# Changelog of Bulk HTTP Security Headers Analyzer - CSP, HSTS (`logiover/bulk-http-security-headers`) Actor

- **URL**: https://apify.com/logiover/bulk-http-security-headers/changelog.md
- **Full Actor documentation**: https://apify.com/logiover/bulk-http-security-headers.md

## Changelog

### 2026-09-23

- Fleet-wide quality audit. Verified end to end against live data and re-checked the input schema, the output columns and the run configuration.
- Run reliability reviewed: 100.0% of public runs succeeded in the last 30 days.
- Input schema, output schema and pricing configuration reviewed.

### 2026-09-01

- Fleet-wide health check. Verified against this Actor's real run history: 30-day success rate, output row counts, per-field fill rates, and peak memory against the configured memory limit.
- Reviewed for the failure patterns that have cost this fleet runs — unguarded proxy setup, retry loops that can outlast the run's own time budget, and full-page HTML parsing that can exhaust a small container.
- No change to input, output fields or scraping logic.

### 2026-08-11

- Maintenance release: refreshed the build and dependencies.
- Re-verified live execution, non-empty structured output and dataset field/type integrity.
- Reviewed reliability (retries, pagination) and output quality as part of a full-fleet QA pass.

### 2026-08-01

- Completed the August 2026 full health check: verified empty/programmatic default, Console UI default, and two source-informed alternative inputs on Apify.
- Confirmed successful live execution, non-empty structured output, dataset-field/type integrity, and logical sample quality within the 5-minute quality window.
- Fixed the run Output link from `{{links.apiDefaultDatasetUrl}}` to `{{links.apiDefaultDatasetUrl}}/items` so the results table opens the dataset items endpoint.

### 2026-07-18

- Maintenance & reliability pass — re-verified end-to-end against live data via the Apify API; confirmed the Actor completes successfully and returns non-empty, well-formed results within the 5-minute quality window on its default input.
- Refreshed build so the latest version is current; no change to inputs, output fields or scraping logic.

### 2026-07-12

- Input is now fully optional — running with empty input scans a built-in set of well-known sites, so you always get results.
- Added `maxResults` (default 1000) to bound large/empty runs and keep them fast and cheap.
- Added `sortBy` dropdown (input order / highest score / worst offenders / best grade) to order the output.
- Numeric fields (`statusCode`, `securityScore`, `passCount`, `totalChecks`, `latencyMs`, `hstsMaxAge`) are now real numbers, and every pass/HSTS flag (`cspPass`, `hstsPass`, `hstsIncludeSubdomains`, `hstsPreload`, `xFrameOptionsPass`, etc.) is a real boolean (previously strings).
- Added a per-record dataset `fields` schema (nullable-safe) with titles and descriptions.
- Added a ~4-minute time budget: long runs stop gracefully and save everything collected.
- Proxy defaults to Apify Proxy (AUTO); the dead DATACENTER-only group is never forced.

### 2026-06-28

- Health check passed — actor verified working end-to-end on Apify platform.
- Changelog refreshed for Store quality compliance.

### 2026-06-24

- Initial release — 11 security header checks with weighted scoring, A+ to F grading, no API key, CSV/JSON export.
