fix: stop publishing development noise and dropping security notes in release notes - #179
Merged
Merged
Conversation
… release notes The release body generated by build.yml is not an internal artefact: the in-app updater downloads it and shows it to end users. Two defects in the old inline-bash generator were visible there. Development noise was published verbatim. Any commit type the old sed did not know (it handled only feat|fix|perf|a11y|docs) fell through to the catch-all "## Other" section with its raw prefix intact, so users read lines such as "Test: rename unused QApplication holder to satisfy CodeQL" and "Refactor(window): extract auto-update subsystem into UpdateController". Development-only types are now dropped instead of being dumped into a catch-all. Security notes were silently deleted. The dependabot heuristic 'bump.*from.*to' was unanchored and applied to every subject, including hand-written ones, so a commit like "security(deps): bump pillow from 12.2.0 to 12.3.0" was discarded without a trace. This was a near miss in practice: the real commit "fix: pin cryptography for the Flatpak and bump pypdf past six CVEs", already on main, survived only because its wording happens not to contain " from ... to ". The noise heuristic is now anchored and is applied only to subjects that carry no recognised type, so a hand-written security note can no longer be swallowed. Security changes also get their own "## Security" section, ordered first because for a PDF tool it is the change users most need to see. The heading has an update.section.security key in all 8 languages of app/translations.json, matching the existing section headings. The categorisation moved out of inline bash in the workflow YAML and into scripts/release_notes.py, which is why it was never testable before. The module is stdlib-only on purpose: the release job has no setup-python step and runs it with the runner's system interpreter. Routing is driven by a single _TYPE_DESTINATION table mapping each commit type to a heading or to None. The earlier two-structure version (a drop-set plus a routing map) grew a branch that could never be reached, because a type in the drop-set was re-tested for a scope further down. With one entry per type that class of bug is not expressible. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…atenation in a list' Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Deploying pdfapps with
|
| Latest commit: |
dd4dbe7
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://31473faf.pdfapps.pages.dev |
| Branch Preview URL: | https://fix-release-notes-other-sect.pdfapps.pages.dev |
…atenation in a list' Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…atenation in a list' Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…atenation in a list' Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The release body generated by
build.ymlis not an internal artefact: the in-app updater downloads it and shows it to end users. Two defects in the old inline-bash generator were visible there.Development noise was published verbatim
Any commit type the old
seddid not know (it handled onlyfeat|fix|perf|a11y|docs) fell through to the catch-all## Othersection with its raw prefix intact, so users read lines such asTest: rename unused QApplication holder to satisfy CodeQLandRefactor(window): extract auto-update subsystem into UpdateController. Development-only types are now dropped rather than dumped into a catch-all.Security notes were silently deleted
The dependabot heuristic
bump.*from.*towas unanchored and applied to every subject, including hand-written ones, so a commit likesecurity(deps): bump pillow from 12.2.0 to 12.3.0was discarded without a trace.This was a near miss in practice, not a theoretical concern: the real commit
fix: pin cryptography for the Flatpak and bump pypdf past six CVEs, already onmain, survived only because its wording happens not to contain" from ... to ". The heuristic is now anchored and is applied only to subjects that carry no recognised type, so a hand-written security note can no longer be swallowed.This is why the change is
fix:and notchore:.New
## SecuritysectionSecurity changes get their own section, ordered first because for a PDF tool it is the change users most need to see. The heading has an
update.section.securitykey in all 8 languages ofapp/translations.json, matching the existing section headings.Logic moved out of YAML
The categorisation moved from inline bash in the workflow into
scripts/release_notes.py, which is why it was never testable before. The module is stdlib-only on purpose: thereleasejob has nosetup-pythonstep and runs it with the runner's system interpreter.Single routing table
Routing is driven by one
_TYPE_DESTINATIONtable mapping each commit type to a heading or toNone. The earlier two-structure version (a drop-set plus a routing map) grew a branch that could never be reached, because a type in the drop-set was re-tested for a scope further down. With one entry per type, that class of bug is not expressible.Verification
What is not done
Two defensive clauses of
_NOISE_REhave no test pinning them, and both are recorded here rather than left implicit:^(?:chore|build|ci)?\(?deps\)?:and\[bot\]without an anchor. Measured real-world exposure for both is zero over this repository's history.\[bot\]has the same failure mode this PR fixes fordependabot: as a bare substring it could drop an ordinary subject that merely contains it. Declared and deliberately not resolved here.CI note
build.ymltriggers only onpushofv*tags and onworkflow_dispatch, and thereleasejob is additionally gated onstartsWith(github.ref, 'refs/tags/v'). This PR therefore does not runbuild.yml; the edited generator step executes for the first time on the next version tag.🤖 Generated with Claude Code