Skip to content

[docs] CHANGELOG omnibus entry + capture two PR #55 lessons#58

Merged
trilamsr merged 1 commit into
mainfrom
worktree-followups-changelog-notes
May 18, 2026
Merged

[docs] CHANGELOG omnibus entry + capture two PR #55 lessons#58
trilamsr merged 1 commit into
mainfrom
worktree-followups-changelog-notes

Conversation

@trilamsr

Copy link
Copy Markdown
Contributor

What this PR does

Backfills documentation tracking that PR #55 (the follow-ups omnibus)
didn't touch:

  1. CHANGELOG.md — new ### Security section under [Unreleased]
    with the SHA-pin / cosign-flag-tightening entries; new ### Changed
    rows for the Rekor logIndex URL emission in release notes and
    mod-verify wired into make ci.
  2. docs/notes/pr-workflow.md — repo-wide lesson: audit
    docs/FOLLOWUPS.md rows for staleness before implementing. 2 of
    10 omnibus items were already shipped but still listed; trust the
    code, not the row.
  3. .claude/notes/automation.md — agent-internal lesson: don't
    escape backticks inside a single-quoted HEREDOC. PR [chore] follow-ups omnibus: SHA-pin Actions + idiom sweep + cleanup #55's body fed
    the pr-lint awk regex literal backslashes instead of
    triple-backticks; the required check went red until the body was
    re-edited via gh pr edit.

No code changes; make doc-check clean.

Linked issue(s)

No linked issue.

Release notes

NONE

Checklist

  • No code change; docs-only
  • make doc-check passes
  • Commits are signed off

🤖 Generated with Claude Code

Backfills the doc-tracking that the omnibus PR (#55) didn't touch:

- CHANGELOG.md: new `### Security` section with the SHA-pin / cosign-
  flag-tightening entries, plus `### Changed` rows for the Rekor
  logIndex URL emission and `mod-verify` in `make ci`.
- docs/notes/pr-workflow.md: lesson on auditing FOLLOWUPS bullets for
  staleness before implementing. 2 of 10 omnibus items were already
  shipped but still listed; trust the code, not the row.
- .claude/notes/automation.md: lesson on not escaping backticks inside
  a single-quoted HEREDOC. PR #55's body fed the pr-lint awk regex
  literal backslashes instead of triple-backticks; required check went
  red until the body was re-edited via `gh pr edit`.

No code changes; `make doc-check` clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Signed-off-by: Tri Lam <trilamsr@gmail.com>
@trilamsr trilamsr enabled auto-merge (squash) May 18, 2026 19:21
@trilamsr trilamsr merged commit aa56b1a into main May 18, 2026
5 checks passed
@trilamsr trilamsr deleted the worktree-followups-changelog-notes branch May 18, 2026 19:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant