From 36657c4f8bbe77d6202c10d654f4f682062439f1 Mon Sep 17 00:00:00 2001 From: devolutionsbot <31221910+devolutionsbot@users.noreply.github.com> Date: Thu, 17 Sep 2026 08:49:00 -0400 Subject: [PATCH 1/4] chore(release): prepare for publishing --- Cargo.lock | 54 ++++---- policies/rust/now-policy-api/CHANGELOG.md | 118 ++++++++++++++++++ policies/rust/now-policy-api/Cargo.toml | 4 +- .../now-policy-server-template/CHANGELOG.md | 118 ++++++++++++++++++ .../now-policy-server-template/Cargo.toml | 6 +- policies/rust/now-policy/CHANGELOG.md | 118 ++++++++++++++++++ policies/rust/now-policy/Cargo.toml | 2 +- 7 files changed, 387 insertions(+), 33 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index 2afaca0..228c722 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -55,7 +55,7 @@ checksum = "82f6aeea286b8eb4dd3431a1be1b59d290ace00f5bfd8e2a159bc2a05e2c1667" dependencies = [ "proc-macro2", "quote", - "syn 3.0.5", + "syn 3.0.6", ] [[package]] @@ -139,9 +139,9 @@ dependencies = [ [[package]] name = "cfg-if" -version = "1.0.4" +version = "1.0.5" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801" +checksum = "4e7648175b45a9a48536d676f68d918270699102aa8dab5496df06904c914600" [[package]] name = "chrono" @@ -203,7 +203,7 @@ checksum = "c6232dd377dcc64799954cbd3a9bb882e9cdc1308ccd87b1c098f1fb2eaf82a8" dependencies = [ "proc-macro2", "quote", - "syn 3.0.5", + "syn 3.0.6", ] [[package]] @@ -305,7 +305,7 @@ checksum = "9fb9654ba8355388abeb8dcb4fc62f511300867002afc858860463bdd9fe0c44" dependencies = [ "proc-macro2", "quote", - "syn 3.0.5", + "syn 3.0.6", ] [[package]] @@ -613,7 +613,7 @@ dependencies = [ [[package]] name = "now-policy" -version = "0.4.0" +version = "0.5.0" dependencies = [ "chrono", "schemars", @@ -626,7 +626,7 @@ dependencies = [ [[package]] name = "now-policy-api" -version = "0.5.0" +version = "0.6.0" dependencies = [ "chrono", "derive_more", @@ -641,7 +641,7 @@ dependencies = [ [[package]] name = "now-policy-server-template" -version = "0.5.0" +version = "0.6.0" dependencies = [ "aide", "async-trait", @@ -765,7 +765,7 @@ checksum = "92ecd8964f8453721699a1ed72037b0db49ce2f5a5138486ee89bed6f67cdf3a" dependencies = [ "proc-macro2", "quote", - "syn 3.0.5", + "syn 3.0.6", ] [[package]] @@ -913,7 +913,7 @@ checksum = "e7a5d71263a5a7d47b41f6b3f06ba276f10cc18b0931f1799f710578e2309348" dependencies = [ "proc-macro2", "quote", - "syn 3.0.5", + "syn 3.0.6", ] [[package]] @@ -1035,9 +1035,9 @@ dependencies = [ [[package]] name = "syn" -version = "3.0.5" +version = "3.0.6" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "12df2e0110f65b775f769bb17ef989067a1d931b2eb822bd4346631eeada89f9" +checksum = "8593e8e72159ed2257d083c7a454a85cbf854f37a0966d8d483aff8c8a3ebcee" dependencies = [ "proc-macro2", "quote", @@ -1052,13 +1052,13 @@ checksum = "0bf256ce5efdfa370213c1dabab5935a12e49f2c58d15e9eac2870d3b4f27263" [[package]] name = "synstructure" -version = "0.13.2" +version = "0.14.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "728a70f3dbaf5bab7f0c4b1ac8d7ae5ea60a4b5549c8a5914361c99147a709d2" +checksum = "901704edd0dfe137f1987838ee4f259e4e063c31371bdb423f7ae38ec6f77f02" dependencies = [ "proc-macro2", "quote", - "syn 2.0.119", + "syn 3.0.6", ] [[package]] @@ -1078,7 +1078,7 @@ checksum = "bc04cd3e1236dd4a98afca4569f2deb3f120e5422a4023be2cb683f8486292af" dependencies = [ "proc-macro2", "quote", - "syn 3.0.5", + "syn 3.0.6", ] [[package]] @@ -1110,7 +1110,7 @@ checksum = "78773a2a397f451582ce068015985c33193cf6dea8b74d2a639fe457b2f07b0e" dependencies = [ "proc-macro2", "quote", - "syn 3.0.5", + "syn 3.0.6", ] [[package]] @@ -1202,9 +1202,9 @@ dependencies = [ [[package]] name = "unicode-ident" -version = "1.0.24" +version = "1.0.26" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "e6e4313cd5fcd3dad5cafa179702e2b244f760991f45397d14d4ebf38247da75" +checksum = "d245f478577f809a851594d02313b640fb437e0bb33866753cff937863096954" [[package]] name = "unicode-segmentation" @@ -1280,7 +1280,7 @@ dependencies = [ "bumpalo", "proc-macro2", "quote", - "syn 3.0.5", + "syn 3.0.6", "wasm-bindgen-shared", ] @@ -1404,13 +1404,13 @@ dependencies = [ [[package]] name = "yoke-derive" -version = "0.8.2" +version = "0.8.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "de844c262c8848816172cef550288e7dc6c7b7814b4ee56b3e1553f275f1858e" +checksum = "33811428bee40dbceb6d545e95754741d17a6aef9a4849f0fd62e2ba4f412a78" dependencies = [ "proc-macro2", "quote", - "syn 2.0.119", + "syn 3.0.6", "synstructure", ] @@ -1425,13 +1425,13 @@ dependencies = [ [[package]] name = "zerofrom-derive" -version = "0.1.7" +version = "0.1.8" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "11532158c46691caf0f2593ea8358fed6bbf68a0315e80aae9bd41fbade684a1" +checksum = "f75b4683f6c7f45248d4d64056a24298c6281e0993356d7d1b4a1a962ef10d4a" dependencies = [ "proc-macro2", "quote", - "syn 2.0.119", + "syn 3.0.6", "synstructure", ] @@ -1465,7 +1465,7 @@ checksum = "34df6fc39dbd26ddc9c10e6a2984476e13acce22e64e4487636ef494369225da" dependencies = [ "proc-macro2", "quote", - "syn 3.0.5", + "syn 3.0.6", ] [[package]] diff --git a/policies/rust/now-policy-api/CHANGELOG.md b/policies/rust/now-policy-api/CHANGELOG.md index f2385e4..4e6967a 100644 --- a/policies/rust/now-policy-api/CHANGELOG.md +++ b/policies/rust/now-policy-api/CHANGELOG.md @@ -7,6 +7,124 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## Unreleased +## [[0.6.0](https://github.com/Devolutions/now-libraries/compare/now-policy-api-v0.5.0...now-policy-api-v0.6.0)] - 2026-09-17 + +### Features + +- [**breaking**] Harden and finalize the policy contract ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) + + ## Summary + + - reject duplicate JSON property names before typed .NET policy/broker + deserialization, including nested and Unicode-escape-equivalent names; + all policy input paths also reject unknown members + - expose one strict-by-definition .NET policy serializer surface: + `PolicySerializer.Options`, `Deserialize`, and the document + `ParseJson` helpers; remove redundant strict/non-strict model contexts + and entry points + - replace the eight boolean match arrays with optional scalar booleans + (`null`/omitted = unrestricted, canonical output omitted) + - canonicalize empty collection filters to omitted output; reject + duplicate collection values consistently across schemas/Rust/.NET; + preserve effective-nonempty persisted rules + - enforce operational validity windows: when both metadata bounds are + present, `ValidFrom` must be strictly earlier than `ValidUntil` by + normalized instant + - make `Constraints` valid only on Allow rules + - remove serialized `PolicyType`, `RulePrecedence`, and `PackageNames`; + precedence is fixed as lower priority first, Deny wins Allow/Deny ties, + then document order + - rename `Elevation` to `ExecutionElevation` and `Sources` to exact + `SourceNames`; runtime collection bounds match the published schemas, + and nonempty source names require exactly one manager + - make package identifiers explicit `Exact` or `Patterns` modes and + versions explicit `Exact` or semantic `Range` modes; provide atomic .NET + mode-switch APIs + - regenerate policy/draft schemas and OpenAPI 3.1 schemas with JSON + Schema null unions (no legacy `nullable`) + + `PolicyFormatVersion` remains in the compatible 1.x line. This is an + intentional pre-release package/API break with no legacy aliases or + conversion. + + ## Canonical semantics + + - boolean condition omitted or `null`: does not narrow; `false`/`true`: + exact request characteristic + - collection omitted or `[]`: does not narrow; canonical output omits + empty collections; duplicate values are invalid + - validity bound omitted or `null`: that side is unbounded; canonical + output omits it; equal or inverted two-sided windows are invalid + - brokers reject operations before `ValidFrom` or after `ValidUntil` on + every request, with no fallback policy + - `PackageIdentifiers.Exact`: validated stable identifiers; wildcard + characters rejected + - `PackageIdentifiers.Patterns`: explicit wildcard patterns that may + authorize multiple identifiers + - `Version.Exact`: one or more arbitrary real package version strings; + `Version.Range`: semantic versions only + - `SourceNames`: exact configured source names, no URLs/pattern + matching, exactly one selected manager, at most 128 names + - `Managers`: at most 16 distinct manager values + - `ExecutionElevation`: `Elevated` when scope is Machine or requested + elevation is Elevated; `Standard` otherwise + + ## Consumer migration + + **Gateway** + - remove construction/references for `PolicyType`, `RulePrecedence`, + `PackageNames`, `Sources`, `Elevation`, `Versions`, and `VersionRange` + - replace removed model serializer APIs with + `PolicySerializer.Deserialize` or the document `ParseJson` helpers + - preserve fixed evaluator precedence and remove the old PackageNames + fail-closed branch/tests + - assume constraints are absent on Deny rules + - compute `ExecutionElevation` exactly from Machine scope or requested + elevation + - implement `SourceNames`, package identifier modes, and version modes + - retain per-request UTC validity enforcement with no fallback and add + exact `ValidFrom`/`ValidUntil` boundary tests if missing + + **UniGetUI** + - remove old field display/edit/help; show constraints only for Allow + rules + - replace removed model serializer APIs with + `PolicySerializer.Deserialize` or the document `ParseJson` helpers + - keep friendly-name search only as a UI lookup that resolves stable + identifiers + - auto-generate unique priorities by visible order + - use date/time controls with inline `ValidFrom < ValidUntil` validation + - incomplete blank rules may exist transiently in the editor but must + never be serialized/saved + + ## Validation + + - .NET 9: Model **174/174**, Client **262/262** + - .NET 10: Model **174/174**, Client **262/262** + - Rust: `now-policy` **36/36**, `now-policy-api` **18/18**, server + **7/7**, server samples **28/28** + - clippy `-D warnings`, dotnet/cargo formatting, deterministic + schema/OpenAPI regeneration + - Cargo package verification for model/API/server and NuGet pack for + Model/API/Client + - reflection-disabled NativeAOT smoke covering duplicate rejection, + validity windows, and canonical contract paths + - GPT-6 Astra full review and follow-ups; all material findings + addressed, final confirmation clean + + ## Release impact + + Required coordinated Rust releases: `now-policy` **0.5.0**, + `now-policy-api` **0.6.0** (updating its `now-policy` dependency), and + `now-policy-server-template` **0.6.0**. Publish the Model/API/Client + NuGets together using the next date-based workflow version (validated + with **2026.09.17.0**, normalized to **2026.9.17**). No release, package + publication, merge, or auto-merge is included. + + --------- + + + ## [[0.5.0](https://github.com/Devolutions/now-libraries/compare/now-policy-api-v0.4.0...now-policy-api-v0.5.0)] - 2026-09-15 ### Features diff --git a/policies/rust/now-policy-api/Cargo.toml b/policies/rust/now-policy-api/Cargo.toml index 1e4293c..23b06bc 100644 --- a/policies/rust/now-policy-api/Cargo.toml +++ b/policies/rust/now-policy-api/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "now-policy-api" -version = "0.5.0" +version = "0.6.0" edition = "2024" license.workspace = true homepage.workspace = true @@ -16,7 +16,7 @@ workspace = true [dependencies] chrono = { version = "0.4", features = ["serde"] } derive_more = { version = "2", features = ["as_ref", "deref", "display", "from"] } -now-policy = { version = "0.4", path = "../now-policy" } +now-policy = { version = "0.5", path = "../now-policy" } schemars = { version = "0.9", features = ["chrono04"] } semver = "1" serde = { version = "1", features = ["derive"] } diff --git a/policies/rust/now-policy-server-template/CHANGELOG.md b/policies/rust/now-policy-server-template/CHANGELOG.md index 8fa18e6..b885253 100644 --- a/policies/rust/now-policy-server-template/CHANGELOG.md +++ b/policies/rust/now-policy-server-template/CHANGELOG.md @@ -7,6 +7,124 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## Unreleased +## [[0.6.0](https://github.com/Devolutions/now-libraries/compare/now-policy-server-template-v0.5.0...now-policy-server-template-v0.6.0)] - 2026-09-17 + +### Features + +- [**breaking**] Harden and finalize the policy contract ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) + + ## Summary + + - reject duplicate JSON property names before typed .NET policy/broker + deserialization, including nested and Unicode-escape-equivalent names; + all policy input paths also reject unknown members + - expose one strict-by-definition .NET policy serializer surface: + `PolicySerializer.Options`, `Deserialize`, and the document + `ParseJson` helpers; remove redundant strict/non-strict model contexts + and entry points + - replace the eight boolean match arrays with optional scalar booleans + (`null`/omitted = unrestricted, canonical output omitted) + - canonicalize empty collection filters to omitted output; reject + duplicate collection values consistently across schemas/Rust/.NET; + preserve effective-nonempty persisted rules + - enforce operational validity windows: when both metadata bounds are + present, `ValidFrom` must be strictly earlier than `ValidUntil` by + normalized instant + - make `Constraints` valid only on Allow rules + - remove serialized `PolicyType`, `RulePrecedence`, and `PackageNames`; + precedence is fixed as lower priority first, Deny wins Allow/Deny ties, + then document order + - rename `Elevation` to `ExecutionElevation` and `Sources` to exact + `SourceNames`; runtime collection bounds match the published schemas, + and nonempty source names require exactly one manager + - make package identifiers explicit `Exact` or `Patterns` modes and + versions explicit `Exact` or semantic `Range` modes; provide atomic .NET + mode-switch APIs + - regenerate policy/draft schemas and OpenAPI 3.1 schemas with JSON + Schema null unions (no legacy `nullable`) + + `PolicyFormatVersion` remains in the compatible 1.x line. This is an + intentional pre-release package/API break with no legacy aliases or + conversion. + + ## Canonical semantics + + - boolean condition omitted or `null`: does not narrow; `false`/`true`: + exact request characteristic + - collection omitted or `[]`: does not narrow; canonical output omits + empty collections; duplicate values are invalid + - validity bound omitted or `null`: that side is unbounded; canonical + output omits it; equal or inverted two-sided windows are invalid + - brokers reject operations before `ValidFrom` or after `ValidUntil` on + every request, with no fallback policy + - `PackageIdentifiers.Exact`: validated stable identifiers; wildcard + characters rejected + - `PackageIdentifiers.Patterns`: explicit wildcard patterns that may + authorize multiple identifiers + - `Version.Exact`: one or more arbitrary real package version strings; + `Version.Range`: semantic versions only + - `SourceNames`: exact configured source names, no URLs/pattern + matching, exactly one selected manager, at most 128 names + - `Managers`: at most 16 distinct manager values + - `ExecutionElevation`: `Elevated` when scope is Machine or requested + elevation is Elevated; `Standard` otherwise + + ## Consumer migration + + **Gateway** + - remove construction/references for `PolicyType`, `RulePrecedence`, + `PackageNames`, `Sources`, `Elevation`, `Versions`, and `VersionRange` + - replace removed model serializer APIs with + `PolicySerializer.Deserialize` or the document `ParseJson` helpers + - preserve fixed evaluator precedence and remove the old PackageNames + fail-closed branch/tests + - assume constraints are absent on Deny rules + - compute `ExecutionElevation` exactly from Machine scope or requested + elevation + - implement `SourceNames`, package identifier modes, and version modes + - retain per-request UTC validity enforcement with no fallback and add + exact `ValidFrom`/`ValidUntil` boundary tests if missing + + **UniGetUI** + - remove old field display/edit/help; show constraints only for Allow + rules + - replace removed model serializer APIs with + `PolicySerializer.Deserialize` or the document `ParseJson` helpers + - keep friendly-name search only as a UI lookup that resolves stable + identifiers + - auto-generate unique priorities by visible order + - use date/time controls with inline `ValidFrom < ValidUntil` validation + - incomplete blank rules may exist transiently in the editor but must + never be serialized/saved + + ## Validation + + - .NET 9: Model **174/174**, Client **262/262** + - .NET 10: Model **174/174**, Client **262/262** + - Rust: `now-policy` **36/36**, `now-policy-api` **18/18**, server + **7/7**, server samples **28/28** + - clippy `-D warnings`, dotnet/cargo formatting, deterministic + schema/OpenAPI regeneration + - Cargo package verification for model/API/server and NuGet pack for + Model/API/Client + - reflection-disabled NativeAOT smoke covering duplicate rejection, + validity windows, and canonical contract paths + - GPT-6 Astra full review and follow-ups; all material findings + addressed, final confirmation clean + + ## Release impact + + Required coordinated Rust releases: `now-policy` **0.5.0**, + `now-policy-api` **0.6.0** (updating its `now-policy` dependency), and + `now-policy-server-template` **0.6.0**. Publish the Model/API/Client + NuGets together using the next date-based workflow version (validated + with **2026.09.17.0**, normalized to **2026.9.17**). No release, package + publication, merge, or auto-merge is included. + + --------- + + + ## [[0.5.0](https://github.com/Devolutions/now-libraries/compare/now-policy-server-template-v0.4.0...now-policy-server-template-v0.5.0)] - 2026-09-15 ### Features diff --git a/policies/rust/now-policy-server-template/Cargo.toml b/policies/rust/now-policy-server-template/Cargo.toml index 43d8ef7..d7f754b 100644 --- a/policies/rust/now-policy-server-template/Cargo.toml +++ b/policies/rust/now-policy-server-template/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "now-policy-server-template" -version = "0.5.0" +version = "0.6.0" edition = "2024" license.workspace = true homepage.workspace = true @@ -17,8 +17,8 @@ workspace = true aide = { version = "0.15", features = ["axum", "axum-json"] } async-trait = "0.1" axum = { version = "0.8", default-features = false, features = ["json"] } -now-policy-api = { version = "0.5", path = "../now-policy-api" } -now-policy = { version = "0.4", path = "../now-policy" } +now-policy-api = { version = "0.6", path = "../now-policy-api" } +now-policy = { version = "0.5", path = "../now-policy" } schemars = "0.9" serde = { version = "1", features = ["derive"] } serde_json = "1" diff --git a/policies/rust/now-policy/CHANGELOG.md b/policies/rust/now-policy/CHANGELOG.md index c1b5c2f..5d6576a 100644 --- a/policies/rust/now-policy/CHANGELOG.md +++ b/policies/rust/now-policy/CHANGELOG.md @@ -7,6 +7,124 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## Unreleased +## [[0.5.0](https://github.com/Devolutions/now-libraries/compare/now-policy-v0.4.0...now-policy-v0.5.0)] - 2026-09-17 + +### Features + +- [**breaking**] Harden and finalize the policy contract ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) + + ## Summary + + - reject duplicate JSON property names before typed .NET policy/broker + deserialization, including nested and Unicode-escape-equivalent names; + all policy input paths also reject unknown members + - expose one strict-by-definition .NET policy serializer surface: + `PolicySerializer.Options`, `Deserialize`, and the document + `ParseJson` helpers; remove redundant strict/non-strict model contexts + and entry points + - replace the eight boolean match arrays with optional scalar booleans + (`null`/omitted = unrestricted, canonical output omitted) + - canonicalize empty collection filters to omitted output; reject + duplicate collection values consistently across schemas/Rust/.NET; + preserve effective-nonempty persisted rules + - enforce operational validity windows: when both metadata bounds are + present, `ValidFrom` must be strictly earlier than `ValidUntil` by + normalized instant + - make `Constraints` valid only on Allow rules + - remove serialized `PolicyType`, `RulePrecedence`, and `PackageNames`; + precedence is fixed as lower priority first, Deny wins Allow/Deny ties, + then document order + - rename `Elevation` to `ExecutionElevation` and `Sources` to exact + `SourceNames`; runtime collection bounds match the published schemas, + and nonempty source names require exactly one manager + - make package identifiers explicit `Exact` or `Patterns` modes and + versions explicit `Exact` or semantic `Range` modes; provide atomic .NET + mode-switch APIs + - regenerate policy/draft schemas and OpenAPI 3.1 schemas with JSON + Schema null unions (no legacy `nullable`) + + `PolicyFormatVersion` remains in the compatible 1.x line. This is an + intentional pre-release package/API break with no legacy aliases or + conversion. + + ## Canonical semantics + + - boolean condition omitted or `null`: does not narrow; `false`/`true`: + exact request characteristic + - collection omitted or `[]`: does not narrow; canonical output omits + empty collections; duplicate values are invalid + - validity bound omitted or `null`: that side is unbounded; canonical + output omits it; equal or inverted two-sided windows are invalid + - brokers reject operations before `ValidFrom` or after `ValidUntil` on + every request, with no fallback policy + - `PackageIdentifiers.Exact`: validated stable identifiers; wildcard + characters rejected + - `PackageIdentifiers.Patterns`: explicit wildcard patterns that may + authorize multiple identifiers + - `Version.Exact`: one or more arbitrary real package version strings; + `Version.Range`: semantic versions only + - `SourceNames`: exact configured source names, no URLs/pattern + matching, exactly one selected manager, at most 128 names + - `Managers`: at most 16 distinct manager values + - `ExecutionElevation`: `Elevated` when scope is Machine or requested + elevation is Elevated; `Standard` otherwise + + ## Consumer migration + + **Gateway** + - remove construction/references for `PolicyType`, `RulePrecedence`, + `PackageNames`, `Sources`, `Elevation`, `Versions`, and `VersionRange` + - replace removed model serializer APIs with + `PolicySerializer.Deserialize` or the document `ParseJson` helpers + - preserve fixed evaluator precedence and remove the old PackageNames + fail-closed branch/tests + - assume constraints are absent on Deny rules + - compute `ExecutionElevation` exactly from Machine scope or requested + elevation + - implement `SourceNames`, package identifier modes, and version modes + - retain per-request UTC validity enforcement with no fallback and add + exact `ValidFrom`/`ValidUntil` boundary tests if missing + + **UniGetUI** + - remove old field display/edit/help; show constraints only for Allow + rules + - replace removed model serializer APIs with + `PolicySerializer.Deserialize` or the document `ParseJson` helpers + - keep friendly-name search only as a UI lookup that resolves stable + identifiers + - auto-generate unique priorities by visible order + - use date/time controls with inline `ValidFrom < ValidUntil` validation + - incomplete blank rules may exist transiently in the editor but must + never be serialized/saved + + ## Validation + + - .NET 9: Model **174/174**, Client **262/262** + - .NET 10: Model **174/174**, Client **262/262** + - Rust: `now-policy` **36/36**, `now-policy-api` **18/18**, server + **7/7**, server samples **28/28** + - clippy `-D warnings`, dotnet/cargo formatting, deterministic + schema/OpenAPI regeneration + - Cargo package verification for model/API/server and NuGet pack for + Model/API/Client + - reflection-disabled NativeAOT smoke covering duplicate rejection, + validity windows, and canonical contract paths + - GPT-6 Astra full review and follow-ups; all material findings + addressed, final confirmation clean + + ## Release impact + + Required coordinated Rust releases: `now-policy` **0.5.0**, + `now-policy-api` **0.6.0** (updating its `now-policy` dependency), and + `now-policy-server-template` **0.6.0**. Publish the Model/API/Client + NuGets together using the next date-based workflow version (validated + with **2026.09.17.0**, normalized to **2026.9.17**). No release, package + publication, merge, or auto-merge is included. + + --------- + + + ## [[0.4.0](https://github.com/Devolutions/now-libraries/compare/now-policy-v0.3.0...now-policy-v0.4.0)] - 2026-09-15 ### Features diff --git a/policies/rust/now-policy/Cargo.toml b/policies/rust/now-policy/Cargo.toml index 94ef10a..cd85d76 100644 --- a/policies/rust/now-policy/Cargo.toml +++ b/policies/rust/now-policy/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "now-policy" -version = "0.4.0" +version = "0.5.0" edition = "2024" license.workspace = true homepage.workspace = true From 35da32fa1b912b74e246c1d248ae737d5d12137c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Beno=C3=AEt=20CORTIER?= Date: Thu, 17 Sep 2026 22:31:48 +0900 Subject: [PATCH 2/4] chore(release): clean policy changelogs Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- policies/rust/now-policy-api/CHANGELOG.md | 114 +---------------- .../now-policy-server-template/CHANGELOG.md | 113 +---------------- policies/rust/now-policy/CHANGELOG.md | 120 ++---------------- 3 files changed, 14 insertions(+), 333 deletions(-) diff --git a/policies/rust/now-policy-api/CHANGELOG.md b/policies/rust/now-policy-api/CHANGELOG.md index 4e6967a..03be0e2 100644 --- a/policies/rust/now-policy-api/CHANGELOG.md +++ b/policies/rust/now-policy-api/CHANGELOG.md @@ -11,117 +11,9 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Features -- [**breaking**] Harden and finalize the policy contract ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) - - ## Summary - - - reject duplicate JSON property names before typed .NET policy/broker - deserialization, including nested and Unicode-escape-equivalent names; - all policy input paths also reject unknown members - - expose one strict-by-definition .NET policy serializer surface: - `PolicySerializer.Options`, `Deserialize`, and the document - `ParseJson` helpers; remove redundant strict/non-strict model contexts - and entry points - - replace the eight boolean match arrays with optional scalar booleans - (`null`/omitted = unrestricted, canonical output omitted) - - canonicalize empty collection filters to omitted output; reject - duplicate collection values consistently across schemas/Rust/.NET; - preserve effective-nonempty persisted rules - - enforce operational validity windows: when both metadata bounds are - present, `ValidFrom` must be strictly earlier than `ValidUntil` by - normalized instant - - make `Constraints` valid only on Allow rules - - remove serialized `PolicyType`, `RulePrecedence`, and `PackageNames`; - precedence is fixed as lower priority first, Deny wins Allow/Deny ties, - then document order - - rename `Elevation` to `ExecutionElevation` and `Sources` to exact - `SourceNames`; runtime collection bounds match the published schemas, - and nonempty source names require exactly one manager - - make package identifiers explicit `Exact` or `Patterns` modes and - versions explicit `Exact` or semantic `Range` modes; provide atomic .NET - mode-switch APIs - - regenerate policy/draft schemas and OpenAPI 3.1 schemas with JSON - Schema null unions (no legacy `nullable`) - - `PolicyFormatVersion` remains in the compatible 1.x line. This is an - intentional pre-release package/API break with no legacy aliases or - conversion. - - ## Canonical semantics - - - boolean condition omitted or `null`: does not narrow; `false`/`true`: - exact request characteristic - - collection omitted or `[]`: does not narrow; canonical output omits - empty collections; duplicate values are invalid - - validity bound omitted or `null`: that side is unbounded; canonical - output omits it; equal or inverted two-sided windows are invalid - - brokers reject operations before `ValidFrom` or after `ValidUntil` on - every request, with no fallback policy - - `PackageIdentifiers.Exact`: validated stable identifiers; wildcard - characters rejected - - `PackageIdentifiers.Patterns`: explicit wildcard patterns that may - authorize multiple identifiers - - `Version.Exact`: one or more arbitrary real package version strings; - `Version.Range`: semantic versions only - - `SourceNames`: exact configured source names, no URLs/pattern - matching, exactly one selected manager, at most 128 names - - `Managers`: at most 16 distinct manager values - - `ExecutionElevation`: `Elevated` when scope is Machine or requested - elevation is Elevated; `Standard` otherwise - - ## Consumer migration - - **Gateway** - - remove construction/references for `PolicyType`, `RulePrecedence`, - `PackageNames`, `Sources`, `Elevation`, `Versions`, and `VersionRange` - - replace removed model serializer APIs with - `PolicySerializer.Deserialize` or the document `ParseJson` helpers - - preserve fixed evaluator precedence and remove the old PackageNames - fail-closed branch/tests - - assume constraints are absent on Deny rules - - compute `ExecutionElevation` exactly from Machine scope or requested - elevation - - implement `SourceNames`, package identifier modes, and version modes - - retain per-request UTC validity enforcement with no fallback and add - exact `ValidFrom`/`ValidUntil` boundary tests if missing - - **UniGetUI** - - remove old field display/edit/help; show constraints only for Allow - rules - - replace removed model serializer APIs with - `PolicySerializer.Deserialize` or the document `ParseJson` helpers - - keep friendly-name search only as a UI lookup that resolves stable - identifiers - - auto-generate unique priorities by visible order - - use date/time controls with inline `ValidFrom < ValidUntil` validation - - incomplete blank rules may exist transiently in the editor but must - never be serialized/saved - - ## Validation - - - .NET 9: Model **174/174**, Client **262/262** - - .NET 10: Model **174/174**, Client **262/262** - - Rust: `now-policy` **36/36**, `now-policy-api` **18/18**, server - **7/7**, server samples **28/28** - - clippy `-D warnings`, dotnet/cargo formatting, deterministic - schema/OpenAPI regeneration - - Cargo package verification for model/API/server and NuGet pack for - Model/API/Client - - reflection-disabled NativeAOT smoke covering duplicate rejection, - validity windows, and canonical contract paths - - GPT-6 Astra full review and follow-ups; all material findings - addressed, final confirmation clean - - ## Release impact - - Required coordinated Rust releases: `now-policy` **0.5.0**, - `now-policy-api` **0.6.0** (updating its `now-policy` dependency), and - `now-policy-server-template` **0.6.0**. Publish the Model/API/Client - NuGets together using the next date-based workflow version (validated - with **2026.09.17.0**, normalized to **2026.9.17**). No release, package - publication, merge, or auto-merge is included. - - --------- +- [**breaking**] Update policy-bearing API models and OpenAPI schemas to the `now-policy` 0.5 policy document contract ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- [**breaking**] Remove `PolicyFindingCode::IneffectiveBooleanMatch` and `PolicyFindingCode::UnsupportedPolicyType` ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- Represent nullable values in the published OpenAPI schema with OpenAPI 3.1 type unions instead of the legacy `nullable` keyword ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) diff --git a/policies/rust/now-policy-server-template/CHANGELOG.md b/policies/rust/now-policy-server-template/CHANGELOG.md index b885253..cdee4f7 100644 --- a/policies/rust/now-policy-server-template/CHANGELOG.md +++ b/policies/rust/now-policy-server-template/CHANGELOG.md @@ -11,117 +11,8 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Features -- [**breaking**] Harden and finalize the policy contract ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) - - ## Summary - - - reject duplicate JSON property names before typed .NET policy/broker - deserialization, including nested and Unicode-escape-equivalent names; - all policy input paths also reject unknown members - - expose one strict-by-definition .NET policy serializer surface: - `PolicySerializer.Options`, `Deserialize`, and the document - `ParseJson` helpers; remove redundant strict/non-strict model contexts - and entry points - - replace the eight boolean match arrays with optional scalar booleans - (`null`/omitted = unrestricted, canonical output omitted) - - canonicalize empty collection filters to omitted output; reject - duplicate collection values consistently across schemas/Rust/.NET; - preserve effective-nonempty persisted rules - - enforce operational validity windows: when both metadata bounds are - present, `ValidFrom` must be strictly earlier than `ValidUntil` by - normalized instant - - make `Constraints` valid only on Allow rules - - remove serialized `PolicyType`, `RulePrecedence`, and `PackageNames`; - precedence is fixed as lower priority first, Deny wins Allow/Deny ties, - then document order - - rename `Elevation` to `ExecutionElevation` and `Sources` to exact - `SourceNames`; runtime collection bounds match the published schemas, - and nonempty source names require exactly one manager - - make package identifiers explicit `Exact` or `Patterns` modes and - versions explicit `Exact` or semantic `Range` modes; provide atomic .NET - mode-switch APIs - - regenerate policy/draft schemas and OpenAPI 3.1 schemas with JSON - Schema null unions (no legacy `nullable`) - - `PolicyFormatVersion` remains in the compatible 1.x line. This is an - intentional pre-release package/API break with no legacy aliases or - conversion. - - ## Canonical semantics - - - boolean condition omitted or `null`: does not narrow; `false`/`true`: - exact request characteristic - - collection omitted or `[]`: does not narrow; canonical output omits - empty collections; duplicate values are invalid - - validity bound omitted or `null`: that side is unbounded; canonical - output omits it; equal or inverted two-sided windows are invalid - - brokers reject operations before `ValidFrom` or after `ValidUntil` on - every request, with no fallback policy - - `PackageIdentifiers.Exact`: validated stable identifiers; wildcard - characters rejected - - `PackageIdentifiers.Patterns`: explicit wildcard patterns that may - authorize multiple identifiers - - `Version.Exact`: one or more arbitrary real package version strings; - `Version.Range`: semantic versions only - - `SourceNames`: exact configured source names, no URLs/pattern - matching, exactly one selected manager, at most 128 names - - `Managers`: at most 16 distinct manager values - - `ExecutionElevation`: `Elevated` when scope is Machine or requested - elevation is Elevated; `Standard` otherwise - - ## Consumer migration - - **Gateway** - - remove construction/references for `PolicyType`, `RulePrecedence`, - `PackageNames`, `Sources`, `Elevation`, `Versions`, and `VersionRange` - - replace removed model serializer APIs with - `PolicySerializer.Deserialize` or the document `ParseJson` helpers - - preserve fixed evaluator precedence and remove the old PackageNames - fail-closed branch/tests - - assume constraints are absent on Deny rules - - compute `ExecutionElevation` exactly from Machine scope or requested - elevation - - implement `SourceNames`, package identifier modes, and version modes - - retain per-request UTC validity enforcement with no fallback and add - exact `ValidFrom`/`ValidUntil` boundary tests if missing - - **UniGetUI** - - remove old field display/edit/help; show constraints only for Allow - rules - - replace removed model serializer APIs with - `PolicySerializer.Deserialize` or the document `ParseJson` helpers - - keep friendly-name search only as a UI lookup that resolves stable - identifiers - - auto-generate unique priorities by visible order - - use date/time controls with inline `ValidFrom < ValidUntil` validation - - incomplete blank rules may exist transiently in the editor but must - never be serialized/saved - - ## Validation - - - .NET 9: Model **174/174**, Client **262/262** - - .NET 10: Model **174/174**, Client **262/262** - - Rust: `now-policy` **36/36**, `now-policy-api` **18/18**, server - **7/7**, server samples **28/28** - - clippy `-D warnings`, dotnet/cargo formatting, deterministic - schema/OpenAPI regeneration - - Cargo package verification for model/API/server and NuGet pack for - Model/API/Client - - reflection-disabled NativeAOT smoke covering duplicate rejection, - validity windows, and canonical contract paths - - GPT-6 Astra full review and follow-ups; all material findings - addressed, final confirmation clean - - ## Release impact - - Required coordinated Rust releases: `now-policy` **0.5.0**, - `now-policy-api` **0.6.0** (updating its `now-policy` dependency), and - `now-policy-server-template` **0.6.0**. Publish the Model/API/Client - NuGets together using the next date-based workflow version (validated - with **2026.09.17.0**, normalized to **2026.9.17**). No release, package - publication, merge, or auto-merge is included. - - --------- +- [**breaking**] Update the re-exported policy API models to the `now-policy-api` 0.6 and `now-policy` 0.5 policy document contract ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- Generate OpenAPI documents with OpenAPI 3.1 type unions for nullable values instead of the legacy `nullable` keyword ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) diff --git a/policies/rust/now-policy/CHANGELOG.md b/policies/rust/now-policy/CHANGELOG.md index 5d6576a..5c00e0b 100644 --- a/policies/rust/now-policy/CHANGELOG.md +++ b/policies/rust/now-policy/CHANGELOG.md @@ -11,117 +11,15 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Features -- [**breaking**] Harden and finalize the policy contract ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) - - ## Summary - - - reject duplicate JSON property names before typed .NET policy/broker - deserialization, including nested and Unicode-escape-equivalent names; - all policy input paths also reject unknown members - - expose one strict-by-definition .NET policy serializer surface: - `PolicySerializer.Options`, `Deserialize`, and the document - `ParseJson` helpers; remove redundant strict/non-strict model contexts - and entry points - - replace the eight boolean match arrays with optional scalar booleans - (`null`/omitted = unrestricted, canonical output omitted) - - canonicalize empty collection filters to omitted output; reject - duplicate collection values consistently across schemas/Rust/.NET; - preserve effective-nonempty persisted rules - - enforce operational validity windows: when both metadata bounds are - present, `ValidFrom` must be strictly earlier than `ValidUntil` by - normalized instant - - make `Constraints` valid only on Allow rules - - remove serialized `PolicyType`, `RulePrecedence`, and `PackageNames`; - precedence is fixed as lower priority first, Deny wins Allow/Deny ties, - then document order - - rename `Elevation` to `ExecutionElevation` and `Sources` to exact - `SourceNames`; runtime collection bounds match the published schemas, - and nonempty source names require exactly one manager - - make package identifiers explicit `Exact` or `Patterns` modes and - versions explicit `Exact` or semantic `Range` modes; provide atomic .NET - mode-switch APIs - - regenerate policy/draft schemas and OpenAPI 3.1 schemas with JSON - Schema null unions (no legacy `nullable`) - - `PolicyFormatVersion` remains in the compatible 1.x line. This is an - intentional pre-release package/API break with no legacy aliases or - conversion. - - ## Canonical semantics - - - boolean condition omitted or `null`: does not narrow; `false`/`true`: - exact request characteristic - - collection omitted or `[]`: does not narrow; canonical output omits - empty collections; duplicate values are invalid - - validity bound omitted or `null`: that side is unbounded; canonical - output omits it; equal or inverted two-sided windows are invalid - - brokers reject operations before `ValidFrom` or after `ValidUntil` on - every request, with no fallback policy - - `PackageIdentifiers.Exact`: validated stable identifiers; wildcard - characters rejected - - `PackageIdentifiers.Patterns`: explicit wildcard patterns that may - authorize multiple identifiers - - `Version.Exact`: one or more arbitrary real package version strings; - `Version.Range`: semantic versions only - - `SourceNames`: exact configured source names, no URLs/pattern - matching, exactly one selected manager, at most 128 names - - `Managers`: at most 16 distinct manager values - - `ExecutionElevation`: `Elevated` when scope is Machine or requested - elevation is Elevated; `Standard` otherwise - - ## Consumer migration - - **Gateway** - - remove construction/references for `PolicyType`, `RulePrecedence`, - `PackageNames`, `Sources`, `Elevation`, `Versions`, and `VersionRange` - - replace removed model serializer APIs with - `PolicySerializer.Deserialize` or the document `ParseJson` helpers - - preserve fixed evaluator precedence and remove the old PackageNames - fail-closed branch/tests - - assume constraints are absent on Deny rules - - compute `ExecutionElevation` exactly from Machine scope or requested - elevation - - implement `SourceNames`, package identifier modes, and version modes - - retain per-request UTC validity enforcement with no fallback and add - exact `ValidFrom`/`ValidUntil` boundary tests if missing - - **UniGetUI** - - remove old field display/edit/help; show constraints only for Allow - rules - - replace removed model serializer APIs with - `PolicySerializer.Deserialize` or the document `ParseJson` helpers - - keep friendly-name search only as a UI lookup that resolves stable - identifiers - - auto-generate unique priorities by visible order - - use date/time controls with inline `ValidFrom < ValidUntil` validation - - incomplete blank rules may exist transiently in the editor but must - never be serialized/saved - - ## Validation - - - .NET 9: Model **174/174**, Client **262/262** - - .NET 10: Model **174/174**, Client **262/262** - - Rust: `now-policy` **36/36**, `now-policy-api` **18/18**, server - **7/7**, server samples **28/28** - - clippy `-D warnings`, dotnet/cargo formatting, deterministic - schema/OpenAPI regeneration - - Cargo package verification for model/API/server and NuGet pack for - Model/API/Client - - reflection-disabled NativeAOT smoke covering duplicate rejection, - validity windows, and canonical contract paths - - GPT-6 Astra full review and follow-ups; all material findings - addressed, final confirmation clean - - ## Release impact - - Required coordinated Rust releases: `now-policy` **0.5.0**, - `now-policy-api` **0.6.0** (updating its `now-policy` dependency), and - `now-policy-server-template` **0.6.0**. Publish the Model/API/Client - NuGets together using the next date-based workflow version (validated - with **2026.09.17.0**, normalized to **2026.9.17**). No release, package - publication, merge, or auto-merge is included. - - --------- +- [**breaking**] Remove `PolicyDocument::policy_type`, `PolicyDraftDocument::policy_type`, and `PolicyEnforcement::rule_precedence`; rule precedence is now fixed by priority, deny ties, and document order ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- [**breaking**] Replace `PolicyMatch::package_identifiers` with `Option` using exactly one `Exact` or `Patterns` mode, and remove `PolicyMatch::package_names` ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- [**breaking**] Replace `PolicyMatch::versions` and `version_range` with `version: Option`; range bounds now use `SemanticVersion` ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- [**breaking**] Rename `PolicyMatch::sources` to `source_names`, which uses exact `SourceName` values and requires exactly one manager when nonempty ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- [**breaking**] Rename `PolicyMatch::elevation` to `execution_elevation`, which matches effective execution privilege ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- [**breaking**] Change the boolean `PolicyMatch` filters from `BTreeSet` to optional scalar booleans ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- Reject duplicate values in collection match filters and omit empty filters from serialized policies ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- Reject policy metadata whose `ValidFrom` is not earlier than `ValidUntil` ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- Reject `PolicyRule::constraints` on deny rules ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) From ff9b7209cb468e454c0e81ddd04337d923ca4065 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Thu, 17 Sep 2026 13:33:27 +0000 Subject: [PATCH 3/4] chore(release): remove incorrect breaking marker in server-template changelog Co-authored-by: CBenoit <3809077+CBenoit@users.noreply.github.com> --- policies/rust/now-policy-server-template/CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/policies/rust/now-policy-server-template/CHANGELOG.md b/policies/rust/now-policy-server-template/CHANGELOG.md index cdee4f7..79373d7 100644 --- a/policies/rust/now-policy-server-template/CHANGELOG.md +++ b/policies/rust/now-policy-server-template/CHANGELOG.md @@ -11,7 +11,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Features -- [**breaking**] Update the re-exported policy API models to the `now-policy-api` 0.6 and `now-policy` 0.5 policy document contract ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- Update the re-exported policy API models to the `now-policy-api` 0.6 and `now-policy` 0.5 policy document contract ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) - Generate OpenAPI documents with OpenAPI 3.1 type unions for nullable values instead of the legacy `nullable` keyword ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) From bf1b96c24b8e12902e47b4857dacef29f5ca713c Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Thu, 17 Sep 2026 13:37:34 +0000 Subject: [PATCH 4/4] chore(release): restore breaking marker for server-template changelog Co-authored-by: CBenoit <3809077+CBenoit@users.noreply.github.com> --- policies/rust/now-policy-server-template/CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/policies/rust/now-policy-server-template/CHANGELOG.md b/policies/rust/now-policy-server-template/CHANGELOG.md index 79373d7..cdee4f7 100644 --- a/policies/rust/now-policy-server-template/CHANGELOG.md +++ b/policies/rust/now-policy-server-template/CHANGELOG.md @@ -11,7 +11,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Features -- Update the re-exported policy API models to the `now-policy-api` 0.6 and `now-policy` 0.5 policy document contract ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) +- [**breaking**] Update the re-exported policy API models to the `now-policy-api` 0.6 and `now-policy` 0.5 policy document contract ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a)) - Generate OpenAPI documents with OpenAPI 3.1 type unions for nullable values instead of the legacy `nullable` keyword ([#109](https://github.com/Devolutions/now-libraries/issues/109)) ([3ab49ad765](https://github.com/Devolutions/now-libraries/commit/3ab49ad76590c325293f50ac4129230ec2b2191a))