Skip to content

feat(sdlc-workflow): add release-notes skill (reapply #195) - #325

Open
mrizzi wants to merge 1 commit into
mainfrom
reapply-195-release-notes
Open

mrizzi wants to merge 1 commit into
mainfrom
reapply-195-release-notes

Conversation

@mrizzi

@mrizzi mrizzi commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Reintroduces the change from #195, which was reverted in #324 after being merged by mistake.

This is a "revert the revert" of #324, so the diff is identical to the original #195. Opened for proper review before merging.

Summary by Sourcery

Add the release-notes skill to support the end-to-end Jira release note workflow.

New Features:

  • Add a release-notes skill to guide engineers and technical writers through documenting, reviewing, and approving Jira release notes.

Enhancements:

  • Define release-note templates, Jira field mappings, workflow modes, validation rules, and safeguards for accurate customer-facing release-note content.

@sourcery-ai

sourcery-ai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Reviewer's Guide

Reintroduces the release-notes skill as a new workflow definition, covering Jira-based authoring, technical-writer review, and engineer approval with configuration-driven fields and tracker links.

Sequence diagram for release note authoring and approval

sequenceDiagram
    actor Engineer
    actor TechnicalWriter
    participant Skill as release-notes skill
    participant Jira
    participant Tracker as Release Notes tracker

    Engineer->>Skill: /release-notes ISSUE
    Skill->>Jira: Fetch issue and configuration
    Jira-->>Skill: Issue and release note fields
    Skill-->>Engineer: Preview release note template
    Engineer->>Skill: Confirm type and text
    Skill->>Jira: editJiraIssue(fields)
    Skill->>Jira: createIssueLink(type=Document)
    Jira-->>Skill: Fields and tracker link saved

    TechnicalWriter->>Skill: /release-notes review ISSUE
    Skill->>Jira: Read release note fields
    Jira-->>Skill: In Progress release note
    Skill-->>TechnicalWriter: Present text for review
    TechnicalWriter->>Skill: Confirm AsciiDoc rewrite
    Skill->>Jira: editJiraIssue(text, status=Proposed)
    Skill->>Jira: Post review comment

    Engineer->>Skill: /release-notes approve ISSUE
    Skill->>Jira: Read proposed release note
    Jira-->>Skill: Proposed release note
    Engineer->>Skill: Approve or reject
    alt Approve
        Skill->>Jira: editJiraIssue(status=Done)
        Skill->>Jira: Post approval comment
    else Reject
        Skill->>Jira: editJiraIssue(status=Rejected)
        Skill->>Jira: Post feedback comment
    end
Loading

State diagram for the release notes Jira workflow

stateDiagram-v2
    [*] --> InProgress: Engineer documents issue
    InProgress --> Proposed: Technical writer reviews and rewrites
    Proposed --> Done: Engineer approves
    Proposed --> Rejected: Engineer requests changes
    Rejected --> Proposed: Technical writer revises
    InProgress --> NotRequired: Engineer determines no note is needed
    Done --> [*]
    NotRequired --> [*]
Loading

File-Level Changes

Change Details Files
Adds a Jira-only release-notes skill with separate document, technical-writer review, and engineer approval workflows.
  • Defines command arguments and mode selection for documenting, reviewing, or approving release notes.
  • Adds guardrails for Jira-only updates, content provenance, CVE exclusion, filesystem safety, and MCP/REST fallback behavior.
  • Defines release-note templates, configurable Jira field mappings, document-link handling, and required comment footnotes.
  • Implements document mode for assessing relevance, selecting a type, collecting and previewing content, updating fields, and linking release trackers.
  • Implements review mode for validating fields, rewriting approved content in AsciiDoc, proposing it, and notifying the assignee.
  • Implements approve mode for reviewing proposed text, marking it Done or Rejected, and notifying the technical writer.
plugins/sdlc-workflow/skills/release-notes/SKILL.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="plugins/sdlc-workflow/skills/release-notes/SKILL.md" line_range="27" />
<code_context>
+
+### Exception: JIRA REST API Fallback
+
+When Atlassian MCP is unavailable, this skill may use the Bash tool to invoke the JIRA REST API v3 via `python3 scripts/jira-client.py`. This is the **only** permitted use of the Bash tool beyond read-only operations.
+
+- Allowed: `bash -c "python3 scripts/jira-client.py <command>"`
</code_context>
<issue_to_address>
**Repository file executes shell code**

When the REST fallback is selected and the repository contains an attacker-controlled `.env` file, the fallback guidance tells the assistant to source the repository's `.env` file; shell commands in an attacker-controlled file then run with the user's privileges and can read or exfiltrate Jira credentials.

Parse `.env` as data with a non-executing loader, and do not source repository-controlled files in the user's shell.
</issue_to_address>

Sourcery assessment

Needs a human reviewer. 1 finding to address first, and if the workflow is wrong, it could write incorrect release-note fields, create an incorrect Jira link, or post a misleading comment that remains after the skill is reverted. Those effects are bounded and can generally be corrected or removed by rerunning the workflow or repairing the Jira issue.

Blocking findings: plugins/sdlc-workflow/skills/release-notes/SKILL.md:27


Sourcery is free for open source - if you like our reviews please consider sharing them ✨


### Exception: JIRA REST API Fallback

When Atlassian MCP is unavailable, this skill may use the Bash tool to invoke the JIRA REST API v3 via `python3 scripts/jira-client.py`. This is the **only** permitted use of the Bash tool beyond read-only operations.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High · Repository file executes shell code

When the REST fallback is selected and the repository contains an attacker-controlled .env file, the fallback guidance tells the assistant to source the repository's .env file; shell commands in an attacker-controlled file then run with the user's privileges and can read or exfiltrate Jira credentials.

Parse .env as data with a non-executing loader, and do not source repository-controlled files in the user's shell.

Prompt for AI agents
In `plugins/sdlc-workflow/skills/release-notes/SKILL.md` at line 27:

**Repository file executes shell code**

When the REST fallback is selected and the repository contains an attacker-controlled `.env` file, the fallback guidance tells the assistant to source the repository's `.env` file; shell commands in an attacker-controlled file then run with the user's privileges and can read or exfiltrate Jira credentials.

Parse `.env` as data with a non-executing loader, and do not source repository-controlled files in the user's shell.

@ptomanRH
ptomanRH requested a review from mrrajan October 6, 2026 12:50

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant