## semaphoreui/semaphore — v2.20.0-alpha2…v2.20.0-alpha3

_467+ commits._

### Features
- **feat(workflows): add environment variables about current workflow run** (99e92da)
- **feat(audit): record runner registration, unregistration and rejected reports** (0deaa2e)
- **feat(audit): record admin runner changes** (89e5d7f)
- **feat(audit): record task approvals, stops and history deletion** (5f94433)
- **feat(audit): attribute dispatch failures to the server** (5f0cbfe)
- **feat(audit): record task completion and approval requests** (f2a2882)
- **feat(audit): record task starts with their trigger** (2d7c648)
- **feat(audit): add task and runner event kinds** (4d5d66c)
- **Merge pull request #4156 from befika/sem-122-problem-support-for-private-git-collectionsroles** (ffaf288)
- **feat(audit): record environment events with partial secret saves** (09112d8)
- **feat(audit): record credential and secret storage events** (7cbb41c)
- **feat(audit): record integration, matcher, extractor and alias events** (82ec77d)
- **feat(audit): record template and schedule events** (3201251)
- **feat(audit): record inventory, repository and host config events** (e8680db)
- **feat(audit): record project, backup export and restore events** (543ecbf)
- **feat(audit): add resource and secret event kinds with partial success** (1da4760)
- **feat(audit): describe the audit section in the config schema** (1ee751f)
- **feat(audit): let the export lease report its validity** (045b657)
- **feat(audit): add the audit export lease seam** (2e03740)
- **feat(audit): record project membership, role and template permission changes** (7ddf80a)
- **feat(audit): record MFA, user, API token, identity and settings changes** (e169a8d)
- **feat(audit): record logins, logouts, provisioning and identity links** (5175f9e)
- **feat(audit): record actor, token rejects, denials and CSRF blocks** (4a03311)
- **feat(audit): start audit with the server and record the start event** (f4a3321)
- **feat(audit): add request middleware with trusted-proxy source IP** (5a69b0b)
- **feat(audit): add audit configuration section** (48834a2)
- **feat(audit): add recorder and test recorder** (99a2fdf)
- **feat(audit): add columnar audit tables with gap-free sequence** (e545a96)
- **feat(audit): add event catalog, envelope and actor context** (38ffcd1)
- **feat(workflows): add workflow revisions** (d2d7c29)
- **feat(workflows): move using cursor** (0d601c1)
- **feat(workflows): collapse global bar and save state in local storage** (bd8e695)
- **feat(workflows): hotkeys** (0583127)
- **feat(workflows): update docs** (6567c46)
- **feat(workflows): update canvas background** (a5de4c6)
- **feat(workflows): update UI** (a7ab9e3)
- **Merge branch 'sem-122-problem-support-for-private-git-collectionsroles' of github.com:befika/semaphore into sem-122-problem-support-for-private-git-collectionsroles** (48e6629)
- **Merge branch 'develop' of github.com:befika/semaphore into sem-122-problem-support-for-private-git-collectionsroles** (ee627cc)
- **feat(integrations): add HMAC-SHA512 webhook auth method** (51cbe3a)
- **feat(ui): show/hide public key** (14f4856)

### Fixes
- **fix(audit): keep parent_task_id for every task.execution/create trigger** (4711cd3)
- **fix(audit): make TaskRunner.endReason atomic** (b0755f8)
- **fix(audit): record a refused runner registration only for token refusals** (e7d177c)
- **fix(audit): take the task.execution/create trigger from the caller** (5d40acd)
- **fix(audit): record the project on runner unregister events** (f392ea1)
- **fix(audit): name the checked path in a refused runner registration** (4818c14)
- **fix(secret-storage): delete the storage keys before the storage, MySQL 8 has no cascade for them** (fe0b4d8)
- **fix(secret-storage): refuse an unsupported source type also when the secret is not replaced** (7d7ceca)
- **fix(audit): drop key_failed, a secret storage delete removes its keys by cascade** (2dee0f6)
- **fix(audit): record a restore that failed after the project was created as a partial success** (8bb7bc1)
- **fix(secret-storage): refuse an unsupported source type before saving the storage** (12da981)
- **fix(audit): read the secret storage before deleting the environment** (ca9371d)
- **fix(audit): mark environment and secret storage syncs as Pro in the catalog** (98463c1)
- **fix(audit): record schedule switches that change the state, count integration aliases on restore, check alias ownership and name deleted integrations** (7c991e6)
- **fix(runners): answer 204 to an unregister of a runner already removed** (09b7815)
- **fix(audit): record environment and secret storage deletes that left secrets behind** (baa0051)
- **fix(api-docs): list the stopped workflow run status** (89a7cee)
- **fix(audit): name the secret storage in its delete event** (e630497)
- **fix(audit): drop unknown permission bits on restore and reject them in template permissions** (dde04e2)
- **fix(audit): record schedule switches in full updates, the stored credential type and restored aliases** (644bf17)
- **fix(audit): record template and project creation that failed after the row was stored** (e4bba35)
- **fix(audit): tolerate a missing task params row when deleting schedules and integrations** (78f042b)
- **fix(audit): report a missing row from resource deletes** (d25bda8)
- **fix(audit): record a delete only when the database confirms it** (1b32bf8)
- **fix(audit): record only the API tokens this request deleted** (0039c7e)
- **fix(audit): record a recovery as soon as the TOTP is deleted** (e4024f4)
- **fix(audit): bound role slugs in membership events** (19a5f7a)
- **fix(audit): record every API token the prefix delete removed** (34ddc26)
- **fix(audit): bound the wait for a connection when storing an event** (be92a20)
- **fix(audit): record auth.login once per MFA-verified session** (1bb663c)
- **fix(audit): scope role update and delete to the role's scope** (5a1c2b5)
- **fix(audit): record auth.login once the session is usable** (d8e3d37)
- **fix(audit): omit new_role when a role change is refused** (f7647dc)
- **fix(audit): reject unknown role permission bits** (2b1ff7e)
- **fix(workflows): rename endpoint** (8bb263e)
- **fix(workflows): distinguish task confirmation from approval outcomes** (b2e45e2)
- **fix(workflows): delete run on project delete** (fb96df0)
- **fix: update docs** (5edf620)
- **fix(workflows): canvas scroll** (f7363bc)
- **fix(workfloes): scroll** (b772c28)
- **fix(workflows): move moving issue** (395a498)
- **fix(workflows): context menu scroll style** (9a61d6b)
- **fix(workflows): ui style** (24a1ef6)
- **fix(galaxy): merge git rewrites with project credential mappings** (679e434)
- **Merge pull request #4197 from NewMayur/fix-git-auth-baremetal** (ac08b99)
- **fix(host-config): check mappings before secret storage side effects** (e5d6e84)
- **fix(api): redact repository credentials in the event feed, ship the proxy docs** (de959c6)
- **fix(git): treat an empty HOME as unset and match URL schemes case-insensitively** (10ae2ec)
- **fix(migration): move host config table** (6689fb3)
- **fix(host-config): apply mappings to Ansible and fix Copilot review findings** (7141711)
- **fix: merge conflict** (c765e6e)
- **fix(db): drop event_backup_5784568** (2a0e38a)
- **Merge pull request #4266 from EyJunge1/fix/3385-log-copy-no-timestamps** (c7f60aa)
- **Merge pull request #4270 from EyJunge1/fix/3066-hmac-sha512** (8f4f757)
- **fix: test** (b1d16be)
- **Merge branch 'develop' into fix-git-auth-baremetal** (e9dc6c0)
- **Merge pull request #4267 from EyJunge1/fix/3455-schedule-timezone-alert** (eef9fd4)
- **fix(git): keep go_git URL auth and redact repository URLs in task logs** (78c3019)
- **fix(git): forward proxy env and encode credentials for bare-metal clones** (4f96162)
- **fix(ui): align schedule alert localStorage key on read** (52fc5de)
- **fix(ui): make schedule timezone alert dismissible** (21e6326)
- **fix(ui): exclude log timestamps from text selection** (4338c0c)

### Backend
- **Merge pull request #4300 from semaphoreui/feat/audit-log-tasks** (722ff19)
- **Merge pull request #4291 from semaphoreui/feat/audit-log** (ddaec4c)
- **Merge pull request #4287 from semaphoreui/feat/refactor_workflows** (a746396)
- **Merge branch 'feat/refactor_workflows' of github.com:semaphoreui/semaphore into feat/refactor_workflows** (c50c1d3)
- **agents: update workflows tasks** (449d084)
- **agents: refactor structure** (c6f93b1)
- **agents(workflows): update researches** (539d98a)
- **agents(workflows): update workflows plan** (5fdfe0a)
- **Merge pull request #4251 from befika/sem-272-host-config-page** (232bfb2)
- **Merge branch 'develop' of github.com:befika/semaphore into sem-272-host-config-page** (7d0b24a)
- **Merge branch 'sem-272-host-config-page' of github.com:befika/semaphore into sem-272-host-config-page** (b2a9dcc)
- **agents(hosts): plan for ssh agent usage** (8ab60f5)
- **Merge branch 'develop' of github.com:befika/semaphore into sem-272-host-config-page** (8045306)
- **Merge branch 'develop' of github.com:semaphoreui/semaphore into develop** (58bb79e)
- **Merge pull request #4273 from semaphoreui/renovate/dotenv-18.x-lockfile** (e6e035b)
- **Merge pull request #4271 from EyJunge1/chore/4155-t-setenv** (2f8a49f)
- **Merge pull request #3656 from semaphoreui/feat/gen_ssh_key** (e95560f)

### Tests
- **test(audit): assert the end reason in the endReason race test** (a77bbe4)
- **test(audit): drop redundant active assignment in runner test** (7ed04d2)
- **test(dredd): delete real integration aliases instead of a missing one** (b8e9dbf)
- **test(galaxy): cover credential mappings alongside repository credentials** (199f1e0)
- **test(audit): restore config and cookie globals in session tests** (d5f33bc)
- **test(integrations): cover hmac-sha512 in ReceiveIntegration** (4fe1f68)

### Docs
- **docs(audit): update docs submodule pointer** (0527599)
- **docs(audit): update docs submodule pointer** (47d47ec)
- **docs(audit): update docs submodule pointer** (0600d2e)
- **docs(audit): update docs submodule pointer** (650a2c3)
- **docs(audit): list task and runner events as available** (ac3187f)
- **docs(audit): update the docs pointer** (51270aa)
- **docs(audit): update the docs pointer** (43555af)
- **docs(audit): update the docs pointer** (c11c086)
- **docs(audit): update the docs pointer** (03f2ad6)
- **docs(audit): update the docs pointer** (7783994)
- **docs(audit): update the docs pointer** (f3436bb)
- **docs(audit): list resource and secret events as available** (a5b832d)
- **docs(audit): point the docs submodule at the reader-friendly audit pages** (3b51f6a)
- **docs(audit): describe the audit options in plain words** (dcbf197)
- **docs(audit): drop the audit events generator** (5fe4f3c)
- **docs(audit): generate the audit event reference and link the docs** (d2788eb)
- **docs: update docs** (d0bc82b)
- **docs: update submodule** (f04b63f)

### Chore
- **chore: update docs** (877ffe4)
- **refactor(audit): delete the project row after the loop in DeleteProject** (9512c4f)
- **ci: disable docs check** (09cf6b9)
- **refactor(workflows): remove extra code** (0c6912b)
- **refactor(repos): invert secure param in GetGitURL** (903e982)
- **chore(deps): update dependency dotenv to v18.0.3** (6f3d6b2)
- **chore(tests): replace os.Setenv with t.Setenv** (9d828e7)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/semaphoreui/semaphore?utm_source=github-action)._