Repository navigation
docs: add the v1.8.0 changelog and backfill two missing releases - #67
Merged
Merged
Conversation
v1.8.0 covers everything since v1.7.0: the typed RateLimitError, the three token-minting and throttle-classification fixes, the webhook empty-secret fix, and the coverage and dependency work. Two of those alter behaviour a caller can depend on, so they sit under Changed with the consequence stated rather than among the fixes: a 403 permission failure no longer matches errors.Is(err, ErrRateLimited), and WithApplicationTokenExpiration now rejects values at or below 90s, which the README's own example used to use. The webhook fix gets its own Security heading for the same reason. v1.6.0 and v1.7.0 were tagged and published as GitHub releases but never written here, so the file jumped from February to now and implied nothing shipped in between. Both are backfilled from their release notes, v1.6.0 converted into the headings this file uses. Adds a note on the module path. The /v2 line is permanently retracted and unreachable: go list -m -versions reports no versions for it, and go get resolves none of the three. The note records that the retract block lives only in the v2.0.2 tag, since v2/ is no longer on main, so deleting that tag would silently restore v2.0.0 and v2.0.1.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #67 +/- ##
=======================================
Coverage 99.31% 99.31%
=======================================
Files 4 4
Lines 294 294
=======================================
Hits 292 292
Misses 2 2 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
CHANGELOG.mdstopped at v1.5.1, so it jumped from February to now and implied nothing shipped in between. v1.6.0 and v1.7.0 were both tagged and published as GitHub releases but never written here. This adds the v1.8.0 entry, backfills those two, and records why there will never be a v2.Changes
RateLimitError(feat: return a typed RateLimitError carrying the retry hint #65), the three token-minting and throttle-classification fixes (fix: correct three bugs in token minting and throttle classification #63), the JWT caching and installation ID fixes (fix: cache the app JWT with a custom client, reject a bad installation ID #62), the webhook and timeout fixes (fix: close an empty-secret webhook bypass and an unbounded token wait #61), and the coverage work (test: cover every reachable branch, drop a test that hit the network #66)errors.Is(err, ErrRateLimited), andWithApplicationTokenExpirationrejects values at or below 90s — which the README's own example used to use. The webhook empty-secret fix gets its own Security heading/v2line is permanently retractedRationale
Every PR attribution was checked against the merge log rather than inferred, which corrected two — the
resp.Body.Closefix and the README slimming both came via #54.Invalidateis deliberately absent: PR #64 was closed rather than merged, so it is not inmain.The v2 retraction was verified rather than assumed.
go list -m -versionsreports no versions for the v2 path, only-retractedrevealsv2.0.0 v2.0.1 v2.0.2, andgo get .../v2@latestfalls back to v1 and reports no such package — v2.0.2 self-retracts, so the whole line is unreachable. The note records that theretractblock now lives only in thev2.0.2tag, becausev2/is no longer onmain; deleting that tag would silently make v2.0.0 and v2.0.1 installable again.Migration Notes
Documentation only, no code changes.
Two things to check before merging: the v1.8.0 heading is dated 2026-09-18 and the tag does not exist yet, so the date needs adjusting if the release slips. And 1.8.0 as a minor is a judgement call — the 403 reclassification can break a caller branching on
errors.Is, which strict semver would call breaking. A major is not available given v2 is retracted, which is why the consequence is spelled out under Changed instead.