diff --git a/CHANGELOG.md b/CHANGELOG.md index 2c5ccd30..f3cb196c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -28,6 +28,23 @@ the compatibility and migration notes before upgrading. view (`GET /v1/supply-chain/repositories/{id}/component`). No route means no outbound license traffic. Migration 034 adds the evidence, enrichment-job, and assessment tables. +- Portfolio read APIs over the caller's authorized repositories: an overview + whose every count names its denominator, keyset-paginated unique + coordinates with ecosystem, search, license, and assessment filters, + bounded facets, a coordinate detail listing authorized occurrences, a CSV + export with provenance columns and formula-safe cells, and a snapshot + comparison that separates component, declared-license, and edge changes + from document metadata changes. +- Standards-based imports of SPDX 2.3 JSON and CycloneDX 1.6 JSON into + declared `import::