Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

publish email: Include changelog info for the published version #3695

Closed
kevmoo opened this issue Jun 9, 2020 · 3 comments
Closed

publish email: Include changelog info for the published version #3695

kevmoo opened this issue Jun 9, 2020 · 3 comments

Comments

@kevmoo
Copy link
Member

kevmoo commented Jun 9, 2020

now that we can parse the changelog, it'd be great to get the changelog details for the published release!

@jonasfj jonasfj added this to the On Deck milestone Jun 9, 2020
@jonasfj
Copy link
Member

jonasfj commented Jun 9, 2020

We send these emails to enable package owners to discover malicious publishing events, in case their account is compromised.

Allowing a potential attacker to define a section of the email is probably not a huge concern. As coming up with a fake/innocent CHANGELOG entry can be hard.

But we should note that the purpose of these emails is not to notify people who are interested in updates about a package.

@kevmoo
Copy link
Member Author

kevmoo commented Jun 9, 2020

But we should note that the purpose of these emails is not to notify people who are interested in updates about a package.

Yup. But I've noticed that these end up being FYI emails that someone else on my team has published something. I end up clicking and going to the changelog to see what's new

@isoos
Copy link
Collaborator

isoos commented Oct 30, 2020

Duplicate of #2028, closing this.

@isoos isoos closed this as completed Oct 30, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants