All notable changes to this project are documented here. The format follows Keep a Changelog, and the project adheres to Semantic Versioning.
- Marketplace display name from Conviso GitHub Sync Task to Sync External Scans with Conviso.
Workflows keep using
convisoappsec/github-sync-task@v1.
First release.
api-key,project-id,integrationandcompany-idinputs, triggering theassociateProjectmutation against the Conviso GraphQL API.repository-urlandbranchinputs, so a scan is recorded against the repository and branch it came from. Both default to the workflow's own context (GITHUB_SERVER_URL/GITHUB_REPOSITORYandGITHUB_BASE_REF/GITHUB_REF), so the common case needs no configuration.- A warning when
branchresolves withoutrepository-url, the combination Conviso Platform discards without a word. asset-idandasset-nameoutputs, exposing the associated Asset to later steps.- Masking of the API key through
core.setSecret, so it appears as***in the run log even when a workflow passes it literally. - CI that typechecks, tests, and fails when the committed
dist/no longer matches the sources. - A workflow that moves the
v<major>tag on every published release.
- Input names are lowercase and hyphenated, following GitHub Actions convention.
- The
Originheader sent to Conviso isGitHub Actions Conviso Task, identifying which CI the call came from. - Two behaviours are deliberate: a GraphQL error in the response body does not fail the step, and branch association depends on a per-company feature flag in Conviso Platform. Both are documented in docs/publishing-marketplace.md.