Repository navigation
LogDrop Taint v1.24.1
LogDrop Taint v1.24.1
Two things reach you with this release, and the larger one is not the version
number.
A report that never arrives no longer fails your build. Every outcome of
sending to the panel — unreachable, refused key, rejected report — is now a loud
warning and a green step. It used to depend on which code came back: a rejected
report broke the build, an unreachable panel did not. That split rested on "a
400 is your own fault", which is not always true. A bundle id deleted or renamed
in the panel answers 400. A licence moved to another project answers 400.
Neither is something the developer whose pull request just went red can fix.
Set fail-on-delivery-error: "true" if you want the hard gate: then any failure
to deliver is exit 1. One switch, no per-code table.
A fix in the same area, which mattered more than the policy: GitHub runs shell:
bash with -e, and an unreachable panel was killing the step on the curl line —
before the branch that handles it and before the switch could be read. So the
one case the promise is most needed for was the one case it did not hold.
The action repository has been renamed to
initialcodess/logdrop-taint-ios-action, matching the Android half, which already
named its platform. Your existing uses: initialcodess/logdrop-taint-action@v1
keeps working — GitHub redirects — but new pipelines should use the new name,
and so should the download URLs in the CircleCI, GitLab, Jenkins, Bitrise,
fastlane and local recipes.
The analyzer itself changed in one line: the informationUri in every SARIF now
names the renamed repository, so the link in your report and in the panel points
at somewhere that exists rather than somewhere that forwards.
No rule, default, exit code or flag of the scan itself changed. Findings on the
same code are identical to 1.24.0.