Skip to content

Commit 5286466

Browse files
committed
doc: update git node land instructions for security releases
Signed-off-by: Antoine du Hamel <duhamelantoine1995@gmail.com>
1 parent cebe424 commit 5286466

1 file changed

Lines changed: 5 additions & 4 deletions

File tree

doc/contributing/releases.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -272,11 +272,12 @@ $ git reset --hard upstream/vN.x
272272
The list of patches to include should be listed in the "Next Security Release"
273273
issue in `nodejs-private`. Ask the security release steward if you're unsure.
274274

275-
The `git node land` tool does not work with the `nodejs-private`
276-
organization. To land a PR in Node.js private, use `git cherry-pick` to apply
277-
each commit from the PR. You will also need to manually apply the PR
278-
metadata (`PR-URL`, `Reviewed-by`, etc.) by amending the commit messages. If
275+
To use the `git node land` tool to land Pull Requests in the `nodejs-private`
276+
organization, you need to specify the full URL to the Pull Request and make sure
277+
you provide a GitHub token with read permission to the private repository. If
279278
known, additionally include `CVE-ID: CVE-XXXX-XXXXX` in the commit metadata.
279+
Make sure to sign and push to resulting commit to the private repository and not
280+
the public one.
280281

281282
**Note**: Do not run CI on the PRs in `nodejs-private` until CI is locked down.
282283
You can integrate the PRs into the proposal without running full CI.

0 commit comments

Comments
 (0)