- Fixed multiple bugs: device‑trust username overflow, mixed‑case JSON RPC field handling, Slack plugin token refresh reliability, access‑list prefix query issues, Okta app removal after restart, and SCIM membership change restrictions.
- Added new features: Helm chart support for the event‑handler configure command, tctl command to delete Okta assignment resources, and OCI SDK updates for new regions.
- Enhanced security/audit logging: untrusted‑device application session rejections are now consistently recorded as MFA‑failed AppSessionStart failures.