fix: changelog provenance [skip ci] #11

Merged
rcsheets merged 3 commits from fix/changelog-provenance into main 2026-07-22 10:09:00 +00:00
Owner

Fix a few issues with the changelog generation hack, and regenerate the changelog itself

Fix a few issues with the changelog generation hack, and regenerate the changelog itself
Release entries no longer state or imply who or what wrote them. The
summarizer prompt gains a rule forbidding authorship claims (human- or
machine-written), and the CHANGELOG header now discloses, once and up top,
that entries are LLM-generated summaries of each release's commits. AGENTS.md
records that this split is intentional so a future agent does not "reconcile"
it by deleting one side.

Add hack/enstubbify.sh: the excise half of regenerating an entry. It replaces
a release's notes with a STUB (or, with --create, adds a missing section in
sorted position) so hack/backfill-changelog.sh can write a fresh summary over
it through the corrected prompt.

Move the file-editing plumbing every writer shares into changelog-lib.sh --
require_changelog, repo_url, compare_link, and replace_section_body -- so
update, backfill, and enstubbify reach into CHANGELOG.md the same way instead
of each carrying its own copy.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Collaborator

Automated review by pr-reviewer v0.37.0 | Safety Check | Claude Sonnet 5 | tracking id r-608e8f-67811e
This is an AI-generated review and may contain mistakes.

Status: ✅ Completed


⚠️ The primary review (Mistral Small) failed. The review below is from Claude Sonnet 5, which reviewed the same diff.

✅ Verdict: LGTM — Purely internal changelog-tooling refactor and regenerated changelog/doc content; no secrets, no production code changes, no obvious bugs.

This PR is a refactor of changelog tooling scripts plus a regenerated CHANGELOG.md and a new AGENTS.md note. Reviewing for anything alarming:

  • hack/changelog-lib.sh: consolidates shared helpers (require_changelog, repo_url, compare_link, replace_section_body) that were previously duplicated in update-changelog.sh and backfill-changelog.sh. The logic appears to be a faithful extraction — same awk pattern, same behavior, just deduplicated. CHANGELOG var now defaults via ${CHANGELOG:-CHANGELOG.md}, overridable for tests, which is reasonable.
  • hack/enstubbify.sh is a new script but only mutates CHANGELOG.md locally (git tag lookups, no network calls, no destructive git operations against remote). It requires a tag to exist before stubbing, which is a sane safety check.
  • No secrets, credentials, or binaries introduced. repo_url explicitly strips embedded credentials from the git remote URL before use — a good sign, not a red flag.
  • No changes to production Go code, HTTP handling, auth, or deployment configs — this is purely internal build/release tooling plus documentation/changelog content.
  • No tests added, but this matches the nature of the change (shell script refactor + content regeneration) and prior PR context suggests this is a known internal tool with lower test rigor.
  • AGENTS.md addition is just a documentation/policy note explaining an intentional discrepancy between the changelog header and the prompt instructions — not a functional change.
  • The regenerated CHANGELOG.md content is just prose; nothing suspicious like leaked secrets or malicious links.

Nothing here looks like an accidentally committed credential, a broken production code path, or a security issue. This is a safe, self-contained internal tooling change.

*Automated review by [pr-reviewer](https://git.brooktrails.org/brooktrails/pr-reviewer) v0.37.0 | Safety Check | Claude Sonnet 5 | tracking id `r-608e8f-67811e`* *This is an AI-generated review and may contain mistakes.* **Status:** ✅ Completed --- > ⚠️ The primary review (**Mistral Small**) failed. The review below is from **Claude Sonnet 5**, which reviewed the same diff. **✅ Verdict: LGTM** — Purely internal changelog-tooling refactor and regenerated changelog/doc content; no secrets, no production code changes, no obvious bugs. This PR is a refactor of changelog tooling scripts plus a regenerated CHANGELOG.md and a new AGENTS.md note. Reviewing for anything alarming: - `hack/changelog-lib.sh`: consolidates shared helpers (`require_changelog`, `repo_url`, `compare_link`, `replace_section_body`) that were previously duplicated in `update-changelog.sh` and `backfill-changelog.sh`. The logic appears to be a faithful extraction — same awk pattern, same behavior, just deduplicated. `CHANGELOG` var now defaults via `${CHANGELOG:-CHANGELOG.md}`, overridable for tests, which is reasonable. - `hack/enstubbify.sh` is a new script but only mutates CHANGELOG.md locally (git tag lookups, no network calls, no destructive git operations against remote). It requires a tag to exist before stubbing, which is a sane safety check. - No secrets, credentials, or binaries introduced. `repo_url` explicitly strips embedded credentials from the git remote URL before use — a good sign, not a red flag. - No changes to production Go code, HTTP handling, auth, or deployment configs — this is purely internal build/release tooling plus documentation/changelog content. - No tests added, but this matches the nature of the change (shell script refactor + content regeneration) and prior PR context suggests this is a known internal tool with lower test rigor. - AGENTS.md addition is just a documentation/policy note explaining an intentional discrepancy between the changelog header and the prompt instructions — not a functional change. - The regenerated CHANGELOG.md content is just prose; nothing suspicious like leaked secrets or malicious links. Nothing here looks like an accidentally committed credential, a broken production code path, or a security issue. This is a safe, self-contained internal tooling change.
rcsheets deleted branch fix/changelog-provenance 2026-07-22 10:09:00 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
brooktrails/slp!11
No description provided.