-
Notifications
You must be signed in to change notification settings - Fork 24
No changelog or git tag for 2.7.0 #39
Copy link
Copy link
Open
Description
I see that 2.7.0 has been released on npm for a while, but there is no associated changelog or tag on the repo for me to easily see what was released. It would be great to keep these in sync so users can know what to expect from upgrades. Seeing a new npm version without an associated git tag—or other indication in the repo—also triggered some alarm bells for me around supply chain attacks, for which I had to diff the version locally to reassure myself. I've had success using semantic-release and commitlint in the past to keep the repo as the source of truth for publishing and versioning, which might be relevant.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels