You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Seven repositories that ship a package do not call require-changelog #18
Eight repositories in this organization ship something installable and do not
call the organization's require-changelog workflow. fab was one of them,
and that omission is the direct cause of Keel-Linux/fab#7: pull requests #4
and #5 there both changed share/product.mk, a path the package ships, with
no changelog entry, and the version was bumped at packaging time instead. fab is wired up in Keel-Linux/fab#9. The other seven are not.
This is in tracker rather than in each repository because the question
"which repositories are gated" is org-wide; the fixes are per repository and
each needs its own issue there.
Audited 2026-09-28, against the default branch of all 39 non-archived repositories
The gate is .github/workflows/require-changelog.yml in Keel-Linux/.github,
with its logic in bin/require-changelog. It is workflow_call only, so it
does nothing unless a repository calls it. 15 repositories do.
Ships something installable, gate missing
Repo
What it ships
Workflows present
keel-core
./changelog, keel-core-19.0 (1) keel
test-shell, test-appliance
keel-nodejs-nginx
./changelog
one appliance job behind if: vars.KEEL_LXC_RUNNER == 'true'
tkldev
./changelog
test-shell
keel-odoo
./changelog
no .github/ at all
keel-moodle
./changelog
no .github/ at all
keel-ejabberd
./changelog
no .github/ at all
keel-nginx-php-fastcgi
./changelog
no .github/ at all
keel-core is the serious one: it is the parent of every appliance layer,
and its root changelog is what bt-layer records in the manifest and what make-release-deb.py turns into the release package. The fix for all seven
is the recipe form of the caller, as in keel-redis, with exempt adjusted
per repository.
Adding the gate would be a silent no-op
These five have debian/control and debian/rules but no committed debian/changelog, the version being produced at build time. bin/require-changelog returns 0 when the changelog file is absent, so
dropping the standard caller in gives a permanently green package / changelog check that asserts nothing:
Each needs a decision about where its version lives before a gate can mean
anything. The last three have no .github/workflows/ at all.
Two properties of the gate worth deciding on
exempt has drifted.keel-redis and keel-wordpress exempt \.art/; keel-mariadb, keel-nodebb, keel-postgresql and keel-apache-php do not; the three unit-* repositories exempt neither keel/ nor \.art/. The omissions are the stricter direction, so nothing
is unsafe, but an .art/ change forces a changelog bump in four recipes
and not in four others.
The gate does not gate itself, and its blast radius is the whole
organization. All 15 callers pin @main, and the job also checks out keel-linux/.github@main for bin/require-changelog at run time, so a
regression in that script silently disables the gate in all 15 consumers
at once. Keel-Linux/.github's own tests.yml runs only test-shell.
Deliberate for a tooling repository, but worth stating.
What closes this
An issue and a pull request in each of the seven repositories, wiring the
gate.
A ruling on the five that have no committed changelog: either commit one
and gate it, or record that they are not gated and why.
A ruling on whether bin/require-changelog should fail rather than pass
when the changelog it was pointed at does not exist. A gate that cannot
find its subject and reports success is the failure mode that let The build reads the staging archive without verifying it #7
happen, one level up.
Eight repositories in this organization ship something installable and do not
call the organization's
require-changelogworkflow.fabwas one of them,and that omission is the direct cause of Keel-Linux/fab#7: pull requests #4
and #5 there both changed
share/product.mk, a path the package ships, withno changelog entry, and the version was bumped at packaging time instead.
fabis wired up in Keel-Linux/fab#9. The other seven are not.This is in
trackerrather than in each repository because the question"which repositories are gated" is org-wide; the fixes are per repository and
each needs its own issue there.
Audited 2026-09-28, against the default branch of all 39 non-archived repositories
The gate is
.github/workflows/require-changelog.ymlinKeel-Linux/.github,with its logic in
bin/require-changelog. It isworkflow_callonly, so itdoes nothing unless a repository calls it. 15 repositories do.
Ships something installable, gate missing
keel-core./changelog,keel-core-19.0 (1) keeltest-shell,test-appliancekeel-nodejs-nginx./changelogappliancejob behindif: vars.KEEL_LXC_RUNNER == 'true'tkldev./changelogtest-shellkeel-odoo./changelog.github/at allkeel-moodle./changelog.github/at allkeel-ejabberd./changelog.github/at allkeel-nginx-php-fastcgi./changelog.github/at allkeel-coreis the serious one: it is the parent of every appliance layer,and its root
changelogis whatbt-layerrecords in the manifest and whatmake-release-deb.pyturns into the release package. The fix for all sevenis the recipe form of the caller, as in
keel-redis, withexemptadjustedper repository.
Adding the gate would be a silent no-op
These five have
debian/controlanddebian/rulesbut no committeddebian/changelog, the version being produced at build time.bin/require-changelogreturns 0 when the changelog file is absent, sodropping the standard caller in gives a permanently green
package / changelogcheck that asserts nothing:webmin,turnkey-chroot,tklbam,turnkey-pylib,tklbam-python-boto.Each needs a decision about where its version lives before a gate can mean
anything. The last three have no
.github/workflows/at all.Two properties of the gate worth deciding on
exempthas drifted.keel-redisandkeel-wordpressexempt\.art/;keel-mariadb,keel-nodebb,keel-postgresqlandkeel-apache-phpdo not; the threeunit-*repositories exempt neitherkeel/nor\.art/. The omissions are the stricter direction, so nothingis unsafe, but an
.art/change forces a changelog bump in four recipesand not in four others.
organization. All 15 callers pin
@main, and the job also checks outkeel-linux/.github@mainforbin/require-changelogat run time, so aregression in that script silently disables the gate in all 15 consumers
at once.
Keel-Linux/.github's owntests.ymlruns onlytest-shell.Deliberate for a tooling repository, but worth stating.
What closes this
gate.
and gate it, or record that they are not gated and why.
bin/require-changelogshould fail rather than passwhen the changelog it was pointed at does not exist. A gate that cannot
find its subject and reports success is the failure mode that let The build reads the staging archive without verifying it #7
happen, one level up.