Skip to content

Release notes

Every release's page is composed from docs/releases/v<VERSION>.md, the only part written by hand. It holds a ## Highlights ⭐️ section of two to four bullets, each * **<Feature>**: <one or two plain sentences>. The release script adds GitHub's generated change list, the SHA-256 of every asset and the Full Changelog link.

A release that fixes a vulnerability

The EU Cyber Resilience Act expects a security update to say what it fixes and for which versions, and so do the people deciding whether to upgrade. A highlight that announces a fixed vulnerability:

  • starts its label with "Security fix", so it cannot be mistaken for an ordinary change;
  • names its advisory ID: the GitHub security advisory (GHSA-…), and the CVE or Go vulnerability ID (CVE-…, GO-…) where one exists;
  • states the affected versions, as Affected versions: v0.0.3 to v0.0.8.

For example:

* **Security fix: a redirect no longer carries the API key**: GHSA-xxxx-xxxx-xxxx. Affected versions: v0.0.3 to v0.0.8. Upgrade to this release; there is no workaround.

The release preflight (go run ./scripts/cra/main.go preflight) fails a highlights file where a "Security fix" names no advisory ID, or where any advisory ID comes without its affected versions.

Vulnerabilities in dependencies that do not affect passmcp

govulncheck reports vulnerabilities in passmcp's dependencies and whether passmcp's code reaches them. When a release carries a dependency with a known vulnerability that passmcp does not reach, the release attaches an OpenVEX document, passmcp.openvex.json, that says not_affected for each one, with the reason:

  • vulnerable_code_not_present: passmcp requires the module but does not import the vulnerable package;
  • vulnerable_code_not_in_execute_path: the package is imported, but no vulnerable symbol is reachable from passmcp's code.

A vulnerability passmcp does reach is affected, and is fixed before the release rather than documented. The release workflow generates and validates the document:

govulncheck -format json ./... > vuln.json
go run ./scripts/cra/main.go vex --in vuln.json \
  --product pkg:golang/satellion.com/[email protected] \
  --out passmcp.openvex.json