chore: align changelog config with actually-allowed commit types - #799
Conversation
release-please-config.json declared visible/hidden sections for revert, build and style, but the commit-msg hook only ever allows feat/fix/perf/refactor/docs/test/chore/ci, so those sections could never receive an entry. Drops the dead ones, and makes the existing "Security" section reachable by adding security as an allowed type. Updates CONTRIBUTING.md's type list to match.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
| `refactor`, `docs`, `test`, `chore`, `ci`, `security`. Use `security` | ||
| for a fix whose primary purpose is closing a vulnerability, so it gets | ||
| its own changelog section instead of blending into Bug Fixes. |
There was a problem hiding this comment.
Security fixes may not ship A PR containing only a
security: commit now follows the documented convention, but the simple release strategy does not bump a version for that type alone. The Security changelog entry is only a category, not a release trigger. Until another releasable commit lands, release-please will not open a release PR, delaying shipment of the vulnerability fix.
Prompt To Fix With AI
This is a comment left during a code review.
Path: CONTRIBUTING.md
Line: 24-26
Comment:
**Security fixes may not ship** A PR containing only a `security:` commit now follows the documented convention, but the `simple` release strategy does not bump a version for that type alone. The Security changelog entry is only a category, not a release trigger. Until another releasable commit lands, release-please will not open a release PR, delaying shipment of the vulnerability fix.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.


Summary
release-please-config.jsondeclared changelog sections forrevert,build,stylecommit types, but the commit-msg hook only ever allowsfeat|fix|perf|refactor|docs|test|chore|ci, so those sections were dead config.securityas an allowed commit type in the commit-msg hook, removes the three unreachable sections (revert,build,style) from release-please config, and corrects CONTRIBUTING.md's documented type list (was missingci, now documentssecuritytoo).What this doesn't do
Test plan
release-please-config.jsonvalidated as JSONsecurity:andbuild:sample subjectsgo build ./...,go vet ./..., golangci-lint, pre-commit, pre-push all passThe PR should not merge until a security-only fix can trigger a release.
Findings
Fix with agent prompt
Summary
The PR adds
securityto the commit-message convention, documents when to use it, and removes three changelog mappings for types the hook rejects.Diagram
%%{init: {'theme': 'neutral'}}%% flowchart LR A["security: fix merged"] --> B["release-please reads commits"] B --> C["Security changelog category"] B --> D{"Releasable version bump?"} D -- "No, for security alone" --> E["No release PR until another releasable commit"]Reviews (1) · Last reviewed commit: "chore: align changelog config with actua..."