Release v5.0.0
Breaking change: commit subjects render as literal text
Every changelog line now wraps the commit subject in an inline-code span.
before: - [f723555](.../commit/f723555) - build(deps-dev): bump @vercel/ncc to 0.45.0 (#470)
after: - [f723555](.../commit/f723555) - ` build(deps-dev): bump @vercel/ncc to 0.45.0 (#470) `
A commit subject is untrusted input. Anyone whose pull request you merge
chooses that text, and this action pastes it directly into your release notes.
Rendered as active Markdown, a subject could contribute links, images,
@mentions, issue references, raw HTML, or additional changelog entries to a
release it had no business editing. Rendering it as literal text closes that
off.
What this costs you. Subjects render monospace, and #123, GH-123, bare
commit SHAs, and :emoji: inside a subject no longer autolink. Because
GitHub's squash merge appends (#123) to the subject by default, most lines
in a typical repository lose that link. The generated commit link at the start
of each line is unaffected. Control characters, line and paragraph separators,
and bidirectional-control characters are replaced with spaces, so a subject can
never span more than its own line.
No inputs or outputs changed, and the No Changes. sentinel is unchanged.
Staying on the previous format
v4.9.0
carries every security and dependency fix in this release -- including undici
7.29.0, which closes 12 advisories -- with the v4 output format untouched. Pin
metcalfc/changelog-generator@v4 to stay there. The v4 tag will keep moving
on the maintenance line.
What is in this release
Relative to v4.9.0, v5.0.0 adds only the escaping change. Both releases share
everything else:
- Render changelog subjects as literal text (#475) -- v5 only
- Keep release tag names out of shell source (#473)
- Verify release bundle before attestation (#474)
- Bound the dependency overrides and clear the undici advisories (#476)
- Stop
bump:workflowrewriting pinned actions' provenance comments (#477) - Bump
@vercel/ncc(#470),eslint(#472),globals(#471),codeql-action(#469)
Full history: v4.8.0...v5.0.0