Skip to content

Block a release PR from merging until its per-version changelog exists on the source branch (next or hotfixes) #359

Description

@Shinrai

Problem

A next → master (or hotfixes → master) release PR can merge without a curated changelog for its version. generate-comprehensive-changelog looks for docs/changelog[s]/v<major>/v<version>.md. When the file is missing, it silently falls back to the auto-generated "What's Changed" dump, and that becomes the release commit, the tag message and the GitHub Release body. Nothing fails, so a release can ship with machine-generated notes and a stale README "What's New".

Seen on 2026-10-03: CLDMV/node-android-tv-remote's release PR #47 (v2.1.8) was mergeable before any v2.1.8 changelog existed. The notes were added afterwards in CLDMV/node-android-tv-remote#49.

Proposal

Add a required check to the release-PR workflows (the persistent release PR opened by workflow-next-release.yml / workflow-hotfixes-release.yml) that:

  1. Resolves the version the release PR will ship. That's the same version the release title uses, so read it from the computed plan rather than recomputing it.
  2. Looks for the per-version changelog file on the release PR's source branch, whichever branch the PR comes from: next for a next → master release, hotfixes for a hotfixes → master release. It uses the same resolution order as readVersionChangelogFile: the explicit changelog-file input, then <dir>/v<major>/v<version>.md, <dir>/v<version>.md, <dir>/<version>.md, under docs/changelog and docs/changelogs.
  3. Fails with a clear message naming the expected path and branch when the file is missing. It re-runs when the source branch changes, so it turns green once the doc PR merges into it.
  4. Optionally warns, without failing, when the README "✨ What's New" Latest block doesn't name the version.
  5. Repo opt-out. A repository Actions variable, CLDMV_SKIP_CHANGELOG_CHECK=1, read through the vars context, the same pattern as CLDMV_SKIP_CODE_SCANNING and CLDMV_SKIP_FROZEN_LOCKFILE. When it's set, the check still runs but reports success with a notice ("changelog check skipped by CLDMV_SKIP_CHANGELOG_CHECK"), so the required check is satisfied rather than missing. When it's unset, the check is enforced. Document it with the other CLDMV_SKIP_* variables.

Considerations

  • Default: enforced for every v4 repo. Repos that don't keep per-version changelogs (non-library repos) set the opt-out variable.
  • Bot-only releases: a release made only of dependency bumps still needs a file; the changelog skill handles that quickly. Consider whether a release with only deps: commits should be exempt automatically, or left to the opt-out.
  • Ruleset: add the new check name to the release branch's required checks in the org ruleset, and to release-merge.yml's workflows: list so the merge gate waits for it.
  • Fleet: it's caller-level wherever a new check name or input is involved, so the template and consumers need syncing, like other release-flow changes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority: mediumShould be addressed in the normal course of developmentstatus: not startedNot implemented yet — no code exists for thistype: future featureA feature idea that is out of scope for now but worth revisiting later

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions