Skip to content

Record the stale-ref refusal in the changelog - #186

Merged
davidmckayv merged 1 commit into
mainfrom
docs/changelog-covers-the-stale-ref-refusal
Aug 22, 2026
Merged

Record the stale-ref refusal in the changelog#186
davidmckayv merged 1 commit into
mainfrom
docs/changelog-covers-the-stale-ref-refusal

Conversation

@davidmckayv

Copy link
Copy Markdown
Contributor

#183 landed without a changelog line, and it is the one of the four that most needed one: it changes what a deployment does. A click citing a ref this server holds a snapshot for and cannot resolve is now refused, where it used to be carried out with the boundary unable to see the element.

An operator upgrading past it will see refusals they did not see before. That is correct — those are the actions that were going through without the rule seeing what they touched — but meeting it with no warning reads as a regression, and the security fix underneath is invisible.

The entry says what changed, why the refusal is the fix rather than the fault, what is deliberately left untouched (actions naming no element, and a computer this deployment holds no snapshot for), and what a Bot does when it meets one.

#184 correctly has no entry: same tools, same order, same refusals. By this file's own rule a line belongs here when a deployment behaves differently afterwards, and that one does not.

#183 changes what a deployment does: a click citing a ref this server
holds a snapshot for and cannot resolve is refused where it used to be
carried out with the boundary blind to the element.

It landed without a line here. That is the one shape of omission this file
exists to prevent — an operator upgrading meets refusals nothing warned
them about, and the security fix underneath them is invisible.
@davidmckayv
davidmckayv merged commit a7f8850 into main Aug 22, 2026
8 checks passed
@davidmckayv
davidmckayv deleted the docs/changelog-covers-the-stale-ref-refusal branch August 22, 2026 21:31
@davidmckayv davidmckayv mentioned this pull request Aug 22, 2026
2 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant