Gap
@releasekit/notes casts its parsed input to VersionOutput and reads fields off it. versionOutputToChangelogInput guards only the top-level changelogs array — anything malformed below that surfaces as a raw TypeError rather than an actionable input error.
On main, today:
parseVersionOutput('{"changelogs":[{"packageName":"a"}]}')
→ TypeError: Cannot read properties of undefined (reading 'map')
The CLI reports that as a general error, so a user piping a hand-assembled or truncated file gets a stack-shaped message pointing at our internals instead of "this input is missing entries".
@releasekit/publish already does this properly — parseInput validates against a Zod VersionOutputSchema and raises INPUT_VALIDATION_ERROR with the offending paths. notes should match.
Scope
- A Zod schema for the
VersionOutput shape notes actually consumes, applied in parseVersionOutput after the envelope unwrap.
- Failures raise
InputParseError (or a new InputValidationError, mirroring publish's split) with the field paths.
- Reuse or share publish's schema rather than writing a second one that can drift — they describe the same contract.
Context
Raised by Greptile on #616, which made notes accept the enveloped form of the same input. Confirmed pre-existing: bare input on main behaves identically, so it isn't a regression from that PR and was left out of it rather than expanding its scope.
Worth doing alongside — or as part of — the pipe-contract work in #544, since it hardens the same boundary.
Gap
@releasekit/notescasts its parsed input toVersionOutputand reads fields off it.versionOutputToChangelogInputguards only the top-levelchangelogsarray — anything malformed below that surfaces as a rawTypeErrorrather than an actionable input error.On
main, today:The CLI reports that as a general error, so a user piping a hand-assembled or truncated file gets a stack-shaped message pointing at our internals instead of "this input is missing
entries".@releasekit/publishalready does this properly —parseInputvalidates against a ZodVersionOutputSchemaand raisesINPUT_VALIDATION_ERRORwith the offending paths.notesshould match.Scope
VersionOutputshapenotesactually consumes, applied inparseVersionOutputafter the envelope unwrap.InputParseError(or a newInputValidationError, mirroring publish's split) with the field paths.Context
Raised by Greptile on #616, which made
notesaccept the enveloped form of the same input. Confirmed pre-existing: bare input onmainbehaves identically, so it isn't a regression from that PR and was left out of it rather than expanding its scope.Worth doing alongside — or as part of — the pipe-contract work in #544, since it hardens the same boundary.