Skip to content

Latest commit

 

History

History
41 lines (31 loc) · 1.87 KB

File metadata and controls

41 lines (31 loc) · 1.87 KB

Changelog

All notable changes to this project are documented here. The format follows Keep a Changelog, and the project adheres to Semantic Versioning.

[1.0.1] — Unreleased

Changed

  • Marketplace display name from Conviso GitHub Sync Task to Sync External Scans with Conviso. Workflows keep using convisoappsec/github-sync-task@v1.

[1.0.0] — 2026-08-10

First release.

Added

  • api-key, project-id, integration and company-id inputs, triggering the associateProject mutation against the Conviso GraphQL API.
  • repository-url and branch inputs, so a scan is recorded against the repository and branch it came from. Both default to the workflow's own context (GITHUB_SERVER_URL/GITHUB_REPOSITORY and GITHUB_BASE_REF/GITHUB_REF), so the common case needs no configuration.
  • A warning when branch resolves without repository-url, the combination Conviso Platform discards without a word.
  • asset-id and asset-name outputs, exposing the associated Asset to later steps.
  • Masking of the API key through core.setSecret, so it appears as *** in the run log even when a workflow passes it literally.
  • CI that typechecks, tests, and fails when the committed dist/ no longer matches the sources.
  • A workflow that moves the v<major> tag on every published release.

Notes

  • Input names are lowercase and hyphenated, following GitHub Actions convention.
  • The Origin header sent to Conviso is GitHub Actions Conviso Task, identifying which CI the call came from.
  • Two behaviours are deliberate: a GraphQL error in the response body does not fail the step, and branch association depends on a per-company feature flag in Conviso Platform. Both are documented in docs/publishing-marketplace.md.