CycloneDX / CycloneDX/cyclonedx-core-java

Improve Release Process

Offen
#203 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
enhancement
Vorherrschende Sprache
Java
Sterne
120
Forks
90
Ø Merge
12 Std. 43 Min.
Gemergte PRs (30 T.)
18

Beschreibung

I would like to see an improved release process...

* [Releases](https://github.com/CycloneDX/cyclonedx-core-java/releases) populated with release notes. This will help repo watchers who configure customise events for "Releases" only.

* [CHANGELOG.md](https://github.com/CycloneDX/cyclonedx-core-java/blob/master/CHANGELOG.md) updated for every release (or replaced by the usage of release notes?)

* Improved uses of semantic versioning. Should not the additions to license mapping in 7.1.4 have warranted a minor release (7.2.0) instead of a patch release?

All of the above are used by dependabot PRs that update cyclonedx-core-java in downstream projects. Thus, addressing release notes (and/or changelog) should make a dependabot PR easier to review and approve. A difference in patch vs minor version can change the way that dependabot itself works.

As an additional justification, a wee story....

The release of [cyclonedx-core-java-7.1.4](https://github.com/CycloneDX/cyclonedx-core-java/releases/tag/cyclonedx-core-java-7.1.4) caused problems for me when it was included in `cyclonedx-maven-plugin` 2.7.0 and then BOMs generated using that release of the plugin resulted in displayed "License" in Dependency-Track to change for some components

Affected components were ones that use dual licensing and where one of the licenses now started to succesfully map to an SPDX license ID. Dependency-Track 4.5.0 does not support dual licences in the UI and prefers the ID over name. Hence the change of what license gets displayed. This caused me to spend a couple of hours investigating why things had changed. Bear in mind that the changes might have resulted in a policy violation.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne mit der Prüfung der Releases-Seite des Repositorys, von CHANGELOG.md und des in der Issue verlinkten Releases cyclonedx-core-java-7.1.4. Ermittle den gewünschten Workflow für Release Notes, Changelog und Semantic Versioning; die abgeschlossene Arbeit sollte für nachgelagerte Dependabot-Reviewer die Änderungen und Auswirkungen auf die Version jedes Releases klar erkennbar machen.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
github, java
Bereich
documentation, release
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.