Derive CHANGELOG.md into the published mirror #83

Closed
opened 2026-09-22 15:47:00 +01:00 by cruelacid · 0 comments
Owner

Part of #77. Needs the ledger (#82).

Why

The mirror is what users install from. It currently ships no changelog, and the
GitHub release notes are install instructions and a SHA-256 by design.

What to do

Generate CHANGELOG.md from docs/changelog-plugin.md in build-mirror.mjs,
the way readme() already generates the README — generated, never
hand-edited
, or the single-master property is lost.

Four places need it, and missing any one fails the build rather than shipping
half a change:

  • the stage() allowlist — clean() wipes .mirror every run, so anything not
    staged deliberately is absent;
  • the required list;
  • readme()'s documentation links;
  • PUBLIC_DOCS, if the source is referenced from under docs/.

Watch for

The FORBIDDEN substring scan, which rejects packages/server, plan-phase,
positioning.md and more. This is why the plugin ledger is separate from the
server one. Verify with node scripts/build-mirror.mjs --check.

Remember these are published comments: the mirror is public, so nothing
staged may cite a private doc.

Part of #77. Needs the ledger (#82). ## Why The mirror is what users install from. It currently ships no changelog, and the GitHub release notes are install instructions and a SHA-256 by design. ## What to do Generate `CHANGELOG.md` from `docs/changelog-plugin.md` in `build-mirror.mjs`, the way `readme()` already generates the README — **generated, never hand-edited**, or the single-master property is lost. Four places need it, and missing any one fails the build rather than shipping half a change: - the `stage()` allowlist — `clean()` wipes `.mirror` every run, so anything not staged deliberately is absent; - the `required` list; - `readme()`'s documentation links; - `PUBLIC_DOCS`, if the source is referenced from under `docs/`. ## Watch for The `FORBIDDEN` substring scan, which rejects `packages/server`, `plan-phase`, `positioning.md` and more. This is why the plugin ledger is separate from the server one. Verify with `node scripts/build-mirror.mjs --check`. Remember these are **published comments**: the mirror is public, so nothing staged may cite a private doc.
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda#83
No description provided.