Repository navigation
Conversation
This reverts commit 6f9a990.
Reviewer's GuideReintroduces the release-notes skill as a new workflow definition, covering Jira-based authoring, technical-writer review, and engineer approval with configuration-driven fields and tracker links. Sequence diagram for release note authoring and approvalsequenceDiagram
actor Engineer
actor TechnicalWriter
participant Skill as release-notes skill
participant Jira
participant Tracker as Release Notes tracker
Engineer->>Skill: /release-notes ISSUE
Skill->>Jira: Fetch issue and configuration
Jira-->>Skill: Issue and release note fields
Skill-->>Engineer: Preview release note template
Engineer->>Skill: Confirm type and text
Skill->>Jira: editJiraIssue(fields)
Skill->>Jira: createIssueLink(type=Document)
Jira-->>Skill: Fields and tracker link saved
TechnicalWriter->>Skill: /release-notes review ISSUE
Skill->>Jira: Read release note fields
Jira-->>Skill: In Progress release note
Skill-->>TechnicalWriter: Present text for review
TechnicalWriter->>Skill: Confirm AsciiDoc rewrite
Skill->>Jira: editJiraIssue(text, status=Proposed)
Skill->>Jira: Post review comment
Engineer->>Skill: /release-notes approve ISSUE
Skill->>Jira: Read proposed release note
Jira-->>Skill: Proposed release note
Engineer->>Skill: Approve or reject
alt Approve
Skill->>Jira: editJiraIssue(status=Done)
Skill->>Jira: Post approval comment
else Reject
Skill->>Jira: editJiraIssue(status=Rejected)
Skill->>Jira: Post feedback comment
end
State diagram for the release notes Jira workflowstateDiagram-v2
[*] --> InProgress: Engineer documents issue
InProgress --> Proposed: Technical writer reviews and rewrites
Proposed --> Done: Engineer approves
Proposed --> Rejected: Engineer requests changes
Rejected --> Proposed: Technical writer revises
InProgress --> NotRequired: Engineer determines no note is needed
Done --> [*]
NotRequired --> [*]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="plugins/sdlc-workflow/skills/release-notes/SKILL.md" line_range="27" />
<code_context>
+
+### Exception: JIRA REST API Fallback
+
+When Atlassian MCP is unavailable, this skill may use the Bash tool to invoke the JIRA REST API v3 via `python3 scripts/jira-client.py`. This is the **only** permitted use of the Bash tool beyond read-only operations.
+
+- Allowed: `bash -c "python3 scripts/jira-client.py <command>"`
</code_context>
<issue_to_address>
**Repository file executes shell code**
When the REST fallback is selected and the repository contains an attacker-controlled `.env` file, the fallback guidance tells the assistant to source the repository's `.env` file; shell commands in an attacker-controlled file then run with the user's privileges and can read or exfiltrate Jira credentials.
Parse `.env` as data with a non-executing loader, and do not source repository-controlled files in the user's shell.
</issue_to_address>Sourcery assessment
Needs a human reviewer. 1 finding to address first, and if the workflow is wrong, it could write incorrect release-note fields, create an incorrect Jira link, or post a misleading comment that remains after the skill is reverted. Those effects are bounded and can generally be corrected or removed by rerunning the workflow or repairing the Jira issue.
Blocking findings: plugins/sdlc-workflow/skills/release-notes/SKILL.md:27
|
|
||
| ### Exception: JIRA REST API Fallback | ||
|
|
||
| When Atlassian MCP is unavailable, this skill may use the Bash tool to invoke the JIRA REST API v3 via `python3 scripts/jira-client.py`. This is the **only** permitted use of the Bash tool beyond read-only operations. |
There was a problem hiding this comment.
🟠 High · Repository file executes shell code
When the REST fallback is selected and the repository contains an attacker-controlled .env file, the fallback guidance tells the assistant to source the repository's .env file; shell commands in an attacker-controlled file then run with the user's privileges and can read or exfiltrate Jira credentials.
Parse .env as data with a non-executing loader, and do not source repository-controlled files in the user's shell.
Prompt for AI agents
In `plugins/sdlc-workflow/skills/release-notes/SKILL.md` at line 27:
**Repository file executes shell code**
When the REST fallback is selected and the repository contains an attacker-controlled `.env` file, the fallback guidance tells the assistant to source the repository's `.env` file; shell commands in an attacker-controlled file then run with the user's privileges and can read or exfiltrate Jira credentials.
Parse `.env` as data with a non-executing loader, and do not source repository-controlled files in the user's shell.
Reintroduces the change from #195, which was reverted in #324 after being merged by mistake.
This is a "revert the revert" of #324, so the diff is identical to the original #195. Opened for proper review before merging.
Summary by Sourcery
Add the release-notes skill to support the end-to-end Jira release note workflow.
New Features:
Enhancements: