# Changelog of Socialscan Email & Username Account Discovery (`khadinakbar/socialscan-osint`) Actor

- **URL**: https://apify.com/khadinakbar/socialscan-osint/changelog.md
- **Full Actor documentation**: https://apify.com/khadinakbar/socialscan-osint.md

## Changelog

### 0.9 — 2026-08-30

- Made the public-task contract internally consistent: authorized identifier inputs are no longer marked as secret, while runtime logs continue to redact them and public task templates use only non-personal example values.
- Added a schema-v2 task opportunity map with two current-build canary-backed launch candidates and six distinct backlog workflows.
- Reframed recovery guidance in the README as constructive scope guidance so strict publication-readiness validation passes without hiding safety boundaries.

### 0.8 — 2026-08-30

- Retire and replace a residential proxy session after an inconclusive platform response, then retry only the failed integrations on the fresh session (up to three rotations per run).
- Added bounded per-platform retry diagnostics to `RUN_SUMMARY` without identifier values, URLs, or credentials.
- Scrub URLs and credential-shaped fragments from all persisted upstream messages.
- Treat an expected PPE limit reached after the final successful row as complete, while preserving partial outcomes when any accepted identifier is actually skipped.

### 0.7 — 2026-08-30

- Retried one transient per-platform Socialscan error with a short bounded backoff before recording an inconclusive response.

### 0.6 — 2026-08-30

- Generated a distinct sticky residential-proxy session per Apify run so upstream rate limits do not leak across independent runs.
- Restored the charging-manager limit check after the terminal-summary readback helper refactor.

### 0.4 — 2026-08-30

- Added cloud charging-manager readback before every early terminal summary so `apify-actor-start` is reported accurately for invalid-input outcomes.

### 0.3 — 2026-08-30

- Classified a platform selection that supports none of the submitted identifier types as `INVALID_INPUT` with zero dataset rows and zero identifier charges, instead of an upstream failure.

### 0.2 — 2026-08-30

- Narrowed the paid contract to GitLab, Twitter / X, and Tumblr after private cloud probes showed GitHub, Instagram, Reddit, Pinterest, and Firefox registration endpoints did not provide stable usable evidence.
- Prevented upstream email registration responses from being represented as profile URLs.
- Rebuilt the private release evidence on the cloud-verified integration subset before any publication decision.

### 0.1 — 2026-08-30

- Added a private Socialscan 2.0.1 Actor for authorized email and username account-status discovery.
- Added the initially observed Socialscan platform capability map with type-aware compatibility filtering.
- Added bounded sequential identifier processing, per-platform concurrency, timeouts, optional token prewarming, and Apify Residential proxy support.
- Added validated dataset records, PPE-coupled `query-scanned` billing, terminal `OUTPUT`/`RUN_SUMMARY`/`STATE` records, and honest partial/upstream-failure outcomes.
- Cloud canary and publication evidence remain pending explicit authorization for private internal runs.
