diff --git a/developer_manual/release-process/manual.rst b/developer_manual/release-process/manual.rst index 8b92f17..25d3838 100644 --- a/developer_manual/release-process/manual.rst +++ b/developer_manual/release-process/manual.rst @@ -14,7 +14,7 @@ Download the verified ``release-tool.phar`` version used by ``LibreCodeCoop/gith .. code-block:: bash php release-tool.phar config:validate --config .nextcloud-release.yml --root . --json - php release-tool.phar release:plan --config .nextcloud-release.yml --root . --branch stableXX --channel final --mode normal --json + php release-tool.phar release:plan --config .nextcloud-release.yml --root . --branch stableXX --channel final --json The plan output should identify the previous reachable release tag, exact planning SHA, proposed version, target per-major changelog, milestone and blockers. @@ -42,4 +42,4 @@ Recovery rules * If the release branch advances after the release PR merge, do not create the draft from the old finalized state. * If publication fails, fix the publisher problem and rerun verification. Do not reinterpret or regenerate release notes. * If a tag/release points to the wrong commit, repair the GitHub Release/tag identity before publication verification can succeed. -* For security mode, never put advisory-private details in workflow inputs, changelog text, artifacts or public documentation. +* Keep confidential security work in the repository security advisory temporary private fork. Once the fix is public, its Conventional Commit / pull request title must be safe to publish; never put advisory-private details in public pull request titles, workflow inputs, changelog text, artifacts or public documentation. diff --git a/developer_manual/release-process/preparing.rst b/developer_manual/release-process/preparing.rst index 57a7f7c..791e14d 100644 --- a/developer_manual/release-process/preparing.rst +++ b/developer_manual/release-process/preparing.rst @@ -29,11 +29,14 @@ Inputs ``create_follow_up_milestone`` Whether a follow-up milestone should be created during the post-merge transition. -``mode`` - ``normal`` or ``security``. +Security fixes +-------------- -``safe_public_text`` - Public-safe wording for security mode. Advisory-private details must not be put in public release text. +Security fixes must be developed through the repository security advisory flow and, while confidential, in its temporary private fork. + +When the fix reaches the public repository, its Conventional Commit / pull request title must already be safe to publish. The release tool treats that public title like any other release activity, so a ``fix: ...`` entry remains under ``Fixed`` and does not require a special release mode or a public security label. + +Do not put advisory-private details in public pull request titles, changelog text, workflow inputs, artifacts or public documentation. Publish the advisory according to the coordinated disclosure plan once the patched release is ready. Generated PR ------------