v1.0.47
Security note: this release was reviewed (the security audit record covers the released commit, with no source drift), and was published with one known open finding accepted:
tsanetgit/Zendesk_App#96(durable audit trail), a documentation deliverable deliberately sequenced after the v2 webhook migrationtsanetgit/Zendesk_App#101. No unreviewed change shipped in this release.
Security fix: API-sourced values in the collaboration card are now escaped before rendering (tsanetgit/Zendesk_App#111). The case token is no longer interpolated into markup or a CSS selector at all.
Also in this release cycle: members are now told how to verify this package before installing it (tsanetgit/Zendesk_App#110), documented in the ZAF Quick Start, the Implementation Guide, and the published Security Considerations page.
Verify provenance before install:
gh attestation verify tsanet-connect-v1.0.47.zip --repo tsanetgit/Zendesk_App
sha256sum -c checksums.txt
Install via Zendesk Admin Center → Apps and integrations → Zendesk Support apps → Upload/Update private app.