Breaking changes
- chore(integrations)!: Remove legacy Google SecOps Python actions (#3583)
Case management
- fix(cases): Strip NUL bytes from case comment content (#3594)
Tables
- feat(tables): Add semantic search column controls (#3577)
- feat(tables+actions): Add ranked semantic table search (#3576)
- feat(tables): Track semantic search indexing lifecycle (#3572)
- feat(tables): Reuse AI providers for search embeddings (#3518)
Agents
- fix(agents): Preserve chunked HTTP request bodies (#3610)
- fix(agents+integrations): Surface and block custom actions shadowing builtins (#3579)
- feat(agents): Add pluggable session backends (#3570)
- feat(enterprise+skills): Add folders and tags for agent skills (#3553)
- fix(agents): Distinguish gateway cooldown from provider throttling (#3538)
Integrations
- docs(integrations): Document the OAuth redirect URI (#3590)
- feat(integrations): Add Rapid7 templates and bulk export MCP server (#3588)
- feat(integrations): Add Perplexity MCP server (#3587)
- feat(integrations): Add Azure DevOps OAuth providers and HTTP templates (#3581)
Engine
- fix(engine): Surface workload stderr in sandbox workload failures (#3595)
- feat(engine): Index table text in durable background batches (#3575)
API
- fix(ui+api): Show real item counts on workflow folders (#3571)
User interface
- fix(ui): Use official Google SecOps logo for Google Chronicle (#3585)
- fix(ui): Allow mouse wheel scrolling in folder picker dropdowns (#3569)
Infrastructure
- fix(infra): Port alpha.2.1 migration re-parenting to main (#3614)
- ci: Enforce linear Alembic migrations (#3613)
- fix(infra): Merge alembic heads so upgrade head resolves (#3612)
Documentation
- docs: Clarify alpha hotfix release branches (#3611)
Full changelog: 1.1.0-alpha.2.1...1.1.0-alpha.5