Skip to content

packaging: the copyright line in both Chocolatey packages and both WinGet manifests - #154

Merged
donislawdev merged 1 commit into
mainfrom
packaging/copyright
Sep 29, 2026
Merged

donislawdev merged 1 commit into
mainfrom
packaging/copyright

Conversation

@donislawdev

@donislawdev donislawdev commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Chocolatey's moderation asked for a <copyright> element when it approved 0.4.0. This fills it in both Chocolatey packages, and WinGet's optional Copyright field in both manifests, with the line tfg license prints: Copyright (C) 2026 DonislawDev. It arrives with the next release. The published 0.4.0 packages stay as they are.

  • build_packages.py keeps the line beside the product name and the licence, the two values it already held a copy of.
  • New guard TestEveryPackageCarriesTheCopyrightTheProgramPrints renders the packages and reads the four files. Each must carry exactly one copyright line, equal to the one in internal/version/version.go. A template that loses the element fails as surely as a copy that drifts.
  • Chocolatey refuses a copyright shorter than four characters (rule CPMR0001). WinGet's schema 1.12.0 allows 3 to 512 characters, and winget show prints the field.

How it was checked: rendered v0.4.0, choco pack of both packages exits 0, the .nuspec read back out of each .nupkg carries the line, and winget validate of both manifests succeeds.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Improvements
    • Added copyright information to Chocolatey and WinGet package metadata, matching the copyright displayed by the application.
    • Package checks now verify that each package includes the matching copyright information.

…nGet manifests

Chocolatey's moderation asked for a <copyright> element when it approved
0.4.0. The renderer now fills it, and WinGet's optional Copyright field, with
the line tfg license prints - Copyright (C) 2026 DonislawDev - so a package
and the program say the same thing. It arrives with the next release; the
published 0.4.0 packages stay as they are.

The guard reads what the renderer wrote, not its copy of the line: each of
the four files carries exactly one copyright line, equal to the one in
internal/version/version.go. A template that loses the element fails as
surely as a copy that drifts from the program.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 68535486-b1fc-4bd6-a3cd-30dd311105c6

📥 Commits

Reviewing files that changed from the base of the PR and between 9c634d5 and d1ed4ce.

📒 Files selected for processing (5)
  • .github/scripts/build_packages.py
  • internal/guard/packaging_test.go
  • packaging/README.md
  • packaging/chocolatey/package.nuspec.in
  • packaging/winget/locale.en-US.yaml.in

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (18)
  • GitHub Check: review new dependencies
  • GitHub Check: semgrep
  • GitHub Check: known vulnerabilities
  • GitHub Check: test on macos-latest
  • GitHub Check: test on ubuntu-latest
  • GitHub Check: the installer installs and leaves
  • GitHub Check: reference tools actually installed
  • GitHub Check: staticcheck
  • GitHub Check: the Chocolatey packages install and leave
  • GitHub Check: what this push touched
  • GitHub Check: linters
  • GitHub Check: bill of materials
  • GitHub Check: test on windows-latest
  • GitHub Check: coverage gate
  • GitHub Check: import table of the window binary
  • GitHub Check: Analyze (go)
  • GitHub Check: Analyze (actions)
  • GitHub Check: Analyze (python)
🧰 Additional context used
📓 Path-based instructions (12)
Packaging and release configuration of a desktop app.

⚙️ CodeRabbit configuration file

Files:

  • packaging/winget/locale.en-US.yaml.in
  • packaging/chocolatey/package.nuspec.in
  • packaging/README.md
Applies to text shown to the user (labels, buttons, tooltips, placeholders, dialogs, errors, status messages, empty states, translations).

⚙️ CodeRabbit configuration file

Files:

  • internal/guard/packaging_test.go
Verify tests check real behavior and would fail if the implementation were broken.

⚙️ CodeRabbit configuration file

Files:

  • internal/guard/packaging_test.go
These are end-user desktop applications.

⚙️ CodeRabbit configuration file

Files:

  • internal/guard/packaging_test.go
Performance is a known weak spot of these projects.

⚙️ CodeRabbit configuration file

Files:

  • internal/guard/packaging_test.go
Applies only to code that builds or styles a GUI.

⚙️ CodeRabbit configuration file

Files:

  • internal/guard/packaging_test.go
Domain: test file generator (Go; `tfg` CLI and `tfg-gui` Fyne window over one engine).

⚙️ CodeRabbit configuration file

Files:

  • internal/guard/packaging_test.go
SECURITY, HIGH PRIORITY.

⚙️ CodeRabbit configuration file

Files:

  • internal/guard/packaging_test.go
These apps are QA/developer tools.

⚙️ CodeRabbit configuration file

Files:

  • internal/guard/packaging_test.go
Go code.

⚙️ CodeRabbit configuration file

Files:

  • internal/guard/packaging_test.go
Check that documentation matches the actual code in this PR: commands, flags, config keys, file paths, build steps and examples must exist.

⚙️ CodeRabbit configuration file

Files:

  • packaging/README.md
All code in this repository is written by an AI coding agent (Claude Code).

⚙️ CodeRabbit configuration file

Files:

  • packaging/winget/locale.en-US.yaml.in
  • internal/guard/packaging_test.go
  • packaging/chocolatey/package.nuspec.in
  • packaging/README.md
🪛 LanguageTool
packaging/README.md

[grammar] ~8-~8: Ensure spelling is correct
Context: ... keeps a copy of, the product name, the licence and the copyright line, are held to the...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


📝 Walkthrough

Walkthrough

The package renderer now supplies a copyright value to the Chocolatey and WinGet templates. A test checks that all four package metadata files contain the same copyright value as the program.

Changes

Package copyright metadata

Layer / File(s) Summary
Render and verify package copyright
.github/scripts/build_packages.py, packaging/chocolatey/package.nuspec.in, packaging/winget/locale.en-US.yaml.in, internal/guard/packaging_test.go, packaging/README.md
The renderer defines and supplies COPYRIGHT to both package templates. The test checks the four rendered metadata files against the program’s copyright line. The README describes the added guard.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested labels: packaging

Merge Risk: ⚪ Minimal · up to d1ed4

The next release’s Chocolatey and WinGet metadata will carry the same copyright text printed by the program, with a guard checking all four rendered files. No merge-blocking issue is evident.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to d1ed4

The new copyright field is informational. The review found no new installation authority, runtime boundary, or material security risk introduced by this change.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The affected exposure is the copyright text in generated Chocolatey and WinGet metadata; the reviewed change does not expand runtime or installation privileges.

Trust Boundaries and Controls

  • observed — The new value enters the existing renderer as a fixed constant rather than through the checksum-file input read by the build path.
🚥 Pre-merge checks | ✅ 14
✅ Passed checks (14 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: adding the copyright line to both Chocolatey packages and both WinGet manifests. It is specific and within the length limit.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Tests For Changed Behavior ✅ Passed The PR changes package rendering and package metadata, not application runtime behavior. It adds TestEveryPackageCarriesTheCopyrightTheProgramPrints, which checks all four rendered package files aga…
No Secrets Or Debug Leftovers ✅ Passed The PR adds no CLAUDE.md, AGENTS.md, .claude/, or .env paths. Added lines contain package copyright metadata, template wiring, documentation, and a test. No credentials, tokens, private endpoints, loc…
No Hardcoded Ui Styling ✅ Passed The PR does not add or change GUI code. The authoritative diff only changes packaging.py, a packaging test, README documentation, and Chocolatey/WinGet metadata templates. No XAML, Slint, Fyne, Tkinte…
No Obvious Performance Problems ✅ Passed No clear performance problem is introduced. The production change adds one constant, one template substitution, and two metadata fields. The new test renders once, then checks four fixed package files…
Desktop Robustness ✅ Passed The PR adds package copyright metadata, a renderer value, documentation, and a consistency test. It does not add working-directory asset loads, settings writes, long operations, destructive actions, a…
Safe File Parsing ✅ Passed PASS. The PR adds a fixed copyright scalar and places it in existing XML and YAML templates. The new guard uses os.ReadFile and Go's regexp on renderer output; it does not deserialize XML/YAML, ex…
System Changes Are Reversible ✅ Passed PASS: The pull request changes package metadata, a copyright substitution, documentation, and a validation test. It does not add or change code that modifies network filters, proxies, firewalls, syste…
Clear User-Facing Text ✅ Passed The PR adds the clear metadata label Copyright with the exact value Copyright (C) 2026 DonislawDev to both Chocolatey and WinGet package outputs. The related README and renderer text consistently …
No Resource Leaks ✅ Passed The pull request changes only package metadata, a Python substitution constant, documentation, and a Go validation test. The new test performs regex checks on rendered text; it adds no handlers, timer…
Scope, Duplication And Docs ✅ Passed PASS: The five changed files all implement the stated copyright metadata change, its consistency guard, or related packaging documentation. The renderer extends its existing centralized values table a…

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@donislawdev
donislawdev merged commit 36a1dd5 into main Sep 29, 2026
22 checks passed
@donislawdev
donislawdev deleted the packaging/copyright branch September 29, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant