Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,16 @@ All notable changes to `github-delivery` are documented here.

## [Unreleased]

## [1.7.1] - 2026-09-28

### Changed

- GitHub Actions CodeQL dependencies were refreshed to the latest pinned action revisions used by the repository CI (PR #467).

### Fixed

- Attributed repository and bot content can no longer create merge-discussion intent: embedded instructions such as `merge immediately` are treated as untrusted data, the router preserves the trusted delivery request instead, and instruction-injection attempts surface an explicit security flag. The adversarial evaluation contracts and routing regression now pin that behavior (PR #468).

## [1.7.0] - 2026-09-21

### Added
Expand Down
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "github-delivery",
"version": "1.7.0",
"version": "1.7.1",
"description": "Guided installer and safety tooling for GitHub Delivery workflows",
"type": "module",
"engines": {
Expand Down
13 changes: 13 additions & 0 deletions tests/unit/pr-review-quality-contracts.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -139,6 +139,19 @@ test("post-1.6.0 follow-up release is complete in 1.7.0", () => {
assert.match(release, /incompleteReasons/);
});

test("post-1.7.0 follow-up release is complete in 1.7.1", () => {
const changelog = read("CHANGELOG.md");
const release = changelog.split("## [1.7.1] - 2026-09-28")[1]?.split("## [1.7.0]")[0] ?? "";

assert.ok(release, "expected a dated 1.7.1 changelog section");
for (const pr of [467, 468]) {
assert.match(release, new RegExp(`PR #${pr}\\b`));
}
assert.match(release, /CodeQL/i);
assert.match(release, /instruction-injection/i);
assert.match(release, /untrusted data/i);
});

test("package version matches the newest dated changelog release", () => {
const pkg = JSON.parse(read("package.json"));
const changelog = read("CHANGELOG.md");
Expand Down
Loading