3.3.0 — the core package's release notes fit nuget.org's limit - #7
Merged
Merged
Conversation
… and the gate checks it nuget.org refuses a package whose release notes run past 35,000 characters, and says so only at the push: publish.yml failed on master after PR #6 merged, with "A nuget package's ReleaseNotes property may not be more than 35000 characters long." The core package's notes were 60,284 characters; 3.2.0 had shipped at 34,310, so any 3.3.0 entry would have met it. Nothing was pushed, so 3.3.0 is still unused on nuget.org. The 3.3.0 entry stays whole. Every earlier entry is cut down to its heading, under a pointer to the releases page, which keeps the full text, and to the breaking-changes page. 28,394 characters in the packed nuspec. build/check-version.ps1 now measures the release notes of all four packages as nuget.org reads them and fails past 35,000, so the next overrun is a red check on the pull request rather than a failed release. It fails on the notes that were merged and passes on these. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Deploying doc-dynamicwhere with
|
| Latest commit: |
1d383db
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://877ed8e5.doc-dynamicwhere.pages.dev |
| Branch Preview URL: | https://fix-release-notes-length-3-3.doc-dynamicwhere.pages.dev |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The changes are low-risk and directly address the publish failure, with only minor messaging/link-format nits noted.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
This PR addresses a NuGet.org publishing failure by reducing the size of the core package release notes and adding a build-time guard to prevent any package’s <PackageReleaseNotes> from exceeding NuGet.org’s ~35,000 character limit.
Changes:
- Trims older release note entries in the core
.csprojdown to headings, keeping the full 3.3.0 entry and pointing readers to GitHub Releases and the breaking-changes page. - Extends
build/check-version.ps1to measure<PackageReleaseNotes>length for all four packages and fail early if any exceed 35,000 characters.
| File | Description |
|---|---|
| DynamicWhere.ex/DynamicWhere.ex.csproj | Shortens historical release notes and adds pointers to external pages to stay under NuGet.org limits. |
| build/check-version.ps1 | Adds a release-notes length check across all package .csproj files to fail CI before publish. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+208
to
+213
| if ($tooLong.Count -gt 0) { | ||
| Write-Host "::error::Release notes nuget.org would refuse" | ||
|
|
||
| foreach ($problem in $tooLong) { | ||
| Write-Host " $problem" | ||
| } |
| Security fix: under the convenience tier, Selects naming a navigation whose element key (Id) is denied was narrowed to the allowed fields beneath it, and the core's typed projection added the key back. Such a narrowing is refused with FieldDeniedForSelect in both tiers, as naming a sibling of the key already was. A navigation named through another, such as Main.Lead, now gates the key of Main, which the projection adds; it did not. | ||
|
|
||
| Security fix: Selects naming a member typed as a collection the core does not unwrap, such as IReadOnlyList<T>, returned every field beneath it, denied ones included, in both tiers. The projection gate read collections through a narrower list than the attribute walker that puts policy on the fields beneath; it now reads them the same way. Denials beneath a named member are also read from the policy's own rules, so a denied property with no setter and a rule on a path reached through a cycle are found, and a member carrying a field denied where no path reaches it, deeper than the walker, inside a framework collection such as Dictionary<string, T> or on a subtype, is refused under the strict tier, and under the convenience tier narrowed where the core can narrow it and refused where it cannot. | ||
| Earlier releases, in brief. The full notes of each are on the releases page, https://github.com/Sajadh92/DynamicWhere.ex/releases, and every behaviour change is on https://doc.dynamicwhere.com/docs/breaking-changes. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


The publish run for 3.3.0 failed at the push: nuget.org refuses release notes past 35,000 characters, and the core package's were 60,284. Nothing was pushed, so 3.3.0 is still unused on nuget.org. The docs site is already live from the merge of #6.
build/check-version.ps1measures the release notes of all four packages and fails past 35,000, so the next overrun is a red check on a pull request rather than a failed release. It fails on the notes that were merged and passes on these.No code change. Description, tags and title of all four packages are far inside their limits.
🤖 Generated with Claude Code