Skip to content

Seven repositories that ship a package do not call require-changelog #18

Description

@marcos-mendez

Eight repositories in this organization ship something installable and do not
call the organization's require-changelog workflow. fab was one of them,
and that omission is the direct cause of Keel-Linux/fab#7: pull requests #4
and #5 there both changed share/product.mk, a path the package ships, with
no changelog entry, and the version was bumped at packaging time instead.
fab is wired up in Keel-Linux/fab#9. The other seven are not.

This is in tracker rather than in each repository because the question
"which repositories are gated" is org-wide; the fixes are per repository and
each needs its own issue there.

Audited 2026-09-28, against the default branch of all 39 non-archived repositories

The gate is .github/workflows/require-changelog.yml in Keel-Linux/.github,
with its logic in bin/require-changelog. It is workflow_call only, so it
does nothing unless a repository calls it. 15 repositories do.

Ships something installable, gate missing

Repo What it ships Workflows present
keel-core ./changelog, keel-core-19.0 (1) keel test-shell, test-appliance
keel-nodejs-nginx ./changelog one appliance job behind if: vars.KEEL_LXC_RUNNER == 'true'
tkldev ./changelog test-shell
keel-odoo ./changelog no .github/ at all
keel-moodle ./changelog no .github/ at all
keel-ejabberd ./changelog no .github/ at all
keel-nginx-php-fastcgi ./changelog no .github/ at all

keel-core is the serious one: it is the parent of every appliance layer,
and its root changelog is what bt-layer records in the manifest and what
make-release-deb.py turns into the release package. The fix for all seven
is the recipe form of the caller, as in keel-redis, with exempt adjusted
per repository.

Adding the gate would be a silent no-op

These five have debian/control and debian/rules but no committed
debian/changelog
, the version being produced at build time.
bin/require-changelog returns 0 when the changelog file is absent, so
dropping the standard caller in gives a permanently green package / changelog check that asserts nothing:

webmin, turnkey-chroot, tklbam, turnkey-pylib, tklbam-python-boto.

Each needs a decision about where its version lives before a gate can mean
anything. The last three have no .github/workflows/ at all.

Two properties of the gate worth deciding on

  • exempt has drifted. keel-redis and keel-wordpress exempt
    \.art/; keel-mariadb, keel-nodebb, keel-postgresql and
    keel-apache-php do not; the three unit-* repositories exempt neither
    keel/ nor \.art/. The omissions are the stricter direction, so nothing
    is unsafe, but an .art/ change forces a changelog bump in four recipes
    and not in four others.
  • The gate does not gate itself, and its blast radius is the whole
    organization.
    All 15 callers pin @main, and the job also checks out
    keel-linux/.github@main for bin/require-changelog at run time, so a
    regression in that script silently disables the gate in all 15 consumers
    at once. Keel-Linux/.github's own tests.yml runs only test-shell.
    Deliberate for a tooling repository, but worth stating.

What closes this

  • An issue and a pull request in each of the seven repositories, wiring the
    gate.
  • A ruling on the five that have no committed changelog: either commit one
    and gate it, or record that they are not gated and why.
  • A ruling on whether bin/require-changelog should fail rather than pass
    when the changelog it was pointed at does not exist. A gate that cannot
    find its subject and reports success is the failure mode that let The build reads the staging archive without verifying it #7
    happen, one level up.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions