero-dependency GitHub Actions audit with eight high-confidence heuristic checks, Markdown/JSON output, and configurable failure thresholds.</p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/custom-amazon-bedrock-agent-action/</link><pubDate>Sun, 09 Aug 2026 21:55:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide feedback. It integrates with Amazon Bedrock Knowledge Bases for context-aware insights, enhancing its capability in code quality improvement, security assessments, and performance optimizations. This action is highly customizable and integrates seamlessly into the PR process, posting analysis results as markdown-formatted comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide feedback. It integrates with Amazon Bedrock Knowledge Bases for context-aware insights, enhancing its capability in code quality improvement, security assessments, and performance optimizations. This action is highly customizable and integrates seamlessly into the PR process, posting analysis results as markdown-formatted comments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sherpa.sh/</link><pubDate>Sun, 09 Aug 2026 21:54:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh automates the deployment of any cloud provider, framework, or infrastructure need using plain English prompts. It handles server setup, DNS configuration, SSL certificates, CDN integration, database management, backups, load balancing, and more, allowing developers to focus on their code while Sherpa takes care of the infrastructure behind it.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh automates the deployment of any cloud provider, framework, or infrastructure need using plain English prompts. It handles server setup, DNS configuration, SSL certificates, CDN integration, database management, backups, load balancing, and more, allowing developers to focus on their code while Sherpa takes care of the infrastructure behind it.</p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/smyklot/</link><pubDate>Sun, 09 Aug 2026 21:53:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.16.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges based on CODEOWNERS. It validates permissions against the .github/CODEOWNERS file, handling slash commands, mentions, bare commands, and emojis for approval and merge. The app supports multiple repositories, provides reaction-based commands, and includes features like cleanup, deduplication, and flexible configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.16.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges based on CODEOWNERS. It validates permissions against the <code>.github/CODEOWNERS</code> file, handling slash commands, mentions, bare commands, and emojis for approval and merge. The app supports multiple repositories, provides reaction-based commands, and includes features like cleanup, deduplication, and flexible configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1160-2026-08-09"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.15.1...v1.16.0">1.16.0</a> (2026-08-09)</h2>
<h2 id="smyklot-v1160">Smyklot v1.16.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.16.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>89f3c8df376c23c74c4bdb3b8547c73b716ddd51 chore(release): bump version to 1.16.0</li>
<li>a2f20b0a49d0d854b1ce73d89ff78cee69481129 feat(panel): add routed repository management (#167)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/classroom-to-sheets-integration/</link><pubDate>Sun, 09 Aug 2026 21:52:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates GitHub Classroom with Google Sheets to automatically update assignment results. It enables teachers to track student progress and grades directly in a spreadsheet. The action requires setting up Google Sheet API credentials and creating a shared sheet accessible by the service account. Users can integrate it into their workflows using pre-defined inputs, such as student names, task results, and table IDs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates GitHub Classroom with Google Sheets to automatically update assignment results. It enables teachers to track student progress and grades directly in a spreadsheet. The action requires setting up Google Sheet API credentials and creating a shared sheet accessible by the service account. Users can integrate it into their workflows using pre-defined inputs, such as student names, task results, and table IDs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>GitHub Stats Cards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/github-stats-cards/</link><pubDate>Sun, 09 Aug 2026 21:51:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/github-stats-cards/</guid><description>Version updated for https://github.com/stn1slv/github-stats-cards to version v1.1.10.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Stats Card action generates beautiful SVG statistics cards for GitHub profiles. It automates the process of updating user profile SVG files automatically on a schedule, and provides features such as 50+ built-in themes, comprehensive stats, top languages, top contributions, smart weighting, aligned layouts, customization options, and internationalization support. The action is particularly useful for creating visually appealing READMEs with GitHub-related statistics that are updated regularly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stn1slv/github-stats-cards">https://github.com/stn1slv/github-stats-cards</a></strong> to version <strong>v1.1.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-stats-cards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Stats Card action generates beautiful SVG statistics cards for GitHub profiles. It automates the process of updating user profile SVG files automatically on a schedule, and provides features such as 50+ built-in themes, comprehensive stats, top languages, top contributions, smart weighting, aligned layouts, customization options, and internationalization support. The action is particularly useful for creating visually appealing READMEs with GitHub-related statistics that are updated regularly.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/stn1slv/github-stats-cards/compare/v1.1.9...v1.1.10">https://github.com/stn1slv/github-stats-cards/compare/v1.1.9...v1.1.10</a></p>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/setup-tombi/</link><pubDate>Sun, 09 Aug 2026 21:50:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.8.
This action is used across all versions by 144 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi, a version control tool, in your GitHub Actions workflow. It supports installing Tombi from a specific version, a lock file, or the latest available version by default. The action also provides options to cache the installation and customize the cache directory.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.2.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>144</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up Tombi, a version control tool, in your GitHub Actions workflow. It supports installing Tombi from a specific version, a lock file, or the latest available version by default. The action also provides options to cache the installation and customize the cache directory.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.2.8">tombi v1.2.8</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.8">https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.8</a></p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/wails3-build-action/</link><pubDate>Sun, 09 Aug 2026 21:48:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the build process for Wails.io v3 projects, installing GoLang and NodeJS, and running a build. It supports building for multiple platforms and provides options to obfuscate builds, cache the build, and upload artifacts or publish releases on tagged builds.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the build process for Wails.io v3 projects, installing GoLang and NodeJS, and running a build. It supports building for multiple platforms and provides options to obfuscate builds, cache the build, and upload artifacts or publish releases on tagged builds.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Install bashunit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/install-bashunit/</link><pubDate>Sun, 09 Aug 2026 21:47:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/install-bashunit/</guid><description>Version updated for https://github.com/TypedDevs/bashunit to version 0.45.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action is a simple testing framework for Bash scripts. It automates the writing, execution, and verification of test cases in Bash 3.0+ scripts. Key capabilities include 75 assertions, spies, mocks, data providers, snapshots, and more, making it easy to write maintainable and reliable tests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TypedDevs/bashunit">https://github.com/TypedDevs/bashunit</a></strong> to version <strong>0.45.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-bashunit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action is a simple testing framework for Bash scripts. It automates the writing, execution, and verification of test cases in Bash 3.0+ scripts. Key capabilities include 75 assertions, spies, mocks, data providers, snapshots, and more, making it easy to write maintainable and reliable tests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-improvements">✨ Improvements</h2>
<ul>
<li><code>assert_is_symlink</code>, <code>assert_is_not_symlink</code> and <code>assert_symlink_to</code> assert on a symbolic link itself, which every other filesystem assertion follows through to the target (#981)</li>
<li><code>assert_true</code> and <code>assert_false</code> accept a command with its arguments — <code>assert_true test -d /tmp</code>. A single argument keeps its previous meaning (#994)</li>
<li>Named snapshot assertions support multiple snapshots per test; mismatches show the resolved path and <code>--snapshot-update</code> hint (#986)</li>
</ul>
<h2 id="-changes">🛠️ Changes</h2>
<ul>
<li><code>assert_true</code> / <code>assert_false</code> report <code>unknown command</code> / <code>not executable</code> instead of a bare exit code 127 or 126 (#982)</li>
<li>Core comparison assertions report missing required arguments as usage errors instead of comparing against empty values (#983)</li>
<li>Performance: Literal snapshots bypass placeholder regex processing unless they contain a placeholder (about 13x faster) (#985)</li>
<li>Performance: <code>assert_within_delta</code> uses fixed-point arithmetic for common values, with a <code>bc</code>/<code>awk</code> fallback for unsupported inputs (about 6.6x faster) (#979)</li>
<li>Performance: Spy assertions and call counters use builtins instead of <code>cat</code> and command substitutions (about 6.5x faster) (#978)</li>
<li>Performance: <code>assert_contains_ignore_case</code> uses Bash&rsquo;s <code>nocasematch</code> where available, falling back to <code>tr</code> on Bash 3.0 (about 10x faster) (#977)</li>
<li>Build: standalone binaries omit source comments while preserving heredoc content and source markers, reducing the current artifact by about 22% (#990)</li>
<li>Internal: Split <code>src/runner.sh</code> and <code>src/coverage.sh</code> into focused modules with no behavior change; see <a href="adrs/adr-010-src-module-directories.md">ADR-010</a> (#924, #925)</li>
</ul>
<h2 id="-bug-fixes">🐛 Bug Fixes</h2>
<ul>
<li>Snapshot placeholders no longer match anything at all without <code>perl</code>; the <code>grep</code> fallback treated a multi-line pattern as separate alternatives, and now uses <code>awk</code> over the whole value (#1002)</li>
<li>Snapshots resolve correctly for an absolute test path; the <code>./</code> prefix made them cwd-relative, so a stray snapshot was recorded and every snapshot assertion passed (#1002)</li>
<li><code>assert_false</code> no longer passes when the command does not exist; exit codes 127 and 126 fail both boolean assertions, because the command never ran (#982)</li>
<li><code>assert_have_been_called_times</code> and <code>assert_have_been_called_nth_with</code> report a usage error for a non-numeric count instead of leaking a raw <code>integer expression expected</code> (#984)</li>
<li>A failing test whose output quotes a shell-error phrase is no longer also reported as a runtime error (#992)</li>
<li>Runtime errors are recognised from the exit code when the diagnostic text is translated or redirected away (#998)</li>
<li><code>assert_within_delta</code> accepts a leading <code>+</code> on any operand (#979)</li>
<li>Invalid <code>BASHUNIT_SHARD_INDEX</code> / <code>BASHUNIT_SHARD_TOTAL</code> values now fail with a clear error instead of reaching raw arithmetic or reporting no tests (#969)</li>
<li>Date assertions reject unparseable values instead of crashing or treating them as epoch 0 (#968)</li>
<li><code>assert_json_equals</code> rejects invalid JSON instead of considering two unparseable values equal (#967)</li>
<li>Parallel runs preserve results from same-named test files in different directories (#959)</li>
<li>Coverage no longer counts variable assignments as functions or emits malformed LCOV records for assignments containing <code>|</code> (#936)</li>
<li>The nightly coverage workflow discovers nested unit tests while excluding coverage meta-tests and fixtures (#980)</li>
<li><code>build.sh</code> deduplicates embedded files by repository-relative path, preventing duplicate or missing modules with the same filename (#923)</li>
<li><code>bashunit doc</code> no longer errors when the default bootstrap file is missing (#929)</li>
</ul>
<h2 id="-contributors">👥 Contributors</h2>
<ul>
<li>@Chemaclass</li>
<li>@objctp</li>
</ul>
<h2 id="checksum">Checksum</h2>
<p>SHA256: <code>19983f26299825ff26cfbb90e6b3b6e86fc8044168191d3e8b86f615313a80a9</code></p>
<p><strong>Full Changelog:</strong> <a href="https://github.com/TypedDevs/bashunit/compare/0.44.0...0.45.0">0.44.0&hellip;0.45.0</a></p>
]]></content:encoded></item><item><title>Build and push Docker images with WarpBuild</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/build-and-push-docker-images-with-warpbuild/</link><pubDate>Sun, 09 Aug 2026 21:46:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/build-and-push-docker-images-with-warpbuild/</guid><description>Version updated for https://github.com/WarpBuilds/build-push-action to version v7.0.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 40 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action builds and pushes Docker images using WarpBuild’s remote builders with support for multi-platform build, secrets, remote cache, and different builder deployment/namespacing options. It allows users to use powerful features of BuildKit by leveraging the additional profile-name input required to specify the WarpBuild profile to use.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/WarpBuilds/build-push-action">https://github.com/WarpBuilds/build-push-action</a></strong> to version <strong>v7.0.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>40</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-and-push-docker-images-with-warpbuild">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action builds and pushes Docker images using WarpBuild&rsquo;s remote builders with support for multi-platform build, secrets, remote cache, and different builder deployment/namespacing options. It allows users to use powerful features of BuildKit by leveraging the additional <code>profile-name</code> input required to specify the WarpBuild profile to use.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Synced with upstream v7.</p>
<ul>
<li>ESM sources bundled with esbuild to <code>dist/index.cjs</code></li>
<li><code>@docker/actions-toolkit</code> 0.68 → 0.92, <code>@actions/core</code> 1.x → 3.x</li>
<li>tests migrated to vitest, package manager to yarn 4</li>
</ul>
<p>WarpBuild remote builder behaviour is unchanged. <code>v6</code> is unaffected and remains available.</p>
]]></content:encoded></item><item><title>Setup odoopack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/setup-odoopack/</link><pubDate>Sun, 09 Aug 2026 21:45:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/setup-odoopack/</guid><description>Version updated for https://github.com/wimwenigerkind/setup-odoopack to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action setup-odoopack installs the odoopack CLI tool and adds it to the system’s PATH. It allows users to easily manage Odoo packages by automating tasks such as installing versions, configuring private registries with tokens, and retrieving installation details. The action supports specifying versions, registry URLs, and authentication tokens for a more secure setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wimwenigerkind/setup-odoopack">https://github.com/wimwenigerkind/setup-odoopack</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-odoopack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>setup-odoopack</code> installs the <code>odoopack</code> CLI tool and adds it to the system&rsquo;s PATH. It allows users to easily manage Odoo packages by automating tasks such as installing versions, configuring private registries with tokens, and retrieving installation details. The action supports specifying versions, registry URLs, and authentication tokens for a more secure setup.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wimwenigerkind/setup-odoopack/commits/v0.1.0">https://github.com/wimwenigerkind/setup-odoopack/commits/v0.1.0</a></p>
]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/kover-report-action/</link><pubDate>Sun, 09 Aug 2026 21:44:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.22.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Kover Report Action is a GitHub Action designed to generate and report code coverage from Kover XML reports across Kotlin/Android projects with support for multi-module projects. It automates the process of aggregating coverage data from various modules, applying customizable thresholds, and integrating results into pull requests via comments or as artifacts. The action supports both command-based discovery and glob pattern module paths and can generate history graphs to track coverage trends over time.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v3.1.22</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Kover Report Action is a GitHub Action designed to generate and report code coverage from Kover XML reports across Kotlin/Android projects with support for multi-module projects. It automates the process of aggregating coverage data from various modules, applying customizable thresholds, and integrating results into pull requests via comments or as artifacts. The action supports both command-based discovery and glob pattern module paths and can generate history graphs to track coverage trends over time.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3.1.22: PR #160 - chore(deps): update dependency pnpm to v11.17.0</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/b.ia-accessibility-checker/</link><pubDate>Sun, 09 Aug 2026 21:43:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows companies to ensure their products comply with WCAG guidelines for specific audience groups by defining requirements and using AI analysis. The action helps reduce learning curve costs and ensures higher revenue by focusing on the right audience, promoting effective accessibility solutions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows companies to ensure their products comply with WCAG guidelines for specific audience groups by defining requirements and using AI analysis. The action helps reduce learning curve costs and ensures higher revenue by focusing on the right audience, promoting effective accessibility solutions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>reflint reference-integrity linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/reflint-reference-integrity-linter/</link><pubDate>Sun, 09 Aug 2026 14:07:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/reflint-reference-integrity-linter/</guid><description>Version updated for https://github.com/hyuga611/reflint to version v0.9.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The reflint action is a zero-dependency linter for AI-agent configuration files, specifically AGENTS.md, llms.txt, and CLAUDE.md. It checks that all references in these files are valid and real by verifying the existence of the referenced scripts, paths, and files. If any broken references are found, the action fails CI, preventing stale configurations from being merged. The linter can be used as a GitHub Action or a CLI tool for checking reference integrity across different stacks and repository types.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hyuga611/reflint">https://github.com/hyuga611/reflint</a></strong> to version <strong>v0.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/reflint-reference-integrity-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The reflint action is a zero-dependency linter for AI-agent configuration files, specifically AGENTS.md, llms.txt, and CLAUDE.md. It checks that all references in these files are valid and real by verifying the existence of the referenced scripts, paths, and files. If any broken references are found, the action fails CI, preventing stale configurations from being merged. The linter can be used as a GitHub Action or a CLI tool for checking reference integrity across different stacks and repository types.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hyuga611/reflint/compare/v0.8.3...v0.9.1">https://github.com/hyuga611/reflint/compare/v0.8.3...v0.9.1</a></p>
]]></content:encoded></item><item><title>skills-lint SKILL.md linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/skills-lint-skill.md-linter/</link><pubDate>Sun, 09 Aug 2026 14:06:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/skills-lint-skill.md-linter/</guid><description>Version updated for https://github.com/hyuga611/skills-lint to version v0.7.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Skills-Lint is a zero-dependency linter for Anthropic Agent Skills that checks for referential integrity, frontmatter consistency, and skill collisions. It ensures that SKILL.md references exist on disk and resolves internal links and script references in the references/ directory. The action fails PRs when there are broken references or duplicate skills based on name or description similarity. It supports both local and CI usage through GitHub Actions workflows or as a CLI tool.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hyuga611/skills-lint">https://github.com/hyuga611/skills-lint</a></strong> to version <strong>v0.7.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skills-lint-skill-md-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Skills-Lint</strong> is a zero-dependency linter for Anthropic Agent Skills that checks for referential integrity, frontmatter consistency, and skill collisions. It ensures that <code>SKILL.md</code> references exist on disk and resolves internal links and script references in the <code>references/</code> directory. The action fails PRs when there are broken references or duplicate skills based on name or description similarity. It supports both local and CI usage through GitHub Actions workflows or as a CLI tool.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hyuga611/skills-lint/compare/v0.6.1...v0.7.2">https://github.com/hyuga611/skills-lint/compare/v0.6.1...v0.7.2</a></p>
]]></content:encoded></item><item><title>JFrog Boost</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/jfrog-boost/</link><pubDate>Sun, 09 Aug 2026 14:04:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/jfrog-boost/</guid><description>Version updated for https://github.com/jfrog/boost to version v0.11.2.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 4 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Boost is an OpenTelemetry-based tool that reduces noise in log output by trimming safe data while preserving essential information such as errors, timings, and cache hits. It optimizes agent performance without affecting their output quality, ensuring agents remain sharp and efficient. Boost supports various platforms, including macOS, Linux, Windows WSL, and Windows PowerShell, and is available for installation via curl or PowerShell scripts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jfrog/boost">https://github.com/jfrog/boost</a></strong> to version <strong>v0.11.2</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>4</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jfrog-boost">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Boost is an OpenTelemetry-based tool that reduces noise in log output by trimming safe data while preserving essential information such as errors, timings, and cache hits. It optimizes agent performance without affecting their output quality, ensuring agents remain sharp and efficient. Boost supports various platforms, including macOS, Linux, Windows WSL, and Windows PowerShell, and is available for installation via curl or PowerShell scripts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.7.23 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/41">https://github.com/jfrog/boost/pull/41</a></li>
<li>Release v0.7.25 by @menachemm-byte in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
<li>docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/47">https://github.com/jfrog/boost/pull/47</a></li>
<li>docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/48">https://github.com/jfrog/boost/pull/48</a></li>
<li>docs(readme): add how-to-use walkthrough GIF above Quick start by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/52">https://github.com/jfrog/boost/pull/52</a></li>
<li>docs(readme): add Boost comparison table by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/53">https://github.com/jfrog/boost/pull/53</a></li>
<li>fix: install.ps1 by @menachemm-byte in <a href="https://github.com/jfrog/boost/pull/54">https://github.com/jfrog/boost/pull/54</a></li>
<li>docs: refresh README badges, install, use cases, and agent guide by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/56">https://github.com/jfrog/boost/pull/56</a></li>
<li>docs(readme): localize repo main page with language selector by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/59">https://github.com/jfrog/boost/pull/59</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@menachemm-byte made their first contribution in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jfrog/boost/compare/v0.7.23...v0.11.2">https://github.com/jfrog/boost/compare/v0.7.23...v0.11.2</a></p>
]]></content:encoded></item><item><title>Agent Sync Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/agent-sync-action/</link><pubDate>Sun, 09 Aug 2026 14:03:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/agent-sync-action/</guid><description>Version updated for https://github.com/julien777z/agent-sync-action to version v0.0.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action synchronizes Claude, Cursor, and Codex configurations from a single canonical .agents/ directory to various providers. It links skills, rules, agents, hooks, and settings, validates JSON, front matter, metadata, slugs, and provider configuration, and automatically generates AGENTS.md. The action supports direct commits, pull requests, or read-only dry runs, and can install external skills to keep them current.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/julien777z/agent-sync-action">https://github.com/julien777z/agent-sync-action</a></strong> to version <strong>v0.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-sync-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action synchronizes Claude, Cursor, and Codex configurations from a single canonical <code>.agents/</code> directory to various providers. It links skills, rules, agents, hooks, and settings, validates JSON, front matter, metadata, slugs, and provider configuration, and automatically generates <code>AGENTS.md</code>. The action supports direct commits, pull requests, or read-only dry runs, and can install external skills to keep them current.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>refactor: rename external skill sync field by @julien777z in <a href="https://github.com/julien777z/agent-sync-action/pull/28">https://github.com/julien777z/agent-sync-action/pull/28</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/julien777z/agent-sync-action/compare/v0.0.4...v0.0.5">https://github.com/julien777z/agent-sync-action/compare/v0.0.4...v0.0.5</a></p>
]]></content:encoded></item><item><title>AI ReviewBot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/ai-reviewbot/</link><pubDate>Sun, 09 Aug 2026 14:01:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/ai-reviewbot/</guid><description>Version updated for https://github.com/KonstZiv/ai-code-reviewer to version v1.0.0b13.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI ReviewBot is an AI-powered code review tool that automates the process of analyzing and commenting on code in GitHub and GitLab. It uses Google Gemini or Mistral AI to identify vulnerabilities, suggest improvements, and highlight good practices with inline suggestions that can be applied directly within PRs or MRs. The tool provides transparent metrics such as tokens used, latency, and estimated cost, helping developers understand the impact of their changes before merging into the main branch.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/KonstZiv/ai-code-reviewer">https://github.com/KonstZiv/ai-code-reviewer</a></strong> to version <strong>v1.0.0b13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-reviewbot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI ReviewBot is an AI-powered code review tool that automates the process of analyzing and commenting on code in GitHub and GitLab. It uses Google Gemini or Mistral AI to identify vulnerabilities, suggest improvements, and highlight good practices with inline suggestions that can be applied directly within PRs or MRs. The tool provides transparent metrics such as tokens used, latency, and estimated cost, helping developers understand the impact of their changes before merging into the main branch.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release 1.0.0b13</p>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/odin-scan-smart-contract-security/</link><pubDate>Sun, 09 Aug 2026 14:00:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Odin Scan is an AI-powered smart contract security analysis action that automatically scans CosmWasm, Solana, and EVM projects. It integrates directly into GitHub workflows to catch vulnerabilities before they reach production, providing detailed security alerts in PR comments and inline annotations. The action supports multi-platform detection, configurable thresholds, and GitHub Code Scanning integration, allowing for comprehensive security monitoring of smart contracts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Odin Scan is an AI-powered smart contract security analysis action that automatically scans CosmWasm, Solana, and EVM projects. It integrates directly into GitHub workflows to catch vulnerabilities before they reach production, providing detailed security alerts in PR comments and inline annotations. The action supports multi-platform detection, configurable thresholds, and GitHub Code Scanning integration, allowing for comprehensive security monitoring of smart contracts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add comment-triggered PR scans (ac72e5f)</li>
<li>docs: expand findings-visibility section with threat model and annotation rationale (0404708)</li>
<li>feat: add findings-visibility input for graduated public disclosure control (f18df59)</li>
<li>fix: show findings detail in PR comment with fallback to medium (c2e43c8)</li>
<li>fix: new comment per run, show only critical/high findings, rebuild dist (e237b62)</li>
<li>feat: use GitHub App installation token for branded PR comments (3abce4e)</li>
<li>feat: enrich PR comment with emojis, descriptions, and fix report URL (27cc2f2)</li>
<li>fix: gzip SARIF before base64 encoding for Code Scanning upload (d9eed9f)</li>
<li>fix: include sourcemap-register.js in dist (bd265af)</li>
<li>docs: add privacy policy (b78db44)</li>
</ul>
]]></content:encoded></item><item><title>OpenTelemetry for GitHub Workflows, Jobs and Steps</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/opentelemetry-for-github-workflows-jobs-and-steps/</link><pubDate>Sun, 09 Aug 2026 13:59:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/opentelemetry-for-github-workflows-jobs-and-steps/</guid><description>Version updated for https://github.com/plengauer/Thoth to version v5.60.0.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the collection and propagation of OpenTelemetry spans, metrics, and logs from shell scripts and GitHub workflows. It provides automatic context propagation via HTTP, auto-instrumentation of all commands, and supports installation via Debian or RPM packages, as well as distributable GitHub actions for workflow-level and job-level instrumentation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plengauer/Thoth">https://github.com/plengauer/Thoth</a></strong> to version <strong>v5.60.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>14</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/opentelemetry-for-github-workflows-jobs-and-steps">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the collection and propagation of OpenTelemetry spans, metrics, and logs from shell scripts and GitHub workflows. It provides automatic context propagation via HTTP, auto-instrumentation of all commands, and supports installation via Debian or RPM packages, as well as distributable GitHub actions for workflow-level and job-level instrumentation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Recompile Agentic Workflows by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3713">https://github.com/plengauer/Thoth/pull/3713</a></li>
<li>Update opentelemetry-js monorepo by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3708">https://github.com/plengauer/Thoth/pull/3708</a></li>
<li>Update Demo injection_docker_renovate by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3718">https://github.com/plengauer/Thoth/pull/3718</a></li>
<li>Update Demo observe_subprocesses by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3717">https://github.com/plengauer/Thoth/pull/3717</a></li>
<li>Update Demo observe_subprocesses by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3727">https://github.com/plengauer/Thoth/pull/3727</a></li>
<li>Update Demo _complex_download_github_releases by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3716">https://github.com/plengauer/Thoth/pull/3716</a></li>
<li>Update Demo injection_docker_renovate by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3728">https://github.com/plengauer/Thoth/pull/3728</a></li>
<li>Deploy OpenTelemetry by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3720">https://github.com/plengauer/Thoth/pull/3720</a></li>
<li>Pin dependencies by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3721">https://github.com/plengauer/Thoth/pull/3721</a></li>
<li>Update renovatebot/github-action action to v46.1.18 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3729">https://github.com/plengauer/Thoth/pull/3729</a></li>
<li>Update docker/setup-qemu-action action to v4.2.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3701">https://github.com/plengauer/Thoth/pull/3701</a></li>
<li>Update github/gh-aw-actions action to v0.82.3 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3724">https://github.com/plengauer/Thoth/pull/3724</a></li>
<li>Update plengauer/opentelemetry-github action to v5.59.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3725">https://github.com/plengauer/Thoth/pull/3725</a></li>
<li>Update actions/setup-java action to v5.5.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3740">https://github.com/plengauer/Thoth/pull/3740</a></li>
<li>Update otel/opentelemetry-collector-contrib Docker tag to v0.156.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3741">https://github.com/plengauer/Thoth/pull/3741</a></li>
<li>Fix <code>sudo --</code> injection: place <code>--preserve-env</code> before end-of-options separator by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3739">https://github.com/plengauer/Thoth/pull/3739</a></li>
<li>Temporarily disable superlinter injection by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3771">https://github.com/plengauer/Thoth/pull/3771</a></li>
<li>Update opentelemetry-python monorepo by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3779">https://github.com/plengauer/Thoth/pull/3779</a></li>
<li>Deploy OpenTelemetry by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3743">https://github.com/plengauer/Thoth/pull/3743</a></li>
<li>Update dependency org.junit.jupiter:junit-jupiter to v6.1.2 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3763">https://github.com/plengauer/Thoth/pull/3763</a></li>
<li>Update renovatebot/github-action action to v46.1.19 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3764">https://github.com/plengauer/Thoth/pull/3764</a></li>
<li>Group Traceloop Renovate updates with OpenTelemetry dependencies by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3784">https://github.com/plengauer/Thoth/pull/3784</a></li>
<li>Transition quality linting from super-linter to MegaLinter by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3777">https://github.com/plengauer/Thoth/pull/3777</a></li>
<li>Add musl/Node HTTP docker integration coverage by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3742">https://github.com/plengauer/Thoth/pull/3742</a></li>
<li>Fix publish workflow: only mark release as latest when no higher version exists by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3761">https://github.com/plengauer/Thoth/pull/3761</a></li>
<li>Reduce renovate test matrix from 10 to 3 runs by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3773">https://github.com/plengauer/Thoth/pull/3773</a></li>
<li>Update actions/setup-dotnet action to v6 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3780">https://github.com/plengauer/Thoth/pull/3780</a></li>
<li>Update actions/setup-java action to v5.6.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3778">https://github.com/plengauer/Thoth/pull/3778</a></li>
<li>Update Demo injection_deep_java by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3749">https://github.com/plengauer/Thoth/pull/3749</a></li>
<li>Update github/gh-aw-actions action to v0.82.12 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3746">https://github.com/plengauer/Thoth/pull/3746</a></li>
<li>Update dependency @actions/cache by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3726">https://github.com/plengauer/Thoth/pull/3726</a></li>
<li>Update Demo injection_deep_python by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3751">https://github.com/plengauer/Thoth/pull/3751</a></li>
<li>Update ghcr.io/plengauer/opentelemetry-github-workflow-instrumentation-runner Docker tag to v5.59.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3723">https://github.com/plengauer/Thoth/pull/3723</a></li>
<li>Update Demo injection_inner_xargs_parallel by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3750">https://github.com/plengauer/Thoth/pull/3750</a></li>
<li>Update Demo context_propagation_http_netcat by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3753">https://github.com/plengauer/Thoth/pull/3753</a></li>
<li>Update actions/setup-node action to v7 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3770">https://github.com/plengauer/Thoth/pull/3770</a></li>
<li>Fix superlinter injection by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3734">https://github.com/plengauer/Thoth/pull/3734</a></li>
<li>Fix deployment workflow downgrades permissions by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3757">https://github.com/plengauer/Thoth/pull/3757</a></li>
<li>Update Test Images by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3786">https://github.com/plengauer/Thoth/pull/3786</a></li>
<li>Serialize publish job executions via concurrency group by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3762">https://github.com/plengauer/Thoth/pull/3762</a></li>
<li>Update Demo observe_subprocesses by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3752">https://github.com/plengauer/Thoth/pull/3752</a></li>
<li>Update Demo _complex_download_github_releases by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3748">https://github.com/plengauer/Thoth/pull/3748</a></li>
<li>Pin dependencies by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3792">https://github.com/plengauer/Thoth/pull/3792</a></li>
<li>Update softprops/action-gh-release action to v3.0.2 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3768">https://github.com/plengauer/Thoth/pull/3768</a></li>
<li>Lock file maintenance by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3765">https://github.com/plengauer/Thoth/pull/3765</a></li>
<li>Update Demo injection_deep_node by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3754">https://github.com/plengauer/Thoth/pull/3754</a></li>
<li>Update Demo injection_docker_renovate by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3755">https://github.com/plengauer/Thoth/pull/3755</a></li>
<li>Update renovatebot/github-action action to v46.1.20 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3799">https://github.com/plengauer/Thoth/pull/3799</a></li>
<li>Update actions/setup-python action to v7 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3800">https://github.com/plengauer/Thoth/pull/3800</a></li>
<li>Update opentelemetry-js monorepo by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3802">https://github.com/plengauer/Thoth/pull/3802</a></li>
<li>Update github/codeql-action action to v3.37.3 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3801">https://github.com/plengauer/Thoth/pull/3801</a></li>
<li>Update github/gh-aw-actions action to v0.83.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3798">https://github.com/plengauer/Thoth/pull/3798</a></li>
<li>Update dependency io.opentelemetry.javaagent:opentelemetry-javaagent to v2.30.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3810">https://github.com/plengauer/Thoth/pull/3810</a></li>
<li>Update otel/opentelemetry-collector-contrib Docker tag to v0.157.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3812">https://github.com/plengauer/Thoth/pull/3812</a></li>
<li>Recompile Agentic Workflows by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3744">https://github.com/plengauer/Thoth/pull/3744</a></li>
<li>Update actions/checkout action to v7.0.1 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3797">https://github.com/plengauer/Thoth/pull/3797</a></li>
<li>Add Renovate-trackable version comments to OpenTelemetry GitHub action SHA pins by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3815">https://github.com/plengauer/Thoth/pull/3815</a></li>
<li>Temporarily disable uploading of the sarif file by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3823">https://github.com/plengauer/Thoth/pull/3823</a></li>
<li>MegaLinter config: exclude generated files, disable non-applicable linters, fix jscpd threshold by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3833">https://github.com/plengauer/Thoth/pull/3833</a></li>
<li>Rework copilot instructions: remove SHA-pin rule, add lock.yml guidance, fix stale facts by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3828">https://github.com/plengauer/Thoth/pull/3828</a></li>
<li>Fix corroborated Python analyzer bugs in SDK detector loading and action bootstrap by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3851">https://github.com/plengauer/Thoth/pull/3851</a></li>
<li>Docs: resolve markdownlint/table formatter findings across README, demos, and skills docs by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3856">https://github.com/plengauer/Thoth/pull/3856</a></li>
<li>Propagate otel SDK version in workflow instrumentation on Alpine/busybox by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3712">https://github.com/plengauer/Thoth/pull/3712</a></li>
<li>Add cspell.json project dictionary to eliminate false positive spell-check noise by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3857">https://github.com/plengauer/Thoth/pull/3857</a></li>
<li>Update actions/github-script digest to 3a2844b by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3820">https://github.com/plengauer/Thoth/pull/3820</a></li>
<li>Add explicit <code>idna&gt;=3.15</code> constraint for SDK wrapper requirements by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3861">https://github.com/plengauer/Thoth/pull/3861</a></li>
<li>Harden C HTTP instrumentation and forward wrapper: allocation checks, bounded formatting, and canonical formatting pass by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3862">https://github.com/plengauer/Thoth/pull/3862</a></li>
<li>Add MegaLinter config for non-applicable rules and jscpd threshold by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3865">https://github.com/plengauer/Thoth/pull/3865</a></li>
<li>Split deploy action into deploy and deploy-local by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3829">https://github.com/plengauer/Thoth/pull/3829</a></li>
<li>Fix shellcheck findings in hand-written workflow YAML (actionlint/MegaLinter) by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3860">https://github.com/plengauer/Thoth/pull/3860</a></li>
<li>Fix Python style findings: bare except, F811 duplicate imports, type annotations, method-assign by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3870">https://github.com/plengauer/Thoth/pull/3870</a></li>
<li>Add per-user rate limit to autotriage agentic workflow by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3874">https://github.com/plengauer/Thoth/pull/3874</a></li>
<li>Automatic Version Bump by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3879">https://github.com/plengauer/Thoth/pull/3879</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/plengauer/Thoth/compare/v5.59...v5.60.0">https://github.com/plengauer/Thoth/compare/v5.59...v5.60.0</a></p>
]]></content:encoded></item><item><title>llms-txt-check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/llms-txt-check/</link><pubDate>Sun, 09 Aug 2026 13:58:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/llms-txt-check/</guid><description>Version updated for https://github.com/portdeveloper/llms-txt-check-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The llms-txt-check action validates a website’s llms.txt file against what it serves by checking each listed URL. It helps prevent serving-layer breakage by failing the deploy if any URL is not accessible or returns HTML instead of markdown. The action wraps the llms-txt-check tool and provides an easy-to-use GitHub Action for continuous integration purposes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/portdeveloper/llms-txt-check-action">https://github.com/portdeveloper/llms-txt-check-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/llms-txt-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The llms-txt-check action validates a website&rsquo;s <code>llms.txt</code> file against what it serves by checking each listed URL. It helps prevent serving-layer breakage by failing the deploy if any URL is not accessible or returns HTML instead of markdown. The action wraps the llms-txt-check tool and provides an easy-to-use GitHub Action for continuous integration purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release: wraps llms-txt-check 0.1.4 as a composite action.</p>
]]></content:encoded></item><item><title>quantakrypto Quantum Readiness Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/quantakrypto-quantum-readiness-scan/</link><pubDate>Sun, 09 Aug 2026 13:57:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/quantakrypto-quantum-readiness-scan/</guid><description>Version updated for https://github.com/quantakrypto/pqc-tools to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action runs the qScan and Sieve checks in CI to identify quantum-vulnerable crypto, annotate the diff, and fail the build only on new findings. It provides SARIF output for code-scanning upload and supports compliance mandates with dates and deadlines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quantakrypto/pqc-tools">https://github.com/quantakrypto/pqc-tools</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quantakrypto-quantum-readiness-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action runs the qScan and Sieve checks in CI to identify quantum-vulnerable crypto, annotate the diff, and fail the build only on new findings. It provides SARIF output for code-scanning upload and supports compliance mandates with dates and deadlines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Minor. Three additive features and two user-facing bug fixes. Nothing existing changes shape, and no exit code moves.</p>
<h2 id="fixed">Fixed</h2>
<p><strong>Our SARIF was rejected by GitHub code scanning, in full.</strong> A result&rsquo;s <code>taxa[]</code> holds reporting-descriptor references directly; we wrapped them in <code>target</code>, which is relationship shape. GitHub refused the entire file, so every consumer following the workflow we document — action writes SARIF, <code>upload-sarif</code> publishes it — had been getting nothing in their Security tab. Two safeguards agreed with the bug and are fixed with it: the validator never looked inside <code>taxa</code>, and the unit test asserted the broken shape. Found by running our own scanner against our own repository for the first time.</p>
<p><strong>qProbe refuses a URL as a URL</strong>, not as a CIDR block, and names the host to use. <code>qprobe --i-own-this https://example.com</code> used to fail with &ldquo;qProbe probes one host at a time, not ranges&rdquo; — an error describing a mistake the operator had not made.</p>
<h2 id="added">Added</h2>
<p><strong>One workflow runs any combination of the three checks.</strong> <code>checks: scan,conformance,probe</code> — any subset. It replaces three separate workflow files that each shelled out to <code>npx</code> and turned the JSON into a result payload with inline <code>jq</code>, which put our reporting logic inside repositories we cannot fix. <code>checks</code> defaults to <code>scan</code>, exactly what the action did before, so an existing workflow keeps working unchanged.</p>
<p><strong><code>ignore</code> and <code>include</code> inputs.</strong> The CLI had both; the action had neither, so anything reachable only through the action could not exclude a path. Content, fixtures and docs that <em>describe</em> cryptography match the detectors and become findings nobody wanted scanned. A baseline was the only workaround and it is the wrong tool: it records a finding as known debt, and a blog post mentioning RSA is not debt.</p>
<p><strong>Sieve reports <code>ERROR</code> when the implementation could not be run</strong>, distinct from <code>FAIL</code>. Pointing <code>--impl</code> at a command that does not exist used to produce ~35 high-severity conformance defects tagged with bug classes that were never exercised — a confident verdict about code that never executed. It now reports one harness finding that names the actual cause, quoting the diagnostic line from the child&rsquo;s stderr.</p>
<h2 id="note-for-existing-users">Note for existing users</h2>
<p>The moving <code>v1</code> Action tag now points at this release, so <code>uses: quantakrypto/pqc-tools/packages/action@v1</code> picks up the unified action. It is backward compatible: <code>checks</code> defaults to <code>scan</code>, and the outputs, gate, exit codes and annotations are unchanged.</p>
<p>Under a platform dispatch the action now reports the result itself. A workflow that also has its own reporting step will find the callback token already consumed and get a 403 on the second post; the first write wins and the job stays green. Removing that step is tidier but not required.</p>
]]></content:encoded></item><item><title>Basilisk AI Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/basilisk-ai-security-scan/</link><pubDate>Sun, 09 Aug 2026 13:56:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/basilisk-ai-security-scan/</guid><description>Version updated for https://github.com/regaan/basilisk to version v2.0.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Basilisk is an open-source AI red teaming and LLM security testing framework that automates adversarial prompt testing against various LLM models using evolutionary prompt search. It helps security researchers, penetration testers, and defensive teams perform repeatable LLM security testing workflows efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/regaan/basilisk">https://github.com/regaan/basilisk</a></strong> to version <strong>v2.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/basilisk-ai-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Basilisk is an open-source AI red teaming and LLM security testing framework that automates adversarial prompt testing against various LLM models using evolutionary prompt search. It helps security researchers, penetration testers, and defensive teams perform repeatable LLM security testing workflows efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="basilisk-v202">Basilisk v2.0.2</h2>
<p>AI Red Teaming Framework - Smart Prompt Evolution for LLM Security Testing.</p>
<h3 id="downloads">Downloads</h3>
<table>
  <thead>
      <tr>
          <th>Platform</th>
          <th>File</th>
          <th>Trust</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Windows</strong></td>
          <td><code>.exe</code> (NSIS installer)</td>
          <td>Community Build - COMMUNITY BUILD: Windows artifact is not Authenticode-signed and will trigger trust warnings.</td>
      </tr>
      <tr>
          <td><strong>macOS</strong></td>
          <td><code>.dmg</code> (Apple Disk Image)</td>
          <td>Community Build - COMMUNITY BUILD: macOS artifact is not Apple Developer signed and notarized.</td>
      </tr>
      <tr>
          <td><strong>Linux (Universal)</strong></td>
          <td><code>.AppImage</code></td>
          <td>Community Build - COMMUNITY BUILD: Linux packages are unsigned and include keyless CI provenance.</td>
      </tr>
      <tr>
          <td><strong>Arch Linux</strong></td>
          <td><code>.pacman</code></td>
          <td>Community Build - COMMUNITY BUILD: Linux packages are unsigned and include keyless CI provenance.</td>
      </tr>
      <tr>
          <td><strong>Ubuntu/Debian</strong></td>
          <td><code>.deb</code></td>
          <td>Community Build - COMMUNITY BUILD: Linux packages are unsigned and include keyless CI provenance.</td>
      </tr>
      <tr>
          <td><strong>Fedora/RHEL</strong></td>
          <td><code>.rpm</code></td>
          <td>Community Build - COMMUNITY BUILD: Linux packages are unsigned and include keyless CI provenance.</td>
      </tr>
  </tbody>
</table>
<h3 id="supply-chain-security">Supply-Chain Security</h3>
<ul>
<li>Release metadata includes <code>release-manifest.json</code>, <code>sbom.json</code>, and <code>provenance.json</code></li>
<li>Release assets include keyless Sigstore provenance proofs generated by GitHub Actions</li>
<li>Desktop artifacts are explicitly labeled as <code>Vendor-Signed Build</code> or <code>Community Build</code></li>
<li>Community installers are unsigned and do not claim Apple Developer or Windows Authenticode trust</li>
</ul>
<h3 id="install-via-pip">Install via pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install basilisk-ai
</span></span></code></pre></div><h3 id="install-via-docker">Install via Docker</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull rothackers/basilisk
</span></span><span style="display:flex;"><span>docker run --rm rothackers/basilisk scan --help
</span></span></code></pre></div>]]></content:encoded></item><item><title>docker-hash</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/docker-hash/</link><pubDate>Sun, 09 Aug 2026 13:54:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/docker-hash/</guid><description>Version updated for https://github.com/RemkoMolier/docker-hash to version v0.3.19.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary docker-hash is a Go tool that computes a SHA-256 hash of Docker images based on their Dockerfile content, build arguments, and referenced files. It helps in detecting changes to these components and can be used for cache-busting and deterministic CI pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RemkoMolier/docker-hash">https://github.com/RemkoMolier/docker-hash</a></strong> to version <strong>v0.3.19</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-hash">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>docker-hash</code> is a Go tool that computes a SHA-256 hash of Docker images based on their Dockerfile content, build arguments, and referenced files. It helps in detecting changes to these components and can be used for cache-busting and deterministic CI pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="bug-fixes">Bug fixes</h3>
<ul>
<li>fix(deps): update module github.com/google/go-containerregistry to v0.21.9 (#196)</li>
</ul>
]]></content:encoded></item><item><title>SBOMlyze Diff</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sbomlyze-diff/</link><pubDate>Sun, 09 Aug 2026 13:53:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sbomlyze-diff/</guid><description>Version updated for https://github.com/rezmoss/sbomlyze to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action compares Software Bills of Materials to identify changes in packages, including security issues and integrity risks. It helps organizations ensure that their software supply chain is secure by automatically flagging unauthorized package modifications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rezmoss/sbomlyze">https://github.com/rezmoss/sbomlyze</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sbomlyze-diff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action compares Software Bills of Materials to identify changes in packages, including security issues and integrity risks. It helps organizations ensure that their software supply chain is secure by automatically flagging unauthorized package modifications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>fc7cbf4284b9704d1691111946a86e5cec30d7ec  feat(action): add secure SBOM diff GitHub Action MVP</li>
<li>6f00ac9029063e85ec795de2ff501a64b4a832b5  feat(action): add secure SBOM diff GitHub Action MVP</li>
<li>6d2ebbd4ac629998608d887d9b83c129f66c56c8 chore(main): release 0.4.0</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Aug0826 5 by @rezmoss in <a href="https://github.com/rezmoss/sbomlyze/pull/37">https://github.com/rezmoss/sbomlyze/pull/37</a></li>
<li>chore(main): release 0.4.0 by @github-actions[bot] in <a href="https://github.com/rezmoss/sbomlyze/pull/38">https://github.com/rezmoss/sbomlyze/pull/38</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@github-actions[bot] made their first contribution in <a href="https://github.com/rezmoss/sbomlyze/pull/38">https://github.com/rezmoss/sbomlyze/pull/38</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/rezmoss/sbomlyze/compare/v0.3.7...v0.4.0">https://github.com/rezmoss/sbomlyze/compare/v0.3.7...v0.4.0</a></p>
]]></content:encoded></item><item><title>spec.md check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/spec.md-check/</link><pubDate>Sun, 09 Aug 2026 13:52:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/spec.md-check/</guid><description>Version updated for https://github.com/rosenjcb/spec.md to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary spec-md is a tool designed to create machine-readable specifications using Markdown. It allows developers to align their work by defining requirements and QA test cases in a structured format (*.spec.md). The action automates the process of linting specs, ensuring that every test case has a stable id (TC-XXXX) and failing CI when the spec differs from the implementation or tests. This helps maintain consistency across development and ensures high-quality software by reducing ambiguity and gaps in understanding.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rosenjcb/spec.md">https://github.com/rosenjcb/spec.md</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spec-md-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>spec-md</strong> is a tool designed to create machine-readable specifications using Markdown. It allows developers to align their work by defining requirements and QA test cases in a structured format (<code>*.spec.md</code>). The action automates the process of linting specs, ensuring that every test case has a stable id (<code>TC-XXXX</code>) and failing CI when the spec differs from the implementation or tests. This helps maintain consistency across development and ensures high-quality software by reducing ambiguity and gaps in understanding.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="rosenjcbspec-md-v040">@rosenjcb/spec-md v0.4.0</h2>
<h3 id="minor-changes">Minor Changes</h3>
<ul>
<li>
<p>46a7977: Replace sequential TC-N test-case ids with stable opaque TC-XXXX identifiers. lint validates format and uniqueness only (no contiguous order for TC); coverage matches [TC-XXXX] tags; new generates stable ids; add <code>spec-md id</code> and <code>spec-md migrate-ids</code> for allocation and one-shot migration of legacy tables.</p>
<p>Brand the product as <strong>spec-md</strong> (hyphen) everywhere except the <code>*.spec.md</code> file extension and the existing GitHub repo path <code>rosenjcb/spec.md</code>, so skill/plugin ids stay regex-friendly.</p>
<p>Drop the <code>[NEW]</code> / <code>[UPDATED]</code> / <code>[REMOVED]</code> row lifecycle convention. Specs are the current contract only; git and review records carry the delta. The CLI no longer special-cases those tags.</p>
</li>
</ul>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install --save-dev @rosenjcb/spec-md@0.4.0
</span></span><span style="display:flex;"><span>npx @rosenjcb/spec-md check
</span></span></code></pre></div><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">rosenjcb/spec.md@v0.4.0</span>
</span></span></code></pre></div><blockquote>
<p><strong>GitHub Action Marketplace:</strong> automated releases do not check &ldquo;Publish to Marketplace&rdquo;.
On the first release, open the release in GitHub and enable marketplace publishing manually.
See <a href="https://github.com/rosenjcb/spec.md/blob/main/RELEASING.md">RELEASING.md</a>.</p>
</blockquote>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: make install flag commands runnable in sequence by @rosenjcb in <a href="https://github.com/rosenjcb/spec-md/pull/16">https://github.com/rosenjcb/spec-md/pull/16</a></li>
<li>Stable TC-XXXX test ids and spec-md rebrand by @rosenjcb in <a href="https://github.com/rosenjcb/spec-md/pull/18">https://github.com/rosenjcb/spec-md/pull/18</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/rosenjcb/spec-md/compare/v0.3.6...v0.4.0">https://github.com/rosenjcb/spec-md/compare/v0.3.6...v0.4.0</a></p>
]]></content:encoded></item><item><title>Docker Compose Cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/docker-compose-cache/</link><pubDate>Sun, 09 Aug 2026 13:51:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/docker-compose-cache/</guid><description>Version updated for https://github.com/seijikohara/docker-compose-cache-action to version v1.8.21.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Docker Compose Cache Action automates the caching of Docker images used in Docker Compose files to speed up CI/CD workflows. It parses the Compose files, caches each image as a separate tarball with its digest for verification, and selectively pulls images only when necessary. This ensures efficient use of cache and reduces build times by avoiding repeated downloads of unchanged images. The action supports multiple Compose files and allows for specifying which images to exclude from caching.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seijikohara/docker-compose-cache-action">https://github.com/seijikohara/docker-compose-cache-action</a></strong> to version <strong>v1.8.21</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-compose-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Docker Compose Cache Action automates the caching of Docker images used in Docker Compose files to speed up CI/CD workflows. It parses the Compose files, caches each image as a separate tarball with its digest for verification, and selectively pulls images only when necessary. This ensures efficient use of cache and reduces build times by avoiding repeated downloads of unchanged images. The action supports multiple Compose files and allows for specifying which images to exclude from caching.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update dependency oxfmt to ^0.62.0 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/327">https://github.com/seijikohara/docker-compose-cache-action/pull/327</a></li>
<li>chore(deps): update pnpm to v11.19.0 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/328">https://github.com/seijikohara/docker-compose-cache-action/pull/328</a></li>
<li>chore(deps): update dependency taze to v20 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/329">https://github.com/seijikohara/docker-compose-cache-action/pull/329</a></li>
<li>chore(deps): update pnpm/action-setup action to v6.0.10 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/326">https://github.com/seijikohara/docker-compose-cache-action/pull/326</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/330">https://github.com/seijikohara/docker-compose-cache-action/pull/330</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.20...v1.8.21">https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.20...v1.8.21</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sherpa.sh/</link><pubDate>Sun, 09 Aug 2026 13:50:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven tool that automates cloud infrastructure deployment by understanding human intent and creating the necessary resources to ship applications. It simplifies the process of setting up environments across various clouds, frameworks, and configurations using natural language prompts. The action supports multiple providers, integrates seamlessly with GitHub Actions, and offers features for resource specification, custom domains, load balancing, CDN configuration, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven tool that automates cloud infrastructure deployment by understanding human intent and creating the necessary resources to ship applications. It simplifies the process of setting up environments across various clouds, frameworks, and configurations using natural language prompts. The action supports multiple providers, integrates seamlessly with GitHub Actions, and offers features for resource specification, custom domains, load balancing, CDN configuration, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>agent-trace eval</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/agent-trace-eval/</link><pubDate>Sun, 09 Aug 2026 13:49:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/agent-trace-eval/</guid><description>Version updated for https://github.com/Siddhant-K-code/agent-trace to version v0.83.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The agent-trace GitHub Action is designed to trace and replay the actions of AI agents, providing insights into tool calls, file operations, decision points, error recovery, and actual commands. It captures the full session and allows for exporting to observability tools like Datadog, Honeycomb, New Relic, or Splunk, setting rules to control the agent’s behavior. The action supports CLI hooks, MCP proxy integration, and Python decorator options for capturing tool calls without needing an MCP server.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Siddhant-K-code/agent-trace">https://github.com/Siddhant-K-code/agent-trace</a></strong> to version <strong>v0.83.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-trace-eval">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>agent-trace</code> GitHub Action is designed to trace and replay the actions of AI agents, providing insights into tool calls, file operations, decision points, error recovery, and actual commands. It captures the full session and allows for exporting to observability tools like Datadog, Honeycomb, New Relic, or Splunk, setting rules to control the agent&rsquo;s behavior. The action supports CLI hooks, MCP proxy integration, and Python decorator options for capturing tool calls without needing an MCP server.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: restore editor session lifecycle tracking (#224)</li>
</ul>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/spek-openspec-static-site/</link><pubDate>Sun, 09 Aug 2026 13:47:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: spek is a lightweight, read-only viewer for OpenSpec content that provides structured browsing with features such as BDD syntax highlighting, task progress tracking, and full-text search. It allows users to navigate through specs, changes, and tasks within a repository, including handling multiple worktrees efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary</strong>: spek is a lightweight, read-only viewer for OpenSpec content that provides structured browsing with features such as BDD syntax highlighting, task progress tracking, and full-text search. It allows users to navigate through specs, changes, and tasks within a repository, including handling multiple worktrees efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Highlight: a spec opens as an outline with substance, instead of a wall of text.</strong> Reported as &ldquo;you are asked to read all these fine details, but you don&rsquo;t even really know the shape of the thing first&rdquo; (issue #42, filed from the IntelliJ plugin).</p>
<ul>
<li><strong>Requirements and scenarios fold in place.</strong> Each <code>### Requirement:</code> shows its heading <em>and</em> its lead SHALL paragraph; each <code>#### Scenario:</code> shows as a heading with its WHEN/THEN body collapsed. Scenario blocks are 59% of the character volume in this repo&rsquo;s own specs — so the first screen becomes a contents page that still says what each requirement requires, rather than a parallel index you have to leave the content to read. Expand all / Collapse all is available, and your choice is remembered</li>
<li><strong>Find-in-page still finds folded text, and links still land.</strong> Folding uses the browser&rsquo;s native disclosure elements rather than hiding content with CSS, so <code>Ctrl+F</code> reaches text inside a collapsed scenario. Navigating to a heading — from the table of contents, from a <code>#hash</code> on load, or from VS Code&rsquo;s navigate-to command — expands whatever encloses it before scrolling, so a link never arrives at something invisible</li>
<li><strong>Folding applies only to spec-shaped content</strong> — the spec detail page and a change&rsquo;s Specs tab. Proposal, design and other markdown artifacts render unfolded exactly as before</li>
<li><strong>Every BDD keyword is legible in the light theme.</strong> WHEN / THEN / SHALL and the rest were hard-coded to one set of colours shared by both themes, and against the light background all 8 failed WCAG AA — 7 below even 3:1, with <code>THEN</code> at <strong>1.43:1</strong>. The dark theme passed everywhere, which is why this went unseen. Light now has its own values in the same hue families, clearing AA at 5.17–6.47:1; dark is unchanged byte for byte, and no hue or pill fill moves on either theme</li>
<li><strong>A highlighted keyword no longer renders lighter than the emphasis around it.</strong> A keyword inside <code>**bold**</code> was drawn at a lower font weight than the bold text containing it</li>
<li><em>Internal:</em> the TypeScript and Kotlin task parsers are now verified against one shared fixture corpus, so a case added in one language is asserted by both from the next run. <code>@spekjs/core</code> also gained the artifact sort function that had been living in the web package</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/classroom-to-sheets-integration/</link><pubDate>Sun, 09 Aug 2026 13:46:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates GitHub Classroom with Google Sheets to automatically send assignment results. It allows you to track students’ progress and automate grading tasks. The key capabilities include updating Google Sheets with task scores based on GitHub actions and ensuring that the sheet structure is dynamically adjusted to accommodate new tasks or additional columns.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates GitHub Classroom with Google Sheets to automatically send assignment results. It allows you to track students&rsquo; progress and automate grading tasks. The key capabilities include updating Google Sheets with task scores based on GitHub actions and ensuring that the sheet structure is dynamically adjusted to accommodate new tasks or additional columns.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>Sentinel Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sentinel-review/</link><pubDate>Sun, 09 Aug 2026 13:46:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sentinel-review/</guid><description>Version updated for https://github.com/Stackgirl01/sentinel-review to version v1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sentinel Review is an AI-powered security review action that analyzes pull requests by reading diffs and reasoning about them with Claude. It catches reasoning-based issues like hardcoded secrets, SQL injection, auth bypasses, and more. The action posts inline comments on PRs, providing context for human reviewers to address potential security vulnerabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Stackgirl01/sentinel-review">https://github.com/Stackgirl01/sentinel-review</a></strong> to version <strong>v1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sentinel-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sentinel Review is an AI-powered security review action that analyzes pull requests by reading diffs and reasoning about them with Claude. It catches reasoning-based issues like hardcoded secrets, SQL injection, auth bypasses, and more. The action posts inline comments on PRs, providing context for human reviewers to address potential security vulnerabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fixes an edge case where a diff hunk&rsquo;s line number could be valid on
both the old and new file (common in hunks with a small edit inside a
large context block). Previously the code guessed which side to use,
which could silently attach a comment to the wrong physical line.</p>
<p>Findings now explicitly declare which side (old/new file) a line
number refers to, and the mapping is validated against the actual
diff hunk before posting.</p>
<p>v1 remains unchanged and available for anyone still pinned to it.</p>
]]></content:encoded></item><item><title>go-skeptic</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/go-skeptic/</link><pubDate>Sun, 09 Aug 2026 13:45:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/go-skeptic/</guid><description>Version updated for https://github.com/TGPSKI/skeptic to version v0.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary skeptic is a local repository trust auditor that detects structural vulnerabilities in the gaps between existing security tools, focusing on attack-enabling conditions rather than artifacts. It targets CI/CD trust boundary violations, agentic ecosystem poisoning, and “nobody reviews this” attack surfaces by scanning filesystems for specific patterns and behaviors.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TGPSKI/skeptic">https://github.com/TGPSKI/skeptic</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-skeptic">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>skeptic</code> is a local repository trust auditor that detects structural vulnerabilities in the gaps between existing security tools, focusing on attack-enabling conditions rather than artifacts. It targets CI/CD trust boundary violations, agentic ecosystem poisoning, and &ldquo;nobody reviews this&rdquo; attack surfaces by scanning filesystems for specific patterns and behaviors.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Apply <code>--ignore-paths</code> to the <code>GRAPH-</code>, <code>DEP-</code>, and <code>PROV-</code> check families.
All three walk the tree themselves and never received the patterns, so an
explicitly excluded directory still produced <code>high</code> and <code>critical</code> findings
that counted toward <code>--fail-on</code>. They also reported the walked path rather
than one relative to the scan root, which no repo-relative pattern could match
and which leaked the scanning host&rsquo;s directory layout. The matcher moves to
<code>internal/pathfilter</code> so the two walkers cannot disagree about what &ldquo;ignored&rdquo;
means (#88)</li>
<li>Omit waived findings from SARIF. Code scanning turns every result into an
alert and does not honor <code>result.suppressions</code>, so a waived finding opened an
alert the repository had already reviewed and failed the check on any pull
request touching that file. The complete record stays in the JSON report,
which carries <code>suppressed</code> and <code>suppression_reason</code> (#96, #98)</li>
<li>Label waived findings in markdown output. They rendered identically to live
ones, reading as open findings nobody had acted on (#96)</li>
<li><code>model.ExpandHomePath</code> concatenated the home directory with the rest of the
path, so <code>~/foo/bar</code> became <code>C:\Users\me/foo/bar</code> on Windows (#66)</li>
<li><code>correlation.filePathRelativeToRepo</code> accepted paths outside the repository on
Windows. <code>filepath.IsAbs</code> is false for a rooted path with no volume, so
<code>/etc/passwd</code> was joined onto the repo root and passed containment (#66)</li>
<li><code>security.CheckWorldWritableArtifacts</code> reported every artifact as
world-writable on Windows. Go synthesizes <code>0666</code> for any writable file there,
so the POSIX other-write bit carries no information. It now reports nothing on
Windows rather than noise (#66)</li>
<li><code>corpus.groupFindingsByArtifact</code> bucketed a finding under an empty artifact ID
when its path began with a separator (#66)</li>
<li>The results artifact was named from <code>format</code> and <code>fail-on</code> alone, so two
invocations of the action in one job collided</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li><code>windows-latest</code> job running <code>go vet</code> and <code>go test -race</code>.
<code>internal/corpus/flock_windows.go</code> shipped in v0.3.0 and had never executed;
its first run confirmed <code>LockFileEx</code>/<code>UnlockFileEx</code> work. Integration tests
stay POSIX-only (#66)</li>
<li>Sigstore build provenance on every release archive and <code>checksums.txt</code>, via
<code>actions/attest-build-provenance</code>. Verify with
<code>gh attestation verify &lt;archive&gt; --repo TGPSKI/skeptic</code>. Attestation runs
before the release is published, so a failure produces no release; dry runs
skip it (#4)</li>
<li>Committed <code>.skeptic.json</code> and <code>.skeptic-waivers.json</code>. They gate this
repository&rsquo;s CI and are the reference pair to copy. Markdown stays scanned;
accepted findings are waived with a <code>file_sha256</code> pin, so a waiver lapses when
the file changes (#65)</li>
<li><code>make waivers-check</code> and <code>make waivers-refresh</code>. Editing a waived file breaks
its pin, which is the mechanism working and needs a supported way to re-pin.
<code>waivers-refresh</code> prints the findings each waiver will suppress again, because
re-pinning without reading turns a waiver back into an ignore rule (#93)</li>
<li><code>.github/workflows/ruleset-drift.yml</code>, <code>scripts/ruleset-drift.py</code>, and
<code>make ruleset-drift</code> compare committed <code>.github/ruleset-*.json</code> against the
live rulesets weekly, on dispatch, and on any PR touching them. A token
without repo admin scope receives a reduced view with <code>bypass_actors</code> absent,
which the script detects and reports as a skip rather than diffing against it
(#85)</li>
<li><code>run-id</code> action output, carried into the results artifact name</li>
<li><code>.gitattributes</code> pinning LF on checkout, so Windows <code>core.autocrlf</code> cannot
rewrite line endings and break <code>gofmt</code> or a fixture hash (#66)</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>The CI self-scan blocks. It discarded stderr and its exit code with
<code>|| true</code>, so 487 findings and a 100/100 risk score enforced nothing. It now
runs through the local composite action, which also exercises <code>action.yml</code> on
every CI run (#65)</li>
<li>The release workflow waits for <code>ci.yml</code> to reach <code>completed</code> instead of
reading its conclusion once. An in-progress run has a null conclusion and a
run not yet created returns nothing, and both read as failure — exactly the
window between merging and dispatching a release (#67)</li>
<li><code>.github/ruleset-main.json</code> declared <code>&quot;bypass_actors&quot;: []</code> while the live
ruleset grants <code>RepositoryRole</code> 5 an always bypass. All three ruleset files
are regenerated from live (#85)</li>
<li><code>.gitignore</code> stops ignoring <code>.skeptic.json</code> and <code>.skeptic-waivers.json</code> (#65)</li>
<li><code>test-windows</code> is a required status check on <code>main</code></li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li><code>docs/GITHUB_ACTION.md</code> gains a permissions table, a runner OS and
architecture support matrix, a recipe for running the action twice in one job,
and a statement that SARIF excludes waived findings while JSON retains them.
<code>go-version</code> said &ldquo;Go version for building skeptic&rdquo; without noting it applies
only to the source-build fallback</li>
<li>README documents installing from a release archive — download, checksum,
attestation verify, extract — which did not exist though v0.3.0 shipped five
archives (#4)</li>
<li>README documents the committed scan config as a worked example, including why
a SHA-pinned waiver beats an ignore rule for markdown (#65)</li>
<li><code>CONTRIBUTING.md</code> gains <strong>Provenance</strong>, <strong>Branch rulesets</strong>, and <strong>Scan
waivers</strong> sections. The second states that a ruleset change goes in the file
and on the server in the same change (#4, #85, #93)</li>
</ul>
<h3 id="known-limitations">Known limitations</h3>
<ul>
<li>The ruleset drift check needs a <code>RULESET_READ_TOKEN</code> secret with repo admin
scope. Without it the default <code>GITHUB_TOKEN</code> returns a reduced view and the
workflow warns and skips rather than comparing (#85)</li>
<li><code>.skeptic.json</code> excludes <code>internal/rules/</code> and <code>internal/checks/</code>, so skeptic
does not scan its own detection sources. Every pattern it looks for is present
there as a literal by construction</li>
<li>Waiver pins cover a whole file, so an unrelated edit invalidates them and two
pull requests touching the same waived file conflict on the pin (#100)</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/wails3-build-action/</link><pubDate>Sun, 09 Aug 2026 13:44:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of building a Wails.io project using GoLang and NodeJS. It installs the necessary tools, runs the build process, and optionally uploads the results to GitHub. The action supports various configurations such as specifying the Go version, Wails version, build name, platform, and upload options.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of building a Wails.io project using GoLang and NodeJS. It installs the necessary tools, runs the build process, and optionally uploads the results to GitHub. The action supports various configurations such as specifying the Go version, Wails version, build name, platform, and upload options.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>setup-typos</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/setup-typos/</link><pubDate>Sun, 09 Aug 2026 13:43:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/setup-typos/</guid><description>Version updated for https://github.com/try-chance/setup-typos to version v0.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs the crate-ci/typos tool and adds it to the system’s PATH. It automates the process of checking for typos in a repository by running typos .. The action supports various input parameters for specifying the version, GitHub token, and runner architecture, ensuring flexibility in how the tool is used within different environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/try-chance/setup-typos">https://github.com/try-chance/setup-typos</a></strong> to version <strong>v0.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-typos">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs the <a href="https://github.com/crate-ci/typos">crate-ci/typos</a> tool and adds it to the system&rsquo;s PATH. It automates the process of checking for typos in a repository by running <code>typos .</code>. The action supports various input parameters for specifying the version, GitHub token, and runner architecture, ensuring flexibility in how the tool is used within different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/try-chance/setup-typos/compare/v0.0.1...v0.0.2">https://github.com/try-chance/setup-typos/compare/v0.0.1...v0.0.2</a></p>
]]></content:encoded></item><item><title>MCP Test Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/mcp-test-harness/</link><pubDate>Sun, 09 Aug 2026 13:42:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/mcp-test-harness/</guid><description>Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v5.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The MCP Test Harness is a pytest-style testing framework designed to automate the testing of Multi-Cloud Platform (MCP) servers. It supports TypeScript, Java, Go, and .NET languages, automates various test cases including load testing, chaos engineering, resilience testing, security testing, and generates comprehensive reports.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaquarkhan/mcp-test-harness">https://github.com/vaquarkhan/mcp-test-harness</a></strong> to version <strong>v5.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-test-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The MCP Test Harness is a pytest-style testing framework designed to automate the testing of Multi-Cloud Platform (MCP) servers. It supports TypeScript, Java, Go, and .NET languages, automates various test cases including load testing, chaos engineering, resilience testing, security testing, and generates comprehensive reports.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="summary">Summary</h2>
<ul>
<li>Load test enhancements: <code>assert_throughput</code> duration soak, p90/p95 gates, weighted mixes; new <code>assert_load_phases</code> ramps</li>
<li>Docs guide sticky testing-mode tabs (Load / Chaos / Resiliency / Security / Reports)</li>
<li>Suite A security packs, ecosystem download totals, pytest hygiene from the 4.0.1→5.0.0 line</li>
<li>Align all <strong>23</strong> PyPI artifacts (core + 22 provider shims) at <strong>5.0.0</strong></li>
</ul>
<p>See CHANGELOG.md for full details.</p>
]]></content:encoded></item><item><title>GitHub self-hosted runners for Hetzner Cloud</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/github-self-hosted-runners-for-hetzner-cloud/</link><pubDate>Sun, 09 Aug 2026 13:41:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/github-self-hosted-runners-for-hetzner-cloud/</guid><description>Version updated for https://github.com/wydler/hcloud-self-hosted-github-runner to version 1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically launches a Hetzner Cloud server as a self-hosted GitHub Actions runner just before a job starts, executes the workflow, and then terminates the server upon completion. It helps in cost savings by potentially reducing hourly costs compared to using GitHub-managed runners, especially for large or frequent builds. The action is designed to be user-friendly and easily auditable with clear documentation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wydler/hcloud-self-hosted-github-runner">https://github.com/wydler/hcloud-self-hosted-github-runner</a></strong> to version <strong>1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-self-hosted-runners-for-hetzner-cloud">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically launches a Hetzner Cloud server as a self-hosted GitHub Actions runner just before a job starts, executes the workflow, and then terminates the server upon completion. It helps in cost savings by potentially reducing hourly costs compared to using GitHub-managed runners, especially for large or frequent builds. The action is designed to be user-friendly and easily auditable with clear documentation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): Update github/codeql-action from v4.36.0 to v4.36.2 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/45">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/45</a></li>
<li>chore(deps): Update renovatebot/github-action from v46.1.14 to v46.1.15 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/49">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/49</a></li>
<li>chore(deps): Update actions/checkout from v6.0.3 to v7.0.0 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/50">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/50</a></li>
<li>chore(deps): Update renovatebot/github-action from v46.1.15 to v46.1.16 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/54">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/54</a></li>
<li>chore(deps): Update github/codeql-action from v4.36.2 to v4.36.3 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/58">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/58</a></li>
<li>chore(deps): Update renovatebot/github-action from v46.1.16 to v46.1.17 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/59">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/59</a></li>
<li>chore(deps): Update renovatebot/github-action from v46.1.17 to v46.1.18 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/63">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/63</a></li>
<li>chore(deps): Update github/codeql-action from v4.36.3 to v4.37.0 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/64">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/64</a></li>
<li>chore(deps): Update renovatebot/github-action from v46.1.18 to v46.1.19 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/70">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/70</a></li>
<li>chore(deps): Update github/codeql-action from v4.37.0 to v4.37.1 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/69">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/69</a></li>
<li>chore(deps): Update actions/checkout from v7.0.0 to v7.0.1 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/72">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/72</a></li>
<li>chore(deps): Update github/codeql-action from v4.37.1 to v4.37.3 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/73">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/73</a></li>
<li>chore(deps): Update renovatebot/github-action from v46.1.19 to v46.1.20 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/74">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/74</a></li>
<li>chore(deps): Update github/codeql-action from v4.37.3 to v4.37.4 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/78">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/78</a></li>
<li>chore(deps): Update renovatebot/github-action from v46.1.20 to v46.2.0 by @renovate-dependency-app[bot] in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/79">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/79</a></li>
<li>Add custom labels support for GitHub Runner by @dwydler in <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/pull/80">https://github.com/wydler/hcloud-self-hosted-github-runner/pull/80</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wydler/hcloud-self-hosted-github-runner/compare/1.1.1...1.2.0">https://github.com/wydler/hcloud-self-hosted-github-runner/compare/1.1.1...1.2.0</a></p>
]]></content:encoded></item><item><title>YAMLResume</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/yamlresume/</link><pubDate>Sun, 09 Aug 2026 13:40:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/yamlresume/</guid><description>Version updated for https://github.com/yamlresume/action to version v0.14.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The YAMLResume GitHub Action automates the process of building professional resumes from YAML files using the YAMLResume CLI. It supports multiple resume builds, customizable build options, and outputs generated file paths for subsequent steps. The action can generate both LaTeX and PDF files and is suitable for use in workflows to handle custom PDF pipelines or to upload artifacts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yamlresume/action">https://github.com/yamlresume/action</a></strong> to version <strong>v0.14.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yamlresume">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The YAMLResume GitHub Action automates the process of building professional resumes from YAML files using the YAMLResume CLI. It supports multiple resume builds, customizable build options, and outputs generated file paths for subsequent steps. The action can generate both LaTeX and PDF files and is suitable for use in workflows to handle custom PDF pipelines or to upload artifacts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="features">Features</h3>
<ul>
<li>bump yamlresume from v0.13.2 to v0.14.1 (<a href="https://github.com/yamlresume/action/commit/8323c5d354faed4c1e777196bd8ebb35eb626a6a">8323c5d</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yamlresume/action/compare/v0.13.2...v0.14.1">https://github.com/yamlresume/action/compare/v0.13.2...v0.14.1</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/b.ia-accessibility-checker/</link><pubDate>Sun, 09 Aug 2026 13:39:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows users to define an audience and a percentage of guidelines they want to meet, enabling them to focus on accessibility for a specific group that represents a larger market share. The action uses AI for analysis, making it flexible and effective for companies aiming to improve their product’s accessibility.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows users to define an audience and a percentage of guidelines they want to meet, enabling them to focus on accessibility for a specific group that represents a larger market share. The action uses AI for analysis, making it flexible and effective for companies aiming to improve their product&rsquo;s accessibility.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>MegaLinter Custom Flavor ee-pod-iac-md-py</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/megalinter-custom-flavor-ee-pod-iac-md-py/</link><pubDate>Sun, 09 Aug 2026 06:00:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/megalinter-custom-flavor-ee-pod-iac-md-py/</guid><description>Version updated for https://github.com/mckraken/megalinter-custom-flavor-iac-md-py to version v10.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a customized version of MegaLinter tailored to optimize Docker image size. It includes several linters such as BICEP, CloudFormation, JSON, Markdown, Python, Terraform, and YAML for linting and formatting tasks. The action automates the setup and execution of these linters on various files in repositories, providing a streamlined development workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mckraken/megalinter-custom-flavor-iac-md-py">https://github.com/mckraken/megalinter-custom-flavor-iac-md-py</a></strong> to version <strong>v10.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/megalinter-custom-flavor-ee-pod-iac-md-py">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a customized version of MegaLinter tailored to optimize Docker image size. It includes several linters such as BICEP, CloudFormation, JSON, Markdown, Python, Terraform, and YAML for linting and formatting tasks. The action automates the setup and execution of these linters on various files in repositories, providing a streamlined development workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Automated release to sync with MegaLinter version v10.0.0.</p>
<p>This release was automatically created to build a custom MegaLinter flavor based on the upstream MegaLinter release v10.0.0.</p>
<p>For more information about changes in this version, see the <a href="https://github.com/oxsecurity/megalinter/releases/tag/v10.0.0">MegaLinter changelog</a>.</p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/totem-shield/</link><pubDate>Sun, 09 Aug 2026 05:59:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.114.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a technical documentation assistant that uses markdown lessons to enforce coding best practices and maintain project context. It provides deterministic linting, an offline queryable knowledge index, and zero-LLM-powered review capabilities, helping developers avoid architectural mistakes and keep project rules in the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.114.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a technical documentation assistant that uses markdown lessons to enforce coding best practices and maintain project context. It provides deterministic linting, an offline queryable knowledge index, and zero-LLM-powered review capabilities, helping developers avoid architectural mistakes and keep project rules in the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>Matrix SVG Contribution Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/matrix-svg-contribution-generator/</link><pubDate>Sun, 09 Aug 2026 05:58:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/matrix-svg-contribution-generator/</guid><description>Version updated for https://github.com/N1k0droid/matrix-svg-contrib to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action N1k0droid/matrix-svg-contrib generates an animated Matrix code rain contribution graph for a GitHub profile README. It automatically generates the animation based on the user’s GitHub activity and displays it in either minimal or expanded layout with legends. The action supports both light and dark themes, customizable cell sizes, and can be easily integrated into a README.md.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/N1k0droid/matrix-svg-contrib">https://github.com/N1k0droid/matrix-svg-contrib</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/matrix-svg-contribution-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>N1k0droid/matrix-svg-contrib</code> generates an animated Matrix code rain contribution graph for a GitHub profile README. It automatically generates the animation based on the user&rsquo;s GitHub activity and displays it in either minimal or expanded layout with legends. The action supports both light and dark themes, customizable cell sizes, and can be easily integrated into a <code>README.md</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Delete dist/tmp (a31aa06)</li>
<li>Add files via upload (fd70f0f)</li>
<li>Create tmp (dfde15a)</li>
<li>First Commit (6ebe98d)</li>
</ul>
]]></content:encoded></item><item><title>Vigil — AI Security Review by Claude</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/vigil-ai-security-review-by-claude/</link><pubDate>Sun, 09 Aug 2026 05:57:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/vigil-ai-security-review-by-claude/</guid><description>Version updated for https://github.com/nadirzhon/vigil to version v1.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Vigil is a GitHub Action that performs AI-based security reviews on pull requests by analyzing changes using Claude. It detects injection, hard-coded secrets, broken authorization, unsafe crypto, SSRF, XSS, and other security vulnerabilities. The tool reports these findings as comments directly in the pull request with severity levels, confidence scores, and fixes suggested for each issue.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nadirzhon/vigil">https://github.com/nadirzhon/vigil</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vigil-ai-security-review-by-claude">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Vigil is a GitHub Action that performs AI-based security reviews on pull requests by analyzing changes using Claude. It detects injection, hard-coded secrets, broken authorization, unsafe crypto, SSRF, XSS, and other security vulnerabilities. The tool reports these findings as comments directly in the pull request with severity levels, confidence scores, and fixes suggested for each issue.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI security review for every pull request, powered by Claude.
Flags injection, hard-coded secrets, and broken authorization
inline on the PR, with a severity gate. Add with:
uses: nadirzhon/vigil@v1</p>
]]></content:encoded></item><item><title>XAI Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/xai-review/</link><pubDate>Sun, 09 Aug 2026 05:56:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/xai-review/</guid><description>Version updated for https://github.com/Nikita-Filonov/ai-review to version v0.76.0.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Review is a developer tool that automates AI-powered code reviews in your CI/CD pipeline, providing inline comments, summary reviews, and AI-generated replies directly inside merge requests. It supports multiple LLM providers, VCS integration, customizable prompts, agent mode, and flexible configuration options, running client-side without proxying or inspecting requests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nikita-Filonov/ai-review">https://github.com/Nikita-Filonov/ai-review</a></strong> to version <strong>v0.76.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xai-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Review is a developer tool that automates AI-powered code reviews in your CI/CD pipeline, providing inline comments, summary reviews, and AI-generated replies directly inside merge requests. It supports multiple LLM providers, VCS integration, customizable prompts, agent mode, and flexible configuration options, running client-side without proxying or inspecting requests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>openai (81a1242)</li>
<li>json (c9fabe9)</li>
<li>git (983de68)</li>
<li>up version (8f9c85c)</li>
<li>Merge pull request #118 from dansan/fix/clear-summary-inline-fallback (a8ce69a)</li>
<li>Update pyproject.toml (d4acc01)</li>
<li>gitlab (826fc99)</li>
<li>Merge pull request #117 from dansan/feature/gitlab-draft-note-hygiene (a80c7ce)</li>
<li>fix(review): clear inline-fallback comments alongside summary comments (f2c6237)</li>
<li>fix(http): do not retry the non-idempotent draft-note bulk publish (93490a5)</li>
</ul>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/odin-scan-smart-contract-security/</link><pubDate>Sun, 09 Aug 2026 05:55:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security scanning of CosmWasm, Solana, and EVM projects using AI-powered smart contract analysis. It integrates with GitHub Code Scanning to provide native security alerts in pull requests, posts detailed findings as inline comments on changed files, and allows for configurable severity thresholds. The action supports automatic platform detection or explicit specification, triggers scans via PR comments, and uploads full reports and SARIF data for further analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the security scanning of CosmWasm, Solana, and EVM projects using AI-powered smart contract analysis. It integrates with GitHub Code Scanning to provide native security alerts in pull requests, posts detailed findings as inline comments on changed files, and allows for configurable severity thresholds. The action supports automatic platform detection or explicit specification, triggers scans via PR comments, and uploads full reports and SARIF data for further analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial Release</p>
<p>AI-powered smart contract security analysis, now integrated directly into your GitHub workflow.</p>
<p>✨ Features</p>
<p>Multi-Platform Support</p>
<ul>
<li>CosmWasm - Rust-based smart contracts for Cosmos SDK</li>
<li>Solana (SVM) - Anchor and native Solana programs</li>
<li>EVM - Solidity and Vyper contracts</li>
<li>Auto-detection - Automatically identifies platform from your repo</li>
</ul>
<p>GitHub Integration</p>
<ul>
<li>Code Scanning - SARIF upload for native security alerts in the Security tab</li>
<li>PR Comments - Severity summary and top findings posted directly on pull requests</li>
<li>Inline Annotations - Critical/high findings appear as errors, medium/low as warnings on diffs</li>
<li>Artifact Upload - Full JSON report available as workflow artifact</li>
</ul>
<p>Customization</p>
<ul>
<li>Severity Thresholds - Fail builds at critical, high, medium, or low severity</li>
<li>Platform Override - Force specific platform detection when auto-detect isn&rsquo;t enough</li>
<li>Timeout Control - Configurable analysis timeout (default: 30 minutes)</li>
<li>Flexible Triggers - Run on push, PR, schedule, or manual dispatch</li>
</ul>
<p>🚀 Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Security Scan</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&#39;on&#39;</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">main</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">security-events</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">api-key</span>: <span style="color:#e6db74">&#39;${{ secrets.ODIN_SCAN_API_KEY }}&#39;</span>
</span></span></code></pre></div><p>📋 Requirements</p>
<ul>
<li>Odin Scan Pro subscription - Required for API access</li>
<li>API Key - Generate at <a href="https://odinscan.ai/dashboard/settings">https://odinscan.ai/dashboard/settings</a></li>
<li>GitHub Permissions - contents: read, security-events: write (for SARIF), pull-requests: write (for
comments)</li>
</ul>
<p>🔧 Configuration</p>
<p>All Inputs</p>
<p>| ┌────────────────────┬─────────────────────┬──────────────────────────────────────────────┐ |
| │       Input        │       Default       │                 Description                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ api-key            │ Required            │ Your Odin Scan API key (odin_sk_*)           │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ platform           │ auto                │ Target platform: auto, cosmwasm, solana, evm │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ severity-threshold │ high                │ Fail at: critical, high, medium, low, none   │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ fail-on-findings   │ true                │ Whether to fail workflow on findings         │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ comment-on-pr      │ true                │ Post summary comment on PRs                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-sarif       │ true                │ Upload SARIF to Code Scanning                │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-artifact    │ true                │ Upload full report as artifact               │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ timeout            │ 1800                │ Max analysis wait time (seconds)             │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ github-token       │ ${{ github.token }} │ Token for PR comments and SARIF              │ |
| └────────────────────┴─────────────────────┴──────────────────────────────────────────────┘ |</p>
<p>All Outputs</p>
<ul>
<li>analysis-id - Unique analysis identifier</li>
<li>status - Analysis status (completed, failed)</li>
<li>total-findings - Total number of findings</li>
<li>critical-count, high-count, medium-count, low-count - Counts by severity</li>
<li>report-url - Link to full report on Odin Scan</li>
<li>sarif-file - Path to generated SARIF file</li>
</ul>
<p>📝 Example Workflows</p>
<p>Basic (Auto-detect)</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span></code></pre></div><p>EVM with Medium Threshold</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">platform</span>: <span style="color:#ae81ff">evm</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">severity-threshold</span>: <span style="color:#ae81ff">medium</span>
</span></span></code></pre></div><p>Only on Solidity Changes</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#39;**.sol&#39;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">foundry.toml</span>
</span></span></code></pre></div><p>🔒 Security &amp; Privacy</p>
<ul>
<li>All API communication over HTTPS (TLS 1.2+)</li>
<li>API keys automatically masked in logs</li>
<li>No data stored by the action (stateless)</li>
<li>See <a href="https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md">https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md</a> for details</li>
</ul>
<p>📖 Documentation</p>
<ul>
<li>Action README - <a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></li>
<li>Odin Scan Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
<li>Get API Key - <a href="https://app.odinscan.ai/settings">https://app.odinscan.ai/settings</a></li>
</ul>
<p>🐛 Known Limitations</p>
<ul>
<li>Private repos - Requires github-token with repo access</li>
<li>Large repos - May need increased timeout for complex codebases</li>
<li>Code Scanning - Requires GitHub Advanced Security on private repos</li>
</ul>
<p>🙏 Support</p>
<ul>
<li>Issues - <a href="https://github.com/Odin-Scan/odin-scan-action/issues">https://github.com/Odin-Scan/odin-scan-action/issues</a></li>
<li>Email - <a href="mailto:support@odinscan.ai">support@odinscan.ai</a></li>
<li>Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
</ul>
<hr>
<p>Full Changelog: <a href="https://github.com/Odin-Scan/odin-scan-action/commits/v1">https://github.com/Odin-Scan/odin-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>Garita PII Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/garita-pii-guard/</link><pubDate>Sun, 09 Aug 2026 05:54:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/garita-pii-guard/</guid><description>Version updated for https://github.com/proscar87/garita to version v0.27.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Garita is a GitHub Action that prevents sensitive personal and credential information from entering your repository by enforcing rules for various identity verification codes (e.g., CURP, RFC) using regular expressions in its configuration. It helps automate the process of checking files against a list of prohibited identifiers to maintain data integrity while auditing financial transactions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/proscar87/garita">https://github.com/proscar87/garita</a></strong> to version <strong>v0.27.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/garita-pii-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Garita is a GitHub Action that prevents sensitive personal and credential information from entering your repository by enforcing rules for various identity verification codes (e.g., CURP, RFC) using regular expressions in its configuration. It helps automate the process of checking files against a list of prohibited identifiers to maintain data integrity while auditing financial transactions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>El arreglo más rentable del roadmap, y el primero que sale del frente de <strong>ruido</strong> — la mitad de la doctrina que llevábamos seis oleadas sin medir.</p>
<p><code>llave_privada</code> casaba la cabecera PEM sin exigir que hubiera llave debajo. <strong>Medido sobre <code>twilio-python</code>: 48 hallazgos, los 48 documentación.</strong> Ahora 0, y ese repositorio pasa de rojo a verde, que era el veredicto correcto.</p>
<p>Las señales que separan una llave de su mención resultaron ser tres:</p>
<ul>
<li>La cabecera <strong>sin cuerpo</strong> no es una llave (una mención en un docstring, un comentario que explica el formato).</li>
<li>En la misma línea, el cuerpo va <strong>pegado</strong> a la cabecera o tras un salto escapado —<code>KEY-----\nMIIE…</code>, como se guarda en un <code>.env</code> o un JSON—, <strong>nunca tras un espacio</strong>: un PEM de verdad lleva salto de línea ahí, y lo que se ve con espacios es el manual enseñando el formato con una llave recortada.</li>
<li>Y si delante hay una <strong>frase</strong> (seis palabras o más), es documentación: una llave real vive tras <code>KEY=&quot;</code>, <code>&quot;key&quot;: &quot;</code> o <code>private_key = &quot;</code>.</li>
</ul>
<p>Las diez formas reales siguen sonando, verificadas una por una: PEM normal, <strong>cifrada</strong> con sus cabeceras RFC 1421 (<code>Proc-Type</code>, <code>DEK-Info</code>), OPENSSH, en <code>.env</code> con <code>\n</code> y con <code>\r\n</code>, en JSON pegada, en asignación y en una llamada con varios argumentos.</p>
<p>279 pruebas.</p>
]]></content:encoded></item><item><title>Configure Node.js</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/configure-node.js/</link><pubDate>Sun, 09 Aug 2026 05:53:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/configure-node.js/</guid><description>Version updated for https://github.com/pwrdrvr/configure-nodejs to version v1.3.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of Node.js, detects the package manager (npm, pnpm, or Yarn), enables Corepack when necessary, and restores the correct cache to optimize build times. It handles different cache scenarios efficiently by running cold installs only when absolutely necessary, reducing costs associated with cache misses during warm cache restoration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pwrdrvr/configure-nodejs">https://github.com/pwrdrvr/configure-nodejs</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/configure-node-js">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the installation of Node.js, detects the package manager (npm, pnpm, or Yarn), enables Corepack when necessary, and restores the correct cache to optimize build times. It handles different cache scenarios efficiently by running cold installs only when absolutely necessary, reducing costs associated with cache misses during warm cache restoration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fixes a dependency cache bug that could hand a job a <code>node_modules</code> built against a different Node.js ABI.</p>
<h2 id="the-fix">The fix</h2>
<p>The cache key interpolated the <code>node-version</code> input verbatim. For a spec that can cross a major release — <code>lts/*</code>, <code>latest</code>, <code>&gt;=20</code> — that segment stayed constant while the runner image&rsquo;s Node.js moved from one major to the next. Because npm and Yarn skip installation entirely on a cache hit, the restored tree was used as-is, so any compiled native addon in it had been built against a different <code>NODE_MODULE_VERSION</code>:</p>
<pre tabindex="0"><code>Error: The module &#39;.../binding.node&#39; was compiled against a different Node.js version
</code></pre><p>The cache key is now built from the Node.js <strong>major</strong>, which is exactly the ABI boundary: <code>NODE_MODULE_VERSION</code> changes with each major and is stable within one.</p>
<p><strong>Affected:</strong> npm and Yarn projects using a <code>node-version</code> that can cross a major. Specs pinned within one major (<code>24.x</code>, <code>24.14.1</code>, the <code>22.x</code> default) were never at risk. pnpm reinstalls on every run, so it was not exposed either.</p>
<h2 id="what-you-will-notice">What you will notice</h2>
<p><strong>Every project takes one cold cache miss on upgrade.</strong> The key segment changes from the raw spec to the major, so existing entries no longer match. One rebuild, then back to normal.</p>
<p><strong><code>lookup-only</code> gates on floating specs now install Node.js even on a cache hit.</strong> A spec that can cross a major cannot be classified from its string, so <code>actions/setup-node</code> has to resolve it before the key exists. This costs those specs the restore-before-setup fast path — typically a second or two, since a floating spec resolves to a version already in the runner toolcache. Pinned specs, including the <code>22.x</code> default, keep the fast path untouched and still skip Node.js installation entirely on a hit.</p>
<p><strong>Gate and consumer keys now match on the major.</strong> A gate on <code>24.x</code> and a consumer on <code>24.14.1</code> previously produced two different keys, so the gate warmed an entry nobody read. They now share one. A gate on <code>24.x</code> and a consumer on <code>22.x</code> still correctly do not.</p>
<h2 id="added">Added</h2>
<ul>
<li><strong><code>node-major</code> output</strong> — the Node.js major the cache key was built from. Useful for asserting that a gate job and its consumers agree.</li>
</ul>
<h2 id="also-in-this-release">Also in this release</h2>
<ul>
<li>The README now explains the cache-priming gate job pattern the action is built around, including the fan-out and retry-trap failure modes it exists to prevent (#9).</li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/pwrdrvr/configure-nodejs/compare/v1.2.0...v1.3.0">https://github.com/pwrdrvr/configure-nodejs/compare/v1.2.0...v1.3.0</a></p>
]]></content:encoded></item><item><title>Allure Notifications</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/allure-notifications/</link><pubDate>Sun, 09 Aug 2026 05:53:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/allure-notifications/</guid><description>Version updated for https://github.com/qa-guru/allure-notifications to version v6.0.14.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates sending test results to a Telegram channel using Allure reports. It supports various workflows, including one for integrating with the Marketplace, another for native npm CLI usage, and an alternative capability using an Allure plugin. The action can be run manually or as part of a release gate workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/qa-guru/allure-notifications">https://github.com/qa-guru/allure-notifications</a></strong> to version <strong>v6.0.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/allure-notifications">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates sending test results to a Telegram channel using Allure reports. It supports various workflows, including one for integrating with the Marketplace, another for native npm CLI usage, and an alternative capability using an Allure plugin. The action can be run manually or as part of a release gate workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="npm-hard-cut">npm hard cut</h2>
<ul>
<li>Public packages move to flat <code>@qa-guru/*</code> (parity with allure-report-kit).</li>
<li>CLI: <code>@qa-guru/allure-notifications@6.0.14</code> (bin name <code>allure-notifications</code> unchanged).</li>
<li>Libs: <code>@qa-guru/allure-notifications-{config,pyramid,core,plugin}@6.0.14</code>.</li>
<li>Abandoned: bare <code>allure-notifications</code> and <code>@allure-notifications/*</code> (deprecated on npm).</li>
<li>Publish org: <code>qa-guru</code> only — see <code>docs/npm-publish.md</code>.</li>
</ul>
<h2 id="consumer">Consumer</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx @qa-guru/allure-notifications@6.0.14 send --config config.json --live
</span></span></code></pre></div><p>After local <code>npm i @qa-guru/allure-notifications</code>, <code>npx --no-install allure-notifications send …</code> still works via bin.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/qa-guru/allure-notifications/compare/v6.0.13...v6.0.14">https://github.com/qa-guru/allure-notifications/compare/v6.0.13...v6.0.14</a></p>
]]></content:encoded></item><item><title>wavedash-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/wavedash-action/</link><pubDate>Sun, 09 Aug 2026 05:52:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/wavedash-action/</guid><description>Version updated for https://github.com/remarkablegames/wavedash-action to version v1.1.0.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The WaveDash Action automates the process of uploading and publishing web game files to Wavedash, an online platform for hosting games. It supports creating wavedash.toml configuration files automatically if not provided, and allows users to publish builds with additional metadata such as build messages and changelog items during the publish process. The action is designed to streamline the deployment of web games to Wavedash by handling the configuration and file uploads efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablegames/wavedash-action">https://github.com/remarkablegames/wavedash-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wavedash-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The WaveDash Action automates the process of uploading and publishing web game files to Wavedash, an online platform for hosting games. It supports creating <code>wavedash.toml</code> configuration files automatically if not provided, and allows users to publish builds with additional metadata such as build messages and changelog items during the publish process. The action is designed to streamline the deployment of web games to Wavedash by handling the configuration and file uploads efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="110-2026-08-09"><a href="https://github.com/remarkablegames/wavedash-action/compare/v1.0.4...v1.1.0">1.1.0</a> (2026-08-09)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>action:</strong> add optional cache input for wavedash CLI install (<a href="https://github.com/remarkablegames/wavedash-action/issues/12">#12</a>) (<a href="https://github.com/remarkablegames/wavedash-action/commit/8ba13c9c6c66e085c92214e2308556876e01f5ee">8ba13c9</a>)</li>
</ul>
]]></content:encoded></item><item><title>Arcana CI Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/arcana-ci-gate/</link><pubDate>Sun, 09 Aug 2026 05:51:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/arcana-ci-gate/</guid><description>Version updated for https://github.com/RewithSolo/arcana-gate to version v1.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Arcana Gate is a deterministic quality gate CLI tool that uses Tarot Major Arcana to make release decisions. It automates the deployment process by checking for negative cards before proceeding, thereby ensuring the integrity and safety of software deployments in production. The action provides absolute determinism through SHA-256 hashing and ensures zero flaky outcomes, making it ideal for DevSecOps teams.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RewithSolo/arcana-gate">https://github.com/RewithSolo/arcana-gate</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/arcana-ci-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Arcana Gate</strong> is a deterministic quality gate CLI tool that uses Tarot Major Arcana to make release decisions. It automates the deployment process by checking for negative cards before proceeding, thereby ensuring the integrity and safety of software deployments in production. The action provides absolute determinism through SHA-256 hashing and ensures zero flaky outcomes, making it ideal for DevSecOps teams.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="arcana-gate-v101--new-release-">Arcana Gate v1.0.1 — New Release 🔮</h1>
<p>Enable GitHub Summary Markdown report and update card render.</p>
<p align="center">
  <img src="https://raw.githubusercontent.com/RewithSolo/arcana-gate/main/assets/demo.png" alt="Arcana Gate Preview Negative" width="48%"/>
  <img src="https://raw.githubusercontent.com/RewithSolo/arcana-gate/main/assets/demo_summary.png" alt="Arcana Gate Preview Positive" width="48%"/>
</p>
<h3 id="-quick-start">📦 Quick Start</h3>
<h4 id="usage-in-github-actions">Usage in GitHub Actions:</h4>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Run Arcana Gate Check</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">RewithSolo/arcana-gate@v1.0.1</span>
</span></span></code></pre></div><h4 id="running-cli-manually">Running CLI Manually:</h4>
<p>Download the pre-built binary for your OS from the <strong>Assets</strong> section below, or build it from source:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>go build -o arcana-gate ./cmd/arcana-gate
</span></span><span style="display:flex;"><span>./arcana-gate
</span></span></code></pre></div><p><strong>Full Changelog</strong>: <a href="https://github.com/RewithSolo/arcana-gate/commits/v1.0.1">https://github.com/RewithSolo/arcana-gate/commits/v1.0.1</a></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>3be5fc12d74362024e315f19ea1aa462d788f227 ci: add demo workflow for test arcana-gate</li>
<li>16c88373a008ea5b4e8b72364b7411937e64e752 fix: action.yaml</li>
<li>d496fa3210c99ef4585654a6b1f54ad8b9edf0c4 fix: action.yaml</li>
<li>b3a8979d183627917973a5bfc0be8a832e03ff89 fix: visual render and refactor action.yaml to composite</li>
</ul>
]]></content:encoded></item><item><title>scheck-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/scheck-action/</link><pubDate>Sun, 09 Aug 2026 05:50:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/scheck-action/</guid><description>Version updated for https://github.com/rh-jfuller/scheck-action-v1 to version 0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The scheck GitHub Action automates JSON/YAML validation against assertion-based rules using the scheck tool. It supports text, JSON, and SARIF output formats with optional uploading to GitHub Code Scanning. Key capabilities include flexible rule file selection, support for multiple phases, input/output formats, and non-blocking validation options.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rh-jfuller/scheck-action-v1">https://github.com/rh-jfuller/scheck-action-v1</a></strong> to version <strong>0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/scheck-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The scheck GitHub Action automates JSON/YAML validation against assertion-based rules using the scheck tool. It supports text, JSON, and SARIF output formats with optional uploading to GitHub Code Scanning. Key capabilities include flexible rule file selection, support for multiple phases, input/output formats, and non-blocking validation options.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release of the scheck GitHub Action.</p>
<p>Validate JSON/YAML documents against <a href="https://github.com/rh-jfuller/scheck">scheck</a> assertion-based rules directly in your CI pipeline.</p>
<h2 id="features">Features</h2>
<ul>
<li>Install scheck automatically (any version, defaults to latest)</li>
<li>Validate documents against one or more rule files</li>
<li>Support for all rule formats: DSL, JSON, Schematron, freetext</li>
<li>Optional phase and context (JSONPath subtree) filtering</li>
<li>Text or JSON output</li>
<li>Configurable fail-on-findings behavior</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">rh-jfuller/scheck-action-v1@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">document</span>: <span style="color:#ae81ff">config.json</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">rules</span>: <span style="color:#ae81ff">rules/security.scheck</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>aislop — AI Code Quality Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/aislop-ai-code-quality-gate/</link><pubDate>Sun, 09 Aug 2026 05:50:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/aislop-ai-code-quality-gate/</guid><description>Version updated for https://github.com/scanaislop/aislop to version v0.14.1.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aislop GitHub Action is designed to detect and score AI-slop, such as narrative comments, swallowed exceptions, hidden fallbacks, as any casts, hallucinated imports, duplicated helpers, dead code, todo stubs, oversized functions in your codebase. It provides a comprehensive set of rules for 10 programming languages (TypeScript, JavaScript, Expo/React Native, Python, Go, Rust, Ruby, PHP, C#, and C/C++) to ensure code quality and maintainability. The action scores every change with sub-second speed and is deterministic, using no LLM in the runtime path. It supports installation via npm, Yarn, Bun, Homebrew, and PyPI, and offers CLI tools for repair, auto-fix, CI mode, and per-edit hooks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scanaislop/aislop">https://github.com/scanaislop/aislop</a></strong> to version <strong>v0.14.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aislop-ai-code-quality-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The aislop GitHub Action is designed to detect and score AI-slop, such as narrative comments, swallowed exceptions, hidden fallbacks, <code>as any</code> casts, hallucinated imports, duplicated helpers, dead code, todo stubs, oversized functions in your codebase. It provides a comprehensive set of rules for 10 programming languages (TypeScript, JavaScript, Expo/React Native, Python, Go, Rust, Ruby, PHP, C#, and C/C++) to ensure code quality and maintainability. The action scores every change with sub-second speed and is deterministic, using no LLM in the runtime path. It supports installation via npm, Yarn, Bun, Homebrew, and PyPI, and offers CLI tools for repair, auto-fix, CI mode, and per-edit hooks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v0.14.1 expands aislop to 10 language targets with first-class C# and C/C++ support, plus accuracy and reliability improvements across the scanner.</p>
<h3 id="added">Added</h3>
<ul>
<li><strong>C# support.</strong> Project discovery, formatting, linting, complexity analysis, dependency checks, and C#-specific AI-slop rules.</li>
<li><strong>C/C++ support.</strong> Detection and scoring with cppcheck, clang-tidy, clang-format, complexity analysis, and C/C++-specific AI-slop rules.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Reduced false findings in C# and C++ strings, comments, raw strings, and interpolated code.</li>
<li>Improved file discovery and exclusions across platforms and nested repositories.</li>
<li>Improved CLI behavior for invalid targets, timed-out tools, Windows tool lookup, dependency scans, and Python imports.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Refreshed project dependencies and CI tooling.</li>
<li>Split large integration modules into smaller, focused components.</li>
</ul>
<h3 id="validation">Validation</h3>
<ul>
<li>2,032 tests passing across 198 files</li>
<li>Linux and Windows CI passing</li>
<li>Aislop self-scan at 100/100 with zero findings</li>
<li>npm package dry run completed for <code>aislop@0.14.1</code></li>
</ul>
]]></content:encoded></item><item><title>Profile Cards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/profile-cards/</link><pubDate>Sun, 09 Aug 2026 05:49:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/profile-cards/</guid><description>Version updated for https://github.com/seijikohara/profile-cards-action to version v0.0.6.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates profile README cards as SVG from the GitHub GraphQL API. It produces various statistics such as lifetime and current-year contributions, stars, followers, merged pull requests, issues, public repositories, recently contributed-to repositories, contribution history, streaks, contribution composition, activity rhythm, and a language treemap. The generated files are self-hosted and theme-aware, using Primer color tokens for blending into both themes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seijikohara/profile-cards-action">https://github.com/seijikohara/profile-cards-action</a></strong> to version <strong>v0.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/profile-cards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates profile README cards as SVG from the GitHub GraphQL API. It produces various statistics such as lifetime and current-year contributions, stars, followers, merged pull requests, issues, public repositories, recently contributed-to repositories, contribution history, streaks, contribution composition, activity rhythm, and a language treemap. The generated files are self-hosted and theme-aware, using Primer color tokens for blending into both themes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update pnpm to v11.19.0 by @renovate[bot] in <a href="https://github.com/seijikohara/profile-cards-action/pull/17">https://github.com/seijikohara/profile-cards-action/pull/17</a></li>
<li>chore(deps): update dependency oxfmt to ^0.62.0 by @renovate[bot] in <a href="https://github.com/seijikohara/profile-cards-action/pull/16">https://github.com/seijikohara/profile-cards-action/pull/16</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/seijikohara/profile-cards-action/pull/19">https://github.com/seijikohara/profile-cards-action/pull/19</a></li>
<li>fix(ci): reconcile release tags instead of erroring, and bound test concurrency by @seijikohara in <a href="https://github.com/seijikohara/profile-cards-action/pull/20">https://github.com/seijikohara/profile-cards-action/pull/20</a></li>
<li>refactor(ci): move the release into a convergent single-purpose workflow by @seijikohara in <a href="https://github.com/seijikohara/profile-cards-action/pull/21">https://github.com/seijikohara/profile-cards-action/pull/21</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/seijikohara/profile-cards-action/compare/v0.0.5...v0.0.6">https://github.com/seijikohara/profile-cards-action/compare/v0.0.5...v0.0.6</a></p>
]]></content:encoded></item><item><title>Storybook VRT (green/red diff)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/storybook-vrt-green/red-diff/</link><pubDate>Sun, 09 Aug 2026 05:48:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/storybook-vrt-green/red-diff/</guid><description>Version updated for https://github.com/sgash708/chromagic to version v1.2.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The chromagic GitHub Action is a Chromatic-like tool for visual regression testing that allows developers to compare the static Storybook builds of different commits and pull requests against a baseline. It captures every changed story, compares them with the baseline, and posts green/red diffs as inline comments in the PR. The main purpose is to help developers catch visual regressions early during the development process by automatically generating side-by-side comparisons between expected and actual screenshots.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sgash708/chromagic">https://github.com/sgash708/chromagic</a></strong> to version <strong>v1.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/storybook-vrt-green-red-diff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The chromagic GitHub Action is a Chromatic-like tool for visual regression testing that allows developers to compare the static Storybook builds of different commits and pull requests against a baseline. It captures every changed story, compares them with the baseline, and posts green/red diffs as inline comments in the PR. The main purpose is to help developers catch visual regressions early during the development process by automatically generating side-by-side comparisons between expected and actual screenshots.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="123-2026-08-09"><a href="https://github.com/sgash708/chromagic/compare/v1.2.2...v1.2.3">1.2.3</a> (2026-08-09)</h2>
<h3 id="performance-improvements">Performance Improvements</h3>
<ul>
<li>setup-chromeのinstall-dependenciesを無効化(検証中) (<a href="https://github.com/sgash708/chromagic/issues/10">#10</a>) (<a href="https://github.com/sgash708/chromagic/commit/1ccd3b8af5e98e02cf6d8c70575a188e2788d9a4">1ccd3b8</a>)</li>
</ul>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sherpa.sh/</link><pubDate>Sun, 09 Aug 2026 05:47:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven tool that automates the deployment of infrastructure based on natural language descriptions. It simplifies cloud deployment by translating human-readable instructions into optimized, secure configurations across various cloud providers, such as AWS, Google Cloud, and more. Sherpa’s capabilities include creating servers, setting up DNS and SSL certificates, configuring CDNs, databases, backups, load balancing, and more. The platform is designed for developers who want to focus on writing code rather than managing infrastructure, offering open-source transparency and community-driven improvements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven tool that automates the deployment of infrastructure based on natural language descriptions. It simplifies cloud deployment by translating human-readable instructions into optimized, secure configurations across various cloud providers, such as AWS, Google Cloud, and more. Sherpa&rsquo;s capabilities include creating servers, setting up DNS and SSL certificates, configuring CDNs, databases, backups, load balancing, and more. The platform is designed for developers who want to focus on writing code rather than managing infrastructure, offering open-source transparency and community-driven improvements.</p>
]]></content:encoded></item><item><title>Change Capsule</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/change-capsule/</link><pubDate>Sun, 09 Aug 2026 05:46:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/change-capsule/</guid><description>Version updated for https://github.com/SiliconState/change-capsule to version v0.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Capsule is an isolated Git worktree and evidence tool that ensures reproducibility of code changes by verifying the execution of commands in a controlled environment without access to the original machine. It allows for testing and verification of patches independently of their source repository, providing both a reproduction check and a mechanism for creating verifiable receipts that can be used to verify the execution results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SiliconState/change-capsule">https://github.com/SiliconState/change-capsule</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/change-capsule">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Capsule is an isolated Git worktree and evidence tool that ensures reproducibility of code changes by verifying the execution of commands in a controlled environment without access to the original machine. It allows for testing and verification of patches independently of their source repository, providing both a reproduction check and a mechanism for creating verifiable receipts that can be used to verify the execution results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SiliconState/change-capsule/compare/v0.3.0...v0.3.1">https://github.com/SiliconState/change-capsule/compare/v0.3.0...v0.3.1</a></p>
]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/smyklot/</link><pubDate>Sun, 09 Aug 2026 05:45:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.15.1.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges based on the repository’s CODEOWNERS file. It simplifies PR management by providing commands to approve, merge, or cleanup comments. The app ensures only authorized users can approve changes and supports multiple command formats for ease of use.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.15.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges based on the repository&rsquo;s CODEOWNERS file. It simplifies PR management by providing commands to approve, merge, or cleanup comments. The app ensures only authorized users can approve changes and supports multiple command formats for ease of use.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1151-2026-08-09"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.15.0...v1.15.1">1.15.1</a> (2026-08-09)</h2>
<h2 id="smyklot-v1151">Smyklot v1.15.1</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.15.1</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>8dfb4510ca0764ec5519644f8c90b49323ae6979 chore(release): bump version to 1.15.1</li>
<li>7334eb982655e15733bb7fb7cbb3313c13d3d5ec fix(panel): keep empty command lists as arrays (#162)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/update-a-config-file-with-values-from-environment/</link><pubDate>Sun, 09 Aug 2026 05:44:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces placeholders in a configuration file with values from environment variables. It automates the process of dynamically configuring application settings based on environment-specific configurations without hardcoding sensitive information directly into the codebase.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces placeholders in a configuration file with values from environment variables. It automates the process of dynamically configuring application settings based on environment-specific configurations without hardcoding sensitive information directly into the codebase.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sun, 09 Aug 2026 05:44:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by executing npm ci and npm run bundle to build the project before committing the built files, ensuring that the latest version of the application is deployed in the swarm environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by executing <code>npm ci</code> and <code>npm run bundle</code> to build the project before committing the built files, ensuring that the latest version of the application is deployed in the swarm environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/classroom-to-sheets-integration/</link><pubDate>Sun, 09 Aug 2026 05:44:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates Google Sheets as an alternative submission method for assignments in GitHub Classroom. It automates the process of updating a specified Google sheet with students’ task results from GitHub Actions workflows. The action requires setting up Google Cloud credentials and sharing the sheet with a service account, then configuring secrets in your repository to integrate seamlessly into your workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates Google Sheets as an alternative submission method for assignments in GitHub Classroom. It automates the process of updating a specified Google sheet with students&rsquo; task results from GitHub Actions workflows. The action requires setting up Google Cloud credentials and sharing the sheet with a service account, then configuring secrets in your repository to integrate seamlessly into your workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>Sentinel Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sentinel-review/</link><pubDate>Sun, 09 Aug 2026 05:44:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/sentinel-review/</guid><description>Version updated for https://github.com/Stackgirl01/sentinel-review to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sentinel Review is an AI-powered security review GitHub Action that reads pull request diffs, reasons about them using Claude, and posts findings as inline comments. It helps catch reasoning-based issues like hardcoded secrets, SQL injection, auth bypasses, and missing input validation on untrusted data. The action is a complementary layer to static analysis tools like CodeQL and Snyk, catching logic-level issues that pattern matchers might miss.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Stackgirl01/sentinel-review">https://github.com/Stackgirl01/sentinel-review</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sentinel-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sentinel Review is an AI-powered security review GitHub Action that reads pull request diffs, reasons about them using Claude, and posts findings as inline comments. It helps catch reasoning-based issues like hardcoded secrets, SQL injection, auth bypasses, and missing input validation on untrusted data. The action is a complementary layer to static analysis tools like CodeQL and Snyk, catching logic-level issues that pattern matchers might miss.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Initial commit: Sentinel Review GitHub Action (5817ba7)</li>
</ul>
]]></content:encoded></item><item><title>Get PR Submit token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/get-pr-submit-token/</link><pubDate>Sun, 09 Aug 2026 05:43:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/get-pr-submit-token/</guid><description>Version updated for https://github.com/tiangolo/pr-submit to version 0.0.1.
This action is used across all versions by 34 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PR Submit GitHub App automates the process of issuing short-lived, repository-scoped tokens for workflows that create branches and pull requests. It helps manage access permissions and ensures secure token issuance, focusing on security through OAuth 2.0 with OIDC in specific contexts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tiangolo/pr-submit">https://github.com/tiangolo/pr-submit</a></strong> to version <strong>0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>34</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/get-pr-submit-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The PR Submit GitHub App automates the process of issuing short-lived, repository-scoped tokens for workflows that create branches and pull requests. It helps manage access permissions and ensures secure token issuance, focusing on security through OAuth 2.0 with OIDC in specific contexts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="features">Features</h3>
<ul>
<li>✨ Add PR Submit.</li>
</ul>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/compose-lint/</link><pubDate>Sun, 09 Aug 2026 05:42:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.15.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The compose-lint GitHub Action is a security-focused linter for Docker Compose files. It checks for dangerous misconfigurations such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, and hard-coded credentials before they reach production. The action auto-fixes the unambiguous issues and provides a dry-run option to identify potential vulnerabilities in your Docker Compose configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.15.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>compose-lint</code> GitHub Action is a security-focused linter for Docker Compose files. It checks for dangerous misconfigurations such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, and hard-coded credentials before they reach production. The action auto-fixes the unambiguous issues and provides a dry-run option to identify potential vulnerabilities in your Docker Compose configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Rule-doc headings are now phrased for the queries users actually search
(issue #471): every <code>docs/rules/</code> H1 leads with the rule id then names the
directive and the symptom it produces (e.g. &ldquo;CL-0007: read_only — fixing
&lsquo;Read-only file system&rsquo; errors&rdquo;), and the docs-site nav labels — which set
each page&rsquo;s <code>&lt;title&gt;</code> — are synced to match. Affects the site, the GitHub
view, and <code>--explain</code> output; rule ids and content are unchanged.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>CL-0003&rsquo;s compatibility guidance claimed root-dropping entrypoints
(<code>gosu</code>/<code>su-exec</code>: postgres, redis, mysql, …) crash-loop under
<code>no-new-privileges</code> — <strong>live-verified false</strong>: nnp blocks privilege <em>gain</em>
at <code>execve</code> (sudo, setuid bits, file capabilities), not a root process&rsquo;s
downward <code>setuid()</code>, and a su-exec image (valkey) runs healthy under the
flag. The doc and fix text are rewritten around the verified semantics,
and a CI premise check now pins the drop-unaffected fact so the wrong
claim cannot silently return.</li>
<li>Fixed file matching in <code>.pre-commit-hooks.yaml</code> that was incorrectly including
<code>.compose-lint.yml</code> if present in the commits. This generated errors
meaning pre-commit will always fail (issue #465). The hook now matches only
names beginning <code>compose</code> or <code>docker-compose</code>, and an <code>exclude</code> pattern skips
compose-lint&rsquo;s own config in either spelling — <code>.compose-lint.yml</code> and the
dotless <code>compose-lint.yml</code> that <code>init -o</code> can write — with either extension.
<strong>Note</strong> environment specific files, e.g. <code>compose-dev.yml</code>, still match, but
files with prefixes, e.g. <code>dev-compose.yml</code>, no longer do.</li>
</ul>
<h3 id="changed-1">Changed</h3>
<ul>
<li>CL-0003 gains the &ldquo;Reading the failure&rdquo; treatment (the last rule from the
symptom-table survey): sudo&rsquo;s explicit nnp message (captured live), the
silent case — a setuid <code>execve</code> under nnp <em>succeeds</em> with privileges
unchanged (CI-proven: exit 0, euid intact), so failures surface later as
ordinary permission errors — the <code>NoNewPrivs</code> <code>/proc</code> confirmation step,
and an explicit warning not to confuse the crash-looping <code>cap_drop</code>
symptom (CL-0006&rsquo;s <code>SETUID</code> row) with this setting.</li>
</ul>
<h3 id="changed-2">Changed</h3>
<ul>
<li>CL-0012, CL-0018, and CL-0022 get the symptom → remedy treatment
(issue #479, same pattern as CL-0006/CL-0007): each rule doc gains a
&ldquo;Reading the failure&rdquo; table quoting verbatim, live-captured error messages.
CL-0012 maps the fork-failure wordings (chronically misattributed to
<code>ulimit -u</code>) to the pids cgroup with a <code>pids.max</code>/<code>pids.current</code>
confirmation step; CL-0018 maps non-root <code>Permission denied</code> writes by
mount type, backed by two CI-proven facts — a tmpfs over an existing image
directory inherits its root ownership (use <code>uid=</code>/<code>gid=</code>), and named-volume
initial ownership follows Docker&rsquo;s copy-up rules; CL-0022 frames the
<code>noexec</code> exec failure as relocate-first, <code>:exec</code>-with-documented-reason
last, since the naive fix is the finding. Six new CI premise checks prove
the busybox rows live. CL-0002&rsquo;s fix text now points at CL-0006&rsquo;s
capability-determination guide instead of stopping at <code>&lt;SPECIFIC_CAP&gt;</code>.</li>
</ul>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/cowork-harness/</link><pubDate>Sun, 09 Aug 2026 05:41:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.21.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a tool designed to automate and test Claude Cowork skills without using the actual Desktop application. It mimics the runtime environment closely, allowing developers to run tests across various scenarios in a headless manner, including CI pipelines. The action supports both protocol-only and live test tiers, requiring different setups for token-based or desktop-based testing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.21.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a tool designed to automate and test Claude Cowork skills without using the actual Desktop application. It mimics the runtime environment closely, allowing developers to run tests across various scenarios in a headless manner, including CI pipelines. The action supports both protocol-only and live test tiers, requiring different setups for token-based or desktop-based testing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>The agent-image pin silently skipped the full-parity variant.</strong> <code>doctor</code> picked the local registry
digest by matching only the ghcr-qualified repository (<code>ghcr.io/owner/name@sha256:…</code>). Docker records a
RepoDigest per repository the image is known by, and that set is not predictable: <code>cowork-agent-full:2</code>
carries only the bare <code>cowork-agent-full@sha256:…</code>. The ghcr-only filter missed it, the image was
reported as a local build, and the pin check quietly did nothing for every full-parity user — a skipped
check reads exactly like a passing one. Both forms are now matched, with the ghcr-qualified digest
preferred when they disagree.</li>
<li><strong>A <code>main</code> CI run could be cancelled, making a good commit unpublishable.</strong> <code>ci.yml</code> cancelled
in-progress runs for any ref; <code>require-ci-success</code> requires <code>conclusion == success</code> for the SHA it
checks, and <code>cancelled</code> is not it. Merging two PRs minutes apart left the earlier merge commit
unpublishable. Cancellation now applies to pull-request refs only.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>The freshness check&rsquo;s &ldquo;works offline&rdquo; property is now a guard, not a claim.</strong> It was argued from the
absence of a registry call, and an absence cannot fail when someone reintroduces one. A test now asserts
the path contains exactly one spawn — the local <code>image inspect</code> — and no registry command. Comments are
stripped before the check, so the guard cannot be satisfied by deleting its own rationale.</li>
<li><strong><code>publish-image.yml</code> gains a <code>dry_run</code> input</strong> (maintainer-facing): it runs the CI gate and the
immutable-tag collision guard, then stops before building or pushing. The guard&rsquo;s <em>refusal</em> path was
otherwise untestable without risking a repointed <code>:2-r&lt;N&gt;</code>, which is the one thing a digest pin cannot
survive.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 1.21.1 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/112">https://github.com/yaniv-golan/cowork-harness/pull/112</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.21.1">https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.21.1</a></p>
]]></content:encoded></item><item><title>Zuke Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/zuke-build/</link><pubDate>Sun, 09 Aug 2026 05:40:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/09/zuke-build/</guid><description>Version updated for https://github.com/zuke-build/zuke to version ai-v1.8.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Zuke is a code-based build automation system for Deno and TypeScript that allows developers to define builds as TypeScript classes. Each target is represented by a class field with a fluent API, enabling easy dependency management and topological sorting of targets before execution. Zuke runs these targets in a controlled environment, handling errors gracefully and capturing output for logging purposes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zuke-build/zuke">https://github.com/zuke-build/zuke</a></strong> to version <strong>ai-v1.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zuke-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Zuke is a code-based build automation system for Deno and TypeScript that allows developers to define builds as TypeScript classes. Each target is represented by a class field with a fluent API, enabling easy dependency management and topological sorting of targets before execution. Zuke runs these targets in a controlled environment, handling errors gracefully and capturing output for logging purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="181-2026-08-08"><a href="https://github.com/zuke-build/zuke/compare/ai-v1.8.0...ai-v1.8.1">1.8.1</a> (2026-08-08)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>release v1.0.2, and repair what cutting it exposed (<a href="https://github.com/zuke-build/zuke/issues/308">#308</a>) (<a href="https://github.com/zuke-build/zuke/commit/87ce09ddae03558efb01fab657e316b362df89f7">87ce09d</a>)</li>
</ul>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/odin-scan-smart-contract-security/</link><pubDate>Sat, 08 Aug 2026 22:13:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security analysis of smart contracts using Odin Scan, supporting CosmWasm, Solana, and EVM platforms. It integrates seamlessly with GitHub workflows to catch vulnerabilities early in development cycles, providing detailed reports and inline annotations. Users can trigger scans by commenting on pull requests or programmatically via API keys.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the security analysis of smart contracts using Odin Scan, supporting CosmWasm, Solana, and EVM platforms. It integrates seamlessly with GitHub workflows to catch vulnerabilities early in development cycles, providing detailed reports and inline annotations. Users can trigger scans by commenting on pull requests or programmatically via API keys.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add comment-triggered PR scans (ac72e5f)</li>
<li>docs: expand findings-visibility section with threat model and annotation rationale (0404708)</li>
<li>feat: add findings-visibility input for graduated public disclosure control (f18df59)</li>
<li>fix: show findings detail in PR comment with fallback to medium (c2e43c8)</li>
<li>fix: new comment per run, show only critical/high findings, rebuild dist (e237b62)</li>
<li>feat: use GitHub App installation token for branded PR comments (3abce4e)</li>
<li>feat: enrich PR comment with emojis, descriptions, and fix report URL (27cc2f2)</li>
<li>fix: gzip SARIF before base64 encoding for Code Scanning upload (d9eed9f)</li>
<li>fix: include sourcemap-register.js in dist (bd265af)</li>
<li>docs: add privacy policy (b78db44)</li>
</ul>
]]></content:encoded></item><item><title>svelte-vitals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/svelte-vitals/</link><pubDate>Sat, 08 Aug 2026 22:12:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/svelte-vitals/</guid><description>Version updated for https://github.com/oekazuma/svelte-vitals-action to version v0.8.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary svelte-vitals-action is a GitHub Action that automates SvelteKit code-health checks using svelte-vitals, providing inline annotations on pull requests, a job summary, and a sticky PR comment. It solves problems by automatically running static SEO, Performance, Correctness, Security, and Architecture checks and reporting findings in real-time via GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oekazuma/svelte-vitals-action">https://github.com/oekazuma/svelte-vitals-action</a></strong> to version <strong>v0.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/svelte-vitals">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>svelte-vitals-action</code> is a GitHub Action that automates SvelteKit code-health checks using <code>svelte-vitals</code>, providing inline annotations on pull requests, a job summary, and a sticky PR comment. It solves problems by automatically running static SEO, Performance, Correctness, Security, and Architecture checks and reporting findings in real-time via GitHub Actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="minor-changes">Minor Changes</h3>
<ul>
<li>
<p>376842d: Update the bundled analyzer to <code>svelte-vitals</code> 0.44.0 / <code>@svelte-vitals/core</code> 0.38.0. The action&rsquo;s inputs and outputs are unchanged, and the step still fails on <code>failOn</code> severity rather than on any score. What changes is the numbers the report prints and what the scan finds:</p>
<ul>
<li><strong>Category scores rise wherever a category checks few things.</strong> Within one <code>(category, scope)</code> pair a <code>warning</code> now costs five times an <code>info</code> and a <code>critical</code> fifteen times, so a more severe finding always costs more there. Across pairs it does not: a key is never scored against less than 25 points of checks, so in a one-rule pair the three severities give 96, 80 and 40, where a lone <code>warning</code> used to score 0. Anything reading the Health number out of the job summary should be recalibrated — this moves in the opposite direction from the previous release.</li>
<li><strong>New findings in TypeScript-heavy projects.</strong> Rune declarations behind a TS cast (<code>let count = $state(0) as number</code>) now feed the same facts as the uncast form, and imports inside <code>.svelte.ts</code> / <code>.svelte.js</code> runes modules are now collected — so <code>performance/heavy-import</code>, <code>performance/namespace-import</code>, <code>architecture/private-scope-import</code> and <code>architecture/route-component-import</code> see code they used to skip. These were silent false negatives, not new checks.</li>
<li><strong>The <code>diff</code> input no longer drops findings in non-ASCII paths.</strong> Git octal-escapes such paths under its default <code>core.quotePath</code>, which never matched the raw UTF-8 location, so findings under e.g. a Japanese route directory vanished from a diff-scoped run. Changed-file detection now reads NUL-separated output.</li>
<li>New opt-in rule <code>architecture/reserved-name-placement</code> says which positions a reserved directory name may appear in, the inverse of <code>architecture/reserved-directory-names</code>. Off until its placement maps are configured, so it adds nothing to a scan until then.</li>
</ul>
</li>
<li>
<p>613dbf8: Update the bundled analyzer to <code>svelte-vitals</code> 0.44.1 / <code>@svelte-vitals/core</code> 0.39.0. The action&rsquo;s inputs and outputs are unchanged, and the step still fails on <code>failOn</code> severity rather than on any score. What changes is what a scoped run reports and the scores beside it:</p>
<ul>
<li><strong>A <code>diff</code>-scoped run&rsquo;s Health drops, and the old number was wrong.</strong> Every rule&rsquo;s passing results now carry the same <code>location</code> a penalized result would, so changed-file filtering had to stop keeping a result merely because its <code>location</code> was in the changed set. Before this, a single incidental passing SEO check on a changed file could promote its whole category from absent to a fabricated 100 and pull Health upward. On the reference shape — one critical <code>correctness</code> finding plus one such SEO pass, both on changed files — Health moves from 89 to 79, and 79 is the correct number. If you read the Health value out of the job summary on <code>diff</code>-scoped runs, expect it lower and recalibrate against it. One pass of the same shape is deliberately kept: <code>architecture/unit-entry-file</code>&rsquo;s route-less seed still survives <code>diff</code> scoping, so <code>architecture</code> keeps its own upward pull — that tradeoff predates this release and is unchanged by it.</li>
<li><strong>The <code>baseline</code> input no longer masks a genuine regression.</strong> For <code>seo/title-presence</code> and the ten <code>headTagRule</code>-backed ids (<code>canonical-url</code>, <code>og-title</code>, <code>og-image</code>, <code>charset</code>, <code>viewport</code>, <code>twitter-card</code>, <code>description-presence</code>, <code>og-description</code>, <code>json-ld</code>, <code>og-url</code>), a route that passed at the baseline ref and then regressed — a deleted <code>&lt;title&gt;</code>, say — produced identical comparison keys on both sides and was dropped as &ldquo;not new&rdquo;. Comparison is now penalized-findings-only, so those regressions are reported. Passing results no longer appear in baseline-scoped output at all.</li>
<li><strong>A <code>files:</code>-scoped <code>severity: 'off'</code> override now removes a rule&rsquo;s passing seed</strong>, not just its penalized findings, which it always claimed to do. Scores move where such an override is configured — the upstream reproduction goes 98 → 96 once the stale seed is gone.</li>
<li><strong>A scoped run no longer warns that suppressions are stale just because the scope hid their findings.</strong> With <code>svelte-vitals-suppressions.json</code> present, using the <code>diff</code> and <code>baseline</code> inputs together printed a misleading &ldquo;N stale entries — re-run <code>--update-suppressions</code> to prune&rdquo; annotation on every run. Staleness is now judged against the project-wide result set, so that annotation stops.</li>
<li><code>architecture/prop-count</code>, on by default, now counts named props destructured alongside a rest element (<code>let { a, b, ...rest } = $props()</code>) instead of staying silent on the whole destructure. It can only surface findings on components that were previously invisible to it; the <code>max</code> default stays 6.</li>
<li><code>architecture/reserved-directory-names</code> gains <code>anyCaseUnitScopes</code>, governing units whose name does not begin A–Z — the lowercase and <code>.ts</code>-entry units <code>unitScopes</code> could never reach. Defaults to <code>{}</code>, so a project that does not declare it sees no new findings.</li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>Open Delivery Spec</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/open-delivery-spec/</link><pubDate>Sat, 08 Aug 2026 22:11:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/open-delivery-spec/</guid><description>Version updated for https://github.com/open-delivery-spec/validate-action to version v0.2.8.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The ODS Validate Action automates the governance and visibility process for AI-assisted code, ensuring that low-quality AI-generated code does not reach production. It automatically attributes AI-generated code, analyzes its quality using built-in rules and external analyzers via SARIF, scores technical debt impact, and enforces policies using OPA Rego. The action is designed to run on every pull request and is easy to use with a YAML configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/open-delivery-spec/validate-action">https://github.com/open-delivery-spec/validate-action</a></strong> to version <strong>v0.2.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/open-delivery-spec">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The ODS Validate Action automates the governance and visibility process for AI-assisted code, ensuring that low-quality AI-generated code does not reach production. It automatically attributes AI-generated code, analyzes its quality using built-in rules and external analyzers via SARIF, scores technical debt impact, and enforces policies using OPA Rego. The action is designed to run on every pull request and is easy to use with a YAML configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h2 id="-features">🚀 Features</h2>
<ul>
<li>feat: emit the AI-code evidence document with the report artifact by @shenxianpeng in #81</li>
<li>feat: detect shallow checkouts and explain the degradation + fix by @shenxianpeng in #80</li>
</ul>
<h2 id="-maintenance">👻 Maintenance</h2>
<ul>
<li>chore: bump default cli-ref to v0.7.6 by @shenxianpeng in #84</li>
<li>chore: same-day upstream updates (dependabot + cli-ref bot daily) by @shenxianpeng in #83</li>
<li>chore: dogfood the current action release (v0.2.5 → v0.2.7) by @shenxianpeng in #82</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/open-delivery-spec/validate-action/compare/v0.2.7...v0.2.8">https://github.com/open-delivery-spec/validate-action/compare/v0.2.7...v0.2.8</a></p>
]]></content:encoded></item><item><title>Critical URL SEO Release Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/critical-url-seo-release-guard/</link><pubDate>Sat, 08 Aug 2026 22:09:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/critical-url-seo-release-guard/</guid><description>Version updated for https://github.com/plainproof-labs/release-regression-guard to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Release Regression Guard is a GitHub Action that automates SEO checks on deployed pages. It compares repository-declared critical URLs with an expectation manifest, ensuring the site’s content meets SEO requirements after deployment. The action reports each check as pass, fail, unknown, or a documented temporary exception. Key capabilities include verifying final HTTP status and redirects, checking noindex settings, canonical links, metadata presence, sitemap membership, and internal links.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plainproof-labs/release-regression-guard">https://github.com/plainproof-labs/release-regression-guard</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/critical-url-seo-release-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Release Regression Guard is a GitHub Action that automates SEO checks on deployed pages. It compares repository-declared critical URLs with an expectation manifest, ensuring the site&rsquo;s content meets SEO requirements after deployment. The action reports each check as <code>pass</code>, <code>fail</code>, <code>unknown</code>, or a documented temporary <code>exception</code>. Key capabilities include verifying final HTTP status and redirects, checking noindex settings, canonical links, metadata presence, sitemap membership, and internal links.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="release-regression-guard-v101">Release Regression Guard v1.0.1</h1>
<p>This compatibility patch declares the Node.js 24 Action runtime used by current GitHub-hosted runners.</p>
<p>Inputs, outputs, manifest checks, report formats, privacy boundaries, and network behavior are unchanged. The public package passed 15/15 tests and the Action entrypoint completed 19/19 deterministic checks.</p>
<p>The compatible <code>v1</code> tag now points to this release. The immutable <code>v1.0.0</code> tag remains available for reproducibility.</p>
]]></content:encoded></item><item><title>Configure Node.js</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/configure-node.js/</link><pubDate>Sat, 08 Aug 2026 22:08:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/configure-node.js/</guid><description>Version updated for https://github.com/pwrdrvr/configure-nodejs to version v1.2.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action pwrdrvr/configure-nodejs automates the process of installing Node.js, detecting and enabling the appropriate package manager (npm, pnpm, or Yarn), restoring caches for different package managers, and installing dependencies only when necessary. It solves the problem of cold cache misses by using Corepack to handle pinned versions and ensures that all jobs in a workflow can benefit from shared cache states. The action supports native execution on Linux, macOS, and Windows platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pwrdrvr/configure-nodejs">https://github.com/pwrdrvr/configure-nodejs</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/configure-node-js">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>pwrdrvr/configure-nodejs</code> automates the process of installing Node.js, detecting and enabling the appropriate package manager (npm, pnpm, or Yarn), restoring caches for different package managers, and installing dependencies only when necessary. It solves the problem of cold cache misses by using Corepack to handle pinned versions and ensures that all jobs in a workflow can benefit from shared cache states. The action supports native execution on Linux, macOS, and Windows platforms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Added first-class Windows support while preserving the existing Linux and macOS action contract.</li>
<li>Added native execution for pinned Corepack package-manager activation, pnpm store discovery, cache restore/save, and frozen dependency installation.</li>
<li>Added phase timing outputs for cache, Node setup, package-manager activation, store discovery, installation, and total action duration.</li>
</ul>
<h2 id="validation">Validation</h2>
<ul>
<li>Added unit coverage on Linux, macOS, and Windows.</li>
<li>Added npm, pnpm, and Yarn cache-prime/restore fixtures across all three operating systems.</li>
</ul>
<p>Existing inputs, outputs, lookup-only behavior, cache identity, and frozen/immutable install semantics remain compatible with <code>v1</code> consumers.</p>
<p>Thanks to @huntharo for the contribution.</p>
]]></content:encoded></item><item><title>QWED Protocol Verification</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/qwed-protocol-verification/</link><pubDate>Sat, 08 Aug 2026 22:07:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/qwed-protocol-verification/</guid><description>Version updated for https://github.com/QWED-AI/qwed-verification to version v7.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose and Functionality: QWED is a production-grade AI verification engine that provides deterministic trust boundaries for any LLM. It automates the detection and prevention of AI hallucinations, ensuring the integrity and reliability of AI outputs and processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/QWED-AI/qwed-verification">https://github.com/QWED-AI/qwed-verification</a></strong> to version <strong>v7.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qwed-protocol-verification">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Purpose and Functionality</strong>: QWED is a production-grade AI verification engine that provides deterministic trust boundaries for any LLM. It automates the detection and prevention of AI hallucinations, ensuring the integrity and reliability of AI outputs and processes.</p>
<p><strong>Problem it Solves</strong>: The main issue addressed by QWED is the inherent uncertainty and potential biases in AI systems due to their complex and dynamic nature. By using multiple verification engines and agent security guards, QWED ensures that AI outputs are not only accurate but also transparent and verifiable, reducing the risk of AI-generated misinformation or harmful actions.</p>
<p><strong>Key Capabilities</strong>: QWED offers various features including model-agnostic support for a wide range of LLMs, budget-friendly pricing options, and integration with Docker containers. It provides detailed reports on verification outcomes, allowing developers to understand how their AI systems perform in terms of accuracy and trustworthiness.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="qwed-v700">QWED v7.0.0</h1>
<p>v7.0.0 completes META #216: every one of QWED&rsquo;s 13 verification engines now speaks the same contract — the unified 3-layer DiagnosticResult (status / agent_message / developer_fields / proof_ref). This is the release where QWED&rsquo;s definition of verification stops being a promise kept by discipline and becomes a guarantee enforced by construction, in every engine.</p>
<hr>
<h2 id="from-fixing-verification-to-defining-it">From fixing verification to defining it</h2>
<p>Earlier releases asked: <em>&ldquo;Where is verification wrong?&rdquo;</em> — hunting fail-open bugs where an engine could say VERIFIED without a proof. That was necessary, but it treated verification as something to patch.</p>
<p>The architecture has since matured, and the question changed. It is no longer <em>&ldquo;how do we fix verification?&rdquo;</em> but <em>&ldquo;what IS verification, and how must it be done?&rdquo;</em> v7.0.0 is the answer, applied universally:</p>
<p><strong>Verification is a deterministic proof, bound to evidence — or it is nothing.</strong></p>
<p>With all 13 engines on one contract, that definition is no longer enforced engine-by-engine. It is structural. You cannot construct a VERIFIED result without a proof_ref, in any engine, by construction.</p>
<h2 id="what-verification-means-to-us-and-now-in-code">What verification means to us (and now, in code)</h2>
<p>v7.0.0 codifies what does — and does not — count as verification:</p>
<ul>
<li><strong>Execution is not verification.</strong> Code that runs cleanly and returns a number proves only that it ran. Stats execution success is <code>UNVERIFIABLE</code>, never <code>VERIFIED</code>.</li>
<li><strong>Agreement is not verification.</strong> Consensus and cross-engine votes are advisory; they never produce <code>VERIFIED</code>.</li>
<li><strong>Confidence is not verification.</strong> A high heuristic/LLM/VLM score is carried as <code>advisory_checks</code>, never promoted to a status.</li>
<li><strong>A proof is verification.</strong> <code>VERIFIED</code> requires a non-empty <code>proof_ref</code> — a deterministic hash binding the verdict to the exact evidence that justified it.</li>
<li><strong>UNVERIFIABLE is an honest answer.</strong> &ldquo;We could not prove this&rdquo; is a first-class, fail-closed result — not a failure state.</li>
</ul>
<blockquote>
<p>If it can&rsquo;t be proven, it doesn&rsquo;t ship. That invariant is now enforced in all 13 engines, not just asserted.</p>
</blockquote>
<hr>
<h2 id="whats-new">What&rsquo;s new</h2>
<h3 id="all-13-engines-conform-to-diagnosticresult">All 13 engines conform to DiagnosticResult</h3>
<p>Schema, SQL, Code, SecureCodeExecutor, and Stats join the previously-migrated Math, Logic, Symbolic, Fact, Image, Graph, Reasoning, and Consensus engines on the 3-layer contract. No engine returns an ad-hoc dict anymore.</p>
<h3 id="truth-is-separated-from-admission">Truth is separated from admission</h3>
<p><code>POST /verify/code</code> reports proven-unsafe code as <strong>VERIFIED-as-unsafe</strong> (<code>is_valid = false</code>, bound <code>proof_ref</code>) — a <em>truth</em> guarantee (&ldquo;we checked it and it&rsquo;s unsafe&rdquo;) — while a separate <code>admission = BLOCKED</code> decision gates execution. Authority-only consumers can no longer admit unsafe code by reading <code>status == &quot;VERIFIED&quot;</code>.</p>
<h3 id="fail-closed-batch-verification">Fail-closed batch verification</h3>
<p>Fact / image / SQL / code batches are authoritative only when <strong>every</strong> item is proven. Any refuted or blocked item fails the whole batch closed; batch <code>proof_ref</code> binds full claim digests plus the shared input (image/context).</p>
<h3 id="evidence-is-preserved-never-fabricated">Evidence is preserved, never fabricated</h3>
<p>Stats retain the observed result, generated code, columns, and a deterministic dataset fingerprint on UNVERIFIABLE. Deferred capabilities (deterministic claim evaluation, schema validation) are tracked as #298 / #299 — filed, not faked.</p>
<hr>
<h2 id="-breaking-changes">⚠️ Breaking changes</h2>
<ul>
<li><strong><code>POST /verify/code</code></strong> now returns HTTP 200 with <code>status = &quot;VERIFIED&quot;</code> for proven-unsafe code (previously <code>status = &quot;BLOCKED&quot;</code>). Admission is driven by the new <code>admission</code> field and <code>developer_fields.is_valid</code>. Consumers branching on <code>status</code> for safety gating <strong>must</strong> switch to <code>admission</code> / <code>is_valid</code>.</li>
<li><strong><code>POST /verify/stats</code></strong> reports execution success as <code>status = &quot;UNVERIFIABLE&quot;</code> (previously <code>VERIFIED</code>), with the observed value at <code>developer_fields.observed_result</code>. Execution success alone is never presented as a proven claim.</li>
</ul>
<hr>
<h2 id="version-propagation-600--700">Version propagation (6.0.0 → 7.0.0)</h2>
<ul>
<li><code>qwed</code> (PyPI) · <code>qwed_sdk</code> (Python) · <code>@qwed-ai/sdk</code> (npm) · <code>qwed</code> (crates.io)</li>
<li>API version marker</li>
<li>Kubernetes deployment image: pinned to the published <code>6.0.0</code> until the release publishes the <code>7.0.0</code> image, then bumped (avoids ImagePullBackOff)</li>
</ul>
<h2 id="included-prs-merged-after-v600">Included PRs (merged after v6.0.0)</h2>
<ul>
<li>#294 SchemaVerifier → DiagnosticResult (#255)</li>
<li>#295 SQLVerifier → DiagnosticResult (#253)</li>
<li>#296 CodeVerifier + SecureCodeExecutor → DiagnosticResult (#254)</li>
<li>#297 StatsVerifier → DiagnosticResult (#256) + fact/image batch</li>
</ul>
<h2 id="github-action">GitHub Action</h2>
<p>The QWED Verification GitHub Action lives in [<a href="https://github.com/QWED-AI/qwed-verification-action">QWED-AI/qwed-verification-action</a>](<a href="https://github.com/QWED-AI/qwed-verification-action)">https://github.com/QWED-AI/qwed-verification-action)</a>. It wraps the <code>qwedai/qwed-verification</code> Docker image, is versioned independently, and is not published from this repository — no action release is part of v7.0.0.</p>
<hr>
<p><em>The QWED Protocol: if it can&rsquo;t be verified, it doesn&rsquo;t ship.</em></p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/kaniko-build-action/</link><pubDate>Sat, 08 Aug 2026 22:05:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or “Hello” followed by a specified name to the log. It solves the problem of automating simple greetings in a Docker environment, providing flexibility through the who-to-greet input parameter. The action also includes an output that displays the current time at greeting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or &ldquo;Hello&rdquo; followed by a specified name to the log. It solves the problem of automating simple greetings in a Docker environment, providing flexibility through the <code>who-to-greet</code> input parameter. The action also includes an output that displays the current time at greeting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>Supabase Storage Upload Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/supabase-storage-upload-action/</link><pubDate>Sat, 08 Aug 2026 22:05:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/supabase-storage-upload-action/</guid><description>Version updated for https://github.com/runrly/supabase-storage-upload-action to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading files from a GitHub Actions workspace to Supabase Storage. It supports both dry runs and actual uploads, allowing you to validate and plan file transfers before execution. The action can upload multiple files with customizable configurations such as bucket names, caching, and content types.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/runrly/supabase-storage-upload-action">https://github.com/runrly/supabase-storage-upload-action</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supabase-storage-upload-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading files from a GitHub Actions workspace to Supabase Storage. It supports both dry runs and actual uploads, allowing you to validate and plan file transfers before execution. The action can upload multiple files with customizable configurations such as bucket names, caching, and content types.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>c9cf928: Refresh bundled dependencies and regenerate the Action distribution.</li>
<li>8400c60: Patch vulnerable transitive dependencies in the bundled Action.</li>
<li>ee4aad0: Simplify upload guard clauses while preserving validation diagnostics.</li>
</ul>
]]></content:encoded></item><item><title>Podcast xml(rss) generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/podcast-xmlrss-generator/</link><pubDate>Sat, 08 Aug 2026 22:04:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/podcast-xmlrss-generator/</guid><description>Version updated for https://github.com/salmankalam/podcast-xml-rss--generator to version v2.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating a podcast RSS feed from an XML file. It uses Docker to set up a machine, copies necessary files, and then calls a script that parses the XML, generates the RSS feed, and uploads it back to the repository where the original XML file is stored. This helps maintain consistency in podcast metadata across different platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/salmankalam/podcast-xml-rss--generator">https://github.com/salmankalam/podcast-xml-rss--generator</a></strong> to version <strong>v2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/podcast-xml-rss-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating a podcast RSS feed from an XML file. It uses Docker to set up a machine, copies necessary files, and then calls a script that parses the XML, generates the RSS feed, and uploads it back to the repository where the original XML file is stored. This helps maintain consistency in podcast metadata across different platforms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/salmankalam/podcast-xml-rss--generator/compare/v1.0...v2.0">https://github.com/salmankalam/podcast-xml-rss--generator/compare/v1.0...v2.0</a></p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/agentauditkit-mcp-security-scan/</link><pubDate>Sat, 08 Aug 2026 22:04:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.70.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner designed to audit AI agent pipelines and identify misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. It runs fully offline and deterministically, producing auditor-ready compliance-evidence packs that include SARIF for GitHub Security tab and PDF evidence reports mapped to 12 security frameworks. The action supports 85 scanner modules including AST-based Python taint analysis and regex pattern scanners for TypeScript/JavaScript and Rust.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.70</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit is a security scanner designed to audit AI agent pipelines and identify misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. It runs fully offline and deterministically, producing auditor-ready compliance-evidence packs that include SARIF for GitHub Security tab and PDF evidence reports mapped to 12 security frameworks. The action supports 85 scanner modules including AST-based Python taint analysis and regex pattern scanners for TypeScript/JavaScript and Rust.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.70
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.70
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.70</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: fail the release on a stale description, one docs URL, derivable scanner count by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/555">https://github.com/sattyamjjain/agent-audit-kit/pull/555</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.69...v0.3.70">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.69...v0.3.70</a></p>
]]></content:encoded></item><item><title>SentinelDen Studio Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/sentinelden-studio-audit/</link><pubDate>Sat, 08 Aug 2026 22:02:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/sentinelden-studio-audit/</guid><description>Version updated for https://github.com/sentinelden/sentinelctl-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates SentinelDen Studio’s security audit tools into your iOS or Android build pipeline to detect and report vulnerabilities. It automates the process of running audits on pull requests, providing detailed findings in GitHub’s Security tab. The action supports both Mach-O and APK/DEX parsing, as well as secret and crypto-misuse detection, with configurable severity thresholds and a license key for premium features.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sentinelden/sentinelctl-action">https://github.com/sentinelden/sentinelctl-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sentinelden-studio-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates SentinelDen Studio&rsquo;s security audit tools into your iOS or Android build pipeline to detect and report vulnerabilities. It automates the process of running audits on pull requests, providing detailed findings in GitHub&rsquo;s Security tab. The action supports both Mach-O and APK/DEX parsing, as well as secret and crypto-misuse detection, with configurable severity thresholds and a license key for premium features.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Audits your iOS or Android build in CI and surfaces findings in GitHub code scanning via SARIF.</p>
<p>Runs the same static engine as the SentinelDen Studio desktop app: Mach-O and
APK/DEX parsing, OWASP MASVS control coverage, CycloneDX SBOM, secret and
crypto-misuse detection, and a policy gate that can fail the build.</p>
<p>No account, no key, no charge. The audit runs entirely on your runner; your
binary is never uploaded anywhere.</p>
<p>Not included: PDF reports, dynamic analysis, arm64 runners.</p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/custom-amazon-bedrock-agent-action/</link><pubDate>Sat, 08 Aug 2026 22:02:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the analysis of files in a pull request using Amazon Bedrock Agent. It provides customizable prompt generation and can integrate with Amazon Bedrock Knowledge Bases to enhance insights. Key features include tailored analysis, context-awareness, flexibility, file filtering, AI-powered insights, language agnosticism, and seamless integration into GitHub workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the analysis of files in a pull request using Amazon Bedrock Agent. It provides customizable prompt generation and can integrate with Amazon Bedrock Knowledge Bases to enhance insights. Key features include tailored analysis, context-awareness, flexibility, file filtering, AI-powered insights, language agnosticism, and seamless integration into GitHub workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/sherpa.sh/</link><pubDate>Sat, 08 Aug 2026 22:01:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven tool that simplifies deployment across various cloud providers by automatically configuring infrastructure based on plain English prompts. It supports a wide range of services, including servers, DNS, SSL certificates, CDNs, databases, backups, load balancing, and more. Key features include:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven tool that simplifies deployment across various cloud providers by automatically configuring infrastructure based on plain English prompts. It supports a wide range of services, including servers, DNS, SSL certificates, CDNs, databases, backups, load balancing, and more. Key features include:</p>
<ul>
<li>Open-source and community-driven</li>
<li>Automatically selects optimal cloud providers</li>
<li>Supports multiple programming frameworks</li>
<li>Eliminates the need for YAML files and infrastructure management expertise</li>
<li>Provides a seamless experience similar to Vercel/Netlify/Heroku for developers</li>
</ul>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Smyklot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/smyklot/</link><pubDate>Sat, 08 Aug 2026 22:00:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/smyklot/</guid><description>Version updated for https://github.com/smykla-skalski/smyklot to version v1.14.0.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository’s CODEOWNERS file. It allows users to comment with commands or react using emojis, and handles multiple formats of input such as slash commands, mentions, and bare commands. The app supports various merge methods like squash and rebase, provides reaction-based commands for approval, cleanup, and help, and includes features like approval deduplication and minimal permissions adherence.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smykla-skalski/smyklot">https://github.com/smykla-skalski/smyklot</a></strong> to version <strong>v1.14.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smyklot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Smyklot is a GitHub App that automates pull request approvals and merges by validating permissions against the repository&rsquo;s CODEOWNERS file. It allows users to comment with commands or react using emojis, and handles multiple formats of input such as slash commands, mentions, and bare commands. The app supports various merge methods like squash and rebase, provides reaction-based commands for approval, cleanup, and help, and includes features like approval deduplication and minimal permissions adherence.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1140-2026-08-08"><a href="https://github.com/smykla-skalski/smyklot/compare/v1.13.0...v1.14.0">1.14.0</a> (2026-08-08)</h2>
<h2 id="smyklot-v1140">Smyklot v1.14.0</h2>
<p>Docker image: <code>ghcr.io/smykla-skalski/smyklot:1.14.0</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>15bc6586e383c17b14b38bbb1606fc519e833b80 chore(release): bump version to 1.14.0</li>
<li>af677182065e78ffaef775de89cb9c868ef217c9 feat(deploy): run the service on Fly (#152)</li>
</ul>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/update-a-config-file-with-values-from-environment/</link><pubDate>Sat, 08 Aug 2026 21:58:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The config-file-from-env GitHub Action automates the process of replacing placeholders in configuration files with environment variables. This action is particularly useful for managing sensitive information and configurations securely, ensuring that they are not hardcoded into your codebase or exposed publicly. It helps streamline deployment processes by dynamically injecting environment-specific settings directly into config files, reducing the risk of accidental exposure or misconfiguration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>config-file-from-env</code> GitHub Action automates the process of replacing placeholders in configuration files with environment variables. This action is particularly useful for managing sensitive information and configurations securely, ensuring that they are not hardcoded into your codebase or exposed publicly. It helps streamline deployment processes by dynamically injecting environment-specific settings directly into config files, reducing the risk of accidental exposure or misconfiguration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add support for .env files (e706be3)</li>
<li>chore: More info (d440258)</li>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sat, 08 Aug 2026 21:58:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of building a JavaScript bundle before deploying it to a Swarm service. It ensures that all necessary dependencies are installed and the application is ready for deployment, thus simplifying the build and deployment pipeline.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of building a JavaScript bundle before deploying it to a Swarm service. It ensures that all necessary dependencies are installed and the application is ready for deployment, thus simplifying the build and deployment pipeline.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/ssg-static-site-generator/</link><pubDate>Sat, 08 Aug 2026 21:58:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.23.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a static site generator written in Go that converts Markdown files with YAML frontmatter into a complete website. It includes features like built-in themes, templates, and SEO metadata, as well as image processing and deployment capabilities to various platforms. The tool is designed to be fast, efficient, and easy to use for creating and managing websites.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.23</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a static site generator written in Go that converts Markdown files with YAML frontmatter into a complete website. It includes features like built-in themes, templates, and SEO metadata, as well as image processing and deployment capabilities to various platforms. The tool is designed to be fast, efficient, and easy to use for creating and managing websites.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: list &ndash;not-found-off in &ndash;help by @spagu in <a href="https://github.com/spagu/ssg/pull/105">https://github.com/spagu/ssg/pull/105</a></li>
<li>Release 1.8.23 by @spagu in <a href="https://github.com/spagu/ssg/pull/108">https://github.com/spagu/ssg/pull/108</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.22...v1.8.23">https://github.com/spagu/ssg/compare/v1.8.22...v1.8.23</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/classroom-to-sheets-integration/</link><pubDate>Sat, 08 Aug 2026 21:57:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending assignment results from GitHub Classroom to Google Sheets. It integrates with the Google Sheets API to update scores and tasks automatically. The main purpose is to streamline data transfer between students’ submissions and their performance metrics, reducing manual effort and improving transparency in grading processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending assignment results from GitHub Classroom to Google Sheets. It integrates with the Google Sheets API to update scores and tasks automatically. The main purpose is to streamline data transfer between students&rsquo; submissions and their performance metrics, reducing manual effort and improving transparency in grading processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/runward-gate/</link><pubDate>Sat, 08 Aug 2026 21:56:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.33.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose: Runward is an open-source delivery methodology that verifies the engineering decisions behind AI-written code, ensuring that critical aspects like architecture and security are properly documented and implemented.
Problem Solved: It helps in automating and ensuring that the engineering process follows best practices by verifying that the decisions made during coding align with predefined standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.33.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Purpose:</strong> Runward is an open-source delivery methodology that verifies the engineering decisions behind AI-written code, ensuring that critical aspects like architecture and security are properly documented and implemented.</p>
<p><strong>Problem Solved:</strong> It helps in automating and ensuring that the engineering process follows best practices by verifying that the decisions made during coding align with predefined standards.</p>
<p><strong>Key Capabilities:</strong> Runward provides a deterministic verification mechanism for AI-generated code, ensuring that the decisions behind it are clear and verifiable.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>No verdict changes.</strong> Four places where the output claimed more than it established, or less than it knew.</p>
<p>All four came out of an investigation into whether runward should issue an attestation that an application was built with it. The answer to that was <strong>no</strong> — and the reasons produced this release.</p>
<h2 id="the-machine-surface-was-quieter-than-the-terminal">The machine surface was quieter than the terminal</h2>
<p><code>check --strict --json</code> carried no counters, no corpus status, no seal. An agent driving on <code>--json</code> — which is how this tool is meant to be consumed, and how a CI reads it <strong>blind</strong> — could not tell a mission carrying real evidence from one answering <code>n/a</code> to every row. Both said <code>verdict: &quot;clean&quot;</code>.</p>
<p>That inverts ADR-0045&rsquo;s own finding one layer out: <em>the worst case must not be the quietest.</em></p>
<table>
  <thead>
      <tr>
          <th></th>
          <th>reference mission</th>
          <th>same mission, every row <code>n/a</code></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>before</td>
          <td><code>verdict: clean</code></td>
          <td><code>verdict: clean</code> — <strong>identical object</strong></td>
      </tr>
      <tr>
          <td>after</td>
          <td><code>applied 23 · na 13 · typed 20</code></td>
          <td><code>applied 11 · na 25 · typed 8</code></td>
      </tr>
  </tbody>
</table>
<p>Additive per ADR-0030: <code>evidence</code>, <code>corpus</code>, <code>seal</code>, <code>criticalScope</code>, <code>gateNonScope</code>, under <code>--strict</code> only. <strong><code>gateNonScope</code> travels with the counters on purpose</strong> — a consumer that keeps the numbers and drops the caveat is the next entry.</p>
<h2 id="the-declared-non-scope-shipped-in-one-pack-out-of-four">The declared non-scope shipped in one pack out of four</h2>
<p>Present in the ISO/IEC 42001 draft. <strong>Absent</strong> from the NIST AI RMF draft, the EU AI Act draft, and the OSCAL component-definition — the artifact that leaves for a third-party GRC tool was the one carrying no reservation.</p>
<p>The prose around a pack does not travel with it. <strong>A caveat that stays home was not made.</strong> All four carry it now, the OSCAL one in its metadata <code>remarks</code> so it survives ingestion.</p>
<h2 id="the-gate-demands-31-of-the-45-criticalhigh-rules">The gate demands 31 of the 45 CRITICAL/HIGH rules</h2>
<p>The conformance section printed <em>&ldquo;Architect: 6 rule(s) accounted for … Govern: 12&rdquo;</em> and stopped, which reads as though the critical set were covered. It is not: <strong>14 rules are mapped to no gated phase and are never asked about, five of them CRITICAL</strong>, including <code>checklist-pre-production-security</code> and <code>checklist-pre-production-resilience</code>.</p>
<p>Reported, never gated. A rule with <code>phases: []</code> is documentation the operator may apply without the gate asking, and gating it would red every honest mission on day one. Leaving it unsaid was the defect: it let a reader believe a sentence the output never supported.</p>
<pre tabindex="0"><code>scope: 31 of 45 CRITICAL/HIGH rules are mapped to a gated phase.
       The other 14 are never demanded by this gate: …
</code></pre><h2 id="the-seal-date-is-declared-not-observed">The seal date is declared, not observed</h2>
<p><code>runward/evidence-lock.json</code> carries <code>sealedAt</code>, and nothing signs the lock. Editing the field by hand yields <code>✓ seal intact — sealed 1999-12-31</code> with exit 0.</p>
<p><strong>Nothing changes for an honest user</strong> — <code>check --freeze</code> writes the real date, as it always did — and nothing here is repairable: an unsigned file inside the audited repository cannot testify about itself. What the seal proves is unchanged: the cited files still hash to what they hashed when it was written. The printed line now says the <em>when</em> is the mission&rsquo;s word.</p>
<p>Recorded as RWD-2026-0022 and RWD-2026-0023, under a register section that says plainly these are <strong>properties of where the data lives, not bugs awaiting a patch</strong>.</p>
<h2 id="method-note">Method note</h2>
<p>Every guard added here was checked <strong>by removing the fix</strong>: drop <code>gateNonScope</code> from the payload, remove the reservation from the drafts, stop computing <code>criticalScope</code> — each one reds. A guard nobody tried to break is a guard nobody has tested.</p>
<p><strong>Full changelog</strong>: <a href="https://github.com/stranxik/runward/blob/main/CHANGELOG.md">https://github.com/stranxik/runward/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>agents-md-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/agents-md-lint/</link><pubDate>Sat, 08 Aug 2026 21:55:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/agents-md-lint/</guid><description>Version updated for https://github.com/Taiizor/agents-md-cookbook to version v1.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The agents-md-cookbook GitHub Action automates the creation of a standardized AGENTS.md file that outlines coding guidelines and best practices, ensuring consistency across multiple development tools. This action helps developers maintain clear documentation on how their projects should be structured, tested, and managed, leveraging a set of pre-defined templates for various programming languages and frameworks. By providing linting capabilities and compatibility with multiple code generation tools, it simplifies the setup process and reduces the risk of errors in coding agent configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Taiizor/agents-md-cookbook">https://github.com/Taiizor/agents-md-cookbook</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-md-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>agents-md-cookbook</code> GitHub Action automates the creation of a standardized <code>AGENTS.md</code> file that outlines coding guidelines and best practices, ensuring consistency across multiple development tools. This action helps developers maintain clear documentation on how their projects should be structured, tested, and managed, leveraging a set of pre-defined templates for various programming languages and frameworks. By providing linting capabilities and compatibility with multiple code generation tools, it simplifies the setup process and reduces the risk of errors in coding agent configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release <strong>v1.0.1</strong> of <strong>agents-md-cookbook</strong> — bringing new stack templates, security guidelines, and updated tooling dependencies.</p>
<h2 id="whats-new-in-v101">What&rsquo;s new in v1.0.1</h2>
<ul>
<li><strong>New Template: Tuurio OIDC + React + Vite</strong> (<a href="./templates/tuurio-oidc-react-vite/AGENTS.md"><code>templates/tuurio-oidc-react-vite/AGENTS.md</code></a>) — A command-first guide for integrating Tuurio ID into React/Vite public clients using OpenID Connect, Authorization Code, and PKCE S256 with strict agent security boundaries. (#13 by @kraus-it)</li>
<li><strong>Version Alignment:</strong> Updated workspace version to <code>1.0.1</code> across <code>agents-md-cookbook</code>, <code>agents-md-lint</code>, and <code>agents-md-migrate</code>.</li>
<li><strong>Tooling &amp; Dependency Updates:</strong> Upgraded <code>markdownlint-cli2</code>, <code>typescript</code>, <code>@types/node</code>, and <code>actions/checkout</code> to latest releases.</li>
</ul>
<h2 id="quick-start">Quick start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>bunx agents-md-migrate@1.0.1          <span style="color:#75715e"># convert legacy rule files -&gt; AGENTS.md</span>
</span></span><span style="display:flex;"><span>bunx agents-md-lint@1.0.1 AGENTS.md   <span style="color:#75715e"># lint and score it</span>
</span></span></code></pre></div><p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Taiizor/agents-md-cookbook@v1.0.1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">path</span>: <span style="color:#ae81ff">AGENTS.md</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Get PR Push token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/get-pr-push-token/</link><pubDate>Sat, 08 Aug 2026 21:54:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/get-pr-push-token/</guid><description>Version updated for https://github.com/tiangolo/pr-push to version 0.0.3.
This action is used across all versions by 32 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PR Push GitHub App automates the process of obtaining a short-lived, repository-scoped token for approved workflows that update existing pull request branches. It solves the problem of managing tokens securely and efficiently by allowing authorized workflows to request them directly from the app without exposing sensitive information in the repository’s codebase. The action provides features such as token verification based on workflow versions and branch origin, ensuring secure and controlled access.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tiangolo/pr-push">https://github.com/tiangolo/pr-push</a></strong> to version <strong>0.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>32</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/get-pr-push-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The PR Push GitHub App automates the process of obtaining a short-lived, repository-scoped token for approved workflows that update existing pull request branches. It solves the problem of managing tokens securely and efficiently by allowing authorized workflows to request them directly from the app without exposing sensitive information in the repository&rsquo;s codebase. The action provides features such as token verification based on workflow versions and branch origin, ensuring secure and controlled access.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixes">Fixes</h3>
<ul>
<li>🐛 Support private repository pull requests. PR <a href="https://github.com/tiangolo/pr-push/pull/11">#11</a> by <a href="https://github.com/tiangolo">@tiangolo</a>.</li>
</ul>
]]></content:encoded></item><item><title>darnlink — self-healing Markdown links</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/darnlink-self-healing-markdown-links/</link><pubDate>Sat, 08 Aug 2026 21:53:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/darnlink-self-healing-markdown-links/</guid><description>Version updated for https://github.com/txemi/darnlink to version v0.19.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The darnlink GitHub Action automates the process of updating Markdown links after reorganization, ensuring they remain valid and self-healing. It automatically replaces stale paths with updated ones based on a file’s UUID, thus preventing broken links from occurring due to file movement or renaming. The action supports cross-repo web links for verifying and anchoring links across different repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/txemi/darnlink">https://github.com/txemi/darnlink</a></strong> to version <strong>v0.19.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/darnlink-self-healing-markdown-links">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>darnlink</code> GitHub Action automates the process of updating Markdown links after reorganization, ensuring they remain valid and self-healing. It automatically replaces stale paths with updated ones based on a file&rsquo;s UUID, thus preventing broken links from occurring due to file movement or renaming. The action supports cross-repo web links for verifying and anchoring links across different repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong><code>web-check</code>: the text report no longer prints one line per <code>web_unverifiable</code> finding.</strong> It lists
the first <code>UNVERIFIABLE_PREVIEW</code> (20) and then a <code>... and N more</code> line. <code>web_unverifiable</code> is
informational — it never fails the exit — so on a documentation repo whose Markdown holds a few
thousand ordinary external links (docs sites, videos, intranet URLs: anything that is not a GitHub
blob/raw URL) the old report emitted thousands of lines. Two consequences, both fixed: the
actionable <code>web_mismatch</code> / <code>web_not_found</code> lines were buried in the noise, and a caller reading
the output through a pipe could be flooded — in a <code>pre-push</code> git hook, whose stdio is a
non-blocking pipe, the run died with <code>BlockingIOError: write could not complete without blocking</code>,
so a phase that had found <strong>nothing wrong</strong> (<code>exit 0</code> when run standalone) blocked every push in
the repo until <code>--no-verify</code> was used. Nothing is silenced (Constitution II): the full total stays
in the summary line and <code>--json</code> still carries every finding. <code>web_mismatch</code>, <code>web_not_found</code> and
<code>web_anchor</code> are still listed in full — they are actionable and they do fail the exit. Tests in
<code>tests/test_weblinks.py</code>.</li>
</ul>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/rustscript-action/</link><pubDate>Sat, 08 Aug 2026 21:51:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.2.31.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that interprets Rust scripts without compiling them. It provides quick execution and validation of Rust code using a register-based virtual machine, with caching to improve performance. The action can be used to run, check, or build Rust scripts directly from the command line, making it a convenient alternative to traditional Rust compilation processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.2.31</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a tool that interprets Rust scripts without compiling them. It provides quick execution and validation of Rust code using a register-based virtual machine, with caching to improve performance. The action can be used to run, check, or build Rust scripts directly from the command line, making it a convenient alternative to traditional Rust compilation processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.31">https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.31</a></p>
]]></content:encoded></item><item><title>Move Closed Issue to Top of Project Column</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/move-closed-issue-to-top-of-project-column/</link><pubDate>Sat, 08 Aug 2026 21:50:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/move-closed-issue-to-top-of-project-column/</guid><description>Version updated for https://github.com/wozaki/project-closed-issue-move-to-top-action to version v1.25.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of moving closed issues to the top of a specified column in a GitHub Project V2. It checks if an issue is closed, updates its status to the given column, and ensures that recently closed issues are always visible at the top of the project board. The action supports multiple projects with different configurations using a matrix strategy.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wozaki/project-closed-issue-move-to-top-action">https://github.com/wozaki/project-closed-issue-move-to-top-action</a></strong> to version <strong>v1.25.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-closed-issue-to-top-of-project-column">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of moving closed issues to the top of a specified column in a GitHub Project V2. It checks if an issue is closed, updates its status to the given column, and ensures that recently closed issues are always visible at the top of the project board. The action supports multiple projects with different configurations using a matrix strategy.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">wozaki/project-closed-issue-move-to-top-action@efa9392d38defad4527f7ef175efca6c268fe119</span> <span style="color:#75715e"># v1.25.0</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(deps): update dependency @octokit/plugin-retry to v8.1.1 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/180">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/180</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.24.0...v1.25.0">https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.24.0...v1.25.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/b.ia-accessibility-checker/</link><pubDate>Sat, 08 Aug 2026 21:50:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in your CI/CD pipeline. It enables developers to define target audiences and percentages of WCAG guidelines required, providing flexibility in focusing on specific user groups. The action uses AI for analyzing and measuring guidelines, ensuring code compliance without the need for complex tools or learning curves.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in your CI/CD pipeline. It enables developers to define target audiences and percentages of WCAG guidelines required, providing flexibility in focusing on specific user groups. The action uses AI for analyzing and measuring guidelines, ensuring code compliance without the need for complex tools or learning curves.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>Zuke Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/zuke-build/</link><pubDate>Sat, 08 Aug 2026 21:48:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/zuke-build/</guid><description>Version updated for https://github.com/zuke-build/zuke to version v1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the execution of shell commands in your project using a tagged template that simplifies process running with sensible defaults such as capturing output and throwing on failure. It provides a simple, explicit approach to building tasks by focusing on discovery, building a dependency graph, sorting targets, and executing them.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zuke-build/zuke">https://github.com/zuke-build/zuke</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zuke-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the execution of shell commands in your project using a tagged template that simplifies process running with sensible defaults such as capturing output and throwing on failure. It provides a simple, explicit approach to building tasks by focusing on discovery, building a dependency graph, sorting targets, and executing them.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Updates <code>step-security/harden-runner</code> to v2.20.1.</p>
<p>Nothing about the action&rsquo;s interface changes: the same seven inputs, the same behaviour, the same ordering. This exists so the bump reaches anyone sing zuke-build/zuke@v1 — a pinned action only ships a fix when the tag it is pinned to moves.</p>
<p>Pin the full commit SHA rather than the moving v1 tag: <code>zuke-build/zuke@5400f044d0b56206b0fa48c90b30486df205c7c6</code></p>
]]></content:encoded></item><item><title>PR Rigor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/pr-rigor/</link><pubDate>Sat, 08 Aug 2026 14:47:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/pr-rigor/</guid><description>Version updated for https://github.com/Hassan7253/pr-rigor to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PR Rigor is a GitHub Action that automates the repeatable first-pass checks on pull requests to ensure they are prepared for focused human review. It identifies missing context, absent tests, risky workflow permission changes, probable credential files, high-confidence secret patterns, unpinned third-party Actions, dependency changes, migrations, public API changes, generated-file noise, and oversized diffs. The action provides a detailed report with specific recovery steps for each finding, helping maintainers ensure their pull requests are ready for review without introducing new risks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Hassan7253/pr-rigor">https://github.com/Hassan7253/pr-rigor</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-rigor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PR Rigor is a GitHub Action that automates the repeatable first-pass checks on pull requests to ensure they are prepared for focused human review. It identifies missing context, absent tests, risky workflow permission changes, probable credential files, high-confidence secret patterns, unpinned third-party Actions, dependency changes, migrations, public API changes, generated-file noise, and oversized diffs. The action provides a detailed report with specific recovery steps for each finding, helping maintainers ensure their pull requests are ready for review without introducing new risks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: add maintainer note by @Hassan7253 in <a href="https://github.com/Hassan7253/pr-rigor/pull/2">https://github.com/Hassan7253/pr-rigor/pull/2</a></li>
<li>Detect unsafe pull_request_target checkouts by @Hassan7253 in <a href="https://github.com/Hassan7253/pr-rigor/pull/3">https://github.com/Hassan7253/pr-rigor/pull/3</a></li>
<li>feat: add Eval Lab and v1.1.0 evaluation infrastructure by @Hassan7253 in <a href="https://github.com/Hassan7253/pr-rigor/pull/4">https://github.com/Hassan7253/pr-rigor/pull/4</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@Hassan7253 made their first contribution in <a href="https://github.com/Hassan7253/pr-rigor/pull/2">https://github.com/Hassan7253/pr-rigor/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Hassan7253/pr-rigor/compare/v1...v1.1.0">https://github.com/Hassan7253/pr-rigor/compare/v1...v1.1.0</a></p>
]]></content:encoded></item><item><title>ArvanCloud Edge Computing Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/arvancloud-edge-computing-action/</link><pubDate>Sat, 08 Aug 2026 14:46:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/arvancloud-edge-computing-action/</guid><description>Version updated for https://github.com/hatamiarash7/ar-ec-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a JavaScript bundle to Arvancloud’s Edge Computing service. It takes a built bundle file and deploys it to a specified Edge Computing application in a GitHub workflow. The action requires an API token stored as a secret, specifying the Edge Computing app name and optionally the file path and working directory for the build output. It provides outputs for deployment ID, status, and creation timestamp, with detailed summaries written to the job summary.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hatamiarash7/ar-ec-action">https://github.com/hatamiarash7/ar-ec-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/arvancloud-edge-computing-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a JavaScript bundle to Arvancloud&rsquo;s Edge Computing service. It takes a built bundle file and deploys it to a specified Edge Computing application in a GitHub workflow. The action requires an API token stored as a secret, specifying the Edge Computing app name and optionally the file path and working directory for the build output. It provides outputs for deployment ID, status, and creation timestamp, with detailed summaries written to the job summary.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update the logo and the header of the job summary.</li>
<li>Improve documentation.</li>
</ul>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hatamiarash7/ar-ec-action/compare/v1...v1.0.3">https://github.com/hatamiarash7/ar-ec-action/compare/v1...v1.0.3</a></p>
]]></content:encoded></item><item><title>slack-build-notifier</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/slack-build-notifier/</link><pubDate>Sat, 08 Aug 2026 14:45:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/slack-build-notifier/</guid><description>Version updated for https://github.com/hennejg/slack-build-notifier to version v1.1.
This action is used across all versions by 25 repositories. Action Type This is a Node action using Node version 12.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sends notifications to a Slack channel when a build status changes. It supports legacy webhook features and provides more compact templates while retaining essential information. Future enhancements include using Slack blocks for improved presentation, test failure summaries, and selective mentions based on job status change. The action is configured through parameters such as status, text, author name, mention options, and payload formats.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hennejg/slack-build-notifier">https://github.com/hennejg/slack-build-notifier</a></strong> to version <strong>v1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>25</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>12</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/slack-build-notifier">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sends notifications to a Slack channel when a build status changes. It supports legacy webhook features and provides more compact templates while retaining essential information. Future enhancements include using Slack blocks for improved presentation, test failure summaries, and selective mentions based on job status change. The action is configured through parameters such as status, text, author name, mention options, and payload formats.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Remove erroneously committed artifacts (83e0fda)</li>
<li>Build release (10e0389)</li>
<li>Fix channel field (0682480)</li>
<li>Fix typo, Icon (ff6f799)</li>
<li>Merge pull request #1 from hennejg/just_playing_around (6769f45)</li>
<li>Update Branding (22d888f)</li>
<li>Hide more fields by default (7d10d8f)</li>
<li>Simplify template (93ed17e)</li>
<li>Can a default be set using action.yml? (07bf727)</li>
<li>There seems to be no way of accessing the job status (5cedcab)</li>
</ul>
]]></content:encoded></item><item><title>Supply Chain Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/supply-chain-guard/</link><pubDate>Sat, 08 Aug 2026 14:44:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/supply-chain-guard/</guid><description>Version updated for https://github.com/homeofe/supply-chain-guard to version v5.25.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The supply-chain-guard GitHub Action is an open-source tool that performs a comprehensive supply-chain security scan for various ecosystems including npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, and GitHub repositories. It detects malware campaigns such as GlassWorm, Vidar/GhostSocks, and Shai-Hulud, as well as fake AI tool repos and account takeovers. The action generates CycloneDX SBOMs with real dependency inventories and SLSA provenance for each scan result.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/homeofe/supply-chain-guard">https://github.com/homeofe/supply-chain-guard</a></strong> to version <strong>v5.25.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supply-chain-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>supply-chain-guard</code> GitHub Action is an open-source tool that performs a comprehensive supply-chain security scan for various ecosystems including npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, and GitHub repositories. It detects malware campaigns such as GlassWorm, Vidar/GhostSocks, and Shai-Hulud, as well as fake AI tool repos and account takeovers. The action generates CycloneDX SBOMs with real dependency inventories and SLSA provenance for each scan result.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="5258---2026-08-08">[5.25.8] - 2026-08-08</h2>
<h3 id="added">Added</h3>
<ul>
<li>Threat feed: 250 malicious-package IOCs imported from the GitHub Advisory Database with
OSV.dev corroboration (2026-08-08 sweep, 230 npm and 20 PyPI). 4,498 advisories were
fetched over 45 pages; the page cap was not hit and no <code>--allow-truncated</code> or
<code>--allow-backlog</code> override was used. 49 mappable entries remain behind the <code>--limit 250</code>
cap, all of them drainable inside the <code>--days 14</code> window, so the next scheduled run takes
them. The batch continues the Tinkoff/T-Bank <code>dolyame-ui-*</code> / <code>devplatform-*</code> /
<code>delivery-ci-*</code> / <code>ded-pwa-*</code> dependency-confusion wave (roughly 130 names at the 35.x
internal version series), adds a <code>@depup/*</code> cluster that mimics upstream releases with a
<code>-depup.N</code> version suffix, a PyPI single-character-typosquat set (<code>pydanticc</code>, <code>flasq</code>,
<code>idnna</code>, <code>fastapii</code>), an AI-agent impersonation cluster (<code>aclade-agent</code>, <code>agenthub-ai</code>,
<code>mangomind-agent</code>), and a web3 tooling cluster (<code>hardhat-cap</code>, <code>hardhat-set</code>,
<code>forge-gas-diff</code>, <code>gas-diff-core</code>, <code>@coralxyz/anchor</code>).</li>
<li>IOC blocklist: second indicator wave for the ChainDrop npm worm (Microsoft and Datadog
published the resolver internals after the initial 2026-08-04 write-ups). Added the two
sibling C2 routers resolved from the same Ethereum contract, <code>pypi-get[.]com</code> and
<code>js-mirror[.]com</code>, the earlier rotation target <code>awqhnjewqjkl[.]icu</code>, four SHA-256 hashes
from the later re-obfuscation waves (the <code>.vscode/tasks.json</code> IDE persistence hook, a
re-obfuscated stage-2 stealer, the <code>zZ.bin</code> loader, and the embedded GitHub Actions
<code>Runner.Worker</code> memory dumper), and the two fixed marker names of the exfiltration
repositories the worm creates under each victim account. Every hash was re-confirmed by
exact-string search against an independent write-up before ingestion; a fifth hash from
the same source could not be corroborated and was deliberately left out. The public
Ethereum RPC providers the resolver calls are deliberately not ingested - they are shared
infrastructure, and a negative test pins that.</li>
<li>IOC blocklist: two follow-up indicators for the Alibaba developer toolchain RAT from
Corgea&rsquo;s analysis - the live <code>raw.githubusercontent[.]com</code> config dead-drop path under
the already-blocked attacker account, and <code>node-data-utils@1.0.1</code>, a nineteenth staging
package neither the advisory databases nor the original write-up listed. Both are
single-source and carry confidence 0.85. The package is version-pinned rather than
blocked by name, and the <code>raw.githubusercontent[.]com</code> host is never listed on its own.</li>
</ul>
<h3 id="security">Security</h3>
<ul>
<li>Lockfile: <code>nanoid</code> 3.3.16 to 3.3.18, resolving GHSA-2v37-7h3g-55p8 (high). A
development-only transitive dependency, reached through <code>vitest</code> -&gt; <code>vite</code> -&gt; <code>postcss</code>;
the published package still has <code>commander</code> as its only runtime dependency, so no
consumer was ever exposed. Included here because the newly published advisory turns the
<code>npm audit --audit-level=high</code> CI gate red on every branch until the lockfile moves.</li>
</ul>
]]></content:encoded></item><item><title>Harmans Code Coverage Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/harmans-code-coverage-report/</link><pubDate>Sat, 08 Aug 2026 14:43:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/harmans-code-coverage-report/</guid><description>Version updated for https://github.com/hrgui/lcov-reporter-action to version v0.2.18-alpha.12.
This action is used across all versions by 7 repositories. Action Type This is a Node action using Node version 12.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action comments a pull request with an HTML test coverage report based on the lcov report generated by your test runner. It automates the process of providing clear and actionable feedback on code coverage, helping developers identify areas that need improvement or missing tests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hrgui/lcov-reporter-action">https://github.com/hrgui/lcov-reporter-action</a></strong> to version <strong>v0.2.18-alpha.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>12</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harman-s-code-coverage-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action comments a pull request with an HTML test coverage report based on the lcov report generated by your test runner. It automates the process of providing clear and actionable feedback on code coverage, helping developers identify areas that need improvement or missing tests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>v0.2.18-alpha.12 (9b198cd)</li>
<li>Fix assignment to variable (45cc885)</li>
<li>v0.2.18-alpha.11 (75beb2d)</li>
<li>Fix reference to response (6edf6e7)</li>
<li>v0.2.18-alpha.10 (b7526f1)</li>
<li>Simplify file fetching loop (4c67927)</li>
<li>v0.2.18-alpha.9 (6668b90)</li>
<li>Use different method to fetch files (b8a2437)</li>
<li>v0.2.18-alpha.8 (acb967c)</li>
<li>v0.2.18-alpha.7 (74dd039)</li>
</ul>
]]></content:encoded></item><item><title>SAM Doctor AWS Deployment Diagnostics</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/sam-doctor-aws-deployment-diagnostics/</link><pubDate>Sat, 08 Aug 2026 14:41:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/sam-doctor-aws-deployment-diagnostics/</guid><description>Version updated for https://github.com/jakegold1647/sam-doctor to version v0.9.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action analyzes the log of failed AWS SAM, CloudFormation, or GitHub Actions deployments locally and identifies common failure patterns by providing a concise diagnosis, redacted evidence lines, verification commands, and links to official documentation. It helps developers quickly diagnose issues without accessing AWS or making network calls, focusing on specific error lines and rollback context for effective troubleshooting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jakegold1647/sam-doctor">https://github.com/jakegold1647/sam-doctor</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sam-doctor-aws-deployment-diagnostics">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action analyzes the log of failed AWS SAM, CloudFormation, or GitHub Actions deployments locally and identifies common failure patterns by providing a concise diagnosis, redacted evidence lines, verification commands, and links to official documentation. It helps developers quickly diagnose issues without accessing AWS or making network calls, focusing on specific error lines and rollback context for effective troubleshooting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<p><strong>Stable rule ids</strong> (#37, contributed in #47). Every rule now carries a permanent id like <code>iam.deny.explicit</code>, in JSON reports as <code>rule_id</code> and in the rules catalog as <code>id</code>. Titles keep improving; the id is the integration key. <code>docs/stability.md</code> records the commitment.</p>
<p><strong>SARIF output</strong> (#43). <code>--format sarif</code> on <code>diagnose</code>, <code>demo</code>, and <code>batch</code> emits a SARIF 2.1.0 run ready for GitHub code scanning, with the stable id as <code>ruleId</code>. A narrowed schema contract ships in <code>docs/schemas/sarif-report.schema.json</code> (contributed in #54).</p>
<p><strong>Confidence gating</strong> (#38). <code>--fail-on-confidence high|medium</code> on the CLI and <code>fail-on-confidence</code> on the Action gate the exit status without hiding any finding. <code>sam-doctor init --fail-on-confidence</code> writes it into the generated workflow (contributed in #52).</p>
<p><strong>Safer init</strong> (#36, contributed in #51). Generated workflows are manual-only (<code>workflow_dispatch</code>) until you opt into <code>--on-push</code> - trying <code>init</code> can no longer wire up an automatic AWS deployment.</p>
<p><strong>request-packet</strong> (#41, contributed in #53). When no rule matches, <code>sam-doctor request-packet</code> writes a small redacted excerpt around the first likely error for a rule request - never the whole log.</p>
<p><strong>Windows CI</strong> (#42). The documented support path is now enforced: the suite, gates, and the composite Action itself run on <code>windows-latest</code>.</p>
<h2 id="new-rules">New rules</h2>
<ul>
<li>The template failed SAM or CloudFormation schema validation (#30, contributed in #48)</li>
<li>The deployment bucket denied access to the packaged artifacts (#28)</li>
<li>An S3 bucket name in the template is already taken (#20)</li>
<li>The template exceeds a CloudFormation size or count quota (#46)</li>
<li>Another CloudFormation operation is already in progress on the stack (#44)</li>
<li>SAM could not upload a build artifact referenced by the template (#45)</li>
</ul>
<p>The catalog is now 44 rules, every one backed by a positive/negative fixture pair in the registry gate (#40, started in #49), and 20 have dedicated error-reference pages kept honest by the drift gate (#39, contributed in #50).</p>
<p>Full details in <a href="https://github.com/jakegold1647/sam-doctor/blob/main/CHANGELOG.md">CHANGELOG.md</a>. Thanks to @waterlemonnn for six merged PRs in this release.</p>
]]></content:encoded></item><item><title>EvalCanary Diff</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/evalcanary-diff/</link><pubDate>Sat, 08 Aug 2026 14:40:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/evalcanary-diff/</guid><description>Version updated for https://github.com/lmdixon23/evalcanary to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary EvalCanary automates the process of evaluating and comparing two different evaluators for a fixed set of cases. It helps detect drift in evaluation results when an evaluator is updated, ensuring that changes to verifiers or scorers do not introduce unexpected behavior. The action provides detailed reports on how individual cases change between versions and offers insights into subgroup effects and uncertainty estimates.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lmdixon23/evalcanary">https://github.com/lmdixon23/evalcanary</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/evalcanary-diff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>EvalCanary automates the process of evaluating and comparing two different evaluators for a fixed set of cases. It helps detect drift in evaluation results when an evaluator is updated, ensuring that changes to verifiers or scorers do not introduce unexpected behavior. The action provides detailed reports on how individual cases change between versions and offers insights into subgroup effects and uncertainty estimates.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="evalcanary-v011">EvalCanary v0.1.1</h1>
<p>EvalCanary v0.1.1 is a maintenance release. It does not add product features.</p>
<h2 id="changed">Changed</h2>
<ul>
<li>Updated CodeQL <code>init</code> and <code>analyze</code> together to the same reviewed full commit SHA.</li>
<li>Migrated packaging license metadata to the PEP 639 SPDX form.</li>
<li>Raised the Setuptools build-system floor to a version that supports PEP 639.</li>
<li>Added a dedicated Dependabot group for CodeQL sub-actions so compatible updates
are proposed together.</li>
</ul>
<h2 id="verification">Verification</h2>
<p>Release commit: <code>859d8aa47ba199ac91f6e795b0c6b9a6cc424591</code></p>
<p>External canary commit: <code>f2644878bb61aabbde7aee34ec1137a2c96761fe</code><br>
External canary workflow run: <code>31250415906</code></p>
<p>The exact <code>v0.1.1</code> tag was consumed successfully on Windows, Linux, and macOS,
including the intentionally blocking policy path and review-packet privacy audit.</p>
<p>The wheel is byte-reproducible across two fresh exact-tag builds. The release
sdist is canonically repacked only after two independently built raw sdists are
verified to have identical logical contents.</p>
<h2 id="compatibility">Compatibility</h2>
<p>Python 3.11 through 3.14.</p>
<h2 id="license">License</h2>
<p>MIT</p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/totem-shield/</link><pubDate>Sat, 08 Aug 2026 14:38:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.113.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based toolkit that helps manage project lessons, rules, and context using plain markdown files. It provides a local, zero-LLM linter to enforce lint rules derived from these lessons, ensuring deterministic behavior. This approach reduces the risk of architectural mistakes in AI coding agents by keeping the project’s history and context within the repository itself.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.113.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a file-based toolkit that helps manage project lessons, rules, and context using plain markdown files. It provides a local, zero-LLM linter to enforce lint rules derived from these lessons, ensuring deterministic behavior. This approach reduces the risk of architectural mistakes in AI coding agents by keeping the project&rsquo;s history and context within the repository itself.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>Upload to Nexus Mods</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/upload-to-nexus-mods/</link><pubDate>Sat, 08 Aug 2026 14:37:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/upload-to-nexus-mods/</guid><description>Version updated for https://github.com/Nexus-Mods/upload-action to version v1.0.0-beta.9.
This action is used across all versions by 79 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading new versions of files to NexusMods using their v3 API. It solves the problem of manually uploading mod files by integrating it into a CI/CD workflow, allowing developers to automate the release process and streamline their development workflow. The action provides features for uploading files with customizable metadata such as version number, display name, and description, while also supporting advanced options like archiving existing versions and managing download settings for mod managers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nexus-Mods/upload-action">https://github.com/Nexus-Mods/upload-action</a></strong> to version <strong>v1.0.0-beta.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>79</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/upload-to-nexus-mods">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading new versions of files to NexusMods using their v3 API. It solves the problem of manually uploading mod files by integrating it into a CI/CD workflow, allowing developers to automate the release process and streamline their development workflow. The action provides features for uploading files with customizable metadata such as version number, display name, and description, while also supporting advanced options like archiving existing versions and managing download settings for mod managers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: add update_mod_version input parameter by @bengosney in <a href="https://github.com/Nexus-Mods/upload-action/pull/31">https://github.com/Nexus-Mods/upload-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Nexus-Mods/upload-action/compare/v1.0.0-beta.8...v1.0.0-beta.9">https://github.com/Nexus-Mods/upload-action/compare/v1.0.0-beta.8...v1.0.0-beta.9</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/go-proxy-cache-updater/</link><pubDate>Sat, 08 Aug 2026 14:36:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.40.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Go Proxy Cache Updater Action automatically pulls new Go module releases to your proxy cache when tags are created, ensuring your module is immediately available and documentation is updated on platforms like pkg.go.dev. It supports standard version (vX.Y.Z) and submodule version tags (submodule/path/vX.Y.Z) formats, custom import paths, and customizable proxy configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.40</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Go Proxy Cache Updater Action automatically pulls new Go module releases to your proxy cache when tags are created, ensuring your module is immediately available and documentation is updated on platforms like pkg.go.dev. It supports standard version (<code>vX.Y.Z</code>) and submodule version tags (<code>submodule/path/vX.Y.Z</code>) formats, custom import paths, and customizable proxy configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1140-2026-08-08"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.39...v1.1.40">1.1.40</a> (2026-08-08)</h2>
]]></content:encoded></item><item><title>Nox Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/nox-security-scanner/</link><pubDate>Sat, 08 Aug 2026 14:35:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/nox-security-scanner/</guid><description>Version updated for https://github.com/Nox-HQ/nox to version v1.27.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Nox is an open-source, offline-first static analysis tool designed for AI application developers. It scans their applications to identify potential security risks such as prompt injection, embedding leakage, agent over-privilege, and more. Nox also detects vulnerabilities in code and dependency provenance issues. The main purpose of Nox is to provide a static analyzer that helps developers ensure the safety and integrity of their AI applications without requiring access to external services or sending code to vendors.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nox-HQ/nox">https://github.com/Nox-HQ/nox</a></strong> to version <strong>v1.27.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nox-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Nox is an open-source, offline-first static analysis tool designed for AI application developers. It scans their applications to identify potential security risks such as prompt injection, embedding leakage, agent over-privilege, and more. Nox also detects vulnerabilities in code and dependency provenance issues. The main purpose of Nox is to provide a static analyzer that helps developers ensure the safety and integrity of their AI applications without requiring access to external services or sending code to vendors.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="nox-v1270-2026-08-08t100713z">Nox v1.27.0 (2026-08-08T10:07:13Z)</h2>
<p>Language-agnostic security scanner with first-class AI application security.</p>
<h3 id="installation">Installation</h3>
<h4 id="macoslinux-homebrew">macOS/Linux (Homebrew)</h4>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap felixgeelhaar/tap
</span></span><span style="display:flex;"><span>brew install nox
</span></span></code></pre></div><h4 id="direct-download">Direct Download</h4>
<p>Download the appropriate archive for your platform from the assets below.</p>
<h3 id="whats-changed-1">What&rsquo;s Changed</h3>
<h2 id="changelog">Changelog</h2>
<h3 id="features">Features</h3>
<ul>
<li>741c99069af0a41520802ab1f70b57b7e6948e0f feat(action): install the plugins .nox.yaml requires (#447)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>88ebfb7ccfac52d96efca4d67cafcc3c0bc7a1c7 fix(report): serialize plugin enrichments to findings.json (#441)</li>
</ul>
<h3 id="others">Others</h3>
<ul>
<li>6defba1fb83c9f44cdffd989781a0057d287eceb chore(deps): bump github.com/openai/openai-go/v3 from 3.46.0 to 3.48.0 (#443)</li>
<li>59ba75d9d3b51318ea1b1dfae4643a63aa0ceb64 chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.0 (#442)</li>
<li>a541dc351d00697384c2199494f2be46731595dc chore(deps-dev): bump @types/node from 26.1.1 to 26.1.2 in /editors/vscode (#444)</li>
<li>6aba53ab68346f12e980a1ba5ebf69a21ba7a0c0 chore(release): changelog for 1.27.0</li>
<li>cf71e405dad325c4c3de57aa486a0a6f00084596 chore(security): nox remediation (deps + actions) (#446)</li>
<li>1b64c2b2b11b22cfec6e1a53869bffe791a9d289 docs(roady): both enrichment plugins converted and released as 0.3.0 (#440)</li>
<li>ac53f661fdd64c8b8a55ae4fa110ec89d741e645 docs(roady): record the enrichment-plugin precision work and what is left (#438)</li>
<li>a33518c4bc5f4e180281bba9da49acc029d0dd88 docs(roady): record triage-agent&rsquo;s conversion to a post-scan plugin (#439)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nox-hq/nox/compare/v1.26.0...v1.27.0">https://github.com/nox-hq/nox/compare/v1.26.0...v1.27.0</a></p>
]]></content:encoded></item><item><title>Changelog Bot Runner Nyaomaru</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/changelog-bot-runner-nyaomaru/</link><pubDate>Sat, 08 Aug 2026 14:34:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/changelog-bot-runner-nyaomaru/</guid><description>Version updated for https://github.com/nyaomaru/changelog-bot to version v0.6.9.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @nyaomaru/changelog-bot GitHub Action automates the process of creating polished changelog entries by combining commit history, PR titles, and release notes. It solves problems related to tedious manual changelog writing by generating concise entries automatically. The action supports LLM superpowers for tone-aware summaries or uses a robust heuristic fallback if necessary. It can open PRs with updated changelogs and maintain compare links and release notes in the correct format. Safe defaults are included to prevent issues like duplicate versions and failed releases due to AI unavailability. The tool is designed to be used as a GitHub Action, reusable workflow, or CLI, reducing the need for fragile scripting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nyaomaru/changelog-bot">https://github.com/nyaomaru/changelog-bot</a></strong> to version <strong>v0.6.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/changelog-bot-runner-nyaomaru">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>@nyaomaru/changelog-bot</code> GitHub Action automates the process of creating polished changelog entries by combining commit history, PR titles, and release notes. It solves problems related to tedious manual changelog writing by generating concise entries automatically. The action supports LLM superpowers for tone-aware summaries or uses a robust heuristic fallback if necessary. It can open PRs with updated changelogs and maintain compare links and release notes in the correct format. Safe defaults are included to prevent issues like duplicate versions and failed releases due to AI unavailability. The tool is designed to be used as a GitHub Action, reusable workflow, or CLI, reducing the need for fragile scripting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>test: improve changelog file and git helper coverage by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/174">https://github.com/nyaomaru/changelog-bot/pull/174</a></li>
<li>docs(changelog): 0.6.8 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/173">https://github.com/nyaomaru/changelog-bot/pull/173</a></li>
<li>refactor: split GitHub API responsibilities by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/175">https://github.com/nyaomaru/changelog-bot/pull/175</a></li>
<li>Release: 0.6.9 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/176">https://github.com/nyaomaru/changelog-bot/pull/176</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.9">https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.9</a></p>
]]></content:encoded></item><item><title>Critical URL SEO Release Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/critical-url-seo-release-guard/</link><pubDate>Sat, 08 Aug 2026 14:33:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/critical-url-seo-release-guard/</guid><description>Version updated for https://github.com/plainproof-labs/release-regression-guard to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Release Regression Guard is a GitHub Action that automates critical URL checks for SEO purposes after deployments. It compares repository-declared URLs against an expectation manifest, reporting pass/fail outcomes with detailed summaries and evidence. The action supports various checks such as HTTP status, same-origin redirects, indexing, canonical URLs, metadata presence, sitemap membership, and internal links. Users can install the Action from a published version or SHA, ensuring robustness and maintainability in their workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plainproof-labs/release-regression-guard">https://github.com/plainproof-labs/release-regression-guard</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/critical-url-seo-release-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Release Regression Guard is a GitHub Action that automates critical URL checks for SEO purposes after deployments. It compares repository-declared URLs against an expectation manifest, reporting pass/fail outcomes with detailed summaries and evidence. The action supports various checks such as HTTP status, same-origin redirects, indexing, canonical URLs, metadata presence, sitemap membership, and internal links. Users can install the Action from a published version or SHA, ensuring robustness and maintainability in their workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v1-release-and-marketplace-copy">v1 release and Marketplace copy</h1>
<h2 id="release-title">Release title</h2>
<p>Release Regression Guard v1.0.0</p>
<h2 id="marketplace-category">Marketplace category</h2>
<p>Primary: Continuous integration</p>
<h2 id="short-description">Short description</h2>
<p>Check repository-declared critical URLs after a deploy and keep JSON, SARIF,
and Markdown regression evidence.</p>
<h2 id="release-notes">Release notes</h2>
<p>Release Regression Guard v1 is one manifest-driven GitHub Action for technical
SEO and release owners. It checks declared critical URL status and same-origin
redirects, robots/noindex, canonical, required metadata, sitemap membership,
and required internal links.</p>
<p>Authentication, blocking, temporary transport or server failures, and
ambiguous JavaScript shells remain visible as <code>unknown</code>. The Action does not
guess an SEO score and does not require a third-party secret or service.</p>
<p>Start with the README installation workflow, copy the minimal manifest, set the
deployed origin, and download the JSON, SARIF, and Markdown workflow artifact.
Deterministic pass and fail fixtures are included for local verification.</p>
]]></content:encoded></item><item><title>Oversight Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/oversight-lint/</link><pubDate>Sat, 08 Aug 2026 14:32:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/oversight-lint/</guid><description>Version updated for https://github.com/rachelslurs/oversight-lint-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates linting of Storybook MCP components manifest files using the oversight-lint tool. It checks that each component has comprehensive documentation, failing the build if any components are missing descriptions or have incomplete docgen content. The action integrates with the storybook-addon-oversight for real-time documentation surfaces in Storybook during development.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rachelslurs/oversight-lint-action">https://github.com/rachelslurs/oversight-lint-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oversight-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates linting of Storybook MCP components manifest files using the <code>oversight-lint</code> tool. It checks that each component has comprehensive documentation, failing the build if any components are missing descriptions or have incomplete docgen content. The action integrates with the <code>storybook-addon-oversight</code> for real-time documentation surfaces in Storybook during development.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runs <code>oversight-lint@0.7.0</code>, gated by this repository&rsquo;s canary. Override with the <code>version</code> input.</p>
]]></content:encoded></item><item><title>wavedash-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/wavedash-action/</link><pubDate>Sat, 08 Aug 2026 14:31:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/wavedash-action/</guid><description>Version updated for https://github.com/remarkablegames/wavedash-action to version v1.0.4.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates uploading and publishing web game files to Wavedash. It simplifies the process of integrating Wavedash functionality into your project, handling both auto-creation of wavedash.toml and injection of the Wavedash SDK into HTML entrypoints. The action supports various configurations for game ID, upload directory, and entrypoint, as well as options to publish builds with release notes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablegames/wavedash-action">https://github.com/remarkablegames/wavedash-action</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wavedash-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates uploading and publishing web game files to Wavedash. It simplifies the process of integrating Wavedash functionality into your project, handling both auto-creation of <code>wavedash.toml</code> and injection of the Wavedash SDK into HTML entrypoints. The action supports various configurations for game ID, upload directory, and entrypoint, as well as options to publish builds with release notes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="104-2026-08-08"><a href="https://github.com/remarkablegames/wavedash-action/compare/v1.0.3...v1.0.4">1.0.4</a> (2026-08-08)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump @wvdsh/sdk-js from 1.3.41 to 1.3.43 (<a href="https://github.com/remarkablegames/wavedash-action/issues/10">#10</a>) (<a href="https://github.com/remarkablegames/wavedash-action/commit/a27139be40ff944b696b6fa73e755b4aa1268e99">a27139b</a>)</li>
</ul>
]]></content:encoded></item><item><title>docker-hash</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/docker-hash/</link><pubDate>Sat, 08 Aug 2026 14:30:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/docker-hash/</guid><description>Version updated for https://github.com/RemkoMolier/docker-hash to version v0.3.18.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action computes a deterministic SHA-256 hash for a Docker image build, based on the Dockerfile content, any build arguments, and files referenced by COPY/ADD instructions within the build context. It helps in cache-busting, change detection, and creating deterministic CI pipelines by ensuring that the hash changes whenever there are updates to the Dockerfile or its dependencies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RemkoMolier/docker-hash">https://github.com/RemkoMolier/docker-hash</a></strong> to version <strong>v0.3.18</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-hash">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action computes a deterministic SHA-256 hash for a Docker image build, based on the Dockerfile content, any build arguments, and files referenced by COPY/ADD instructions within the build context. It helps in cache-busting, change detection, and creating deterministic CI pipelines by ensuring that the hash changes whenever there are updates to the Dockerfile or its dependencies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="bug-fixes">Bug fixes</h3>
<ul>
<li>fix(deps): update module github.com/moby/buildkit to v0.32.1 (#194)</li>
</ul>
]]></content:encoded></item><item><title>Argus AI Code Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/argus-ai-code-reviewer/</link><pubDate>Sat, 08 Aug 2026 14:28:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/argus-ai-code-reviewer/</guid><description>Version updated for https://github.com/SahooShuvranshu/Argus to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ARGUS is a GitHub Action that automates an AI-driven 3-stage review process on Pull Requests, generating visual topology flowcharts, enforcing architectural compliance, and catching technical debt. It uses Google Gemini for LLM inference and supports OpenAI cloud compatibility.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SahooShuvranshu/Argus">https://github.com/SahooShuvranshu/Argus</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/argus-ai-code-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ARGUS is a GitHub Action that automates an AI-driven 3-stage review process on Pull Requests, generating visual topology flowcharts, enforcing architectural compliance, and catching technical debt. It uses Google Gemini for LLM inference and supports OpenAI cloud compatibility.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v100--argus-autonomous-3-stage-ai-code-reviewer--architecture-guardian-">v1.0.0 — ARGUS: Autonomous 3-Stage AI Code Reviewer &amp; Architecture Guardian 👁️⚡</h1>
<h2 id="-argus-v100--autonomous-3-stage-ai-pr-reviewer">👁️ ARGUS v1.0.0 — Autonomous 3-Stage AI PR Reviewer</h2>
<p>We are excited to announce the initial release of <strong>ARGUS v1.0.0</strong>, an autonomous GitHub Action that executes a 3-stage AI code review pipeline on every Pull Request. ARGUS automatically generates visual topology maps, enforces architectural compliance, and scans for technical debt and security leaks before code merges into production.</p>
<hr>
<h2 id="-key-features--capabilities">✨ Key Features &amp; Capabilities</h2>
<h3 id="1--stage-1-atlas-visual-impact-map">1. 🎨 Stage 1: Atlas (Visual Impact Map)</h3>
<ul>
<li>Parses raw PR git diffs into interactive <strong>Mermaid.js flowcharts</strong> (<code>flowchart TD</code>).</li>
<li>Visualizes modified files, module relationships, and control flow changes in a clean, collapsible section inside the PR review comment.</li>
</ul>
<h3 id="2--stage-2-athena-architecture-compliance-guard">2. 🏛️ Stage 2: Athena (Architecture Compliance Guard)</h3>
<ul>
<li>Cross-references PR code changes against your repository&rsquo;s <code>architecture.md</code> specification.</li>
<li>Detects architectural decay, forbidden cross-layer imports, and modular boundary violations automatically.</li>
</ul>
<h3 id="3--stage-3-hermes-technical-debt--security-scanner">3. ⚡ Stage 3: Hermes (Technical Debt &amp; Security Scanner)</h3>
<ul>
<li>Inspects modified files line-by-line to flag code quality issues and secret leaks:
<ul>
<li><code>🔴 BLOCK</code>: Hardcoded API keys, private tokens, or security vulnerabilities.</li>
<li><code>🟡 WARN</code>: Unfinished <code>// TODO</code>, <code>// FIXME</code>, or empty function stubs.</li>
<li><code>🔵 INFO</code>: Leftover debugging statements (e.g., <code>console.log</code>).</li>
</ul>
</li>
</ul>
<h3 id="4--universal-ai-cloud-provider-support">4. 🤖 Universal AI Cloud Provider Support</h3>
<ul>
<li><strong>Google Gemini (Default)</strong>: Natively powered by <code>@google/genai</code> (<code>gemini-2.0-flash</code>).</li>
<li><strong>OpenAI-Compatible Providers</strong>: Configure custom endpoints and API keys for <strong>NVIDIA NIM</strong>, <strong>OpenRouter</strong>, <strong>Groq Cloud</strong>, or <strong>OpenAI Direct</strong>.</li>
</ul>
<h3 id="5--fallback-static-analysis-engine">5. 🛡️ Fallback Static Analysis Engine</h3>
<ul>
<li>Includes an offline static regex parser. If AI model rate limits (HTTP 429) or network errors occur, ARGUS seamlessly completes the PR evaluation without breaking your CI build pipeline.</li>
</ul>
<h3 id="6--idempotent-pr-commenting">6. 👁️ Idempotent PR Commenting</h3>
<ul>
<li>Automatically creates and updates a single review comment (<code>&lt;!-- ARGUS-REVIEW-COMMENT --&gt;</code>) per Pull Request, keeping discussion threads clean and organized.</li>
</ul>
<hr>
<h2 id="-quick-start-setup-githubworkflowsargusyml">🚀 Quick Start Setup (<code>.github/workflows/argus.yml</code>)</h2>
<p>Add ARGUS to your repository by creating <code>.github/workflows/argus.yml</code>:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">ARGUS AI Code Review</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">types</span>: [<span style="color:#ae81ff">opened, synchronize, reopened]</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">argus-review</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">name</span>: <span style="color:#ae81ff">ARGUS 3-Stage AI PR Review</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">issues</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Checkout Code</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Setup Node.js</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/setup-node@v4</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">node-version</span>: <span style="color:#ae81ff">20</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">cache</span>: <span style="color:#e6db74">&#39;npm&#39;</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Install Dependencies</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">run</span>: <span style="color:#ae81ff">npm ci</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Run ARGUS AI Reviewer</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">SahooShuvranshu/Argus@v1.0.0</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">github-token</span>: <span style="color:#ae81ff">${{ secrets.GITHUB_TOKEN }}</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">gemini-api-key</span>: <span style="color:#ae81ff">${{ secrets.GEMINI_API_KEY }}</span>
</span></span></code></pre></div><hr>
<h2 id="-documentation--links">🔗 Documentation &amp; Links</h2>
<ul>
<li>🛒 <strong>GitHub Marketplace</strong>: <a href="https://github.com/marketplace/actions/argus-ai-code-reviewer">Argus AI Code Reviewer</a></li>
<li>🌐 <strong>Live Showcase &amp; Playground</strong>: <a href="https://sahooshuvranshu.github.io/Argus/">Interactive Showcase Site</a></li>
<li>📖 <strong>Technical Setup Guides</strong>: <a href="https://sahooshuvranshu.github.io/Argus/documentation.html">Documentation Hub</a></li>
<li>📜 <strong>Architecture Spec</strong>: <a href="https://github.com/SahooShuvranshu/Argus/blob/main/architecture.md"><code>architecture.md</code></a></li>
</ul>
<hr>
<p><em>Developed by <a href="https://github.com/SahooShuvranshu">SahooShuvranshu</a>.</em></p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/agentauditkit-mcp-security-scan/</link><pubDate>Sat, 08 Aug 2026 14:27:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.69.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a security scanner designed to audit AI agent pipelines. It runs offline and deterministically, finds misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. Key capabilities include running fully offline, producing auditor-ready compliance-evidence packs, and supporting OWASP coverage for top security categories. The action provides a total of 284 rules across 12 categories, with 85 scanner modules, including AST-based Python taint analysis and regex pattern scanners for TypeScript/JavaScript and Rust.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.69</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a security scanner designed to audit AI agent pipelines. It runs offline and deterministically, finds misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. Key capabilities include running fully offline, producing auditor-ready compliance-evidence packs, and supporting OWASP coverage for top security categories. The action provides a total of 284 rules across 12 categories, with 85 scanner modules, including AST-based Python taint analysis and regex pattern scanners for TypeScript/JavaScript and Rust.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.69
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.69
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.69</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.68...v0.3.69">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.68...v0.3.69</a></p>
]]></content:encoded></item><item><title>Storybook VRT (green/red diff)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/storybook-vrt-green/red-diff/</link><pubDate>Sat, 08 Aug 2026 14:26:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/storybook-vrt-green/red-diff/</guid><description>Version updated for https://github.com/sgash708/chromagic to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The chromagic GitHub Action automates Chromatic-like visual regression testing for Storybook projects without relying on external SaaS. It captures screenshot diffs of changed stories and posts them as inline comments in PRs, providing a two-color green/red diff to highlight differences. The action supports multiple viewports and customizable thresholds and outputs counts of changed, new, deleted, matching, and total stories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sgash708/chromagic">https://github.com/sgash708/chromagic</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/storybook-vrt-green-red-diff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The chromagic GitHub Action automates Chromatic-like visual regression testing for Storybook projects without relying on external SaaS. It captures screenshot diffs of changed stories and posts them as inline comments in PRs, providing a two-color green/red diff to highlight differences. The action supports multiple viewports and customizable thresholds and outputs counts of changed, new, deleted, matching, and total stories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="121-2026-08-08"><a href="https://github.com/sgash708/chromagic/compare/v1.2.0...v1.2.1">1.2.1</a> (2026-08-08)</h2>
<h3 id="performance-improvements">Performance Improvements</h3>
<ul>
<li>Chrome for Testingとaction依存をactions/cacheでキャッシュ (<a href="https://github.com/sgash708/chromagic/issues/8">#8</a>) (<a href="https://github.com/sgash708/chromagic/commit/c66e0061f3df94c07a88381560ff339160748ff4">c66e006</a>)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/classroom-to-sheets-integration/</link><pubDate>Sat, 08 Aug 2026 14:25:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending assignment results from GitHub Classroom to Google Sheets. It uses Google Sheets API credentials stored as secrets and integrates with the classroom-resources/autograding-command-grader@v1 grader to fetch task results. The action automatically updates or creates necessary columns and rows in the Google sheet based on student names and task results, making it easy to track grading progress across a class.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending assignment results from GitHub Classroom to Google Sheets. It uses Google Sheets API credentials stored as secrets and integrates with the <code>classroom-resources/autograding-command-grader@v1</code> grader to fetch task results. The action automatically updates or creates necessary columns and rows in the Google sheet based on student names and task results, making it easy to track grading progress across a class.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/runward-gate/</link><pubDate>Sat, 08 Aug 2026 14:24:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.33.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: Runward is an open-source method for verifying engineering decisions in AI-generated code. It automates the verification process of architectural, security, and operational aspects by creating a deterministic gate that checks the integrity of the delivered software. The action simplifies the setup and execution of the verification process with a single command.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.33.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> Runward is an open-source method for verifying engineering decisions in AI-generated code. It automates the verification process of architectural, security, and operational aspects by creating a deterministic gate that checks the integrity of the delivered software. The action simplifies the setup and execution of the verification process with a single command.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>A false green, in the release published the same day.</strong> One <code>rm</code> on a file the audited party owns, and a corpus of 64 rule files reduced to the word <code>ok</code> crossed the gate.</p>
<pre tabindex="0"><code>64 rule files reduced to &#34;ok&#34;, scaffold-lock.json present  -&gt;  exit 1
64 rule files reduced to &#34;ok&#34;, scaffold-lock.json deleted  -&gt;  exit 0
</code></pre><p>Reproduced against <code>runward@0.33.0</code> installed from npm, not against a working tree.</p>
<h2 id="what-was-open">What was open</h2>
<p><code>corpusDivergence</code> answers <code>unrecorded</code> when a mission keeps its own rule copy and carries no <code>scaffold-lock.json</code>. That is a compatibility path for missions predating the lock, and it printed a warning while contributing <strong>nothing</strong> to the verdict.</p>
<p>The lock lives in the audited repository. So <em>&ldquo;this mission predates the lock&rdquo;</em> and <em>&ldquo;someone deleted the lock&rdquo;</em> are the same observation, and the second costs one command. <strong><a href="https://github.com/stranxik/runward/blob/main/docs/adr/ADR-0045-the-gate-cannot-be-satisfied-by-paperwork.md">ADR-0045</a> class 1 reopens by deleting a file instead of re-signing it</strong> — and the known-defects register called that class closed.</p>
<p>It is also the aggravating form ADR-0045 names, one storey up: the gate said it could not check, in prose, next to a green exit code. <strong>Where the gate cannot verify, it says so in the run, and the run is the exit code.</strong></p>
<h2 id="the-fix-and-what-it-leaves-alone">The fix, and what it leaves alone</h2>
<p><code>unrecorded</code> is a named line of the verdict from this release.</p>
<table>
  <thead>
      <tr>
          <th>Case</th>
          <th>0.33.0</th>
          <th>0.33.1</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>fabricated corpus + lock deleted</td>
          <td><strong>0</strong></td>
          <td>1, with a named reason</td>
      </tr>
      <tr>
          <td>shipped example, intact</td>
          <td>0</td>
          <td>0</td>
      </tr>
      <tr>
          <td>no local rule copy (<code>package</code>)</td>
          <td>0</td>
          <td>0</td>
      </tr>
      <tr>
          <td>runward&rsquo;s own mission</td>
          <td>0</td>
          <td>0</td>
      </tr>
  </tbody>
</table>
<p>A legacy mission is one <code>runward update</code> away, and the safest configuration — no local copy at all — was never the one punished.</p>
<h2 id="guarded-twice-and-one-guard-had-to-be-repaired">Guarded twice, and one guard had to be repaired</h2>
<p><code>test/unit/verdict.test.js</code> pins both directions and kills two mutants. <code>test/audit-corpus.js</code> replays it end to end — and <strong>the first draft of that replay was decorative</strong>: it renamed the rule files, so every manifest row cited a slug that no longer existed and the mission reddened on conformance, which made the case pass with the fix removed. It guts the bodies in place now: green with the fix, exit 0 without it.</p>
<h2 id="how-it-was-found-which-belongs-in-the-record">How it was found, which belongs in the record</h2>
<p>Not by re-running the audit method ADR-0045 says to re-run on any release touching these modules. By an investigation into an unrelated product question, where an analyst asked to build the cheapest mission that would earn a hypothetical attestation built it. <strong>A reevaluation trigger is only as good as whoever remembers to pull it.</strong></p>
<p>ADR-0045 gains an amendment stating that class 1 was not closed, rather than leaving a ratified decision claiming a closure that did not hold. The register gains RWD-2026-0021 and corrects the RWD-2026-0001 entry.</p>
<h2 id="also">Also</h2>
<ul>
<li>The SBOM round-trip guard shipped with <code>workflow_dispatch</code> only, which was the defect it exists to prevent: a guard someone has to remember is a guard that does not run. It fires on any pull request touching <code>release.yml</code>.</li>
<li><code>chalk</code> 6.0.0, verified with colours forced since the suite redirects to files and emits no escape sequence at all: six outputs on 5.6.2 and 6.0.0, <strong>byte-identical</strong>.</li>
<li>Dependency advisories closed (<code>js-yaml</code> 5.2.3, <code>fast-uri</code> 3.1.5). <code>npm audit</code> reports 0.</li>
</ul>
<p><strong>Full changelog</strong>: <a href="https://github.com/stranxik/runward/blob/main/CHANGELOG.md">https://github.com/stranxik/runward/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Get PR Push token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/get-pr-push-token/</link><pubDate>Sat, 08 Aug 2026 14:23:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/get-pr-push-token/</guid><description>Version updated for https://github.com/tiangolo/pr-push to version 0.0.1.
This action is used across all versions by 4 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PR Push GitHub App automates the process of issuing short-lived, repository-scoped tokens for workflows that update pull request branches. It helps manage access to sensitive information securely and efficiently by granting permissions only to authorized workflows, thereby enhancing security and reducing potential vulnerabilities. The action ensures that tokens are issued only when necessary and is designed to integrate seamlessly with GitHub Actions workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tiangolo/pr-push">https://github.com/tiangolo/pr-push</a></strong> to version <strong>0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/get-pr-push-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The PR Push GitHub App automates the process of issuing short-lived, repository-scoped tokens for workflows that update pull request branches. It helps manage access to sensitive information securely and efficiently by granting permissions only to authorized workflows, thereby enhancing security and reducing potential vulnerabilities. The action ensures that tokens are issued only when necessary and is designed to integrate seamlessly with GitHub Actions workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixes">Fixes</h3>
<ul>
<li>🐛 Avoid hardcoding app version in tests. PR <a href="https://github.com/tiangolo/pr-push/pull/6">#6</a> by <a href="https://github.com/tiangolo">@tiangolo</a>.</li>
<li>🐛 Fix Docker Action imports. PR <a href="https://github.com/tiangolo/pr-push/pull/2">#2</a> by <a href="https://github.com/tiangolo">@tiangolo</a>.</li>
</ul>
<h3 id="docs">Docs</h3>
<ul>
<li>📝 Write README. PR <a href="https://github.com/tiangolo/pr-push/pull/3">#3</a> by <a href="https://github.com/tiangolo">@tiangolo</a>.</li>
</ul>
<h3 id="internal">Internal</h3>
<ul>
<li>👷 Add release workflows. PR <a href="https://github.com/tiangolo/pr-push/pull/4">#4</a> by <a href="https://github.com/tiangolo">@tiangolo</a>.</li>
</ul>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/compose-lint/</link><pubDate>Sat, 08 Aug 2026 14:22:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.15.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a security-focused linter for Docker Compose files that automates static analysis to catch dangerous misconfigurations. It identifies issues such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, and hard-coded credentials, providing auto-fixes where possible. The action solves the problem of catching vulnerabilities in Docker Compose configurations before they reach production, using OWASP and CIS benchmarks for guidance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.15.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a security-focused linter for Docker Compose files that automates static analysis to catch dangerous misconfigurations. It identifies issues such as privileged containers, unpinned images, host-network sharing, sensitive bind mounts, and hard-coded credentials, providing auto-fixes where possible. The action solves the problem of catching vulnerabilities in Docker Compose configurations before they reach production, using OWASP and CIS benchmarks for guidance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>Documentation site at <a href="https://tmatens.github.io/compose-lint/">https://tmatens.github.io/compose-lint/</a> (issue
#470) — the rule docs, configuration guide, severity model, hardening
walkthrough, and State of Compose report, built by mkdocs from the same
<code>docs/</code> markdown that <code>--explain</code> prints (single source, no duplicated
pages) and deployed to GitHub Pages by the new <code>docs</code> workflow on every
push to <code>main</code>. The docs toolchain is hash-pinned in
<code>requirements-docs.lock</code> (new <code>docs</code> extra).</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>The README&rsquo;s <em>State of Compose</em> report link was relative, so it 404&rsquo;d in
the PyPI rendering of the project description; it now points at the docs
site, as do the rule-table and hardening-guide links (previously GitHub
blob URLs).</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p>CL-0007&rsquo;s guidance gets the same symptom → remedy treatment as CL-0006
(issue #474): the rule doc gains a &ldquo;Reading the failure&rdquo; table mapping
verbatim <code>Read-only file system</code> errors to remedies <strong>by path type</strong> —
ephemeral paths to <code>tmpfs:</code>, persistent data to a named volume (never
<code>tmpfs</code>, which silently erases it on restart), plus the masked
<code>No such file or directory</code> symptom when the image lacks the directory.
The finding&rsquo;s <code>fix</code> text carries the path-type rule and points at
<code>--explain CL-0007</code>. Four new CI premise checks prove the busybox rows
live, including that named volumes stay writable under <code>read_only</code>.</p>
</li>
<li>
<p>The CL-0006 symptom → capability table now covers 11 mappings — added
<code>NET_ADMIN</code>, <code>SYS_NICE</code>, <code>SYS_TIME</code>, <code>FOWNER</code>, <code>KILL</code>, and <code>IPC_LOCK</code> — and
quotes the verbatim error messages real tools emit, captured from live
container runs (issue #468). Every mapping is re-proven on each CI run by
new checks in <code>scripts/validate_rule_premises.py</code> — the operation must fail
under <code>cap_drop: [ALL]</code> (busybox wordings asserted verbatim; coreutils
variants captured live but not CI-asserted) and succeed with only the
mapped capability added — so an engine default change that invalidates a
row (as Docker 20.10&rsquo;s <code>ip_unprivileged_port_start=0</code> did for the old
&ldquo;low ports need <code>NET_BIND_SERVICE</code>&rdquo; folklore) fails CI instead of aging
silently in the docs.</p>
</li>
<li>
<p>CL-0006&rsquo;s fix guidance now teaches how to <em>determine</em> an image&rsquo;s required
capability set instead of stopping at a <code>&lt;SPECIFIC_CAP&gt;</code> placeholder
(issue #4). The finding&rsquo;s <code>fix</code> text gains the drop-and-observe method and
the common <code>Operation not permitted</code> → capability mappings, and
<code>docs/rules/CL-0006.md</code> (also served by <code>--explain CL-0006</code>) gains a full
&ldquo;Determining required capabilities&rdquo; section covering the symptom→capability
table, the <code>capable</code> BPF tool, <code>docker diff</code>, and entrypoint inspection.
Both stress verifying <em>function</em>, not just startup: capability failures are
often non-fatal, silently degrading a feature (e.g. DHCP device discovery
under a dropped <code>NET_RAW</code>) while the container stays &ldquo;healthy&rdquo; — so review
logs and exercise background behaviors after every change.
Guidance-only per <a href="docs/adr/019-withdraw-security-profile-catalog.md">ADR-019</a>:
no per-image capability data is bundled.</p>
</li>
</ul>
]]></content:encoded></item><item><title>Setup Upwarden</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/setup-upwarden/</link><pubDate>Sat, 08 Aug 2026 14:21:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/setup-upwarden/</guid><description>Version updated for https://github.com/upwarden-io/setup-upwarden to version v2.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
The setup-upwarden GitHub Action is a composite action designed to automate dependency fetches in CI pipelines by authenticating and attributing requests through the Upwarden proxy using OIDC. It simplifies the process of managing dependencies securely, ensuring that each fetch is authenticated, attributed, and policy-enforced. The action supports various package managers, including npm, pnpm, yarn, pip, Maven, Gradle, Bun, Cargo (crates), Go modules, NuGet, and allows for static mode with a standing Upwarden key in cases where OIDC is not available.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/upwarden-io/setup-upwarden">https://github.com/upwarden-io/setup-upwarden</a></strong> to version <strong>v2.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-upwarden">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>The <code>setup-upwarden</code> GitHub Action is a composite action designed to automate dependency fetches in CI pipelines by authenticating and attributing requests through the Upwarden proxy using OIDC. It simplifies the process of managing dependencies securely, ensuring that each fetch is authenticated, attributed, and policy-enforced. The action supports various package managers, including npm, pnpm, yarn, pip, Maven, Gradle, Bun, Cargo (crates), Go modules, NuGet, and allows for static mode with a standing Upwarden key in cases where OIDC is not available.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="tool-bun--first-class-bun-support"><code>tool: bun</code> — first-class bun support</h2>
<p>bun is advertised on every pricing tier and sits in the dashboard ecosystem picker, and the proxy has always spoken it — only this action was missing a <code>tool:</code> value. Now:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">id-token</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">upwarden-io/setup-upwarden@v2</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">tool</span>: <span style="color:#ae81ff">bun</span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">run</span>: <span style="color:#ae81ff">bun install</span>
</span></span></code></pre></div><h3 id="credential-handling-is-unchanged-tier-b-preserved">Credential handling is unchanged (Tier B preserved)</h3>
<p>bun is wired through <code>.npmrc</code>, <strong>not</strong> <code>bunfig.toml</code>. That is not a fallback — it is the only shape that keeps the credential off disk. Measured on bun 1.3.8 against a local capture listener:</p>
<ul>
<li>bun <strong>reads</strong> a project-level <code>.npmrc</code>, and</li>
<li>bun <strong>expands <code>${VAR}</code></strong> from the process environment at install time</li>
</ul>
<p>so the file carries <code>//host/:_authToken=${UPWARDEN_CREDENTIAL}</code> and the secret never lands on disk. <code>bunfig.toml</code> has no equivalent reference-to-env form for the auth token, so using it would have forced the credential into a file.</p>
<p><strong>Precedence</strong>, also measured: with both a project <code>.npmrc</code> and a pre-existing <code>bunfig.toml</code> present, bun uses the <code>.npmrc</code>. The managed block wins over a customer&rsquo;s existing bunfig.</p>
<h3 id="notes">Notes</h3>
<ul>
<li>Routing joins the existing npm family (<code>npm|pnpm|yarn|yarn-classic|bun</code> → <code>npm.pkg.upwarden.io</code>) — no new protocol, host or URL shape.</li>
<li>The writer targets the <strong>project</strong> <code>.npmrc</code>, deliberately unlike <code>pnpm.sh</code> (pnpm ≥11.5.3 dropped env interpolation in project files; bun has no such restriction).</li>
<li>Supported-tool count goes from 9 to 10.</li>
</ul>
<p>Consumers on <code>@v2</code> get this automatically.</p>
]]></content:encoded></item><item><title>AI Slop PR Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/ai-slop-pr-guard/</link><pubDate>Sat, 08 Aug 2026 14:19:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/ai-slop-pr-guard/</guid><description>Version updated for https://github.com/Zensoro/ai-slop-detector to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses pure regular expression structural features to score PR/Issue bodies, flagging suspected AI-generated content with a label and scored comment. It labels without automatically closing issues unless opted in. The action is designed to reduce false positives by subtracting human signals such as referencing issue numbers or short bodies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zensoro/ai-slop-detector">https://github.com/Zensoro/ai-slop-detector</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-slop-pr-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses pure regular expression structural features to score PR/Issue bodies, flagging suspected AI-generated content with a label and scored comment. It labels without automatically closing issues unless opted in. The action is designed to reduce false positives by subtracting human signals such as referencing issue numbers or short bodies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v100--ai-slop-pr-guard">v1.0.0 — AI Slop PR Guard</h2>
<p><strong>The $0 AI-slop guard for open-source maintainers.</strong> Pure regex, zero dependencies, label-only by default.</p>
<h3 id="what-it-does">What it does</h3>
<ul>
<li>Scores PR/Issue bodies on open; flags probable AI-generated slop with a label + scored comment</li>
<li>Never auto-closes unless you opt in; members/bots never flagged</li>
</ul>
<h3 id="reliability">Reliability</h3>
<ul>
<li>API retry/backoff on 429/5xx, graceful non-fatal error handling</li>
<li>Short bodies (&lt;20 chars) skipped</li>
</ul>
<h3 id="accuracy">Accuracy</h3>
<ul>
<li>Human signals (issue references) subtract from the score — fewer false positives</li>
</ul>
<h3 id="docs">Docs</h3>
<ul>
<li>Real demo screenshot, FAQ, bilingual README</li>
<li>Issue/PR templates + GitHub Sponsors funding</li>
</ul>
<h3 id="signals-measured-on-gh-archive-2025-0708">Signals (measured on GH Archive 2025-07/08)</h3>
<table>
  <thead>
      <tr>
          <th>Signal</th>
          <th>AI PRs</th>
          <th>Human PRs</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>## Test</code> headers</td>
          <td>78.3%</td>
          <td>0.8% (~98x)</td>
      </tr>
      <tr>
          <td><code>##</code> section headers</td>
          <td>95.1%</td>
          <td>8.2% (~11.6x)</td>
      </tr>
      <tr>
          <td>✅ emoji</td>
          <td>17.9%</td>
          <td>0%</td>
      </tr>
  </tbody>
</table>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Zensoro/ai-slop-detector@v1</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Zuke Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/zuke-build/</link><pubDate>Sat, 08 Aug 2026 14:18:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/zuke-build/</guid><description>Version updated for https://github.com/zuke-build/zuke to version v1.0.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Zuke automates the creation of build pipelines in various CI/CD platforms using a TypeScript-driven approach. It solves the problem of managing complex build processes by providing a type-safe way to define targets and their dependencies through a class-based syntax. The action generates GitHub Actions, GitLab CI, or Azure Pipelines YAML based on the project’s configuration, ensuring consistent and maintainable builds across different environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zuke-build/zuke">https://github.com/zuke-build/zuke</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zuke-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Zuke automates the creation of build pipelines in various CI/CD platforms using a TypeScript-driven approach. It solves the problem of managing complex build processes by providing a type-safe way to define targets and their dependencies through a class-based syntax. The action generates GitHub Actions, GitLab CI, or Azure Pipelines YAML based on the project&rsquo;s configuration, ensuring consistent and maintainable builds across different environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds a <code>ref</code> input, so a job can check out a branch other than the one the event points at — the head branch of a pull request, for instance, when a later step pushes a fix back to it.</p>
<p>It arrives with a refusal. On any event other than <code>pull_request</code>, <code>push</code>, <code>merge_group</code>, <code>workflow_dispatch</code>, <code>schedule</code> or <code>release</code>, passing ref fails the action outright. Those six are the events whose ref can only come from someone who could push the same code directly; everything else — <code>issue_comment</code> and the <code>slash-command</code> pattern, <code>workflow_run</code>, <code>pull_request_target</code>, the discussion and review events — lets a contributor&rsquo;s text choose what gets checked out while the job holds the repository&rsquo;s secrets. The list is an allowlist rather than a denylist, so an event GitHub adds later is refused rather than silently permitted.</p>
<p>Pin the full commit SHA rather than the moving v1 tag: <code>zuke-build/zuke@7a62523bb4569e4d90e972dee74bf9cf09cd436f</code></p>
]]></content:encoded></item><item><title>Hiero Solo Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/hiero-solo-action/</link><pubDate>Sat, 08 Aug 2026 06:24:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/hiero-solo-action/</guid><description>Version updated for https://github.com/hiero-ledger/hiero-solo-action to version v0.23.0.
This action is used across all versions by 25 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup of a Hiero Solo network by deploying one or more consensus nodes, optionally including a block node and a mirror node. It provisions an account with 10 million hbars and outputs the account details as action output. The action can configure various network settings such as ports and version numbers for different components.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hiero-ledger/hiero-solo-action">https://github.com/hiero-ledger/hiero-solo-action</a></strong> to version <strong>v0.23.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>25</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hiero-solo-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup of a Hiero Solo network by deploying one or more consensus nodes, optionally including a block node and a mirror node. It provisions an account with 10 million hbars and outputs the account details as action output. The action can configure various network settings such as ports and version numbers for different components.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: update solo version to 0.82.1 by @andrewb1269 in <a href="https://github.com/hiero-ledger/hiero-solo-action/pull/142">https://github.com/hiero-ledger/hiero-solo-action/pull/142</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@andrewb1269 made their first contribution in <a href="https://github.com/hiero-ledger/hiero-solo-action/pull/142">https://github.com/hiero-ledger/hiero-solo-action/pull/142</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hiero-ledger/hiero-solo-action/compare/v0.22.0...v0.23.0">https://github.com/hiero-ledger/hiero-solo-action/compare/v0.22.0...v0.23.0</a></p>
]]></content:encoded></item><item><title>Harmans Code Coverage Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/harmans-code-coverage-report/</link><pubDate>Sat, 08 Aug 2026 06:23:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/harmans-code-coverage-report/</guid><description>Version updated for https://github.com/hrgui/lcov-reporter-action to version v0.1.0.
This action is used across all versions by 7 repositories. Action Type This is a Node action using Node version 12.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action generates a HTML test coverage report based on the lcov coverage report generated by your test runner and comments it to a pull request. It does not run any tests but expects them to have been run by another action already. The key capabilities include generating a detailed coverage report, linking to specific files where coverage is lower, and displaying the total coverage percentage.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hrgui/lcov-reporter-action">https://github.com/hrgui/lcov-reporter-action</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>12</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harman-s-code-coverage-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action generates a HTML test coverage report based on the lcov coverage report generated by your test runner and comments it to a pull request. It does not run any tests but expects them to have been run by another action already. The key capabilities include generating a detailed coverage report, linking to specific files where coverage is lower, and displaying the total coverage percentage.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: when adding a check-run, need to report a conclusion (4e9b678)</li>
<li>feat: support for reporting coverage as a check-run for fuller detail (ae6159f)</li>
<li>actions.yml change for testing (e274627)</li>
<li>feat: delete previous comments (8c7f043)</li>
<li>chore: repo location for testing (50f4d9b)</li>
<li>v0.2.17 (b786241)</li>
<li>v0.2.17-alpha.5 (05abfce)</li>
<li>Use diff to build coverage (f3494ba)</li>
<li>v0.2.17-alpha.4 (506f94b)</li>
<li>Allow diffing of lcov files (4148348)</li>
</ul>
]]></content:encoded></item><item><title>sops tools installer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/sops-tools-installer/</link><pubDate>Sat, 08 Aug 2026 06:21:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/sops-tools-installer/</guid><description>Version updated for https://github.com/jkroepke/setup-sops to version v1.5.64.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs and caches a specific version of sops, a tool for encrypting and decrypting sensitive files. It simplifies managing encrypted secrets in repositories by automating the installation process, ensuring consistent usage across different workflows, and providing easy access to the binary via environment variables.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jkroepke/setup-sops">https://github.com/jkroepke/setup-sops</a></strong> to version <strong>v1.5.64</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sops-tools-installer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs and caches a specific version of <code>sops</code>, a tool for encrypting and decrypting sensitive files. It simplifies managing encrypted secrets in repositories by automating the installation process, ensuring consistent usage across different workflows, and providing easy access to the binary via environment variables.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.5.64 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="-dependencies">🛠️ Dependencies</h3>
<ul>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/jkroepke/setup-sops/pull/268">https://github.com/jkroepke/setup-sops/pull/268</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jkroepke/setup-sops/compare/v1.5.63...v1.5.64">https://github.com/jkroepke/setup-sops/compare/v1.5.63...v1.5.64</a></p>
]]></content:encoded></item><item><title>stackit-cli tools installer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/stackit-cli-tools-installer/</link><pubDate>Sat, 08 Aug 2026 06:21:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/stackit-cli-tools-installer/</guid><description>Version updated for https://github.com/jkroepke/setup-stackit-cli to version v1.2.96.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs a specific version of stackit-cli binary on the runner, allowing users to define which version of stackit-cli will be used in their workflows. It supports both the latest stable release and any semantic version string like v2.16.7, automatically caching the binary path in the PATH environment variable.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jkroepke/setup-stackit-cli">https://github.com/jkroepke/setup-stackit-cli</a></strong> to version <strong>v1.2.96</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/stackit-cli-tools-installer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs a specific version of stackit-cli binary on the runner, allowing users to define which version of stackit-cli will be used in their workflows. It supports both the latest stable release and any semantic version string like v2.16.7, automatically caching the binary path in the PATH environment variable.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.2.96 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="-dependencies">🛠️ Dependencies</h3>
<ul>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/jkroepke/setup-stackit-cli/pull/302">https://github.com/jkroepke/setup-stackit-cli/pull/302</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.95...v1.2.96">https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.95...v1.2.96</a></p>
]]></content:encoded></item><item><title>LinkedIn Post</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/linkedin-post/</link><pubDate>Sat, 08 Aug 2026 06:20:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/linkedin-post/</guid><description>Version updated for https://github.com/julioliraup/linkedin-post to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of publishing text or image posts to LinkedIn using the official Posts API. It simplifies the integration by wrapping the LinkedIn Images and Posts APIs in a composite action, allowing users to publish content with minimal code. The action supports both text-only and text + image posts and is easy to set up by adding secrets for OAuth access tokens and URNs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/julioliraup/linkedin-post">https://github.com/julioliraup/linkedin-post</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/linkedin-post">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of publishing text or image posts to LinkedIn using the official Posts API. It simplifies the integration by wrapping the LinkedIn Images and Posts APIs in a composite action, allowing users to publish content with minimal code. The action supports both text-only and text + image posts and is easy to set up by adding secrets for OAuth access tokens and URNs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First stable release of the <strong>linkedin-post</strong> GitHub Action — a lightweight, dependency-free way to publish content to LinkedIn directly from your CI/CD pipeline.</p>
<hr>
<h3 id="-features">✨ Features</h3>
<ul>
<li><strong>Text-only posts</strong> — publish any text content to your LinkedIn profile with a single workflow step.</li>
<li><strong>Image posts</strong> — attach a local image (JPG, PNG or GIF) alongside your text using the LinkedIn Images API.</li>
<li><strong>Official API only</strong> — built on top of the LinkedIn REST <a href="https://learn.microsoft.com/en-us/linkedin/marketing/community-management/shares/posts-api">Posts API</a> and <a href="https://learn.microsoft.com/en-us/linkedin/marketing/community-management/shares/images-api">Images API</a>. No third-party SDKs.</li>
<li><strong>Composite Action</strong> — uses plain Python + <code>requests</code>, no Docker image required. Fast cold start.</li>
<li><strong>Configurable Python version</strong> — pin any Python 3.x version via <code>python_version</code> input (default: <code>3.11</code>).</li>
<li><strong>Structured outputs</strong> — exposes <code>post_id</code> (LinkedIn URN) and <code>status</code> (<code>success</code> / <code>failure</code>) for downstream steps.</li>
</ul>
<hr>
<h3 id="-inputs">📥 Inputs</h3>
<table>
  <thead>
      <tr>
          <th>Input</th>
          <th>Required</th>
          <th>Default</th>
          <th>Description</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>linkedin_access_token</code></td>
          <td>✅</td>
          <td>—</td>
          <td>OAuth 2.0 Access Token</td>
      </tr>
      <tr>
          <td><code>linkedin_person_urn</code></td>
          <td>✅</td>
          <td>—</td>
          <td>Author URN (<code>urn:li:person:...</code>)</td>
      </tr>
      <tr>
          <td><code>post_text</code></td>
          <td>❌</td>
          <td><code>&quot;Posted automatically via GitHub Actions!&quot;</code></td>
          <td>Body of the post</td>
      </tr>
      <tr>
          <td><code>image_path</code></td>
          <td>❌</td>
          <td><code>&quot;&quot;</code></td>
          <td>Path to a local image file</td>
      </tr>
      <tr>
          <td><code>python_version</code></td>
          <td>❌</td>
          <td><code>3.11</code></td>
          <td>Python version on the runner</td>
      </tr>
  </tbody>
</table>
<hr>
<h3 id="-outputs">📤 Outputs</h3>
<table>
  <thead>
      <tr>
          <th>Output</th>
          <th>Description</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>post_id</code></td>
          <td>LinkedIn URN of the published post</td>
      </tr>
      <tr>
          <td><code>status</code></td>
          <td><code>&quot;success&quot;</code> or <code>&quot;failure&quot;</code></td>
      </tr>
  </tbody>
</table>
<hr>
<h3 id="-minimal-example">📋 Minimal Example</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Post to LinkedIn</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">julioliraup/linkedin-post@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">linkedin_access_token</span>: <span style="color:#ae81ff">${{ secrets.LINKEDIN_TOKEN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">linkedin_person_urn</span>:   <span style="color:#ae81ff">${{ secrets.LINKEDIN_URN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">post_text</span>: <span style="color:#e6db74">&#34;🚀 New release is live!&#34;</span>
</span></span></code></pre></div><hr>
<h3 id="-api-version">🔧 API Version</h3>
<p>Pinned to <code>LinkedIn-Version: 202508</code>.</p>
<hr>
<h3 id="-license">📄 License</h3>
<p><a href="LICENSE">GPL-3.0</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/neurolink-ai/</link><pubDate>Sat, 08 Aug 2026 06:19:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v10.10.10.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is an AI integration platform that provides a unified API for accessing multiple AI providers. It allows developers to switch providers with minimal changes and leverage built-in tools. The action automates tasks such as integrating AI into applications, handling different output modes (avatar or music), and optimizing costs using intelligent routing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v10.10.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is an AI integration platform that provides a unified API for accessing multiple AI providers. It allows developers to switch providers with minimal changes and leverage built-in tools. The action automates tasks such as integrating AI into applications, handling different output modes (avatar or music), and optimizing costs using intelligent routing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="101010-2026-08-07"><a href="https://github.com/juspay/neurolink/compare/v10.10.9...v10.10.10">10.10.10</a> (2026-08-07)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(audio):</strong>  explain why a transcript is missing instead of returning nothing (<a href="https://github.com/juspay/neurolink/commit/c5ef0bf3afba4e040819ed975341723c9f29ea12">c5ef0bf</a>), closes <a href="https://github.com/juspay/neurolink/issues/416">#416</a></li>
<li><strong>(csv):</strong>  skip blank lines in raw content via skipEmptyLines (<a href="https://github.com/juspay/neurolink/commit/919afc307fd91de80bf064e98f9018eeb4f4ab95">919afc3</a>), closes <a href="https://github.com/juspay/neurolink/issues/1284">#1284</a> <a href="https://github.com/juspay/neurolink/issues/373">#373</a></li>
</ul>
]]></content:encoded></item><item><title>.NET Quality Enforcer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/.net-quality-enforcer/</link><pubDate>Sat, 08 Aug 2026 06:18:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/.net-quality-enforcer/</guid><description>Version updated for https://github.com/KaramTNC/dotnet-quality-enforcer to version main-5ce2c8288e30d65d128a492b5b709df1986873f6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary .NET Quality Enforcer is a configurable quality gate for .NET, Python, Java, Kotlin, TypeScript, JavaScript, Go, and Rust repositories. It provides reusable checks to enforce architectural boundaries, code size and complexity, source and namespace layout, public API XML documentation, test architecture and naming conventions, and Cobertura repository, diff, and branch coverage. The enforcer provides the analysis engine and tests while consuming repositories provide policies, baselines, source layout, layer names, thresholds, and CI paths.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/KaramTNC/dotnet-quality-enforcer">https://github.com/KaramTNC/dotnet-quality-enforcer</a></strong> to version <strong>main-5ce2c8288e30d65d128a492b5b709df1986873f6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/net-quality-enforcer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>.NET Quality Enforcer</code> is a configurable quality gate for .NET, Python, Java, Kotlin, TypeScript, JavaScript, Go, and Rust repositories. It provides reusable checks to enforce architectural boundaries, code size and complexity, source and namespace layout, public API XML documentation, test architecture and naming conventions, and Cobertura repository, diff, and branch coverage. The enforcer provides the analysis engine and tests while consuming repositories provide policies, baselines, source layout, layer names, thresholds, and CI paths.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Promote semantic release automation to main by @KaramTNC in <a href="https://github.com/KaramTNC/dotnet-quality-enforcer/pull/21">https://github.com/KaramTNC/dotnet-quality-enforcer/pull/21</a></li>
<li>Improve README clarity and references by @KaramTNC in <a href="https://github.com/KaramTNC/dotnet-quality-enforcer/pull/22">https://github.com/KaramTNC/dotnet-quality-enforcer/pull/22</a></li>
<li>Promote quality audit improvements to main by @KaramTNC in <a href="https://github.com/KaramTNC/dotnet-quality-enforcer/pull/25">https://github.com/KaramTNC/dotnet-quality-enforcer/pull/25</a></li>
<li>Add multi-language adapters and self-enforcing CI by @KaramTNC in <a href="https://github.com/KaramTNC/dotnet-quality-enforcer/pull/39">https://github.com/KaramTNC/dotnet-quality-enforcer/pull/39</a></li>
<li>Fix main package build version inference by @KaramTNC in <a href="https://github.com/KaramTNC/dotnet-quality-enforcer/pull/40">https://github.com/KaramTNC/dotnet-quality-enforcer/pull/40</a></li>
<li>Fix release distribution validation by @KaramTNC in <a href="https://github.com/KaramTNC/dotnet-quality-enforcer/pull/42">https://github.com/KaramTNC/dotnet-quality-enforcer/pull/42</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/KaramTNC/dotnet-quality-enforcer/compare/main-6235f480a6294b880ff42534f8a8fa3bfae06af3...main-5ce2c8288e30d65d128a492b5b709df1986873f6">https://github.com/KaramTNC/dotnet-quality-enforcer/compare/main-6235f480a6294b880ff42534f8a8fa3bfae06af3...main-5ce2c8288e30d65d128a492b5b709df1986873f6</a></p>
]]></content:encoded></item><item><title>SearchDeadCode</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/searchdeadcode/</link><pubDate>Sat, 08 Aug 2026 06:17:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/searchdeadcode/</guid><description>Version updated for https://github.com/KevinDoremy/SearchDeadCode to version vscode-v0.20.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SearchDeadCode is a static code analysis tool that scans Kotlin and Java sources directly without requiring a JDK or Gradle build. It identifies unused classes, methods, and variables, providing runtime proof of their dead status. The tool is fast, with scan times ranging from 0.3 seconds to less than three minutes for large projects, and supports over 54 detectors. Users can review findings and choose to delete them safely, either through a dry run or by restoring the project if needed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/KevinDoremy/SearchDeadCode">https://github.com/KevinDoremy/SearchDeadCode</a></strong> to version <strong>vscode-v0.20.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/searchdeadcode">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SearchDeadCode is a static code analysis tool that scans Kotlin and Java sources directly without requiring a JDK or Gradle build. It identifies unused classes, methods, and variables, providing runtime proof of their dead status. The tool is fast, with scan times ranging from 0.3 seconds to less than three minutes for large projects, and supports over 54 detectors. Users can review findings and choose to delete them safely, either through a dry run or by restoring the project if needed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>SearchDeadCode for VS Code 0.20.0.</p>
<p>Analyzer binaries come from crate release v0.20.0.</p>
<p>Install from the <a href="https://marketplace.visualstudio.com/items?itemName=elumine.searchdeadcode">Marketplace</a>
or <a href="https://open-vsx.org/extension/elumine/searchdeadcode">Open VSX</a>, or grab the
VSIX for your platform below.</p>
<p>See <a href="https://github.com/KevinDoremy/SearchDeadCode/blob/main/editors/vscode/CHANGELOG.md">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>Kusari Ingest</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/kusari-ingest/</link><pubDate>Sat, 08 Aug 2026 06:16:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/kusari-ingest/</guid><description>Version updated for https://github.com/kusaridev/kusari-ingest to version v4.11.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of ingesting various artifacts, such as SBOMs and SLSA attestations, into the Kusari Platform. It simplifies the integration of security information directly from your GitHub workflows, enabling quick access to your tenant’s data. The action supports authentication via client credentials or API keys, requiring specific permissions for different tasks like checking blocked packages, generating machine-readable results, and mapping components.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kusaridev/kusari-ingest">https://github.com/kusaridev/kusari-ingest</a></strong> to version <strong>v4.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kusari-ingest">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of ingesting various artifacts, such as SBOMs and SLSA attestations, into the Kusari Platform. It simplifies the integration of security information directly from your GitHub workflows, enabling quick access to your tenant’s data. The action supports authentication via client credentials or API keys, requiring specific permissions for different tasks like checking blocked packages, generating machine-readable results, and mapping components.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update kusari-cli to v2.10.1 by @nchelluri in <a href="https://github.com/kusaridev/kusari-ingest/pull/44">https://github.com/kusaridev/kusari-ingest/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kusaridev/kusari-ingest/compare/v4.10.0...v4.11.0">https://github.com/kusaridev/kusari-ingest/compare/v4.10.0...v4.11.0</a></p>
]]></content:encoded></item><item><title>GitHub Informer for Zoho Cliq</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/github-informer-for-zoho-cliq/</link><pubDate>Sat, 08 Aug 2026 06:15:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/github-informer-for-zoho-cliq/</guid><description>Version updated for https://github.com/Lincy-Zoho/GitHub-Informer-New to version v1.8.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action Integrations-dev/GitHub-Informer@v1 automates the integration between GitHub and Zoho Cliq, allowing users to send notifications about various GitHub events directly to their Cliq channels. It requires a webhook token and channel API endpoint or unique name, which can be added as a GitHub Secret. Users can customize messages for individual events or set a default message for all events. Additionally, it provides shortcuts to include variables like the event type, action, user, repository, branch/tag, workflow, etc., in their notifications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lincy-Zoho/GitHub-Informer-New">https://github.com/Lincy-Zoho/GitHub-Informer-New</a></strong> to version <strong>v1.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-informer-for-zoho-cliq">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action Integrations-dev/GitHub-Informer@v1 automates the integration between GitHub and Zoho Cliq, allowing users to send notifications about various GitHub events directly to their Cliq channels. It requires a webhook token and channel API endpoint or unique name, which can be added as a GitHub Secret. Users can customize messages for individual events or set a default message for all events. Additionally, it provides shortcuts to include variables like the event type, action, user, repository, branch/tag, workflow, etc., in their notifications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update GitHub_Informer_New.java (0bbed3c)</li>
<li>Add pull request diff URL to review gate methods (22547d7)</li>
<li>Update GitHub_Informer_New.java (8a674bb)</li>
<li>Update GitHub_Informer_New.java (24d288a)</li>
<li>Update GitHub_Informer_New.java (4833589)</li>
<li>Enhance AI review response format and details (cc649e1)</li>
<li>Update GitHub_Informer_New.java (0331161)</li>
<li>Enhance AI Review Gate functionality with new methods (6d6d746)</li>
<li>Update action.yml (e011286)</li>
<li>Update GitHub_Informer_New.java (58e180d)</li>
</ul>
]]></content:encoded></item><item><title>Lineaje Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/lineaje-scan/</link><pubDate>Sat, 08 Aug 2026 06:14:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/lineaje-scan/</guid><description>Version updated for https://github.com/lineaje-actions/lineaje-actions to version v1.11.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Lineaje Scan Action automates the scanning of container images and source code for vulnerabilities using the Lineaje platform. It prints a vulnerability summary and generates a fix plan when requested, allowing users to rebuild and rescan images to verify fixes. The action supports various programming languages and can scan both Dockerfile-based and source-based projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lineaje-actions/lineaje-actions">https://github.com/lineaje-actions/lineaje-actions</a></strong> to version <strong>v1.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lineaje-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Lineaje Scan Action automates the scanning of container images and source code for vulnerabilities using the Lineaje platform. It prints a vulnerability summary and generates a fix plan when requested, allowing users to rebuild and rescan images to verify fixes. The action supports various programming languages and can scan both Dockerfile-based and source-based projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: enhance input options for scan action and remove deprecated inputs (66d6e85)</li>
<li>pin CycloneDX (bed56ea)</li>
<li>update dotnet workflow (5a27cb3)</li>
<li>feat: rust support (c62e2f2)</li>
<li>added option to test in other envs (f4f86d0)</li>
<li>feat: add gos_mode input for GOS premium registry configuration (7ff2ecc)</li>
<li>Merge branch &lsquo;main&rsquo; of <a href="https://github.com/lineaje-com/lineaje-scan-action">https://github.com/lineaje-com/lineaje-scan-action</a> (295d2be)</li>
<li>Merge pull request #2 from lineaje-com/fix/data-svc-attempts (c4077d8)</li>
<li>Merge branch &lsquo;main&rsquo; of <a href="https://github.com/lineaje-com/lineaje-scan-action">https://github.com/lineaje-com/lineaje-scan-action</a> (96201f1)</li>
<li>Merge branch &lsquo;main&rsquo; of <a href="https://github.com/lineaje-com/lineaje-scan-action">https://github.com/lineaje-com/lineaje-scan-action</a> (b4eb2d8)</li>
</ul>
]]></content:encoded></item><item><title>OSS Security Policy as Code</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/oss-security-policy-as-code/</link><pubDate>Sat, 08 Aug 2026 06:13:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/oss-security-policy-as-code/</guid><description>Version updated for https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit to version v10.0.8.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary oss-policy-kit is a tool that evaluates OSS repositories against security policies using local files and evidence, generating Markdown, JSON, and SARIF reports. It provides detailed assurance grades based on the type of verification (deterministic, signal, or evidence-backed) and supports various report formats for both human review and automation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit">https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit</a></strong> to version <strong>v10.0.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oss-security-policy-as-code">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>oss-policy-kit</code> is a tool that evaluates OSS repositories against security policies using local files and evidence, generating Markdown, JSON, and SARIF reports. It provides detailed assurance grades based on the type of verification (deterministic, signal, or evidence-backed) and supports various report formats for both human review and automation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="oss-security-policy-as-code-starter-kit-v1008">OSS Security Policy as Code Starter Kit v10.0.8</h2>
<p>Housekeeping. A full X-ray of the project closed the items it left open, and three of them turned out not to be what the internal register said they were.</p>
<p><strong>Nothing about how the kit evaluates changed.</strong> No control verdict, no <code>summary_by_status</code>, no <code>results_digest</code>, no <code>reports/2.0</code> or <code>findings/1.0</code> shape, and no exit code for a valid run moves here. Upgrading from v10.0.7 requires no action.</p>
<hr>
<h2 id="highlights">Highlights</h2>
<h3 id="two-control-states-reached-you-as-an-undocumented-value">Two control states reached you as an undocumented value</h3>
<p><code>map_status_to_reports_v2</code> ends in a defensive fallback that returns <code>UNKNOWN</code> with <code>reason: &quot;unmapped-source-status&quot;</code> for a status it does not recognise. That value appears in no document, no schema and no <code>--help</code> output, so anyone who received it had nothing to act on.</p>
<p><code>ControlStatus</code> has nine members and the mapping covered seven. <code>NOT_EVALUATED</code> and <code>NOT_OBSERVABLE</code> fell through. <code>NOT_EVALUATED</code> is returned by evaluators across five modules — <code>OSS-SCORECARD-001</code> uses it whenever no Scorecard JSON is supplied — so an ordinary run was enough to put the undocumented discriminator into a report.</p>
<p>Both are now mapped, and the distinction is kept rather than collapsed:</p>
<table>
  <thead>
      <tr>
          <th>Status</th>
          <th>Reported as</th>
          <th>Meaning</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>not-evaluated</code></td>
          <td><code>UNKNOWN</code> / <code>reason: &quot;not-evaluated&quot;</code></td>
          <td>An input was not supplied, so no verdict was attempted. Supplying it changes the outcome.</td>
      </tr>
      <tr>
          <td><code>not-observable</code></td>
          <td><code>UNKNOWN</code> / <code>reason: &quot;not-observable-in-clone&quot;</code></td>
          <td>The fact sits structurally outside a clone. No input resolves it.</td>
      </tr>
  </tbody>
</table>
<p><code>docs/reports-contract-v2.0.md</code> now lists every <code>reason</code> value, and states plainly that <code>unmapped-source-status</code> reaching a report is a defect in the kit rather than a statement about your repository.</p>
<hr>
<h2 id="improvements">Improvements</h2>
<ul>
<li><strong>Waiver documentation named the wrong key.</strong> Five places taught <code>expires_on</code> as the key to use — the example and the sentence beneath it in <code>docs/iac-terraform.md</code>, the edit hint in the quickstart, and the remediation message of the Bicep, CloudFormation and Pulumi evaluators. The canonical key is <code>expires_at</code>. <code>expires_on</code> remains accepted, verified by writing a waiver with each spelling and confirming both apply, so existing files keep working.</li>
<li><strong><code>init</code> carried a second copy of the stack-label map.</strong> It had already drifted from the one in <code>profile_hints</code>, the module that emits those signals: one knew <code>container_docker</code>, the other knew <code>node_lockfile</code>, so the stack a repository was reported to use depended on which module answered. There is now one source, and a test that pins the container label so a Dockerfile-only repository is still named.</li>
</ul>
<h2 id="internal">Internal</h2>
<p>These change no shipped behaviour, but they are why the release exists.</p>
<ul>
<li>The packaging test compared the two template copies byte for byte, so its verdict depended on the checkout rather than on content. It now compares content, with a separate assertion that the shipped copy is LF — the wheel is still held to the stricter rule.</li>
<li><code>api.deps.dev</code> is reachable from the dependency-review job. That check had been passing for months without ever exercising its own network path, because no pull request had added a dependency for it to look up.</li>
<li>Three guards were added, each mutation-tested: every <code>ControlStatus</code> must be mapped and both copies of the map must agree; the stack labels must have one source; and the template comparison must still fail on real drift.</li>
</ul>
<h2 id="security">Security</h2>
<p>No vulnerability is fixed in this release. Release artifacts are unchanged in shape: signed wheel and sdist, CycloneDX SBOM, in-toto provenance attestation.</p>
<p>The dependency-review job carries a named allowance for three advisories against <code>mcp 1.23.3</code>, a transitive dependency of semgrep. It is scoped to those three advisory IDs rather than lowering the severity threshold, so every other vulnerable package still fails the gate. semgrep pins <code>mcp</code> exactly, so no upgrade exists; the allowance is removed as soon as semgrep depends on <code>mcp &gt;= 1.28.1</code>.</p>
<h2 id="upgrading">Upgrading</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>pip install --upgrade oss-policy-kit
</span></span></code></pre></div><p>No migration is required from v10.0.7.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit/compare/v10.0.7...v10.0.8">https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit/compare/v10.0.7...v10.0.8</a></p>
]]></content:encoded></item><item><title>SecondBrainAction</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/secondbrainaction/</link><pubDate>Sat, 08 Aug 2026 06:12:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/secondbrainaction/</guid><description>Version updated for https://github.com/mcasperson/SecondBrain to version +run3081-attempt1.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates retrieval and analysis of data from multiple external sources using Large Language Models (LLMs). It uses Retrieval Augmented Generation (RAG) techniques to filter and query data based on keywords, providing insights and summaries from various data sources. This is particularly useful for generating reports, summaries, and insights from disconnected and diverse datasets.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcasperson/SecondBrain">https://github.com/mcasperson/SecondBrain</a></strong> to version <strong>+run3081-attempt1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/secondbrainaction">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates retrieval and analysis of data from multiple external sources using Large Language Models (LLMs). It uses Retrieval Augmented Generation (RAG) techniques to filter and query data based on keywords, providing insights and summaries from various data sources. This is particularly useful for generating reports, summaries, and insights from disconnected and diverse datasets.</p>
]]></content:encoded></item><item><title>QHSE Professionals CI/CD Run ATF Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/qhse-professionals-ci/cd-run-atf-test-suite/</link><pubDate>Sat, 08 Aug 2026 06:11:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/qhse-professionals-ci/cd-run-atf-test-suite/</guid><description>Version updated for https://github.com/mikevdberge/sncicd-tests-run to version 1.0.14.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running automated test suites in ServiceNow using Basic or API Key authentication, allowing users to define test parameters such as browser name, version, operating system, and test suite details. It helps streamline the CI/CD process by enabling developers to execute tests in different environments with ease.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikevdberge/sncicd-tests-run">https://github.com/mikevdberge/sncicd-tests-run</a></strong> to version <strong>1.0.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qhse-professionals-ci-cd-run-atf-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running automated test suites in ServiceNow using Basic or API Key authentication, allowing users to define test parameters such as browser name, version, operating system, and test suite details. It helps streamline the CI/CD process by enabling developers to execute tests in different environments with ease.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.13...1.0.14">https://github.com/mikevdberge/sncicd-tests-run/compare/1.0.13...1.0.14</a></p>
]]></content:encoded></item><item><title>Upload to Nexus Mods</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/upload-to-nexus-mods/</link><pubDate>Sat, 08 Aug 2026 06:10:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/upload-to-nexus-mods/</guid><description>Version updated for https://github.com/Nexus-Mods/upload-action to version v1.0.0-beta.10.
This action is used across all versions by 79 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading a new version of a file to NexusMods using the Nexus Mods v3 API. It solves the problem of manually managing file uploads, simplifying the release process by integrating with CI/CD workflows. Key capabilities include uploading files, setting version details, and handling various upload options such as archiving existing versions and enabling mod manager downloads.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nexus-Mods/upload-action">https://github.com/Nexus-Mods/upload-action</a></strong> to version <strong>v1.0.0-beta.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>79</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/upload-to-nexus-mods">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading a new version of a file to NexusMods using the Nexus Mods v3 API. It solves the problem of manually managing file uploads, simplifying the release process by integrating with CI/CD workflows. Key capabilities include uploading files, setting version details, and handling various upload options such as archiving existing versions and enabling mod manager downloads.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: adding the add changelog endpoint to the action by @ashleynexusmods in <a href="https://github.com/Nexus-Mods/upload-action/pull/32">https://github.com/Nexus-Mods/upload-action/pull/32</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Nexus-Mods/upload-action/compare/v1.0.0-beta.9...v1.0.0-beta.10">https://github.com/Nexus-Mods/upload-action/compare/v1.0.0-beta.9...v1.0.0-beta.10</a></p>
]]></content:encoded></item><item><title>Allure Notifications</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/allure-notifications/</link><pubDate>Sat, 08 Aug 2026 06:09:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/allure-notifications/</guid><description>Version updated for https://github.com/qa-guru/allure-notifications to version v6.0.13.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically generates Allure reports and sends them to a Telegram channel using a shared configuration. It provides three variants: a Marketplace Action, a Native npm CLI, and an Allure plugin capability. The action supports both dry-run and live modes, where live mode requires specific environment variables for authentication.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/qa-guru/allure-notifications">https://github.com/qa-guru/allure-notifications</a></strong> to version <strong>v6.0.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/allure-notifications">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically generates Allure reports and sends them to a Telegram channel using a shared configuration. It provides three variants: a Marketplace Action, a Native npm CLI, and an Allure plugin capability. The action supports both dry-run and live modes, where live mode requires specific environment variables for authentication.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="github-marketplace-action">GitHub Marketplace Action</h2>
<ul>
<li>Adds the root <code>qa-guru/allure-notifications@v6</code> composite Action for sending from an existing Allure report.</li>
<li>Adds in-memory CLI overrides for report/results paths, project, and report/dashboard/TestOps/build links.</li>
<li>Resolves override paths from the consumer workspace or <code>working-directory</code>; static config paths keep config-relative semantics.</li>
<li>Removes consumer runtime JSON rendering and the legacy double-generate runnable workflow from the primary path.</li>
</ul>
<h2 id="verified">Verified</h2>
<ul>
<li>Action E2E: <a href="https://github.com/qa-guru/allure-notifications/actions/runs/31217764924">https://github.com/qa-guru/allure-notifications/actions/runs/31217764924</a></li>
<li>TypeScript CI: <a href="https://github.com/qa-guru/allure-notifications/actions/runs/31217766066">https://github.com/qa-guru/allure-notifications/actions/runs/31217766066</a></li>
<li>npm: <code>allure-notifications@6.0.13</code> and coordinated <code>@allure-notifications/{config,pyramid,core,plugin}@6.0.13</code></li>
<li>Pipeline contract: tests → allure-results → one <code>allure generate</code> → Action send</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/qa-guru/allure-notifications/compare/v6.0.12...v6.0.13">https://github.com/qa-guru/allure-notifications/compare/v6.0.12...v6.0.13</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/custom-amazon-bedrock-agent-action/</link><pubDate>Sat, 08 Aug 2026 06:07:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in pull requests and provide feedback by leveraging a system prompt that defines the foundational behavior and knowledge base. It supports customizable prompts, file ignoring using .gitignore, and integrates with Amazon Bedrock Knowledge Bases for context-aware insights, enhancing analysis capabilities for code quality improvement, security assessments, and performance optimizations. The action is tailored for various use cases beyond code review, such as security and compliance assessments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in pull requests and provide feedback by leveraging a system prompt that defines the foundational behavior and knowledge base. It supports customizable prompts, file ignoring using <code>.gitignore</code>, and integrates with Amazon Bedrock Knowledge Bases for context-aware insights, enhancing analysis capabilities for code quality improvement, security assessments, and performance optimizations. The action is tailored for various use cases beyond code review, such as security and compliance assessments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/sherpa.sh/</link><pubDate>Sat, 08 Aug 2026 06:07:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI tool designed to automate the deployment of applications across different cloud providers. It simplifies the process of setting up and managing infrastructure by providing clear instructions in plain English, allowing developers to focus on writing their code rather than dealing with complex configuration files or understanding vendor-specific tools. The action supports a wide range of cloud platforms, frameworks, and requirements through its user-friendly interface and powerful AI capabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI tool designed to automate the deployment of applications across different cloud providers. It simplifies the process of setting up and managing infrastructure by providing clear instructions in plain English, allowing developers to focus on writing their code rather than dealing with complex configuration files or understanding vendor-specific tools. The action supports a wide range of cloud platforms, frameworks, and requirements through its user-friendly interface and powerful AI capabilities.</p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/ssg-static-site-generator/</link><pubDate>Sat, 08 Aug 2026 06:06:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.21.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that transforms Markdown content with YAML frontmatter into a complete website, including features like clean URLs, templates, feeds, search, image processing, and native deployment to various platforms. It supports multiple template engines and provides options for SEO metadata, webp conversion, and responsive images. The action is designed to automate the creation and management of static websites efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.21</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that transforms Markdown content with YAML frontmatter into a complete website, including features like clean URLs, templates, feeds, search, image processing, and native deployment to various platforms. It supports multiple template engines and provides options for SEO metadata, webp conversion, and responsive images. The action is designed to automate the creation and management of static websites efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.21 — fix format: feed over HTTP, show an aggregated feed, document declared feeds (#90–#93) by @spagu in <a href="https://github.com/spagu/ssg/pull/94">https://github.com/spagu/ssg/pull/94</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.20...v1.8.21">https://github.com/spagu/ssg/compare/v1.8.20...v1.8.21</a></p>
]]></content:encoded></item><item><title>Fastlane-AI-Changelog</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/fastlane-ai-changelog/</link><pubDate>Sat, 08 Aug 2026 06:04:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/fastlane-ai-changelog/</guid><description>Version updated for https://github.com/SwufeFox/Fastlane-AI-Changelog to version v1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates user-friendly update notes (What’s New) for Android apps and writes them directly into the Fastlane metadata directory using AI. It supports OpenAI and other compatible models, allowing for seamless integration with Google Play and Fastlane workflows. The action extracts commit messages in full detail, provides smart range selection, and ensures content is concise within specified character limits, supporting multiple languages.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SwufeFox/Fastlane-AI-Changelog">https://github.com/SwufeFox/Fastlane-AI-Changelog</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fastlane-ai-changelog">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates user-friendly update notes (What&rsquo;s New) for Android apps and writes them directly into the Fastlane metadata directory using AI. It supports OpenAI and other compatible models, allowing for seamless integration with Google Play and Fastlane workflows. The action extracts commit messages in full detail, provides smart range selection, and ensures content is concise within specified character limits, supporting multiple languages.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update action.yml (1042df5)</li>
<li>Update action.yml (7cd9dfb)</li>
<li>Update action.yml (cbb5601)</li>
<li>Update action.yml (433c899)</li>
<li>Update action.yml (79084b5)</li>
<li>Update action.yml (abd0032)</li>
<li>Update action.yml (9993464)</li>
<li>Update action.yml (2d49ca8)</li>
<li>Update action.yml (532ca98)</li>
<li>Create update-semver.yml (fa09b66)</li>
</ul>
]]></content:encoded></item><item><title>Terraform Module Releaser</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/terraform-module-releaser/</link><pubDate>Sat, 08 Aug 2026 06:03:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/terraform-module-releaser/</guid><description>Version updated for https://github.com/techpivot/terraform-module-releaser to version v2.2.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 33 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the management of Terraform modules within a monorepo, providing features like efficient module tagging, smart versioning, comprehensive wiki generation, release automation, and self-maintenance. It simplifies the process of maintaining Terraform modules by automating tasks such as generating Git tags, creating releases, and updating documentation. The action works seamlessly with GitHub.com and GHES environments, ensuring a smooth transition between cloud and on-premises deployments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/techpivot/terraform-module-releaser">https://github.com/techpivot/terraform-module-releaser</a></strong> to version <strong>v2.2.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>33</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/terraform-module-releaser">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the management of Terraform modules within a monorepo, providing features like efficient module tagging, smart versioning, comprehensive wiki generation, release automation, and self-maintenance. It simplifies the process of maintaining Terraform modules by automating tasks such as generating Git tags, creating releases, and updating documentation. The action works seamlessly with GitHub.com and GHES environments, ensuring a smooth transition between cloud and on-premises deployments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="-new-features">✨ New Features</h3>
<ul>
<li>
<p><strong>Self-Healing, Idempotent Releases</strong> 🔁: Re-running a merged workflow now converges to the correct state instead of guessing. Previously the entire merge handler was gated on a single hidden marker in a pull request comment, which meant a deleted release could never be restored and a run that died between pushing a tag and creating its release was unrecoverable. Release state now lives in the release itself. @virgofx (#503)</p>
<ul>
<li>A re-run never over-bumps a version or publishes a duplicate release.</li>
<li>A release you delete by hand is recreated at its original version, not a new one.</li>
<li>A run interrupted between the tag push and the release creation is repaired on re-run.</li>
<li>A tag that cannot be proven to belong to the current pull request is never claimed; it is left for its owning pull request to heal while the current one releases above it.</li>
<li><code>changed-modules-map</code> gains an <code>action</code> field (<code>created</code>, <code>recovered</code>, <code>skipped</code>, or <code>none</code>) so downstream jobs can tell a fresh release apart from a no-op.</li>
</ul>
</li>
<li>
<p><strong>Quieter Pull Requests With No Changes</strong> 🔇: New <code>hide-no-changes-pr-comment</code> input. When enabled, the &ldquo;Release Plan&rdquo; comment is collapsed rather than posted loudly on pull requests that change no Terraform modules, have no pending tag or release cleanup, and pass the wiki check. Defaults to <code>false</code>, so existing behavior is unchanged. @leetrout (#470)</p>
</li>
</ul>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li>
<p><strong>Module terraform-docs Config Honored</strong> 📄: Module-scoped <code>.terraform-docs.yml</code> files are now discovered and merged with the action&rsquo;s wiki-safe defaults instead of being removed from the workspace, so your formatting and content settings survive wiki generation. @virgofx (#430)</p>
</li>
<li>
<p><strong>Wiki Validation Runs Before Merge</strong> ✅: Wiki checks now run as a real preflight on open pull requests, with checkout failures and terraform-docs failures reported separately and per-module errors surfaced directly in the pull request comment. Broken wiki configuration is caught while the pull request is still open rather than at merge time. @virgofx (#430)</p>
</li>
</ul>
<h3 id="-improvements">🛠 Improvements</h3>
<ul>
<li>
<p><strong>Accurate Release Outputs</strong> 🎯: <code>changed-modules-map.releaseTag</code> now always names a tag that actually exists. Previously it reported the optimistically computed next version even when nothing was published, so downstream jobs could resolve a ref that was never created.</p>
</li>
<li>
<p><strong>Fewer API Calls On Open Pull Requests</strong> ⚡: Pull request comments are no longer paginated on every event. Open pull request runs read no comments at all, and the remaining reads request 100 per page instead of the default 30, which meaningfully reduces rate-limit pressure on high-traffic monorepos.</p>
</li>
</ul>
<h3 id="-dependencies">📦 Dependencies</h3>
<p>Consolidates 49 dependency updates (#431 through #501):</p>
<ul>
<li><strong>Security and runtime</strong>: <code>brace-expansion</code> 5.0.5 → 5.0.9, <code>qs</code> 6.15.0 → 6.15.2, <code>ip-address</code> and <code>express-rate-limit</code>, <code>which</code> 6 → 7, <code>js-yaml</code> 4.2.0 → 4.3.0, <code>conventional-commits-parser</code> 6.4.0 → 7.1.0, <code>@actions/core</code>, <code>fast-uri</code>, <code>minimatch</code>, <code>p-limit</code>.</li>
<li><strong>GitHub Actions</strong>: <code>actions/checkout</code> 6 → 7, <code>actions/setup-node</code> 6 → 7, <code>actions/github-script</code> 8 → 9, <code>github/codeql-action</code>, <code>super-linter/super-linter</code>, <code>SonarSource/sonarqube-scan-action</code> 7 → 8.</li>
<li><strong>Development tooling</strong>: TypeScript, Vitest, Biome, esbuild, <code>@types/node</code> 25 → 26, <code>ts-deepmerge</code> 7 → 8, <code>hono</code>.</li>
</ul>
<hr>
<h3 id="-upgrade-notes">📌 Upgrade Notes</h3>
<p>This release is backward compatible. No inputs changed, nothing was removed, and the action still runs on <code>node24</code>. Two behaviors are worth knowing about before you upgrade:</p>
<ol>
<li>
<p><strong><code>releaseTag</code> can now be <code>null</code>.</strong> On merge runs, <code>changed-modules-map</code> is re-emitted with what was actually published. When a module was skipped or nothing was released, <code>releaseTag</code> is <code>null</code> and <code>action</code> is <code>&quot;skipped&quot;</code> or <code>&quot;none&quot;</code>. If you consume this output, branch on <code>action</code> before treating <code>releaseTag</code> as a newly published tag:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>echo <span style="color:#e6db74">&#39;${{ steps.release.outputs.changed-modules-map }}&#39;</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  | jq -r <span style="color:#e6db74">&#39;to_entries[] | select(.value.action == &#34;created&#34;) | .value.releaseTag&#39;</span>
</span></span></code></pre></div></li>
<li>
<p><strong>Obsolete tag/release cleanup and wiki regeneration are now skipped when the checkout is stale.</strong> If the base branch advances past a pull request&rsquo;s merge commit before its workflow runs, those steps are skipped with a warning rather than operating on an out-of-date view of the repository. This prevents a re-run of an older pull request from deleting tags, releases, and wiki pages for modules added since. It is self-correcting on the next merge.</p>
</li>
</ol>
<h6 id="full-changelog">Full Changelog: <a href="https://github.com/techpivot/terraform-module-releaser/compare/v2.1.0...v2.2.0">https://github.com/techpivot/terraform-module-releaser/compare/v2.1.0...v2.2.0</a></h6>
]]></content:encoded></item><item><title>Advanced Jules PR Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/advanced-jules-pr-reviewer/</link><pubDate>Sat, 08 Aug 2026 06:02:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/advanced-jules-pr-reviewer/</guid><description>Version updated for https://github.com/thalesraymond/jules-pr-reviewer to version v1.5.0.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary A GitHub Action that uses Jules, a Gemini-powered cloud coding agent, to review pull requests and post comments on specific lines of code. It helps catch security flaws and provides inline comments, which can be resolved automatically if fixed. The action also allows for customization through inline rules or a rules file in the repository, enabling project-level or shared rule management.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thalesraymond/jules-pr-reviewer">https://github.com/thalesraymond/jules-pr-reviewer</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/advanced-jules-pr-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>A GitHub Action that uses Jules, a Gemini-powered cloud coding agent, to review pull requests and post comments on specific lines of code. It helps catch security flaws and provides inline comments, which can be resolved automatically if fixed. The action also allows for customization through inline rules or a rules file in the repository, enabling project-level or shared rule management.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="150-2026-08-07"><a href="https://github.com/thalesraymond/jules-pr-reviewer/compare/v1.4.0...v1.5.0">1.5.0</a> (2026-08-07)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>agent:</strong> add agentic mode (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/d7197be6ac8283b59a0040ce2b30117dfa6761f7">d7197be</a>), closes <a href="https://github.com/thalesraymond/jules-pr-reviewer/issues/103">#103</a></li>
<li>improve jules context (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/35aa78c765857cee34c5433dd45e31af8eec63bb">35aa78c</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>agentic mode:</strong> fix rule for retry/fallback (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/610befe96ae8edddbc46dab3ba763e3f34e43808">610befe</a>)</li>
<li><strong>agentic mode:</strong> small fixes (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/bdd27691509305fa3a51702ef1bc118226f6c028">bdd2769</a>)</li>
<li><strong>archive:</strong> make sure fallback sessions are also archived (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/71ea5b2bc8c5331bb36e80e8c6697b8adbe07169">71ea5b2</a>)</li>
<li>fixes agentic changes (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/759813a60ed01e71ff57ac1118ec44cdca8eb091">759813a</a>)</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/wails3-build-action/</link><pubDate>Sat, 08 Aug 2026 06:01:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action ToQuery/wails3-build-action automates the building of Wails projects using Go and Node.js. It installs these dependencies, builds the project according to specified configurations, and optionally uploads the results to GitHub or a release if it’s a tagged build. The action supports building for various platforms and includes options for obfuscation and customizing Node.js and Deno settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>ToQuery/wails3-build-action</code> automates the building of Wails projects using Go and Node.js. It installs these dependencies, builds the project according to specified configurations, and optionally uploads the results to GitHub or a release if it&rsquo;s a tagged build. The action supports building for various platforms and includes options for obfuscation and customizing Node.js and Deno settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Move Closed Issue to Top of Project Column</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/move-closed-issue-to-top-of-project-column/</link><pubDate>Sat, 08 Aug 2026 06:00:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/move-closed-issue-to-top-of-project-column/</guid><description>Version updated for https://github.com/wozaki/project-closed-issue-move-to-top-action to version v1.24.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically moves closed issues to the top of a specified column in a GitHub Project V2, ensuring recent closed issues are always visible at the top of your project board. It supports multiple projects with different configurations and requires a GitHub token with project scope.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wozaki/project-closed-issue-move-to-top-action">https://github.com/wozaki/project-closed-issue-move-to-top-action</a></strong> to version <strong>v1.24.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-closed-issue-to-top-of-project-column">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically moves closed issues to the top of a specified column in a GitHub Project V2, ensuring recent closed issues are always visible at the top of your project board. It supports multiple projects with different configurations and requires a GitHub token with project scope.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">wozaki/project-closed-issue-move-to-top-action@0979a6bd449b89bb55e7b9a4808a015e1d8f878a</span> <span style="color:#75715e"># v1.24.0</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/175">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/175</a></li>
<li>chore(deps): update node.js to v24.18.1 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/176">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/176</a></li>
<li>chore(deps): update int128/release-typescript-action action to v1.78.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/178">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/178</a></li>
<li>chore(deps): update pnpm to v11.19.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/177">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/177</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/179">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/179</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.23.0...v1.24.0">https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.23.0...v1.24.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/b.ia-accessibility-checker/</link><pubDate>Sat, 08 Aug 2026 05:59:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/08/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The B.IA GitHub Action enables accessibility checks in CI/CD pipelines by automatically evaluating code against WCAG guidelines based on specified audiences and percentages. It maps guidelines and uses AI to assess their impact, allowing companies to ensure compliance with accessibility standards more efficiently. The action automates the process of checking code for accessibility issues before merging changes into production, helping teams meet accessibility requirements effectively without extensive learning or additional tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The B.IA GitHub Action enables accessibility checks in CI/CD pipelines by automatically evaluating code against WCAG guidelines based on specified audiences and percentages. It maps guidelines and uses AI to assess their impact, allowing companies to ensure compliance with accessibility standards more efficiently. The action automates the process of checking code for accessibility issues before merging changes into production, helping teams meet accessibility requirements effectively without extensive learning or additional tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>FHIR Validation Markdown Renderer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/fhir-validation-markdown-renderer/</link><pubDate>Fri, 07 Aug 2026 22:45:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/fhir-validation-markdown-renderer/</guid><description>Version updated for https://github.com/patrick-werner/validation-outcome-markdown-renderer to version v1.5.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action parses a FHIR OperationOutcome bundle and emits annotations in the GitHub Checks UI for issues at or above the configured severity. It supports filtering out known issues using specified patterns in filename, messageId, details (with wildcard), and location, and generates a summary Markdown table in PR comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/patrick-werner/validation-outcome-markdown-renderer">https://github.com/patrick-werner/validation-outcome-markdown-renderer</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fhir-validation-markdown-renderer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action parses a FHIR <code>OperationOutcome</code> bundle and emits annotations in the GitHub Checks UI for issues at or above the configured severity. It supports filtering out known issues using specified patterns in filename, messageId, details (with wildcard), and location, and generates a summary Markdown table in PR comments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="150---2026-08-07">[1.5.0] - 2026-08-07</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>The action runs on the <code>node24</code> runtime instead of <code>node20</code>, which GitHub has
deprecated. Workflows keep working unchanged, but the runner has to be new enough to
provide Node 24: GitHub-hosted runners are, self-hosted runners need runner 2.327.1
or newer, and GitHub Enterprise Server needs 3.19 or newer. On an older runner the
step fails to start rather than falling back to Node 20.</li>
</ul>
]]></content:encoded></item><item><title>Pingram Send Email</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/pingram-send-email/</link><pubDate>Fri, 07 Aug 2026 22:44:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/pingram-send-email/</guid><description>Version updated for https://github.com/pingram-io/github-actions-send-email to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Pingram to send emails and SMS from workflows. It automates various notifications such as build failures, deployment statuses, and release notes, allowing you to configure recipients, subjects, and HTML bodies directly in your workflow YAML files without additional setup required. The action supports sending emails via the API key stored as a repository secret, with options for customization including sender details, reply-to addresses, and scheduled sends.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pingram-io/github-actions-send-email">https://github.com/pingram-io/github-actions-send-email</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pingram-send-email">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Pingram to send emails and SMS from workflows. It automates various notifications such as build failures, deployment statuses, and release notes, allowing you to configure recipients, subjects, and HTML bodies directly in your workflow YAML files without additional setup required. The action supports sending emails via the API key stored as a repository secret, with options for customization including sender details, reply-to addresses, and scheduled sends.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pingram-io/github-actions-send-email/commits/v1.0.0">https://github.com/pingram-io/github-actions-send-email/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Pingram Send SMS</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/pingram-send-sms/</link><pubDate>Fri, 07 Aug 2026 22:43:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/pingram-send-sms/</guid><description>Version updated for https://github.com/pingram-io/github-actions-send-sms to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sends SMS notifications using the Pingram API to notify on-call personnel, capture tracking IDs, and send media-only MMS. It supports sending SMS to individual or multiple recipients, scheduling sends, and logging tracking IDs for each notification. The action can be configured with various parameters such as API key, message content, recipient numbers, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pingram-io/github-actions-send-sms">https://github.com/pingram-io/github-actions-send-sms</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pingram-send-sms">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sends SMS notifications using the Pingram API to notify on-call personnel, capture tracking IDs, and send media-only MMS. It supports sending SMS to individual or multiple recipients, scheduling sends, and logging tracking IDs for each notification. The action can be configured with various parameters such as API key, message content, recipient numbers, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pingram-io/github-actions-send-sms/commits/v1.0.0">https://github.com/pingram-io/github-actions-send-sms/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Rust Lint Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/rust-lint-action/</link><pubDate>Fri, 07 Aug 2026 22:42:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/rust-lint-action/</guid><description>Version updated for https://github.com/Profiidev/rust-lint-action to version v4.3.1.
This action is used across all versions by 26 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Rust Lint Action automates the process of linting Rust code using Clippy. It helps developers maintain clean, error-free Rust projects by identifying potential issues and suggesting improvements in their codebase.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Profiidev/rust-lint-action">https://github.com/Profiidev/rust-lint-action</a></strong> to version <strong>v4.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>26</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rust-lint-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Rust Lint Action automates the process of linting Rust code using Clippy. It helps developers maintain clean, error-free Rust projects by identifying potential issues and suggesting improvements in their codebase.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Lint action version v4.3.1 has been released!</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: docker user by @Profiidev in <a href="https://github.com/Profiidev/rust-lint-action/pull/34">https://github.com/Profiidev/rust-lint-action/pull/34</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/35">https://github.com/Profiidev/rust-lint-action/pull/35</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/36">https://github.com/Profiidev/rust-lint-action/pull/36</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/37">https://github.com/Profiidev/rust-lint-action/pull/37</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/38">https://github.com/Profiidev/rust-lint-action/pull/38</a></li>
<li>chore(deps): update all digest updates by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/39">https://github.com/Profiidev/rust-lint-action/pull/39</a></li>
<li>chore(deps): update all non-major dependencies by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/40">https://github.com/Profiidev/rust-lint-action/pull/40</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/41">https://github.com/Profiidev/rust-lint-action/pull/41</a></li>
<li>fix: svelte check warnings ignored by @Profiidev in <a href="https://github.com/Profiidev/rust-lint-action/pull/42">https://github.com/Profiidev/rust-lint-action/pull/42</a></li>
<li>Release version v4.3.1 by @profidev-commit-bot[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/43">https://github.com/Profiidev/rust-lint-action/pull/43</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Profiidev/rust-lint-action/compare/v4.3.0...v4.3.1">https://github.com/Profiidev/rust-lint-action/compare/v4.3.0...v4.3.1</a></p>
]]></content:encoded></item><item><title>Garita PII Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/garita-pii-guard/</link><pubDate>Fri, 07 Aug 2026 22:42:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/garita-pii-guard/</guid><description>Version updated for https://github.com/proscar87/garita to version v0.26.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Garita is an action designed to prevent personal and sensitive data from entering your repository by detecting patterns that match known identifiers such as CURP, RFC, CLABE, CPF, CUIT, RUT, DNI, IBAN, etc. It uses a YAML configuration file to specify which patterns are considered potentially sensitive, allowing you to control what is protected while still maintaining flexibility for testing and development purposes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/proscar87/garita">https://github.com/proscar87/garita</a></strong> to version <strong>v0.26.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/garita-pii-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Garita is an action designed to prevent personal and sensitive data from entering your repository by detecting patterns that match known identifiers such as CURP, RFC, CLABE, CPF, CUIT, RUT, DNI, IBAN, etc. It uses a YAML configuration file to specify which patterns are considered potentially sensitive, allowing you to control what is protected while still maintaining flexibility for testing and development purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Usar Garita en un repositorio real <strong>implica</strong> tener exenciones: siempre hay datos que sí deben estar ahí —un catálogo público, los vectores oficiales de un validador, las actas donde alguien aparece por su cargo—. El reporte ya decía «exenta el archivo CON SU MOTIVO», pero no decía cómo, y escribir el YAML de memoria es fricción; la fricción termina en «mejor apago el paso».</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>garita --proponer-exenciones     <span style="color:#75715e"># escribe el bloque; el motivo lo escribes tú</span>
</span></span></code></pre></div><p>Imprime el bloque listo para pegar, agrupado por archivo y acotado a los detectores que dispararon, <strong>con el motivo en blanco</strong>.</p>
<p>Lo importante es que el circuito ya cerraba solo: <strong>un motivo vacío es código 2</strong>, así que el esqueleto no se puede pegar y olvidar — detiene a Garita en vez de callarla. Quien lo llena está escribiendo la justificación que dentro de un año permitirá evaluar si la exención sigue valiendo.</p>
<p>No imprime ningún valor (la exención se define por archivo y detector), y no se combina con <code>--historial</code>, <code>--linea-base</code> ni los formatos de documento: como <code>--explicar</code>, rechaza con 2 lo que no va a cumplir.</p>
<p>Seis pruebas nuevas (276 en total).</p>
]]></content:encoded></item><item><title>YourTomo</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/yourtomo/</link><pubDate>Fri, 07 Aug 2026 22:41:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/yourtomo/</guid><description>Version updated for https://github.com/prsdx/YourTomo to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary YourTomo is a GitHub Action that automates the creation of animated SVGs that represent your GitHub activity, including contributions, push streaks, and more. It provides customizable visualizations like a pixel cat to enhance your GitHub profile, helping users stay engaged with their repositories through regular updates. The action supports various states and conditions to dynamically change the appearance of the cat based on your activity data.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prsdx/YourTomo">https://github.com/prsdx/YourTomo</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yourtomo">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>YourTomo is a GitHub Action that automates the creation of animated SVGs that represent your GitHub activity, including contributions, push streaks, and more. It provides customizable visualizations like a pixel cat to enhance your GitHub profile, helping users stay engaged with their repositories through regular updates. The action supports various states and conditions to dynamically change the appearance of the cat based on your activity data.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: force-state input to preview any pet state on demand (988c75e)</li>
<li>Prune extra summary-card themes [skip ci] (8f5abd4)</li>
<li>Generate profile summary cards (6b58bac)</li>
<li>Update pet state [skip ci] (46d0c27)</li>
<li>Remove &lsquo;See it alive&rsquo; section from README (2629999)</li>
<li>docs: restructure README, add gallery, fix branding consistency (231a69e)</li>
<li>fix: unique action name for Marketplace (6c5cd24)</li>
<li>fix: unique action name for Marketplace (8e900a0)</li>
<li>fix: unique action name and shorten description for Marketplace (be8d0dd)</li>
<li>fix: use valid Marketplace branding color (3ce9582)</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/kaniko-build-action/</link><pubDate>Fri, 07 Aug 2026 22:39:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or “Hello” + a specified name to the log. It solves the problem of automating the greeting process, which can be useful for testing and documentation purposes.
What’s Changed My first action is ready (5619594) Initial commit (2a56a2a)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or &ldquo;Hello&rdquo; + a specified name to the log. It solves the problem of automating the greeting process, which can be useful for testing and documentation purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>list-changed-directories</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/list-changed-directories/</link><pubDate>Fri, 07 Aug 2026 22:38:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/list-changed-directories/</guid><description>Version updated for https://github.com/sankichi92/list-changed-directories to version v1.2.3.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action list-changed-directories outputs a list of directories that have changed and include a specified target file. It automates the execution of jobs only on directories that have changed, solving challenges with GitHub Actions’ matrix and event limitations. The action works for push and pull_request events and requires providing a target filename and paths to files that all directories including the target file depend on.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sankichi92/list-changed-directories">https://github.com/sankichi92/list-changed-directories</a></strong> to version <strong>v1.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/list-changed-directories">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>list-changed-directories</code> outputs a list of directories that have changed and include a specified target file. It automates the execution of jobs only on directories that have changed, solving challenges with GitHub Actions&rsquo; matrix and event limitations. The action works for <code>push</code> and <code>pull_request</code> events and requires providing a target filename and paths to files that all directories including the target file depend on.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump @actions/core from 3.0.0 to 3.0.1 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/395">https://github.com/sankichi92/list-changed-directories/pull/395</a></li>
<li>Bump @actions/github from 9.1.0 to 9.1.1 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/396">https://github.com/sankichi92/list-changed-directories/pull/396</a></li>
<li>Bump @vercel/ncc from 0.38.4 to 0.44.1 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/431">https://github.com/sankichi92/list-changed-directories/pull/431</a></li>
</ul>
<details>
<summary>Development environment changes</summary>
<ul>
<li>Bump dependabot/fetch-metadata from 3.0.0 to 3.1.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/389">https://github.com/sankichi92/list-changed-directories/pull/389</a></li>
<li>Bump pnpm/action-setup from 6.0.0 to 6.0.3 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/391">https://github.com/sankichi92/list-changed-directories/pull/391</a></li>
<li>Bump eslint from 10.2.0 to 10.2.1 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/392">https://github.com/sankichi92/list-changed-directories/pull/392</a></li>
<li>Bump prettier from 3.8.1 to 3.8.3 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/393">https://github.com/sankichi92/list-changed-directories/pull/393</a></li>
<li>Bump typescript-eslint from 8.58.0 to 8.59.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/394">https://github.com/sankichi92/list-changed-directories/pull/394</a></li>
<li>Bump actions/setup-node from 6.3.0 to 6.4.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/390">https://github.com/sankichi92/list-changed-directories/pull/390</a></li>
<li>Bump typescript-eslint from 8.59.0 to 8.59.1 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/397">https://github.com/sankichi92/list-changed-directories/pull/397</a></li>
<li>Update pnpm to v10.33.2 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/398">https://github.com/sankichi92/list-changed-directories/pull/398</a></li>
<li>Bump pnpm/action-setup from 6.0.3 to 6.0.5 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/399">https://github.com/sankichi92/list-changed-directories/pull/399</a></li>
<li>Update pnpm to v10.33.3 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/400">https://github.com/sankichi92/list-changed-directories/pull/400</a></li>
<li>Update pnpm to v11 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/401">https://github.com/sankichi92/list-changed-directories/pull/401</a></li>
<li>Bump pnpm/action-setup from 6.0.5 to 6.0.8 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/402">https://github.com/sankichi92/list-changed-directories/pull/402</a></li>
<li>Bump typescript-eslint from 8.59.1 to 8.59.3 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/403">https://github.com/sankichi92/list-changed-directories/pull/403</a></li>
<li>Bump globals from 17.5.0 to 17.6.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/405">https://github.com/sankichi92/list-changed-directories/pull/405</a></li>
<li>Update pnpm to v11.0.9 - autoclosed by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/406">https://github.com/sankichi92/list-changed-directories/pull/406</a></li>
<li>Update pnpm to v11.1.1 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/407">https://github.com/sankichi92/list-changed-directories/pull/407</a></li>
<li>Bump eslint from 10.2.1 to 10.3.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/404">https://github.com/sankichi92/list-changed-directories/pull/404</a></li>
<li>Bump typescript-eslint from 8.59.3 to 8.59.4 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/408">https://github.com/sankichi92/list-changed-directories/pull/408</a></li>
<li>Update pnpm to v11.1.3 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/410">https://github.com/sankichi92/list-changed-directories/pull/410</a></li>
<li>Bump eslint from 10.3.0 to 10.4.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/409">https://github.com/sankichi92/list-changed-directories/pull/409</a></li>
<li>Bump typescript-eslint from 8.59.4 to 8.60.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/411">https://github.com/sankichi92/list-changed-directories/pull/411</a></li>
<li>Update pnpm to v11.3.0 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/412">https://github.com/sankichi92/list-changed-directories/pull/412</a></li>
<li>Bump actions/checkout from 6.0.2 to 6.0.3 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/413">https://github.com/sankichi92/list-changed-directories/pull/413</a></li>
<li>Bump typescript-eslint from 8.60.0 to 8.60.1 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/414">https://github.com/sankichi92/list-changed-directories/pull/414</a></li>
<li>Bump eslint from 10.4.0 to 10.4.1 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/415">https://github.com/sankichi92/list-changed-directories/pull/415</a></li>
<li>Update pnpm to v11.5.1 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/416">https://github.com/sankichi92/list-changed-directories/pull/416</a></li>
<li>Bump typescript-eslint from 8.60.1 to 8.61.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/417">https://github.com/sankichi92/list-changed-directories/pull/417</a></li>
<li>Update pnpm to v11.5.2 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/418">https://github.com/sankichi92/list-changed-directories/pull/418</a></li>
<li>Bump pnpm/action-setup from 6.0.8 to 6.0.9 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/419">https://github.com/sankichi92/list-changed-directories/pull/419</a></li>
<li>Bump eslint from 10.4.1 to 10.5.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/420">https://github.com/sankichi92/list-changed-directories/pull/420</a></li>
<li>Bump prettier from 3.8.3 to 3.8.4 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/421">https://github.com/sankichi92/list-changed-directories/pull/421</a></li>
<li>Bump typescript-eslint from 8.61.0 to 8.61.1 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/423">https://github.com/sankichi92/list-changed-directories/pull/423</a></li>
<li>Update pnpm to v11.5.3 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/424">https://github.com/sankichi92/list-changed-directories/pull/424</a></li>
<li>Update pnpm to v11.7.0 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/425">https://github.com/sankichi92/list-changed-directories/pull/425</a></li>
<li>Update pnpm to v11.8.0 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/427">https://github.com/sankichi92/list-changed-directories/pull/427</a></li>
<li>Bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/426">https://github.com/sankichi92/list-changed-directories/pull/426</a></li>
<li>Bump globals from 17.6.0 to 17.7.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/428">https://github.com/sankichi92/list-changed-directories/pull/428</a></li>
<li>Bump eslint from 10.5.0 to 10.6.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/430">https://github.com/sankichi92/list-changed-directories/pull/430</a></li>
<li>Update pnpm to v11.9.0 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/432">https://github.com/sankichi92/list-changed-directories/pull/432</a></li>
<li>Bump prettier from 3.8.4 to 3.9.4 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/433">https://github.com/sankichi92/list-changed-directories/pull/433</a></li>
<li>Update pnpm to v11.10.0 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/435">https://github.com/sankichi92/list-changed-directories/pull/435</a></li>
<li>Bump prettier from 3.9.4 to 3.9.5 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/437">https://github.com/sankichi92/list-changed-directories/pull/437</a></li>
<li>Bump eslint from 10.6.0 to 10.7.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/439">https://github.com/sankichi92/list-changed-directories/pull/439</a></li>
<li>Update pnpm to v11.11.0 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/440">https://github.com/sankichi92/list-changed-directories/pull/440</a></li>
<li>Bump actions/setup-node from 6.4.0 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/436">https://github.com/sankichi92/list-changed-directories/pull/436</a></li>
<li>Bump actions/checkout from 7.0.0 to 7.0.1 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/441">https://github.com/sankichi92/list-changed-directories/pull/441</a></li>
<li>Update pnpm to v11.15.1 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/442">https://github.com/sankichi92/list-changed-directories/pull/442</a></li>
<li>Bump globals from 17.7.0 to 17.8.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/443">https://github.com/sankichi92/list-changed-directories/pull/443</a></li>
<li>Bump typescript-eslint from 8.61.1 to 8.65.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/445">https://github.com/sankichi92/list-changed-directories/pull/445</a></li>
<li>Update pnpm to v11.17.0 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/446">https://github.com/sankichi92/list-changed-directories/pull/446</a></li>
<li>Bump pnpm/action-setup from 6.0.9 to 6.0.10 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/447">https://github.com/sankichi92/list-changed-directories/pull/447</a></li>
<li>Bump typescript-eslint from 8.65.0 to 8.66.0 by @dependabot[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/448">https://github.com/sankichi92/list-changed-directories/pull/448</a></li>
<li>Update pnpm to v11.20.0 by @renovate[bot] in <a href="https://github.com/sankichi92/list-changed-directories/pull/449">https://github.com/sankichi92/list-changed-directories/pull/449</a></li>
</ul>
</details>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sankichi92/list-changed-directories/compare/v1.2.2...v1.2.3">https://github.com/sankichi92/list-changed-directories/compare/v1.2.2...v1.2.3</a></p>
]]></content:encoded></item><item><title>Tangled Mirror</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/tangled-mirror/</link><pubDate>Fri, 07 Aug 2026 22:37:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/tangled-mirror/</guid><description>Version updated for https://github.com/sethcottle/tangled-mirror to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Tangled Mirror GitHub Action keeps a Tangled repo in sync with one that lives on GitHub. It checks the knot’s host key, sends only the refs it asks for, and won’t delete anything unless told to. The action requires an SSH key registered with Tangled and a known hosts file containing the knot’s host key.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sethcottle/tangled-mirror">https://github.com/sethcottle/tangled-mirror</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tangled-mirror">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Tangled Mirror GitHub Action keeps a Tangled repo in sync with one that lives on GitHub. It checks the knot&rsquo;s host key, sends only the refs it asks for, and won&rsquo;t delete anything unless told to. The action requires an SSH key registered with Tangled and a known hosts file containing the knot&rsquo;s host key.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Fixed</strong></p>
<ul>
<li>
<p>Boolean inputs are now validated instead of being compared against the literal
string <code>true</code>. Previously any other value quietly meant false, so <code>yes</code>, <code>1</code>,
<code>True</code>, and an empty string all disabled whatever they were passed to.</p>
<p>Since <code>tags</code> defaults on, that could silently stop tags being mirrored. The
empty case was the realistic one: on a <code>workflow_run</code> or <code>schedule</code> trigger
there are no dispatch inputs, so <code>inputs.tags</code> expands to an empty string. If
you have one workflow serving both a manual dispatch and an automatic trigger,
every automatic run would have dropped your tags without saying anything.</p>
<p>The error now names that cause and shows the fallback to use.</p>
</li>
</ul>
<p><strong>Docs</strong></p>
<ul>
<li>Added a pattern for repositories whose release workflow moves a rolling tag.
Mirroring on <code>push</code> races the tag update, so the knot keeps the previous value
until something else gets pushed. Trigger on <code>workflow_run</code> after the release
workflow finishes instead.</li>
</ul>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/custom-amazon-bedrock-agent-action/</link><pubDate>Fri, 07 Aug 2026 22:36:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback. It is highly customizable, allowing you to tailor the analysis based on your specific requirements and use cases, including integrating with Amazon Bedrock Knowledge Bases for enhanced context-aware insights. The action enables code quality improvement, security assessments, and performance optimizations by processing PR files using tailored prompts and utilizing pre-integrated knowledge bases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback. It is highly customizable, allowing you to tailor the analysis based on your specific requirements and use cases, including integrating with Amazon Bedrock Knowledge Bases for enhanced context-aware insights. The action enables code quality improvement, security assessments, and performance optimizations by processing PR files using tailored prompts and utilizing pre-integrated knowledge bases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Setup BATS</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/setup-bats/</link><pubDate>Fri, 07 Aug 2026 22:35:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/setup-bats/</guid><description>Version updated for https://github.com/sgerrand/setup-bats-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs the Bash Automated Testing System (BATS) in a workflow, allowing users to easily automate testing scripts. It supports both resolving the latest version and specifying specific versions through inputs, providing flexibility for different use cases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sgerrand/setup-bats-action">https://github.com/sgerrand/setup-bats-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-bats">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs the Bash Automated Testing System (BATS) in a workflow, allowing users to easily automate testing scripts. It supports both resolving the latest version and specifying specific versions through inputs, providing flexibility for different use cases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="103-2026-08-07"><a href="https://github.com/sgerrand/setup-bats-action/compare/v1.0.2...v1.0.3">1.0.3</a> (2026-08-07)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>validate version input against semver pattern (<a href="https://github.com/sgerrand/setup-bats-action/issues/28">#28</a>) (<a href="https://github.com/sgerrand/setup-bats-action/commit/c144d68d9984dccd22f74cef49b6c90501194fbd">c144d68</a>)</li>
</ul>
]]></content:encoded></item><item><title>Trigger CI with empty commit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/trigger-ci-with-empty-commit/</link><pubDate>Fri, 07 Aug 2026 22:35:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/trigger-ci-with-empty-commit/</guid><description>Version updated for https://github.com/Shamrock-code/action-trigger-ci-empty-commit to version v1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically triggers CI by pushing an empty commit to a pull request branch when a maintainer adds a specific label (trigger-ci). It handles both main repository branches and fork PRs, ensuring that the action can push to fork PRs if Allow edits from maintainers is enabled. If push is not possible (e.g., in a forked repo without this setting), it posts a comment with instructions on how to manually trigger CI.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Shamrock-code/action-trigger-ci-empty-commit">https://github.com/Shamrock-code/action-trigger-ci-empty-commit</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/trigger-ci-with-empty-commit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically triggers CI by pushing an empty commit to a pull request branch when a maintainer adds a specific label (<code>trigger-ci</code>). It handles both main repository branches and fork PRs, ensuring that the action can push to fork PRs if <strong>Allow edits from maintainers</strong> is enabled. If push is not possible (e.g., in a forked repo without this setting), it posts a comment with instructions on how to manually trigger CI.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This is the initial release of this action used to trigger a CI job on a PR (from fork or same repo) by creating an empty commit on the PR.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Shamrock-code/action-trigger-ci-empty-commit/commits/v1">https://github.com/Shamrock-code/action-trigger-ci-empty-commit/commits/v1</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/sherpa.sh/</link><pubDate>Fri, 07 Aug 2026 22:34:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh automates the deployment of applications to various cloud providers by translating plain English descriptions into optimized infrastructure configurations. It simplifies the process of setting up servers, DNS, SSL certificates, CDN, databases, backups, and load balancing using AI-driven decision-making. This action is particularly useful for developers who want to focus on writing code instead of configuring complex infrastructure files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh automates the deployment of applications to various cloud providers by translating plain English descriptions into optimized infrastructure configurations. It simplifies the process of setting up servers, DNS, SSL certificates, CDN, databases, backups, and load balancing using AI-driven decision-making. This action is particularly useful for developers who want to focus on writing code instead of configuring complex infrastructure files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Validate Syscribe Model</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/validate-syscribe-model/</link><pubDate>Fri, 07 Aug 2026 22:33:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/validate-syscribe-model/</guid><description>Version updated for https://github.com/sjames/syscribe to version v0.34.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Syscribe is a documentation system for SysMLv2 models that uses Markdown and YAML to create human-readable, agent-native, version-controlled, and traceable files. It supports 40+ element types including native Requirements and TestCases with SIL/ASIL levels, ADRs, and Safety analysis tools like HARA, FMEA, etc. The system allows teams to manage models in a git repository alongside code, supporting features like cross-repo references, reproducibility checks, and traceability rules.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sjames/syscribe">https://github.com/sjames/syscribe</a></strong> to version <strong>v0.34.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/validate-syscribe-model">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Syscribe is a documentation system for SysMLv2 models that uses Markdown and YAML to create human-readable, agent-native, version-controlled, and traceable files. It supports 40+ element types including native Requirements and TestCases with SIL/ASIL levels, ADRs, and Safety analysis tools like HARA, FMEA, etc. The system allows teams to manage models in a git repository alongside code, supporting features like cross-repo references, reproducibility checks, and traceability rules.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sjames/syscribe/compare/v0...v0.34.0">https://github.com/sjames/syscribe/compare/v0...v0.34.0</a></p>
]]></content:encoded></item><item><title>Snowflake Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/snowflake-actions/</link><pubDate>Fri, 07 Aug 2026 22:32:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/snowflake-actions/</guid><description>Version updated for https://github.com/snowflakedb/snowflake-actions to version v3.3.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 1 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action installs and configures the Snowflake CLI, allowing users to automate tasks such as deploying dbt projects, streamlit apps, DCM pipelines, and running SQL queries directly from their CI/CD workflows. It supports OIDC authentication for secure access to Snowflake without storing secrets and is recommended for environments where OIDC is available.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snowflakedb/snowflake-actions">https://github.com/snowflakedb/snowflake-actions</a></strong> to version <strong>v3.3.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>1</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/snowflake-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action installs and configures the Snowflake CLI, allowing users to automate tasks such as deploying dbt projects, streamlit apps, DCM pipelines, and running SQL queries directly from their CI/CD workflows. It supports OIDC authentication for secure access to Snowflake without storing secrets and is recommended for environments where OIDC is available.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Snowflake Actions v3.3.0</strong></p>
<h2 id="improvements">Improvements</h2>
<ul>
<li><strong>DCM composite actions</strong> (<code>dcm/</code>): the changeset now sits in a collapsible <code>collapse/expand</code> section in both the job summary and the PR comment, with the processing steps above it and the totals line below it. <code>dcm-plan</code> leaves it expanded, <code>dcm-deploy</code> starts it collapsed. (#29)</li>
<li><strong>DCM composite actions</strong> (<code>dcm/</code>): <code>dcm-deploy</code> output is colour-coded like <code>dcm-plan</code> output (:large_green_square: <code>CREATE</code>, :large_yellow_square: <code>ALTER</code>, :large_red_square: <code>DROP</code>), having previously rendered through the generic summary path. (#29)</li>
</ul>
<h2 id="fixes">Fixes</h2>
<ul>
<li><strong>DCM composite actions</strong> (<code>dcm/</code>): PR comments no longer exceed GitHub’s 65536-character body limit. A plan of a few hundred entities used to fail the job outright with <code>Validation Failed: body is too long</code>; oversized output is now truncated at a line boundary with a pointer to the run log and the uploaded artifact. (#29)</li>
<li><strong>DCM composite actions</strong> (<code>dcm/</code>): <code>dcm-deploy</code> drop detection reads <code>out/plan_result.json</code> instead of <code>out/plan/plan_result.json</code>, which had failed since the latest release of Snowflake CLI 3.24 with <code>Plan output file not found</code>. (#29)</li>
</ul>
<h2 id="notes">Notes</h2>
<ul>
<li>Anyone using <code>comment-on-pr: “true”</code> will see a different comment shape after upgrading. No input changed and no action is required.
<strong>Usage:</strong> <code>uses: snowflakedb/snowflake-actions@v3</code>
<strong>Full Changelog</strong>: <a href="https://github.com/snowflakedb/snowflake-actions/compare/v3.2.0...v3.3.0">github.com/snowflakedb/snowflake-actions/compare/…</a></li>
</ul>
]]></content:encoded></item><item><title>Ward - Pre-Agent Metadata Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/ward-pre-agent-metadata-scanner/</link><pubDate>Fri, 07 Aug 2026 22:31:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/ward-pre-agent-metadata-scanner/</guid><description>Version updated for https://github.com/Sonofg0tham/ward to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Ward is a GitHub Action that automates the detection of prompt injection in various metadata fields such as branch names, commit messages, PR titles, and file names before they reach AI code reviewers or security tools. It helps prevent malicious intent by scanning these untrusted strings to catch potential attacks that traditional security tools may miss. Ward provides a 0% false-positive rate across different corpora and LLM judges, ensuring the highest level of safety for AI-driven code review processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Sonofg0tham/ward">https://github.com/Sonofg0tham/ward</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ward-pre-agent-metadata-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Ward is a GitHub Action that automates the detection of prompt injection in various metadata fields such as branch names, commit messages, PR titles, and file names before they reach AI code reviewers or security tools. It helps prevent malicious intent by scanning these untrusted strings to catch potential attacks that traditional security tools may miss. Ward provides a 0% false-positive rate across different corpora and LLM judges, ensuring the highest level of safety for AI-driven code review processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fail closed: 22 adversarial audit rounds over the whole codebase by @Sonofg0tham in <a href="https://github.com/Sonofg0tham/ward/pull/11">https://github.com/Sonofg0tham/ward/pull/11</a></li>
<li>Close a suppression bypass, make SECURITY.md honest, refresh the social preview by @Sonofg0tham in <a href="https://github.com/Sonofg0tham/ward/pull/13">https://github.com/Sonofg0tham/ward/pull/13</a></li>
<li>Release 0.3.0 by @Sonofg0tham in <a href="https://github.com/Sonofg0tham/ward/pull/14">https://github.com/Sonofg0tham/ward/pull/14</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Sonofg0tham/ward/commits/v0.3.0">https://github.com/Sonofg0tham/ward/commits/v0.3.0</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/classroom-to-sheets-integration/</link><pubDate>Fri, 07 Aug 2026 22:29:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending assignment results from Google Classroom to a Google Sheet. It integrates with the Google Sheets API to update specified columns and rows based on task results provided by other grader actions in the workflow. The action ensures that the sheet is properly structured and handles both existing and new students dynamically, making it easy to integrate into larger workflows for automated grading systems.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending assignment results from Google Classroom to a Google Sheet. It integrates with the Google Sheets API to update specified columns and rows based on task results provided by other grader actions in the workflow. The action ensures that the sheet is properly structured and handles both existing and new students dynamically, making it easy to integrate into larger workflows for automated grading systems.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>OTLP GitHubAction Exporter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/otlp-githubaction-exporter/</link><pubDate>Fri, 07 Aug 2026 22:29:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/otlp-githubaction-exporter/</guid><description>Version updated for https://github.com/StephenGoodall/OTLP-GitHubAction-Exporter to version v3.2.10.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The OTLP GitHub Action Exporter is a tool that automates the export of GitHub Actions runs as OpenTelemetry Traces, Metrics, and Logs. It allows users to monitor their CI/CD workflows by exporting details and metrics from these runs via an OTLP endpoint, which can be configured for Dynatrace or New Relic. The action supports automatic token authentication and requires specific API tokens and configurations to work correctly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/StephenGoodall/OTLP-GitHubAction-Exporter">https://github.com/StephenGoodall/OTLP-GitHubAction-Exporter</a></strong> to version <strong>v3.2.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/otlp-githubaction-exporter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The OTLP GitHub Action Exporter is a tool that automates the export of GitHub Actions runs as OpenTelemetry Traces, Metrics, and Logs. It allows users to monitor their CI/CD workflows by exporting details and metrics from these runs via an OTLP endpoint, which can be configured for Dynatrace or New Relic. The action supports automatic token authentication and requires specific API tokens and configurations to work correctly.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="3210-2026-08-07"><a href="https://github.com/StephenGoodall/OTLP-GitHubAction-Exporter/compare/v3.2.9...v3.2.10">3.2.10</a> (2026-08-07)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> Update Dependabot commit message configuration (<a href="https://github.com/StephenGoodall/OTLP-GitHubAction-Exporter/commit/16435488acbf2cc08f106b90a5491cb3e6222d06">1643548</a>)</li>
</ul>
]]></content:encoded></item><item><title>TeXRA Agent</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/texra-agent/</link><pubDate>Fri, 07 Aug 2026 22:27:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/texra-agent/</guid><description>Version updated for https://github.com/texra-ai/texra-action to version v1.1.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, texra-action, automates the integration of TeXRA tools into CI/CD workflows. It allows users to review pull requests inline using TeXRA’s AI agents or run any agent headlessly in CI environments, consuming and displaying the results directly within PRs. The action uses @texra-ai/cli to execute TeXRA commands and can be configured to post inline comments or generate summary reviews.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/texra-ai/texra-action">https://github.com/texra-ai/texra-action</a></strong> to version <strong>v1.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/texra-agent">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>texra-action</code>, automates the integration of <a href="https://texra.ai">TeXRA</a> tools into CI/CD workflows. It allows users to review pull requests inline using TeXRA&rsquo;s AI agents or run any agent headlessly in CI environments, consuming and displaying the results directly within PRs. The action uses <code>@texra-ai/cli</code> to execute TeXRA commands and can be configured to post inline comments or generate summary reviews.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: skip when the review workflow is not yet on the default branch by @LionSR in <a href="https://github.com/texra-ai/texra-action/pull/9">https://github.com/texra-ai/texra-action/pull/9</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/texra-ai/texra-action/compare/v1...v1.1.4">https://github.com/texra-ai/texra-action/compare/v1...v1.1.4</a></p>
]]></content:encoded></item><item><title>skillx — verify a signed skill</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/skillx-verify-a-signed-skill/</link><pubDate>Fri, 07 Aug 2026 22:27:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/skillx-verify-a-signed-skill/</guid><description>Version updated for https://github.com/The-Holding-Company/skillx-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the verification of signed agent “SKILL.md” files using JWS signatures and DID documents. It solves the problem of trusting unsigned or tampered skills in workflows by providing a CI-native gate that checks for validity and potential prompt-injection vulnerabilities. The action supports multiple use cases, including verifying single skills, several skills simultaneously, and handling results without failing builds when necessary.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/The-Holding-Company/skillx-action">https://github.com/The-Holding-Company/skillx-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skillx-verify-a-signed-skill">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the verification of signed agent &ldquo;SKILL.md&rdquo; files using JWS signatures and DID documents. It solves the problem of trusting unsigned or tampered skills in workflows by providing a CI-native gate that checks for validity and potential prompt-injection vulnerabilities. The action supports multiple use cases, including verifying single skills, several skills simultaneously, and handling results without failing builds when necessary.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Verifies a signed agent <code>SKILL.md</code> (detached ES256 JWS + <code>did:web</code> resolution from the publisher&rsquo;s own domain) before your pipeline or agent trusts it.</li>
<li>Exact outcomes: <code>VERIFIED</code>, <code>UNSIGNED</code>, <code>INVALID</code>. INVALID always fails the job; UNSIGNED fails unless <code>allow-unsigned: 'true'</code>.</li>
<li>Optional prompt-injection content scan (on by default).</li>
<li>Verifier <code>skillx.py</code> is vendored and pinned in this release — nothing is fetched at runtime except the skill under test and the publisher&rsquo;s public DID document.</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">The-Holding-Company/skillx-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">skill-url</span>: <span style="color:#ae81ff">https://example.com/SKILL.md</span>
</span></span></code></pre></div><p>Docs: <a href="https://skillx.md/publish.html">https://skillx.md/publish.html</a></p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/wails3-build-action/</link><pubDate>Fri, 07 Aug 2026 22:25:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the building of Wails.io applications using GoLang and NodeJS, providing options for customizing the build process, including obfuscation, platform support, caching, and artifact uploading. It supports building on macOS, Windows, and Linux, and can handle multiple platforms simultaneously.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the building of Wails.io applications using GoLang and NodeJS, providing options for customizing the build process, including obfuscation, platform support, caching, and artifact uploading. It supports building on macOS, Windows, and Linux, and can handle multiple platforms simultaneously.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>Verificate Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/verificate-gate/</link><pubDate>Fri, 07 Aug 2026 22:25:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/verificate-gate/</guid><description>Version updated for https://github.com/Verificate-Dev/verificate-gate-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Verificate Gate GitHub Action is designed to block pull requests that contain broken AI code, such as hallucinated APIs, mock/placeholder detections, or reward-gaming tests. It automates the process of checking every changed code file through a set of deterministic reality gates and fails the check on a veto, ensuring that only clean and reliable changes are allowed to merge into the repository. The action provides a clear and concise way to maintain quality in AI-driven projects by identifying potential issues early.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Verificate-Dev/verificate-gate-action">https://github.com/Verificate-Dev/verificate-gate-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/verificate-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Verificate Gate GitHub Action is designed to block pull requests that contain broken AI code, such as hallucinated APIs, mock/placeholder detections, or reward-gaming tests. It automates the process of checking every changed code file through a set of deterministic reality gates and fails the check on a veto, ensuring that only clean and reliable changes are allowed to merge into the repository. The action provides a clear and concise way to maintain quality in AI-driven projects by identifying potential issues early.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The merge gate for AI-written code. Add one workflow and Verificate reviews every changed code file on a pull request through 17 deterministic reality gates + a frontier-model review. A veto fails the check and blocks the merge until it&rsquo;s fixed.</p>
<p>Why: ask a model &ldquo;is this OK to merge?&rdquo; and, in a natural workflow, it misses the failures agents make most — reward-gaming tests and hallucinated APIs. On a planted-defect corpus, a frontier model reviewing its own diff caught these 0/6; this gate caught both 6/6, with 0 false positives on clean code.</p>
<p>Add it in 5 lines:</p>
<pre><code>- uses: Verificate-Dev/verificate-gate-action@v1
  with:
    verificate-api-key: ${{ secrets.VERIFICATE_API_KEY }}   # optional; free tier works without
    fail-on: reject
</code></pre>
<p>Then make <code>verificate-gate</code> a required status check.</p>
<p>Safe by design: fails closed only on a real veto; fails open on any infra error, so a gate outage never blocks your team. Reviews only changed files, no code executed. Free tier, no signup to try.</p>
<p>Full benchmark + reproducible scripts: <a href="https://github.com/Verificate-Dev/verificate-mcp-quickstart/blob/master/COMPARISON.md">https://github.com/Verificate-Dev/verificate-mcp-quickstart/blob/master/COMPARISON.md</a></p>
<p>Attach binaries / files: leave empty — Actions ship as source, no artifact needed.</p>
]]></content:encoded></item><item><title>Sync Issues and PRs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/sync-issues-and-prs/</link><pubDate>Fri, 07 Aug 2026 22:23:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/sync-issues-and-prs/</guid><description>Version updated for https://github.com/vig-os/sync-issues-action to version v0.5.0.
This action is used across all versions by 9 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action synchronizes all issues and pull requests from a repository to markdown files, including comments and conversations, groups review threads with diff snippets when available, preserves original bodies, and includes metadata. It can be used to generate static documentation or backups of issues and pull requests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vig-os/sync-issues-action">https://github.com/vig-os/sync-issues-action</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>9</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sync-issues-and-prs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action synchronizes all issues and pull requests from a repository to markdown files, including comments and conversations, groups review threads with diff snippets when available, preserves original bodies, and includes metadata. It can be used to generate static documentation or backups of issues and pull requests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>No changelog notes found for 0.5.0</p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/cowork-harness/</link><pubDate>Fri, 07 Aug 2026 22:22:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.20.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cowork-harness action is a scriptable, CI-friendly test harness that reproduces Claude Cowork’s observable runtime contract closely enough to test skills without the locked Desktop app. It creates a sandboxed environment, simulates the agent and its constraints (e.g., sealed filesystem, MCP-only cross-boundary), and can run tests in various fidelity tiers such as replay or live with different requirements like token-free or with real resources.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.20.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The cowork-harness action is a scriptable, CI-friendly test harness that reproduces Claude Cowork&rsquo;s observable runtime contract closely enough to test skills without the locked Desktop app. It creates a sandboxed environment, simulates the agent and its constraints (e.g., sealed filesystem, MCP-only cross-boundary), and can run tests in various fidelity tiers such as replay or live with different requirements like token-free or with real resources.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="upgrade-notes">Upgrade notes</h3>
<ul>
<li>
<p><strong><code>record --dry-run</code> now refuses what the real <code>record</code> refuses, so a batch preflight can no longer
green a scenario the paid run rejects.</strong> It already ran the real loader; it now also applies the
scenario-level refusals — <code>on_unanswered: prompt</code> (previously enforced in the single-file arm only,
never in a directory batch) and the new unsatisfiable-assert pairing. A directory dry run reports
<strong>every</strong> offender rather than stopping at the first, since the point of previewing N scenarios is to
learn about all N in one pass, and exits 1 when any is refused. <code>--quiet</code> still mutes the readiness
preview and never a refusal. Caught by a founder-skills consumer who noted that the refusal shipped on
the execution path only — while <code>record --dry-run</code> is what we document, in four places, as the
token-free way to validate a scenario, and is what their CI and re-record script call.</p>
</li>
<li>
<p><strong>Two <code>COWORK_*</code> env vars are removed from the covered surface, and this is deliberately NOT a major
bump.</strong> <code>COWORK_EGRESS_PROXY</code> and <code>COWORK_DOCKER_NETWORK</code> leave the documented env-var set that
<a href="./SPEC.md#12-versioning--the-10-compatibility-contract">SPEC.md §12</a> covers, and
<a href="./RELEASING.md#versioning-semver">RELEASING.md</a>&rsquo;s rule reads &ldquo;a removal … means a <strong>major</strong> bump&rdquo;.
The exception is taken knowingly: both knobs were <strong>provably inert</strong> — every container-like tier built
its egress sidecar before the env branch could execute, and <code>microvm</code> never read them at all (see
<em>Fixed</em>, below) — so no run&rsquo;s behaviour changes in either direction, and no configuration that worked
before stops working. Setting either variable was a no-op before this release and is a no-op after it.
Recorded here rather than left silent, so the contract is departed from on purpose and once, not by
accident. <code>COWORK_PROXY_IMAGE</code> is genuinely live and unchanged.</p>
<p>Note for anyone auditing this later: <code>npm run check:surface</code> does <strong>not</strong> catch a removal like this.
It compares the current code against the committed snapshot, which was regenerated in the same
commits — so it reports <code>+0 -0 ~0</code>. The removal is visible only by diffing
<code>test/fixtures/surface-baseline.json</code> across the release boundary
(<code>git diff v1.19.0..v1.20.0 -- test/fixtures/surface-baseline.json</code>).</p>
</li>
<li>
<p><strong>Four scenario shapes that lint clean today may newly fail <code>cowork-harness lint --strict --min-severity WARN</code></strong> (the invocation the CI recipe teaches). None is a false alarm — each is a
scenario that was already not testing what it looked like it tested:</p>
<ol>
<li>A presence assertion paired with its absence sibling → new <code>assert-contradiction</code> ERROR (and the
run itself is now refused): <code>questions_count_max: 0</code> with a gate-presence key, <code>no_hook_blocked</code>
with <code>hook_blocked</code>, or <code>no_path_denied</code> with <code>path_denied</code>/<code>vm_path_denied</code>.</li>
<li><code>gate_answers_delivered: true</code> paired with <code>gate_answer_count_min: 0</code> → the zero floor no longer
counts as a companion. <strong>Most likely to already be in an existing corpus.</strong> Fix: raise the floor to
<code>1</code>, or drop <code>gate_answers_delivered</code>.</li>
<li><code>tool_called: &quot;askuserquestion&quot;</code> (or any wrong-case spelling) alongside <code>gate_answers_delivered</code>
→ the glob is case-sensitive and never matched the gate; it no longer silences the rule.</li>
<li><code>tool_called: &quot;Ask.*Question&quot;</code> → a regex-shaped value, already rejected at scenario load by the
tool-glob schema, no longer silences the rule either. Use <code>Ask*Question</code>.</li>
</ol>
<p>Conversely, <code>gate_answers_delivered: false</code> <strong>stops</strong> warning — if you carry a suppression for it, it
can go.</p>
</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong><code>record --dry-run</code> reports the batch cost estimate, with or without <code>--max-budget-usd</code>.</strong> The
summed worst-case cost from prior-run history was already computed on every batch preflight and then
discarded unless it happened to exceed a cap — so the only way to learn what a re-record would cost
was to bisect <code>--max-budget-usd</code> until it refused. It is now printed on the passing path (text) and
carried as <code>estimatedCostUsd</code> + <code>unpricedScenarios</code> in the <code>--output-format json</code> payload, and the
refusal path is unchanged. A total summed over partially-unpriced history is labelled a <strong>LOWER
BOUND</strong> and names the scenarios contributing $0, so a fresh corpus&rsquo;s <code>$0.0000</code> can never read as
authoritative.</p>
</li>
<li>
<p><strong><code>doctor</code> checks the agent image against a digest this release pins, offline.</strong> The check previously
asked GHCR what the floating <code>:2</code> tag pointed at <em>at that moment</em>: it needed network and
<code>docker buildx</code> (degrading to <code>unknown</code> when either was missing), and it could only ever establish that
two digests differ — never which one the harness expected, since a floating tag can be repointed in
either direction. It now compares against <code>docker/agent-image.json</code>, <strong>per variant</strong>, so a
<code>cowork-agent-full:2</code> user is checked against the full-parity image rather than the base one. The
remedy is digest-addressed (<code>docker pull …@sha256:…</code>), because pulling <code>:2</code> cannot satisfy a pin to an
older revision. A locally built image and an unpinned image both stay quiet skips, and a stopped Docker
daemon reports <code>unknown</code> rather than a confident &ldquo;built locally&rdquo;.</p>
</li>
<li>
<p><strong>The agent image can be published at an immutable <code>:2-r&lt;N&gt;</code> revision tag without moving <code>:2</code>.</strong>
<code>docker/agent-image.json</code> carries the image&rsquo;s own revision counter (deliberately not the harness
version — a version-keyed co-tag encodes something that was never the image&rsquo;s identity, and
republishing at an existing version would repoint a tag a pin depends on). A manual
<code>publish-image.yml</code> run now defaults to <code>immutable_only</code>, publishing <code>:2-r&lt;N&gt;</code> for both variants and
leaving the floating <code>:2</code> untouched, so no existing consumer&rsquo;s next pull changes. Release tag pushes
are unaffected. The workflow refuses to repoint an existing <code>:2-r&lt;N&gt;</code> and fails <strong>closed</strong> when it
cannot enumerate tags — an inconclusive check must never read as &ldquo;tag absent&rdquo;. See
<a href="./docs/maintenance.md#publishing-an-agent-image-revision">docs/maintenance.md</a>.</p>
</li>
<li>
<p><strong><code>run</code> / <code>skill</code> / <code>record</code> now refuse an unsatisfiable assertion pairing before spawning, and
<code>lint</code> reports it as <code>assert-contradiction</code> (ERROR).</strong> Three pairs, each one assertion requiring a
record to exist next to its sibling requiring none to, on a single evidence channel:</p>
<ul>
<li><code>questions_count_max: 0</code> with <code>gate_answer_count_min: &gt;= 1</code>, <code>question_asked</code>, or
<code>gate_answers_delivered: false</code> — a delivered gate records at least one question.</li>
<li><code>no_hook_blocked</code> with <code>hook_blocked</code> — one hook-event list.</li>
<li><code>no_path_denied</code> with <code>path_denied</code> or <code>vm_path_denied</code> — one path-denial list.</li>
</ul>
<p>Previously each cost a live run to discover. Where the evidence is absent both halves fail
evidence-unavailable rather than passing, and the denial keys are hostloop-only so a wrong tier fails
both too — no combination produced a silent both-pass, only a guaranteed one. Each negative key
<strong>on its own</strong> is unaffected; <code>questions_count_max: 0</code> in particular remains the supported way to
declare a gate-clean scenario.</p>
<p>This is a <strong>command-level</strong> refusal, not a schema change: <code>schema/scenario.schema.json</code> still accepts
the document, so the covered input contract (<a href="./SPEC.md#12-versioning--the-10-compatibility-contract">SPEC.md §12</a>)
is untouched and no cassette is affected.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><strong>Platform baseline <code>desktop-1.26832.0</code> (agent ELF <code>2.1.222</code>), with no behavioural change to the
modeled spawn contract.</strong> The ELF&rsquo;s SHA-256 matches Anthropic&rsquo;s official <code>linux-arm64</code> release
checksum. The Cowork system prompt, the sub-agent append, <code>coworkSyspromptMap</code>, the mount-mode
anchors and the egress allowlist are all unchanged — the whole sentinel set passed. All three
committed cassettes replay clean (re-stamped, not re-recorded — no live agent runs at replay tier, so
their recorded behaviour could not move).</p>
<p>Desktop constructs one new spawn-env key, <code>CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC</code>. It is
<strong>allowlisted rather than pinned</strong>: both of its construction sites sit inside the
<code>accountType === &quot;3p&quot;</code> object literal and are further conditional on <code>telemetry.disableNonessential</code>,
alongside <code>DISABLE_GROWTHBOOK</code>/<code>DISABLE_TELEMETRY</code>, which are allowlisted for the same reason. Pinning
it would bake a third-party-provider key into a baseline that describes the first-party spawn.</p>
<p>Two gate movements worth naming, neither of which changes emulated behaviour.
<code>scheduledTaskToolsApprovableByAutoMode</code> flipped to force-on, but Cowork spawns with
<code>CLAUDE_CODE_DISABLE_CRON=1</code> regardless and the scheduled-task tool set is unchanged. And
<code>coworkRuntimeConfig</code> began <em>serving</em> <code>skillsSyncIntervalMs</code>/<code>pluginsSyncIntervalMs</code> (20 min) plus
<code>pluginsFullSyncStalenessMs</code> (1 h) instead of letting them fall back to code defaults — the code
reading them already shipped. Cowork therefore re-syncs host skills and plugins into a live session
roughly every 20 minutes; the harness stages once per run and never re-stages, which is a deliberate
divergence — it stages from a git-tracked, immutable-per-run source, so there is no mid-run mutation
for it to observe.</p>
</li>
<li>
<p><strong>The agent image&rsquo;s base layer is pinned by digest.</strong> <code>docker/Dockerfile.agent</code> builds
<code>FROM ubuntu:22.04@sha256:3b06811b…</code> instead of the floating <code>22.04</code> tag. This Dockerfile has no
<code>COPY</code>/<code>ADD</code> — every byte comes from the base plus apt and pip — so with a floating base, rebuilding
an unchanged recipe produced a different image and &ldquo;the recipe didn&rsquo;t change&rdquo; said nothing about the
contents. Rebuild locally to pick this up; the toolchain versions are unchanged (verified: Ubuntu
22.04, Node 22.22.3, numpy 2.2.6 / pandas 2.3.3 / openpyxl 3.1.5, <code>LANG=C.UTF-8</code>, uid-1000 <code>ubuntu</code>).</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong><code>lint</code>&rsquo;s <code>vacuous-gate-assert</code> rule was wrong in four ways, two of them silent.</strong> The rule exists to
catch a <code>gate_answers_delivered</code> that guards nothing, and it read only assertion <strong>key names</strong>, never
their values:</p>
<ul>
<li>It fired on <code>gate_answers_delivered: **false**</code>, whose premise is the opposite — that assertion
demands a confirmed delivery <em>failure</em>, so zero gates fails it. A correct negative-path scenario was
told, in a build-failing warning, that it passed vacuously.</li>
<li>It accepted <code>gate_answer_count_min: **0**</code> as the presence companion. <code>delivered &gt;= 0</code> always holds,
so the pairing everyone reads as &ldquo;and a gate must actually fire&rdquo; asserted nothing — a silent
false-green wearing the correct idiom&rsquo;s clothes.</li>
<li>It matched <code>tool_called</code> with a case-insensitive <code>re.search</code>, but that field is a <strong>glob</strong>
(anchored, case-sensitive, only <code>*</code>/<code>?</code> special). Valid globs that do pin the gate
(<code>Ask*Question</code>, <code>*Question</code>, <code>**/AskUserQuestion</code>, <code>**/*</code>) were flagged anyway, while
<code>askuserquestion</code> — which can never match — silenced the rule. The matcher is now a port of the
harness&rsquo;s own glob engine, with a differential test against it.</li>
<li>Its remedy only ever said &ldquo;add a presence companion&rdquo;. For a scenario that is gate-clean <strong>by
design</strong> every branch of that was wrong, and the correct fix — drop the key, it asserts nothing
there — was never named. The fix line now carries both branches, and when a scenario already
declares <code>questions_count_max: 0</code> the finding says the key is <em>inert here, drop it</em> rather than
telling you to add a gate.</li>
</ul>
<p>Thanks to the founder-skills consumer whose report surfaced the one-sided remedy; the other three came
out of investigating it.</p>
</li>
<li>
<p><strong><code>expect_denied</code> could not tell an empty egress channel from an allowed host.</strong> The expansion into
<code>egress_denied</code> assertions was duplicated in the live run and the verify path, and both reported a bare
<code>expected &lt;host&gt; to be denied</code> even when the proxy had recorded nothing at all — so a tier whose shell
could reach no host read identically to one that correctly denied the host you asked about. The two
copies now share one helper with three distinct outcomes, and the verify path passes its
<code>egressMissing</code> signal through, so a <code>result.json</code> with no <code>egress</code> field reports evidence-unavailable
rather than a failed assertion. Assertion <em>outcomes</em> are unchanged — only the message, and only in the
cases that were previously indistinguishable.</p>
</li>
<li>
<p><strong>Two documented networking overrides never worked.</strong> <code>COWORK_EGRESS_PROXY</code> and
<code>COWORK_DOCKER_NETWORK</code> sat behind values the caller always supplies — every container-like tier builds
its egress sidecar before spawning, so the env branch could not execute in any tier, and <code>microvm</code>
never read them at all. README advertised both as working knobs, which is worse than an undocumented
dead branch: the docs vouched for a promise the code could not keep. They are removed rather than
wired up — redirecting a run at a proxy or network the harness did not create would silently move the
boundary <code>boundary-check</code> exists to prove. <code>COWORK_PROXY_IMAGE</code>, in the same README bullet, is
genuinely live and unchanged.</p>
</li>
<li>
<p><strong>The golden host-loop snapshot asserted a container that does not exist at that tier.</strong> It was built
from the container-shaped helper, so it pinned a full agent env and a <code>claude -p …</code> argv for a sidecar
that has neither — the same &ldquo;test a shape nothing runs&rdquo; defect that let host-loop bash egress die
unnoticed. It now models the real sidecar: proxy env only, <code>sleep infinity</code>, and the ELF bound
read-only for parity. <code>SPEC.md</code> §3.4 and <code>dockerRunArgv</code>&rsquo;s own doc comment both claimed no agent binary
is bind-mounted there, which was false since the host/VM split; both now say what actually happens —
no agent <em>argv</em> runs in the sidecar, but the ELF <em>is</em> bound.</p>
</li>
<li>
<p><strong><code>hostloop</code> <code>bash</code> had no egress at all — a regression dating to v0.21.0.</strong> The VM sidecar that <code>bash</code>
runs in via <code>docker exec</code> was spawned with an empty env on a Docker network with no route off-box, so
shell commands could reach <strong>neither allowlisted nor denied hosts</strong>: both failed identically with a DNS
error. The allowlist was not enforced there so much as bypassed by being unreachable — while
<a href="./docs/boundary.md">docs/boundary.md</a>, <a href="./docs/scenario.md">docs/scenario.md</a>,
<a href="./docs/session.md">docs/session.md</a> and <a href="./docs/fidelity-gaps.md">docs/fidelity-gaps.md</a> all described
the allowlist as enforced at this tier, one of them recommending it for testing egress policy. The
native host/VM process split introduced the gap by replacing the sidecar&rsquo;s computed env with a literal
and orphaning the <code>egressProxy</code> parameter that fed it — the parameter kept being passed in and was
simply never read. <code>bash</code> at <code>hostloop</code> now reaches the same allowlist as <code>container</code>, through the same
proxy.</p>
<p>A sixth <code>boundary-check</code> probe (<code>hostloop-bash-egress</code>) pins it, and it consumes the runtime&rsquo;s own env
builder rather than a hand-assembled copy — the distinction that matters, since every hand-built check
stayed green throughout the regression. It asserts an allowlisted host is reachable <strong>and</strong> an off-list
host refused; the reachable half is load-bearing, because a sidecar with no egress also refuses
everything and is otherwise indistinguishable from working enforcement.</p>
</li>
<li>
<p><strong>The egress proxy intercepted the sandbox&rsquo;s own loopback traffic.</strong> The spawn env set
<code>HTTP_PROXY</code>/<code>http_proxy</code> (and the HTTPS pair) with no <code>NO_PROXY</code>, so a proxy-honouring client asking
for <code>http://localhost:PORT</code> had the request diverted to the allowlist proxy — which lives in a
<em>different</em> container, where <code>localhost</code> means the proxy itself — and answered <code>403</code>. A skill that
started a local server and curled it failed against an unrelated process. Cowork&rsquo;s allowlist is a
public-egress filter that does not stand between a process and its own loopback, and the harness
already encoded that intent at the microvm tier (the guest firewall explicitly accepts <code>lo</code> and
<code>127.0.0.0/8</code>) while the proxy vars defeated it. The spawn env now sets
<code>NO_PROXY</code>/<code>no_proxy=localhost,127.0.0.1,::1</code>, scoped to loopback only. A fifth <code>boundary-check</code> probe
(<code>loopback-not-proxied</code>) pins the behaviour and carries a positive control, so it cannot pass merely
because nothing was proxied.</p>
</li>
<li>
<p><strong><code>boundary-check</code> tested a proxy configuration nothing actually ran.</strong> Its probe passed only the two
UPPERCASE proxy vars, and curl honours <code>http_proxy</code> in lower case only for <code>http://</code> URLs (the
CVE-2016-5385 mitigation) — so plain-HTTP probes went unproxied. The probe and the agent spawn now
derive their proxy env from one shared definition and cannot diverge.</p>
</li>
<li>
<p><strong>A blank <code>COWORK_AGENT_IMAGE</code> or <code>COWORK_CONTAINER_RUNTIME</code> produced an empty ref instead of the
default.</strong> Both were resolved with <code>process.env.X ?? &quot;default&quot;</code>, which passes <code>&quot;&quot;</code> straight through, so
a bare <code>COWORK_AGENT_IMAGE=</code> in a <code>.env</code> or a shell export made every container invocation fail with an
opaque runtime error. A blank or whitespace-only value now falls back to the default. Both are resolved
in one place (<code>src/runtime/agent-image.ts</code>) rather than at the 7 and 10 call sites that previously
duplicated the expression, so the default and the override semantics can no longer drift apart.</p>
</li>
<li>
<p><strong><code>doctor</code>&rsquo;s stale-image warning claimed a direction it never measured.</strong> The check compares the local
pulled digest against whatever <code>ghcr.io/…/cowork-agent-base:2</code> points at now, which establishes that
the two differ — not that the published one is newer. <code>:2</code> floats and can be repointed either way. The
detail now reads <code>local &lt;image&gt; no longer matches the current published &lt;ref&gt;</code>; the <code>warn</code> status and
the re-pull remedy are unchanged, as is JSON output (<code>state</code> already carried this).</p>
</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>build(image): pin the agent base layer + guard the workflow properties CI cannot check by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/104">https://github.com/yaniv-golan/cowork-harness/pull/104</a></li>
<li>refactor(image): resolve the agent image and container runtime in one place by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/105">https://github.com/yaniv-golan/cowork-harness/pull/105</a></li>
<li>build(image): publish an immutable :2-r<N> revision without moving :2 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/107">https://github.com/yaniv-golan/cowork-harness/pull/107</a></li>
<li>docs(releasing): drop the last claim that the live suite runs on release PRs by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/106">https://github.com/yaniv-golan/cowork-harness/pull/106</a></li>
<li>fix(publish): immutable_only was inverted and moved :2 anyway by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/108">https://github.com/yaniv-golan/cowork-harness/pull/108</a></li>
<li>feat(doctor): check the agent image against a pinned digest, offline by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/109">https://github.com/yaniv-golan/cowork-harness/pull/109</a></li>
<li>build(deps): Bump docker/login-action from 4.5.2 to 4.6.0 in the actions group across 1 directory by @dependabot[bot] in <a href="https://github.com/yaniv-golan/cowork-harness/pull/97">https://github.com/yaniv-golan/cowork-harness/pull/97</a></li>
<li>chore(deps-dev): Bump fast-uri from 3.1.4 to 3.1.5 by @dependabot[bot] in <a href="https://github.com/yaniv-golan/cowork-harness/pull/99">https://github.com/yaniv-golan/cowork-harness/pull/99</a></li>
<li>chore(deps): Bump undici from 7.28.0 to 7.29.0 by @dependabot[bot] in <a href="https://github.com/yaniv-golan/cowork-harness/pull/98">https://github.com/yaniv-golan/cowork-harness/pull/98</a></li>
<li>build(deps-dev): bump postcss from 8.5.19 to 8.5.25 by @dependabot[bot] in <a href="https://github.com/yaniv-golan/cowork-harness/pull/101">https://github.com/yaniv-golan/cowork-harness/pull/101</a></li>
<li>build(deps): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/yaniv-golan/cowork-harness/pull/102">https://github.com/yaniv-golan/cowork-harness/pull/102</a></li>
<li>build(deps-dev): bump jsdom from 29.1.1 to 30.0.1 by @dependabot[bot] in <a href="https://github.com/yaniv-golan/cowork-harness/pull/96">https://github.com/yaniv-golan/cowork-harness/pull/96</a></li>
<li>release: 1.20.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/110">https://github.com/yaniv-golan/cowork-harness/pull/110</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.20.0">https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.20.0</a></p>
]]></content:encoded></item><item><title>Zuke Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/zuke-build/</link><pubDate>Fri, 07 Aug 2026 22:21:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/zuke-build/</guid><description>Version updated for https://github.com/zuke-build/zuke to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a small and explicit build automation tool that uses tagged template runs processes with sane defaults (throw on failure, capture output) and is injection-safe. It can generate GitHub Actions, GitLab CI, or Azure Pipelines YAML based on the provider specified in the configuration. The main purpose of this action is to automate code-based builds without relying on plugins or bespoke DSLs, providing a clean and refactor-safe approach to CI/CD workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zuke-build/zuke">https://github.com/zuke-build/zuke</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zuke-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a small and explicit build automation tool that uses tagged template runs processes with sane defaults (throw on failure, capture output) and is injection-safe. It can generate GitHub Actions, GitLab CI, or Azure Pipelines YAML based on the provider specified in the configuration. The main purpose of this action is to automate code-based builds without relying on plugins or bespoke DSLs, providing a clean and refactor-safe approach to CI/CD workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of the <code>zuke-build/zuke</code> composite action.</p>
<p>Three steps every Zuke job starts with, in one:</p>
<ol>
<li><strong>Harden the runner</strong> — <code>step-security/harden-runner</code>, before anything it governs.</li>
<li><strong>Check out</strong> the repository.</li>
<li><strong>Run a Zuke target.</strong></li>
</ol>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">ci</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">zuke-build/zuke@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">target</span>: <span style="color:#ae81ff">ci</span>
</span></span></code></pre></div><p>It goes <strong>first</strong> in the job — a remote action is fetched by the runner, not from your workspace, so it needs no checkout before it. That&rsquo;s the point: an egress policy only governs what runs after it.</p>
<h3 id="inputs">Inputs</h3>
<table>
  <thead>
      <tr>
          <th>Input</th>
          <th>Default</th>
          <th>What it does</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>target</code></td>
          <td><code>&quot;&quot;</code></td>
          <td>The Zuke target to run. Omit to harden and check out only.</td>
      </tr>
      <tr>
          <td><code>egress-policy</code></td>
          <td><code>audit</code></td>
          <td><code>audit</code> records outbound traffic; <code>block</code> enforces <code>allowed-endpoints</code>.</td>
      </tr>
      <tr>
          <td><code>allowed-endpoints</code></td>
          <td><code>&quot;&quot;</code></td>
          <td>Space-separated <code>host:port</code> list permitted under <code>block</code>.</td>
      </tr>
      <tr>
          <td><code>persist-credentials</code></td>
          <td><code>false</code></td>
          <td>Leave the token in git config, for a later push.</td>
      </tr>
      <tr>
          <td><code>fetch-depth</code></td>
          <td><code>1</code></td>
          <td>Commits to fetch. <code>0</code> is the full history, which a secret scan needs.</td>
      </tr>
      <tr>
          <td><code>deno-version</code></td>
          <td><code>&quot;&quot;</code></td>
          <td>Install this Deno. Usually unnecessary — the <code>./zuke</code> launcher bootstraps its own.</td>
      </tr>
  </tbody>
</table>
<h3 id="two-things-worth-knowing">Two things worth knowing</h3>
<p><strong>Pin the SHA.</strong> <code>@v1</code> moves. Whoever can move it can run code in your job — and you&rsquo;ve delegated your hardening to this step, so a moved tag could simply not harden:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">zuke-build/zuke@04ec1c67b0937db3bb5d19fe2b6f62a506e04432</span> <span style="color:#75715e"># v1.0.0</span>
</span></span></code></pre></div><p><strong><code>egress-policy</code> starts at <code>audit</code>, not <code>block</code></strong> — harden-runner&rsquo;s own default is <code>block</code>. Deliberate, since <code>block</code> with an empty <code>allowed-endpoints</code> fails a build on its first outbound request. It means the default configuration <em>records</em> egress rather than enforcing it. Run once on <code>audit</code>, take the endpoint list from the run&rsquo;s insights, then set both.</p>
<p>Running a target needs a committed <code>./zuke</code> launcher — that&rsquo;s what <code>zuke setup</code> writes. Without one the step fails with an annotation naming the fix.</p>
<p><strong>Docs:</strong> <a href="https://github.com/zuke-build/zuke/blob/master/docs/getting-started.md#the-zuke-buildzuke-action">the action</a> · <a href="https://github.com/zuke-build/zuke">Zuke</a></p>
]]></content:encoded></item><item><title>Postman Onboarding GCP Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/postman-onboarding-gcp-spec-discovery/</link><pubDate>Fri, 07 Aug 2026 14:47:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/postman-onboarding-gcp-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-gcp-spec-discovery-action to version v1.2.4.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of discovering and exporting OpenAPI specifications from Google Cloud services, such as BigQuery, Cloud Functions, and Firestore, using Application Default Credentials or Workload Identity Federation. It helps developers integrate their GCP resources seamlessly into Postman for onboarding, reducing manual effort by automatically resolving service configurations based on labels or specific API IDs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action">https://github.com/postman-cs/postman-gcp-spec-discovery-action</a></strong> to version <strong>v1.2.4</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-gcp-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of discovering and exporting OpenAPI specifications from Google Cloud services, such as BigQuery, Cloud Functions, and Firestore, using Application Default Credentials or Workload Identity Federation. It helps developers integrate their GCP resources seamlessly into Postman for onboarding, reducing manual effort by automatically resolving service configurations based on labels or specific API IDs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut and verify tags by ancestry by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/27">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/27</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/30">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/30</a></li>
<li>fix(test): assert the packaged version against package.json by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/31">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/31</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/32">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/32</a></li>
<li>fix(release): fetch the tag parent before ancestry checks by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/33">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/33</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/34">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/34</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/35">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/35</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/36">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/36</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/40">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/40</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/42">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/42</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/43">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/43</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/44">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/compare/v1.1.8...v1.2.4">https://github.com/postman-cs/postman-gcp-spec-discovery-action/compare/v1.1.8...v1.2.4</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Insights Linking</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/postman-onboarding-insights-linking/</link><pubDate>Fri, 07 Aug 2026 14:46:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/postman-onboarding-insights-linking/</guid><description>Version updated for https://github.com/postman-cs/postman-insights-onboarding-action to version v2.4.4.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of linking services discovered by Postman Insights to API Catalog workspaces and git repositories after deployment. It helps ensure that all discovered services are included in the organization’s catalog with detailed information such as a collection, repo link, and live telemetry. The action uses a human-user PMAK and session access token for authentication and validates these credentials before linking writes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-insights-onboarding-action">https://github.com/postman-cs/postman-insights-onboarding-action</a></strong> to version <strong>v2.4.4</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-insights-linking">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of linking services discovered by Postman Insights to API Catalog workspaces and git repositories after deployment. It helps ensure that all discovered services are included in the organization&rsquo;s catalog with detailed information such as a collection, repo link, and live telemetry. The action uses a human-user PMAK and session access token for authentication and validates these credentials before linking writes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut from bootstrap by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/66">https://github.com/postman-cs/postman-insights-onboarding-action/pull/66</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/67">https://github.com/postman-cs/postman-insights-onboarding-action/pull/67</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/68">https://github.com/postman-cs/postman-insights-onboarding-action/pull/68</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/69">https://github.com/postman-cs/postman-insights-onboarding-action/pull/69</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/70">https://github.com/postman-cs/postman-insights-onboarding-action/pull/70</a></li>
<li>feat: ship self-contained SEA binary (no npm/Node) by @mmorales-post in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/64">https://github.com/postman-cs/postman-insights-onboarding-action/pull/64</a></li>
<li>fix: accept live human Insights sessions by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/71">https://github.com/postman-cs/postman-insights-onboarding-action/pull/71</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/76">https://github.com/postman-cs/postman-insights-onboarding-action/pull/76</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/78">https://github.com/postman-cs/postman-insights-onboarding-action/pull/78</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/79">https://github.com/postman-cs/postman-insights-onboarding-action/pull/79</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@mmorales-post made their first contribution in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/64">https://github.com/postman-cs/postman-insights-onboarding-action/pull/64</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2.1.8...v2.4.4">https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2.1.8...v2.4.4</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut from bootstrap by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/66">https://github.com/postman-cs/postman-insights-onboarding-action/pull/66</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/67">https://github.com/postman-cs/postman-insights-onboarding-action/pull/67</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/68">https://github.com/postman-cs/postman-insights-onboarding-action/pull/68</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/69">https://github.com/postman-cs/postman-insights-onboarding-action/pull/69</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/70">https://github.com/postman-cs/postman-insights-onboarding-action/pull/70</a></li>
<li>feat: ship self-contained SEA binary (no npm/Node) by @mmorales-post in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/64">https://github.com/postman-cs/postman-insights-onboarding-action/pull/64</a></li>
<li>fix: accept live human Insights sessions by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/71">https://github.com/postman-cs/postman-insights-onboarding-action/pull/71</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/76">https://github.com/postman-cs/postman-insights-onboarding-action/pull/76</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/78">https://github.com/postman-cs/postman-insights-onboarding-action/pull/78</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/79">https://github.com/postman-cs/postman-insights-onboarding-action/pull/79</a></li>
</ul>
<h2 id="new-contributors-1">New Contributors</h2>
<ul>
<li>@mmorales-post made their first contribution in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/64">https://github.com/postman-cs/postman-insights-onboarding-action/pull/64</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2.1.8...v2.4.4">https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2.1.8...v2.4.4</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut from bootstrap by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/66">https://github.com/postman-cs/postman-insights-onboarding-action/pull/66</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/67">https://github.com/postman-cs/postman-insights-onboarding-action/pull/67</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/68">https://github.com/postman-cs/postman-insights-onboarding-action/pull/68</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/69">https://github.com/postman-cs/postman-insights-onboarding-action/pull/69</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/70">https://github.com/postman-cs/postman-insights-onboarding-action/pull/70</a></li>
<li>feat: ship self-contained SEA binary (no npm/Node) by @mmorales-post in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/64">https://github.com/postman-cs/postman-insights-onboarding-action/pull/64</a></li>
<li>fix: accept live human Insights sessions by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/71">https://github.com/postman-cs/postman-insights-onboarding-action/pull/71</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/76">https://github.com/postman-cs/postman-insights-onboarding-action/pull/76</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/78">https://github.com/postman-cs/postman-insights-onboarding-action/pull/78</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/79">https://github.com/postman-cs/postman-insights-onboarding-action/pull/79</a></li>
</ul>
<h2 id="new-contributors-2">New Contributors</h2>
<ul>
<li>@mmorales-post made their first contribution in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/64">https://github.com/postman-cs/postman-insights-onboarding-action/pull/64</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2.1.8...v2.4.4">https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2.1.8...v2.4.4</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/postman-onboarding-repo-sync/</link><pubDate>Fri, 07 Aug 2026 14:45:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.9.3.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of exporting Postman collections and environments into a repository and setting up CI, mock servers, and monitors around them. It solves the problem of ensuring that project assets are centralized and managed within the codebase, facilitating easier collaboration and deployment. The action provides capabilities to export projects, manage environments, and configure CI settings for integration with GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.9.3</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of exporting Postman collections and environments into a repository and setting up CI, mock servers, and monitors around them. It solves the problem of ensuring that project assets are centralized and managed within the codebase, facilitating easier collaboration and deployment. The action provides capabilities to export projects, manage environments, and configure CI settings for integration with GitHub Actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>perf(repo-sync): bound artifact acquisition reads by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/116">https://github.com/postman-cs/postman-repo-sync-action/pull/116</a></li>
<li>fix(deps): replace deprecated Faker with compatible v6 by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/117">https://github.com/postman-cs/postman-repo-sync-action/pull/117</a></li>
<li>fix(repo-mutation): reconcile stale branch before push by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/118">https://github.com/postman-cs/postman-repo-sync-action/pull/118</a></li>
<li>fix(repo-mutation): resolve generated artifact conflicts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/119">https://github.com/postman-cs/postman-repo-sync-action/pull/119</a></li>
<li>fix(release): notify the composite after Repo Sync publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/121">https://github.com/postman-cs/postman-repo-sync-action/pull/121</a></li>
<li>feat: add generated asset sync control by @sean-riney in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/123">https://github.com/postman-cs/postman-repo-sync-action/pull/123</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/126">https://github.com/postman-cs/postman-repo-sync-action/pull/126</a></li>
<li>fix(mock): default mocks to private by @andrewpostymt in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/125">https://github.com/postman-cs/postman-repo-sync-action/pull/125</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/128">https://github.com/postman-cs/postman-repo-sync-action/pull/128</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.9.3">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.9.3</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>perf(repo-sync): bound artifact acquisition reads by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/116">https://github.com/postman-cs/postman-repo-sync-action/pull/116</a></li>
<li>fix(deps): replace deprecated Faker with compatible v6 by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/117">https://github.com/postman-cs/postman-repo-sync-action/pull/117</a></li>
<li>fix(repo-mutation): reconcile stale branch before push by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/118">https://github.com/postman-cs/postman-repo-sync-action/pull/118</a></li>
<li>fix(repo-mutation): resolve generated artifact conflicts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/119">https://github.com/postman-cs/postman-repo-sync-action/pull/119</a></li>
<li>fix(release): notify the composite after Repo Sync publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/121">https://github.com/postman-cs/postman-repo-sync-action/pull/121</a></li>
<li>feat: add generated asset sync control by @sean-riney in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/123">https://github.com/postman-cs/postman-repo-sync-action/pull/123</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/126">https://github.com/postman-cs/postman-repo-sync-action/pull/126</a></li>
<li>fix(mock): default mocks to private by @andrewpostymt in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/125">https://github.com/postman-cs/postman-repo-sync-action/pull/125</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/128">https://github.com/postman-cs/postman-repo-sync-action/pull/128</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.9.3">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.9.3</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>perf(repo-sync): bound artifact acquisition reads by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/116">https://github.com/postman-cs/postman-repo-sync-action/pull/116</a></li>
<li>fix(deps): replace deprecated Faker with compatible v6 by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/117">https://github.com/postman-cs/postman-repo-sync-action/pull/117</a></li>
<li>fix(repo-mutation): reconcile stale branch before push by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/118">https://github.com/postman-cs/postman-repo-sync-action/pull/118</a></li>
<li>fix(repo-mutation): resolve generated artifact conflicts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/119">https://github.com/postman-cs/postman-repo-sync-action/pull/119</a></li>
<li>fix(release): notify the composite after Repo Sync publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/121">https://github.com/postman-cs/postman-repo-sync-action/pull/121</a></li>
<li>feat: add generated asset sync control by @sean-riney in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/123">https://github.com/postman-cs/postman-repo-sync-action/pull/123</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/126">https://github.com/postman-cs/postman-repo-sync-action/pull/126</a></li>
<li>fix(mock): default mocks to private by @andrewpostymt in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/125">https://github.com/postman-cs/postman-repo-sync-action/pull/125</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/128">https://github.com/postman-cs/postman-repo-sync-action/pull/128</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.9.3">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.9.3</a></p>
<h2 id="whats-changed-4">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>perf(repo-sync): bound artifact acquisition reads by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/116">https://github.com/postman-cs/postman-repo-sync-action/pull/116</a></li>
<li>fix(deps): replace deprecated Faker with compatible v6 by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/117">https://github.com/postman-cs/postman-repo-sync-action/pull/117</a></li>
<li>fix(repo-mutation): reconcile stale branch before push by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/118">https://github.com/postman-cs/postman-repo-sync-action/pull/118</a></li>
<li>fix(repo-mutation): resolve generated artifact conflicts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/119">https://github.com/postman-cs/postman-repo-sync-action/pull/119</a></li>
<li>fix(release): notify the composite after Repo Sync publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/121">https://github.com/postman-cs/postman-repo-sync-action/pull/121</a></li>
<li>feat: add generated asset sync control by @sean-riney in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/123">https://github.com/postman-cs/postman-repo-sync-action/pull/123</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/126">https://github.com/postman-cs/postman-repo-sync-action/pull/126</a></li>
<li>fix(mock): default mocks to private by @andrewpostymt in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/125">https://github.com/postman-cs/postman-repo-sync-action/pull/125</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/128">https://github.com/postman-cs/postman-repo-sync-action/pull/128</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.9.3">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.9.3</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Service Token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/postman-onboarding-service-token/</link><pubDate>Fri, 07 Aug 2026 14:44:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/postman-onboarding-service-token/</guid><description>Version updated for https://github.com/postman-cs/postman-resolve-service-token-action to version v2.1.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of minting fresh service account access tokens and team IDs for use in Postman Onboarding workflows. It solves the problem of managing service account credentials securely by generating them directly from the CI environment, reducing the need to store sensitive information in repository secrets or personal access tokens (PMAKs). The key capabilities include:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-resolve-service-token-action">https://github.com/postman-cs/postman-resolve-service-token-action</a></strong> to version <strong>v2.1.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-service-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of minting fresh service account access tokens and team IDs for use in Postman Onboarding workflows. It solves the problem of managing service account credentials securely by generating them directly from the CI environment, reducing the need to store sensitive information in repository secrets or personal access tokens (PMAKs). The key capabilities include:</p>
<ol>
<li><strong>Token Generation</strong>: Automatically generates a fresh access token and team ID for each run.</li>
<li><strong>Compliance with Postman Policies</strong>: Uses service account credentials as specified by Postman&rsquo;s API onboarding suite, ensuring compliance with security policies.</li>
<li><strong>Scalability</strong>: Suitable for CI/CD pipelines that require frequent token generation, such as those in a staging or development environment.</li>
</ol>
<p>The action is particularly useful for workflows that need to onboard new projects or update existing ones while maintaining security standards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(release): verify service-token artifacts and async monitors by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/37">https://github.com/postman-cs/postman-resolve-service-token-action/pull/37</a></li>
<li>perf(ci): accelerate Windows parity gate by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/38">https://github.com/postman-cs/postman-resolve-service-token-action/pull/38</a></li>
<li>test: avoid empty npm CLI path on Windows by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/39">https://github.com/postman-cs/postman-resolve-service-token-action/pull/39</a></li>
<li>chore: prepare v2.0.5 release by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/40">https://github.com/postman-cs/postman-resolve-service-token-action/pull/40</a></li>
<li>fix(release): classify dispatch-cut runs by the cut tag ref by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/41">https://github.com/postman-cs/postman-resolve-service-token-action/pull/41</a></li>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/42">https://github.com/postman-cs/postman-resolve-service-token-action/pull/42</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/43">https://github.com/postman-cs/postman-resolve-service-token-action/pull/43</a></li>
<li>fix(release): pass the required version input when dispatching a cut tag by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/44">https://github.com/postman-cs/postman-resolve-service-token-action/pull/44</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/45">https://github.com/postman-cs/postman-resolve-service-token-action/pull/45</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/46">https://github.com/postman-cs/postman-resolve-service-token-action/pull/46</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/47">https://github.com/postman-cs/postman-resolve-service-token-action/pull/47</a></li>
<li>chore(deps): bump the npm-minor-patch group across 1 directory with 3 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/51">https://github.com/postman-cs/postman-resolve-service-token-action/pull/51</a></li>
<li>fix(ci): make cache pin assertion semantic by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/52">https://github.com/postman-cs/postman-resolve-service-token-action/pull/52</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-resolve-service-token-action/compare/v2.0.4...v2.1.1">https://github.com/postman-cs/postman-resolve-service-token-action/compare/v2.0.4...v2.1.1</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Smoke Flow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/postman-onboarding-smoke-flow/</link><pubDate>Fri, 07 Aug 2026 14:43:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/postman-onboarding-smoke-flow/</guid><description>Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v3.4.2.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action reshapes and organizes a Postman Smoke collection into an ordered journey using the specified flow path. It automatically derives or curates a manifest from the OpenAPI specification if none is provided, supports OAuth2 and API key authentication, and can handle concurrent runs through lease-based concurrency management. The action is part of the Postman API Onboarding suite and requires a Postman access token for execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-smoke-flow-action">https://github.com/postman-cs/postman-smoke-flow-action</a></strong> to version <strong>v3.4.2</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-smoke-flow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action reshapes and organizes a Postman Smoke collection into an ordered journey using the specified flow path. It automatically derives or curates a manifest from the OpenAPI specification if none is provided, supports OAuth2 and API key authentication, and can handle concurrent runs through lease-based concurrency management. The action is part of the Postman API Onboarding suite and requires a Postman access token for execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): cut immutable tags only after gates pass on main by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/57">https://github.com/postman-cs/postman-smoke-flow-action/pull/57</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/58">https://github.com/postman-cs/postman-smoke-flow-action/pull/58</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/59">https://github.com/postman-cs/postman-smoke-flow-action/pull/59</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/60">https://github.com/postman-cs/postman-smoke-flow-action/pull/60</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/61">https://github.com/postman-cs/postman-smoke-flow-action/pull/61</a></li>
<li>fix(release): notify the composite after Smoke Flow publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/64">https://github.com/postman-cs/postman-smoke-flow-action/pull/64</a></li>
<li>fix(ci): split dist parity and add Dependabot writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/66">https://github.com/postman-cs/postman-smoke-flow-action/pull/66</a></li>
<li>fix(ci): use checkout v7 tag for writeback by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/68">https://github.com/postman-cs/postman-smoke-flow-action/pull/68</a></li>
<li>fix(ci): trigger writeback on dependabot branches by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/69">https://github.com/postman-cs/postman-smoke-flow-action/pull/69</a></li>
<li>fix(ci): pin writeback actions to immutable SHAs by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/70">https://github.com/postman-cs/postman-smoke-flow-action/pull/70</a></li>
<li>fix(ci): address Codex writeback feedback by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/71">https://github.com/postman-cs/postman-smoke-flow-action/pull/71</a></li>
<li>fix(ci): use ESM execSync and update permission test by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/72">https://github.com/postman-cs/postman-smoke-flow-action/pull/72</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.7...v3.4.2">https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.7...v3.4.2</a></p>
]]></content:encoded></item><item><title>GitHub Profile README Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/github-profile-readme-site/</link><pubDate>Fri, 07 Aug 2026 14:42:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/github-profile-readme-site/</guid><description>Version updated for https://github.com/profile-icons/github-profile-readme-site to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a static Astro site based on a user or organization’s README.md file. It generates an accessible, internationalized profile website with features such as profile avatar, tagline, icon links, and i18n translations, all while supporting GitHub README Markdown formatting. The action can be set up through repository templates or directly in workflow files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/profile-icons/github-profile-readme-site">https://github.com/profile-icons/github-profile-readme-site</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-profile-readme-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a static Astro site based on a user or organization&rsquo;s <code>README.md</code> file. It generates an accessible, internationalized profile website with features such as profile avatar, tagline, icon links, and i18n translations, all while supporting GitHub README Markdown formatting. The action can be set up through repository templates or directly in workflow files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="github-profile-readme-site---initial-release">GitHub Profile README Site - Initial Release</h1>
<p>Deploy your GitHub user or organization profile <code>README.md</code> as a static Astro.js site using Actions with:</p>
<ul>
<li>profile avatar</li>
<li>tagline</li>
<li>icon links</li>
<li>i18n translations</li>
<li>and full support of GitHub README Markdown format</li>
</ul>
<p>An example site can be found here: <a href="https://profile-icons.github.io/github-profile-readme-site/">https://profile-icons.github.io/github-profile-readme-site/</a></p>
<h2 id="instructions">Instructions</h2>
<p>Refer to the <a href="https://github.com/profile-icons/github-profile-readme-site#github-profile-readme-site">repository <code>README.md</code></a></p>
]]></content:encoded></item><item><title>Garita PII Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/garita-pii-guard/</link><pubDate>Fri, 07 Aug 2026 14:41:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/garita-pii-guard/</guid><description>Version updated for https://github.com/proscar87/garita to version v0.24.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Garita is a GitHub Action that helps prevent sensitive information like personal names, credit card numbers, and passwords from being committed to repositories. It uses a configuration file to specify which patterns are prohibited, and it checks files against this list using regular expressions. This ensures compliance with data protection regulations such as the FLPDPPP (Federal Law for Protection of Personal Data in Mexico).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/proscar87/garita">https://github.com/proscar87/garita</a></strong> to version <strong>v0.24.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/garita-pii-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Garita is a GitHub Action that helps prevent sensitive information like personal names, credit card numbers, and passwords from being committed to repositories. It uses a configuration file to specify which patterns are prohibited, and it checks files against this list using regular expressions. This ensures compliance with data protection regulations such as the FLPDPPP (Federal Law for Protection of Personal Data in Mexico).</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Los cuatro confirmados del frente de <strong>evasión</strong> de la quinta oleada. Ninguno requiere mala fe: así es como los datos entran de verdad.</p>
<ul>
<li><strong>NFD</strong>: <code>descifrar()</code> normaliza a NFC. Sin eso, un archivo con «Cédula» escrito como <em>e + acento combinante</em> —lo que produce macOS y varios exportadores— era otra cadena para cada patrón acentuado del proyecto. Los detectores con <code>exige_contexto</code> quedaban <strong>completamente</strong> ciegos y el de nombres no casaba un solo nombre con acento.</li>
<li><strong>El detector de nombres pasa a <code>finditer</code></strong>: con <code>search</code>, un padrón exportado en una sola línea —un JSON de <code>jq -c</code>— reportaba <strong>un</strong> nombre de cuatrocientos. Y la línea base congela ese 1, así que después se podían agregar los demás sin que el veredicto cambiara.</li>
<li><strong>Secretos sin comillas</strong>: <code>.env</code>, <code>.properties</code>, <code>.ini</code>, el bloque <code>environment:</code> de un docker-compose, un <code>Secret</code> de Kubernetes. Ahí <code>DB_PASSWORD=&lt;20 aleatorios&gt;</code> no lo veía nadie — el hueco justo bajo el consejo que la propia herramienta imprime. El código normal (<code>password = config.db_password</code>, la tupla de <code>requests</code>) sigue sin marcarse. De paso, el nombre admite prefijos: <code>DB_</code>, <code>APP_</code>, <code>spring.datasource.</code> — antes ni con comillas casaba.</li>
<li><strong>Una coincidencia que es un campo completo</strong> ya no vive «dentro de un número»: una fila de export bancario llegaba al umbral de la ventana con sus propios importes y la CLABE válida se descartaba sin validar nada.</li>
</ul>
<p>Cinco pruebas nuevas (255 en total). En un repo consumidor real, esto destapó <strong>cuatro nombres de personas</strong> que se estaban perdiendo.</p>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/raviqqe/muffy/</link><pubDate>Fri, 07 Aug 2026 14:39:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.4.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation of static websites, including checking for broken links and HTML errors across multiple pages. It offers recursive link checking, markup validation, persistent caching with configurable cache ages and stale-while-revalidate periods, concurrency and rate limits, and integrates robots.txt and sitemap support. The action is particularly useful for maintaining website integrity and ensuring a consistent user experience.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.4.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation of static websites, including checking for broken links and HTML errors across multiple pages. It offers recursive link checking, markup validation, persistent caching with configurable cache ages and stale-while-revalidate periods, concurrency and rate limits, and integrates <code>robots.txt</code> and sitemap support. The action is particularly useful for maintaining website integrity and ensuring a consistent user experience.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>b6e841670ad24776b45aaf6811ccc91338edd391 Bump version (#1224)</li>
<li>57bd3df04a0d8da546c902eec263d5344c35dac0 Fix user permission on Docker (#1222)</li>
<li>694027b2d7929ffd09919e50a456ae3a0c069b99 Update pnpm (#1221)</li>
<li>affb2721c8ad2efd84c308299592e94557b09bd0 Fix combination operator behaviour in RNC (#1220)</li>
<li>1942431ce5caff04ef75bb117f948f4e154569fb Cache versioning with major and minor versions (#1219)</li>
<li>6e4b756875a54cca377f46f1068e91c71d5e42fc Move RNC schema logic (#1216)</li>
<li>e2dce930d3a45e3b29eda223de742e6deb383c15 Remove <code>external</code> hop (#1218)</li>
<li>4e66de3541f3ce83468a3d4958da11e0f87b0dbc Wildcard names (#1183)</li>
</ul>
]]></content:encoded></item><item><title>wavedash-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/wavedash-action/</link><pubDate>Fri, 07 Aug 2026 14:39:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/wavedash-action/</guid><description>Version updated for https://github.com/remarkablegames/wavedash-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading and publishing web game files to Wavedash. It simplifies the integration of Wavedash into game development workflows, handling configuration file creation and injection of the Wavedash SDK as needed. The action supports various inputs such as API token, game ID, upload directory, entrypoint, SDK version, and options for building and publishing games with release notes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablegames/wavedash-action">https://github.com/remarkablegames/wavedash-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wavedash-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading and publishing web game files to Wavedash. It simplifies the integration of Wavedash into game development workflows, handling configuration file creation and injection of the Wavedash SDK as needed. The action supports various inputs such as API token, game ID, upload directory, entrypoint, SDK version, and options for building and publishing games with release notes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="103-2026-08-07"><a href="https://github.com/remarkablegames/wavedash-action/compare/v1.0.2...v1.0.3">1.0.3</a> (2026-08-07)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump @wvdsh/sdk-js from 1.3.40 to 1.3.41 (<a href="https://github.com/remarkablegames/wavedash-action/issues/8">#8</a>) (<a href="https://github.com/remarkablegames/wavedash-action/commit/e384fb4faeebc53232a8f65d4011f052111a6864">e384fb4</a>)</li>
</ul>
]]></content:encoded></item><item><title>PR Explainer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/pr-explainer/</link><pubDate>Fri, 07 Aug 2026 14:37:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/pr-explainer/</guid><description>Version updated for https://github.com/rhty/pr-explainer to version v0.2.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PR Explainer is a GitHub Action that automates the creation of interactive HTML explanations for pull requests. It uses OpenAI or Anthropic to generate explanations based on the changes in a PR and posts the link back to the PR’s comment thread. The action provides features like responsive HTML reports, sandboxing for security, and customizable language support.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rhty/pr-explainer">https://github.com/rhty/pr-explainer</a></strong> to version <strong>v0.2.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-explainer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PR Explainer is a GitHub Action that automates the creation of interactive HTML explanations for pull requests. It uses OpenAI or Anthropic to generate explanations based on the changes in a PR and posts the link back to the PR&rsquo;s comment thread. The action provides features like responsive HTML reports, sandboxing for security, and customizable language support.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Align package version metadata with release tag v0.2.3 by @rhty with @Copilot in <a href="https://github.com/rhty/pr-explainer/pull/9">https://github.com/rhty/pr-explainer/pull/9</a></li>
<li>Fix GitHub Pages deploy job stuck in deployment_queued timeout by @rhty with @Copilot in <a href="https://github.com/rhty/pr-explainer/pull/10">https://github.com/rhty/pr-explainer/pull/10</a></li>
<li>chore: bump version to v0.2.5 by @rhty with @Copilot in <a href="https://github.com/rhty/pr-explainer/pull/11">https://github.com/rhty/pr-explainer/pull/11</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@rhty with @Copilot made their first contribution in <a href="https://github.com/rhty/pr-explainer/pull/9">https://github.com/rhty/pr-explainer/pull/9</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/rhty/pr-explainer/compare/v0.2.1...v0.2.5">https://github.com/rhty/pr-explainer/compare/v0.2.1...v0.2.5</a></p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/kaniko-build-action/</link><pubDate>Fri, 07 Aug 2026 14:36:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints a greeting message either to “Hello World” or “Hello” followed by a specified name, along with the current time. It automates the task of creating simple greetings and timestamps in automated workflows, making it useful for various applications where personalized messages are needed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints a greeting message either to &ldquo;Hello World&rdquo; or &ldquo;Hello&rdquo; followed by a specified name, along with the current time. It automates the task of creating simple greetings and timestamps in automated workflows, making it useful for various applications where personalized messages are needed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>Vibe Index</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/vibe-index/</link><pubDate>Fri, 07 Aug 2026 14:36:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/vibe-index/</guid><description>Version updated for https://github.com/roxblnfk/action-vibe-index to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Vibe Index automatically calculates and displays how much of a repository’s code was written by AI versus humans through its git history. It provides a simple, customizable badge to show this information, helping contributors assess the level of AI involvement in their projects. The action can be run as part of a GitHub Actions workflow to update the badge on each push or on demand.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/roxblnfk/action-vibe-index">https://github.com/roxblnfk/action-vibe-index</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibe-index">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Vibe Index</strong> automatically calculates and displays how much of a repository&rsquo;s code was written by AI versus humans through its git history. It provides a simple, customizable badge to show this information, helping contributors assess the level of AI involvement in their projects. The action can be run as part of a GitHub Actions workflow to update the badge on each push or on demand.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="140-2026-08-07"><a href="https://github.com/roxblnfk/action-vibe-index/compare/v1.3.1...v1.4.0">1.4.0</a> (2026-08-07)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>signatures:</strong> detect JetBrains Junie as an AI committer (<a href="https://github.com/roxblnfk/action-vibe-index/commit/828664a2a71795fe986718c1f0a440f18c74f90f">828664a</a>)</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>explain where push:true lands the badge (branch vs release PR) (<a href="https://github.com/roxblnfk/action-vibe-index/commit/d2cbec6d44440f1c5f9eaf24ca47524345d13fb4">d2cbec6</a>)</li>
</ul>
]]></content:encoded></item><item><title>scalified/docker-run-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/scalified/docker-run-action/</link><pubDate>Fri, 07 Aug 2026 14:35:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/scalified/docker-run-action/</guid><description>Version updated for https://github.com/Scalified/docker-run-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Docker Run GitHub Action allows developers to automate the execution of docker run commands with customizable inputs, solving the problem of needing to manually write and maintain repetitive Docker command configurations in workflows. It provides key capabilities such as running containers in detached mode, setting environment variables, and configuring health checks. The action is useful for automating container management tasks within GitHub CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Scalified/docker-run-action">https://github.com/Scalified/docker-run-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/scalified-docker-run-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Docker Run GitHub Action allows developers to automate the execution of <code>docker run</code> commands with customizable inputs, solving the problem of needing to manually write and maintain repetitive Docker command configurations in workflows. It provides key capabilities such as running containers in detached mode, setting environment variables, and configuring health checks. The action is useful for automating container management tasks within GitHub CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: networks (5776dd4)</li>
<li>Extend container health check wait time (3c2b4c1)</li>
<li>feat: 1.0.0 (05b343a)</li>
<li>Initial commit (871c53a)</li>
</ul>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/sherpa.sh/</link><pubDate>Fri, 07 Aug 2026 14:34:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven tool that simplifies infrastructure management by automating the deployment of applications across various cloud providers. It uses natural language prompts to generate and configure complex infrastructure configurations, eliminating the need for manual YAML files or DevOps expertise. With Sherpa, developers can describe their application requirements in plain English, and it handles the rest, from server provisioning to load balancing and CDN configuration. The tool is designed to be open-source, transparent, and community-driven, allowing users to see exactly how their infrastructure works and contribute to its development.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven tool that simplifies infrastructure management by automating the deployment of applications across various cloud providers. It uses natural language prompts to generate and configure complex infrastructure configurations, eliminating the need for manual YAML files or DevOps expertise. With Sherpa, developers can describe their application requirements in plain English, and it handles the rest, from server provisioning to load balancing and CDN configuration. The tool is designed to be open-source, transparent, and community-driven, allowing users to see exactly how their infrastructure works and contribute to its development.</p>
]]></content:encoded></item><item><title>Socket Basics Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/socket-basics-security-scanner/</link><pubDate>Fri, 07 Aug 2026 14:33:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/socket-basics-security-scanner/</guid><description>Version updated for https://github.com/SocketDev/socket-basics to version v3.0.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 8 repositories.
Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Socket Basics automates the process of running various security scanners across multiple languages and container images, providing a unified view of findings. It normalizes outputs into Socket’s standardized format and delivers results through preferred notification channels, including pull request comments. The tool is configured in the Socket Dashboard and can be easily integrated into GitHub Actions with a scoped API key for secure scanning without requiring any workflow changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SocketDev/socket-basics">https://github.com/SocketDev/socket-basics</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>8</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/socket-basics-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Socket Basics automates the process of running various security scanners across multiple languages and container images, providing a unified view of findings. It normalizes outputs into Socket&rsquo;s standardized format and delivers results through preferred notification channels, including pull request comments. The tool is configured in the Socket Dashboard and can be easily integrated into GitHub Actions with a scoped API key for secure scanning without requiring any workflow changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="summary">Summary</h2>
<p><strong>Major release:</strong> Trivy-backed scanning returns, now built and published through Socket&rsquo;s own supply chain ⚡️</p>
<h3 id="-added">🐳 Added</h3>
<ul>
<li>Container image and Dockerfile scanning (<a href="https://trivy.dev">Trivy</a>) restored in the pre-built GitHub Action and Docker images. Trivy now comes from a <strong>Socket-built distribution</strong> — rebuilt from unmodified upstream source (<code>v0.73.0</code>) by Socket&rsquo;s own release pipeline and pinned by digest in the Dockerfiles (<code>TRIVY_IMAGE</code> build arg; overridable for builds without registry access).</li>
<li>End-to-end integration test for the Trivy connector (fixture Dockerfile scan through <code>--dockerfiles</code>), plus smoke-test assertions that the bundled <code>trivy</code> matches the pinned version and can execute the connector&rsquo;s scan path.</li>
<li>Reintroduced <code>latest</code> and <code>latest-heavy</code> floating Docker tag aliases for customers who prefer always receiving the latest Socket Basics releases.
<ul>
<li><strong>We still recommend pinning an exact version or digest for secure, reproducible pipelines.</strong></li>
<li>Exact version tags remain immutable registry-side.</li>
</ul>
</li>
</ul>
<h3 id="-changed">🔄 Changed</h3>
<ul>
<li><strong>Behavioral (the reason this is a major):</strong> Trivy-backed scanning was intentionally disabled in the <code>2.x.x</code> pre-built images following repeated Trivy supply-chain compromises, and documented as such throughout the project. With this <code>3.0.0</code> release, <strong>Trivy is deliberately re-enabled</strong>: configurations that set Trivy parameters (<code>--images</code>, <code>--dockerfiles</code>, <code>trivy_vuln_enabled</code>, …) will begin producing container / Dockerfile findings again.
<ul>
<li>🚨 <strong>TL;DR: pipelines that gate on findings should expect new results on the first run after upgrading.</strong></li>
</ul>
</li>
<li>OSS toolchain refresh: TruffleHog <code>v3.96.0</code>, OpenGrep <code>v1.26.0</code> (SAST rule updates may shift findings), uv <code>v0.12.1</code>, gosec <code>v2.28.0</code>, Go <code>v1.26.5</code> (<code>app_tests</code>), Socket CLI <code>v2.6.3</code> (<code>Dockerfile.heavy</code>), and the <code>socketdev</code> Python SDK to <code>v3.5.0</code> (typed fail-closed batch purl parameters).
<ul>
<li>Runtime bases (<code>python:3.12</code>, <code>node:22</code>) remain unchanged.</li>
</ul>
</li>
<li>Dependabot no longer tracks the <code>aquasecurity/trivy</code> base image; Trivy updates flow through Socket&rsquo;s release process, never independent bumps.</li>
</ul>
<h3 id="-fixed">🔧 Fixed</h3>
<ul>
<li>The <code>app_tests</code> image had been unbuildable since the repository layout migration (stale source references, wrong build context, dereferenced <code>npm</code> symlinks, corrupt <code>uv.lock</code>) — repaired and building in CI again.</li>
<li>Documentation: removed the now-outdated &ldquo;temporarily ships without Trivy&rdquo; notices repo-wide (they described the intentional 2.x posture); APT install instructions now use upstream&rsquo;s <code>generic</code> distribution (required since Trivy <code>v0.72.0</code>).
<ul>
<li>Warnings against using Trivy <code>v0.69.4</code>–<code>v0.69.6</code> (the compromised version range) retained for native installs.</li>
</ul>
</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SocketDev/socket-basics/compare/v2.2.1...v3.0.0">https://github.com/SocketDev/socket-basics/compare/v2.2.1...v3.0.0</a></p>
]]></content:encoded></item><item><title>Contributors Generator Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/contributors-generator-action/</link><pubDate>Fri, 07 Aug 2026 14:32:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/contributors-generator-action/</guid><description>Version updated for https://github.com/somaz94/contributors-action to version v1.2.0.
This action is used across all versions by 14 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Contributors Action automates the generation and management of a contributors list from GitHub repository data. It supports various output formats such as table, list, or image grid, allows section updates, filtering, sorting, customization, and dry runs to preview outputs before writing files. The action is useful for maintaining a comprehensive contributors’ page within repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/contributors-action">https://github.com/somaz94/contributors-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>14</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/contributors-generator-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Contributors Action automates the generation and management of a contributors list from GitHub repository data. It supports various output formats such as table, list, or image grid, allows section updates, filtering, sorting, customization, and dry runs to preview outputs before writing files. The action is useful for maintaining a comprehensive contributors&rsquo; page within repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="cicd">CI/CD</h3>
<ul>
<li>add PR welcome workflow stub by @somaz94</li>
<li>add ok-to-test workflow stub by @somaz94</li>
<li>use reusable contributors workflow by @somaz94</li>
<li>use reusable dependabot-auto-merge workflow by @somaz94</li>
<li>use reusable issue-greeting workflow by @somaz94</li>
<li>use reusable stale-issues workflow by @somaz94</li>
<li>adopt semantic-pr, labels, lock-threads, PR size, and auto-assign reusables by @somaz94</li>
<li>remove DCO workflow by @somaz94</li>
<li>add a golangci-lint config scoped to defect-finding linters by @somaz94</li>
</ul>
<h3 id="chore">Chore</h3>
<ul>
<li>bump golang from <code>3ad5730</code> to <code>0178a64</code> (#11) by @dependabot[bot] in #11</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>ship a prebuilt multi-arch image instead of building per run by @somaz94</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/contributors-action/compare/v1.1.2...v1.2.0">https://github.com/somaz94/contributors-action/compare/v1.1.2...v1.2.0</a></p>
]]></content:encoded></item><item><title>Helm OCI Push</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/helm-oci-push/</link><pubDate>Fri, 07 Aug 2026 14:31:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/helm-oci-push/</guid><description>Version updated for https://github.com/somaz94/helm-oci-push-action to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action helm-oci-push-action automates the process of pushing Helm charts to various OCI registries, including Google Container Registry (GHCR), Amazon Elastic Container Registry (ECR), and more. It supports different input modes such as pre-packaged tarball globs, comma-separated chart paths, and directory scans, making it versatile for both development and deployment workflows. The action provides features like dry-run mode for PR validation, skipping existing versions to ensure idempotent releases, and handling authentication via either provider-specific actions or directly with the registry URL if already authenticated.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/helm-oci-push-action">https://github.com/somaz94/helm-oci-push-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/helm-oci-push">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>helm-oci-push-action</code> automates the process of pushing Helm charts to various OCI registries, including Google Container Registry (GHCR), Amazon Elastic Container Registry (ECR), and more. It supports different input modes such as pre-packaged tarball globs, comma-separated chart paths, and directory scans, making it versatile for both development and deployment workflows. The action provides features like dry-run mode for PR validation, skipping existing versions to ensure idempotent releases, and handling authentication via either provider-specific actions or directly with the registry URL if already authenticated.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>Resolve helm latest via get.helm.sh to avoid GitHub API rate limit (438970a)</li>
<li>Fetch helm on the build platform so the arm64 image builds without emulation (6163690)</li>
</ul>
<h3 id="cicd">CI/CD</h3>
<ul>
<li>Add DCO check via shared reusable workflow (7d8e394)</li>
<li>Pin Helm version and authenticate setup-helm to reduce CI flakes (f2a4b02)</li>
<li>Add PR welcome workflow stub (531af39)</li>
<li>Add ok-to-test workflow stub (53bf7d8)</li>
<li>Use reusable contributors workflow (9a37e8c)</li>
<li>Use reusable dependabot-auto-merge workflow (fad8371)</li>
<li>Use reusable issue-greeting workflow (02c310d)</li>
<li>Use reusable stale-issues workflow (9d5d1bd)</li>
<li>Adopt semantic-pr, labels, lock-threads, PR size, and auto-assign reusables (1423e52)</li>
<li>Remove DCO workflow (89fb70c)</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>Update changelog (a8629b2)</li>
<li>Update changelog (02d1b35)</li>
<li>Update changelog (d63df31)</li>
</ul>
<h3 id="miscellaneous">Miscellaneous</h3>
<ul>
<li>Bump alpine from 3.23 to 3.24 in the docker-minor group (#2) (3e7ad91)</li>
<li>Bump actions/checkout from 6 to 7 (#3) (e6bb891)</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>Ship a prebuilt multi-arch image instead of building per run (3d5364a)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/helm-oci-push-action/compare/v1.0.2...v1.1.0">https://github.com/somaz94/helm-oci-push-action/compare/v1.0.2...v1.1.0</a></p>
]]></content:encoded></item><item><title>Ternary Operator Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/ternary-operator-action/</link><pubDate>Fri, 07 Aug 2026 14:30:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/ternary-operator-action/</guid><description>Version updated for https://github.com/somaz94/ternary-operator to version v1.6.1.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action evaluates conditional expressions and sets dynamic outputs based on the results, solving problems related to creating flexible, condition-driven workflows. It supports multiple conditions, rich operators, case-insensitive comparisons, default values, JSON output, simple syntax, debugging, zero dependencies, and fast execution. The action is useful for conditional deployments, dynamic configuration, feature flags, multi-environment CI/CD, and resource scaling.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/ternary-operator">https://github.com/somaz94/ternary-operator</a></strong> to version <strong>v1.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ternary-operator-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action evaluates conditional expressions and sets dynamic outputs based on the results, solving problems related to creating flexible, condition-driven workflows. It supports multiple conditions, rich operators, case-insensitive comparisons, default values, JSON output, simple syntax, debugging, zero dependencies, and fast execution. The action is useful for conditional deployments, dynamic configuration, feature flags, multi-environment CI/CD, and resource scaling.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="chore">Chore</h3>
<ul>
<li>bump the action image to v1.6.1 by @somaz94</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/ternary-operator/compare/v1.6.0...v1.6.1">https://github.com/somaz94/ternary-operator/compare/v1.6.0...v1.6.1</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/classroom-to-sheets-integration/</link><pubDate>Fri, 07 Aug 2026 14:28:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending assignment results from GitHub Classroom to a Google Sheet. It integrates with Google Sheets API and allows users to automatically update their grades in a shared Google Sheet using the student’s GitHub username. The action requires setting up specific secrets for authentication, including service account credentials and Google Sheet IDs. Users can integrate this action into their GitHub workflows to streamline grading processes by updating results directly in their Google Sheets.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending assignment results from GitHub Classroom to a Google Sheet. It integrates with Google Sheets API and allows users to automatically update their grades in a shared Google Sheet using the student&rsquo;s GitHub username. The action requires setting up specific secrets for authentication, including service account credentials and Google Sheet IDs. Users can integrate this action into their GitHub workflows to streamline grading processes by updating results directly in their Google Sheets.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>GitGalaxy Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/gitgalaxy-scanner/</link><pubDate>Fri, 07 Aug 2026 14:28:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/gitgalaxy-scanner/</guid><description>Version updated for https://github.com/squid-protocol/gitgalaxy to version v2.4.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GitGalaxy automates the scan of large, multi-language codebases that do not compile cleanly by scanning the entire system as one entity without needing to build each language separately. It provides a comprehensive analysis including SARIF files, CycloneDX SBOMs, and risk-exposure scores per file, folder, and repo, which can be integrated into CI/CD pipelines for faster development and security monitoring.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/squid-protocol/gitgalaxy">https://github.com/squid-protocol/gitgalaxy</a></strong> to version <strong>v2.4.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gitgalaxy-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GitGalaxy automates the scan of large, multi-language codebases that do not compile cleanly by scanning the entire system as one entity without needing to build each language separately. It provides a comprehensive analysis including SARIF files, CycloneDX SBOMs, and risk-exposure scores per file, folder, and repo, which can be integrated into CI/CD pipelines for faster development and security monitoring.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="gitgalaxy-v247-the-calibration-release">GitGalaxy v2.4.7: The Calibration Release</h1>
<p>v2.4.6 was about proving the regex engine wouldn&rsquo;t break under adversarial input. This cycle closes out two epics that started as a result: a corpus-wide audit of the risk equations for the same class of bug that let one dangerous function call score 10x differently depending on which language it was written in (epic #1056), and a full pass deepening structural-signature test coverage across all 45 supported languages (epic #1069). Along the way, four real extraction-correctness bugs got found and fixed, six separate PRs removed thirteen risk-scoring signals that couldn&rsquo;t be structurally backed by a regex-only engine rather than keeping them at a false confidence level, and a second round of README fixes corrected six more claims that didn&rsquo;t match the code.</p>
<h2 id="correctness-fixes-the-extraction-engine">Correctness Fixes: The Extraction Engine</h2>
<p><strong>Nested functions were silently dropped from every language (#1045)</strong></p>
<p><em>What we found:</em> Two of the extraction engine&rsquo;s four slicing modes (<code>_slice_by_braces</code> and <code>_slice_by_indentation</code> in <code>detector.py</code>) shared a guard — <code>if start_idx &lt; last_end_idx: continue</code> — that skipped any function match starting before the previous match&rsquo;s end. A nested or inner function necessarily starts before its enclosing function ends, so every nested function was silently dropped instead of becoming its own <code>FunctionNode</code>: undercounting <code>function_count</code> and folding the nested function&rsquo;s complexity into its parent&rsquo;s aggregate instead of reporting it separately.</p>
<p><em>Why nothing caught it:</em> no existing test exercised a <code>def</code>-inside-<code>def</code> or brace-nested function; the suite covered top-level extraction exhaustively but never a nested case.</p>
<p><em>What we did:</em> removed the guard — each match already resolves its own end independently from its own start (brace-depth tracking for braces, dedent tracking for indentation), so once a nested match is allowed through at all it&rsquo;s already correctly bounded. Added regression tests for both brace-style and indentation-style nesting, plus a sibling-nested case.</p>
<p><em>Known limitations:</em> function counts are expected to increase for any corpus file with nested functions — that&rsquo;s the intended effect. Local verification didn&rsquo;t include a <code>crucible_check.py</code> run (no <code>LANGUAGE_CRUCIBLE_PATH</code> configured for this PR); deferred to CI&rsquo;s <code>crucible-audit</code> per the repo&rsquo;s cost-conscious-verification convention.</p>
<p><strong>Nested classes truncated their own outer class&rsquo;s scope (#1044)</strong></p>
<p><em>What we found:</em> class scope was computed as &ldquo;declaration to the <em>next</em> class declaration&rsquo;s start,&rdquo; so a class nested inside another one truncated the outer class&rsquo;s scope right where the nested class began — silently dropping every method declared after it from <code>method_count</code>, <code>state_entanglement</code>, and <code>lcom_score</code>.</p>
<p><em>Why nothing caught it:</em> no regression test exercised nested classes; the bug required tracing three separate mechanisms at once (scope resolution, method-to-class linking, and shared string/comment shielding) to reproduce.</p>
<p><em>What we did:</em> resolve each class&rsquo;s real end via brace-depth (or dedent-depth) tracking, the same dispatch already used for function slicing, and fixed method-linking to assign each function to its innermost enclosing class only. Two more bugs surfaced while doing this: <code>class_pattern</code>&rsquo;s leading <code>\s*</code> could anchor on a blank line before <code>class</code> instead of the declaration itself, corrupting the new indent-depth math (fixed by anchoring on the class name&rsquo;s own position); and <code>func_start</code> was matching against pre-macro-shield code instead of post-shield code, so C-family <code>#ifdef</code>/<code>#else</code> dead-branch shielding had been silently a no-op. Concretely: Godot&rsquo;s <code>object.h</code> went from one bogus 464-line <code>initialize_class</code> function to roughly 20 correctly-sized, correctly-named real methods — verified by hand against the actual file.</p>
<p><em>Known limitations:</em> none identified beyond scope; both golden-master fixtures were reblessed and <code>crucible_check.py</code> passed clean on both full-precision and zero-dependency modes.</p>
<p><strong>Argument counts inflated by commas inside nested types (#1036)</strong></p>
<p><em>What we found:</em> argument counting ran <code>.count(&quot;,&quot;)</code> over the whole captured function signature, so any nested comma — generic type hints (<code>Map&lt;A, B&gt;</code>, <code>Dict[str, int]</code>), default dict/list literals, or nested callback signatures — inflated the count as if each were a separate top-level argument. FastAPI&rsquo;s <code>HTTPException.__init__</code>, whose params are wrapped in heavily-nested <code>Annotated[..., Doc(&quot;&quot;&quot;...&quot;&quot;&quot;)]</code> hints, was a real example of the overcount in the corpus.</p>
<p><em>What we did:</em> added a depth- and string-aware sweep (<code>_count_top_level_args</code>) that tracks <code>()</code>, <code>[]</code>, <code>{}</code>, <code>&lt;&gt;</code> nesting and skips commas inside string literals, counting only true top-level argument separators.</p>
<p><em>Verification:</em> both golden masters reblessed (structural magnitude and 3D coordinates shift for files with nested-bracket signatures, cascading corpus-wide since positions are relative), <code>crucible_check.py</code> clean on both modes, and manual synthetic cases confirmed by hand (<code>def foo(data: Dict[str, int])</code> → 1 arg; <code>def foo(data: dict = {&quot;x&quot;: 1, &quot;y&quot;: 2}, z=5)</code> → 2 args; <code>foo(Map&lt;String, Integer&gt; data, int y)</code> → 2 args).</p>
<p><strong>A hardcoded 250-function-per-file cap was silently truncating the densest files in the corpus (#1063)</strong></p>
<p><em>What we found:</em> <code>detector.py</code>&rsquo;s <code>MAX_SATELLITES = 250</code> discarded any function beyond the 250th in a single file, with no flag, log, or trace for consumers. Only 5 files in the ~935-file language-crucible corpus ever hit it (<code>roslyn/LanguageParser.cs</code>, <code>flutter/semantics.dart</code>, <code>zig/InternPool.zig</code>, <code>wasmtime_pulley_interp.rs</code>, an Apollo-11 AGC assembly file), but their real function counts — 406 to 607, confirmed locally — were frozen at exactly 250, understating file mass and blinding downstream risk ranking for exactly the files that should have ranked highest.</p>
<p><em>What we did:</em> removed the cap entirely rather than just surfacing a truncation flag — <code>finditer()</code> already scans every match unconditionally regardless of the cap, so the only added cost is metric calculation on the extra matches for those 5 files.</p>
<p><em>Why the golden-master diff is large:</em> ~309 entries changed, but the cause is singular — those 5 files&rsquo; corrected mass ripples into repo-wide summary stats and the 3D spatial layout, since PageRank/blast-radius coordinates are computed relative to the whole corpus. No unrelated file&rsquo;s function count or content changed.</p>
<h2 id="risk-equation-calibration-epic-1056">Risk-Equation Calibration (Epic #1056)</h2>
<p>Epic #1056 audited every tier-aware <code>_calc_*()</code> risk equation in <code>signal_processor.py</code> for the class of bug found in the previous cycle: a language-tier constant (<code>fc</code>/<code>irc</code>/<code>ot</code> — the framework&rsquo;s &ldquo;how much credit does this language&rsquo;s type system earn&rdquo; inputs) that inverts or wildly distorts scoring for otherwise-identical evidence. A reusable audit harness (<code>audit_risk_equations.py</code>, #1097) swept every equation for two things: direction (tier1 should never score above tier2/tier3 for the same evidence) and magnitude (flagging any tier ratio over 5x). Of the 11 equations in scope, 5 (<code>_calc_graveyard</code>, <code>_calc_api_exposure</code>, <code>_calc_spec_alignment</code>, <code>_calc_civil_war</code>, <code>_calc_secrets_risk</code>) take no tier constant at all — confirmed tier-blind by construction, not swept further. Of the remaining 6, one had already been fixed (see below) and one more calibration bug turned up:</p>
<p><strong>Identical dangerous code scored 10x differently depending on language (#1067)</strong></p>
<p><em>What we found:</em> <code>_calc_safety()</code> subtracted a flat 0.25 <code>systems_buffer</code> from <code>net_exposure</code> for any tier2/tier3 language (Python, JS, C/C++, Ruby, Kotlin, PHP, and everything else). Since real files&rsquo; <code>net_exposure</code> is typically well under 0.25, the flat subtraction wiped out nearly all attack signal instead of tempering it: identical dangerous-execution evidence — one <code>eval()</code>/<code>os.system()</code> call — scored 52–66 on a Rust file but only 5–7 on a Python file of the same size.</p>
<p><em>What we did:</em> replaced the flat subtraction with a proportional discount (<code>systems_buffer_ratio</code>, default 0.75) applied to attack density itself, so small signal takes a small hit and large signal a proportionally larger one, never erased outright.</p>
<p><em>Verification:</em> golden masters reblessed — the fix intentionally raises <code>safety_score</code>/<code>cumulative_risk</code> for a large fraction of non-tier1-language files in the corpus, which is the point of the fix. <code>crucible_check.py</code> clean on both modes.</p>
<p><strong><code>high_risk_execution</code> was double-counted across two risk dimensions (#1061)</strong></p>
<p><em>What we found:</em> a single <code>eval</code>/<code>exec</code>/shell-execution call was weighted in both <code>cognitive_load</code> (as part of <code>heavy_logic</code>&rsquo;s danger density) and <code>safety_score</code> (its intended home dimension), compressing the risk axis and diluting signal from other structural dangers.</p>
<p><em>What we did:</em> removed it from <code>cognitive_load</code>; <code>safety_score</code> keeps it as designed.</p>
<p><em>Verification:</em> all 213 diffs in each reblessed golden-master fixture were <code>cognitive_load</code> decreases — exactly the expected effect, with no other risk dimension moving.</p>
<p><strong>Small files diverged up to 8.4x by language tier on identical documentation evidence (#1100)</strong></p>
<p><em>What we found:</em> running the new audit harness surfaced that <code>_calc_documentation()</code> was the only tier-aware equation with no small-file smoothing term, causing up to 8.38x tier1-vs-tier3 divergence for identical documentation evidence at 10–20 line files, versus a normal 1.2–1.7x divergence at typical 150–500 line files. A secondary bug: a genuinely risk-free file scored a spurious ~11.92 (the sigmoid&rsquo;s asymptotic floor at zero density) instead of a true 0.</p>
<p><em>What we did:</em> added a <code>loc_smoothing</code> constant (default 20.0), matching the existing pattern already used by <code>_calc_safety</code>&rsquo;s <code>laplace_smoothing</code> and <code>_calc_concurrency</code>/<code>_calc_state_flux</code>&rsquo;s <code>loc_padding</code>, plus an early zero-hit return guard.</p>
<p><em>Verification:</em> tier2-vs-tier3 divergence at <code>loc=10, hits=1</code> dropped from 8.38x to within the expected pair range; both golden masters reblessed (all 572 diffs per fixture are documentation-exposure decreases for small files — the intended effect); <code>crucible_check.py</code> clean on both modes.</p>
<h2 id="metrics-removed-as-overreaching-continuing-epic-1025">Metrics Removed as Overreaching (continuing Epic #1025)</h2>
<p>The same pattern from last cycle — a score built from unrelated regex hit-counts co-occurring in a file, presented with a confidence a regex-only engine can&rsquo;t structurally back — turned up in six more places and was removed rather than kept at a false confidence level:</p>
<ul>
<li><strong>LCOM</strong> (#1042): computed <code>total_flux / total_args</code>, a ratio of unrelated hit-counts with no real connection to method-to-method cohesion. Investigating a proper redesign surfaced the two nested-scope bugs fixed above as prerequisites — and even with those fixed, a regex-only cohesion measure has systematic style-driven blind spots (shared &ldquo;blob&rdquo; attributes like <code>self.state</code>/<code>self.logger</code> make god-objects look maximally cohesive; Python&rsquo;s <code>@property</code> splits one logical field into two names; composition hides real coupling that never touches <code>self</code>). Removed outright rather than reimplemented under those constraints.</li>
<li><strong>Five AST-dependent Security &amp; Vulnerability metrics</strong> — <code>prompt_injection</code>, <code>agentic_rce</code>, <code>injection_surface</code>, <code>obscured_payload</code>, <code>memory_corruption</code> (#1038): built from unrelated regex categories co-occurring with zero real data-flow or control-flow proof. <code>llm_recorder.py</code> had been reporting these as &ldquo;🚨 Agentic RCE (Critical)&hellip; confirmed execution vectors.&rdquo; Two issues turned up beyond the removal plan itself: a <code>KeyError</code> risk in <code>audit_recorder.py</code> that hardcoded a label lookup into the mapping being trimmed (would have thrown on the next real scan), and a schema distinction that mattered — <code>SIGNAL_SCHEMA</code>&rsquo;s positional order feeds the archetype-classifier&rsquo;s K-Means feature vector, unlike <code>RISK_SCHEMA</code> (output-only), so naively deleting entries would have silently reclassified nearly every file&rsquo;s architectural archetype corpus-wide. Only caught by reading a full golden-master diff line-by-line; invisible to the unit suite.</li>
<li><strong><code>big_o_depth</code> and <code>is_recursive</code></strong> (#1032): indentation-depth Big-O tracking and name-occurrence recursion detection, both systematic false-positive generators — whitespace geometry isn&rsquo;t algorithmic complexity, and counting a function&rsquo;s own name inside its body triggers on docstrings, comments, and patterns like <code>super().setUp()</code>. Removed engine-wide, including the &ldquo;Algorithmic Network Bottleneck&rdquo; feature in <code>network_risk_sensor.py</code> and the concurrency starvation multiplier that depended on it.</li>
<li><strong><code>logic_bomb</code> and <code>algorithmic_dos</code></strong> (#1029): flagged standard defensive-validation code and deeply-indented-but-harmless server loops as malicious via regex co-occurrence rather than real control/data-flow analysis. Removed engine-wide, including the two dedicated wiki pages that documented them.</li>
<li><strong><code>db_complexity</code></strong> (#1021): summed unrelated <code>io</code>, <code>serialization_parsing</code>, and <code>state_mutation</code> hit-counts, so any IO-heavy or mutation-heavy function scored as &ldquo;DB complex&rdquo; with zero actual database or ORM involvement. Removed from 5 downstream consumers beyond the issue&rsquo;s own checklist, found by grep rather than guesswork.</li>
<li><strong><code>ai_appsec_sensor.py</code>&rsquo;s RCE-funnel and exfiltration co-occurrence checks</strong> (#1103): the exact hallucinated-co-occurrence pattern already removed from <code>RISK_SCHEMA</code>/<code>SIGNAL_SCHEMA</code> above, reimplemented independently under different field names in this module — so the earlier removal&rsquo;s blast-radius grep (searching for the removed schema <em>names</em>) never found it. Arguably worse than what it duplicated: <code>sarif_recorder.py</code> had been surfacing these at SARIF&rsquo;s blocking-confidence <code>error</code> level, which GitHub code scanning and most CI gates treat as a confirmed finding. The surviving <code>over_permissioned_agent</code> check is untouched — it gates on a library-import signal (an agent-orchestration framework is present), not a runtime-behavior claim.</li>
</ul>
<h2 id="structural-signature-test-hardening-closes-epic-1069">Structural-Signature Test Hardening (closes Epic #1069)</h2>
<p>Epic #1069 deepened the non-extraction-pillar structural-signature test suite (branch/io/safety_bypasses/ReDoS coverage — not the four <code>func_start</code>/<code>args</code>/<code>class_start</code>/<code>_dependency_capture</code> extraction regexes) across all 45 supported languages. All five sub-issues closed this cycle:</p>
<ul>
<li><strong>ReDoS coverage for 6 languages with none</strong> (#1077): haskell, kotlin, lua, ruby, scala, and swift had zero <code>assert_redos_immune</code> calls anywhere in their strict test files. Every candidate rule was diagnosed with a geometric-scaling check before writing a test; all came back linear. No regex bugs found.</li>
<li><strong>Proved the remaining ReDoS coverage gap wasn&rsquo;t hiding anything</strong> (#1083): built a geometric sweep scanner (<code>sweep_redos_scaling.py</code>) that intercepts every <code>assert_redos_immune</code> adversarial payload across the entire suite and evaluates it at N = 2,000 through 128,000. Result: 300 rules across 37 languages, zero exhibiting true O(n²) scaling.</li>
<li><strong>44 signature keys with zero test coverage across 6 languages</strong> (#1079): most notably, Python&rsquo;s and JavaScript&rsquo;s entire AI/ML extension pack (<code>llm_api</code>, <code>llm_orchestrator</code>, <code>llm_vector_store</code>, <code>ml_traditional</code>, <code>dl_frameworks</code>) had no detection test coverage at all — a real blind spot in a supply-chain-risk detection feature, not just a test-depth gap. Every candidate empirically verified against the real compiled regex; no engine bugs found.</li>
<li><strong>False-positive (ghost-prevention) coverage for 17 languages</strong> (#1081): over 70% of those languages&rsquo; test cases had no negative/lookalike snippet at all. Generated realistic near-miss snippets (boundary-sensitive substrings, keyword-referencing comments, case-mismatched identifiers) for all of them; zero real regex bugs found despite hundreds of adversarial lookalikes thrown at the engine.</li>
<li><strong>Deep adversarial case coverage across effectively every language</strong> (#1087): multi-line splits, modifier stacking, nested generics, boundary noise. Found and fixed several real regex gaps along the way: a missing Swift <code>throws</code> binding, PowerShell <code>hidden</code>/<code>static</code> method modifiers, Lua generic types, and tightened multiline/nested-bracket bounds that closed a couple of ReDoS gaps on closures and lambdas.</li>
<li><strong>Tooling</strong>: <code>audit_strict_coverage.py</code> (the coverage-gap detector that founded the epic), a generalized <code>verify_candidates.py</code>, the <code>how_to_harden_strict_signatures.md</code> checklist, and a Haiku-pinned <code>strict-signature-scout</code> subagent so this mechanical gap-reporting work doesn&rsquo;t run on a premium model (#1075).</li>
</ul>
<p>Every PR in this epic that touched an actual regex pattern reblessed both golden masters and passed <code>crucible_check.py</code> clean on both full-precision and zero-dependency modes before merging.</p>
<h2 id="readme--docs-credibility-pass">README &amp; Docs Credibility Pass</h2>
<p>A second round responding to the same &ldquo;too much marketing language&rdquo; feedback that started the correction v2.4.6&rsquo;s release notes exemplified the wrong way to respond to:</p>
<ul>
<li><strong>Tone/accuracy pass across all 20 READMEs</strong> — root, all 13 module/tool READMEs, all 6 <code>tests/</code> READMEs (#1106): reordered sections by how a skeptical reader would trust them (proof and benchmarks before adoption numbers), added a comparison table against Semgrep/CodeQL/Snyk/Dependabot, and added <code>docs/how_to_maintain_the_readme.md</code> plus <code>docs/how_to_write_release_notes.md</code> as durable style guides — this note follows them. Found real bugs while doing it, not just tone: the root README&rsquo;s &ldquo;0 dependencies&rdquo; claim was false (PyYAML was a hard dependency; fixed for real this cycle, see below); <code>dev_agent_firewall.py</code>&rsquo;s README described a nonexistent &ldquo;complexity factor&rdquo; and a removed threshold as current; <code>supply_chain_security/README.md</code> attributed <code>manifest_parser.py</code> to the wrong directory; three mutually inconsistent throughput numbers (40k/90k/100k LOC/s) appeared across two READMEs, none matching the actual measured 71,076 LOC/s benchmark average; contributor docs told readers to run <code>python3 -m unittest discover tests/</code> when the real test runner is pytest; <code>tests/cobol_mainframe/readme.md</code> was a stale duplicate of the old whole-suite index, describing the wrong 12 files.</li>
<li><strong>Replaced a fully copy-pasted README</strong> (#1108): <code>gitgalaxy/tools/terabyte_log_scanning/README.md</code> was a verbatim copy of <code>cobol_to_java/README.md</code> — same title, same COBOL module list, same CICS transcript — and never once mentioned the two scripts actually in that directory. Rewritten after reading both scripts in full, with a real verified example run (a synthetic log containing one Visa number, one SSN, one AWS key — actual CLI output and actual masked evidence log, not invented numbers).</li>
<li><strong>Added a &ldquo;What Pain Point Does This Solve?&rdquo; section ahead of the architecture diagram</strong> (#1107): direct response to feedback that a first-time reader couldn&rsquo;t tell whether GitGalaxy competes with CodeQL/Semgrep/SonarQube before reading fairly deep into the README. Cites a real, checkable example — Kubernetes, 1.39M LOC across Go/YAML/JSON/Shell/Proto, scanned in 50.83s — instead of an abstract claim, and states plainly that a handful of 20M+ LOC repos take a few minutes rather than asserting a blanket &ldquo;under a minute.&rdquo;</li>
<li><strong>Backed the speed claim with a fitted rate model instead of one example</strong> (#1113): <code>time(s) ≈ 3.36e-05 × LOC^0.969</code> above ~4,258 LOC (R²=0.88, fit from a 599-repo batch), flat ~0.11s below that threshold, with a self-updating chart embedded from the benchmark repo instead of a static image that would go stale.</li>
</ul>
<h2 id="dependencies--supply-chain">Dependencies &amp; Supply Chain</h2>
<p><strong>Restored the true 0-dependency install (#1112)</strong></p>
<p><em>What we found:</em> <code>pyproject.toml</code> listed <code>PyYAML&gt;=6.0</code> as a hard install-time dependency even though it&rsquo;s only ever imported lazily at 3 call sites (<code>config_resolver.py</code>, <code>full_api_network_map.py</code>, <code>galaxyscope.py</code>&rsquo;s <code>--config</code> handling), all originally designed to tolerate its absence. <code>galaxyscope.py</code>&rsquo;s <code>--config</code> interceptor did the worst version of this: on missing PyYAML it silently no-opped with zero log output.</p>
<p><em>What we did:</em> moved PyYAML into a <code>gitgalaxy[yaml]</code> optional extra (core <code>dependencies</code> is now <code>[]</code>), and hardened all 3 call sites to fail loudly with an actionable install command instead of silently doing nothing. Every CI workflow and pipeline template that assumes YAML support now installs the <code>[yaml]</code> extra explicitly.</p>
<p><strong>Manifest-parser ecosystem expansion (#1050)</strong></p>
<p>Extended SBOM dependency extraction and physical on-disk verification to modern Python (<code>pyproject.toml</code>/<code>poetry.lock</code>/<code>Pipfile</code>), .NET/NuGet, C/C++ (Conan/vcpkg), Gradle, CocoaPods, Swift Package Manager, Dart/Flutter, and JS/TS alternative lockfiles (<code>yarn.lock</code>/<code>pnpm-lock.yaml</code>). Extended supply-chain security auditing (direct git/URL dependency refs, insecure registries) to <code>pyproject.toml</code>, <code>yarn.lock</code>, and Gradle build scripts.</p>
<h2 id="wiki--docs-site">Wiki &amp; Docs Site</h2>
<p>Four fixes to the GitHub Pages wiki (324 pages), found during an audit this cycle:</p>
<ul>
<li>106 dead <code>file:///home/...</code> absolute-path links across 82 pages — resolved only on the original author&rsquo;s own machine — rewritten to real GitHub blob URLs or relative wiki paths (#1117).</li>
<li>Enabled Material for MkDocs&rsquo; <code>navigation.tabs</code>/<code>sections</code>/<code>search</code>/<code>content.code.copy</code> features, never turned on despite the wiki&rsquo;s size; fixed a resulting 13-tab overflow (confirmed in the built CSS) by consolidating the 8 numbered sections under one tab (#1123).</li>
<li>Added a discovery index for 56 previously-unlinked per-repo architectural-brief pages that had no path to them from the site nav (#1125).</li>
<li>The homepage&rsquo;s hand-maintained &ldquo;Master Documentation Index&rdquo; had drifted from the real site nav — Claims 8 and 10 were promoted as must-reads in a callout box above it, then missing from the index itself, along with 9 other pages promoted the same way. Renamed it to &ldquo;Quick Navigation (Popular Starting Points)&rdquo; with an honest disclaimer instead of building sync tooling to keep two copies of the nav in lockstep, and fixed every section where a page was promoted above but missing below — verified programmatically against <code>mkdocs.yml</code>&rsquo;s nav, not by re-reading the page a second time (#1127).</li>
</ul>
<h2 id="tooling--internal">Tooling &amp; Internal</h2>
<ul>
<li><strong>Fixed <code>--incremental</code> Delta Scan, broken since it was added</strong> (#1034): <code>galaxyscope.py</code> imported <code>state_rehydrator</code> from the wrong module path (<code>ModuleNotFoundError</code> on every real invocation). Masked because the only test covering it mocked the import at both the correct and the incorrect <code>sys.modules</code> path &ldquo;to ensure any underlying import passes smoothly&rdquo; — the test was written to tolerate the exact bug it should have caught. Verified the fix with a row-for-row parity check between an incremental scan and a fresh full scan of the same commit: identical file/function/complexity counts and PageRank scores across 224 files and 1,170 functions.</li>
<li>Reframed the LLM Recorder&rsquo;s system prompt from a rigid SAST-analyzer persona to a &ldquo;Technical Storyteller&rdquo; persona, with an explicit instruction not to restate a heuristic&rsquo;s raw label (e.g. &ldquo;Logic Bomb&rdquo;) as a confirmed finding of malice (#1048).</li>
<li>Split a single 14,664-line, 621-test strict-signature file into 45 per-language files, then colocated them alongside the existing per-language extraction tests (#1057, #1059).</li>
<li>CI: added, then partially reverted, a <code>workflow_dispatch</code> trigger after push-triggered scans silently stopped firing for 4 consecutive merges to <code>main</code> (#1109, #1110); regenerated a ruff baseline that had drifted from an unrelated PR&rsquo;s line-shifts and was failing every subsequent PR&rsquo;s lint gate regardless of what it touched (#1114); routine CodeQL and Muninn scanner version bumps (#1028, #1022).</li>
<li>Added the <code>harden-language-extraction</code> skill, cross-referenced from <code>CLAUDE.md</code>, for future per-language hardening work.</li>
</ul>
<h2 id="known-limitations-documented-and-deferred-on-purpose">Known Limitations, Documented and Deferred on Purpose</h2>
<ul>
<li>The 5 risk equations confirmed tier-blind by construction (<code>_calc_graveyard</code>, <code>_calc_api_exposure</code>, <code>_calc_spec_alignment</code>, <code>_calc_civil_war</code>, <code>_calc_secrets_risk</code>) were not audited for other calibration issues this cycle — epic #1056 only confirmed they take no tier constant, not that they&rsquo;re otherwise correct.</li>
<li>The AST-dependent metrics removed this cycle (<code>prompt_injection</code>, <code>agentic_rce</code>, <code>injection_surface</code>, <code>obscured_payload</code>, <code>memory_corruption</code>, plus <code>ai_appsec_sensor.py</code>&rsquo;s RCE-funnel/exfiltration checks) have no regex-only replacement. This is an intentional scope reduction, not a temporary gap — GitGalaxy currently makes no claim about AI-agent RCE or prompt-injection risk beyond the surviving <code>over_permissioned_agent</code> (import-identity) signal.</li>
<li>19 Museum of Code teardown pages remain unwired from the wiki&rsquo;s site navigation, reachable only by an in-page link from the Museum&rsquo;s own index rather than the sidebar — out of scope for this cycle&rsquo;s wiki fixes, tracked separately.</li>
</ul>
<hr>
<p><strong>Full changelog:</strong> <a href="https://github.com/squid-protocol/gitgalaxy/compare/v2.4.6...v2.4.7"><code>v2.4.6...v2.4.7</code></a></p>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/compose-lint/</link><pubDate>Fri, 07 Aug 2026 14:26:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.15.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The compose-lint action is a security-focused linter for Docker Compose files that checks for dangerous misconfigurations before they reach production. It catches common security flaws such as privilege issues, network exposure, and supply-chain vulnerabilities by static analysis of the docker-compose.yml and compose.yaml files. The action provides an auto-fix feature with a dry-run option to identify potential security issues in your Docker Compose configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.15.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>compose-lint</code> action is a security-focused linter for Docker Compose files that checks for dangerous misconfigurations before they reach production. It catches common security flaws such as privilege issues, network exposure, and supply-chain vulnerabilities by static analysis of the <code>docker-compose.yml</code> and <code>compose.yaml</code> files. The action provides an auto-fix feature with a dry-run option to identify potential security issues in your Docker Compose configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="removed">Removed</h3>
<ul>
<li>
<p><strong>Profile enrichment has been withdrawn</strong> (<a href="docs/adr/019-withdraw-security-profile-catalog.md">ADR-019</a>,
superseding ADR-017 and ADR-018). The <code>compose_lint.profiles</code> package, the
<code>scripts/validate_profiles.py</code> validator, the <code>profile-validate</code> CI gate, the
<code>profiles</code> config block, and <code>run_rules</code>&rsquo; <code>profile_lookup</code> parameter are all
gone — roughly 2,200 lines across source, tests and docs.</p>
<p>The feature matched a service&rsquo;s <code>image:</code> against a catalog of csd-derived
security profiles and appended an image-specific hint to a finding&rsquo;s <code>fix</code>
text. It shipped as an opt-in experimental preview, and the automation that
ADR-017 §7 requires before any profile may be endorsed as <code>validated</code> (issue
#360) was never built — it depends on csd emitting the catalog schema and on a
BPF-capable runner. compose-lint was therefore carrying a complete consumer of
a catalog that does not exist, behind a flag whose only honest setting was off.</p>
<p><strong>Upgrade impact is limited to configuration.</strong> A leftover <code>profiles:</code> block in
<code>.compose-lint.yml</code> is now simply an unrecognized top-level key: it takes the
standard warn-and-continue path, printing a stderr warning and leaving the exit
code unchanged, so ordinary runs keep working. Under <code>--strict-config</code> it is a
hard error (exit 2), as any unrecognized key is. No finding, severity, exit
code, or output format changes — enrichment was additive-only, so nothing that
was reported before is reported differently now.</p>
<p><code>CL-0009</code> (&ldquo;Security profile disabled&rdquo;) is <strong>unaffected</strong>: it covers seccomp
and AppArmor <code>security_opt</code> settings and is unrelated to this catalog.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>The GitHub Action snippet in <code>README.md</code> now pins the current release.
<code>publish.yml</code>&rsquo;s <code>bump-marketplace-smoke-pin</code> job rewrote the
<code>tmatens/compose-lint@&lt;sha&gt; # vX.Y.Z</code> pin only in
<code>.github/workflows/marketplace-smoke.yml</code>, so the copy-paste snippet users
actually take from the README stayed a release behind every time — it was
still on v0.14.0 after v0.14.1 shipped. The job now rewrites both files,
and the stale pin is corrected.</li>
<li><code>release-prep.yml</code> now bumps the self-referencing version pins in
<code>README.md</code> and <code>docs/</code> as part of the version-bump commit. The
<code>version-consistency</code> job has required those pins to match
<code>pyproject.toml</code> since #443, but release-prep only touched
<code>pyproject.toml</code>, <code>__init__.py</code>, and <code>CHANGELOG.md</code> — so the release PR it
opened failed its own required check on every release and needed a
hand-pushed fixup commit.</li>
<li>The sdist no longer ships whatever happens to sit in the maintainer&rsquo;s
working tree. <code>[tool.hatch.build.targets.sdist]</code> was a denylist of nine
known paths, but hatchling ships everything the <em>root</em> <code>.gitignore</code> does
not exclude and does not read nested <code>.gitignore</code> files — so a local
virtualenv, which writes its own <code>.gitignore: *</code> and is therefore
invisible to <code>git status</code>, was swept in: 158 of 445 entries, 35% of a
3.5 MB archive, including <code>bin/python</code> as an absolute symlink into the
build machine&rsquo;s filesystem. Such an archive is not merely untidy but
unusable — uv rejects it as an invalid tar — and nothing caught it:
<code>twine check</code> validates metadata, not contents, and <code>publish.yml</code>&rsquo;s
content guard inspects the wheel alone. The sdist target is now a
root-anchored allowlist, and <code>publish.yml</code> gates the sdist on symlinks
and virtualenv markers. Published artifacts were never affected: release
builds run from a clean checkout, and the wheel packages <code>src/</code> only.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Documentation no longer describes auto-fixable findings as &ldquo;safe&rdquo;. <code>README.md</code>,
<code>docs/dockerhub-overview.md</code>, and <code>docs/SECURITY-EXPECTATIONS.md</code> said <code>fix</code>
applies &ldquo;safe, mechanical edits&rdquo;, which invites the reading that applying them
is harmless. Per ADR-014 the guarantee is a property of the <em>edit</em> — one
unambiguous value, no collateral change, still-valid YAML — not of the
outcome: <code>read_only: true</code> and the <code>127.0.0.1</code> port rebind both change runtime
behavior by design, and are surfaced with a <code>⚠ behavior-changing</code> caveat
rather than withheld. The docs now say &ldquo;mechanically unambiguous&rdquo;, state the
edit/outcome distinction explicitly, and show the caveat line a user will see.</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/wails3-build-action/</link><pubDate>Fri, 07 Aug 2026 14:25:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building of Wails.io projects using GoLang and NodeJS. It installs necessary dependencies, builds the application for different platforms (Linux, Windows, macOS), and uploads the results to GitHub or releases on tagged builds. The action provides options to customize the build process, including obfuscation, cache usage, and the use of different package managers like npm, pnpm, and Deno.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building of Wails.io projects using GoLang and NodeJS. It installs necessary dependencies, builds the application for different platforms (Linux, Windows, macOS), and uploads the results to GitHub or releases on tagged builds. The action provides options to customize the build process, including obfuscation, cache usage, and the use of different package managers like npm, pnpm, and Deno.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>SMF Flutter Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/smf-flutter-release/</link><pubDate>Fri, 07 Aug 2026 14:24:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/smf-flutter-release/</guid><description>Version updated for https://github.com/Ventairy/smf-action to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the release process of Flutter apps by generating and managing pull requests for iOS and Android versions. It allows for independent versioning and testing before final approval, ensuring that only verified artifacts are released to production.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Ventairy/smf-action">https://github.com/Ventairy/smf-action</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/smf-flutter-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the release process of Flutter apps by generating and managing pull requests for iOS and Android versions. It allows for independent versioning and testing before final approval, ensuring that only verified artifacts are released to production.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="121-2026-08-07"><a href="https://github.com/Ventairy/smf-action/compare/v1.2.0...v1.2.1">1.2.1</a> (2026-08-07)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> pin patched brace-expansion (<a href="https://github.com/Ventairy/smf-action/issues/19">#19</a>) (<a href="https://github.com/Ventairy/smf-action/commit/6eab86be3c0cfad0ee70f640ed91572f3d255cef">6eab86b</a>)</li>
<li><strong>runtime:</strong> use smf_cli 1.1.0 (<a href="https://github.com/Ventairy/smf-action/issues/20">#20</a>) (<a href="https://github.com/Ventairy/smf-action/commit/2cfea8e708b794324b1c2049c197a236606833d9">2cfea8e</a>)</li>
</ul>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/vibgrate-scan/</link><pubDate>Fri, 07 Aug 2026 14:24:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.807.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action @vibgrate/cli provides a local codebase intelligence tool for AI coding agents. It generates a deterministic code graph and drift score to help developers understand the current state of their codebase and identify potential risks, allowing them to make informed decisions about updates and improvements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.807.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>@vibgrate/cli</code> provides a local codebase intelligence tool for AI coding agents. It generates a deterministic code graph and drift score to help developers understand the current state of their codebase and identify potential risks, allowing them to make informed decisions about updates and improvements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268071">Vibgrate CLI 2026.807.1</h1>
<p><em>Released 2026-08-07</em></p>
<p>This release of the vg command-line scanner includes improvements to the handling of large file operations and fixes for session history and todo management. These changes enhance the user experience by providing clearer feedback and maintaining context in ongoing tasks.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="improved">Improved</h3>
<ul>
<li>VG Code no longer dumps the full file body into the transcript when deleting or creating a large file, showing a short line-count summary instead.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>VG Code now marks remaining focus-chain todos done when the agent finishes, preventing the checklist from sticking at Progress N−1/N.</li>
<li>VG Code session history now keeps full prompts and final answers, ensuring that reopening a prior chat reloads the complete thread.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.806.2, interleaved on one runner against the pinned corpus (189 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21605 count</td>
          <td>21605 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>10836 count</td>
          <td>10836 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.94 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>674 ms</td>
          <td>680.30 ms</td>
      </tr>
  </tbody>
</table>
<p>2 regression(s) — published, not omitted:</p>
<ul>
<li>Tasks passed on both arms: 33 → 31 (-6.1%)</li>
<li>Comparable-task rate (both arms passed / total): 0.94 → 0.89 (-6.1%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.807.1">https://vibgrate.com/changelog/cli/2026.807.1</a></p>
]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/kover-report-action/</link><pubDate>Fri, 07 Aug 2026 14:22:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.19.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Kover Report Action is a GitHub Action designed to automate the generation and reporting of code coverage from Kover XML reports in Kotlin/Android projects. It supports multi-module support, flexible discovery options, configurable thresholds, PR integration, coverage history tracking, and customizable outputs. The action uses Gradle or glob patterns to locate coverage files and provides visual ASCII graphs for trend analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v3.1.19</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Kover Report Action is a GitHub Action designed to automate the generation and reporting of code coverage from Kover XML reports in Kotlin/Android projects. It supports multi-module support, flexible discovery options, configurable thresholds, PR integration, coverage history tracking, and customizable outputs. The action uses Gradle or glob patterns to locate coverage files and provides visual ASCII graphs for trend analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3.1.19: PR #157 - chore(deps): lock file maintenance</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/b.ia-accessibility-checker/</link><pubDate>Fri, 07 Aug 2026 14:21:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It helps companies ensure their code meets WCAG guidelines by defining target audiences and percentages of guidelines to be met. The action uses AI analysis to assess the compliance of code, allowing developers to focus on meeting accessibility requirements for a specific audience, improving product performance and revenue.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It helps companies ensure their code meets WCAG guidelines by defining target audiences and percentages of guidelines to be met. The action uses AI analysis to assess the compliance of code, allowing developers to focus on meeting accessibility requirements for a specific audience, improving product performance and revenue.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/postman-onboarding-repo-sync/</link><pubDate>Fri, 07 Aug 2026 07:34:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.9.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of exporting Postman collections and environments into a repository, setting up CI pipelines with mocks and monitors, and managing secrets. It solves the problem of manually exporting and configuring these assets, which can be time-consuming and error-prone. The action provides inputs for project details, workspace IDs, collection IDs, environment configurations, and authentication tokens, and outputs are generated workflows and artifacts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.9.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of exporting Postman collections and environments into a repository, setting up CI pipelines with mocks and monitors, and managing secrets. It solves the problem of manually exporting and configuring these assets, which can be time-consuming and error-prone. The action provides inputs for project details, workspace IDs, collection IDs, environment configurations, and authentication tokens, and outputs are generated workflows and artifacts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>perf(repo-sync): bound artifact acquisition reads by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/116">https://github.com/postman-cs/postman-repo-sync-action/pull/116</a></li>
<li>fix(deps): replace deprecated Faker with compatible v6 by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/117">https://github.com/postman-cs/postman-repo-sync-action/pull/117</a></li>
<li>fix(repo-mutation): reconcile stale branch before push by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/118">https://github.com/postman-cs/postman-repo-sync-action/pull/118</a></li>
<li>fix(repo-mutation): resolve generated artifact conflicts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/119">https://github.com/postman-cs/postman-repo-sync-action/pull/119</a></li>
<li>fix(release): notify the composite after Repo Sync publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/121">https://github.com/postman-cs/postman-repo-sync-action/pull/121</a></li>
<li>feat: add generated asset sync control by @sean-riney in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/123">https://github.com/postman-cs/postman-repo-sync-action/pull/123</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.9.0">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.9.0</a></p>
]]></content:encoded></item><item><title>Garita PII Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/garita-pii-guard/</link><pubDate>Fri, 07 Aug 2026 07:32:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/garita-pii-guard/</guid><description>Version updated for https://github.com/proscar87/garita to version v0.23.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Garita is a GitHub Action that enforces data protection policies by monitoring and preventing sensitive information from being added to repositories. It uses regular expressions and validation rules to check file contents against predefined lists of prohibited patterns such as names, CURPs, RFCs, CLABEs, NSS numbers, Mexican phone numbers, secret tokens, and JWTs. The action focuses on ensuring that personal data is not included in source code or commit history by leveraging existing tools like git-secrets and provides a simple YAML configuration file to manage the list of prohibited patterns.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/proscar87/garita">https://github.com/proscar87/garita</a></strong> to version <strong>v0.23.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/garita-pii-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Garita is a GitHub Action that enforces data protection policies by monitoring and preventing sensitive information from being added to repositories. It uses regular expressions and validation rules to check file contents against predefined lists of prohibited patterns such as names, CURPs, RFCs, CLABEs, NSS numbers, Mexican phone numbers, secret tokens, and JWTs. The action focuses on ensuring that personal data is not included in source code or commit history by leveraging existing tools like <code>git-secrets</code> and provides a simple YAML configuration file to manage the list of prohibited patterns.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Lo urgente de la <strong>quinta oleada</strong>: diez confirmados, cero refutados, los diez falsos negativos. Cinco salen aquí.</p>
<p><strong>Tres eran regresiones propias de las últimas horas:</strong></p>
<ul>
<li><strong>La codificación se decide por byte.</strong> Tercera versión de <code>descifrar()</code> y segunda ceguera: v0.17.0 leía el archivo entero como cp1252 y un byte Latin-1 arruinaba los acentos del UTF-8 mayoritario; v0.20.2 lo invirtió y bastaba <strong>un</strong> carácter UTF-8 para arruinar los del padrón Latin-1 — la población que v0.17.0 existía para leer. Ahora sólo la secuencia inválida se lee como cp1252: las tres direcciones conservan sus acentos. No había que elegir.</li>
<li><strong><code>Ilegible</code> sólo cubría <code>read_bytes</code></strong>: un <em>directorio</em> sin permiso —la forma en que aparece en un contenedor de CI con otro UID— dejaba el archivo en «binarios o muy grandes» y aprobaba con 0.</li>
<li><strong><code>os.geteuid()</code> no existe en Windows</strong> y el decorador se evalúa al crear la clase: desde v0.22.0 el job de <code>windows-latest</code> <strong>no corría ni una de las 248 pruebas</strong>. «Cero pruebas» y «todo verde» se parecen demasiado en un tablero.</li>
</ul>
<p><strong>Y dos más:</strong></p>
<ul>
<li><strong>Un BOM en la lista de nombres borraba el primer nombre</strong> y el repo salía verde. Es lo que v0.21.0 cerró en <code>config.py</code> y no se llevó a <code>fuentes.py</code>; aquí lo que desaparece no es una clave, es una persona del padrón.</li>
<li><strong><code>dentro_de_url</code> se acota de verdad</strong>: el arreglo de v0.23.0 quitó la copia, pero los siete separadores ausentes seguían barriendo la línea entera. Y la prueba de rendimiento pasa a medir la forma, no el reloj.</li>
</ul>
<p>El resto de la oleada —NFD, los secretos sin comillas de un <code>.env</code>, el padrón de una sola línea— queda en <code>ROADMAP.md</code> con recetas.</p>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/prowler-security-scan/</link><pubDate>Fri, 07 Aug 2026 07:31:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.38.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Prowler action automates the deployment and monitoring of Prowler, an Open Source cloud security platform that provides real-time security checks and integrations for managing cloud environments effectively. It simplifies the process of implementing comprehensive security measures across various cloud services, ensuring compliance with industry standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.38.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Prowler action automates the deployment and monitoring of Prowler, an Open Source cloud security platform that provides real-time security checks and integrations for managing cloud environments effectively. It simplifies the process of implementing comprehensive security measures across various cloud services, ensuring compliance with industry standards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-new-features-to-highlight-in-this-version">✨ New features to highlight in this version</h1>
<p>Enjoy them all now for free at <a href="https://cloud.prowler.com/">https://cloud.prowler.com/</a></p>
<h2 id="-compliance-watchlist">📌 Compliance Watchlist</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Compliance Watchlist keeps the frameworks an organization tracks in one shared list. Pin frameworks from any compliance view, manage several at once through a searchable catalog, and filter the Compliance section to show only the pinned frameworks.</p>
<p>The Overview page now reports the latest score for every pinned framework, while finding details highlight the watched frameworks associated with each check. Universal frameworks remain a single watchlist entry across provider views, keeping the organization&rsquo;s priorities consistent everywhere.</p>
<p><img src="https://github.com/prowler-cloud/prowler/blob/master/docs/images/compliance/prowler-app-compliance-watchlist-editor.png" alt="Compliance Watchlist editor"></p>
<p>Read more in the <a href="https://docs.prowler.com/user-guide/compliance/tutorials/compliance#tracking-frameworks-with-the-compliance-watchlist">Compliance Watchlist documentation</a>.</p>
<h2 id="-saml-sso---multiple-email-domains">🔐 SAML SSO - Multiple Email Domains</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>One SAML configuration can now authorize a primary email domain and up to 19 additional domains through the same Identity Provider. Every domain shares one stable Assertion Consumer Service (ACS) URL based on the primary domain, so subsidiaries, acquired companies, regional domains, and multiple brands no longer require separate tenants or duplicated SAML applications.</p>
<p>Domain ownership remains tenant-bound throughout the authentication flow. During service provider-initiated sign-in, the discovery domain and the domain asserted by the Identity Provider must resolve to the same tenant before provisioning continues.</p>
<p><img src="https://github.com/prowler-cloud/prowler/blob/master/docs/images/prowler-app/saml/saml-multiple-domains.png" alt="SAML configuration with multiple email domains"></p>
<p>Read more in the <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-sso#add-multiple-saml-domains">SAML SSO documentation</a>.</p>
<h2 id="-user-sign-in-methods">👥 User Sign-In Methods</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>The Users table now shows each account&rsquo;s sign-in methods as tags, including email/password, Google, GitHub, SAML with linked domains, and Partner SSO. Accounts without a reported method display a placeholder.</p>
<p><img src="https://github.com/user-attachments/assets/799871c3-94f0-400b-b766-71be8e8ff5eb" alt="Users table showing sign-in method tags"></p>
<h2 id="-attack-paths---expanded-aws-privilege-escalation-coverage">🕸️ Attack Paths - Expanded AWS Privilege-Escalation Coverage</h2>
<p>Attack Paths adds 20 AWS privilege-escalation queries from <a href="https://pathfinding.cloud">pathfinding.cloud</a>, while <code>iam_policy_allows_privilege_escalation</code> gains 22 additional escalation combinations.</p>
<p>The new coverage includes service <code>iam:PassRole</code> paths across AWS Batch, Braket, Cognito Identity, ECS, EMR, EMR Serverless, GameLift, Glue, EC2 Image Builder, Kinesis Analytics, HealthOmics, EventBridge Scheduler, Systems Manager, and Step Functions. It also covers existing-resource abuse, permissions-boundary removal, role assumption, and IAM Identity Center permission-set policy injection.</p>
<p>The query catalog now exposes each AWS query&rsquo;s outcome category, distinguishing code execution, privilege escalation, public exposure, and resource inventory.</p>
<p>Explore the full Attack Paths query catalog at <a href="https://hub.prowler.com/attack-paths">Prowler Hub</a>.</p>
<p>Read more in the <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-attack-paths">Attack Paths documentation</a>.</p>
<h2 id="-checks">🔍 Checks</h2>
<h3 id="microsoft-365">Microsoft 365</h3>
<p>Twelve new checks expand the coverage of CIS Microsoft 365 Foundations Benchmark v7.0.0:</p>
<ul>
<li><strong>Admin Center:</strong> Shared Bookings is disabled.</li>
<li><strong>Defender:</strong> Priority account protection and strict preset security policies are enabled.</li>
<li><strong>Entra ID:</strong> Six checks cover device registration restrictions, local administrator behavior, device limits, LAPS, and BitLocker key visibility.</li>
<li><strong>Exchange Online:</strong> Personal accounts in Outlook on the web are disabled and Direct Send is rejected.</li>
<li><strong>Microsoft Teams:</strong> External access from trial-only tenants is blocked.</li>
</ul>
<p>Explore all Microsoft 365 checks at <a href="https://hub.prowler.com/check?provider=m365">Prowler Hub</a>.</p>
<h2 id="-security">🔐 Security</h2>
<ul>
<li>Prowler API, UI, SDK, and MCP container images now publish per-architecture Software Bills of Materials (SBOMs) and build-provenance attestations. Prowler Cloud production and Prowler Private Cloud images carry the same attestations.</li>
<li>SDK and API container builds verify the checksums of downloaded PowerShell, Trivy, and zizmor binaries before installation.</li>
<li>Grype now complements Trivy across the container-image security gates, detecting components and vulnerabilities that manifest-based scanners can miss and blocking fixable high and critical findings.</li>
<li><code>aiohttp</code> was upgraded to 3.14.3 to address CVE-2026-69244. <code>cryptography</code> was upgraded to 50.0.0 to address CVE-2026-69247 and CVE-2026-69249.</li>
</ul>
<hr>
<h2 id="ui">UI</h2>
<h3 id="-added">🚀 Added</h3>
<ul>
<li>Sign-in method indicators in the Prowler Cloud Users table, including linked SAML domains <a href="https://github.com/prowler-cloud/prowler/pull/12268">(#12268)</a></li>
<li>Compliance watchlist: pin frameworks from any compliance view and filter every view down to the pinned ones, including the overview card and a finding&rsquo;s compliance chips (Prowler Cloud only) <a href="https://github.com/prowler-cloud/prowler/pull/12300">(#12300)</a></li>
<li>Multiple verified email domains in a single SAML configuration for Prowler Cloud <a href="https://github.com/prowler-cloud/prowler/pull/12332">(#12332)</a></li>
<li>Container images now ship an SBOM and build provenance as OCI attestations <a href="https://github.com/prowler-cloud/prowler/pull/12352">(#12352)</a></li>
</ul>
<h3 id="-changed">🔄 Changed</h3>
<ul>
<li><code>Add Provider</code> wizard documentation link targeting each provider&rsquo;s credentials section and selected authentication method <a href="https://github.com/prowler-cloud/prowler/pull/12218">(#12218)</a></li>
</ul>
<h3 id="-fixed">🐞 Fixed</h3>
<ul>
<li>Imported scans now appear on the Scans page even when no provider is connected <a href="https://github.com/prowler-cloud/prowler/pull/12025">(#12025)</a></li>
<li>Feedback widget no longer obscures page and side-panel actions <a href="https://github.com/prowler-cloud/prowler/pull/12282">(#12282)</a></li>
<li>Rows-per-page selector no longer disappears when the chosen page size collapses a table to a single page <a href="https://github.com/prowler-cloud/prowler/pull/12299">(#12299)</a></li>
<li>Overview ThreatScore card no longer leaves unused horizontal space at responsive layout boundaries <a href="https://github.com/prowler-cloud/prowler/pull/12317">(#12317)</a></li>
<li>Overview metric cards stack below the desktop layout threshold and preserve readable widths when aligned <a href="https://github.com/prowler-cloud/prowler/pull/12323">(#12323)</a></li>
<li>Overview metric cards now align horizontally at medium desktop widths <a href="https://github.com/prowler-cloud/prowler/pull/12323">(#12323)</a></li>
<li>AWS and GCP organization onboarding launches all linked provider scans through one bulk operation <a href="https://github.com/prowler-cloud/prowler/pull/12350">(#12350)</a></li>
<li><code>/compliance</code> no longer fails while compliance overview data is still being generated <a href="https://github.com/prowler-cloud/prowler/pull/12358">(#12358)</a></li>
<li><code>Client Secret</code> and <code>Refresh Token</code> labels in the GCP organization authentication form <a href="https://github.com/prowler-cloud/prowler/pull/12362">(#12362)</a></li>
</ul>
<h3 id="-security-1">🔐 Security</h3>
<ul>
<li>Removed the <code>apk upgrade</code> from the UI image and moved the base digest forward instead, so the image is reproducible from its pin rather than from whatever Alpine serves at build time <a href="https://github.com/prowler-cloud/prowler/pull/12313">(#12313)</a></li>
</ul>
<h2 id="api">API</h2>
<h3 id="-added-1">🚀 Added</h3>
<ul>
<li>Attack Paths adds 20 AWS privilege-escalation detection queries from pathfinding.cloud, covering service PassRole escalations (Batch, Braket, Cognito Identity, ECS, EMR, EMR Serverless, GameLift, Glue, EC2 Image Builder, Kinesis Analytics, HealthOmics, EventBridge Scheduler, SSM, Step Functions), CodeDeploy and Step Functions existing-resource abuse, role permissions-boundary removal with role assumption, and IAM Identity Center permission-set policy injection <a href="https://github.com/prowler-cloud/prowler/pull/12237">(#12237)</a></li>
<li>Attack Paths query metadata now carries an outcome (Code execution, Privilege escalation, Public exposure, or Resource inventory), exposed on the queries endpoint so the graph can show a terminal outcome node <a href="https://github.com/prowler-cloud/prowler/pull/12344">(#12344)</a></li>
<li>Container images now ship an SBOM and build provenance as OCI attestations <a href="https://github.com/prowler-cloud/prowler/pull/12352">(#12352)</a></li>
</ul>
<h3 id="-changed-1">🔄 Changed</h3>
<ul>
<li>Pin the container vulnerability scanner to Trivy v0.72.0, matching prowler-registry and partner-portal <a href="https://github.com/prowler-cloud/prowler/pull/12346">(#12346)</a></li>
</ul>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li>Compliance report output directory failures are now logged with the exception attached and fingerprinted by <code>errno</code> in Sentry, so <code>ENOSPC</code>, <code>ENOENT</code> and <code>EACCES</code> no longer share a single issue <a href="https://github.com/prowler-cloud/prowler/pull/12142">(#12142)</a></li>
<li>Restored the SDK dependency to <code>@master</code> now that the dependency bumps have landed there, and regenerated the lock. The API image no longer builds against a temporary integration branch <a href="https://github.com/prowler-cloud/prowler/pull/12309">(#12309)</a></li>
</ul>
<h3 id="-security-2">🔐 Security</h3>
<ul>
<li>The API container image now verifies the checksum of every third-party binary it downloads (PowerShell, Trivy, zizmor) before installing it <a href="https://github.com/prowler-cloud/prowler/pull/12334">(#12334)</a></li>
<li>Upgrade aiohttp to 3.14.3 to pick up the fix for CVE-2026-69244 <a href="https://github.com/prowler-cloud/prowler/pull/12340">(#12340)</a></li>
<li>Upgrade cryptography to 50.0.0, closing CVE-2026-69247 and CVE-2026-69249 <a href="https://github.com/prowler-cloud/prowler/pull/12356">(#12356)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-added-2">🚀 Added</h3>
<ul>
<li><code>admincenter_shared_bookings_disabled</code> check for M365 provider, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 control 1.3.9 <a href="https://github.com/prowler-cloud/prowler/pull/12147">(#12147)</a></li>
<li><code>defender_priority_account_protection_enabled</code> and <code>defender_strict_preset_security_policy_enabled</code> checks for M365 provider, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 controls 2.4.1 and 2.4.2 <a href="https://github.com/prowler-cloud/prowler/pull/12148">(#12148)</a></li>
<li><code>exchange_owa_mailbox_policy_personal_accounts_disabled</code> and <code>exchange_organization_reject_direct_send_enabled</code> checks for M365 provider, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 controls 6.3.2 and 6.5.5 <a href="https://github.com/prowler-cloud/prowler/pull/12149">(#12149)</a></li>
<li><code>teams_external_access_trial_tenants_blocked</code> check for M365 provider, verifying that Teams external access with trial-only tenants is blocked, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 control 8.2.4 <a href="https://github.com/prowler-cloud/prowler/pull/12151">(#12151)</a></li>
<li><code>entra_device_registration_join_restricted</code>, <code>entra_device_registration_max_devices_per_user_limited</code>, <code>entra_device_registration_global_admins_not_local_admins</code>, <code>entra_device_registration_registering_user_not_local_admin</code>, <code>entra_device_registration_laps_enabled</code> and <code>entra_policy_default_user_cannot_read_bitlocker_keys</code> checks for M365 provider, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 device registration controls (5.1.4.x) <a href="https://github.com/prowler-cloud/prowler/pull/12152">(#12152)</a></li>
<li>The IAM privilege-escalation check now detects 22 additional pathfinding.cloud escalation paths across AWS Batch, Braket, CodeDeploy, Cognito Identity, ECS, EMR, EMR Serverless, GameLift, Glue, EC2 Image Builder, Kinesis Analytics, HealthOmics, EventBridge Scheduler, SSM Automation, Step Functions, IAM permissions boundaries, and IAM Identity Center (SSO) <a href="https://github.com/prowler-cloud/prowler/pull/12237">(#12237)</a></li>
<li>Container images now ship an SBOM and build provenance as OCI attestations <a href="https://github.com/prowler-cloud/prowler/pull/12352">(#12352)</a></li>
</ul>
<h3 id="-changed-2">🔄 Changed</h3>
<ul>
<li>Highlighted key security terms in the Risk description of 8 existing M365 checks <a href="https://github.com/prowler-cloud/prowler/pull/12156">(#12156)</a></li>
<li>Moved the Trivy suppressions from the classic <code>.trivyignore</code> to <code>.trivyignore.yaml</code>, so each entry is scoped to the package it names instead of suppressing its CVE across the whole image <a href="https://github.com/prowler-cloud/prowler/pull/12314">(#12314)</a></li>
<li>The <code>securityhub_delegated_admin_enabled_all_regions</code>, <code>guardduty_delegated_admin_enabled_all_regions</code> and <code>config_delegated_admin_and_org_aggregator_all_regions</code> checks now report MANUAL instead of FAIL when the delegated administrator status cannot be read and no independent misconfiguration is detected, which happens on member accounts that are not registered as delegated administrators because the API is restricted to the organization management account and to delegated administrator accounts <a href="https://github.com/prowler-cloud/prowler/pull/12319">(#12319)</a></li>
<li>Pin the container vulnerability scanner to Trivy v0.72.0, matching prowler-registry and partner-portal <a href="https://github.com/prowler-cloud/prowler/pull/12346">(#12346)</a></li>
<li>Quote the unquoted shell expansions in the release and build workflows <a href="https://github.com/prowler-cloud/prowler/pull/12365">(#12365)</a></li>
<li>Fix the remaining shellcheck findings in workflows and enable the check <a href="https://github.com/prowler-cloud/prowler/pull/12367">(#12367)</a></li>
</ul>
<h3 id="-fixed-2">🐞 Fixed</h3>
<ul>
<li>Spurious error log output from <code>Get-ApplicationAccessPolicy</code> on M365 tenants without application access policies <a href="https://github.com/prowler-cloud/prowler/pull/12149">(#12149)</a></li>
<li>Secret checks no longer report credential-free JDBC connection strings as embedded credentials <a href="https://github.com/prowler-cloud/prowler/pull/12288">(#12288)</a></li>
<li>A failed <code>ListOrganizationAdminAccounts</code> lookup in one region no longer marks the Security Hub delegated administrator status as undetermined in every other region <a href="https://github.com/prowler-cloud/prowler/pull/12319">(#12319)</a></li>
<li><code>securityhub_delegated_admin_enabled_all_regions</code> no longer reports FAIL with <code>delegated administrator status could not be determined</code> on accounts that do have a Security Hub delegated administrator; <code>ListOrganizationAdminAccounts</code> responses are now parsed with the <code>AccountId</code> and <code>Status</code> fields the API actually returns <a href="https://github.com/prowler-cloud/prowler/pull/12319">(#12319)</a></li>
<li><code>guardduty_delegated_admin_enabled_all_regions</code> no longer reports <code>no delegated administrator configured</code> when the lookup was denied or failed, which asserted absence where there was only lack of visibility <a href="https://github.com/prowler-cloud/prowler/pull/12319">(#12319)</a></li>
<li>OCI Identity service no longer drops the whole dynamic groups, groups, policies or users listing when the OCI API returns null optional fields such as <code>matching_rule</code> <a href="https://github.com/prowler-cloud/prowler/pull/12327">(#12327)</a></li>
<li>Alibaba Cloud STS credential validation retries transient connection failures and reports exhausted attempts as connection errors instead of invalid credentials <a href="https://github.com/prowler-cloud/prowler/pull/12353">(#12353)</a></li>
</ul>
<h3 id="-security-3">🔐 Security</h3>
<ul>
<li>Bumped the Compose DozerDB image from 5.26.3.0 to 5.26.27.0, which moves it off Debian 11 and onto Debian 13 <a href="https://github.com/prowler-cloud/prowler/pull/12320">(#12320)</a></li>
<li>The SDK container image now verifies the checksum of every third-party binary it downloads (PowerShell, Trivy, zizmor) before installing it <a href="https://github.com/prowler-cloud/prowler/pull/12334">(#12334)</a></li>
<li>Upgrade aiohttp to 3.14.3 to pick up the fix for CVE-2026-69244 <a href="https://github.com/prowler-cloud/prowler/pull/12340">(#12340)</a></li>
<li>Upgrade cryptography to 50.0.0, closing CVE-2026-69247 and CVE-2026-69249 <a href="https://github.com/prowler-cloud/prowler/pull/12356">(#12356)</a></li>
</ul>
<h2 id="mcp">MCP</h2>
<h3 id="-added-3">🚀 Added</h3>
<ul>
<li>Test foundation for the MCP server with shared fixtures, JSON:API builders, mocked HTTP transports and CI coverage reporting <a href="https://github.com/prowler-cloud/prowler/pull/12291">(#12291)</a></li>
<li>Test coverage for the integrations tools and models, pinning the connection-check choreography and the Jira dispatch retry safety <a href="https://github.com/prowler-cloud/prowler/pull/12343">(#12343)</a></li>
<li>Container images now ship an SBOM and build provenance as OCI attestations <a href="https://github.com/prowler-cloud/prowler/pull/12352">(#12352)</a></li>
</ul>
<h3 id="-changed-3">🔄 Changed</h3>
<ul>
<li><code>prowler_send_findings_to_jira</code> now reports <code>safe_to_retry</code> on every outcome, true only when Prowler knows no Jira work item was created: a dispatch the API refused is retryable, one that failed on the server or got no answer is not <a href="https://github.com/prowler-cloud/prowler/pull/12343">(#12343)</a></li>
<li><code>prowler_list_integrations</code> no longer requests the <code>configuration</code> it discards, now that the API tolerates a sparse fieldset without it <a href="https://github.com/prowler-cloud/prowler/pull/12343">(#12343)</a></li>
</ul>
<h3 id="-security-4">🔐 Security</h3>
<ul>
<li>Upgrade cryptography to 50.0.0, closing CVE-2026-69247 and CVE-2026-69249 <a href="https://github.com/prowler-cloud/prowler/pull/12356">(#12356)</a></li>
</ul>
]]></content:encoded></item><item><title>SnapDrift</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/snapdrift/</link><pubDate>Fri, 07 Aug 2026 07:30:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/snapdrift/</guid><description>Version updated for https://github.com/ranacseruet/snapdrift to version v0.8.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SnapDrift captures full-page application frames, compares them against a known baseline, and reports drift directly in GitHub Actions. It solves issues related to detecting UI changes across pull requests by automating the baseline capture, pull request drift detection, and report upserts. Key capabilities include route scoping, drift enforcement through diff.mode, and support for both local and hosted Snap backends.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ranacseruet/snapdrift">https://github.com/ranacseruet/snapdrift</a></strong> to version <strong>v0.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/snapdrift">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SnapDrift captures full-page application frames, compares them against a known baseline, and reports drift directly in GitHub Actions. It solves issues related to detecting UI changes across pull requests by automating the baseline capture, pull request drift detection, and report upserts. Key capabilities include route scoping, drift enforcement through <code>diff.mode</code>, and support for both local and hosted Snap backends.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release that makes the root action publishable to the GitHub Marketplace. Publishing <code>v0.8.0</code> failed validation.</p>
<h2 id="fixes">Fixes</h2>
<ul>
<li><strong>The root action can actually be published to the Marketplace</strong> — its description was 130 characters, and GitHub rejects the listing at 125 or more. Shortened to 115, leading with &ldquo;visual regression&rdquo; so the listing matches what people search for. <code>npm run validate:actions</code> and <code>tests/marketplace-metadata.test.js</code> now enforce the limit against the root action; the sub-action descriptions are unaffected, since the rule only applies to the published entry point.</li>
</ul>
<h2 id="upgrading">Upgrading</h2>
<p>No functional change from <code>v0.8.0</code> — the dispatcher, its inputs, its outputs, and the wrapper actions are all identical. Only the metadata description changed. If you are already on <code>v0.8.0</code>, move to <code>v0.8.1</code> for consistency with the published listing; nothing will behave differently.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">SnapDrift Report</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">ranacseruet/snapdrift@v0.8.1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">mode</span>: <span style="color:#ae81ff">pr-diff</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">github-token</span>: <span style="color:#ae81ff">${{ secrets.GITHUB_TOKEN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">repo-config-path</span>: <span style="color:#ae81ff">.github/snapdrift.json</span>
</span></span></code></pre></div><p><strong>Full changelog:</strong> <a href="https://github.com/ranacseruet/snapdrift/blob/main/CHANGELOG.md">https://github.com/ranacseruet/snapdrift/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>setup-love</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/setup-love/</link><pubDate>Fri, 07 Aug 2026 07:29:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/setup-love/</guid><description>Version updated for https://github.com/remarkablegames/setup-love to version v1.0.8.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
This GitHub Action automates the setup of the LÖVE game engine in your CI/CD workflows on GitHub Actions. It simplifies the process of integrating LÖVE into projects, allowing developers to easily run and test their games using this popular 2D game development framework.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablegames/setup-love">https://github.com/remarkablegames/setup-love</a></strong> to version <strong>v1.0.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-love">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary</strong>:</p>
<p>This GitHub Action automates the setup of the LÖVE game engine in your CI/CD workflows on GitHub Actions. It simplifies the process of integrating LÖVE into projects, allowing developers to easily run and test their games using this popular 2D game development framework.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="108-2026-08-06"><a href="https://github.com/remarkablegames/setup-love/compare/v1.0.7...v1.0.8">1.0.8</a> (2026-08-06)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump undici from 6.27.0 to 6.28.0 (<a href="https://github.com/remarkablegames/setup-love/issues/270">#270</a>) (<a href="https://github.com/remarkablegames/setup-love/commit/1c3862ebd5cb19068d972c6b43921081d5b140c8">1c3862e</a>)</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/kaniko-build-action/</link><pubDate>Fri, 07 Aug 2026 07:28:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting to a specified person. It solves the problem of automating greetings and outputs the time of greeting, making it useful for logging purposes in projects that require automated interactions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting to a specified person. It solves the problem of automating greetings and outputs the time of greeting, making it useful for logging purposes in projects that require automated interactions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>Extract Commit Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/extract-commit-action/</link><pubDate>Fri, 07 Aug 2026 07:28:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/extract-commit-action/</guid><description>Version updated for https://github.com/somaz94/commit-info-extractor to version v1.5.0.
This action is used across all versions by 3 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Extract Commit Action is a versatile GitHub Action that automates the extraction of information from commit messages using customizable patterns or commands. It supports text, JSON, and CSV output formats and allows control over the number of commits analyzed to handle long-running operations efficiently. The action is designed to streamline development workflows by providing flexible extraction options and fail-safe mechanisms for handling empty results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/commit-info-extractor">https://github.com/somaz94/commit-info-extractor</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/extract-commit-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Extract Commit Action is a versatile GitHub Action that automates the extraction of information from commit messages using customizable patterns or commands. It supports text, JSON, and CSV output formats and allows control over the number of commits analyzed to handle long-running operations efficiently. The action is designed to streamline development workflows by providing flexible extraction options and fail-safe mechanisms for handling empty results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="build">Build</h3>
<ul>
<li>bump actions/checkout from 6 to 7 by @dependabot[bot]</li>
<li>bump actions/setup-python from 6 to 7 (#14) by @dependabot[bot] in #14</li>
</ul>
<h3 id="cicd">CI/CD</h3>
<ul>
<li>add DCO check via shared reusable workflow by @somaz94</li>
<li>add PR welcome workflow stub by @somaz94</li>
<li>add ok-to-test workflow stub by @somaz94</li>
<li>use reusable contributors workflow by @somaz94</li>
<li>use reusable dependabot-auto-merge workflow by @somaz94</li>
<li>use reusable issue-greeting workflow by @somaz94</li>
<li>use reusable stale-issues workflow by @somaz94</li>
<li>adopt semantic-pr, labels, lock-threads, PR size, and auto-assign reusables by @somaz94</li>
<li>remove DCO workflow by @somaz94</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>ship a prebuilt multi-arch image instead of building per run by @somaz94</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/commit-info-extractor/compare/v1.4.3...v1.5.0">https://github.com/somaz94/commit-info-extractor/compare/v1.4.3...v1.5.0</a></p>
]]></content:encoded></item><item><title>Environment/Output Setter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/environment/output-setter/</link><pubDate>Fri, 07 Aug 2026 07:27:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/environment/output-setter/</guid><description>Version updated for https://github.com/somaz94/env-output-setter to version v1.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Environment/Output Setter is a GitHub Action that simplifies setting multiple environment variables and outputs for your workflows. It automates tasks such as dynamically defining environment variables or output values, which can be reused across different steps and workflows. The action provides features like value transformation, JSON support, and retry mechanisms to ensure robustness in complex environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/env-output-setter">https://github.com/somaz94/env-output-setter</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/environment-output-setter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <strong>GitHub Environment/Output Setter</strong> is a GitHub Action that simplifies setting multiple environment variables and outputs for your workflows. It automates tasks such as dynamically defining environment variables or output values, which can be reused across different steps and workflows. The action provides features like value transformation, JSON support, and retry mechanisms to ensure robustness in complex environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="cicd">CI/CD</h3>
<ul>
<li>add a golangci-lint config scoped to defect-finding linters by @somaz94</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>ship a prebuilt multi-arch image instead of building per run by @somaz94</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/env-output-setter/compare/v1.8.1...v1.9.0">https://github.com/somaz94/env-output-setter/compare/v1.8.1...v1.9.0</a></p>
]]></content:encoded></item><item><title>Go Changelog Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/go-changelog-generator/</link><pubDate>Fri, 07 Aug 2026 07:26:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/go-changelog-generator/</guid><description>Version updated for https://github.com/somaz94/go-changelog-action to version v1.1.0.
This action is used across all versions by 10 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Go Changelog Action automates the process of generating change logs from git history using Conventional Commits format. It groups changes by type, highlights breaking changes, supports PR links and issue references, generates compare links, includes contributors section per release, and allows custom configuration options such as tag patterns, date formats, and excluded types.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/go-changelog-action">https://github.com/somaz94/go-changelog-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-changelog-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Go Changelog Action automates the process of generating change logs from git history using Conventional Commits format. It groups changes by type, highlights breaking changes, supports PR links and issue references, generates compare links, includes contributors section per release, and allows custom configuration options such as tag patterns, date formats, and excluded types.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="cicd">CI/CD</h3>
<ul>
<li>add a golangci-lint config scoped to defect-finding linters by @somaz94</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>ship a prebuilt multi-arch image instead of building per run by @somaz94</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/go-changelog-action/compare/v1.0.10...v1.1.0">https://github.com/somaz94/go-changelog-action/compare/v1.0.10...v1.1.0</a></p>
]]></content:encoded></item><item><title>Go Git Commit Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/go-git-commit-action/</link><pubDate>Fri, 07 Aug 2026 07:25:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/go-git-commit-action/</guid><description>Version updated for https://github.com/somaz94/go-git-commit-action to version v1.9.0.
This action is used across all versions by 18 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Go Git Commit Action automates Git commit, push, tag, and pull request operations using the Go programming language. It provides a fast and reliable solution with features such as flexible file pattern support, secure authentication handling, and the ability to create and delete tags. The action is designed to streamline development workflows by reducing manual steps involved in Git management.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/go-git-commit-action">https://github.com/somaz94/go-git-commit-action</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-git-commit-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Go Git Commit Action automates Git commit, push, tag, and pull request operations using the Go programming language. It provides a fast and reliable solution with features such as flexible file pattern support, secure authentication handling, and the ability to create and delete tags. The action is designed to streamline development workflows by reducing manual steps involved in Git management.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="cicd">CI/CD</h3>
<ul>
<li>add a golangci-lint config scoped to defect-finding linters by @somaz94</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>ship a prebuilt multi-arch image instead of building per run by @somaz94</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/go-git-commit-action/compare/v1.8.2...v1.9.0">https://github.com/somaz94/go-git-commit-action/compare/v1.8.2...v1.9.0</a></p>
]]></content:encoded></item><item><title>Multi Git Mirror</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/multi-git-mirror/</link><pubDate>Fri, 07 Aug 2026 07:24:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/multi-git-mirror/</guid><description>Version updated for https://github.com/somaz94/multi-git-mirror to version v1.2.0.
This action is used across all versions by 36 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This Go-based GitHub Action automates the process of mirroring Git repositories to multiple Git hosting providers, including GitLab, GitHub, Bitbucket, AWS CodeCommit, and others. It supports selective branch mirroring, tag mirroring, force push, and parallel mirroring for efficient repository management across different platforms. The action also includes a dry run option to check connectivity before performing the mirroring process and outputs results in JSON format for downstream integration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/multi-git-mirror">https://github.com/somaz94/multi-git-mirror</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>36</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/multi-git-mirror">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This Go-based GitHub Action automates the process of mirroring Git repositories to multiple Git hosting providers, including GitLab, GitHub, Bitbucket, AWS CodeCommit, and others. It supports selective branch mirroring, tag mirroring, force push, and parallel mirroring for efficient repository management across different platforms. The action also includes a dry run option to check connectivity before performing the mirroring process and outputs results in JSON format for downstream integration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="cicd">CI/CD</h3>
<ul>
<li>add concurrency guards to recurring workflows by @somaz94</li>
<li>add DCO check via shared reusable workflow by @somaz94</li>
<li>add PR welcome workflow stub by @somaz94</li>
<li>add ok-to-test workflow stub by @somaz94</li>
<li>use reusable contributors workflow by @somaz94</li>
<li>use reusable dependabot-auto-merge workflow by @somaz94</li>
<li>use reusable issue-greeting workflow by @somaz94</li>
<li>use reusable stale-issues workflow by @somaz94</li>
<li>adopt semantic-pr, labels, lock-threads, PR size, and auto-assign reusables by @somaz94</li>
<li>remove DCO workflow by @somaz94</li>
<li>add a golangci-lint config scoped to defect-finding linters by @somaz94</li>
</ul>
<h3 id="chore">Chore</h3>
<ul>
<li>add git config protection to CLAUDE.md by @somaz94</li>
<li>remove duplicate rules from CLAUDE.md (moved to global) by @somaz94</li>
<li>bump softprops/action-gh-release from 2 to 3 by @dependabot[bot]</li>
<li>bump dependabot/fetch-metadata from 2 to 3 by @dependabot[bot]</li>
<li>bump actions/github-script from 8 to 9 by @dependabot[bot]</li>
<li>bump alpine from 3.23 to 3.24 in the docker-minor group (#5) by @dependabot[bot] in #5</li>
<li>bump actions/checkout from 6 to 7 (#6) by @dependabot[bot] in #6</li>
<li>bump actions/setup-go from 6 to 7 by @dependabot[bot]</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>remove duplicate rules covered by global CLAUDE.md by @somaz94</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>ship a prebuilt multi-arch image instead of building per run by @somaz94</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/multi-git-mirror/compare/v1.1.1...v1.2.0">https://github.com/somaz94/multi-git-mirror/compare/v1.1.1...v1.2.0</a></p>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/pipr-review/</link><pubDate>Fri, 07 Aug 2026 07:22:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.8.0.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipr automates AI code reviews across multiple code hosts. It supports various platforms including GitHub, GitLab, Azure DevOps, Bitbucket, Gitea, Forgejo, and Codeberg. Users can configure different models, set up review limits, and compose custom workflows using a typed SDK. Pipr validates findings before publishing comments and integrates seamlessly into existing CI/CD processes without tying policies to specific platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Pipr automates AI code reviews across multiple code hosts. It supports various platforms including GitHub, GitLab, Azure DevOps, Bitbucket, Gitea, Forgejo, and Codeberg. Users can configure different models, set up review limits, and compose custom workflows using a typed SDK. Pipr validates findings before publishing comments and integrates seamlessly into existing CI/CD processes without tying policies to specific platforms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="080-2026-08-06"><a href="https://github.com/somus/pipr/compare/v0.7.0...v0.8.0">0.8.0</a> (2026-08-06)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li>trigger 0.8.0 release</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li>improve review run observability (<a href="https://github.com/somus/pipr/issues/141">#141</a>) (<a href="https://github.com/somus/pipr/commit/b975983f237935330b4033a42f40e75db1ea2ede">b975983</a>)</li>
<li><strong>sdk:</strong> validate custom findings through task context (<a href="https://github.com/somus/pipr/issues/144">#144</a>) (<a href="https://github.com/somus/pipr/commit/99a3838eca92318d0b67c6c85b139c830022a4ee">99a3838</a>)</li>
<li>trigger 0.8.0 release (<a href="https://github.com/somus/pipr/commit/4821a0a903fa88515d6915eeee4e8d2160ff610d">4821a0a</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>bitbucket:</strong> scope fork checkout credentials (<a href="https://github.com/somus/pipr/issues/143">#143</a>) (<a href="https://github.com/somus/pipr/commit/13dfdf60f83a826b34503e2e200efb02f1066717">13dfdf6</a>)</li>
</ul>
]]></content:encoded></item><item><title>Spare Parts LGTM</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/spare-parts-lgtm/</link><pubDate>Fri, 07 Aug 2026 07:21:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/spare-parts-lgtm/</guid><description>Version updated for https://github.com/sparepartslabs/spareparts-lgtm to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary LGTM is a GitHub Action that automates the process of asking reviewers questions about the changes in a pull request. It helps ensure that reviewers have read and understood the code before approving it. The action uses AI-generated prompts to verify if reviewers have truly read the PR content. It provides two or three questions, allowing for a deeper review if needed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sparepartslabs/spareparts-lgtm">https://github.com/sparepartslabs/spareparts-lgtm</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spare-parts-lgtm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>LGTM is a GitHub Action that automates the process of asking reviewers questions about the changes in a pull request. It helps ensure that reviewers have read and understood the code before approving it. The action uses AI-generated prompts to verify if reviewers have truly read the PR content. It provides two or three questions, allowing for a deeper review if needed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Display name only. The action is listed as <strong>Spare Parts LGTM</strong>, because the GitHub Marketplace requires a globally unique name and &ldquo;LGTM&rdquo; is not one.</p>
<p>Nothing about using it changes:</p>
<ul>
<li>the reference is still <code>uses: sparepartslabs/spareparts-lgtm@v1</code></li>
<li>the check is still <code>LGTM — review confirmed</code></li>
<li>the bot is still summoned with <code>@lgtm</code></li>
</ul>
<p><code>v1</code> now points here, so anyone on the major tag picks this up without changing a line.</p>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/runward-gate/</link><pubDate>Fri, 07 Aug 2026 07:20:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.33.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is an open-source tool designed to verify the engineering decisions behind AI-generated code by using plain code. It automates the verification process of full engineering missions from framing through handover, ensuring that the load-bearing decisions are followed and documented effectively. Runward provides a deterministic gate that checks against predefined expectations, preventing unintended outcomes and ensuring code integrity.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.33.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Runward is an open-source tool designed to verify the engineering decisions behind AI-generated code by using plain code. It automates the verification process of full engineering missions from framing through handover, ensuring that the load-bearing decisions are followed and documented effectively. Runward provides a deterministic gate that checks against predefined expectations, preventing unintended outcomes and ensuring code integrity.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>0.32.0 fixed what an audit found. This one measures what the net that guards it would catch, and publishes the answer with everything in it that counts against us.</strong></p>
<p>No behaviour of the gate changes. 24 golden outputs across four missions and six flag combinations are byte-identical to 0.32.0, exit codes included.</p>
<h2 id="how-much-does-this-test-suite-actually-detect">How much does this test suite actually detect</h2>
<p>A full mutation pass (Stryker 9.6.1) on the seven library modules the verdict is computed from. <strong>Mutation score 60.78 %</strong> — 2 973 mutants, 1 769 killed, 38 timeout, 1 166 survived, in 2 h 35.</p>
<p>A survivor count is not a defect count, and treating it as one produces a day of false findings. So: 433 survivors carry mutators able to flip a <em>decision</em> and were re-run against the whole net (unit suite, self-gate, OSCAL validation, end-to-end smoke). <strong>53 died there, 380 survived everything.</strong> 246 of those were then instructed one function at a time, each by applying the mutant to a real mission and reading the verdict rather than reasoning about the code. <strong>181 now die</strong>, measured centrally rather than claimed.</p>
<p>Three mechanisms were <strong>correct in every shipped release</strong> and guarded by <strong>no test</strong>:</p>
<table>
  <thead>
      <tr>
          <th>Mechanism</th>
          <th>What one mutation does</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Seal tamper detection</td>
          <td>One field returned false in <code>verifyEvidenceLock</code> takes a sealed, tampered mission from exit 1 to <strong>exit 0</strong>. <code>check.ts</code> gates the whole seal section on it, so the violations were neither printed nor counted. Reproduced by hand.</td>
      </tr>
      <tr>
          <td>The ReDoS screen (ADR-0020)</td>
          <td>The nested-group collapse loop was entered by no fixture. It could be deleted with the suite still green.</td>
      </tr>
      <tr>
          <td>Pointer containment</td>
          <td>The repository fallback was dead code under test: every containment test ran in a bare temp directory.</td>
      </tr>
  </tbody>
</table>
<p><strong>One correction the pass forced on its own reading</strong>, and the reason ADR-0046 exists: a surviving mutant is <em>not</em> automatically a false green. Forcing <code>artifactState</code> to call every ADR directory <code>filled</code> survives the unit suite, the self-gate, the smoke run <strong>and</strong> the audit corpus — and the mission is still <strong>refused</strong>, because a typed pointer does not resolve. Defence in depth. What it corrupts is the printed line, and for this tool a proof surface that lies under a correct verdict is a defect of its own.</p>
<p>Mutation testing is adopted as an <strong>instrument, never a gate</strong>. No score is ever a crossing condition: a number in a manifest is a verdict satisfied by a figure nobody re-derived, which is exactly what ADR-0045 forbids, and runward does not do to itself what it refuses from an operator.</p>
<h2 id="the-verdict-is-now-computed-where-a-test-can-reach-it">The verdict is now computed where a test can reach it</h2>
<p>The largest absence of that measurement was the one that mattered: <code>src/commands/check.ts</code>, where the verdict is assembled and the exit code chosen, sat at <strong>8.70 % line and 0 % function coverage</strong>, no unit test imported it, and the mutation pass could not reach it at all.</p>
<p><code>src/lib/verdict.ts</code> is now a pure reading of the mission: it prints nothing, never touches <code>process.exitCode</code>, runs no hook. <strong>97.79 % line, 100 % function</strong>, and inside the measured perimeter from now on. 12 hand-written mutants, 11 killed; the survivor is argued rather than assumed (ADR-0047).</p>
<h2 id="what-we-publish-about-ourselves">What we publish about ourselves</h2>
<ul>
<li><strong><code>docs/compliance/known-defects.md</code></strong> — 20 entries in four classes, each with the version range it affects and the command that verifies it. It lists <strong>both directions</strong>: the undue passes <em>and</em> the five undue refusals that shipped in 0.31.x. A register that only published false greens describes half a campaign.</li>
<li><strong><code>docs/compliance/regulated-adoption.md</code></strong> gains the axis it was missing. It was written on the shape of a SaaS questionnaire; the axis that decides for a tool that renders a verdict — <strong>whether the verdict is right</strong> — was absent from all 82 lines. New section 8 works the tool-confidence analysis through for medical device, automotive, rail and airborne software, <strong>adverse case first</strong>, and asserts no level and no class for runward in any scheme.</li>
<li>Its footer no longer claims every verifiable claim on the page is enforced in CI. That was a reassuring count over a set the author chose.</li>
<li>One published falsehood corrected: <code>GATE_NON_SCOPE</code> is <strong>not</strong> printed in every compliance pack. It appears only in the ISO/IEC 42001 draft — and the pack it is missing from is the one that goes to a high-risk provider.</li>
</ul>
<h2 id="guards-that-had-a-broken-perimeter">Guards that had a broken perimeter</h2>
<p>Four instances in one week, the recurring defect of this repository:</p>
<ul>
<li><strong>The reproducible-build job had never once compared two tarballs</strong> — <code>npm pack --pack-destination</code> does not create the directory, so it exited ENOENT on its own output path. The claim it guards is true; the guard never reached the comparison.</li>
<li><strong>The overclaim guard</strong> saw neither <code>TQL</code>, nor <code>TCL2/3</code>, nor the rail classes. Widened <em>before</em> the section that produces that risk was written.</li>
<li><strong><code>CITATION.cff</code> was pinned at 0.21.0</strong> for eleven releases.</li>
<li><code>docs/compliance/eu-ai-act.md</code> contradicted itself two lines apart on the high-risk binding date.</li>
</ul>
<h2 id="also">Also</h2>
<ul>
<li><code>test/audit-corpus.js</code> — the adversarial campaign behind ADR-0045 becomes a corpus anyone can replay against the real CLI.</li>
<li><code>regimes/eu-ai-act@2026-1744.json</code> — the expired sheet had missed an amending regulation. The dated-facts watch now detects that the <strong>text</strong> moved instead of waiting for a date we guessed.</li>
<li>Unit suite <strong>209 → 342</strong>. Whole-project line coverage 74.90 → 79.70 %.</li>
</ul>
<p><strong>Full changelog</strong>: <a href="https://github.com/stranxik/runward/blob/main/CHANGELOG.md">https://github.com/stranxik/runward/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>MCP Tenant Isolation Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/mcp-tenant-isolation-scan/</link><pubDate>Fri, 07 Aug 2026 07:19:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/mcp-tenant-isolation-scan/</guid><description>Version updated for https://github.com/subodhkc/mcp-tenant-isolation to version v1.6.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, mcp-tenant-isolation, is a static analysis tool designed to detect and prevent cross-tenant data leakage in multi-tenant SaaS applications and MCP server codebases. It uses 57 deterministic rules to check for common vulnerabilities related to tenant isolation, database query filtering, IDOR prevention, cache key scoping, RLS, schema gaps, and MCP-specific risks such as tool visibility, cache prefix, session binding, credential vault, and more. The tool supports various frameworks including Prisma, Drizzle, raw SQL, Next.js, Express, and Fastify, making it versatile for different types of projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/subodhkc/mcp-tenant-isolation">https://github.com/subodhkc/mcp-tenant-isolation</a></strong> to version <strong>v1.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-tenant-isolation-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>mcp-tenant-isolation</code>, is a static analysis tool designed to detect and prevent cross-tenant data leakage in multi-tenant SaaS applications and MCP server codebases. It uses 57 deterministic rules to check for common vulnerabilities related to tenant isolation, database query filtering, IDOR prevention, cache key scoping, RLS, schema gaps, and MCP-specific risks such as tool visibility, cache prefix, session binding, credential vault, and more. The tool supports various frameworks including Prisma, Drizzle, raw SQL, Next.js, Express, and Fastify, making it versatile for different types of projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Scans TypeScript and JavaScript codebases for tenant isolation vulnerabilities. 57 deterministic rules covering database query tenant filters, IDOR, cache key scoping, session isolation, file storage scoping, RLS, schema gaps, and MCP-specific risks (tool visibility, cache prefix, session binding, credential vault). Outputs SARIF for GitHub Code Scanning, Markdown for PR reports, and AI-friendly JSON for agent integration. Includes an MCP server for AI agent tool use.
Categories: Security, Developer Tools, Code Quality
Pricing: Free</p>
]]></content:encoded></item><item><title>Set up TestLens</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/set-up-testlens/</link><pubDate>Fri, 07 Aug 2026 07:18:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/set-up-testlens/</guid><description>Version updated for https://github.com/testlens-app/setup-testlens to version v1.9.4.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 39 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action setup-testlens connects Maven or Gradle builds to TestLens for code coverage analysis. It automates the process of instrumenting test tasks with TestLens, providing a type-safe way to integrate TestLens into workflows using Kotlin DSL. The action requires the TestLens GitHub App installation on the repository and supports both Gradle and Maven projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/testlens-app/setup-testlens">https://github.com/testlens-app/setup-testlens</a></strong> to version <strong>v1.9.4</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>39</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/set-up-testlens">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>setup-testlens</code> connects Maven or Gradle builds to TestLens for code coverage analysis. It automates the process of instrumenting test tasks with TestLens, providing a type-safe way to integrate TestLens into workflows using Kotlin DSL. The action requires the TestLens GitHub App installation on the repository and supports both Gradle and Maven projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: capture env vars as properties file during action run by @marcphilipp in <a href="https://github.com/testlens-app/setup-testlens/pull/83">https://github.com/testlens-app/setup-testlens/pull/83</a></li>
<li>feat: print detection result to ease onboarding by @marcphilipp in <a href="https://github.com/testlens-app/setup-testlens/pull/85">https://github.com/testlens-app/setup-testlens/pull/85</a></li>
<li>feat: add <code>working-directory</code> option for non-root checkouts by @marcphilipp in <a href="https://github.com/testlens-app/setup-testlens/pull/86">https://github.com/testlens-app/setup-testlens/pull/86</a></li>
<li>fix: handle empty environment variables</li>
<li>fix: retry connecting to server after initial transient failures</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/testlens-app/setup-testlens/compare/v1.9.3...v1.9.4">https://github.com/testlens-app/setup-testlens/compare/v1.9.3...v1.9.4</a></p>
]]></content:encoded></item><item><title>Advanced Jules PR Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/advanced-jules-pr-reviewer/</link><pubDate>Fri, 07 Aug 2026 07:17:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/advanced-jules-pr-reviewer/</guid><description>Version updated for https://github.com/thalesraymond/jules-pr-reviewer to version v1.4.0.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Google Jules, a Gemini-powered cloud coding agent, to review pull requests and post inline comments with severity levels. It helps identify security flaws in code by analyzing the changes made in a PR, providing line-level feedback and automatically resolving threads if issues are fixed. The action can be configured with custom rules either directly in the workflow or through a file in the repository, enhancing its flexibility and usability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thalesraymond/jules-pr-reviewer">https://github.com/thalesraymond/jules-pr-reviewer</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/advanced-jules-pr-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Google Jules, a Gemini-powered cloud coding agent, to review pull requests and post inline comments with severity levels. It helps identify security flaws in code by analyzing the changes made in a PR, providing line-level feedback and automatically resolving threads if issues are fixed. The action can be configured with custom rules either directly in the workflow or through a file in the repository, enhancing its flexibility and usability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="140-2026-08-06"><a href="https://github.com/thalesraymond/jules-pr-reviewer/compare/v1.3.0...v1.4.0">1.4.0</a> (2026-08-06)</h2>
<h3 id="features">Features</h3>
<ul>
<li>add and integrate strict runtime validation for LLM JSON responses (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/a3485055076ea4bd055dc70f87ea41ec29cbf397">a348505</a>)</li>
<li>add resilient Jules JSON payload extraction (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/e36e44be19c61661d29e60a33f2e708df189764a">e36e44b</a>)</li>
<li>better logs (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/25d3b604e9fc59d47fa656f2be02052ffa1e1279">25d3b60</a>)</li>
<li><strong>code-review:</strong> added suggested changes to jules response (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/d1849dbdf7d4fa97aa99013fcfc87a3e56a5d816">d1849db</a>)</li>
<li>fix formatting issues in src/utils.ts and tests/jules.test.ts (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/a01245e8b3043bab317fc551efa75a94eee8bf5c">a01245e</a>)</li>
<li>github code suggestion (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/d617fe3ece873376d6c1cae67b40fd6384640087">d617fe3</a>)</li>
<li><strong>json-validation:</strong> enable json validation and fallback (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/e0331d563cd5ff78412e3546e759cf9f6194ecff">e0331d5</a>)</li>
<li><strong>jules:</strong> retry logic (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/58f50818f2b3307704b4a934dcf05281358a3f22">58f5081</a>)</li>
<li><strong>logs:</strong> improve logs (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/ffcb246e7e1fc2a4faacbdad414a28423fba5b18">ffcb246</a>)</li>
<li><strong>utils:</strong> add getErrorMessage utility and integrate it across files (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/3ce857a5ea7b800235c22d50a4bec47b07facfbc">3ce857a</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>code-review:</strong> fix action beign unable to parse on multilayer code blocks (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/d2e61874346070fbfbae8497609b27691bf44f94">d2e6187</a>)</li>
<li>pass title property to session create payload to satisfy preconditions (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/df96c9b60481d425935cbbf074c0abc0c019214a">df96c9b</a>)</li>
<li><strong>sec:</strong> match tag with space (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/5792f9781e30fcf9a8f2026c16503b62665c734e">5792f97</a>)</li>
<li><strong>security:</strong> sanitize promptForAgents to prevent HTML injection (<a href="https://github.com/thalesraymond/jules-pr-reviewer/commit/a20dfc674c6006ea40a1cffce4c26ec5dc1db765">a20dfc6</a>)</li>
</ul>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/setup-tombi/</link><pubDate>Fri, 07 Aug 2026 07:16:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.7.
This action is used across all versions by 143 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi, a tool for managing and securing configuration files, in your CI/CD workflows. It simplifies the installation process by allowing users to specify different versions, use lock files for consistency, and verify checksums for integrity. The action supports various runners and provides options to manage cache behavior effectively.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.2.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>143</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up Tombi, a tool for managing and securing configuration files, in your CI/CD workflows. It simplifies the installation process by allowing users to specify different versions, use lock files for consistency, and verify checksums for integrity. The action supports various runners and provides options to manage cache behavior effectively.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.2.7">tombi v1.2.7</a>.</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Address Dependabot vulnerabilities by @ya7010 in <a href="https://github.com/tombi-toml/setup-tombi/pull/46">https://github.com/tombi-toml/setup-tombi/pull/46</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.7">https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.7</a></p>
]]></content:encoded></item><item><title>Veracode Configure</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/veracode-configure/</link><pubDate>Fri, 07 Aug 2026 07:14:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/veracode-configure/</guid><description>Version updated for https://github.com/vcode-config/configure to version v0.03.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The veracode-config GitHub Action automates the process of onboarding repositories into the Veracode Workflow integration. It checks for and creates an Application Profile, persists inventory and workflow configuration values in custom metadata, and exposes reusable workflow outputs for downstream jobs. The action inventories programming languages, package managers, and non-GitHub build definitions, and can refresh or update these inventories as needed. It supports various configuration options and provides outputs for application GUIDs and workflow configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vcode-config/configure">https://github.com/vcode-config/configure</a></strong> to version <strong>v0.03</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/veracode-configure">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>veracode-config</code> GitHub Action automates the process of onboarding repositories into the Veracode Workflow integration. It checks for and creates an Application Profile, persists inventory and workflow configuration values in custom metadata, and exposes reusable workflow outputs for downstream jobs. The action inventories programming languages, package managers, and non-GitHub build definitions, and can refresh or update these inventories as needed. It supports various configuration options and provides outputs for application GUIDs and workflow configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>better logging (a0d1ee7)</li>
<li>Corrected the main call to use dist/index.mjs (abcc572)</li>
<li>initial commit (460d6f7)</li>
</ul>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/vibgrate-scan/</link><pubDate>Fri, 07 Aug 2026 07:13:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.806.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @vibgrate/cli GitHub Action is a local tool that analyzes your codebase to determine its current state and how it compares to previous versions. It provides a code graph and drift score, which helps identify dependencies and potential risks related to outdated libraries or runtime issues. The action is designed to run on the user’s machine without relying on external APIs or networks, making it efficient for local development and collaboration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.806.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>@vibgrate/cli</code> GitHub Action is a local tool that analyzes your codebase to determine its current state and how it compares to previous versions. It provides a code graph and drift score, which helps identify dependencies and potential risks related to outdated libraries or runtime issues. The action is designed to run on the user&rsquo;s machine without relying on external APIs or networks, making it efficient for local development and collaboration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268062">Vibgrate CLI 2026.806.2</h1>
<p><em>Released 2026-08-06</em></p>
<p>This release of the vg command-line scanner includes important fixes and new capabilities. Notably, it improves stability when the semantic backend encounters issues and introduces several new features for enhanced functionality.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>VG Code can now stream shell command output, maintain a task checklist, fetch and search the web under policy, edit Jupyter notebook cells, start a local browser session, and spawn a worktree-scoped subagent.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Code Graph Ask no longer crashes the language server when the semantic backend is broken.</li>
</ul>
<h3 id="security">Security</h3>
<ul>
<li>Updated @modelcontextprotocol/sdk and yaml to patched releases addressing known supply-chain advisories.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.806.1, interleaved on one runner against the pinned corpus (189 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21601 count</td>
          <td>21601 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>10830 count</td>
          <td>10830 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.94 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>645.80 ms</td>
          <td>647.10 ms</td>
      </tr>
  </tbody>
</table>
<p>2 regression(s) — published, not omitted:</p>
<ul>
<li>Tasks passed on both arms: 33 → 31 (-6.1%)</li>
<li>Comparable-task rate (both arms passed / total): 0.94 → 0.89 (-6.1%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.806.2">https://vibgrate.com/changelog/cli/2026.806.2</a></p>
]]></content:encoded></item><item><title>Vigilnz Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/vigilnz-security-scan/</link><pubDate>Fri, 07 Aug 2026 07:11:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/vigilnz-security-scan/</guid><description>Version updated for https://github.com/Vigilnz/vigilnz-scan-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Vigilnz Security Scan Action automates security scans for applications and repositories using Vigilnz’s API. It supports SCA, SBOM, SAST, IAC SCAN, SECRET SCAN, DAST, and CONTAINER SCAN. The action makes it easy to integrate security scanning into GitHub workflows by generating an API key, storing it securely in secrets, and adding the action to the workflow configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Vigilnz/vigilnz-scan-action">https://github.com/Vigilnz/vigilnz-scan-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vigilnz-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Vigilnz Security Scan Action automates security scans for applications and repositories using Vigilnz&rsquo;s API. It supports SCA, SBOM, SAST, IAC SCAN, SECRET SCAN, DAST, and CONTAINER SCAN. The action makes it easy to integrate security scanning into GitHub workflows by generating an API key, storing it securely in secrets, and adding the action to the workflow configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Add api-client.js for handling Vigilnz REST API interactions including authentication, scan submission, status polling, and result summary retrieval.</li>
<li>Introduce constants.js for shared constants across the action, including API URLs and timeout settings.</li>
<li>Create inputs.js to read and normalize action inputs, including environment resolution and credential handling.</li>
<li>Develop report.js to publish action outputs and render job summary tables for scan results.</li>
<li>Add wait-for-scans.js to poll scan targets until completion, aggregate results, and evaluate severity gates.</li>
</ul>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/rustscript-action/</link><pubDate>Fri, 07 Aug 2026 07:10:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.2.25.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The RustScript GitHub Action interprets and runs Rust scripts without compiling them fully, using a practical subset of the language. It provides a lightweight alternative to running full Rust projects by executing scripts directly with a register VM. The action supports running scripts, validating them, building native binaries, checking supported methods, cleaning caches, updating releases, and displaying version information.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.2.25</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The RustScript GitHub Action interprets and runs Rust scripts without compiling them fully, using a practical subset of the language. It provides a lightweight alternative to running full Rust projects by executing scripts directly with a register VM. The action supports running scripts, validating them, building native binaries, checking supported methods, cleaning caches, updating releases, and displaying version information.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.25">https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.25</a></p>
]]></content:encoded></item><item><title>MidnightBSD-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/midnightbsd-vm/</link><pubDate>Fri, 07 Aug 2026 07:09:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/midnightbsd-vm/</guid><description>Version updated for https://github.com/vmactions/midnightbsd-vm to version v1.0.5.
This action is used across all versions by 34 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running CI jobs on MidnightBSD. It supports a variety of releases and architectures, including x86_64. The action allows users to pass environment variables, run commands, and share code between their host machine and the VM using rsync, sshfs, nfs, or scp. Users can specify which shell to use within the VM. The latest major version is recommended for use, with instructions on migrating from previous versions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/midnightbsd-vm">https://github.com/vmactions/midnightbsd-vm</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>34</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/midnightbsd-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running CI jobs on MidnightBSD. It supports a variety of releases and architectures, including x86_64. The action allows users to pass environment variables, run commands, and share code between their host machine and the VM using rsync, sshfs, nfs, or scp. Users can specify which shell to use within the VM. The latest major version is recommended for use, with instructions on migrating from previous versions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>move to 4.0.7</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/midnightbsd-vm/compare/v1.0.4...v1.0.5">https://github.com/vmactions/midnightbsd-vm/compare/v1.0.4...v1.0.5</a></p>
]]></content:encoded></item><item><title>ESLint AI Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/eslint-ai-guard/</link><pubDate>Fri, 07 Aug 2026 07:08:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/eslint-ai-guard/</guid><description>Version updated for https://github.com/YashJadhav21/eslint-plugin-ai-guard to version v1.3.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose and Functionality: The GitHub Action ai-guard is designed to prevent AI-generated code from introducing reliability and security bugs into your project by identifying and flagging patterns that are consistently incorrect.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YashJadhav21/eslint-plugin-ai-guard">https://github.com/YashJadhav21/eslint-plugin-ai-guard</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/eslint-ai-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Purpose and Functionality:</strong> The GitHub Action <strong>ai-guard</strong> is designed to prevent AI-generated code from introducing reliability and security bugs into your project by identifying and flagging patterns that are consistently incorrect.</p>
<p><strong>Problems Solved:</strong> It helps catch errors such as missing error handling, asynchronous callback errors, insecure API usage, and dead scaffolding in generated code.</p>
<p><strong>Key Capabilities:</strong></p>
<ul>
<li><strong>Inline PR Annotations:</strong> Highlights issues directly within GitHub pull requests.</li>
<li><strong>SARIF Reports for Code Scanning:</strong> Provides detailed reports for GitHub Code Scanning to support automated security audits.</li>
<li><strong>Blocking Merges:</strong> Prevents the merge of potentially risky changes until issues are addressed.</li>
</ul>
<p><strong>Installation and Quick Start:</strong> No additional configuration is required; it automatically integrates with GitHub workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="ai-guard-v130">AI Guard v1.3.0</h1>
<p>This release focuses on improving reliability, developer experience, and GitHub integration.</p>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li>Reduced false positives after validation against multiple real-world repositories.</li>
<li>Improved <code>ai-guard init --yes</code> for one-command project setup.</li>
<li>Better GitHub Actions integration with SARIF output and PR annotations.</li>
<li>Added FAQs, troubleshooting guides, and benchmark documentation.</li>
<li>Improved self-validation and workflow reliability.</li>
</ul>
<h2 id="github-action">GitHub Action</h2>
<p>Run AI Guard directly in your CI:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">YashJadhav21/eslint-plugin-ai-guard@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">preset</span>: <span style="color:#ae81ff">recommended</span>
</span></span></code></pre></div><p>The Action can:</p>
<ul>
<li>Review changed files in pull requests</li>
<li>Generate SARIF reports</li>
<li>Upload results to GitHub Code Scanning</li>
<li>Add inline PR annotations</li>
<li>Fail builds based on severity thresholds</li>
</ul>
<h2 id="package">Package</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install --save-dev eslint-plugin-ai-guard
</span></span></code></pre></div><p>or</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx ai-guard init --yes
</span></span></code></pre></div><h2 id="resources">Resources</h2>
<ul>
<li><strong>GitHub:</strong> <a href="https://github.com/YashJadhav21/eslint-plugin-ai-guard">https://github.com/YashJadhav21/eslint-plugin-ai-guard</a></li>
<li><strong>npm:</strong> <a href="https://www.npmjs.com/package/eslint-plugin-ai-guard">https://www.npmjs.com/package/eslint-plugin-ai-guard</a></li>
</ul>
<h2 id="demo">Demo</h2>
<img width="1348" height="600" alt="ezgif com-speed" src="https://github.com/user-attachments/assets/81b9ae6c-fb0f-4492-8d94-9869bcbea505" />
<hr>
<p>Thanks to everyone who has tried AI Guard, opened discussions, shared feedback, or adopted it in their projects. Every suggestion has helped improve the rules and reduce false positives.</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/b.ia-accessibility-checker/</link><pubDate>Fri, 07 Aug 2026 07:07:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines, enabling companies to ensure their code meets WCAG guidelines. It simplifies the process by defining an audience and specifying the percentage of guidelines to be met. This helps focus on a larger share of the audience, improving overall product accessibility and revenue potential.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines, enabling companies to ensure their code meets WCAG guidelines. It simplifies the process by defining an audience and specifying the percentage of guidelines to be met. This helps focus on a larger share of the audience, improving overall product accessibility and revenue potential.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>vibecheck-ai-slop</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/vibecheck-ai-slop/</link><pubDate>Fri, 07 Aug 2026 07:05:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/07/vibecheck-ai-slop/</guid><description>Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.20.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary vibecheck is a code scanning tool that implements 39 rules to catch AI-generated code smells. It helps identify security issues, error handling problems, and code quality issues in AI-generated code without requiring API keys or configuration. The action can be run directly, globally installed, or used as a standalone binary for macOS and Linux platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuvrajangadsingh/vibecheck">https://github.com/yuvrajangadsingh/vibecheck</a></strong> to version <strong>v1.20.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibecheck-ai-slop">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>vibecheck is a code scanning tool that implements 39 rules to catch AI-generated code smells. It helps identify security issues, error handling problems, and code quality issues in AI-generated code without requiring API keys or configuration. The action can be run directly, globally installed, or used as a standalone binary for macOS and Linux platforms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>v1.20.1: stop discarding piped output on exit by @yuvrajangadsingh in <a href="https://github.com/yuvrajangadsingh/vibecheck/pull/14">https://github.com/yuvrajangadsingh/vibecheck/pull/14</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yuvrajangadsingh/vibecheck/compare/v1.20.0...v1.20.1">https://github.com/yuvrajangadsingh/vibecheck/compare/v1.20.0...v1.20.1</a></p>
]]></content:encoded></item><item><title>quantakrypto Quantum Readiness Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/quantakrypto-quantum-readiness-scan/</link><pubDate>Thu, 06 Aug 2026 06:33:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/quantakrypto-quantum-readiness-scan/</guid><description>Version updated for https://github.com/quantakrypto/pqc-tools to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is designed to automate the detection of quantum-vulnerable cryptography in codebases using the @quantakrypto/qscan tool. It runs qScan as part of a CI pipeline and can fail the build if new quantum vulnerabilities are found, providing SARIF output for analysis. The action supports multiple programming languages and includes features like triage with an AI coding agent and remediation support.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quantakrypto/pqc-tools">https://github.com/quantakrypto/pqc-tools</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quantakrypto-quantum-readiness-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is designed to automate the detection of quantum-vulnerable cryptography in codebases using the <code>@quantakrypto/qscan</code> tool. It runs qScan as part of a CI pipeline and can fail the build if new quantum vulnerabilities are found, providing SARIF output for analysis. The action supports multiple programming languages and includes features like triage with an AI coding agent and remediation support.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The <code>--mandate</code> compliance gate becomes CI-consumable, and an org cryptography policy can compose with it. SemVer: <strong>minor</strong> (additive features). Two exit-code behavior changes are called out below — read them before upgrading a <code>--mandate</code> pipeline.</p>
<h3 id="added">Added</h3>
<ul>
<li><strong>Machine-readable mandate verdicts</strong> — <code>--format json</code> gains a top-level <code>mandateMapping</code>; <code>--format sarif</code> carries the same under <code>run.properties.mandate</code>; <code>--format evidence</code> embeds a <strong>date-pinned, hashed</strong> <code>mandateMapping</code> in the ISO/IEC 27001 A.8.24 attestation. The GitHub Action threads the same verdicts into its uploaded SARIF.</li>
<li><strong><code>--policy</code> composes with <code>--mandate</code></strong> — families the org explicitly permits or is transitioning are annotated (<code>policyVerdict</code> / <code>acknowledged</code>) and exempt from the early gate (<code>--fail-now</code> / <code>--lead-months</code>); a <strong>passed disallow deadline still fails</strong>, and <code>prohibited</code> always wins over <code>permitted</code>. Exposed as a new <code>policy</code> input on the Action.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Exit-code loosening (opt-in):</strong> with <code>--policy</code> <strong>and</strong> <code>--mandate --fail-now</code>/<code>--lead-months</code>, a permitted/in-transition family no longer trips the early gate (it did in 0.8.0). Only affects runs passing both flags.</li>
<li><strong>Exit-code tightening:</strong> the CLI now evaluates the mandate gate on <strong>pre-baseline</strong> findings, matching the Action — a <code>--baseline</code> no longer waives a regulatory <strong>deadline</strong>.</li>
<li><strong><code>--mandate cnsa-2.0</code> disallow date moved 2035 → 2033</strong> — CNSA 2.0 now encodes its own exclusive-use timeline (deprecate 2030 / disallow 2033) from <code>PQC_STANDARDS.cnsaTimeline</code>; <code>nist-ir-8547</code> keeps 2035.</li>
<li><strong>Pre-1.0 shape change:</strong> <code>MandateEvaluation</code> / <code>MandateFindingVerdict</code> gained required fields; runtime behavior for existing <code>evaluateMandates</code> callers is identical.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Evidence hash reproducibility</strong> — <code>evaluateMandates</code> pins <code>now</code> to UTC midnight, so the attested hash is identical for any two same-day runs on a commit.</li>
</ul>
<p>Full notes in <a href="https://github.com/quantakrypto/pqc-tools/blob/main/CHANGELOG.md">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>Xcode Packages Update</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/xcode-packages-update/</link><pubDate>Thu, 06 Aug 2026 06:32:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/xcode-packages-update/</guid><description>Version updated for https://github.com/quver/xcode-packages-update to version v4.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action resolves Xcode Swift Package Manager dependencies and generates a detailed report of changes, including additions, removals, and version updates. It also produces an HTML dependency report, a CycloneDX SBOM, and automatically classifies packages as App or Development based on the presence of specific files in the project structure. The action can be used with both Xcode projects and workspaces and outputs a human-readable summary for PR descriptions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quver/xcode-packages-update">https://github.com/quver/xcode-packages-update</a></strong> to version <strong>v4.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xcode-packages-update">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action resolves Xcode Swift Package Manager dependencies and generates a detailed report of changes, including additions, removals, and version updates. It also produces an HTML dependency report, a CycloneDX SBOM, and automatically classifies packages as App or Development based on the presence of specific files in the project structure. The action can be used with both Xcode projects and workspaces and outputs a human-readable summary for PR descriptions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #78 from quver/release/v4.0.1 (9e0e694)</li>
<li>release: v4.0.1 (671b4de)</li>
<li>Merge pull request #75 from quver/dependabot/npm_and_yarn/dev-dependencies-6155092b98 (c294437)</li>
<li>build(deps-dev): bump the dev-dependencies group across 1 directory with 3 updates (1b36406)</li>
<li>Merge pull request #77 from quver/dependabot/npm_and_yarn/postcss-8.5.25 (7892ef0)</li>
<li>build(deps-dev): bump postcss from 8.5.22 to 8.5.25 (83e37e1)</li>
<li>Merge pull request #76 from quver/dependabot/npm_and_yarn/undici-6.28.0 (408b949)</li>
<li>build: update dist (e5aafd6)</li>
<li>build(deps): bump undici from 6.27.0 to 6.28.0 (440f113)</li>
<li>Merge pull request #74 from quver/release/v4.0.0 (bf75b9c)</li>
</ul>
]]></content:encoded></item><item><title>setup-renpy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/setup-renpy/</link><pubDate>Thu, 06 Aug 2026 06:30:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/setup-renpy/</guid><description>Version updated for https://github.com/remarkablegames/setup-renpy to version v2.2.2.
This action is used across all versions by 19 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup and management of Ren’Py CLI on GitHub Actions workflows. It simplifies the process of using Ren’Py for game development by providing a straightforward way to install, configure, and execute Ren’Py commands directly from your workflow files. The action supports various features such as setting up different launchers and configuring support for Android, iOS, and web platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablegames/setup-renpy">https://github.com/remarkablegames/setup-renpy</a></strong> to version <strong>v2.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>19</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-renpy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup and management of Ren&rsquo;Py CLI on GitHub Actions workflows. It simplifies the process of using Ren&rsquo;Py for game development by providing a straightforward way to install, configure, and execute Ren&rsquo;Py commands directly from your workflow files. The action supports various features such as setting up different launchers and configuring support for Android, iOS, and web platforms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="222-2026-08-06"><a href="https://github.com/remarkablegames/setup-renpy/compare/v2.2.1...v2.2.2">2.2.2</a> (2026-08-06)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump undici from 6.27.0 to 6.28.0 (<a href="https://github.com/remarkablegames/setup-renpy/issues/672">#672</a>) (<a href="https://github.com/remarkablegames/setup-renpy/commit/d15a8a57419682616f4fdd555a895ee4ba7ce296">d15a8a5</a>)</li>
</ul>
]]></content:encoded></item><item><title>wavedash-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/wavedash-action/</link><pubDate>Thu, 06 Aug 2026 06:29:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/wavedash-action/</guid><description>Version updated for https://github.com/remarkablegames/wavedash-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading and publishing web games to Wavedash. It can handle both manual configuration files (wavedash.toml) and auto-creation based on entrypoint HTML. The action supports various inputs such as API token, game ID, upload directory, entrypoint file, SDK version, and release details for publishing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablegames/wavedash-action">https://github.com/remarkablegames/wavedash-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wavedash-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading and publishing web games to Wavedash. It can handle both manual configuration files (<code>wavedash.toml</code>) and auto-creation based on entrypoint HTML. The action supports various inputs such as API token, game ID, upload directory, entrypoint file, SDK version, and release details for publishing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="101-2026-08-05"><a href="https://github.com/remarkablegames/wavedash-action/compare/v1.0.0...v1.0.1">1.0.1</a> (2026-08-05)</h2>
<h3 id="performance-improvements">Performance Improvements</h3>
<ul>
<li><strong>sdk:</strong> add modulepreload link before <code>&lt;/head&gt;</code> for early SDK fetch (<a href="https://github.com/remarkablegames/wavedash-action/issues/4">#4</a>) (<a href="https://github.com/remarkablegames/wavedash-action/commit/7d5446139a8b9e0d1f6d58740f90db6c3fef779c">7d54461</a>)</li>
</ul>
]]></content:encoded></item><item><title>setup-maestro-cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/setup-maestro-cli/</link><pubDate>Thu, 06 Aug 2026 06:28:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/setup-maestro-cli/</guid><description>Version updated for https://github.com/remarkablemark/setup-maestro-cli to version v1.0.20.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-maestro-cli GitHub Action automates the setup and configuration of Maestro CLI in a GitHub Actions workflow. It simplifies the process of integrating Maestro into projects by providing a straightforward way to install and use it, which can be useful for CI/CD pipelines that require automated testing or deployment tasks related to mobile development.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablemark/setup-maestro-cli">https://github.com/remarkablemark/setup-maestro-cli</a></strong> to version <strong>v1.0.20</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-maestro-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>setup-maestro-cli</code> GitHub Action automates the setup and configuration of Maestro CLI in a GitHub Actions workflow. It simplifies the process of integrating Maestro into projects by providing a straightforward way to install and use it, which can be useful for CI/CD pipelines that require automated testing or deployment tasks related to mobile development.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1020-2026-08-05"><a href="https://github.com/remarkablemark/setup-maestro-cli/compare/v1.0.19...v1.0.20">1.0.20</a> (2026-08-05)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump undici from 6.27.0 to 6.28.0 (<a href="https://github.com/remarkablemark/setup-maestro-cli/issues/274">#274</a>) (<a href="https://github.com/remarkablemark/setup-maestro-cli/commit/39f09931b4b8d9ace83f97861b89177a4e7cdc6d">39f0993</a>)</li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/kaniko-build-action/</link><pubDate>Thu, 06 Aug 2026 06:27:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting to a specified person, and also provides the current time. It automates the process of adding greetings to logs, enhancing logging functionality for projects that require personalized messages or timestamps in their outputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting to a specified person, and also provides the current time. It automates the process of adding greetings to logs, enhancing logging functionality for projects that require personalized messages or timestamps in their outputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/rumdl-action/</link><pubDate>Thu, 06 Aug 2026 06:27:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.52.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rumdl is a fast and efficient Markdown linter and formatter written in Rust, offering over 80 lint rules to ensure consistency and best practices in Markdown files. It provides automatic formatting with the --fix option and supports multiple Markdown flavors, including GFM, MkDocs, MDX, Quarto, and MyST.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.52</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>rumdl is a fast and efficient Markdown linter and formatter written in Rust, offering over 80 lint rules to ensure consistency and best practices in Markdown files. It provides automatic formatting with the <code>--fix</code> option and supports multiple Markdown flavors, including GFM, MkDocs, MDX, Quarto, and MyST.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>md012</strong>: report blank lines before a code block that ends the document (#791) (<a href="https://github.com/rvben/rumdl/commit/e897556460ba0209ad9e768ae64ec5579e1715bc">e897556</a>)</li>
<li><strong>rules</strong>: treat a template shortcode tag as opaque markup (<a href="https://github.com/rvben/rumdl/commit/696218496edc7c1aa9403a970311fb19085930f9">6962184</a>)</li>
<li><strong>cli</strong>: report a piped document&rsquo;s findings on stdout like every other run (<a href="https://github.com/rvben/rumdl/commit/47f8a50d7cf8cf98754a13cfe2adb12868d05a89">47f8a50</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.52-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.52-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.52-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.52-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-apple-darwin.tar.gz">rumdl-v0.2.52-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-apple-darwin.tar.gz">rumdl-v0.2.52-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-pc-windows-msvc.zip">rumdl-v0.2.52-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Build docs with mmdoc</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/build-docs-with-mmdoc/</link><pubDate>Thu, 06 Aug 2026 06:26:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/build-docs-with-mmdoc/</guid><description>Version updated for https://github.com/ryantm/mmdoc-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The mmdoc Action automates the generation of single-page and multi-page HTML documentation using [mmdoc], a tool for generating static documentation from Markdown files. It helps developers deploy their documentation to GitHub Pages, providing both single-page and multi-page outputs. The action also allows users to configure every option through inputs, pinning mmdoc to a specific version, and supports runner support on GitHub-hosted Linux and macOS runners.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ryantm/mmdoc-action">https://github.com/ryantm/mmdoc-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-docs-with-mmdoc">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The mmdoc Action automates the generation of single-page and multi-page HTML documentation using [mmdoc], a tool for generating static documentation from Markdown files. It helps developers deploy their documentation to GitHub Pages, providing both single-page and multi-page outputs. The action also allows users to configure every option through inputs, pinning mmdoc to a specific version, and supports runner support on GitHub-hosted Linux and macOS runners.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ryantm/mmdoc-action/commits/v1.0.0">https://github.com/ryantm/mmdoc-action/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>sarif-kit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/sarif-kit/</link><pubDate>Thu, 06 Aug 2026 06:25:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/sarif-kit/</guid><description>Version updated for https://github.com/sarif-kit/sarif-kit to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action converts the native output of popular security scanners into valid SARIF 2.1.0 format, which can then be uploaded to GitHub Code Scanning for automated analysis. It automates the conversion process, addressing issues where tools like pip-audit, codespell, and yamllint do not natively emit SARIF. The action is available in both GitHub Actions workflows and on your machine, supporting various tools such as pip-audit, yamllint, and codespell.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sarif-kit/sarif-kit">https://github.com/sarif-kit/sarif-kit</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sarif-kit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action converts the native output of popular security scanners into valid SARIF 2.1.0 format, which can then be uploaded to GitHub Code Scanning for automated analysis. It automates the conversion process, addressing issues where tools like pip-audit, codespell, and yamllint do not natively emit SARIF. The action is available in both GitHub Actions workflows and on your machine, supporting various tools such as pip-audit, yamllint, and codespell.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v011-2026-08-05">v0.1.1 (2026-08-05)</h2>
<p><em>This release is published under the Apache-2.0 License.</em></p>
<h3 id="continuous-integration">Continuous Integration</h3>
<ul>
<li>Cut releases with semantic-release (<a href="https://github.com/sarif-kit/sarif-kit/commit/2a79749376b9aebc1bc3e3467d1816847b94d498"><code>2a79749</code></a>)</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>
<p>Action snippets in the adapter pages (<a href="https://github.com/sarif-kit/sarif-kit/commit/7b4231521985ead2f117ba403b5f127d2a7cb869"><code>7b42315</code></a>)</p>
</li>
<li>
<p>Lead the readme with the action (<a href="https://github.com/sarif-kit/sarif-kit/commit/d9b9b4940bef15ecb78ed77e674248d6ccb0073c"><code>d9b9b49</code></a>)</p>
</li>
<li>
<p>Point installs at pypi (<a href="https://github.com/sarif-kit/sarif-kit/commit/d3b973ff90ad28871fccf1207c2ad46761d04fe8"><code>d3b973f</code></a>)</p>
</li>
<li>
<p>Tighten the category note (<a href="https://github.com/sarif-kit/sarif-kit/commit/4357770a32ad1e8b80ef506050e9172420e11ea7"><code>4357770</code></a>)</p>
</li>
</ul>
<hr>
<p><strong>Detailed Changes</strong>: <a href="https://github.com/sarif-kit/sarif-kit/compare/v0.1.0...v0.1.1">v0.1.0&hellip;v0.1.1</a></p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/agentauditkit-mcp-security-scan/</link><pubDate>Thu, 06 Aug 2026 06:24:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.68.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner designed to audit AI agent pipelines for potential misconfigurations, hardcoded secrets, tool poisoning, and other vulnerabilities. It is the missing npm audit solution specifically tailored for AI agents, running offline and deterministically without relying on an LLM. The action produces auditor-ready compliance-evidence packs including SARIF reports and PDF evidence reports mapped to 12 security frameworks, ensuring precision and reliability in security audits.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.68</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>AgentAuditKit</strong> is a security scanner designed to audit AI agent pipelines for potential misconfigurations, hardcoded secrets, tool poisoning, and other vulnerabilities. It is the missing <code>npm audit</code> solution specifically tailored for AI agents, running offline and deterministically without relying on an LLM. The action produces auditor-ready compliance-evidence packs including SARIF reports and PDF evidence reports mapped to 12 security frameworks, ensuring precision and reliability in security audits.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.68
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.68
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.68</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fail the release loudly on a stale repo description, adjudicate the CVE queue by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/532">https://github.com/sattyamjjain/agent-audit-kit/pull/532</a></li>
<li>fix: render repo description from RULE_COUNT, dispose of the open CVE queue by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/536">https://github.com/sattyamjjain/agent-audit-kit/pull/536</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.67...v0.3.68">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.67...v0.3.68</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/custom-amazon-bedrock-agent-action/</link><pubDate>Thu, 06 Aug 2026 06:22:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provides feedback by generating tailored prompts based on user-defined configurations. The action supports customizable agent analysis, memory support, flexible use cases, file ignoring, AI-powered insights, language-agnostic analysis, and seamless integration with AWS services like Amazon Bedrock Knowledge Bases. It enhances the PR process with tailored, context-aware insights and integrates smoothly into existing workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provides feedback by generating tailored prompts based on user-defined configurations. The action supports customizable agent analysis, memory support, flexible use cases, file ignoring, AI-powered insights, language-agnostic analysis, and seamless integration with AWS services like Amazon Bedrock Knowledge Bases. It enhances the PR process with tailored, context-aware insights and integrates smoothly into existing workflows.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-json" data-lang="json"><span style="display:flex;"><span>{
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">&#34;name&#34;</span>: <span style="color:#e6db74">&#34;Custom Amazon Bedrock Agent Action&#34;</span>,
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">&#34;description&#34;</span>: <span style="color:#e6db74">&#34;Automates file analysis in a pull request using Amazon Bedrock Agent.&#34;</span>,
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">&#34;keyCapabilities&#34;</span>: [<span style="color:#e6db74">&#34;Customizable Analysis&#34;</span>, <span style="color:#e6db74">&#34;Memory Support&#34;</span>, <span style="color:#e6db74">&#34;Flexible Use Cases&#34;</span>, <span style="color:#e6db74">&#34;File Ignoring&#34;</span>, <span style="color:#e6db74">&#34;AI-Powered Insights&#34;</span>],
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">&#34;integratedServices&#34;</span>: [<span style="color:#e6db74">&#34;Amazon Bedrock Knowledge Bases&#34;</span>]
</span></span><span style="display:flex;"><span>}
</span></span></code></pre></div><h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Setup UniGo</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/setup-unigo/</link><pubDate>Thu, 06 Aug 2026 06:21:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/setup-unigo/</guid><description>Version updated for https://github.com/snowdreamtech/setup-unigo to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action setup-unigo automates the installation and configuration of UniGo, a runtime and tools manager. It supports various install methods including npm, pip (coming soon), GitHub Release, and go install. The action also offers smart auto-detection, caching with customizable cache key templates, and support for GitHub proxies in restricted networks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snowdreamtech/setup-unigo">https://github.com/snowdreamtech/setup-unigo</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-unigo">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>setup-unigo</code> automates the installation and configuration of UniGo, a runtime and tools manager. It supports various install methods including npm, pip (coming soon), GitHub Release, and go install. The action also offers smart auto-detection, caching with customizable cache key templates, and support for GitHub proxies in restricted networks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="020-2026-08-05"><a href="https://github.com/snowdreamtech/setup-unigo/compare/v0.1.0...v0.2.0">0.2.0</a> (2026-08-05)</h2>
<h3 id="features">Features</h3>
<ul>
<li>inject shims into GITHUB_PATH dynamically (<a href="https://github.com/snowdreamtech/setup-unigo/commit/57691664e131b1c709b6e083835de8d0d827e742">5769166</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>remove fallback restore-keys for cache restoration (<a href="https://github.com/snowdreamtech/setup-unigo/commit/52e61bf43e63b2e5f390c05bbf20e19f5221aded">52e61bf</a>)</li>
</ul>
]]></content:encoded></item><item><title>Setup UniStack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/setup-unistack/</link><pubDate>Thu, 06 Aug 2026 06:20:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/setup-unistack/</guid><description>Version updated for https://github.com/snowdreamtech/setup-unistack to version v0.2.0.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation and configuration of UniStack, a runtime and tool manager. It supports multiple install methods such as npm, pip (coming soon), GitHub Release, and Go installation. The action can also handle GitHub Proxy support for restricted networks and provides caching with customizable cache key templates.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snowdreamtech/setup-unistack">https://github.com/snowdreamtech/setup-unistack</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-unistack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the installation and configuration of UniStack, a runtime and tool manager. It supports multiple install methods such as npm, pip (coming soon), GitHub Release, and Go installation. The action can also handle GitHub Proxy support for restricted networks and provides caching with customizable cache key templates.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="020-2026-08-05"><a href="https://github.com/snowdreamtech/setup-unistack/compare/v0.1.0...v0.2.0">0.2.0</a> (2026-08-05)</h2>
<h3 id="features">Features</h3>
<ul>
<li>inject shims into GITHUB_PATH dynamically (<a href="https://github.com/snowdreamtech/setup-unistack/commit/78a7860e0d1f7496972669217f23313bea4d281f">78a7860</a>)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Thu, 06 Aug 2026 06:19:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The deploy-swarm-service GitHub Action automates the process of deploying a Docker service to a Swarm cluster. It ensures that all necessary dependencies are installed and the application is properly bundled before deployment, addressing common issues related to environment setup and bundling processes for production environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>deploy-swarm-service</code> GitHub Action automates the process of deploying a Docker service to a Swarm cluster. It ensures that all necessary dependencies are installed and the application is properly bundled before deployment, addressing common issues related to environment setup and bundling processes for production environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>Sprocket CI/CD</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/sprocket-ci/cd/</link><pubDate>Thu, 06 Aug 2026 06:19:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/sprocket-ci/cd/</guid><description>Version updated for https://github.com/stjude-rust-labs/sprocket-action to version v0.28.1.
This action is used across all versions by 8 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub action provides a set of WDL-related tools from the Sprocket command line tool, including check, lint, validate, and format functionalities, which can automate static analysis, validation, and formatting tasks in CI/CD pipelines. The action supports various inputs such as linting options, exceptions, ignore patterns, and more, allowing for customization based on project requirements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stjude-rust-labs/sprocket-action">https://github.com/stjude-rust-labs/sprocket-action</a></strong> to version <strong>v0.28.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sprocket-ci-cd">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub action provides a set of WDL-related tools from the Sprocket command line tool, including check, lint, validate, and format functionalities, which can automate static analysis, validation, and formatting tasks in CI/CD pipelines. The action supports various inputs such as linting options, exceptions, ignore patterns, and more, allowing for customization based on project requirements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Bumps <code>sprocket</code> to <a href="https://github.com/stjude-rust-labs/sprocket/releases/tag/v0.28.1">v0.28.1</a>.</p>
]]></content:encoded></item><item><title>Setup Task (go-task/task)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/setup-task-go-task/task/</link><pubDate>Thu, 06 Aug 2026 06:18:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/setup-task-go-task/task/</guid><description>Version updated for https://github.com/tenthirtyam/setup-task to version v1.0.8.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up the Task task runner in a GitHub Actions workflow. It supports specifying the Task version, custom variables, and enabling verbose logging. The action can be used to automate Task setup in workflows, providing flexibility and ease of use.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tenthirtyam/setup-task">https://github.com/tenthirtyam/setup-task</a></strong> to version <strong>v1.0.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-task-go-task-task">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up the Task task runner in a GitHub Actions workflow. It supports specifying the Task version, custom variables, and enabling verbose logging. The action can be used to automate Task setup in workflows, providing flexibility and ease of use.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">tenthirtyam/setup-task@v1.0.8</span>
</span></span></code></pre></div><p>Refer to the <a href="https://github.com/tenthirtyam/setup-task/blob/main/README.md"><code>README.md</code></a> for detailed usage information.</p>
]]></content:encoded></item><item><title>Run Godlint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/run-godlint/</link><pubDate>Thu, 06 Aug 2026 06:17:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/run-godlint/</guid><description>Version updated for https://github.com/tomerwave/godlint to version v0.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the enforcement of coding standards and best practices using the Godlint tool. It helps prevent architectural drift, ensures consistency across languages, and enforces deterministic policies by running checks locally and in CI. The action supports various programming languages like Rust, TypeScript, JavaScript, and Python, providing a unified set of rules for architecture, security boundaries, and engineering standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tomerwave/godlint">https://github.com/tomerwave/godlint</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-godlint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the enforcement of coding standards and best practices using the Godlint tool. It helps prevent architectural drift, ensures consistency across languages, and enforces deterministic policies by running checks locally and in CI. The action supports various programming languages like Rust, TypeScript, JavaScript, and Python, providing a unified set of rules for architecture, security boundaries, and engineering standards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><code>git/branch-naming</code> checks pull-request branches through <code>GITHUB_HEAD_REF</code> and local checked-out
branches through Git. It replaces Godlint&rsquo;s bespoke branch-name script and separate pull-request job,
runs in <code>recommended@1</code>, and allows repositories to replace the accepted types or admit automation
branch patterns.</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/wails3-build-action/</link><pubDate>Thu, 06 Aug 2026 06:16:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building of Wails.io projects using GoLang and NodeJS. It supports various build configurations, including obfuscation, caching, and uploading artifacts to GitHub or releases on tagged builds. The action is particularly useful for developers who need to automate the build process for their Wails applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building of Wails.io projects using GoLang and NodeJS. It supports various build configurations, including obfuscation, caching, and uploading artifacts to GitHub or releases on tagged builds. The action is particularly useful for developers who need to automate the build process for their Wails applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>aicheck-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/aicheck-scan/</link><pubDate>Thu, 06 Aug 2026 06:15:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/aicheck-scan/</guid><description>Version updated for https://github.com/unauthdev/aicheck-scan to version v1.2.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aicheck-scan GitHub Action automates the detection of unauthenticated AI services in your environment. It provides a continuous inventory and performs live probes to identify exposed AI services in CI builds or across an estate. The action supports multiple deployment methods, including pip CLI, GitHub Actions, Docker containers, and a web-based scanner.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/unauthdev/aicheck-scan">https://github.com/unauthdev/aicheck-scan</a></strong> to version <strong>v1.2.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aicheck-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>aicheck-scan</code> GitHub Action automates the detection of unauthenticated AI services in your environment. It provides a continuous inventory and performs live probes to identify exposed AI services in CI builds or across an estate. The action supports multiple deployment methods, including pip CLI, GitHub Actions, Docker containers, and a web-based scanner.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Two ways to find shadow AI, one engine:</p>
<p><strong>Passive</strong>: <code>aicheck inventory --flow-logs vpc.log.gz</code> — turn AWS VPC Flow Logs (text/gz) or JSONL into an AI-service inventory offline. Port attribution with data-plane/management roles, flow-shape corroboration vs scanner noise, &lsquo;already internet-scanned&rsquo; flags from Censys/Shodan ranges, zero packets sent. <code>--verify</code> upgrades flow-attributed rows with a Class A sweep.</p>
<p><strong>Class B pack #1</strong>: <code>--deep --deep-packs data-plane --i-own-these-targets</code> — zero-byte TCP connect to Milvus :19530 / Qdrant :6334 / Weaviate :50051. Finding only on conjunction (Class A fingerprint AND data-plane accept); honest evidence: reachable, not data-accessible.</p>
<p>Also: drift-honest inventory, auth-state observations (1.2.4), Milvus + Attu checker, structured CVEs, schema_version 1, HMAC webhooks. SHA256 sums are appended below by the publish workflow.</p>
<h2 id="sha256">SHA256</h2>
<pre tabindex="0"><code>7975a758ed0612745ad8d70383aa05319c57d60805a4eccbe35c132132d039d1  aicheck_scan-1.2.5-py3-none-any.whl
cfc50f337524b402720d68b272f6f9f32eb436b51cead3c13e5c7c7a670bd5b6  aicheck_scan-1.2.5.tar.gz
</code></pre>]]></content:encoded></item><item><title>Flutter Fast Build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/flutter-fast-build/</link><pubDate>Thu, 06 Aug 2026 06:14:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/flutter-fast-build/</guid><description>Version updated for https://github.com/verf1CT/flutter-fast-build-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Flutter Fast Build Action is designed for automating Flutter app builds, testing, and deployments. It provides intelligent caching, supports monorepo discovery, offers direct Firebase/App Store Connect deployment hooks, and automatically uploads artifacts as GitHub workflow outputs. The action simplifies CI/CD processes by reducing build times through caching and enabling parallel job execution for monorepos.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/verf1CT/flutter-fast-build-action">https://github.com/verf1CT/flutter-fast-build-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/flutter-fast-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Flutter Fast Build Action is designed for automating Flutter app builds, testing, and deployments. It provides intelligent caching, supports monorepo discovery, offers direct Firebase/App Store Connect deployment hooks, and automatically uploads artifacts as GitHub workflow outputs. The action simplifies CI/CD processes by reducing build times through caching and enabling parallel job execution for monorepos.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>docs: overhaul README for Marketplace</p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/vibgrate-scan/</link><pubDate>Thu, 06 Aug 2026 06:13:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.805.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action provides a tool to analyze the technical and versioning aspects of a local codebase. It generates a deterministic code graph and drift score, which indicates how far behind the codebase is with respect to runtime/framework updates and dependency age, helping developers prioritize upgrades and maintainability. The tool runs locally on the user’s machine without relying on APIs or network calls, ensuring all data stays within the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.805.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action provides a tool to analyze the technical and versioning aspects of a local codebase. It generates a deterministic code graph and drift score, which indicates how far behind the codebase is with respect to runtime/framework updates and dependency age, helping developers prioritize upgrades and maintainability. The tool runs locally on the user&rsquo;s machine without relying on APIs or network calls, ensuring all data stays within the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268052">Vibgrate CLI 2026.805.2</h1>
<p><em>Released 2026-08-05</em></p>
<p>Routine maintenance update for the CLI.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Maintenance release with internal improvements and dependency updates.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.805.1, interleaved on one runner against the pinned corpus (189 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21503 count</td>
          <td>21503 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>10698 count</td>
          <td>10698 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.94 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>641.20 ms</td>
          <td>642.10 ms</td>
      </tr>
  </tbody>
</table>
<p>2 regression(s) — published, not omitted:</p>
<ul>
<li>Tasks passed on both arms: 33 → 31 (-6.1%)</li>
<li>Comparable-task rate (both arms passed / total): 0.94 → 0.89 (-6.1%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.805.2">https://vibgrate.com/changelog/cli/2026.805.2</a></p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/rustscript-action/</link><pubDate>Thu, 06 Aug 2026 06:12:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.2.24.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that interprets Rust scripts without needing to compile them fully. It can run scripts directly or as compiled binaries, providing quick feedback and testing without waiting for the entire compilation process. The action automates tasks such as running scripts, validating them, building them, and listing supported methods per receiver and engine.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.2.24</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a tool that interprets Rust scripts without needing to compile them fully. It can run scripts directly or as compiled binaries, providing quick feedback and testing without waiting for the entire compilation process. The action automates tasks such as running scripts, validating them, building them, and listing supported methods per receiver and engine.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.24">https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.24</a></p>
]]></content:encoded></item><item><title>Setup HarmonyOS tools</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/setup-harmonyos-tools/</link><pubDate>Thu, 06 Aug 2026 06:11:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/setup-harmonyos-tools/</guid><description>Version updated for https://github.com/wm-develop/setup-ohos to version v3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, setup-ohos, automates the setup of the HarmonyOS NEXT (API12+) building environment in a GitHub Actions workflow. It downloads and installs the latest CLI tools and SDK versions, ensuring that developers can easily build and test their applications on the platform. The action supports macOS and Windows with specific installation instructions for libGL1 on Linux. Users can configure the version of the CLI tools to be used, cache the SDK, and access environment variables related to the SDK’s home directories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wm-develop/setup-ohos">https://github.com/wm-develop/setup-ohos</a></strong> to version <strong>v3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-harmonyos-tools">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>setup-ohos</code>, automates the setup of the HarmonyOS NEXT (API12+) building environment in a GitHub Actions workflow. It downloads and installs the latest CLI tools and SDK versions, ensuring that developers can easily build and test their applications on the platform. The action supports macOS and Windows with specific installation instructions for <code>libGL1</code> on Linux. Users can configure the version of the CLI tools to be used, cache the SDK, and access environment variables related to the SDK&rsquo;s home directories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>update setup.sh (695a5d3)</li>
<li>chore (1f4ec7a)</li>
<li>test use cache (4dbb630)</li>
<li>fix windows path (8136e0f)</li>
<li>fix: use bash on windows (e43beb7)</li>
<li>fix filename (5124d8c)</li>
<li>fix gh token (f16c2ca)</li>
<li>feat: support more runner arch (89c72db)</li>
<li>Update version information formatting in README (ed8745d)</li>
<li>Update version numbers in README.md (71e2c59)</li>
</ul>
]]></content:encoded></item><item><title>Legion Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/legion-runner/</link><pubDate>Thu, 06 Aug 2026 06:10:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/legion-runner/</guid><description>Version updated for https://github.com/Wraith-security/Legion_runner to version v1.0.58.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Legion Runner is an open-source action designed to protect CI/CD pipelines from supply chain attacks by monitoring and blocking outbound connections from GitHub Actions jobs. It records every outbound connection, names the process behind it, and blocks any unauthorized destinations, ensuring that only allowed services can be accessed. The Action has no dependencies and runs on pure Node built-ins with optional eBPF capture and file-integrity helpers for enhanced security features.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Wraith-security/Legion_runner">https://github.com/Wraith-security/Legion_runner</a></strong> to version <strong>v1.0.58</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/legion-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Legion Runner is an open-source action designed to protect CI/CD pipelines from supply chain attacks by monitoring and blocking outbound connections from GitHub Actions jobs. It records every outbound connection, names the process behind it, and blocks any unauthorized destinations, ensuring that only allowed services can be accessed. The Action has no dependencies and runs on pure Node built-ins with optional eBPF capture and file-integrity helpers for enhanced security features.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Curated egress presets (<code>allowed-presets</code>)</strong>: opt-in per-ecosystem allowlists
(npm, yarn, pnpm, pip, pypi, cargo, rust, go, maven, gradle, nuget, apt, debian,
docker) so block mode &ldquo;just works&rdquo; for common toolchains without hand-listing
endpoints. e.g. <code>allowed-presets: &quot;cargo, apt&quot;</code>. Unit-tested.</li>
<li><strong>Download integrity verification</strong>: the action verifies the <code>legionr-bpf</code> /
<code>legionr-fim</code> release binaries against a <code>.sha256</code> sidecar before running them
(the release now attaches the checksums), and <strong>fails closed</strong> — an
unverified/corrupted/tampered download is rejected and the action degrades
instead of executing it.</li>
<li><strong><code>learned-baseline</code> input</strong> (default <code>true</code>): in block mode, also allow
destinations previously learned into the Actions cache. Set <code>false</code> to enforce
ONLY the explicit allowlist (inline + policy-file + GitHub) with no cache
read/write — used by the enforce self-test for deterministic deny.</li>
<li><strong>File-integrity / tamper detection (Rust <code>legionr-fim</code> agent)</strong>: snapshots
high-value tamper targets at job start (credential/config files, <code>.git</code>
config + hooks, and checked-out source) and diffs them at job end, surfacing
anything overwritten, deleted, or chmod&rsquo;d in the summary. Only sha256 hashes
are stored — never contents. New inputs <code>file-integrity</code> (auto|off) and
<code>fim-extra-paths</code>. <code>file-integrity: auto</code> downloads the agent from the latest
release (plain stable Rust, no eBPF toolchain) and degrades to a silent skip
if unavailable. Logic lives in <code>legionr-core::fim</code> (unit-tested); the binary
is a release asset like <code>legionr-bpf</code>, built + attached by <code>release.yml</code>.</li>
<li><strong>Package repositories roll-up (<code>📦</code>)</strong>: the summary now classifies named
outbound destinations into their ecosystem/registry (npm, PyPI, crates.io,
apt, Docker, Go, NuGet, Maven, Gradle, RubyGems, Alpine, GitHub) and shows a
<strong>Package repositories reached</strong> table — registry, ecosystem, connections, and
the process that reached each. Supply-chain risk hides in <em>which</em> registries a
build talks to, so we surface them directly instead of leaving you to read
IPs. Bare IPs that never got a forward name get a coarse CDN/provider hint
(Fastly/Cloudflare/GitHub) via CIDR match — honest about ambiguity (a shared
CDN can&rsquo;t name a registry). Logic in <code>action/repos.js</code>, fully unit-tested.</li>
<li><strong>Combined cross-job egress report (one summary for the whole run)</strong>: GitHub
has no run-level summary, so each job emits its captured egress as a JSON
artifact (<code>node action/report.js emit</code>) and a final <code>egress-report</code> job merges
them into a SINGLE table — which job + process reached what — with a package
repositories roll-up and a per-job diagnostics block (<code>render</code>). Wired into CI;
<code>render</code> is pure and unit-tested. Pairs with <code>job-summary: false</code> so the run
shows one combined summary instead of one table per job.</li>
<li><strong><code>job-summary</code> input</strong> (default <code>true</code>): set <code>false</code> to keep monitoring and
enforcement fully active but suppress the connections table in the job summary.
Useful when many jobs in one workflow each run the action and you only want the
table once (our own CI uses it so a run shows one table, not one per job).</li>
<li><strong>Secure diagnostics line</strong> in the summary: reports which resolution path
actually fired (<code>forwarder on/off · captured DNS records N · getaddrinfo route … · named X/Y destinations</code>) so a run that comes back as bare IPs is triagable.
Secure by construction — only booleans, counts, and a fixed enum; never the
upstream resolver IP, file paths, captured hostnames, or env values.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>The live e2e tier is out of CI.</strong> <code>.github/workflows/e2e.yml</code> now runs only
the credential-free <code>local</code> job. The removed <code>live</code> job registered a runner
against a fixed external scope that this org cannot install the App on, so it
could only skip silently or fail noisily, and neither outcome said anything
about the runner. <code>scripts/e2e.sh --mode live</code> still works and can be pointed
at any scope you control, but the scope is now mandatory (<code>--scope owner/repo</code>
or <code>E2E_SCOPE</code>) instead of defaulting to a hardcoded constant: the harness
will not guess a target it registers a real runner against. The <code>local</code> tier
falls back to <code>$GITHUB_REPOSITORY</code> since it provisions with <code>--no-probe</code> and
never reaches GitHub.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>FIM hashing builds against <code>sha2</code> 0.11.</strong> The digest type changed to
<code>hybrid_array::Array</code>, which does not implement <code>LowerHex</code>, so
<code>format!(&quot;{:x}&quot;, ..)</code> in <code>fim::hash_file</code> stopped compiling. The digest is now
hex-encoded byte by byte, which works on both 0.10 and 0.11. Two tests pin the
behaviour: the exact sha256 of <code>abc</code>, and a 64-char length/charset assertion so
a dropped leading zero cannot pass silently. Unblocks the <code>cargo-major</code>
dependency group (<code>sha2</code> 0.10.9 to 0.11.0, <code>thiserror</code> 1 to 2.0.18).</li>
<li><strong>Block mode no longer hangs the runner at teardown.</strong> <code>applyEgressBlock</code>
installed a default-deny <code>LEGION_EGRESS</code> chain in <code>OUTPUT</code> and nothing ever
removed it, so the runner&rsquo;s own completion call (to rotating GitHub-backend IPs
not in the static seed) was dropped and the job spun until timeout. <code>post()</code>
now tears the firewall down (<code>removeEgressBlock</code>).</li>
<li><strong>Runner hang from leaked daemons.</strong> The post step left privileged background
processes alive — eBPF agent, DNS forwarder — and the <code>/proc</code> monitor could
wedge in a blocking <code>ss</code> subprocess. The monitor now reads <code>/proc/net/tcp</code>
directly (no subprocess); daemons are reliably reaped.</li>
<li><strong>No more spurious &ldquo;could not resolve&rdquo; annotations.</strong> Allowlist entries that
are wildcard parents with no A record of their own (e.g. <code>blob.core.windows.net</code>,
<code>actions.githubusercontent.com</code>) used to emit one CI <strong>warning annotation</strong>
each on every run. They are benign: the action skips them, and their subdomains
are still observed via PTR / DNS capture (and opened just-in-time in block
mode). They are now collected into a single plain-text log line instead.</li>
<li><strong>Docs/labels</strong>: the eBPF mechanism is a <strong>tracepoint on <code>sys_enter_connect</code></strong>
(not a &ldquo;kprobe on tcp_connect&rdquo;); the sampler is <code>/proc</code>-only (the &ldquo;ss&rdquo; fallback
was removed). Corrected the runtime log line, summary label, and README.</li>
<li><strong>Outbound connections showed as bare IPs when systemd-resolved owns
<code>getaddrinfo</code>.</strong> The <code>nsswitch</code> reroute didn&rsquo;t always stick, so package-repo
lookups bypassed the capture forwarder and were never named. The forwarder now
targets the <em>real</em> upstream (systemd-resolved&rsquo;s actual servers, not the
<code>127.0.0.53</code> stub), and when the bypass is detected but the nsswitch reroute
fails, Legion redirects systemd-resolved itself at the forwarder via a
<code>resolved.conf.d</code> drop-in — <strong>verify-or-revert</strong> and restored on teardown, so
it never breaks the job&rsquo;s DNS.</li>
<li><strong>IPv4-mapped IPv6 destinations rendered as long expanded addresses</strong>
(<code>0000:0000:0000:0000:0000:ffff:HHHH:HHHH</code>) in the summary. The <code>/proc</code> sampler
emitted the expanded form while <code>normalizeIp</code> only collapsed the compressed
<code>::ffff:</code> form. Both now collapse to dotted IPv4 (and the v4/v6 tables dedupe).
(Shipped in v1.0.35.)</li>
<li>Removed dead <code>action/baseline.js</code>; pinned <code>release.yml</code> checkout to v6.</li>
</ul>
<h3 id="reliability">Reliability</h3>
<ul>
<li><strong>Tests for the paths that kept breaking</strong>: the firewall rule builders
(<code>egressBlockRules</code>/<code>egressUnblockRules</code> — order, DNS-allow, DROP-last,
OUTPUT-jump-removed-first), the checksum parser, the curated presets, and a
<strong>full-stack PR gate</strong> that runs block + DNS-capture + eBPF and asserts the
job finalizes (catches any teardown-hang regression), plus the package-repo
classifier (host-suffix + CIDR matching). Action test count 19 → 37.</li>
</ul>
<h3 id="changed-1">Changed</h3>
<ul>
<li>Removed em-dashes from the job-summary output (headers, the unresolved-host
note, the enforce hint, and empty-cell placeholders) for plainer rendering.</li>
<li><strong>Name more destinations</strong>: route glibc <code>getaddrinfo</code> (curl/apt/cargo/git)
through the DNS-capture forwarder via an <code>nsswitch.conf</code> reroute, so hosts
resolved by systemd-resolved (which ignores <code>resolv.conf</code>) are now captured
and named — not just <code>resolv.conf</code>/c-ares callers. Health-checked and restored
on teardown. (A connection to a hard-coded IP with no PTR still shows the IP —
there is no name to resolve.)</li>
<li>More accurate &ldquo;unresolved destination&rdquo; note in the summary (a name may have
been resolved outside the capture path, vs. a genuine raw-IP connection).</li>
<li><strong>We dogfood our own action.</strong> Every real-work job in this repo (CI, release,
eBPF agent, FIM self-test) now runs Legion Runner as its first step (<code>@v1</code>,
audit) — our CI is hardened by the product it ships.</li>
<li><strong>Docs-only PRs skip the build/test matrix</strong> (and the release it gates) via
<code>paths-ignore</code>; a <code>docs-passthrough</code> workflow reports the same check names
green so required checks stay satisfied and README edits stay mergeable
without burning CI minutes.</li>
<li><strong>Our CI now captures names.</strong> The dogfooded harden steps run with
<code>dns-capture: true</code> (still <code>audit</code> — monitor, don&rsquo;t firewall), so job summaries
show real destination and package-repository names instead of bare IPs, and the
capture path is exercised on every run. Safe now that <code>@v1</code> (&gt;= 1.0.35) carries
the teardown + systemd-resolved fixes.</li>
</ul>
]]></content:encoded></item><item><title>vibecheck-ai-slop</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/vibecheck-ai-slop/</link><pubDate>Thu, 06 Aug 2026 06:09:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/06/vibecheck-ai-slop/</guid><description>Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.19.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary vibecheck is an AI code quality tool that detects common code smells and security vulnerabilities in JavaScript/TypeScript projects. It provides 39 rules to catch errors, security issues, and stylistic problems in generated AI-generated code. The action runs locally, stays fast, and requires no configuration or API keys.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuvrajangadsingh/vibecheck">https://github.com/yuvrajangadsingh/vibecheck</a></strong> to version <strong>v1.19.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibecheck-ai-slop">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>vibecheck is an AI code quality tool that detects common code smells and security vulnerabilities in JavaScript/TypeScript projects. It provides 39 rules to catch errors, security issues, and stylistic problems in generated AI-generated code. The action runs locally, stays fast, and requires no configuration or API keys.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This closes the class of bug where vibecheck exits 0 and prints &ldquo;no issues&rdquo; while a real finding sits in a file it was supposed to scan.</p>
<p><strong>Existing builds may newly report findings.</strong> That is the point of the release. If a run goes red after upgrading, it was passing on something it never looked at.</p>
<h2 id="--staged-read-the-wrong-file"><code>--staged</code> read the wrong file</h2>
<p>It built its line map from <code>git diff --cached</code> and then scanned the <strong>working tree</strong>. Stage an <code>eval()</code>, overwrite the working copy with clean code, and the commit went through green — the pre-commit hook case, which is the entire reason the flag exists.</p>
<p>The index is now snapshotted once with <code>git write-tree</code>, and both the line map and the file contents come from that immutable tree, so they can never describe different states. Blobs are fetched by OID. Discovery moved to git too, since a file staged and then deleted from the working tree never came back from the file glob.</p>
<h2 id="files-the-scanner-could-not-read-were-reported-as-clean">Files the scanner could not read were reported as clean</h2>
<p>&ldquo;Couldn&rsquo;t look&rdquo; and &ldquo;looked, it&rsquo;s fine&rdquo; were the same outcome. An unreadable file, a file over the 1MB cap, an explicitly named symlinked file, and a filename with a leading <code>!</code> or a backslash all exited 0 on a file containing <code>eval()</code>.</p>
<p>Skips are now reported with a reason and exit 2. Files you mean to skip belong in <code>ignore</code>, which stays silent.</p>
<h2 id="--diff-stdin-trusted-that-your-checkout-matched-the-diff"><code>--diff-stdin</code> trusted that your checkout matched the diff</h2>
<p>It took line numbers from the diff and bytes from the checkout, and nothing checked the two described the same content. <code>gh pr diff 42 | vibecheck --diff-stdin .</code> against any other checkout looked for findings at line numbers that meant nothing. It now verifies through the blob hashes in the <code>index</code> headers and exits 2 on a mismatch.</p>
<h2 id="config-could-hide-files-from-the-linter">Config could hide files from the linter</h2>
<p><code>.gitattributes</code> marking a source file <code>binary</code>, a textconv filter, <code>diff.mnemonicPrefix</code> and <code>diff.noprefix</code> each made whole files or whole diffs parse as nothing changed.</p>
<h2 id="also">Also</h2>
<ul>
<li><code>--staged --fix</code> is refused: once findings describe the index there is nothing coherent for a fixer that writes the working tree to do.</li>
<li>Unborn SHA-256 repositories work.</li>
<li>Slop score counts baselined findings (from v1.18.0), so a baseline cannot send it to 100.</li>
</ul>
<p>407 tests, up from 376. Three adversarial review rounds; the third caught two false positives the second introduced.</p>
<h2 id="known-limitations">Known limitations</h2>
<p>Documented in the README. All need non-default git configuration: a <code>.gitattributes</code> clean filter shifts <code>--diff</code> line numbers (<code>--staged</code> is unaffected); a diff from another repository with sub-7-character <code>index</code> hashes cannot be verified; explicitly naming a staged symlink scans its referent; a modify-then-delete stream is not refused.</p>
<p>Separately, diff mode reports findings on changed lines, so a multiline finding whose anchor line did not change is not reported even when your edit created it.</p>
]]></content:encoded></item><item><title>move-test-gen coverage check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/move-test-gen-coverage-check/</link><pubDate>Wed, 05 Aug 2026 15:07:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/move-test-gen-coverage-check/</guid><description>Version updated for https://github.com/mehvetero/move-test-gen to version v1.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, move-test-gen, is an Agent Skill designed to automatically generate edge-case test suites for Sui Move functions. It covers various scenarios such as boundary values, arithmetic edges, access control issues, state machine failures, and economic conditions, ensuring comprehensive testing of Move modules. The action automates the process of generating test files that can be executed using the sui move test command, helping developers catch potential bugs and edge cases in their Move code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mehvetero/move-test-gen">https://github.com/mehvetero/move-test-gen</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-test-gen-coverage-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>move-test-gen</code>, is an Agent Skill designed to automatically generate edge-case test suites for Sui Move functions. It covers various scenarios such as boundary values, arithmetic edges, access control issues, state machine failures, and economic conditions, ensuring comprehensive testing of Move modules. The action automates the process of generating test files that can be executed using the <code>sui move test</code> command, helping developers catch potential bugs and edge cases in their Move code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<h3 id="two-new-lint-rules">Two new lint rules</h3>
<table>
  <thead>
      <tr>
          <th>Rule</th>
          <th>Severity</th>
          <th>Pattern</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>MOV-005</strong></td>
          <td>HIGH</td>
          <td>Authorization check result discarded — <code>vector::contains()</code> or <code>has()</code> called, bool returned and thrown away. The check runs but never enforces. <a href="https://github.com/Typus-Lab/typus/blob/a918e98c4f7d3a28d0d809d3263d8c21e90d3c01/typus_oracle/sources/oracle.move#L146">Typus Finance $3.44M exploit</a> (Oct 2025) was exactly this pattern.</td>
      </tr>
      <tr>
          <td><strong>MOV-006</strong></td>
          <td>LOW</td>
          <td>Same abort code in <code>assert!</code> across 2+ public functions — callers cannot distinguish which function aborted.</td>
      </tr>
  </tbody>
</table>
<p><strong>MOV-005 FP handling:</strong></p>
<ul>
<li>Void functions that abort internally (like <code>admin::verify()</code>) are not flagged — calling them without binding the result is correct.</li>
<li><code>let _ = vector::contains(...)</code> (explicit discard) is not flagged — an intentional discard is a design decision, not a forgotten check.</li>
</ul>
<p><strong>MOV-006 FP handling:</strong></p>
<ul>
<li>Lowercase variable names (<code>now</code>, <code>user</code>, <code>clock</code>) appearing as assert second arguments are filtered — these are parameters, not error constants.</li>
<li>Shared error constants across a module is a common Move convention. LOW severity reflects this; the finding is a diagnostic signal (&ldquo;consider unique codes for debuggability&rdquo;), not a vulnerability.</li>
</ul>
<h3 id="gate-improvements-from-v130">Gate improvements (from v1.3.0)</h3>
<ul>
<li>SIGTERM handler — CI timeout no longer leaves temp directories behind</li>
<li><code>walkDir</code> shared module — eliminates diverged copies across lint and coverage</li>
<li>Testability pre-check: <code>blocker</code> vs <code>cost</code> severity split (community feedback from forums.sui.io)</li>
<li>Round count corrected 47→46 (doc-grounding finding from CoalLedger field run)</li>
</ul>
<h3 id="validated-against">Validated against</h3>
<table>
  <thead>
      <tr>
          <th>Protocol</th>
          <th>Files</th>
          <th>Findings</th>
          <th>Notes</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>SuiTears</td>
          <td>68</td>
          <td>77</td>
          <td>26 access-control, 15 downcast, 14 div-zero, 13 shared-abort, 9 unchecked-mul</td>
      </tr>
      <tr>
          <td>Bucket Protocol</td>
          <td>58</td>
          <td>68</td>
          <td>37 access-control, 10 shared-abort, 10 unchecked-mul, 6 div-zero, 5 downcast</td>
      </tr>
      <tr>
          <td>Typus Finance</td>
          <td>128</td>
          <td>353</td>
          <td>148 access-control, 113 downcast, 48 unchecked-mul, 30 shared-abort, 14 div-zero</td>
      </tr>
      <tr>
          <td>Kriya DEX</td>
          <td>3</td>
          <td>1</td>
          <td><code>update_pool</code> no access control (MOV-001) — matches <a href="https://github.com/efficacy-finance/kriya-dex-interface/issues/2">our manual finding</a></td>
      </tr>
      <tr>
          <td>Scallop</td>
          <td>172</td>
          <td>1</td>
          <td>After 82→1 FP reduction (9 commits in v1.2.0)</td>
      </tr>
  </tbody>
</table>
<p>MOV-001 (access control) dominates because it flags any <code>public fun</code> with <code>&amp;mut</code> and no capability parameter. Library functions like <code>bitmap::set()</code> and <code>vector::push_back()</code> are intentionally permissionless — these are known FPs documented in the README. The FP rate on protocol-level code (non-library) is ~10%.</p>
<h3 id="eval-lab">Eval lab</h3>
<p>5 campaigns, 13 scenarios, 46 rounds — all RETIRED (a scenario is retired when 2 consecutive dry rounds + 1 varied-angle sweep produce no new findings, following the <a href="https://github.com/mehvetero/move-test-gen/blob/main/eval/RESULTS.md">retirement-by-saturation protocol</a>). Generator models: GPT-5.5, Claude 4.8, DeepSeek-v4-pro.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx skills add mehvetero/move-test-gen
</span></span></code></pre></div><p>As a GitHub Action (tag reference):</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">mehvetero/move-test-gen@v1.4.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">sources</span>: <span style="color:#ae81ff">sources</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">tests</span>: <span style="color:#ae81ff">tests</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">lint</span>: <span style="color:#e6db74">&#39;true&#39;</span>
</span></span></code></pre></div><p>For supply-chain-hardened pinning, use the commit SHA:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">mehvetero/move-test-gen@b76c684</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">sources</span>: <span style="color:#ae81ff">sources</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">tests</span>: <span style="color:#ae81ff">tests</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">lint</span>: <span style="color:#e6db74">&#39;true&#39;</span>
</span></span></code></pre></div><p>Full changelog: v1.3.0&hellip;v1.4.0</p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/totem-shield/</link><pubDate>Wed, 05 Aug 2026 15:06:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.111.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a tool that uses markdown lessons to enforce project rules and context, eliminating the need for LLMs to reinvent existing helpers. It provides deterministic linting and a queryable knowledge index derived from these lessons, ensuring architectural integrity and reducing errors in code reviews.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.111.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a tool that uses markdown lessons to enforce project rules and context, eliminating the need for LLMs to reinvent existing helpers. It provides deterministic linting and a queryable knowledge index derived from these lessons, ensuring architectural integrity and reducing errors in code reviews.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>JaCoCo Report to PR Comment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/jacoco-report-to-pr-comment/</link><pubDate>Wed, 05 Aug 2026 15:04:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/jacoco-report-to-pr-comment/</guid><description>Version updated for https://github.com/MoranaApps/jacoco-report to version v3.1.2.
This action is used across all versions by 9 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the publication of JaCoCo coverage reports as comments in pull requests, solving the problem of manually reviewing coverage numbers by hunting through CI logs. It provides key capabilities such as global and per-group thresholds, baseline comparison, flexible comment levels, and skip-unchanged filter.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MoranaApps/jacoco-report">https://github.com/MoranaApps/jacoco-report</a></strong> to version <strong>v3.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>9</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jacoco-report-to-pr-comment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the publication of JaCoCo coverage reports as comments in pull requests, solving the problem of manually reviewing coverage numbers by hunting through CI logs. It provides key capabilities such as global and per-group thresholds, baseline comparison, flexible comment levels, and skip-unchanged filter.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="bugfixes-">Bugfixes 🛠</h3>
<ul>
<li>#203 <em>Issue: Changed Files with 0 Coverage Incorrectly Pass Per-File Threshold</em> developed by @miroslavpojer in #204
<ul>
<li>Changed files with 0% coverage for the selected metric now correctly fail per-file thresholds greater than 0%</li>
<li>Improved transparency in PR comment tables: files with no coverage data are properly evaluated</li>
<li>Fixed regression where Main.scala with 0% instruction coverage was incorrectly marked as passing 60% threshold</li>
<li>All changed files are now uniformly evaluated against per-file thresholds regardless of metric weight</li>
</ul>
</li>
<li>Bug: #211 <em>Bug report content</em> developed by @miroslavpojer in #212
<ul>
<li>Fixed: <code>evaluate-unchanged: false</code> now correctly excludes reports and report groups with no changed files from all pass/fail evaluation (violations, overall threshold, changed-files threshold, per-group status) instead of only hiding them from the PR comment.</li>
</ul>
</li>
</ul>
<h3 id="infrastructure-">Infrastructure ⚙️</h3>
<ul>
<li>PR: #205 <em>chore(deps): update actions/setup-python action to v6.3.0</em> developed by @renovate[bot]</li>
<li>PR: #206 <em>chore(deps): update dependency mypy to v2.2.0</em> developed by @renovate[bot]</li>
<li>PR: #207 <em>chore(deps): update lycheeverse/lychee-action action to v2.9.0</em> developed by @renovate[bot]</li>
<li>PR: #208 <em>chore(deps): update python dependencies</em> developed by @renovate[bot]</li>
<li>PR: #209 <em>chore(deps): update actions/setup-python action to v7</em> developed by @renovate[bot]</li>
<li>PR: #210 <em>chore(deps): update actions/checkout action to v7.0.1</em> developed by @renovate[bot]</li>
</ul>
<h4 id="full-changelog">Full Changelog</h4>
<p><a href="https://github.com/MoranaApps/jacoco-report/compare/v3.1.1...v3.1.2">https://github.com/MoranaApps/jacoco-report/compare/v3.1.1...v3.1.2</a></p>
]]></content:encoded></item><item><title>Conventional Changelog Lite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/conventional-changelog-lite/</link><pubDate>Wed, 05 Aug 2026 15:04:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/conventional-changelog-lite/</guid><description>Version updated for https://github.com/mrdoodles/conventional-changelog to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates a comprehensive changelog from Conventional Commits, providing a detailed list of changes in the form of commits, grouped by type and referenced by their SHA. It solves the problem of automating the creation and maintenance of a complete changelog based on commit messages, ensuring that all new features, bug fixes, and other changes are included in the file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mrdoodles/conventional-changelog">https://github.com/mrdoodles/conventional-changelog</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/conventional-changelog-lite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates a comprehensive changelog from Conventional Commits, providing a detailed list of changes in the form of commits, grouped by type and referenced by their SHA. It solves the problem of automating the creation and maintenance of a complete changelog based on commit messages, ensuring that all new features, bug fixes, and other changes are included in the file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: update name for the marketplace by @mrdoodles in <a href="https://github.com/mrdoodles/conventional-changelog/pull/1">https://github.com/mrdoodles/conventional-changelog/pull/1</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@mrdoodles made their first contribution in <a href="https://github.com/mrdoodles/conventional-changelog/pull/1">https://github.com/mrdoodles/conventional-changelog/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mrdoodles/conventional-changelog/compare/v1...v1.0.2">https://github.com/mrdoodles/conventional-changelog/compare/v1...v1.0.2</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/go-proxy-cache-updater/</link><pubDate>Wed, 05 Aug 2026 15:02:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.39.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically pulls new releases of Go modules to a specified proxy cache when tags are created, ensuring that the module is immediately available and documentation is updated on platforms like pkg.go.dev. It supports both standard and submodule version tags and offers customizable proxy configurations and import paths. The action can be easily integrated into workflows using actions/setup-go for setting up the Go environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.39</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically pulls new releases of Go modules to a specified proxy cache when tags are created, ensuring that the module is immediately available and documentation is updated on platforms like pkg.go.dev. It supports both standard and submodule version tags and offers customizable proxy configurations and import paths. The action can be easily integrated into workflows using actions/setup-go for setting up the Go environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1139-2026-08-05"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.38...v1.1.39">1.1.39</a> (2026-08-05)</h2>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/odin-scan-smart-contract-security/</link><pubDate>Wed, 05 Aug 2026 15:01:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Odin Scan GitHub Action is a tool that performs AI-powered security scans on CosmWasm, Solana, and EVM projects. It integrates directly into your GitHub workflow to catch vulnerabilities before they reach production. Key capabilities include multi-platform support, automatic platform detection, and GitHub Code Scanning integration for native security alerts. The action can also post PR comments, provide inline annotations, and trigger scans via comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Odin Scan GitHub Action is a tool that performs AI-powered security scans on CosmWasm, Solana, and EVM projects. It integrates directly into your GitHub workflow to catch vulnerabilities before they reach production. Key capabilities include multi-platform support, automatic platform detection, and GitHub Code Scanning integration for native security alerts. The action can also post PR comments, provide inline annotations, and trigger scans via comments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial Release</p>
<p>AI-powered smart contract security analysis, now integrated directly into your GitHub workflow.</p>
<p>✨ Features</p>
<p>Multi-Platform Support</p>
<ul>
<li>CosmWasm - Rust-based smart contracts for Cosmos SDK</li>
<li>Solana (SVM) - Anchor and native Solana programs</li>
<li>EVM - Solidity and Vyper contracts</li>
<li>Auto-detection - Automatically identifies platform from your repo</li>
</ul>
<p>GitHub Integration</p>
<ul>
<li>Code Scanning - SARIF upload for native security alerts in the Security tab</li>
<li>PR Comments - Severity summary and top findings posted directly on pull requests</li>
<li>Inline Annotations - Critical/high findings appear as errors, medium/low as warnings on diffs</li>
<li>Artifact Upload - Full JSON report available as workflow artifact</li>
</ul>
<p>Customization</p>
<ul>
<li>Severity Thresholds - Fail builds at critical, high, medium, or low severity</li>
<li>Platform Override - Force specific platform detection when auto-detect isn&rsquo;t enough</li>
<li>Timeout Control - Configurable analysis timeout (default: 30 minutes)</li>
<li>Flexible Triggers - Run on push, PR, schedule, or manual dispatch</li>
</ul>
<p>🚀 Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Security Scan</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&#39;on&#39;</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">main</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">security-events</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">api-key</span>: <span style="color:#e6db74">&#39;${{ secrets.ODIN_SCAN_API_KEY }}&#39;</span>
</span></span></code></pre></div><p>📋 Requirements</p>
<ul>
<li>Odin Scan Pro subscription - Required for API access</li>
<li>API Key - Generate at <a href="https://odinscan.ai/dashboard/settings">https://odinscan.ai/dashboard/settings</a></li>
<li>GitHub Permissions - contents: read, security-events: write (for SARIF), pull-requests: write (for
comments)</li>
</ul>
<p>🔧 Configuration</p>
<p>All Inputs</p>
<p>| ┌────────────────────┬─────────────────────┬──────────────────────────────────────────────┐ |
| │       Input        │       Default       │                 Description                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ api-key            │ Required            │ Your Odin Scan API key (odin_sk_*)           │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ platform           │ auto                │ Target platform: auto, cosmwasm, solana, evm │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ severity-threshold │ high                │ Fail at: critical, high, medium, low, none   │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ fail-on-findings   │ true                │ Whether to fail workflow on findings         │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ comment-on-pr      │ true                │ Post summary comment on PRs                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-sarif       │ true                │ Upload SARIF to Code Scanning                │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-artifact    │ true                │ Upload full report as artifact               │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ timeout            │ 1800                │ Max analysis wait time (seconds)             │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ github-token       │ ${{ github.token }} │ Token for PR comments and SARIF              │ |
| └────────────────────┴─────────────────────┴──────────────────────────────────────────────┘ |</p>
<p>All Outputs</p>
<ul>
<li>analysis-id - Unique analysis identifier</li>
<li>status - Analysis status (completed, failed)</li>
<li>total-findings - Total number of findings</li>
<li>critical-count, high-count, medium-count, low-count - Counts by severity</li>
<li>report-url - Link to full report on Odin Scan</li>
<li>sarif-file - Path to generated SARIF file</li>
</ul>
<p>📝 Example Workflows</p>
<p>Basic (Auto-detect)</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span></code></pre></div><p>EVM with Medium Threshold</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">platform</span>: <span style="color:#ae81ff">evm</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">severity-threshold</span>: <span style="color:#ae81ff">medium</span>
</span></span></code></pre></div><p>Only on Solidity Changes</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#39;**.sol&#39;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">foundry.toml</span>
</span></span></code></pre></div><p>🔒 Security &amp; Privacy</p>
<ul>
<li>All API communication over HTTPS (TLS 1.2+)</li>
<li>API keys automatically masked in logs</li>
<li>No data stored by the action (stateless)</li>
<li>See <a href="https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md">https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md</a> for details</li>
</ul>
<p>📖 Documentation</p>
<ul>
<li>Action README - <a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></li>
<li>Odin Scan Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
<li>Get API Key - <a href="https://app.odinscan.ai/settings">https://app.odinscan.ai/settings</a></li>
</ul>
<p>🐛 Known Limitations</p>
<ul>
<li>Private repos - Requires github-token with repo access</li>
<li>Large repos - May need increased timeout for complex codebases</li>
<li>Code Scanning - Requires GitHub Advanced Security on private repos</li>
</ul>
<p>🙏 Support</p>
<ul>
<li>Issues - <a href="https://github.com/Odin-Scan/odin-scan-action/issues">https://github.com/Odin-Scan/odin-scan-action/issues</a></li>
<li>Email - <a href="mailto:support@odinscan.ai">support@odinscan.ai</a></li>
<li>Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
</ul>
<hr>
<p>Full Changelog: <a href="https://github.com/Odin-Scan/odin-scan-action/commits/v1">https://github.com/Odin-Scan/odin-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>AI Model Lifecycle Monitor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/ai-model-lifecycle-monitor/</link><pubDate>Wed, 05 Aug 2026 15:00:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/ai-model-lifecycle-monitor/</guid><description>Version updated for https://github.com/oscarnilsson98/ai-model-end-of-life-action to version v3.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the monitoring of AI models referenced in your codebase. It checks for known deprecations and shutdowns from deprecations.info, providing warnings or failures before a model is no longer available. The action reads evidence directly from Git commits, allowing for quick setup and warning-only operations by default. Enforcement can be enabled with policy files to fail jobs when specific conditions are met.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action">https://github.com/oscarnilsson98/ai-model-end-of-life-action</a></strong> to version <strong>v3.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-model-lifecycle-monitor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the monitoring of AI models referenced in your codebase. It checks for known deprecations and shutdowns from <code>deprecations.info</code>, providing warnings or failures before a model is no longer available. The action reads evidence directly from Git commits, allowing for quick setup and warning-only operations by default. Enforcement can be enabled with policy files to fail jobs when specific conditions are met.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: re-qualify the detector rules against openai v7 and azurerm v5 by @oscarnilsson98 in <a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action/pull/17">https://github.com/oscarnilsson98/ai-model-end-of-life-action/pull/17</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action/compare/v3.1.0...v3.1.1">https://github.com/oscarnilsson98/ai-model-end-of-life-action/compare/v3.1.0...v3.1.1</a></p>
]]></content:encoded></item><item><title>Garita PII Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/garita-pii-guard/</link><pubDate>Wed, 05 Aug 2026 14:59:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/garita-pii-guard/</guid><description>Version updated for https://github.com/proscar87/garita to version v0.12.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Garita is a GitHub Action that prevents sensitive personal and credential data from entering your repository. It uses a whitelist of allowed names, domains, or serial numbers to detect potential PII in commit messages and files. The action supports various detectors such as CURP, RFC, CLABE, NSS, phone numbers, JWTs, and more, with the ability to ignore certain patterns like passwords. Garita provides a single list that prevents sensitive data from entering the repository by reading it directly from your configuration file without executing it.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/proscar87/garita">https://github.com/proscar87/garita</a></strong> to version <strong>v0.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/garita-pii-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Garita is a GitHub Action that prevents sensitive personal and credential data from entering your repository. It uses a whitelist of allowed names, domains, or serial numbers to detect potential PII in commit messages and files. The action supports various detectors such as CURP, RFC, CLABE, NSS, phone numbers, JWTs, and more, with the ability to ignore certain patterns like passwords. Garita provides a single list that prevents sensitive data from entering the repository by reading it directly from your configuration file without executing it.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Tres países nuevos con algoritmo reproducido contra vectores públicos: RIF venezolano (SENIAT/PDVSA), RUC paraguayo (código oficial de la SET), NIT guatemalteco (spec FEL de la SAT). Bolivia, Costa Rica y Panamá quedan fuera documentados: sin fuente verificable no hay detector. Dieciséis países.</p>
]]></content:encoded></item><item><title>holt ci</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/holt-ci/</link><pubDate>Wed, 05 Aug 2026 14:58:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/holt-ci/</guid><description>Version updated for https://github.com/Raed2180416/holt to version v0.3.1.
This action is used across all versions by 1 repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary holt automates the process of inspecting and managing commits, staged edits, local files, and relationships across multiple Git repositories. It helps prevent duplicate work by ensuring that each worktree’s changes are coordinated and preserved before being merged into a shared decision surface. The action ensures that only verifiable work is destroyed, avoiding unintended deletions and preserving unique content.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Raed2180416/holt">https://github.com/Raed2180416/holt</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<p>Go to the <a href="https://github.com/marketplace/actions/holt-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>holt automates the process of inspecting and managing commits, staged edits, local files, and relationships across multiple Git repositories. It helps prevent duplicate work by ensuring that each worktree&rsquo;s changes are coordinated and preserved before being merged into a shared decision surface. The action ensures that only verifiable work is destroyed, avoiding unintended deletions and preserving unique content.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="holt-031--safety-and-correctness-fixes">holt 0.3.1 — safety and correctness fixes</h2>
<p><strong>Safety and correctness fixes across the guard, integration, and analysis paths.</strong> If you are
running 0.3.0, upgrade.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install -g https://github.com/Raed2180416/holt/releases/download/v0.3.1/holt.tgz
</span></span></code></pre></div><p>One command — no clone, no build. This signed artifact was built from the immutable <code>v0.3.1</code> tag,
package-audited, checksum-verified and installed on the Ubuntu Node 24 release runner before
publication. The public benchmark and broader platform matrix remain available for independent
evaluation and future release cycles. <code>holt.tgz</code> is a stable name, so this URL keeps working; the
versioned <code>holt-0.3.1.tgz</code> is attached alongside it.</p>
<h3 id="guard-fixes">Guard fixes</h3>
<ul>
<li><strong>The hooks <code>holt integrate</code> installs disarmed the guard.</strong> For Claude Code, integrate wires the
blocking guard <em>and</em> the brief. Both used one report cache keyed only on the repository root, so
the brief&rsquo;s analysis — computed without your own worktree — was served to the guard as though it
were the guard&rsquo;s own. Cold cache: <code>git clean -fd</code> was refused, naming the symbol at risk. Run the
brief hook first, and the
identical command was allowed. Same for <code>git reset --hard</code>, <code>git checkout -- .</code> and
<code>git stash push -u</code>.</li>
<li><strong>A space in your path turned the guard off.</strong> Eight of nine destructive forms flipped from
refuse to allow. <code>C:\Users\First Last\project</code> and <code>~/My Drive/project</code> are ordinary paths.</li>
<li><strong>A newline in a worktree name turned it off too</strong> — and <code>holt risk</code> <em>named</em> that worktree as
holding work found nowhere else in the same breath.</li>
<li><strong><code>rm -rf &lt;repository root&gt;</code> was allowed.</strong> Correct by the guard&rsquo;s own rule, since a clean tree
holds no sole copy — and <code>.git</code> is inside that path, so it takes every commit, branch, reflog,
stash and rescue ref with it. <code>git worktree remove</code> refuses the main working tree; <code>rm</code> does not.</li>
<li><strong>The hook could stall every tool call</strong> for as long as the host held stdin open. It now reads the
bounded hook payload and returns without waiting for an unrelated end-of-stream signal.</li>
</ul>
<h3 id="integration-ownership-fixes">Integration ownership fixes</h3>
<ul>
<li><strong><code>holt integrate</code> deleted third-party hooks.</strong> A fixture with seven foreign PreToolUse entries
came back with one. A corporate guardrail was claimed because its command contained <code>--host</code>; an
npm package because its name contained <code>holt</code>; a script because the <em>username</em> in its path did.</li>
<li><strong><code>holt uninstall</code> deleted config files in repositories holt had never been installed into</strong> —
all sixteen project MCP targets, each printing &ldquo;Only holt&rsquo;s own entries were touched&rdquo;.</li>
<li><strong>A legal JSONC trailing comma cost a team both of their MCP servers.</strong> <code>.mcp.json</code> is JSONC;
holt read it with a parser that was not. The read failed, the failure was recorded as &ldquo;no file&rdquo;,
and integrate then <em>created</em> the file it had just failed to read.</li>
<li><strong>A hand-written <code>.git/hooks/pre-commit</code> was deleted</strong> for mentioning holt in a comment.</li>
<li><strong><code>holt integrate --dry-run</code> wrote 21 files.</strong> It is now a real preview.</li>
</ul>
<p>Ownership is now argv-shaped — the program being executed must actually <em>be</em> holt — and a config
holt cannot parse is left byte-for-byte alone rather than replaced.</p>
<h3 id="correctness">Correctness</h3>
<ul>
<li><strong>A repository with one worktree reported zero risk while holding real risk.</strong> Reported from the
field: <code>holt risk</code> said <code>scanned 0/0, nothing at risk</code> while the tree held 24 uncommitted changes
and 9 symbols that existed nowhere else. The primary worktree is now scanned when it is the only
one. It is still never a deletion candidate.</li>
<li><strong>Duplicate detection reported false positives without ctags</strong> — a function&rsquo;s &ldquo;declared body&rdquo; was
its signature line alone, so any two functions sharing a name and an arity compared as identical.</li>
<li><strong><code>holt auto</code> announced a lock git had already refused</strong>, and <code>holt protect</code> exited 0 having
failed. Both now tell the truth, and an action that failed exits non-zero.</li>
<li><strong><code>holt discard</code> printed no ref</strong> while telling you the content was &ldquo;recoverable from the ref
above&rdquo;. It now prints the ref, the commit and the exact restore command.</li>
<li><strong>holt refused ordinary commands</strong> whose arguments came from shell substitutions. Over-refusal is
a defect: a refusal you cannot act on teaches you to ignore the next one.</li>
</ul>
<h3 id="test-and-supply-chain-integrity">Test and supply-chain integrity</h3>
<ul>
<li>A source-stripping bug meant substantial product code never reached the no-telemetry and
path-comparison gates. The no-telemetry guarantee survived the widened scan; it was
under-verified, not false.</li>
<li>The static-analysis ratchet <strong>wrote a zero and passed</strong> when the type checker could not run, and
its config meant nothing was really being type-checked. The ratchet now fails when the checker
fails and proves it inspected real product code.</li>
<li>Both benchmark harnesses reported &ldquo;correct&rdquo; for runs that graded <strong>nothing</strong>. §1&rsquo;s headline
result included ungraded verdicts and a summary line that divided the planted count by itself.
The validators now refuse missing denominators and ungraded rows instead of turning unknowns into
success.</li>
</ul>
<h3 id="evidence-status">Evidence status</h3>
<p>The benchmark methods and validation rules are documented in
<a href="https://github.com/Raed2180416/holt/blob/main/BENCHMARKS.md">BENCHMARKS.md</a>. This release body does
not publish a performance rate or agent-utility lift until the exact release artifact has a retained,
checksum-bearing result that the release can link directly.</p>
<h3 id="coverage-guide">Coverage guide</h3>
<p>Host coverage is graded rather than implied. Contract-tested integrations are separated from live
host runs, and a host is not described as blocking until its real allow, deny and failure paths have
been driven. <a href="https://github.com/Raed2180416/holt/blob/main/HOSTS.md">HOSTS.md</a> records the current
level for each host from the generated manifest.</p>
<hr>
<p><em>Holt is part of Contrare Research. Product and research queries:
<a href="mailto:research.contrare@outlook.com">research.contrare@outlook.com</a>.</em></p>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/raviqqe/muffy/</link><pubDate>Wed, 05 Aug 2026 14:56:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.4.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation of static websites using the Nu HTML validator. It can check a set of websites or a single website, and it is also available as a Docker image for easy integration into build pipelines. The action provides a simple command-line interface to validate websites and supports GitHub Actions for continuous integration purposes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation of static websites using the Nu HTML validator. It can check a set of websites or a single website, and it is also available as a Docker image for easy integration into build pipelines. The action provides a simple command-line interface to validate websites and supports GitHub Actions for continuous integration purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>1ae5074bc36f43fd84cdbf1f28417ea69e061485 Bump version (#1199)</li>
<li>a472aa9ef75c14ac94c35d0f3706ecf720fb17fb Resolve concurrency after increasing open file limit (#1198)</li>
<li>5ce0ee2315165d17683c0c645d06c8845cec3ef4 Refactor time tests (#1197)</li>
<li>d4f3b0f9b71cd36666a3650f0ec5790a3333b217 Increase nofile limit (#1196)</li>
<li>81f1769b1a58e74d4220d638e97d98da33f20871 Support MathML (#1195)</li>
<li>cc68fa76f1027bf143117fbfca656782274aca21 Update action versions in doc (#1194)</li>
<li>6f5b46cb125f0d8f0615de1fba2eec36becee024 Yellow based theme (#1193)</li>
<li>0afc612dbc593d974a42cc31eef6c89586355b21 Bump @astrojs/starlight from 0.41.5 to 0.41.6 in /doc in the astro group (#1190)</li>
<li>b594933ba9ec8c3d8a8f83ee0d95d3b58b2c72a2 Bump homebrew/actions/setup-homebrew from 2026.07.29.1 to 2026.08.03.1 (#1192)</li>
<li>0e3a2a05275fe75c744ee82a8d8d5998f4abef5e Bump clap from 4.6.4 to 4.6.5 (#1191)</li>
<li>912063fe16e8d2866e98586aeb0b864850655a3c Update icon (#1189)</li>
<li>885a72e4c8afa79d69219f5057b2eba9bf3e6f6e Update icon (#1188)</li>
<li>4be9fb3b3f6ff130e5407cd9ec85599fadcdbb6a Remove warning (#1187)</li>
<li>2b8120981720a5d17dc32e2d300ede23fab04884 Update icons (#1186)</li>
</ul>
]]></content:encoded></item><item><title>Healthchecks Ping Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/healthchecks-ping-action/</link><pubDate>Wed, 05 Aug 2026 14:56:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/healthchecks-ping-action/</guid><description>Version updated for https://github.com/reecetech/healthchecks-action to version v0.28.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates with Healthchecks.io to monitor the health of your scheduled jobs and workflows by sending pings at the start and end of a job’s execution. It helps in ensuring that you’re always aware of the job’s status and can quickly diagnose issues if any arise. The action automatically sends pings based on whether the job is successful or fails, providing clear feedback to Healthchecks.io.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/reecetech/healthchecks-action">https://github.com/reecetech/healthchecks-action</a></strong> to version <strong>v0.28.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/healthchecks-ping-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates with Healthchecks.io to monitor the health of your scheduled jobs and workflows by sending pings at the start and end of a job&rsquo;s execution. It helps in ensuring that you&rsquo;re always aware of the job&rsquo;s status and can quickly diagnose issues if any arise. The action automatically sends pings based on whether the job is successful or fails, providing clear feedback to Healthchecks.io.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #66 from reecetech/dependabot/github_actions/EndBug/add-and-commit-10 (be7086c)</li>
<li>Merge branch &lsquo;main&rsquo; into dependabot/github_actions/EndBug/add-and-commit-10 (5fe9907)</li>
<li>Merge pull request #69 from reecetech/dependabot/npm_and_yarn/types/node-25.5.2 (7aad411)</li>
<li>Update README (2db2d12)</li>
<li>Merge branch &lsquo;main&rsquo; into dependabot/npm_and_yarn/types/node-25.5.2 (ac6f9ee)</li>
<li>Merge pull request #71 from reecetech/optional-skip-pings (def3b0f)</li>
<li>Update compiled action source (dist/*.js) (1e1edac)</li>
<li>Potential fix for pull request finding (c8ebb2d)</li>
<li>Potential fix for pull request finding (fdde497)</li>
<li>Merge branch &lsquo;optional-skip-pings&rsquo; of github.com:reecetech/healthchecks-action into optional-skip-pings (d15acde)</li>
</ul>
]]></content:encoded></item><item><title>wavedash-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/wavedash-action/</link><pubDate>Wed, 05 Aug 2026 14:55:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/wavedash-action/</guid><description>Version updated for https://github.com/remarkablegames/wavedash-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading and publishing web game files to Wavedash. It handles both uploading existing builds or auto-creating new projects using a wavedash.toml file. Users can customize various parameters such as token, config file path, game ID, upload directory, entrypoint, SDK version, and publish options. The action supports building and publishing with release notes, and it provides outputs for the build ID, playtest URL, and whether the build was published.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablegames/wavedash-action">https://github.com/remarkablegames/wavedash-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wavedash-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading and publishing web game files to Wavedash. It handles both uploading existing builds or auto-creating new projects using a <code>wavedash.toml</code> file. Users can customize various parameters such as token, config file path, game ID, upload directory, entrypoint, SDK version, and publish options. The action supports building and publishing with release notes, and it provides outputs for the build ID, playtest URL, and whether the build was published.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="100-2026-08-05">1.0.0 (2026-08-05)</h2>
<h3 id="features">Features</h3>
<ul>
<li>upload and publish game files to Wavedash (<a href="https://github.com/remarkablegames/wavedash-action/commit/3da8c9687b98c257a28564cf0700e4987c9c68bd">3da8c96</a>)</li>
</ul>
]]></content:encoded></item><item><title>VeriFenceAction</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/verifenceaction/</link><pubDate>Wed, 05 Aug 2026 14:54:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/verifenceaction/</guid><description>Version updated for https://github.com/Ridadata/doc-doctor to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Doc Doctor is a GitHub Action that automatically executes and verifies code snippets marked with verify in Markdown files. It checks for broken code and posts a PR comment if any snippet fails, ensuring documentation examples remain accurate. The action supports various programming languages and provides options to set timeouts and specify which files to scan.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Ridadata/doc-doctor">https://github.com/Ridadata/doc-doctor</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/verifenceaction">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Doc Doctor is a GitHub Action that automatically executes and verifies code snippets marked with <code>verify</code> in Markdown files. It checks for broken code and posts a PR comment if any snippet fails, ensuring documentation examples remain accurate. The action supports various programming languages and provides options to set timeouts and specify which files to scan.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial public release.</p>
<ul>
<li>Extracts <code>lang verify</code> code blocks from Markdown and executes them (Node, Python, Bash runtimes)</li>
<li>Optional output-diffing via an adjacent <code>text expect</code> block</li>
<li>Posts one summarized PR comment, updated in place on re-runs</li>
</ul>
<p>Pin to <code>Ridadata/doc-doctor@v1</code> (tracks future v1.x patches) or <code>@v1.0.2</code> (fixed).</p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/kaniko-build-action/</link><pubDate>Wed, 05 Aug 2026 14:53:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, “Hello world docker action,” prints a greeting message either “Hello World” or personalized to any specified name to the console. It automates tasks related to printing greetings and can be used in workflows to notify contributors by displaying their names or welcome messages. The action supports configuration through an input parameter for the person’s name and provides an output with the current time, enhancing its versatility for logging and notifications within projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, &ldquo;Hello world docker action,&rdquo; prints a greeting message either &ldquo;Hello World&rdquo; or personalized to any specified name to the console. It automates tasks related to printing greetings and can be used in workflows to notify contributors by displaying their names or welcome messages. The action supports configuration through an input parameter for the person&rsquo;s name and provides an output with the current time, enhancing its versatility for logging and notifications within projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>sarif-kit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/sarif-kit/</link><pubDate>Wed, 05 Aug 2026 14:53:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/sarif-kit/</guid><description>Version updated for https://github.com/sarif-kit/sarif-kit to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The sarif-kit action converts the native output of various scanners and linters into valid SARIF 2.1.0, making them compatible with GitHub Code Scanning. It automates the process of converting tool outputs to SARIF format, which is required for integrating security scans into CI/CD pipelines. The action supports tools like pip-audit, yamllint, and codespell, automatically detecting the correct adapter and providing options for customizing the input and output paths, including rewriting absolute paths as relative ones and handling multiple findings in a single SARIF file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sarif-kit/sarif-kit">https://github.com/sarif-kit/sarif-kit</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sarif-kit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The sarif-kit action converts the native output of various scanners and linters into valid SARIF 2.1.0, making them compatible with GitHub Code Scanning. It automates the process of converting tool outputs to SARIF format, which is required for integrating security scans into CI/CD pipelines. The action supports tools like pip-audit, yamllint, and codespell, automatically detecting the correct adapter and providing options for customizing the input and output paths, including rewriting absolute paths as relative ones and handling multiple findings in a single SARIF file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>sarif-kit converts the native output of pip-audit, yamllint and codespell into SARIF 2.1.0 that GitHub Code Scanning accepts. This first release covers the converter core, the three adapters, the CLI and the GitHub Action.</p>
<p>The CLI has three commands. convert turns a tool&rsquo;s output into SARIF, either with &ndash;tool or with &ndash;auto, which works the adapter out from the shape of the input. validate checks any SARIF file against the official schema. merge combines files while keeping to GitHub&rsquo;s rule of one analysis category per run. Exit codes are 0 for success, 1 for findings under &ndash;fail-on-findings and 2 for errors, and there is a man page.</p>
<p>The action wraps the CLI in a prebuilt container image, ghcr.io/sarif-kit/sarif-kit:0.1.0, so nothing installs Python on your runner. Chain github/codeql-action/upload-sarif to get the alerts into the Security tab.</p>
<p>Passing the schema is not what makes an adapter finished here. Every adapter ships with real captured fixtures and golden tests, and its output has been uploaded to a real repository and read in the Code Scanning UI. <a href="https://github.com/sarif-kit/demo">sarif-kit/demo</a> runs all three tools against a repository broken on purpose, if you want to see the alerts before wiring anything up.</p>
]]></content:encoded></item><item><title>greenbump</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/greenbump/</link><pubDate>Wed, 05 Aug 2026 14:52:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/greenbump/</guid><description>Version updated for https://github.com/shidesheng0218/greenbump to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary greenbump is a tool that automates the process of upgrading dependencies and automatically fixes any code issues introduced by the upgrade. It uses AI to identify and fix the code changes needed after a dependency update, ensuring that the build and tests pass before merging the changes into your main branch.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shidesheng0218/greenbump">https://github.com/shidesheng0218/greenbump</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/greenbump">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>greenbump is a tool that automates the process of upgrading dependencies and automatically fixes any code issues introduced by the upgrade. It uses AI to identify and fix the code changes needed after a dependency update, ensuring that the build and tests pass before merging the changes into your main branch.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>See <a href="https://github.com/shidesheng0218/greenbump/blob/master/CHANGELOG.md">CHANGELOG.md</a> for details.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/shidesheng0218/greenbump/compare/v0.1.0...v0.2.0">https://github.com/shidesheng0218/greenbump/compare/v0.1.0...v0.2.0</a></p>
]]></content:encoded></item><item><title>Harnessie Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/harnessie-verify/</link><pubDate>Wed, 05 Aug 2026 14:50:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/harnessie-verify/</guid><description>Version updated for https://github.com/snapsynapse/harnessie-verify-action to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The harnessie-verify-action claims-by-claim verification of pull requests, automating deterministic checks against actual artifacts and providing a review interface. It solves problems related to ensuring code correctness through automated testing and reduces reliance on untrusted diffs by running verifiers in sandboxed environments. The action is powered by Harnessie and supports OpenAI-compatible endpoints for model inference, ensuring security and compliance with GitHub’s protection mechanisms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snapsynapse/harnessie-verify-action">https://github.com/snapsynapse/harnessie-verify-action</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harnessie-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The harnessie-verify-action claims-by-claim verification of pull requests, automating deterministic checks against actual artifacts and providing a review interface. It solves problems related to ensuring code correctness through automated testing and reduces reliance on untrusted diffs by running verifiers in sandboxed environments. The action is powered by Harnessie and supports OpenAI-compatible endpoints for model inference, ensuring security and compliance with GitHub&rsquo;s protection mechanisms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="what-changed">What changed</h2>
<ul>
<li>Pins the Action&rsquo;s tested default to the released <code>harnessie==0.8.0</code> package.</li>
<li>Preserves every public input, output, and fail-closed verdict mapping.</li>
<li>Extracts the <code>pull_request_target</code> refusal into one guard shared by runtime and CI.</li>
<li>Replaces the previously unreachable conditional refusal job with executable unsafe-trigger and safe-trigger cases.</li>
<li>Links this adapter&rsquo;s ownership and release boundary to Harnessie&rsquo;s federated ecosystem contract.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li>Pull request CI: all four Ubuntu jobs passed, including FAILED, CANNOT_VERIFY fail-closed, CANNOT_VERIFY advisory, and unsafe-trigger refusal.</li>
<li>Exact merge commit CI: all four jobs passed at <code>7d22949b3feb86f9dd7c00634bb40a48987a1943</code>.</li>
<li>Public package smoke: an isolated install reported Harnessie 0.8.0; metadata, import, sandbox probe, and CLI help passed.</li>
<li>Local Action/YAML contract checks, shell syntax, trigger-guard adversarial cases, and <code>git diff --check</code> passed.</li>
</ul>
<h2 id="residuals">Residuals</h2>
<ul>
<li>A VERIFIED verdict still requires the consuming repository&rsquo;s configured verifier endpoint and key. Release CI remains intentionally offline through the mock provider.</li>
<li>Local deterministic-check replication on macOS failed closed because the GitHub Action&rsquo;s bubblewrap setup is Linux-specific. Ubuntu release CI is the executable matrix for check-result mappings.</li>
<li>GitHub currently forces <code>actions/checkout@v4</code> onto Node 24 and emits its Node 20 deprecation warning. All release jobs pass; updating that upstream CI dependency is separate maintenance.</li>
</ul>
<p>Exact version: <code>snapsynapse/harnessie-verify-action@v0.1.1</code></p>
<p>Stable major after promotion: <code>snapsynapse/harnessie-verify-action@v0</code></p>
]]></content:encoded></item><item><title>Run Godlint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/run-godlint/</link><pubDate>Wed, 05 Aug 2026 14:49:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/run-godlint/</guid><description>Version updated for https://github.com/tomerwave/godlint to version v0.6.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Godlint is an executable engineering constitution tool that automates code quality checks across various programming languages. It ensures that all contributors adhere to defined rules and boundaries, promoting a consistent architecture and enforcing policies locally and in CI.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tomerwave/godlint">https://github.com/tomerwave/godlint</a></strong> to version <strong>v0.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-godlint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Godlint is an executable engineering constitution tool that automates code quality checks across various programming languages. It ensures that all contributors adhere to defined rules and boundaries, promoting a consistent architecture and enforcing policies locally and in CI.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>architecture/filename-case</code> now ignores framework-required dynamic route filenames beginning with
<code>[name]</code>, <code>[...name]</code> or <code>[[...name]]</code>. Astro and Next.js use those segments as routing syntax, so
renaming them changes the route rather than correcting a convention. Malformed bracketed names remain
findings.</li>
</ul>
]]></content:encoded></item><item><title>Modern Pterodactyl Power</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/modern-pterodactyl-power/</link><pubDate>Wed, 05 Aug 2026 14:48:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/modern-pterodactyl-power/</guid><description>Version updated for https://github.com/tooobiiii/modern-pterodactyl-power to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Modern Pterodactyl Power GitHub Action sends power signals (start, stop, restart, or kill) to servers on a Pterodactyl panel, automating server management tasks. It targets the client API power endpoint and runs on Node.js 24 without additional dependencies. The action supports sending restart commands and provides outputs for the signal and state of the server after delivery.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tooobiiii/modern-pterodactyl-power">https://github.com/tooobiiii/modern-pterodactyl-power</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/modern-pterodactyl-power">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Modern Pterodactyl Power GitHub Action sends power signals (<code>start</code>, <code>stop</code>, <code>restart</code>, or <code>kill</code>) to servers on a Pterodactyl panel, automating server management tasks. It targets the client API power endpoint and runs on Node.js 24 without additional dependencies. The action supports sending restart commands and provides outputs for the signal and state of the server after delivery.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Check the readme</p>
]]></content:encoded></item><item><title>aicheck-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/aicheck-scan/</link><pubDate>Wed, 05 Aug 2026 14:47:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/aicheck-scan/</guid><description>Version updated for https://github.com/unauthdev/aicheck-scan to version v1.2.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, aicheck, scans your AI infrastructure to detect unauthenticated services, ensuring security in CI/CD pipelines. It supports multiple deployment options including pip CLI, GitHub Actions, Docker containers, and a web interface. The action automatically checks for AI services without authentication and can fail the build if such services are detected.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/unauthdev/aicheck-scan">https://github.com/unauthdev/aicheck-scan</a></strong> to version <strong>v1.2.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aicheck-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>aicheck</code>, scans your AI infrastructure to detect unauthenticated services, ensuring security in CI/CD pipelines. It supports multiple deployment options including pip CLI, GitHub Actions, Docker containers, and a web interface. The action automatically checks for AI services without authentication and can fail the build if such services are detected.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Auth-state granularity: findings (no-auth, graded), observations (auth-present, INFO, never graded), unknown (partial probe coverage, surfaced). Wired for Ollama, vLLM, Jupyter, Ray, Qdrant, Milvus, ComfyUI, Gradio, n8n, Open WebUI. Also: hardened fingerprints (validated against ~1,100 real banners), structured CVE fields, Milvus + Attu checker, drift-honest inventory, schema_version 1, HMAC webhooks. SHA256 sums are appended below by the publish workflow.</p>
<h2 id="sha256">SHA256</h2>
<pre tabindex="0"><code>2f8b50a16b5f1233b26a2b3fffe1d5aa7e4d773831c1e21b9941009a6bf3bbdf  aicheck_scan-1.2.4.tar.gz
3dad337ea530cce33d185c24a74c32227d8d3597f6bdf921dedbca069f739ade  aicheck_scan-1.2.4-py3-none-any.whl
</code></pre>]]></content:encoded></item><item><title>Commit via GitHub API</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/commit-via-github-api/</link><pubDate>Wed, 05 Aug 2026 14:46:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/commit-via-github-api/</guid><description>Version updated for https://github.com/vig-os/commit-action to version v0.3.2.
This action is used across all versions by 7 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Commit Action is a GitHub Action that automates the process of committing changes to a repository using the GitHub API, creating signed commits and bypassing branch protection rulesets. It supports modular design, type safety, comprehensive testing, and efficient handling of text files with fewer REST calls. Users can use it as a standalone action or as a CLI script, with customizable options for commit messages, file paths, and retry settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vig-os/commit-action">https://github.com/vig-os/commit-action</a></strong> to version <strong>v0.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/commit-via-github-api">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Commit Action is a GitHub Action that automates the process of committing changes to a repository using the GitHub API, creating signed commits and bypassing branch protection rulesets. It supports modular design, type safety, comprehensive testing, and efficient handling of text files with fewer REST calls. Users can use it as a standalone action or as a CLI script, with customizable options for commit messages, file paths, and retry settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>No changelog notes found for 0.3.2</p>
]]></content:encoded></item><item><title>Sync Issues and PRs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/sync-issues-and-prs/</link><pubDate>Wed, 05 Aug 2026 14:44:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/sync-issues-and-prs/</guid><description>Version updated for https://github.com/vig-os/sync-issues-action to version v0.4.1.
This action is used across all versions by 9 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action synchronizes all issues and pull requests from a repository to markdown files, preserving metadata such as labels, dates, authors, and relationships. It supports syncing closed issues/PRs, filtering by issue/PR numbers or ranges, and using options like custom formatting commands and attachment downloading. The action provides outputs for the number of synced items, last sync timestamp, modified file paths, and GitHub tokens used during execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vig-os/sync-issues-action">https://github.com/vig-os/sync-issues-action</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>9</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sync-issues-and-prs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action synchronizes all issues and pull requests from a repository to markdown files, preserving metadata such as labels, dates, authors, and relationships. It supports syncing closed issues/PRs, filtering by issue/PR numbers or ranges, and using options like custom formatting commands and attachment downloading. The action provides outputs for the number of synced items, last sync timestamp, modified file paths, and GitHub tokens used during execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>No changelog notes found for 0.4.1</p>
]]></content:encoded></item><item><title>install spaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/install-spaces/</link><pubDate>Wed, 05 Aug 2026 14:43:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/install-spaces/</guid><description>Version updated for https://github.com/work-spaces/install-spaces to version v0.20.3.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The install-spaces GitHub Action automates the installation of Spaces, a cloud-based platform for managing large-scale data processing tasks. It simplifies the process by providing a streamlined way to set up Spaces on your Github Actions workflows, reducing deployment time and streamlining development processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/install-spaces">https://github.com/work-spaces/install-spaces</a></strong> to version <strong>v0.20.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-spaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>install-spaces</code> GitHub Action automates the installation of Spaces, a cloud-based platform for managing large-scale data processing tasks. It simplifies the process by providing a streamlined way to set up Spaces on your Github Actions workflows, reducing deployment time and streamlining development processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.20.3 by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/40">https://github.com/work-spaces/install-spaces/pull/40</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/install-spaces/compare/v0.20.1...v0.20.3">https://github.com/work-spaces/install-spaces/compare/v0.20.1...v0.20.3</a></p>
]]></content:encoded></item><item><title>Legion Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/legion-runner/</link><pubDate>Wed, 05 Aug 2026 14:43:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/legion-runner/</guid><description>Version updated for https://github.com/Wraith-security/Legion_runner to version v1.0.57.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Legion Runner is an open-source GitHub Action that strengthens CI security by monitoring and blocking outbound connections from jobs. It records connection details, names processes, and checks for file tampering, enhancing defense against supply chain attacks without leaving the runner environment. The action uses Rust for its core components and can be integrated into any job, including hosted runners.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Wraith-security/Legion_runner">https://github.com/Wraith-security/Legion_runner</a></strong> to version <strong>v1.0.57</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/legion-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Legion Runner is an open-source GitHub Action that strengthens CI security by monitoring and blocking outbound connections from jobs. It records connection details, names processes, and checks for file tampering, enhancing defense against supply chain attacks without leaving the runner environment. The action uses Rust for its core components and can be integrated into any job, including hosted runners.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Curated egress presets (<code>allowed-presets</code>)</strong>: opt-in per-ecosystem allowlists
(npm, yarn, pnpm, pip, pypi, cargo, rust, go, maven, gradle, nuget, apt, debian,
docker) so block mode &ldquo;just works&rdquo; for common toolchains without hand-listing
endpoints. e.g. <code>allowed-presets: &quot;cargo, apt&quot;</code>. Unit-tested.</li>
<li><strong>Download integrity verification</strong>: the action verifies the <code>legionr-bpf</code> /
<code>legionr-fim</code> release binaries against a <code>.sha256</code> sidecar before running them
(the release now attaches the checksums), and <strong>fails closed</strong> — an
unverified/corrupted/tampered download is rejected and the action degrades
instead of executing it.</li>
<li><strong><code>learned-baseline</code> input</strong> (default <code>true</code>): in block mode, also allow
destinations previously learned into the Actions cache. Set <code>false</code> to enforce
ONLY the explicit allowlist (inline + policy-file + GitHub) with no cache
read/write — used by the enforce self-test for deterministic deny.</li>
<li><strong>File-integrity / tamper detection (Rust <code>legionr-fim</code> agent)</strong>: snapshots
high-value tamper targets at job start (credential/config files, <code>.git</code>
config + hooks, and checked-out source) and diffs them at job end, surfacing
anything overwritten, deleted, or chmod&rsquo;d in the summary. Only sha256 hashes
are stored — never contents. New inputs <code>file-integrity</code> (auto|off) and
<code>fim-extra-paths</code>. <code>file-integrity: auto</code> downloads the agent from the latest
release (plain stable Rust, no eBPF toolchain) and degrades to a silent skip
if unavailable. Logic lives in <code>legionr-core::fim</code> (unit-tested); the binary
is a release asset like <code>legionr-bpf</code>, built + attached by <code>release.yml</code>.</li>
<li><strong>Package repositories roll-up (<code>📦</code>)</strong>: the summary now classifies named
outbound destinations into their ecosystem/registry (npm, PyPI, crates.io,
apt, Docker, Go, NuGet, Maven, Gradle, RubyGems, Alpine, GitHub) and shows a
<strong>Package repositories reached</strong> table — registry, ecosystem, connections, and
the process that reached each. Supply-chain risk hides in <em>which</em> registries a
build talks to, so we surface them directly instead of leaving you to read
IPs. Bare IPs that never got a forward name get a coarse CDN/provider hint
(Fastly/Cloudflare/GitHub) via CIDR match — honest about ambiguity (a shared
CDN can&rsquo;t name a registry). Logic in <code>action/repos.js</code>, fully unit-tested.</li>
<li><strong>Combined cross-job egress report (one summary for the whole run)</strong>: GitHub
has no run-level summary, so each job emits its captured egress as a JSON
artifact (<code>node action/report.js emit</code>) and a final <code>egress-report</code> job merges
them into a SINGLE table — which job + process reached what — with a package
repositories roll-up and a per-job diagnostics block (<code>render</code>). Wired into CI;
<code>render</code> is pure and unit-tested. Pairs with <code>job-summary: false</code> so the run
shows one combined summary instead of one table per job.</li>
<li><strong><code>job-summary</code> input</strong> (default <code>true</code>): set <code>false</code> to keep monitoring and
enforcement fully active but suppress the connections table in the job summary.
Useful when many jobs in one workflow each run the action and you only want the
table once (our own CI uses it so a run shows one table, not one per job).</li>
<li><strong>Secure diagnostics line</strong> in the summary: reports which resolution path
actually fired (<code>forwarder on/off · captured DNS records N · getaddrinfo route … · named X/Y destinations</code>) so a run that comes back as bare IPs is triagable.
Secure by construction — only booleans, counts, and a fixed enum; never the
upstream resolver IP, file paths, captured hostnames, or env values.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>The live e2e tier is out of CI.</strong> <code>.github/workflows/e2e.yml</code> now runs only
the credential-free <code>local</code> job. The removed <code>live</code> job registered a runner
against a fixed external scope that this org cannot install the App on, so it
could only skip silently or fail noisily, and neither outcome said anything
about the runner. <code>scripts/e2e.sh --mode live</code> still works and can be pointed
at any scope you control, but the scope is now mandatory (<code>--scope owner/repo</code>
or <code>E2E_SCOPE</code>) instead of defaulting to a hardcoded constant: the harness
will not guess a target it registers a real runner against. The <code>local</code> tier
falls back to <code>$GITHUB_REPOSITORY</code> since it provisions with <code>--no-probe</code> and
never reaches GitHub.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>FIM hashing builds against <code>sha2</code> 0.11.</strong> The digest type changed to
<code>hybrid_array::Array</code>, which does not implement <code>LowerHex</code>, so
<code>format!(&quot;{:x}&quot;, ..)</code> in <code>fim::hash_file</code> stopped compiling. The digest is now
hex-encoded byte by byte, which works on both 0.10 and 0.11. Two tests pin the
behaviour: the exact sha256 of <code>abc</code>, and a 64-char length/charset assertion so
a dropped leading zero cannot pass silently. Unblocks the <code>cargo-major</code>
dependency group (<code>sha2</code> 0.10.9 to 0.11.0, <code>thiserror</code> 1 to 2.0.18).</li>
<li><strong>Block mode no longer hangs the runner at teardown.</strong> <code>applyEgressBlock</code>
installed a default-deny <code>LEGION_EGRESS</code> chain in <code>OUTPUT</code> and nothing ever
removed it, so the runner&rsquo;s own completion call (to rotating GitHub-backend IPs
not in the static seed) was dropped and the job spun until timeout. <code>post()</code>
now tears the firewall down (<code>removeEgressBlock</code>).</li>
<li><strong>Runner hang from leaked daemons.</strong> The post step left privileged background
processes alive — eBPF agent, DNS forwarder — and the <code>/proc</code> monitor could
wedge in a blocking <code>ss</code> subprocess. The monitor now reads <code>/proc/net/tcp</code>
directly (no subprocess); daemons are reliably reaped.</li>
<li><strong>No more spurious &ldquo;could not resolve&rdquo; annotations.</strong> Allowlist entries that
are wildcard parents with no A record of their own (e.g. <code>blob.core.windows.net</code>,
<code>actions.githubusercontent.com</code>) used to emit one CI <strong>warning annotation</strong>
each on every run. They are benign: the action skips them, and their subdomains
are still observed via PTR / DNS capture (and opened just-in-time in block
mode). They are now collected into a single plain-text log line instead.</li>
<li><strong>Docs/labels</strong>: the eBPF mechanism is a <strong>tracepoint on <code>sys_enter_connect</code></strong>
(not a &ldquo;kprobe on tcp_connect&rdquo;); the sampler is <code>/proc</code>-only (the &ldquo;ss&rdquo; fallback
was removed). Corrected the runtime log line, summary label, and README.</li>
<li><strong>Outbound connections showed as bare IPs when systemd-resolved owns
<code>getaddrinfo</code>.</strong> The <code>nsswitch</code> reroute didn&rsquo;t always stick, so package-repo
lookups bypassed the capture forwarder and were never named. The forwarder now
targets the <em>real</em> upstream (systemd-resolved&rsquo;s actual servers, not the
<code>127.0.0.53</code> stub), and when the bypass is detected but the nsswitch reroute
fails, Legion redirects systemd-resolved itself at the forwarder via a
<code>resolved.conf.d</code> drop-in — <strong>verify-or-revert</strong> and restored on teardown, so
it never breaks the job&rsquo;s DNS.</li>
<li><strong>IPv4-mapped IPv6 destinations rendered as long expanded addresses</strong>
(<code>0000:0000:0000:0000:0000:ffff:HHHH:HHHH</code>) in the summary. The <code>/proc</code> sampler
emitted the expanded form while <code>normalizeIp</code> only collapsed the compressed
<code>::ffff:</code> form. Both now collapse to dotted IPv4 (and the v4/v6 tables dedupe).
(Shipped in v1.0.35.)</li>
<li>Removed dead <code>action/baseline.js</code>; pinned <code>release.yml</code> checkout to v6.</li>
</ul>
<h3 id="reliability">Reliability</h3>
<ul>
<li><strong>Tests for the paths that kept breaking</strong>: the firewall rule builders
(<code>egressBlockRules</code>/<code>egressUnblockRules</code> — order, DNS-allow, DROP-last,
OUTPUT-jump-removed-first), the checksum parser, the curated presets, and a
<strong>full-stack PR gate</strong> that runs block + DNS-capture + eBPF and asserts the
job finalizes (catches any teardown-hang regression), plus the package-repo
classifier (host-suffix + CIDR matching). Action test count 19 → 37.</li>
</ul>
<h3 id="changed-1">Changed</h3>
<ul>
<li>Removed em-dashes from the job-summary output (headers, the unresolved-host
note, the enforce hint, and empty-cell placeholders) for plainer rendering.</li>
<li><strong>Name more destinations</strong>: route glibc <code>getaddrinfo</code> (curl/apt/cargo/git)
through the DNS-capture forwarder via an <code>nsswitch.conf</code> reroute, so hosts
resolved by systemd-resolved (which ignores <code>resolv.conf</code>) are now captured
and named — not just <code>resolv.conf</code>/c-ares callers. Health-checked and restored
on teardown. (A connection to a hard-coded IP with no PTR still shows the IP —
there is no name to resolve.)</li>
<li>More accurate &ldquo;unresolved destination&rdquo; note in the summary (a name may have
been resolved outside the capture path, vs. a genuine raw-IP connection).</li>
<li><strong>We dogfood our own action.</strong> Every real-work job in this repo (CI, release,
eBPF agent, FIM self-test) now runs Legion Runner as its first step (<code>@v1</code>,
audit) — our CI is hardened by the product it ships.</li>
<li><strong>Docs-only PRs skip the build/test matrix</strong> (and the release it gates) via
<code>paths-ignore</code>; a <code>docs-passthrough</code> workflow reports the same check names
green so required checks stay satisfied and README edits stay mergeable
without burning CI minutes.</li>
<li><strong>Our CI now captures names.</strong> The dogfooded harden steps run with
<code>dns-capture: true</code> (still <code>audit</code> — monitor, don&rsquo;t firewall), so job summaries
show real destination and package-repository names instead of bare IPs, and the
capture path is exercised on every run. Safe now that <code>@v1</code> (&gt;= 1.0.35) carries
the teardown + systemd-resolved fixes.</li>
</ul>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/b.ia-accessibility-checker/</link><pubDate>Wed, 05 Aug 2026 14:42:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks during CI/CD pipelines, allowing companies to ensure their code meets WCAG guidelines for specific audiences. It uses AI to map and measure guidelines against these audience groups, enabling developers to focus on meeting the most critical requirements effectively.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks during CI/CD pipelines, allowing companies to ensure their code meets WCAG guidelines for specific audiences. It uses AI to map and measure guidelines against these audience groups, enabling developers to focus on meeting the most critical requirements effectively.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>vibecheck-ai-slop</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/vibecheck-ai-slop/</link><pubDate>Wed, 05 Aug 2026 14:41:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/vibecheck-ai-slop/</guid><description>Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.17.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary vibecheck is a tool that automates static code analysis to catch AI-generated code smells, such as hard-coded secrets, empty catch blocks, and SQL query concatenation. It provides over 40 rules to detect common issues in AI-generated codebases. The action runs locally and is zero-config, requiring no installation or API keys. It supports macOS, Linux, and standalone binaries for Python developers and can be run directly from the command line without Node.js or npm.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuvrajangadsingh/vibecheck">https://github.com/yuvrajangadsingh/vibecheck</a></strong> to version <strong>v1.17.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibecheck-ai-slop">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>vibecheck is a tool that automates static code analysis to catch AI-generated code smells, such as hard-coded secrets, empty catch blocks, and SQL query concatenation. It provides over 40 rules to detect common issues in AI-generated codebases. The action runs locally and is zero-config, requiring no installation or API keys. It supports macOS, Linux, and standalone binaries for Python developers and can be run directly from the command line without Node.js or npm.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch for a real defect in v1.17.0, found by dogfooding and a Codex review pass. <strong>If you use the slop score, upgrade.</strong></p>
<h2 id="the-score-was-flattering-in-diff-mode">The score was flattering in diff mode</h2>
<p>The score is findings per KLOC of a whole codebase. With <code>--diff</code> only changed lines are scanned, and the 1 KLOC floor then divides those findings by 1000.</p>
<p>I added an <code>eval()</code> and a <code>console.log</code> to this repo, making it strictly worse:</p>
<table>
  <thead>
      <tr>
          <th>mode</th>
          <th>score</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>--diff --score</code></td>
          <td><strong>69 (B)</strong></td>
      </tr>
      <tr>
          <td>full scan</td>
          <td><strong>46 (C)</strong></td>
      </tr>
  </tbody>
</table>
<p>The diff-scoped number is <em>better</em>, on a change that made the code worse. A gate like <code>--diff --min-score 60</code> would have passed a commit adding <code>eval()</code> that the full codebase fails.</p>
<p><code>--score</code>, <code>--min-score</code> and <code>--badge</code> now refuse to run with <code>--diff</code>, <code>--staged</code> or <code>--diff-stdin</code>. Use <code>--fail-on</code> and <code>--max-warnings</code> for pull requests, <code>--min-score</code> for the codebase.</p>
<p>Also closes a second hole: the empty-changeset early return ran before the score was computed, so <code>--diff --badge x.svg</code> silently wrote no file and exited 0.</p>
<h2 id="the-v1170-guard-test-was-weaker-than-i-said">The v1.17.0 guard test was weaker than I said</h2>
<p>I claimed it made recalibrating D50 without moving the bands fail the build. It didn&rsquo;t. Codex showed it still passed when D50 moved 30 → 20, and when C&rsquo;s floor moved 40 → 50.</p>
<p>It now asserts the actual design claim, that C spans the corpus interquartile range:</p>
<table>
  <thead>
      <tr>
          <th>mutation</th>
          <th>v1.17.0 test</th>
          <th>v1.17.1 test</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>D50 30 → 20</td>
          <td>passed</td>
          <td><strong>fails</strong></td>
      </tr>
      <tr>
          <td>C floor 40 → 50</td>
          <td>passed</td>
          <td><strong>fails</strong></td>
      </tr>
      <tr>
          <td>revert to 90=A bands</td>
          <td>fails</td>
          <td>fails</td>
      </tr>
  </tbody>
</table>
<h2 id="computescore-guarded">computeScore guarded</h2>
<p>It&rsquo;s exported. <code>computeScore([warn], undefined)</code> returned <code>NaN</code> graded F; <code>computeScore([warn], 1000, -30)</code> returned <code>107</code> graded A. Now clamped. Not reachable from the CLI.</p>
<p>376 tests, up from 373.</p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/neurolink-ai/</link><pubDate>Wed, 05 Aug 2026 06:30:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v10.8.18.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that unifies 30+ AI providers and models under one consistent API. It provides a practical, TypeScript-first way to integrate AI into any application with features like switchable providers, built-in tools, enterprise memory, failover, automatic cost optimization, and support for various AI modalities. The platform also offers quick setup instructions and a vision for the future of AI architectures.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v10.8.18</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is a universal AI integration platform that unifies 30+ AI providers and models under one consistent API. It provides a practical, TypeScript-first way to integrate AI into any application with features like switchable providers, built-in tools, enterprise memory, failover, automatic cost optimization, and support for various AI modalities. The platform also offers quick setup instructions and a vision for the future of AI architectures.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="10818-2026-08-04"><a href="https://github.com/juspay/neurolink/compare/v10.8.17...v10.8.18">10.8.18</a> (2026-08-04)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(proxy):</strong>  let a ModelPool fail over when one member&rsquo;s model is missing (<a href="https://github.com/juspay/neurolink/commit/8ae086b13b4c53cd9242fc15bf93f25b01aa10c1">8ae086b</a>), closes <a href="https://github.com/juspay/member/issues/2">member#2</a></li>
</ul>
]]></content:encoded></item><item><title>AI ReviewBot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/ai-reviewbot/</link><pubDate>Wed, 05 Aug 2026 06:30:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/ai-reviewbot/</guid><description>Version updated for https://github.com/KonstZiv/ai-code-reviewer to version v1.0.0b13.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI ReviewBot is a GitHub Action that uses AI to provide intelligent code review feedback directly within pull requests and merge requests. It analyzes your repository’s code, identifies vulnerabilities, provides inline suggestions, and highlights good practices. The action automatically discovers the project’s languages, frameworks, and CI pipeline to avoid duplication of feedback. You can customize its behavior with environment variables such as discovery settings and API keys for AI providers like Google Gemini or Mistral.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/KonstZiv/ai-code-reviewer">https://github.com/KonstZiv/ai-code-reviewer</a></strong> to version <strong>v1.0.0b13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-reviewbot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI ReviewBot is a GitHub Action that uses AI to provide intelligent code review feedback directly within pull requests and merge requests. It analyzes your repository&rsquo;s code, identifies vulnerabilities, provides inline suggestions, and highlights good practices. The action automatically discovers the project&rsquo;s languages, frameworks, and CI pipeline to avoid duplication of feedback. You can customize its behavior with environment variables such as discovery settings and API keys for AI providers like Google Gemini or Mistral.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release 1.0.0b13</p>
]]></content:encoded></item><item><title>datamodel-code-generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/datamodel-code-generator/</link><pubDate>Wed, 05 Aug 2026 06:28:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/datamodel-code-generator/</guid><description>Version updated for https://github.com/koxudaxi/datamodel-code-generator to version 0.72.1.
This action is used across all versions by 3,412 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The datamodel-code-generator GitHub Action generates Python data models from various schema definitions, supporting OpenAPI 3, AsyncAPI, JSON Schema, Apache Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, and MCP tool schemas. It can also convert existing Python types (Pydantic, dataclass, TypedDict) into different output types. The action handles complex schemas with features like $ref, allOf, oneOf, anyOf, enums, and nested types.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/koxudaxi/datamodel-code-generator">https://github.com/koxudaxi/datamodel-code-generator</a></strong> to version <strong>0.72.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3,412</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/datamodel-code-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>datamodel-code-generator</code> GitHub Action generates Python data models from various schema definitions, supporting OpenAPI 3, AsyncAPI, JSON Schema, Apache Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, and MCP tool schemas. It can also convert existing Python types (Pydantic, dataclass, TypedDict) into different output types. The action handles complex schemas with features like <code>$ref</code>, <code>allOf</code>, <code>oneOf</code>, <code>anyOf</code>, enums, and nested types.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add TypedDict total=False option by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3689">https://github.com/koxudaxi/datamodel-code-generator/pull/3689</a></li>
<li>Update CHANGELOG for 0.72.0 by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3690">https://github.com/koxudaxi/datamodel-code-generator/pull/3690</a></li>
<li>Support import overrides by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3691">https://github.com/koxudaxi/datamodel-code-generator/pull/3691</a></li>
<li>Update release benchmark data by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3692">https://github.com/koxudaxi/datamodel-code-generator/pull/3692</a></li>
<li>Resolve Python type imports by target by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3694">https://github.com/koxudaxi/datamodel-code-generator/pull/3694</a></li>
<li>Support TypeAliasType for non-Pydantic output by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3688">https://github.com/koxudaxi/datamodel-code-generator/pull/3688</a></li>
<li>Bind Python type imports by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3696">https://github.com/koxudaxi/datamodel-code-generator/pull/3696</a></li>
<li>Structure input model runtime types by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3693">https://github.com/koxudaxi/datamodel-code-generator/pull/3693</a></li>
<li>Fix &ndash;use-exact-imports for dotted ancestor package case by @bokshitsky in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3697">https://github.com/koxudaxi/datamodel-code-generator/pull/3697</a></li>
<li>Embed package version at build time by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3699">https://github.com/koxudaxi/datamodel-code-generator/pull/3699</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@bokshitsky made their first contribution in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3697">https://github.com/koxudaxi/datamodel-code-generator/pull/3697</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/koxudaxi/datamodel-code-generator/compare/0.72.0...0.72.1">https://github.com/koxudaxi/datamodel-code-generator/compare/0.72.0...0.72.1</a></p>
]]></content:encoded></item><item><title>Slackalaka</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/slackalaka/</link><pubDate>Wed, 05 Aug 2026 06:27:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/slackalaka/</guid><description>Version updated for https://github.com/mallowigi/tag-n-slack to version 0.2.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action tag-n-slack creates a new tag with a changelog from either CHANGELOG.md or the latest commit hash and message. It automates the creation of release tags, notifies Slack about the release, and includes optional ticket information in the notification. The key capabilities include version retrieval strategies, slack notification customization, and ticket configuration options.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mallowigi/tag-n-slack">https://github.com/mallowigi/tag-n-slack</a></strong> to version <strong>0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/slackalaka">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>tag-n-slack</code> creates a new tag with a changelog from either <code>CHANGELOG.md</code> or the latest commit hash and message. It automates the creation of release tags, notifies Slack about the release, and includes optional ticket information in the notification. The key capabilities include version retrieval strategies, slack notification customization, and ticket configuration options.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Truncate changelog content before subversion headers during parsing (4cba572)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (d48462d)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (e8cca16)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (0998ab2)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (74b7ec6)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (995b49e)</li>
<li>Add watch mode and enhance error handling for <code>findPackageJson</code> (58f570c)</li>
<li>Add watch mode and enhance error handling for <code>findPackageJson</code> (0a6a3ea)</li>
<li>Add watch mode and enhance error handling for <code>findPackageJson</code> (d616c7f)</li>
<li>Migrate codebase and dependencies to ES modules. (bd554c2)</li>
</ul>
]]></content:encoded></item><item><title>Brew Bumper</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/brew-bumper/</link><pubDate>Wed, 05 Aug 2026 06:26:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/brew-bumper/</guid><description>Version updated for https://github.com/mattmc3/brew-bumper to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Brew Bumper is a GitHub Action that automatically updates Homebrew formula versions and SHA-256 checksums in your tap. It runs on a schedule or manual trigger, resolving the latest tag for each formula, downloading the artifact, and rewriting the file in place. The action supports pinning specific formulas, excluding certain formulas, and handling different release patterns to ensure only relevant updates are made.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mattmc3/brew-bumper">https://github.com/mattmc3/brew-bumper</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/brew-bumper">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Brew Bumper is a GitHub Action that automatically updates Homebrew formula versions and SHA-256 checksums in your tap. It runs on a schedule or manual trigger, resolving the latest tag for each formula, downloading the artifact, and rewriting the file in place. The action supports pinning specific formulas, excluding certain formulas, and handling different release patterns to ensure only relevant updates are made.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="102---2026-08-04">[1.0.2] - 2026-08-04</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>release-pattern</code> and <code>exclude-pattern</code> inputs.</strong> A tag counts as a release when it fully matches
<code>release-pattern</code>, which defaults to <code>v?\d+(\.\d+)*</code>. <code>exclude-pattern</code> then drops any tag that
matched, one unanchored regex per line, so rules stack one at a time instead of growing into an
alternation. Projects that tag another way opt in by widening the pattern, including those that
ship nothing but prereleases.</li>
<li><strong>Prebuilt-binary formulas with more than one architecture.</strong> Every arch block gets its own
artifact downloaded and its own checksum rewritten, so <code>on_arm</code> beside <code>on_intel</code> means two
downloads and two new checksums. Blocks nested inside <code>on_macos</code> or <code>on_linux</code> count too.</li>
<li><strong><code>recheck</code> input.</strong> Re-downloads the assets and rewrites any checksum that no longer matches, even
when the version is already current. Off by default, since it costs a download per asset per run.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Tag selection is a pattern you supply rather than a set of built-in heuristics.</strong> The digit test,
the prerelease word list and the fallback to whatever GitHub called the latest release are gone.
A repo with no matching tag is skipped rather than guessed at.</li>
<li><strong>A formula&rsquo;s repo falls back to its download <code>url</code></strong> when <code>homepage</code> points at a project site
instead of the repo.</li>
<li><strong>The tag scan warns when it stops at its page cap</strong>, rather than reporting the newest tag it
happened to see as the newest tag there is.</li>
<li><strong>The <code>updated</code> output reports every asset, which changes its shape.</strong> Entries are now
<code>{formula, version, assets}</code>, where each asset is <code>{path, url, sha256}</code>. The old
<code>{formula, version, url, sha256}</code> carried one url and one checksum, so a two-arch formula
published half of what it had written. Anything reading <code>.url</code> or <code>.sha256</code> off an entry needs to
read <code>.assets</code> instead.</li>
</ul>
<h3 id="removed">Removed</h3>
<ul>
<li><strong><code>prerelease-markers</code> input</strong>, replaced by <code>release-pattern</code> and <code>exclude-pattern</code>. Anyone setting
it needs to move to the new inputs. It shipped and was removed the same day, before anything
depended on it.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Parenthesized stanzas are read.</strong> Calls like <code>url(&quot;...&quot;)</code>, <code>version(&quot;...&quot;)</code> and <code>sha256(&quot;...&quot;)</code>
used to be invisible and could make a formula read as head-only.</li>
<li><strong>Binary urls with extra interpolation are refused.</strong> After <code>#{version}</code> is replaced, any leftover
interpolation now fails before download instead of reporting a nonsense url.</li>
<li><strong>A lone plain source url must already be a GitHub tag archive.</strong> Other plain urls are refused
instead of silently becoming <code>github.com/&lt;repo&gt;/archive/refs/tags/&lt;tag&gt;.tar.gz</code>.</li>
<li><strong>GitHub repo detection requires the exact <code>github.com</code> host.</strong> Lookalike hosts no longer count,
and fallback release urls still derive the repo from their first two path segments.</li>
<li><strong>Duplicate stanza keys are disambiguated consistently.</strong> Duplicate arch paths now get distinct
checksums instead of tripping the edit guard.</li>
<li><strong>A <code>url</code> templated with <code>#{version}</code> no longer needs an arch block.</strong> A formula naming a single
artifact at the top level, with no <code>on_arm</code> or <code>on_intel</code>, was refused outright. The mirror case,
a plain top-level url sitting beside an arch block, is now refused rather than bumping the plain
one and leaving the arch checksum stale.</li>
<li><strong>A second architecture no longer keeps its old checksum.</strong> A formula with an <code>on_intel</code> block had
its <code>version</code> and <code>on_arm</code> checksum bumped while <code>on_intel</code> kept the stale one, producing a formula
that installed on one architecture and failed verification on the other, silently. Run with
<code>recheck</code> to repair a formula already in that state.</li>
<li><strong><code>on_arm</code> nested inside <code>on_macos</code> is found.</strong> It used to read as head-only and was never bumped.</li>
<li><strong>A <code>patch</code> or <code>livecheck</code> url is no longer mistaken for the formula&rsquo;s own.</strong> A patch&rsquo;s <code>sha256</code>
could be overwritten with a release checksum, and a <code>livecheck</code> url stopped a head-only formula
from being skipped.</li>
<li><strong>Single-quoted stanza values are read.</strong> <code>url '...'</code> used to vanish, and an invisible url reads as
head-only.</li>
<li><strong>A url that cannot be read fails the formula instead of passing as head-only</strong>, naming the block it
is in. &ldquo;Nothing to bump&rdquo; and &ldquo;I could not read this file&rdquo; were the same answer, which is how
several of these bugs stayed hidden.</li>
<li><strong>A binary url that hardcodes its version is refused.</strong> Without <code>#{version}</code> in the url there is
nowhere to put the new version, so the old asset was hashed and filed under the new one.</li>
<li><strong>Committing no longer writes a git identity into your repo.</strong> <code>github-actions[bot]</code> was written
into <code>.git/config</code> and overrode an identity you had already set. It is now passed for the commit
alone, and only when the repo has none of its own.</li>
<li><strong><code>GITHUB_OUTPUT</code> uses a random heredoc delimiter</strong>, so a value containing the old fixed one cannot
close the block early.</li>
<li><strong><code>changed</code> and <code>updated</code> are set on every exit.</strong> A run that gave up early, on a missing formula
directory, an unknown formula name, or an invalid pattern, wrote no outputs at all, so a step
reading <code>steps.bump.outputs.changed</code> got an empty string rather than <code>&quot;false&quot;</code>.</li>
</ul>
<h3 id="security">Security</h3>
<ul>
<li><strong>The API token is attached by exact host match.</strong> It was decided by string prefix, so a host like
<code>api.github.com.example</code> would have received it. For binary formulas the download url comes from
the formula file, so a tap could steer a token-bearing request off-host.</li>
</ul>
]]></content:encoded></item><item><title>postmortem supply-chain gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/postmortem-supply-chain-gate/</link><pubDate>Wed, 05 Aug 2026 06:25:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/postmortem-supply-chain-gate/</guid><description>Version updated for https://github.com/mlab-sh/postmortem to version v2.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The postmortem action performs offline static analysis of dependencies across multiple ecosystems (npm, pip, poetry, Cargo, Go, Java, and NuGet) to detect potential security vulnerabilities and malicious code. It can also audit the system’s installed packages and provide reputation intelligence on dependencies. The action is designed to be offline by default and can be configured to run online for additional details such as known vulnerabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mlab-sh/postmortem">https://github.com/mlab-sh/postmortem</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postmortem-supply-chain-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The postmortem action performs offline static analysis of dependencies across multiple ecosystems (npm, pip, poetry, Cargo, Go, Java, and NuGet) to detect potential security vulnerabilities and malicious code. It can also audit the system&rsquo;s installed packages and provide reputation intelligence on dependencies. The action is designed to be offline by default and can be configured to run online for additional details such as known vulnerabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mlab-sh/postmortem/compare/v2...v2.1.0">https://github.com/mlab-sh/postmortem/compare/v2...v2.1.0</a></p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/totem-shield/</link><pubDate>Wed, 05 Aug 2026 06:24:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.111.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based toolkit that uses plain markdown lessons to enforce project rules and context. It provides a local, zero-LLM linter that enforces these rules and generates a queryable knowledge index derived from the lessons. This helps prevent architectural mistakes and ensures code consistency across team members.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.111.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a file-based toolkit that uses plain markdown lessons to enforce project rules and context. It provides a local, zero-LLM linter that enforces these rules and generates a queryable knowledge index derived from the lessons. This helps prevent architectural mistakes and ensures code consistency across team members.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/go-proxy-cache-updater/</link><pubDate>Wed, 05 Aug 2026 06:23:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.38.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically updates a proxy cache to include new Go module releases and ensures documentation is updated on platforms like pkg.go.dev. It supports both standard version tags (vX.Y.Z) and submodule version tags (submodule/path/vX.Y.Z), allowing users to specify custom import paths, set specific Go versions, and configure caching options. The action uses the GitHub Actions framework to trigger on new release events and utilizes the actions/setup-go tool for setting up the Go environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.38</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically updates a proxy cache to include new Go module releases and ensures documentation is updated on platforms like pkg.go.dev. It supports both standard version tags (<code>vX.Y.Z</code>) and submodule version tags (<code>submodule/path/vX.Y.Z</code>), allowing users to specify custom import paths, set specific Go versions, and configure caching options. The action uses the GitHub Actions framework to trigger on new release events and utilizes the <code>actions/setup-go</code> tool for setting up the Go environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1138-2026-08-04"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.37...v1.1.38">1.1.38</a> (2026-08-04)</h2>
]]></content:encoded></item><item><title>Shoutrrr GitHub Notifications Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/shoutrrr-github-notifications-action/</link><pubDate>Wed, 05 Aug 2026 06:21:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/shoutrrr-github-notifications-action/</guid><description>Version updated for https://github.com/nicholas-fedor/shoutrrr-action to version v1.0.23.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sends notifications using the Shoutrrr service from your GitHub Actions workflows. It allows you to configure various options such as URL, title, and message for different services supported by Shoutrrr. The action is only compatible with Linux runners due to its dependencies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/shoutrrr-action">https://github.com/nicholas-fedor/shoutrrr-action</a></strong> to version <strong>v1.0.23</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shoutrrr-github-notifications-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sends notifications using the Shoutrrr service from your GitHub Actions workflows. It allows you to configure various options such as URL, title, and message for different services supported by Shoutrrr. The action is only compatible with Linux runners due to its dependencies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="2026-08-05">(2026-08-05)</h2>
<h2 id="1023-2026-08-05"><small>1.0.23 (2026-08-05)</small></h2>
<ul>
<li>chore(deps): update docker.io/nickfedor/shoutrrr docker tag to v0.17.0 (#532) (<a href="https://github.com/nicholas-fedor/shoutrrr-action/commit/ea910e8">ea910e8</a>), closes <a href="https://github.com/nicholas-fedor/shoutrrr-action/issues/532">#532</a></li>
</ul>
]]></content:encoded></item><item><title>Tukimatsu Chan - Japanese Month-End Detector</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/tukimatsu-chan-japanese-month-end-detector/</link><pubDate>Wed, 05 Aug 2026 06:20:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/tukimatsu-chan-japanese-month-end-detector/</guid><description>Version updated for https://github.com/nikuteresa/tukimatsu_chan to version v0.1.4.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary tukimatsu_chan GitHub Actionは、月末の最終営業日を判定するシンプルなツールです。このアクションはCLAude Desktopを使用して作成され、GitHub Actionsワークフローで利用することができます。機能的には、今日が月末の最終営業日（土日祝日を除外）かどうかを判定します，并且日本の祝日に対応しています。
What’s Changed What’s Changed build(deps): bump json from 2.19.3 to 2.19.9 by @dependabot[bot] in https://github.com/nikuteresa/tukimatsu_chan/pull/10 Full Changelog: https://github.com/nikuteresa/tukimatsu_chan/compare/v0.1.3...v0.1.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nikuteresa/tukimatsu_chan">https://github.com/nikuteresa/tukimatsu_chan</a></strong> to version <strong>v0.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tukimatsu-chan-japanese-month-end-detector">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>tukimatsu_chan</code> GitHub Actionは、月末の最終営業日を判定するシンプルなツールです。このアクションはCLAude Desktopを使用して作成され、GitHub Actionsワークフローで利用することができます。機能的には、今日が月末の最終営業日（土日祝日を除外）かどうかを判定します，并且日本の祝日に対応しています。</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>build(deps): bump json from 2.19.3 to 2.19.9 by @dependabot[bot] in <a href="https://github.com/nikuteresa/tukimatsu_chan/pull/10">https://github.com/nikuteresa/tukimatsu_chan/pull/10</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nikuteresa/tukimatsu_chan/compare/v0.1.3...v0.1.4">https://github.com/nikuteresa/tukimatsu_chan/compare/v0.1.3...v0.1.4</a></p>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/odin-scan-smart-contract-security/</link><pubDate>Wed, 05 Aug 2026 06:19:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Odin Scan GitHub Action is an AI-powered security analysis tool for CosmWasm, Solana, and EVM projects. It automates the detection of vulnerabilities by analyzing smart contracts and reports findings directly on pull requests or via SARIF files. The action supports various platforms and customizable severity thresholds to ensure continuous code quality and security.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Odin Scan GitHub Action is an AI-powered security analysis tool for CosmWasm, Solana, and EVM projects. It automates the detection of vulnerabilities by analyzing smart contracts and reports findings directly on pull requests or via SARIF files. The action supports various platforms and customizable severity thresholds to ensure continuous code quality and security.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add comment-triggered PR scans (ac72e5f)</li>
<li>docs: expand findings-visibility section with threat model and annotation rationale (0404708)</li>
<li>feat: add findings-visibility input for graduated public disclosure control (f18df59)</li>
<li>fix: show findings detail in PR comment with fallback to medium (c2e43c8)</li>
<li>fix: new comment per run, show only critical/high findings, rebuild dist (e237b62)</li>
<li>feat: use GitHub App installation token for branded PR comments (3abce4e)</li>
<li>feat: enrich PR comment with emojis, descriptions, and fix report URL (27cc2f2)</li>
<li>fix: gzip SARIF before base64 encoding for Code Scanning upload (d9eed9f)</li>
<li>fix: include sourcemap-register.js in dist (bd265af)</li>
<li>docs: add privacy policy (b78db44)</li>
</ul>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/postman-api-onboarding/</link><pubDate>Wed, 05 Aug 2026 06:18:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v3.2.12.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of setting up and onboarding a new API repository into Postman. It handles various tasks such as workspace creation, OpenAPI specification upload, collection generation, artifact synchronization, and automated testing, including smoke tests and contract enforcement layers. The action provides a comprehensive solution for integrating API services with Postman, ensuring test coverage and compliance checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v3.2.12</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of setting up and onboarding a new API repository into Postman. It handles various tasks such as workspace creation, OpenAPI specification upload, collection generation, artifact synchronization, and automated testing, including smoke tests and contract enforcement layers. The action provides a comprehensive solution for integrating API services with Postman, ensuring test coverage and compliance checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/91">https://github.com/postman-cs/postman-api-onboarding-action/pull/91</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/92">https://github.com/postman-cs/postman-api-onboarding-action/pull/92</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/93">https://github.com/postman-cs/postman-api-onboarding-action/pull/93</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/94">https://github.com/postman-cs/postman-api-onboarding-action/pull/94</a></li>
<li>chore(deps): pin Insights onboarding v2.2.1 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/95">https://github.com/postman-cs/postman-api-onboarding-action/pull/95</a></li>
<li>fix: consume Insights human-session normalization by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/96">https://github.com/postman-cs/postman-api-onboarding-action/pull/96</a></li>
<li>fix: consume repo-sync v2.2.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/97">https://github.com/postman-cs/postman-api-onboarding-action/pull/97</a></li>
<li>fix: expose mock environment and refresh Azure pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/98">https://github.com/postman-cs/postman-api-onboarding-action/pull/98</a></li>
<li>feat: pass mock visibility policy through to repo-sync by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/99">https://github.com/postman-cs/postman-api-onboarding-action/pull/99</a></li>
<li>chore: pin repo-sync v2.4.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/100">https://github.com/postman-cs/postman-api-onboarding-action/pull/100</a></li>
<li>fix: document private mock credential paths for consumers by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/101">https://github.com/postman-cs/postman-api-onboarding-action/pull/101</a></li>
<li>fix(deps): advance the bootstrap pin to v2.13.2 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/102">https://github.com/postman-cs/postman-api-onboarding-action/pull/102</a></li>
<li>fix(deps): advance bootstrap and repo-sync pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/103">https://github.com/postman-cs/postman-api-onboarding-action/pull/103</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/104">https://github.com/postman-cs/postman-api-onboarding-action/pull/104</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.8 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/105">https://github.com/postman-cs/postman-api-onboarding-action/pull/105</a></li>
<li>fix(deps): advance bootstrap pin to v2.13.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/106">https://github.com/postman-cs/postman-api-onboarding-action/pull/106</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>fix(ci): validate sibling pins without local checkouts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/111">https://github.com/postman-cs/postman-api-onboarding-action/pull/111</a></li>
<li>feat(azure-devops): forward an explicit workspace squad id from the Windows template by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/112">https://github.com/postman-cs/postman-api-onboarding-action/pull/112</a></li>
<li>fix(release): harden composite pin and E2E releases by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/113">https://github.com/postman-cs/postman-api-onboarding-action/pull/113</a></li>
<li>fix(release): supersede stale aliases with pending cuts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/114">https://github.com/postman-cs/postman-api-onboarding-action/pull/114</a></li>
<li>fix(release): wait for correlated E2E run names by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/115">https://github.com/postman-cs/postman-api-onboarding-action/pull/115</a></li>
<li>fix(release): keep pin ratchet synchronized by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/116">https://github.com/postman-cs/postman-api-onboarding-action/pull/116</a></li>
<li>fix(ci): preserve pin updater test fixtures by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/117">https://github.com/postman-cs/postman-api-onboarding-action/pull/117</a></li>
<li>fix(release): reconcile failed release completions by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/118">https://github.com/postman-cs/postman-api-onboarding-action/pull/118</a></li>
<li>fix(release): emit automated completion events by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/119">https://github.com/postman-cs/postman-api-onboarding-action/pull/119</a></li>
<li>fix(release): bound failed release recovery by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/120">https://github.com/postman-cs/postman-api-onboarding-action/pull/120</a></li>
<li>fix(release): hold auto release through E2E completion by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/121">https://github.com/postman-cs/postman-api-onboarding-action/pull/121</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@github-actions[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.2.12">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.2.12</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/postman-onboarding-repo-sync/</link><pubDate>Wed, 05 Aug 2026 06:17:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.8.10.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of exporting Postman collections and environments into a repository, setting up CI, mock servers, and monitors around them. It solves the problem of manual setup by providing an automated way to manage API assets in a version-controlled manner. The action also integrates with other actions for authentication and workspace management, allowing seamless integration with larger workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.8.10</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of exporting Postman collections and environments into a repository, setting up CI, mock servers, and monitors around them. It solves the problem of manual setup by providing an automated way to manage API assets in a version-controlled manner. The action also integrates with other actions for authentication and workspace management, allowing seamless integration with larger workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>perf(repo-sync): bound artifact acquisition reads by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/116">https://github.com/postman-cs/postman-repo-sync-action/pull/116</a></li>
<li>fix(deps): replace deprecated Faker with compatible v6 by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/117">https://github.com/postman-cs/postman-repo-sync-action/pull/117</a></li>
<li>fix(repo-mutation): reconcile stale branch before push by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/118">https://github.com/postman-cs/postman-repo-sync-action/pull/118</a></li>
<li>fix(repo-mutation): resolve generated artifact conflicts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/119">https://github.com/postman-cs/postman-repo-sync-action/pull/119</a></li>
<li>fix(release): notify the composite after Repo Sync publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/121">https://github.com/postman-cs/postman-repo-sync-action/pull/121</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.8.10">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.8.10</a></p>
]]></content:encoded></item><item><title>Wrangler Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/wrangler-deploy/</link><pubDate>Wed, 05 Aug 2026 06:16:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/wrangler-deploy/</guid><description>Version updated for https://github.com/risu729/wrangler-deploy-action to version v1.2.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Wrangler Deploy Action automates the deployment of Cloudflare Workers from GitHub Actions, providing a consistent workflow for preview and production deployments. It leverages Wrangler’s version already declared in the caller package or configured through mise, ensuring no additional installation is required. The action supports both pull-request previews with wrangler versions upload and dry-run fallbacks for forks without preview credentials. For production deployments, it checks for Cloudflare credentials and fails if missing, uploads Worker secrets atomically, and outputs URLs and deployment targets directly to the GitHub Actions job summary.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/risu729/wrangler-deploy-action">https://github.com/risu729/wrangler-deploy-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wrangler-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Wrangler Deploy Action automates the deployment of Cloudflare Workers from GitHub Actions, providing a consistent workflow for preview and production deployments. It leverages Wrangler&rsquo;s version already declared in the caller package or configured through mise, ensuring no additional installation is required. The action supports both pull-request previews with <code>wrangler versions upload</code> and dry-run fallbacks for forks without preview credentials. For production deployments, it checks for Cloudflare credentials and fails if missing, uploads Worker secrets atomically, and outputs URLs and deployment targets directly to the GitHub Actions job summary.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="120-2026-08-04"><a href="https://github.com/risu729/wrangler-deploy-action/compare/v1.1.0...v1.2.0">1.2.0</a> (2026-08-04)</h1>
<h3 id="features">Features</h3>
<ul>
<li>support deployment secrets (<a href="https://github.com/risu729/wrangler-deploy-action/issues/11">#11</a>) (<a href="https://github.com/risu729/wrangler-deploy-action/commit/e943f9681fb250fa0d0a104bd95ea121c510d192">e943f96</a>)</li>
</ul>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/sherpa.sh/</link><pubDate>Wed, 05 Aug 2026 06:14:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven infrastructure automation tool that simplifies deployment by allowing developers to describe their cloud requirements in plain English. It generates and configures servers, DNS, SSL certificates, CDNs, databases, backups, load balancing, and more automatically. With Sherpa, developers can deploy any application or framework across various cloud providers without needing extensive configuration knowledge.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven infrastructure automation tool that simplifies deployment by allowing developers to describe their cloud requirements in plain English. It generates and configures servers, DNS, SSL certificates, CDNs, databases, backups, load balancing, and more automatically. With Sherpa, developers can deploy any application or framework across various cloud providers without needing extensive configuration knowledge.</p>
]]></content:encoded></item><item><title>Setup UniRTM</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/setup-unirtm/</link><pubDate>Wed, 05 Aug 2026 06:13:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/setup-unirtm/</guid><description>Version updated for https://github.com/snowdreamtech/setup-unirtm to version v0.7.0.
This action is used across all versions by 36 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “setup-unirtm” automates the installation and configuration of UniRTM, a runtime and tool manager. It offers smart auto-detection, multiple install methods (npm, pip, GitHub Release, go), GitHub Proxy support, caching using Handlebars templates, and cross-platform support for Linux, macOS, and Windows. The action can be customized with specific versions, installation methods, and GitHub tokens to handle restricted networks or mirrors.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snowdreamtech/setup-unirtm">https://github.com/snowdreamtech/setup-unirtm</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>36</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-unirtm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;setup-unirtm&rdquo; automates the installation and configuration of UniRTM, a runtime and tool manager. It offers smart auto-detection, multiple install methods (npm, pip, GitHub Release, go), GitHub Proxy support, caching using Handlebars templates, and cross-platform support for Linux, macOS, and Windows. The action can be customized with specific versions, installation methods, and GitHub tokens to handle restricted networks or mirrors.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="070-2026-08-05"><a href="https://github.com/snowdreamtech/setup-unirtm/compare/v0.6.0...v0.7.0">0.7.0</a> (2026-08-05)</h2>
<h3 id="features">Features</h3>
<ul>
<li>inject shims into GITHUB_PATH dynamically (<a href="https://github.com/snowdreamtech/setup-unirtm/commit/7288285ac17c2f52cf659bd599483c5ae2262963">7288285</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>correct go install path and add rolldown optional binding (<a href="https://github.com/snowdreamtech/setup-unirtm/commit/80e4a6e5d5238b59c8165cd1f8bcddd434194807">80e4a6e</a>)</li>
<li>remove fallback restore-keys for cache restoration (<a href="https://github.com/snowdreamtech/setup-unirtm/commit/f5b4f709b2b0de2d6afa56b02720387430110097">f5b4f70</a>)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/ssg-static-site-generator/</link><pubDate>Wed, 05 Aug 2026 06:12:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.18.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG (Static Site Generator) is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It automates tasks like content creation, rendering HTML, and deployment to various platforms such as GitHub Pages, Netlify, and Vercel. SSG provides features for SEO, image processing, and cloud integration, making it suitable for blogs, documentation sites, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.18</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG (Static Site Generator) is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It automates tasks like content creation, rendering HTML, and deployment to various platforms such as GitHub Pages, Netlify, and Vercel. SSG provides features for SEO, image processing, and cloud integration, making it suitable for blogs, documentation sites, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Build-time validation of the generated output (#74, #75, #76, #77, #78) + flaky-test fix by @spagu in <a href="https://github.com/spagu/ssg/pull/73">https://github.com/spagu/ssg/pull/73</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.17...v1.8.18">https://github.com/spagu/ssg/compare/v1.8.17...v1.8.18</a></p>
]]></content:encoded></item><item><title>Claude Code Marketplace Manager</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/claude-code-marketplace-manager/</link><pubDate>Wed, 05 Aug 2026 06:11:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/claude-code-marketplace-manager/</guid><description>Version updated for https://github.com/spencerbeggs/claude-code-marketplace-manager to version 1.0.3.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose and Functionality: This GitHub Action automates the process of modifying a Claude Code marketplace manifest to re-pin plugin entries. It ensures that only explicit changes are made, preserves formatting, and signs commits through a GitHub App.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spencerbeggs/claude-code-marketplace-manager">https://github.com/spencerbeggs/claude-code-marketplace-manager</a></strong> to version <strong>1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/claude-code-marketplace-manager">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Purpose and Functionality</strong>: This GitHub Action automates the process of modifying a Claude Code marketplace manifest to re-pin plugin entries. It ensures that only explicit changes are made, preserves formatting, and signs commits through a GitHub App.</p>
<p><strong>Problems Solved or Tasks Automated</strong>: The action simplifies the task of repinning plugins by handling JSON parsing and validation, ensuring that updates are precise and compliant with branch protection rules.</p>
<p><strong>Key Capabilities</strong>: - Partially merges plugin entries in <code>.claude-plugin/marketplace.json</code>.</p>
<ul>
<li>Validates changes before committing.</li>
<li>Uses a GitHub App for server-side verification and signing.</li>
</ul>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><code>land</code> now refuses <code>pr</code> mode when <code>base</code> and <code>branch</code> are the same. Previously nothing stopped the two from colliding, and the single <code>GitBranch.upsert</code> would move the <em>base</em> branch itself onto the new commit — landing an unreviewed change directly on it, with the pull request call only failing afterward on a head equal to its base. The guard runs before the commit is built, so <code>land</code>&rsquo;s error channel now also includes <code>InvalidInputError</code>. <code>commit</code> mode is unaffected — it never reads <code>branch</code>. <a href="https://github.com/spencerbeggs/claude-code-marketplace-manager/pull/20">#20</a></li>
</ul>
<ul>
<li>Fixed a <code>pr</code> mode race where the action&rsquo;s own pull request could be auto-closed by GitHub. The landing sequence now builds the finished commit first and moves the head branch straight onto it with a single update, so the branch never passes through a state where it&rsquo;s identical to <code>base</code> (which GitHub reads as an empty diff and auto-closes). The existing force-reset guarantee is unchanged: every <code>pr</code>-mode run still discards the previous run&rsquo;s commits and re-roots on <code>base</code>&rsquo;s current tip.</li>
<li>Auto-merge is now requested as a separate step after the pull request is opened or updated, so a repository that rejects the requested merge method no longer makes PR creation itself look like it failed. A failure to enable auto-merge still fails the run.</li>
</ul>
<h3 id="refactoring">Refactoring</h3>
<ul>
<li>Default-branch resolution now goes through the library&rsquo;s repository service instead of a hand-written API type cast.</li>
<li>Consolidated four internal error types into a single structured error with a <code>kind</code> field, and collapsed duplicate layer wiring between the <code>pre</code> and <code>post</code> phases. <a href="https://github.com/spencerbeggs/claude-code-marketplace-manager/pull/20">#20</a></li>
</ul>
<h3 id="dependencies">Dependencies</h3>
<ul>
<li>
<table>
  <thead>
      <tr>
          <th>Dependency</th>
          <th>Type</th>
          <th>Action</th>
          <th>From</th>
          <th>To</th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>@effected/jsonc</td>
          <td>dependency</td>
          <td>updated</td>
          <td>~0.5.1</td>
          <td>~0.5.2</td>
          <td><a href="https://github.com/spencerbeggs/claude-code-marketplace-manager/pull/17">#17</a> Thanks <a href="https://github.com/apps/spencerbeggs">@spencerbeggs</a>!</td>
      </tr>
  </tbody>
</table>
</li>
</ul>
<ul>
<li>
<table>
  <thead>
      <tr>
          <th>Dependency</th>
          <th>Type</th>
          <th>Action</th>
          <th>From</th>
          <th>To</th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>@savvy-web/github-action-effects</td>
          <td>dependency</td>
          <td>removed</td>
          <td>^3.1.0</td>
          <td>—</td>
          <td></td>
      </tr>
      <tr>
          <td>@effected/github</td>
          <td>dependency</td>
          <td>added</td>
          <td>—</td>
          <td>~0.2.2</td>
          <td></td>
      </tr>
      <tr>
          <td>@effected/github-actions</td>
          <td>dependency</td>
          <td>added</td>
          <td>—</td>
          <td>~0.5.0</td>
          <td><a href="https://github.com/spencerbeggs/claude-code-marketplace-manager/pull/20">#20</a> Thanks <a href="https://github.com/spencerbeggs">@spencerbeggs</a>!</td>
      </tr>
  </tbody>
</table>
</li>
</ul>
<h3 id="patch-changes">Patch Changes</h3>
<p>Thanks to <a href="https://github.com/spencerbeggs">@spencerbeggs</a> for their contributions!</p>
<blockquote>
<p>This is a version-only release. No packages were published to a registry.</p>
</blockquote>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/classroom-to-sheets-integration/</link><pubDate>Wed, 05 Aug 2026 06:10:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the integration between GitHub Classroom and Google Sheets. It sends assignment results from GitHub Classroom to a specified Google Sheet, updating existing rows or creating new ones as necessary. The action requires Google Sheets API credentials and is configured via GitHub Actions secrets for authentication. Users can specify student names, task results, and table IDs in their workflow files, and the action will dynamically update the spreadsheet with the results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the integration between GitHub Classroom and Google Sheets. It sends assignment results from GitHub Classroom to a specified Google Sheet, updating existing rows or creating new ones as necessary. The action requires Google Sheets API credentials and is configured via GitHub Actions secrets for authentication. Users can specify student names, task results, and table IDs in their workflow files, and the action will dynamically update the spreadsheet with the results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>ArchGuard - Architectural Drift Detector</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/archguard-architectural-drift-detector/</link><pubDate>Wed, 05 Aug 2026 06:09:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/archguard-architectural-drift-detector/</guid><description>Version updated for https://github.com/Tgenz1213/ArchGuard to version v1.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ArchGuard is a tool that uses LLMs to monitor code changes against established architectural decisions (ADRs) and helps prevent “architectural drift”. It alerts developers of potential violations in ADRs before they are merged into the repository. ArchGuard supports local analysis using Ollama models or cloud-based services like OpenAI, with a focus on maintaining privacy by keeping all data local unless explicitly configured otherwise.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tgenz1213/ArchGuard">https://github.com/Tgenz1213/ArchGuard</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/archguard-architectural-drift-detector">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ArchGuard is a tool that uses LLMs to monitor code changes against established architectural decisions (ADRs) and helps prevent &ldquo;architectural drift&rdquo;. It alerts developers of potential violations in ADRs before they are merged into the repository. ArchGuard supports local analysis using Ollama models or cloud-based services like OpenAI, with a focus on maintaining privacy by keeping all data local unless explicitly configured otherwise.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>26ac1be4941fb06513e47710363e6193a1a088e2 build(deps): bump github.com/ollama/ollama from 0.32.4 to 0.32.5 (#59)</li>
<li>f626c10be9870927e57e2182ba43aed984325eb1 build(deps): bump github.com/pgvector/pgvector-go from 0.4.0 to 0.4.1 (#60)</li>
<li>4ae73a9a897713e8f743afc579561d920ba3b92b build(deps): bump github.com/pgvector/pgvector-go/pgx (#58)</li>
<li>7cecf702f90bfa7438d2537fcb3754ebc3ef9f35 build(deps): bump google.golang.org/genai from 1.65.0 to 1.66.0 (#61)</li>
<li>379e47b60dbc3bf45caea2111d29796a2e7700e6 fix(index): enable hnsw.iterative_scan for project-filtered ArchGuard search (#65)</li>
<li>804c6a589966b87255a23f76a6e3f1420bba5112 test(index): add HNSW project_name-filter recall/latency benchmark (#44) (#63)</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/wails3-build-action/</link><pubDate>Wed, 05 Aug 2026 06:08:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action ToQuery/wails3-build-action@v3 automates the building of Wails.io projects for various platforms. It installs GoLang and NodeJS, runs a build process, and can upload the results to GitHub or publish releases on tagged builds. The action supports customizing build configurations such as platform, caching, and uploading options, and provides detailed configuration options for Node.js and Deno settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>ToQuery/wails3-build-action@v3</code> automates the building of Wails.io projects for various platforms. It installs GoLang and NodeJS, runs a build process, and can upload the results to GitHub or publish releases on tagged builds. The action supports customizing build configurations such as platform, caching, and uploading options, and provides detailed configuration options for Node.js and Deno settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>VyQL security scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/vyql-security-scan/</link><pubDate>Wed, 05 Aug 2026 06:07:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/vyql-security-scan/</guid><description>Version updated for https://github.com/vyprai/vyql-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates a security scan using VyQL, a multi-language security scanner. It checks the checked-out repository, fails the build if any HIGH or CRITICAL findings are detected, and uploads SARIF results to code scanning. The action supports versioning for reproducibility and provides inputs for customizing the scan path, severity level, and output format.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vyprai/vyql-action">https://github.com/vyprai/vyql-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vyql-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates a security scan using VyQL, a multi-language security scanner. It checks the checked-out repository, fails the build if any HIGH or CRITICAL findings are detected, and uploads SARIF results to code scanning. The action supports versioning for reproducibility and provides inputs for customizing the scan path, severity level, and output format.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Run a <a href="https://github.com/vyprai/vyql">VyQL</a> security scan in GitHub Actions: follow tainted data from where it enters your code to where it does something dangerous, fail the build on what it finds, and put the results in the Security tab.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v5</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vyprai/vyql-action@v1</span>
</span></span></code></pre></div><p>That is the whole minimal usage. It scans the checked-out repository, fails on any HIGH or CRITICAL finding, and uploads SARIF to code scanning.</p>
<h2 id="what-makes-the-findings-usable">What makes the findings usable</h2>
<p>Every finding names the source, the sink, the path between them, and <strong>the neutralizing controls it looked for and did not find</strong> — so a finding tells you what would have made it safe, not just that something looks wrong.</p>
<h2 id="adopting-it-on-an-existing-codebase">Adopting it on an existing codebase</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vyprai/vyql-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">none       </span> <span style="color:#75715e"># report without failing the build</span>
</span></span></code></pre></div><p>Findings still reach the Security tab while the build stays green. VyQL also supports a triage baseline, so a scan can report only what is new.</p>
<h2 id="common-inputs">Common inputs</h2>
<table>
  <thead>
      <tr>
          <th>Input</th>
          <th>Default</th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>path</code></td>
          <td><code>.</code></td>
          <td>what to scan</td>
      </tr>
      <tr>
          <td><code>version</code></td>
          <td><code>latest</code></td>
          <td>which VyQL release; pin it for reproducible runs</td>
      </tr>
      <tr>
          <td><code>fail-on</code></td>
          <td><code>high</code></td>
          <td><code>none</code>, <code>info</code>, <code>low</code>, <code>medium</code>, <code>high</code>, <code>critical</code></td>
      </tr>
      <tr>
          <td><code>exit-code</code></td>
          <td><code>1</code></td>
          <td>status when <code>fail-on</code> is met</td>
      </tr>
      <tr>
          <td><code>upload-sarif</code></td>
          <td><code>true</code></td>
          <td>needs <code>security-events: write</code></td>
      </tr>
  </tbody>
</table>
<h2 id="requirements">Requirements</h2>
<ul>
<li><strong>Linux or macOS runners.</strong> VyQL publishes <code>linux/amd64</code>, <code>linux/arm64</code>, <code>darwin/amd64</code>, <code>darwin/arm64</code>; on Windows the action fails with that message rather than something obscure.</li>
<li><strong><code>security-events: write</code></strong> for the SARIF upload. On a private repository that also needs GitHub Advanced Security — without it the upload step fails while the scan result still stands.</li>
<li><strong>VyQL v0.2.0 or newer</strong>, which this release is verified against.</li>
</ul>
<h2 id="verified">Verified</h2>
<p>Exercised on Linux and macOS against VyQL v0.2.0: the gate fires on a vulnerable fixture, <code>fail-on: none</code> reports without gating, a custom <code>exit-code</code> is honoured, and clean code passes with valid SARIF.</p>
<p>Full documentation: <a href="https://github.com/vyprai/vyql-action#readme">README</a></p>
]]></content:encoded></item><item><title>spaces checkout run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/spaces-checkout-run/</link><pubDate>Wed, 05 Aug 2026 06:06:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/spaces-checkout-run/</guid><description>Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.20.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of checking out and running a workspace in WorkSpaces using the spaces CLI. It simplifies the setup and execution of workspace commands by handling the installation of the CLI and passing arguments directly to the necessary commands, thus reducing manual intervention in workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/spaces-checkout-run">https://github.com/work-spaces/spaces-checkout-run</a></strong> to version <strong>v0.20.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spaces-checkout-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of checking out and running a workspace in WorkSpaces using the <code>spaces</code> CLI. It simplifies the setup and execution of workspace commands by handling the installation of the CLI and passing arguments directly to the necessary commands, thus reducing manual intervention in workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.20.3 by @tyler-gilbert in <a href="https://github.com/work-spaces/spaces-checkout-run/pull/34">https://github.com/work-spaces/spaces-checkout-run/pull/34</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/spaces-checkout-run/compare/v0.20.1...v0.20.3">https://github.com/work-spaces/spaces-checkout-run/compare/v0.20.1...v0.20.3</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/b.ia-accessibility-checker/</link><pubDate>Wed, 05 Aug 2026 06:05:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks within CI/CD pipelines, helping companies ensure their code meets accessibility standards. It allows users to define target audiences and guideline percentages, facilitating the adoption of accessibility in products by providing AI-driven feedback for improvement. The solution simplifies accessibility efforts by focusing on critical user groups, reducing external solutions’ costs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks within CI/CD pipelines, helping companies ensure their code meets accessibility standards. It allows users to define target audiences and guideline percentages, facilitating the adoption of accessibility in products by providing AI-driven feedback for improvement. The solution simplifies accessibility efforts by focusing on critical user groups, reducing external solutions&rsquo; costs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>Gonzalgo trust audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/gonzalgo-trust-audit/</link><pubDate>Wed, 05 Aug 2026 06:04:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/05/gonzalgo-trust-audit/</guid><description>Version updated for https://github.com/zengineco/gonzalgo to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary gonzalgo is a Python tool that helps developers understand how Lean theorems depend on axioms and other assumptions. It can identify if a theorem relies on sorry statements, detect where an axiom is inherited from dependencies, and help determine which steps introduced specific axioms into proofs. The action also allows for automated checks to fail builds when certain axioms are used in incomplete or unproven code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zengineco/gonzalgo">https://github.com/zengineco/gonzalgo</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gonzalgo-trust-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>gonzalgo</code> is a Python tool that helps developers understand how Lean theorems depend on axioms and other assumptions. It can identify if a theorem relies on <code>sorry</code> statements, detect where an axiom is inherited from dependencies, and help determine which steps introduced specific axioms into proofs. The action also allows for automated checks to fail builds when certain axioms are used in incomplete or unproven code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Composite GitHub Action: fails a Lean 4 build when any theorem rests on an unfinished proof or on trusting the compiler rather than the kernel. Verified in CI against a clean project and one whose sorry is two steps upstream &ndash; Lean reports one warning, the audit finds two contaminated theorems.</p>
]]></content:encoded></item><item><title>Deploy to VPS</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/deploy-to-vps/</link><pubDate>Tue, 04 Aug 2026 22:40:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/deploy-to-vps/</guid><description>Version updated for https://github.com/mujeeb-enfin/deploy-to-vps to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of projects to a VPS using SSH. It supports various strategies like Node.js + PM2, Node.js + Docker, and static sites, allowing users to deploy their applications with ease. The action provides features such as dry-run mode, structured outputs, and step summaries, making it user-friendly for developers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mujeeb-enfin/deploy-to-vps">https://github.com/mujeeb-enfin/deploy-to-vps</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-to-vps">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of projects to a VPS using SSH. It supports various strategies like Node.js + PM2, Node.js + Docker, and static sites, allowing users to deploy their applications with ease. The action provides features such as dry-run mode, structured outputs, and step summaries, making it user-friendly for developers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A multi-strategy GitHub Action for SSH-based deployments. Pick from node-pm2, node-docker, static, or custom. Production-hardened with shell-injection safety, fingerprint pinning, dry-run mode, and step summaries.</p>
]]></content:encoded></item><item><title>NetOfficeFw/nuget-login</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/netofficefw/nuget-login/</link><pubDate>Tue, 04 Aug 2026 22:38:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/netofficefw/nuget-login/</guid><description>Version updated for https://github.com/NetOfficeFw/nuget-login to version v2.0.1.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action securely logs in to NuGet servers using OpenID Connect (OIDC) tokens, obtaining a short-lived API key that can be used for package publishing. It automates the process of authenticating with NuGet services without requiring passwords or other sensitive information. The action outputs an API key that can be used in subsequent steps to publish packages to NuGet.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NetOfficeFw/nuget-login">https://github.com/NetOfficeFw/nuget-login</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/netofficefw-nuget-login">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action securely logs in to NuGet servers using OpenID Connect (OIDC) tokens, obtaining a short-lived API key that can be used for package publishing. It automates the process of authenticating with NuGet services without requiring passwords or other sensitive information. The action outputs an API key that can be used in subsequent steps to publish packages to NuGet.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changes">Changes</h3>
<ul>
<li>Updated packages</li>
</ul>
]]></content:encoded></item><item><title>NewScan Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/newscan-security-scan/</link><pubDate>Tue, 04 Aug 2026 22:38:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/newscan-security-scan/</guid><description>Version updated for https://github.com/NewNormal-Security/newscan-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the NewScan penetration testing tool for security scanning in CI pipelines. It runs on every pull request or deploy, generates SARIF reports, and fails builds based on predefined severity levels. The action supports various scan modes (APIs, web apps, etc.) with customizable profiles and fail-on settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NewNormal-Security/newscan-action">https://github.com/NewNormal-Security/newscan-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/newscan-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the NewScan penetration testing tool for security scanning in CI pipelines. It runs on every pull request or deploy, generates SARIF reports, and fails builds based on predefined severity levels. The action supports various scan modes (APIs, web apps, etc.) with customizable profiles and fail-on settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First tagged release of the NewScan GitHub Action — the Pro CI gate that fails a build on new
security findings.</p>
<ul>
<li>SARIF upload to GitHub code scanning, with an artifact fallback when Advanced Security is off,
and <code>continue-on-error</code> so a SARIF problem can&rsquo;t fail an otherwise-passing gate.</li>
<li><code>upload-artifact</code> v7 / <code>upload-sarif</code> v4 (Node 24 — no Node 20 deprecation warnings).</li>
<li>Example workflows for a preview-URL gate and an ephemeral-service scan.</li>
</ul>
<p><code>v1</code> tracks this release. Requires a NewScan Pro license in the <code>NEWSCAN_LICENSE</code> secret.</p>
]]></content:encoded></item><item><title>GH Stars</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/gh-stars/</link><pubDate>Tue, 04 Aug 2026 22:36:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/gh-stars/</guid><description>Version updated for https://github.com/nicoloboschi/gh-stars to version v1.1.4.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GH Stars action automates the tracking and visualization of a GitHub repository’s stargazer history. It uses the GITHUB_TOKEN to backfill missing stargazers, retain daily observed totals, and generate an embeddable chart that can be included in READMEs. The action supports customizable line colors and outputs SVG files for embedding. Users can also store generated charts in a separate repository for better integration with other systems.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicoloboschi/gh-stars">https://github.com/nicoloboschi/gh-stars</a></strong> to version <strong>v1.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gh-stars">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GH Stars action automates the tracking and visualization of a GitHub repository&rsquo;s stargazer history. It uses the <code>GITHUB_TOKEN</code> to backfill missing stargazers, retain daily observed totals, and generate an embeddable chart that can be included in READMEs. The action supports customizable line colors and outputs SVG files for embedding. Users can also store generated charts in a separate repository for better integration with other systems.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nicoloboschi/gh-stars/compare/v1...v1.1.4">https://github.com/nicoloboschi/gh-stars/compare/v1...v1.1.4</a></p>
]]></content:encoded></item><item><title>blitsbom SBOM report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/blitsbom-sbom-report/</link><pubDate>Tue, 04 Aug 2026 22:35:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/blitsbom-sbom-report/</guid><description>Version updated for https://github.com/no42-org/blitsbom to version v0.7.1.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary blitsbom is a browser-based tool that converts CycloneDX and SPDX SBOM files into clean, searchable HTML reports, which can be used for dependency management and license verification. It offers a zero-install experience by running directly from a file:// URL without any external dependencies. The action can also generate standalone HTML reports from an SBOM and upload them to GitHub Actions workflows for automated release reporting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/no42-org/blitsbom">https://github.com/no42-org/blitsbom</a></strong> to version <strong>v0.7.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/blitsbom-sbom-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>blitsbom is a browser-based tool that converts CycloneDX and SPDX SBOM files into clean, searchable HTML reports, which can be used for dependency management and license verification. It offers a zero-install experience by running directly from a file:// URL without any external dependencies. The action can also generate standalone HTML reports from an SBOM and upload them to GitHub Actions workflows for automated release reporting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Maintenance release with no functional changes to the viewer or the report action: it refreshes every dependency updated since v0.7.0 (12 update PRs across npm, GitHub Actions and Docker).</li>
<li>The release SBOM is now generated with syft v1.49.0, up from v1.42.3 (#190), picking up several catalogers&rsquo; accuracy fixes.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/no42-org/blitsbom/compare/v0.7.0...v0.7.1">https://github.com/no42-org/blitsbom/compare/v0.7.0...v0.7.1</a></p>
]]></content:encoded></item><item><title>Nuon CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/nuon-cli/</link><pubDate>Tue, 04 Aug 2026 22:34:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/nuon-cli/</guid><description>Version updated for https://github.com/nuonco/actions-nuon to version v0.4.1.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: This GitHub Action automates the execution of Nuon CLI commands within CI/CD workflows. It supports two authentication methods: OIDC federation or API token, making it easy to integrate Nuon’s infrastructure management into existing projects. The action provides flexibility in configuring and executing Nuon commands based on user needs, with options for specifying Org ID, app ID, API URL, and OAuth audience.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nuonco/actions-nuon">https://github.com/nuonco/actions-nuon</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nuon-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary</strong>: This GitHub Action automates the execution of Nuon CLI commands within CI/CD workflows. It supports two authentication methods: OIDC federation or API token, making it easy to integrate Nuon&rsquo;s infrastructure management into existing projects. The action provides flexibility in configuring and executing Nuon commands based on user needs, with options for specifying Org ID, app ID, API URL, and OAuth audience.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: yaml syntax error in description (#12) (58da122)</li>
<li>feat: support using oidc with the cli (#11) (500be20)</li>
<li>feat: use &ndash;no-input flag (#8) (b144959)</li>
<li>feat: Make input <code>command</code> optional, allowing for setup use cases (#7) (1c320c6)</li>
<li>fix: The NUON_VERSION env var was not being picked up by install script (#6) (866d9e5)</li>
<li>feat: Set <code>NUON_CONFIG_FILE</code> variable for subsequent steps (#4) (352448d)</li>
<li>fix: Use the correct value for <code>NUON_VERSION</code> while installing (#5) (0d28fb9)</li>
<li>chore: rename for publication (#3) (3cc58a1)</li>
<li>chore: noop changes: trigger version bump (#2) (2769fe0)</li>
<li>chore: github action (#1) (8a9ea15)</li>
</ul>
]]></content:encoded></item><item><title>Lint Codebase</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/lint-codebase/</link><pubDate>Tue, 04 Aug 2026 22:33:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/lint-codebase/</guid><description>Version updated for https://github.com/pako-23/action-linters to version v0.0.2.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action runs various linters on your codebase, including actionlint, ansible-lint, hadolint, markdownlint, and yamllint. The results are reported as commit statuses and job summaries. It requires the checks: write permission to post statuses via the GitHub API.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pako-23/action-linters">https://github.com/pako-23/action-linters</a></strong> to version <strong>v0.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lint-codebase">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action runs various linters on your codebase, including actionlint, ansible-lint, hadolint, markdownlint, and yamllint. The results are reported as commit statuses and job summaries. It requires the <code>checks: write</code> permission to post statuses via the GitHub API.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pako-23/action-linters/compare/v0...v0.0.2">https://github.com/pako-23/action-linters/compare/v0...v0.0.2</a></p>
]]></content:encoded></item><item><title>Setup pnpm with runtime</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/setup-pnpm-with-runtime/</link><pubDate>Tue, 04 Aug 2026 22:32:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/setup-pnpm-with-runtime/</guid><description>Version updated for https://github.com/pnpm/setup to version v2.0.0.
This action is used across all versions by 202 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of pnpm and a JavaScript runtime (Node.js, Bun, or Deno) in a single step. It downloads the self-contained pnpm release binary directly from pnpm’s GitHub releases and sets up the requested runtime on PATH. This eliminates the need for separate setup steps like actions/setup-node, oven-sh/setup-bun, or denoland/setup-deno. The action supports automatic installation of a specified version of pnpm, a custom destination for pnpm files, and caching the store directory. It also handles runtime selection based on devEngines.runtime in package.json or defaults to LTS versions for Node.js.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pnpm/setup">https://github.com/pnpm/setup</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>202</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-pnpm-with-runtime">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the installation of pnpm and a JavaScript runtime (Node.js, Bun, or Deno) in a single step. It downloads the self-contained pnpm release binary directly from pnpm&rsquo;s GitHub releases and sets up the requested runtime on <code>PATH</code>. This eliminates the need for separate setup steps like <code>actions/setup-node</code>, <code>oven-sh/setup-bun</code>, or <code>denoland/setup-deno</code>. The action supports automatic installation of a specified version of pnpm, a custom destination for pnpm files, and caching the store directory. It also handles runtime selection based on <code>devEngines.runtime</code> in <code>package.json</code> or defaults to LTS versions for Node.js.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The action no longer installs pnpm through npm. It downloads pnpm&rsquo;s self-contained release binary for the runner&rsquo;s platform straight from pnpm&rsquo;s GitHub releases, verifies it against the SHA-256 digest GitHub publishes for the asset, and puts it on <code>PATH</code>. No Node.js, no npm, no <code>@pnpm/exe</code>, no <code>self-update</code> round-trip.</p>
<p>That also makes the action immune to broken npm artifacts. pnpm 11.13.0&rsquo;s <code>@pnpm/exe</code> build shipped without its platform binary, which made <code>v1</code> install a placeholder file that failed later with <code>This: not found</code> and exit code 127. The GitHub release binary for that same version is fine, so <code>v2</code> installs it correctly. <code>v2</code> additionally verifies the install by running <code>pnpm --version</code> and comparing it against the requested version, so a bad artifact fails immediately with a clear message instead of surfacing as a confusing error in a later step.</p>
<h2 id="breaking-changes">Breaking changes</h2>
<p><strong>pnpm v11 or newer is required.</strong> <code>v1</code> could set up pnpm 10 via <code>pnpm self-update</code>; <code>v2</code> rejects anything below v11 with an explanatory error. The action is built around pnpm&rsquo;s self-contained release binaries and the <code>pnpm runtime</code> command, both of which arrived in v11.</p>
<p>If you need pnpm 10 or older, use <a href="https://github.com/pnpm/action-setup"><code>pnpm/action-setup</code></a> instead.</p>
<p><strong>The <code>bin-dest</code> output points somewhere new.</strong> It was <code>~/setup-pnpm/node_modules/.bin/bin</code>; it is now <code>~/setup-pnpm</code> (the <code>dest</code> directory itself). Workflows that read the output are unaffected — it still names the directory holding <code>pnpm</code> — but anything that hardcoded the old path needs updating.</p>
<p><strong><code>cache-hit</code> is stricter.</strong> It is now <code>true</code> only on an exact key match. <code>v1</code> reported <code>true</code> for any restore. This matches what <code>actions/cache</code> means by <code>cache-hit</code>.</p>
<p>No inputs or outputs were removed or renamed.</p>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li><strong>Flexible version specs.</strong> <code>version</code> accepts an exact version (<code>12.0.0-beta.4</code>), a semver range (<code>^12.0.0</code>), or an npm dist-tag (<code>next-12</code>). It is still optional when <code>packageManager</code> or <code>devEngines.packageManager</code> is set in <code>package.json</code>.</li>
<li><strong>Partial store cache reuse.</strong> Cache restore now falls back to restore keys, so a single changed dependency no longer forces a full re-download of the store.</li>
<li><strong>New <code>token</code> input.</strong> Used for the GitHub release lookup, defaulting to <code>${{ github.token }}</code> so the low anonymous API rate limit doesn&rsquo;t apply. It rarely needs to be set.</li>
<li><strong><code>pnpx</code>, <code>pn</code>, and <code>pnx</code> aliases</strong> are linked next to the <code>pnpm</code> binary.</li>
</ul>
<h2 id="upgrading">Upgrading</h2>
<p>For most workflows the upgrade is the tag:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-diff" data-lang="diff"><span style="display:flex;"><span><span style="color:#f92672">-      - uses: pnpm/setup@v1
</span></span></span><span style="display:flex;"><span><span style="color:#a6e22e">+      - uses: pnpm/setup@v2
</span></span></span></code></pre></div><p>Check first that the pnpm version you install — via the <code>version</code> input, <code>packageManager</code>, or <code>devEngines.packageManager</code> — is v11 or newer.</p>
<p>One platform caveat: pnpm v11 publishes no binary for Intel macOS (<code>darwin-x64</code>). Use pnpm v12 or newer on Intel macOS runners.</p>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-api-onboarding/</link><pubDate>Tue, 04 Aug 2026 22:31:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v3.2.11.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of setting up a new API repository by integrating with Postman. It handles tasks such as creating a workspace, uploading an OpenAPI specification, generating collections and environments, configuring mocks and monitors, and running smoke and contract tests. The action also integrates with GitHub for continuous integration, ensuring that all tests are automatically rerun on every push, pull request, or schedule.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v3.2.11</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of setting up a new API repository by integrating with Postman. It handles tasks such as creating a workspace, uploading an OpenAPI specification, generating collections and environments, configuring mocks and monitors, and running smoke and contract tests. The action also integrates with GitHub for continuous integration, ensuring that all tests are automatically rerun on every push, pull request, or schedule.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/91">https://github.com/postman-cs/postman-api-onboarding-action/pull/91</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/92">https://github.com/postman-cs/postman-api-onboarding-action/pull/92</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/93">https://github.com/postman-cs/postman-api-onboarding-action/pull/93</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/94">https://github.com/postman-cs/postman-api-onboarding-action/pull/94</a></li>
<li>chore(deps): pin Insights onboarding v2.2.1 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/95">https://github.com/postman-cs/postman-api-onboarding-action/pull/95</a></li>
<li>fix: consume Insights human-session normalization by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/96">https://github.com/postman-cs/postman-api-onboarding-action/pull/96</a></li>
<li>fix: consume repo-sync v2.2.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/97">https://github.com/postman-cs/postman-api-onboarding-action/pull/97</a></li>
<li>fix: expose mock environment and refresh Azure pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/98">https://github.com/postman-cs/postman-api-onboarding-action/pull/98</a></li>
<li>feat: pass mock visibility policy through to repo-sync by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/99">https://github.com/postman-cs/postman-api-onboarding-action/pull/99</a></li>
<li>chore: pin repo-sync v2.4.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/100">https://github.com/postman-cs/postman-api-onboarding-action/pull/100</a></li>
<li>fix: document private mock credential paths for consumers by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/101">https://github.com/postman-cs/postman-api-onboarding-action/pull/101</a></li>
<li>fix(deps): advance the bootstrap pin to v2.13.2 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/102">https://github.com/postman-cs/postman-api-onboarding-action/pull/102</a></li>
<li>fix(deps): advance bootstrap and repo-sync pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/103">https://github.com/postman-cs/postman-api-onboarding-action/pull/103</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/104">https://github.com/postman-cs/postman-api-onboarding-action/pull/104</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.8 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/105">https://github.com/postman-cs/postman-api-onboarding-action/pull/105</a></li>
<li>fix(deps): advance bootstrap pin to v2.13.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/106">https://github.com/postman-cs/postman-api-onboarding-action/pull/106</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>fix(ci): validate sibling pins without local checkouts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/111">https://github.com/postman-cs/postman-api-onboarding-action/pull/111</a></li>
<li>feat(azure-devops): forward an explicit workspace squad id from the Windows template by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/112">https://github.com/postman-cs/postman-api-onboarding-action/pull/112</a></li>
<li>fix(release): harden composite pin and E2E releases by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/113">https://github.com/postman-cs/postman-api-onboarding-action/pull/113</a></li>
<li>fix(release): supersede stale aliases with pending cuts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/114">https://github.com/postman-cs/postman-api-onboarding-action/pull/114</a></li>
<li>fix(release): wait for correlated E2E run names by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/115">https://github.com/postman-cs/postman-api-onboarding-action/pull/115</a></li>
<li>fix(release): keep pin ratchet synchronized by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/116">https://github.com/postman-cs/postman-api-onboarding-action/pull/116</a></li>
<li>fix(ci): preserve pin updater test fixtures by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/117">https://github.com/postman-cs/postman-api-onboarding-action/pull/117</a></li>
<li>fix(release): reconcile failed release completions by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/118">https://github.com/postman-cs/postman-api-onboarding-action/pull/118</a></li>
<li>fix(release): emit automated completion events by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/119">https://github.com/postman-cs/postman-api-onboarding-action/pull/119</a></li>
<li>fix(release): bound failed release recovery by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/120">https://github.com/postman-cs/postman-api-onboarding-action/pull/120</a></li>
<li>fix(release): hold auto release through E2E completion by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/121">https://github.com/postman-cs/postman-api-onboarding-action/pull/121</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@github-actions[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.2.11">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.2.11</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-onboarding-repo-sync/</link><pubDate>Tue, 04 Aug 2026 22:30:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.8.9.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of synchronizing Postman collections and environments into a repository. It generates CI workflows to manage these assets, including mock servers and monitors. The action requires a Postman API key or a service-token step to mint one, along with workspace and collection IDs from inputs or configuration files. It supports multiple sync modes, allowing for both commit-only and full push operations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.8.9</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of synchronizing Postman collections and environments into a repository. It generates CI workflows to manage these assets, including mock servers and monitors. The action requires a Postman API key or a service-token step to mint one, along with workspace and collection IDs from inputs or configuration files. It supports multiple sync modes, allowing for both commit-only and full push operations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>perf(repo-sync): bound artifact acquisition reads by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/116">https://github.com/postman-cs/postman-repo-sync-action/pull/116</a></li>
<li>fix(deps): replace deprecated Faker with compatible v6 by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/117">https://github.com/postman-cs/postman-repo-sync-action/pull/117</a></li>
<li>fix(repo-mutation): reconcile stale branch before push by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/118">https://github.com/postman-cs/postman-repo-sync-action/pull/118</a></li>
<li>fix(repo-mutation): resolve generated artifact conflicts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/119">https://github.com/postman-cs/postman-repo-sync-action/pull/119</a></li>
<li>fix(release): notify the composite after Repo Sync publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/121">https://github.com/postman-cs/postman-repo-sync-action/pull/121</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.8.9">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.8.9</a></p>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/prowler-security-scan/</link><pubDate>Tue, 04 Aug 2026 22:29:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.37.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Prowler is an Open Source Cloud Security Platform designed to automate security and compliance across any cloud environment, offering over 3,000 checks and integrations with leading compliance frameworks. The action automates Prowler’s functionality into GitHub Actions workflows, simplifying the integration of security audits into CI/CD pipelines. It supports various cloud providers and provides detailed reports on potential security issues.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.37.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Prowler is an Open Source Cloud Security Platform designed to automate security and compliance across any cloud environment, offering over 3,000 checks and integrations with leading compliance frameworks. The action automates Prowler&rsquo;s functionality into GitHub Actions workflows, simplifying the integration of security audits into CI/CD pipelines. It supports various cloud providers and provides detailed reports on potential security issues.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="ui">UI</h2>
<h3 id="-fixed">🐞 Fixed</h3>
<ul>
<li>Fixed image optimization in the production container: Next.js standalone tracing omitted <code>sharp</code>&rsquo;s native <code>libvips</code> library, so every image was served unoptimized <a href="https://github.com/prowler-cloud/prowler/pull/12307">(#12307)</a></li>
</ul>
<h3 id="-security">🔐 Security</h3>
<ul>
<li>The UI container image now patches musl and zlib alongside OpenSSL, and <code>sharp</code> is pinned to 0.35.3, clearing the image&rsquo;s remaining CVEs <a href="https://github.com/prowler-cloud/prowler/pull/12307">(#12307)</a></li>
</ul>
<h2 id="api">API</h2>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li>Entra Conditional Access guest-user checks no longer report false FAILs in M365 scans: microsoft-kiota packages overridden to 1.9.10 so <code>guestOrExternalUserTypes</code> (a flags enum Graph serializes as a comma-separated string) deserializes correctly instead of returning an empty list <a href="https://github.com/prowler-cloud/prowler/pull/12315">(#12315)</a></li>
</ul>
<h3 id="-security-1">🔐 Security</h3>
<ul>
<li>The API container image now builds on Debian 13 (trixie), taking its critical CVE count from 18 to 4 <a href="https://github.com/prowler-cloud/prowler/pull/12311">(#12311)</a></li>
<li>Bumped PowerShell, Trivy and uv in the API container image, clearing 14 high-severity CVEs <a href="https://github.com/prowler-cloud/prowler/pull/12311">(#12311)</a></li>
<li>Bumped <code>workos</code> and <code>pyopenssl</code> so the API can move to <code>cryptography</code> 48.0.1 <a href="https://github.com/prowler-cloud/prowler/pull/12311">(#12311)</a></li>
<li>Removed <code>gnupg</code> and <code>apt-transport-https</code> from the API container image <a href="https://github.com/prowler-cloud/prowler/pull/12311">(#12311)</a></li>
<li>The API container image no longer ships <code>git</code>; removing it also dropped <code>perl</code>, <code>perl-modules</code>, <code>libperl</code> and <code>liberror-perl</code>, clearing 12 critical CVEs. Only <code>perl-base</code> remains, which Debian marks Essential and cannot be removed <a href="https://github.com/prowler-cloud/prowler/pull/12311">(#12311)</a></li>
<li>Removed <code>pip</code> from the API container image, clearing two high-severity CVEs in the vendored copies of <code>setuptools</code> and <code>msgpack</code> <a href="https://github.com/prowler-cloud/prowler/pull/12311">(#12311)</a></li>
<li>Bumped <code>pillow</code> to 12.3.0, <code>httplib2</code> to 0.32.0 and <code>pyasn1</code> to 0.6.4 to resolve known CVEs <a href="https://github.com/prowler-cloud/prowler/pull/12311">(#12311)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-changed">🔄 Changed</h3>
<ul>
<li>Huawei Cloud exception codes moved from <code>19000</code>-<code>19007</code> to <code>20000</code>-<code>20007</code>, resolving a collision with E2E Networks which reserves <code>19000</code>-<code>19999</code> <a href="https://github.com/prowler-cloud/prowler/pull/12306">(#12306)</a></li>
</ul>
<h3 id="-fixed-2">🐞 Fixed</h3>
<ul>
<li>Checks registered through the <code>prowler.checks.&lt;provider&gt;</code> entry-point group can now run against built-in providers. The built-in probe in <code>_resolve_check_module</code> used a bare <code>find_spec</code>, which imports the parent package to search it and so raised <code>ModuleNotFoundError</code> for a plug-in check instead of returning <code>None</code>, aborting the lookup before the entry points were consulted. Such a check was discovered, listed and selected for execution, then silently produced no findings. <a href="https://github.com/prowler-cloud/prowler/pull/12312">(#12312)</a></li>
<li>Entra Conditional Access guest-user checks no longer report false FAILs: microsoft-kiota packages bumped to 1.9.10 so <code>guestOrExternalUserTypes</code> (a flags enum Graph serializes as a comma-separated string) deserializes correctly instead of returning an empty list <a href="https://github.com/prowler-cloud/prowler/pull/12315">(#12315)</a></li>
</ul>
<h3 id="-security-2">🔐 Security</h3>
<ul>
<li>Bumped the Compose <code>postgres</code> and <code>valkey</code> images, clearing 10 critical CVEs <a href="https://github.com/prowler-cloud/prowler/pull/12307">(#12307)</a></li>
<li>Bumped PowerShell, Trivy, uv and <code>joserfc</code> in the container images, clearing 14 high-severity CVEs from the SDK and API images <a href="https://github.com/prowler-cloud/prowler/pull/12307">(#12307)</a></li>
<li>Bumped <code>httplib2</code> to 0.32.0 and <code>pyasn1</code> to 0.6.4 to resolve known CVEs <a href="https://github.com/prowler-cloud/prowler/pull/12307">(#12307)</a></li>
<li>The SDK container image now builds on Debian 13 (trixie), clearing the unfixable <code>libsqlite3-0</code> and <code>zlib1g</code> criticals <a href="https://github.com/prowler-cloud/prowler/pull/12307">(#12307)</a></li>
<li>Bumped <code>cryptography</code> to 48.0.1 to resolve GHSA-537c-gmf6-5ccf, along with the <code>oci</code>, <code>alibabacloud-tea-openapi</code>, <code>darabonba-core</code> and <code>py-ocsf-models</code> bumps it requires <a href="https://github.com/prowler-cloud/prowler/pull/12307">(#12307)</a></li>
<li>Removed <code>pip</code> from the SDK container image, clearing two high-severity CVEs in the vendored copies of <code>setuptools</code> and <code>msgpack</code> <a href="https://github.com/prowler-cloud/prowler/pull/12307">(#12307)</a></li>
<li>Removed <code>wget</code>, <code>gnupg</code> and <code>apt-transport-https</code> from the SDK runtime image <a href="https://github.com/prowler-cloud/prowler/pull/12307">(#12307)</a></li>
</ul>
<h2 id="mcp">MCP</h2>
<h3 id="-security-3">🔐 Security</h3>
<ul>
<li>Bumped <code>fastmcp</code> and pinned <code>cryptography</code>, <code>joserfc</code>, <code>mcp</code> and <code>python-multipart</code>, clearing all 7 high-severity CVEs from the MCP image <a href="https://github.com/prowler-cloud/prowler/pull/12307">(#12307)</a></li>
</ul>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/kaniko-build-action/</link><pubDate>Tue, 04 Aug 2026 22:27:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints a greeting message to the console, either “Hello World” or “Hello [name]” of a specified person. It automates the process of customizing and displaying greetings based on user input.
What’s Changed Full Changelog: https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints a greeting message to the console, either &ldquo;Hello World&rdquo; or &ldquo;Hello [name]&rdquo; of a specified person. It automates the process of customizing and displaying greetings based on user input.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/rumdl-action/</link><pubDate>Tue, 04 Aug 2026 22:27:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.50.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rumdl is a high-performance Markdown linter and formatter written in Rust that offers speed, numerous lint rules, automatic formatting, and support for various Markdown flavors. It simplifies the process of ensuring consistent Markdown quality by providing a modern CLI tool with detailed error reporting and configuration options.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.50</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>rumdl is a high-performance Markdown linter and formatter written in Rust that offers speed, numerous lint rules, automatic formatting, and support for various Markdown flavors. It simplifies the process of ensuring consistent Markdown quality by providing a modern CLI tool with detailed error reporting and configuration options.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>md077</strong>: support fixed continuation indent config (#786) (<a href="https://github.com/rvben/rumdl/commit/fea63227ae14db43956303a2bbae97ac41d7f68c">fea6322</a>)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>md065</strong>: leave markers alone inside a block that hides its content (<a href="https://github.com/rvben/rumdl/commit/26543648458feb2111e46ec6e6cbb301917636d5">2654364</a>)</li>
<li><strong>md065</strong>: report thematic breaks written with spaces between markers (<a href="https://github.com/rvben/rumdl/commit/1d292366b43bf2dbcc20d1f22ceb0e6fb73652ab">1d29236</a>)</li>
<li><strong>md076</strong>: ask the parser whether a list item&rsquo;s block is really fenced (<a href="https://github.com/rvben/rumdl/commit/fd616c2c31009eb8b39d29836b2ef7b51242e8a6">fd616c2</a>)</li>
<li><strong>md022</strong>: require a blank line below a heading above a spaced thematic break (<a href="https://github.com/rvben/rumdl/commit/27120f25a9b620fcc0f827ed77b97f2f6b57f4f4">27120f2</a>)</li>
<li><strong>MD076</strong>: preserve fenced list item spacing (#788) (<a href="https://github.com/rvben/rumdl/commit/2d60067a2ff5e38875919c7c57190b77f8d7eb9f">2d60067</a>)</li>
<li><strong>md022</strong>: use the same list test below a heading in check and fix (#790) (<a href="https://github.com/rvben/rumdl/commit/ef926b78500015769c23423ebbcf9e332de87385">ef926b7</a>)</li>
<li><strong>md040</strong>: locate the fence a list marker holds instead of assuming the indent (<a href="https://github.com/rvben/rumdl/commit/6099a6c11d687480bdaf82f01d8f9695d5998570">6099a6c</a>)</li>
<li><strong>md077</strong>: keep the strict-flavor minimum as a floor under a configured indent (<a href="https://github.com/rvben/rumdl/commit/cfaad2e072c5a69a9e28b9678b126c7f3642b9d4">cfaad2e</a>)</li>
<li><strong>md077</strong>: reject a configured indent of 0 (<a href="https://github.com/rvben/rumdl/commit/1ac97a338a109ddc91eee3db557c5798402f8a72">1ac97a3</a>)</li>
<li><strong>md077</strong>: accept the indent option instead of reporting it as unknown (<a href="https://github.com/rvben/rumdl/commit/cba175c0bb148b9a9f5b5dc4082aa00f46da815c">cba175c</a>)</li>
<li><strong>md013</strong>: stop exempting a complete link followed by a parenthesized aside (<a href="https://github.com/rvben/rumdl/commit/722fad6984692318160f7ddce71b55701c20d280">722fad6</a>)</li>
<li><strong>md013</strong>: keep nested links intact when reflowing emphasis spans (#779) (<a href="https://github.com/rvben/rumdl/commit/cb652371b3f498df009ef4b1018b49efcc1388c6">cb65237</a>)</li>
<li><strong>md013</strong>: exempt standalone links with nested markup or unresolved references (#781) (<a href="https://github.com/rvben/rumdl/commit/2c52283cb6906f6620cfd3986b3d4dc300175e5e">2c52283</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.50-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.50-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.50-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.50-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-x86_64-apple-darwin.tar.gz">rumdl-v0.2.50-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-aarch64-apple-darwin.tar.gz">rumdl-v0.2.50-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-x86_64-pc-windows-msvc.zip">rumdl-v0.2.50-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.50/rumdl-v0.2.50-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Zetestic</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/zetestic/</link><pubDate>Tue, 04 Aug 2026 22:26:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/zetestic/</guid><description>Version updated for https://github.com/Rzhan9/prtestbot to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary A GitHub Action and Python tool that automatically reviews Pull Request diffs to determine if changes have adequate test coverage by analyzing code diff, locating related existing tests, identifying changed/added behavior, determining coverage status, and suggesting concrete tests. It posts a formatted report as a PR comment and updates its previous comment on subsequent commits.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Rzhan9/prtestbot">https://github.com/Rzhan9/prtestbot</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zetestic">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>A GitHub Action and Python tool that automatically reviews Pull Request diffs to determine if changes have adequate test coverage by analyzing code diff, locating related existing tests, identifying changed/added behavior, determining coverage status, and suggesting concrete tests. It posts a formatted report as a PR comment and updates its previous comment on subsequent commits.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Will now keep track of a score based on how many test obligations are created and how many are actually adequately covered. If 10 obligations are created and 8 are fulfilled, the score will be 8/10. The bot will now also fail if the final score is less than 70%.</p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/custom-amazon-bedrock-agent-action/</link><pubDate>Tue, 04 Aug 2026 22:25:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback. The action automates code quality improvement, security assessments, and performance optimizations by leveraging customizable prompts and context-aware insights from Amazon Bedrock Knowledge Bases. It integrates seamlessly with AWS services, enhancing the analysis capability for more precise and coherent feedback.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback. The action automates code quality improvement, security assessments, and performance optimizations by leveraging customizable prompts and context-aware insights from Amazon Bedrock Knowledge Bases. It integrates seamlessly with AWS services, enhancing the analysis capability for more precise and coherent feedback.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/sherpa.sh/</link><pubDate>Tue, 04 Aug 2026 22:24:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven GitHub Action that automates the deployment of applications to various cloud providers. It simplifies infrastructure management by allowing developers to describe their requirements in plain English, and Sherpa automatically configures and deploys the necessary resources, including servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more. The action supports popular development frameworks like Next.js, SvelteKit, and Nuxt, as well as integration with various cloud providers such as AWS, Google Cloud, and Azure.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven GitHub Action that automates the deployment of applications to various cloud providers. It simplifies infrastructure management by allowing developers to describe their requirements in plain English, and Sherpa automatically configures and deploys the necessary resources, including servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more. The action supports popular development frameworks like Next.js, SvelteKit, and Nuxt, as well as integration with various cloud providers such as AWS, Google Cloud, and Azure.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>E2E Testing Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/e2e-testing-suite/</link><pubDate>Tue, 04 Aug 2026 22:22:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/e2e-testing-suite/</guid><description>Version updated for https://github.com/SillyLittleTech/E2E to version 2.7.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates end-to-end testing of a website by capturing screenshots across multiple viewports and modes, running accessibility tests, performing unit tests, and generating a rich Markdown report on pull requests. It simplifies the process of testing web applications without requiring additional test scripts in the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SillyLittleTech/E2E">https://github.com/SillyLittleTech/E2E</a></strong> to version <strong>2.7.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/e2e-testing-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates end-to-end testing of a website by capturing screenshots across multiple viewports and modes, running accessibility tests, performing unit tests, and generating a rich Markdown report on pull requests. It simplifies the process of testing web applications without requiring additional test scripts in the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: Make E2E action modular and dynamic by @kiyarose in <a href="https://github.com/SillyLittleTech/E2E/pull/3">https://github.com/SillyLittleTech/E2E/pull/3</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SillyLittleTech/E2E/compare/0.1...2.7.3">https://github.com/SillyLittleTech/E2E/compare/0.1...2.7.3</a></p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/ssg-static-site-generator/</link><pubDate>Tue, 04 Aug 2026 22:21:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.17.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a static site generator written in Go that converts Markdown content with YAML frontmatter into a complete website, including features like built-in themes, templates, search engines, and image processing. It optimizes performance and ensures deterministic builds, making it suitable for blogs and WordPress migrations while also supporting documentation and other types of websites.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.17</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a static site generator written in Go that converts Markdown content with YAML frontmatter into a complete website, including features like built-in themes, templates, search engines, and image processing. It optimizes performance and ensures deterministic builds, making it suitable for blogs and WordPress migrations while also supporting documentation and other types of websites.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.17 — up to 5.25x faster builds, four parallel-render races fixed, determinism + golden now in CI by @spagu in <a href="https://github.com/spagu/ssg/pull/72">https://github.com/spagu/ssg/pull/72</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.16...v1.8.17">https://github.com/spagu/ssg/compare/v1.8.16...v1.8.17</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/classroom-to-sheets-integration/</link><pubDate>Tue, 04 Aug 2026 22:20:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending assignment results from GitHub Classroom to Google Sheets. It uses Google Sheets API credentials and integrates with GitHub Actions workflows to update specific tasks’ results in a predefined sheet. The action allows for dynamic column creation based on task names, ensuring compatibility with different grading systems.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending assignment results from GitHub Classroom to Google Sheets. It uses Google Sheets API credentials and integrates with GitHub Actions workflows to update specific tasks&rsquo; results in a predefined sheet. The action allows for dynamic column creation based on task names, ensuring compatibility with different grading systems.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/runward-gate/</link><pubDate>Tue, 04 Aug 2026 22:19:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.32.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is an open-source delivery methodology that verifies engineering decisions behind AI-generated code. It helps ensure that projects are designed, implemented, and deployed with rigor, using plain code to validate architectural and security measures. The action automates the verification of these decisions through a deterministic gate process, providing compliance evidence for ISO 42001, NIST AI RMF, and EU AI Act standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.32.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Runward is an open-source delivery methodology that verifies engineering decisions behind AI-generated code. It helps ensure that projects are designed, implemented, and deployed with rigor, using plain code to validate architectural and security measures. The action automates the verification of these decisions through a deterministic gate process, providing compliance evidence for ISO 42001, NIST AI RMF, and EU AI Act standards.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>The largest correctness release this project has had.</strong> Five adversarial audits, every case <em>executed</em> against the shipped binary rather than reasoned about.</p>
<p>Three asked <em>&ldquo;how do I get a false green&rdquo;</em>. Two asked the opposite: <em>&ldquo;where does the gate cry on a mission that is telling the truth&rdquo;</em>. Both halves were needed — <strong>of the nine hardening classes written in the morning, four cried on the honest case.</strong></p>
<h2 id="the-gate-could-be-satisfied-by-paperwork">The gate could be satisfied by paperwork</h2>
<p><code>check --strict</code> exited 0 on missions containing <strong>no evidence at all</strong>. The cheapest cost <strong>2 726 bytes of arbitrary text and zero lines of project code</strong>, with the seal applied and the ISO 42001 pack assembled on top.</p>
<p>The aggravating form: <strong>the emptiest missions produced the most reassuring output.</strong> Citing each rule&rsquo;s own file printed <code>36 of 36 typed pointers the gate opened and checked (100%)</code>. Answering <code>n/a</code> to all 36 rules removed the only vacuity signal, because that counter printed only when <code>applied &gt; 0</code>.</p>
<p>Closed: the corpus is checked against the <strong>installed package</strong> rather than a lock the audited party can re-sign; circular evidence is refused (<code>file:&lt;manifest&gt;#&lt;slug&gt;</code> was a universal green key, the slug being column 1 of every row); a 0-byte ADR, the scaffolded template, a rejected or unratified decision no longer satisfy a deviation; containment actually runs on the real path, so a symlink to <code>/etc/hosts</code> no longer turns the seal into a file-read oracle; the seal covers the claim and not only the files it cites; the counter is unconditional and counts only pointers the gate could open; the grammar is read before anything rewrites it; and a catastrophic signature can no longer hang the gate in CI.</p>
<h2 id="the-gate-refused-honest-missions">The gate refused honest missions</h2>
<p>A <strong>Windows checkout</strong> made all 64 rules read as empty and the gate announced <em>&ldquo;the mapping may have been stripped&rdquo;</em> — git doing its documented job accused the operator. <strong>npm/pnpm workspaces</strong> broke under the containment hardening, a regression introduced by the first half of this same release. An <strong>unreadable file</strong> was a crash rather than a verdict, and <code>--json</code> stopped being JSON. The gate <strong>punished precision</strong>: a path outside the project passed as prose and failed as a typed pointer. A <strong>documentary rule</strong> could not be proven at all. <strong>House rules</strong> made a normal team&rsquo;s mission red. And <code>file:SRC/Guard.TS</code> went green on macOS while failing on Linux CI.</p>
<p>All closed, each verified by re-running the case that produced the wrong verdict.</p>
<h2 id="what-this-changes-for-you">What this changes for you</h2>
<p><strong>Missions that were green may go red</strong> — a hand-edited rule, a deviation resting on an unratified ADR, a circular pointer. Those verdicts were about something other than what they claimed.</p>
<p><strong>Missions that were red may go green</strong> — every Windows checkout, every workspace.</p>
<p>Nothing changes in the exit-code contract, the machine surface, or the six phases. And none of this makes the gate judge whether evidence <em>implements</em> a rule: <code>GATE_NON_SCOPE</code> is unchanged and remains the honest statement of depth.</p>
<p><a href="https://github.com/stranxik/runward/blob/main/docs/adr/ADR-0045-the-gate-cannot-be-satisfied-by-paperwork.md">ADR-0045</a> records the nine classes, what stays declared, the alternatives refused, and the one class deliberately <strong>not</strong> done with the measurement that made it near-redundant.</p>
<p><strong>196 unit tests.</strong> runward&rsquo;s own mission and the shipped example green throughout.</p>
<p>Full changelog: <a href="https://github.com/stranxik/runward/blob/main/CHANGELOG.md">CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/wails3-build-action/</link><pubDate>Tue, 04 Aug 2026 22:18:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building of Wails.io applications using GoLang and NodeJS. It supports various build platforms, obfuscation options, and uploads artifacts to GitHub or a release on tagged builds. The default configuration is set up to build for multiple platforms and upload results to GitHub. Users can customize the action by specifying different Go and Wails versions, build names, platforms, and uploading settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building of Wails.io applications using GoLang and NodeJS. It supports various build platforms, obfuscation options, and uploads artifacts to GitHub or a release on tagged builds. The default configuration is set up to build for multiple platforms and upload results to GitHub. Users can customize the action by specifying different Go and Wails versions, build names, platforms, and uploading settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>aicheck-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/aicheck-scan/</link><pubDate>Tue, 04 Aug 2026 22:17:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/aicheck-scan/</guid><description>Version updated for https://github.com/unauthdev/aicheck-scan to version v1.2.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aicheck GitHub Action automates the detection of AI services with unauthenticated access, providing visibility into potential security risks in a CI/CD pipeline. It supports multiple deployment platforms and offers various ways to integrate it, including as a Docker image, GitHub Action, or standalone command-line tool. The action helps ensure that AI services are securely configured and minimizes exposure by identifying services without authentication mechanisms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/unauthdev/aicheck-scan">https://github.com/unauthdev/aicheck-scan</a></strong> to version <strong>v1.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aicheck-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>aicheck</code> GitHub Action automates the detection of AI services with unauthenticated access, providing visibility into potential security risks in a CI/CD pipeline. It supports multiple deployment platforms and offers various ways to integrate it, including as a Docker image, GitHub Action, or standalone command-line tool. The action helps ensure that AI services are securely configured and minimizes exposure by identifying services without authentication mechanisms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Drift-honest inventory (unreachable hosts no longer report fixed), probe-coverage surfacing, hardened fingerprints (validated against ~1,100 real Shodan banners, zero cross-FP), structured CVE fields in findings, Milvus + Attu checker, schema_version 1 on inventory output, HMAC-signed webhooks, supply-chain gates (SBOM, image provenance, digest-pinned base). SHA256 sums of the distributions are appended below by the publish workflow.</p>
<h2 id="sha256">SHA256</h2>
<pre tabindex="0"><code>e7bf39779533902ccab8b2109b1c4ac83a59f8cf5ad2086e02a1c479c0f75088  aicheck_scan-1.2.3-py3-none-any.whl
1315bf900dad60619027088d8c07b1208c63926114ea48ba9d0b2db1a7ebafe1  aicheck_scan-1.2.3.tar.gz
</code></pre>]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/b.ia-accessibility-checker/</link><pubDate>Tue, 04 Aug 2026 22:16:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks for code in CI/CD pipelines, allowing developers to focus on meeting WCAG guidelines across multiple audiences efficiently. The action uses AI to analyze and measure the accessibility of code against predefined requirements, ensuring compliance with various guidelines for different target groups. This helps companies avoid unnecessary efforts and focuses on high-value user groups.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks for code in CI/CD pipelines, allowing developers to focus on meeting WCAG guidelines across multiple audiences efficiently. The action uses AI to analyze and measure the accessibility of code against predefined requirements, ensuring compliance with various guidelines for different target groups. This helps companies avoid unnecessary efforts and focuses on high-value user groups.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>vibecheck-ai-slop</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/vibecheck-ai-slop/</link><pubDate>Tue, 04 Aug 2026 22:15:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/vibecheck-ai-slop/</guid><description>Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.16.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary vibecheck is an AI-generated code smell checker that automates the identification of common coding issues in AI-generated code. It provides 39 rules to detect security vulnerabilities, error handling problems, and code quality issues without requiring configuration or API keys. The tool runs locally and is available as a standalone binary for macOS and Linux.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuvrajangadsingh/vibecheck">https://github.com/yuvrajangadsingh/vibecheck</a></strong> to version <strong>v1.16.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibecheck-ai-slop">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>vibecheck is an AI-generated code smell checker that automates the identification of common coding issues in AI-generated code. It provides 39 rules to detect security vulnerabilities, error handling problems, and code quality issues without requiring configuration or API keys. The tool runs locally and is available as a standalone binary for macOS and Linux.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yuvrajangadsingh/vibecheck/compare/v1.16.0...v1.16.1">https://github.com/yuvrajangadsingh/vibecheck/compare/v1.16.0...v1.16.1</a></p>
]]></content:encoded></item><item><title>AGENTS.md Lint (Schliff)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/agents.md-lint-schliff/</link><pubDate>Tue, 04 Aug 2026 22:13:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/agents.md-lint-schliff/</guid><description>Version updated for https://github.com/Zandereins/schliff to version v8.10.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Schliff is a tool that evaluates the quality and coherence of AGENTS.md files used to drive AI tools like Cursor, Codex, Copilot, and Claude Code. It provides deterministic scores based on an explicit rubric, ensuring consistent evaluation across different machines. The action automates this process by scoring AGENTS.md files and allows for reproducible results through versioned rubrics.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zandereins/schliff">https://github.com/Zandereins/schliff</a></strong> to version <strong>v8.10.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-md-lint-schliff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Schliff is a tool that evaluates the quality and coherence of AGENTS.md files used to drive AI tools like Cursor, Codex, Copilot, and Claude Code. It provides deterministic scores based on an explicit rubric, ensuring consistent evaluation across different machines. The action automates this process by scoring <code>AGENTS.md</code> files and allows for reproducible results through versioned rubrics.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>The hosted playground, leaderboard and badge endpoint have been retired.</strong> The CLI, the GitHub Action, the pre-commit hook and the Claude Code skill are unaffected and continue to be maintained.</p>
<p>This release exists for one reason: <code>pyproject.toml</code> sets <code>readme = &quot;README.md&quot;</code>, so the PyPI project page kept advertising services that no longer answer. The wheel itself is functionally unchanged from 8.10.0.</p>
<h2 id="removed--the-hosted-surfaces">Removed — the hosted surfaces</h2>
<p><code>schliff-playground.vercel.app</code> and <code>schliff-leaderboard.vercel.app</code> now serve a static retirement notice and hold no functions and no environment variables. The Redis instance behind the leaderboard&rsquo;s rate limiter has been deleted.</p>
<p><strong>The reason is not the one this started as.</strong> The trigger was a provider-identification duty, which for a non-monetised open-source demo is genuinely disputed. The load-bearing reason is the <strong>data-protection information duty</strong>, which attaches to <em>processing</em> rather than to how an operator presents themselves — visitor IPs used as rate-limit keys are processing, and no address, wording change or legal opinion discharges it. It is a permanent operating obligation, and it was being paid for surfaces with <strong>no demonstrable demand</strong>: web analytics was never enabled on either project, and a code search for both URLs returned references in three repositories, all maintainer-owned.</p>
<p><strong>Badges already embedded in a README do not break.</strong> <code>/api/badge</code> still answers — as a static shields endpoint reporting <code>retired</code> in grey. Both Vercel projects are kept rather than deleted, deliberately: a released <code>*.vercel.app</code> subdomain is re-registrable, and this project&rsquo;s own Action had already written the playground URL into third-party pull requests.</p>
<p>The application code and its tests stay in the repository. Full rationale and the rejected alternatives — a service address, a static client-side rebuild, deleting the projects — are in <a href="https://github.com/Zandereins/schliff/blob/main/docs/adr/0008-retire-hosted-surfaces.md"><code>docs/adr/0008-retire-hosted-surfaces.md</code></a>.</p>
<h2 id="fixed--the-documented-ci-recipe">Fixed — the documented CI recipe</h2>
<p>If you copied the GitHub Action example from the README, <strong>please re-check it against the new one.</strong></p>
<ul>
<li><strong>It granted no permissions while the feature it documents needs one.</strong> <code>comment-on-pr</code> defaults to <code>true</code> and the comment step needs <code>pull-requests: write</code>. In repositories whose default token is read-only the documented feature failed silently; in repositories with a read-write default the workflow ran with more privilege than it needed. The example now carries the minimal set.</li>
<li><strong>Added the missing warning against <code>pull_request_target</code>.</strong> It is exactly the trigger you reach for when fork-PR comments fail, and it pairs a write-scoped token with a checkout of untrusted code. On a fork PR the read-only token is the <em>intended</em> degradation — score and exit code still work, only the comment is skipped.</li>
<li><strong>The example pinned <code>actions/checkout@v4</code></strong> while every workflow in this repository pins by commit SHA. It now uses the same SHA those workflows already trust.</li>
</ul>
<h2 id="changed--where-a-model-is-involved-and-where-it-is-not">Changed — where a model is involved, and where it is not</h2>
<p>The README now states it plainly instead of leaving it to be inferred. Scoring calls <strong>no</strong> model, and core schliff is literally zero-dependency — <code>pyproject.toml</code> declares no <code>dependencies</code> at all. The two opt-in extras that do call one run <strong>from your machine with your own API key</strong>; this project operates no inference service, holds no key of yours, and receives nothing you score. Without the extra installed those paths refuse to run rather than degrading silently, and <code>schliff evolve --budget 0</code> never imports the LLM path at all. The install table now names the actual packages (<code>anthropic</code>, <code>pydantic</code>, <code>litellm</code>) instead of saying &ldquo;LLM client&rdquo;.</p>
<h2 id="verification">Verification</h2>
<ul>
<li>1939 tests pass on 3.10 / 3.11 / 3.12 / 3.13 and macOS; <code>ruff==0.15.8</code> and markdownlint clean</li>
<li><code>python -m build</code> + <code>twine check</code>: both artifacts PASSED</li>
<li>The built wheel, installed into a clean non-editable venv, loads from <code>site-packages</code> and reports <code>8.10.1</code>; all four fixes from 8.10.0 re-verified inside that artifact</li>
<li><code>install.sh</code> reports <code>Schliff v8.10.1</code>; the README hero block reproduces byte-for-byte against the real CLI</li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/Zandereins/schliff/compare/v8.10.0...v8.10.1">https://github.com/Zandereins/schliff/compare/v8.10.0...v8.10.1</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-onboarding-repo-sync/</link><pubDate>Tue, 04 Aug 2026 15:07:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.8.8.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action synchronizes Postman collections, environments, CI workflows, and monitors into a repository. It automates the setup of API onboarding by exporting and integrating Postman resources with your existing CI/CD pipeline. The action supports various configurations like workspace-specific assets, environment runtime URLs, and postman credentials to ensure seamless integration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.8.8</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action synchronizes Postman collections, environments, CI workflows, and monitors into a repository. It automates the setup of API onboarding by exporting and integrating Postman resources with your existing CI/CD pipeline. The action supports various configurations like workspace-specific assets, environment runtime URLs, and postman credentials to ensure seamless integration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>perf(repo-sync): bound artifact acquisition reads by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/116">https://github.com/postman-cs/postman-repo-sync-action/pull/116</a></li>
<li>fix(deps): replace deprecated Faker with compatible v6 by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/117">https://github.com/postman-cs/postman-repo-sync-action/pull/117</a></li>
<li>fix(repo-mutation): reconcile stale branch before push by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/118">https://github.com/postman-cs/postman-repo-sync-action/pull/118</a></li>
<li>fix(repo-mutation): resolve generated artifact conflicts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/119">https://github.com/postman-cs/postman-repo-sync-action/pull/119</a></li>
<li>fix(release): notify the composite after Repo Sync publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/121">https://github.com/postman-cs/postman-repo-sync-action/pull/121</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.8.8">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.8.8</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Smoke Flow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-onboarding-smoke-flow/</link><pubDate>Tue, 04 Aug 2026 15:06:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-onboarding-smoke-flow/</guid><description>Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v3.3.2.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Smoke Flow GitHub Action reshapes a generated Postman Smoke collection into an ordered smoke journey, automating the process of curating and organizing API tests. It supports automatic flow path creation based on an explicit flow-path or derived manifest from an OpenAPI spec, with optional OAuth2 and API key authentication. The action integrates seamlessly with the broader Postman API Onboarding suite for streamlined project setup and testing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-smoke-flow-action">https://github.com/postman-cs/postman-smoke-flow-action</a></strong> to version <strong>v3.3.2</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-smoke-flow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Smoke Flow GitHub Action reshapes a generated Postman Smoke collection into an ordered smoke journey, automating the process of curating and organizing API tests. It supports automatic flow path creation based on an explicit <code>flow-path</code> or derived manifest from an OpenAPI spec, with optional OAuth2 and API key authentication. The action integrates seamlessly with the broader Postman API Onboarding suite for streamlined project setup and testing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): cut immutable tags only after gates pass on main by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/57">https://github.com/postman-cs/postman-smoke-flow-action/pull/57</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/58">https://github.com/postman-cs/postman-smoke-flow-action/pull/58</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/59">https://github.com/postman-cs/postman-smoke-flow-action/pull/59</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/60">https://github.com/postman-cs/postman-smoke-flow-action/pull/60</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/61">https://github.com/postman-cs/postman-smoke-flow-action/pull/61</a></li>
<li>fix(release): notify the composite after Smoke Flow publish by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/64">https://github.com/postman-cs/postman-smoke-flow-action/pull/64</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.7...v3.3.2">https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.7...v3.3.2</a></p>
]]></content:encoded></item><item><title>diff-sentry malicious change scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/diff-sentry-malicious-change-scan/</link><pubDate>Tue, 04 Aug 2026 15:05:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/diff-sentry-malicious-change-scan/</guid><description>Version updated for https://github.com/qazbnm456/diff-sentry to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary diff-sentry is a GitHub Action designed to scan pull requests against potential malicious or obfuscated code patterns using machine learning models. It checks for various attack vectors such as workflow configuration, obfuscation, execution techniques, and exfiltration, providing evidence-based alerts without relying on an API key or model. The action runs efficiently under read-only tokens and can be configured to skip certain paths and report only specific severities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/qazbnm456/diff-sentry">https://github.com/qazbnm456/diff-sentry</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/diff-sentry-malicious-change-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>diff-sentry is a GitHub Action designed to scan pull requests against potential malicious or obfuscated code patterns using machine learning models. It checks for various attack vectors such as workflow configuration, obfuscation, execution techniques, and exfiltration, providing evidence-based alerts without relying on an API key or model. The action runs efficiently under read-only tokens and can be configured to skip certain paths and report only specific severities.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The first release, and a repositioning: the front door is now a GitHub Action anyone installs in fifteen lines. The trajectory / studio / fine-tuning half stays, as the second goal for people who run the infrastructure themselves.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">diff-sentry</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>: <span style="color:#ae81ff">pull_request</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">fetch-depth</span>: <span style="color:#ae81ff">0</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">qazbnm456/diff-sentry@v0.4.0</span>
</span></span></code></pre></div><p>No API key, no model, no network. It runs on fork pull requests under the read-only token they already get.</p>
<h2 id="highlights">Highlights</h2>
<p><strong>Ten new rules covering the AsyncAPI &ldquo;Miasma&rdquo; families.</strong> Reconstructing that supply-chain attack stage by stage found seven of its eight stages passing the rules silently: they were shell- and YAML-shaped while the attack was Node end to end. Now covered: <code>pull_request_target</code> that checks out the PR head (<code>pwn-request</code>, critical), payloads shoved past the diff viewport by a long whitespace run, bidi-override and zero-width characters, detached child processes, inline <code>node -e</code>, fetch-to-disk droppers, <code>_0x…</code> obfuscated identifiers, and IPFS/permaweb gateways.</p>
<p><strong>Severities are tuned, not maximal.</strong> A plain workflow edit is <code>medium</code> and does not fail your build. <code>pull_request_target</code> alone is <code>medium</code>, because that is the ordinary label-bot shape; it becomes <code>critical</code> only when the same workflow also checks out the PR head. Rules that would be noisy alone require two halves to fire. Every rule ships with its negative case, and the corpus pins both.</p>
<p><strong>Evidence a model cannot suppress.</strong> The deterministic rules run before any model takes a turn, and the alert decision is derived from the union of recorded hits rather than from a model&rsquo;s self-report. A successful prompt injection can skew a verdict; it cannot remove a piece of evidence. In the Action, no model runs at all.</p>
<p><strong>It runs on its own pull requests.</strong> This repo&rsquo;s CI uses the Action it publishes, scanned by the rules in the PR rather than the ones already on main, so every PR is an integration test of what you install. It caught a real defect on its first run.</p>
<p><strong>Deliberately not <code>pull_request_target</code>.</strong> Handing model credentials to a fork PR run requires exactly the misconfiguration that opened the Miasma compromise. The README documents the safe way to comment results back on a fork PR instead.</p>
<h2 id="also-in-this-release">Also in this release</h2>
<ul>
<li><code>diff-sentry scan</code> — the deterministic layer as a standalone command, with a <code>diff-sentry</code> console entry point.</li>
<li>Fixed: <code>scan</code> no longer flags what a diff <em>deletes</em>. Scanning a raw diff used to flag a change for the payload it was removing, which turns every remediation commit red.</li>
<li><code>rlm-kit</code> → <code>rlm-harness</code> 1.0.0 from PyPI; nothing in the dependency closure resolves outside PyPI any more.</li>
</ul>
<p>Full detail in <a href="https://github.com/qazbnm456/diff-sentry/blob/main/CHANGELOG.md">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>docker-hash</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/docker-hash/</link><pubDate>Tue, 04 Aug 2026 15:04:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/docker-hash/</guid><description>Version updated for https://github.com/RemkoMolier/docker-hash to version v0.3.17.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the computation of a deterministic SHA-256 hash for Docker images, based on various factors such as the Dockerfile content, build arguments, and files referenced in the build context. It is useful for cache-busting, change detection, and ensuring reproducibility in CI pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RemkoMolier/docker-hash">https://github.com/RemkoMolier/docker-hash</a></strong> to version <strong>v0.3.17</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-hash">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action automates the computation of a deterministic SHA-256 hash for Docker images, based on various factors such as the Dockerfile content, build arguments, and files referenced in the build context. It is useful for cache-busting, change detection, and ensuring reproducibility in CI pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="bug-fixes">Bug fixes</h3>
<ul>
<li>fix(deps): update dependency markdownlint-cli2 to v0.23.2 (#189)</li>
<li>fix(deps): update module github.com/google/go-containerregistry to v0.21.8 (#192)</li>
</ul>
]]></content:encoded></item><item><title>codemetrics complexity gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/codemetrics-complexity-gate/</link><pubDate>Tue, 04 Aug 2026 15:03:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/codemetrics-complexity-gate/</guid><description>Version updated for https://github.com/richardwooding/codemetrics to version v0.12.4.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The codemetrics action automates code complexity analysis across multiple programming languages, providing both cyclomatic and cognitive complexity metrics. It is a CLI tool that can be installed via Homebrew or go install, and it can also serve as a GitHub Action to gate pull requests based on function complexity. The action installs the latest codemetrics binary for the runner and fails the check if any function in the PR exceeds a specified threshold.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/richardwooding/codemetrics">https://github.com/richardwooding/codemetrics</a></strong> to version <strong>v0.12.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codemetrics-complexity-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>codemetrics</code> action automates code complexity analysis across multiple programming languages, providing both cyclomatic and cognitive complexity metrics. It is a CLI tool that can be installed via Homebrew or <code>go install</code>, and it can also serve as a GitHub Action to gate pull requests based on function complexity. The action installs the latest <code>codemetrics</code> binary for the runner and fails the check if any function in the PR exceeds a specified threshold.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="others">Others</h3>
<ul>
<li>1b1bb8cb76601a49436800c91dae91d1a6e4d74f: chore(deps): Bump github.com/odvcencio/gotreesitter (#34) (@dependabot[bot])</li>
</ul>
]]></content:encoded></item><item><title>file-search-on review gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/file-search-on-review-gate/</link><pubDate>Tue, 04 Aug 2026 15:01:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/file-search-on-review-gate/</guid><description>Version updated for https://github.com/richardwooding/file-search-on to version v0.119.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action performs a file search on a directory tree using CEL expressions to filter files based on metadata and content-type-specific attributes. It supports 74 file formats across thirteen content-type families, including document, markup, data, plain text, images, audio, video, office, ebooks, and source code. The action is designed for use with Claude Code, allowing users to query files by their content types.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/richardwooding/file-search-on">https://github.com/richardwooding/file-search-on</a></strong> to version <strong>v0.119.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/file-search-on-review-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action performs a file search on a directory tree using CEL expressions to filter files based on metadata and content-type-specific attributes. It supports 74 file formats across thirteen content-type families, including document, markup, data, plain text, images, audio, video, office, ebooks, and source code. The action is designed for use with Claude Code, allowing users to query files by their content types.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="others">Others</h3>
<ul>
<li>215b6263a31741c3db2ffe4b9cdcdaf80ac72219 chore(deps): Bump the minor-and-patch group with 2 updates (#567)</li>
<li>175cb0f0411e3c32a6c6e2c676b4d1b6b773d0af chore(deps): bump codemetrics to v0.12.4, treesitter-symbols to v0.6.4</li>
</ul>
]]></content:encoded></item><item><title>runs-on/action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/runs-on/action/</link><pubDate>Tue, 04 Aug 2026 15:00:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/runs-on/action/</guid><description>Version updated for https://github.com/runs-on/action to version v2.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The runs-on/action GitHub Action is designed to enhance RunsOn’s features by providing magic caching, which allows for faster execution of workflows by caching dependencies and results. It also offers options to display environment variables, job costs, and additional metrics using CloudWatch agent. The action helps streamline the workflow process by reducing the time spent on repeated tasks and improving efficiency.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/runs-on/action">https://github.com/runs-on/action</a></strong> to version <strong>v2.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runs-on-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>runs-on/action</code> GitHub Action is designed to enhance RunsOn&rsquo;s features by providing magic caching, which allows for faster execution of workflows by caching dependencies and results. It also offers options to display environment variables, job costs, and additional metrics using CloudWatch agent. The action helps streamline the workflow process by reducing the time spent on repeated tasks and improving efficiency.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Remove global sudo from action wrapper by @crohr in <a href="https://github.com/runs-on/action/pull/42">https://github.com/runs-on/action/pull/42</a></li>
<li>Add sticky disk cache modes by @crohr in <a href="https://github.com/runs-on/action/pull/43">https://github.com/runs-on/action/pull/43</a></li>
<li>Clean interrupted Git repacks before sticky snapshots by @crohr in <a href="https://github.com/runs-on/action/pull/48">https://github.com/runs-on/action/pull/48</a></li>
<li>Scope cold Git mirrors to workflow history by @crohr in <a href="https://github.com/runs-on/action/pull/50">https://github.com/runs-on/action/pull/50</a></li>
<li>Fix warm cache symlink merges by @crohr in <a href="https://github.com/runs-on/action/pull/52">https://github.com/runs-on/action/pull/52</a></li>
<li>Authenticate read-only Git LFS lock requests by @crohr in <a href="https://github.com/runs-on/action/pull/51">https://github.com/runs-on/action/pull/51</a></li>
<li>Refactor sticky cache runtime state by @crohr in <a href="https://github.com/runs-on/action/pull/46">https://github.com/runs-on/action/pull/46</a></li>
<li>Allow verified Windows sticky mount roots by @crohr in <a href="https://github.com/runs-on/action/pull/53">https://github.com/runs-on/action/pull/53</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/runs-on/action/compare/v2.2.0...v2.3.0">https://github.com/runs-on/action/compare/v2.2.0...v2.3.0</a></p>
]]></content:encoded></item><item><title>SpecGuard CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/specguard-ci/</link><pubDate>Tue, 04 Aug 2026 14:59:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/specguard-ci/</guid><description>Version updated for https://github.com/Sawaiz-zip/spec-guard to version v0.4.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SpecGuard is a GitHub Action that automates semantic governance of spec files by evaluating changes against locked project goals and scopes. It helps catch unintentional scope shifts early in the development process and ensures that all PRs adhere to the established project direction, preventing potential issues later on during merges.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Sawaiz-zip/spec-guard">https://github.com/Sawaiz-zip/spec-guard</a></strong> to version <strong>v0.4.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/specguard-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SpecGuard is a GitHub Action that automates semantic governance of spec files by evaluating changes against locked project goals and scopes. It helps catch unintentional scope shifts early in the development process and ensures that all PRs adhere to the established project direction, preventing potential issues later on during merges.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="specguard-v044">SpecGuard v0.4.4</h2>
<p>Completes the local/CI parity work on the advisory surfaces.</p>
<h3 id="fix-since-v043">Fix since v0.4.3</h3>
<ul>
<li><strong>MCP write-time tools are now multi-scope aware (#17):</strong> <code>check_proposed_change</code>, <code>check_permission</code>, and <code>get_scope_lock</code> judged a path against the repo-root lock only. In a monorepo they now resolve the path&rsquo;s own package scope (nearest-ancestor <code>.specguard/lock.json</code>), matching the merge gate. <code>get_scope_lock</code> gains an optional <code>path</code>. Adds <code>resolve_scope_for_path</code> to the scope resolver.</li>
</ul>
<p>No engine/classification changes; no provider or default-model change. Not yet on PyPI (the Action still pins <code>specguard-ci==0.4.0</code>).</p>
]]></content:encoded></item><item><title>SFDT for Salesforce</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/sfdt-for-salesforce/</link><pubDate>Tue, 04 Aug 2026 14:58:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/sfdt-for-salesforce/</guid><description>Version updated for https://github.com/scoobydrew83/sfdt to version v0.22.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the deployment, testing, and release management of Salesforce projects using the @sfdt/cli. It provides interactive workflows, automated release manifest generation, parallel Apex test execution, code and test quality analysis, pre-release validation, rollback support, post-deploy smoke testing, org metadata drift detection, multi-package project support, AI-based deployment error log interpretation, PR description generation, and more. The Action supports CI/CD pipeline templates for various platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scoobydrew83/sfdt">https://github.com/scoobydrew83/sfdt</a></strong> to version <strong>v0.22.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdt-for-salesforce">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the deployment, testing, and release management of Salesforce projects using the <code>@sfdt/cli</code>. It provides interactive workflows, automated release manifest generation, parallel Apex test execution, code and test quality analysis, pre-release validation, rollback support, post-deploy smoke testing, org metadata drift detection, multi-package project support, AI-based deployment error log interpretation, PR description generation, and more. The Action supports CI/CD pipeline templates for various platforms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>test: retry the CSRF token fetch instead of failing open by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/321">https://github.com/scoobydrew83/sfdt/pull/321</a></li>
<li>fix(security): validate CI template values; harden two shipped pipelines by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/323">https://github.com/scoobydrew83/sfdt/pull/323</a></li>
<li>chore: release v0.22.1 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/324">https://github.com/scoobydrew83/sfdt/pull/324</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scoobydrew83/sfdt/compare/v0.22.0...v0.22.1">https://github.com/scoobydrew83/sfdt/compare/v0.22.0...v0.22.1</a></p>
]]></content:encoded></item><item><title>Muninn Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/muninn-security-scanner/</link><pubDate>Tue, 04 Aug 2026 14:56:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/muninn-security-scanner/</guid><description>Version updated for https://github.com/skaldlab/muninn to version v0.3.7.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Muninn is an open-source security scanning tool that automates and unifies the execution of various security scanners in GitHub Actions workflows. It normalizes scan outputs into a single format, including PR comments, SARIF uploads, and structured JSON. Muninn helps identify vulnerabilities across multiple tools, ensuring comprehensive coverage while reducing duplication of findings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skaldlab/muninn">https://github.com/skaldlab/muninn</a></strong> to version <strong>v0.3.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/muninn-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Muninn is an open-source security scanning tool that automates and unifies the execution of various security scanners in GitHub Actions workflows. It normalizes scan outputs into a single format, including PR comments, SARIF uploads, and structured JSON. Muninn helps identify vulnerabilities across multiple tools, ensuring comprehensive coverage while reducing duplication of findings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="changelog">Changelog</h1>
<h2 id="unreleased">[Unreleased]</h2>
<h3 id="changed">Changed</h3>
<h2 id="037---2026-08-04">[0.3.7] - 2026-08-04</h2>
<h3 id="changed-1">Changed</h3>
<ul>
<li>GitPython floor raised to &gt;=3.1.55 for GHSA-94p4-4cq8-9g67 (incomplete
expandvars fix in create_remote / Remote.add).</li>
<li>cryptography floor raised to &gt;=50.0.0 for GHSA-g6cj-pr64-35w5
(CVE-2026-69247: PKCS#7 EnvelopedData Bleichenbacher oracle).</li>
<li>aiohttp floor raised to &gt;=3.14.3; scanner lockfile recompiled with click 8.3.3
and mcp 1.28.1 security overrides.</li>
<li>Docker image scanner updates: trivy 0.73.0, semgrep 1.172.0, zizmor 1.29.0
(checkov remains at 3.2.531 pending aiohttp cap lift; 3.2.533+ also caps
<code>aiohttp&lt;3.14</code>).</li>
</ul>
<h2 id="036---2026-07-22">[0.3.6] - 2026-07-22</h2>
<h3 id="changed-2">Changed</h3>
<ul>
<li>Docker image scanner updates: zizmor 1.28.0 (replaces yanked 1.27.0);
GitPython floor raised to &gt;=3.1.52 for checkov-transitive GHSA highs
(checkov remains at 3.2.531 pending aiohttp cap lift).</li>
<li>Go toolchain bumped to 1.26.5.</li>
</ul>
<h2 id="035---2026-07-20">[0.3.5] - 2026-07-20</h2>
<h3 id="changed-3">Changed</h3>
<ul>
<li>Docker image scanner updates: semgrep 1.170.0, zizmor 1.27.0 (checkov
remains at 3.2.531 pending aiohttp cap lift).</li>
</ul>
<h2 id="034---2026-07-04">[0.3.4] - 2026-07-04</h2>
<h3 id="changed-4">Changed</h3>
<ul>
<li>Docker image scanner updates: osv-scanner 2.4.0, trivy 0.72.0, semgrep
1.168.0, zizmor 1.26.1 (checkov remains at 3.2.531 pending aiohttp cap lift).</li>
</ul>
<h2 id="033---2026-06-17">[0.3.3] - 2026-06-17</h2>
<h3 id="changed-5">Changed</h3>
<ul>
<li>Trivy default severity is now all levels (<code>UNKNOWN</code> through <code>CRITICAL</code>) instead
of <code>CRITICAL</code> and <code>HIGH</code> only. osv-scanner and trivy now overlap on
medium/low advisories by default so cross-scanner dedup and <code>Detected by</code>
work without extra config. Consumers can narrow the Trivy scan with
<code>scanners.trivy.severity</code>; <code>fail-on</code> still controls which findings fail the run.</li>
</ul>
<h2 id="032---2026-06-16">[0.3.2] - 2026-06-16</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Suppressions with <code>tool</code> and/or <code>rule-id</code> are now applied. Previously only <code>id</code>
(path substring) and <code>fingerprint</code> matchers worked; tool+rule-id entries
parsed from <code>muninn.yml</code> but silently no-op&rsquo;d.</li>
</ul>
<h2 id="031---2026-06-16">[0.3.1] - 2026-06-16</h2>
<h3 id="fixed-1">Fixed</h3>
<ul>
<li>Poutine v1.x JSON parsing: findings from poutine 1.1.6+ (<code>rule_id</code>, <code>meta</code>,
<code>rules</code>, <code>blobshas</code>) now populate title, rule, and file in PR comments instead
of empty shells (<code>File: :0</code>, `Rule: ``) (#41).</li>
<li>Actionlint PR comments: fall back to <code>kind</code> (e.g. <code>expression</code>) when
<code>rule.name</code> is absent; omit empty Rule lines.</li>
<li>Poutine injection findings: render <code>injection_sources</code> as formatted
<strong>Sources</strong> instead of plain <code>meta.details</code> text.</li>
</ul>
<h3 id="changed-6">Changed</h3>
<ul>
<li>PR comment layout: shared field helpers; non-dependency findings follow
File → Rule → optional extras → description; single-scanner dependency
findings use <strong>File</strong> instead of a redundant <strong>Source</strong> line.</li>
</ul>
<h2 id="030---2026-06-16">[0.3.0] - 2026-06-16</h2>
<h3 id="added">Added</h3>
<ul>
<li>Cross-scanner deduplication by advisory id: findings that report the same
CVE/GHSA for the same package from different scanners (e.g. OSV-Scanner from a
lockfile and Trivy from a container layer) are now collapsed into a single
finding. The contributing scanners are recorded in a new <code>detected_by</code> field
(surfaced in the JSON report, the PR comment&rsquo;s &ldquo;Detected by&rdquo; line, and a
<code>detectedBy</code> SARIF result property). A CVE is preferred over GHSA so the same
vulnerability converges on one id across scanners (#27).</li>
<li>Richer dependency finding rendering: aggregated dependency findings now appear
under a neutral <code>[dependency]</code> heading (instead of a single scanner&rsquo;s name)
with <code>Package</code>, <code>Advisory</code> (including the shared CVE), <code>Detected by</code>, and a
<code>Sources</code> list showing where each scanner observed it. A new <code>sources</code> field on
the finding (per-scanner <code>tool</code> + <code>file</code>) backs the JSON report (#27).</li>
</ul>
<h3 id="fixed-2">Fixed</h3>
<ul>
<li>PR comment rendering: scanner descriptions are flattened to a single line and
their Markdown (code fences, headings) neutralized, so an unbalanced ``` fence
can no longer swallow later findings and the footer into a code block.</li>
</ul>
<h2 id="020---2026-06-15">[0.2.0] - 2026-06-15</h2>
<p>Supply-chain hardening for the scanner image and signed, verifiable releases
(closes #30).</p>
<h3 id="added-1">Added</h3>
<ul>
<li>Pinned every bundled binary scanner to an exact version with SHA256 checksum
verification in the Docker image — gitleaks, zizmor, actionlint, poutine,
osv-scanner, trivy (#31)</li>
<li>Hash-locked the pip-installed scanners (semgrep, checkov, zizmor) via a fully
pinned, multi-arch <code>requirements-scanners.txt</code> installed with
<code>pip --require-hashes</code> (#33)</li>
<li>Renovate configuration to auto-PR scanner version bumps, with a CI job that
refreshes the pinned checksums (#32)</li>
<li>Keyless (OIDC) cosign signing of the published container image and of the
release binary checksums (Sigstore bundle <code>checksums.txt.sigstore.json</code>) (#34)</li>
<li>SBOM (SPDX) attached to every release and as an image attestation (#34)</li>
<li>Max-mode SLSA build provenance attestation on the container image (#34)</li>
<li>&ldquo;Verifying releases&rdquo; instructions in the README (#34)</li>
</ul>
<h3 id="changed-7">Changed</h3>
<ul>
<li>Pinned checkov to 3.2.531 (from 3.3.1) so its dependency tree resolves the
patched aiohttp 3.14.1 and drops the unfixable python-ecdsa Minerva
dependency that checkov 3.3.x introduced. Revisit when a newer checkov lifts
its <code>aiohttp&lt;3.14</code> cap (#33)</li>
</ul>
<h2 id="010---2026-06-14">[0.1.0] - 2026-06-14</h2>
<h3 id="added-2">Added</h3>
<ul>
<li>8 security scanners: gitleaks, zizmor, actionlint, poutine,
semgrep, osv-scanner, trivy, checkov</li>
<li>Unified Finding schema with fingerprinting</li>
<li>Three output formats: SARIF 2.1.0, JSON, GitHub PR comment</li>
<li>GitHub Action with outputs</li>
<li>Config-driven scanner behavior via muninn.yml</li>
<li>Suppression management with expiry dates</li>
<li>90%+ test coverage enforced in CI</li>
<li>Integration tests with real scanner binaries</li>
<li>Self-scan: Muninn scans itself on every PR</li>
</ul>
<p>Built by Skald Lab — skaldlab.dev</p>
]]></content:encoded></item><item><title>Cloudflare API Shield Upload</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/cloudflare-api-shield-upload/</link><pubDate>Tue, 04 Aug 2026 14:55:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/cloudflare-api-shield-upload/</guid><description>Version updated for https://github.com/SocksTheWolf/cloudflare-upload-spec to version v1.2.4.
This action is used across all versions by 7 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading OpenAPI specifications to Cloudflare’s API Shield, allowing developers to manage their APIs efficiently without manual intervention. It provides capabilities for uploading a single specification file and optionally deleting other files with the same name. The action is particularly useful for continuous integration pipelines where automatic API updates are required.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SocksTheWolf/cloudflare-upload-spec">https://github.com/SocksTheWolf/cloudflare-upload-spec</a></strong> to version <strong>v1.2.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cloudflare-api-shield-upload">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading OpenAPI specifications to Cloudflare&rsquo;s API Shield, allowing developers to manage their APIs efficiently without manual intervention. It provides capabilities for uploading a single specification file and optionally deleting other files with the same name. The action is particularly useful for continuous integration pipelines where automatic API updates are required.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Updated Actions Build</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SocksTheWolf/cloudflare-upload-spec/compare/v1.2.3...v1.2.4">https://github.com/SocksTheWolf/cloudflare-upload-spec/compare/v1.2.3...v1.2.4</a></p>
]]></content:encoded></item><item><title>Read or Modify JSON</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/read-or-modify-json/</link><pubDate>Tue, 04 Aug 2026 14:55:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/read-or-modify-json/</guid><description>Version updated for https://github.com/SocksTheWolf/github-action-json to version v1.5.1.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, github-action-json, allows users to read and optionally modify JSON files or the package.json file. It provides functionality to replace JSON data, remove keys, and execute a dry run without making any changes to the file. The action supports various inputs for customization such as specifying the path, replacing JSON data, removing keys, and performing a dry run.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SocksTheWolf/github-action-json">https://github.com/SocksTheWolf/github-action-json</a></strong> to version <strong>v1.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/read-or-modify-json">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>github-action-json</code>, allows users to read and optionally modify JSON files or the <code>package.json</code> file. It provides functionality to replace JSON data, remove keys, and execute a dry run without making any changes to the file. The action supports various inputs for customization such as specifying the path, replacing JSON data, removing keys, and performing a dry run.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Updated Actions Build</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SocksTheWolf/github-action-json/compare/v1.5.0...v1.5.1">https://github.com/SocksTheWolf/github-action-json/compare/v1.5.0...v1.5.1</a></p>
]]></content:encoded></item><item><title>Jekyll Redirects for Cloudflare</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/jekyll-redirects-for-cloudflare/</link><pubDate>Tue, 04 Aug 2026 14:54:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/jekyll-redirects-for-cloudflare/</guid><description>Version updated for https://github.com/SocksTheWolf/jekyll-cloudflare-redirects to version v1.2.4.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Jekyll Redirects for Cloudflare GitHub Action automates the process of transforming Jekyll’s redirects.json into a _redirects file suitable for use with Cloudflare. This action is particularly useful after any Jekyll build to ensure that the website redirects are correctly configured before deployment, helping to improve site performance and user experience by reducing server load and improving SEO through better URL management.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SocksTheWolf/jekyll-cloudflare-redirects">https://github.com/SocksTheWolf/jekyll-cloudflare-redirects</a></strong> to version <strong>v1.2.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jekyll-redirects-for-cloudflare">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Jekyll Redirects for Cloudflare GitHub Action automates the process of transforming Jekyll&rsquo;s <code>redirects.json</code> into a <code>_redirects</code> file suitable for use with Cloudflare. This action is particularly useful after any Jekyll build to ensure that the website redirects are correctly configured before deployment, helping to improve site performance and user experience by reducing server load and improving SEO through better URL management.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Updated Actions Build</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SocksTheWolf/jekyll-cloudflare-redirects/compare/v1.2.3...v1.2.4">https://github.com/SocksTheWolf/jekyll-cloudflare-redirects/compare/v1.2.3...v1.2.4</a></p>
]]></content:encoded></item><item><title>Go Git Commit Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/go-git-commit-action/</link><pubDate>Tue, 04 Aug 2026 14:53:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/go-git-commit-action/</guid><description>Version updated for https://github.com/somaz94/go-git-commit-action to version v1.8.2.
This action is used across all versions by 18 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Git commit, push, tag, and pull request operations. It is written in Go for performance and reliability, supporting multiple file patterns and secure authentication through environment variables or secrets. The action can be used to automate the release process of software projects by creating tags and pushing commits, as well as automatically creating pull requests for code changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/go-git-commit-action">https://github.com/somaz94/go-git-commit-action</a></strong> to version <strong>v1.8.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-git-commit-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates Git commit, push, tag, and pull request operations. It is written in Go for performance and reliability, supporting multiple file patterns and secure authentication through environment variables or secrets. The action can be used to automate the release process of software projects by creating tags and pushing commits, as well as automatically creating pull requests for code changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>skip the push when there was nothing to commit by @somaz94</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/go-git-commit-action/compare/v1.8.1...v1.8.2">https://github.com/somaz94/go-git-commit-action/compare/v1.8.1...v1.8.2</a></p>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/update-a-config-file-with-values-from-environment/</link><pubDate>Tue, 04 Aug 2026 14:52:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The config-file-from-env GitHub Action reads environment variables and replaces placeholders in a configuration file with their corresponding values. This helps in dynamically configuring applications based on the environment, enhancing flexibility and ease of deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>config-file-from-env</code> GitHub Action reads environment variables and replaces placeholders in a configuration file with their corresponding values. This helps in dynamically configuring applications based on the environment, enhancing flexibility and ease of deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/classroom-to-sheets-integration/</link><pubDate>Tue, 04 Aug 2026 14:52:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates GitHub Classroom with Google Sheets, automating the process of sending assignment results. It uses service account credentials and shares the Google sheet with the service account to ensure secure communication between GitHub Actions and Google Sheets. The action supports automatic column creation based on graded tasks and updates student grades in real-time within the Google Sheet.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates GitHub Classroom with Google Sheets, automating the process of sending assignment results. It uses service account credentials and shares the Google sheet with the service account to ensure secure communication between GitHub Actions and Google Sheets. The action supports automatic column creation based on graded tasks and updates student grades in real-time within the Google Sheet.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>xilo-nix-cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/xilo-nix-cache/</link><pubDate>Tue, 04 Aug 2026 14:52:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/xilo-nix-cache/</guid><description>Version updated for https://github.com/stubbedev/xilo to version v1.0.13.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The xilo GitHub Action automates the setup and management of a self-hosted Nix binary cache. It provides a single Go binary with no external services, supports multi-tenant storage with user accounts and organizations, offers a dashboard for managing caches, tokens, users, and activities, and can revoke push/pull tokens instantly. It also ships a 9 MB distroless Docker image and serves zstd pulls from stored frames.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stubbedev/xilo">https://github.com/stubbedev/xilo</a></strong> to version <strong>v1.0.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xilo-nix-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The xilo GitHub Action automates the setup and management of a self-hosted Nix binary cache. It provides a single Go binary with no external services, supports multi-tenant storage with user accounts and organizations, offers a dashboard for managing caches, tokens, users, and activities, and can revoke push/pull tokens instantly. It also ships a 9 MB distroless Docker image and serves zstd pulls from stored frames.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/stubbedev/xilo/compare/v1...v1.0.13">https://github.com/stubbedev/xilo/compare/v1...v1.0.13</a></p>
]]></content:encoded></item><item><title>Run Godlint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/run-godlint/</link><pubDate>Tue, 04 Aug 2026 14:50:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/run-godlint/</guid><description>Version updated for https://github.com/tomerwave/godlint to version v0.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Godlint is an executable engineering tool that enforces deterministic policies across multiple programming languages, helping to maintain architecture, security boundaries, and engineering standards in collaborative development environments. It automates quality checks locally and in CI, ensuring that changes adhere to predefined rules and exceptions can be managed with accountability and expiration dates.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tomerwave/godlint">https://github.com/tomerwave/godlint</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-godlint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Godlint is an executable engineering tool that enforces deterministic policies across multiple programming languages, helping to maintain architecture, security boundaries, and engineering standards in collaborative development environments. It automates quality checks locally and in CI, ensuring that changes adhere to predefined rules and exceptions can be managed with accountability and expiration dates.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p>Rules take <code>only-in</code> and <code>allow-in</code>: the paths a rule applies to, and the exemptions inside them.
<code>allow-in</code> existed on eleven of fifty rules, each implementing it itself, and <code>only-in</code> did not exist
at all — so a rule that is inherently about one part of a tree could not say so. The only way to say
&ldquo;this rule does not belong here&rdquo; was <code>exclude</code>, which drops a path for <strong>every</strong> rule at once: one
misplaced rule cost you every other rule in that directory. This repository is the evidence, having
excluded <code>scripts</code> and <code>packaging</code> wholesale to silence one rule, hiding 21 unrelated findings to do
it. This change does not lift that exclusion, and it does remove the reason for it: every one of
those rules can now be declared per path, so what keeps the two directories out of the scan is the
21 findings underneath, each wanting its own change.</p>
<p>The narrower setting decides, so <code>allow-in</code> carves exceptions out of <code>only-in</code>, and both empty means
every file, which is what a rule naming no paths wants.</p>
<p>It is one implementation rather than fifty because the check sits in <code>rules::report</code>, the single
function that turns a violation into a finding. A rule cannot forget to honour its own scope, because
no rule consults it. The eleven hand-written <code>allow-in</code> checks are gone, matching the same globs
against the same path as before. <code>Rule::Configuration</code> now requires <code>Scoped</code>, so a new rule does not
compile until its configuration can say where its rule applies — the property is held by the compiler
rather than by a checklist.</p>
<p>One rule needed more than that, and it is the interesting one. <code>ci/stale-action-refs</code> reports a
contradiction <em>between</em> files: one commit labelled <code># v3</code> in one workflow and <code># v4</code> in another. Scope
there has to gate what the rule <em>reads</em>, not only what it reports — otherwise excluding a workflow
still produces a finding in the file that was not excluded, caused by the one that was. Its own test
said so in its name, <code>allow_in_removes_a_workflow_from_reporting_and_repository_evidence</code>, and it
failed the moment the central check replaced its own. A rule whose verdict depends on more than the
file it reports in must scope its evidence. Review found the other half of that untested — evidence
honouring <code>allow-in</code> while ignoring <code>only-in</code> passed all 881 tests — so the mirror case is pinned
too — in both directions. Review then found a third shape: both scope tests assert that nothing is
reported, so an evidence filter that <em>over</em>-drops was unpinned, and dropping every workflow the
moment <code>only-in</code> is non-empty passed all 882 tests. That is the worse failure of the two, because
<code>only-in</code> is the setting whose purpose is to point a rule <em>at</em> something. The fixture that already
demands five findings now sets <code>only-in</code> as well, so those five expectations pin the positive
direction and the same block pins the interaction — <code>allow-in</code> still carves <code>allowed.yml</code> out of an
<code>only-in</code> that includes it. Its three-pattern list is load-bearing for a second reason found while
reviewing it: it is the only multi-pattern <code>only-in</code> anywhere in the suite, so it is the only thing
pinning that <code>only-in</code> matches as a disjunction over every pattern rather than checking the first.
A fourth shape came out of the same review — no test had a non-empty <code>only-in</code>, a file outside it,
<em>and</em> findings expected from the files inside, so narrowing that must still report was unpinned and
a guard written at the wrong granularity silenced the rule whenever anything was out of scope. Two
workflows in scope contradicting each other, one outside, now pin it. Four directions each for
<code>only-in</code> and <code>allow-in</code>: reports inside, silent outside, the interaction between them, and the
evidence path separately from the reporting path.</p>
<p>One sharp edge, documented rather than fixed: <code>only-in</code> narrows, so a pattern matching nothing
leaves a rule with nowhere to apply and it reports nothing, anywhere, without saying so. A typo in
<code>exclude</code> or <code>allow-in</code> fails safe because a pattern matching nothing changes nothing; a typo here
fails open. A misspelled key is still caught by validation, only a misspelled path is not.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><code>policy/unused-suppression</code> reports a directive that silences nothing whatever the reason, where it
previously excused a rule set to <code>off</code>. Three things can make a directive dead — the finding was
fixed, the rule is <code>off</code>, or the rule is scoped away from that path by <code>only-in</code> or <code>allow-in</code> — and
the rule reported the first and third while treating the second as dormant. That split was not a
policy, it was two answers to one question: <code>off</code> was excused deliberately so a gradual adoption
would not turn the inactive parts of a policy into failures, and scope arrived later, took the
opposite answer, and nobody reconciled them.</p>
<p>Reported in all three now, because a dormant exemption and a dead one are indistinguishable from
outside, and only one is harmless. A directive nobody is watching silences a real finding the day
the severity or the scope changes, un-reviewed — the same reasoning that made a stale drift
declaration fail rather than notice. The gradual-adoption cost is real and now written down in
<code>docs/suppressions.md</code> along with the way to pay it: this rule takes a severity like any other, so
<code>warning</code> covers a cleanup in progress.</p>
<p>A fourth case belongs in that list and was missing from the first draft of this entry: a rule the
configuration never mentions at all never runs, so a directive naming it is as dead as one for a
rule set to <code>off</code>. Reported too, and tested.</p>
</li>
<li>
<p><code>policy/unused-suppression</code> cannot switch itself off. <code>severity: off</code> is now rejected as invalid
configuration, and so are <code>only-in</code> and <code>allow-in</code> on that rule — scoping a rule to nothing is
switching it off by another name, and <code>only-in</code>/<code>allow-in</code> reached every rule two releases ago,
which quietly gave the one rule meant to be undefeatable two new ways to be defeated. A rule able
to retire itself could retire every exemption it audits. <code>warning</code> is still accepted and is how to
absorb a cleanup without failing the build.</p>
<p>Scope of that claim, because a wider one would be false: it is the rule&rsquo;s own configuration that
cannot retire it. A top-level <code>exclude</code> still drops a path from the scan for every rule including
this one — Godlint&rsquo;s own <code>godlint.yaml</code> relies on it, and doing so hides 19 dead directives in the
CLI fixture tree on purpose — and so does naming paths on the command line. And the check lives in
configuration validation, which runs when the CLI loads a file, so a <code>godlint-core</code> consumer
deserialising a <code>Config</code> directly is not bound by it. Making the shape unrepresentable rather than
rejected is the version that would bind both, and is its own change.</p>
<p>The message it prints changed with it, because the old one became false the moment the rule stopped
requiring the target to be enabled: <code>Suppression does not silence an enabled finding; remove it or narrow the rule</code> said <em>enabled</em> when enablement is no longer the criterion, and offered <em>narrow the
rule</em> as a remedy that does not exist when the rule is off everywhere. It now reads <code>Suppression silences nothing; remove it, or restore the rule it names to this path.</code> — a statement that is true
in all four cases, and advice that does not tell a reader to delete a reviewed exemption they may
want when the rule returns.</p>
</li>
<li>
<p>A declaration in <code>.github/accepted-drift.md</code> that the released binary does not report fails the
released-agreement check instead of printing a notice nobody reads. <code>docs/releasing.md</code> said the
quiet part out loud — &ldquo;deleting it is remembered rather than enforced&rdquo; — and remembering is not a
gate. What makes it worth failing is what a declaration is: it stands ready to accept disagreement
in one named rule, so a line left behind after the drift it described is resolved will silently
accept the <em>next</em> drift in that rule, which is the one case this check exists to catch. A stale
declaration is not untidiness, it is an exemption nobody is watching. The pressure lands where the
release process already expected it: the first pull request after a release either deletes the file
or goes red naming each line to remove.</p>
<p>Three things look like a stale declaration and are not, and calling any of them stale would have
been worse than the notice it replaces, because the instruction is <em>delete the line</em>. Staleness
reads &ldquo;not among the rules the release reported&rdquo;, so it is only sound where that list is the whole
list. It is not when the release could not read this repository&rsquo;s configuration — it reported
nothing about any rule, so failing there would fail every pull request that adds a configuration
key, for declarations that are perfectly good. It is not when a finding&rsquo;s rule id could not be
parsed, because the unreadable one may <em>be</em> the declared rule. And it is not when the release
claimed findings and the annotations hold none, which is no record rather than a record of nothing.
None of the three is called stale. The configuration case reports its declarations <em>unexercised</em>
and passes; the other two report them <em>not examined</em> and leave the run red on the findings they
could not read, unless a drift label declares those, which is the escape a label has always been.
A stale declaration also does not short-circuit the undeclared-finding report: a run with both
says both,
and names every stale line with its own kind rather than the first — the first attempt got the
short-circuit wrong and the suite caught it, and review caught the rest.</p>
</li>
<li>
<p>The drift gate reads the status the released binary exited with instead of matching a sentence in
its output. It decided whether the release could read the configuration by grepping for
<code>Configuration is invalid</code>, and the binary being grepped is a <em>past</em> release — so no test in this
repository could hold that wording still, and rewording it in a later version would have silently
reclassified an unreadable configuration as drift, the one failure the gate exists to prevent. It
now reads the action&rsquo;s <code>status</code> output, which has to be fixed to exist at all for a run with
findings (below), and when the status says the check did not finish it asks the release itself:
<code>config validate</code> answers <em>can you read this configuration</em> with an exit status, and has since the
first release, so every binary the gate can run understands the question. Two things follow beyond
the plumbing. A release that cannot parse a file exits 2 having still reported what it did reach,
and those partial findings were read as drift with a choice of labels offered; a verdict on part of
a tree is not a verdict, so that now fails and says so. And the guidance the gate printed said
adding a <em>rule</em> lands there, which stopped being true when a release started ignoring an unknown
rule key with a notice — only a configuration key, a suite or a configuration version reaches it.
A tree with no <code>godlint.yaml</code> at all is now reported rather than waved through: the release cannot
read a file that is not there, so with no check for one a repository stating no policy read as a
release too old to understand it, which is the same silent pass from the other direction.
The step&rsquo;s own conclusion is still read, for the one question the status cannot answer: a step
after the check failing leaves Godlint&rsquo;s own status honest while the action failed for its own
reason. That the outcome is read at all was <code>ci/no-silenced-failure</code> reporting this repository&rsquo;s
drift job the moment nothing did. <code>docs/ci.md</code> documents the <code>status</code> output, which existed
undocumented, and what each status means.</p>
</li>
<li>
<p><code>validate-pull-request.py</code> asks for a changelog entry when any shipped source file changes, rather
than when one of five hand-listed paths does. What the old list omitted decided the policy:
<code>config/rules.rs</code> holds every default threshold, so <strong>raising one — the most user-visible change
this project can make — needed no entry at all</strong>, and neither did <code>suites.rs</code>, which decides what a
suite enables and at what severity. Exemptions are now named with a reason instead of inferred from
a list of what someone remembered to include, and an entry that says nothing a user can observe
changed is a valid entry, which is the sentence a refactor should be made to write. Those entries go
under a new <code>### Internal</code> category that <code>check-release.py</code> leaves out of the release body, because
the body is the section verbatim and reaches people who will never read this repository — so the log
keeps the refactor and the announcement does not carry it. A file leaving <code>crates/*/src/</code> counts as
a change to it: <code>git diff --name-only</code> resolves a rename to its destination, so moving a shipped
module into <code>tests/</code> reported nothing at all until the diff was taken with <code>--no-renames</code>. The
category names are constrained too, because the release body is name-sensitive: <code>### internal</code>
would have shipped a refactor to users while looking right in the file.</p>
</li>
<li>
<p>Suppression matching is grouped by file instead of comparing every finding with every suppression.
<code>apply</code> scanned the whole suppression list for each finding and <code>policy/unused-suppression</code> scanned
the whole finding list for each suppression, so the cost grew with the <em>product</em> of two
repository-sized numbers — the only step in the pipeline that did — and nearly every comparison
established that two unrelated files are not the same file. On 3,000 files carrying 2,000
suppressions <code>godlint check</code> goes from 468ms to 339ms; doubling that corpus takes the pairwise path
to 1,093ms and the grouped path to 616ms, so the gap widens as a repository grows. Grouping cannot
change which suppression matches: <code>covers</code> already required the paths to be equal, and <code>Ord</code> on a
path agrees with <code>==</code> on it, so the map admits and rejects exactly the pairs the scan did.</p>
</li>
<li>
<p>Reading and parsing files runs on every core. The scan walked discovered files one at a time while
read, parse and fact collection are independent per file and share nothing mutable — 85% of the run
on one core. Chunks are merged in chunk order, so the facts arrive in the same order they did
sequentially and the output does not depend on how the work was divided. Measured on a 2,104-file
tree with ten cores: 1,244ms to 467ms, and eight consecutive runs are byte-identical. A tree of 32
files or fewer stays sequential, and a second thread appears at 33 — measured at that boundary, the
difference is inside the noise either way, because a run of that size is dominated by the 69ms it
takes to start and read the configuration. The win is 2.66× on a large repository and nothing at all
on a small one. Where a machine reports one core, <code>available_parallelism</code> returns 1 and the
sequential path is taken.</p>
</li>
<li>
<p>Deciding that a path is not excluded no longer allocates. <code>glob::segment_matches</code> built two
<code>Vec&lt;char&gt;</code>s and a table per segment comparison before comparing anything, including for the
literal patterns every <code>exclude:</code> list is made of — <code>target</code>, <code>node_modules</code>, <code>.venv</code>. Measured on
a 2,104-file tree, <code>godlint check</code> goes from 1.61s to 1.50s, and the output is byte-identical over
3,712 findings. Every rule&rsquo;s <code>allow-in</code> and <code>test-paths</code> matching takes the same path, so it is
faster too. A pattern holding <code>*</code> or <code>?</code> still goes through the matcher unchanged.</p>
</li>
<li>
<p><code>validate-pull-request.py</code> refuses a changelog that names a release twice, lists a category twice,
or holds an entry under no category. A conflict resolution that keeps both sides leaves a second
<code>## [Unreleased]</code> behind; it renders, and it passed every other check, which is how two of them
reached <code>main</code> in one night of rebases. The section they damaged is now one heading per category.</p>
</li>
<li>
<p><code>validate-pull-request.py</code> refuses a tracked file carrying a merge-conflict marker. <code>git rebase --continue</code> accepts a staged file whose conflict was never resolved, so a botched resolution lands
as a commit that looks deliberate — which is exactly what happened while rebasing this branch, and
all 1046 checks passed over a changelog full of <code>&lt;&lt;&lt;&lt;&lt;&lt;&lt;</code>.</p>
</li>
<li>
<p><code>validate-pull-request.py</code> compares the mutation gate&rsquo;s scope with the tree rather than only with
the mutation workflow&rsquo;s trigger paths. Twelve files in <code>godlint-core</code> — including the ones that
decide which files are scanned, whether an <code>exclude</code> pattern matches, and whether a suppression
has expired — generate no mutants at all, and nothing said so. Each is now named with the reason
it is outside, a file that is neither examined nor named fails the check, and #245 carries the
plan for bringing them in.</p>
</li>
<li>
<p><code>maintainability/cognitive-complexity</code> counts a Rust <code>let … else</code> as a branch, weighted by the
nesting it sits at, the way every other branching form is counted. <code>decision-complexity</code> already
counted it, so the two metrics disagreed about whether a refutable binding is a decision; a
<code>let Some(value) = option else { return; }</code> now costs 1 at the top level and 3 inside an <code>if</code>.
Nothing in this repository crosses the threshold of 15 as a result.</p>
</li>
<li>
<p>Every function&rsquo;s metrics come from one walk of its syntax tree instead of five. Decision points,
cognitive score, return paths, statement count and block depth each recursed the same subtree
separately, re-reading every node&rsquo;s kind each time; on a 10,160-file tree that was 29% of the whole
run, more than parsing. One traversal carries the nesting level, block depth and else position that
the five walks each tracked alone. Measured on a 2,104-file tree, <code>godlint check</code> goes from 1.53s to
1.27s, with identical output over 16,896 findings when every metric&rsquo;s limit is set to 1 so each
function reports all five of its measured values — with the single deliberate exception below.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>The action&rsquo;s job summary appears when there are findings, which is the only time it was ever for.
GitHub invokes a <code>shell: bash</code> step as <code>bash -e</code>, and a script&rsquo;s own <code>set -uo pipefail</code> cannot undo
the <code>-e</code> it was invoked with, so the step ended at <code>godlint check | tee</code> the moment the check
reported anything — before writing the findings count, before writing the status, and before the
two steps after it, which a composite action skips once one fails. So <code>summary</code>, whose whole reason
for existing is that GitHub renders only so many annotations and a first adoption produces
hundreds, ran only against trees that had nothing to summarise, where it printed <code>No findings.</code>
The <code>findings</code> and <code>status</code> outputs were empty for the same reason, and <code>docs/ci.md</code> explained that
with the wrong cause — a composite action withholding its outputs when it fails, which measurably
it does not — and a wrong explanation is why the real one went unexamined this long. Found by
asserting in the <code>dirty</code> workflow job that the action fails <em>with findings</em>, where it had asserted
only that it fails: an aborting step and findings failing a run look identical from outside, so the
failure that job proved all along was the abort. Turning <code>-e</code> off covers the <code>tee</code> that writes the
annotations as well, so its status is now checked rather than assumed — a half-written annotations
file would otherwise have every count and every later step describing a shorter run than happened.
The step now has a test that runs its own body, extracted from <code>action.yml</code> so the test cannot
drift from the shipped step, under the shell GitHub uses. It was written after this step broke a
second time in the same pull request, for the neighbouring reason: <code>PIPESTATUS</code> describes the last
pipeline and an assignment is a command, so reading it on two lines read the second from the
assignment. Both breakages were invisible from outside — the step failed, GitHub skipped the rest
of the action, and the job failed the way findings fail. The test catches both, and catches
<code>| tee &quot;$output&quot; || true</code>, the obvious fix that silently reports every run as status 0.</li>
<li>A blank <code>helpers</code> or <code>test-paths</code> entry for <code>testing/no-test-helper-in-production</code> is rejected as
invalid configuration. The two were broken differently: <code>helpers: [&quot;&quot;]</code> matched the empty segments
that splitting a Rust <code>::</code> path on one colon produced and reported <code>crate::tests::helper</code> with the
message <code>names , which is test scaffolding</code>, while a blank <code>test-paths</code> entry matched nothing at all,
so the option looked configured and did nothing. Every other list-valued option in the schema
already refused a blank entry; these two were missed.</li>
<li>Four decisions in the analysers had no test depending on them, which a full mutation sweep of
<code>main</code> found: a Rust <code>use {std, core};</code> brace list must contribute no import, an ordinary <code>let</code>
must not count as a branch where a <code>let … else</code> does, and <code>.tsx</code> must be parsed by the TSX grammar
while <code>.ts</code> is parsed by the TypeScript one. That last pair reject each other&rsquo;s syntax in both
directions — JSX under TypeScript and an angle-bracket type assertion under TSX — so swapping them
broke nothing any test noticed until now.</li>
<li><code>validate-pull-request.py</code>&rsquo;s change-scoped checks see the working tree, not only what is committed.
They read <code>git diff &lt;release line&gt;...HEAD</code>, so a local run before the commit — which is most of them —
found no changed files, skipped the checks, and printed that every check passed. Staged, unstaged and
untracked paths all count now, and the changelog check consequently fails locally at the point the
entry is missing rather than in CI.</li>
<li><code>ci/no-silenced-failure</code> reports <code>continue-on-error: True</code> and <code>TRUE</code>, not only the lowercase
spelling. YAML&rsquo;s core schema calls all three true and GitHub honours each, so a capital letter
silenced a step and the rule said nothing — a false negative in the one rule whose whole job is
noticing a check that cannot fail. <code>yes</code>, <code>on</code> and a quoted <code>&quot;true&quot;</code> stay silent: they are not
booleans in the core schema, and reporting them would rest on a guess about GitHub&rsquo;s coercion that
cannot be checked without a network. Found by probing the built binary while reviewing the rule,
not by reading it.
plan for bringing them in. The walk covers every crate: <code>godlint-cli</code> was outside the gate in
its entirety, including the module that decides the JSON, SARIF and annotation shapes three
other gates parse.</li>
<li>Two more gates in <code>validate-pull-request.py</code> stopped taking a proxy for the thing. The workflow
toolchain check globbed <code>*.yml</code> while <code>source.rs</code> reads both <code>yaml</code> and <code>yml</code>, so a workflow named
<code>.yaml</code> was scanned by Godlint and invisible to the gate; and &ldquo;every mutation exclusion needs a
reason&rdquo; counted comment lines against exclusion lines, which passed one exclusion with a five-line
essay beside four with none. Each exclusion is now paired with the line above it.</li>
<li>The lists <code>recommended@1</code> enforces by default are pinned by tests. Nothing asserted them: every
test passed its own markers, test paths and helpers, so deleting <code>XXX</code> from the marker defaults —
which silently stops <code>policy/todo-requires-reference</code> asking for a reference on an <code>XXX:</code> comment
in every repository using the suite — passed all 1,860 checks. This repository writes no comments
in Rust, so its own dogfooding could not notice either. Found when a one-line pull request proposed
exactly that change under a title claiming to add a marker.</li>
<li><code>maintainability/function-nesting</code> no longer charges a function for the blocks inside a closure it
returns. A curried <code>a =&gt; b =&gt; { … }</code> reported the <em>outer</em> function&rsquo;s depth as the inner closure&rsquo;s,
while <code>decision-complexity</code>, <code>cognitive-complexity</code>, <code>return-count</code> and <code>function-statements</code> all
reported the outer function as empty — so one metric contradicted the other four and the rule
reference, which says a closure&rsquo;s own complexity belongs to the closure. The inner closure still
gets its own finding at its own depth. Found by review of the walk consolidation, which made the
inconsistency visible; across 453,807 functions in a 26,404-file corpus this changes 127 functions
in 51 files, all of them curried, and none in this repository.</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/wails3-build-action/</link><pubDate>Tue, 04 Aug 2026 14:49:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub action automates the build process for Wails.io v3 projects by installing GoLang and NodeJS, then running a build. It supports building for multiple platforms and can obfuscate the build using Garble. The default behavior uploads the results to GitHub, but it also uploads them to release when triggered on a tag. Users can specify additional options such as Go version, Wails version, build name, obfuscation, platform, cache use, and package upload.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub action automates the build process for Wails.io v3 projects by installing GoLang and NodeJS, then running a build. It supports building for multiple platforms and can obfuscate the build using Garble. The default behavior uploads the results to GitHub, but it also uploads them to release when triggered on a tag. Users can specify additional options such as Go version, Wails version, build name, obfuscation, platform, cache use, and package upload.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Proficiency — Go API Performance</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/proficiency-go-api-performance/</link><pubDate>Tue, 04 Aug 2026 14:48:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/proficiency-go-api-performance/</guid><description>Version updated for https://github.com/tuxerrante/proficiency to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the profiling of Go API endpoints to catch performance regressions before they are merged into a main branch. It generates a versioned report with CPU, heap, and block profiles, which can be compared between commits or pull requests using regression rules. The tool is designed for OpenAPI-enabled services with /debug/pprof/ enabled and provides a stable JSON report for artifacts and automation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tuxerrante/proficiency">https://github.com/tuxerrante/proficiency</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/proficiency-go-api-performance">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the profiling of Go API endpoints to catch performance regressions before they are merged into a main branch. It generates a versioned report with CPU, heap, and block profiles, which can be compared between commits or pull requests using regression rules. The tool is designed for OpenAPI-enabled services with <code>/debug/pprof/</code> enabled and provides a stable JSON report for artifacts and automation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(marketplace): polish v0 Action launch by @tuxerrante in <a href="https://github.com/tuxerrante/proficiency/pull/76">https://github.com/tuxerrante/proficiency/pull/76</a></li>
<li>chore(release): prepare v0.2.1 Marketplace launch by @tuxerrante in <a href="https://github.com/tuxerrante/proficiency/pull/77">https://github.com/tuxerrante/proficiency/pull/77</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tuxerrante/proficiency/compare/v0.2.0...v0.2.1">https://github.com/tuxerrante/proficiency/compare/v0.2.0...v0.2.1</a></p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/vibgrate-scan/</link><pubDate>Tue, 04 Aug 2026 14:47:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.804.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary @vibgrate/cli is a tool designed to analyze codebases locally using AI coding agents. It helps answer questions about the codebase’s structure and drift, providing insights such as drift scores, ranked upgrade priorities, and impact surfaces. The action runs on your machine without requiring API keys or network calls, making it useful for developers who want to perform local analysis without leaving their repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.804.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>@vibgrate/cli</code> is a tool designed to analyze codebases locally using AI coding agents. It helps answer questions about the codebase&rsquo;s structure and drift, providing insights such as drift scores, ranked upgrade priorities, and impact surfaces. The action runs on your machine without requiring API keys or network calls, making it useful for developers who want to perform local analysis without leaving their repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268041">Vibgrate CLI 2026.804.1</h1>
<p><em>Released 2026-08-04</em></p>
<p>This release of the Vibgrate CLI includes a fix that improves log management during scans. The output from the Editor LSP is now handled more effectively.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Editor LSP no longer dumps the full scan JSON into the main log; the artifact is sent on vibgrate/scanArtifact for Output ▸ Vibgrate Scan.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.803.5, interleaved on one runner against the pinned corpus (189 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21474 count</td>
          <td>21474 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>10674 count</td>
          <td>10674 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.94 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>696.30 ms</td>
          <td>699 ms</td>
      </tr>
  </tbody>
</table>
<p>2 regression(s) — published, not omitted:</p>
<ul>
<li>Tasks passed on both arms: 33 → 31 (-6.1%)</li>
<li>Comparable-task rate (both arms passed / total): 0.94 → 0.89 (-6.1%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.804.1">https://vibgrate.com/changelog/cli/2026.804.1</a></p>
]]></content:encoded></item><item><title>Setup vp</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/setup-vp/</link><pubDate>Tue, 04 Aug 2026 14:46:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/setup-vp/</guid><description>Version updated for https://github.com/voidzero-dev/setup-vp to version v1.16.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action setup-vp automates the setup of Vite+ globally with optional Node.js version management, caching dependencies using lock files, and running vp install. It supports multiple package managers and integrates with GitLab CI/CD and Azure Pipelines templates. The action is designed to streamline the setup process for developers working on projects that depend on Vite+.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/voidzero-dev/setup-vp">https://github.com/voidzero-dev/setup-vp</a></strong> to version <strong>v1.16.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-vp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>setup-vp</code> automates the setup of Vite+ globally with optional Node.js version management, caching dependencies using lock files, and running <code>vp install</code>. It supports multiple package managers and integrates with GitLab CI/CD and Azure Pipelines templates. The action is designed to streamline the setup process for developers working on projects that depend on Vite+.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: use exact version tags instead of the moving v1 tag by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/116">https://github.com/voidzero-dev/setup-vp/pull/116</a></li>
<li>fix: stop defaulting setup-ref/setupRef to the frozen v1 tag by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/117">https://github.com/voidzero-dev/setup-vp/pull/117</a></li>
<li>chore: release v1.16.1 by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/118">https://github.com/voidzero-dev/setup-vp/pull/118</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/voidzero-dev/setup-vp/compare/v1.16.0...v1.16.1">https://github.com/voidzero-dev/setup-vp/compare/v1.16.0...v1.16.1</a></p>
]]></content:encoded></item><item><title>VICE Security Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/vice-security-audit/</link><pubDate>Tue, 04 Aug 2026 14:44:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/vice-security-audit/</guid><description>Version updated for https://github.com/Webba-Creative-Technologies/vice to version v3.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary VICE is a comprehensive security auditing tool that automates the process of identifying vulnerabilities in web applications. It offers two modes: remote scan and local audit. The remote scan mode crawls a website, checks exposed services, and runs security probes within a selected scope. The local audit mode analyzes source code, .env files, and dependencies for SQL injection, XSS, and RLS issues. VICE also ships as a GitHub Action that integrates with CI/CD pipelines to continuously monitor and report on application security.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Webba-Creative-Technologies/vice">https://github.com/Webba-Creative-Technologies/vice</a></strong> to version <strong>v3.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vice-security-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>VICE is a comprehensive security auditing tool that automates the process of identifying vulnerabilities in web applications. It offers two modes: remote scan and local audit. The remote scan mode crawls a website, checks exposed services, and runs security probes within a selected scope. The local audit mode analyzes source code, <code>.env</code> files, and dependencies for SQL injection, XSS, and RLS issues. VICE also ships as a GitHub Action that integrates with CI/CD pipelines to continuously monitor and report on application security.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>VICE 3.4.0 adds a complete security scanning module for AI and RAG application APIs.</p>
<h2 id="ai-and-rag-security-module">AI and RAG security module</h2>
<p>The new module includes bounded, non-destructive checks for:</p>
<ul>
<li>Access control and authentication</li>
<li>Rate limiting and abuse protection</li>
<li>Prompt injection</li>
<li>Retrieval and tenant isolation</li>
<li>Sensitive data exposure</li>
<li>Connected tools and function calling</li>
<li>Generic JSON APIs</li>
<li>OpenAI-compatible APIs</li>
<li>Server-Sent Events responses</li>
</ul>
<p>The module supports environment-backed authentication profiles and keeps sensitive evidence redacted.</p>
<p>It can be used directly from the interactive scanner or through a dedicated configuration file for automated scans.</p>
<h2 id="more-reliable-findings">More reliable findings</h2>
<p>This release also includes a broad false-positive reduction pass across local and remote audits.</p>
<ul>
<li>Missing CSRF and rate limiting controls are only reported when the related feature exists.</li>
<li>Login security findings require an actual authentication flow.</li>
<li>SPA fallback pages are distinguished from real API and administrative endpoints.</li>
<li>Temporary DNS and browser failures are reported as incomplete coverage instead of vulnerabilities.</li>
<li>Generic migrations, ordinary public storage and unconfirmed services no longer produce important findings.</li>
<li>Placeholder credentials, documentation keys and example values are filtered more accurately.</li>
<li>Sensitive values remain redacted from findings and reports.</li>
</ul>
<h2 id="github-action">GitHub Action</h2>
<p>The <code>v3</code> tag points to this release:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Webba-Creative-Technologies/vice@v3</span>
</span></span></code></pre></div><h2 id="upgrade">Upgrade</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install -g vice-security@3.4.0
</span></span></code></pre></div><p>VICE 3.4.0 remains compatible with existing 3.x CLI commands and report formats.</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/b.ia-accessibility-checker/</link><pubDate>Tue, 04 Aug 2026 14:42:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility testing in CI/CD pipelines by checking if the code meets specified WCAG guidelines for different target audiences. It provides flexible audience targeting and AI-driven analysis to help companies ensure their products are accessible, reducing learning curve costs and errors compared to using external solutions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility testing in CI/CD pipelines by checking if the code meets specified WCAG guidelines for different target audiences. It provides flexible audience targeting and AI-driven analysis to help companies ensure their products are accessible, reducing learning curve costs and errors compared to using external solutions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>AGENTS.md Lint (Schliff)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/agents.md-lint-schliff/</link><pubDate>Tue, 04 Aug 2026 14:41:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/agents.md-lint-schliff/</guid><description>Version updated for https://github.com/Zandereins/schliff to version v8.10.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Schliff scores AGENTS.md against an explicit, versioned rubric to ensure deterministic quality scores for AI instruction files, preventing the degradation of tools like Cursor, Codex, Copilot, and Claude Code due to rotting files. It provides a rule engine that can be read, pinned, and gated CI on.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zandereins/schliff">https://github.com/Zandereins/schliff</a></strong> to version <strong>v8.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-md-lint-schliff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Schliff scores AGENTS.md against an explicit, versioned rubric to ensure deterministic quality scores for AI instruction files, preventing the degradation of tools like Cursor, Codex, Copilot, and Claude Code due to rotting files. It provides a rule engine that can be read, pinned, and gated CI on.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Four correctness fixes in the same place: a value that describes <em>how</em> a file was measured, reported wrongly. Two had been sitting on <code>main</code> unreleased since 2026-07-31; the other two were found while verifying them.</p>
<p><strong>This is a minor, not a patch, because one fix lowers scores.</strong> <code>schliff score --format skill</code> on a file without YAML frontmatter now agrees with <code>--format skill.md</code> — which means it reports the lower, un-normalized number. Auto-detection, every other command, and the playground are unaffected.</p>
<h2 id="fixed">Fixed</h2>
<h3 id="--format-skill-and---format-skillmd-scored-the-same-file-differently-173"><code>--format skill</code> and <code>--format skill.md</code> scored the same file differently (#173)</h3>
<pre tabindex="0"><code>schliff score AGENTS.md --format skill     → composite 39.3
schliff score AGENTS.md --format skill.md  → composite 34.5
</code></pre><p>Across the 29 tracked instruction files in this repo, <strong>exactly the 8 that carry no YAML frontmatter</strong> diverged, by <strong>4.7–5.5 composite points</strong> — two of them real files in the project&rsquo;s own benchmark corpus.</p>
<p><code>shared.build_scores</code> branched on a raw string compare (<code>fmt != &quot;skill.md&quot;</code>), so the public <code>skill</code> alias entered a normalization branch that its canonical twin skips. For a file without frontmatter that branch invents a name and description from the body and scores the wrapped copy:</p>
<pre tabindex="0"><code>--format skill     structure 80, issues: [no_real_examples]
--format skill.md  structure 50, issues: [no_frontmatter, no_real_examples]
</code></pre><p>The alias was hiding the exact defect the structure dimension exists to report.</p>
<p>Two spellings of one format agreeing is not a judgment call for a deterministic scorer; which side they agree on is. Normalization exists so formats that <em>legitimately</em> carry no frontmatter (CLAUDE.md, AGENTS.md, <code>.cursorrules</code>) are scorable at all — and a SKILL.md is defined by its frontmatter. So the un-normalized number is the measurement, and 39.3 was the flattered one.</p>
<p><strong>Nothing that pins a format in CI can change verdict:</strong> a stated format reaches the engine only through <code>score</code>, never through <code>verify</code>.</p>
<h3 id="--format-system-prompt-silently-dropped-the-security-dimension-168"><code>--format system-prompt</code> silently dropped the security dimension (#168)</h3>
<p>The same file, the same version, scored <code>49.4</code> with 7 dimensions when the format was detected and <code>36.8</code> with 6 and no <code>security</code> when it was stated through the public hyphenated alias — a spread of 5.9 to 15.0 points across five files (as recorded in the fix&rsquo;s spec). The user who pins the format explicitly, the more careful thing to do in CI, got the wrong number.</p>
<p><code>security</code> is a <strong>core</strong> headline dimension for <code>system_prompt</code> (weight 0.15), not the opt-in side signal it is for the skill.md family. Dispatch now resolves through a single <code>registry.resolve_format()</code>.</p>
<h3 id="schliff-doctor-typo-exited-0-169"><code>schliff doctor &lt;typo&gt;</code> exited 0 (#169)</h3>
<p>A named directory that does not exist rendered &ldquo;No skills found. Check skill directories.&rdquo; and exited successfully — indistinguishable from an empty directory, so no CI gate could catch the typo. The report then listed the <em>default</em> scan directories, which it had not scanned, as if those were the ones that came up empty. <code>verify</code> had always errored on a missing file; <code>doctor</code> disagreed with it.</p>
<p>Validation sits at the CLI boundary, so library callers are untouched, and only paths you <em>name</em> are checked — the built-in defaults stay optional, because <code>.claude/skills</code> legitimately does not exist in most repos.</p>
<h3 id="the-version-stamped-into-every-score-described-the-installed-package-not-the-running-engine-172">The version stamped into every score described the installed package, not the running engine (#172)</h3>
<p><code>_resolve_version()</code> read <code>importlib.metadata</code> — the installed dist-info — while its docstring promised the value &ldquo;can never drift from pyproject.toml&rdquo;. In a source or editable checkout those are different things.</p>
<p>Measured in this repo before the fix: all three gated version sources said <code>8.9.0</code>, <code>schliff version</code> said <code>8.1.0</code>, and the console script was loading the 8.9.0 working tree the whole time.</p>
<p>Not cosmetic — <code>score --json</code> stamps this value as <code>version</code>, so it propagated into benchmark JSONL and leaderboard entries, attributing measurements to an engine version that never produced them. <strong>A <code>pip install</code> user was never affected</strong>; their metadata matches their code.</p>
<h2 id="also">Also</h2>
<ul>
<li>The reported format now uses canonical names instead of echoing the <code>--format</code> alias. A genuine SKILL.md scored with <code>--format skill</code> used to print <code>Format: skill (normalized)</code>, where neither half was true. (#173)</li>
<li>Repaired a stale <code>CHANGELOG.md</code> footer: <code>[Unreleased]</code> still compared against <code>v8.8.2</code>, skipping <code>v8.9.0</code>.</li>
<li>GitHub Actions bumps: <code>codeql-action</code> v4.37.4, <code>gh-action-pypi-publish</code> v1.14.2. (#171)</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li><strong>1939 tests collected</strong>, green on 3.10 / 3.11 / 3.12 / 3.13 and macOS (1934 passed + 5 corpus-gated skips in CI); <code>ruff==0.15.8</code> and markdownlint clean</li>
<li>Two-sided gate for #173: 29 files × 12 format values, comparing the composite <em>and</em> every per-dimension score — <strong>340/348 cells byte-identical</strong>, and the 8 that moved are exactly the accused set, each now equal to its canonical twin</li>
<li><code>python -m build</code> + <code>twine check</code>: both artifacts PASSED</li>
<li>The built wheel, installed into a clean non-editable venv, reports <code>schliff 8.10.0</code>, and all four fixes hold in the shipped artifact</li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/Zandereins/schliff/compare/v8.9.0...v8.10.0">https://github.com/Zandereins/schliff/compare/v8.9.0...v8.10.0</a></p>
]]></content:encoded></item><item><title>NivL1 AI PR Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/nivl1-ai-pr-reviewer/</link><pubDate>Tue, 04 Aug 2026 07:28:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/nivl1-ai-pr-reviewer/</guid><description>Version updated for https://github.com/NivL1/ai-pr-reviewer to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates AI-powered code review on pull requests using a NestJS service and GitHub Action. It handles HMAC-validated webhook ingestion, incremental re-review of changes since the last review, and provides containerized deployment with multi-stage Dockerfile and docker-compose. The service supports LLM calls behind a single service boundary, including Anthropic today and a potential second provider in the future.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NivL1/ai-pr-reviewer">https://github.com/NivL1/ai-pr-reviewer</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nivl1-ai-pr-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action automates AI-powered code review on pull requests using a NestJS service and GitHub Action. It handles HMAC-validated webhook ingestion, incremental re-review of changes since the last review, and provides containerized deployment with multi-stage Dockerfile and <code>docker-compose</code>. The service supports LLM calls behind a single service boundary, including Anthropic today and a potential second provider in the future.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>LLM-powered PR review, as a GitHub Action.</strong> Drop it into any repo&rsquo;s CI to get inline code review comments on every pull request — no server to run, no webhook to expose.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">NivL1/ai-pr-reviewer@v0.1.2</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic-api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><p><strong>What it does differently:</strong></p>
<ul>
<li><strong>Reviews only what&rsquo;s new.</strong> Most PR-review bots re-diff the whole PR on every push and repeat the same comments across every commit. This one tracks its own last review on a PR and only looks at what changed since then.</li>
<li><strong>Filters the noise before it reaches the model.</strong> Generated files, lockfiles, and sourcemaps are stripped from the diff automatically — no token budget spent reviewing things nobody reviews by hand anyway.</li>
<li><strong>Cost-bounded.</strong> <code>max-diff-lines</code> skips the review outright on PRs too large to sanely review in one pass, instead of silently truncating and reviewing half a diff.</li>
<li><strong>Model-pinnable.</strong> Point it at whichever Claude model you want via the <code>model</code> input.</li>
</ul>
<p>Full input reference and setup notes: <a href="https://github.com/NivL1/ai-pr-reviewer#readme">README</a> · <a href="https://github.com/NivL1/ai-pr-reviewer/blob/master/docs/runbook.md">runbook</a>.</p>
]]></content:encoded></item><item><title>CordC Action(modify by CordCloud Action)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/cordc-actionmodify-by-cordcloud-action/</link><pubDate>Tue, 04 Aug 2026 07:27:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/cordc-actionmodify-by-cordcloud-action/</guid><description>Version updated for https://github.com/opcwj/cordcloud-action to version Error loading version from page [https://github.com/marketplace/actions/cordc-action-modify-by-cordcloud-action], unable to determine latest release.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary CordCloud Action 是一个 GitHub Actions 动作，用于自动续命 CordCloud 帐号。该动作通过 schedule 触发，每天自动签到并领取流量续命。用户可以配置邮件和密码等参数，并选择是否启用两步验证。此外，该动作还支持自定义设备指纹、IMAP 服务器和端口等选项，以适应不同的使用场景。</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/opcwj/cordcloud-action">https://github.com/opcwj/cordcloud-action</a></strong> to version <strong>Error loading version from page [https://github.com/marketplace/actions/cordc-action-modify-by-cordcloud-action], unable to determine latest release</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cordc-action-modify-by-cordcloud-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>CordCloud Action 是一个 GitHub Actions 动作，用于自动续命 CordCloud 帐号。该动作通过 <code>schedule</code> 触发，每天自动签到并领取流量续命。用户可以配置邮件和密码等参数，并选择是否启用两步验证。此外，该动作还支持自定义设备指纹、IMAP 服务器和端口等选项，以适应不同的使用场景。</p>
]]></content:encoded></item><item><title>Get Latest Release Information</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/get-latest-release-information/</link><pubDate>Tue, 04 Aug 2026 07:26:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/get-latest-release-information/</guid><description>Version updated for https://github.com/ophiosdev/github-action-latest-release to version v0.2.1.
This action is used across all versions by 6 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “Get Latest Release” retrieves the latest release from another repository, handling various options like including drafts and prereleases, excluding or including certain tags, and using personal access tokens for private repositories. It outputs the release version tag, ID, description, URL, and asset URL. The action helps automate the retrieval of release information for integration into workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ophiosdev/github-action-latest-release">https://github.com/ophiosdev/github-action-latest-release</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/get-latest-release-information">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;Get Latest Release&rdquo; retrieves the latest release from another repository, handling various options like including drafts and prereleases, excluding or including certain tags, and using personal access tokens for private repositories. It outputs the release version tag, ID, description, URL, and asset URL. The action helps automate the retrieval of release information for integration into workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update dependency @octokit/rest to v22 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/30">https://github.com/ophiosdev/github-action-latest-release/pull/30</a></li>
<li>chore(deps): update dependency @actions/core to v3 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/28">https://github.com/ophiosdev/github-action-latest-release/pull/28</a></li>
<li>chore(deps): update all non-major dependencies by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/27">https://github.com/ophiosdev/github-action-latest-release/pull/27</a></li>
<li>chore(deps): update actions/setup-node action to v7 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/21">https://github.com/ophiosdev/github-action-latest-release/pull/21</a></li>
<li>chore(deps-dev): bump fast-xml-parser from 5.2.5 to 5.10.1 by @dependabot[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/39">https://github.com/ophiosdev/github-action-latest-release/pull/39</a></li>
<li>chore(deps-dev): bump flatted from 3.3.3 to 3.4.4 by @dependabot[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/38">https://github.com/ophiosdev/github-action-latest-release/pull/38</a></li>
<li>chore(deps-dev): bump lodash from 4.17.21 to 4.18.1 by @dependabot[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/37">https://github.com/ophiosdev/github-action-latest-release/pull/37</a></li>
<li>chore(deps): update dependency @actions/github to v9 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/29">https://github.com/ophiosdev/github-action-latest-release/pull/29</a></li>
<li>chore(deps): update dependency glob to v13 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/25">https://github.com/ophiosdev/github-action-latest-release/pull/25</a></li>
<li>chore(deps): update dependency @github/local-action to v7 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/23">https://github.com/ophiosdev/github-action-latest-release/pull/23</a></li>
<li>chore(deps): update dependency @eslint/compat to v2 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/22">https://github.com/ophiosdev/github-action-latest-release/pull/22</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/39">https://github.com/ophiosdev/github-action-latest-release/pull/39</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ophiosdev/github-action-latest-release/compare/v0.2.0...v0.2.1">https://github.com/ophiosdev/github-action-latest-release/compare/v0.2.0...v0.2.1</a></p>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-api-onboarding/</link><pubDate>Tue, 04 Aug 2026 07:25:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v3.2.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman API Onboarding Action automates the process of setting up and managing a new API repository by integrating various Postman tools. It helps developers bootstrap their project, upload an OpenAPI specification, generate collections for smoke testing and contract enforcement, and integrate with GitHub for continuous integration. The action also configures mock servers and monitors to ensure that the service behaves as expected.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v3.2.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman API Onboarding Action automates the process of setting up and managing a new API repository by integrating various Postman tools. It helps developers bootstrap their project, upload an OpenAPI specification, generate collections for smoke testing and contract enforcement, and integrate with GitHub for continuous integration. The action also configures mock servers and monitors to ensure that the service behaves as expected.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/91">https://github.com/postman-cs/postman-api-onboarding-action/pull/91</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/92">https://github.com/postman-cs/postman-api-onboarding-action/pull/92</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/93">https://github.com/postman-cs/postman-api-onboarding-action/pull/93</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/94">https://github.com/postman-cs/postman-api-onboarding-action/pull/94</a></li>
<li>chore(deps): pin Insights onboarding v2.2.1 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/95">https://github.com/postman-cs/postman-api-onboarding-action/pull/95</a></li>
<li>fix: consume Insights human-session normalization by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/96">https://github.com/postman-cs/postman-api-onboarding-action/pull/96</a></li>
<li>fix: consume repo-sync v2.2.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/97">https://github.com/postman-cs/postman-api-onboarding-action/pull/97</a></li>
<li>fix: expose mock environment and refresh Azure pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/98">https://github.com/postman-cs/postman-api-onboarding-action/pull/98</a></li>
<li>feat: pass mock visibility policy through to repo-sync by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/99">https://github.com/postman-cs/postman-api-onboarding-action/pull/99</a></li>
<li>chore: pin repo-sync v2.4.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/100">https://github.com/postman-cs/postman-api-onboarding-action/pull/100</a></li>
<li>fix: document private mock credential paths for consumers by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/101">https://github.com/postman-cs/postman-api-onboarding-action/pull/101</a></li>
<li>fix(deps): advance the bootstrap pin to v2.13.2 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/102">https://github.com/postman-cs/postman-api-onboarding-action/pull/102</a></li>
<li>fix(deps): advance bootstrap and repo-sync pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/103">https://github.com/postman-cs/postman-api-onboarding-action/pull/103</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/104">https://github.com/postman-cs/postman-api-onboarding-action/pull/104</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.8 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/105">https://github.com/postman-cs/postman-api-onboarding-action/pull/105</a></li>
<li>fix(deps): advance bootstrap pin to v2.13.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/106">https://github.com/postman-cs/postman-api-onboarding-action/pull/106</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>fix(ci): validate sibling pins without local checkouts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/111">https://github.com/postman-cs/postman-api-onboarding-action/pull/111</a></li>
<li>feat(azure-devops): forward an explicit workspace squad id from the Windows template by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/112">https://github.com/postman-cs/postman-api-onboarding-action/pull/112</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@github-actions[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.2.0">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.2.0</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/91">https://github.com/postman-cs/postman-api-onboarding-action/pull/91</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/92">https://github.com/postman-cs/postman-api-onboarding-action/pull/92</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/93">https://github.com/postman-cs/postman-api-onboarding-action/pull/93</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/94">https://github.com/postman-cs/postman-api-onboarding-action/pull/94</a></li>
<li>chore(deps): pin Insights onboarding v2.2.1 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/95">https://github.com/postman-cs/postman-api-onboarding-action/pull/95</a></li>
<li>fix: consume Insights human-session normalization by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/96">https://github.com/postman-cs/postman-api-onboarding-action/pull/96</a></li>
<li>fix: consume repo-sync v2.2.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/97">https://github.com/postman-cs/postman-api-onboarding-action/pull/97</a></li>
<li>fix: expose mock environment and refresh Azure pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/98">https://github.com/postman-cs/postman-api-onboarding-action/pull/98</a></li>
<li>feat: pass mock visibility policy through to repo-sync by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/99">https://github.com/postman-cs/postman-api-onboarding-action/pull/99</a></li>
<li>chore: pin repo-sync v2.4.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/100">https://github.com/postman-cs/postman-api-onboarding-action/pull/100</a></li>
<li>fix: document private mock credential paths for consumers by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/101">https://github.com/postman-cs/postman-api-onboarding-action/pull/101</a></li>
<li>fix(deps): advance the bootstrap pin to v2.13.2 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/102">https://github.com/postman-cs/postman-api-onboarding-action/pull/102</a></li>
<li>fix(deps): advance bootstrap and repo-sync pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/103">https://github.com/postman-cs/postman-api-onboarding-action/pull/103</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/104">https://github.com/postman-cs/postman-api-onboarding-action/pull/104</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.8 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/105">https://github.com/postman-cs/postman-api-onboarding-action/pull/105</a></li>
<li>fix(deps): advance bootstrap pin to v2.13.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/106">https://github.com/postman-cs/postman-api-onboarding-action/pull/106</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>fix(ci): validate sibling pins without local checkouts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/111">https://github.com/postman-cs/postman-api-onboarding-action/pull/111</a></li>
<li>feat(azure-devops): forward an explicit workspace squad id from the Windows template by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/112">https://github.com/postman-cs/postman-api-onboarding-action/pull/112</a></li>
</ul>
<h2 id="new-contributors-1">New Contributors</h2>
<ul>
<li>@github-actions[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.2.0">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.2.0</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/91">https://github.com/postman-cs/postman-api-onboarding-action/pull/91</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/92">https://github.com/postman-cs/postman-api-onboarding-action/pull/92</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/93">https://github.com/postman-cs/postman-api-onboarding-action/pull/93</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/94">https://github.com/postman-cs/postman-api-onboarding-action/pull/94</a></li>
<li>chore(deps): pin Insights onboarding v2.2.1 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/95">https://github.com/postman-cs/postman-api-onboarding-action/pull/95</a></li>
<li>fix: consume Insights human-session normalization by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/96">https://github.com/postman-cs/postman-api-onboarding-action/pull/96</a></li>
<li>fix: consume repo-sync v2.2.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/97">https://github.com/postman-cs/postman-api-onboarding-action/pull/97</a></li>
<li>fix: expose mock environment and refresh Azure pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/98">https://github.com/postman-cs/postman-api-onboarding-action/pull/98</a></li>
<li>feat: pass mock visibility policy through to repo-sync by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/99">https://github.com/postman-cs/postman-api-onboarding-action/pull/99</a></li>
<li>chore: pin repo-sync v2.4.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/100">https://github.com/postman-cs/postman-api-onboarding-action/pull/100</a></li>
<li>fix: document private mock credential paths for consumers by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/101">https://github.com/postman-cs/postman-api-onboarding-action/pull/101</a></li>
<li>fix(deps): advance the bootstrap pin to v2.13.2 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/102">https://github.com/postman-cs/postman-api-onboarding-action/pull/102</a></li>
<li>fix(deps): advance bootstrap and repo-sync pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/103">https://github.com/postman-cs/postman-api-onboarding-action/pull/103</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/104">https://github.com/postman-cs/postman-api-onboarding-action/pull/104</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.8 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/105">https://github.com/postman-cs/postman-api-onboarding-action/pull/105</a></li>
<li>fix(deps): advance bootstrap pin to v2.13.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/106">https://github.com/postman-cs/postman-api-onboarding-action/pull/106</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>fix(ci): validate sibling pins without local checkouts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/111">https://github.com/postman-cs/postman-api-onboarding-action/pull/111</a></li>
<li>feat(azure-devops): forward an explicit workspace squad id from the Windows template by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/112">https://github.com/postman-cs/postman-api-onboarding-action/pull/112</a></li>
</ul>
<h2 id="new-contributors-2">New Contributors</h2>
<ul>
<li>@github-actions[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.2.0">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.2.0</a></p>
<h2 id="whats-changed-4">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/91">https://github.com/postman-cs/postman-api-onboarding-action/pull/91</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/92">https://github.com/postman-cs/postman-api-onboarding-action/pull/92</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/93">https://github.com/postman-cs/postman-api-onboarding-action/pull/93</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/94">https://github.com/postman-cs/postman-api-onboarding-action/pull/94</a></li>
<li>chore(deps): pin Insights onboarding v2.2.1 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/95">https://github.com/postman-cs/postman-api-onboarding-action/pull/95</a></li>
<li>fix: consume Insights human-session normalization by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/96">https://github.com/postman-cs/postman-api-onboarding-action/pull/96</a></li>
<li>fix: consume repo-sync v2.2.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/97">https://github.com/postman-cs/postman-api-onboarding-action/pull/97</a></li>
<li>fix: expose mock environment and refresh Azure pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/98">https://github.com/postman-cs/postman-api-onboarding-action/pull/98</a></li>
<li>feat: pass mock visibility policy through to repo-sync by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/99">https://github.com/postman-cs/postman-api-onboarding-action/pull/99</a></li>
<li>chore: pin repo-sync v2.4.0 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/100">https://github.com/postman-cs/postman-api-onboarding-action/pull/100</a></li>
<li>fix: document private mock credential paths for consumers by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/101">https://github.com/postman-cs/postman-api-onboarding-action/pull/101</a></li>
<li>fix(deps): advance the bootstrap pin to v2.13.2 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/102">https://github.com/postman-cs/postman-api-onboarding-action/pull/102</a></li>
<li>fix(deps): advance bootstrap and repo-sync pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/103">https://github.com/postman-cs/postman-api-onboarding-action/pull/103</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/104">https://github.com/postman-cs/postman-api-onboarding-action/pull/104</a></li>
<li>fix(deps): advance repo-sync pin to v2.6.8 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/105">https://github.com/postman-cs/postman-api-onboarding-action/pull/105</a></li>
<li>fix(deps): advance bootstrap pin to v2.13.7 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/106">https://github.com/postman-cs/postman-api-onboarding-action/pull/106</a></li>
<li>fix(deps): advance sibling pins to the latest released tags by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
<li>fix(ci): validate sibling pins without local checkouts by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/111">https://github.com/postman-cs/postman-api-onboarding-action/pull/111</a></li>
<li>feat(azure-devops): forward an explicit workspace squad id from the Windows template by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/112">https://github.com/postman-cs/postman-api-onboarding-action/pull/112</a></li>
</ul>
<h2 id="new-contributors-3">New Contributors</h2>
<ul>
<li>@github-actions[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/107">https://github.com/postman-cs/postman-api-onboarding-action/pull/107</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.2.0">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.8...v3.2.0</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-onboarding-workspace-bootstrap/</link><pubDate>Tue, 04 Aug 2026 07:24:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.17.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Workspace Bootstrap action automates the process of creating a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections with executable tests. It solves the problem of setting up Postman workspaces quickly and efficiently, ensuring that all necessary test cases are generated based on the OpenAPI spec. The action provides dynamic contract tests and supports multiple protocols, including gRPC, SOAP, GraphQL, AsyncAPI, and MCP lanes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.17.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Workspace Bootstrap action automates the process of creating a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections with executable tests. It solves the problem of setting up Postman workspaces quickly and efficiently, ensuring that all necessary test cases are generated based on the OpenAPI spec. The action provides dynamic contract tests and supports multiple protocols, including gRPC, SOAP, GraphQL, AsyncAPI, and MCP lanes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: normalize multifile receipt after v2.16.1 by @github-actions[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/179">https://github.com/postman-cs/postman-bootstrap-action/pull/179</a></li>
<li>fix(gateway-assets): fail closed when org squad discovery is indeterminate by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/180">https://github.com/postman-cs/postman-bootstrap-action/pull/180</a></li>
<li>feat(release): gate aliases on correlated E2E by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/181">https://github.com/postman-cs/postman-bootstrap-action/pull/181</a></li>
<li>fix(release): wait for run-name hydration by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/182">https://github.com/postman-cs/postman-bootstrap-action/pull/182</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2.16.1...v2.17.1">https://github.com/postman-cs/postman-bootstrap-action/compare/v2.16.1...v2.17.1</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Smoke Flow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-onboarding-smoke-flow/</link><pubDate>Tue, 04 Aug 2026 07:23:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/postman-onboarding-smoke-flow/</guid><description>Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v3.3.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action reshapes a generated Postman Smoke collection into an ordered smoke journey using one explicit flow path or a derived manifest from the OpenAPI spec. It automates the process of organizing and running tests, providing options for OAuth2 and API key authentication. The action is part of the larger Postman API Onboarding suite and can be used to streamline the onboarding process for new projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-smoke-flow-action">https://github.com/postman-cs/postman-smoke-flow-action</a></strong> to version <strong>v3.3.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-smoke-flow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action reshapes a generated Postman Smoke collection into an ordered smoke journey using one explicit flow path or a derived manifest from the OpenAPI spec. It automates the process of organizing and running tests, providing options for OAuth2 and API key authentication. The action is part of the larger Postman API Onboarding suite and can be used to streamline the onboarding process for new projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): cut immutable tags only after gates pass on main by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/57">https://github.com/postman-cs/postman-smoke-flow-action/pull/57</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/58">https://github.com/postman-cs/postman-smoke-flow-action/pull/58</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/59">https://github.com/postman-cs/postman-smoke-flow-action/pull/59</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/60">https://github.com/postman-cs/postman-smoke-flow-action/pull/60</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/61">https://github.com/postman-cs/postman-smoke-flow-action/pull/61</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.7...v3.3.1">https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.7...v3.3.1</a></p>
]]></content:encoded></item><item><title>Garita PII Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/garita-pii-guard/</link><pubDate>Tue, 04 Aug 2026 07:22:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/garita-pii-guard/</guid><description>Version updated for https://github.com/proscar87/garita to version v0.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Garita is a GitHub Action that blocks sensitive personal data and credentials from entering your repository by comparing them against predefined patterns or lists. It helps prevent the inclusion of PII like names, CURPs, RFCs, CLABEs, NSSs, Mexican phone numbers, secrets, and sensitive configurations in version-controlled files. The tool uses regular expressions to identify and block sensitive data, providing a secure way to manage project information without exposing personal identifiable information.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/proscar87/garita">https://github.com/proscar87/garita</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/garita-pii-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Garita is a GitHub Action that blocks sensitive personal data and credentials from entering your repository by comparing them against predefined patterns or lists. It helps prevent the inclusion of PII like names, CURPs, RFCs, CLABEs, NSSs, Mexican phone numbers, secrets, and sensitive configurations in version-controlled files. The tool uses regular expressions to identify and block sensitive data, providing a secure way to manage project information without exposing personal identifiable information.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Dos frentes, ambos con evidencia de repos reales:</p>
<h2 id="calibración-de-datos-raspados">Calibración de datos raspados</h2>
<p>Un repo de scraping enseñó dos clases de falso positivo nuevas: los <strong>segmentos de dígitos en URLs de CDN</strong> (un ID de foto de Instagram pasa el módulo de la CLABE y el catálogo de bancos) y las <strong>marcas de tiempo de 14 dígitos</strong> (un timestamp del Wayback Machine pasa el doble módulo 11 del CNPJ). Dos reglas con principio:</p>
<ul>
<li><strong>Dentro de una URL, el hallazgo baja a aviso</strong> — no se calla, porque una CLABE en la ruta de un API sí puede ser fuga real y cegarse está prohibido; pero tampoco rompe el build por cada foto raspada. Aplica a todos los detectores de identificadores.</li>
<li><strong>CNPJ pelón exige que lo nombren</strong> — la misma medicina que ya tomaba el CPF, por otra enfermedad. Con la puntuación oficial (<code>12.345.678/0001-XX</code>) dispara solo.</li>
</ul>
<p>El repo que originó el reporte pasó de 5 errores a <strong>0</strong>, con todo el ruido degradado a avisos visibles. Los 10 proyectos de control: idénticos a la base, 0 errores.</p>
<h2 id="dos-países-más--">Dos países más: 🇪🇨 🇩🇴</h2>
<ul>
<li><strong>Ecuador — cédula</strong>: módulo 10 del Registro Civil (coeficientes 2-1-2-1…), con estructura de provincia (01-24, 30) y tercer dígito de persona natural.</li>
<li><strong>Rep. Dominicana — cédula</strong>: el Luhn de la JCE, formato <code>001-1234567-8</code>.</li>
</ul>
<p>Ambas con contexto obligatorio: diez u once dígitos pelones compiten con teléfonos y folios, y en ningún país se escribe una cédula sin llamarla cédula.</p>
<p>Son <strong>trece países</strong>: 🇲🇽 🇦🇷 🇧🇷 🇨🇱 🇨🇴 🇪🇨 🇪🇸 🇵🇪 🇺🇾 🇩🇴 🇺🇸 🇨🇦 🇵🇹</p>
<p><strong>Instalación</strong>: <code>pip install garita</code> · Action <code>proscar87/garita@v0</code> · pre-commit <code>rev: v0.7.0</code></p>
]]></content:encoded></item><item><title>Oversight Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/oversight-lint/</link><pubDate>Tue, 04 Aug 2026 07:20:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/oversight-lint/</guid><description>Version updated for https://github.com/rachelslurs/oversight-lint-action to version v1.1.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates linting of Storybook MCP components to ensure component documentation is present. It fails the build if any components are missing documentation, helping catch regressions early in the development cycle. The action reads the built components JSON from a manifest and compares it against expected documentation using rules defined in oversight.config.json.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rachelslurs/oversight-lint-action">https://github.com/rachelslurs/oversight-lint-action</a></strong> to version <strong>v1.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oversight-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates linting of Storybook MCP components to ensure component documentation is present. It fails the build if any components are missing documentation, helping catch regressions early in the development cycle. The action reads the built components JSON from a manifest and compares it against expected documentation using rules defined in <code>oversight.config.json</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runs <code>oversight-lint@0.6.2</code>, gated by this repository&rsquo;s canary. Override with the <code>version</code> input.</p>
]]></content:encoded></item><item><title>Podcast Generator 17.38</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/podcast-generator-17.38/</link><pubDate>Tue, 04 Aug 2026 07:19:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/podcast-generator-17.38/</guid><description>Version updated for https://github.com/real-eric-sobek/podcast-generator to version v1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates podcasts based on a template. It automates the process of creating audio files using text-to-speech (TTS) technology, which can save time and effort for podcast producers by allowing them to focus on content creation instead of recording and editing audio manually. The action supports various languages and dialects and can generate different types of podcasts such as interview shows or news reports.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/real-eric-sobek/podcast-generator">https://github.com/real-eric-sobek/podcast-generator</a></strong> to version <strong>v1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/podcast-generator-17-38">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates podcasts based on a template. It automates the process of creating audio files using text-to-speech (TTS) technology, which can save time and effort for podcast producers by allowing them to focus on content creation instead of recording and editing audio manually. The action supports various languages and dialects and can generate different types of podcasts such as interview shows or news reports.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/real-eric-sobek/podcast-generator/commits/v1.0">https://github.com/real-eric-sobek/podcast-generator/commits/v1.0</a></p>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/remyx-outrider/</link><pubDate>Tue, 04 Aug 2026 07:19:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.48.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Outrider is a GitHub Action that automates the validation and comparison of new machine learning methods against existing codebases, helping teams measure changes against metrics they already track. It uses ephemeral runners to prevent context pollution and supports multiple model backends, including Anthropic Opus and z.ai GLM-5.2, allowing for efficient exploration and selection of methods.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.48</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Outrider is a GitHub Action that automates the validation and comparison of new machine learning methods against existing codebases, helping teams measure changes against metrics they already track. It uses ephemeral runners to prevent context pollution and supports multiple model backends, including Anthropic Opus and z.ai GLM-5.2, allowing for efficient exploration and selection of methods.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="feature">Feature</h2>
<p><strong><code>mode=brief</code></strong> — a paper-less companion to the recommend flow. A design brief (via <code>INPUT_LEAD_CONTENT</code>) is the sole spec; no ranker call, no arXiv anchor. Composes the same leaf helpers as the paper-anchored path so downstream gates (path allowlist, integration, stub density) and telemetry (step summary, run cost) work identically.</p>
<p>Same PR-vs-Issue routing, same self-review discipline. The <code>INVOCATION.md</code> variant drops the Mode 1/2/3 paper-porting framing but keeps the scope + honesty rules intact.</p>
<h2 id="details">Details</h2>
<ul>
<li>License enrichment for briefs: every cited GitHub / HF-model / HF-dataset URL (capped at 5) gets its license fetched best-effort and rendered as a compact multi-entry block in the PR body. <code>user-attachments/raw/blob</code> GitHub paths and HF dataset URLs (<code>huggingface.co/datasets/…</code>) surface correctly.</li>
<li><code>Refs: #N</code> auto-link when the brief cites GitHub issue numbers or URLs.</li>
<li>Brief-mode invocation carries the same &ldquo;do not run git commands during your session&rdquo; guard the paper-anchored path uses, so <code>commit_and_push</code>&rsquo;s HEAD-matches-origin sanity check holds.</li>
<li><code>publish=branch</code> honored: pushes the drafter branch, no PR object.</li>
</ul>
<h2 id="trigger">Trigger</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>gh workflow run outrider.yml --repo &lt;target&gt; <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  -f mode<span style="color:#f92672">=</span>brief <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  -f lead-content<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;</span><span style="color:#66d9ef">$(</span>cat design-brief.md<span style="color:#66d9ef">)</span><span style="color:#e6db74">&#34;</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  -f publish<span style="color:#f92672">=</span>pr <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  -f provider<span style="color:#f92672">=</span>zai <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  -f model<span style="color:#f92672">=</span>glm-5.2
</span></span></code></pre></div><p>Customer workflow templates need <code>mode</code> + <code>lead-content</code> inputs declared for this to reach the composite action. Existing installs can re-run <code>outrider init</code> (or hand-edit) to expose them.</p>
<h2 id="compatibility">Compatibility</h2>
<p>Composite action, no breaking changes. Pinned callers on <code>@v1</code> pick up brief mode + the parser fix (v1.7.47) automatically. Paper-anchored <code>mode=recommend</code> behavior is unchanged.</p>
<h2 id="validation">Validation</h2>
<p>1165 tests pass. Live-tested against <code>remyxai/VQASynth</code> on issues #28, #30, #31, #33, #41, #47, #48, #51, #53 — each brief-mode dispatch produced a scoped implementation the convention pass could further refine.</p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/kaniko-build-action/</link><pubDate>Tue, 04 Aug 2026 07:18:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or a personalized greeting to a specified person. It automates tasks related to sending greetings and provides flexibility in customizing the greeting message by allowing input of a name.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or a personalized greeting to a specified person. It automates tasks related to sending greetings and provides flexibility in customizing the greeting message by allowing input of a name.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>SpecGuard CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/specguard-ci/</link><pubDate>Tue, 04 Aug 2026 07:18:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/specguard-ci/</guid><description>Version updated for https://github.com/Sawaiz-zip/spec-guard to version v0.4.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SpecGuard is a GitHub Action that enforces semantic governance by checking the scope and content of spec files against locked goals and scopes, preventing potential direction shifts without proper approvals. It uses AI to analyze changes and provides warnings or blocks based on confidence levels. The action integrates with Anthropic for AI-powered analysis, enhancing its functionality and accuracy in detecting scope changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Sawaiz-zip/spec-guard">https://github.com/Sawaiz-zip/spec-guard</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/specguard-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SpecGuard is a GitHub Action that enforces semantic governance by checking the scope and content of spec files against locked goals and scopes, preventing potential direction shifts without proper approvals. It uses AI to analyze changes and provides warnings or blocks based on confidence levels. The action integrates with Anthropic for AI-powered analysis, enhancing its functionality and accuracy in detecting scope changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="specguard-v041">SpecGuard v0.4.1</h2>
<p>Semantic governance gate for spec files — classifies PR changes against a locked project goal/scope and blocks unauthorized drift.</p>
<h3 id="what-changed-since-v040">What changed since v0.4.0</h3>
<ul>
<li>Self-documenting <code>init</code> templates: richly-commented <code>roles.yml</code>/<code>config.yml</code>, a scaffolded <code>regions.yml</code>, and a <code>lock.json</code> that no longer carries unexplained null metadata (<code>specs/008-config-templates/</code>)</li>
<li>Package version metadata (<code>pyproject.toml</code>, <code>__init__.py</code>) bumped to <code>0.4.1</code></li>
</ul>
<h3 id="using-this-release">Using this release</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Sawaiz-zip/spec-guard@v0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic-api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><p><strong>Note:</strong> <code>specguard-ci</code> on PyPI and the composite action (<code>action.yml</code>) are still pinned to <code>0.4.0</code> — publishing <code>0.4.1</code> to PyPI is a separate, pending step. The <code>v0</code> moving tag and <code>action.yml</code>&rsquo;s pin will be updated together once <code>0.4.1</code> is live on PyPI, so the running Action never breaks.</p>
<h3 id="full-history">Full history</h3>
<p>001 CI gate → 002 local tools → 003 provider-agnostic classifier → 004 framework adapters → 005 approval commands → 006 GitHub App → 007 advanced governance → 008 config templates. See <code>specs/</code> for individual feature specs.</p>
]]></content:encoded></item><item><title>wary-sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/wary-sh/</link><pubDate>Tue, 04 Aug 2026 07:16:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/wary-sh/</guid><description>Version updated for https://github.com/sawyermd511-bit/wary to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Wary action checks if a package name is real and not a typosquat, helping developers avoid installing potentially malicious packages by focusing on legitimate names. It automates the verification process of package names before installation, providing a tool to scan projects and detect new dependencies that could be impersonations or hallucinations from AI assistants.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sawyermd511-bit/wary">https://github.com/sawyermd511-bit/wary</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wary-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Wary action checks if a package name is real and not a typosquat, helping developers avoid installing potentially malicious packages by focusing on legitimate names. It automates the verification process of package names before installation, providing a tool to scan projects and detect new dependencies that could be impersonations or hallucinations from AI assistants.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of wary — verifies packages are real and not typosquats before you install them.</p>
]]></content:encoded></item><item><title>Docker Compose Cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/docker-compose-cache/</link><pubDate>Tue, 04 Aug 2026 07:15:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/docker-compose-cache/</guid><description>Version updated for https://github.com/seijikohara/docker-compose-cache-action to version v1.8.20.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the caching of Docker images used in Docker Compose files to speed up CI/CD workflows. It parses and caches each image as a separate tarball, verifies freshness using digests, and selectively pulls images based on cache status and digest verification. This reduces build times by avoiding unnecessary downloads and ensures consistent image versions across builds.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seijikohara/docker-compose-cache-action">https://github.com/seijikohara/docker-compose-cache-action</a></strong> to version <strong>v1.8.20</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-compose-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the caching of Docker images used in Docker Compose files to speed up CI/CD workflows. It parses and caches each image as a separate tarball, verifies freshness using digests, and selectively pulls images based on cache status and digest verification. This reduces build times by avoiding unnecessary downloads and ensures consistent image versions across builds.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update actions/setup-node action to v7 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/316">https://github.com/seijikohara/docker-compose-cache-action/pull/316</a></li>
<li>chore(deps): update dependency oxlint-tsgolint to v7 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/317">https://github.com/seijikohara/docker-compose-cache-action/pull/317</a></li>
<li>fix(ci): resolve the pnpm version from packageManager only by @seijikohara in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/320">https://github.com/seijikohara/docker-compose-cache-action/pull/320</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/322">https://github.com/seijikohara/docker-compose-cache-action/pull/322</a></li>
<li>chore(deps): update dependency oxfmt to ^0.61.0 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/321">https://github.com/seijikohara/docker-compose-cache-action/pull/321</a></li>
<li>chore(deps): update pnpm to v11.18.0 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/323">https://github.com/seijikohara/docker-compose-cache-action/pull/323</a></li>
<li>fix(renovate): ignore the dist-commit bot author by @seijikohara in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/325">https://github.com/seijikohara/docker-compose-cache-action/pull/325</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/324">https://github.com/seijikohara/docker-compose-cache-action/pull/324</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.19...v1.8.20">https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.19...v1.8.20</a></p>
]]></content:encoded></item><item><title>Profile Cards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/profile-cards/</link><pubDate>Tue, 04 Aug 2026 07:14:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/profile-cards/</guid><description>Version updated for https://github.com/seijikohara/profile-cards-action to version v0.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Profile Cards Action is a GitHub Action that generates SVG profile README cards from the GitHub GraphQL API. It automates the process of creating detailed and visually appealing profile cards, including overview, contribution history, streaks, composition, activity rhythm, and language treemap. The action produces self-hosted SVG files and can commit them back to the repository, making the cards theme-aware and reproducible.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seijikohara/profile-cards-action">https://github.com/seijikohara/profile-cards-action</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/profile-cards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Profile Cards Action is a GitHub Action that generates SVG profile README cards from the GitHub GraphQL API. It automates the process of creating detailed and visually appealing profile cards, including overview, contribution history, streaks, composition, activity rhythm, and language treemap. The action produces self-hosted SVG files and can commit them back to the repository, making the cards theme-aware and reproducible.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>build: trust the committed lockfile during install by @seijikohara in <a href="https://github.com/seijikohara/profile-cards-action/pull/5">https://github.com/seijikohara/profile-cards-action/pull/5</a></li>
<li>chore(deps): pin dependencies by @renovate[bot] in <a href="https://github.com/seijikohara/profile-cards-action/pull/7">https://github.com/seijikohara/profile-cards-action/pull/7</a></li>
<li>chore(deps): update dependency oxfmt to ^0.61.0 by @renovate[bot] in <a href="https://github.com/seijikohara/profile-cards-action/pull/8">https://github.com/seijikohara/profile-cards-action/pull/8</a></li>
<li>chore(deps): update pnpm to v11.18.0 by @renovate[bot] in <a href="https://github.com/seijikohara/profile-cards-action/pull/9">https://github.com/seijikohara/profile-cards-action/pull/9</a></li>
<li>fix(renovate): ignore the dist-commit bot author by @seijikohara in <a href="https://github.com/seijikohara/profile-cards-action/pull/12">https://github.com/seijikohara/profile-cards-action/pull/12</a></li>
<li>chore(deps): update actions/setup-node action to v7 by @renovate[bot] in <a href="https://github.com/seijikohara/profile-cards-action/pull/10">https://github.com/seijikohara/profile-cards-action/pull/10</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/seijikohara/profile-cards-action/pull/11">https://github.com/seijikohara/profile-cards-action/pull/11</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@renovate[bot] made their first contribution in <a href="https://github.com/seijikohara/profile-cards-action/pull/7">https://github.com/seijikohara/profile-cards-action/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/seijikohara/profile-cards-action/compare/v0.0.3...v0.0.4">https://github.com/seijikohara/profile-cards-action/compare/v0.0.3...v0.0.4</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/custom-amazon-bedrock-agent-action/</link><pubDate>Tue, 04 Aug 2026 07:13:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide feedback. It is customizable to meet specific requirements and can integrate with Amazon Bedrock Knowledge Bases for enriched, context-aware insights. The action supports various programming languages and integrates seamlessly into the PR process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses Amazon Bedrock Agent to analyze files in a pull request and provide feedback. It is customizable to meet specific requirements and can integrate with Amazon Bedrock Knowledge Bases for enriched, context-aware insights. The action supports various programming languages and integrates seamlessly into the PR process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Read or Modify JSON</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/read-or-modify-json/</link><pubDate>Tue, 04 Aug 2026 07:13:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/read-or-modify-json/</guid><description>Version updated for https://github.com/SocksTheWolf/github-action-json to version v1.5.0.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action provides a way to edit or read JSON files, including package.json. It allows users to replace or remove specific keys within the JSON file and supports recursive merging of nested objects. The action is useful for automating tasks that require updating configuration files in a repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SocksTheWolf/github-action-json">https://github.com/SocksTheWolf/github-action-json</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/read-or-modify-json">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action provides a way to edit or read JSON files, including <code>package.json</code>. It allows users to replace or remove specific keys within the JSON file and supports recursive merging of nested objects. The action is useful for automating tasks that require updating configuration files in a repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Moves entire action to typescript</li>
<li>Changes build method to more up to date (uses rollup)</li>
<li>Allows for new input <code>removeKey</code></li>
<li>Don&rsquo;t write the json file if there&rsquo;s no changes to the file made</li>
<li>Update readme</li>
<li>Update dependencies</li>
<li>Change to NPM over yarn</li>
<li>Add dryRun input</li>
</ul>
]]></content:encoded></item><item><title>Go Git Commit Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/go-git-commit-action/</link><pubDate>Tue, 04 Aug 2026 07:12:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/go-git-commit-action/</guid><description>Version updated for https://github.com/somaz94/go-git-commit-action to version v1.8.1.
This action is used across all versions by 18 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Go Git Commit Action automates git commit, push, tag, and pull request operations, written in Go for better performance and reliability. It solves common automation needs by providing a simple interface to manage commits, tags, and PRs from GitHub Actions workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/go-git-commit-action">https://github.com/somaz94/go-git-commit-action</a></strong> to version <strong>v1.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-git-commit-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Go Git Commit Action automates git commit, push, tag, and pull request operations, written in Go for better performance and reliability. It solves common automation needs by providing a simple interface to manage commits, tags, and PRs from GitHub Actions workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>detect a missing remote branch from the ls-remote listing, not its exit code by @somaz94</li>
<li>fail the action when a label, reviewer, assignee or close call is rejected by @somaz94</li>
</ul>
<h3 id="refactoring">Refactoring</h3>
<ul>
<li>route git execution through a Runner seam to make the git package testable by @somaz94</li>
</ul>
<h3 id="testing">Testing</h3>
<ul>
<li>add an injectable API base URL so the PR paths run against httptest by @somaz94</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/go-git-commit-action/compare/v1.8.0...v1.8.1">https://github.com/somaz94/go-git-commit-action/compare/v1.8.0...v1.8.1</a></p>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/update-a-config-file-with-values-from-environment/</link><pubDate>Tue, 04 Aug 2026 07:11:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces environment variables in a specified configuration file with their actual values from your GitHub Actions workflow. It automates the process of substituting environment variables into configuration files, making it easier to manage sensitive information securely within workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces environment variables in a specified configuration file with their actual values from your GitHub Actions workflow. It automates the process of substituting environment variables into configuration files, making it easier to manage sensitive information securely within workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add support for .env files (e706be3)</li>
<li>chore: More info (d440258)</li>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/classroom-to-sheets-integration/</link><pubDate>Tue, 04 Aug 2026 07:11:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates GitHub Classroom with Google Sheets to automatically update assignment results. It automates the process of sending task grades directly to a specified Google Sheet, making it easy to track and view performance data in one centralized location. The action requires API credentials for Google Sheets and is designed to work with specific secrets in your organization’s GitHub settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates GitHub Classroom with Google Sheets to automatically update assignment results. It automates the process of sending task grades directly to a specified Google Sheet, making it easy to track and view performance data in one centralized location. The action requires API credentials for Google Sheets and is designed to work with specific secrets in your organization&rsquo;s GitHub settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>xilo-nix-cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/xilo-nix-cache/</link><pubDate>Tue, 04 Aug 2026 07:10:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/xilo-nix-cache/</guid><description>Version updated for https://github.com/stubbedev/xilo to version v1.0.12.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The xilo action is a self-hosted Nix binary cache that uses pure-Go SQLite to store and serve binaries efficiently. It features:
Never stalls on concurrent pushes due to a single writer goroutine. Multi-tenant support with personal accounts, organizations, and optional self-registration offers. A cachix-style admin dashboard for managing caches, tokens, users, and accounts. Instant token revocation and content-addressed chunked deduplication (FastCDC). Support for storing chunks on local disk or any S3-compatible bucket. Scalability through PostgreSQL as a backend storage system. What’s Changed Full Changelog: https://github.com/stubbedev/xilo/compare/v1...v1.0.12</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stubbedev/xilo">https://github.com/stubbedev/xilo</a></strong> to version <strong>v1.0.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xilo-nix-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The xilo action is a self-hosted Nix binary cache that uses pure-Go SQLite to store and serve binaries efficiently. It features:</p>
<ul>
<li>Never stalls on concurrent pushes due to a single writer goroutine.</li>
<li>Multi-tenant support with personal accounts, organizations, and optional self-registration offers.</li>
<li>A cachix-style admin dashboard for managing caches, tokens, users, and accounts.</li>
<li>Instant token revocation and content-addressed chunked deduplication (FastCDC).</li>
<li>Support for storing chunks on local disk or any S3-compatible bucket.</li>
<li>Scalability through PostgreSQL as a backend storage system.</li>
</ul>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/stubbedev/xilo/compare/v1...v1.0.12">https://github.com/stubbedev/xilo/compare/v1...v1.0.12</a></p>
]]></content:encoded></item><item><title>Sigbound</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/sigbound/</link><pubDate>Tue, 04 Aug 2026 07:09:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/sigbound/</guid><description>Version updated for https://github.com/surya-koritala/sigbound to version v2.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sigbound is a GitHub Action that automates the process of merging code from multiple AI coding agents in parallel by handling conflicts automatically using a model. It combines non-conflicting changes efficiently, resolves overlaps with a model, verifies every merge on build and test commands, and ensures only verified merges land. The action supports custom models for planning, agent execution, conflict resolution, and repair, running on top of plain git and working across any host without replacing existing tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/surya-koritala/sigbound">https://github.com/surya-koritala/sigbound</a></strong> to version <strong>v2.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sigbound">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sigbound is a GitHub Action that automates the process of merging code from multiple AI coding agents in parallel by handling conflicts automatically using a model. It combines non-conflicting changes efficiently, resolves overlaps with a model, verifies every merge on build and test commands, and ensures only verified merges land. The action supports custom models for planning, agent execution, conflict resolution, and repair, running on top of plain git and working across any host without replacing existing tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/wails3-build-action/</link><pubDate>Tue, 04 Aug 2026 07:07:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building of Wails.io projects using GoLang and NodeJS. It installs necessary dependencies, builds the project for specified platforms and architectures, and optionally uploads the results to GitHub or a release on tag. The action supports various configurations for build settings, node.js, pnpm, and Deno, making it versatile for different Wails projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building of Wails.io projects using GoLang and NodeJS. It installs necessary dependencies, builds the project for specified platforms and architectures, and optionally uploads the results to GitHub or a release on tag. The action supports various configurations for build settings, node.js, pnpm, and Deno, making it versatile for different Wails projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>Vale Linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/vale-linter/</link><pubDate>Tue, 04 Aug 2026 07:07:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/vale-linter/</guid><description>Version updated for https://github.com/vale-cli/vale-action to version v3.0.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 4,052 repositories.
Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of running Vale, a tool for static code analysis, in pull requests. It solves problems related to managing and executing Vale across various repositories by providing an official action that simplifies installation, management, and execution with ease. The key capabilities include:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vale-cli/vale-action">https://github.com/vale-cli/vale-action</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>4,052</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vale-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of running Vale, a tool for static code analysis, in pull requests. It solves problems related to managing and executing Vale across various repositories by providing an official action that simplifies installation, management, and execution with ease. The key capabilities include:</p>
<ul>
<li>Running Vale on Linux, macOS, and Windows</li>
<li>Handling different markup formats by installing external parsers</li>
<li>Offering suggested changes for resolved alerts</li>
<li>Using specific reporters like <code>github-pr-review</code> to post comments in pull requests</li>
<li>Caching style paths to speed up subsequent runs</li>
</ul>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="breaking">Breaking</h2>
<p>Nothing was renamed or removed, but several behaviors changed. Each has a way back.</p>
<ul>
<li><strong>reviewdog 0.17.0 → 0.21.0.</strong> Workflows triggered on <code>push</code> using a <code>github-pr-*</code> reporter previously reported nothing (<code>this is not PullRequest build</code>, exit 0). They now lint, and can fail. Pin <code>reviewdog_version: 0.17.0</code> to keep the old behavior.</li>
<li><strong>The <code>level</code> input is honored.</strong> It was read from <code>action.yml</code> and never used. Checks that concluded <em>neutral</em> can now conclude <em>failure</em>. Leave <code>level</code> unset for the previous behavior.</li>
<li><strong><code>fail_on_error: true</code> fails on errors only.</strong> It previously failed on a finding of any severity for every reporter except the check ones, so a lone suggestion ended the run. Use <code>fail_level: any</code> to restore that.</li>
<li><strong>GitHub&rsquo;s 10-annotation limit no longer fails the job</strong> when <code>fail_on_error: false</code>. You get a warning naming how many alerts went unshown.</li>
<li><strong>Pinning <code>@reviewdog</code></strong> tracks the branch, which is now v3. Pin <code>@v3</code>, or <code>@v2</code> to stay put.</li>
</ul>
<h2 id="added">Added</h2>
<ul>
<li><strong>Suggested fixes.</strong> Alerts that Vale knows how to resolve are posted as suggested changes you can commit from the pull request — the same replacements the language server offers. Requires <code>reporter: github-pr-review</code>.</li>
<li><strong>macOS, Windows, and ARM runners.</strong> The action previously only ran on Linux x86-64.</li>
<li><strong>New inputs:</strong> <code>config</code>, <code>filter</code>, <code>glob</code>, <code>min_alert_level</code>, <code>fail_level</code>, <code>sync</code>, <code>reviewdog_version</code>. <code>workdir</code> is now declared and documented.</li>
<li><strong>Caching.</strong> Binaries go in the runner&rsquo;s tool cache, and <code>sync: false</code> lets you restore a cached <code>StylesPath</code> instead of re-downloading every package each run.</li>
<li><strong>Downloads are verified</strong> against each release&rsquo;s published checksums.</li>
</ul>
<h2 id="fixed">Fixed</h2>
<ul>
<li>Crash on large output — <code>write EPIPE</code> when reviewdog exited before reading it all (#122)</li>
<li>An empty <code>files</code> list failing with <code>lstat : no such file or directory</code> (#141)</li>
<li>Pull requests whose diff exceeds 20,000 lines (#153)</li>
<li>The annotation limit failing runs regardless of <code>fail_on_error</code> (#89, #150)</li>
<li>A warning failing the workflow under <code>fail_on_error: true</code> (#84)</li>
<li>Nothing reported on <code>push</code> events (#103)</li>
<li>The <code>level</code> input being ignored (#106)</li>
<li>Wildcards in <code>files</code> — use the <code>glob</code> input; the warning now says so (#123)</li>
<li>Scheduled runs on runners that write a thin event payload (#69)</li>
<li><code>vale_flags</code> splitting on whitespace, which broke <code>--filter='.Level == &quot;error&quot;'</code></li>
<li>Vale&rsquo;s own error is reported when it exits with a runtime error, instead of an exit code</li>
</ul>
<h2 id="internal">Internal</h2>
<p>The action now ships as a single bundled <code>dist/index.js</code>; <code>node_modules</code> is no longer committed, taking the repository from 1,035 tracked files to 23. CI fails if the bundle is out of date with the source.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vale-cli/vale-action/compare/2.1.2...v3.0.0">https://github.com/vale-cli/vale-action/compare/2.1.2...v3.0.0</a></p>
]]></content:encoded></item><item><title>Legion Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/legion-runner/</link><pubDate>Tue, 04 Aug 2026 07:05:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/legion-runner/</guid><description>Version updated for https://github.com/Wraith-security/Legion_runner to version v1.0.55.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Legion Runner is an open-source action designed to protect GitHub Actions jobs against supply chain attacks by monitoring and blocking outbound connections based on predefined allowlists. It records process names, fingerprints credentials and configuration files, and runs without dependencies or sending data to external services. The Action can be integrated as the first step of a job and provides modes for logging and blocking outbound traffic.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Wraith-security/Legion_runner">https://github.com/Wraith-security/Legion_runner</a></strong> to version <strong>v1.0.55</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/legion-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Legion Runner is an open-source action designed to protect GitHub Actions jobs against supply chain attacks by monitoring and blocking outbound connections based on predefined allowlists. It records process names, fingerprints credentials and configuration files, and runs without dependencies or sending data to external services. The Action can be integrated as the first step of a job and provides modes for logging and blocking outbound traffic.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Curated egress presets (<code>allowed-presets</code>)</strong>: opt-in per-ecosystem allowlists
(npm, yarn, pnpm, pip, pypi, cargo, rust, go, maven, gradle, nuget, apt, debian,
docker) so block mode &ldquo;just works&rdquo; for common toolchains without hand-listing
endpoints. e.g. <code>allowed-presets: &quot;cargo, apt&quot;</code>. Unit-tested.</li>
<li><strong>Download integrity verification</strong>: the action verifies the <code>legionr-bpf</code> /
<code>legionr-fim</code> release binaries against a <code>.sha256</code> sidecar before running them
(the release now attaches the checksums), and <strong>fails closed</strong> — an
unverified/corrupted/tampered download is rejected and the action degrades
instead of executing it.</li>
<li><strong><code>learned-baseline</code> input</strong> (default <code>true</code>): in block mode, also allow
destinations previously learned into the Actions cache. Set <code>false</code> to enforce
ONLY the explicit allowlist (inline + policy-file + GitHub) with no cache
read/write — used by the enforce self-test for deterministic deny.</li>
<li><strong>File-integrity / tamper detection (Rust <code>legionr-fim</code> agent)</strong>: snapshots
high-value tamper targets at job start (credential/config files, <code>.git</code>
config + hooks, and checked-out source) and diffs them at job end, surfacing
anything overwritten, deleted, or chmod&rsquo;d in the summary. Only sha256 hashes
are stored — never contents. New inputs <code>file-integrity</code> (auto|off) and
<code>fim-extra-paths</code>. <code>file-integrity: auto</code> downloads the agent from the latest
release (plain stable Rust, no eBPF toolchain) and degrades to a silent skip
if unavailable. Logic lives in <code>legionr-core::fim</code> (unit-tested); the binary
is a release asset like <code>legionr-bpf</code>, built + attached by <code>release.yml</code>.</li>
<li><strong>Package repositories roll-up (<code>📦</code>)</strong>: the summary now classifies named
outbound destinations into their ecosystem/registry (npm, PyPI, crates.io,
apt, Docker, Go, NuGet, Maven, Gradle, RubyGems, Alpine, GitHub) and shows a
<strong>Package repositories reached</strong> table — registry, ecosystem, connections, and
the process that reached each. Supply-chain risk hides in <em>which</em> registries a
build talks to, so we surface them directly instead of leaving you to read
IPs. Bare IPs that never got a forward name get a coarse CDN/provider hint
(Fastly/Cloudflare/GitHub) via CIDR match — honest about ambiguity (a shared
CDN can&rsquo;t name a registry). Logic in <code>action/repos.js</code>, fully unit-tested.</li>
<li><strong>Combined cross-job egress report (one summary for the whole run)</strong>: GitHub
has no run-level summary, so each job emits its captured egress as a JSON
artifact (<code>node action/report.js emit</code>) and a final <code>egress-report</code> job merges
them into a SINGLE table — which job + process reached what — with a package
repositories roll-up and a per-job diagnostics block (<code>render</code>). Wired into CI;
<code>render</code> is pure and unit-tested. Pairs with <code>job-summary: false</code> so the run
shows one combined summary instead of one table per job.</li>
<li><strong><code>job-summary</code> input</strong> (default <code>true</code>): set <code>false</code> to keep monitoring and
enforcement fully active but suppress the connections table in the job summary.
Useful when many jobs in one workflow each run the action and you only want the
table once (our own CI uses it so a run shows one table, not one per job).</li>
<li><strong>Secure diagnostics line</strong> in the summary: reports which resolution path
actually fired (<code>forwarder on/off · captured DNS records N · getaddrinfo route … · named X/Y destinations</code>) so a run that comes back as bare IPs is triagable.
Secure by construction — only booleans, counts, and a fixed enum; never the
upstream resolver IP, file paths, captured hostnames, or env values.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>The live e2e tier is out of CI.</strong> <code>.github/workflows/e2e.yml</code> now runs only
the credential-free <code>local</code> job. The removed <code>live</code> job registered a runner
against a fixed external scope that this org cannot install the App on, so it
could only skip silently or fail noisily, and neither outcome said anything
about the runner. <code>scripts/e2e.sh --mode live</code> still works and can be pointed
at any scope you control, but the scope is now mandatory (<code>--scope owner/repo</code>
or <code>E2E_SCOPE</code>) instead of defaulting to a hardcoded constant: the harness
will not guess a target it registers a real runner against. The <code>local</code> tier
falls back to <code>$GITHUB_REPOSITORY</code> since it provisions with <code>--no-probe</code> and
never reaches GitHub.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>FIM hashing builds against <code>sha2</code> 0.11.</strong> The digest type changed to
<code>hybrid_array::Array</code>, which does not implement <code>LowerHex</code>, so
<code>format!(&quot;{:x}&quot;, ..)</code> in <code>fim::hash_file</code> stopped compiling. The digest is now
hex-encoded byte by byte, which works on both 0.10 and 0.11. Two tests pin the
behaviour: the exact sha256 of <code>abc</code>, and a 64-char length/charset assertion so
a dropped leading zero cannot pass silently. Unblocks the <code>cargo-major</code>
dependency group (<code>sha2</code> 0.10.9 to 0.11.0, <code>thiserror</code> 1 to 2.0.18).</li>
<li><strong>Block mode no longer hangs the runner at teardown.</strong> <code>applyEgressBlock</code>
installed a default-deny <code>LEGION_EGRESS</code> chain in <code>OUTPUT</code> and nothing ever
removed it, so the runner&rsquo;s own completion call (to rotating GitHub-backend IPs
not in the static seed) was dropped and the job spun until timeout. <code>post()</code>
now tears the firewall down (<code>removeEgressBlock</code>).</li>
<li><strong>Runner hang from leaked daemons.</strong> The post step left privileged background
processes alive — eBPF agent, DNS forwarder — and the <code>/proc</code> monitor could
wedge in a blocking <code>ss</code> subprocess. The monitor now reads <code>/proc/net/tcp</code>
directly (no subprocess); daemons are reliably reaped.</li>
<li><strong>No more spurious &ldquo;could not resolve&rdquo; annotations.</strong> Allowlist entries that
are wildcard parents with no A record of their own (e.g. <code>blob.core.windows.net</code>,
<code>actions.githubusercontent.com</code>) used to emit one CI <strong>warning annotation</strong>
each on every run. They are benign: the action skips them, and their subdomains
are still observed via PTR / DNS capture (and opened just-in-time in block
mode). They are now collected into a single plain-text log line instead.</li>
<li><strong>Docs/labels</strong>: the eBPF mechanism is a <strong>tracepoint on <code>sys_enter_connect</code></strong>
(not a &ldquo;kprobe on tcp_connect&rdquo;); the sampler is <code>/proc</code>-only (the &ldquo;ss&rdquo; fallback
was removed). Corrected the runtime log line, summary label, and README.</li>
<li><strong>Outbound connections showed as bare IPs when systemd-resolved owns
<code>getaddrinfo</code>.</strong> The <code>nsswitch</code> reroute didn&rsquo;t always stick, so package-repo
lookups bypassed the capture forwarder and were never named. The forwarder now
targets the <em>real</em> upstream (systemd-resolved&rsquo;s actual servers, not the
<code>127.0.0.53</code> stub), and when the bypass is detected but the nsswitch reroute
fails, Legion redirects systemd-resolved itself at the forwarder via a
<code>resolved.conf.d</code> drop-in — <strong>verify-or-revert</strong> and restored on teardown, so
it never breaks the job&rsquo;s DNS.</li>
<li><strong>IPv4-mapped IPv6 destinations rendered as long expanded addresses</strong>
(<code>0000:0000:0000:0000:0000:ffff:HHHH:HHHH</code>) in the summary. The <code>/proc</code> sampler
emitted the expanded form while <code>normalizeIp</code> only collapsed the compressed
<code>::ffff:</code> form. Both now collapse to dotted IPv4 (and the v4/v6 tables dedupe).
(Shipped in v1.0.35.)</li>
<li>Removed dead <code>action/baseline.js</code>; pinned <code>release.yml</code> checkout to v6.</li>
</ul>
<h3 id="reliability">Reliability</h3>
<ul>
<li><strong>Tests for the paths that kept breaking</strong>: the firewall rule builders
(<code>egressBlockRules</code>/<code>egressUnblockRules</code> — order, DNS-allow, DROP-last,
OUTPUT-jump-removed-first), the checksum parser, the curated presets, and a
<strong>full-stack PR gate</strong> that runs block + DNS-capture + eBPF and asserts the
job finalizes (catches any teardown-hang regression), plus the package-repo
classifier (host-suffix + CIDR matching). Action test count 19 → 37.</li>
</ul>
<h3 id="changed-1">Changed</h3>
<ul>
<li>Removed em-dashes from the job-summary output (headers, the unresolved-host
note, the enforce hint, and empty-cell placeholders) for plainer rendering.</li>
<li><strong>Name more destinations</strong>: route glibc <code>getaddrinfo</code> (curl/apt/cargo/git)
through the DNS-capture forwarder via an <code>nsswitch.conf</code> reroute, so hosts
resolved by systemd-resolved (which ignores <code>resolv.conf</code>) are now captured
and named — not just <code>resolv.conf</code>/c-ares callers. Health-checked and restored
on teardown. (A connection to a hard-coded IP with no PTR still shows the IP —
there is no name to resolve.)</li>
<li>More accurate &ldquo;unresolved destination&rdquo; note in the summary (a name may have
been resolved outside the capture path, vs. a genuine raw-IP connection).</li>
<li><strong>We dogfood our own action.</strong> Every real-work job in this repo (CI, release,
eBPF agent, FIM self-test) now runs Legion Runner as its first step (<code>@v1</code>,
audit) — our CI is hardened by the product it ships.</li>
<li><strong>Docs-only PRs skip the build/test matrix</strong> (and the release it gates) via
<code>paths-ignore</code>; a <code>docs-passthrough</code> workflow reports the same check names
green so required checks stay satisfied and README edits stay mergeable
without burning CI minutes.</li>
<li><strong>Our CI now captures names.</strong> The dogfooded harden steps run with
<code>dns-capture: true</code> (still <code>audit</code> — monitor, don&rsquo;t firewall), so job summaries
show real destination and package-repository names instead of bare IPs, and the
capture path is exercised on every run. Safe now that <code>@v1</code> (&gt;= 1.0.35) carries
the teardown + systemd-resolved fixes.</li>
</ul>
]]></content:encoded></item><item><title>Vibe-Guard-AICoding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/vibe-guard-aicoding/</link><pubDate>Tue, 04 Aug 2026 07:04:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/04/vibe-guard-aicoding/</guid><description>Version updated for https://github.com/YUTAKONDO1205/VibeGuard to version v0.3.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary VibeGuard is a security scanner designed to detect bugs in AI-generated code that can go unnoticed during development. It provides inline diagnostics while writing code in VS Code, real-time scanning of web pages using the Chrome extension, and automated analysis before merging pull requests via CLI and GitHub Action. The tool ensures consistency across different tools and environments by running the same analysis engine.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YUTAKONDO1205/VibeGuard">https://github.com/YUTAKONDO1205/VibeGuard</a></strong> to version <strong>v0.3.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibe-guard-aicoding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>VibeGuard is a security scanner designed to detect bugs in AI-generated code that can go unnoticed during development. It provides inline diagnostics while writing code in VS Code, real-time scanning of web pages using the Chrome extension, and automated analysis before merging pull requests via CLI and GitHub Action. The tool ensures consistency across different tools and environments by running the same analysis engine.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/YUTAKONDO1205/VibeGuard/compare/v0...v0.3.4">https://github.com/YUTAKONDO1205/VibeGuard/compare/v0...v0.3.4</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/go-proxy-cache-updater/</link><pubDate>Mon, 03 Aug 2026 22:57:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.37.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically updates a specified Go proxy cache when new tags are created that match semantic version patterns. It supports both standard and submodule version tags and allows custom configuration of the proxy, import path, and Go version. The action automates the process of pulling the latest module versions to ensure quick availability on platforms like pkg.go.dev.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.37</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically updates a specified Go proxy cache when new tags are created that match semantic version patterns. It supports both standard and submodule version tags and allows custom configuration of the proxy, import path, and Go version. The action automates the process of pulling the latest module versions to ensure quick availability on platforms like pkg.go.dev.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1137-2026-08-03"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.36...v1.1.37">1.1.37</a> (2026-08-03)</h2>
]]></content:encoded></item><item><title>Build Component</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/build-component/</link><pubDate>Mon, 03 Aug 2026 22:55:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/build-component/</guid><description>Version updated for https://github.com/nuonco/actions-build to version v1.5.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of a new build for a Nuon component using the Nuon CLI. It simplifies the process of building components by abstracting away the need to manually execute the CLI commands, especially useful for CI/CD pipelines. The action supports OIDC authentication for token retrieval and provides an option to fall back on storing a secret API token if OIDC is not available.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nuonco/actions-build">https://github.com/nuonco/actions-build</a></strong> to version <strong>v1.5.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-component">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of a new build for a Nuon component using the Nuon CLI. It simplifies the process of building components by abstracting away the need to manually execute the CLI commands, especially useful for CI/CD pipelines. The action supports OIDC authentication for token retrieval and provides an option to fall back on storing a secret API token if OIDC is not available.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: repair GitHub Actions builds (#24) (780e941)</li>
<li>chore: add MIT license (#23) (e86244a)</li>
<li>chore: remove integration test (#22) (dad3832)</li>
<li>feat: improve action output (#21) (6b8b7be)</li>
<li>fix: properly set build id as output (#20) (2be440d)</li>
<li>feat: expose app_id field (#19) (b36932e)</li>
<li>feat: use reusable pr checks workflow (#15) (e233878)</li>
<li>refactor: put integration tests in their own workflow (#14) (369ad75)</li>
<li>fix: reusable tagging workflow was merged (#13) (e2e3d99)</li>
<li>refactor: clean up unused workflow (#12) (641161a)</li>
</ul>
]]></content:encoded></item><item><title>Nuon CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/nuon-cli/</link><pubDate>Mon, 03 Aug 2026 22:55:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/nuon-cli/</guid><description>Version updated for https://github.com/nuonco/actions-nuon to version v0.4.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the integration of Nuon CLI into CI/CD workflows. It provides options for both OIDC federation and API token authentication, allowing users to manage Nuon infrastructure directly within their GitHub Actions processes. The action supports executing various Nuon commands and outputs detailed information about Nuon operations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nuonco/actions-nuon">https://github.com/nuonco/actions-nuon</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nuon-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the integration of Nuon CLI into CI/CD workflows. It provides options for both OIDC federation and API token authentication, allowing users to manage Nuon infrastructure directly within their GitHub Actions processes. The action supports executing various Nuon commands and outputs detailed information about Nuon operations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: support using oidc with the cli (#11) (500be20)</li>
<li>feat: use &ndash;no-input flag (#8) (b144959)</li>
<li>feat: Make input <code>command</code> optional, allowing for setup use cases (#7) (1c320c6)</li>
<li>fix: The NUON_VERSION env var was not being picked up by install script (#6) (866d9e5)</li>
<li>feat: Set <code>NUON_CONFIG_FILE</code> variable for subsequent steps (#4) (352448d)</li>
<li>fix: Use the correct value for <code>NUON_VERSION</code> while installing (#5) (0d28fb9)</li>
<li>chore: rename for publication (#3) (3cc58a1)</li>
<li>chore: noop changes: trigger version bump (#2) (2769fe0)</li>
<li>chore: github action (#1) (8a9ea15)</li>
<li>Initial commit (c3fe348)</li>
</ul>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/odin-scan-smart-contract-security/</link><pubDate>Mon, 03 Aug 2026 22:54:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Odin Scan is a GitHub Action that performs AI-powered smart contract security analysis for CosmWasm, Solana, and EVM projects. It automatically detects the target platform and integrates with GitHub Code Scanning to provide native security alerts. The action supports automatic platform detection, PR comments, inline annotations, comment-triggered scans, configurable thresholds, artifact upload, and SARIF file generation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Odin Scan is a GitHub Action that performs AI-powered smart contract security analysis for CosmWasm, Solana, and EVM projects. It automatically detects the target platform and integrates with GitHub Code Scanning to provide native security alerts. The action supports automatic platform detection, PR comments, inline annotations, comment-triggered scans, configurable thresholds, artifact upload, and SARIF file generation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add comment-triggered PR scans (ac72e5f)</li>
<li>docs: expand findings-visibility section with threat model and annotation rationale (0404708)</li>
<li>feat: add findings-visibility input for graduated public disclosure control (f18df59)</li>
<li>fix: show findings detail in PR comment with fallback to medium (c2e43c8)</li>
<li>fix: new comment per run, show only critical/high findings, rebuild dist (e237b62)</li>
<li>feat: use GitHub App installation token for branded PR comments (3abce4e)</li>
<li>feat: enrich PR comment with emojis, descriptions, and fix report URL (27cc2f2)</li>
<li>fix: gzip SARIF before base64 encoding for Code Scanning upload (d9eed9f)</li>
<li>fix: include sourcemap-register.js in dist (bd265af)</li>
<li>docs: add privacy policy (b78db44)</li>
</ul>
]]></content:encoded></item><item><title>Get Latest Release Information</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/get-latest-release-information/</link><pubDate>Mon, 03 Aug 2026 22:52:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/get-latest-release-information/</guid><description>Version updated for https://github.com/ophiosdev/github-action-latest-release to version v0.2.0.
This action is used across all versions by 6 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action retrieves the latest release from another repository, supporting various filtering options like including drafts and prereleases. It provides outputs such as the release version tag, ID, description, and API URLs for assets, useful for automating builds or deployments based on the latest release data.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ophiosdev/github-action-latest-release">https://github.com/ophiosdev/github-action-latest-release</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/get-latest-release-information">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action retrieves the latest release from another repository, supporting various filtering options like including drafts and prereleases. It provides outputs such as the release version tag, ID, description, and API URLs for assets, useful for automating builds or deployments based on the latest release data.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: Configure Renovate by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/1">https://github.com/ophiosdev/github-action-latest-release/pull/1</a></li>
<li>chore(deps): update dependency eslint-plugin-prettier to v5.5.5 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/2">https://github.com/ophiosdev/github-action-latest-release/pull/2</a></li>
<li>chore(deps): update dependency typescript to v5.9.3 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/3">https://github.com/ophiosdev/github-action-latest-release/pull/3</a></li>
<li>chore(deps): update test-room-7/action-update-file action to v2.1.0 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/17">https://github.com/ophiosdev/github-action-latest-release/pull/17</a></li>
<li>chore(deps): update dependency eslint-plugin-prettier to v5.5.6 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/16">https://github.com/ophiosdev/github-action-latest-release/pull/16</a></li>
<li>chore(deps): update typescript-eslint monorepo to v8.65.0 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/12">https://github.com/ophiosdev/github-action-latest-release/pull/12</a></li>
<li>chore(deps): update python docker tag to v3.14 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/11">https://github.com/ophiosdev/github-action-latest-release/pull/11</a></li>
<li>chore(deps): update dependency prettier to v3.9.6 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/10">https://github.com/ophiosdev/github-action-latest-release/pull/10</a></li>
<li>chore(deps): update dependency eslint-plugin-jest to v29.16.0 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/9">https://github.com/ophiosdev/github-action-latest-release/pull/9</a></li>
<li>chore(deps): update dependency eslint to v9.39.5 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/8">https://github.com/ophiosdev/github-action-latest-release/pull/8</a></li>
<li>chore(deps): update dependency esbuild to v0.28.1 - autoclosed by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/7">https://github.com/ophiosdev/github-action-latest-release/pull/7</a></li>
<li>chore(deps): update dependency @types/node to v22.20.1 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/6">https://github.com/ophiosdev/github-action-latest-release/pull/6</a></li>
<li>chore(deps): update dependency @eslint/compat to v1.4.1 by @renovate[bot] in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/5">https://github.com/ophiosdev/github-action-latest-release/pull/5</a></li>
<li>feat: ✨add support to get latests version from tags if no releases available by @tmeckel in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/20">https://github.com/ophiosdev/github-action-latest-release/pull/20</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@renovate[bot] made their first contribution in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/1">https://github.com/ophiosdev/github-action-latest-release/pull/1</a></li>
<li>@tmeckel made their first contribution in <a href="https://github.com/ophiosdev/github-action-latest-release/pull/20">https://github.com/ophiosdev/github-action-latest-release/pull/20</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ophiosdev/github-action-latest-release/compare/v0.1.0...v0.2.0">https://github.com/ophiosdev/github-action-latest-release/compare/v0.1.0...v0.2.0</a></p>
]]></content:encoded></item><item><title>AI Model Lifecycle Monitor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/ai-model-lifecycle-monitor/</link><pubDate>Mon, 03 Aug 2026 22:51:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/ai-model-lifecycle-monitor/</guid><description>Version updated for https://github.com/oscarnilsson98/ai-model-end-of-life-action to version v3.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks AI models referenced by committed application and deployment code against the deprecations.info lifecycle feed to warn before known shutdowns. It reads evidence directly from Git commits, writes annotations, a job summary, stable outputs, and a complete JSON report.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action">https://github.com/oscarnilsson98/ai-model-end-of-life-action</a></strong> to version <strong>v3.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-model-lifecycle-monitor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks AI models referenced by committed application and deployment code against the <a href="https://deprecations.info">deprecations.info</a> lifecycle feed to warn before known shutdowns. It reads evidence directly from Git commits, writes annotations, a job summary, stable outputs, and a complete JSON report.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Automate GitHub action releases by @oscarnilsson98 in <a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action/pull/6">https://github.com/oscarnilsson98/ai-model-end-of-life-action/pull/6</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action/compare/v3.0.1...v3.0.2">https://github.com/oscarnilsson98/ai-model-end-of-life-action/compare/v3.0.1...v3.0.2</a></p>
]]></content:encoded></item><item><title>ADR 2.0 Agent Promotion</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/adr-2.0-agent-promotion/</link><pubDate>Mon, 03 Aug 2026 22:50:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/adr-2.0-agent-promotion/</guid><description>Version updated for https://github.com/p2achAI/adr-agent to version v2.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ADR 2.0 is a GitHub Action designed to automate the promotion of AI-generated AARs into formal ADR documents, enhancing architectural consistency in AI-assisted software development by providing automation, integration with AI agents, and machine-verifiable rules. The action handles AAR creation, ADR promotion, human review, continuous enforcement through validation rules, and benefits from a philosophy that accepts AI-driven design reasoning and captures decisions with minimal friction.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/p2achAI/adr-agent">https://github.com/p2achAI/adr-agent</a></strong> to version <strong>v2.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/adr-2-0-agent-promotion">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ADR 2.0 is a GitHub Action designed to automate the promotion of AI-generated AARs into formal ADR documents, enhancing architectural consistency in AI-assisted software development by providing automation, integration with AI agents, and machine-verifiable rules. The action handles AAR creation, ADR promotion, human review, continuous enforcement through validation rules, and benefits from a philosophy that accepts AI-driven design reasoning and captures decisions with minimal friction.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>ownership backfill에서 허용 taxonomy 기반 domain 분류를 함께 수행합니다.</p>
]]></content:encoded></item><item><title>vord Static Analysis</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/vord-static-analysis/</link><pubDate>Mon, 03 Aug 2026 22:49:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/vord-static-analysis/</guid><description>Version updated for https://github.com/pmaojo/vord to version v0.8.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is designed to perform static analysis on code written in 24 different programming languages. It uses a guardrail that checks the code before it’s written and by itself. The action is self-contained, with no external dependencies required beyond Rust and Docker (if used as a CI tool).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pmaojo/vord">https://github.com/pmaojo/vord</a></strong> to version <strong>v0.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vord-static-analysis">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is designed to perform static analysis on code written in 24 different programming languages. It uses a guardrail that checks the code before it&rsquo;s written and by itself. The action is self-contained, with no external dependencies required beyond Rust and Docker (if used as a CI tool).</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add three react ruleset rules from &ldquo;You Might Not Need an Effect&rdquo; by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/158">https://github.com/pmaojo/vord/pull/158</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.7.2...v0.8.0">https://github.com/pmaojo/vord/compare/v0.7.2...v0.8.0</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>Add three react ruleset rules from &ldquo;You Might Not Need an Effect&rdquo; by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/158">https://github.com/pmaojo/vord/pull/158</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.7.2...v0.8.0">https://github.com/pmaojo/vord/compare/v0.7.2...v0.8.0</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>Add three react ruleset rules from &ldquo;You Might Not Need an Effect&rdquo; by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/158">https://github.com/pmaojo/vord/pull/158</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.7.2...v0.8.0">https://github.com/pmaojo/vord/compare/v0.7.2...v0.8.0</a></p>
<h2 id="whats-changed-4">What&rsquo;s Changed</h2>
<ul>
<li>Add three react ruleset rules from &ldquo;You Might Not Need an Effect&rdquo; by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/158">https://github.com/pmaojo/vord/pull/158</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.7.2...v0.8.0">https://github.com/pmaojo/vord/compare/v0.7.2...v0.8.0</a></p>
<h2 id="whats-changed-5">What&rsquo;s Changed</h2>
<ul>
<li>Add three react ruleset rules from &ldquo;You Might Not Need an Effect&rdquo; by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/158">https://github.com/pmaojo/vord/pull/158</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.7.2...v0.8.0">https://github.com/pmaojo/vord/compare/v0.7.2...v0.8.0</a></p>
]]></content:encoded></item><item><title>Setup Flutter with pub cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/setup-flutter-with-pub-cache/</link><pubDate>Mon, 03 Aug 2026 22:48:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/setup-flutter-with-pub-cache/</guid><description>Version updated for https://github.com/Project516/setup-flutter to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Flutter and caches its pub cache, automating the process of installing Flutter, restoring the pub cache, and running flutter pub get. It simplifies CI/CD pipelines by reducing repetitive setup steps, especially when dealing with different versions or channels of Flutter.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Project516/setup-flutter">https://github.com/Project516/setup-flutter</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-flutter-with-pub-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up Flutter and caches its pub cache, automating the process of installing Flutter, restoring the pub cache, and running <code>flutter pub get</code>. It simplifies CI/CD pipelines by reducing repetitive setup steps, especially when dealing with different versions or channels of Flutter.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(cache): resolve pub cache path from PUB_CACHE for cross-OS runners by @cappy-dev in <a href="https://github.com/Project516/setup-flutter/pull/2">https://github.com/Project516/setup-flutter/pull/2</a></li>
<li>Configure Renovate by @renovate[bot] in <a href="https://github.com/Project516/setup-flutter/pull/1">https://github.com/Project516/setup-flutter/pull/1</a></li>
<li>ci: verify the composite action across runner OSes by @Project516 in <a href="https://github.com/Project516/setup-flutter/pull/4">https://github.com/Project516/setup-flutter/pull/4</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@cappy-dev made their first contribution in <a href="https://github.com/Project516/setup-flutter/pull/2">https://github.com/Project516/setup-flutter/pull/2</a></li>
<li>@renovate[bot] made their first contribution in <a href="https://github.com/Project516/setup-flutter/pull/1">https://github.com/Project516/setup-flutter/pull/1</a></li>
<li>@Project516 made their first contribution in <a href="https://github.com/Project516/setup-flutter/pull/4">https://github.com/Project516/setup-flutter/pull/4</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Project516/setup-flutter/compare/v1...v1.0.1">https://github.com/Project516/setup-flutter/compare/v1...v1.0.1</a></p>
]]></content:encoded></item><item><title>Garita PII Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/garita-pii-guard/</link><pubDate>Mon, 03 Aug 2026 22:48:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/garita-pii-guard/</guid><description>Version updated for https://github.com/proscar87/garita to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Garita is a GitHub Action that prevents sensitive personal and credential information from being pushed to your repository. It uses patterns to detect and block sensitive data such as names, CURPs, RFCs, CLABEs, NSS numbers, Mexican phone numbers, JWTs, and passwords. The main functionality is to maintain the principle that “the line is the lot, not the name,” ensuring that financial information can be versioned while personal data remains private.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/proscar87/garita">https://github.com/proscar87/garita</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/garita-pii-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Garita is a GitHub Action that prevents sensitive personal and credential information from being pushed to your repository. It uses patterns to detect and block sensitive data such as names, CURPs, RFCs, CLABEs, NSS numbers, Mexican phone numbers, JWTs, and passwords. The main functionality is to maintain the principle that &ldquo;the line is the lot, not the name,&rdquo; ensuring that financial information can be versioned while personal data remains private.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Garita revisa lo que git rastrea y bloquea el commit cuando encuentra un dato personal o una credencial. Sin dependencias.</p>
<h2 id="qué-trae">Qué trae</h2>
<p><strong>Siete países.</strong> Argentina, Brasil, Chile, Colombia, España, México y Perú — cada uno un módulo que el registro descubre solo. CURP, RFC, CLABE, NSS, CPF, CNPJ (incluido el alfanumérico de 2026), RUT, NIT, CUIT, DNI/NIE/CIF/IBAN, RUC. Todos validados por dígito verificador, no por forma.</p>
<p><strong>Validado contra proyectos reales.</strong> axios, Chart.js, express, faker, flask, hugo, prettier, requests, sinatra y vite: 19,920 archivos, <strong>cero errores</strong>. Es el número que importa — un guardián ruidoso se desinstala, y ese día deja pasar el dato de verdad.</p>
<p><strong>Lee la lista de nombres del propio proyecto.</strong> Si ya tienes un generador de datos sintéticos con los nombres que no deben salir, Garita los extrae por AST sin ejecutar el archivo. La lista no se duplica y no se desincroniza.</p>
<p><strong>Avisa de exenciones muertas.</strong> Una exención que no coincide con ningún archivo significa que algo se renombró y la protección se cayó sin decírtelo.</p>
<h2 id="cómo-se-usa">Cómo se usa</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">proscar87/garita@v0.2.0</span>
</span></span></code></pre></div><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#75715e"># .pre-commit-config.yaml</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">repo</span>: <span style="color:#ae81ff">https://github.com/proscar87/garita</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">rev</span>: <span style="color:#ae81ff">v0.2.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">hooks</span>: [{<span style="color:#f92672">id</span>: <span style="color:#ae81ff">garita}]</span>
</span></span></code></pre></div><p><code>docs/AGREGAR_PAIS.md</code> explica cómo agregar el tuyo: es un archivo, no una rama.</p>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/prowler-security-scan/</link><pubDate>Mon, 03 Aug 2026 22:46:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.37.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Prowler scans to detect vulnerabilities in your AWS resources, helping you maintain security and compliance in any cloud environment. It offers real-time monitoring and seamless integrations with popular tools like Slack, making it easy to integrate into CI/CD pipelines or on-premises environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.37.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates Prowler scans to detect vulnerabilities in your AWS resources, helping you maintain security and compliance in any cloud environment. It offers real-time monitoring and seamless integrations with popular tools like Slack, making it easy to integrate into CI/CD pipelines or on-premises environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-new-features-to-highlight-in-this-version">✨ New features to highlight in this version</h1>
<p>Enjoy them all now for free at <a href="https://cloud.prowler.com">https://cloud.prowler.com</a></p>
<h2 id="-lighthouse-ai--context-aware-chat-and-a-bigger-toolbox">💬 Lighthouse AI — Context-Aware Chat and a Bigger Toolbox</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Lighthouse AI is now aware of your working context when in Prowler Cloud. Messages carry page-aware context — the page you are on, the finding or resource open in the side panel, and its metadata — so &ldquo;explain this&rdquo; just works, and each page offers concise contextual suggestions to start from.</p>
<img width="1920" height="1080" alt="side-panel-context-aware" src="https://github.com/user-attachments/assets/7c87300e-dde7-401f-a475-0d51bbe68e0a" />
<p>Lighthouse also gained access to every tool family the Prowler MCP server advertises: scan configurations, scan scheduling, finding triage, alert rules and recipients, integrations, users, and roles. Every action remains gated by RBAC: Lighthouse AI can only do what the user asking could do themselves.</p>
<p>Read more in the <a href="https://docs.prowler.com/getting-started/products/prowler-cloud-lighthouse">Lighthouse AI documentation</a>.</p>
<h2 id="-prowler-mcp--integrations-users-and-roles">🔌 Prowler MCP — Integrations, Users, and Roles</h2>
<p>Prowler MCP gained three tool families, available on both the Cloud and the self-hosted Local MCP Server:</p>
<ul>
<li><strong><a href="https://docs.prowler.com/getting-started/basic-usage/prowler-mcp-tools#integrations-management">Integrations</a></strong> — manage where Prowler sends its results, with the full lifecycle for Amazon S3, AWS Security Hub, and Jira: create them, update credentials, configuration and attached providers, re-check connections, and delete them — plus turning findings into Jira work items directly from a conversation.</li>
<li><strong><a href="https://docs.prowler.com/getting-started/basic-usage/prowler-mcp-tools#user-management">Users</a></strong> — read-only tools to list the tenant users with their emails and identify the authenticated user.</li>
<li><strong><a href="https://docs.prowler.com/getting-started/basic-usage/prowler-mcp-tools#role-management">Roles</a></strong> — browse the RBAC roles defined in the tenant, inspect the capabilities each one grants, and set the role a user holds.</li>
</ul>
<p>Read more in the <a href="https://docs.prowler.com/getting-started/basic-usage/prowler-mcp-tools#prowler-tools">Prowler MCP tools reference</a>.</p>
<h2 id="-prowler-mcp--cloud-only-tools">☁️ Prowler MCP — Cloud-Only Tools</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>. These tools are exposed only by the Cloud MCP Server at <code>https://mcp.prowler.com/mcp</code>; the self-hosted Local MCP Server <strong>does not</strong> include them.</p>
</blockquote>
<p>A new <code>prowler_cloud_*</code> namespace adds 32 tools so your AI assistant can run Prowler Cloud workflows end to end instead of only reading from them:</p>
<ul>
<li><strong><a href="https://docs.prowler.com/getting-started/basic-usage/prowler-mcp-tools#alerts">Alerts</a></strong> — create and manage alert rules and email recipients, and browse the fired-alert history. Rule conditions can be dry-run before saving, so you can see what a rule would match without persisting anything.</li>
<li><strong><a href="https://docs.prowler.com/getting-started/basic-usage/prowler-mcp-tools#findings-triage">Findings Triage</a></strong> — set a finding&rsquo;s triage status and attach notes documenting the decision. Unlike muting, the finding stays visible.</li>
<li><strong><a href="https://docs.prowler.com/getting-started/basic-usage/prowler-mcp-tools#scan-scheduling">Scan Scheduling</a></strong> — configure daily, interval, weekly, or monthly recurring scans, one provider at a time or applied across many at once.</li>
<li><strong><a href="https://docs.prowler.com/getting-started/basic-usage/prowler-mcp-tools#scan-configurations">Scan Configurations</a></strong> — build reusable scan configuration and attach them to providers.</li>
</ul>
<p>Read more in the <a href="https://docs.prowler.com/getting-started/basic-usage/prowler-mcp-tools#prowler-cloud-tools">Prowler Cloud MCP tools reference</a>.</p>
<h2 id="-compliance--grouped-by-provider-of-the-same-type">🧭 Compliance — Grouped by provider of the same type</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>One framework, every provider, a single answer. Building on the cross-provider-type roll-up, the Compliance section now groups compliance for all providers of the same type: a <strong>single-provider framework</strong> — CIS AWS, CIS GCP, ENS for Azure — is aggregated across the latest completed scan of every provider of that type. Each framework card rolls up into a consolidated posture with a per-provider breakdown, a findings drill-down, and a combined executive PDF report. Requirement status follows the same strict precedence (FAIL over PASS over MANUAL), so one failing provider flags the requirement for the whole estate.</p>
<img width="1920" height="1080" alt="prowler-app-across-providers-expanded" src="https://github.com/user-attachments/assets/d15a1d62-4e2f-4309-ae42-52e7c826c5e9" />
<p>The Compliance tabs were also renamed to say what they aggregate: &ldquo;Per Scan&rdquo; is now <strong>Single Scan</strong>, &ldquo;Cross-Provider&rdquo; is now <strong>Multiple Scans</strong>, and Compliance lands on Multiple Scans by default.</p>
<img width="1920" height="1080" alt="prowler-app-across-providers-detail" src="https://github.com/user-attachments/assets/3d3f8578-c875-4b87-b090-6de61c47ef39" />
<p>Read more in the <a href="https://docs.prowler.com/user-guide/compliance/tutorials/cross-provider-compliance">Cross-Provider Compliance documentation</a>.</p>
<h2 id="-gcp-organization-onboarding">☁️ GCP Organization Onboarding</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Onboarding an entire Google Cloud organization is now a single guided flow. Provide an organization-level credential and Prowler discovers the full hierarchy, every folder and project. Pick the folders and projects to onboard from a selection tree, set custom aliases, test the connection, and launch: each selected project is registered as a provider, with no need to add them one by one. Post-onboarding management is covered too, including credential replacement and organization-wide deletion.</p>
<p>Read more in the <a href="https://docs.prowler.com/user-guide/tutorials/prowler-cloud-gcp-organizations">GCP Organizations documentation</a>.</p>
<h2 id="-attack-paths--more-privilege-escalation-queries">🕸️ Attack Paths — More Privilege Escalation Queries</h2>
<p>Attack Paths adds four AWS privilege-escalation detection queries from <a href="https://pathfinding.cloud">pathfinding.cloud</a>. Thanks to @paramanandmallik!</p>
<ul>
<li><strong><a href="https://hub.prowler.com/attack-paths/aws-sts-privesc-cross-account-trust">STS-002</a></strong> — cross-account role trust</li>
<li><strong><a href="https://hub.prowler.com/attack-paths/aws-sts-privesc-wildcard-trust">STS-003</a></strong> — wildcard role trust</li>
<li><strong><a href="https://hub.prowler.com/attack-paths/aws-iam-privesc-delete-user-permissions-boundary">IAM-022</a></strong> — user permissions-boundary removal</li>
<li><strong><a href="https://hub.prowler.com/attack-paths/aws-sso-privesc-permission-set-escalation">SSO-001</a></strong> — IAM Identity Center permission-set escalation</li>
</ul>
<p>The query info panel now links every query to its page on <a href="https://hub.prowler.com">Prowler Hub</a>, and the IAM privilege-escalation queries were reworked to run efficiently on accounts with many IAM roles, users, or groups, fixing runtime errors and timeouts on large graphs.</p>
<p>Read more in the <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-attack-paths">Attack Paths documentation</a>.</p>
<h2 id="-aws-confidential-computing--nitro-enclaves-checks">🛡️ AWS Confidential Computing — Nitro Enclaves Checks</h2>
<p>Prowler adds the first CSPM coverage for confidential computing workloads on AWS, with <strong>11 new checks</strong> for <a href="https://aws.amazon.com/ec2/nitro/nitro-enclaves/">Nitro Enclaves</a>, developed together with <a href="https://www.linkedin.com/in/gruizesteban/">Guillermo Ruiz</a> from AWS.</p>
<ul>
<li><strong>Workload host environment (EC2)</strong> — five <code>ec2_confidential_workload_host_*</code> checks for the parent instance: IMDSv2 not enforced, public IP exposure, unrestricted ingress, exposed vsock proxy ports, and hosts not running.</li>
<li><strong>KMS attestation policy</strong> — six <code>kms_key_enclave_*</code> checks for the key policies gating enclave secrets: attestation not enforced or bypassable, missing deployment binding, debug-mode attestations, PCR mismatches, and unknown enclave images.</li>
</ul>
<p>All checks are fully passive, using AWS APIs and CloudTrail with no instance access or SSM agent required, and are mapped across 23 compliance frameworks, including NIST 800-53 Rev 5, PCI-DSS v4.0, ISO 27001:2022, SOC 2, HIPAA, and MITRE ATT&amp;CK.</p>
<p>Read more about it this <a href="https://prowler.com/blog/your-llm-runs-in-a-nitro-enclave-who-is-checking-the-enclave">blog post</a>.</p>
<p>Try them out now at <a href="https://cloud.prowler.com/sign-up">cloud.prowler.com</a>!</p>
<h2 id="-new-provider--huawei-cloud">🏢 New Provider — Huawei Cloud</h2>
<p>Prowler now scans <a href="https://www.huaweicloud.com/"><strong>Huawei Cloud</strong></a>, with <strong>25 checks</strong> across ten services: CTS, ECS, ELB, EVS, IAM, KMS, OBS, RDS, VPC, and WAF, plus the CIS Huawei Cloud Foundations Benchmark 1.0 compliance framework. Thanks to @tomitobio for their 1st provider in Prowler!</p>
<p>To scan a Huawei Cloud account, export the IAM user&rsquo;s access key credentials and run Prowler CLI:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>export HUAWEICLOUD_ACCESS_KEY_ID<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;your-access-key-id&#34;</span>
</span></span><span style="display:flex;"><span>export HUAWEICLOUD_SECRET_ACCESS_KEY<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;your-secret-access-key&#34;</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>prowler huaweicloud
</span></span></code></pre></div><p>Read more in the <a href="https://docs.prowler.com/user-guide/providers/huaweicloud/getting-started-huaweicloud">Huawei Cloud documentation</a>. Explore all Huawei Cloud checks at <a href="https://hub.prowler.com/check?provider=huaweicloud">Prowler Hub</a>.</p>
<h2 id="-checks">🔍 Checks</h2>
<h3 id="aws">AWS</h3>
<ul>
<li><code>codecommit_repository_no_secrets</code>, alongside the new <code>codecommit</code> service, scans files tracked at the tip of each repository&rsquo;s default branch for hardcoded secrets. Thanks to @Sid-0602!</li>
<li><code>glue_catalog_connection_no_secrets</code> detects secrets in Glue Data Catalog connection properties. Thanks to @l46983284-cpu, @Rishi943, and @UTKARSH698!</li>
<li><code>ec2_instance_stopped_older_than_specific_days</code> detects EC2 instances stopped longer than a configurable number of days (default 30). Thanks to @Nithin078!</li>
<li><code>sagemaker_endpoint_config_kms_encryption_enabled</code> verifies SageMaker endpoint configurations use a KMS key for storage volume encryption. Thanks to @Nithin078 and @l46983284-cpu!</li>
</ul>
<p>Read more in the <a href="https://docs.prowler.com/user-guide/providers/aws/getting-started-aws">AWS documentation</a>.</p>
<p>Explore all AWS checks at <a href="https://hub.prowler.com/check?provider=aws">Prowler Hub</a>.</p>
<h2 id="-ocsf-output--mitre-attck-enrichment">📤 OCSF Output — MITRE ATT&amp;CK Enrichment</h2>
<p>OCSF detection finding output now populates <code>finding_info.analytic</code> with the Prowler check rule and <code>finding_info.attacks</code> with MITRE ATT&amp;CK technique and tactic objects for findings with MITRE ATT&amp;CK compliance metadata. Thanks to @AlexanderSanin!</p>
<h2 id="-fixed">🐞 Fixed</h2>
<ul>
<li>AWS Security Hub integrations now persist successful recovery checks during finding delivery, keeping connection status and the last-checked time accurate.</li>
<li>Social sign-up now creates authentication, tenant, and membership records in a single transaction, fully rolling back failed provisioning to prevent incomplete accounts.</li>
<li>The SAML configuration form keeps the ACS URL field stable while generating the callback URL and exposes the copy action only after a valid URL is available.</li>
<li>SAML users without a <code>userType</code> attribute and without an existing role now receive a least-privilege <code>read_only</code> fallback role, so role-dependent operations continue to work without granting management permissions.</li>
</ul>
<h2 id="-security">🔐 Security</h2>
<ul>
<li>Provider deletion, connection checks, scan creation, provider secrets, provider groups, and daily schedules now respect role provider-group visibility.</li>
<li>HTML reports escape provider-originated finding fields, preventing stored cross-site scripting through malicious cloud resource tags. <a href="https://github.com/prowler-cloud/prowler/security/advisories/GHSA-c2jg-2778-ggm4">https://github.com/prowler-cloud/prowler/security/advisories/GHSA-c2jg-2778-ggm4</a></li>
<li>Authentication with an API key whose owning user was deleted now returns <code>401</code>, and user deletion revokes the user&rsquo;s API keys across all their tenants.</li>
</ul>
<h2 id="-external-contributors">🙌 External Contributors</h2>
<p>Thank you to our community contributors for this release!</p>
<ul>
<li>@tomitobio: Huawei Cloud provider with CIS 1.0 benchmark (<a href="https://github.com/prowler-cloud/prowler/pull/11950">#11950</a>)</li>
<li>@paramanandmallik: four AWS privilege-escalation Attack Paths queries (<a href="https://github.com/prowler-cloud/prowler/pull/11460">#11460</a>)</li>
<li>@Sid-0602: AWS <code>codecommit</code> service and <code>codecommit_repository_no_secrets</code> check (<a href="https://github.com/prowler-cloud/prowler/pull/11846">#11846</a>)</li>
<li>@l46983284-cpu, @Rishi943, and @UTKARSH698: AWS <code>glue_catalog_connection_no_secrets</code> check (<a href="https://github.com/prowler-cloud/prowler/pull/11963">#11963</a>)</li>
<li>@Nithin078: AWS <code>ec2_instance_stopped_older_than_specific_days</code> (<a href="https://github.com/prowler-cloud/prowler/pull/12076">#12076</a>) and <code>sagemaker_endpoint_config_kms_encryption_enabled</code> (<a href="https://github.com/prowler-cloud/prowler/pull/12118">#12118</a>, co-authored with @l46983284-cpu) checks</li>
<li>@AlexanderSanin: MITRE ATT&amp;CK enrichment in OCSF detection finding output (<a href="https://github.com/prowler-cloud/prowler/pull/11492">#11492</a>)</li>
<li>@stefanobaldo: GCP gen2 Cloud Functions IAM policy retrieval is now thread-safe (<a href="https://github.com/prowler-cloud/prowler/pull/12107">#12107</a>)</li>
<li>@rayair250-droid: GCP SSH and RDP firewall checks now detect exposed ports in any position within multi-port rules (<a href="https://github.com/prowler-cloud/prowler/pull/12115">#12115</a>)</li>
<li>@jbchief-dev: secret ignore patterns now use Kingfisher-compatible LF line indexing (<a href="https://github.com/prowler-cloud/prowler/pull/12141">#12141</a>)</li>
<li>@bmbferreira: Helm chart improvements — immutable chart versions on release (<a href="https://github.com/prowler-cloud/prowler/pull/12056">#12056</a>) and capped Celery worker concurrency (<a href="https://github.com/prowler-cloud/prowler/pull/12054">#12054</a>)</li>
</ul>
<hr>
<h2 id="ui">UI</h2>
<h3 id="-added">🚀 Added</h3>
<ul>
<li>Lighthouse AI contextual messages with page-aware prompts, focused side-panel details, selected-resource metadata, and retry-safe historical badges <a href="https://github.com/prowler-cloud/prowler/pull/12069">(#12069)</a></li>
<li>Cross-account compliance view in the Multiple Scans tab: an &ldquo;Across providers&rdquo; section listing single-provider frameworks aggregatable across every account of the same provider type, with a per-account detail, findings drill-down and combined PDF report (Prowler Cloud only) <a href="https://github.com/prowler-cloud/prowler/pull/12086">(#12086)</a></li>
<li>In Prowler Cloud, authenticated users can send product feedback through a persistent widget backed by a PostHog headless survey, rendered with native Prowler components and editable from the PostHog dashboard <a href="https://github.com/prowler-cloud/prowler/pull/12116">(#12116)</a></li>
<li>Attack Paths query info panel now links every query to its page on Prowler Hub <a href="https://github.com/prowler-cloud/prowler/pull/12145">(#12145)</a></li>
<li>Warning before replacing an organization credential or deleting an organization, listing the providers affected <a href="https://github.com/prowler-cloud/prowler/pull/12255">(#12255)</a></li>
<li>GCP organization onboarding in the provider wizard: add every project of an organization at once, choosing which discovered projects to include (Prowler Cloud only) <a href="https://github.com/prowler-cloud/prowler/pull/12255">(#12255)</a></li>
<li>Sign-up campaign attribution preserves <code>promo_code</code> and <code>utm_*</code> params across auth redirects, sign-in/sign-up links, Google/GitHub OAuth callbacks, and <code>POST /users</code> <a href="https://github.com/prowler-cloud/prowler/pull/12269">(#12269)</a></li>
</ul>
<h3 id="-changed">🔄 Changed</h3>
<ul>
<li><code>/compliance</code> now lands on the Multiple Scans tab; links carrying a <code>scanId</code> keep opening Single Scan <a href="https://github.com/prowler-cloud/prowler/pull/12086">(#12086)</a></li>
<li>Compliance tab naming: &ldquo;Per Scan&rdquo; is now &ldquo;Single Scan&rdquo; and &ldquo;Cross-Provider&rdquo; is now &ldquo;Multiple Scans&rdquo;, with matching &ldquo;Across provider types&rdquo; and &ldquo;Across providers&rdquo; section headers explaining each aggregation axis <a href="https://github.com/prowler-cloud/prowler/pull/12086">(#12086)</a></li>
<li>Lighthouse contextual suggestions now show concise actions while preserving detailed prompts for chat <a href="https://github.com/prowler-cloud/prowler/pull/12219">(#12219)</a></li>
<li>Providers page groups GCP projects under their organization and folders <a href="https://github.com/prowler-cloud/prowler/pull/12255">(#12255)</a></li>
</ul>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li>Attack Paths now classify cloud-provider finding resources separately from Prowler findings <a href="https://github.com/prowler-cloud/prowler/pull/11244">(#11244)</a></li>
<li>Finding delta colors and integration update button labels restored <a href="https://github.com/prowler-cloud/prowler/pull/12160">(#12160)</a></li>
<li>Long unbroken messages in Lighthouse chat no longer overflow their message bubble <a href="https://github.com/prowler-cloud/prowler/pull/12215">(#12215)</a></li>
<li>SAML ACS URL field remains visible while generating the callback URL from the email domain <a href="https://github.com/prowler-cloud/prowler/pull/12236">(#12236)</a></li>
</ul>
<h2 id="api">API</h2>
<h3 id="-added-1">🚀 Added</h3>
<ul>
<li>Attack Paths: four AWS privilege-escalation detection queries from pathfinding.cloud: cross-account role trust (STS-002), wildcard role trust (STS-003), user permissions-boundary removal (IAM-022), and IAM Identity Center permission-set escalation (SSO-001) <a href="https://github.com/prowler-cloud/prowler/pull/11460">(#11460)</a></li>
</ul>
<h3 id="-fixed-2">🐞 Fixed</h3>
<ul>
<li>Attack Paths IAM privilege-escalation queries no longer build an all-nodes × all-resource-items cartesian product, fixing runtime errors and timeouts on accounts with many IAM roles, users, or groups <a href="https://github.com/prowler-cloud/prowler/pull/12136">(#12136)</a></li>
<li><code>task_args</code> serialization no longer returns HTTP 500 errors when Celery truncates stored task keyword arguments <a href="https://github.com/prowler-cloud/prowler/pull/12165">(#12165)</a></li>
<li>Attack Paths predefined queries on migrated graphs are now scoped with the provider label, letting the graph database seed from its label index instead of a global label scan and preventing query timeouts on Neptune <a href="https://github.com/prowler-cloud/prowler/pull/12167">(#12167)</a></li>
<li>Authentication with an API key whose owning user was deleted now returns <code>401</code> instead of an unhandled <code>AttributeError</code>, and user deletion now revokes the user&rsquo;s API keys across all their tenants <a href="https://github.com/prowler-cloud/prowler/pull/12210">(#12210)</a></li>
<li>AWS Security Hub integrations now persist successful connection checks during finding delivery so their connection status and last checked timestamp stay current <a href="https://github.com/prowler-cloud/prowler/pull/12212">(#12212)</a></li>
<li>SAML users without a <code>userType</code> attribute and without an existing role in the SAML tenant now receive a least-privilege <code>read_only</code> fallback role; a numeric suffix is used when that name belongs to a role with different permissions <a href="https://github.com/prowler-cloud/prowler/pull/12223">(#12223)</a></li>
<li>Social signups create users and authentication records in one database transaction, preventing incomplete accounts when provisioning fails <a href="https://github.com/prowler-cloud/prowler/pull/12245">(#12245)</a></li>
<li>Requesting integrations with a sparse fieldset that leaves out <code>configuration</code> no longer returns HTTP 500 errors when the tenant has a Jira integration <a href="https://github.com/prowler-cloud/prowler/pull/12261">(#12261)</a></li>
</ul>
<h3 id="-security-1">🔐 Security</h3>
<ul>
<li>Provider deletion and connection checks, scan creation, provider secrets, provider groups, and daily schedules now respect role provider-group visibility <a href="https://github.com/prowler-cloud/prowler/pull/12216">(#12216)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-added-2">🚀 Added</h3>
<ul>
<li>OCSF detection finding output now populates <code>finding_info.analytic</code> as the Prowler check rule and <code>finding_info.attacks</code> as MITRE ATT&amp;CK technique and tactic objects for findings with MITRE-ATTACK compliance metadata <a href="https://github.com/prowler-cloud/prowler/pull/11492">(#11492)</a></li>
<li><code>codecommit</code> service and <code>codecommit_repository_no_secrets</code> check for AWS provider, scanning files tracked at the tip of each repository&rsquo;s default branch for hardcoded secrets <a href="https://github.com/prowler-cloud/prowler/pull/11846">(#11846)</a></li>
<li>Huawei Cloud provider, with CTS, ECS, ELB, EVS, IAM, KMS, OBS, RDS, VPC and WAF services and a CIS 1.0 compliance benchmark <a href="https://github.com/prowler-cloud/prowler/pull/11950">(#11950)</a></li>
<li><code>glue_catalog_connection_no_secrets</code> check to detect secrets in Glue Data Catalog connection properties <a href="https://github.com/prowler-cloud/prowler/pull/11963">(#11963)</a></li>
<li><code>ec2_instance_stopped_older_than_specific_days</code> check for AWS provider, detecting EC2 instances stopped longer than a configurable number of days (default 30) <a href="https://github.com/prowler-cloud/prowler/pull/12076">(#12076)</a></li>
<li><code>sagemaker_endpoint_config_kms_encryption_enabled</code> check verifying SageMaker endpoint configurations use a KMS key for storage volume encryption <a href="https://github.com/prowler-cloud/prowler/pull/12118">(#12118)</a></li>
<li>11 AWS Nitro Enclaves security checks providing the first CSPM coverage for confidential computing workloads, covering both host environment (<code>ec2_confidential_workload_host_*</code>) and KMS attestation policy (<code>kms_key_enclave_*</code>), fully passive via boto3 and CloudTrail LookupEvents <a href="https://github.com/prowler-cloud/prowler/pull/12283">(#12283)</a></li>
</ul>
<h3 id="-fixed-3">🐞 Fixed</h3>
<ul>
<li>Scan configuration schema no longer exposes SDK/CLI-only providers such as <code>e2enetworks</code>; the aggregated schema served by <code>/scan-configurations/schema</code> now includes only app providers (<code>sdk_only = False</code>) <a href="https://github.com/prowler-cloud/prowler/pull/12094">(#12094)</a></li>
<li>GCP Cloud Functions gen2 IAM policy retrieval now uses a per-request HTTP client, preventing a process crash from concurrent thread-unsafe <code>httplib2</code> access when a project has several gen2 functions <a href="https://github.com/prowler-cloud/prowler/pull/12107">(#12107)</a></li>
<li>GCP firewall SSH and RDP checks now detect exposed target ports in any position within multi-port rules <a href="https://github.com/prowler-cloud/prowler/pull/12115">(#12115)</a></li>
<li>Secret ignore patterns now use Kingfisher-compatible LF line indexing for scanned content containing ASCII control characters <a href="https://github.com/prowler-cloud/prowler/pull/12141">(#12141)</a></li>
<li>Jira descriptions with inline code nested in bold or italic Markdown now render as valid ADF <a href="https://github.com/prowler-cloud/prowler/pull/12158">(#12158)</a></li>
</ul>
<h3 id="-security-2">🔐 Security</h3>
<ul>
<li>HTML reports escape provider-originated finding fields to prevent stored cross-site scripting through malicious cloud resource tags <a href="https://github.com/prowler-cloud/prowler/pull/12221">(#12221)</a></li>
</ul>
<h2 id="mcp">MCP</h2>
<h3 id="-added-3">🚀 Added</h3>
<ul>
<li>Read-only user management tools <code>prowler_list_users</code>, <code>prowler_get_user</code>, and <code>prowler_get_current_user</code> for listing tenant users with their emails and identifying the authenticated user <a href="https://github.com/prowler-cloud/prowler/pull/12088">(#12088)</a></li>
<li>RBAC role tools <code>prowler_list_roles</code>, <code>prowler_get_role</code>, <code>prowler_get_user_roles</code>, and <code>prowler_set_user_role</code> for browsing roles and setting the role a user holds <a href="https://github.com/prowler-cloud/prowler/pull/12088">(#12088)</a></li>
<li>Integrations tools to manage Amazon S3, AWS Security Hub and Jira integrations, and to send findings to Jira <a href="https://github.com/prowler-cloud/prowler/pull/12138">(#12138)</a></li>
</ul>
<h3 id="-changed-1">🔄 Changed</h3>
<ul>
<li>README now documents the Cloud-only <code>prowler_cloud_*</code> tools available on the hosted Prowler MCP (alerts, findings triage, scan scheduling, scan configurations), and corrects the Prowler Hub check count and the scan orchestration capabilities <a href="https://github.com/prowler-cloud/prowler/pull/12266">(#12266)</a></li>
</ul>
<h3 id="-fixed-4">🐞 Fixed</h3>
<ul>
<li>Memory leak in HTTP mode caused by streamable-HTTP sessions being retained for the process lifetime when clients never sent <code>DELETE /mcp</code>; the server now runs stateless <a href="https://github.com/prowler-cloud/prowler/pull/12235">(#12235)</a></li>
<li><code>prowler_list_integrations</code> failing with a 500 error on tenants with a Jira integration, caused by the request leaving <code>configuration</code> out of the sparse fieldset <a href="https://github.com/prowler-cloud/prowler/pull/12259">(#12259)</a></li>
</ul>
]]></content:encoded></item><item><title>Qualflare — Upload Test Results</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/qualflare-upload-test-results/</link><pubDate>Mon, 03 Aug 2026 22:45:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/qualflare-upload-test-results/</guid><description>Version updated for https://github.com/Qualflare/qualflare-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Qualflare GitHub Action automates the process of uploading test results from CI pipelines to Qualflare, a platform that provides AI-driven tools for analyzing and optimizing software quality. It simplifies the testing workflow by eliminating the need for manual installation or configuration and supports multiple frameworks out-of-the-box, allowing users to focus on their development without worrying about the underlying infrastructure.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Qualflare/qualflare-action">https://github.com/Qualflare/qualflare-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qualflare-upload-test-results">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Qualflare GitHub Action automates the process of uploading test results from CI pipelines to Qualflare, a platform that provides AI-driven tools for analyzing and optimizing software quality. It simplifies the testing workflow by eliminating the need for manual installation or configuration and supports multiple frameworks out-of-the-box, allowing users to focus on their development without worrying about the underlying infrastructure.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Shorten the action description to meet GitHub Marketplace&rsquo;s 125-char limit (no functional change; inputs, behavior, and branding unchanged). <code>uses: Qualflare/qualflare-action@v1</code> continues to work.</p>
]]></content:encoded></item><item><title>setup-openapi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/setup-openapi/</link><pubDate>Mon, 03 Aug 2026 22:45:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/setup-openapi/</guid><description>Version updated for https://github.com/remarkablemark/setup-openapi to version v1.1.12.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up a workflow for generating OpenAPI clients using the OpenAPI Generator CLI. It installs Java, downloads the CLI tool, caches it by version, and exposes the binary for use in GitHub Actions workflows. The action supports generating various client languages such as Ruby from an OpenAPI specification file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablemark/setup-openapi">https://github.com/remarkablemark/setup-openapi</a></strong> to version <strong>v1.1.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-openapi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up a workflow for generating OpenAPI clients using the OpenAPI Generator CLI. It installs Java, downloads the CLI tool, caches it by version, and exposes the binary for use in GitHub Actions workflows. The action supports generating various client languages such as Ruby from an OpenAPI specification file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1112-2026-08-03"><a href="https://github.com/remarkablemark/setup-openapi/compare/v1.1.11...v1.1.12">1.1.12</a> (2026-08-03)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump actions/setup-java from 5.6.0 to 5.7.0 (<a href="https://github.com/remarkablemark/setup-openapi/issues/34">#34</a>) (<a href="https://github.com/remarkablemark/setup-openapi/commit/c2795f205379f3d0903291c9aff33683c251d137">c2795f2</a>)</li>
</ul>
]]></content:encoded></item><item><title>Reoclo Load Secrets</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/reoclo-load-secrets/</link><pubDate>Mon, 03 Aug 2026 22:44:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/reoclo-load-secrets/</guid><description>Version updated for https://github.com/reoclo/load-secrets to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Reoclo Load Secrets action reads secrets from the Reoclo Secrets Manager into a GitHub Actions environment, automating the process of securely managing sensitive information without storing them directly in GitHub Secrets. This helps maintain a single source of truth for secrets and ensures that only authorized projects have access to them during runtime. The action also provides options to filter which secrets are loaded, add prefixes to variable names, and unset them after the job is completed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/reoclo/load-secrets">https://github.com/reoclo/load-secrets</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/reoclo-load-secrets">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Reoclo Load Secrets action reads secrets from the Reoclo Secrets Manager into a GitHub Actions environment, automating the process of securely managing sensitive information without storing them directly in GitHub Secrets. This helps maintain a single source of truth for secrets and ensures that only authorized projects have access to them during runtime. The action also provides options to filter which secrets are loaded, add prefixes to variable names, and unset them after the job is completed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/reoclo/load-secrets/commits/v1.0.0">https://github.com/reoclo/load-secrets/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>GoFS File Server</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/gofs-file-server/</link><pubDate>Mon, 03 Aug 2026 22:43:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/gofs-file-server/</guid><description>Version updated for https://github.com/samzong/gofs to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a lightweight, fast HTTP file server written in Go that provides a simple web interface for browsing files, supports secure path handling, optional authentication, modern UI with advanced features like upload and folder creation, WebDAV support, production-ready features such as structured logs and graceful shutdown, and can mount multiple directories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/samzong/gofs">https://github.com/samzong/gofs</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gofs-file-server">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a lightweight, fast HTTP file server written in Go that provides a simple web interface for browsing files, supports secure path handling, optional authentication, modern UI with advanced features like upload and folder creation, WebDAV support, production-ready features such as structured logs and graceful shutdown, and can mount multiple directories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="docker-images">Docker Images</h3>
<p>Multi-architecture Docker images are available on GitHub Container Registry and Docker Hub:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span><span style="color:#75715e"># Pull from GitHub Container Registry</span>
</span></span><span style="display:flex;"><span>docker pull ghcr.io/samzong/gofs:v0.4.0
</span></span><span style="display:flex;"><span>docker pull ghcr.io/samzong/gofs:latest
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Pull from Docker Hub</span>
</span></span><span style="display:flex;"><span>docker pull samzong/gofs:v0.4.0
</span></span><span style="display:flex;"><span>docker pull samzong/gofs:latest
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Run the container</span>
</span></span><span style="display:flex;"><span>docker run -p 8000:8000 -v <span style="color:#66d9ef">$(</span>pwd<span style="color:#66d9ef">)</span>:/data:ro samzong/gofs:v0.4.0
</span></span></code></pre></div><p>Supported architectures: <code>linux/amd64</code>, <code>linux/arm64</code></p>
<h2 id="changelog">Changelog</h2>
<ul>
<li>d7ac6d43ddd5cead18a869e0edd62f6d4cd610d5 Add DeepWiki to README.md</li>
<li>bc87cce91a1435cd7de3dc010a4189cba19b0f87 chore(deps): bump golang.org/x/crypto</li>
<li>38ef280b75053d5f990449c7b79b8e7ef17b7b24 feat(skill): add bundled gofs agent support (#15)</li>
<li>b9f0b8c9e4802a497a64bf5ab45d680695f76781 fix(ci): update release Trivy action to v0.36.0 (#16)</li>
<li>05e3ff0cd718fae321763dcc0bb66f308c4ca584 ♻️ refactor(config): drop classic theme, fallback to default</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/samzong/gofs/compare/v0.3.0...v0.4.0">https://github.com/samzong/gofs/compare/v0.3.0...v0.4.0</a></p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/agentauditkit-mcp-security-scan/</link><pubDate>Mon, 03 Aug 2026 22:42:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.67.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner designed to audit AI agent pipelines for misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. It runs fully offline and deterministically, avoiding the need for network calls and ensuring consistent findings. Additionally, it produces auditor-ready compliance-evidence packs in SARIF format, covering multiple security categories and frameworks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.67</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit is a security scanner designed to audit AI agent pipelines for misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 agent platforms. It runs fully offline and deterministically, avoiding the need for network calls and ensuring consistent findings. Additionally, it produces auditor-ready compliance-evidence packs in SARIF format, covering multiple security categories and frameworks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.67
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.67
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.67</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Guard the repo description and the corpus N against drift by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/529">https://github.com/sattyamjjain/agent-audit-kit/pull/529</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.66...v0.3.67">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.66...v0.3.67</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/sherpa.sh/</link><pubDate>Mon, 03 Aug 2026 22:40:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven automation tool that simplifies the process of deploying applications across multiple cloud providers. It translates plain English descriptions into optimal infrastructure configurations, automating tasks such as server setup, DNS management, CDN configuration, and database integration. By focusing on developer intent rather than detailed YAML files or vendor-specific tools, Sherpa aims to make deployment more efficient and less error-prone.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven automation tool that simplifies the process of deploying applications across multiple cloud providers. It translates plain English descriptions into optimal infrastructure configurations, automating tasks such as server setup, DNS management, CDN configuration, and database integration. By focusing on developer intent rather than detailed YAML files or vendor-specific tools, Sherpa aims to make deployment more efficient and less error-prone.</p>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Mon, 03 Aug 2026 22:39:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The deploy-swarm-service GitHub Action automates the deployment of a Swarm service by bundling frontend assets and committing them to the repository. This ensures that the build artifacts are available for use in the production environment, simplifying the deployment process and reducing manual intervention required.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>deploy-swarm-service</code> GitHub Action automates the deployment of a Swarm service by bundling frontend assets and committing them to the repository. This ensures that the build artifacts are available for use in the production environment, simplifying the deployment process and reducing manual intervention required.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>Tenzai Test</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/tenzai-test/</link><pubDate>Mon, 03 Aug 2026 22:39:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/tenzai-test/</guid><description>Version updated for https://github.com/TenzaiLtd/tenzai-github-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates an AI-powered security test on a deployed application using Tenzai. It triggers a commit-diff scan after deployment, providing real-time feedback through a Tenzai check run in GitHub. The action automatically detects previous deployments and handles different environments per workflow, ensuring efficient testing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TenzaiLtd/tenzai-github-action">https://github.com/TenzaiLtd/tenzai-github-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tenzai-test">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates an AI-powered security test on a deployed application using Tenzai. It triggers a commit-diff scan after deployment, providing real-time feedback through a Tenzai check run in GitHub. The action automatically detects previous deployments and handles different environments per workflow, ensuring efficient testing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ENG-6199: Resolve workflow base through merge base by @Dor256 in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/11">https://github.com/TenzaiLtd/tenzai-github-action/pull/11</a></li>
<li>Bump prettier from 3.9.5 to 3.9.6 in the npm group by @dependabot[bot] in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/12">https://github.com/TenzaiLtd/tenzai-github-action/pull/12</a></li>
<li>Bump actions/checkout from 7.0.0 to 7.0.1 in the github-actions group by @dependabot[bot] in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/10">https://github.com/TenzaiLtd/tenzai-github-action/pull/10</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/TenzaiLtd/tenzai-github-action/compare/v1.0.2...v1.0.3">https://github.com/TenzaiLtd/tenzai-github-action/compare/v1.0.2...v1.0.3</a></p>
]]></content:encoded></item><item><title>Sequa – Deterministic AI Testing ⭐</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/sequa-deterministic-ai-testing/</link><pubDate>Mon, 03 Aug 2026 22:38:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/sequa-deterministic-ai-testing/</guid><description>Version updated for https://github.com/thetechnoadvisor/sequa to version v0.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sequa records AI executions once and replays them locally, reducing test run time, API costs, and dependency on internet connectivity. It supports multiple frameworks like OpenAI, Anthropic, LangChain, and LangGraph, offering features such as deterministic testing, phase 2 AI regression testing engine, and searchable AI executions &amp;amp; instant replay capabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thetechnoadvisor/sequa">https://github.com/thetechnoadvisor/sequa</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sequa-deterministic-ai-testing">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sequa records AI executions once and replays them locally, reducing test run time, API costs, and dependency on internet connectivity. It supports multiple frameworks like OpenAI, Anthropic, LangChain, and LangGraph, offering features such as deterministic testing, phase 2 AI regression testing engine, and searchable AI executions &amp; instant replay capabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: implement regression testing mode and add utility for result comparison (bce5243)</li>
<li>feat: upgrade the pyproject version (5af1386)</li>
<li>feat: implement pytest plugin for LLM testing with marker support and CI/CD integration (fbda344)</li>
<li>chore: update readme.md (34cbfb7)</li>
<li>feat: update version (10eea22)</li>
<li>feat: update demo.ipynb with git like cassette search and replay debugging engine (0d0937b)</li>
<li>feat: implement new search module (cc44592)</li>
<li>Update ci cd (6c6e8aa)</li>
<li>feat: implement interactive benchmark demos and automate CI/CD pipeline with release tagging (977d704)</li>
<li>feat: add Sequa dashboard web interface and implement new video script and comparison demos (8d8a166)</li>
</ul>
]]></content:encoded></item><item><title>aicheck-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/aicheck-scan/</link><pubDate>Mon, 03 Aug 2026 22:37:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/aicheck-scan/</guid><description>Version updated for https://github.com/unauthdev/aicheck-scan to version v1.1.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, aicheck, evaluates AI stack services used in a job by live-probing them. It checks if any exposed self-hosted AI services are present and reports their exposure grade (A–F) along with links to fix cards in the run summary and SARIF format for code scanning. The action is useful for ensuring AI services in PRs are secure and not exposed without proper authentication.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/unauthdev/aicheck-scan">https://github.com/unauthdev/aicheck-scan</a></strong> to version <strong>v1.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aicheck-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>aicheck</code>, evaluates AI stack services used in a job by live-probing them. It checks if any exposed self-hosted AI services are present and reports their exposure grade (A–F) along with links to fix cards in the run summary and SARIF format for code scanning. The action is useful for ensuring AI services in PRs are secure and not exposed without proper authentication.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li>Detect exposed RedisInsight / Redis Commander consoles (GET-only, ASI06 agent-memory framing)</li>
<li>Marketplace README badge points at the live listing</li>
</ul>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">unauthdev/aicheck-scan@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">target</span>: <span style="color:#ae81ff">localhost</span>
</span></span></code></pre></div><p>Pin <code>@v1.1.6</code> for this release. SARIF code scanning remains on by default.</p>
]]></content:encoded></item><item><title>Veracode Config</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/veracode-config/</link><pubDate>Mon, 03 Aug 2026 22:36:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/veracode-config/</guid><description>Version updated for https://github.com/vcode-john/veracode-config to version v0.06.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The veracode-config GitHub Action helps onboard repositories into the Veracode Workflow integration by automating the process of creating or updating application profiles. It checks for an existing profile, inventories repository information such as programming languages and package managers, persists this information in custom metadata, and exposes reusable workflow outputs for downstream jobs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vcode-john/veracode-config">https://github.com/vcode-john/veracode-config</a></strong> to version <strong>v0.06</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/veracode-config">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>veracode-config</code> GitHub Action helps onboard repositories into the Veracode Workflow integration by automating the process of creating or updating application profiles. It checks for an existing profile, inventories repository information such as programming languages and package managers, persists this information in custom metadata, and exposes reusable workflow outputs for downstream jobs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>another test (8d6c1b4)</li>
<li>tried again (4b9172a)</li>
<li>Fixxed rollup config to include all the code (bcfcf2b)</li>
<li>Updated rollup.config.mjs to output main.mjs instead of index.js, and updated index.js to import from dist/main instead of src/main. (ba0bf90)</li>
<li>Updated index to use the dist main.js (3f0124e)</li>
<li>Added rollup to handle dependencies (7b51a93)</li>
<li>Update to node24 (26a6a27)</li>
<li>Updated .gitignore to include .DS_Store files, which are macOS system files that should not be tracked in version control. This change helps keep the repository clean and avoids unnecessary clutter from system-specific files. (244a907)</li>
<li>initial commit (852b2df)</li>
</ul>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/vibgrate-scan/</link><pubDate>Mon, 03 Aug 2026 22:35:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.803.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @vibgrate/cli GitHub Action automates local codebase intelligence, providing a deterministic code graph and drift score to AI coding agents. It helps identify dependencies, runtime lag, and EOL proximity, offering ranked upgrade priorities to ensure up-to-date libraries and frameworks on the user’s machine without relying on APIs or network connections.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.803.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>@vibgrate/cli</code> GitHub Action automates local codebase intelligence, providing a deterministic code graph and drift score to AI coding agents. It helps identify dependencies, runtime lag, and EOL proximity, offering ranked upgrade priorities to ensure up-to-date libraries and frameworks on the user&rsquo;s machine without relying on APIs or network connections.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268035">Vibgrate CLI 2026.803.5</h1>
<p><em>Released 2026-08-03</em></p>
<p>Routine maintenance update for the CLI.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Maintenance release with internal improvements and dependency updates.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.803.4, interleaved on one runner against the pinned corpus (189 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21461 count</td>
          <td>21461 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>10659 count</td>
          <td>10659 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.94 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>688.50 ms</td>
          <td>687.50 ms</td>
      </tr>
  </tbody>
</table>
<p>2 regression(s) — published, not omitted:</p>
<ul>
<li>Tasks passed on both arms: 33 → 31 (-6.1%)</li>
<li>Comparable-task rate (both arms passed / total): 0.94 → 0.89 (-6.1%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.803.5">https://vibgrate.com/changelog/cli/2026.803.5</a></p>
]]></content:encoded></item><item><title>IIS Versioned Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/iis-versioned-deploy/</link><pubDate>Mon, 03 Aug 2026 22:33:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/iis-versioned-deploy/</guid><description>Version updated for https://github.com/wallymathieu/iis-deploy to version v5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The IIS Versioned Deploy action automates the deployment of a website to a versioned directory within IIS, avoiding downtime. It uses PowerShell scripts to update the IIS website’s physical path and retains only the specified number of release folders. Users can specify the website name, virtual application name, source path, destination path, release prefix, and number of releases to keep. The action supports deploying on multiple runners using matrix strategies and is also available as an Azure DevOps pipeline task.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wallymathieu/iis-deploy">https://github.com/wallymathieu/iis-deploy</a></strong> to version <strong>v5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/iis-versioned-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The IIS Versioned Deploy action automates the deployment of a website to a versioned directory within IIS, avoiding downtime. It uses PowerShell scripts to update the IIS website&rsquo;s physical path and retains only the specified number of release folders. Users can specify the website name, virtual application name, source path, destination path, release prefix, and number of releases to keep. The action supports deploying on multiple runners using matrix strategies and is also available as an Azure DevOps pipeline task.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Harden docs by pinning action references to immutable commit SHAs by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/4">https://github.com/wallymathieu/iis-deploy/pull/4</a></li>
<li>Harden IIS release cleanup against unsafe directory deletion by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/6">https://github.com/wallymathieu/iis-deploy/pull/6</a></li>
<li>Add AppCmd operational guidance docs for IIS deploy action by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/7">https://github.com/wallymathieu/iis-deploy/pull/7</a></li>
<li>Azure devops by @brainfucknow in <a href="https://github.com/wallymathieu/iis-deploy/pull/8">https://github.com/wallymathieu/iis-deploy/pull/8</a></li>
<li>Create azure-devops-task.yml by @wallymathieu in <a href="https://github.com/wallymathieu/iis-deploy/pull/9">https://github.com/wallymathieu/iis-deploy/pull/9</a></li>
<li>Improve build pipeline descriptions and artifact name by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/10">https://github.com/wallymathieu/iis-deploy/pull/10</a></li>
<li>Add Pester CI pipeline and fix module import failure by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/11">https://github.com/wallymathieu/iis-deploy/pull/11</a></li>
<li>Use a dedicated overview for the Azure DevOps marketplace listing by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/12">https://github.com/wallymathieu/iis-deploy/pull/12</a></li>
<li>Make releaseParentDir optional, defaulting to the parent of the current site directory by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/13">https://github.com/wallymathieu/iis-deploy/pull/13</a></li>
<li>Expand Pester coverage for IisDeploy PowerShell module by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/15">https://github.com/wallymathieu/iis-deploy/pull/15</a></li>
<li>Make release folder prefix configurable by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/14">https://github.com/wallymathieu/iis-deploy/pull/14</a></li>
<li>Fix <code>website-name</code> input mismatch and add alternatives to README by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/16">https://github.com/wallymathieu/iis-deploy/pull/16</a></li>
<li>Align GitHub Actions and Azure DevOps deployment documentation by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/17">https://github.com/wallymathieu/iis-deploy/pull/17</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@brainfucknow made their first contribution in <a href="https://github.com/wallymathieu/iis-deploy/pull/8">https://github.com/wallymathieu/iis-deploy/pull/8</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wallymathieu/iis-deploy/compare/v4...v5">https://github.com/wallymathieu/iis-deploy/compare/v4...v5</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>Harden docs by pinning action references to immutable commit SHAs by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/4">https://github.com/wallymathieu/iis-deploy/pull/4</a></li>
<li>Harden IIS release cleanup against unsafe directory deletion by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/6">https://github.com/wallymathieu/iis-deploy/pull/6</a></li>
<li>Add AppCmd operational guidance docs for IIS deploy action by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/7">https://github.com/wallymathieu/iis-deploy/pull/7</a></li>
<li>Azure devops by @brainfucknow in <a href="https://github.com/wallymathieu/iis-deploy/pull/8">https://github.com/wallymathieu/iis-deploy/pull/8</a></li>
<li>Create azure-devops-task.yml by @wallymathieu in <a href="https://github.com/wallymathieu/iis-deploy/pull/9">https://github.com/wallymathieu/iis-deploy/pull/9</a></li>
<li>Improve build pipeline descriptions and artifact name by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/10">https://github.com/wallymathieu/iis-deploy/pull/10</a></li>
<li>Add Pester CI pipeline and fix module import failure by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/11">https://github.com/wallymathieu/iis-deploy/pull/11</a></li>
<li>Use a dedicated overview for the Azure DevOps marketplace listing by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/12">https://github.com/wallymathieu/iis-deploy/pull/12</a></li>
<li>Make releaseParentDir optional, defaulting to the parent of the current site directory by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/13">https://github.com/wallymathieu/iis-deploy/pull/13</a></li>
<li>Expand Pester coverage for IisDeploy PowerShell module by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/15">https://github.com/wallymathieu/iis-deploy/pull/15</a></li>
<li>Make release folder prefix configurable by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/14">https://github.com/wallymathieu/iis-deploy/pull/14</a></li>
<li>Fix <code>website-name</code> input mismatch and add alternatives to README by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/16">https://github.com/wallymathieu/iis-deploy/pull/16</a></li>
<li>Align GitHub Actions and Azure DevOps deployment documentation by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/17">https://github.com/wallymathieu/iis-deploy/pull/17</a></li>
<li>Bump Azure DevOps extension version to 0.1.4 by @wallymathieu with @Copilot in <a href="https://github.com/wallymathieu/iis-deploy/pull/18">https://github.com/wallymathieu/iis-deploy/pull/18</a></li>
</ul>
<h2 id="new-contributors-1">New Contributors</h2>
<ul>
<li>@brainfucknow made their first contribution in <a href="https://github.com/wallymathieu/iis-deploy/pull/8">https://github.com/wallymathieu/iis-deploy/pull/8</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wallymathieu/iis-deploy/compare/v4...v5">https://github.com/wallymathieu/iis-deploy/compare/v4...v5</a></p>
]]></content:encoded></item><item><title>Zephyr Preview Environments</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/zephyr-preview-environments/</link><pubDate>Mon, 03 Aug 2026 22:32:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/zephyr-preview-environments/</guid><description>Version updated for https://github.com/ZephyrCloudIO/zephyr-preview-environment-action to version v1.0.0.
This action is used across all versions by 7 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation, update, and cleanup of preview environments for pull requests in a repository using Zephyr Cloud. It keeps one persistent comment updated with exact version, environment, tag, and dashboard links, streamlining code review processes by providing immediate preview deployments. The action supports Zephyr authentication via an organization CI token, GitHub token for pull request comments, and a custom GitHub App for branding comment authors.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zephyr-preview-environments">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation, update, and cleanup of preview environments for pull requests in a repository using Zephyr Cloud. It keeps one persistent comment updated with exact version, environment, tag, and dashboard links, streamlining code review processes by providing immediate preview deployments. The action supports Zephyr authentication via an organization CI token, GitHub token for pull request comments, and a custom GitHub App for branding comment authors.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(deps): remediate Vanta SCA advisories (overdue + due ≤8d) by @ryok90 in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/89">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/89</a></li>
<li>fix(actions): run preview action on Node 24 by @zackarychapple in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/92">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/92</a></li>
<li>feat: refresh preview deployment comments by @Nsttt in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/94">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/94</a></li>
<li>chore: prepare v1.0.0 release by @Nsttt in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/95">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/95</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@zackarychapple made their first contribution in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/92">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/92</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/compare/v0.2.0...v1.0.0">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/compare/v0.2.0...v1.0.0</a></p>
]]></content:encoded></item><item><title>zero-harm-ai-gha</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/zero-harm-ai-gha/</link><pubDate>Mon, 03 Aug 2026 22:31:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/zero-harm-ai-gha/</guid><description>Version updated for https://github.com/Zero-Harm-AI-LLC/zero-harm-ai-gha to version v1.0.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action zero-harm-ai-gha detects AI-specific security risks in pull requests, such as prompt injection risk, secrets exposure, and unsafe LLM tool usage. It provides automated security checks to help developers prevent misuse of large language models (LLMs) by scanning code diffs before merge and emitting annotations for review. The action supports various output formats, including GitHub Actions annotations, JSON, Markdown, and SARIF.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zero-Harm-AI-LLC/zero-harm-ai-gha">https://github.com/Zero-Harm-AI-LLC/zero-harm-ai-gha</a></strong> to version <strong>v1.0.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zero-harm-ai-gha">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>zero-harm-ai-gha</code> detects AI-specific security risks in pull requests, such as prompt injection risk, secrets exposure, and unsafe LLM tool usage. It provides automated security checks to help developers prevent misuse of large language models (LLMs) by scanning code diffs before merge and emitting annotations for review. The action supports various output formats, including GitHub Actions annotations, JSON, Markdown, and SARIF.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="zero-harm-ai-gha-v107">zero-harm-ai-gha v1.0.7</h2>
<p>This release updates the GitHub Action branding and repository references to the new <code>zero-harm-ai-gha</code> name, and adds optional AI-mode support for <code>zero-harm-ai-detectors</code> while preserving the default heuristic behavior.</p>
<h3 id="whats-new">What’s new</h3>
<ul>
<li>renamed the GitHub Action display name to <code>zero-harm-ai-gha</code></li>
<li>updated README, workflow examples, sample repo references, and Marketplace-facing copy to match the new name</li>
<li>updated sample workflow naming and findings artifact/output filenames</li>
<li>added <code>ai-mode</code> input to the GitHub Action</li>
<li>added <code>--ai-mode</code> flag to the CLI</li>
<li>PromptShield’s detector integration now enables AI mode by constructing <code>AIConfig()</code> for <code>zero-harm-ai-detectors</code> when requested</li>
<li>default behavior remains unchanged: if <code>ai-mode</code> is not enabled, detection continues to use heuristic mode</li>
</ul>
<h3 id="usage">Usage</h3>
<p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Zero-Harm-AI-LLC/zero-harm-ai-gha@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">ai-mode</span>: <span style="color:#66d9ef">true</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>agent-bom Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/agent-bom-scan/</link><pubDate>Mon, 03 Aug 2026 15:17:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/agent-bom-scan/</guid><description>Version updated for https://github.com/msaad00/agent-bom to version v0.98.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action is designed to automate the scanning of software repositories, images, and cloud accounts using a centralized control plane. It provides a unified approach to managing evidence across different environments and enforcing AI or MCP runtime policies in infrastructure that users control. The action can be used without an account and supports multiple package ecosystems and compliance surfaces, with no need for API keys.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaad00/agent-bom">https://github.com/msaad00/agent-bom</a></strong> to version <strong>v0.98.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-bom-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action is designed to automate the scanning of software repositories, images, and cloud accounts using a centralized control plane. It provides a unified approach to managing evidence across different environments and enforcing AI or MCP runtime policies in infrastructure that users control. The action can be used without an account and supports multiple package ecosystems and compliance surfaces, with no need for API keys.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): consolidate dependency and registry maintenance by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4516">https://github.com/msaad00/agent-bom/pull/4516</a></li>
<li>fix(registries): harden Glama release freshness by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4517">https://github.com/msaad00/agent-bom/pull/4517</a></li>
<li>fix(cwpp): enforce runtime evidence integrity by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4518">https://github.com/msaad00/agent-bom/pull/4518</a></li>
<li>fix(ci): remove privileged untrusted checkout by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4519">https://github.com/msaad00/agent-bom/pull/4519</a></li>
<li>feat(runtime): add canonical client profile foundation by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4520">https://github.com/msaad00/agent-bom/pull/4520</a></li>
<li>feat(runtime): enforce canonical client profiles in gateway by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4521">https://github.com/msaad00/agent-bom/pull/4521</a></li>
<li>Restore scanning feature description in README by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4522">https://github.com/msaad00/agent-bom/pull/4522</a></li>
<li>docs(readme): lead with control-plane scale by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4524">https://github.com/msaad00/agent-bom/pull/4524</a></li>
<li>fix(docs): align README storefront contract by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4525">https://github.com/msaad00/agent-bom/pull/4525</a></li>
<li>feat(runtime): add durable gateway activity ledger by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4523">https://github.com/msaad00/agent-bom/pull/4523</a></li>
<li>chore(deps): consolidate UI and workflow maintenance by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4534">https://github.com/msaad00/agent-bom/pull/4534</a></li>
<li>fix(security): enforce trusted maintenance and trial boundaries by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4535">https://github.com/msaad00/agent-bom/pull/4535</a></li>
<li>fix(graph): make topology and completeness contracts honest by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4536">https://github.com/msaad00/agent-bom/pull/4536</a></li>
<li>fix(deploy): harden AWS control-plane secret wiring by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4537">https://github.com/msaad00/agent-bom/pull/4537</a></li>
<li>test(deploy): guard the AWS control-plane secret wiring contract by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4539">https://github.com/msaad00/agent-bom/pull/4539</a></li>
<li>test(overview): isolate the process-global caches /v1/overview reads by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4540">https://github.com/msaad00/agent-bom/pull/4540</a></li>
<li>fix(cwpp): serialize runtime-evidence schema bootstrap across processes by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4541">https://github.com/msaad00/agent-bom/pull/4541</a></li>
<li>chore(deps): bump @tanstack/react-virtual from 3.14.8 to 3.14.9 in /ui by @dependabot[bot] in <a href="https://github.com/msaad00/agent-bom/pull/4542">https://github.com/msaad00/agent-bom/pull/4542</a></li>
<li>fix(gateway): make agent containment actually contain by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4544">https://github.com/msaad00/agent-bom/pull/4544</a></li>
<li>chore(deps-dev): bump jsdom from 30.0.0 to 30.0.1 in /ui by @dependabot[bot] in <a href="https://github.com/msaad00/agent-bom/pull/4543">https://github.com/msaad00/agent-bom/pull/4543</a></li>
<li>feat(cost): attribute LLM spend and fuse it into the unified graph by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4545">https://github.com/msaad00/agent-bom/pull/4545</a></li>
<li>feat(graph): surface spend and one-click containment on the canvas by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4547">https://github.com/msaad00/agent-bom/pull/4547</a></li>
<li>fix(gateway): stop identity revocation failing open on a large roster by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4548">https://github.com/msaad00/agent-bom/pull/4548</a></li>
<li>fix(mcp): pin the MCP SDK to the major that ships our entry point by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4550">https://github.com/msaad00/agent-bom/pull/4550</a></li>
<li>fix(ci): make MCP server tests hermetic instead of registry-dependent by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4549">https://github.com/msaad00/agent-bom/pull/4549</a></li>
<li>test(cloud): stop faked provider SDKs leaking between test files by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4553">https://github.com/msaad00/agent-bom/pull/4553</a></li>
<li>fix(scan): resolve conflicting advisory severities upward, not by sort order by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4551">https://github.com/msaad00/agent-bom/pull/4551</a></li>
<li>fix(ci): keep the metrics snapshot working when git refuses the checkout by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4554">https://github.com/msaad00/agent-bom/pull/4554</a></li>
<li>perf(gateway): stop the live feed freezing the whole control plane by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4555">https://github.com/msaad00/agent-bom/pull/4555</a></li>
<li>fix(graph): a filtered view of a truncated snapshot is still truncated by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4557">https://github.com/msaad00/agent-bom/pull/4557</a></li>
<li>fix(audit): stop one tenant&rsquo;s policy audit entry discarding another&rsquo;s by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4556">https://github.com/msaad00/agent-bom/pull/4556</a></li>
<li>perf(gateway): make the activity feed durable and cursor-backed by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4558">https://github.com/msaad00/agent-bom/pull/4558</a></li>
<li>fix(cis): fail closed on stale remediation bindings by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4559">https://github.com/msaad00/agent-bom/pull/4559</a></li>
<li>fix(cis): restrict root remediation to break-glass use by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4560">https://github.com/msaad00/agent-bom/pull/4560</a></li>
<li>fix(cis): restore provider-verified remediation commands by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4561">https://github.com/msaad00/agent-bom/pull/4561</a></li>
<li>fix(integrity): fail closed on missing and malformed evidence by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4562">https://github.com/msaad00/agent-bom/pull/4562</a></li>
<li>Remove image section from README by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4563">https://github.com/msaad00/agent-bom/pull/4563</a></li>
<li>fix(runtime): bind tenant work and bound hot paths by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4564">https://github.com/msaad00/agent-bom/pull/4564</a></li>
<li>ci: route documentation-only changes through fast gates by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4565">https://github.com/msaad00/agent-bom/pull/4565</a></li>
<li>fix(control-plane): restore bounded result honesty by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4566">https://github.com/msaad00/agent-bom/pull/4566</a></li>
<li>fix(models): surface malicious artifacts as findings by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4567">https://github.com/msaad00/agent-bom/pull/4567</a></li>
<li>fix(skills): audit instruction-only files by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4568">https://github.com/msaad00/agent-bom/pull/4568</a></li>
<li>fix(graph): scope credential identity to servers by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4569">https://github.com/msaad00/agent-bom/pull/4569</a></li>
<li>fix(graph): bound Postgres edge reconciliation by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4570">https://github.com/msaad00/agent-bom/pull/4570</a></li>
<li>chore(deps): bump lucide-react from 1.27.0 to 1.28.0 in /ui by @dependabot[bot] in <a href="https://github.com/msaad00/agent-bom/pull/4572">https://github.com/msaad00/agent-bom/pull/4572</a></li>
<li>chore(deps): update release and registry actions by @dependabot[bot] in <a href="https://github.com/msaad00/agent-bom/pull/4573">https://github.com/msaad00/agent-bom/pull/4573</a></li>
<li>fix(api): reject malformed requests, degrade on unreadable manifests, and close tenant gaps by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4576">https://github.com/msaad00/agent-bom/pull/4576</a></li>
<li>fix(compliance): score only the controls the scan actually evidenced by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4579">https://github.com/msaad00/agent-bom/pull/4579</a></li>
<li>fix: stop reporting bounded, sampled, and uncomparable results as certain by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4580">https://github.com/msaad00/agent-bom/pull/4580</a></li>
<li>test(ui): stop a debug screenshot failing the large-graph E2E by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4581">https://github.com/msaad00/agent-bom/pull/4581</a></li>
<li>fix: report the degraded evidence the product already detected by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4582">https://github.com/msaad00/agent-bom/pull/4582</a></li>
<li>fix(compliance): derive the posture score from the status, once by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4583">https://github.com/msaad00/agent-bom/pull/4583</a></li>
<li>docs: correct the PCI coverage claim and record what shipped by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4586">https://github.com/msaad00/agent-bom/pull/4586</a></li>
<li>fix(hub): stop compliance ingest breaking on a date certain by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4587">https://github.com/msaad00/agent-bom/pull/4587</a></li>
<li>test(scale): guard the read path&rsquo;s shape, not the runner&rsquo;s mood by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4588">https://github.com/msaad00/agent-bom/pull/4588</a></li>
<li>test(scale): assert the paging contract instead of timing it by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4591">https://github.com/msaad00/agent-bom/pull/4591</a></li>
<li>perf(findings): let the severity filter reach the store in the facet pass by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4592">https://github.com/msaad00/agent-bom/pull/4592</a></li>
<li>fix(scan): scan the whole archive, promote every model flag, run the IaC rules by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4593">https://github.com/msaad00/agent-bom/pull/4593</a></li>
<li>fix(scan): order Packagist, NuGet and RubyGems by their own version rules by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4594">https://github.com/msaad00/agent-bom/pull/4594</a></li>
<li>fix(graph): stop a bounded traversal reporting its own budget as the total by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4595">https://github.com/msaad00/agent-bom/pull/4595</a></li>
<li>fix(output): carry the KEV deadline everywhere and stop unresolvable bounds passing as confident by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4596">https://github.com/msaad00/agent-bom/pull/4596</a></li>
<li>chore(metrics): stop the snapshot re-stamping itself on every run by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4597">https://github.com/msaad00/agent-bom/pull/4597</a></li>
<li>fix: close the pre-freeze P0 batch across fleet tenancy, skills detection, graph rollup and version ordering by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4599">https://github.com/msaad00/agent-bom/pull/4599</a></li>
<li>fix(graph): make attack-path search honest about its bounds and stop it scanning the estate per hop by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4600">https://github.com/msaad00/agent-bom/pull/4600</a></li>
<li>fix: gateway enforcement, write/read contract alignment, and a scale-to-zero demo by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4601">https://github.com/msaad00/agent-bom/pull/4601</a></li>
<li>fix(audit): read the tenant that was asked for, and run the Postgres suites CI never ran by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4603">https://github.com/msaad00/agent-bom/pull/4603</a></li>
<li>fix(ingest): report what the batch actually stored, not what it received by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4604">https://github.com/msaad00/agent-bom/pull/4604</a></li>
<li>chore(docs): stop advertising a hosted demo from the public repo by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4605">https://github.com/msaad00/agent-bom/pull/4605</a></li>
<li>fix(cli): check the inventory path before refreshing the vuln DB by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4606">https://github.com/msaad00/agent-bom/pull/4606</a></li>
<li>test(gateway): assert the loop stayed free, not how fast the runner was by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4608">https://github.com/msaad00/agent-bom/pull/4608</a></li>
<li>fix(azure): call SDK methods that exist, and let CI see when they don&rsquo;t by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4609">https://github.com/msaad00/agent-bom/pull/4609</a></li>
<li>fix(release): close 0.98.3 correctness gaps by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4610">https://github.com/msaad00/agent-bom/pull/4610</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/msaad00/agent-bom/compare/v0.98.2...v0.98.3">https://github.com/msaad00/agent-bom/compare/v0.98.2...v0.98.3</a></p>
]]></content:encoded></item><item><title>Agent Security Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/agent-security-harness/</link><pubDate>Mon, 03 Aug 2026 15:15:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/agent-security-harness/</guid><description>Version updated for https://github.com/msaleme/red-team-blue-team-agent-fabric to version v4.13.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Security Harness automates security tests to detect potential vulnerabilities in agents. It performs multiple tests across modules and provides OWASP Agentic AI coverage reports on threat scenarios and mitigation controls. The action supports various protocols like MCP, x402, and hitl, and helps identify potential issues before they can be exploited.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaleme/red-team-blue-team-agent-fabric">https://github.com/msaleme/red-team-blue-team-agent-fabric</a></strong> to version <strong>v4.13.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-security-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Agent Security Harness automates security tests to detect potential vulnerabilities in agents. It performs multiple tests across modules and provides OWASP Agentic AI coverage reports on threat scenarios and mitigation controls. The action supports various protocols like MCP, x402, and hitl, and helps identify potential issues before they can be exploited.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="the-fix">The fix</h2>
<p><strong>All eight HITL tests could report PASS against a target they never reached.</strong></p>
<p>v4.13.0 shipped a guard that treated only a transport failure (<code>_status == 0</code>) as &ldquo;no answer&rdquo;. A <strong>live</strong> host that does not implement the approval or message channel answers every probe with 404 — which is not status 0, so the guard passed it through to readers that scored it as evidence.</p>
<p>Measured against v4.13.0:</p>
<pre tabindex="0"><code>v4.13.0 vs 404            -&gt; 5 of 8 PASSED
v4.13.0 vs 401            -&gt; 5 of 8 PASSED
v4.13.0 vs 500            -&gt; 5 of 8 PASSED
v4.13.0 vs 200+rpc-error  -&gt; 5 of 8 PASSED

v4.13.1 vs each of the above -&gt; 0 of 8 PASSED
</code></pre><table>
  <thead>
      <tr>
          <th>Test</th>
          <th>Wrong verdict in v4.13.0</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>HITL-001</strong> (High)</td>
          <td>404/401/500 → <em>&ldquo;25 approval requests bounded by the target&rdquo;</em> — an endpoint that does not exist scored as a rate limit</td>
      </tr>
      <tr>
          <td><strong>HITL-002</strong></td>
          <td>200 with no <code>queue_position</code> → counted as successful risk prioritisation</td>
      </tr>
      <tr>
          <td><strong>HITL-003 / HITL-004</strong></td>
          <td>404 → a <em>fabricated finding</em> against a request never serviced; HTTP 403 <code>Access denied</code> matched the reversal regex and passed</td>
      </tr>
      <tr>
          <td><strong>HITL-005…008</strong></td>
          <td>404 <strong>and 200 + JSON-RPC error envelope</strong> → <em>&ldquo;refused or emitted no lure&rdquo;</em> — an error body contains no lure</td>
      </tr>
  </tbody>
</table>
<p>The JSON-RPC case is the one worth pausing on: HTTP says 200 while the application layer says &ldquo;method not found&rdquo;. That is the normal way a JSON-RPC server reports an unimplemented method, and it defeated a status-code-only guard.</p>
<p><strong>The fix:</strong> <code>_serviced()</code> — a verdict is recorded only for a 2xx that does not carry a JSON-RPC error envelope. Everything else is INCONCLUSIVE, with the status histogram attached so the verdict is auditable. HITL-001 keeps <code>429</code> as an affirmative rate-limit signal.</p>
<h3 id="why-the-suite-did-not-catch-it">Why the suite did not catch it</h3>
<p>The v4.13.0 regression test asserted that nothing passes against a dead target — by mocking <code>_status: 0</code>, <strong>the same assumption the implementation made</strong>. Test and code were two copies of one belief, so the suite stayed green while the defect was live. A non-independent oracle, in the module written specifically to stop a security test manufacturing assurance.</p>
<h2 id="documentation-accuracy-sweep">Documentation accuracy sweep</h2>
<ul>
<li><strong>Two DOIs belonged to other researchers.</strong> <code>10.5281/zenodo.15105866</code> is a MALDI mass-spectrometry dataset by Ranes et al.; <code>10.5281/zenodo.15106553</code> is an e-learning article by Toshtemirov. Both were published here under this author&rsquo;s titles, in four files each — including a document written for a standards venue. All nine DOIs re-verified against <code>doi.org</code>; seven are genuine and retained, the two above replaced with verified records rather than re-pointed at a guessed identifier. The README carries a standing correction.</li>
<li><strong>A guard that could not fail.</strong> <code>test_test_count_consistent_in_crosswalk</code> matched a string <code>cli.py</code> does not contain, so its assertion was unreachable. It passed while the crosswalk said 595 and the canonical count was 603.</li>
<li><strong><code>595 tests / 43 modules</code> in twelve live files</strong>, including both AIUC-1 submission documents and <code>CITATION.cff</code>. Repo-wide count guards added, with dated snapshots excluded so history is not rewritten.</li>
<li><strong>Citation honesty.</strong> README and ROADMAP now state that a 2026-08-02 OpenAlex audit found <strong>30 citation edges and 0 qualifying independent citations</strong> — every edge a self-citation.</li>
<li><strong>Coverage report re-pinned.</strong> The header claimed harness 4.13.1 against a commit predating it. Change history is now data-driven and records that no verdict changed and the adjudication was not redone.</li>
</ul>
<h2 id="scope">Scope</h2>
<p>No test IDs, counts or coverage verdicts change. <strong>603 tests across 44 modules.</strong> OWASP Agentic v1.1 T1–T17 remains <strong>13 direct, 4 partial, 0 not evidenced</strong>. What changes is whether a verdict can be trusted.</p>
<p>Credit to Cursor Bugbot, which flagged HITL-001/002 and later the <code>CITATION.cff</code> gap in the guard written to close gaps of that kind.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/msaleme/red-team-blue-team-agent-fabric/compare/v4.13.0...v4.13.1">https://github.com/msaleme/red-team-blue-team-agent-fabric/compare/v4.13.0...v4.13.1</a></p>
]]></content:encoded></item><item><title>GH Stars</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/gh-stars/</link><pubDate>Mon, 03 Aug 2026 15:14:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/gh-stars/</guid><description>Version updated for https://github.com/nicoloboschi/gh-stars to version v1.1.3.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GH Stars is an open-source solution for tracking GitHub stars in self-hosted environments. It automates the process of backfilling stargazer timestamps and maintaining daily star counts to ensure accuracy even after stars are removed. The action uses the GITHUB_TOKEN to fetch recent stargazers and generate a chart that can be embedded in repository READMEs using Markdown.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicoloboschi/gh-stars">https://github.com/nicoloboschi/gh-stars</a></strong> to version <strong>v1.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gh-stars">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GH Stars is an open-source solution for tracking GitHub stars in self-hosted environments. It automates the process of backfilling stargazer timestamps and maintaining daily star counts to ensure accuracy even after stars are removed. The action uses the <code>GITHUB_TOKEN</code> to fetch recent stargazers and generate a chart that can be embedded in repository READMEs using Markdown.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nicoloboschi/gh-stars/compare/v1...v1.1.3">https://github.com/nicoloboschi/gh-stars/compare/v1...v1.1.3</a></p>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/ai-harness-doctor/</link><pubDate>Mon, 03 Aug 2026 15:13:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.23.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor automates the auditing of AI harness files to ensure they are up-to-date and consistent. It helps developers consolidate scattered instructions into a single AGENTS.md file, making it easier to manage and update agent configurations. The action identifies inconsistencies such as conflicting instructions, overlapping files, and mismatches between declarations and code, providing actionable feedback for improving the overall quality of AI responses.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v1.23.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Harness Doctor automates the auditing of AI harness files to ensure they are up-to-date and consistent. It helps developers consolidate scattered instructions into a single <code>AGENTS.md</code> file, making it easier to manage and update agent configurations. The action identifies inconsistencies such as conflicting instructions, overlapping files, and mismatches between declarations and code, providing actionable feedback for improving the overall quality of AI responses.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(validation): correct round 51 phase evidence by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/392">https://github.com/NieZhuZhu/ai-harness-doctor/pull/392</a></li>
<li>fix(repo): remove tracked local node_modules symlink by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/393">https://github.com/NieZhuZhu/ai-harness-doctor/pull/393</a></li>
<li>feat(eval): add bounded parallel task execution by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/394">https://github.com/NieZhuZhu/ai-harness-doctor/pull/394</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1...v1.23.0">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1...v1.23.0</a></p>
]]></content:encoded></item><item><title>svelte-vitals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/svelte-vitals/</link><pubDate>Mon, 03 Aug 2026 15:12:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/svelte-vitals/</guid><description>Version updated for https://github.com/oekazuma/svelte-vitals-action to version v0.6.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The svelte-vitals-action is a GitHub Action that automates static SvelteKit code-health checks such as SEO, performance, correctness, security, and architecture on every pull request. It provides inline annotations in the diff, a job summary, and updates a sticky PR comment with findings. The action uses the svelte-vitals CLI to analyze the project directory and can be easily set up using the generator or by hand.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oekazuma/svelte-vitals-action">https://github.com/oekazuma/svelte-vitals-action</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/svelte-vitals">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The svelte-vitals-action is a GitHub Action that automates static SvelteKit code-health checks such as SEO, performance, correctness, security, and architecture on every pull request. It provides inline annotations in the diff, a job summary, and updates a sticky PR comment with findings. The action uses the svelte-vitals CLI to analyze the project directory and can be easily set up using the generator or by hand.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="minor-changes">Minor Changes</h3>
<ul>
<li>
<p>ca45599: Update the bundled analyzer to <code>svelte-vitals</code> 0.37.0 / <code>@svelte-vitals/core</code> 0.31.1. The action&rsquo;s inputs and outputs are unchanged — what changes is what the scan reports and the numbers it prints:</p>
<ul>
<li><strong>Scores are now floored instead of rounded</strong>, so a reported 100 means the deduction was exactly zero. Every category score and Health can move down by one point, and Health is computed from unrounded category scores (the old double rounding could move it two). A workflow gating on the summary&rsquo;s Health number should expect it a point lower.</li>
<li>One new rule <strong>on by default</strong>: <code>architecture/route-component-import</code> reports a component importing a SvelteKit route entry (<code>+page.svelte</code>, <code>+layout.svelte</code>, <code>+error.svelte</code>, and their <code>@</code> breakout forms). Existing projects may see new <code>info</code> findings; stories, tests and specs are exempt.</li>
<li>Three new opt-in Architecture rules, inert until configured: <code>architecture/unit-entry-file</code>, <code>architecture/directory-naming</code>, <code>architecture/reserved-directory-names</code>.</li>
<li>Import specifiers now resolve through the aliases a project declares in <code>svelte.config.{js,ts}</code> (<code>kit.alias</code>, and <code>kit.files.lib</code> when <code>$lib</code> has been moved). Projects importing through their own aliases will see findings that were previously invisible — <code>security/shared-state-import</code> in particular was inert for them.</li>
<li>Fewer false positives: <code>performance/heavy-import</code> no longer reports type-only imports, which are erased at build.</li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>AI Model Lifecycle Monitor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/ai-model-lifecycle-monitor/</link><pubDate>Mon, 03 Aug 2026 15:11:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/ai-model-lifecycle-monitor/</guid><description>Version updated for https://github.com/oscarnilsson98/ai-model-end-of-life-action to version v3.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks AI models referenced by committed application and deployment code against a lifecycle feed. It provides warnings or fails the job if known models will be shut down within a specified period, helping to ensure compliance with deprecation policies. The action reads evidence directly from the Git commit being assessed and outputs actionable information for developers to address potential issues before they impact production.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action">https://github.com/oscarnilsson98/ai-model-end-of-life-action</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-model-lifecycle-monitor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks AI models referenced by committed application and deployment code against a lifecycle feed. It provides warnings or fails the job if known models will be shut down within a specified period, helping to ensure compliance with deprecation policies. The action reads evidence directly from the Git commit being assessed and outputs actionable information for developers to address potential issues before they impact production.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The first production-ready release of AI Model Lifecycle Monitor discovers model usage directly from committed repository code and warns before known shutdowns. There is no model inventory to generate or maintain.</p>
<h2 id="quick-start">Quick start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v7</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">persist-credentials</span>: <span style="color:#66d9ef">false</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">fetch-depth</span>: <span style="color:#ae81ff">0</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">oscarnilsson98/ai-model-end-of-life-action@v3</span>
</span></span></code></pre></div><p>That warning-only workflow needs no provider credentials, package installation, language setup, or action inputs. For production, pin both actions to reviewed commit SHAs.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Detects supported OpenAI, Anthropic, Google Gen AI, Amazon Bedrock, Azure Terraform, and consumed environment-binding model references without executing repository code.</li>
<li>Reads immutable Git trees rather than arbitrary runner workspace files.</li>
<li>Separates lifecycle outcome, scan coverage, and pull-request comparison health.</li>
<li>Keeps base-branch policy authoritative on pull requests and merge queues.</li>
<li>Supports additive, freshness-bounded checked-in claims for runtime-only evidence.</li>
<li>Publishes bounded reports, annotations, stable fingerprints, job summaries, strict JSON Schemas, and optional Slack snapshots.</li>
<li>Quarantines unreviewed lifecycle-feed changes as partial coverage instead of granting them lifecycle authority.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li>205 deterministic tests and both TypeScript projects pass on the pinned Bun 1.3.14 toolchain.</li>
<li>The committed Node 24 bundle reproduces byte-for-byte.</li>
<li>The packaged zero-input action passes on Linux, macOS, and Windows.</li>
<li>CodeQL reports no alerts at the release gate.</li>
<li>The live adapter validates 416 records: 413 model pairs and 3 explicit non-models, with no lifecycle conflicts or reviewed pair drift.</li>
<li>The exact release tag runs hermetically as <code>no-actionable-risk + complete</code>.</li>
</ul>
<p>See the <a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action#readme">README</a>, <a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action/blob/v3.0.0/docs/v3-product-contract.md">product contract</a>, and <a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action/blob/v3.0.0/docs/v3-detector-contract.md">detector contract</a>.</p>
]]></content:encoded></item><item><title>mdx-embeddings-actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/mdx-embeddings-actions/</link><pubDate>Mon, 03 Aug 2026 15:10:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/mdx-embeddings-actions/</guid><description>Version updated for https://github.com/PieterDePauw/mdx-embeddings-actions to version v0.0.11.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action converts markdown files into embeddings and stores them in a Postgres/Supabase database, allowing for vector similarity search within documentation. It integrates with OpenAI’s API to generate embeddings and uses Supabase as the storage backend for efficient retrieval. The action is designed to be used alongside the headless-vector-search repository for comprehensive documentation search capabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PieterDePauw/mdx-embeddings-actions">https://github.com/PieterDePauw/mdx-embeddings-actions</a></strong> to version <strong>v0.0.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mdx-embeddings-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action converts markdown files into embeddings and stores them in a Postgres/Supabase database, allowing for vector similarity search within documentation. It integrates with OpenAI&rsquo;s API to generate embeddings and uses Supabase as the storage backend for efficient retrieval. The action is designed to be used alongside the <code>headless-vector-search</code> repository for comprehensive documentation search capabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>TOTAL OVERHAUL (2cd1eba)</li>
<li>Refactor processMdxForSearch function for improved code readability and performance (b002cf3)</li>
<li>Refactor parsePaths function to improve code clarity and consistency (d3aa6c6)</li>
<li>Add /dist files (15b298a)</li>
<li>Refactor generateEmbeddings function for improved code readability and removal of unused code (2069271)</li>
<li>Refactor generateEmbeddings function for improved code readability and removal of unused code (3d4485e)</li>
<li>Refactor generateEmbeddings function to improve code readability and remove unused code (dffc3cb)</li>
<li>Refactor generateEmbeddings function to improve code readability and remove unused code (9bc0822)</li>
<li>chore: Update pages table schema to reference parent_page_id column (59d1dc9)</li>
<li>chore: Update package.json to include release script (86e6b5f)</li>
</ul>
]]></content:encoded></item><item><title>vord Static Analysis</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/vord-static-analysis/</link><pubDate>Mon, 03 Aug 2026 15:10:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/vord-static-analysis/</guid><description>Version updated for https://github.com/pmaojo/vord to version v0.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a static analysis tool written in Rust that helps developers ensure code quality before it’s committed. It automates various tasks such as analyzing repositories, setting up hooks for AI agents, and integrating with CI pipelines. The tool supports 24 languages and provides features like intra-file and cross-file taint analysis, symbol extraction, and remediation capabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pmaojo/vord">https://github.com/pmaojo/vord</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vord-static-analysis">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a static analysis tool written in Rust that helps developers ensure code quality before it&rsquo;s committed. It automates various tasks such as analyzing repositories, setting up hooks for AI agents, and integrating with CI pipelines. The tool supports 24 languages and provides features like intra-file and cross-file taint analysis, symbol extraction, and remediation capabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add rulesets/wordpress: a WPCS-shaped ruleset for WordPress best practices by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/155">https://github.com/pmaojo/vord/pull/155</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.6.0...v0.7.0">https://github.com/pmaojo/vord/compare/v0.6.0...v0.7.0</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>Add rulesets/wordpress: a WPCS-shaped ruleset for WordPress best practices by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/155">https://github.com/pmaojo/vord/pull/155</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.6.0...v0.7.0">https://github.com/pmaojo/vord/compare/v0.6.0...v0.7.0</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>Add rulesets/wordpress: a WPCS-shaped ruleset for WordPress best practices by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/155">https://github.com/pmaojo/vord/pull/155</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.6.0...v0.7.0">https://github.com/pmaojo/vord/compare/v0.6.0...v0.7.0</a></p>
<h2 id="whats-changed-4">What&rsquo;s Changed</h2>
<ul>
<li>Add rulesets/wordpress: a WPCS-shaped ruleset for WordPress best practices by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/155">https://github.com/pmaojo/vord/pull/155</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.6.0...v0.7.0">https://github.com/pmaojo/vord/compare/v0.6.0...v0.7.0</a></p>
<h2 id="whats-changed-5">What&rsquo;s Changed</h2>
<ul>
<li>Add rulesets/wordpress: a WPCS-shaped ruleset for WordPress best practices by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/155">https://github.com/pmaojo/vord/pull/155</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.6.0...v0.7.0">https://github.com/pmaojo/vord/compare/v0.6.0...v0.7.0</a></p>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/raviqqe/muffy/</link><pubDate>Mon, 03 Aug 2026 15:08:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Muffy, automates the validation of static websites using the Nu HTML validator. It provides a simple command-line tool and integrates with GitHub Actions to ensure website integrity before deployment. The action allows users to check multiple websites or individual sites directly from the terminal or through GitHub workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Muffy, automates the validation of static websites using the Nu HTML validator. It provides a simple command-line tool and integrates with GitHub Actions to ensure website integrity before deployment. The action allows users to check multiple websites or individual sites directly from the terminal or through GitHub workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>785ae445bd565ed8c477bf65affccad5ba13d289 Bump version (#1185)</li>
<li>241486e4a51bac6ac9ab11e83f6a090321ea3beb Fix double compile of default site configuration (#1184)</li>
<li>ebbf6100627b4b9cac0178822b7ea5786d5c8946 Configuration page on documentation (#1182)</li>
<li>69cd1844df2208bc567914796b8d09e29594dbd0 Inline SVG (#1181)</li>
<li>116f070eec0b5a04dc26aaabd2b8e94a03d48512 GitHub Action page (#1180)</li>
<li>f41c3c1d1c4f408fd20e2f2f947676b043ae5232 DOM errors (#1179)</li>
<li>678f25542d2aa27c4f1e0cd398a61653f833b257 Update readme (#1178)</li>
<li>75ed7e9c6b6d22ac847d9f57d2d7f3b92679606e <code>foreignObject</code> in SVG (#1177)</li>
<li>ed5e19a7cd7e735f658ef243a2227b048769bfd3 Namespace-aware names (#1176)</li>
</ul>
]]></content:encoded></item><item><title>Droid LLM Hunter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/droid-llm-hunter/</link><pubDate>Mon, 03 Aug 2026 15:08:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/droid-llm-hunter/</guid><description>Version updated for https://github.com/roomkangali/droid-llm-hunter to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Main Purpose and Functionality: Droid LLM Hunter is an automated security analysis tool that leverages traditional SAST techniques combined with the powerful context understanding of Large Language Models (LLMs) to identify vulnerabilities in Android applications. It uses Hybrid Decompilation, Context-Aware Analysis, and Intelligent Risk Filtering to ensure focused attention on high-severity findings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/roomkangali/droid-llm-hunter">https://github.com/roomkangali/droid-llm-hunter</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/droid-llm-hunter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Main Purpose and Functionality</strong>: Droid LLM Hunter is an automated security analysis tool that leverages traditional SAST techniques combined with the powerful context understanding of Large Language Models (LLMs) to identify vulnerabilities in Android applications. It uses Hybrid Decompilation, Context-Aware Analysis, and Intelligent Risk Filtering to ensure focused attention on high-severity findings.</p>
<p><strong>Problems it Solves</strong>: The action automates the detection process by replacing keyword-based scanning with LLM-driven analysis, thereby improving both precision and speed. It also provides the capability to generate Proof-of-Concept (PoC) scripts for verified vulnerabilities, transforming from a passive scanner into an active Red Team Assistant.</p>
<p><strong>Key Capabilities</strong>: Droid LLM Hunter supports Hybrid Decompilation, Context-Aware Analysis, Intelligent Risk Filtering, Auto-Exploit Generation, and offers a Dashboard Report and VulnerAppDLH tool for managing security analysis reports.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="update-v130--prompt-quality-test-foundation--testbed-expansion-golden-test-layer-2-consistent-rules-detection-fixes-intent-redirection--vulnerappdlh-v2">UPDATE v1.3.0 — PROMPT QUALITY, TEST FOUNDATION &amp; TESTBED EXPANSION: &ldquo;Golden Test Layer 2, Consistent Rules, Detection Fixes, Intent Redirection &amp; VulnerAppDLH v2&rdquo;</h1>
<p>This release makes the detection <strong>verifiable</strong> and the rule prompts <strong>consistent</strong>. It adds a semantic Golden Test (Layer 2) that runs real scans against the <code>VulnerAppDLH</code> testbed and asserts a recall contract, then uses that safety net to standardize all 26 vulnerability-rule prompts, redesign a few misleading detection patterns, and close two recall gaps — all proven not to regress detection (recall held <strong>16/16</strong> across every change).</p>
<blockquote>
<p>Verified with OpenRouter <code>moonshotai/kimi-k3</code>. Layer 1 (deterministic) grew from 45 → <strong>91 tests</strong>.</p>
</blockquote>
<blockquote>
<p><strong>This release also folds in the originally-planned testbed-expansion follow-up</strong> (now complete): the <code>VulnerAppDLH</code> testbed was extended to <strong>v2.0.0</strong> (8 new vulnerable modules), a brand-new <strong><code>intent_redirection</code></strong> rule was added (<strong>26 toggleable rules</strong> now), and two detection/engine fixes were surfaced by the harness. Final Layer-2 recall against <strong><code>VulnerAppDLHv2.apk</code> → 25/25</strong> (precision green, 0 errors). See sections <strong>[13]–[16]</strong>. Future work is split into focused releases: <strong><code>Update v1.3.1</code></strong> (&ldquo;The Obfuscation Update&rdquo;) then <strong><code>Update v1.3.2</code></strong> (&ldquo;The Supply Chain Update&rdquo;).</p>
</blockquote>
<hr>
<h2 id="-test-foundation--golden-test-layer-2-semantic">🧪 Test Foundation — Golden Test Layer 2 (semantic)</h2>
<h3 id="1-semantic-golden-test--recall-contract--new">[1] Semantic golden test + recall contract 🟢 NEW</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>What</strong></td>
          <td><code>tests/test_golden_vulnerapp.py</code> runs a full scan of <code>VulnerAppDLH.apk</code> and asserts findings <strong>cover</strong> the curated ground-truth <code>{rule → file}</code> set (<code>tests/golden/vulnerapp_expected.json</code>) — a <em>recall contract</em> — plus precision guards (<code>must_not_fire</code>). Counts <code>also_detected_by</code> so dedup can&rsquo;t hide a finding.</td>
      </tr>
      <tr>
          <td><strong>Ground truth</strong></td>
          <td>Derived from the app&rsquo;s SOURCE (not a past scan): 16 intended true-positives across 12 code files + the manifest. Curated to exclude historical false positives.</td>
      </tr>
      <tr>
          <td><strong>Opt-in</strong></td>
          <td>Marked <code>@pytest.mark.llm</code>, skipped by default (<code>pytest</code>), run explicitly with <code>pytest -m llm</code>. Content-addressed cache (v1.2.0) makes re-runs cheap; a changed prompt busts only that rule&rsquo;s cache.</td>
      </tr>
  </tbody>
</table>
<h3 id="2-ci-job-b--semantic-tests-gated--new">[2] CI Job B — semantic tests, gated 🟢 NEW</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>What</strong></td>
          <td>New <code>semantic-test</code> job in <code>.github/workflows/ci.yml</code>, gated to <code>workflow_dispatch</code> OR a PR labeled <code>semantic-test</code> (no auto-schedule → no surprise LLM cost). Wires the <code>OPENROUTER_API_KEY</code> secret.</td>
      </tr>
  </tbody>
</table>
<hr>
<h2 id="-detection-quality--rule-prompts-all-26-rules-now-consistent">🎯 Detection Quality — rule prompts (all 26 rules now consistent)</h2>
<h3 id="3-c-json-only-output-enforcement--high">[3] [C] JSON-only output enforcement 🟠 HIGH</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td>Many rule prompts ended with prose-inviting instructions (&ldquo;explain how to exploit&rdquo;, &ldquo;say Safe&rdquo;, &ldquo;report VULNERABLE&rdquo;) that fight the system prompt&rsquo;s JSON-only contract → parse failures, esp. on weaker models.</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td>A single <code>JSON_ONLY_SUFFIX</code> is appended (engine-level) to every rule call as the final, overriding instruction; removed the worst offender (&ldquo;say Safe&rdquo;) from <code>universal_logic_flaw</code>. 0 parse errors in verification.</td>
      </tr>
  </tbody>
</table>
<h3 id="4-a-language-agnostic-prompts--retired-the-replace-hack--medium">[4] [A] Language-agnostic prompts + retired the <code>replace</code> hack 🟡 MEDIUM</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td>~11 prompts said &ldquo;smali code snippet&rdquo; though the default <code>hybrid</code> mode feeds <strong>Java</strong>; the engine papered over it with a fragile <code>vuln_prompt.replace(&quot;smali&quot;,&quot;java&quot;)</code>.</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td>All rule prompts + <code>summarize_prompt.txt</code> now say &ldquo;decompiled Android code (Java or Smali)&rdquo; with neutral <code>```</code> <code>{code_snippet}</code> wrappers; the <code>replace</code> hack was <strong>removed</strong> from <code>engine.py</code>.</td>
      </tr>
  </tbody>
</table>
<h3 id="5-f-rich-consistent-template-for-terse-rules--medium">[5] [F] Rich, consistent template for terse rules 🟡 MEDIUM</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td>Older rules were 2–3 lines with no taint reasoning, while newer rules had a detailed template — inconsistent quality.</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td>13 covered rules rewritten to <em>Vulnerability pattern → Tainted source → &ldquo;not a finding if…&rdquo;</em> (sql_injection, biometric_bypass, insecure_random/storage/webview/file_permissions, graphql_injection, path_traversal, webview_xss, hardcoded_secrets, exported_components, intent_spoofing, deeplink_hijack, webview_deeplink).</td>
      </tr>
  </tbody>
</table>
<h3 id="6-d-redesigned-misleading-detection-patterns--high">[6] [D] Redesigned misleading detection patterns 🟠 HIGH</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td><code>path_traversal</code> matched <code>openFile</code> — which only hit <code>InsecureFileActivity</code> <em>coincidentally</em> (via <code>openFileOutput</code>), missing the real signal. <code>graphql_injection</code> matched any <code>query = &quot;...&quot;</code> (noisy). <code>universal_logic_flaw</code> (meant to be LLM-exclusive) had a narrow pattern that made gating skip real logic flaws.</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td><code>path_traversal</code> → `(openFile</td>
      </tr>
      <tr>
          <td><strong>Fix (scope)</strong></td>
          <td>Because <code>universal_logic_flaw</code> now runs on every risky file, its prompt was <strong>narrowed</strong> to genuine trust/business-logic flaws and told to <strong>defer</strong> issues owned by dedicated rules (SQLi, GraphQL, secrets, storage, path traversal, deserialization, reflection). This stopped it re-flagging those as &ldquo;logic flaws&rdquo; while keeping the real conceptual flaws (e.g. CryptoActivity client-side auth trust). Verified: recall still 16/16.</td>
      </tr>
  </tbody>
</table>
<h3 id="7-full-consistency-sweep--polish">[7] Full consistency sweep 🟢 POLISH</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>What</strong></td>
          <td>Neutralized the <code>{code_snippet}</code> wrapper fence (<code>```java</code> → <code>```</code>) across 9 newer rules so all 26 rules are uniform. <code>strandhogg</code> and <code>hardcoded_secrets_xml</code> already used the rich template — left unchanged (correct).</td>
      </tr>
  </tbody>
</table>
<hr>
<h2 id="-correctness--recall">🐛 Correctness &amp; Recall</h2>
<h3 id="8-dedicated-pass-rules-leaked-into-the-code-deep-scan--critical">[8] Dedicated-pass rules leaked into the code deep-scan 🔴 CRITICAL</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td>Rules that have their OWN analysis pass were not excluded from the generic <code>analyze_file</code> code scan, so they ran on every risky <code>.java</code> file and false-positived: (a) <code>strandhogg</code> (manifest-only) fired on 8 files incl. library <code>FastServiceLoaderKt</code> — found by the Layer-2 smoke run; (b) <code>hardcoded_secrets_xml</code> (strings.xml-only) fired on <code>SecretsActivity.java</code> / <code>WebViewActivity.java</code> — found by the full all-rules scan.</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td>Single-source constants: <code>MANIFEST_RULES</code> (manifest) and <code>DEDICATED_PASS_RULES = MANIFEST_RULES + hardcoded_secrets_xml</code>, used by every code-scan exclusion. Manifest rules run only in <code>analyze_manifest</code>; <code>hardcoded_secrets_xml</code> only in <code>analyze_strings_xml</code>. + Layer-1 regression tests.</td>
      </tr>
  </tbody>
</table>
<h3 id="9-two-recall-gaps-closed--1616--high">[9] Two recall gaps closed → 16/16 🟠 HIGH</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td>Baseline recall was 14/16: <code>insecure_file_permissions</code> missed <code>InsecureFileActivity</code> (app uses <code>setReadable(true,false)</code> + integer mode, not <code>MODE_WORLD_*</code>); <code>universal_logic_flaw</code> missed <code>CryptoActivity</code> (gated out by its own narrow pattern).</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td>Added `set(Readable</td>
      </tr>
  </tbody>
</table>
<h3 id="10-dual-language-detection-patterns-apktool-mode--low">[10] Dual-language detection patterns (apktool mode) 🟡 LOW</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Fix</strong></td>
          <td><code>unsafe_reflection</code>, <code>insecure_deserialization</code>, <code>pending_intent_hijacking</code>, <code>zip_slip</code> patterns now match both Java (<code>.method</code>) and Smali (<code>;-&gt;method</code>) forms + Layer-1 Smali tests.</td>
      </tr>
  </tbody>
</table>
<h3 id="11-manifest_parserpy-deprecation--trivial">[11] <code>manifest_parser.py</code> deprecation 🟢 TRIVIAL</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Fix</strong></td>
          <td><code>if self.root</code> → <code>if self.root is not None</code> (ElementTree truth-value DeprecationWarning).</td>
      </tr>
  </tbody>
</table>
<hr>
<h2 id="-report-noise">🧹 Report Noise</h2>
<h3 id="12-e-report-level-de-duplication--medium">[12] [E] Report-level de-duplication 🟡 MEDIUM</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td>Overlapping rules flagged the same file repeatedly (WebView trio on one file; <code>universal_logic_flaw</code> fired broadly after [6]).</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td><code>engine._dedupe_findings()</code> (info-preserving): family merge (webview/storage/ipc/deeplink) + generic fold (universal_logic_flaw folded into a same-file specific finding, kept under <code>also_detected_by</code>, standalone only if alone). Added a <code>rule</code> key to every finding. e.g. WebViewActivity: 4 findings → 1 primary + <code>also_detected_by</code>.</td>
      </tr>
  </tbody>
</table>
<hr>
<h2 id="-testbed-expansion--new-detection-originally-planned-as-a-follow-up-folded-in-here">🧱 Testbed Expansion &amp; New Detection (originally planned as a follow-up, folded in here)</h2>
<p>The originally-planned &ldquo;testbed expansion&rdquo; work was completed and merged into this release, giving the previously pattern-only rules real semantic (Layer-2) ground truth.</p>
<h3 id="13-new-rule-intent_redirection--high--new">[13] New rule: <code>intent_redirection</code> 🟠 HIGH — NEW</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>What</strong></td>
          <td>Detects a <strong>confused-deputy Intent redirection</strong>: an exported component pulls a nested Intent from <code>getParcelableExtra(...)</code> and forwards it (<code>startActivity</code> / <code>startService</code> / <code>sendBroadcast</code>) without validating the target — reaching the app&rsquo;s non-exported components or relaying granted URI permissions.</td>
      </tr>
      <tr>
          <td><strong>Why</strong></td>
          <td>Not covered by <code>intent_spoofing</code>, <code>exported_components</code>, or the deep-link rules. Google Play&rsquo;s App Security Improvement program flags exactly this pattern.</td>
      </tr>
      <tr>
          <td><strong>Wiring</strong></td>
          <td>New <code>intent_redirection.yaml</code> (rich template) + <code>RulesSettings</code> field (now <strong>26 toggleable rules</strong>, A–Z) + <code>masvs_mapping.json</code> (MASVS-PLATFORM-1) + <code>settings.yaml</code> entry + Layer-1 golden coverage. <code>detection_pattern: getParcelableExtra\s*[(&lt;]</code> — matches Kotlin source, JADX Java, and Smali.</td>
      </tr>
  </tbody>
</table>
<h3 id="14-testbed-grown-to-vulnerappdlh-v2--golden-layer-2-is-now-2525--new">[14] Testbed grown to VulnerAppDLH v2 → Golden Layer 2 is now 25/25 🟢 NEW</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>What</strong></td>
          <td><code>VulnerAppDLH</code> was extended in place to <strong>v2.0.0</strong> with 8 new vulnerable modules: <code>insecure_deserialization</code>, <code>unsafe_reflection</code>, <code>pending_intent_hijacking</code>, <code>zip_slip</code>, <code>intent_redirection</code>, <code>fragment_injection</code>, <code>strandhogg</code> (now a real TP), and <code>hardcoded_secrets_xml</code>. The Layer-2 harness + baseline now target <strong><code>VulnerAppDLHv2.apk</code></strong>.</td>
      </tr>
      <tr>
          <td><strong>Result</strong></td>
          <td>Recall floor raised <strong>16 → 25</strong> and <strong>verified 25/25</strong> with <code>moonshotai/kimi-k3</code> (precision green, 0 errors). <code>strandhogg</code> moved from negative-control → real TP; <code>hardcoded_secrets</code> on <code>WebViewActivity</code> (a real <code>getSecrets()</code> token the v1 baseline had omitted) was added. Only <code>jetpack_compose_security</code> still lacks semantic coverage (needs a Compose app — deferred).</td>
      </tr>
  </tbody>
</table>
<h3 id="15-engine-static-pattern-hits-bypass-the-llm-risk-triage--critical-recall">[15] Engine: static-pattern hits bypass the LLM risk-triage 🔴 CRITICAL (recall)</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td>In <code>hybrid</code> mode the LLM risk-triage (<code>identify_risky_chunks</code>) can drop a genuinely vulnerable file <em>before</em> rule gating. It dropped <code>ZipSlipActivity</code> even though the <code>zip_slip</code> <code>detection_pattern</code> matched — so no rule ever ran on it.</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td>New <code>Engine._pattern_matched_files()</code>: <strong>first-party</strong> files whose content matches an enabled rule&rsquo;s <code>detection_pattern</code> are deep-scanned regardless of the triage verdict (a static hit is a strong signal). Scoped to the app package so added cost stays bounded to first-party code; library files still go through the normal triage.</td>
      </tr>
  </tbody>
</table>
<h3 id="16-pending_intent_hijacking-match-the-jadx-inlined-flag--high">[16] <code>pending_intent_hijacking</code>: match the JADX-inlined flag 🟠 HIGH</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td>JADX inlines <code>PendingIntent.FLAG_MUTABLE</code> to its integer value <code>33554432</code>, so the literal-only pattern missed <code>PendingIntentActivity</code>.</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td><code>detection_pattern</code> now matches <code>(FLAG_MUTABLE|33554432)</code> (+ Layer-1 test). Same class of decompiler-inlining issue as <code>MODE_WORLD_READABLE</code>→<code>1</code>.</td>
      </tr>
  </tbody>
</table>
<h3 id="17-system-prompt-analysis-rules-refined--reachability-vs-flaw--high">[17] System-prompt analysis rules refined — reachability vs. flaw 🟠 HIGH</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td><code>system_prompt.txt</code>&rsquo;s rule <em>&ldquo;Do not assume context outside the provided snippet&rdquo;</em> made the model blind to manifest-level facts (is the component <code>exported</code>?), so IPC rules hedged or risked false negatives — visible in an <code>intent_redirection</code> scan where the model wrote <em>&ldquo;the AndroidManifest is not provided, so exported status cannot be confirmed&rdquo;</em>.</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td>Rewrote RULES FOR ANALYSIS to (1) <strong>use ALL provided context</strong> (manifest excerpt, cross-references); (2) <strong>separate the flaw (<code>is_vulnerable</code>) from its reachability (<code>confidence</code>)</strong> — but only when the vulnerable pattern is otherwise complete and the sole unknown is reachability; (3) keep <code>evidence</code> minimal. Recall-first, without loosening the &ldquo;distinct evidence / tainted source&rdquo; bar.</td>
      </tr>
  </tbody>
</table>
<h3 id="18-manifest-reachability-injected-into-the-deep-scan--get_component_details-bug-fix--high">[18] Manifest reachability injected into the deep-scan (+ <code>get_component_details</code> bug fix) 🟠 HIGH</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>What</strong></td>
          <td>New <code>Engine._manifest_context_for()</code> injects the analyzed class&rsquo;s AndroidManifest entry (exported status, permission, intent-filters) into the LLM input for code rules — so IPC/exported-dependent rules (<code>intent_redirection</code>, <code>pending_intent_hijacking</code>, <code>fragment_injection</code>, …) get <strong>authoritative reachability</strong> instead of guessing. Kept out of the pattern-gating input (LLM-only) so gating is unaffected.</td>
      </tr>
      <tr>
          <td><strong>Bug fixed</strong></td>
          <td><code>ManifestParser.get_component_details()</code> used ElementTree Element truthiness (<code>if target_node:</code> / <code>if not self.root:</code>); an element with <strong>no children</strong> is falsy, so any component declared without an <code>&lt;intent-filter&gt;</code> (e.g. <code>IntentRedirectionActivity</code>) wrongly returned <code>{}</code> (&ldquo;not found&rdquo;). Now compared with <code>is not None</code>. + Layer-1 regression tests.</td>
      </tr>
  </tbody>
</table>
<hr>
<h2 id="-new-llm-provider">🔌 New LLM Provider</h2>
<h3 id="19-9router-support-router9--new">[19] 9Router support (<code>router9</code>) 🟢 NEW</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>What</strong></td>
          <td>Added <code>router9</code> as a 7th LLM provider: a <strong>self-hosted, OpenAI-compatible LLM router</strong> that fans out to many providers/models behind one local endpoint via a provider-prefixed model name (e.g. <code>gc/gemini-2.5-pro</code> routes through to Gemini). New <code>modules/llm_client/router9.py</code> (<code>Router9Client</code>); wired into <code>LLMSettings</code> (<code>router9_model</code>, <code>router9_api_key</code>, <code>router9_base_url</code>), <code>Engine._setup_llm_client</code>, the <code>config wizard</code>/<code>config model</code> CLI, and <code>settings.yaml</code>.</td>
      </tr>
      <tr>
          <td><strong>Streaming quirk handled</strong></td>
          <td>9Router&rsquo;s <code>/v1/chat/completions</code> endpoint returns a <strong>Server-Sent Events (SSE) stream</strong> (<code>Content-Type: text/event-stream</code>, <code>data: {...}</code> chunks) even for a plain request with no <code>&quot;stream&quot;</code> key set — unlike every other OpenAI-compatible client in this codebase, which expects one JSON body. <code>Router9Client</code> detects this via the <code>Content-Type</code> header and accumulates <code>delta.content</code> fragments across chunks, falling back to a normal single-JSON parse if the router ever returns one. Verified against a real, running 9Router instance during development (not just a synthetic test).</td>
      </tr>
      <tr>
          <td><strong>Operational finding</strong></td>
          <td>Routing to a <strong>reasoning-capable model</strong> (e.g. <code>gemini-2.5-pro</code>) burns part of the <code>max_tokens</code> budget on hidden <code>reasoning_tokens</code> before any visible output — confirmed live: with <code>max_tokens: 200</code> the model returned only a fragment (<code>finish_reason: &quot;length&quot;</code>, <code>reasoning_tokens: 190</code>), while <code>max_tokens: 4096</code> completed correctly. Documented in <code>settings.yaml</code>&rsquo;s inline comment and <code>CONFIGURATION.md</code> (same class of issue as OpenRouter&rsquo;s <code>kimi-k3</code> needing <code>8192</code>).</td>
      </tr>
      <tr>
          <td><strong>Tests</strong></td>
          <td>5 new Layer-1 tests: SSE parsing against the <em>exact</em> chunk shape observed from the real router, malformed-line skipping, <code>[DONE]</code> termination, empty-stream handling, and brace-safe prompt construction. Config test asserts the 3 new <code>LLMSettings</code> fields exist.</td>
      </tr>
  </tbody>
</table>
<hr>
<h2 id="-report-quality">📝 Report Quality</h2>
<h3 id="20-app_summary-rewritten-for-information-density--medium">[20] <code>app_summary</code> rewritten for information density 🟡 MEDIUM</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td>The executive-summary prompt asked for a &ldquo;comprehensive summary&rdquo; with no length or format constraint. Real reports showed ~1000-1600 tokens of markdown essay (headers, tables, repeated disclaimers, and an exhaustive list of <em>absent</em> dangerous permissions) — low information density for a field meant to orient a reviewer in seconds.</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td><code>app_summary_prompt.txt</code> rewritten: explicit 120-180 word budget, bullet points only (no headers/tables), report only permissions actually present (don&rsquo;t enumerate absent ones), no closing disclaimer, and the <strong>exported attack surface prioritized</strong> as the most report-relevant section. Verified live against the real <code>VulnerAppDLHv2</code> manifest: output dropped to ~360 tokens with no loss of security-relevant content. Confirmed <code>app_summary</code> is report-only (never re-injected as LLM context elsewhere), so this is a pure report-quality change with no detection-side risk. + Layer-1 format-safety test.</td>
      </tr>
  </tbody>
</table>
<h3 id="21-attack_surface_map-changed-from-narrative-essay-to-structured-json-inventory--high">[21] <code>attack_surface_map</code> changed from narrative essay to structured JSON inventory 🟠 HIGH</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td>With <code>generate_attack_surface_map: true</code>, the prompt asked for a free-text &ldquo;attack surface map&rdquo; with no schema or format constraint, and the engine stored the raw LLM text verbatim. A real scan produced <strong>~16,000 characters (~4,000 tokens)</strong> of markdown — numbered sections, a full table re-describing every exported activity, ADB example commands, and repeated impact narration that duplicates what the per-file vulnerability findings already say in detail.</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td><code>attack_surface_prompt.txt</code> rewritten to demand a <strong>flat JSON inventory only</strong> (no prose, no markdown, no impact commentary): <code>exported_activities</code>/<code>exported_receivers</code>/<code>exported_services</code>/<code>exported_providers</code> (short names), <code>deep_links</code> (scheme/host/handler triples), <code>unprotected_broadcasts</code>, <code>network</code>/<code>file_io</code>/<code>ipc</code>/<code>deserialization</code>/<code>reflection</code> boolean/tag signals, and <code>manifest_flags</code>. <code>Engine.generate_attack_surface_map</code> now parses the response into a real dict (<code>_parse_llm_response</code>, reused) instead of storing raw text, and returns <code>{&quot;error&quot;: ...}</code> on an empty/unparseable response instead of silently returning nothing. A downstream report renderer is expected to turn this data into bullets/tables.</td>
      </tr>
      <tr>
          <td><strong>Result</strong></td>
          <td>Verified live against the real <code>VulnerAppDLHv2</code> manifest: <strong>~16,000 chars → ~900 chars (~230 tokens)</strong>, a <strong>~17.8x reduction</strong>, with the schema populated correctly (including the correct nuance that <code>ProfileInstallReceiver</code> — protected by the <code>DUMP</code> permission — was excluded from <code>unprotected_broadcasts</code>). Also verified working through the new <code>router9</code> provider with a different model. + 3 Layer-1 tests (success, empty-response, unparseable-response) + a format-safety test.</td>
      </tr>
  </tbody>
</table>
<hr>
<h2 id="-exploit-generation-robustness">🛠️ Exploit Generation Robustness</h2>
<h3 id="22-exploit-prompt-reframed-with-authorization-context--high">[22] Exploit prompt reframed with authorization context 🟠 HIGH</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td><code>--generate-exploit</code> silently returned nothing for some models: <code>exploit_prompt.txt</code> opened with <code>ROLE: Android Security Researcher &amp; Exploit Developer</code> and asked to &ldquo;Generate the PoC Code&rdquo; with no authorization/defensive framing at all — a pattern prone to safety refusals (observed as an empty response, not an explicit refusal string, after ~45-50s — consistent with a reasoning model spending its budget deciding not to comply).</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td>Added an explicit <code>AUTHORIZATION CONTEXT</code> paragraph up front (this is an authorized, sandboxed assessment; the finding was already confirmed by static analysis; the script is for a remediation/QA team, not for discovering new targets), and reframed offensive vocabulary to verification/defensive language throughout (<code>Exploit Developer</code> → <code>Security Verification Engineer</code>, &ldquo;demonstrate a vulnerability&rdquo; → &ldquo;reproduce an already-confirmed finding&rdquo;, &ldquo;API exploitation&rdquo; → &ldquo;API interaction&rdquo;, <code>Generate the PoC Code now</code> → <code>Generate the verification script now</code>). All anti-hallucination constraints and the strict output-format rules were kept unchanged.</td>
      </tr>
      <tr>
          <td><strong>Result</strong></td>
          <td>Verified live on the <code>intent_redirection</code> finding that previously failed: <strong>Anthropic <code>claude-opus-4-6</code> now succeeds</strong> (a complete ADB verification script). One specific reasoning model routed through <code>router9</code> still returned empty even with this fix — confirming the refusal is model-specific, not a wording problem in general, and motivating [23] below.</td>
      </tr>
  </tbody>
</table>
<h3 id="23-per-stage-llm-routing-exploit_provider--exploit_model--high--new">[23] Per-stage LLM routing: <code>exploit_provider</code> / <code>exploit_model</code> 🟠 HIGH — NEW</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>What</strong></td>
          <td>New optional <code>llm.exploit_provider</code> / <code>llm.exploit_model</code> settings let <code>--generate-exploit</code> use a <strong>different provider/model than scanning</strong> — e.g. keep a strong reasoning model for vulnerability analysis, but route exploit-gen to a provider known to comply (per [22], some models still refuse regardless of prompt wording). Neither field re-declares credentials: <code>exploit_provider: anthropic</code> reuses that provider&rsquo;s <em>own</em> <code>anthropic_api_key</code>/<code>anthropic_model</code> already in <code>settings.yaml</code>. Both unset → identical to pre-existing behavior.</td>
      </tr>
      <tr>
          <td><strong>Engine change</strong></td>
          <td><code>Engine._setup_llm_client</code> split into an orchestrator plus a reusable <code>_build_llm_client(provider, model_override=None)</code> (no new LLM-client code — reuses all 7 existing clients). <code>self.exploit_llm_client</code> aliases <code>self.llm_client</code> unless a separate client is actually needed, and is built <strong>only when <code>--generate-exploit</code> is requested</strong> — a typo&rsquo;d <code>exploit_provider</code> can never break a normal scan. Building it is wrapped in try/except: on failure, logs a warning and falls back to the main provider/model rather than crashing. The end-of-run cache-effectiveness log now merges hits/misses from both clients when they differ. <code>_generate_poc</code> now calls <code>self.exploit_llm_client</code> instead of <code>self.llm_client</code>.</td>
      </tr>
      <tr>
          <td><strong>Result</strong></td>
          <td>Verified live end-to-end: main provider stayed on <code>router9</code>/<code>jem/glm-5.2</code> for scanning while <code>exploit_provider: anthropic</code> (set in memory, not written to <code>settings.yaml</code>) routed exploit-gen to <code>claude-opus-4-6</code> — which produced a complete verification script for the exact <code>intent_redirection</code> case that returned empty via <code>router9</code> alone. + 7 Layer-1 tests (model-override resolution, default-to-main, skip-when-disabled, separate-provider routing, model-only override, and safe fallback on a bad provider name).</td>
      </tr>
      <tr>
          <td><strong>Adopted</strong></td>
          <td><code>exploit_provider: anthropic</code> was then set in the real <code>config/settings.yaml</code> and confirmed working on a live <code>--generate-exploit</code> run (main scan stayed on <code>router9</code>; PoC generation succeeded via Anthropic where it had previously returned empty).</td>
      </tr>
  </tbody>
</table>
<h3 id="24-poc-file-extension-misdetected-when-a-script-embeds-another-language--high">[24] PoC file extension misdetected when a script embeds another language 🟠 HIGH</h3>
<table>
  <thead>
      <tr>
          <th></th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Problem</strong></td>
          <td><code>_generate_poc</code>&rsquo;s extension detection scanned the ENTIRE PoC content for signal substrings (<code>&quot;import &quot;</code>, <code>&quot;def &quot;</code>, <code>&quot;Java.perform&quot;</code>, &hellip;) with no priority given to the script&rsquo;s own shebang. A live-generated PoC was a single, valid, directly-executable <code>#!/bin/bash</code> script that embedded a <code>python3 - &lt;&lt; 'EOF' ... EOF</code> heredoc (to run background logcat monitoring, which Bash can&rsquo;t easily do alone) — a legitimate shell-scripting pattern, not the model ignoring the &ldquo;pick ONE format&rdquo; instruction. Because the heredoc&rsquo;s body contains <code>&quot;import &quot;</code>/<code>&quot;def &quot;</code>, the whole-content scan misclassified this Bash script as <code>.py</code>, producing a file that fails if executed as Python.</td>
      </tr>
      <tr>
          <td><strong>Fix</strong></td>
          <td>Extracted the detection logic into <code>Engine._detect_poc_extension()</code> and made the <strong>first line</strong> (the shebang, or the opening token for Frida JS/HTML) authoritative — checked BEFORE any whole-content scan, since that&rsquo;s literally what <code>exploit_prompt.txt</code> already instructs the model to emit there, and what the OS actually uses to run the file. Whole-content sniffing is now only a fallback for the rare case a response doesn&rsquo;t start with a recognized signal.</td>
      </tr>
      <tr>
          <td><strong>Result</strong></td>
          <td>The real misclassified file (bash+heredoc) now correctly resolves to <code>.sh</code>; a similar bash+embedded-Frida-JS case from earlier testing also now resolves to <code>.sh</code>. Existing pure Python/JS/HTML detection unchanged. + 7 Layer-1 tests, including the exact bash+heredoc fixture as a named regression guard.</td>
      </tr>
  </tbody>
</table>
<hr>
<h2 id="-summary">✅ Summary</h2>
<ul>
<li><strong>Golden Test Layer 2</strong> added — real scans assert a recall contract; opt-in + CI-gated.</li>
<li><strong>All rule prompts standardized</strong> — JSON-only output, language-agnostic wording, rich taint-reasoning template, uniform wrappers.</li>
<li><strong>New rule <code>intent_redirection</code></strong> (confused-deputy IPC) → <strong>26 toggleable rules</strong>.</li>
<li><strong>Testbed expanded to VulnerAppDLH v2.0.0</strong> (8 new modules) → Golden Layer 2 recall <strong>verified 25/25</strong> (precision green, 0 errors).</li>
<li><strong>Detection/engine fixes</strong>: <code>strandhogg</code> leak removed; 2 v1 recall gaps closed; <code>path_traversal</code>/<code>graphql</code>/<code>universal_logic_flaw</code> patterns redesigned; 4 patterns dual-language; <code>pending_intent</code> now matches JADX-inlined <code>FLAG_MUTABLE</code>; <strong>first-party static-pattern hits now bypass the LLM risk-triage</strong> (recall fix).</li>
<li><strong>Report de-duplication</strong> collapses overlapping findings without losing data.</li>
<li><strong>Manifest-aware reachability</strong>: IPC/exported-dependent rules no longer guess reachability; the system prompt separates flaw-from-reachability instead of silently hedging.</li>
<li><strong>New 7th LLM provider <code>router9</code></strong> (9Router, self-hosted multi-model router) — handles its unusual SSE-streaming responses and documents a <code>max_tokens</code>/reasoning-token gotcha found via live testing.</li>
<li><strong><code>app_summary</code> report field made dense</strong>: ~1000-1600 token essay → ~360 tokens, same security content, exported attack surface prioritized.</li>
<li><strong><code>attack_surface_map</code> changed from a ~4000-token narrative essay to a ~230-token structured JSON inventory</strong> (exported components, deep links, network/IPC/file-io signals) — a ~17.8x reduction, verified live.</li>
<li><strong>Exploit-generation robustness</strong>: <code>exploit_prompt.txt</code> reframed with authorization context (fixes some model refusals); new <code>llm.exploit_provider</code>/<code>exploit_model</code> routes <code>--generate-exploit</code> to a different, known-permissive provider when a model still refuses — verified live to turn an empty PoC into a working one; PoC file-extension detection now trusts the script&rsquo;s own shebang over whole-content keyword scanning, fixing a live-observed misclassification of a valid Bash+heredoc script as <code>.py</code>.</li>
<li><strong>Every change Layer-2 verified</strong> to not regress detection. Layer 1 = <strong>91 tests</strong>.</li>
<li><strong>Still uncovered</strong>: <code>jetpack_compose_security</code> (needs a Compose app — planned separately). Future work is split into <strong><code>Update v1.3.1</code></strong> (&ldquo;The Obfuscation Update&rdquo;) and <strong><code>Update v1.3.2 </code></strong> (&ldquo;The Supply Chain Update&rdquo; — library deep scan).</li>
</ul>
<hr>
<img width="1246" height="937" alt="Screenshot from 2026-07-31 09-07-23" src="https://github.com/user-attachments/assets/753c1bf4-c9ae-4001-82ed-8c061a02157f" />
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/custom-amazon-bedrock-agent-action/</link><pubDate>Mon, 03 Aug 2026 15:07:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.10.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action leverages Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback. It is highly customizable, allowing users to tailor analysis based on specific requirements and integrates with Amazon Bedrock Knowledge Bases for enriched insights. Key features include tailored agent analysis, file ignoring, AI-powered insights, language-agnostic support, and seamless integration into GitHub workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action leverages Amazon Bedrock Agent to analyze files in a pull request (PR) and provide feedback. It is highly customizable, allowing users to tailor analysis based on specific requirements and integrates with Amazon Bedrock Knowledge Bases for enriched insights. Key features include tailored agent analysis, file ignoring, AI-powered insights, language-agnostic support, and seamless integration into GitHub workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/29</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/30</a></li>
<li>Support push events by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/31</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.9.0...v0.10.0</a></p>
]]></content:encoded></item><item><title>pi GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/pi-github-action/</link><pubDate>Mon, 03 Aug 2026 15:06:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/pi-github-action/</guid><description>Version updated for https://github.com/shaftoe/pi-coding-agent-action to version v2.27.0.
This action is used across all versions by 11 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action integrates the Pi coding agent with GitHub workflows, allowing developers to automate tasks such as issue assistance, PR review, and recurring tasks using Git hosting platforms like GitHub, Codeberg, or self-hosted Forgejo. It provides a familiar CLI interface for running Pi within CI/CD pipelines, offering features like session sharing, auto replies, and integration with GitHub APIs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shaftoe/pi-coding-agent-action">https://github.com/shaftoe/pi-coding-agent-action</a></strong> to version <strong>v2.27.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pi-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action integrates the Pi coding agent with GitHub workflows, allowing developers to automate tasks such as issue assistance, PR review, and recurring tasks using Git hosting platforms like GitHub, Codeberg, or self-hosted Forgejo. It provides a familiar CLI interface for running Pi within CI/CD pipelines, offering features like session sharing, auto replies, and integration with GitHub APIs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="2270---2026-08-03"><a href="https://github.com/shaftoe/pi-coding-agent-action/compare/v2.26.0...v2.27.0">2.27.0</a> - 2026-08-03</h2>
<h3 id="added">Added</h3>
<ul>
<li>dispose Pi sessions after orchestration (#394)</li>
<li>migrate from Bun to Node + Vitest + pnpm (#392)</li>
<li>opt tools into strict sampling, bump Pi to v0.82.1 (#393)</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>deps-ci</strong>: bump actions/setup-node from 6 to 7 (#389)</li>
<li><strong>deps-ci</strong>: bump github/codeql-action from 4 to 4.37.3 (#395)</li>
<li><strong>deps</strong>: update dependencies, Pi to v0.80.10 (#388)</li>
<li><strong>deps</strong>: update dependencies, Pi to v0.81.1 (#390)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>release</strong>: resolve tsx not found in semantic-release prepareCmd (#397)</li>
</ul>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/sherpa.sh/</link><pubDate>Mon, 03 Aug 2026 15:04:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven GitHub Action that simplifies cloud infrastructure deployment by allowing developers to describe their needs in plain English. It automates the creation and configuration of servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more, making it easier for developers to focus on writing code rather than managing infrastructure configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven GitHub Action that simplifies cloud infrastructure deployment by allowing developers to describe their needs in plain English. It automates the creation and configuration of servers, DNS, SSL certificates, CDN, databases, backups, load balancing, and more, making it easier for developers to focus on writing code rather than managing infrastructure configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>create-agent-room Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/create-agent-room-validate/</link><pubDate>Mon, 03 Aug 2026 15:03:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/create-agent-room-validate/</guid><description>Version updated for https://github.com/sipandey/create-agent-room to version v2.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates agent governance rules by enforcing them at multiple layers (agent work, commit, CI, compliance) with shared stop hooks and pre-commit guardrails. It helps prevent common mistakes during agent turns, commits, and builds while providing a clear documentation of governance practices. The action ensures that agents log decisions or use valid waivers when editing files or committing code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipandey/create-agent-room">https://github.com/sipandey/create-agent-room</a></strong> to version <strong>v2.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/create-agent-room-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates agent governance rules by enforcing them at multiple layers (agent work, commit, CI, compliance) with shared stop hooks and pre-commit guardrails. It helps prevent common mistakes during agent turns, commits, and builds while providing a clear documentation of governance practices. The action ensures that agents log decisions or use valid waivers when editing files or committing code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Layer 4 by default:</strong> <code>init --tools git</code> scaffolds <code>create-agent-room eval</code> in CI alongside <code>validate</code> and <code>lint-sessions</code></li>
<li><strong>JavaScript stack template</strong> for the default <code>--language javascript</code> path</li>
<li><strong>Docs refresh:</strong> comparisons.md updated for v2.3.0+; README/CAPABILITIES/enforcement-model aligned</li>
<li><strong>Launch playbooks</strong> in <code>docs/launch/</code> (Show HN, Marketplace, community posts, awesome lists)</li>
</ul>
<h2 id="try-it">Try it</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx create-agent-room@latest init . --yes --tools git,cursor --git
</span></span></code></pre></div><p>Full changelog: <a href="https://github.com/sipandey/create-agent-room/blob/v2.3.1/CHANGELOG.md">CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Mon, 03 Aug 2026 15:02:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service. It ensures that all necessary dependencies are installed and bundled before committing the dist folder to version control, thereby preparing it for deployment to a Docker Swarm cluster.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service. It ensures that all necessary dependencies are installed and bundled before committing the <code>dist</code> folder to version control, thereby preparing it for deployment to a Docker Swarm cluster.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>GitGalaxy Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/gitgalaxy-scanner/</link><pubDate>Mon, 03 Aug 2026 15:02:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/gitgalaxy-scanner/</guid><description>Version updated for https://github.com/squid-protocol/gitgalaxy to version v2.4.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Gitgalaxy is a tool that automates the assessment of full repositories, identifying security risks and refactoring targets. It uses a custom regex/lexical structural-analysis engine to analyze code without requiring compilation and provides detailed reports and visualizations, helping developers prioritize tasks and improve their code quality.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/squid-protocol/gitgalaxy">https://github.com/squid-protocol/gitgalaxy</a></strong> to version <strong>v2.4.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gitgalaxy-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Gitgalaxy is a tool that automates the assessment of full repositories, identifying security risks and refactoring targets. It uses a custom regex/lexical structural-analysis engine to analyze code without requiring compilation and provides detailed reports and visualizations, helping developers prioritize tasks and improve their code quality.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-gitgalaxy-v246-the-structural-hardening-update">🚀 GitGalaxy v2.4.6: The Structural Hardening Update</h1>
<p>We are incredibly excited to announce the release of GitGalaxy v2.4.6. This release represents a monumental milestone in the maturity of our core extraction engine. Over the past cycle, we initiated a comprehensive lockdown of our line-by-line regex parsing architecture across all supported languages.</p>
<p>GitGalaxy has officially transitioned from a &ldquo;best-effort parser&rdquo; to a production-grade, mathematically verified forensic security engine.</p>
<h3 id="-the-hardening-effort-from-700-to-5468-tests">🛡️ The Hardening Effort: From 700 to 5,468 Tests</h3>
<p>Our extraction engine was built for blistering speed (~35,000 LOC/s) and absolute ReDoS immunity, relying on strict horizontal (<code>re.M</code>) matching boundaries rather than slow, brittle AST parsers. But at scale, speed means nothing without precision.</p>
<p>When we started this initiative, we relied on a baseline of ~700 tests. As of today, the GitGalaxy extraction suite boasts a massive <strong>5,468 highly-constrained test cases</strong>.</p>
<p>Through Epic #813 and Epic #518, we individually audited, isolated, and hardened the structural signatures—Dependencies, Functions, Classes, and Arguments—for <strong>all 54 supported languages</strong>.</p>
<h3 id="-our-methodology-the-pathological-gauntlet">🧪 Our Methodology: The Pathological Gauntlet</h3>
<p>We didn&rsquo;t just write &ldquo;happy path&rdquo; tests. We threw the kitchen sink at our regex engine to see where it would break. For every single core Phase 1 rule across all 54 languages, we enforced a strict multi-tier testing standard:</p>
<ol>
<li><strong>Idiomatic Validation:</strong> Ensuring that standard, real-world code conventions (like Apex decorators, Python generics, or Ruby yields) are captured flawlessly.</li>
<li><strong>Negative &amp; Ambiguity Testing:</strong> Ensuring the engine cleanly rejects lookalike tokens and doesn&rsquo;t get confused when a language shares a keyword between two structural rules.</li>
<li><strong>Pathological Survival (The Red Team):</strong> We intentionally fed the engine adversarial, edge-case formats. We injected extreme vertical formatting, deep ReDoS-inducing generic nesting (e.g., <code>List[List[...</code>), and macro-like syntax traps to ensure our engine either parsed them safely or rejected them cleanly.</li>
</ol>
<p>We systematically eliminated dangerous <code>\s+</code> cross-line bridges that allowed logic to &ldquo;leak&rdquo; across lines, replacing them with strictly bounded horizontal whitespace <code>[ \t]+</code>.</p>
<h3 id="-absolute-truth-via-the-golden-crucible">⚖️ Absolute Truth via the Golden Crucible</h3>
<p>To guarantee that these strict theoretical boundaries didn&rsquo;t accidentally break real-world functionality, we utilized our <code>crucible_check.py</code> audit system. Every single regex tweak was cross-referenced against a &ldquo;Golden Master&rdquo; manifest of our entire test corpus.</p>
<p>We confirmed that our fixes caused <strong>zero unintended topological drift</strong>. The architectural mass, dependency maps, and structural boundaries of the real-world codebase remain flawlessly intact.</p>
<h3 id="-what-this-means-for-the-future">🌟 What This Means for the Future</h3>
<p>By locking down the parser at this foundational level, we have eradicated the &ldquo;Garbage In, Garbage Out&rdquo; problem for our LLMs. The AI now receives mathematically precise code boundaries, un-polluted by typosquatting or false-positive function signatures.</p>
<p>GitGalaxy is now ready to perform advanced vulnerability graphing, logic-bomb detection, and threat analysis with absolute, verifiable confidence.</p>
]]></content:encoded></item><item><title>CodeMoat AI Code Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/codemoat-ai-code-security-scanner/</link><pubDate>Mon, 03 Aug 2026 15:01:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/codemoat-ai-code-security-scanner/</guid><description>Version updated for https://github.com/SYCO7/codemoat to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary CodeMoat is a GitHub Action designed to scan AI-generated code for security vulnerabilities, including hardcoded secrets and injection flaws. It uses Semgrep and Gitleaks to detect these vulnerabilities and provides actionable fixes through pull request comments. The action wraps two established open-source engines and adds an AI ruleset targeting specific patterns common in AI-generated code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SYCO7/codemoat">https://github.com/SYCO7/codemoat</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codemoat-ai-code-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>CodeMoat is a GitHub Action designed to scan AI-generated code for security vulnerabilities, including hardcoded secrets and injection flaws. It uses Semgrep and Gitleaks to detect these vulnerabilities and provides actionable fixes through pull request comments. The action wraps two established open-source engines and adds an AI ruleset targeting specific patterns common in AI-generated code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Security scanner for AI-generated code. Runs on every pull request, scans only
the changed files, and posts one updating comment with each finding&rsquo;s severity,
CWE, a suggested fix, and a confidence score from its triage model — so real
issues rise and test-fixture noise sinks.</p>
<p>Wraps Semgrep + Gitleaks and adds 12 rules targeting the mistakes AI coding
agents actually make: wildcard CORS with credentials, auth middleware commented
out &ldquo;temporarily&rdquo;, forgotten debug routes, weak seeded credentials, and more.</p>
<p>No account required. Runs fully self-contained in your CI.</p>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/setup-tombi/</link><pubDate>Mon, 03 Aug 2026 15:00:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.6.
This action is used across all versions by 142 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up the Tombi CLI in your workflow by installing a specific version, resolving from a lock file, and optionally verifying checksums. It supports various platforms and cache behaviors to optimize performance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.2.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>142</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up the Tombi CLI in your workflow by installing a specific version, resolving from a lock file, and optionally verifying checksums. It supports various platforms and cache behaviors to optimize performance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.2.6">tombi v1.2.6</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.6">https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.6</a></p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/wails3-build-action/</link><pubDate>Mon, 03 Aug 2026 14:58:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of building Wails.io projects using GoLang and NodeJS. It installs necessary tools, builds the project for specified platforms, and optionally uploads the results to GitHub or a release on tag. The action supports various configuration options such as specifying the build name, platform, and whether to upload artifacts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of building Wails.io projects using GoLang and NodeJS. It installs necessary tools, builds the project for specified platforms, and optionally uploads the results to GitHub or a release on tag. The action supports various configuration options such as specifying the build name, platform, and whether to upload artifacts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>Railway Image Bump</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/railway-image-bump/</link><pubDate>Mon, 03 Aug 2026 14:57:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/railway-image-bump/</guid><description>Version updated for https://github.com/twopow/railway-deploy-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a new container image to a Railway service in a shared project. It pins the Railway CLI release, resolves service and environment names to IDs, updates the service instance’s image, triggers the deploy, waits for it to complete, and provides outputs for deployment ID, service ID, and environment ID. It supports specifying an optional environment name and handling different types of tokens.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/twopow/railway-deploy-action">https://github.com/twopow/railway-deploy-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/railway-image-bump">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a new container image to a Railway service in a shared project. It pins the Railway CLI release, resolves service and environment names to IDs, updates the service instance&rsquo;s image, triggers the deploy, waits for it to complete, and provides outputs for deployment ID, service ID, and environment ID. It supports specifying an optional environment name and handling different types of tokens.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/twopow/railway-deploy-action/commits/v1">https://github.com/twopow/railway-deploy-action/commits/v1</a></p>
]]></content:encoded></item><item><title>aicheck-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/aicheck-scan/</link><pubDate>Mon, 03 Aug 2026 14:56:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/aicheck-scan/</guid><description>Version updated for https://github.com/unauthdev/aicheck-scan to version v1.1.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks if a PR ships an AI service with no authentication and fails the build if so. It uses a live probe to grade the AI stack and reports the results in SARIF format, providing fix cards for each exposed service. The action supports various installation methods including pip CLI, GitHub Actions, Docker, and a site scanner.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/unauthdev/aicheck-scan">https://github.com/unauthdev/aicheck-scan</a></strong> to version <strong>v1.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aicheck-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks if a PR ships an AI service with no authentication and fails the build if so. It uses a live probe to grade the AI stack and reports the results in SARIF format, providing fix cards for each exposed service. The action supports various installation methods including pip CLI, GitHub Actions, Docker, and a site scanner.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Code QA fixes: dual-stack/IPv6 no longer silent grade-A; Chroma v1/v2 selected by success; filtered <code>--services</code> summaries no longer claim a clean estate.</p>
<p>Also: SARIF-with-findings exercised in selftest; trust/README version-check honesty; Gradio/Langflow fix cards in loop_qa crawl.</p>
<p>Install:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">unauthdev/aicheck-scan@v1</span>
</span></span></code></pre></div><p>or pin <code>@v1.1.4</code>.</p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/vibgrate-scan/</link><pubDate>Mon, 03 Aug 2026 14:55:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.803.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates local codebase intelligence tasks, including generating a deterministic code graph and drift score for AI coding agents. It provides features such as runtime/framework lag, dependency age, and EOL proximity to help identify potential issues in the codebase. The action runs on your machine without relying on API keys or network calls, ensuring no data leaves your repository unless explicitly pushed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.803.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates local codebase intelligence tasks, including generating a deterministic code graph and drift score for AI coding agents. It provides features such as runtime/framework lag, dependency age, and EOL proximity to help identify potential issues in the codebase. The action runs on your machine without relying on API keys or network calls, ensuring no data leaves your repository unless explicitly pushed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268033">Vibgrate CLI 2026.803.3</h1>
<p><em>Released 2026-08-03</em></p>
<p>This release of the Vibgrate CLI includes improvements to task capsule seed ranking and fixes for the <code>vg lsp</code> command to enhance usability and performance.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="improved">Improved</h3>
<ul>
<li>Task Capsule seed ranking now understands conversational follow-ups in <code>vg code</code>, allowing for better context retention and interpretation.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>vg lsp</code> no longer allows a cold semantic index to keep an editor Ask open indefinitely, with improved handling for time budgets and progress reporting.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.803.1, interleaved on one runner against the pinned corpus (189 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21381 count</td>
          <td>21381 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>10551 count</td>
          <td>10551 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.94 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>688.60 ms</td>
          <td>691.30 ms</td>
      </tr>
  </tbody>
</table>
<p>3 regression(s) — published, not omitted:</p>
<ul>
<li>Ask quality — relevance module active (full corpus): 1 → 1.00 (-0.2%)</li>
<li>Tasks passed on both arms: 33 → 31 (-6.1%)</li>
<li>Comparable-task rate (both arms passed / total): 0.94 → 0.89 (-6.1%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.803.3">https://vibgrate.com/changelog/cli/2026.803.3</a></p>
]]></content:encoded></item><item><title>Picket Secret Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/picket-secret-scanner/</link><pubDate>Mon, 03 Aug 2026 14:53:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/picket-secret-scanner/</guid><description>Version updated for https://github.com/willibrandon/picket to version v0.2.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Picket, provides a comprehensive secrets scanner for .NET projects that supports Git changes, Hugging Face models, GitLab resources, and integrates with CI/CD tools like GitHub Actions and Azure Pipelines. It offers a command-line interface for scanning files, repositories, and other sources, as well as support for embedding the scanner into applications using dotnet tool packages or AOT-safe libraries.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/willibrandon/picket">https://github.com/willibrandon/picket</a></strong> to version <strong>v0.2.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/picket-secret-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Picket, provides a comprehensive secrets scanner for .NET projects that supports Git changes, Hugging Face models, GitLab resources, and integrates with CI/CD tools like GitHub Actions and Azure Pipelines. It offers a command-line interface for scanning files, repositories, and other sources, as well as support for embedding the scanner into applications using dotnet tool packages or AOT-safe libraries.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release artifacts include SHA-256 checksums, package-size metadata, and GitHub artifact attestations.</p>
]]></content:encoded></item><item><title>Repo Anti-Rot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/repo-anti-rot/</link><pubDate>Mon, 03 Aug 2026 14:53:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/repo-anti-rot/</guid><description>Version updated for https://github.com/YpCIIIaK/repo-janitor to version v1.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Repo Anti-Rot is a repository health and decay monitor that scans codebases for various types of rot such as undocumented environment variables, abandoned dependencies, stale branches, aging TODOs, committed secrets, dead code, disabled tests, and binary bloat. It scores the repository A-F and provides a dashboard with everything in one place. Optionally, it adds an AI pass to provide short, decisive verdicts on each finding via OpenRouter.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YpCIIIaK/repo-janitor">https://github.com/YpCIIIaK/repo-janitor</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repo-anti-rot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Repo Anti-Rot is a repository health and decay monitor that scans codebases for various types of rot such as undocumented environment variables, abandoned dependencies, stale branches, aging TODOs, committed secrets, dead code, disabled tests, and binary bloat. It scores the repository A-F and provides a dashboard with everything in one place. Optionally, it adds an AI pass to provide short, decisive verdicts on each finding via OpenRouter.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release in which the Action can actually be installed. Everything it does
was already built and tested; only the packaging was missing, and it was missing
quietly — the snippet in the README resolved to a manifest that was not at the
repository root, pointing at a bundle that was git-ignored.</p>
<h2 id="what-it-does">What it does</h2>
<ul>
<li>Scans a repository with 26 checks — secrets, vulnerable and abandoned
dependencies, dead code, stale branches, aging TODOs, dead links, CI health,
license risk, duplicated code — and scores it A–F.</li>
<li><code>fail-on: C</code> (or any letter) fails the job at or below that grade.</li>
<li><code>sarif-file:</code> writes SARIF 2.1.0 for <code>github/codeql-action/upload-sarif</code>, so
findings land in Security ▸ Code scanning and inline on PR diffs.</li>
<li><code>comment-on-pr:</code> posts one sticky summary comment, updated in place.</li>
<li>Outputs <code>score</code>, <code>grade</code> and <code>issues</code> for later steps.</li>
<li><code>dashboard-url:</code> + <code>token:</code> upload the report to a self-hosted dashboard.
Optional — the Action is useful with no server at all.</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>: { <span style="color:#f92672">fetch-depth</span>: <span style="color:#ae81ff">0</span> } <span style="color:#75715e"># full history, so finding ages are real</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">YpCIIIaK/repo-janitor@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">D</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">sarif-file</span>: <span style="color:#ae81ff">repo-anti-rot.sarif</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>@<span style="color:#ae81ff">v1 follows the latest v1 release. That is convenient and it is also a</span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">supply-chain risk — this project&#39;s own workflow-security check flags any action</span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">pinned to a moving tag, including this one. Pin the full SHA if you would rather</span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">audit upgrades yourself.</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#66d9ef">No</span> <span style="color:#ae81ff">account, no signup. npx repo-anti-rot scan . runs the same engine locally.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/kover-report-action/</link><pubDate>Mon, 03 Aug 2026 14:51:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.17.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating and reporting code coverage from Kover XML reports in Kotlin/Android projects with support for multi-module projects. It includes features such as multi- module support, flexible discovery methods, configurable thresholds, PR integration with automatic updates, and tracking coverage history with visual ASCII graphs and trend indicators.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v3.1.17</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating and reporting code coverage from Kover XML reports in Kotlin/Android projects with support for multi-module projects. It includes features such as multi- module support, flexible discovery methods, configurable thresholds, PR integration with automatic updates, and tracking coverage history with visual ASCII graphs and trend indicators.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3.1.17: PR #156 - chore(deps): update pnpm to v11.15.1</p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/b.ia-accessibility-checker/</link><pubDate>Mon, 03 Aug 2026 14:50:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility testing in a CI/CD pipeline. It allows companies to define an audience and percentage of WCAG guidelines to meet, focusing on the most critical users. The action uses AI to analyze code and provide feedback if it does not comply with the specified requirements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility testing in a CI/CD pipeline. It allows companies to define an audience and percentage of WCAG guidelines to meet, focusing on the most critical users. The action uses AI to analyze code and provide feedback if it does not comply with the specified requirements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/run-aer-tests/</link><pubDate>Mon, 03 Aug 2026 06:29:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.29.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, “aer,” automates the execution of Apex unit tests locally without requiring an organization or sandbox. It supports running Apex code and tests against a local metadata environment, ensuring that SOQL queries, DML operations, and governor limits are enforced as in Salesforce. The action allows developers to execute anonymous Apex, step through code using interactive debuggers, and integrate with CI/CD pipelines for efficient testing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.29</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, &ldquo;aer,&rdquo; automates the execution of Apex unit tests locally without requiring an organization or sandbox. It supports running Apex code and tests against a local metadata environment, ensuring that SOQL queries, DML operations, and governor limits are enforced as in Salesforce. The action allows developers to execute anonymous Apex, step through code using interactive debuggers, and integrate with CI/CD pipelines for efficient testing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.29</p>
<ul>
<li>
<p>Reject Unrecognized &ndash;feature Values At Flag Parse Time</p>
</li>
<li>
<p>Give Each Flow Get Records Element Its Own Local In The Queueable</p>
</li>
<li>
<p>Read Flow Polymorphic References Only On The Named Branch</p>
</li>
<li>
<p>Accept The Id Field As An Upsert External ID</p>
</li>
<li>
<p>Convert Flow Custom Error, Collection Filter, And Collection Sort Elements</p>
</li>
<li>
<p>Back ConnectApi Feed Posts And Reads With FeedItem Storage</p>
</li>
<li>
<p>Add Health Cloud Care Plan Objects To The Feature Schema</p>
</li>
<li>
<p>Back ConnectApi Feed Comments With FeedComment Storage</p>
</li>
<li>
<p>Resolve $Flow.InterviewGuid And Reserve The bulk Identifier</p>
</li>
<li>
<p>Auto-Enable Features From SObjectField Tokens And Fix Health Cloud Flags</p>
</li>
<li>
<p>Convert The FIND Function In Flow Formulas</p>
</li>
<li>
<p>Back ConnectApi Feed Likes With FeedLike Storage</p>
</li>
<li>
<p>Complete The ConnectApi Feed Element Edit And Delete Path</p>
</li>
<li>
<p>Fix DescribeFieldResult.isDefaultedOnCreate</p>
</li>
<li>
<p>Add UserServicePresence To The Omni-Channel Feature Schema</p>
</li>
<li>
<p>Resolve $Profile And $Organization In Flows And Correct Id Checksums</p>
</li>
<li>
<p>Auto-Enable Enterprise Territory Management From Object References</p>
</li>
<li>
<p>Fix ConnectApi Feed Element Representation</p>
</li>
<li>
<p>Store A Flow Create Records Element&rsquo;s Output As The New Record&rsquo;s Id</p>
</li>
<li>
<p>Include Tabs And Visualforce Pages In Packages</p>
</li>
<li>
<p>Report Package Tabs And Visualforce Pages In List And Unpack</p>
</li>
<li>
<p>Strip Package Namespace From Mock Package Components</p>
</li>
<li>
<p>Convert Flow TRIM, CONTAINS, Text +, And Process Builder Wait Elements</p>
</li>
<li>
<p>Add The Survey Objects Behind SurveySettings.enableSurvey</p>
</li>
<li>
<p>Support Method Declarations In Trigger Bodies</p>
</li>
<li>
<p>Back ConnectApi Chatter Groups With CollaborationGroup Storage</p>
</li>
<li>
<p>Add The Remaining Survey Objects And Filter Them Like Salesforce Does</p>
</li>
<li>
<p>Auto-Enable The Team Selling Objects From Static Apex References</p>
</li>
<li>
<p>Back ConnectApi Group Records And Announcements With Storage</p>
</li>
<li>
<p>Back Chatter Group Membership Requests With Storage</p>
</li>
<li>
<p>Match Flow Null Semantics And Add Subflow, Approval Submit, Fault Support</p>
</li>
<li>
<p>Read Stored Groups From The Chatter Group List And Batch Readers</p>
</li>
<li>
<p>Bind StubProvider handleMethodCall Parameters Positionally</p>
</li>
<li>
<p>Fix Semantics At The Stub Return And JSON Temporal Boundaries</p>
</li>
<li>
<p>Load Minimal Fixtures Instead Of Full Metadata Trees In cmd Tests</p>
</li>
<li>
<p>Add The Health Cloud Assessment Objects</p>
</li>
<li>
<p>Skip Formula Date Validation, Update Flow Collections, Model Modify All Data</p>
</li>
<li>
<p>Store Chatter Group Photos And Enforce Unique Group Names</p>
</li>
<li>
<p>Parse Date.valueOf Fields As Greedy Digit Runs</p>
</li>
<li>
<p>Add The WorkplaceCommandCenter Feature</p>
</li>
<li>
<p>Drop The All-False FieldPermissions Seed And Enforce Row-Existence Semantics</p>
</li>
<li>
<p>Store Chatter Group Membership Roles And Page Group Members</p>
</li>
<li>
<p>Preserve Double Rendering In Implicit Double-To-Decimal Conversions</p>
</li>
<li>
<p>Derive Person Account Runtime Behavior From The Loaded Schema</p>
</li>
<li>
<p>Read And Write A Group&rsquo;s Chatter Email Frequency</p>
</li>
<li>
<p>Support Latitude And Longitude Field Access On System.Location</p>
</li>
<li>
<p>Require Name On List Custom Settings</p>
</li>
</ul>
]]></content:encoded></item><item><title>Oculum Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/oculum-security-scan/</link><pubDate>Mon, 03 Aug 2026 06:28:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/oculum-security-scan/</guid><description>Version updated for https://github.com/OculumDev/oculum-action to version 1.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Oculum Security Scan GitHub Action is an AI-driven security scanner that detects prompt injection, RAG vulnerabilities, and other potential issues in LLM-powered applications. It automates the detection of hardcoded secrets, SQL injection, XSS, and command injection using both traditional SAST techniques and AI-assisted validation. The action supports various scan depths and provides options to filter scans based on criticality and categories. The tool integrates seamlessly with GitHub workflows for continuous security checks and can output detailed findings to PR comments or inline annotations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OculumDev/oculum-action">https://github.com/OculumDev/oculum-action</a></strong> to version <strong>1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oculum-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Oculum Security Scan GitHub Action is an AI-driven security scanner that detects prompt injection, RAG vulnerabilities, and other potential issues in LLM-powered applications. It automates the detection of hardcoded secrets, SQL injection, XSS, and command injection using both traditional SAST techniques and AI-assisted validation. The action supports various scan depths and provides options to filter scans based on criticality and categories. The tool integrates seamlessly with GitHub workflows for continuous security checks and can output detailed findings to PR comments or inline annotations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Early Release of Oculum Security Scanner</p>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/odin-scan-smart-contract-security/</link><pubDate>Mon, 03 Aug 2026 06:26:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically scans smart contracts written in CosmWasm, Solana, and EVM languages. It integrates seamlessly with GitHub workflows, providing real-time vulnerability detection and reporting through PR comments and inline annotations. The action supports multiple platforms and allows users to configure severity thresholds and trigger on-demand scans via comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically scans smart contracts written in CosmWasm, Solana, and EVM languages. It integrates seamlessly with GitHub workflows, providing real-time vulnerability detection and reporting through PR comments and inline annotations. The action supports multiple platforms and allows users to configure severity thresholds and trigger on-demand scans via comments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🎉 Initial Release</p>
<p>AI-powered smart contract security analysis, now integrated directly into your GitHub workflow.</p>
<p>✨ Features</p>
<p>Multi-Platform Support</p>
<ul>
<li>CosmWasm - Rust-based smart contracts for Cosmos SDK</li>
<li>Solana (SVM) - Anchor and native Solana programs</li>
<li>EVM - Solidity and Vyper contracts</li>
<li>Auto-detection - Automatically identifies platform from your repo</li>
</ul>
<p>GitHub Integration</p>
<ul>
<li>Code Scanning - SARIF upload for native security alerts in the Security tab</li>
<li>PR Comments - Severity summary and top findings posted directly on pull requests</li>
<li>Inline Annotations - Critical/high findings appear as errors, medium/low as warnings on diffs</li>
<li>Artifact Upload - Full JSON report available as workflow artifact</li>
</ul>
<p>Customization</p>
<ul>
<li>Severity Thresholds - Fail builds at critical, high, medium, or low severity</li>
<li>Platform Override - Force specific platform detection when auto-detect isn&rsquo;t enough</li>
<li>Timeout Control - Configurable analysis timeout (default: 30 minutes)</li>
<li>Flexible Triggers - Run on push, PR, schedule, or manual dispatch</li>
</ul>
<p>🚀 Quick Start</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Security Scan</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&#39;on&#39;</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">main</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">security-events</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">api-key</span>: <span style="color:#e6db74">&#39;${{ secrets.ODIN_SCAN_API_KEY }}&#39;</span>
</span></span></code></pre></div><p>📋 Requirements</p>
<ul>
<li>Odin Scan Pro subscription - Required for API access</li>
<li>API Key - Generate at <a href="https://odinscan.ai/dashboard/settings">https://odinscan.ai/dashboard/settings</a></li>
<li>GitHub Permissions - contents: read, security-events: write (for SARIF), pull-requests: write (for
comments)</li>
</ul>
<p>🔧 Configuration</p>
<p>All Inputs</p>
<p>| ┌────────────────────┬─────────────────────┬──────────────────────────────────────────────┐ |
| │       Input        │       Default       │                 Description                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ api-key            │ Required            │ Your Odin Scan API key (odin_sk_*)           │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ platform           │ auto                │ Target platform: auto, cosmwasm, solana, evm │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ severity-threshold │ high                │ Fail at: critical, high, medium, low, none   │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ fail-on-findings   │ true                │ Whether to fail workflow on findings         │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ comment-on-pr      │ true                │ Post summary comment on PRs                  │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-sarif       │ true                │ Upload SARIF to Code Scanning                │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ upload-artifact    │ true                │ Upload full report as artifact               │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ timeout            │ 1800                │ Max analysis wait time (seconds)             │ |
| ├────────────────────┼─────────────────────┼──────────────────────────────────────────────┤ |
| │ github-token       │ ${{ github.token }} │ Token for PR comments and SARIF              │ |
| └────────────────────┴─────────────────────┴──────────────────────────────────────────────┘ |</p>
<p>All Outputs</p>
<ul>
<li>analysis-id - Unique analysis identifier</li>
<li>status - Analysis status (completed, failed)</li>
<li>total-findings - Total number of findings</li>
<li>critical-count, high-count, medium-count, low-count - Counts by severity</li>
<li>report-url - Link to full report on Odin Scan</li>
<li>sarif-file - Path to generated SARIF file</li>
</ul>
<p>📝 Example Workflows</p>
<p>Basic (Auto-detect)</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span></code></pre></div><p>EVM with Medium Threshold</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">odin-scan/odin-scan-action@v1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ODIN_SCAN_API_KEY }}</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">platform</span>: <span style="color:#ae81ff">evm</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">severity-threshold</span>: <span style="color:#ae81ff">medium</span>
</span></span></code></pre></div><p>Only on Solidity Changes</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#39;**.sol&#39;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#ae81ff">foundry.toml</span>
</span></span></code></pre></div><p>🔒 Security &amp; Privacy</p>
<ul>
<li>All API communication over HTTPS (TLS 1.2+)</li>
<li>API keys automatically masked in logs</li>
<li>No data stored by the action (stateless)</li>
<li>See <a href="https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md">https://github.com/Odin-Scan/odin-scan-action/blob/main/PRIVACY.md</a> for details</li>
</ul>
<p>📖 Documentation</p>
<ul>
<li>Action README - <a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></li>
<li>Odin Scan Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
<li>Get API Key - <a href="https://app.odinscan.ai/settings">https://app.odinscan.ai/settings</a></li>
</ul>
<p>🐛 Known Limitations</p>
<ul>
<li>Private repos - Requires github-token with repo access</li>
<li>Large repos - May need increased timeout for complex codebases</li>
<li>Code Scanning - Requires GitHub Advanced Security on private repos</li>
</ul>
<p>🙏 Support</p>
<ul>
<li>Issues - <a href="https://github.com/Odin-Scan/odin-scan-action/issues">https://github.com/Odin-Scan/odin-scan-action/issues</a></li>
<li>Email - <a href="mailto:support@odinscan.ai">support@odinscan.ai</a></li>
<li>Docs - <a href="https://docs.odinscan.ai">https://docs.odinscan.ai</a></li>
</ul>
<hr>
<p>Full Changelog: <a href="https://github.com/Odin-Scan/odin-scan-action/commits/v1">https://github.com/Odin-Scan/odin-scan-action/commits/v1</a></p>
]]></content:encoded></item><item><title>KeyWatch Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/keywatch-scan/</link><pubDate>Mon, 03 Aug 2026 06:25:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/keywatch-scan/</guid><description>Version updated for https://github.com/pixincreate/KeyWatch to version v2.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The KeyWatch GitHub Action automates secret scanning by scanning files and directories, detecting secrets such as passwords, keys, and tokens. It provides a fast and efficient way to scan code repositories or any directory for sensitive information. The action is compatible with various runners, including Linux x64 and macOS x64/arm64, and supports different exit modes for handling findings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pixincreate/KeyWatch">https://github.com/pixincreate/KeyWatch</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/keywatch-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The KeyWatch GitHub Action automates secret scanning by scanning files and directories, detecting secrets such as passwords, keys, and tokens. It provides a fast and efficient way to scan code repositories or any directory for sensitive information. The action is compatible with various runners, including Linux x64 and macOS x64/arm64, and supports different exit modes for handling findings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>GitHub Release asset publishing no longer fails when Action validation generates Python bytecode caches</li>
</ul>
]]></content:encoded></item><item><title>vord Static Analysis</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/vord-static-analysis/</link><pubDate>Mon, 03 Aug 2026 06:24:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/vord-static-analysis/</guid><description>Version updated for https://github.com/pmaojo/vord to version v0.6.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The vord GitHub Action is a static analysis tool written in Rust that analyzes code before it’s committed. It helps identify potential issues and enforce coding standards across multiple programming languages. The action can be used as a CI step to automatically scan repositories and provides an interactive wizard for users to configure and use the tool.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pmaojo/vord">https://github.com/pmaojo/vord</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vord-static-analysis">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>vord</code> GitHub Action is a static analysis tool written in Rust that analyzes code before it&rsquo;s committed. It helps identify potential issues and enforce coding standards across multiple programming languages. The action can be used as a CI step to automatically scan repositories and provides an interactive wizard for users to configure and use the tool.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.6.0: Architecture rule false positive fixes &amp; minor versio… by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/154">https://github.com/pmaojo/vord/pull/154</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.5.0...v0.6.0">https://github.com/pmaojo/vord/compare/v0.5.0...v0.6.0</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.6.0: Architecture rule false positive fixes &amp; minor versio… by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/154">https://github.com/pmaojo/vord/pull/154</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.5.0...v0.6.0">https://github.com/pmaojo/vord/compare/v0.5.0...v0.6.0</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.6.0: Architecture rule false positive fixes &amp; minor versio… by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/154">https://github.com/pmaojo/vord/pull/154</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.5.0...v0.6.0">https://github.com/pmaojo/vord/compare/v0.5.0...v0.6.0</a></p>
<h2 id="whats-changed-4">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.6.0: Architecture rule false positive fixes &amp; minor versio… by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/154">https://github.com/pmaojo/vord/pull/154</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.5.0...v0.6.0">https://github.com/pmaojo/vord/compare/v0.5.0...v0.6.0</a></p>
<h2 id="whats-changed-5">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.6.0: Architecture rule false positive fixes &amp; minor versio… by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/154">https://github.com/pmaojo/vord/pull/154</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.5.0...v0.6.0">https://github.com/pmaojo/vord/compare/v0.5.0...v0.6.0</a></p>
]]></content:encoded></item><item><title>Multi-Style Contribution Snake</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/multi-style-contribution-snake/</link><pubDate>Mon, 03 Aug 2026 06:23:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/multi-style-contribution-snake/</guid><description>Version updated for https://github.com/Pro-Bandey/multi-style-snake-contribution-grid to version v03.08.26.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of a dynamic animated contribution grid for your GitHub repository using 5 distinct styles. It automatically detects the repository owner, generates multiple snake variations in various shapes and themes, renders bold month labels, and creates an automated gallery in a separate branch. The action supports both SVG and GIF formats and can be easily integrated into your profile README for visual representation of your contributions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Pro-Bandey/multi-style-snake-contribution-grid">https://github.com/Pro-Bandey/multi-style-snake-contribution-grid</a></strong> to version <strong>v03.08.26</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/multi-style-contribution-snake">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of a dynamic animated contribution grid for your GitHub repository using 5 distinct styles. It automatically detects the repository owner, generates multiple snake variations in various shapes and themes, renders bold month labels, and creates an automated gallery in a separate branch. The action supports both SVG and GIF formats and can be easily integrated into your profile README for visual representation of your contributions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-multi-style-snake-daily-update">🐍 Multi-Style Snake Daily Update</h2>
<p>Automated daily release to the GitHub Marketplace.</p>
<p><strong>Version Details:</strong></p>
<ul>
<li><strong>Tag:</strong> <code>v03.08.26</code></li>
<li><strong>Release Date:</strong> $(date +&rsquo;%A, %B %d, 20%y')</li>
</ul>
<p><strong>Included Features:</strong></p>
<ul>
<li>5 Unique Snake Styles (Blocks, Rounds, Triangles, Stars, Diamonds)</li>
<li>Automated Month Labels above grids</li>
<li>Dynamic Username Detection</li>
<li>Auto-generated Asset Gallery</li>
</ul>
]]></content:encoded></item><item><title>holt ci</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/holt-ci/</link><pubDate>Mon, 03 Aug 2026 06:21:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/holt-ci/</guid><description>Version updated for https://github.com/Raed2180416/holt to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The holt action is an agent-agnostic tool designed to help developers manage multiple worktrees efficiently. It compares the committed and uncommitted states of git repositories to identify which worktrees contain valuable content that should not be deleted, ensuring safe deletion practices in a multi-agent development environment. By leveraging git’s own worktree lock, holt automatically prevents accidental deletions of worktrees that hold important code changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Raed2180416/holt">https://github.com/Raed2180416/holt</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/holt-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The holt action is an agent-agnostic tool designed to help developers manage multiple worktrees efficiently. It compares the committed and uncommitted states of git repositories to identify which worktrees contain valuable content that should not be deleted, ensuring safe deletion practices in a multi-agent development environment. By leveraging git&rsquo;s own worktree lock, holt automatically prevents accidental deletions of worktrees that hold important code changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="holt-030--measured-and-fixed-where-the-measurement-hurt">holt 0.3.0 — measured, and fixed where the measurement hurt</h2>
<p><strong>Know what your agents made, and don&rsquo;t lose any of it.</strong> You ran a dozen agents overnight; holt
tells you what each worktree actually produced, which ones collide, which are safe to delete, and
it stops an agent deleting work that exists nowhere else.</p>
<p>0.2.0 could act. 0.3.0 is the first release that has been <strong>scored</strong> — against an oracle proven to
share no code with holt — and then fixed where the score was bad.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install -g https://github.com/Raed2180416/holt/releases/download/v0.3.0/holt.tgz
</span></span></code></pre></div><p>One command — no clone, no build. This release is built, installed and driven against a real
repository on Linux, macOS <strong>and</strong> Windows by CI before the file is attached, and the same smoke
test now runs on every commit rather than only at release time. <code>holt.tgz</code> is a stable name, so
this URL keeps working; the versioned <code>holt-0.3.0.tgz</code> is attached alongside it.</p>
<p>holt is not on the npm registry yet — <code>npm install -g holt</code> 404s — so this URL is the install.</p>
<p>Then, in any repository with worktrees:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>holt integrate       <span style="color:#75715e"># wire every agent you use — the whole setup</span>
</span></span><span style="display:flex;"><span>holt auto            <span style="color:#75715e"># locks what would be lost; tells you what needs a decision</span>
</span></span></code></pre></div><h3 id="measured-for-the-first-time">Measured for the first time</h3>
<p>50 languages, 900 worktrees, 18,000 labelled claims, scored against an independent oracle that
shares no code with holt — the independence is proven, not asserted, by a static import-graph
walk, a runtime module-resolution hook, and a probe that proves the hook actually fires
(<code>independence-check.mjs</code>; full detail and reproduction command in <code>BENCHMARKS.md</code> §9):</p>
<table>
  <thead>
      <tr>
          <th>question</th>
          <th>precision</th>
          <th>recall</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>disposable</td>
          <td>1.00</td>
          <td>1.00</td>
      </tr>
      <tr>
          <td>conflict</td>
          <td>1.00</td>
          <td>0.96</td>
      </tr>
      <tr>
          <td>duplicate</td>
          <td>0.75</td>
          <td>1.00</td>
      </tr>
      <tr>
          <td>refuse</td>
          <td>1.00</td>
          <td>1.00</td>
      </tr>
      <tr>
          <td>unique</td>
          <td>1.00</td>
          <td>1.00</td>
      </tr>
  </tbody>
</table>
<p><strong>False &ldquo;safe to delete&rdquo;: 0 of 900</strong>, reproduced across four independent runs. <code>duplicate</code>&rsquo;s
precision and <code>conflict</code>&rsquo;s recall are the two numbers here below 1.00 on purpose — see &ldquo;Known
limits&rdquo; below and <code>BENCHMARKS.md</code> §§8–9 for exactly which cases they are and why closing
<code>duplicate</code> further would mean overriding holt&rsquo;s own correct, hand-verified answer.</p>
<p>Recall on <code>disposable</code> was <strong>0.40</strong> when first measured, and that is the headline fix of this
release: holt was refusing 60% of the work it exists to do. Perfect precision at 0.40 recall is not
a safe tool — it is one that answers &ldquo;I cannot be sure&rdquo; to most of its own question.</p>
<h3 id="whats-new">What&rsquo;s new</h3>
<ul>
<li><strong><code>holt auto</code></strong> — the autopilot. Does everything that cannot lose data by itself (locks what is
at risk, releases locks no longer justified) and hands the destructive half over with the
evidence and the exact command. It never deletes.</li>
<li><strong><code>holt discard &lt;path&gt;</code></strong> — the escape hatch. Captures content to a verified ref <em>first</em>, then
removes it, so the guard stays on and the loss does not. A tracked file is reverted rather than
deleted. Journalled, with the restore command printed.</li>
<li><strong>Redundancy-aware disposal</strong> — a worktree whose content a living sibling also holds is now
correctly disposable. <code>clean --apply</code> re-verifies before each removal, so a redundant set drains
to exactly one survivor; <code>gate</code> refuses it, because the <code>rm -rf</code> a script runs after <code>gate</code> never
looks again.</li>
<li><strong>The guard speaks Windows</strong> — <code>Remove-Item</code>, <code>rd /s /q</code>, <code>del /f /q</code>, <code>Move-Item</code>,
<code>Clear-Content</code> and <code>Set-Content</code> are classified exactly as their POSIX equivalents.</li>
<li><strong>Shell indirection is never a silent allow</strong> — <code>$(echo rm)</code>, a variable-supplied verb and <code>eval</code>
return <em>ask</em>; <code>sh -c &quot;…&quot;</code> and <code>node -e &quot;…&quot;</code> are read and given a real verdict.</li>
<li><strong>Cursor blocks deterministically</strong>, and ten hosts that claimed MCP now actually get a config —
including OpenAI Codex CLI, which needed holt&rsquo;s first TOML writer.</li>
<li><strong>Static analysis</strong> — 20,749 lines shipped with no type checking; now gated by a ratchet that can
go down and never up.</li>
<li><strong>A rewritten site</strong> with a real light mode and a picture of what you actually get.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<p>Seven ways holt could report work as &ldquo;safe to delete&rdquo; when it existed nowhere else — each
reproduced end to end with <code>git fsck</code> confirming the loss, each now covered by a test that was
watched failing first: <code>vendor/</code>, <code>logs/</code> and <code>tmp/</code> treated as generated; <code>git stash</code> unmodeled;
<code>rescue</code> reporting <code>verified:true</code> for a submodule it captured nothing from; <code>discard</code> following a
symlink into another file&rsquo;s work; and <code>node -e &quot;require('fs').rmSync(…)&quot;</code> silently allowed.</p>
<p>Also: a rename/rename conflict reported as &ldquo;no collisions&rdquo;; gitignored <code>.env.local</code> files
manufacturing false HIGH collisions; an O(N²) merge-tree storm; and a ctags argv injection where a
file named <code>-L</code> could leak the contents of files outside the batch.</p>
<h3 id="known-limits">Known limits</h3>
<ul>
<li>Very large repositories are slow with symbols on — the Linux kernel takes ~16 minutes.
<code>--no-symbols</code> is fast and answers a weaker question.</li>
<li>A <code>duplicate</code> verdict is symbol-identity based: two workstreams that each declare a function with
the same name can read as duplicates even when their bodies differ. Measured precision is
<strong>0.75</strong> on the benchmark corpus, and every false positive traces to the one case bench50 plants
on purpose, once per language — the same symbol name and body declared in a second file with
different surrounding content — which is a real, deliberately unresolvable disagreement between a
symbol-identity answer and a content-identity oracle, not an unexamined miss (<code>BENCHMARKS.md</code> §8
has the full breakdown, the fix that <em>did</em> land for a different false-positive class, and why
this specific number does not move further). <code>holt duplicates --deep</code> adds token-level clone
detection (jscpd) for the same question asked a different way.</li>
<li><code>conflict</code> recall is <strong>0.96</strong> (2 of 50 planted conflict pairs missed) rather than 1.00. Both
misses are <code>holt collisions --json --all</code> not surfacing a pair <code>git merge-tree</code> says collides;
which 2 of the 50 repositories miss has moved between scoring runs taken minutes apart during
active work on this exact code path — reported as an open, moving defect with the specific
repositories named (<code>BENCHMARKS.md</code> §9), not smoothed into a single number that looks more settled
than it is.</li>
</ul>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/raviqqe/muffy/</link><pubDate>Mon, 03 Aug 2026 06:19:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the static website validation process using the Muffy tool, which checks HTML and CSS for errors. It can be used to validate a set of websites or a specific website by providing its URL. The action is designed to integrate seamlessly with GitHub workflows for continuous integration and deployment pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the static website validation process using the Muffy tool, which checks HTML and CSS for errors. It can be used to validate a set of websites or a specific website by providing its URL. The action is designed to integrate seamlessly with GitHub workflows for continuous integration and deployment pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>8d7defea09ad275316deb3153be113b3edd6a33e Bump version (#1175)</li>
<li>14cc648f1539993c52b8aacdf09bd12ecfa65ff9 Media type utility (#1174)</li>
<li>dcc1ee584a461d9d14d2850e8e4209a7eab966d2 Markup error (#1173)</li>
<li>7fc023e6a67ee91417b2c7b8e4a9f0fac1e8be48 True XML parser (#1171)</li>
<li>6955275bbb8e7ffcef94eaa6e1c6c7db944ec795 Bump vendor/validator from <code>795db7b</code> to <code>372674c</code> (#1156)</li>
<li>1b0302ed3052edce7c332b4c1a2375f94d009049 SVG validation (#1169)</li>
<li>bc20476f7d781d32cd4bf9d4866b9d8cdcf3c773 Fix <code>ruby</code> (#1170)</li>
<li>b7d76a0c3dbc9849d61617040ee51fd7b38323a5 Improve HTML validation configuration (#1167)</li>
<li>2195aa398d7092b555b385f5847eec69c2431049 Improve RNC validation (#1168)</li>
<li>167431f014352b3e2db8ebe5a08b72a0c110c361 Contextual RNC validation (#1142)</li>
<li>e5d70ee1e7fcb0bcdf397dcca209ab690f032543 Bump homebrew/actions/setup-homebrew from 2026.07.20.1 to 2026.07.29.1 (#1163)</li>
<li>91352eb619dd350561a2841ce5902d70a8eb0692 Bump @biomejs/biome from 2.5.5 to 2.5.6 in /doc (#1161)</li>
<li>e7d3bc76b21e85baab8aadfb1233a0a3082325f2 Bump docker/login-action from 4.5.2 to 4.6.0 (#1166)</li>
<li>6c178cb30904085ba724c2d3b20ed5f27626323c Bump http from 1.4.2 to 1.5.0 (#1164)</li>
<li>f6082c43a75499d6d4b32c0688137159212bfa59 Bump codspeedhq/action from 4.19.1 to 5.0.1 (#1165)</li>
<li>7ec5a18d90025a3ba6f0eabd551229544d78c0d7 Bump astro from 7.1.5 to 7.1.6 in /doc in the astro group (#1162)</li>
<li>6218eaa121813bfe4d99c4eef4a859714cce7ca0 Bump toml from 1.1.3+spec-1.1.0 to 1.1.4+spec-1.1.0 (#1158)</li>
<li>65d4863f2251ecac83808a946ecd3211edd72269 Bump docker/login-action from 4.5.1 to 4.5.2 (#1160)</li>
<li>ced33a9cf9de70764e5e813ffa011648a6bbbf3a Bump the astro group in /doc with 2 updates (#1159)</li>
<li>e9767da32e20474a8553968c5c9991c508ee78cb Bump @types/node from 26.1.1 to 26.1.2 in /doc (#1155)</li>
<li>9efa246aaf7cd680bd0641bd4698e4829c380b29 Bump codspeedhq/action from 4.18.5 to 4.19.1 (#1157)</li>
<li>b7818fdd2f14374c3557e3a1ce2e59b782fe6a82 Bump astro from 7.1.3 to 7.1.4 in /doc in the astro group (#1154)</li>
<li>3225f77490f91d54dd7e85e689d22d249fc6625a Bump scc from 3.8.5 to 3.8.6 (#1153)</li>
</ul>
]]></content:encoded></item><item><title>RelayShield Secret Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/relayshield-secret-scan/</link><pubDate>Mon, 03 Aug 2026 06:19:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/relayshield-secret-scan/</guid><description>Version updated for https://github.com/relayshield/rsscan to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The rsscan GitHub Action is a tool designed to scan for API keys, tokens, and other sensitive credentials in staged changes or commit ranges. It uses pre-commit hooks, GitHub Actions, GitLab CI/CD, CircleCI, Docker containers, and shell scripts to automate the process of detecting and flagging these credentials before they are committed to version control. The action is free and runs entirely on your machine without requiring an account or network calls, ensuring that sensitive information never leaves the host.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/relayshield/rsscan">https://github.com/relayshield/rsscan</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/relayshield-secret-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The rsscan GitHub Action is a tool designed to scan for API keys, tokens, and other sensitive credentials in staged changes or commit ranges. It uses pre-commit hooks, GitHub Actions, GitLab CI/CD, CircleCI, Docker containers, and shell scripts to automate the process of detecting and flagging these credentials before they are committed to version control. The action is free and runs entirely on your machine without requiring an account or network calls, ensuring that sensitive information never leaves the host.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fixes a version-reporting bug.</p>
<p>0.1.1 shipped with a hardcoded <code>__version__ = &quot;0.1.0&quot;</code> while the package version was 0.1.1, so <code>rsscan --version</code> reported the wrong number and the optional <code>--org</code> adoption signal sent the wrong version.</p>
<p><code>__version__</code> is now read from installed package metadata, making <code>pyproject.toml</code> the single source of truth. No change to scanning behaviour.</p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/kaniko-build-action/</link><pubDate>Mon, 03 Aug 2026 06:17:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints a greeting message, either “Hello World” or personalized to a given name, and provides the current time in the log. It automates the task of displaying a customized welcome message for different users on pull requests or other CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints a greeting message, either &ldquo;Hello World&rdquo; or personalized to a given name, and provides the current time in the log. It automates the task of displaying a customized welcome message for different users on pull requests or other CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>Drawio Export Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/drawio-export-action/</link><pubDate>Mon, 03 Aug 2026 06:17:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/drawio-export-action/</guid><description>Version updated for https://github.com/rlespinasse/drawio-export-action to version v2.54.0.
This action is used across all versions by 124 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, rlespinasse/drawio-export-action, automates the process of exporting Draw.io files into various formats such as PDF, PNG, and SVG. It solves the problem of batch converting Draw.io diagrams into different formats without manual intervention, which is particularly useful for generating documentation, presentations, or sharing diagrams across multiple platforms. The action supports exporting single-page diagrams or all pages in a PDF format, with options to customize settings like border width, scale, and quality.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rlespinasse/drawio-export-action">https://github.com/rlespinasse/drawio-export-action</a></strong> to version <strong>v2.54.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>124</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/drawio-export-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, rlespinasse/drawio-export-action, automates the process of exporting Draw.io files into various formats such as PDF, PNG, and SVG. It solves the problem of batch converting Draw.io diagrams into different formats without manual intervention, which is particularly useful for generating documentation, presentations, or sharing diagrams across multiple platforms. The action supports exporting single-page diagrams or all pages in a PDF format, with options to customize settings like border width, scale, and quality.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="2540-2026-08-02"><a href="https://github.com/rlespinasse/drawio-export-action/compare/v2.53.0...v2.54.0">2.54.0</a> (2026-08-02)</h1>
<h3 id="features">Features</h3>
<ul>
<li>bump rlespinasse/drawio-export from v4.54.0 to v4.56.0 (<a href="https://github.com/rlespinasse/drawio-export-action/issues/107">#107</a>) (<a href="https://github.com/rlespinasse/drawio-export-action/commit/6900c4d8a1fb066e0a0a3570574439487546feab">6900c4d</a>)</li>
</ul>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/rumdl-action/</link><pubDate>Mon, 03 Aug 2026 06:16:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.49.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: rumdl is a high-performance Rust-based Markdown linter and formatter that offers 81 lint rules covering common Markdown issues, automatic formatting with --fix, zero dependencies, and multiple installation options (Rust, Python, standalone binaries). It is designed for speed, with benchmarks showing significant performance improvements over alternatives.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.49</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong>
rumdl is a high-performance Rust-based Markdown linter and formatter that offers 81 lint rules covering common Markdown issues, automatic formatting with <code>--fix</code>, zero dependencies, and multiple installation options (Rust, Python, standalone binaries). It is designed for speed, with benchmarks showing significant performance improvements over alternatives.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="security">Security</h3>
<ul>
<li>
<p><strong>config</strong>: keep an extends target&rsquo;s path and contents out of messages about it (<a href="https://github.com/rvben/rumdl/commit/72bcb49ad8cb07d836b048196a7e54a09b202661">72bcb49</a>)</p>
<p>An <code>extends</code> value is expanded from the environment before it is resolved, so naming the
resolved path in an error or warning printed environment variable values wherever that
message went, which under CI is the build log. <code>extends</code> also points at an arbitrary path,
so a target that is not valid TOML had its offending line quoted back. A file reached
through <code>extends</code> is now named by the reference as written, and its own text is never
repeated. A config you name yourself is unchanged, and <code>rumdl config</code>, the language server&rsquo;s
report to its editor, and <code>RUST_LOG=debug</code> still show resolved paths.</p>
<p>Reported privately by Shuvam Kumar.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>md072</strong>: keep every trailing newline when sorting frontmatter keys (<a href="https://github.com/rvben/rumdl/commit/a5e7c4030a18f66bdfbd2c270935eb9d6686511a">a5e7c40</a>)</li>
<li><strong>fix-utils</strong>: measure fix ranges against the content the rule read (<a href="https://github.com/rvben/rumdl/commit/2ed423868e0a8771395fbc1c12b365793f8de9f9">2ed4238</a>)</li>
<li><strong>md044</strong>: read a wikilink&rsquo;s display text, not the page name it hides (<a href="https://github.com/rvben/rumdl/commit/51d584e6f8eef7f728897a9bd348093d696f3f91">51d584e</a>)</li>
<li><strong>md039</strong>: keep wikilinks and nested images intact when trimming link text (<a href="https://github.com/rvben/rumdl/commit/aabd85940900d035a1daf2387ef4e26857e1f01d">aabd859</a>)</li>
<li><strong>md045,md057,md044</strong>: stop reporting wiki embeds as images (<a href="https://github.com/rvben/rumdl/commit/1147d1788809ab70c50af4cdcdb802edc2d4c77b">1147d17</a>)</li>
<li><strong>md058,md065</strong>: preserve the trailing newline when inserting blank lines (#783) (<a href="https://github.com/rvben/rumdl/commit/0ba54cefdf0405d27bd23fb6e69c4b4ad854d133">0ba54ce</a>)</li>
<li><strong>md013</strong>: track line numbers in BlockBuilder for list reflow (#780) (<a href="https://github.com/rvben/rumdl/commit/56e2b3f13dc94c6532f99095482e33a1c56db383">56e2b3f</a>)</li>
<li><strong>mkdocs</strong>: read an indented code block inside a container body as code (<a href="https://github.com/rvben/rumdl/commit/94391349bc613e38c115b646cc3d66dfebe9ea89">9439134</a>)</li>
<li><strong>md087,inline-config</strong>: judge directives in indented container bodies (<a href="https://github.com/rvben/rumdl/commit/9285de1fa70bffdd291377c71ab5fc74a9620371">9285de1</a>)</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li><strong>md038</strong>: judge nested backticks against the outermost spans on a line (<a href="https://github.com/rvben/rumdl/commit/b02ea886d28036c6a920fc0c40f4c466ba2b6f87">b02ea88</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.49-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.49-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.49-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.49-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-x86_64-apple-darwin.tar.gz">rumdl-v0.2.49-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-aarch64-apple-darwin.tar.gz">rumdl-v0.2.49-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-x86_64-pc-windows-msvc.zip">rumdl-v0.2.49-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.49/rumdl-v0.2.49-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/sherpa.sh/</link><pubDate>Mon, 03 Aug 2026 06:15:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven tool that simplifies cloud infrastructure deployment by understanding and automating the process of creating, configuring, and managing various resources. It solves the problem of developers having to manually configure complex infrastructure using YAML files or DevOps expertise. Key capabilities include deploying applications on multiple cloud providers, handling different frameworks, and providing plain English prompts for automated configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven tool that simplifies cloud infrastructure deployment by understanding and automating the process of creating, configuring, and managing various resources. It solves the problem of developers having to manually configure complex infrastructure using YAML files or DevOps expertise. Key capabilities include deploying applications on multiple cloud providers, handling different frameworks, and providing plain English prompts for automated configuration.</p>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Mon, 03 Aug 2026 06:14:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service on a remote server by bundling assets, committing them to the repository, and triggering a deployment process. It solves the problem of managing complex deployments across multiple platforms and ensures that changes are version-controlled for consistency and reproducibility. The action provides a simple interface to deploy services with minimal setup required.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service on a remote server by bundling assets, committing them to the repository, and triggering a deployment process. It solves the problem of managing complex deployments across multiple platforms and ensures that changes are version-controlled for consistency and reproducibility. The action provides a simple interface to deploy services with minimal setup required.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/classroom-to-sheets-integration/</link><pubDate>Mon, 03 Aug 2026 06:14:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates Google Sheets with GitHub Classroom to automatically send assignment results. It uses Google Sheets API credentials and automates the process of updating the grades in a specified sheet based on the results from the classroom-resources/autograding-command-grader@v1 step in your GitHub actions workflow. The action ensures that the correct columns are created for each task result and updates them accordingly, ensuring accurate tracking of submissions in Google Sheets.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates Google Sheets with GitHub Classroom to automatically send assignment results. It uses Google Sheets API credentials and automates the process of updating the grades in a specified sheet based on the results from the <code>classroom-resources/autograding-command-grader@v1</code> step in your GitHub actions workflow. The action ensures that the correct columns are created for each task result and updates them accordingly, ensuring accurate tracking of submissions in Google Sheets.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>monoship</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/monoship/</link><pubDate>Mon, 03 Aug 2026 06:13:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/monoship/</guid><description>Version updated for https://github.com/tada5hi/monoship to version v2.2.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary monoship is a CLI tool that automates the publishing of npm packages from workspaces to registries, including support for OIDC trusted publishing. It checks which workspace packages haven’t been published yet and publishes only what’s needed, making it ideal for CI/CD pipelines alongside release-please.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tada5hi/monoship">https://github.com/tada5hi/monoship</a></strong> to version <strong>v2.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/monoship">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>monoship is a CLI tool that automates the publishing of npm packages from workspaces to registries, including support for OIDC trusted publishing. It checks which workspace packages haven&rsquo;t been published yet and publishes only what&rsquo;s needed, making it ideal for CI/CD pipelines alongside release-please.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="220-2026-08-02"><a href="https://github.com/tada5hi/monoship/compare/v2.1.0...v2.2.0">2.2.0</a> (2026-08-02)</h2>
<h3 id="features">Features</h3>
<ul>
<li>correct latest dist-tag when it trails behind a prerelease (<a href="https://github.com/tada5hi/monoship/issues/439">#439</a>) (<a href="https://github.com/tada5hi/monoship/commit/62a376ec29b7826527b7a891323e318d3f7e1a96">62a376e</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> bump the majorprod group across 1 directory with 3 updates (<a href="https://github.com/tada5hi/monoship/issues/442">#442</a>) (<a href="https://github.com/tada5hi/monoship/commit/d7c0771c7c707e288dc41b4b383aa6cebc9d336e">d7c0771</a>)</li>
<li><strong>deps:</strong> bump the minorandpatch group with 7 updates (<a href="https://github.com/tada5hi/monoship/issues/444">#444</a>) (<a href="https://github.com/tada5hi/monoship/commit/dc865f2edc597f379ce451d44f6e692d06f73814">dc865f2</a>)</li>
</ul>
]]></content:encoded></item><item><title>Azure App Service Settings Community</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/azure-app-service-settings-community/</link><pubDate>Mon, 03 Aug 2026 06:12:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/azure-app-service-settings-community/</guid><description>Version updated for https://github.com/Tango992/azure-appservice-settings to version v1.0.10.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of configuring App settings, connection strings, and general settings in bulk using JSON syntax on Azure Web Apps. It supports ASP.NET, ASP.NET Core, PHP, Java, Python, Go, and Node.js-based web applications. Users can set sensitive data as secrets to ensure secure operations during deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tango992/azure-appservice-settings">https://github.com/Tango992/azure-appservice-settings</a></strong> to version <strong>v1.0.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/azure-app-service-settings-community">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of configuring App settings, connection strings, and general settings in bulk using JSON syntax on Azure Web Apps. It supports ASP.NET, ASP.NET Core, PHP, Java, Python, Go, and Node.js-based web applications. Users can set sensitive data as secrets to ensure secure operations during deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>build(deps-dev): bump esbuild from 0.28.0 to 0.28.1 in the npm_and_yarn group across 1 directory by @dependabot[bot] in <a href="https://github.com/Tango992/azure-appservice-settings/pull/89">https://github.com/Tango992/azure-appservice-settings/pull/89</a></li>
<li>build(deps): bump undici from 6.24.1 to 6.27.0 in the npm_and_yarn group across 1 directory by @dependabot[bot] in <a href="https://github.com/Tango992/azure-appservice-settings/pull/90">https://github.com/Tango992/azure-appservice-settings/pull/90</a></li>
<li>build(deps): bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/Tango992/azure-appservice-settings/pull/91">https://github.com/Tango992/azure-appservice-settings/pull/91</a></li>
<li>build(deps): bump codecov/codecov-action from 6.0.1 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/Tango992/azure-appservice-settings/pull/93">https://github.com/Tango992/azure-appservice-settings/pull/93</a></li>
<li>build(deps): bump github/codeql-action/init from 4.36.1 to 4.37.3 by @dependabot[bot] in <a href="https://github.com/Tango992/azure-appservice-settings/pull/101">https://github.com/Tango992/azure-appservice-settings/pull/101</a></li>
<li>build(deps): bump github/codeql-action/autobuild from 4.36.1 to 4.37.3 by @dependabot[bot] in <a href="https://github.com/Tango992/azure-appservice-settings/pull/100">https://github.com/Tango992/azure-appservice-settings/pull/100</a></li>
<li>build(deps): bump github/codeql-action/analyze from 4.36.1 to 4.37.3 by @dependabot[bot] in <a href="https://github.com/Tango992/azure-appservice-settings/pull/99">https://github.com/Tango992/azure-appservice-settings/pull/99</a></li>
<li>build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 by @dependabot[bot] in <a href="https://github.com/Tango992/azure-appservice-settings/pull/98">https://github.com/Tango992/azure-appservice-settings/pull/98</a></li>
<li>build(deps): bump github/codeql-action/upload-sarif from 4.36.1 to 4.37.3 by @dependabot[bot] in <a href="https://github.com/Tango992/azure-appservice-settings/pull/97">https://github.com/Tango992/azure-appservice-settings/pull/97</a></li>
<li>build(deps): bump brace-expansion from 5.0.6 to 5.0.7 in the npm_and_yarn group across 1 directory by @dependabot[bot] in <a href="https://github.com/Tango992/azure-appservice-settings/pull/96">https://github.com/Tango992/azure-appservice-settings/pull/96</a></li>
<li>Dependency update by @Tango992 in <a href="https://github.com/Tango992/azure-appservice-settings/pull/102">https://github.com/Tango992/azure-appservice-settings/pull/102</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Tango992/azure-appservice-settings/compare/v1...v1.0.10">https://github.com/Tango992/azure-appservice-settings/compare/v1...v1.0.10</a></p>
]]></content:encoded></item><item><title>Review Router Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/review-router-audit/</link><pubDate>Mon, 03 Aug 2026 06:11:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/review-router-audit/</guid><description>Version updated for https://github.com/tenpace-app/review-router-audit to version v1.1.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Review Router Audit checks GitHub repositories to identify stale open pull requests, unreviewed pull requests, and other review-related issues. It reports these metrics in a Markdown summary and JSON format, providing insights into the health of the review process. The action uses the repository-scoped GITHUB_TOKEN to access necessary data and optionally creates a human-readable link for setting up Review Router.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tenpace-app/review-router-audit">https://github.com/tenpace-app/review-router-audit</a></strong> to version <strong>v1.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/review-router-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Review Router Audit checks GitHub repositories to identify stale open pull requests, unreviewed pull requests, and other review-related issues. It reports these metrics in a Markdown summary and JSON format, providing insights into the health of the review process. The action uses the repository-scoped <code>GITHUB_TOKEN</code> to access necessary data and optionally creates a human-readable link for setting up Review Router.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Moves the audit Action to the Tenpace GitHub organization. New workflows should use <code>tenpace-app/review-router-audit@v1</code>; GitHub redirects the previous repository URL.</p>
]]></content:encoded></item><item><title>Set up Review Router</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/set-up-review-router/</link><pubDate>Mon, 03 Aug 2026 06:10:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/set-up-review-router/</guid><description>Version updated for https://github.com/tenpace-app/review-router-setup to version v1.1.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup of a Review Router connection between GitHub and Slack, allowing workflow users to sign in to Tenpace to claim and lock specific repository, Slack destination, routing preset, and reviewer mention policy. The action ensures that no personal credentials or sensitive information are shared, relying on OIDC for authentication.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tenpace-app/review-router-setup">https://github.com/tenpace-app/review-router-setup</a></strong> to version <strong>v1.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/set-up-review-router">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup of a Review Router connection between GitHub and Slack, allowing workflow users to sign in to Tenpace to claim and lock specific repository, Slack destination, routing preset, and reviewer mention policy. The action ensures that no personal credentials or sensitive information are shared, relying on OIDC for authentication.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Publishes the org-owned MCP Registry identity using the canonical <code>https://api.tenpace.com/v1/review-router/mcp</code> endpoint. The previous <code>/mcp</code> endpoint remains available for compatibility.</p>
]]></content:encoded></item><item><title>PlanGuard BYO-AI Explanation</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/planguard-byo-ai-explanation/</link><pubDate>Mon, 03 Aug 2026 06:08:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/planguard-byo-ai-explanation/</guid><description>Version updated for https://github.com/Theorvane/planguard to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PlanGuard automates the process of reviewing Terraform plans by sanitizing them before sending an AI explanation. It ensures that sensitive values are removed from the plan, maintaining a clear boundary between policy decisions and AI assistance. The tool runs in GitHub Actions without needing external services, using only secrets for API keys and environment-protected authentication.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Theorvane/planguard">https://github.com/Theorvane/planguard</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/planguard-byo-ai-explanation">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PlanGuard automates the process of reviewing Terraform plans by sanitizing them before sending an AI explanation. It ensures that sensitive values are removed from the plan, maintaining a clear boundary between policy decisions and AI assistance. The tool runs in GitHub Actions without needing external services, using only secrets for API keys and environment-protected authentication.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="marketplace-metadata-fix">Marketplace metadata fix</h2>
<p>Shortens the root GitHub Action description to 75 characters, satisfying GitHub Marketplace&rsquo;s under-125-character requirement.</p>
<p>The Action behavior and security boundary are unchanged.</p>
]]></content:encoded></item><item><title>List Go Platforms</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/list-go-platforms/</link><pubDate>Mon, 03 Aug 2026 06:07:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/list-go-platforms/</guid><description>Version updated for https://github.com/theory/go-dist-action to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action generates a JSON array of Go-supported platform objects, allowing for the exclusion of specific OSes and architectures. It adds an OS-relevant emoji and GitHub runner to each object. The output can be used to automate tasks involving building or testing across different platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/theory/go-dist-action">https://github.com/theory/go-dist-action</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/list-go-platforms">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action generates a JSON array of Go-supported platform objects, allowing for the exclusion of specific OSes and architectures. It adds an OS-relevant emoji and GitHub runner to each object. The output can be used to automate tasks involving building or testing across different platforms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The theme of this release is <em>Emoji getting better.</em></p>
<h3 id="-improvements">⚡ Improvements</h3>
<ul>
<li>Changed the NetBSD Emoji from ⛳️ to 🚩.</li>
<li>Reformatted the code with ESLint and added missing variable declarations.</li>
</ul>
<hr>
<p>🆚 For more detail compare <a href="https://github.com/theory/go-dist-action/compare/v0.1.1...v0.1.2">changes since v0.1.1</a>.</p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/wails3-build-action/</link><pubDate>Mon, 03 Aug 2026 06:06:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the building of Wails.io projects, a modern cross-platform application framework. It installs GoLang and NodeJS, builds the application for specified platforms, and optionally uploads artifacts to GitHub or releases them on tags. The action supports various build configurations through customizable parameters, making it versatile for different development environments and workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the building of Wails.io projects, a modern cross-platform application framework. It installs GoLang and NodeJS, builds the application for specified platforms, and optionally uploads artifacts to GitHub or releases them on tags. The action supports various build configurations through customizable parameters, making it versatile for different development environments and workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>AI Changelog Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/ai-changelog-updater/</link><pubDate>Mon, 03 Aug 2026 06:05:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/ai-changelog-updater/</guid><description>Version updated for https://github.com/vscheuber/ai-changelog-action to version v1.1.10.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of updating a CHANGELOG.md file by using an AI language model to generate a changelog entry. It gathers information from Git history, merged pull requests, and related repositories, then generates user-focused changes while preserving existing content. Special handling is provided for full releases, consolidating pre-release notes into a clean final version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vscheuber/ai-changelog-action">https://github.com/vscheuber/ai-changelog-action</a></strong> to version <strong>v1.1.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-changelog-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of updating a <code>CHANGELOG.md</code> file by using an AI language model to generate a changelog entry. It gathers information from Git history, merged pull requests, and related repositories, then generates user-focused changes while preserving existing content. Special handling is provided for full releases, consolidating pre-release notes into a clean final version.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Internal pipeline update release. This release updates CI/CD or release automation under <code>.github/</code> without changing functional behavior.</li>
</ul>
]]></content:encoded></item><item><title>Zig Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/zig-actions/</link><pubDate>Mon, 03 Aug 2026 06:04:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/zig-actions/</guid><description>Version updated for https://github.com/YetAnotherMechanicusEnjoyer/zig-actions to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Zig compilation, testing, and documentation generation. It reports compiler errors directly as GitHub annotations for the CI workflow, and also supports deploying generated documentation to a GitHub Pages branch. The action can be configured with various inputs such as Zig version, working directory, test and doc commands, and deployment settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YetAnotherMechanicusEnjoyer/zig-actions">https://github.com/YetAnotherMechanicusEnjoyer/zig-actions</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zig-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates Zig compilation, testing, and documentation generation. It reports compiler errors directly as GitHub annotations for the CI workflow, and also supports deploying generated documentation to a GitHub Pages branch. The action can be configured with various inputs such as Zig version, working directory, test and doc commands, and deployment settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="added-zig-docs-cd--implemented-it-to-all-in-one">Added Zig Docs CD &amp; implemented it to All in one</h1>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/b.ia-accessibility-checker/</link><pubDate>Mon, 03 Aug 2026 06:04:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/03/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows companies to define audiences and guideline percentages, ensuring compliance with WCAG guidelines. The AI component analyzes guidelines at an abstract level, helping developers meet accessibility standards efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows companies to define audiences and guideline percentages, ensuring compliance with WCAG guidelines. The AI component analyzes guidelines at an abstract level, helping developers meet accessibility standards efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item><item><title>AI Agent Discipline Linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/ai-agent-discipline-linter/</link><pubDate>Sun, 02 Aug 2026 21:29:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/ai-agent-discipline-linter/</guid><description>Version updated for https://github.com/naimkatiman/continuous-improvement to version v3.22.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Claude Code is an AI language model that automatically adds three layers of checks and planning to ensure its edits are based on real facts and verified before “done”. It uses a runtime hook and bundled skills to enforce one task per session, conduct TDD, and verify progress in six phases. Continuous Improvement also captures lessons learned and surfaces the most relevant fix from past sessions for related prompts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/naimkatiman/continuous-improvement">https://github.com/naimkatiman/continuous-improvement</a></strong> to version <strong>v3.22.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-agent-discipline-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Claude Code is an AI language model that automatically adds three layers of checks and planning to ensure its edits are based on real facts and verified before &ldquo;done&rdquo;. It uses a runtime hook and bundled skills to enforce one task per session, conduct TDD, and verify progress in six phases. Continuous Improvement also captures lessons learned and surfaces the most relevant fix from past sessions for related prompts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(reconcile): ground-truth pass survives no-upstream, detached HEAD and linked worktrees by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/289">https://github.com/naimkatiman/continuous-improvement/pull/289</a></li>
<li>chore(release): cut v3.22.0 by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/290">https://github.com/naimkatiman/continuous-improvement/pull/290</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/naimkatiman/continuous-improvement/compare/v3...v3.22.0">https://github.com/naimkatiman/continuous-improvement/compare/v3...v3.22.0</a></p>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/ai-harness-doctor/</link><pubDate>Sun, 02 Aug 2026 21:28:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.22.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor audits and consolidates documentation files to ensure that they are comprehensive, coherent, and up-to-date. It helps teams streamline agent instructions by removing inconsistencies and duplicates, leading to more accurate responses and improved performance. This tool ensures that the AI harness is well-maintained and effective in providing clear guidance to developers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v1.22.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Harness Doctor audits and consolidates documentation files to ensure that they are comprehensive, coherent, and up-to-date. It helps teams streamline agent instructions by removing inconsistencies and duplicates, leading to more accurate responses and improved performance. This tool ensures that the AI harness is well-maintained and effective in providing clear guidance to developers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(scan,redaction): detect Tavily, DigitalOcean, Doppler, and SendGrid secrets by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/386">https://github.com/NieZhuZhu/ai-harness-doctor/pull/386</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1...v1.22.0">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1...v1.22.0</a></p>
]]></content:encoded></item><item><title>Feishu Build Notify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/feishu-build-notify/</link><pubDate>Sun, 02 Aug 2026 21:27:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/feishu-build-notify/</guid><description>Version updated for https://github.com/ningkaikok/feishu-notify-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The feishu-notify-action is a GitHub Action that sends notifications to a custom robot in the Fly书 group using Python. It only uses standard libraries, is a composite action, and does not require Docker or image building. It can be easily integrated into existing CI/CD pipelines without needing any software installations or setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ningkaikok/feishu-notify-action">https://github.com/ningkaikok/feishu-notify-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/feishu-build-notify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The feishu-notify-action is a GitHub Action that sends notifications to a custom robot in the Fly书 group using Python. It only uses standard libraries, is a composite action, and does not require Docker or image building. It can be easily integrated into existing CI/CD pipelines without needing any software installations or setup.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>首个版本：把 CI/CD 结果推送到飞书群自定义机器人。</p>
<p>用法见 README。每个项目建议用自己独立的飞书 webhook，不要跨项目共用。</p>
]]></content:encoded></item><item><title>HTML Inline Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/html-inline-actions/</link><pubDate>Sun, 02 Aug 2026 21:24:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/html-inline-actions/</guid><description>Version updated for https://github.com/ntsk/html-inline-actions to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action inlines CSS, JavaScript, and images into HTML files to reduce HTTP requests and improve page load times. It supports batch processing of multiple files and can be configured to skip certain types of inlining based on file type or link attributes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ntsk/html-inline-actions">https://github.com/ntsk/html-inline-actions</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/html-inline-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action inlines CSS, JavaScript, and images into HTML files to reduce HTTP requests and improve page load times. It supports batch processing of multiple files and can be configured to skip certain types of inlining based on file type or link attributes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>The action now runs on the Node 24 runtime (<code>runs.using: 'node24'</code>). GitHub runners have defaulted to Node 24 since June 16, 2026, and Node 20 is removed from runners in fall 2026, after which actions declaring <code>node20</code> no longer start.</li>
</ul>
<h3 id="internal">Internal</h3>
<ul>
<li>Upgraded TypeScript to 6.0, with TypeScript 7 running side by side for the <code>tsc</code> binary (#122, #125)</li>
<li>Upgraded ESLint to 10 and removed <code>eslint-plugin-import</code> (#56, #121)</li>
<li>Added a type check step to CI, which previously had none — <code>rollup</code> does not fail the build on type errors (#122)</li>
<li>Removed unbundled <code>tsc</code> output that had been committed to <code>dist/</code> by mistake (#124)</li>
<li><code>createDataUrl</code> now attaches <code>cause</code> to the error it throws (#121)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ntsk/html-inline-actions/compare/v1.1.1...v1.2.0">https://github.com/ntsk/html-inline-actions/compare/v1.1.1...v1.2.0</a></p>
]]></content:encoded></item><item><title>Offensive360 SAST Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/offensive360-sast-scan/</link><pubDate>Sun, 02 Aug 2026 21:24:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/offensive360-sast-scan/</guid><description>Version updated for https://github.com/offensive360/sast-scan-action to version v1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates a full Offensive360 SAST scan on every push or pull request. It runs deep taint and data-flow analysis across 60+ languages, providing SARIF reports for the GitHub code scanning tab and a severity gate for pipeline failures. The action is free for open source projects and supports various scan types such as dependency scanning, malware detection, and license compliance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/offensive360/sast-scan-action">https://github.com/offensive360/sast-scan-action</a></strong> to version <strong>v1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/offensive360-sast-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates a full Offensive360 SAST scan on every push or pull request. It runs deep taint and data-flow analysis across 60+ languages, providing SARIF reports for the GitHub code scanning tab and a severity gate for pipeline failures. The action is free for open source projects and supports various scan types such as dependency scanning, malware detection, and license compliance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First Marketplace release of the Offensive360 SAST scan action.</p>
<ul>
<li>Full static application security scan (60+ languages, taint/data-flow analysis) on every push or PR</li>
<li>SARIF 2.1.0 output — findings land in the GitHub code scanning tab with file/line, impact, and remediation guidance</li>
<li>Severity gate: fail the job on findings at or above a threshold (<code>fail-on: high</code> by default)</li>
<li>Optional dependency (SCA), malware/binary, and license scans</li>
<li>Outputs for downstream steps: total/critical/high/medium/low counts, scan status, SARIF path</li>
<li>GitLab CI template included (<code>templates/gitlab-ci.yml</code>)</li>
<li>Clear errors for auth failures, concurrent-scan conflicts (409), and proxy timeouts</li>
</ul>
<p>Free for open source: public repos can request a scan token at
<a href="https://offensive360.com/free-for-open-source/">https://offensive360.com/free-for-open-source/</a></p>
]]></content:encoded></item><item><title>Orca Security - SAST Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/orca-security-sast-security/</link><pubDate>Sun, 02 Aug 2026 21:23:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/orca-security-sast-security/</guid><description>Version updated for https://github.com/orcasecurity/shiftleft-sast-action to version v1.0.12.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 32 repositories.
Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Orca Shift Left Security Action automates the scanning of a repository using the Orca SAST tool. It helps identify security vulnerabilities in code by analyzing static analysis results, which can be formatted as JSON or CLI output and saved to an output directory. The action requires the project key, API token, scan paths, and optional settings for excluding certain files or directories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/orcasecurity/shiftleft-sast-action">https://github.com/orcasecurity/shiftleft-sast-action</a></strong> to version <strong>v1.0.12</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>32</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/orca-security-sast-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Orca Shift Left Security Action automates the scanning of a repository using the Orca SAST tool. It helps identify security vulnerabilities in code by analyzing static analysis results, which can be formatted as JSON or CLI output and saved to an output directory. The action requires the project key, API token, scan paths, and optional settings for excluding certain files or directories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>taint flag README.md by @dekelattias-orca in <a href="https://github.com/orcasecurity/shiftleft-sast-action/pull/22">https://github.com/orcasecurity/shiftleft-sast-action/pull/22</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/orcasecurity/shiftleft-sast-action/compare/v1.0.11...v1.0.12">https://github.com/orcasecurity/shiftleft-sast-action/compare/v1.0.11...v1.0.12</a></p>
]]></content:encoded></item><item><title>AI Model End-of-Life Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/ai-model-end-of-life-check/</link><pubDate>Sun, 02 Aug 2026 21:22:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/ai-model-end-of-life-check/</guid><description>Version updated for https://github.com/oscarnilsson98/ai-model-end-of-life-action to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action monitors AI models deployed in an application and provides a real-time lifecycle check by comparing them against community deprecation information. It identifies models that may be deprecated or approaching shutdown, reporting dated shutdowns with undated deprecations as warnings. The action supports scheduled monitoring and can send Slack notifications when model lifecycles are breached.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action">https://github.com/oscarnilsson98/ai-model-end-of-life-action</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-model-end-of-life-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action monitors AI models deployed in an application and provides a real-time lifecycle check by comparing them against community deprecation information. It identifies models that may be deprecated or approaching shutdown, reporting dated shutdowns with undated deprecations as warnings. The action supports scheduled monitoring and can send Slack notifications when model lifecycles are breached.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="ai-model-end-of-life-action-v200">AI Model End-of-Life Action v2.0.0</h2>
<p>v2 turns the action into a bounded, auditable lifecycle-policy gate while keeping the basic workflow small: declare the models you use and get warnings, machine-readable findings, and optional blocking policy before a provider shutdown surprises you.</p>
<h3 id="what-is-new">What is new</h3>
<ul>
<li><strong>Deterministic provenance:</strong> use a workspace-local <code>feed-file</code>, pin exact feed bytes with <code>expected-feed-sha256</code>, and record raw-feed, normalized lifecycle-feed, and inventory SHA-256 identities.</li>
<li><strong>Stable automation identities:</strong> every finding has a stable <code>findingId</code>; <code>alert-fingerprint</code>, retry-safe <code>next-alert-fingerprint</code>, and the compact <code>audit-record</code> avoid daily countdown churn.</li>
<li><strong>Conservative source discovery:</strong> opt in to bounded, exact, case-sensitive discovery of lifecycle-feed model IDs with repository-relative file/line/column coordinates. Discovery is report-only, emits no source snippets, and never changes policy or Slack state.</li>
<li><strong>Better lifecycle policy:</strong> v2 represents scheduled, already-passed, and undated deprecations explicitly; reports unmatched feed history without pretending it proves a model is active; and separates warning windows from blocking thresholds.</li>
<li><strong>Change-aware Slack:</strong> <code>notification-mode: on-change</code> supports initial, changed, unchanged, resolved, and error states through caller-managed fingerprint persistence. Ambiguous webhook POSTs are not retried within a run.</li>
<li><strong>Bounded by construction:</strong> feed documents, inventories, HTTP bodies, source traversal, matcher memory/CPU, annotations, outputs, summaries, and Slack text all have explicit limits and fail safely.</li>
<li><strong>Hardened delivery:</strong> exact Bun 1.3.14 builds, SHA-pinned workflow actions, Linux/macOS/Windows packaged-action tests, CodeQL, Dependabot, private vulnerability reporting, immutable exact releases, and guarded major-tag promotion.</li>
</ul>
<h3 id="upgrade-from-v1">Upgrade from v1</h3>
<p>v2 intentionally changes a few defaults and contracts:</p>
<ul>
<li>The action runtime is Node 24. Self-hosted runners and GitHub Enterprise Server must support Node 24 JavaScript actions.</li>
<li>Undated deprecations are included by default. Set <code>include-undated: &quot;false&quot;</code> for dated-only v1 behavior.</li>
<li>Feed content-age enforcement is opt-in because observation timestamps are not proof that every upstream scraper ran.</li>
<li>Finding date fields are nullable, and each finding now includes <code>status</code> and <code>findingId</code>.</li>
<li><code>has-findings</code> includes configured undated findings; use <code>has-breaches</code> for the blocking-policy result.</li>
</ul>
<p>Recommended immutable pin:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Check AI model lifecycle</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">oscarnilsson98/ai-model-end-of-life-action@08484f432ca1892f269e9d59913c158ea9b304e5</span> <span style="color:#75715e"># v2.0.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">models</span>: <span style="color:#e6db74">&#39;[{&#34;id&#34;:&#34;gpt-5.2&#34;,&#34;provider&#34;:&#34;openai&#34;}]&#39;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">days-before-shutdown</span>: <span style="color:#e6db74">&#34;90&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-within-days</span>: <span style="color:#e6db74">&#34;30&#34;</span>
</span></span></code></pre></div><p>See the <a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action#migrating-from-v1-to-v2">v1 to v2 migration table</a> and the advanced sections in the README before enabling discovery, feed-age policy, or change-aware Slack delivery.</p>
<h3 id="release-verification">Release verification</h3>
<ul>
<li>Independent defect-first review: no remaining findings.</li>
<li>120 deterministic tests with 402 assertions.</li>
<li>Source and CI-helper TypeScript checks.</li>
<li>Packaged action exercised on Linux, macOS, and Windows.</li>
<li>CodeQL completed with zero open alerts on the release commit.</li>
<li>Locked dependency audit found no known vulnerabilities.</li>
<li>The committed Node bundle reproduced twice locally and again from the tag in GitHub Actions.</li>
<li>The live raw and JSON Feed forms were equivalent across 416 lifecycle records and 9 serving platforms at release validation time.</li>
</ul>
<p>The feed remains community-maintained and provider dates can carry regional, tier, or migration-program qualifications. Treat this action as an early-warning, evidence, and policy layer—not as a replacement for provider notices or contracts.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/oscarnilsson98/ai-model-end-of-life-action/compare/v1.5.1...v2.0.0">https://github.com/oscarnilsson98/ai-model-end-of-life-action/compare/v1.5.1...v2.0.0</a></p>
]]></content:encoded></item><item><title>vord Static Analysis</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/vord-static-analysis/</link><pubDate>Sun, 02 Aug 2026 21:21:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/vord-static-analysis/</guid><description>Version updated for https://github.com/pmaojo/vord to version v0.4.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a static analysis tool written in Rust designed to ensure code quality before it’s committed. It performs various checks on the codebase, including detecting potential security issues, identifying duplication, and enforcing coding standards. The action can be used as a CI/CD tool to automatically analyze code changes and gate writes by an AI agent before they are merged into the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pmaojo/vord">https://github.com/pmaojo/vord</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vord-static-analysis">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a static analysis tool written in Rust designed to ensure code quality before it&rsquo;s committed. It performs various checks on the codebase, including detecting potential security issues, identifying duplication, and enforcing coding standards. The action can be used as a CI/CD tool to automatically analyze code changes and gate writes by an AI agent before they are merged into the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: add banner image to README by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/150">https://github.com/pmaojo/vord/pull/150</a></li>
<li>⚡ Bolt: add Rust hexagonal layering &amp; DDD fixtures by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/151">https://github.com/pmaojo/vord/pull/151</a></li>
<li>Bump version to v0.4.1 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/152">https://github.com/pmaojo/vord/pull/152</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.4.0...v0.4.1">https://github.com/pmaojo/vord/compare/v0.4.0...v0.4.1</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>docs: add banner image to README by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/150">https://github.com/pmaojo/vord/pull/150</a></li>
<li>⚡ Bolt: add Rust hexagonal layering &amp; DDD fixtures by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/151">https://github.com/pmaojo/vord/pull/151</a></li>
<li>Bump version to v0.4.1 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/152">https://github.com/pmaojo/vord/pull/152</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.4.0...v0.4.1">https://github.com/pmaojo/vord/compare/v0.4.0...v0.4.1</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>docs: add banner image to README by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/150">https://github.com/pmaojo/vord/pull/150</a></li>
<li>⚡ Bolt: add Rust hexagonal layering &amp; DDD fixtures by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/151">https://github.com/pmaojo/vord/pull/151</a></li>
<li>Bump version to v0.4.1 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/152">https://github.com/pmaojo/vord/pull/152</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.4.0...v0.4.1">https://github.com/pmaojo/vord/compare/v0.4.0...v0.4.1</a></p>
<h2 id="whats-changed-4">What&rsquo;s Changed</h2>
<ul>
<li>docs: add banner image to README by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/150">https://github.com/pmaojo/vord/pull/150</a></li>
<li>⚡ Bolt: add Rust hexagonal layering &amp; DDD fixtures by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/151">https://github.com/pmaojo/vord/pull/151</a></li>
<li>Bump version to v0.4.1 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/152">https://github.com/pmaojo/vord/pull/152</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.4.0...v0.4.1">https://github.com/pmaojo/vord/compare/v0.4.0...v0.4.1</a></p>
<h2 id="whats-changed-5">What&rsquo;s Changed</h2>
<ul>
<li>docs: add banner image to README by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/150">https://github.com/pmaojo/vord/pull/150</a></li>
<li>⚡ Bolt: add Rust hexagonal layering &amp; DDD fixtures by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/151">https://github.com/pmaojo/vord/pull/151</a></li>
<li>Bump version to v0.4.1 by @pmaojo in <a href="https://github.com/pmaojo/vord/pull/152">https://github.com/pmaojo/vord/pull/152</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/vord/compare/v0.4.0...v0.4.1">https://github.com/pmaojo/vord/compare/v0.4.0...v0.4.1</a></p>
]]></content:encoded></item><item><title>Publish HTML presentation to Slidesfly</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/publish-html-presentation-to-slidesfly/</link><pubDate>Sun, 02 Aug 2026 21:20:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/publish-html-presentation-to-slidesfly/</guid><description>Version updated for https://github.com/rare/slidesfly-integrations to version v0.3.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Slidesfly integrations and examples repository contains public, reproducible integration assets for Slidesfly, the publishing layer for existing HTML presentations. It provides GitHub Action for publishing or updating an HTML deck, Gemini CLI extension with Skill and hosted MCP, package-ready Claude Code plugin with Skill, and submitted Cursor plugin with Skill and bundled CLI runner. The repository intentionally excludes private Slidesfly SaaS application implementation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rare/slidesfly-integrations">https://github.com/rare/slidesfly-integrations</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/publish-html-presentation-to-slidesfly">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Slidesfly integrations and examples repository contains public, reproducible integration assets for Slidesfly, the publishing layer for existing HTML presentations. It provides GitHub Action for publishing or updating an HTML deck, Gemini CLI extension with Skill and hosted MCP, package-ready Claude Code plugin with Skill, and submitted Cursor plugin with Skill and bundled CLI runner. The repository intentionally excludes private Slidesfly SaaS application implementation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="npm-distribution-trust-materials">npm distribution trust materials</h2>
<ul>
<li>Mirrors the verified registry tarballs for @slidesfly/cli@0.1.3 and @slidesfly/mcp@0.1.0.</li>
<li>Includes SHA256SUMS and SHA512SUMS; npm integrity and SHA-1 values remain recorded in releases/npm-packages.json.</li>
<li>Upgrades the public GitHub Action to website CLI 0.1.3 and fails closed unless the downloaded CLI matches the pinned SHA-256.</li>
<li>Documents exact fixed-version npm installs and validates live registry tarballs in CI.</li>
</ul>
<h2 id="evidence">Evidence</h2>
<ul>
<li>Validate integrations CI passed on PR #19.</li>
<li>Node 22 clean-host CLI and MCP stdio checks passed.</li>
<li>Anonymous publish, reader/R2 byte identity, delete/404 recovery, uninstall, and exact reinstall passed.</li>
</ul>
<h2 id="known-limits">Known limits</h2>
<ul>
<li>Both npm packages currently expose only one version, so historical downgrade rollback is unavailable and is not claimed.</li>
<li>npm Trusted Publisher OIDC is configured but has not executed a tag publish yet; validate it on the next genuine package release.</li>
</ul>
]]></content:encoded></item><item><title>agents-doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/agents-doctor/</link><pubDate>Sun, 02 Aug 2026 21:18:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/agents-doctor/</guid><description>Version updated for https://github.com/satoissei/agents-doctor to version v0.2.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks and analyzes AGENTS.md files in a repository to determine what gets loaded by agents. It helps identify structural problems with root-level instructions that might overshadow specific code-related instructions, especially in monorepos. The tool reports the exact load order, retained bytes, and instructions that never reach the agent, making it useful for maintenance and debugging purposes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/satoissei/agents-doctor">https://github.com/satoissei/agents-doctor</a></strong> to version <strong>v0.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks and analyzes <code>AGENTS.md</code> files in a repository to determine what gets loaded by agents. It helps identify structural problems with root-level instructions that might overshadow specific code-related instructions, especially in monorepos. The tool reports the exact load order, retained bytes, and instructions that never reach the agent, making it useful for maintenance and debugging purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: harden public security boundaries by @satoissei in <a href="https://github.com/satoissei/agents-doctor/pull/6">https://github.com/satoissei/agents-doctor/pull/6</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/satoissei/agents-doctor/compare/v0.2.2...v0.2.3">https://github.com/satoissei/agents-doctor/compare/v0.2.2...v0.2.3</a></p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/agentauditkit-mcp-security-scan/</link><pubDate>Sun, 02 Aug 2026 21:17:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.66.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
AgentAuditKit is a security scanner designed to audit AI agent pipelines offline and deterministically. It identifies misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 major agent platforms. Unlike hosted scanners, AgentAuditKit runs fully offline and produces auditor-ready compliance-evidence packs using SARIF for the GitHub Security tab and PDF reports mapped to 12 security frameworks, ensuring precision in detection and auditability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.66</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>AgentAuditKit is a security scanner designed to audit AI agent pipelines offline and deterministically. It identifies misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 10 major agent platforms. Unlike hosted scanners, AgentAuditKit runs fully offline and produces auditor-ready compliance-evidence packs using SARIF for the GitHub Security tab and PDF reports mapped to 12 security frameworks, ensuring precision in detection and auditability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.66
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.66
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.66</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): Bump the github-actions group across 1 directory with 9 updates by @dependabot[bot] in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/506">https://github.com/sattyamjjain/agent-audit-kit/pull/506</a></li>
<li>chore(dependabot): stop re-proposing the ruff cap bump by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/521">https://github.com/sattyamjjain/agent-audit-kit/pull/521</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.65...v0.3.66">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.65...v0.3.66</a></p>
]]></content:encoded></item><item><title>Custom Amazon Bedrock Agent Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/custom-amazon-bedrock-agent-action/</link><pubDate>Sun, 02 Aug 2026 21:16:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/custom-amazon-bedrock-agent-action/</guid><description>Version updated for https://github.com/severity1/custom-amazon-bedrock-agent-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates code analysis using Amazon Bedrock Agent and integrates with Amazon Bedrock Knowledge Bases for enriched insights. It allows users to tailor prompt processing and integrate with various AWS services, enhancing flexibility and accuracy in their PR review processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/severity1/custom-amazon-bedrock-agent-action">https://github.com/severity1/custom-amazon-bedrock-agent-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/custom-amazon-bedrock-agent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates code analysis using Amazon Bedrock Agent and integrates with Amazon Bedrock Knowledge Bases for enriched insights. It allows users to tailor prompt processing and integrate with various AWS services, enhancing flexibility and accuracy in their PR review processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>21 closing pr should end agent session by @severity1 in <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27">https://github.com/severity1/custom-amazon-bedrock-agent-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0">https://github.com/severity1/custom-amazon-bedrock-agent-action/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/sherpa.sh/</link><pubDate>Sun, 02 Aug 2026 21:15:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-driven tool that simplifies infrastructure deployment by allowing developers to describe their needs in plain English. It automates the process of setting up servers, DNS configurations, SSL certificates, and more, without requiring developers to write complex YAML files or have extensive DevOps expertise. The action supports multiple cloud providers, frameworks, and integrates seamlessly with GitHub Actions and Claude Code CLI for local testing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-driven tool that simplifies infrastructure deployment by allowing developers to describe their needs in plain English. It automates the process of setting up servers, DNS configurations, SSL certificates, and more, without requiring developers to write complex YAML files or have extensive DevOps expertise. The action supports multiple cloud providers, frameworks, and integrates seamlessly with GitHub Actions and Claude Code CLI for local testing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI-powered deployments in plain English</p>
<p>Sherpa transforms any cloud provider into a deployment platform. Just describe what you want and let the AI handle the infrastructure.</p>
<p>prompt: &ldquo;Deploy my Next.js app on AWS Lambda with CloudFront CDN&rdquo;</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Plain English Infrastructure</strong> - No YAML configs, no Terraform, no DevOps expertise required</li>
<li><strong>Multi-Cloud</strong> - AWS and Cloudflare supported, with more providers coming</li>
<li><strong>GitHub Actions Integration</strong> - Push-to-deploy workflows with memory persistence</li>
<li><strong>Claude Code CLI Support</strong> - Test locally before committing</li>
</ul>
<h2 id="supported-features">Supported Features</h2>
<table>
  <thead>
      <tr>
          <th>Category</th>
          <th>Status</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Next.js deployments</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Static site hosting</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Serverless functions</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>VM provisioning (EC2)</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>SSL certificates</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>CDN configuration</td>
          <td>Partial</td>
      </tr>
  </tbody>
</table>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sherpa-sh/sherpa-action@v1.0.0-alpha</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic_api_key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prompt</span>: <span style="color:#e6db74">&#34;Deploy my app to Cloudflare&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">CLOUDFLARE_API_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.CLOUDFLARE_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">Alpha Notice</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#ae81ff">This is an early release. Expect breaking changes and rough edges. We&#39;d love your feedback—please https://github.com/sherpa-sh/sherpa-action/issues or https://discord.com/invite/Pn7N2Wwbjy.</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sun, 02 Aug 2026 21:14:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Swarm service by running npm ci and npm run bundle on a Linux system. It ensures that the necessary dependencies are installed and the application is bundled before pushing, helping to streamline the development workflow for deploying Dockerized applications using Docker Swarm.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Swarm service by running <code>npm ci</code> and <code>npm run bundle</code> on a Linux system. It ensures that the necessary dependencies are installed and the application is bundled before pushing, helping to streamline the development workflow for deploying Dockerized applications using Docker Swarm.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/ssg-static-site-generator/</link><pubDate>Sun, 02 Aug 2026 21:14:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.16.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: SSG (Static Site Generator) is a fast, deterministic static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It supports various themes and template engines, including built-in simple and krowy, and provides features like sitemap generation, image processing, and deployment to multiple platforms such as Cloudflare Pages, GitHub Pages, Netlify, Vercel, FTP, and SFTP.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary</strong>: SSG (Static Site Generator) is a fast, deterministic static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It supports various themes and template engines, including built-in <code>simple</code> and <code>krowy</code>, and provides features like sitemap generation, image processing, and deployment to multiple platforms such as Cloudflare Pages, GitHub Pages, Netlify, Vercel, FTP, and SFTP.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.16 — build-time AI (models + agents), notifications, comment email, related posts, ssg mcp, changelog data source, config watching by @spagu in <a href="https://github.com/spagu/ssg/pull/71">https://github.com/spagu/ssg/pull/71</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.15...v1.8.16">https://github.com/spagu/ssg/compare/v1.8.15...v1.8.16</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/classroom-to-sheets-integration/</link><pubDate>Sun, 02 Aug 2026 21:13:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates with Google Sheets to automatically update assignment results from GitHub Classroom assignments. It requires setting up Google Cloud credentials and sharing the spreadsheet with the service account email. The action can be configured in a GitHub Actions workflow to send task results to a specified sheet using student names as identifiers. It supports multiple tasks and dynamically creates columns for each graded task, updating or adding them as needed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates with Google Sheets to automatically update assignment results from GitHub Classroom assignments. It requires setting up Google Cloud credentials and sharing the spreadsheet with the service account email. The action can be configured in a GitHub Actions workflow to send task results to a specified sheet using student names as identifiers. It supports multiple tasks and dynamically creates columns for each graded task, updating or adding them as needed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated comments (bf17880)</li>
<li>Updated .dockerignore (498a6f7)</li>
<li>Updated readme (bbb6b5a)</li>
<li>Changed dockerfile to docker pull (8c8584b)</li>
<li>Changed dockerfile to docker pull (23fa131)</li>
<li>Fixed inputs (844c583)</li>
<li>Merge pull request #5 from SPGC/using-result-base64-string (042d99f)</li>
<li>Fixed input name (92dd201)</li>
<li>Merge pull request #4 from SPGC/using-result-base64-string (79dad97)</li>
<li>Code cleanup and fix bug with empty env variables (b474731)</li>
</ul>
]]></content:encoded></item><item><title>rag-redteam</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/rag-redteam/</link><pubDate>Sun, 02 Aug 2026 21:12:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/rag-redteam/</guid><description>Version updated for https://github.com/Srivatsa03/rag-redteam to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rag-redteam is a GitHub Action designed to red-team RAG pipelines by testing them against common vulnerabilities like indirect prompt injection, context leakage, and tool use injection. It automates the process of identifying potential security flaws in the retrieval pipeline without relying solely on general LLM scanners or model-level probing tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Srivatsa03/rag-redteam">https://github.com/Srivatsa03/rag-redteam</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rag-redteam">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>rag-redteam</code> is a GitHub Action designed to red-team RAG pipelines by testing them against common vulnerabilities like indirect prompt injection, context leakage, and tool use injection. It automates the process of identifying potential security flaws in the retrieval pipeline without relying solely on general LLM scanners or model-level probing tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>CI-native everywhere. Adds SARIF 2.1.0 output (&ndash;sarif) so findings appear in the GitHub Security tab / code scanning, exposes it as a GitHub Action input, and adds a pre-commit hook. Install or upgrade: pip install -U rag-redteam</p>
]]></content:encoded></item><item><title>Bundle Size Badge</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/bundle-size-badge/</link><pubDate>Sun, 02 Aug 2026 21:11:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/bundle-size-badge/</guid><description>Version updated for https://github.com/teplostanski/bundle-size-badge to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action Bundle Size Badge measures the default entry as a minified bundle (min + gzip/brotli) and appends an immutable per-version record to publish SVG badges on a dedicated git branch. It solves the problem of providing users with accurate import cost information by focusing on the entry bundle size, not disk space usage.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/teplostanski/bundle-size-badge">https://github.com/teplostanski/bundle-size-badge</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bundle-size-badge">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action Bundle Size Badge measures the default entry as a minified bundle (<code>min + gzip</code>/brotli) and appends an immutable per-version record to publish SVG badges on a dedicated git branch. It solves the problem of providing users with accurate import cost information by focusing on the entry bundle size, not disk space usage.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/teplostanski/bundle-size-badge/compare/v1...v1.0.2">https://github.com/teplostanski/bundle-size-badge/compare/v1...v1.0.2</a></p>
]]></content:encoded></item><item><title>ArchGuard - Architectural Drift Detector</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/archguard-architectural-drift-detector/</link><pubDate>Sun, 02 Aug 2026 21:10:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/archguard-architectural-drift-detector/</guid><description>Version updated for https://github.com/Tgenz1213/ArchGuard to version v1.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ArchGuard is a CLI tool that uses LLMs to verify code changes against established Architectural Decision Records (ADRs). It helps prevent architectural drift by analyzing code changes and ensuring they comply with ADRs. The action automates the process of indexing ADRs and checking for compliance, providing alerts before code merges that violate architectural rules.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tgenz1213/ArchGuard">https://github.com/Tgenz1213/ArchGuard</a></strong> to version <strong>v1.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/archguard-architectural-drift-detector">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ArchGuard is a CLI tool that uses LLMs to verify code changes against established Architectural Decision Records (ADRs). It helps prevent architectural drift by analyzing code changes and ensuring they comply with ADRs. The action automates the process of indexing ADRs and checking for compliance, providing alerts before code merges that violate architectural rules.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Add e2e test coverage for the dual chat/embedding provider split (closes #54).</p>
<ul>
<li><code>internal/cli.Execute</code>&rsquo;s mock-provider test injection point now supports two distinct mock providers (one per role: chat, embed), exercising the dual-provider routing added in PR #52 end-to-end via a real <code>archguard index</code> + <code>archguard check</code> subprocess run, not just at the unit level.</li>
<li>Test-only change: no new CLI flags, config fields, or exit codes; no user-facing behavior change.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Tgenz1213/ArchGuard/compare/v1.4.0...v1.4.1">https://github.com/Tgenz1213/ArchGuard/compare/v1.4.0...v1.4.1</a></p>
]]></content:encoded></item><item><title>TimeTick Tests Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/timetick-tests-runner/</link><pubDate>Sun, 02 Aug 2026 21:08:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/timetick-tests-runner/</guid><description>Version updated for https://github.com/TimeTickIO/timetick-ci to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates OCPP tests using Timetick, a tool for verifying vehicle-to-grid (V2G) interoperability. It can run individual tests or test plans and automatically fail the pipeline if any tests fail. The action supports various options such as creating simulators, specifying existing simulators and hardware, and extracting results into outputs that can be used in subsequent steps or attached to merge requests for GitLab CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TimeTickIO/timetick-ci">https://github.com/TimeTickIO/timetick-ci</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/timetick-tests-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates OCPP tests using Timetick, a tool for verifying vehicle-to-grid (V2G) interoperability. It can run individual tests or test plans and automatically fail the pipeline if any tests fail. The action supports various options such as creating simulators, specifying existing simulators and hardware, and extracting results into outputs that can be used in subsequent steps or attached to merge requests for GitLab CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>docs: correct GitLab usage (badafe6)</li>
<li>feat: add serial number configuration (b2a9067)</li>
<li>docs: gh action template info (81855f9)</li>
<li>init: v1 for github and gitlab (3b1b4d3)</li>
</ul>
]]></content:encoded></item><item><title>AWS CDK Diff PR Commenter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/aws-cdk-diff-pr-commenter/</link><pubDate>Sun, 02 Aug 2026 21:07:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/aws-cdk-diff-pr-commenter/</guid><description>Version updated for https://github.com/towardsthecloud/aws-cdk-diff-pr-commenter to version v1.6.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 6 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of posting CDK diff output as comments on pull requests, helping teams catch potential issues before deploying CDK changes. It supports custom headers and highlights IAM statement, Security Group, Parameter, and Resource changes for better organization in multi-stack setups.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/towardsthecloud/aws-cdk-diff-pr-commenter">https://github.com/towardsthecloud/aws-cdk-diff-pr-commenter</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>6</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aws-cdk-diff-pr-commenter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of posting CDK diff output as comments on pull requests, helping teams catch potential issues before deploying CDK changes. It supports custom headers and highlights IAM statement, Security Group, Parameter, and Resource changes for better organization in multi-stack setups.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="160-2026-08-02"><a href="https://github.com/towardsthecloud/github-actions-builder/compare/v1.5.0...v1.6.0">1.6.0</a> (2026-08-02)</h2>
<h3 id="features">Features</h3>
]]></content:encoded></item><item><title>Terraform Plan PR Commenter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/terraform-plan-pr-commenter/</link><pubDate>Sun, 02 Aug 2026 21:06:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/terraform-plan-pr-commenter/</guid><description>Version updated for https://github.com/towardsthecloud/terraform-plan-pr-commenter to version v1.6.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of posting Terraform plan outputs as comments on Pull Requests, helping teams identify changes to infrastructure directly within their workflow. It supports custom headers and binary plan files for accurate change detection, enhancing collaboration during code reviews.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/towardsthecloud/terraform-plan-pr-commenter">https://github.com/towardsthecloud/terraform-plan-pr-commenter</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>2</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/terraform-plan-pr-commenter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of posting Terraform plan outputs as comments on Pull Requests, helping teams identify changes to infrastructure directly within their workflow. It supports custom headers and binary plan files for accurate change detection, enhancing collaboration during code reviews.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="160-2026-08-02"><a href="https://github.com/towardsthecloud/github-actions-builder/compare/v1.5.0...v1.6.0">1.6.0</a> (2026-08-02)</h2>
<h3 id="features">Features</h3>
<ul>
<li>embed cloudburn usage assumptions in the pr comment (<a href="https://github.com/towardsthecloud/github-actions-builder/issues/13">#13</a>) (<a href="https://github.com/towardsthecloud/github-actions-builder/commit/79d5eadf07a07f2d12436352a9f2080077bbe286">79d5ead</a>), closes <a href="https://github.com/towardsthecloud/terraform-plan-pr-commenter/issues/1">towardsthecloud/terraform-plan-pr-commenter#1</a></li>
</ul>
]]></content:encoded></item><item><title>MCP Test Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/mcp-test-harness/</link><pubDate>Sun, 02 Aug 2026 21:05:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/mcp-test-harness/</guid><description>Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v4.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary of the MCP Test Harness GitHub Action The MCP Test Harness is a CI/CD tool designed to automate the testing of Management Control Plane (MCP) servers using pytest-style syntax. It solves the problem of automating and standardizing testing processes for MCP deployments, ensuring that all components are tested thoroughly before deployment. The action provides key capabilities such as running tests, generating reports, and integrating with various reporting tools, making it a valuable tool for MCP administrators and developers aiming to maintain quality and reliability in their system deployments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaquarkhan/mcp-test-harness">https://github.com/vaquarkhan/mcp-test-harness</a></strong> to version <strong>v4.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-test-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<h3 id="summary-of-the-mcp-test-harness-github-action">Summary of the MCP Test Harness GitHub Action</h3>
<p>The MCP Test Harness is a CI/CD tool designed to automate the testing of Management Control Plane (MCP) servers using pytest-style syntax. It solves the problem of automating and standardizing testing processes for MCP deployments, ensuring that all components are tested thoroughly before deployment. The action provides key capabilities such as running tests, generating reports, and integrating with various reporting tools, making it a valuable tool for MCP administrators and developers aiming to maintain quality and reliability in their system deployments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="summary">Summary</h2>
<ul>
<li>Align all 23 PyPI packages at <strong>4.0.1</strong></li>
<li>Publish GitHub Release so Latest is no longer stuck on v3.0.10</li>
<li>Docs / scan-report / handbook from 4.0.0 line</li>
</ul>
<p>See CHANGELOG.md for details.</p>
]]></content:encoded></item><item><title>PlatformIO Dependency Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/platformio-dependency-updater/</link><pubDate>Sun, 02 Aug 2026 21:04:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/platformio-dependency-updater/</guid><description>Version updated for https://github.com/VIPnytt/platformio-dependency-updater to version v1.0.1.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks a project’s platformio.ini file for available updates for its dependencies. It creates pull requests with the latest versions, including release notes and supports various dependency sources such as PlatformIO, Espressif, Git-based repositories, and custom platform-package versions. The action includes options to limit the cooldown period between updates, specify labels, and control the number of open PRs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VIPnytt/platformio-dependency-updater">https://github.com/VIPnytt/platformio-dependency-updater</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/platformio-dependency-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks a project&rsquo;s <code>platformio.ini</code> file for available updates for its dependencies. It creates pull requests with the latest versions, including release notes and supports various dependency sources such as PlatformIO, Espressif, Git-based repositories, and custom platform-package versions. The action includes options to limit the cooldown period between updates, specify labels, and control the number of open PRs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at main -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="miscellaneous">Miscellaneous</h3>
<ul>
<li>Improved handling of owner-less Registry packages by @JanPetterMG in <a href="https://github.com/VIPnytt/platformio-dependency-updater/pull/44">https://github.com/VIPnytt/platformio-dependency-updater/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VIPnytt/platformio-dependency-updater/compare/v1.0.0...v1.0.1">https://github.com/VIPnytt/platformio-dependency-updater/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>Picket Secret Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/picket-secret-scanner/</link><pubDate>Sun, 02 Aug 2026 21:03:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/picket-secret-scanner/</guid><description>Version updated for https://github.com/willibrandon/picket to version v0.2.8.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Picket is a MIT-licensed secrets scanner for .NET that provides a Gitleaks-compatible command surface, Picket-native scanning capabilities, Native AOT release binaries, dotnet tool packages, and embeddable AOT-safe libraries. It can scan staged, unstaged, and untracked Git changes, Hugging Face models, datasets, Spaces, or buckets with read-only tokens stored in an environment variable, and GitLab issues, comments, releases, and release assets. The action supports CI integrations for GitHub Actions and Azure Pipelines, and it provides a Coding Agent Guards tool to inspect Codex and Claude hook events. Picket also publishes embeddable packages for rules, scanning, reporting, security, and documentation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/willibrandon/picket">https://github.com/willibrandon/picket</a></strong> to version <strong>v0.2.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/picket-secret-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Picket is a MIT-licensed secrets scanner for .NET that provides a Gitleaks-compatible command surface, Picket-native scanning capabilities, Native AOT release binaries, dotnet tool packages, and embeddable AOT-safe libraries. It can scan staged, unstaged, and untracked Git changes, Hugging Face models, datasets, Spaces, or buckets with read-only tokens stored in an environment variable, and GitLab issues, comments, releases, and release assets. The action supports CI integrations for GitHub Actions and Azure Pipelines, and it provides a Coding Agent Guards tool to inspect Codex and Claude hook events. Picket also publishes embeddable packages for rules, scanning, reporting, security, and documentation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release artifacts include SHA-256 checksums, package-size metadata, and GitHub artifact attestations.</p>
]]></content:encoded></item><item><title>vibecheck-ai-slop</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/vibecheck-ai-slop/</link><pubDate>Sun, 02 Aug 2026 21:02:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/vibecheck-ai-slop/</guid><description>Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.15.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The vibecheck GitHub Action automates the detection of AI-generated code smells through ESLint rules. It helps identify common patterns in generated code such as hardcoded secrets, empty catch blocks, and insecure SQL queries. The action runs locally, is zero-config, and provides real-time feedback on issues found in your codebase.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuvrajangadsingh/vibecheck">https://github.com/yuvrajangadsingh/vibecheck</a></strong> to version <strong>v1.15.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibecheck-ai-slop">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The vibecheck GitHub Action automates the detection of AI-generated code smells through ESLint rules. It helps identify common patterns in generated code such as hardcoded secrets, empty catch blocks, and insecure SQL queries. The action runs locally, is zero-config, and provides real-time feedback on issues found in your codebase.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="html-scanning">HTML scanning</h2>
<p><code>.html</code> and <code>.htm</code> files are now scanned. Inline <code>&lt;script&gt;</code> bodies are extracted and linted as JS, and script type matching follows the WHATWG MIME sniffing standard, so JSON, template and importmap scripts are skipped rather than parsed as code. Scripts with <code>src=</code> are treated as external and ignored.</p>
<p>HTML findings are not auto-fixable. A <code>remove-line</code> fix against an extracted script line would either no-op against the snippet guard or delete the surrounding tags, so <code>--fix</code> now declines them instead of reporting a fix it cannot make.</p>
<h2 id="a-real-lexer">A real lexer</h2>
<p>String, template, regex and comment masking moved into <code>src/lexer.ts</code> and is now shared by suppressions, brace tracking and rule matching. <code>suppressions.ts</code> lost 127 lines of hand-rolled scanning in the process.</p>
<p>The practical effect is fewer phantom matches: a <code>}</code> inside a string no longer closes a block that was never open, and a commented-out call no longer counts as a call.</p>
<h2 id="no-console-pollution-false-positives">no-console-pollution false positives</h2>
<p>The rule was flagging console calls that never reach production.</p>
<p>Running v1.14 against a Vite app produced 19 findings. All 19 were wrong. Thirteen sat inside <code>if (import.meta.env.DEV)</code> blocks, which the bundler strips from the production build entirely. The other six were in a <code>scripts/</code> CLI, where writing to stdout is the whole point of the file.</p>
<p>The rule could not have caught this before, because it only ever saw one line at a time and the guard is on a different line. It is now block-aware and tracks the enclosing guard: <code>import.meta.env.DEV</code>, <code>__DEV__</code>, <code>NODE_ENV !== 'production'</code> and <code>NODE_ENV === 'development'</code>, plus the single-line form. <code>scripts/</code>, <code>bin/</code>, <code>tools/</code> and <code>tasks/</code> are treated as CLI directories.</p>
<p><code>NODE_ENV === 'production'</code> is deliberately not treated as a guard. That block ships, so a console call inside it is still a real finding.</p>
<h2 id="other-fixes">Other fixes</h2>
<ul>
<li>single-line <code>catch</code> body extraction no longer runs past the block when outer scopes close on the same line</li>
<li>stdout is allowed to flush before exit instead of calling <code>process.exit</code>, which could truncate piped output</li>
</ul>
<p>341 tests.</p>
<pre tabindex="0"><code>npx @yuvrajangadsingh/vibecheck .
</code></pre><p><strong>Full Changelog</strong>: <a href="https://github.com/yuvrajangadsingh/vibecheck/compare/v1.14.0...v1.15.0">https://github.com/yuvrajangadsingh/vibecheck/compare/v1.14.0...v1.15.0</a></p>
]]></content:encoded></item><item><title>yunq Static Analysis</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/yunq-static-analysis/</link><pubDate>Sun, 02 Aug 2026 06:22:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/yunq-static-analysis/</guid><description>Version updated for https://github.com/pmaojo/yunq to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The yunq action is a tool that provides static analysis and code quality checks in Rust. It automates the process of analyzing code before it reaches disk, ensuring that AI agents are judged by the same guardrail as the platform itself. The key capabilities include:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pmaojo/yunq">https://github.com/pmaojo/yunq</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yunq-static-analysis">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The yunq action is a tool that provides static analysis and code quality checks in Rust. It automates the process of analyzing code before it reaches disk, ensuring that AI agents are judged by the same guardrail as the platform itself. The key capabilities include:</p>
<ul>
<li>Analyzing code written in multiple languages</li>
<li>Ensuring compliance with coding standards and policies</li>
<li>Providing real-time feedback on code quality and potential issues</li>
</ul>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(secrets): ignore lockfiles, yaml, and css variables in high entropy rule by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/134">https://github.com/pmaojo/yunq/pull/134</a></li>
<li>fix(secrets): ignore lockfiles, yaml, and css variables in high entro… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/135">https://github.com/pmaojo/yunq/pull/135</a></li>
<li>feat: advanced static analysis algorithms, A/A/A ratings, SARIF 2.1.0 exporter &amp; React doctor rules by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/136">https://github.com/pmaojo/yunq/pull/136</a></li>
<li>feat(llm): add Google Gemini 3.5+ support &amp; thought_signature preserv… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/137">https://github.com/pmaojo/yunq/pull/137</a></li>
<li>feat(rules): Add owasp:insecure-file-permissions rule by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/139">https://github.com/pmaojo/yunq/pull/139</a></li>
<li>Feat/rulesets expansion and kickoff by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/140">https://github.com/pmaojo/yunq/pull/140</a></li>
<li>feat: add yunq MCP Server, Architecture Graph &amp; Typeshare Rulesets, a… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/141">https://github.com/pmaojo/yunq/pull/141</a></li>
<li>Feature/research gaps by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/142">https://github.com/pmaojo/yunq/pull/142</a></li>
<li>chore: Bump version to v0.3.0 by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/143">https://github.com/pmaojo/yunq/pull/143</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/yunq/compare/v0.2.1...v0.3.0">https://github.com/pmaojo/yunq/compare/v0.2.1...v0.3.0</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>fix(secrets): ignore lockfiles, yaml, and css variables in high entropy rule by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/134">https://github.com/pmaojo/yunq/pull/134</a></li>
<li>fix(secrets): ignore lockfiles, yaml, and css variables in high entro… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/135">https://github.com/pmaojo/yunq/pull/135</a></li>
<li>feat: advanced static analysis algorithms, A/A/A ratings, SARIF 2.1.0 exporter &amp; React doctor rules by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/136">https://github.com/pmaojo/yunq/pull/136</a></li>
<li>feat(llm): add Google Gemini 3.5+ support &amp; thought_signature preserv… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/137">https://github.com/pmaojo/yunq/pull/137</a></li>
<li>feat(rules): Add owasp:insecure-file-permissions rule by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/139">https://github.com/pmaojo/yunq/pull/139</a></li>
<li>Feat/rulesets expansion and kickoff by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/140">https://github.com/pmaojo/yunq/pull/140</a></li>
<li>feat: add yunq MCP Server, Architecture Graph &amp; Typeshare Rulesets, a… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/141">https://github.com/pmaojo/yunq/pull/141</a></li>
<li>Feature/research gaps by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/142">https://github.com/pmaojo/yunq/pull/142</a></li>
<li>chore: Bump version to v0.3.0 by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/143">https://github.com/pmaojo/yunq/pull/143</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/yunq/compare/v0.2.1...v0.3.0">https://github.com/pmaojo/yunq/compare/v0.2.1...v0.3.0</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>fix(secrets): ignore lockfiles, yaml, and css variables in high entropy rule by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/134">https://github.com/pmaojo/yunq/pull/134</a></li>
<li>fix(secrets): ignore lockfiles, yaml, and css variables in high entro… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/135">https://github.com/pmaojo/yunq/pull/135</a></li>
<li>feat: advanced static analysis algorithms, A/A/A ratings, SARIF 2.1.0 exporter &amp; React doctor rules by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/136">https://github.com/pmaojo/yunq/pull/136</a></li>
<li>feat(llm): add Google Gemini 3.5+ support &amp; thought_signature preserv… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/137">https://github.com/pmaojo/yunq/pull/137</a></li>
<li>feat(rules): Add owasp:insecure-file-permissions rule by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/139">https://github.com/pmaojo/yunq/pull/139</a></li>
<li>Feat/rulesets expansion and kickoff by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/140">https://github.com/pmaojo/yunq/pull/140</a></li>
<li>feat: add yunq MCP Server, Architecture Graph &amp; Typeshare Rulesets, a… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/141">https://github.com/pmaojo/yunq/pull/141</a></li>
<li>Feature/research gaps by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/142">https://github.com/pmaojo/yunq/pull/142</a></li>
<li>chore: Bump version to v0.3.0 by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/143">https://github.com/pmaojo/yunq/pull/143</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/yunq/compare/v0.2.1...v0.3.0">https://github.com/pmaojo/yunq/compare/v0.2.1...v0.3.0</a></p>
<h2 id="whats-changed-4">What&rsquo;s Changed</h2>
<ul>
<li>fix(secrets): ignore lockfiles, yaml, and css variables in high entropy rule by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/134">https://github.com/pmaojo/yunq/pull/134</a></li>
<li>fix(secrets): ignore lockfiles, yaml, and css variables in high entro… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/135">https://github.com/pmaojo/yunq/pull/135</a></li>
<li>feat: advanced static analysis algorithms, A/A/A ratings, SARIF 2.1.0 exporter &amp; React doctor rules by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/136">https://github.com/pmaojo/yunq/pull/136</a></li>
<li>feat(llm): add Google Gemini 3.5+ support &amp; thought_signature preserv… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/137">https://github.com/pmaojo/yunq/pull/137</a></li>
<li>feat(rules): Add owasp:insecure-file-permissions rule by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/139">https://github.com/pmaojo/yunq/pull/139</a></li>
<li>Feat/rulesets expansion and kickoff by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/140">https://github.com/pmaojo/yunq/pull/140</a></li>
<li>feat: add yunq MCP Server, Architecture Graph &amp; Typeshare Rulesets, a… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/141">https://github.com/pmaojo/yunq/pull/141</a></li>
<li>Feature/research gaps by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/142">https://github.com/pmaojo/yunq/pull/142</a></li>
<li>chore: Bump version to v0.3.0 by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/143">https://github.com/pmaojo/yunq/pull/143</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/yunq/compare/v0.2.1...v0.3.0">https://github.com/pmaojo/yunq/compare/v0.2.1...v0.3.0</a></p>
<h2 id="whats-changed-5">What&rsquo;s Changed</h2>
<ul>
<li>fix(secrets): ignore lockfiles, yaml, and css variables in high entropy rule by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/134">https://github.com/pmaojo/yunq/pull/134</a></li>
<li>fix(secrets): ignore lockfiles, yaml, and css variables in high entro… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/135">https://github.com/pmaojo/yunq/pull/135</a></li>
<li>feat: advanced static analysis algorithms, A/A/A ratings, SARIF 2.1.0 exporter &amp; React doctor rules by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/136">https://github.com/pmaojo/yunq/pull/136</a></li>
<li>feat(llm): add Google Gemini 3.5+ support &amp; thought_signature preserv… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/137">https://github.com/pmaojo/yunq/pull/137</a></li>
<li>feat(rules): Add owasp:insecure-file-permissions rule by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/139">https://github.com/pmaojo/yunq/pull/139</a></li>
<li>Feat/rulesets expansion and kickoff by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/140">https://github.com/pmaojo/yunq/pull/140</a></li>
<li>feat: add yunq MCP Server, Architecture Graph &amp; Typeshare Rulesets, a… by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/141">https://github.com/pmaojo/yunq/pull/141</a></li>
<li>Feature/research gaps by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/142">https://github.com/pmaojo/yunq/pull/142</a></li>
<li>chore: Bump version to v0.3.0 by @pmaojo in <a href="https://github.com/pmaojo/yunq/pull/143">https://github.com/pmaojo/yunq/pull/143</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pmaojo/yunq/compare/v0.2.1...v0.3.0">https://github.com/pmaojo/yunq/compare/v0.2.1...v0.3.0</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/postman-onboarding-repo-sync/</link><pubDate>Sun, 02 Aug 2026 06:21:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.8.7.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action exports Postman collections and environments into a repository, wires CI, mock servers, and monitors around them. It automates the onboarding of Postman projects to an organization’s repository by synchronizing assets and configuring CI workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.8.7</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action exports Postman collections and environments into a repository, wires CI, mock servers, and monitors around them. It automates the onboarding of Postman projects to an organization&rsquo;s repository by synchronizing assets and configuring CI workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>perf(repo-sync): bound artifact acquisition reads by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/116">https://github.com/postman-cs/postman-repo-sync-action/pull/116</a></li>
<li>fix(deps): replace deprecated Faker with compatible v6 by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/117">https://github.com/postman-cs/postman-repo-sync-action/pull/117</a></li>
<li>fix(repo-mutation): reconcile stale branch before push by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/118">https://github.com/postman-cs/postman-repo-sync-action/pull/118</a></li>
<li>fix(repo-mutation): resolve generated artifact conflicts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/119">https://github.com/postman-cs/postman-repo-sync-action/pull/119</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.8.7">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.8.7</a></p>
]]></content:encoded></item><item><title>QWED Protocol Verification</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/qwed-protocol-verification/</link><pubDate>Sun, 02 Aug 2026 06:19:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/qwed-protocol-verification/</guid><description>Version updated for https://github.com/QWED-AI/qwed-verification to version v6.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary QWED Verification is a production-grade, model-agnostic trust boundary designed to detect and prevent AI hallucinations. It works with any LLM through local models or Docker images, ensuring deterministic verification before output enters production.
What’s Changed v6.0.0 — Trust Boundary Completion Completes the Trust Boundary Completion epic (#263) — all 12/12 sub-issues closed. Every verification API pathway now returns DiagnosticResult and routes through enforce_trust_decision. The trust boundary is no longer advisory: the control plane requires and verifies attestation before admitting VERIFIED results, and VERIFIED is a protocol guarantee backed by a non-empty, deterministic proof_ref — never by execution, agreement, confidence, or provenance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/QWED-AI/qwed-verification">https://github.com/QWED-AI/qwed-verification</a></strong> to version <strong>v6.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/qwed-protocol-verification">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>QWED Verification is a production-grade, model-agnostic trust boundary designed to detect and prevent AI hallucinations. It works with any LLM through local models or Docker images, ensuring deterministic verification before output enters production.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v600--trust-boundary-completion">v6.0.0 — Trust Boundary Completion</h2>
<p>Completes the <strong>Trust Boundary Completion epic (#263)</strong> — all 12/12 sub-issues closed. Every verification API pathway now returns <code>DiagnosticResult</code> and routes through <code>enforce_trust_decision</code>. The trust boundary is no longer advisory: the control plane requires and verifies attestation before admitting VERIFIED results, and VERIFIED is a protocol guarantee backed by a non-empty, deterministic <code>proof_ref</code> — never by execution, agreement, confidence, or provenance.</p>
<blockquote>
<p><strong>⚠️ Breaking change:</strong> <code>/verify/*</code> API responses now use the unified <code>DiagnosticResult</code> schema (status / <code>agent_message</code> / <code>developer_fields</code> / <code>proof_ref</code>). Consumers of the previous ad-hoc dict responses must migrate.</p>
</blockquote>
<h3 id="architecture-observation-vs-admission">Architecture: Observation vs Admission</h3>
<ul>
<li><strong>All <code>/verify/*</code> endpoints return <code>DiagnosticResult</code></strong> — unified 3-layer response contract across every verification surface (#276)</li>
<li><strong>Mandatory attestation in the control plane</strong> — <code>require_attestation=True</code>, attestation issued and verified at the admission boundary; enforced status drives the HTTP response status (#278)</li>
<li><strong>Batch math</strong> routes through <code>DiagnosticResult</code> + attestation + <code>enforce_trust_decision</code> (#282)</li>
<li><strong>Attestation scope alignment</strong> — attest the translated expression, not the natural-language query, so <code>query_hash</code> binds to what was actually verified (#285)</li>
<li><strong>Architecture contract codified</strong> — API = observation surface (honest witness), Control Plane = admission authority (judge); QWED_RULES #13-15</li>
</ul>
<h3 id="verified-is-a-protocol-guarantee">VERIFIED is a protocol guarantee</h3>
<ul>
<li><strong>ConsensusResult</strong> uses <code>DiagnosticStatus</code> enum with <code>proof_ref</code> + <code>verified_evidence</code> (#280)</li>
<li><strong>FactVerifier</strong> heuristic SUPPORTED verdict → UNVERIFIABLE with <code>advisory_checks</code> (#283)</li>
<li><strong>Consensus code execution</strong> advisory-only, VERIFIED → UNVERIFIABLE (#281)</li>
<li><strong>Consensus stats computation</strong> advisory-only, never VERIFIED (#277)</li>
<li><strong>LogicVerifier</strong> migrated to <code>DiagnosticResult</code> (#262)</li>
<li><strong>AgentStateGuard</strong> <code>proof_ref</code> = real sha256 of committed bytes, not a static sentence (#284)</li>
</ul>
<h3 id="engineering--security-hardening">Engineering &amp; Security Hardening</h3>
<ul>
<li><strong>TOCTOU closure</strong> in <code>enforce_trust_decision</code> — <code>developer_fields</code> snapshotted via recursive rebuild (no deepcopy alias window), fail-closed snapshot (#273, #290)</li>
<li><strong>Attestation signature verified before claim decode</strong> — silent generic error for all failure modes (#275, #287)</li>
<li><strong>Tenant-isolated verification cache</strong> — <code>VerificationCache</code> keys namespaced by normalized <code>tenant_id</code> (#274, #286)</li>
<li><strong>Unicode normalization</strong> in AgentStateGuard canonicalization — NFC collisions rejected (#272, #288)</li>
<li><strong>Mandatory proof artifact</strong> for VERIFIED attestations (issuance + consumption, #248)</li>
<li><strong>Credential / JWT / dockerignore security alerts</strong> resolved (#249)</li>
<li><strong>Math whitelist injection bypass</strong> removed (#251)</li>
<li><strong>Engine classification docs</strong> — Proof / Policy Enforcement / Advisory (#247)</li>
</ul>
<h3 id="rules--protocol-semantics">Rules &amp; Protocol Semantics</h3>
<ul>
<li><code>QWED_RULES.md</code> codifies the trust-boundary contract: <strong>#13 Separation of Responsibilities</strong>, <strong>#14 Verification Semantics</strong> (non-empty <code>proof_ref</code> bound to deterministic evidence), <strong>#15 Truth Before Policy</strong> (admission is a separate decision; original result + evidence unchanged). Rules #7/#8 updated for admission-boundary and deterministic-proof semantics.</li>
</ul>
<h3 id="version-propagation">Version Propagation</h3>
<ul>
<li><code>qwed</code> (PyPI): <code>5.3.0</code> -&gt; <code>6.0.0</code></li>
<li><code>qwed_sdk</code> (Python): <code>5.3.0</code> -&gt; <code>6.0.0</code></li>
<li><code>@qwed-ai/sdk</code> (NPM): <code>5.3.0</code> -&gt; <code>6.0.0</code></li>
<li><code>qwed</code> (crates.io/Rust): <code>5.3.0</code> -&gt; <code>6.0.0</code></li>
<li>API version marker: <code>5.3.0</code> -&gt; <code>6.0.0</code></li>
<li>Docker images: <code>5.3.0</code> -&gt; <code>6.0.0</code></li>
</ul>
<h3 id="ecosystem-status">Ecosystem Status</h3>
<ul>
<li><strong>Trust boundary complete</strong> — 12/12 sub-issues closed (Epic #263)</li>
<li><strong>API surfaces conformant</strong> — remaining engine-internal migrations tracked under META #216</li>
<li><strong>Full test suite:</strong> 1655 passed, 102 skipped</li>
</ul>
<h3 id="included-prs">Included PRs</h3>
<ul>
<li>#247 docs: engine classification — Proof / Policy Enforcement / Advisory</li>
<li>#248 fix: enforce mandatory proof artifact on VERIFIED attestations</li>
<li>#249 fix: resolve credential / JWT / dockerignore security alerts</li>
<li>#251 fix: remove math whitelist injection bypass</li>
<li>#260 fix: hybrid engine advisory-only — never VERIFIED without proof</li>
<li>#261 fix: FactVerifier advisory-only</li>
<li>#262 feat: LogicVerifier migrated to DiagnosticResult</li>
<li>#276 fix: migrate all /verify/* endpoints to return DiagnosticResult</li>
<li>#277 fix: consensus stats advisory-only, never VERIFIED</li>
<li>#278 fix: control plane trust enforcement mandatory</li>
<li>#280 fix: ConsensusResult DiagnosticStatus enum + proof_ref + verified_evidence</li>
<li>#281 fix: consensus code execution advisory-only</li>
<li>#282 fix: batch math DiagnosticResult + attestation + enforce_trust_decision</li>
<li>#283 fix: FactVerifier SUPPORTED → UNVERIFIABLE with advisory_checks</li>
<li>#284 fix: AgentStateGuard proof_ref real sha256</li>
<li>#285 fix: attest translated expression, not natural language query</li>
<li>#286 fix: VerificationCache tenant isolation</li>
<li>#287 fix: attestation verify-before-decode + silent generic error</li>
<li>#288 fix: NFC-normalize AgentStateGuard canonicalization</li>
<li>#289 fix: mock network in secret redaction tests (CI)</li>
<li>#290 fix: close TOCTOU in enforce_trust_decision</li>
<li>#291 release: v6.0.0-pre — version bumps, README reframe, CHANGELOG, rules</li>
</ul>
<h3 id="changelog">Changelog</h3>
<p><a href="https://github.com/QWED-AI/qwed-verification/blob/main/CHANGELOG.md#600---2026-08-02">https://github.com/QWED-AI/qwed-verification/blob/main/CHANGELOG.md#600---2026-08-02</a></p>
]]></content:encoded></item><item><title>Open Source Project Security Baseline Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/open-source-project-security-baseline-scanner/</link><pubDate>Sun, 02 Aug 2026 06:18:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/open-source-project-security-baseline-scanner/</guid><description>Version updated for https://github.com/revanite-io/osps-baseline-action to version v1.3.4.
This action is used across all versions by 33 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action for OSPS Baseline automates security assessments against the Open Source Project Security Baseline by running predefined controls on a GitHub repository. It outputs results in YAML, JSON, or SARIF format, allowing users to integrate assessment reports into their CI/CD pipelines and automatically upload them to GitHub’s Security tab as SARIF files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/revanite-io/osps-baseline-action">https://github.com/revanite-io/osps-baseline-action</a></strong> to version <strong>v1.3.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>33</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/open-source-project-security-baseline-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action for OSPS Baseline automates security assessments against the Open Source Project Security Baseline by running predefined controls on a GitHub repository. It outputs results in YAML, JSON, or SARIF format, allowing users to integrate assessment reports into their CI/CD pipelines and automatically upload them to GitHub&rsquo;s Security tab as SARIF files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="changelog">Changelog</h1>
<h2 id="-bug-fixes">🐛 Bug Fixes</h2>
<ul>
<li>fix: bump pvtr scanner image to v0.28.0 @jmeridth (#45)</li>
</ul>
<h2 id="-maintenance">🧰 Maintenance</h2>
<ul>
<li>chore(deps): bump the dependencies group across 1 directory with 3 updates @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#44)</li>
<li>chore(deps): bump the dependencies group with 2 updates @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#42)</li>
<li>chore(deps): bump the dependencies group with 5 updates @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#41)</li>
<li>chore(deps): bump the dependencies group with 3 updates @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#39)</li>
<li>chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#40)</li>
<li>chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2 in the dependencies group @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#38)</li>
<li>chore(deps): bump the dependencies group with 2 updates @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#37)</li>
<li>chore(deps): bump the dependencies group with 5 updates @<a href="https://github.com/apps/dependabot">dependabot[bot]</a> (#36)</li>
</ul>
<p>See details of <a href="https://github.com/revanite-io/osps-baseline-action/compare/v1.3.3...v1.3.4">all code changes</a> since previous release</p>
]]></content:encoded></item><item><title>Arcana CI Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/arcana-ci-gate/</link><pubDate>Sun, 02 Aug 2026 06:17:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/arcana-ci-gate/</guid><description>Version updated for https://github.com/RewithSolo/arcana-gate to version v1.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Arcana Gate is a deterministic quality gate CLI tool and GitHub Action that uses Tarot Major Arcana to delegate deployment decisions. It ensures that only high-quality code passes through the pipeline, reducing risks associated with unpredictable deployments. The action provides strict cryptographic engineering, ensuring reproducibility across different runners and executions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RewithSolo/arcana-gate">https://github.com/RewithSolo/arcana-gate</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/arcana-ci-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Arcana Gate</strong> is a deterministic quality gate CLI tool and GitHub Action that uses Tarot Major Arcana to delegate deployment decisions. It ensures that only high-quality code passes through the pipeline, reducing risks associated with unpredictable deployments. The action provides strict cryptographic engineering, ensuring reproducibility across different runners and executions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="arcana-gate-v100--initial-release-">Arcana Gate v1.0.0 — Initial Release 🔮</h1>
<p>First stable release of <strong>Arcana Gate</strong> — a Go-based CLI tool and GitHub Action for automated deployment gating driven by Major Arcana Tarot cards.</p>
<p align="center">
  <img src="https://raw.githubusercontent.com/RewithSolo/arcana-gate/main/assets/demo.png" alt="Arcana Gate Preview Negative" width="48%"/>
  <img src="https://raw.githubusercontent.com/RewithSolo/arcana-gate/main/assets/demo_positive.png" alt="Arcana Gate Preview Positive" width="48%"/>
</p>
<h3 id="-key-features">🚀 Key Features</h3>
<ul>
<li><strong>Deterministic Gate Engine:</strong> Card selection and orientation (upright / reversed) are calculated deterministically based on the GITHUB_SHA (commit hash).</li>
<li><strong>Tarot Domain Logic:</strong> Clean and isolated business logic for deployment risk assessment powered by the Major Arcana deck.</li>
<li><strong>GitHub Actions Native:</strong> Built-in support for rendering execution results directly into GitHub Step Summary.</li>
</ul>
<h3 id="-security--quality-devsecops">🛡️ Security &amp; Quality (DevSecOps)</h3>
<ul>
<li><strong>0 Known CVEs:</strong> Executables and container builds passed security scans via govulncheck and Trivy (built with Go 1.26 stdlib).</li>
<li><strong>High Test Coverage:</strong> Unit test coverage for core domain logic with race detector (-race) enabled.</li>
<li><strong>Automated Release Pipeline:</strong> Automated multi-platform binary compilation and packaging via GoReleaser v2.</li>
</ul>
<h3 id="-quick-start">📦 Quick Start</h3>
<h4 id="usage-in-github-actions">Usage in GitHub Actions:</h4>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Run Arcana Gate Check</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">RewithSolo/arcana-gate@v1.0.0</span>
</span></span></code></pre></div><h4 id="running-cli-manually">Running CLI Manually:</h4>
<p>Download the pre-built binary for your OS from the <strong>Assets</strong> section below, or build it from source:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>go build -o arcana-gate ./cmd/arcana-gate
</span></span><span style="display:flex;"><span>./arcana-gate
</span></span></code></pre></div><p><strong>Full Changelog</strong>: <a href="https://github.com/RewithSolo/arcana-gate/commits/v1.0.0">https://github.com/RewithSolo/arcana-gate/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/kaniko-build-action/</link><pubDate>Sun, 02 Aug 2026 06:16:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints a greeting message to the log, either “Hello World” or “Hello” followed by the name of the person specified. It automatically handles various inputs and outputs for easy integration into workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints a greeting message to the log, either &ldquo;Hello World&rdquo; or &ldquo;Hello&rdquo; followed by the name of the person specified. It automatically handles various inputs and outputs for easy integration into workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>My first action is ready (5619594)</li>
<li>Initial commit (2a56a2a)</li>
</ul>
]]></content:encoded></item><item><title>spec.md check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/spec.md-check/</link><pubDate>Sun, 02 Aug 2026 06:16:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/spec.md-check/</guid><description>Version updated for https://github.com/rosenjcb/spec.md to version v0.3.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary spec.md is a framework that turns Markdown specifications into a shared source of truth between humans, coding agents, and CI. It ensures alignment by enforcing the structure and ensuring that every QA test case in a spec has a corresponding [TC-N] identifier, thus preventing drift between the system and its documentation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rosenjcb/spec.md">https://github.com/rosenjcb/spec.md</a></strong> to version <strong>v0.3.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spec-md-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>spec.md</strong> is a framework that turns Markdown specifications into a shared source of truth between humans, coding agents, and CI. It ensures alignment by enforcing the structure and ensuring that every QA test case in a spec has a corresponding <code>[TC-N]</code> identifier, thus preventing drift between the system and its documentation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="rosenjcbspec-md-v036">@rosenjcb/spec-md v0.3.6</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>Adopt ASD-STE100 Simplified Technical English as the house style for spec prose. The <code>spec-md new</code> scaffold now states the rules inline, and the skill, the docs, and the pizza-ts example are written to them.</li>
</ul>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install --save-dev @rosenjcb/spec-md@0.3.6
</span></span><span style="display:flex;"><span>npx @rosenjcb/spec-md check
</span></span></code></pre></div><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">rosenjcb/spec.md@v0.3.6</span>
</span></span></code></pre></div><blockquote>
<p><strong>GitHub Action Marketplace:</strong> automated releases do not check &ldquo;Publish to Marketplace&rdquo;.
On the first release, open the release in GitHub and enable marketplace publishing manually.
See <a href="https://github.com/rosenjcb/spec.md/blob/main/RELEASING.md">RELEASING.md</a>.</p>
</blockquote>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Rewrite README for developer onboarding: commands, workflow, mermaid diagrams by @rosenjcb in <a href="https://github.com/rosenjcb/spec.md/pull/12">https://github.com/rosenjcb/spec.md/pull/12</a></li>
<li>Adopt ASD-STE100 Simplified Technical English as house style by @rosenjcb in <a href="https://github.com/rosenjcb/spec.md/pull/15">https://github.com/rosenjcb/spec.md/pull/15</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/rosenjcb/spec.md/compare/v0.3.5...v0.3.6">https://github.com/rosenjcb/spec.md/compare/v0.3.5...v0.3.6</a></p>
]]></content:encoded></item><item><title>Create Robots.txt</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/create-robots.txt/</link><pubDate>Sun, 02 Aug 2026 06:15:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/create-robots.txt/</guid><description>Version updated for https://github.com/s-thom/create-robots-txt-action to version v3.0.0.
This action is used across all versions by 6 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Create Robots.txt Action generates a robots.txt file from various sources, including existing files, cloudflare API tokens to fetch bot categories, known agents API tokens to fetch user agent categories, and allows users to specify allowed and blocked bot names. It automates the creation of a robots.txt file for web scraping and SEO purposes by appending allow rules for all unspecified user agents if requested.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/s-thom/create-robots-txt-action">https://github.com/s-thom/create-robots-txt-action</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/create-robots-txt">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>Create Robots.txt Action</code> generates a robots.txt file from various sources, including existing files, cloudflare API tokens to fetch bot categories, known agents API tokens to fetch user agent categories, and allows users to specify allowed and blocked bot names. It automates the creation of a robots.txt file for web scraping and SEO purposes by appending allow rules for all unspecified user agents if requested.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<blockquote>
<p>[!NOTE]
This release was generated from <a href="https://github.com/s-thom/create-robots-txt-action/commit/367541cb1867c020931706dd02a9d6e45a39d499"><code>367541cb1867c020931706dd02a9d6e45a39d499</code></a>.</p>
</blockquote>
<h3 id="changed">Changed</h3>
<ul>
<li>Dark Visitors has been renamed to Known Agents
<ul>
<li>Previous <code>dark-visitors-*</code> inputs need to be renamed to <code>known-agents-*</code>. The same values will still work.</li>
</ul>
</li>
<li>Cloudflare&rsquo;s bot categories have changed to named constants rather than human-friendly names.</li>
<li>Built action file is no longer committed to <code>main</code>.</li>
</ul>
]]></content:encoded></item><item><title>CrewScore</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/crewscore/</link><pubDate>Sun, 02 Aug 2026 06:14:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/crewscore/</guid><description>Version updated for https://github.com/shmindmaster/crewscore to version v0.6.11.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary CrewScore is an offline tool that scans AI agent system prompts for missing written safety rules, such as injection defense, human approval, cost limits, and stop conditions. It evaluates the coverage of these controls in the text and provides actionable insights on what needs to be added or improved.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shmindmaster/crewscore">https://github.com/shmindmaster/crewscore</a></strong> to version <strong>v0.6.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crewscore">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>CrewScore is an offline tool that scans AI agent system prompts for missing written safety rules, such as injection defense, human approval, cost limits, and stop conditions. It evaluates the coverage of these controls in the text and provides actionable insights on what needs to be added or improved.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>No scoring change. Ruleset remains <code>crewscore-hygiene@0.6.0</code>.</p>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Preserve canonical LF bytes for the generated browser engine and demo SVG on
Windows checkouts with repository-enforced Git attributes. The immutable
<code>v0.6.10</code> tag failed its Windows release gate before PyPI, GitHub Release, or
floating Action tags were published; <code>0.6.11</code> is the forward release.</li>
</ul>
<hr>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/update-a-config-file-with-values-from-environment/</link><pubDate>Sun, 02 Aug 2026 06:13:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces placeholders in a configuration file with values from environment variables. It’s designed to automate the process of managing sensitive information, such as API keys or passwords, without hardcoding them directly into the codebase. The action simplifies the management and deployment of applications by ensuring that sensitive details are stored securely outside of version control.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces placeholders in a configuration file with values from environment variables. It&rsquo;s designed to automate the process of managing sensitive information, such as API keys or passwords, without hardcoding them directly into the codebase. The action simplifies the management and deployment of applications by ensuring that sensitive details are stored securely outside of version control.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sun, 02 Aug 2026 06:12:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Swarm service by running npm ci and npm run bundle, then commits the resulting dist folder to the repository. This ensures that the service is correctly packaged and ready for deployment when pushed to a Git repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Swarm service by running <code>npm ci</code> and <code>npm run bundle</code>, then commits the resulting <code>dist</code> folder to the repository. This ensures that the service is correctly packaged and ready for deployment when pushed to a Git repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>Claude Code Marketplace Manager</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/claude-code-marketplace-manager/</link><pubDate>Sun, 02 Aug 2026 06:12:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/claude-code-marketplace-manager/</guid><description>Version updated for https://github.com/spencerbeggs/claude-code-marketplace-manager to version 1.0.2.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of updating a plugin in a Claude Code marketplace manifest by applying specified changes. It ensures that the update is validated and lands as a signed commit, satisfying branch protection requirements. The action supports manual triggering through a workflow_dispatch event or can be triggered from another repository via a repository_dispatch event.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spencerbeggs/claude-code-marketplace-manager">https://github.com/spencerbeggs/claude-code-marketplace-manager</a></strong> to version <strong>1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/claude-code-marketplace-manager">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of updating a plugin in a Claude Code marketplace manifest by applying specified changes. It ensures that the update is validated and lands as a signed commit, satisfying branch protection requirements. The action supports manual triggering through a <code>workflow_dispatch</code> event or can be triggered from another repository via a <code>repository_dispatch</code> event.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="dependencies">Dependencies</h3>
<ul>
<li>
<table>
  <thead>
      <tr>
          <th>Dependency</th>
          <th>Type</th>
          <th>Action</th>
          <th>From</th>
          <th>To</th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>@savvy-web/github-action-effects</td>
          <td>dependency</td>
          <td>updated</td>
          <td>^3.0.5</td>
          <td>^3.1.0</td>
          <td><a href="https://github.com/spencerbeggs/claude-code-marketplace-manager/pull/8">#8</a> Thanks <a href="https://github.com/apps/spencerbeggs">@spencerbeggs</a>!</td>
      </tr>
  </tbody>
</table>
</li>
</ul>
<h3 id="patch-changes">Patch Changes</h3>
<blockquote>
<p>This is a version-only release. No packages were published to a registry.</p>
</blockquote>
]]></content:encoded></item><item><title>Repoglance Repo Insight</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/repoglance-repo-insight/</link><pubDate>Sun, 02 Aug 2026 06:11:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/repoglance-repo-insight/</guid><description>Version updated for https://github.com/SRJ-ai/repoglance to version v0.2.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The repoglance GitHub Action provides a fast, visual way to analyze code repositories by providing insights into various aspects such as language breakdown, complexity hotspots, TODO tracker, and git activity. It automates the process of gathering and displaying technical information about a repository in a user-friendly format without requiring any configuration or API keys.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SRJ-ai/repoglance">https://github.com/SRJ-ai/repoglance</a></strong> to version <strong>v0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repoglance-repo-insight">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>repoglance</code> GitHub Action provides a fast, visual way to analyze code repositories by providing insights into various aspects such as language breakdown, complexity hotspots, TODO tracker, and git activity. It automates the process of gathering and displaying technical information about a repository in a user-friendly format without requiring any configuration or API keys.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Quality release.</p>
<ul>
<li><strong>Respects <code>.gitignore</code></strong> (via <code>git ls-files</code>) — parity with tokei/scc</li>
<li><strong>Single file read</strong> per file: complexity computed inline during the scan (~half the I/O on large repos)</li>
<li><strong>Block-comment counting</strong> for C-family languages</li>
<li>GitHub repository renamed to <code>SRJ-ai/repoglance</code>; all URLs/badges updated</li>
<li>Added <code>CHANGELOG.md</code>; test suite expanded to 29</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install repoglance
</span></span></code></pre></div>]]></content:encoded></item><item><title>ArchGuard - Architectural Drift Detector</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/archguard-architectural-drift-detector/</link><pubDate>Sun, 02 Aug 2026 06:10:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/archguard-architectural-drift-detector/</guid><description>Version updated for https://github.com/Tgenz1213/ArchGuard to version v1.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ArchGuard is a CLI tool that uses LLMs to detect architectural drift in code changes against established Architectural Decision Records (ADRs). It prevents “architectural drift” by automatically checking code changes to ensure they comply with ADRs. The action provides local analysis, supports multiple LLM providers, and integrates with Confluence for automated ADR retrieval and evaluation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tgenz1213/ArchGuard">https://github.com/Tgenz1213/ArchGuard</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/archguard-architectural-drift-detector">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ArchGuard is a CLI tool that uses LLMs to detect architectural drift in code changes against established Architectural Decision Records (ADRs). It prevents &ldquo;architectural drift&rdquo; by automatically checking code changes to ensure they comply with ADRs. The action provides local analysis, supports multiple LLM providers, and integrates with Confluence for automated ADR retrieval and evaluation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>c54c0159dae92441234db022be4a0364dd42c0c2 feat(llm): add Claude and Voyage AI providers (#52)</li>
</ul>
]]></content:encoded></item><item><title>AccessLedger Accessibility Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/accessledger-accessibility-scan/</link><pubDate>Sun, 02 Aug 2026 06:09:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/accessledger-accessibility-scan/</guid><description>Version updated for https://github.com/TJGaushas/accessledger-scan-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates a Web Content Accessibility Guidelines (WCAG) accessibility scan on every pull request or push in an organization’s repository. It integrates with AccessLedger, a cloud-based tool for tracking accessibility issues across websites. The action runs the scan against a specified URL or site ID and posts the results to a comment on the PR, updating it if changes are made. If violations exceed a certain severity level (default is “serious”), it fails the job. The action logs each scan in AccessLedger for a dated remediation record.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TJGaushas/accessledger-scan-action">https://github.com/TJGaushas/accessledger-scan-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/accessledger-accessibility-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates a Web Content Accessibility Guidelines (WCAG) accessibility scan on every pull request or push in an organization&rsquo;s repository. It integrates with AccessLedger, a cloud-based tool for tracking accessibility issues across websites. The action runs the scan against a specified URL or site ID and posts the results to a comment on the PR, updating it if changes are made. If violations exceed a certain severity level (default is &ldquo;serious&rdquo;), it fails the job. The action logs each scan in AccessLedger for a dated remediation record.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Run a WCAG 2.2 AA scan on every push or pull request, fail the build on serious issues, and record the result in your AccessLedger remediation ledger.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">TJGaushas/accessledger-scan-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api-token</span>: <span style="color:#ae81ff">${{ secrets.ACCESSLEDGER_API_TOKEN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">url</span>: <span style="color:#ae81ff">https://example.com</span>
</span></span></code></pre></div><p><strong>Fixed since v1.0.1</strong></p>
<ul>
<li>The quick start and the example workflow told users to write <code>uses: accessledger/accessledger-action@v1</code>. That org and repo do not exist, so every person who followed the quick start got a 404 on their first run. Corrected to <code>TJGaushas/accessledger-scan-action</code>.</li>
<li>The issue-reporting URL printed on an internal error pointed at the same non-existent repo.</li>
</ul>
<p>The floating <code>v1</code> tag now points at this commit.</p>
<p>Automated testing catches roughly 30–40% of WCAG success criteria. This action is evidence of ongoing testing, not a claim of compliance.</p>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/wails3-build-action/</link><pubDate>Sun, 02 Aug 2026 06:08:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub action automates the process of building Wails.io applications using GoLang and NodeJS. It installs necessary dependencies, builds the application, and optionally uploads the result to GitHub or a release on tagged builds. The default build includes both uploading workflow artifacts and publishing releases. Users can specify various configurations for different platforms, Go and Node.js versions, obfuscation settings, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub action automates the process of building Wails.io applications using GoLang and NodeJS. It installs necessary dependencies, builds the application, and optionally uploads the result to GitHub or a release on tagged builds. The default build includes both uploading workflow artifacts and publishing releases. Users can specify various configurations for different platforms, Go and Node.js versions, obfuscation settings, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.9...v3-alpha.9</a></p>
]]></content:encoded></item><item><title>GuardLine Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/guardline-security-scan/</link><pubDate>Sun, 02 Aug 2026 06:07:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/guardline-security-scan/</guid><description>Version updated for https://github.com/toutlawbradley/GuardLine to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GuardLine is an open-source GitHub Action that automates security scans on pull requests. It scans a codebase for common security issues, including secrets detection, dependency vulnerabilities, configuration risks, code patterns, and permission issues. The action posts findings as comments in the PR and also publishes them as SARIF files for integration with GitHub’s Security tab. Critical findings can block the merge until they are resolved.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/toutlawbradley/GuardLine">https://github.com/toutlawbradley/GuardLine</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/guardline-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GuardLine is an open-source GitHub Action that automates security scans on pull requests. It scans a codebase for common security issues, including secrets detection, dependency vulnerabilities, configuration risks, code patterns, and permission issues. The action posts findings as comments in the PR and also publishes them as SARIF files for integration with GitHub&rsquo;s Security tab. Critical findings can block the merge until they are resolved.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Narrow DependenciesScanner to requirements.txt only, close last open item (4c5a20b)</li>
<li>Add Validation section, fix scanners: config caveat, formatting cleanup (ca5b639)</li>
<li>Merge branch &lsquo;main&rsquo; of <a href="https://github.com/toutlawbradley/GuardLine">https://github.com/toutlawbradley/GuardLine</a> (a22014f)</li>
<li>Fix OSV error handling and ConfigScanner file_pattern bug (8f2cb51)</li>
<li>Merge pull request #5 from toutlawbradley/feature/self-scan-dogfooding (8821a37)</li>
<li>Merge pull request #4 from toutlawbradley/tests/orchestrator-and-reporter-coverage (4b3cd40)</li>
<li>Add tests for Orchestrator and Reporter; fix SecretsScanner regression (60d3d8f)</li>
<li>Add tests for Orchestrator.run() (31b9207)</li>
<li>Document fetch-depth fix and self-scan dogfooding (97fe561)</li>
<li>Added fetch-depth:0 (4efbd40)</li>
</ul>
]]></content:encoded></item><item><title>MCP Test Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/mcp-test-harness/</link><pubDate>Sun, 02 Aug 2026 06:06:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/mcp-test-harness/</guid><description>Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v3.0.10.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The MCP Test Harness automates the testing of MCP servers using pytest-style testing. It solves the problem of manually running tests and provides end-to-end integration testing capabilities, including support for multiple test environments and reporting. The action integrates with various tools and platforms to provide comprehensive security testing solutions for MCP servers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaquarkhan/mcp-test-harness">https://github.com/vaquarkhan/mcp-test-harness</a></strong> to version <strong>v3.0.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-test-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The MCP Test Harness automates the testing of MCP servers using pytest-style testing. It solves the problem of manually running tests and provides end-to-end integration testing capabilities, including support for multiple test environments and reporting. The action integrates with various tools and platforms to provide comprehensive security testing solutions for MCP servers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="mcp-test-harness-3010">mcp-test-harness 3.0.10</h2>
<p>Real provider helpers across all framework packages, plus five new shims.</p>
<h3 id="added">Added</h3>
<ul>
<li>Tool assert + MCP→provider schema converters + config builders on all packages</li>
<li>New: <code>ollama</code>, <code>openrouter</code>, <code>litellm</code>, <code>xai</code>, <code>autogen</code></li>
</ul>
<h3 id="notes">Notes</h3>
<ul>
<li>All <strong>23</strong> PyPI artifacts aligned at <strong>3.0.10</strong></li>
<li>Pins <code>mcp&gt;=1.0.0,&lt;2</code> until MCP SDK 2.x migration</li>
</ul>
]]></content:encoded></item><item><title>AI Changelog Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/ai-changelog-updater/</link><pubDate>Sun, 02 Aug 2026 06:04:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/ai-changelog-updater/</guid><description>Version updated for https://github.com/vscheuber/ai-changelog-action to version v1.1.8.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action updates the “## Unreleased” section of your CHANGELOG.md using an LLM to produce user-focused changelog entries. It gathers Git history, PR titles and bodies, and optional activity from related repositories. For full releases, it consolidates pre-release notes into a clean, de-duplicated set for the final stable version. The action is reusable and can be used in any repository with GitHub Actions enabled.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vscheuber/ai-changelog-action">https://github.com/vscheuber/ai-changelog-action</a></strong> to version <strong>v1.1.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-changelog-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action updates the &ldquo;## Unreleased&rdquo; section of your CHANGELOG.md using an LLM to produce user-focused changelog entries. It gathers Git history, PR titles and bodies, and optional activity from related repositories. For full releases, it consolidates pre-release notes into a clean, de-duplicated set for the final stable version. The action is reusable and can be used in any repository with GitHub Actions enabled.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Enhanced fallback logic to prevent duplicate release lines when no pre-release notes are present, improving the clarity of generated changelogs. (commit f093f69)</li>
</ul>
]]></content:encoded></item><item><title>Picket Secret Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/picket-secret-scanner/</link><pubDate>Sun, 02 Aug 2026 06:03:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/picket-secret-scanner/</guid><description>Version updated for https://github.com/willibrandon/picket to version v0.2.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Picket is a .NET secrets scanner that supports Gitleaks-compatible scanning, provides command-line and interactive tools, and integrates with CI/CD pipelines. It automates the detection of sensitive information in code changes, GitLab projects, Hugging Face resources, and more, using AOT-compiled binaries and libraries for security and performance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/willibrandon/picket">https://github.com/willibrandon/picket</a></strong> to version <strong>v0.2.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/picket-secret-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Picket is a .NET secrets scanner that supports Gitleaks-compatible scanning, provides command-line and interactive tools, and integrates with CI/CD pipelines. It automates the detection of sensitive information in code changes, GitLab projects, Hugging Face resources, and more, using AOT-compiled binaries and libraries for security and performance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release artifacts include SHA-256 checksums, package-size metadata, and GitHub artifact attestations.</p>
]]></content:encoded></item><item><title>install spaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/install-spaces/</link><pubDate>Sun, 02 Aug 2026 06:02:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/install-spaces/</guid><description>Version updated for https://github.com/work-spaces/install-spaces to version v0.20.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of Spaces on a remote server. It simplifies the process of setting up Spaces by handling configuration files and dependencies automatically, reducing manual effort and improving deployment reliability.
What’s Changed What’s Changed Bump version to v0.20.1 by @tyler-gilbert in https://github.com/work-spaces/install-spaces/pull/39 Full Changelog: https://github.com/work-spaces/install-spaces/compare/v0.20.0...v0.20.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/install-spaces">https://github.com/work-spaces/install-spaces</a></strong> to version <strong>v0.20.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-spaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the installation of Spaces on a remote server. It simplifies the process of setting up Spaces by handling configuration files and dependencies automatically, reducing manual effort and improving deployment reliability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.20.1 by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/39">https://github.com/work-spaces/install-spaces/pull/39</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/install-spaces/compare/v0.20.0...v0.20.1">https://github.com/work-spaces/install-spaces/compare/v0.20.0...v0.20.1</a></p>
]]></content:encoded></item><item><title>spaces checkout run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/spaces-checkout-run/</link><pubDate>Sun, 02 Aug 2026 06:02:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/spaces-checkout-run/</guid><description>Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.20.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of checking out and running a Space in a WorkSpaces project using the Spaces CLI. It simplifies the workflow by integrating these operations into a single action, reducing the need for manual steps. The action accepts inputs for checkout and run commands, and optionally requires a GitHub token for authentication.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/spaces-checkout-run">https://github.com/work-spaces/spaces-checkout-run</a></strong> to version <strong>v0.20.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spaces-checkout-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of checking out and running a Space in a WorkSpaces project using the Spaces CLI. It simplifies the workflow by integrating these operations into a single action, reducing the need for manual steps. The action accepts inputs for checkout and run commands, and optionally requires a GitHub token for authentication.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.20.1 by @tyler-gilbert in <a href="https://github.com/work-spaces/spaces-checkout-run/pull/33">https://github.com/work-spaces/spaces-checkout-run/pull/33</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/spaces-checkout-run/compare/v0.20.0...v0.20.1">https://github.com/work-spaces/spaces-checkout-run/compare/v0.20.0...v0.20.1</a></p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/cowork-harness/</link><pubDate>Sun, 02 Aug 2026 06:02:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.17.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is designed to automate and test Claude Cowork skills in a scriptable, CI-ready manner without relying on the Desktop app. It reproduces key aspects of Cowork’s runtime contract, including sealed filesystem, default-deny egress, and MCP-only cross-boundary behavior. This allows developers to test their skills across various scenarios and ensure compatibility with the platform before deploying them.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.17.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is designed to automate and test Claude Cowork skills in a scriptable, CI-ready manner without relying on the Desktop app. It reproduces key aspects of Cowork&rsquo;s runtime contract, including sealed filesystem, default-deny egress, and MCP-only cross-boundary behavior. This allows developers to test their skills across various scenarios and ensure compatibility with the platform before deploying them.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Reported by two consumer skills against published 1.16.0, plus a 54-item documentation review against the
source (32 findings valid). If you relied on the <code>semantic_matches</code> or <code>undelivered_deliverables</code>
documentation, re-check against the corrected text below.</p>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>cowork-harness lint-skill</code> and <code>run</code> now report on a mounted plugin&rsquo;s hook declarations.</strong> Three
findings: <code>hooks-json-misplaced</code> (WARN — see the footgun below), <code>hook-event-unknown</code> (ERROR — a typo,
including a wrong-capitalization one, which never runs anywhere), and <code>hook-event-not-served</code> (INFO —
the event <em>does</em> fire, but the harness offers no assertion key for it, so a scenario cannot gate on it;
assert the hook&rsquo;s observable effect instead). Before this, a plugin declaring <code>UserPromptSubmit</code>
mounted, ran, and produced no comment of any kind — the surface was discoverable only by grepping the
harness&rsquo;s own compiled output, which is exactly what one consumer had to do. The served set is
generated from <code>SERVED_HOOK_EVENTS</code> into the existing <code>assertion-keys.json</code> channel, with the same
drift tests as the assertion-key lists, so a hand-copied set cannot go stale.</li>
<li><strong>New footgun flagged: a plugin&rsquo;s <code>hooks.json</code> must live at <code>&lt;plugin&gt;/hooks/hooks.json</code>.</strong> At the plugin
root it is <strong>silently ignored</strong> — no error, no warning, no log line, nothing fires, which reads exactly
like &ldquo;plugin hooks aren&rsquo;t supported&rdquo;. <code>lint-skill</code> and <code>run</code> now flag it (<code>hooks-json-misplaced</code>).</li>
<li><strong><code>verify-cassettes --allow-empty</code></strong> — an existing but cassette-free directory exits 0 instead of the
default loud 2, for a repo that deliberately commits none (previously every caller wrapped the command
in an <code>ls</code> guard). Scoped to <em>empty directory</em> only: <code>resolveInputs</code> now returns a typed <code>kind</code>
discriminant, so a <strong>missing</strong> path still exits 2 and the flag can never green a typo — the vacuous
pass the loud default exists to prevent.</li>
<li><strong><code>semantic_matches: {include_subagent_text: true}</code></strong> — opt in to sending each sub-agent&rsquo;s <code>kind:&quot;text&quot;</code>
turns to the judge, for a fan-out skill whose real work is otherwise invisible to it. Opt-in because
enlarging the judged document can re-grade an existing rubric. Sub-agent <em>thinking</em> is excluded: it
arrives empty with <code>redacted:true</code>, so including it would pad the document with blanks a judge could
read as &ldquo;the sub-agent did nothing&rdquo;.</li>
<li><strong><code>analyze-skill</code> gains an <code>unscannedArtifactSources</code> field</strong> (JSON) plus a text-mode warning line, so an
explicitly-named target the artifact parser cannot read is reported instead of passing silently. See
Fixed. Directory walks are unaffected; exit codes are unchanged.</li>
<li><strong>New guard <code>test/scenario-key-vocabulary.test.ts</code></strong> — flags a backticked token within edit distance 2 of
a real assertion key that is not one, across 8 consumption surfaces. The existing <code>scenario-docs-sync</code>
guard checks only the forward direction (every key has a doc row) and anchors on table rows, so it could
not see a key named in prose.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>The hook mechanism accepts any event; the default install is unchanged.</strong> Binary-verified against
<code>app.asar</code> 1.24012.9, real Cowork installs three hook event types and six hooks where the harness
installs one — <code>PreToolUse</code> ×4 (<code>Task</code>, <code>Skill</code>, the force-ask set, <code>mcp__.*</code>), <code>PostToolUse:WebSearch</code>,
and <code>UserPromptSubmit</code>. All six are now recorded in each baseline&rsquo;s <code>spawn.hooks</code> as a drift tripwire
(with a <code>served</code> flag), and <code>docs/fidelity-gaps.md</code> gains a Hooks section. The install is unchanged
because <strong>none of the five unserved hooks would change observable behaviour here today</strong>: two never match
(the force-ask set gates four tools this harness doesn&rsquo;t register; the <code>mcp__.*</code> deny hook has no remote
MCP to deny), one never triggers (<code>UserPromptSubmit</code> expands a leading <code>/slash</code>, which a scenario prompt
is not), one cannot be sourced faithfully (<code>PreToolUse:Skill</code> injects <code>additionalContext</code> from Desktop&rsquo;s
plugin/skill registry — inventing that text would put words in the model&rsquo;s context production never
sends), and one is <strong>already covered by a different path</strong>: <code>PostToolUse:WebSearch</code> seeds
<code>webFetchAllowedUrls</code> in production, and the harness reaches the same end by seeding provenance from
<em>every</em> tool result (<code>run.ts</code> → <code>ProvenanceTracker.seedFromToolResult</code>), a faithful-but-less-precise
regex-over-text subset of production&rsquo;s structured extractor, documented as such in
<code>src/hostloop/provenance.ts</code>. The force-ask hook becomes worth serving if <code>save_skill</code> is ever modeled.</li>
<li><strong>A plugin&rsquo;s own hooks DO fire — live-verified at <code>container</code> and <code>hostloop</code>.</strong> There are two hook
channels, not one: the table above is what <em>Desktop</em> installs, while a plugin&rsquo;s own <code>hooks/hooks.json</code>
reaches the agent by the separate <code>--plugin-dir</code> route and is executed by the agent binary itself. A
fixture plugin declaring <code>SessionStart</code> / <code>UserPromptSubmit</code> / <code>PostToolUse</code> had all three fire at both
tiers. What is missing is narrower than &ldquo;hooks don&rsquo;t work here&rdquo;: there is no assertion key for those
events (you cannot <em>gate</em> on one) and no reproduction of the extra hooks production installs. A skill
relying on <code>UserPromptSubmit</code> to inject a rule does work here; it has to be asserted via its effect.</li>
<li><strong>Serving a bare, un-prefixed tool name is confirmed not feasible.</strong> A live probe registered
<code>SendUserFile</code> in <code>--tools</code>/<code>--allowedTools</code> <em>and</em> aliased it via <code>toolAliases</code> →
<code>mcp__cowork__present_files</code>. The alias reached the wire, but the agent advertised 23 tools with
<code>SendUserFile</code> absent, and the model reported it had no such tool. <code>toolAliases</code> only redirects a call
the model already makes; it cannot make a name visible, and <code>--tools</code> silently drops an unrecognized one.
This closes the open question blocking a remote-delivery emulation — that path is dead, and the
remaining option is an MCP-prefixed name with a documented divergence.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong><code>undelivered_deliverables</code> no longer fires on every remote run.</strong> On <code>lane: remote</code> the location arm
of the delivery check is correctly off, but the <code>presentedFiles</code> arm can never match either — no remote
delivery tool is served, so the array is structurally always empty. Every live first-turn remote run
that wrote a file therefore warned &ldquo;never reached the user&rdquo;, which is a claim the evidence cannot
support, and it forced <code>allow_undelivered_deliverables: true</code> into every remote scenario. A new
<code>deliveryObservable()</code> predicate gates the signal, and the new <strong><code>delivery_unobservable</code></strong> warn states
the gap instead of guessing. The two are mutually exclusive, and the new one stays quiet on a run that
produced nothing to deliver — so net warn volume per run is unchanged, not increased.</li>
<li><strong><code>analyze-skill</code> reported a clean scan on files it never parsed.</strong> The help string listed
<code>.ts/.jsx/.tsx</code> among the sources scanned for lost artifact write-backs; the scanner reads
<code>.html/.htm/.js/.mjs/.py</code> only (the in-process parser cannot read TypeScript or JSX). A <code>.ts</code> target
returned no findings, empty <code>artifactScanned</code>, and <code>ok: true</code>.</li>
<li><strong>The unanswered-gate hint named a <code>skill</code>-only flag.</strong> Under <code>on_unanswered: fail</code> the error said
<code>add: --answer &quot;…&quot;</code>, but <code>run --answer</code> exits &ldquo;unexpected argument(s)&rdquo;. The same text appeared in the
<code>run --on-unanswered first</code> success footer and in <code>docs/scenario.md</code>. All three now give the scenario
<code>answers:</code> form first and label <code>--answer</code> as the <code>skill</code> path.</li>
<li><strong><code>semantic_matches</code>&rsquo; judged document is narrower than every doc said.</strong> Both the public schema row and
the companion skill&rsquo;s copy described it as &ldquo;the union of the final message, <strong>the transcript</strong>, and any
authored files&rdquo;. The transcript is <strong>top-level <code>assistant_text</code> only</strong> — it excludes every
<code>tool_use</code>/<code>tool_result</code>, and excludes <strong>all sub-agent text</strong>, including fork-scoped <code>Skill</code>/<code>Agent(fork)</code>
dispatches (whose <em>tool</em> calls the harness does attribute to the main agent — the text path does not).
A rubric claim such as <em>&ldquo;the agent either used a tool to surface the file, or said none was available&rdquo;</em>
can never grade true on its first branch, regardless of behaviour: the evidence is not in the document.
The rows now state the exclusions and warn that tool-invocation claims are unassertable — use
<code>tool_called</code> / <code>present_files_called</code> / <code>subagent_dispatched</code> instead.</li>
<li><strong><code>undelivered_deliverables</code>&rsquo; remedy was lane-blind in the docs.</strong> The runtime message has branched on
lane since 1.16.0 (&ldquo;moving it under <code>outputs/</code> does not help on this lane&rdquo;); <code>docs/scenario.md</code> and the
skill still gave the unconditional &ldquo;write deliverables under <code>outputs/</code>&rdquo;.</li>
<li><strong>The <code>lane: remote</code> rejection advised something impossible.</strong> Asserting <code>user_visible_artifact</code> there
failed with <em>&ldquo;Assert the delivery itself&rdquo;</em> — but no remote delivery tool is modeled, so that phrase
pointed at nothing. It now says so and offers the weaker proxy (<code>file_exists</code> + <code>transcript_matches</code>).
Both call sites and their rationale comments are corrected together.</li>
<li><strong>Four surfaces named an assertion key that does not exist</strong> — <code>subagent_dispatched</code> written without its
trailing &ldquo;ed&rdquo;, in <code>docs/scenario.md</code>, both skill references, and the generated schema. The truncated
spelling is also an internal <code>AgentEvent</code> type, so it appears in the repo. <code>lint</code> reports
<code>unknown-assert-key</code> and <code>run</code> rejects the scenario at load, so no run false-greened.</li>
<li>Also corrected: a nonexistent scenario path in <code>python/README.md</code> and <code>python/cowork_harness.py</code>; the
composite Action&rsquo;s three outputs (<code>ok</code>, <code>envelope-path</code>, <code>summary-md</code>), previously documented only in
<code>action.yml</code>; <code>docs/protocol.md</code>&rsquo;s v1 changelog, silent for six baselines, now stating that they were
verified by <code>sync</code>/asar analysis rather than a live re-run; ~20 rotting line-number citations in
<code>docs/subagents.md</code>, replaced with symbol names; <code>--plugin-dir</code> described as a user-facing flag in
<code>README.md</code>; a missing <code>--enable</code> in <code>docs/session.md</code>&rsquo;s marketplace row; <code>scripts/</code> scope in
<code>docs/critique.md</code>; <code>record --decider-dir</code>, <code>status --follow</code> and <code>--run-dir</code> in <code>docs/decider-dir.md</code>;
three missing <code>Result</code> accessors in <code>python/README.md</code>; the duplicated shipped-examples inventory; and
two example YAML comments with unresolvable paths.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 1.17.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/94">https://github.com/yaniv-golan/cowork-harness/pull/94</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.17.0">https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.17.0</a></p>
]]></content:encoded></item><item><title>Zig Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/zig-actions/</link><pubDate>Sun, 02 Aug 2026 06:01:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/zig-actions/</guid><description>Version updated for https://github.com/YetAnotherMechanicusEnjoyer/zig-actions to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Zig compilation, testing, and formatting checks in a repository. It reports compiler errors directly as GitHub annotations, making it easier for developers to debug issues quickly. The action supports both all-in-one workflows that run all tests and CI-only workflows that only perform CI tasks. Users can specify the version of Zig, working directory, test command, and whether the build should fail on error.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YetAnotherMechanicusEnjoyer/zig-actions">https://github.com/YetAnotherMechanicusEnjoyer/zig-actions</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zig-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates Zig compilation, testing, and formatting checks in a repository. It reports compiler errors directly as GitHub annotations, making it easier for developers to debug issues quickly. The action supports both all-in-one workflows that run all tests and CI-only workflows that only perform CI tasks. Users can specify the version of Zig, working directory, test command, and whether the build should fail on error.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="add-root-action-with-zig-ci-for-now">Add root action with Zig CI (for now)</h1>
]]></content:encoded></item><item><title>quorum-review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/quorum-review/</link><pubDate>Sun, 02 Aug 2026 06:00:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/quorum-review/</guid><description>Version updated for https://github.com/yuting0624/quorum-review to version v1.7.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates and improves code review by running two different AI models—Gemini and Claude—in parallel on the same pull request to find discrepancies and confirm findings independently. It ensures that any identified issues are not due to a single model’s blind spot, providing more reliable results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuting0624/quorum-review">https://github.com/yuting0624/quorum-review</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quorum-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates and improves code review by running two different AI models—Gemini and Claude—in parallel on the same pull request to find discrepancies and confirm findings independently. It ensures that any identified issues are not due to a single model&rsquo;s blind spot, providing more reliable results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Bump to 1.7.0</p>
]]></content:encoded></item><item><title>zizmor-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/zizmor-action/</link><pubDate>Sun, 02 Aug 2026 05:59:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/02/zizmor-action/</guid><description>Version updated for https://github.com/zizmorcore/zizmor-action to version v0.6.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses the zizmor tool to analyze security findings from your code repository, providing detailed reports and annotations on issues such as security vulnerabilities and potential weaknesses. It integrates seamlessly with GitHub’s Advanced Security features, allowing users to visualize and manage security alerts directly within their repositories. The action is designed to be both efficient and user-friendly, offering flexible configuration options for advanced users while maintaining simplicity for beginners.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zizmorcore/zizmor-action">https://github.com/zizmorcore/zizmor-action</a></strong> to version <strong>v0.6.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zizmor-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses the <code>zizmor</code> tool to analyze security findings from your code repository, providing detailed reports and annotations on issues such as security vulnerabilities and potential weaknesses. It integrates seamlessly with GitHub&rsquo;s Advanced Security features, allowing users to visualize and manage security alerts directly within their repositories. The action is designed to be both efficient and user-friendly, offering flexible configuration options for advanced users while maintaining simplicity for beginners.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>zizmor 1.29.0 is now the default version.</p>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/cibuild-action/</link><pubDate>Sat, 01 Aug 2026 22:37:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.4.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cibuild action helps automate iOS and Android CI/CD pipelines by generating non-interactive workflows from YAML configurations. It can auto-detect platforms, collect project-specific secrets, and generate pipeline templates suitable for AI-based agents. Users can customize these templates by adding their own steps or modifying existing ones through the command-line interface.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.4.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The cibuild action helps automate iOS and Android CI/CD pipelines by generating non-interactive workflows from YAML configurations. It can auto-detect platforms, collect project-specific secrets, and generate pipeline templates suitable for AI-based agents. Users can customize these templates by adding their own steps or modifying existing ones through the command-line interface.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.4.7</p>
]]></content:encoded></item><item><title>RollHook Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/rollhook-deploy/</link><pubDate>Sat, 01 Aug 2026 22:35:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/rollhook-deploy/</guid><description>Version updated for https://github.com/jkrumm/rollhook-action to version v1.8.0.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment process using Docker and RollHook. It eliminates the need for secret management by utilizing OIDC tokens provided by GitHub Actions to authenticate with the RollHook registry. The action handles building, pushing, and deploying a Docker image in one step, providing real-time logs through SSE streams. The server-side authorization ensures that only authorized repositories can deploy images to specified branches or tags.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jkrumm/rollhook-action">https://github.com/jkrumm/rollhook-action</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rollhook-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment process using Docker and RollHook. It eliminates the need for secret management by utilizing OIDC tokens provided by GitHub Actions to authenticate with the RollHook registry. The action handles building, pushing, and deploying a Docker image in one step, providing real-time logs through SSE streams. The server-side authorization ensures that only authorized repositories can deploy images to specified branches or tags.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="180-2026-07-31"><a href="https://github.com/jkrumm/rollhook-action/compare/v1.7.0...v1.8.0">1.8.0</a> (2026-07-31)</h1>
<h3 id="features">Features</h3>
<ul>
<li><strong>errors:</strong> diagnose RollHook failures with a one-line verdict (<a href="https://github.com/jkrumm/rollhook-action/commit/ec7c0c960f3194bf91c93a07b769049caa6a995b">ec7c0c9</a>)</li>
</ul>
]]></content:encoded></item><item><title>Register Jolter release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/register-jolter-release/</link><pubDate>Sat, 01 Aug 2026 22:35:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/register-jolter-release/</guid><description>Version updated for https://github.com/jolterjs/register-release-action to version v1.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the process of registering a published plugin release with the Jolter registry. It handles various authentication methods (personal access token, repository-scoped GitHub token, or OIDC) to register the release artifacts, including WebAssembly assets, plugin.json, and optional checksums.txt. The action also supports version and release tag overrides and provides outputs for the registered version and release tag.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jolterjs/register-release-action">https://github.com/jolterjs/register-release-action</a></strong> to version <strong>v1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/register-jolter-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the process of registering a published plugin release with the Jolter registry. It handles various authentication methods (personal access token, repository-scoped GitHub token, or OIDC) to register the release artifacts, including WebAssembly assets, <code>plugin.json</code>, and optional checksums.txt. The action also supports version and release tag overrides and provides outputs for the registered version and release tag.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>GitHub Actions OIDC Authentication</strong>: Added seamless passwordless authentication using GitHub Actions OIDC (<code>id-token: write</code> permission).</li>
<li><strong>New Inputs</strong>:
<ul>
<li><code>id-token</code>: Manually supply an OIDC ID token or let the action automatically fetch one via <code>id-token: write</code> permissions.</li>
<li><code>id-token-audience</code>: Specify a custom audience for the OIDC token if needed.</li>
</ul>
</li>
<li>Updated documentation and workflow examples (<code>examples/register-release.yml</code>) to recommend OIDC as the default authentication method.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Recommended authentication workflow updated to use GitHub Actions <code>id-token: write</code> and <code>contents: write</code> permissions instead of requiring manual token secrets.</li>
</ul>
<h3 id="security--compatibility">Security &amp; Compatibility</h3>
<ul>
<li>Fully backwards compatible with existing <code>token</code>, <code>jolter-token</code>, and <code>github-token</code> authentication options.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jolterjs/register-release-action/compare/v1.2...v1.3">https://github.com/jolterjs/register-release-action/compare/v1.2...v1.3</a></p>
]]></content:encoded></item><item><title>Mise Update Tool</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/mise-update-tool/</link><pubDate>Sat, 01 Aug 2026 22:34:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/mise-update-tool/</guid><description>Version updated for https://github.com/jylenhof/mise-update-tool to version v1.0.2.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates tool upgrades using Mise, a dependency manager for JavaScript projects. It lists and upgrades local tools specified in a mise config file, optionally creating pull requests with commit and branch prefixes if any files are modified during the upgrade process. The action is useful for maintaining consistent dependencies across multiple repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jylenhof/mise-update-tool">https://github.com/jylenhof/mise-update-tool</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mise-update-tool">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates tool upgrades using Mise, a dependency manager for JavaScript projects. It lists and upgrades local tools specified in a mise config file, optionally creating pull requests with commit and branch prefixes if any files are modified during the upgrade process. The action is useful for maintaining consistent dependencies across multiple repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="102-2026-07-17"><a href="https://github.com/jylenhof/mise-update-tool/compare/v1.0.1...v1.0.2">1.0.2</a> (2026-07-17)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>sanitize GitHub mentions in PR release notes (<a href="https://github.com/jylenhof/mise-update-tool/issues/13">#13</a>) (<a href="https://github.com/jylenhof/mise-update-tool/commit/42e47e605b9904c6e9e976a36f9e39ad18203ce0">42e47e6</a>)</li>
</ul>
]]></content:encoded></item><item><title>crabd</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/crabd/</link><pubDate>Sat, 01 Aug 2026 22:33:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/crabd/</guid><description>Version updated for https://github.com/louisescher/crabd to version v0.7.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The crab’d GitHub Action is a versatile coding agent designed to work with multiple models (Anthropic, OpenAI, OpenRouter, and local Ollama) on GitHub and Forgejo. It automates tasks like answering @-mentions, reviewing pull requests, and implementing whole issues, providing a forge-agnostic solution for CI.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/louisescher/crabd">https://github.com/louisescher/crabd</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crab-d">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The crab&rsquo;d GitHub Action is a versatile coding agent designed to work with multiple models (Anthropic, OpenAI, OpenRouter, and local Ollama) on GitHub and Forgejo. It automates tasks like answering <code>@</code>-mentions, reviewing pull requests, and implementing whole issues, providing a forge-agnostic solution for CI.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: version packages by @github-actions[bot] in <a href="https://github.com/louisescher/crabd/pull/36">https://github.com/louisescher/crabd/pull/36</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/louisescher/crabd/compare/v0...v0.7.0">https://github.com/louisescher/crabd/compare/v0...v0.7.0</a></p>
]]></content:encoded></item><item><title>NormWind Tailwind Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/normwind-tailwind-audit/</link><pubDate>Sat, 01 Aug 2026 22:32:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/normwind-tailwind-audit/</guid><description>Version updated for https://github.com/LunarWerxs/NormWind to version v3.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NormWind is a zero-config CLI and GitHub Action that audits and fixes bloated Tailwind utility classes by rewriting them into their short, canonical form. It helps keep class strings concise, consistent, and error-free, ensuring your Tailwind codebase remains clean and maintainable.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LunarWerxs/NormWind">https://github.com/LunarWerxs/NormWind</a></strong> to version <strong>v3.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/normwind-tailwind-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NormWind is a zero-config CLI and GitHub Action that audits and fixes bloated Tailwind utility classes by rewriting them into their short, canonical form. It helps keep class strings concise, consistent, and error-free, ensuring your Tailwind codebase remains clean and maintainable.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="normwind-v370">NormWind v3.7.0</h2>
<p><em>2026-08-01 · GitHub Marketplace Action</em></p>
<ul>
<li><strong>Native GitHub review feedback</strong> — the new <code>NormWind Tailwind Audit</code> Action emits file-and-line annotations, a complete job summary, stable outputs, and a machine-readable JSON report. Findings can fail the job or run in advisory mode; incomplete scans always fail closed.</li>
<li><strong>Self-contained and least privilege</strong> — the JavaScript Action bundles NormWind, Tailwind, Babel, and its reporting runtime; it installs nothing on the runner, requires no secret or write permission, strips inherited secrets from its scanner process, never executes checkout-provided dependencies/tools, and confines source/theme reads to the checked-out workspace.</li>
<li><strong>Reproducible Action releases</strong> — deterministic bundle generation, committed third-party license inventories, bundle-drift tests, and a pre-install local-Action smoke step now gate CI and releases. Moving Action tags no longer trigger duplicate npm publications.</li>
<li><strong>Dependency hardening</strong> — the transitive PostCSS version is refreshed past its source-map path-traversal advisory, leaving <code>npm audit</code> clean.</li>
</ul>
<p><strong>Full comparison:</strong> <a href="https://github.com/LunarWerxs/NormWind/compare/v3.6.2...v3.7.0">v3.6.2&hellip;v3.7.0</a></p>
]]></content:encoded></item><item><title>Slackalaka</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/slackalaka/</link><pubDate>Sat, 01 Aug 2026 22:31:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/slackalaka/</guid><description>Version updated for https://github.com/mallowigi/tag-n-slack to version 0.2.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action creates a new Git tag with a changelog and notifies Slack about the release. It supports two version increment strategies: retrieving version from package.json and commit hash, and using “Squash and Merge” in PRs to get the merge commit’s version and message. The action also removes images and user attachments from the Slack message based on repository privacy settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mallowigi/tag-n-slack">https://github.com/mallowigi/tag-n-slack</a></strong> to version <strong>0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/slackalaka">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action creates a new Git tag with a changelog and notifies Slack about the release. It supports two version increment strategies: retrieving version from <code>package.json</code> and commit hash, and using &ldquo;Squash and Merge&rdquo; in PRs to get the merge commit&rsquo;s version and message. The action also removes images and user attachments from the Slack message based on repository privacy settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Truncate changelog content before subversion headers during parsing (4cba572)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (d48462d)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (e8cca16)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (0998ab2)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (74b7ec6)</li>
<li>Remove redundant error handling for directory listing in <code>findPackageJson</code>. (995b49e)</li>
<li>Add watch mode and enhance error handling for <code>findPackageJson</code> (58f570c)</li>
<li>Add watch mode and enhance error handling for <code>findPackageJson</code> (0a6a3ea)</li>
<li>Add watch mode and enhance error handling for <code>findPackageJson</code> (d616c7f)</li>
<li>Migrate codebase and dependencies to ES modules. (bd554c2)</li>
</ul>
]]></content:encoded></item><item><title>Odin Scan - Smart Contract Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/odin-scan-smart-contract-security/</link><pubDate>Sat, 01 Aug 2026 22:29:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/odin-scan-smart-contract-security/</guid><description>Version updated for https://github.com/Odin-Scan/odin-scan-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses AI to analyze smart contracts across CosmWasm, Solana, and EVM platforms. It integrates with GitHub Code Scanning, provides detailed PR comments and inline annotations, and can automatically detect platforms or be explicitly specified. The action supports configuring severity thresholds, triggering scans via comments, and uploading results as artifacts for further analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odin-Scan/odin-scan-action">https://github.com/Odin-Scan/odin-scan-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/odin-scan-smart-contract-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses AI to analyze smart contracts across CosmWasm, Solana, and EVM platforms. It integrates with GitHub Code Scanning, provides detailed PR comments and inline annotations, and can automatically detect platforms or be explicitly specified. The action supports configuring severity thresholds, triggering scans via comments, and uploading results as artifacts for further analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add comment-triggered PR scans (ac72e5f)</li>
<li>docs: expand findings-visibility section with threat model and annotation rationale (0404708)</li>
<li>feat: add findings-visibility input for graduated public disclosure control (f18df59)</li>
<li>fix: show findings detail in PR comment with fallback to medium (c2e43c8)</li>
<li>fix: new comment per run, show only critical/high findings, rebuild dist (e237b62)</li>
<li>feat: use GitHub App installation token for branded PR comments (3abce4e)</li>
<li>feat: enrich PR comment with emojis, descriptions, and fix report URL (27cc2f2)</li>
<li>fix: gzip SARIF before base64 encoding for Code Scanning upload (d9eed9f)</li>
<li>fix: include sourcemap-register.js in dist (bd265af)</li>
<li>docs: add privacy policy (b78db44)</li>
</ul>
]]></content:encoded></item><item><title>Next CalVer Version</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/next-calver-version/</link><pubDate>Sat, 01 Aug 2026 22:27:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/next-calver-version/</guid><description>Version updated for https://github.com/okaryo/calver to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action calculates the next Calendar Versioning tag from existing repository tags and exposes it as outputs. It does not create Git tags, releases, or manage files but provides inputs for prefix, major version, timezone, and GitHub token. The output includes the generated version, resolved calendar date, daily release sequence number, previous matching CalVer tag, and a flag indicating whether there is a previous version available.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/okaryo/calver">https://github.com/okaryo/calver</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/next-calver-version">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action calculates the next Calendar Versioning tag from existing repository tags and exposes it as outputs. It does not create Git tags, releases, or manage files but provides inputs for prefix, major version, timezone, and GitHub token. The output includes the generated version, resolved calendar date, daily release sequence number, previous matching CalVer tag, and a flag indicating whether there is a previous version available.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update actions/setup-node action to v7 by @renovate[bot] in <a href="https://github.com/okaryo/calver/pull/4">https://github.com/okaryo/calver/pull/4</a></li>
<li>chore(deps): update devdependencies by @renovate[bot] in <a href="https://github.com/okaryo/calver/pull/1">https://github.com/okaryo/calver/pull/1</a></li>
<li>chore(deps): update github actions by @renovate[bot] in <a href="https://github.com/okaryo/calver/pull/2">https://github.com/okaryo/calver/pull/2</a></li>
<li>chore(deps): update devdependencies (major) by @renovate[bot] in <a href="https://github.com/okaryo/calver/pull/5">https://github.com/okaryo/calver/pull/5</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@renovate[bot] made their first contribution in <a href="https://github.com/okaryo/calver/pull/4">https://github.com/okaryo/calver/pull/4</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/okaryo/calver/compare/v1...v1.1.1">https://github.com/okaryo/calver/compare/v1...v1.1.1</a></p>
]]></content:encoded></item><item><title>Sensez - Code Quality Feedback</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/sensez-code-quality-feedback/</link><pubDate>Sat, 01 Aug 2026 22:26:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/sensez-code-quality-feedback/</guid><description>Version updated for https://github.com/popov95s/sensez to version v0.2.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary sensez is a coding agent companion that provides real-time feedback on code quality metrics such as structural maintainability, duplication, dead code, cycles, architecture violations, and design smells. It helps developers catch and fix issues before they become more significant, improving the overall quality of their codebase.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/popov95s/sensez">https://github.com/popov95s/sensez</a></strong> to version <strong>v0.2.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sensez-code-quality-feedback">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>sensez is a coding agent companion that provides real-time feedback on code quality metrics such as structural maintainability, duplication, dead code, cycles, architecture violations, and design smells. It helps developers catch and fix issues before they become more significant, improving the overall quality of their codebase.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="added">Added</h2>
<ul>
<li>New nested_ternary smell for Python, JavaScript, and TypeScript.</li>
</ul>
<h2 id="improved">Improved</h2>
<ul>
<li>Cache TypeScript path-alias resolution per project root.</li>
<li>Eliminate the second AST walk when collecting JavaScript/TypeScript function metrics.</li>
<li>Improve JavaScript/TypeScript traversal coverage and regression tests.</li>
</ul>
<h2 id="fixed">Fixed</h2>
<ul>
<li>Correct schema-call and validator detection for JavaScript record analysis.</li>
<li>Preserve detection of .parse(), .safeParse(), and .decode() validation calls.</li>
</ul>
]]></content:encoded></item><item><title>Postman Onboarding Azure Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/postman-onboarding-azure-spec-discovery/</link><pubDate>Sat, 01 Aug 2026 22:25:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/postman-onboarding-azure-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-azure-spec-discovery-action to version v1.4.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the discovery and export of API specifications from Azure services using existing Azure credentials. It prioritizes various sources, including APIM, App Service, Logic Apps, and more, based on predefined criteria such as committed .postman bindings and repository tags. The action supports OpenAPI, AsyncAPI, and other formats, but not container apps or specific versions of Azure providers like Function bindings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-azure-spec-discovery-action">https://github.com/postman-cs/postman-azure-spec-discovery-action</a></strong> to version <strong>v1.4.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-azure-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the discovery and export of API specifications from Azure services using existing Azure credentials. It prioritizes various sources, including APIM, App Service, Logic Apps, and more, based on predefined criteria such as committed <code>.postman</code> bindings and repository tags. The action supports OpenAPI, AsyncAPI, and other formats, but not container apps or specific versions of Azure providers like Function bindings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/15">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/15</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/18">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/18</a></li>
<li>fix(test): assert the packaged version against package.json by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/19">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/19</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/20">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/20</a></li>
<li>fix(release): fetch the tag parent before ancestry checks by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/21">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/21</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/22">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/22</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/23">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/23</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/24">https://github.com/postman-cs/postman-azure-spec-discovery-action/pull/24</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-azure-spec-discovery-action/compare/v1.3.5...v1.4.1">https://github.com/postman-cs/postman-azure-spec-discovery-action/compare/v1.3.5...v1.4.1</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/postman-onboarding-repo-sync/</link><pubDate>Sat, 01 Aug 2026 22:24:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.8.4.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the process of exporting Postman collections and environments into a repository and configuring CI, mock servers, and monitors around them. It solves problems related to managing API configurations in a version-controlled manner and ensures that testing and monitoring are integrated seamlessly with code changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.8.4</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action automates the process of exporting Postman collections and environments into a repository and configuring CI, mock servers, and monitors around them. It solves problems related to managing API configurations in a version-controlled manner and ensures that testing and monitoring are integrated seamlessly with code changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>perf(repo-sync): bound artifact acquisition reads by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/116">https://github.com/postman-cs/postman-repo-sync-action/pull/116</a></li>
<li>fix(deps): replace deprecated Faker with compatible v6 by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/117">https://github.com/postman-cs/postman-repo-sync-action/pull/117</a></li>
<li>fix(repo-mutation): reconcile stale branch before push by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/118">https://github.com/postman-cs/postman-repo-sync-action/pull/118</a></li>
<li>fix(repo-mutation): resolve generated artifact conflicts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/119">https://github.com/postman-cs/postman-repo-sync-action/pull/119</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.8.4">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.8.4</a></p>
]]></content:encoded></item><item><title>Kaniko Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/kaniko-build-action/</link><pubDate>Sat, 01 Aug 2026 22:23:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/kaniko-build-action/</guid><description>Version updated for https://github.com/RivieraKid/gha-kaniko to version v0.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action prints “Hello World” or “Hello” followed by a name to the log. It automates greeting people, solving the problem of automatically sending personalized greetings in automated workflows. The key capabilities include accepting an input for the person to greet and providing the current time when greeting is sent.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RivieraKid/gha-kaniko">https://github.com/RivieraKid/gha-kaniko</a></strong> to version <strong>v0.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniko-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action prints &ldquo;Hello World&rdquo; or &ldquo;Hello&rdquo; followed by a name to the log. It automates greeting people, solving the problem of automatically sending personalized greetings in automated workflows. The key capabilities include accepting an input for the person to greet and providing the current time when greeting is sent.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1">https://github.com/RivieraKid/gha-kaniko/compare/v1...v0.0.1</a></p>
]]></content:encoded></item><item><title>GHBall</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/ghball/</link><pubDate>Sat, 01 Aug 2026 22:23:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/ghball/</guid><description>Version updated for https://github.com/Sayad-Uddin-Tahsin/GHBall to version 1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates a DX-Ball animation of a user’s GitHub contribution graph and can be configured to run automatically at regular intervals or triggered manually. It allows customization of ball speed, misses before the AI forces a hit, theme, and whether to show a live score counter. The action is available in the GitHub Marketplace and can be integrated into workflows for continuous updates.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Sayad-Uddin-Tahsin/GHBall">https://github.com/Sayad-Uddin-Tahsin/GHBall</a></strong> to version <strong>1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ghball">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates a DX-Ball animation of a user&rsquo;s GitHub contribution graph and can be configured to run automatically at regular intervals or triggered manually. It allows customization of ball speed, misses before the AI forces a hit, theme, and whether to show a live score counter. The action is available in the GitHub Marketplace and can be integrated into workflows for continuous updates.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This update makes GHBall easier to use, improves the visuals.</p>
<p><a href="https://github.com/marketplace/actions/ghball" title="GHBall"><img src="https://img.shields.io/badge/GitHub%20Marketplace-000000?logo=github&logoColor=white&style=for-the-badge" height="35" alt="GitHub Marketplace: GHBall" /></a></p>
<h2 id="what-is-new">What is new?</h2>
<ul>
<li>The internal system has been rebuilt to work faster and more smoothly.</li>
<li>The dark theme colors and score display have been polished for better readability.</li>
<li>A small summary report is now created automatically each time you run GHBall. It includes basic statistics (file size and generation time), the customization options you used, or you can use, and quick-start instructions for adding the badge to your README.</li>
<li>The main instructions page has been updated with clearer steps.</li>
</ul>
<h2 id="how-to-use-it">How to use it?</h2>
<p>To integrate GHBall into your repository, create a workflow file at <em><code>.github/workflows/ghball.yml</code></em> using the sample provided in the instructions. The workflow runs every 2 hours and automatically generates a fresh animation.</p>
<p><a href="https://github.com/Sayad-Uddin-Tahsin/GHBall#github-action-recommended">Full setup guide</a></p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Sayad-Uddin-Tahsin/GHBall/compare/1.0...1.1.0">https://github.com/Sayad-Uddin-Tahsin/GHBall/compare/1.0...1.1.0</a></p>
<hr>
<p align="center"><b>GHBall</b></p>
]]></content:encoded></item><item><title>Ground Cyber Closure Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/ground-cyber-closure-audit/</link><pubDate>Sat, 01 Aug 2026 22:22:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/ground-cyber-closure-audit/</guid><description>Version updated for https://github.com/sergiumargan-sudo/ground-cyber-plugin to version v0.6.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Ground Cyber automates the verification of GitHub security alerts (secret scanning, Dependabot, and code scanning) to ensure closure with verifiable evidence. It provides a comprehensive report detailing which closed alerts are not verifiably closed, addressing issues like unresolved risks and platform-reported fixes without modifying alerts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sergiumargan-sudo/ground-cyber-plugin">https://github.com/sergiumargan-sudo/ground-cyber-plugin</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ground-cyber-closure-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Ground Cyber automates the verification of GitHub security alerts (secret scanning, Dependabot, and code scanning) to ensure closure with verifiable evidence. It provides a comprehensive report detailing which closed alerts are not verifiably closed, addressing issues like unresolved risks and platform-reported fixes without modifying alerts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Answers a launch critique: for Dependabot and code scanning, &ldquo;is this exploitable?&rdquo; is not deterministically provable. v0.6 asks instead whether the closure claim was supported by structured evidence.</p>
<p>New opt-in tiered mode: a documented dismissal rationale scores GCS-2; one carrying a ticket, link, or explicit reachability claim scores GCS-1. Reasons stating the risk was not addressed (no_bandwidth, fix_started) are capped at GCS-2. No dismissal ever reaches GCS-0.</p>
<p>Default stays strict (v0.5 behaviour). The report always prints the rationale it relied on — Ground Cyber verifies that evidence was recorded, not that it is correct.</p>
]]></content:encoded></item><item><title>Automated Changelog Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/automated-changelog-generator/</link><pubDate>Sat, 01 Aug 2026 22:21:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/automated-changelog-generator/</guid><description>Version updated for https://github.com/shazib-summar/automated-changelog-gh to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action updates a CHANGELOG.md file based on commit history and tags. It automatically generates an entry for each new release, regenerates the entire changelog when a tag is pushed, links version changes to GitHub compare views, and optionally commits the updated changelog back to the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shazib-summar/automated-changelog-gh">https://github.com/shazib-summar/automated-changelog-gh</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/automated-changelog-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action updates a <code>CHANGELOG.md</code> file based on commit history and tags. It automatically generates an entry for each new release, regenerates the entire changelog when a tag is pushed, links version changes to GitHub compare views, and optionally commits the updated changelog back to the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(changelog): update changelog for v0.1.2 by @github-actions[bot] in <a href="https://github.com/shazib-summar/automated-changelog-gh/pull/20">https://github.com/shazib-summar/automated-changelog-gh/pull/20</a></li>
<li>chore: move docs to use tag v0.2.0 in examples by @shazib-summar in <a href="https://github.com/shazib-summar/automated-changelog-gh/pull/21">https://github.com/shazib-summar/automated-changelog-gh/pull/21</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/shazib-summar/automated-changelog-gh/compare/v0.1.2...v0.2.0">https://github.com/shazib-summar/automated-changelog-gh/compare/v0.1.2...v0.2.0</a></p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/bernstein-multi-agent-orchestration/</link><pubDate>Sat, 01 Aug 2026 22:20:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.13.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is a deterministic orchestrator for CLI coding agents that uses plain Python scheduling to ensure reproducibility. It automates the orchestration of tasks, ensuring checkable results after execution through lineage and replay capabilities. Each task runs in its own git worktree with isolated mutable state, providing an audit chain and receipts for verifying offline.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein is a deterministic orchestrator for CLI coding agents that uses plain Python scheduling to ensure reproducibility. It automates the orchestration of tasks, ensuring checkable results after execution through lineage and replay capabilities. Each task runs in its own git worktree with isolated mutable state, providing an audit chain and receipts for verifying offline.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A reliability release, and mostly one defect repeated across the release
machinery: a step that could not run reported as a step that passed. The npm
wrapper had been failing inside a green job since 2.3.0; Homebrew, the SBOMs
and the container image never ran at all for a release cut by automation; and
the drift detector meant to catch any of that closed its own tickets over
registries it had failed to read. All four are fixed, the RPM channel is wired
up, and the reconciler now refuses to return a verdict for a channel it could
not probe.</p>
<p>Full details for every item: <a href="https://github.com/sipyourdrink-ltd/bernstein/blob/main/docs/release-notes/v3.13.0.md">docs/release-notes/v3.13.0.md</a>.</p>
<h2 id="behaviour-changes">Behaviour changes</h2>
<ul>
<li><strong>A delegation chain with no recorded scope is now unproven rather than
valid</strong> (#3306). Grading is a separate three-state verdict on <code>ChainResult</code>;
<code>bernstein delegation verify</code> exits 1 on fail, 3 on unproven, 0 on pass. A
script that treated exit 0 as proof of narrowing now sees 3 where it was
previously told nothing was wrong. No receipt schema changed.</li>
<li><strong>A failed npm wrapper publish now fails its job</strong> (#3322). Nothing depends
on <code>publish-npm</code>, so the failure surfaces without holding back PyPI or the
GitHub Release.</li>
<li><strong><code>reconcile-release</code> fails when it could not read a channel</strong> (#3345), and
its auto-close of drift issues requires every channel verified, not merely
no drift observed.</li>
</ul>
<h2 id="release-machinery">Release machinery</h2>
<ul>
<li>Releases created by automation now dispatch their downstream consumers
explicitly — container image, Homebrew tap, SBOM attachment — instead of
relying on an event that a <code>GITHUB_TOKEN</code>-created release never raises
(#3323, #3345).</li>
<li>The SBOM workflow distinguishes a missing release from an API failure;
only the former is skippable (#3345).</li>
<li>RPM builds publish to Copr from the same tag trigger as every other channel,
and a submission failure fails the job (#3325).</li>
<li>The coverage-ratchet guard no longer parses an API error body as a baseline
after the ratchet branch is auto-deleted (#3347).</li>
</ul>
<h2 id="merge-gate">Merge gate</h2>
<ul>
<li>Every pull-request head now receives a <code>review-bot-ack</code> verdict: the
publisher election is deterministic, a cancelled gate run is re-dispatched
once instead of standing down silently, and the publisher&rsquo;s superseded runs
no longer pile up in the Actions history (#3313, #3331).</li>
</ul>
<h2 id="command-line-defects">Command-line defects</h2>
<p>Six defects found by reading the code rather than waiting for reports:</p>
<ul>
<li><code>doctor --json</code> lost its entire payload when one tool probe timed out
(#3330); undo audit logging resolved through a module alias mypy could not
see (#3308); the worker heartbeat busy-looped on re-registration failure
(#3309); <code>agents match</code> crashed on any catalog hit (#3310); prompts over
8191 characters could not spawn through a Windows <code>.cmd</code> shim (#3311); and
<code>stop --force</code> left the watchdog process alive (#3312).</li>
<li>Three typed-interface mismatches in the task lifecycle produced dead-letter
paths that lost incident data (#3315, #3316, #3317).</li>
</ul>
<h2 id="documentation-and-changelog-surfaces">Documentation and changelog surfaces</h2>
<ul>
<li>The changelog surfaces stop contradicting each other: <code>CHANGELOG.md</code> and
<code>docs/CHANGELOG.md</code> are pointer documents, stranded entries moved to
<code>docs/release-notes/unreleased.md</code>, and <code>bernstein changelog</code> serves the
page for the installed version (#3343).</li>
<li>The release flow is documented as it works; configuration files nothing
read are removed (#3340, #3344). Deleted command surfaces are swept out of
the docs, and two claims the code could not back are corrected (#3342).</li>
</ul>
<h2 id="contributors">Contributors</h2>
<ul>
<li>@aeoess designed and implemented delegation-chain grading (#3306): the
closed verifier reason set, fail-dominant composition over the existing
narrowing algebra, the <code>scope_ref</code> cross-check, and the third state for a
chain that records no scope.</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sat, 01 Aug 2026 22:19:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v0.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of a Docker Swarm service by building the project first with npm ci and npm run bundle. It then commits the built dist folder to the repository. The main purpose is to streamline the build process for deploying the application on a Docker Swarm cluster.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v0.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of a Docker Swarm service by building the project first with <code>npm ci</code> and <code>npm run bundle</code>. It then commits the built <code>dist</code> folder to the repository. The main purpose is to streamline the build process for deploying the application on a Docker Swarm cluster.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: Update dependencies (5336574)</li>
<li>fix: Update dependencies (e9c2fe7)</li>
<li>fix: Update dependencies (0b48905)</li>
<li>fix: Update dependencies (7cff14c)</li>
<li>fix: Improve error output (7cd1d73)</li>
<li>fix: Improve error output (92f3eca)</li>
<li>fix: Improve error output (4db44f1)</li>
<li>fix: Update dependencies (0ff3213)</li>
<li>Create README.md (e1316ba)</li>
<li>fix: Run bundle in Linux container to ensure dist is the same locally and on github (eb002ab)</li>
</ul>
]]></content:encoded></item><item><title>Yandex Cloud Federated IAM Token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/yandex-cloud-federated-iam-token/</link><pubDate>Sat, 01 Aug 2026 22:19:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/yandex-cloud-federated-iam-token/</guid><description>Version updated for https://github.com/stat1c-void/yc-fed-iam-action to version v1.0.7.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action retrieves a Yandex Cloud service account IAM token using Workload Identity Federation, enabling workflows to perform actions on Yandex Cloud resources without using authorized keys. It simplifies the setup by handling the ID Token exchange and requires configuring specific Yandex Cloud settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stat1c-void/yc-fed-iam-action">https://github.com/stat1c-void/yc-fed-iam-action</a></strong> to version <strong>v1.0.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yandex-cloud-federated-iam-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action retrieves a Yandex Cloud service account IAM token using Workload Identity Federation, enabling workflows to perform actions on Yandex Cloud resources without using authorized keys. It simplifies the setup by handling the ID Token exchange and requires configuring specific Yandex Cloud settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Updated deps, rebuilt JS.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/stat1c-void/yc-fed-iam-action/compare/v1.0.6...v1.0.7">https://github.com/stat1c-void/yc-fed-iam-action/compare/v1.0.6...v1.0.7</a></p>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/runward-gate/</link><pubDate>Sat, 01 Aug 2026 22:18:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.31.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is an open-source delivery methodology that automates the verification of engineering decisions behind AI-generated code through a deterministic gate process. It helps ensure that the architecture, security, and compliance are thoroughly checked before deployment, providing a clear path from development to production.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.31.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Runward is an open-source delivery methodology that automates the verification of engineering decisions behind AI-generated code through a deterministic gate process. It helps ensure that the architecture, security, and compliance are thoroughly checked before deployment, providing a clear path from development to production.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>An adversarial fact-check on <a href="https://runward.dev/news/2026-08-01-six-tests-that-could-not-fail/">the v0.30.0 article</a> re-tested every claim it made. <strong>Two of the three mutations that article published as harmless were live defects</strong>, and the figure it corrected was itself wrong.</p>
<h2 id="two-mutations-that-were-not-equivalent">Two mutations that were not equivalent</h2>
<p><strong>Bracket balance in the TOML reader.</strong> A <code>#</code> two characters past an opening quote was taken for a comment, the line truncated, an inline array lost its closing bracket, and the balance loop swallowed the rest of the file. The <code>#</code> need not sit on a line runward reads:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-toml" data-lang="toml"><span style="display:flex;"><span>[<span style="color:#a6e22e">vars</span>]
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">DOC_LINKS</span> = [<span style="color:#e6db74">&#34;https://acme.dev/docs#install&#34;</span>]
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>[<span style="color:#a6e22e">triggers</span>]
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">crons</span> = [<span style="color:#e6db74">&#34;0 3 * * *&#34;</span>]
</span></span></code></pre></div><p>That array, in a table runward never consults, destroyed the <code>[triggers]</code> below it. A HIGH rule silently stopped surfacing. The published reasoning argued line by line about an automaton that carries state <strong>across</strong> lines.</p>
<p><strong>Derivation notes.</strong> The binding-source check could mean <em>&ldquo;no other manifest produced anything&rdquo;</em> instead of <em>&ldquo;this one produced nothing&rdquo;</em>: a false note beside a cron just derived from that same file, a real absence silenced, and a note naming <strong>the wrong manifest</strong>. No exit code moved, which is why it was first filed as &ldquo;an informational message&rdquo;. Evidence that points at the wrong file, in a product whose thesis is <em>no step without proof</em>, is not classified by its output channel.</p>
<h2 id="a-published-figure-was-wrong">A published figure was wrong</h2>
<p>The site said the gate can require <strong>27</strong> of 64 craft rules. It is <strong>31</strong>. The catalog computed it from a hand-written literal missing <code>handover</code>, a gated phase, dropping four rules, one of them CRITICAL.</p>
<p>Worse: the article claimed the figure was <em>&ldquo;computed from the machine contract, so it can no longer drift&rdquo;</em>. The set of gated phases was restated by hand, and had <strong>already</strong> drifted. The correction of an overclaim reproduced the failure mode it claimed to remove.</p>
<p><code>rules --json</code> now publishes <strong><code>gatedPhases</code></strong>, read from <code>GATED_DELIVERABLES</code>. Additive field per <a href="https://github.com/stranxik/runward/blob/main/docs/adr/ADR-0024-machine-surface-of-the-rule-set.md">ADR-0024</a>.</p>
<h2 id="the-survivor-that-really-is-equivalent">The survivor that really is equivalent</h2>
<p><code>mission.ts</code>&rsquo;s line filter is equivalent across 3267 comparisons, but <strong>by accident</strong>: only while every shipped template ends with a newline. Strip one and a deliverable flips <code>in-progress</code> to <code>filled</code>, opening a phase. A test now pins that invariant and deliberately does <strong>not</strong> kill the mutation. Guarding the reason beats guarding the symptom.</p>
<h2 id="every-guard-proven-able-to-fail">Every guard proven able to fail</h2>
<p>Each mutation reddens its own test and only it. Removing a template&rsquo;s trailing newline reddens the invariant guard. Reintroducing the old literal verbatim reddens the contract guard.</p>
<p>169 unit tests, self-gate green.</p>
<p>Full changelog: <a href="https://github.com/stranxik/runward/blob/main/CHANGELOG.md">CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Run Godlint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/run-godlint/</link><pubDate>Sat, 01 Aug 2026 22:17:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/run-godlint/</guid><description>Version updated for https://github.com/tomerwave/godlint to version v0.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Godlint is an executable engineering constitution that automates the enforcement of rules across Rust, TypeScript, JavaScript, and Python repositories. It provides guardrails for AI coding agents to catch architectural drift before generated code reaches review, share boundaries and thresholds across a polyglot repository, enforce deterministic policy locally and in CI, account for accountable exceptions with expiring suppressions, and ensure local compliance without dependencies on external LLMs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tomerwave/godlint">https://github.com/tomerwave/godlint</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-godlint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Godlint is an executable engineering constitution that automates the enforcement of rules across Rust, TypeScript, JavaScript, and Python repositories. It provides guardrails for AI coding agents to catch architectural drift before generated code reaches review, share boundaries and thresholds across a polyglot repository, enforce deterministic policy locally and in CI, account for accountable exceptions with expiring suppressions, and ensure local compliance without dependencies on external LLMs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><code>ci/stale-action-refs</code> — makes full commit pins reviewable without network access. It reports a pin
without an inline version label at warning, and reports repository-proven contradictions at the
configured severity when the same action and SHA carry different labels or the same action and label
name different SHAs. A single leading <code>v</code> is normalised before comparing, because <code>v4.6.2</code> and
<code>4.6.2</code> name the same release and reporting them as a contradiction would spend the rule&rsquo;s only
asset — that it speaks when a label lies. <code>allow-in</code> removes paths from reporting and comparison.
The rule deliberately cannot verify that a label names the pinned commit; zizmor&rsquo;s online
<code>stale-action-refs</code> and <code>ref-version-mismatch</code> audits cover that external check.</li>
<li><code>ci/no-silenced-failure</code> — reports checks that cannot make a workflow fail: literal
<code>continue-on-error: true</code> settings and scripts ending <code>|| true</code>, <code>; exit 0</code>, or <code>|| exit 0</code>. A
same-job read of <code>steps.&lt;id&gt;.outcome</code> or <code>.conclusion</code> proves a deliberate soft step and stays
silent. Corpus-common <code>continue-on-error</code> and <code>|| true</code> findings are capped at warning; explicit
exit-zero endings stay at the configured severity.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><code>ci/no-monolithic-job</code> raises the <code>recommended@1</code> step limit from 7 to 20, the p90 of 231 jobs
across 94 workflows in nine widely used repositories. The former limit came from this repository
alone and reported 36% of real jobs. Raising it also made this repository&rsquo;s own <code>release.yml</code>
exemption unnecessary, which is what confirmed the number was wrong rather than the workflow.</li>
<li><code>ci/no-inline-script</code> keeps its limit of 8 after the same measurement — across 981 real scripts it
is p85, and 15% exceed it — so the number is now corpus-backed rather than repository-derived.</li>
<li>A condition written without braces is read as an expression by every rule that reads conditions.
GitHub treats an <code>if:</code> as an expression whether or not it is wrapped in <code>${{ … }}</code>, so
<code>ci/bot-conditions</code> was missing the idiomatic spelling entirely and <code>ci/no-silenced-failure</code>&rsquo;s
escape hatch did not open for it. Both now share one reader.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>style/no-comments</code> no longer reports a returned string literal as a docstring. The check confirmed
the string was the first thing in a block but never that the string <em>was</em> the statement, so a Python
function whose first statement returned a literal — <code>return &quot;active&quot;</code> — was reported as a comment at
error under <code>recommended@1</code>. A real docstring, including a module docstring, still reports. Found by
writing deliberately bad Python to probe for rules Godlint is missing.</li>
<li>A declared drift in <code>.github/accepted-drift.md</code> survives the merge that lands it, so a pull request
that deliberately relaxes a rule no longer has to be re-declared on every subsequent branch.</li>
<li><code>validate-pull-request.py</code> runs its change-scoped checks whether or not <code>--release-line</code> is passed,
and fails when it cannot find a release line to compare against. Only CI passed the flag, so a local
run reported one fewer check than CI ran and printed that all of them passed — including, on one
branch, the check that then failed the pull request.</li>
</ul>
]]></content:encoded></item><item><title>Wails3 Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/wails3-build-action/</link><pubDate>Sat, 01 Aug 2026 22:15:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/wails3-build-action/</guid><description>Version updated for https://github.com/ToQuery/wails3-build-action to version v3-alpha.14.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub action ToQuery/wails3-build-action@v3 automates the process of building Wails.io projects. It installs GoLang and NodeJS, runs a build for specified platforms, and optionally uploads artifacts to GitHub or publishes releases on tagged builds. The action supports various configurations such as Go version, Wails version, build platform, and options like obfuscation and caching.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ToQuery/wails3-build-action">https://github.com/ToQuery/wails3-build-action</a></strong> to version <strong>v3-alpha.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wails3-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub action <code>ToQuery/wails3-build-action@v3</code> automates the process of building Wails.io projects. It installs GoLang and NodeJS, runs a build for specified platforms, and optionally uploads artifacts to GitHub or publishes releases on tagged builds. The action supports various configurations such as Go version, Wails version, build platform, and options like obfuscation and caching.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14">https://github.com/ToQuery/wails3-build-action/compare/v3-alpha.14...v3-alpha.14</a></p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/cowork-harness/</link><pubDate>Sat, 01 Aug 2026 22:15:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.16.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action is a scriptable, CI-friendly test harness that emulates Claude Cowork’s observable runtime contract to test skills without using the locked Desktop app. It reproduces behavior and limitations such as the sealed filesystem, default-deny egress, MCP-only cross-boundary access, and can run in headless mode across various scenarios and CI jobs. The action is useful for developers to ensure their skills work as expected and identify any potential issues before deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.16.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action is a scriptable, CI-friendly test harness that emulates Claude Cowork&rsquo;s observable runtime contract to test skills without using the locked Desktop app. It reproduces behavior and limitations such as the sealed filesystem, default-deny egress, MCP-only cross-boundary access, and can run in headless mode across various scenarios and CI jobs. The action is useful for developers to ensure their skills work as expected and identify any potential issues before deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A founder-skills adoption pass over published 1.15.0 reported no bugs, but re-confirmed the pattern the
prior release was supposed to close: <strong>1.15.0&rsquo;s own docs fix restated a true statement about one code path
(the loader) as though it covered the whole system — the second time in two releases the same failure mode
shipped, against a different sentence.</strong> The over-generalized claim was &ldquo;a key from a newer harness fails
LOUD on an older CLI — it is never silently reinterpreted.&rdquo; True of the loader. False of <code>replay</code>, which is
the token-free CI gate consumers actually run, and which reads a cassette&rsquo;s frozen scenario as a
passthrough object — an unknown top-level key there is silently ignored, and where that key conditions an
assertion (as <code>lane:</code> does), a stale CLI can report green on a cassette the current CLI fails. This release
corrects the wording everywhere it shipped, closes the structural gap that made the silent case possible
in the first place (a conditional cassette-version stamp), and folds in three smaller drift issues the same
audit surfaced.</p>
<p><strong>Upgrade notes.</strong></p>
<ul>
<li><strong><code>replay --assert-from</code>/<code>--reassert</code> now hard-fails on a <code>lane</code>-flipped sibling scenario.</strong> <code>lane</code>
conditions three assertion keys&rsquo; outcomes (<code>user_visible_artifact</code>, <code>present_files_called</code>,
<code>no_scratchpad_leak</code>) but was missing from the recording-shaping drift guard since the key shipped in
1.14.0 — so a command that flips <code>lane:</code> on disk and re-checks was silently re-validating under the
<strong>wrong delivery contract</strong> and could report green regardless. If a currently-green <code>--assert-from</code>/
<code>--reassert</code> invocation starts failing after this upgrade, that is the guard catching a real drift it
should have caught since 1.14.0 — re-record, don&rsquo;t work around it.</li>
<li><strong>A cassette recorded by ≥ 1.16.0 whose scenario carries <code>lane: remote</code> is stamped cassette format
v11</strong>, which an older harness&rsquo;s <code>replay</code> and <code>verify-cassettes</code> both refuse to read — loudly. Only
<code>replay</code> offers an override (<code>--best-effort-future-cassette</code>); <code>verify-cassettes</code> has none by design, a
verification gate being the wrong place for a &ldquo;read it anyway&rdquo; switch, and its refusal says to upgrade
rather than naming a flag it does not accept. Every other scenario — including <code>lane: local</code> or
<code>lane:</code> omitted, nearly all of them — still stamps v10 and replays unchanged on an old install; this is
a conditional stamp, not a blanket format bump.</li>
<li><strong>If you copied 1.15.0&rsquo;s &ldquo;fails LOUD … never silently reinterpreted&rdquo; sentence into your own
documentation, replace it.</strong> The corrected wording is under Fixed, below.</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>Conditional cassette-version stamping — the structural fix (<code>CASSETTE_VERSION</code> → <code>11</code>,
<code>schema/cassette.v11.json</code>).</strong> An unconditional version bump would refuse every new cassette on an older
CLI, including the vast majority that use no new key — a permanent cost for a narrow problem. <code>record</code>
now stamps each cassette with <code>requiredVersionFor(scenario)</code>: the minimum format a reader needs to
interpret THIS scenario&rsquo;s values, not a flat build counter. The predicate is value-aware, not
key-presence-aware — <code>lane</code> is <code>.default(&quot;local&quot;)</code>, so every parsed scenario carries the key, and a
presence check would have stamped v11 on every cassette, reproducing the exact unconditional bump this
design avoids. Only <code>lane: &quot;remote&quot;</code> needs v11 (a pre-<code>lane</code> reader already treats every run as
local-delivery semantics, which is what <code>lane: &quot;local&quot;</code>/omitted asks for). A test pins that every one of
<code>ScenarioObject</code>&rsquo;s keys has an entry in the version-predicate map, so adding a scenario key without
deciding its cassette-version impact reds CI, rather than silently defaulting to &ldquo;harmless.&rdquo; <code>rehash</code>
uses the same shared predicate (previously it re-stamped unconditionally, which would have bumped an
entire clean, lane-free v10 corpus to v11 the moment this shipped — the exact blast radius the
conditional design exists to avoid) and is the <strong>recovery path</strong> for a <code>lane: remote</code> cassette already
recorded by 1.14.0/1.15.0 (stamped v10 there, since the conditional stamp did not exist yet). That
recovery is conditional, not guaranteed: <code>rehash</code> <strong>skips</strong> a cassette whose recorded baseline has
drifted from the live one, and <strong>errors</strong> on a <code>contentSig</code> mismatch rather than silently re-stamping
over a genuine skill-content change. <strong>This does not repair a cassette already recorded by 1.14.0/1.15.0
until <code>rehash</code> is actually run against it, and it cannot make an already-published CLI (1.13.2 and
earlier) speak up about a v10 cassette it already accepts</strong> — those installs are immutable; this fix
helps only ≥ 1.16.0 readers of ≥ 1.16.0-recorded cassettes. <code>replay --best-effort-future-cassette</code>
remains a deliberate, documented override of the v11 refusal — using it on a cassette you did not record
reopens the exact silent-misread hole this release closes.</p>
</li>
<li>
<p><strong><code>replay</code> names an unrecognized frozen top-level scenario key with a <code>::notice::</code></strong>, but only when the
cassette&rsquo;s own <code>cassetteVersion</code> is newer than the running build understands — not on every replay.
Diffing keys unconditionally would trip on a future release&rsquo;s new <strong>defaulted</strong> key on every replay of
every newer cassette (Zod defaults materialize into the frozen scenario at record time, so this build
cannot tell a meaningful value from an unknown key&rsquo;s default); gating on the version signal instead makes
this notice complementary to the version stamp above rather than overlapping it, and keeps it silent on
an ordinary same-version cassette, by design. Non-gating: it cannot move a verdict or an exit code, and it
helps only CLIs ≥ 1.16.0 — it cannot make an already-published CLI speak up about a case it already
accepted.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong><code>record --dry-run</code>&rsquo;s readiness preview no longer reads like a CI failure.</strong> Advertised in 1.15.0 as the
token-free loader check, a usage mode where the token/agent probe is irrelevant by construction — but the
probe still printed <code>✗ MISSING</code> for both, which a CI log reader (and at least one consumer) reasonably
mistook for a broken pipeline. The lines are now worded as informational (&ldquo;fine for <code>--dry-run</code>; only a
real record needs it&rdquo;) instead of <code>✗</code>-prefixed. <strong><code>--quiet</code> now suppresses the preview block</strong> (it was
accepted but a no-op on <code>record</code> before this release) — and, deliberately, nothing else: it does not
suppress <code>✗ broken:</code>/<code>skipped:</code> lines or change an exit code, because muting the loader check&rsquo;s only
named output would gut the feature 1.15.0 documented while leaving the exit code red — the worst of both.
That combination is the point: <strong><code>record scenarios/ --dry-run --quiet</code> is the load gate a CI step wants</strong>
— no output and exit 0 when every scenario loads, and on failure the <code>✗ broken:</code> line naming the file and
the rejected key, exit 1. It belongs next to <code>lint</code> rather than instead of it: <code>lint</code> only <em>warns</em> on an
unknown key, so a scenario that lints with warnings can still be unloadable, and a green <code>lint</code> is not
evidence the suite runs. Documented as a pipeline stage in <code>references/ci-recipe.md</code>.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>The unknown-key strictness rule is corrected at every site it shipped wrong</strong> —
<code>docs/scenario.md</code>, <code>docs/cassette.md</code>, <code>SKILL.md</code>, and <code>references/scenario-schema.md</code>. 1.15.0&rsquo;s own
docs fix stated: &ldquo;a key from a newer harness fails LOUD on an older CLI — it is never silently
reinterpreted,&rdquo; with no path qualifier. That is true of the <strong>loader</strong> (<code>run</code>/<code>skill</code>/<code>record</code>) and false
of <strong><code>replay</code></strong>: a cassette&rsquo;s frozen scenario is a passthrough object, so a top-level key the running CLI
doesn&rsquo;t know is carried but never consulted, and where that key conditions an assertion (as <code>lane:</code>
does), a stale CLI can report green on a cassette the current CLI fails. The corrected statement also
keeps the guarantee this class of fix keeps dropping: frozen <strong>assertions</strong> are not loose — an
unrecognized assertion key in a same-or-older-version cassette is still a hard reject (exit 2), so
<code>replay</code> does not validate nothing. Every site states the same three regimes: a ≥ 1.16.0-recorded
<code>lane: remote</code> cassette (v11, refused loudly by an older <code>replay</code> and <code>verify-cassettes</code> alike); a
1.14.0/1.15.0-recorded one (v10, still silently misread — <code>rehash</code> to fix); and <strong><code>replay --best-effort-future-cassette</code></strong>, which overrides the v11 refusal and reopens the silent-misread path on
purpose. That override is <code>replay</code>-only — <code>verify-cassettes</code> does not accept it.</p>
</li>
<li>
<p><strong><code>record --help</code> documents every flag <code>record</code> accepts.</strong> Two hand-maintained usage strings had drifted
in both directions: <code>--help</code> was missing <code>--max-budget-usd</code> and <code>--decider-model</code> (both present in the
usage-error string), and the usage-error string was missing <code>--dry-run</code> (present in <code>--help</code>). Both
strings are now built from one exported flag set (<code>RECORD_BOOLEAN_FLAGS</code>/<code>RECORD_VALUE_FLAGS</code> in
<code>src/run/cassette.ts</code>), and a test asserts every flag in that set appears in <code>record --help</code> (with an
explicit allowlist for the two deliberate no-ops, <code>--verbose</code>/<code>--quiet</code>&rsquo;s pre-1.16.0 behavior) — so this
class of drift reds CI instead of waiting for a consumer to grep for a flag that exists.</p>
</li>
<li>
<p><strong><code>lane</code> is added to the <code>--assert-from</code>/<code>--reassert</code> recording-shaping drift guard.</strong> <code>lane</code> conditions
assertion outcomes exactly like the six fields the guard already compared, but was never added when the
key shipped in 1.14.0 — see the Upgrade note above for what this changes for a currently-green command.
The three places that enumerate the drift set for a human (the reassert notice, and two usage strings)
now derive from one shared field list instead of hand-repeating it, closing the same drift class as the
<code>record --help</code> fix above — two of those three strings were already stale before this release (missing
<code>fidelity</code>/<code>requires_capabilities</code>, not just <code>lane</code>).</p>
</li>
<li>
<p><strong><code>--dry-run</code> and <code>--rerecord-stale</code>&rsquo;s mutual exclusion is now documented</strong>, in <code>record --help</code>,
<code>docs/cassette.md</code>, and <code>references/task-recipes.md</code>. The guard existed before this release and was
deliberate — dry-running a stale-only re-record would need real filesystem selection work <code>--dry-run</code>
doesn&rsquo;t do — but 1.15.0 advertised the cumulative budget cap specifically for <code>--rerecord-stale</code> sweeps
without mentioning that the exact form it was advertising cannot be pre-flighted. The documented
workaround: dry-run the plain <code>scenarios/</code> directory instead — a superset of what a <code>--rerecord-stale</code>
sweep would actually touch, so it&rsquo;s conservative in the right direction.</p>
</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 1.16.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/93">https://github.com/yaniv-golan/cowork-harness/pull/93</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.16.0">https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.16.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/b.ia-accessibility-checker/</link><pubDate>Sat, 01 Aug 2026 22:13:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v.0.1.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows developers to define requirements and audience profiles, enabling companies to ensure their code meets accessibility guidelines. The action uses AI to analyze code and report on compliance, helping developers improve product accessibility without the need for external solutions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v.0.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that automates accessibility checks in CI/CD pipelines. It allows developers to define requirements and audience profiles, enabling companies to ensure their code meets accessibility guidelines. The action uses AI to analyze code and report on compliance, helping developers improve product accessibility without the need for external solutions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update geminiService.ts (688e09b)</li>
<li>Update README.md (dbe3d74)</li>
<li>Update README.md (0f117a4)</li>
<li>Update README.md (45026e8)</li>
<li>Merge pull request #2 from YuriFAToledo/documentation (04a0849)</li>
<li>Update README.md (8bb0621)</li>
<li>Update README.md (efeffcc)</li>
<li>feat: add pr flow (2bf86c4)</li>
<li>feat: new gemini properties (0d597b1)</li>
<li>fix: enforce properties at gemini json (313ff7b)</li>
</ul>
]]></content:encoded></item><item><title>PixLog Visual Policy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/pixlog-visual-policy/</link><pubDate>Sat, 01 Aug 2026 22:12:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/pixlog-visual-policy/</guid><description>Version updated for https://github.com/zhao-xuan/PixLog to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PixLog is a GitHub Action that analyzes image changes in Git repositories to detect modifications of specific pixels, identifies contributors, and provides provenance information. It helps ensure consistent quality and traceability of images by tracking visual diffs, commits, and their origin.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zhao-xuan/PixLog">https://github.com/zhao-xuan/PixLog</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pixlog-visual-policy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PixLog is a GitHub Action that analyzes image changes in Git repositories to detect modifications of specific pixels, identifies contributors, and provides provenance information. It helps ensure consistent quality and traceability of images by tracking visual diffs, commits, and their origin.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="pixlog-v011">PixLog v0.1.1</h1>
<p>This release makes PixLog straightforward to discover, install, and try while
keeping its Git-native architecture unchanged.</p>
<p><img src="https://raw.githubusercontent.com/zhao-xuan/PixLog/main/docs/assets/demos/pixlog-visual-history.gif" alt="PixLog visual history"></p>
<h2 id="whats-new">What&rsquo;s New</h2>
<ul>
<li>A runnable five-commit demo inside <code>demo/workspace</code>, built from licensed source
images with real <code>pixlog run -- magick ...</code> commands.</li>
<li>Chafa-powered inline before/after/heatmap previews for interactive terminals,
with JSON and NDJSON output kept control-sequence free.</li>
<li>The versioned <strong>PixLog Visual Policy</strong> composite Action for pull requests.</li>
<li>Canonical Go module path <code>github.com/zhao-xuan/PixLog</code>, enabling standard remote
<code>go install</code> commands.</li>
<li>Reproducible README stills, demo recordings, and a 1280x640 social preview.</li>
</ul>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew install zhao-xuan/tap/pixlog chafa
</span></span></code></pre></div><p>Or install the two command entry points with Go:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>go install github.com/zhao-xuan/PixLog/cmd/pixlog@v0.1.1
</span></span><span style="display:flex;"><span>go install github.com/zhao-xuan/PixLog/cmd/git-pixlog@v0.1.1
</span></span></code></pre></div><h2 id="try-the-demo">Try the Demo</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>git clone https://github.com/zhao-xuan/PixLog.git
</span></span><span style="display:flex;"><span>cd PixLog
</span></span><span style="display:flex;"><span>brew install zhao-xuan/tap/pixlog chafa imagemagick
</span></span><span style="display:flex;"><span>bash demo/setup.sh
</span></span><span style="display:flex;"><span>cd demo/workspace
</span></span><span style="display:flex;"><span>pixlog diff HEAD~1 HEAD -- assets/hero.png
</span></span></code></pre></div><h2 id="github-action">GitHub Action</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fetch-depth</span>: <span style="color:#ae81ff">0</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">zhao-xuan/PixLog@v0.1.1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">policy</span>: <span style="color:#ae81ff">.pixlog-policy.json</span>
</span></span></code></pre></div><h2 id="known-limitations">Known Limitations</h2>
<ul>
<li>Built-in pixel decoding currently covers PNG, JPEG, and GIF. Other recognized
formats retain exact-byte history and provenance but may not have visual diff.</li>
<li>Photoshop and browser adapters still require host packaging and validation.</li>
<li>There is no hosted collaboration service, HTTP lock service, or Web review UI.</li>
<li>Hosted-model recipes may be provenance-only and are not claimed to reproduce
deterministically when parameters are unavailable.</li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/zhao-xuan/PixLog/compare/v0.1.0...v0.1.1">https://github.com/zhao-xuan/PixLog/compare/v0.1.0...v0.1.1</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/postman-onboarding-repo-sync/</link><pubDate>Sat, 01 Aug 2026 14:10:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.8.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the process of exporting Postman collections and environments into a repository. It also sets up CI, mock servers, and monitors around these assets. The action solves the problem of managing API testing and monitoring in a team environment by integrating with Postman’s APIs to export data and configure CI workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.8.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action automates the process of exporting Postman collections and environments into a repository. It also sets up CI, mock servers, and monitors around these assets. The action solves the problem of managing API testing and monitoring in a team environment by integrating with Postman&rsquo;s APIs to export data and configure CI workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): port automatic release cut by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/102">https://github.com/postman-cs/postman-repo-sync-action/pull/102</a></li>
<li>fix(release): recover unpublished immutable tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/103">https://github.com/postman-cs/postman-repo-sync-action/pull/103</a></li>
<li>chore(deps): take patched transitive versions from npm audit by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/104">https://github.com/postman-cs/postman-repo-sync-action/pull/104</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/105">https://github.com/postman-cs/postman-repo-sync-action/pull/105</a></li>
<li>fix(release): reconcile incomplete cuts before new tags by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/106">https://github.com/postman-cs/postman-repo-sync-action/pull/106</a></li>
<li>chore(deps): bump the actions group and follow the pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/107">https://github.com/postman-cs/postman-repo-sync-action/pull/107</a></li>
<li>Fix public mock validation before reuse by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/108">https://github.com/postman-cs/postman-repo-sync-action/pull/108</a></li>
<li>feat: add manual mock validation environment by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/109">https://github.com/postman-cs/postman-repo-sync-action/pull/109</a></li>
<li>fix: pin preview test branch context by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/110">https://github.com/postman-cs/postman-repo-sync-action/pull/110</a></li>
<li>feat: support private mocks with runtime credential injection by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/111">https://github.com/postman-cs/postman-repo-sync-action/pull/111</a></li>
<li>fix: bind private mock runtime auth in production by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/112">https://github.com/postman-cs/postman-repo-sync-action/pull/112</a></li>
<li>feat: make private mock credentials self-service across CI, app, and runner by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/113">https://github.com/postman-cs/postman-repo-sync-action/pull/113</a></li>
<li>fix: execute private mock auth hooks for segmented hosts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/114">https://github.com/postman-cs/postman-repo-sync-action/pull/114</a></li>
<li>fix: resolve templated private mock URLs before auth by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/115">https://github.com/postman-cs/postman-repo-sync-action/pull/115</a></li>
<li>perf(repo-sync): bound artifact acquisition reads by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/116">https://github.com/postman-cs/postman-repo-sync-action/pull/116</a></li>
<li>fix(deps): replace deprecated Faker with compatible v6 by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/117">https://github.com/postman-cs/postman-repo-sync-action/pull/117</a></li>
<li>fix(repo-mutation): reconcile stale branch before push by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/118">https://github.com/postman-cs/postman-repo-sync-action/pull/118</a></li>
<li>fix(repo-mutation): resolve generated artifact conflicts by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/119">https://github.com/postman-cs/postman-repo-sync-action/pull/119</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.8.1">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.15...v2.8.1</a></p>
]]></content:encoded></item><item><title>Rams Design Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/rams-design-review/</link><pubDate>Sat, 01 Aug 2026 14:09:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/rams-design-review/</guid><description>Version updated for https://github.com/rams-design/rams-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Rams Design Review is a GitHub Action that automatically scores changes in pull requests, emits structured findings, and automates the merging process based on design defects. It judges PRs by scoring UI changes (0–100), emitting issues and patches for critical designs, and gating merges to address critical defects only. The action can be scheduled to run at specific times or as part of a continuous integration/continuous deployment pipeline.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rams-design/rams-action">https://github.com/rams-design/rams-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rams-design-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Rams Design Review is a GitHub Action that automatically scores changes in pull requests, emits structured findings, and automates the merging process based on design defects. It judges PRs by scoring UI changes (0–100), emitting issues and patches for critical designs, and gating merges to address critical defects only. The action can be scheduled to run at specific times or as part of a continuous integration/continuous deployment pipeline.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Score UI changes 0–100 on every PR or scheduled sweep. Gate on criticals or a score floor. Findings land as structured JSON + git-applyable patches for your own agent step. We judge; your tools repair.</p>
]]></content:encoded></item><item><title>cache-python-deps</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/cache-python-deps/</link><pubDate>Sat, 01 Aug 2026 14:08:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/cache-python-deps/</guid><description>Version updated for https://github.com/re-actors/cache-python-deps to version v1.0.1.
This action is used across all versions by 24 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the management of ABI-sensitive Python dependencies by caching them based on a hash derived from dependency declaration files. It solves the problem of reusing cached dependencies when the Python runtime or ABI stability changes, reducing build times and improving CI/CD efficiency. The action is designed to be used instead of the default cache input in actions/setup-python.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/re-actors/cache-python-deps">https://github.com/re-actors/cache-python-deps</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>24</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cache-python-deps">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the management of ABI-sensitive Python dependencies by caching them based on a hash derived from dependency declaration files. It solves the problem of reusing cached dependencies when the Python runtime or ABI stability changes, reducing build times and improving CI/CD efficiency. The action is designed to be used instead of the default <code>cache</code> input in <code>actions/setup-python</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p align="right"><i>So <a href="https://ep2026.europython.eu/speaker/sviatoslav-sydorenko-sviatoslav-sidorenko/">@webknjaz</a> just <a href="https://ep2026.europython.eu/session/reusable-tox-yml-five-patterns-to-eliminate-ci-cd-boilerplate">returned</a> from <a href="https://ep2026.europython.eu/session/defending-open-source-from-ai-slop-a-maintainer-s-practical-guide">EuroPython 2026</a> last week and remembered to release this… Have fun ;)</i></p>
<h2 id="-internals">🛠️ Internals</h2>
<p><code>actions/cache</code> got bumped to v6 and now runs under Node.js 24. No more runtime warnings. Yay!</p>
<h2 id="-new-contributors">💪 New Contributors</h2>
<ul>
<li>@Spacetown<a href="https://github.com/sponsors/A5rocks">💰</a> reminded me to bump an internal action call in #1</li>
</ul>
<p><strong>🪞 Full Diff</strong>: <a href="https://github.com/re-actors/cache-python-deps/compare/v1.0.0...v1.0.1">https://github.com/re-actors/cache-python-deps/compare/v1.0.0...v1.0.1</a></p>
<p><strong>🧔‍♂️ Release Manager:</strong> <a href="https://github.com/sponsors/webknjaz">@webknjaz 🇺🇦</a></p>
<p><strong>💬 Discuss</strong> <a href="https://github.com/re-actors/cache-python-deps/discussions/2">on GitHub</a>.</p>
<p><a href="https://github.com/sponsors/webknjaz"><img src="https://img.shields.io/badge/%40webknjaz-transparent?logo=githubsponsors&amp;logoColor=%23EA4AAA&amp;label=Sponsor&amp;color=2a313c" alt="GH Sponsors badge"></a></p>
]]></content:encoded></item><item><title>Claude BugBot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/claude-bugbot/</link><pubDate>Sat, 01 Aug 2026 14:07:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/claude-bugbot/</guid><description>Version updated for https://github.com/rekpero/claude-bugbot-github-action to version v1.0.14.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of finding bugs in pull requests using Claude Code, a free alternative to Cursor BugBot. It analyzes PR diffs for various issues like logic errors, security vulnerabilities, and null dereferences and posts inline review comments on affected lines directly. The action is available for free with any Claude Pro or Max subscription by generating a setup token.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rekpero/claude-bugbot-github-action">https://github.com/rekpero/claude-bugbot-github-action</a></strong> to version <strong>v1.0.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/claude-bugbot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of finding bugs in pull requests using Claude Code, a free alternative to Cursor BugBot. It analyzes PR diffs for various issues like logic errors, security vulnerabilities, and null dereferences and posts inline review comments on affected lines directly. The action is available for free with any Claude Pro or Max subscription by generating a setup token.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>Multi-lens review pass</strong> — A single scan of a diff only finds the class of bug that scan was looking for. <code>buildPrompt</code> now carries a <code>REVIEW LENSES</code> block instructing four sequential passes, each hunting a different defect class: (1) a direct scan of the changed lines with no extra context; (2) project rules — read the root <code>CLAUDE.md</code>/<code>AGENTS.md</code> and any in directories the diff touches, flagging a violation only when the file explicitly calls out that specific thing, with the rule quoted in the description; (3) code comments in and around the modified code, including untouched ones, since a comment often states the invariant or ordering requirement the change breaks; (4) git history, reading <code>git log</code>/<code>git blame</code> on the modified lines to catch a change that silently undoes an earlier bug fix. Adapted from the multi-agent <code>/code-review</code> command, which fans five reviewers out over separate perspectives — BugBot is one CLI invocation producing one JSON answer, so the perspectives become sequential passes.</p>
<blockquote>
<p>The history lens is guarded: it checks <code>git rev-parse --is-shallow-repository</code> first and skips itself on a shallow clone rather than guessing from a single commit. <code>actions/checkout@v4</code> defaults to <code>fetch-depth: 1</code>, so this lens stays inert unless the user opts in — <code>example-workflow.yml</code> now carries a commented-out <code>fetch-depth: 0</code> for that.</p>
</blockquote>
</li>
<li>
<p><strong>Confidence scoring with an 80-point reporting threshold</strong> — Surviving candidates are now scored 0–100 against an explicit five-point rubric (0 = false positive or pre-existing; 25 = unverifiable; 50 = real but a nitpick; 75 = double-checked and hit in practice; 100 = certain and frequent), and anything below 80 is dropped silently — not downgraded to a lower severity, not mentioned as a minor note, not folded into the summary. This is the <code>/code-review</code> command&rsquo;s second-pass scoring filter collapsed into a self-check. Scores stay internal reasoning, so <code>jsonSchema</code>, <code>reformatToJson</code>, <code>parseResponse</code>, and every downstream comment formatter are unchanged.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p><strong><code>DO NOT report</code> extended with a false-positive catalog</strong> — Added the exclusions the <code>/code-review</code> command enumerates and this prompt previously left implicit: pre-existing issues and real issues on lines the PR didn&rsquo;t modify; anything a linter, typechecker, or compiler catches on its own (with an explicit instruction not to run or reason about build steps, since CI runs them separately); issues deliberately silenced by a lint-ignore or explanatory comment; behaviour changes that are clearly intentional or part of the PR&rsquo;s broader change; and pedantic nitpicks a senior engineer wouldn&rsquo;t raise.</p>
</li>
<li>
<p><strong><code>IMPORTANT</code> lookup scope reconciled with the new lenses</strong> — The instruction read &ldquo;Only look up what is directly referenced by the changed lines&rdquo;, which directly contradicted the lenses telling Claude to read CLAUDE.md files, surrounding comments, and git history. It now reads &ldquo;what the changed lines directly reference, plus what the REVIEW LENSES below explicitly call for&rdquo;, leaving the ban on broad codebase scanning intact. Contradictory instructions degrade behaviour on both sides of the contradiction, so this is a correctness fix rather than wording.</p>
</li>
</ul>
]]></content:encoded></item><item><title>setup-maestro-cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/setup-maestro-cli/</link><pubDate>Sat, 01 Aug 2026 14:06:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/setup-maestro-cli/</guid><description>Version updated for https://github.com/remarkablemark/setup-maestro-cli to version v1.0.19.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up the Maestro CLI, a tool for automating mobile testing and deployment processes on GitHub Actions workflows. It allows developers to easily integrate Maestro into their CI/CD pipelines to streamline mobile app development workflows, enabling automated UI testing, performance testing, and other mobile-specific tasks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablemark/setup-maestro-cli">https://github.com/remarkablemark/setup-maestro-cli</a></strong> to version <strong>v1.0.19</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-maestro-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up the Maestro CLI, a tool for automating mobile testing and deployment processes on GitHub Actions workflows. It allows developers to easily integrate Maestro into their CI/CD pipelines to streamline mobile app development workflows, enabling automated UI testing, performance testing, and other mobile-specific tasks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1019-2026-08-01"><a href="https://github.com/remarkablemark/setup-maestro-cli/compare/v1.0.18...v1.0.19">1.0.19</a> (2026-08-01)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump maestro from 2.7.0 to 2.8.0 (<a href="https://github.com/remarkablemark/setup-maestro-cli/issues/269">#269</a>) (<a href="https://github.com/remarkablemark/setup-maestro-cli/commit/b722656b6a919516226938a6d19164636ecb72aa">b722656</a>)</li>
</ul>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/remyx-outrider/</link><pubDate>Sat, 01 Aug 2026 14:06:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.45.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation and comparison of new methods against existing codebases, helping teams measure changes using metrics already tracked. It provides a fresh runner for each dispatch, eliminates context pollution, and supports multiple model backends for different use cases. The action can be triggered via schedule or manually by specifying paper pins or search terms, supporting both draft PRs and branch-only mode.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.45</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation and comparison of new methods against existing codebases, helping teams measure changes using metrics already tracked. It provides a fresh runner for each dispatch, eliminates context pollution, and supports multiple model backends for different use cases. The action can be triggered via schedule or manually by specifying paper pins or search terms, supporting both draft PRs and branch-only mode.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="self-hosted--on-prem-endpoint-override">Self-hosted / on-prem endpoint override</h2>
<p>Add <code>base-url</code> as a <code>workflow_dispatch</code> input on this repo&rsquo;s own runner and thread it into the composite action&rsquo;s <code>model-base-url</code>. Explicit override wins; otherwise the per-provider default applies.</p>
<p>Same input landing in the CLI-generated customer template (<code>remyxai outrider init</code>) in parallel — customers with a self-hosted model behind a litellm proxy, vLLM Anthropic shim, on-prem gateway, or Cloudflare Access can now pass a URL through workflow_dispatch instead of forking the template.</p>
<h2 id="compatibility">Compatibility</h2>
<p>Composite action, no breaking changes. Pinned callers on <code>@v1</code> pick this up automatically.</p>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/rumdl-action/</link><pubDate>Sat, 01 Aug 2026 14:05:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.48.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rumdl is a high-performance Markdown linter and formatter written in Rust, offering a modern approach to linting and formatting Markdown files. It supports multiple Markdown flavors, provides automatic formatting with --fix, and offers detailed error reporting for improved development experience. The tool is designed to be fast and easy to use, suitable for both small projects and large repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.48</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>rumdl is a high-performance Markdown linter and formatter written in Rust, offering a modern approach to linting and formatting Markdown files. It supports multiple Markdown flavors, provides automatic formatting with <code>--fix</code>, and offers detailed error reporting for improved development experience. The tool is designed to be fast and easy to use, suitable for both small projects and large repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>md087</strong>: report inline disable comments that suppress nothing (<a href="https://github.com/rvben/rumdl/commit/40fc37da50885e83c32d49cb1ae9dc7a853416fc">40fc37d</a>)</li>
<li><strong>md051,md057</strong>: check path-shaped frontmatter values behind an option (<a href="https://github.com/rvben/rumdl/commit/98a0ff0d24972a34c30d4665cdd6d03108925ee5">98a0ff0</a>)</li>
<li><strong>md033</strong>: add allowed-inside and a no-markdown-equivalent allowlist value (<a href="https://github.com/rvben/rumdl/commit/cb0ba510845caba5b67a7c9bce40516b6227b76f">cb0ba51</a>)</li>
<li>name rules by their readable name in generated output (<a href="https://github.com/rvben/rumdl/commit/3b196d806a1d04117aaedaea7e2ca7669bc5d4a9">3b196d8</a>)</li>
<li><strong>md082</strong>: add allow-parent-headings to accept a heading with subsections (<a href="https://github.com/rvben/rumdl/commit/662d5702ac130ff2485ba9a210eb0289baccaadd">662d570</a>)</li>
<li><strong>md040</strong>: add custom-languages for fence labels Linguist does not know (<a href="https://github.com/rvben/rumdl/commit/1eda9f4bcdd7a37e8b9f17be3c9fc72e1b568c5e">1eda9f4</a>)</li>
<li><strong>md086</strong>: add rule for unclosed comment delimiters (<a href="https://github.com/rvben/rumdl/commit/6cbd27ffb6571839daff260570dfe6c382fd50a3">6cbd27f</a>)</li>
<li><strong>md057</strong>: report relative links that point at their own file (<a href="https://github.com/rvben/rumdl/commit/7fd85fe7721df71c9bc41cadf0ed0afdd2cf1f64">7fd85fe</a>)</li>
<li><strong>lsp</strong>: report inline config problems as diagnostics (<a href="https://github.com/rvben/rumdl/commit/20acc02eb829ab7083270c8b857ab7a49437c83a">20acc02</a>)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>md063</strong>: name the documented style spellings when a style is invalid (<a href="https://github.com/rvben/rumdl/commit/5476db821c40749ed8adbd431930c157b5e06179">5476db8</a>)</li>
<li><strong>md013</strong>: exempt an HTML-only line in a blockquote inside a list item (<a href="https://github.com/rvben/rumdl/commit/98e5d34e2016fc1c7178fba7f3219e56553eae6b">98e5d34</a>)</li>
<li><strong>md013</strong>: exempt nested standalone links (<a href="https://github.com/rvben/rumdl/commit/3be374e51ddd045e9cc8a2ebaf5d33312ba1a60d">3be374e</a>)</li>
<li><strong>md013</strong>: adjust paragraph reflow limit for common indent (<a href="https://github.com/rvben/rumdl/commit/2f7c68e2796b1cb4ab6f59be9955124da6e25b91">2f7c68e</a>)</li>
<li><strong>md032</strong>: avoid warning on pseudo-list markers after recognized lists (<a href="https://github.com/rvben/rumdl/commit/71e6ff5601935ba39a7292ec886cdc54542e76cf">71e6ff5</a>)</li>
<li><strong>md062</strong>: preserve parentheses in link destinations (<a href="https://github.com/rvben/rumdl/commit/8ec2eeab65b3d40e7e749acefeed4f82a5e37b9d">8ec2eea</a>)</li>
<li><strong>md051</strong>: resolve cross-file links whose path carries a query string (<a href="https://github.com/rvben/rumdl/commit/8876d46993a13f390465b1b876ba060530d71d6c">8876d46</a>)</li>
<li><strong>md051,md057</strong>: read frontmatter in documents that hold no body links (<a href="https://github.com/rvben/rumdl/commit/5f35562156f05076005e062e09438610cb791385">5f35562</a>)</li>
<li><strong>md040</strong>: take disabled fences out of the label vote by the shared state (<a href="https://github.com/rvben/rumdl/commit/dd7011d474f366b7eaadc4681a32c0454abc5d14">dd7011d</a>)</li>
<li><strong>md040</strong>: honor a rule alias in a disable comment (<a href="https://github.com/rvben/rumdl/commit/7b86267773a127f667b81d8402070629d8a616e6">7b86267</a>)</li>
<li><strong>md040</strong>: reject custom-languages entries containing whitespace (<a href="https://github.com/rvben/rumdl/commit/651a7ec134d1436b6f7bf76c3f19028b61652a7f">651a7ec</a>)</li>
<li><strong>md040</strong>: stop normalizing fence labels to an invalid preferred alias (<a href="https://github.com/rvben/rumdl/commit/7c10626c7d73ec756e85ca20495672d33a7e59b6">7c10626</a>)</li>
<li><strong>config</strong>: apply map-valued rule options set in rumdl.toml (<a href="https://github.com/rvben/rumdl/commit/a8ff5b6073e8b8a2aa12e3fd8015363108b08899">a8ff5b6</a>)</li>
<li><strong>inline-config</strong>: ignore directives inside indented code blocks (<a href="https://github.com/rvben/rumdl/commit/fee4d6f12a76319f1381d9191f7bb0c9dae44e14">fee4d6f</a>)</li>
<li><strong>config</strong>: warn when an inline enable targets a per-file-ignored rule (<a href="https://github.com/rvben/rumdl/commit/3c3837f468e45aa08114274321b010dcf489ba85">3c3837f</a>)</li>
<li><strong>lsp</strong>: measure diagnostic positions in UTF-16 code units (<a href="https://github.com/rvben/rumdl/commit/3cb34b4c6d37508f79492d84b9975c28eb04a936">3cb34b4</a>)</li>
<li><strong>comments</strong>: read an unclosed comment in a container body, not in code (<a href="https://github.com/rvben/rumdl/commit/85bd3f8b6f9be657b8f7d93b87c988fdfd7479db">85bd3f8</a>)</li>
<li><strong>comments</strong>: hide the block an unclosed <code>&lt;!--</code> opens from every rule (<a href="https://github.com/rvben/rumdl/commit/27c247c9458dd7c3845d59052458ec52e10c30bd">27c247c</a>)</li>
<li><strong>md086</strong>: keep reporting an Obsidian opener below an unclosed HTML one (<a href="https://github.com/rvben/rumdl/commit/a05dff9f4152cd9f0aa7dc770a74a87bf07886af">a05dff9</a>)</li>
<li><strong>md086</strong>: don&rsquo;t report a comment opener the other syntax hides (<a href="https://github.com/rvben/rumdl/commit/4d589a1f6caf218256932ef6c5c1d02b2184cc55">4d589a1</a>)</li>
<li><strong>comments</strong>: ignore Obsidian comment delimiters inside front matter (<a href="https://github.com/rvben/rumdl/commit/441a0a40c3fc9710155a197086efe1ee9464c054">441a0a4</a>)</li>
<li><strong>comments</strong>: ignore comment delimiters inside front matter (<a href="https://github.com/rvben/rumdl/commit/dded694b43c07221b5c62d53bb2ae448aa917289">dded694</a>)</li>
<li><strong>comments</strong>: end an HTML comment at the first &ndash;&gt; after the opener (<a href="https://github.com/rvben/rumdl/commit/274166a47c74e2e53e9a7ac604c2154c8722a772">274166a</a>)</li>
<li><strong>md057</strong>: keep search paths a fallback when matching a link to its own file (<a href="https://github.com/rvben/rumdl/commit/26e88cc2fd82e791faccf5de7e39bb85d2d41a7d">26e88cc</a>)</li>
<li><strong>md057</strong>: anchor reference definition fixes to the link destination (<a href="https://github.com/rvben/rumdl/commit/b930b71f0197133eb5c4fe21325a05183cccc367">b930b71</a>)</li>
<li><strong>lsp</strong>: use defaults when a workspace root&rsquo;s own scope cannot be resolved (<a href="https://github.com/rvben/rumdl/commit/d1777ce975b182c50e63c772d96f0cfd04bf7f64">d1777ce</a>)</li>
<li><strong>cli</strong>: count fixes a document enables with an inline configure-file comment (<a href="https://github.com/rvben/rumdl/commit/f17a5eb48fb62072f81393c816b0d0b66015a89e">f17a5eb</a>)</li>
<li><strong>lsp</strong>: resolve a secondary workspace root&rsquo;s own configuration (<a href="https://github.com/rvben/rumdl/commit/41b9a22b8d4a367b6fcebe4d3c1091d545df34ce">41b9a22</a>)</li>
<li><strong>cli</strong>: count an unloadable subdirectory config as a config warning (<a href="https://github.com/rvben/rumdl/commit/648aa72cec173416e543b2f388de80290fb32d93">648aa72</a>)</li>
<li><strong>md041</strong>: report the fix capability its opt-in fix enables (<a href="https://github.com/rvben/rumdl/commit/ed30c9a1d933a237424a66361bc06a0332e925f8">ed30c9a</a>)</li>
<li><strong>lsp</strong>: resolve workspace configuration from the workspace root (<a href="https://github.com/rvben/rumdl/commit/8e0fceea149e2bac4ad6716737257077462e77ce">8e0fcee</a>)</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li><strong>md062,lint-context</strong>: scan link escapes in one forward pass (<a href="https://github.com/rvben/rumdl/commit/8fff82bdbc0caf7f655335c6d161fe3d2215cf06">8fff82b</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.48-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.48-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.48-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.48-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-x86_64-apple-darwin.tar.gz">rumdl-v0.2.48-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-aarch64-apple-darwin.tar.gz">rumdl-v0.2.48-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-x86_64-pc-windows-msvc.zip">rumdl-v0.2.48-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.48/rumdl-v0.2.48-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/agentauditkit-mcp-security-scan/</link><pubDate>Sat, 01 Aug 2026 14:03:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.65.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The AgentAuditKit action is a security scanner designed to audit AI agent pipelines. It ensures that your code, configs, and secrets remain secure by identifying misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across various platforms. Unlike hosted scanners, it runs fully offline and deterministically, producing auditor-ready compliance-evidence packs in SARIF and PDF formats for 12 security frameworks. It covers 274 rules across 10 agent platforms, including AST-based Python taint analysis and regex pattern scanners for TypeScript/JavaScript and Rust.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.65</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The AgentAuditKit action is a security scanner designed to audit AI agent pipelines. It ensures that your code, configs, and secrets remain secure by identifying misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across various platforms. Unlike hosted scanners, it runs fully offline and deterministically, producing auditor-ready compliance-evidence packs in SARIF and PDF formats for 12 security frameworks. It covers 274 rules across 10 agent platforms, including AST-based Python taint analysis and regex pattern scanners for TypeScript/JavaScript and Rust.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.65
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.65
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.65</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Correct the EU AI Act Art.15 date (AI Omnibus) + re-cut the determinism evidence by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/520">https://github.com/sattyamjjain/agent-audit-kit/pull/520</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.64...v0.3.65">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.64...v0.3.65</a></p>
]]></content:encoded></item><item><title>Automated Changelog Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/automated-changelog-generator/</link><pubDate>Sat, 01 Aug 2026 14:02:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/automated-changelog-generator/</guid><description>Version updated for https://github.com/shazib-summar/automated-changelog-gh to version v0.0.6.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automated-changelog-gh generates and updates a CHANGELOG.md file based on git tags and commit history. It groups commits using Conventional Commits and renders them in Keep a Changelog format. The action can regenerate the entire changelog or update it for a newly released tag, providing links to GitHub compare views and PRs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shazib-summar/automated-changelog-gh">https://github.com/shazib-summar/automated-changelog-gh</a></strong> to version <strong>v0.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/automated-changelog-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>automated-changelog-gh</code> generates and updates a CHANGELOG.md file based on git tags and commit history. It groups commits using Conventional Commits and renders them in Keep a Changelog format. The action can regenerate the entire changelog or update it for a newly released tag, providing links to GitHub compare views and PRs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: update the action version for this repo by @shazib-summar in <a href="https://github.com/shazib-summar/automated-changelog-gh/pull/6">https://github.com/shazib-summar/automated-changelog-gh/pull/6</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/shazib-summar/automated-changelog-gh/compare/v0.0.5...v0.0.6">https://github.com/shazib-summar/automated-changelog-gh/compare/v0.0.5...v0.0.6</a></p>
]]></content:encoded></item><item><title>Sherpa.sh</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/sherpa.sh/</link><pubDate>Sat, 01 Aug 2026 14:01:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/sherpa.sh/</guid><description>Version updated for https://github.com/sherpa-sh/Sherpa-Action to version v1.0.0-alpha.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sherpa.sh is an AI-powered deployment tool that simplifies infrastructure management by translating human-readable descriptions into automated cloud deployments. It streamlines the process of deploying applications across various cloud providers, allowing developers to focus on their code without needing to deal with complex configuration files or understand intricate cloud concepts. With Sherpa, developers can describe their desired application setup in plain English and let the AI handle the rest, from choosing appropriate cloud resources to configuring security settings and optimizing performance for maximum efficiency.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sherpa-sh/Sherpa-Action">https://github.com/sherpa-sh/Sherpa-Action</a></strong> to version <strong>v1.0.0-alpha.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherpa-sh">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sherpa.sh is an AI-powered deployment tool that simplifies infrastructure management by translating human-readable descriptions into automated cloud deployments. It streamlines the process of deploying applications across various cloud providers, allowing developers to focus on their code without needing to deal with complex configuration files or understand intricate cloud concepts. With Sherpa, developers can describe their desired application setup in plain English and let the AI handle the rest, from choosing appropriate cloud resources to configuring security settings and optimizing performance for maximum efficiency.</p>
]]></content:encoded></item><item><title>CrewScore</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/crewscore/</link><pubDate>Sat, 01 Aug 2026 14:00:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/crewscore/</guid><description>Version updated for https://github.com/shmindmaster/crewscore to version v0.6.9.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary CrewScore is an offline tool that checks AI agent prompts for missing written safeguards. It provides a checklist of 23 published controls and identifies gaps in coverage. This helps ensure that prompts cover essential safety features, such as human approval and cost limits, without relying on API keys or LLMs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shmindmaster/crewscore">https://github.com/shmindmaster/crewscore</a></strong> to version <strong>v0.6.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crewscore">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>CrewScore is an offline tool that checks AI agent prompts for missing written safeguards. It provides a checklist of 23 published controls and identifies gaps in coverage. This helps ensure that prompts cover essential safety features, such as human approval and cost limits, without relying on API keys or LLMs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>No scoring change. Ruleset remains <code>crewscore-hygiene@0.6.0</code>.</p>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>The public corpus was labeled more strongly than its provenance allows.</strong>
CrewScore now says &ldquo;production-labeled agent system prompts&rdquo; everywhere,
rather than implying that independent production use was verified.</li>
<li><strong>Owner auto-merge could report success without enabling or completing the
merge.</strong> The controller now retries GitHub&rsquo;s transient merge state, merges an
already-clean PR only at its exact expected head, and fails closed on every
other error. Six executable state-machine tests cover the race paths.</li>
</ul>
<h3 id="improved">Improved</h3>
<ul>
<li>The package and public site now lead with the browser-local instruction
preflight for people shipping AI assistants, while keeping CI as an optional
recurring gate.</li>
<li>Package metadata names the maintainer explicitly, and stale release-demo
automation that no longer represented the product has been removed.</li>
</ul>
<hr>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/bernstein-multi-agent-orchestration/</link><pubDate>Sat, 01 Aug 2026 13:59:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.12.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is a deterministic orchestrator for CLI coding agents that ensures reproducible and isolated runs. It schedules tasks with plain Python, logs lineage, and provides an audit log for verification after execution. The tool helps avoid non-determinism by using hashes to detect mismatches at the exact step. Each task operates in its own Git worktree, ensuring no shared mutable state between agents.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein is a deterministic orchestrator for CLI coding agents that ensures reproducible and isolated runs. It schedules tasks with plain Python, logs lineage, and provides an audit log for verification after execution. The tool helps avoid non-determinism by using hashes to detect mismatches at the exact step. Each task operates in its own Git worktree, ensuring no shared mutable state between agents.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A correctness release. Three surfaces that reported success while doing
something else are fixed: a required quality gate now blocks the merge it was
already logging about, <code>--plan-only</code> no longer runs the work it was asked to
describe, and the write-ahead log recovers a torn tail onto its real
predecessor instead of forking the hash chain off genesis. Around those, the
reap path stops losing agents to worktree-layout drift, the documentation was
re-checked against the code rather than against itself, and the mypy backlog
came down by several hundred errors across a dozen packages. Upgrade in place;
read the behaviour changes first.</p>
<h2 id="behaviour-changes-read-before-upgrading">Behaviour changes (read before upgrading)</h2>
<ul>
<li>
<p><strong>A failed required quality gate now stops the merge (#3254).</strong> One <code>or</code> in
<code>_evaluate_approval_gate</code> covered two unrelated conditions: &ldquo;no approval gate
is configured&rdquo; and &ldquo;the required gate failed&rdquo;. Returning <code>skip_merge=False</code>
is right for the first and wrong for the second, so a failed gate was
reported, recorded as <code>blocked</code> in <code>quality_gates.jsonl</code>, and the branch
merged about 300ms later anyway. The two conditions are now separate. This is
a behaviour change in the direction of the documented contract: work that
previously merged past a failing required gate no longer merges, so a project
that had a permanently red required gate will start seeing merges refused —
which is what the gate was for.</p>
</li>
<li>
<p><strong><code>--plan-only</code> no longer executes the run when the plan came from a
positional plan file (#3255).</strong> <code>plan_file</code> is positional, so
<code>bernstein run plan.yaml --plan-only</code> took the plan-file dispatch, which
called the bootstrap entry point and returned before the flag was ever
consulted: task server, watchdog, spawner, a live agent, a worktree, a
commit, the merge path, exit code 0. The flag is now checked ahead of the
whole <code>--plan-file</code> / <code>--from-plan</code> dispatch, because it is a property of the
run and not of how the plan was supplied. With a plan file present the
preview renders the loaded plan, so its tasks appear with their roles and
models instead of a single synthetic task built from the plan&rsquo;s name, and the
rerun hint points back at the plan file rather than at <code>--from-plan</code>, which
reads only the goal line and would re-decompose from the plan name. The saved
plan is written as UTF-8; the render always emits status glyphs, so the
platform default encoding raised <code>UnicodeEncodeError</code> on a cp1252 locale.</p>
</li>
<li>
<p><strong>A stalled agent that is still writing bytes now gets reaped (#3058).</strong> The
escalation ladder and the Tier-1 watchdog both treat a recently-written
runner log as proof of life, and every adapter except <code>claude</code> merges the
child&rsquo;s stderr into that same file — so retry chatter, a spinner, or a
deprecation warning refreshed the mtime and reset the ladder, with no upper
bound. The deferral is now capped by <code>AGENT.liveness_suppression_cap_s</code>
(900s, overridable via <code>tuning.agent.liveness_suppression_cap_s</code>). Below the
cap a slow first turn keeps the grace it was given; past that much continuous
heartbeat silence the mtime is read as output noise and the ladder escalates,
so a stuck agent releases its worker slot at the escalation threshold instead
of holding it to the wall-clock hard cap.</p>
</li>
<li>
<p><strong>The MCP deprecated tool aliases announced in v3.11.0 for removal in this
release are still served.</strong> That removal did not land in this cycle. Set
<code>BERNSTEIN_MCP_DEPRECATED_ALIASES=0</code> to drop them now and surface any caller
still using an old name.</p>
</li>
</ul>
<h2 id="write-ahead-log">Write-ahead log</h2>
<p>Four defects in <code>core/persistence/wal.py</code>, each reproduced against unmodified
code before the fix (#3270, #3271, #3272, #3273).</p>
<ul>
<li>Torn-tail recovery no longer forks the chain. <code>_load_tail</code> fell back to
<code>(count - 1, GENESIS_HASH)</code> when the trailing line failed to parse, so the
next <code>append</code> chained its <code>prev_hash</code> off genesis rather than off its real
predecessor and the chain forked silently at the truncation point. Recovery
now rescans for the last entry whose stored <code>entry_hash</code> equals the SHA-256
of its own payload and resumes both <code>seq</code> and <code>prev_hash</code> from there, so a
partially-written line cannot become the chain anchor.</li>
<li><code>append</code> is fsync-failure-safe. It wrote and fsynced before advancing <code>seq</code>
and <code>prev_hash</code>, so an <code>fsync</code> raising <code>ENOSPC</code> or <code>EIO</code> left the line
durable with the counters unadvanced and the caller&rsquo;s retry reused the same
sequence number. The file length is now recorded before the write and
truncated back on any failure, then the original error is re-raised.</li>
<li>Recovery reads verify before trusting. <code>find_orphaned_claims</code> and
<code>get_uncommitted_entries</code> treated every parsed entry as authoritative. Both
now read through <code>WALReader.iter_verified_entries</code>, which applies the same
two checks <code>verify_chain</code> makes and drops entries failing either.
Verification is per entry rather than a whole-file gate, because a crashed
run&rsquo;s WAL legitimately ends in a torn line and gating the whole file would
discard exactly the orphans recovery exists to reclaim.</li>
<li><code>close_wal</code> fsyncs the marker&rsquo;s parent directory, so the dirent cannot be
lost in a crash and leave recovery re-scanning an already-handled WAL.</li>
</ul>
<h2 id="agent-lifecycle-and-reaping">Agent lifecycle and reaping</h2>
<ul>
<li>The reap tick&rsquo;s log and <code>.git</code> liveness probe resolves the agent log in every
worktree layout instead of one hardcoded path (#3215), and usage accounting
and the stall-detection aggregator now do the same (#3216). Both consumers
probed only the legacy <code>.sdd/worktrees/&lt;id&gt;/</code> shape, so a session under the
current default layout produced no signal at all: token accounting silently
under-reported, and stall profiling ran on an empty log summary rather than
failing loudly. Both now reuse the same worktree-directory helper, and
<code>check_stalled_tasks</code> passes the session&rsquo;s own reported log path, which the
remote runtime bridge, container, and sandbox spawn paths need because no
candidate layout would find it.</li>
<li>The reap liveness probe is guarded against a session with no local PID
(#3212).</li>
<li>A heartbeat&rsquo;s <code>status</code> is no longer folded into its <code>phase</code> (#3202). The two
describe different things — the heartbeat file&rsquo;s own lifecycle versus the
agent&rsquo;s work stage — and a <code>phase or status</code> fallback meant <code>phase=&quot;starting&quot;</code>
arrived with no writer in the tree producing it. The monitor now reads <code>phase</code>
alone, and the pre-spawn writer emits <code>phase=&quot;starting&quot;</code> explicitly from a
single shared helper. Both halves are load-bearing: an adapter with
<code>consumes_heartbeat_dir=False</code> never overwrites the spawn-time file, so that
writer is the only source of the starting phase for that whole population,
and dropping the fallback without it would have flagged a slow first turn
against the general threshold instead of the starting window.</li>
</ul>
<h2 id="verifiability">Verifiability</h2>
<ul>
<li>Trajectory receipt verification checks the stored bytes rather than a decoded
projection of them (#3211). Verification decoded the file into dataclasses
and rehashed the object, and the decode is lossy twice over: unrecognised
keys are dropped, and <code>journal_entry_hash</code> fell back to a <code>.get</code> default.
Anything outside the schema never reached the hash, so an edited receipt
could verify clean. Three claims the module made that its code did not
implement were corrected at the same time.</li>
</ul>
<h2 id="test-selection-and-ci">Test selection and CI</h2>
<ul>
<li>Diff-scoped test selection picks workflow guards by what they read rather
than by their file name (#3214). The old rule matched the substring
<code>workflow</code> in the test filename, so a guard named after the workflow it pins
— reading the same YAML, breaking on the same edit — was dropped from the
slice. Workflow-only pull requests merged green and the breakage surfaced on
<code>main</code> when the full suite ran.</li>
<li>The stock-server sweep drives the documented SSE operations as streams
(#3274), so an endpoint documented as streaming is now exercised as one.</li>
</ul>
<h2 id="terminal-ui">Terminal UI</h2>
<p>Four defects reported from a single session against the TUI, each fixed with
the test that reproduces it: the debounce timer handles are annotated as
<code>Timer</code> rather than <code>object</code>, which was hiding a missing <code>stop()</code> (#3247);
<code>TaskSearchInput.__init__</code> no longer raises <code>TypeError</code> when a caller passes
<code>placeholder</code> explicitly (#3248); the approval panel reads the selected row
from <code>row_key</code> instead of <code>cursor_row</code>, which is an <code>int</code> and was never the
attribute wanted (#3249); and <code>ApprovalAction</code> is a real <code>Message</code> subclass, so
<code>post_message()</code> type-checks against what it actually receives (#3251).</p>
<h2 id="cost-and-provider-data">Cost and provider data</h2>
<ul>
<li>The MiniMax price table is refreshed and carries cache tiers (#3261); the
shipped table had drifted from the published rates.</li>
<li><code>provider_latency</code> skips malformed JSONL records instead of raising on the
first bad numeric field (#3288), so one corrupt line no longer takes down the
whole reading.</li>
</ul>
<h2 id="typing">Typing</h2>
<p>The mypy backlog came down across twelve packages this cycle: <code>core/protocols</code>
(93 to 41), <code>cli/commands</code> (73 to 3), <code>core/routing</code> (52 to 0),
<code>core/observability</code> (50 to 3), <code>core/quality</code> (47 to 15), <code>tui</code> (41 to 15),
<code>core/communication</code> (35 to 0), <code>core/tasks</code> (23 to 3), plus <code>core/routes</code>,
<code>core/config</code>, and <code>adapters</code>. The pattern that recurs is string constants fed
into <code>cast()</code> — mypy cannot use a string as a type — converted to real PEP 695
<code>type</code> aliases; after that, explicit declarations where a first-branch
assignment fixed a variable&rsquo;s type too early, and casts into the nested shape a
<code>dict[str, object]</code> read actually has. No <code># type: ignore</code> was added to buy any
of it, and the three errors left in <code>cli/commands</code> are real defects an
annotation cannot honestly paper over, filed separately rather than silenced.</p>
<h2 id="documentation">Documentation</h2>
<ul>
<li>Capability claims were verified against the code, with stale counts and
examples corrected (#3275).</li>
<li>The adapter last-green table is regenerated from canary receipts rather than
maintained by hand (#3218, #3280).</li>
</ul>
<h2 id="contributors">Contributors</h2>
<p>This release carries work from:</p>
<ul>
<li><strong>casbrbr-beep</strong> — found and reported the quality-gate polarity defect
(#3254, P0) and contributed the fix (#3266); diagnosed <code>--plan-only</code> (#3255)
down to the exact dispatch branch after a first static read had cleared it,
and specified the design this release implements.</li>
<li><strong>bymyforge</strong> — annotated the <code>tui</code> package (#3236), typed the debounce timer
handles (#3252), fixed the approval-panel row-selection crash (#3253), and
filed four TUI defects (#3247, #3248, #3249, #3251) with reproductions.</li>
<li><strong>qwenbona</strong> — separated heartbeat status from phase, both halves (#3223).</li>
<li><strong>seescer</strong> — annotated the <code>core/observability</code> package (#3265).</li>
<li><strong>PyaaZz</strong> — annotated the <code>core/routes</code> package (#3267).</li>
<li><strong>MochiGem</strong> — converted the <code>core/config</code> string constant type aliases to
<code>type</code> statements (#3287).</li>
<li><strong>Iqbalez</strong> — hardened the provider-latency reader against malformed records
(#3294).</li>
<li><strong>w3lld1</strong> — defined the adapter cast aliases as types (#3246).</li>
<li><strong>mmaxjr</strong> — made <code>bernstein doctor</code> report a missing <code>uv</code> as a failed check
instead of crashing with a raw traceback (#3258).</li>
<li><strong>octo-patch</strong> — corrected the MiniMax price table and added its cache tiers
(#3261).</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sipyourdrink-ltd/bernstein/compare/v3.11.0...v3.12.0">https://github.com/sipyourdrink-ltd/bernstein/compare/v3.11.0...v3.12.0</a></p>
]]></content:encoded></item><item><title>Update a config file with values from environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/update-a-config-file-with-values-from-environment/</link><pubDate>Sat, 01 Aug 2026 13:58:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/update-a-config-file-with-values-from-environment/</guid><description>Version updated for https://github.com/sovarto/config-file-from-env to version v0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action replaces environment variables in a specified configuration file, automating tasks such as updating sensitive data dynamically. It helps ensure that your configuration files remain secure by using secrets and placeholders instead of hard-coded values.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/config-file-from-env">https://github.com/sovarto/config-file-from-env</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-a-config-file-with-values-from-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action replaces environment variables in a specified configuration file, automating tasks such as updating sensitive data dynamically. It helps ensure that your configuration files remain secure by using secrets and placeholders instead of hard-coded values.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add support for .env files (e706be3)</li>
<li>chore: More info (d440258)</li>
<li>feat: Initial version (e440a96)</li>
</ul>
]]></content:encoded></item><item><title>Deploy Docker Swarm cluster services stack</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/deploy-docker-swarm-cluster-services-stack/</link><pubDate>Sat, 01 Aug 2026 13:58:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/deploy-docker-swarm-cluster-services-stack/</guid><description>Version updated for https://github.com/sovarto/deploy-swarm-service to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The deploy-swarm-service GitHub Action automates the deployment of a Docker Swarm service. It ensures that the necessary dependencies are installed and bundled before committing the distribution files to ensure a consistent build environment during deployment. This helps in maintaining the reliability and quality of the application by ensuring all required packages are available when deploying on a Swarm cluster.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sovarto/deploy-swarm-service">https://github.com/sovarto/deploy-swarm-service</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-docker-swarm-cluster-services-stack">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>deploy-swarm-service</code> GitHub Action automates the deployment of a Docker Swarm service. It ensures that the necessary dependencies are installed and bundled before committing the distribution files to ensure a consistent build environment during deployment. This helps in maintaining the reliability and quality of the application by ensuring all required packages are available when deploying on a Swarm cluster.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update to latest Docker version (6435c1d)</li>
<li>feat: Explicitly set traefik inbound network (70d83f9)</li>
<li>feat: Automatically set placement preferences based on placement constraints to spread containers of a service across nodes (51af2c2)</li>
<li>feat: Add support for depends_on (688c023)</li>
<li>feat: Add support for service labels (a36e5ea)</li>
<li>fix: Fix restart policy to always restart because containers sometimes exit with code 0 even though they had an error (01b34f4)</li>
<li>feat: Add support for multiple external routes (d99208c)</li>
<li>feat: Improve update config (3c87f67)</li>
<li>feat: Add support for mounts, max replicas per node and stop signal and grace period (90fa02a)</li>
<li>feat: Add support for resource limits and reservations (b33b12f)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/ssg-static-site-generator/</link><pubDate>Sat, 01 Aug 2026 13:57:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.15.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website, featuring features like built-in themes, templates, search, image processing, and native deployment to various platforms. It automates tasks such as generating HTML from Markdown content and provides support for multiple template engines including Pongo2, Mustache, Handlebars, and SCSS.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.15</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website, featuring features like built-in themes, templates, search, image processing, and native deployment to various platforms. It automates tasks such as generating HTML from Markdown content and provides support for multiple template engines including Pongo2, Mustache, Handlebars, and SCSS.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release 1.8.15 — parallel page rendering, rewrite_md_links on by default by @spagu in <a href="https://github.com/spagu/ssg/pull/68">https://github.com/spagu/ssg/pull/68</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.14...v1.8.15">https://github.com/spagu/ssg/compare/v1.8.14...v1.8.15</a></p>
]]></content:encoded></item><item><title>Classroom to sheets integration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/classroom-to-sheets-integration/</link><pubDate>Sat, 01 Aug 2026 13:56:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/classroom-to-sheets-integration/</guid><description>Version updated for https://github.com/SPGC/ClassroomToSheetsIntegration to version v0.1.0marketplace.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending assignment results from a Google Classroom to a designated Google Sheet. It integrates with the classroom-resources/autograding-command-grader@v1 grader, enabling users to track and view their grades in real-time within a Google sheet. The action requires setting up Google API credentials and sharing the sheet with the service account email, then configuring secrets for authentication. Users can customize the Google sheet’s structure by adding additional columns or rows as needed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SPGC/ClassroomToSheetsIntegration">https://github.com/SPGC/ClassroomToSheetsIntegration</a></strong> to version <strong>v0.1.0marketplace</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/classroom-to-sheets-integration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending assignment results from a Google Classroom to a designated Google Sheet. It integrates with the <code>classroom-resources/autograding-command-grader@v1</code> grader, enabling users to track and view their grades in real-time within a Google sheet. The action requires setting up Google API credentials and sharing the sheet with the service account email, then configuring secrets for authentication. Users can customize the Google sheet&rsquo;s structure by adding additional columns or rows as needed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First working version with basic functionality</p>
]]></content:encoded></item><item><title>nix init</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/nix-init/</link><pubDate>Sat, 01 Aug 2026 13:55:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/nix-init/</guid><description>Version updated for https://github.com/spotdemo4/nix-init to version v1.63.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action initializes Nix-based repositories by automating common setup tasks such as creating a GitHub app token, checking out the repository, setting up Git user information, installing Nix, configuring it based on flake settings, and handling caching. It supports various platforms like GitHub, Gitea, and Forgejo and can be used to streamline workflows by reducing repetitive code across different jobs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spotdemo4/nix-init">https://github.com/spotdemo4/nix-init</a></strong> to version <strong>v1.63.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nix-init">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action initializes Nix-based repositories by automating common setup tasks such as creating a GitHub app token, checking out the repository, setting up Git user information, installing Nix, configuring it based on flake settings, and handling caching. It supports various platforms like GitHub, Gitea, and Forgejo and can be used to streamline workflows by reducing repetitive code across different jobs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: migrate automation to Forgejo (a759c06de3986e168a3e547ab51fad1b18390798)</li>
<li>bump: v1.62.1 -&gt; v1.63.0 (3111d9c56193a4983beca8b41a2e0835678abcaa)</li>
<li>ci(release): add GitHub release workflow (44a3ccd1e9f6caabe79cbb9f1bd2c924f6a4896c)</li>
<li>chore: remove unnecessary warn from readme (d17aabe1d7b35fa73303b3f2b30bb1d2ae58326e)</li>
<li>chore(deps): update spotdemo4/nix-init action to v1.62.1 (#1) (ad10da069c7f87f43aa1aa06a36f2a32d3c8378b)</li>
</ul>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/runward-gate/</link><pubDate>Sat, 01 Aug 2026 13:55:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.30.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward verifies engineering decisions behind AI-written code, ensuring that load-bearing decisions are followed during software development. This tool helps in automating the verification process by providing deterministic checks on architectural, security, and operational aspects of the system after deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.30.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Runward verifies engineering decisions behind AI-written code</strong>, ensuring that load-bearing decisions are followed during software development. This tool helps in automating the verification process by providing deterministic checks on architectural, security, and operational aspects of the system after deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>An <strong>internal-validity pass</strong>: instead of adding surface, mutate the source and see whether the tests notice. 42 valid mutations, 36 killed or type-caught, <strong>6 survivors — three of them real holes</strong>. Everything here was found by measurement, not by reading.</p>
<h2 id="the-one-shipped-behaviour-change">The one shipped behaviour change</h2>
<p><strong><code>AGENTS.md</code> now carries the gesture its own obligation needs.</strong> It already told the agent to <em>&ldquo;confront them at the point of action, not from memory&rdquo;</em> — and then named only <code>runward explain &lt;rule&gt;</code>, which reads a rule whose <strong>name you already know</strong>. It never said how to find out <strong>which</strong> rules govern the file being touched. The obligation had no instrument, so it could not be executed.</p>
<p><code>runward rules --for &lt;paths&gt;</code> is now in the same sentence, with the honesty clause that must travel with it: rules declaring no territory are counted, never matched.</p>
<p>This is <strong>not</strong> an extension of <a href="https://github.com/stranxik/runward/blob/main/docs/adr/ADR-0042-craft-rule-confrontation-is-continuous-not-a-gate-crossing-ritual.md">ADR-0042</a>, which deliberately kept the confrontation step out of the non-building workflows. <code>AGENTS.md</code> is not a workflow: it is the contract handed to the agent <strong>every session</strong>, and it already carried the obligation.</p>
<blockquote>
<p><code>runward update</code> does not refresh <code>AGENTS.md</code>, and is right not to — it is a mission deliverable (<a href="https://github.com/stranxik/runward/blob/main/docs/adr/ADR-0010-agents-md-as-a-first-class-handover-deliverable.md">ADR-0010</a>), not shipped method. <strong>Existing missions do not receive this; new ones do.</strong> An existing mission that wants it copies the sentence.</p>
</blockquote>
<h2 id="holes-the-mutation-bench-found">Holes the mutation bench found</h2>
<table>
  <thead>
      <tr>
          <th>Hole</th>
          <th>Why it mattered</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>resolveFile</code> traversal guard</td>
          <td>the path <strong>every <code>applied</code> row goes through</strong>. <code>verifyEvidenceLock</code> had its traversal test; pointer resolution did not</td>
      </tr>
      <tr>
          <td><code>findMissionRoot</code> climb</td>
          <td>the one behaviour that makes <code>runward check</code> usable from anywhere inside a repo, which is how it is actually run</td>
      </tr>
      <tr>
          <td><code>*</code> crossing a path separator</td>
          <td>a declared territory silently <strong>wider</strong> than declared — rules surfacing on files they do not govern</td>
      </tr>
      <tr>
          <td>a block comment eating its line</td>
          <td>drops whatever follows <code>/*</code> on the same line of a <code>wrangler.jsonc</code></td>
      </tr>
  </tbody>
</table>
<h2 id="when-not-to-seal-measured">When NOT to seal, measured</h2>
<p>Sealing this repository would seal 25 files, and <strong>25 of 25 changed within 30 days</strong>. A committed lock here would turn <code>check --strict</code> red on the first commit after every seal, making <code>--freeze</code> a per-commit ritual and the red meaningless.</p>
<p>The opt-in was right. The boundary was written nowhere — and an operator in a regulated setting is exactly the one who would seal everything on principle, then meet a permanently red gate without understanding why. <strong>Seal what has stopped moving</strong>: a handover, a release, a version entering operation. (<a href="https://github.com/stranxik/runward/blob/main/docs/adr/ADR-0021-blocking-drift-and-evidence-sealing.md">ADR-0021 amendment</a>)</p>
<h2 id="honest-bounds">Honest bounds</h2>
<p>Three survivors were <strong>not</strong> holes, and they are named as such rather than papered over with contrived fixtures. <strong>107 candidate mutations were not tried</strong> — the bench is bounded per file. This is a sample, not a proof of coverage.</p>
<p>165 unit tests, self-gate green.</p>
<p>Full changelog: <a href="https://github.com/stranxik/runward/blob/main/CHANGELOG.md">CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Crosspost Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/crosspost-action/</link><pubDate>Sat, 01 Aug 2026 13:54:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/crosspost-action/</guid><description>Version updated for https://github.com/tgagor/action-crosspost to version v1.6.6.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Crosspost your latest content from GitHub Actions to multiple social networks using a sitemap or RSS/Atom feed. This action filters and posts content by age and URL patterns, with options for dry-run mode, failure strategies, and metadata prefilling. The user needs to configure the feed-url and select the desired social networks for posting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tgagor/action-crosspost">https://github.com/tgagor/action-crosspost</a></strong> to version <strong>v1.6.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crosspost-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Crosspost your latest content from GitHub Actions to multiple social networks using a sitemap or RSS/Atom feed.</strong> This action filters and posts content by age and URL patterns, with options for dry-run mode, failure strategies, and metadata prefilling. The user needs to configure the <code>feed-url</code> and select the desired social networks for posting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="166-2026-08-01"><a href="https://github.com/tgagor/action-crosspost/compare/v1.6.5...v1.6.6">1.6.6</a> (2026-08-01)</h3>
]]></content:encoded></item><item><title>tmas-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/tmas-scan/</link><pubDate>Sat, 01 Aug 2026 13:53:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/tmas-scan/</guid><description>Version updated for https://github.com/trendmicro/tmas-scan-action to version v3.3.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs and uses the TMAS CLI tool to scan artifacts in your workspace for open-source vulnerabilities, malware, and secrets. It provides detailed scan findings in logs and outputs a summary report for review. The action supports various artifact types and requires TrendAI Vision One™ credentials and an API key to function.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/trendmicro/tmas-scan-action">https://github.com/trendmicro/tmas-scan-action</a></strong> to version <strong>v3.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tmas-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs and uses the TMAS CLI tool to scan artifacts in your workspace for open-source vulnerabilities, malware, and secrets. It provides detailed scan findings in logs and outputs a summary report for review. The action supports various artifact types and requires TrendAI Vision One™ credentials and an API key to function.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The <code>tmas-scan-action</code> now writes the TMAS scan results summary to the GitHub Action job summary. This works for every run, including scheduled or final-stage build runs that are not associated with a pull request, so results no longer have to be retrieved from the JSON logs</p>
]]></content:encoded></item><item><title>Semver Bump and Cargo Publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/semver-bump-and-cargo-publish/</link><pubDate>Sat, 01 Aug 2026 13:52:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/semver-bump-and-cargo-publish/</guid><description>Version updated for https://github.com/tsnl/semver-bump-and-cargo-publish to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action tsnl/semver-bump-and-cargo-publish automates the process of bumping the version of a Rust crate according to semantic versioning rules and publishing it to crates.io. It handles automatic bumping, tagging creation, and registry publishing, with options for dry runs and rollback on failure. The action also supports branch awareness and includes safeguards against manual misconfigurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tsnl/semver-bump-and-cargo-publish">https://github.com/tsnl/semver-bump-and-cargo-publish</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/semver-bump-and-cargo-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>tsnl/semver-bump-and-cargo-publish</code> automates the process of bumping the version of a Rust crate according to semantic versioning rules and publishing it to crates.io. It handles automatic bumping, tagging creation, and registry publishing, with options for dry runs and rollback on failure. The action also supports branch awareness and includes safeguards against manual misconfigurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Harden the action: registry-confirmed rollback with modes, remote tag check, SHA pins, CI by @tsnl in <a href="https://github.com/tsnl/semver-bump-and-cargo-publish/pull/3">https://github.com/tsnl/semver-bump-and-cargo-publish/pull/3</a></li>
<li>Rollback modes, remote tag check, SHA pins, and CI (the rest of #3) by @tsnl in <a href="https://github.com/tsnl/semver-bump-and-cargo-publish/pull/4">https://github.com/tsnl/semver-bump-and-cargo-publish/pull/4</a></li>
<li>Docs: remove the false testing claim, stop over-granting GITHUB_TOKEN, fix PAT vocabulary by @tsnl in <a href="https://github.com/tsnl/semver-bump-and-cargo-publish/pull/5">https://github.com/tsnl/semver-bump-and-cargo-publish/pull/5</a></li>
<li>Add a release-tags workflow: tag, Release, and floating-v1 move in one dispatch by @tsnl in <a href="https://github.com/tsnl/semver-bump-and-cargo-publish/pull/6">https://github.com/tsnl/semver-bump-and-cargo-publish/pull/6</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tsnl/semver-bump-and-cargo-publish/compare/v1...v1.1.0">https://github.com/tsnl/semver-bump-and-cargo-publish/compare/v1...v1.1.0</a></p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/vibgrate-scan/</link><pubDate>Sat, 01 Aug 2026 13:51:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.801.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Vibgrate CLI action provides local codebase intelligence for AI coding agents, including a deterministic code graph, drift score (drift behind runtime/framework lag and dependency age), and prioritized upgrade priorities. It runs on your machine without API keys or network calls, providing an interactive command-line simulator to see how it works.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.801.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Vibgrate CLI action provides local codebase intelligence for AI coding agents, including a deterministic code graph, drift score (drift behind runtime/framework lag and dependency age), and prioritized upgrade priorities. It runs on your machine without API keys or network calls, providing an interactive command-line simulator to see how it works.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20268011">Vibgrate CLI 2026.801.1</h1>
<p><em>Released 2026-08-01</em></p>
<p>Routine maintenance update for the CLI.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Maintenance release with internal improvements and dependency updates.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.731.3, interleaved on one runner against the pinned corpus (182 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>21236 count</td>
          <td>21236 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>10322 count</td>
          <td>10322 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.98 ratio</td>
          <td>0.94 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>545.60 ms</td>
          <td>541.40 ms</td>
      </tr>
  </tbody>
</table>
<p>21 regression(s) — published, not omitted:</p>
<ul>
<li>Locate accuracy (top-1): 0.98 → 0.94 (-4.4%)</li>
<li>Locate accuracy (top-3): 0.93 → 0.92 (-1.4%)</li>
<li>Locate accuracy (top-5): 0.95 → 0.93 (-2.0%)</li>
<li>Locate top-1 — bash: 0.97 → 0.94 (-2.4%)</li>
<li>Locate top-1 — c: 1 → 0.96 (-4.4%)</li>
<li>Locate top-1 — cpp: 1 → 0.94 (-5.6%)</li>
<li>Locate top-1 — cs: 0.98 → 0.92 (-5.7%)</li>
<li>Locate top-1 — dart: 0.99 → 0.96 (-3.3%)</li>
<li>Locate top-1 — elixir: 0.98 → 0.94 (-3.5%)</li>
<li>Locate top-1 — java: 0.93 → 0.86 (-8.3%)</li>
<li>Locate top-1 — js: 0.99 → 0.92 (-6.8%)</li>
<li>Locate top-1 — kotlin: 1 → 0.92 (-7.8%)</li>
<li>Locate top-1 — lua: 1 → 0.98 (-2.2%)</li>
<li>Locate top-1 — php: 0.98 → 0.93 (-4.6%)</li>
<li>Locate top-1 — py: 0.94 → 0.88 (-7.0%)</li>
<li>Locate top-1 — rb: 0.96 → 0.94 (-1.3%)</li>
<li>Locate top-1 — rust: 0.99 → 0.96 (-3.3%)</li>
<li>Locate top-1 — scala: 1 → 0.97 (-3.3%)</li>
<li>Locate top-1 — swift: 1 → 0.98 (-2.2%)</li>
<li>Locate top-1 — ts: 0.92 → 0.83 (-9.7%)</li>
<li>Locate top-1 — zig: 1 → 0.97 (-3.3%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.801.1">https://vibgrate.com/changelog/cli/2026.801.1</a></p>
]]></content:encoded></item><item><title>Picket Secret Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/picket-secret-scanner/</link><pubDate>Sat, 01 Aug 2026 13:49:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/picket-secret-scanner/</guid><description>Version updated for https://github.com/willibrandon/picket to version v0.2.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Picket is a MIT-licensed secrets scanner for .NET, providing a Gitleaks-compatible command surface, Native AOT release binaries, and dotnet tool packages. It automates the scanning of Git changes, Hugging Face models, GitLab projects, and more, offering flexibility in integration with CI systems like GitHub Actions and Azure Pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/willibrandon/picket">https://github.com/willibrandon/picket</a></strong> to version <strong>v0.2.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/picket-secret-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Picket is a MIT-licensed secrets scanner for .NET, providing a Gitleaks-compatible command surface, Native AOT release binaries, and dotnet tool packages. It automates the scanning of Git changes, Hugging Face models, GitLab projects, and more, offering flexibility in integration with CI systems like GitHub Actions and Azure Pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release artifacts include SHA-256 checksums, package-size metadata, and GitHub artifact attestations.</p>
]]></content:encoded></item><item><title>Move Closed Issue to Top of Project Column</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/move-closed-issue-to-top-of-project-column/</link><pubDate>Sat, 01 Aug 2026 13:49:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/move-closed-issue-to-top-of-project-column/</guid><description>Version updated for https://github.com/wozaki/project-closed-issue-move-to-top-action to version v1.23.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of moving closed issues to the top of a specified column in GitHub Project V2. It checks if an issue belongs to a specific project and updates its status to the specified column, ensuring recently closed issues are always at the top of the project board. The action supports multiple projects with different settings using a matrix strategy.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wozaki/project-closed-issue-move-to-top-action">https://github.com/wozaki/project-closed-issue-move-to-top-action</a></strong> to version <strong>v1.23.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-closed-issue-to-top-of-project-column">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of moving closed issues to the top of a specified column in GitHub Project V2. It checks if an issue belongs to a specific project and updates its status to the specified column, ensuring recently closed issues are always at the top of the project board. The action supports multiple projects with different settings using a matrix strategy.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">wozaki/project-closed-issue-move-to-top-action@eb0301053f0b4959350aa7772f9093b6939f52c1</span> <span style="color:#75715e"># v1.23.0</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update pnpm to v11 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/108">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/108</a></li>
<li>chore(deps): update actions/checkout action to v7.0.1 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/169">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/169</a></li>
<li>chore(deps): update dependency @tsconfig/node24 to v24.0.4 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/170">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/170</a></li>
<li>chore(deps): update pnpm to v11.17.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/172">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/172</a></li>
<li>chore(deps): update int128/release-typescript-action action to v1.77.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/173">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/173</a></li>
<li>chore(deps): update int128/wait-for-workflows-action action to v1.89.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/171">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/171</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/174">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/174</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.22.0...v1.23.0">https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.22.0...v1.23.0</a></p>
]]></content:encoded></item><item><title>B.IA Accessibility Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/b.ia-accessibility-checker/</link><pubDate>Sat, 01 Aug 2026 13:48:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/08/01/b.ia-accessibility-checker/</guid><description>Version updated for https://github.com/YuriFAToledo/B.IA to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 16.
Go to the GitHub Marketplace to find the latest changes.
Action Summary B.IA is a GitHub Action that enables automatic accessibility checks in CI/CD pipelines. It helps companies ensure their code meets WCAG guidelines for specific audiences, improving their products’ accessibility and revenue potential. The action provides flexibility by focusing on the most significant audience and uses AI to analyze guidelines, making it easier for developers to maintain accessible solutions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuriFAToledo/B.IA">https://github.com/YuriFAToledo/B.IA</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>16</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/b-ia-accessibility-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>B.IA is a GitHub Action that enables automatic accessibility checks in CI/CD pipelines. It helps companies ensure their code meets WCAG guidelines for specific audiences, improving their products&rsquo; accessibility and revenue potential. The action provides flexibility by focusing on the most significant audience and uses AI to analyze guidelines, making it easier for developers to maintain accessible solutions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add parse debug (229d26d)</li>
<li>feat: json response schema (3d2a1fe)</li>
<li>feat: update build (1646112)</li>
<li>feat: update code (41bf74f)</li>
<li>feat: update dist (5ffd432)</li>
<li>feat: add githubToken in action (b20caef)</li>
<li>feat: add logs for debug (a29f11d)</li>
<li>fix: order (75ba53e)</li>
<li>feat: add runController (7338606)</li>
<li>feat: add service (34c25e0)</li>
</ul>
]]></content:encoded></item></channel></rss>