Releases: thejefflarson/soundcheck-action
Release list
v1.0.40
Bumps soundcheck to v1.17.1 — a bugfix release that restores the skill catalog on target-repo reviews.
Prior to v1.17.1, design-review and vulnerability-audit subagents silently fell back to "apply checklist from memory" because they tried to read skill files with a relative path that resolved to the audited repo, not the plugin. This action now shells out to a soundcheck that fires the actual skill catalog.
Expect a meaningful jump in findings quality — the plugin's core value was being bypassed on every review this action performed.
No breaking changes.
v1.0.39
Bumps soundcheck to v1.17.0 and the claude CLI pin to 2.1.214.
The v1.17.0 changes on the soundcheck side:
hotspot-mappingnow covers rendering/output sinks and dependency/config manifests (previously blindspots)vulnerability-auditis exhaustive per hotspot — picks every applicable skill, sweeps sibling code
Benchmark against OWASP Juice Shop: reviews now produce ~2× more findings and lift strict recall from 33% → 67%, with zero hallucinations across residual findings.
No breaking changes to inputs, outputs, or workflow shape.
v1.0.38
Pin soundcheck → v1.16.3 (hooks now invoke python3 instead of bare python, fixes #24). @v1 now points here.
v1.0.37
Pin soundcheck → v1.16.2 (README freshness refresh from v1.16 sweep). @v1 now points here.
v1.0.36
Pin soundcheck → v1.16.1 (remove non-discriminating benchmark-securityeval). @v1 now points here.
v1.0.35
Pin soundcheck → v1.16.0 (invert supply-chain skill: lockfiles + auto-merge, not exact pinning). @v1 now points here.
v1.0.33
Pin soundcheck → v1.15.4 (drop unused JSON trailer from contract-review). @v1 now points here.
v1.0.32
Pin soundcheck → v1.15.3 (contract-review renders Markdown report). @v1 now points here.
v1.0.31
Pin soundcheck → v1.15.2 (contract-review: thread threat model into contract-audit). @v1 now points here.
v1.0.30
Pin soundcheck → v1.15.1 (orchestrator: explicit threat model threading). @v1 now points here.