Changelog: June 23, 2026#29
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Workflows to automatically generate PRs for you. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 22c92df61b
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| **Mark a finding as a duplicate**: You can now mark a finding as a duplicate of another finding in the same repository. Duplicate findings are judged by the canonical finding's severity when evaluating your fail-on threshold, and the API key endpoint supports the same action. | ||
|
|
||
| **Duplicate marking in the MCP tool**: The `update_finding` MCP tool now accepts a `duplicate_of` field so you can mark or unmark duplicates programmatically. |
There was a problem hiding this comment.
Document duplicate_of in the API/MCP references
This entry announces duplicate marking through the API key endpoint and the update_finding MCP tool, but the referenced docs still describe PATCH /findings/{id} as requiring only state or severity and list no duplicate_of field, while the MCP tool table still says update_finding only updates state or severity; rg duplicate_of finds no documentation outside this changelog. Users following the new API/MCP announcement cannot discover the request shape and may conclude the new field is unsupported.
Useful? React with 👍 / 👎.
Add the June 18, 2026 entry (from PR #25, being closed) as a single section and remove items from the June 23 entry that it already covers: triage check updates, duplicate marking, scan volume chart, and the legal-agreement-before-trial note. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…eat models Lead the June 23 changelog with the new Context page (Repositories + Applications tabs), announce Applications and application-level threat models, and add the threat-model update note on PRs. Group the context/threat-model items together and keep the remaining changes (redacted findings, org fail-on default, SSO, MCP duplicates, PR link, taint trace) after. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Merge the five threat-model bullets (reading view, editable, sync status, generate/sync label, PR update note) into a single "Threat models" entry covering the main changes. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Drop "A new" from the Context page item label and tighten the consolidated threat-models description. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…entries Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This PR consolidates two changelog windows into one entry stack:
Documentation TODOs
These shipped features still need docs. The changelog links only to pages that already exist — add or update these, then link them:
From the June 18 section