Skip to content

release: v4.31.0 - run automatically as part of the standard v4 set - #368

Open
cldmv-bot[bot] wants to merge 9 commits into
masterfrom
next
Open

cldmv-bot[bot] wants to merge 9 commits into
masterfrom
next

Conversation

@cldmv-bot

@cldmv-bot cldmv-bot Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

🚀 What's Changed

💥 Breaking Changes

No breaking changes

✨ Features

🐛 Bug Fixes

📦 Dependencies

🔧 Other Changes

👥 Contributors

Co-authored-by: Shinrai Shinrai@users.noreply.github.com

Shinrai and others added 8 commits October 4, 2026 01:20
…4 set

The sync-release-notes caller becomes a standard companion every v4 repo
carries, and it no longer waits for a manual dispatch:

- Template triggers: release: published (releases are created with the bot
  App token, so the event fires), push to the default branch touching
  docs/changelog/** or docs/changelogs/** (a companion, not a required
  check, so the paths filter is fine), and workflow_dispatch with all the
  switches.
- Automatic runs apply changes: sync bodies from the changelog files and
  re-publish draft releases whose tag exists. Creating missing tags and
  releases stays manual (dispatch switches).
- Tag creation refuses to run without the bot GPG key, and flags a tag
  that came out unsigned because GitHub forced the REST fallback.
- Idempotent full sweep: a run with nothing to change says so. Drift that
  needs a decision is a warning; the job fails only when an attempted
  repair fails.
- Least privilege: GITHUB_TOKEN is contents: read; every write uses the
  App token. Runs queue per repo.
- Docs list it in the standard set (README, examples/README,
  WORKFLOW-SETUP-GUIDE, AGENT-SCAFFOLDING, release-flow-v4).

Refs #362
git's default message cleanup treats lines starting with # as comments, so
the signed v1.2.4 tag in CLDMV/configs lost every changelog heading
(# ... Changelog, ## Overview, ## Bug Fixes). Create annotated tags from a
message file with --cleanup=verbatim everywhere: tag/create and tag/update
(release tags and rolling tags), fix-orphaned-releases, and the tag-health
re-sign / re-point paths via a shared annotatedTagArgs() helper. A new test
asserts a ## heading survives creation and replacement.

Refs #362
…og file

Adds one file per version for the 74 v4 releases that shipped without a
docs/changelogs/vX.Y.Z.md: every patch release from v4.0.1 through
v4.25.1, and everything from v4.26.1 through v4.30.6. Each is written from
the diff against the previous release and the PRs it contains, so the
release automation and sync-release-notes can resolve an exact-version
file for every v4 release.

Patch releases that changed a consumer-facing default are listed under
Breaking Changes with upgrade steps: v4.16.3 (LTS-only matrix default),
v4.27.1 (Node matrix bounds), v4.27.3 (default-on docs check) and v4.29.1
(--ignore-scripts on the default publish command).
v4.30.7 shipped #361 (next-reset carries late merges onto the release
instead of dropping them, lease-guarded ref updates, wait-for-tags gate
limited to CLDMV/.github) and #363 (tag-health re-signs tags in place
instead of delete + recreate, tags signed at creation, publish fails on a
draft or tagless release, changelog file as the release body, mention
neutralizing, and the new sync-release-notes workflow).

The README gains a What's New section with v4.30.7 as the latest release
and v4.30.3 through v4.30.6 as recent releases.
Re-applies the security bump from #349. It merged into hotfixes, but its
release PR #353 was closed unmerged and hotfixes has since been reset, so
master still ships 5.0.9 (Dependabot alert #4). Dev-only, via
eslint > minimatch.
@cldmv-bot cldmv-bot Bot added ! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: minor This release adds new functionality in a backwards-compatible way type: bug Something is broken or not behaving as expected type: feature Implements new functionality — a PR or issue that adds a feature area: core Touches core library / runtime source code area: tests Touches test files, fixtures, or test infrastructure type: ci Changes to CI workflows, actions, or build pipelines type: config Changes to repository or project configuration files type: documentation Relates to docs, README updates, guides, or inline code comments labels Oct 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: core Touches core library / runtime source code area: tests Touches test files, fixtures, or test infrastructure ! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: minor This release adds new functionality in a backwards-compatible way type: bug Something is broken or not behaving as expected type: ci Changes to CI workflows, actions, or build pipelines type: config Changes to repository or project configuration files type: documentation Relates to docs, README updates, guides, or inline code comments type: feature Implements new functionality — a PR or issue that adds a feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant