Skip to content

Seeking advice from the security council on PR #69

Open
@fcollonval

Description

At JupyterLab weekly call, we discussed the PR adding a silent option to the releaser (to publish security release mainly). We would like some members of the security council to look at it and to provide some advice on the process:

jupyter-server/jupyter_releaser#526

For now, if the silent option is set, the changelog file in the repository will be updated with a placeholder instead of the list of changes and the GitHub release will stay in draft mode (with the real changelog to be included in the changelog when made public).

To limit the changelog visibility, that PR should be updated to remove the changelog from the CI job logs. But there will be still a higher visibility of the draft release compare to the advisories.

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions