Skip to content

fix: stop publishing development noise and dropping security notes in release notes - #179

Merged
nelsonduarte merged 5 commits into
mainfrom
fix/release-notes-other-section
Sep 12, 2026
Merged

nelsonduarte merged 5 commits into
mainfrom
fix/release-notes-other-section

Conversation

@nelsonduarte

Copy link
Copy Markdown
Owner

The release body generated by build.yml is not an internal artefact: the in-app updater downloads it and shows it to end users. Two defects in the old inline-bash generator were visible there.

Development noise was published verbatim

Any commit type the old sed did not know (it handled only feat|fix|perf|a11y|docs) fell through to the catch-all ## Other section with its raw prefix intact, so users read lines such as Test: rename unused QApplication holder to satisfy CodeQL and Refactor(window): extract auto-update subsystem into UpdateController. Development-only types are now dropped rather than dumped into a catch-all.

Security notes were silently deleted

The dependabot heuristic bump.*from.*to was unanchored and applied to every subject, including hand-written ones, so a commit like security(deps): bump pillow from 12.2.0 to 12.3.0 was discarded without a trace.

This was a near miss in practice, not a theoretical concern: the real commit fix: pin cryptography for the Flatpak and bump pypdf past six CVEs, already on main, survived only because its wording happens not to contain " from ... to ". The heuristic is now anchored and is applied only to subjects that carry no recognised type, so a hand-written security note can no longer be swallowed.

This is why the change is fix: and not chore:.

New ## Security section

Security changes get their own section, ordered first because for a PDF tool it is the change users most need to see. The heading has an update.section.security key in all 8 languages of app/translations.json, matching the existing section headings.

Logic moved out of YAML

The categorisation moved from inline bash in the workflow into scripts/release_notes.py, which is why it was never testable before. The module is stdlib-only on purpose: the release job has no setup-python step and runs it with the runner's system interpreter.

Single routing table

Routing is driven by one _TYPE_DESTINATION table mapping each commit type to a heading or to None. The earlier two-structure version (a drop-set plus a routing map) grew a branch that could never be reached, because a type in the drop-set was re-tested for a scope further down. With one entry per type, that class of bug is not expressible.

Verification

  • Test suite goes from 681 to 746 passing (2 skipped, unchanged).
  • Behaviour proved identical over the real tag-to-tag intervals of this repository's history: 968 classifications measured by the implementer, 495 subjects by the reviewer, 520 by the QA tester, all with zero differences.
  • 9 mutations killed by the QA tester against the final version.
  • In-app update dialog validated in all 8 languages.
  • The SHA256 checksums block appended by the next workflow step is intact and unchanged.

What is not done

Two defensive clauses of _NOISE_RE have no test pinning them, and both are recorded here rather than left implicit:

  • ^(?:chore|build|ci)?\(?deps\)?: and \[bot\] without an anchor. Measured real-world exposure for both is zero over this repository's history.
  • The unanchored \[bot\] has the same failure mode this PR fixes for dependabot: as a bare substring it could drop an ordinary subject that merely contains it. Declared and deliberately not resolved here.

CI note

build.yml triggers only on push of v* tags and on workflow_dispatch, and the release job is additionally gated on startsWith(github.ref, 'refs/tags/v'). This PR therefore does not run build.yml; the edited generator step executes for the first time on the next version tag.

🤖 Generated with Claude Code

… release notes

The release body generated by build.yml is not an internal artefact: the
in-app updater downloads it and shows it to end users. Two defects in the
old inline-bash generator were visible there.

Development noise was published verbatim. Any commit type the old sed did
not know (it handled only feat|fix|perf|a11y|docs) fell through to the
catch-all "## Other" section with its raw prefix intact, so users read
lines such as "Test: rename unused QApplication holder to satisfy CodeQL"
and "Refactor(window): extract auto-update subsystem into
UpdateController". Development-only types are now dropped instead of
being dumped into a catch-all.

Security notes were silently deleted. The dependabot heuristic
'bump.*from.*to' was unanchored and applied to every subject, including
hand-written ones, so a commit like "security(deps): bump pillow from
12.2.0 to 12.3.0" was discarded without a trace. This was a near miss in
practice: the real commit "fix: pin cryptography for the Flatpak and bump
pypdf past six CVEs", already on main, survived only because its wording
happens not to contain " from ... to ". The noise heuristic is now
anchored and is applied only to subjects that carry no recognised type,
so a hand-written security note can no longer be swallowed.

Security changes also get their own "## Security" section, ordered first
because for a PDF tool it is the change users most need to see. The
heading has an update.section.security key in all 8 languages of
app/translations.json, matching the existing section headings.

The categorisation moved out of inline bash in the workflow YAML and into
scripts/release_notes.py, which is why it was never testable before. The
module is stdlib-only on purpose: the release job has no setup-python
step and runs it with the runner's system interpreter.

Routing is driven by a single _TYPE_DESTINATION table mapping each commit
type to a heading or to None. The earlier two-structure version (a
drop-set plus a routing map) grew a branch that could never be reached,
because a type in the drop-set was re-tested for a scope further down.
With one entry per type that class of bug is not expressible.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Comment thread tests/test_release_notes_generator.py Fixed
Comment thread tests/test_release_notes_generator.py Fixed
Comment thread tests/test_release_notes_generator.py Fixed
Comment thread tests/test_release_notes_generator.py Fixed
Comment thread tests/test_release_notes_generator.py Fixed
…atenation in a list'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Deploying pdfapps with  Cloudflare Pages  Cloudflare Pages

Latest commit: dd4dbe7
Status: ✅  Deploy successful!
Preview URL: https://31473faf.pdfapps.pages.dev
Branch Preview URL: https://fix-release-notes-other-sect.pdfapps.pages.dev

View logs

nelsonduarte and others added 3 commits September 12, 2026 21:58
…atenation in a list'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…atenation in a list'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…atenation in a list'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@nelsonduarte
nelsonduarte merged commit 7a76cb7 into main Sep 12, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants