Problem
A next → master (or hotfixes → master) release PR can merge without a curated changelog for its version. generate-comprehensive-changelog looks for docs/changelog[s]/v<major>/v<version>.md. When the file is missing, it silently falls back to the auto-generated "What's Changed" dump, and that becomes the release commit, the tag message and the GitHub Release body. Nothing fails, so a release can ship with machine-generated notes and a stale README "What's New".
Seen on 2026-10-03: CLDMV/node-android-tv-remote's release PR #47 (v2.1.8) was mergeable before any v2.1.8 changelog existed. The notes were added afterwards in CLDMV/node-android-tv-remote#49.
Proposal
Add a required check to the release-PR workflows (the persistent release PR opened by workflow-next-release.yml / workflow-hotfixes-release.yml) that:
- Resolves the version the release PR will ship. That's the same version the release title uses, so read it from the computed plan rather than recomputing it.
- Looks for the per-version changelog file on the release PR's source branch, whichever branch the PR comes from:
next for a next → master release, hotfixes for a hotfixes → master release. It uses the same resolution order as readVersionChangelogFile: the explicit changelog-file input, then <dir>/v<major>/v<version>.md, <dir>/v<version>.md, <dir>/<version>.md, under docs/changelog and docs/changelogs.
- Fails with a clear message naming the expected path and branch when the file is missing. It re-runs when the source branch changes, so it turns green once the doc PR merges into it.
- Optionally warns, without failing, when the README "✨ What's New" Latest block doesn't name the version.
- Repo opt-out. A repository Actions variable,
CLDMV_SKIP_CHANGELOG_CHECK=1, read through the vars context, the same pattern as CLDMV_SKIP_CODE_SCANNING and CLDMV_SKIP_FROZEN_LOCKFILE. When it's set, the check still runs but reports success with a notice ("changelog check skipped by CLDMV_SKIP_CHANGELOG_CHECK"), so the required check is satisfied rather than missing. When it's unset, the check is enforced. Document it with the other CLDMV_SKIP_* variables.
Considerations
- Default: enforced for every v4 repo. Repos that don't keep per-version changelogs (non-library repos) set the opt-out variable.
- Bot-only releases: a release made only of dependency bumps still needs a file; the changelog skill handles that quickly. Consider whether a release with only
deps: commits should be exempt automatically, or left to the opt-out.
- Ruleset: add the new check name to the release branch's required checks in the org ruleset, and to
release-merge.yml's workflows: list so the merge gate waits for it.
- Fleet: it's caller-level wherever a new check name or input is involved, so the template and consumers need syncing, like other release-flow changes.
Problem
A
next → master(orhotfixes → master) release PR can merge without a curated changelog for its version.generate-comprehensive-changeloglooks fordocs/changelog[s]/v<major>/v<version>.md. When the file is missing, it silently falls back to the auto-generated "What's Changed" dump, and that becomes the release commit, the tag message and the GitHub Release body. Nothing fails, so a release can ship with machine-generated notes and a stale README "What's New".Seen on 2026-10-03: CLDMV/node-android-tv-remote's release PR #47 (v2.1.8) was mergeable before any v2.1.8 changelog existed. The notes were added afterwards in CLDMV/node-android-tv-remote#49.
Proposal
Add a required check to the release-PR workflows (the persistent release PR opened by
workflow-next-release.yml/workflow-hotfixes-release.yml) that:nextfor anext → masterrelease,hotfixesfor ahotfixes → masterrelease. It uses the same resolution order asreadVersionChangelogFile: the explicitchangelog-fileinput, then<dir>/v<major>/v<version>.md,<dir>/v<version>.md,<dir>/<version>.md, underdocs/changeloganddocs/changelogs.CLDMV_SKIP_CHANGELOG_CHECK=1, read through thevarscontext, the same pattern asCLDMV_SKIP_CODE_SCANNINGandCLDMV_SKIP_FROZEN_LOCKFILE. When it's set, the check still runs but reports success with a notice ("changelog check skipped by CLDMV_SKIP_CHANGELOG_CHECK"), so the required check is satisfied rather than missing. When it's unset, the check is enforced. Document it with the otherCLDMV_SKIP_*variables.Considerations
deps:commits should be exempt automatically, or left to the opt-out.release-merge.yml'sworkflows:list so the merge gate waits for it.