Affects
Teams that use Flowker’s generic HTTP executor to retrieve externally hosted content.What changed
The documentation now covers the optionalcontent_digest SHA-256 pin for the generic HTTP executor. When configured, Flowker fails closed if the retrieved content does not match the digest.
This is a documentation correction of the current runtime behavior; it does not announce a runtime release.
Impact
Classification: Review recommended.What you need to do
Review HTTP executor integrations that need integrity pinning. Add and maintaincontent_digest only where you can manage the expected SHA-256 value.
