Release Notes
Origin release notes
Weekly changes to Origin on the web and in the Origin API. Each entry covers one week of changes and is labeled with the Monday that starts it. Endpoint-level API changes are in the Origin API changelog.
Web
- Find merged pull requests. A repository's pull requests list has a new Merged tab with a count, and
is:mergedin the search box now filters to merged pull requests. - Request Changes reviews now block merging. A Request Changes review from someone with write access blocks the pull request from merging until it's resolved, and dismissing someone else's Request Changes review requires write access. Pending reviews you haven't submitted no longer count as approvals or blockers, and reviews on the pull request page are ordered by when they were submitted.
- Choose repositories when requesting an app, and cancel pending requests. When you request an app install, you can pick all repositories or specific ones, with the repository from the install link preselected. A pending request shows its status, and you can cancel it from that status button. Namespace owners or team admins get an email when someone requests an install, and you get an email when your request is approved or denied. The install page also shows the app's publisher, verification, and website, a View Listing button, and the account you're signed in as.
- IP allowlists apply to people, not your apps. When your team has an inbound IP allowlist, it now applies only to user credentials, so apps, service accounts, and agents are no longer blocked. The allowlist is also checked on Origin web pages and repository downloads, and it can hold up to 1,000 entries. Owners can read and replace the allowlist through the Origin API; see the Origin API changelog.
- Clearer Git errors and safer pushes. When Git is denied access to an Origin repository, it now explains why, including which Cursor account was used and how to switch. Pushing a file larger than 100 MB is rejected with an error naming the file and its size. Pushes to
HEADor to ref names outsiderefs/are refused instead of moving the default branch, and a malformed ref name is rejected on its own while the rest of the push lands. - Blame follows renames. Blame now follows file renames the way
git blamedoes, so lines in a renamed file keep the commit that wrote them instead of pointing at the rename. Branch and tag names that look like commit hashes now resolve to the branch or tag, and commit lists and comparisons use the same merge base and ordering as Git. - CODEOWNERS matches GitHub more closely. CODEOWNERS patterns now follow gitignore rules, so directory and anchored patterns resolve owners the way GitHub does, and logins with underscores are accepted. Email entries resolve only to people who can review the repository. When code owners can't be determined, for example because the file is too large or too many files changed, the code owner requirement is blocked with an explanation instead of passing or failing silently.
- Rulesets are enforced more strictly. Pull requests into a branch frozen by an active ruleset that blocks merges now show "Merging is blocked by a ruleset." unless you can bypass it. An active ruleset with a rule type Origin doesn't recognize now blocks merging instead of being skipped, and saving a rule that can't run in that kind of ruleset fails with an error. Merge when ready now waits for ruleset rules to pass even if you could bypass them.
- Fixes to merge when ready. Merge when ready no longer merges a commit pushed after checks ran, waits for a newly linked parent pull request to merge first, and turning it off reliably stops a pending merge. A merged pull request now records the commit that actually landed it.
- Fewer false merge conflicts. Pull requests with an edit next to a line inserted on the base branch now show as mergeable when Git would merge them cleanly, instead of reporting a conflict. When a pull request's head commit is missing, it asks you to push the branch again instead of showing an error.
- Fixes to stacked pull requests. After a stacked pull request's base lands and it's retargeted, its diff and restack include only its own commits. Restacking keeps conflict resolutions from merges with trunk, including onto a squash-landed parent. A pull request drafted or closed at the moment its stack merged now shows as merged.
- Fixes to diffs on large and renamed changes. Renamed files are paired the way Git pairs them, line counts match Git for final-newline and line-ending changes, and diffs for deeply nested changes now load instead of failing. On very large pull requests, Load more now fetches the next batch of files.
- Fixes to pull request pages. Reopening a pull request whose head or base branch was deleted now tells you to restore the branch first. Permalinks now open the right file when its path has spaces or non-ASCII characters. Authors and reviewers who acted through an app show that app next to their name.
API
- Prepare and inspect merges through the Origin API. A new call rebuilds a pull request's test merge ref against the current base and reports whether it's mergeable, conflicted, or pending, with the merge, base, and head commits. Mergeability responses also include the head commit they were computed against. See the Origin API changelog.
- Scope check runs to a base commit. Apps can pass a base commit when posting check runs so a check counts only for pull requests with that base, and the base commit appears in check responses, the Origin SDK, and check run webhooks. Check runs posted with a failing status keep that status. See the Origin API changelog.
- More of Origin is available through the Origin API. You can read, add, and remove reactions on pull request comments, check a user's permission on a repository, and list commits within a time range. Responses for repositories, commits, and pull requests, and pull request webhooks, now link to the page on Cursor. Ruleset bypass users now use public user IDs, which is a breaking change. See the Origin API changelog for details.
Web
- Sign in to repositories with SSH certificates from your team's certificate authority. Team admins can add trusted SSH certificate authorities from the SSH certificate authorities section of the API Keys page, so members can clone, fetch, push, and use LFS with short-lived OpenSSH certificates instead of registering individual keys. Admins can also require certificates, which blocks registered SSH keys and API keys over HTTPS while certificates and the Origin CLI keep working. The same controls are available in the Origin API; see the Origin API changelog.
- Build stacked pull request workflows on the Origin API. Pull requests returned by the Origin API and carried in pull request webhooks now include their stack and parent pull request, and you can set or clear a stack parent when you create or update a pull request. You can also list every pull request in a stack. See the Origin API changelog for field details and the breaking change to the old parent field.
- Squash merges keep credit for everyone who contributed. When you squash-merge a pull request, the merge commit now adds a Co-authored-by trailer for each author of the squashed commits and for anyone those commits already listed as a co-author. Cursor's agent and bot addresses are skipped, and no one is listed twice. When a bot's pull request is squash-merged, the person who merged it and the people who approved its latest version are credited as co-authors.
- Choose exactly where an app gets installed, and review permission reductions one by one. App install links now open a consent page for a specific namespace. If you can install the app in more than one, you pick from a "Choose where to install" list first, and the install button names the namespace you picked. When an installed app asks for fewer permissions, its page shows a "Permissions can be reduced" notice, and on the review page you can keep or remove each permission it would drop.
- The audit log now records repository clones and fetches, and shows who edited or deleted a comment. When a person clones or fetches an Origin repository, your team's audit log now records it, along with their email and whether they used HTTPS or SSH. Background autofetches and machine actors are left out. Audit entries for pull request comment edits and deletes now name the person who made the change, not the comment's original author.
- Fixes to merging and stacked pull requests. Pull requests with nothing left to merge are now blocked instead of landing an empty commit. Stacks with already-merged lower changes now land on the correct base, restacks list conflicted files when they stop, and a cancelled rerun no longer turns a passing check red or blocks merge when ready. Reopened pull requests also pick up commits pushed while they were closed.
- Fixes to pull request diffs and the Files changed view. Expand all on huge files no longer freezes the tab, pull requests over the file limit let you load more files, code owner shields are back, and your pending review comments show as drafts right away.
- Fixes to pull request pages and repository settings. Searching a repository's pull requests with an unsupported filter like
is:mergednow shows an empty state that explains the filter and offers Clear search, instead of silently showing the default list. Repository and namespace permission settings only list Admins and Members when they have access, and committing a suggested edit without a name and email on your profile now explains what's missing. - Fixes to code tours. Code tours created before a tour update now regenerate with the latest version instead of showing outdated content, while tours prepared ahead of time still appear right away. Tours no longer include stray planning notes from the model, and custom tours are left unchanged.
- Fixes to Git operations. Rejected pushes now show the real reason next to each ref instead of a generic unpack error. Blame and file history are correct for paths with non-ASCII characters, and repositories with consecutive dots in their names now work in clone and push URLs.
- Fixes to cancelled Bugbot checks. When a Bugbot review is cancelled on a pull request, its check now shows as cancelled instead of neutral, so a check that later becomes required can no longer pass without a finished review. Checks left on a commit the pull request has moved past still show as neutral, unless the check is required.
API
- Apps can act on behalf of namespace members. Origin apps can now request short-lived installation user tokens that act as a member of the namespace, named by user ID or email, for API calls and HTTPS git clone, fetch, and push. Work done this way is attributed to the member "via" the app across API responses, webhooks, audit logs, and the PR page. Installations need the new User Delegation permission; see the Origin API changelog for details.
- More of your pull request workflow is available through the Origin API and webhooks. You can now delete pull request comments, filter pull requests by head commit, see what each check run write did, and read a version's potential merge commit through the Origin API and Origin SDK. Webhooks now cover comment reactions and name who removed a label, and expired app installation tokens return a clear error. See the Origin API changelog for details.
Web
- Clearer repository access, and access is removed when people or groups go away. The Permissions tab in codebase and repository settings is now called Access, and each group there shows whether it's a Team Group, Org Group, or Synced Group from your identity provider, with its member count. When someone leaves a team or organization, they lose the repository access they had through its groups. When an organization group is deleted, the repository and namespace access it granted is removed automatically.
- Emails when team or group changes affect your repo access. When you join or leave a team or group, Origin now emails you once per change, listing the repositories and codebases you gained or lost access to. Each resource in access emails links to its page in Origin.
- Redesigned Apps pages with a Marketplace and clearer install screens. The Apps page in your codebase settings now opens to a Marketplace for browsing apps, with a separate Manage view for installed apps. The install screen shows whether an app is Verified by Cursor, meaning it's listed in the Marketplace, or Not verified by Cursor. It also has a simpler choice of repositories. App pages can list the publisher's public Cursor plugins, and every viewer of a repository's Apps settings can open installed apps' pages.
- Faster pull request, repository list pages. Pull request pages now show the title, status, branches, Auto-merge badge, and existing reviewers on first paint instead of placeholders. Repository lists and a repository's Pull requests list render their first page with the page.
- Build pull request searches with suggestions. The search box on the pull requests list now suggests qualifiers like
author:,label:,assignee:,review:,is:, andsort:as you type, along with matching values such as repository collaborators and labels. Recognized qualifiers are highlighted in the box so you can see which filters apply. - Submodule updates show up properly in pull request diffs. When a pull request adds, updates, or removes a submodule, the Files changed tab now shows a submodule card with the old and new commits instead of an error or an empty file. When both commits come from the same repository on GitHub or Origin, the card links to a comparison between them.
- Repository downloads start right away and extract into one folder. Downloading a repository archive from the codebase page now returns the file directly, even when it has not been prepared yet, so you no longer need to wait and retry. Archives extract into a single
owner-repo-shortsha/folder and download with that name, matching the layout other Git hosts use. See the Origin API changelog for details. - Clearer names for Bugbot and Security Review checks. Bugbot checks on pull requests now appear as "Cursor / Cursor Bugbot" and "Cursor / Cursor Bugbot Autofix" under one Cursor group, instead of repeating the same name twice. Security Review checks now appear under "Cursor Security Agent" with the automation name as the check title, instead of an internal account name.
- Create a repository from the Codebase welcome screen. If you can create repositories, have none yet, and haven't dismissed the Codebase welcome screen, it now has a Create Repo button under Sync from GitHub that opens the New Repo dialog.
- Safer pushes, app installs, and rebases. Pushing a branch or tag whose name isn't valid UTF-8 now rejects only that ref with a clear error, while the rest of the push lands. Creating or installing an app is now refused for namespaces that can't write to Origin, matching repository creation. Commits Origin replays, for example when rebasing a pull request, now keep their jj change-id so jj users keep change identity.
- Fixes to stacked pull requests and retargeting. Retargeting a pull request to the base it already has, or to a merged ancestor's branch, no longer detaches it from its stack, and merged stack members now show the branch they landed on as their base. Restacking works on branches that contain merge commits, CODEOWNERS review requests after a retarget match the rules the merge check enforces, and reopened pull requests run CI against a fresh merge with the current base.
- Fixes to pull request diffs and the API. Diff timeouts now show a timeout error instead of a generic error, the HTTP API
:syncMirrorendpoint works again, and browsing a repository with no commits reports an empty repository error. - Search commits by SHA. A repository's Commits page now has a search box. Type at least five characters of a commit SHA to preview matching commits, or press Enter to list the commits that start with that SHA.
API
- Search file contents through the Origin API. A new Grep Contents operation in the Origin API searches the files in a repository at any ref and returns the matching lines. You can use a regular expression or exact text, ask for surrounding context lines, and narrow the search with include and exclude globs. See the Origin API changelog for details.
- Check whether a pull request can merge from the API. A new preview endpoint in the Origin API tells you whether a pull request is mergeable and, if not, what is blocking it: required checks, approvals, code owner approvals, merge conflicts, or the shape of its stack. You can pass an expected head commit so the answer fails fast if the pull request has moved. See the Origin API changelog for details.
- Sort pull requests by recent activity and list only merged ones. When you list pull requests through the Origin API, you can now sort them by last update instead of creation time and filter to merged pull requests only. Sorting by update time also works in the Origin MCP server's pull request listing tool. See the Origin API changelog for details.
- Delete branches through the Origin API. You can now delete a branch from a script or integration with the Origin API, without pushing a deletion. The default branch and branches in mirrored repositories can't be deleted this way, and open pull requests from the deleted branch are closed. See the Origin API changelog for details.
- Add repositories to an existing app installation through the Origin API. Namespace admins can now add repositories to an app installation through the Origin API without going through the install flow again. The call only adds repositories and never changes the app's permissions. If the app isn't installed yet, the error now explains that an admin must finish the first install in the browser and includes the link to open. Listing an installation's repositories now also accepts a case-insensitive filter on repository name or
owner/repo. See the Origin API changelog for details. - Webhooks for pull request labels. Origin apps can subscribe to
pull_request.label.addedandpull_request.label.removedevents, so your automations can react when labels change on a pull request. Each event includes the pull request and the label, and label-added events also include who added it. See the Origin API changelog for payload details. - Email alerts when webhook deliveries pause. If your Origin app's webhook deliveries are paused automatically after repeated failures, namespace admins and the people who created or last edited the app now get an email with a failure summary, recovery steps, and a link to manage deliveries. Receivers now have up to 10 seconds to respond before a delivery times out, up from 5. Check run created and completed payloads no longer include a top-level
actor; usecheck_run.actorinstead. See the Origin API changelog. - Scope changes for apps and repository creation. Reading app details through the Origin API now requires the namespace apps read scope, and creating or mirroring repositories requires the "Create repositories" scope. See the Origin API changelog for details.
Web
- Stacked pull requests merge as one commit, and your commit text lands. Merging a pull request in a stack now lands it together with the open pull requests below it as a single commit. When you merge a single pull request, the commit title and message you edit in the merge popover now land exactly as written.
- Pause, resume, and test app webhook deliveries. Your app's settings page now has a Webhook Deliveries section. Once the app has a webhook URL, the section shows whether deliveries are active or paused, and has Pause, Resume, and Send Test Delivery buttons. Events that queue up while deliveries are paused are dropped, not sent late when you resume. Origin may also pause deliveries on its own, but only after a receiver has failed every delivery for 72 hours, with at least 20 failed deliveries in that time.
- Codebase settings has a sidebar and linkable sections. Codebase settings now uses a sidebar instead of tabs, with a Back to Codebase link at the top. Each section, such as Permissions and Apps, has its own URL you can bookmark or share, and older settings links redirect to the right section.
- Download a copy of your repository. Repository settings now have a Data section on the Advanced tab with a Download repository button that saves a tarball of the latest default branch. Origin API clients can request the same archive for any ref; see the Origin API changelog.
- See the pull requests behind a commit. When a commit was pushed as the head of an Origin pull request, or is the merge commit Origin created when landing pull requests, its commit details now include a References section listing those pull requests' branches, with links to each branch and its pull request. Each pull request shows whether it is open, draft, merged, or closed, and long lists collapse behind More and Less. References appear on repositories hosted on Origin, not on repositories mirrored from GitHub.
- Easier-to-scan pull request lists. Pull request lists now show larger titles that wrap instead of truncating, with a line under each title showing the pull request number, its author, and how long ago it was opened. Rows highlight on hover and match the style of the commits table.
- Image previews in pull request changes. Added or changed PNG, JPEG, GIF, and WebP files in a pull request's Changes tab now show a preview instead of an empty binary file card. Transparent images sit on a checkerboard background, so light icons stay visible in light theme and dark icons in dark theme.
- Safer pushes to Origin repositories. Origin now refuses a
git pushthat deletes a repository's default branch, with the error "refusing to delete the current branch", matching Git and GitHub. Other branches can still be deleted. Pull request refs underrefs/pull/andrefs/changes/no longer appear when you push and can't be overwritten by a push. - Pull request bases must be existing branches. Creating or retargeting a pull request now rejects a base that is a commit SHA, a tag, or a branch that doesn't exist, with an error saying the base must name an existing branch. Before, these bases were accepted but left the pull request unable to get a merge ref for CI or to be merged.
- Merge when ready no longer gets stuck on pull requests that can never merge. If a queued merge fails for a permanent reason, such as missing permissions or a pull request that no longer exists, merge when ready now turns itself off instead of retrying indefinitely. Merge conflicts and a changed head still leave it on.
- Re-run checks on pull requests. Completed checks whose app allows retries now show a re-run button on the pull request, and you can also re-run them with a new Origin API endpoint. The check reads as pending, and still blocks merge if it is required, until the app posts a new result. Apps receive a new
repository.check_run.rerequestedwebhook, and check runs now includererequested_by. - Fixes to pull request pages and sign-in. A brief problem with Cursor's session check no longer signs you out of pull request pages, and stack pages load faster and still open for large organizations.
- Fixes to repository reads and merge errors. File and blame reads on repositories with long delta chains no longer fail. Merging branches with unrelated histories, and checking whether stacks with more than 200 pull requests can merge, now return clear errors instead of internal server errors.
- Fixes to repository pages and links. Commit links in GitHub's URL format (
/owner/repo/commit/<sha>) on Origin's git host now redirect to the repository page instead of failing. Pinned and Recently Viewed repository cards now update their source icon when a repository's mirror status changes, and the "Origin access is not enabled" error now points you to cursor.com/codebase to request access.
API
- Manage Origin apps from the API. You can now create, list, view, and update your namespace's apps through the Origin API, and add or revoke the signing keys they authenticate with, so you can script app setup and rotate keys without the web UI. App responses also include the owning namespace, description, website, and default scopes. See the Origin API changelog for endpoint details.
- Manage repository mirrors from the Origin API. You can now change a mirrored repository's mirror state, detach it from its upstream source to make it a native repository, and poll the transition job until it finishes, all from the Origin API. See the Origin API changelog for endpoints and required scopes.
- Choose merge or squash when merging through the API. The Origin API's Merge Pull Request operation and the
merge_pull_requestMCP tool take an optional merge method,mergeorsquash. Leave it out to use the repository's default. If you ask for a method the repository doesn't allow, the error starts with the same sentence other forges use, so existing merge tooling recognizes it. See the Origin API changelog. - Service account keys can read repository settings. Repo-scoped team API keys for service accounts can now read repository settings, rulesets, and labels through the Origin API, so automation can audit rulesets and compare settings without a user token. Changing settings still requires a user. See the Origin API changelog for details.
- More detail in Origin API webhooks. Installation objects in webhook payloads now include when the installation was last updated, comment-created events carry the new thread's created and updated times, and every event payload is now documented with a sample. See the Origin API changelog for field details.
- Fixes to Origin API comments and webhooks. Creating an inline comment or review through the Origin API with a line range past the end of the file now fails with a clear error naming the file and its line count, instead of being accepted. Webhook events are no longer dropped when a brief database outage interrupts delivery; they are retried. See the Origin API changelog for details.
- Manage owner and repository access from the Origin API. You can now list, grant, change, and remove the access that users, groups, and team groups have on an owner or a repository through the Origin API. Each grant shows its permission level. See the Origin API changelog for endpoints and required scopes.
- Update repository settings from the Origin API. You can now change a repository's default branch, allowed merge methods, automatic branch deletion on merge, and visibility through the Origin API. Repository responses also include these settings, so you can read and update them programmatically. See the Origin API changelog for endpoint details.
Web
- Let specific people and apps bypass a ruleset. In a repository's Settings > Rules and Protections, the ruleset dialog now has a Bypass list. You can add up to 15 people with repository access or installed apps, and set each one to Always or Pull requests only. Bypass actors can merge pull requests into refs that the ruleset would otherwise block, for example with a block-merges rule.
- App creators can manage the apps they create. When you create an Origin app, you're now made its admin, so you can view and update its settings, signing keys, and icon without being a namespace admin. Namespace and team admins can still manage the app, and permission checks for app settings now give the same answer as the actions themselves.
- Clearer app permission updates. When you update an installed app's permissions, the review page now lists new permissions, permissions that will be revoked, and a collapsible list of permissions you've already granted. Apps that request a write permission now also get the matching read permission, so they can read the data they're allowed to change.
- Simpler app pages and clearer publisher details. Creating an app no longer asks for a slug, and app pages under codebase settings now use the app's ID, so links stay stable. The app details page shows who created and last updated it. Clicking an installed app in a repository's Apps settings tab opens its installation details, and policy dialogs list app scopes in their own section.
- Email notifications when your repository access changes. Origin now emails you when you're granted or lose access to a repository or namespace, including changes that come through a group or team membership. You don't get an email for changes you made yourself, or for the temporary draft repositories created when you start a new project with an agent.
- Clearer repository access controls. The Add People button and dialog on the codebase and repository Permissions tabs are now called Grant Access, and people or groups who already have access show their current access level, including custom policies, instead of "Already added." Repository settings now describe Private visibility as "Only users with direct access and codebase admins."
- Request reviews on personal repositories. On repositories owned by a personal account, the pull request reviewer picker now lists the owner and people you've granted access to the repository, and you can request their review. Previously the picker showed no one for personal repositories.
- Simpler commenting on your own pull requests, and replies held in your pending review. On a pull request you authored, the review button now reads Comment and opens a comment-only composer, without approve or request-changes options. Replies to review threads now join your pending review and stay private until you submit it.
- Readable author filters on the pull requests page. When you pick an author from the filter dropdowns on a repository's pull requests page, the search box and URL now show the person's name, like
author:"Ada Lovelace", instead of an unreadable ID. Shared links that use names still resolve to the right people. - Audit logs now show who pushed to a repository. Repository push entries in your team's audit log now record the pushing user's email instead of "unknown". Pushes made by an app or service account show that account instead. Review authors and CI check actors now appear as public IDs (
user_…,app_…,sa_…) instead of older internal ID formats. - Fixes to merging and restacking pull requests. Squash merges no longer land on the base branch while leaving the pull request open, and stack merges no longer fail with an orphan-commit error after the merge has landed. Merges and restacks no longer fail when the base branch moves at the same moment, and restacking works when a pull request's recorded base has drifted from its branch. Merges in repositories mirrored to GitHub no longer wait on the GitHub push.
- Fixes to pull request pages. Agent-generated images in code tours load correctly, and commits signed by Cursor Agent show the Cursor Agent name and avatar. Code tours on stacked PRs no longer show a stale tour after the base changes.
- Fixes to clone, fetch, and push reliability. Clones and fetches of large or mirrored repositories no longer fail with a 504 or drop while the server prepares the pack, and no longer briefly miss branches or tags during a repository restore. Pushes no longer print a spurious mirror warning when mirroring is disabled, and pull request diffs, mergeability checks, and blame no longer return server errors when repository metadata can't be read.
API
- Commit files and create branches through the Origin API. You can now commit file changes directly to an existing branch and create new branches at a given commit using the Origin API, without a local clone. Commits can require the branch to still point at an expected commit, so concurrent writes don't overwrite each other. The Origin Go SDK supports both. See the Origin API changelog for details.
- Apps are now identified by ID and display name across the Origin API, SDK, and webhooks. App objects, app actors, and webhook app payloads, including the test ping, no longer include a
slugfield. Check run groups no longer return the deprecatedapp_name, so readactor.display_nameinstead. If your integration keys on the app slug, switch to the appid. See the Origin API changelog for the affected fields. - New webhook events and faster recovery from failed deliveries. Apps can subscribe to a new
repository.metadata.updatedwebhook, which fires when a repository's default branch changes and includes the full repository. Installed apps now also get aninstallation.updatedevent when a namespace is renamed, with the new namespace and repository coordinates. Failed deliveries are retried after 5 seconds first, so brief network blips recover sooner. See the Origin API changelog for details. - Filter pull request comments and comment on whole files from the API. You can now list pull request comments within a creation-time window or only from specific threads, and open comment threads on an entire changed file instead of a single line, from the Origin API and Go SDK. See the Origin API changelog for details.
- More precise check-run and pull request lists in the Origin API. You can now filter a commit's check runs by check name and status (queued, in progress, or completed), and check-run lists for a commit or suite now return only the latest attempt of each run instead of superseded retries. Filtering pull requests by author now also accepts a user's email address, matched case-insensitively. See the Origin API changelog for details.
- API responses and webhooks now say more about who did what. User actors in Origin API responses and webhooks now include a display name and, for users with a public profile, their handle. App actors include the app's registered display name, and requested reviewers include their email. REST responses also return fields that hold default values, such as
draft: false, instead of leaving them out. See the Origin API changelog for field details. - The Origin API spec now lists the credentials and scopes each endpoint needs. Each operation in the Origin API's OpenAPI spec now says which credential types can call it (app, installation, or user) and which scopes it requires. Operations that need no extra scope, such as app and installation metadata and webhook deliveries, are marked as authentication-only. Duplicate operation IDs for the extra repository tarball and matching-refs routes are fixed, so client generators no longer fail on the spec. See the Origin API changelog.