Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions developer_manual/release-process/manual.rst
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ Download the verified ``release-tool.phar`` version used by ``LibreCodeCoop/gith
.. code-block:: bash

php release-tool.phar config:validate --config .nextcloud-release.yml --root . --json
php release-tool.phar release:plan --config .nextcloud-release.yml --root . --branch stableXX --channel final --mode normal --json
php release-tool.phar release:plan --config .nextcloud-release.yml --root . --branch stableXX --channel final --json

The plan output should identify the previous reachable release tag, exact planning SHA, proposed version, target per-major changelog, milestone and blockers.

Expand Down Expand Up @@ -42,4 +42,4 @@ Recovery rules
* If the release branch advances after the release PR merge, do not create the draft from the old finalized state.
* If publication fails, fix the publisher problem and rerun verification. Do not reinterpret or regenerate release notes.
* If a tag/release points to the wrong commit, repair the GitHub Release/tag identity before publication verification can succeed.
* For security mode, never put advisory-private details in workflow inputs, changelog text, artifacts or public documentation.
* Keep confidential security work in the repository security advisory temporary private fork. Once the fix is public, its Conventional Commit / pull request title must be safe to publish; never put advisory-private details in public pull request titles, workflow inputs, changelog text, artifacts or public documentation.
11 changes: 7 additions & 4 deletions developer_manual/release-process/preparing.rst
Original file line number Diff line number Diff line change
Expand Up @@ -29,11 +29,14 @@ Inputs
``create_follow_up_milestone``
Whether a follow-up milestone should be created during the post-merge transition.

``mode``
``normal`` or ``security``.
Security fixes
--------------

``safe_public_text``
Public-safe wording for security mode. Advisory-private details must not be put in public release text.
Security fixes must be developed through the repository security advisory flow and, while confidential, in its temporary private fork.

When the fix reaches the public repository, its Conventional Commit / pull request title must already be safe to publish. The release tool treats that public title like any other release activity, so a ``fix: ...`` entry remains under ``Fixed`` and does not require a special release mode or a public security label.

Do not put advisory-private details in public pull request titles, changelog text, workflow inputs, artifacts or public documentation. Publish the advisory according to the coordinated disclosure plan once the patched release is ready.

Generated PR
------------
Expand Down
Loading