From 2072cd1fe3b74da46fd6de40966931d1fb1405fa Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Tue, 22 Sep 2026 18:14:03 -0300 Subject: [PATCH 1/4] docs: classify security fixes by PR label --- developer_manual/release-process/preparing.rst | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/developer_manual/release-process/preparing.rst b/developer_manual/release-process/preparing.rst index 57a7f7c..93d97b9 100644 --- a/developer_manual/release-process/preparing.rst +++ b/developer_manual/release-process/preparing.rst @@ -29,11 +29,14 @@ Inputs ``create_follow_up_milestone`` Whether a follow-up milestone should be created during the post-merge transition. -``mode`` - ``normal`` or ``security``. +Security fixes +-------------- -``safe_public_text`` - Public-safe wording for security mode. Advisory-private details must not be put in public release text. +Security is classified per pull request, not per release. + +A pull request that fixes a security issue must have a public-safe Conventional Commit title and the ``security`` label. The release tool places that pull request under the ``Security`` changelog category while preserving all other public release activity normally. + +Do not put advisory-private details in the pull request title, changelog text, workflow inputs, artifacts or public documentation. The advisory remains the source for private vulnerability details until disclosure. Generated PR ------------ From 0e61be387866e00620b7c93d8880ee0c7956caec Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Tue, 22 Sep 2026 18:14:06 -0300 Subject: [PATCH 2/4] docs: remove release-wide security mode --- developer_manual/release-process/manual.rst | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/developer_manual/release-process/manual.rst b/developer_manual/release-process/manual.rst index 8b92f17..2bd9ff7 100644 --- a/developer_manual/release-process/manual.rst +++ b/developer_manual/release-process/manual.rst @@ -14,7 +14,7 @@ Download the verified ``release-tool.phar`` version used by ``LibreCodeCoop/gith .. code-block:: bash php release-tool.phar config:validate --config .nextcloud-release.yml --root . --json - php release-tool.phar release:plan --config .nextcloud-release.yml --root . --branch stableXX --channel final --mode normal --json + php release-tool.phar release:plan --config .nextcloud-release.yml --root . --branch stableXX --channel final --json The plan output should identify the previous reachable release tag, exact planning SHA, proposed version, target per-major changelog, milestone and blockers. @@ -42,4 +42,4 @@ Recovery rules * If the release branch advances after the release PR merge, do not create the draft from the old finalized state. * If publication fails, fix the publisher problem and rerun verification. Do not reinterpret or regenerate release notes. * If a tag/release points to the wrong commit, repair the GitHub Release/tag identity before publication verification can succeed. -* For security mode, never put advisory-private details in workflow inputs, changelog text, artifacts or public documentation. +* Security fixes are classified by the ``security`` pull request label. Keep the pull request title public-safe and never put advisory-private details in pull request titles, workflow inputs, changelog text, artifacts or public documentation. From c289f5aa0b726853990473c81e8bcbe46ed9a7fd Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Tue, 22 Sep 2026 18:15:45 -0300 Subject: [PATCH 3/4] docs: keep pre-disclosure security work private --- developer_manual/release-process/preparing.rst | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/developer_manual/release-process/preparing.rst b/developer_manual/release-process/preparing.rst index 93d97b9..791e14d 100644 --- a/developer_manual/release-process/preparing.rst +++ b/developer_manual/release-process/preparing.rst @@ -32,11 +32,11 @@ Inputs Security fixes -------------- -Security is classified per pull request, not per release. +Security fixes must be developed through the repository security advisory flow and, while confidential, in its temporary private fork. -A pull request that fixes a security issue must have a public-safe Conventional Commit title and the ``security`` label. The release tool places that pull request under the ``Security`` changelog category while preserving all other public release activity normally. +When the fix reaches the public repository, its Conventional Commit / pull request title must already be safe to publish. The release tool treats that public title like any other release activity, so a ``fix: ...`` entry remains under ``Fixed`` and does not require a special release mode or a public security label. -Do not put advisory-private details in the pull request title, changelog text, workflow inputs, artifacts or public documentation. The advisory remains the source for private vulnerability details until disclosure. +Do not put advisory-private details in public pull request titles, changelog text, workflow inputs, artifacts or public documentation. Publish the advisory according to the coordinated disclosure plan once the patched release is ready. Generated PR ------------ From 42de4a67051d1b57c1af0fd6c374d42b35da219f Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Tue, 22 Sep 2026 18:15:49 -0300 Subject: [PATCH 4/4] docs: document private advisory release flow --- developer_manual/release-process/manual.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/developer_manual/release-process/manual.rst b/developer_manual/release-process/manual.rst index 2bd9ff7..25d3838 100644 --- a/developer_manual/release-process/manual.rst +++ b/developer_manual/release-process/manual.rst @@ -42,4 +42,4 @@ Recovery rules * If the release branch advances after the release PR merge, do not create the draft from the old finalized state. * If publication fails, fix the publisher problem and rerun verification. Do not reinterpret or regenerate release notes. * If a tag/release points to the wrong commit, repair the GitHub Release/tag identity before publication verification can succeed. -* Security fixes are classified by the ``security`` pull request label. Keep the pull request title public-safe and never put advisory-private details in pull request titles, workflow inputs, changelog text, artifacts or public documentation. +* Keep confidential security work in the repository security advisory temporary private fork. Once the fix is public, its Conventional Commit / pull request title must be safe to publish; never put advisory-private details in public pull request titles, workflow inputs, changelog text, artifacts or public documentation.