Skip to content

chore: align changelog config with actually-allowed commit types - #799

Merged
thegdsks merged 1 commit into
mainfrom
chore/release-changelog-quality
Sep 29, 2026
Merged

thegdsks merged 1 commit into
mainfrom
chore/release-changelog-quality

Conversation

@thegdsks

@thegdsks thegdsks commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Summary

  • release-please-config.json declared changelog sections for revert, build, style commit types, but the commit-msg hook only ever allows feat|fix|perf|refactor|docs|test|chore|ci, so those sections were dead config.
  • Worse: the visible "Security" section had no matching allowed commit type either, so real security fixes (SSRF, email injection, zip slip, path injection, enrollment CA pin, dependency security bumps) were landing anonymously in the generic "Bug Fixes" bucket instead of a dedicated Security section.
  • Adds security as an allowed commit type in the commit-msg hook, removes the three unreachable sections (revert, build, style) from release-please config, and corrects CONTRIBUTING.md's documented type list (was missing ci, now documents security too).

What this doesn't do

  • Does not touch the currently-open release-please PR chore(main): release 0.2.0-beta.15 #664 (needs the owner's manual close/reopen/merge per this repo's own bot-classifier limitation).
  • Does not address release cadence noise (8 point releases in one day on 2026-09-23) since that's a merge-process question, not a config bug.

Test plan

  • release-please-config.json validated as JSON
  • commit-msg hook regex tested against security: and build: sample subjects
  • go build ./..., go vet ./..., golangci-lint, pre-commit, pre-push all pass

RetriggerConfidence Score: 4/5

The PR should not merge until a security-only fix can trigger a release.

Findings

  1. P1 Security fixes may not ship ▶
Fix with agent prompt
### Issue 1
CONTRIBUTING.md:24-26
A PR containing only a `security:` commit now follows the documented convention, but the `simple` release strategy does not bump a version for that type alone. The Security changelog entry is only a category, not a release trigger. Until another releasable commit lands, release-please will not open a release PR, delaying shipment of the vulnerability fix.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
Summary

The PR adds security to the commit-message convention, documents when to use it, and removes three changelog mappings for types the hook rejects.

  • Security changes can be categorized under the existing Security heading, but a security-only commit does not itself trigger a release.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A["security: fix merged"] --> B["release-please reads commits"]
  B --> C["Security changelog category"]
  B --> D{"Releasable version bump?"}
  D -- "No, for security alone" --> E["No release PR until another releasable commit"]
Loading

Reviews (1) · Last reviewed commit: "chore: align changelog config with actua..."

release-please-config.json declared visible/hidden sections for
revert, build and style, but the commit-msg hook only ever allows
feat/fix/perf/refactor/docs/test/chore/ci, so those sections could
never receive an entry. Drops the dead ones, and makes the existing
"Security" section reachable by adding security as an allowed type.
Updates CONTRIBUTING.md's type list to match.
@thegdsks
thegdsks enabled auto-merge (squash) September 29, 2026 01:32
@github-actions github-actions Bot added type/chore Tooling, CI, release plumbing area/ci .github/, scripts/ type/docs Documentation only size/s 10-49 lines changed labels Sep 29, 2026
@thegdsks
thegdsks merged commit 59a217e into main Sep 29, 2026
15 of 16 checks passed
@github-actions
github-actions Bot deleted the chore/release-changelog-quality branch September 29, 2026 01:32
@sonarqubecloud

Copy link
Copy Markdown

@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 192ec3d3-631a-42c3-ac48-1075e25b9280

📥 Commits

Reviewing files that changed from the base of the PR and between 2e2969f and a01c842.

📒 Files selected for processing (3)
  • CONTRIBUTING.md
  • release-please-config.json
  • scripts/git-hooks/commit-msg
 ____________________________________________________________________________________________________________________
< Always design for concurrency. Allow for concurrency, and you'll design cleaner interfaces with fewer assumptions. >
 --------------------------------------------------------------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread CONTRIBUTING.md
Comment on lines +24 to +26
`refactor`, `docs`, `test`, `chore`, `ci`, `security`. Use `security`
for a fix whose primary purpose is closing a vulnerability, so it gets
its own changelog section instead of blending into Bug Fixes.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Security fixes may not ship A PR containing only a security: commit now follows the documented convention, but the simple release strategy does not bump a version for that type alone. The Security changelog entry is only a category, not a release trigger. Until another releasable commit lands, release-please will not open a release PR, delaying shipment of the vulnerability fix.

Prompt To Fix With AI
This is a comment left during a code review.
Path: CONTRIBUTING.md
Line: 24-26

Comment:
**Security fixes may not ship** A PR containing only a `security:` commit now follows the documented convention, but the `simple` release strategy does not bump a version for that type alone. The Security changelog entry is only a category, not a release trigger. Until another releasable commit lands, release-please will not open a release PR, delaying shipment of the vulnerability fix.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/ci .github/, scripts/ size/s 10-49 lines changed type/chore Tooling, CI, release plumbing type/docs Documentation only

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant