Repository keeps a changelog
docs/changelog@v1
The repository has a changelog, so what changed between two releases is written down instead of pieced together from commits.
| Id | docs/changelog |
| Version | v1 |
| Category | docs |
| Default severity | info |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | files |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
files | Presence, size and line counts of the well known files a repository is expected to carry, plus any extra path the guardrail asks for. | path |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "docs/changelog@v1",
"severity": "info",
"with": {
"path": "CHANGELOG.md",
"minLines": "5"
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
path | Path to the changelog, relative to the directory the CLI runs in. | CHANGELOG.md | GUARDRAIL_INPUT_PATH |
minLines | How many non-blank lines it needs before it counts as kept. | 5 | GUARDRAIL_INPUT_MINLINES |
How to fix
Add a CHANGELOG.md at the repository root and update it with each release:
# Changelog
## 1.4.0
### Added
- Token rotation on the public API.
### Fixed
- Expired sessions were accepted for one further request.See Keep a Changelog. The commit log is not a changelog: commits are written for the person making the change, while the changelog is written for the people using the result.
More in docs
docs/agent-instructions. The repository has an instruction file for coding agents, long enough to say something and short enough to be read in full.docs/code-of-conduct. The repository has aCODE_OF_CONDUCT.md, so the standard contributors are held to, and who enforces it, is written down.docs/contributing. The repository has aCONTRIBUTING.mdexplaining how a change is proposed, built and reviewed.docs/license-present. The repository has a licence file, so what people may do with the code is written down, not assumed.docs/readme. The repository has a README that says more than just its title.docs/security-policy. The repository has aSECURITY.mdsaying where to report a security problem.