Skip to content

3.3.0 — the core package's release notes fit nuget.org's limit - #7

Merged
Sajadh92 merged 1 commit into
masterfrom
fix/release-notes-length-3.3.0
Sep 21, 2026
Merged

Sajadh92 merged 1 commit into
masterfrom
fix/release-notes-length-3.3.0

Conversation

@Sajadh92

Copy link
Copy Markdown
Owner

The publish run for 3.3.0 failed at the push: nuget.org refuses release notes past 35,000 characters, and the core package's were 60,284. Nothing was pushed, so 3.3.0 is still unused on nuget.org. The docs site is already live from the merge of #6.

  • The 3.3.0 entry stays whole. Earlier entries are cut down to their headings, under a pointer to the releases page and the breaking-changes page. 28,394 characters in the packed nuspec.
  • build/check-version.ps1 measures the release notes of all four packages and fails past 35,000, so the next overrun is a red check on a pull request rather than a failed release. It fails on the notes that were merged and passes on these.

No code change. Description, tags and title of all four packages are far inside their limits.

🤖 Generated with Claude Code

… and the gate checks it

nuget.org refuses a package whose release notes run past 35,000 characters, and
says so only at the push: publish.yml failed on master after PR #6 merged, with
"A nuget package's ReleaseNotes property may not be more than 35000 characters
long." The core package's notes were 60,284 characters; 3.2.0 had shipped at
34,310, so any 3.3.0 entry would have met it. Nothing was pushed, so 3.3.0 is
still unused on nuget.org.

The 3.3.0 entry stays whole. Every earlier entry is cut down to its heading,
under a pointer to the releases page, which keeps the full text, and to the
breaking-changes page. 28,394 characters in the packed nuspec.

build/check-version.ps1 now measures the release notes of all four packages as
nuget.org reads them and fails past 35,000, so the next overrun is a red check
on the pull request rather than a failed release. It fails on the notes that
were merged and passes on these.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 21, 2026 08:22
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying doc-dynamicwhere with  Cloudflare Pages  Cloudflare Pages

Latest commit: 1d383db
Status: ✅  Deploy successful!
Preview URL: https://877ed8e5.doc-dynamicwhere.pages.dev
Branch Preview URL: https://fix-release-notes-length-3-3.doc-dynamicwhere.pages.dev

View logs

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The changes are low-risk and directly address the publish failure, with only minor messaging/link-format nits noted.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

This PR addresses a NuGet.org publishing failure by reducing the size of the core package release notes and adding a build-time guard to prevent any package’s <PackageReleaseNotes> from exceeding NuGet.org’s ~35,000 character limit.

Changes:

  • Trims older release note entries in the core .csproj down to headings, keeping the full 3.3.0 entry and pointing readers to GitHub Releases and the breaking-changes page.
  • Extends build/check-version.ps1 to measure <PackageReleaseNotes> length for all four packages and fail early if any exceed 35,000 characters.
File Description
DynamicWhere.ex/​DynamicWhere.ex.csproj Shortens historical release notes and adds pointers to external pages to stay under NuGet.org limits.
build/​check-version.ps1 Adds a release-notes length check across all package .csproj files to fail CI before publish.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread build/check-version.ps1
Comment on lines +208 to +213
if ($tooLong.Count -gt 0) {
Write-Host "::error::Release notes nuget.org would refuse"

foreach ($problem in $tooLong) {
Write-Host " $problem"
}
Security fix: under the convenience tier, Selects naming a navigation whose element key (Id) is denied was narrowed to the allowed fields beneath it, and the core's typed projection added the key back. Such a narrowing is refused with FieldDeniedForSelect in both tiers, as naming a sibling of the key already was. A navigation named through another, such as Main.Lead, now gates the key of Main, which the projection adds; it did not.

Security fix: Selects naming a member typed as a collection the core does not unwrap, such as IReadOnlyList&lt;T&gt;, returned every field beneath it, denied ones included, in both tiers. The projection gate read collections through a narrower list than the attribute walker that puts policy on the fields beneath; it now reads them the same way. Denials beneath a named member are also read from the policy's own rules, so a denied property with no setter and a rule on a path reached through a cycle are found, and a member carrying a field denied where no path reaches it, deeper than the walker, inside a framework collection such as Dictionary&lt;string, T&gt; or on a subtype, is refused under the strict tier, and under the convenience tier narrowed where the core can narrow it and refused where it cannot.
Earlier releases, in brief. The full notes of each are on the releases page, https://github.com/Sajadh92/DynamicWhere.ex/releases, and every behaviour change is on https://doc.dynamicwhere.com/docs/breaking-changes.
@Sajadh92
Sajadh92 merged commit 0fdb6cb into master Sep 21, 2026
6 checks passed
@Sajadh92
Sajadh92 deleted the fix/release-notes-length-3.3.0 branch September 21, 2026 08:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants