Skip to content

Create a verified changelog and reuse the existing security release-notes structure #115

Description

@jmanico

Reviewed 2026-09-25 (America/Los_Angeles) against main at bd249f5. Execution order and cross-issue ownership: #169. Batch 05.

This scope replaces the dated implementation prescriptions in the original report and earlier comments; linked historical evidence remains useful but must be rechecked before implementation.

Current state

README News now includes 1.4.1 security fixes and merged 1.5 changes. releases/1.4.1.md already provides a structured release record with coordinates and verification, so a template should build on it. Central is still pending (#111).

  • Seed CHANGELOG.md from verified tags/releases, merged PRs and existing News entries, preserving historical Java/API/packaging compatibility facts. Do not infer releases from open proposals.
  • Keep Unreleased at 1.5.0 and include only merged changes; Add XML 1.1 tags and EL functions to both taglibs #168 remains pending until merge. Distinguish the GitHub 1.4.1 release from Central availability.
  • Extract a reusable notes template into existing release documentation: highlights/security, compatibility, categorized changes, coordinates, verification and publication status.
  • Coordinate Rewrite the README and context guide, incorporating #114 and current 1.5 contracts #128's README shortening while preserving the prominent upgrade warning and links. Do not modify historical signed assets/tags to match formatting.
  • Record whether historical GitHub release titles/missing entries need metadata-only cleanup; preserve dates and provenance. Any update to 1.4.1 notes must retain security and pending-publication details until verified otherwise.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: docsConsumer/contributor documentation and project metadata.documentationpriority: P2Planned maintenance; follow the ordered batch and documented dependencies.triage: readyScope reviewed; actionable within its batch, subject to the normal PR process.

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions