This checklist helps maintainers prepare and publish a release safely.
- Pre-release
- Security checklist (12.4.1)
- Tag and publish
- Post-release checks
- Coverage goals
- Release history
Run the full release pipeline:
make release-checkExpected steps:
- Asset build (
pnpm run build) - Composer validation and lock sync
- Code style checks
- Static analysis (Rector dry run + PHPStan)
- PHP and TypeScript test suites with coverage
- Demo verification (
demo/Makefilerelease-check)
Before tagging, confirm each item in SECURITY.md — Release security checklist. Note confirmation in the release PR or tag message.
- Move
[Unreleased]entries indocs/CHANGELOG.mdto a new## [X.Y.Z] - YYYY-MM-DDsection. - Update
docs/UPGRADING.mdif consumers must change code or configuration. - Create an annotated tag:
git tag -a vX.Y.Z -m "Release vX.Y.Z". - Push the tag:
git push origin vX.Y.Z. - Confirm GitHub workflows
release.ymlandsync-releases.ymlcompleted successfully.
- Verify Packagist metadata is updated.
- Confirm the GitHub release contains the tag message and changelog section.
- Validate installation in a clean Symfony app:
composer require nowo-tech/cookie-consent-bundle- Smoke-test the consent modal (bootstrap and tailwind if applicable).
- PHP: ≥99% line coverage (prefer 100%;
make test-coverage) - TypeScript: ~94% line coverage, 90% minimum enforced (
make test-ts)
Update README Tests and coverage percentages after each release when coverage changes materially.
- v1.9.5 —
nowo_cookie_consent_render()in-process modal embed (no kernel sub-request). - v1.9.2 — Memoize consent profile Doctrine lookups per request; reuse resolved config in modal sub-request.
- v1.9.0 — CSP-safe standalone modal CSS; Beacon skin upstream; bottom-left + equal-weight defaults for new profiles.
- v1.7.0 — Cold-start skip for Doctrine-backed consent (SiteBackup attribute).
| Version | Date | Notes |
|---|---|---|
| 1.9.5 | 2026-08-21 | nowo_cookie_consent_render() — in-process modal (no sub-request) |
| 1.9.2 | 2026-08-19 | Consent profile lookup memoization; modal sub-request reuse |
| 1.9.0 | 2026-08-15 | Standalone nowo-cookie-consent.css; skip style inject under CSP; skin polish |
| 1.8.0 | 2026-08-15 | Mid-migration schema probe for cookie config table |
| 1.7.0 | 2026-08-15 | Cold-start schema skip; Site Backup attribute contract |
| 1.6.3 | 2026-08-11 | render_routes public whitelist |
| 1.6.2 | 2026-08-11 | Inventory query memoization / single form attach |
| 1.6.1 | 2026-08-11 | skip_render_routes + nowo_cookie_consent_should_render() |
| 1.6.0 | 2026-08-04 | UiKit ^1.4 composition; FormKit ^2; Twig Extra gate; Twig-CS-Fixer; confirm dialog for inventory delete |
| 1.5.2 | 2026-08-03 | Demo Twig Inspector from Packagist (fix demo-smoke on standalone CI checkout) |
| 1.5.1 | 2026-08-03 | REQ-UI-001: stack host javascripts via parent() in admin/base.html.twig; BC layout aliases extend base |
| 1.5.0 | 2026-08-01 | Route-based settings sections; one FormType per tab under Form/Settings/; admin area/section tabs; single form card |
| 1.4.9 | 2026-08-01 | nowo-ui.css for custom/tailwind/none admin; inject from base when using host layout |
| 1.4.8 | 2026-07-30 | Modal JS SameOrigin CSRF double-submit for XHR (csrf_protection: true safe with Stimulus-less posts) |
| 1.4.7 | 2026-07-30 | Twig CSRF field via form.children._token |
| 1.4.6 | 2026-07-30 | Skip CSRF widget when consent form has no _token |
| 1.4.5 | 2026-07-30 | Twig prependPath for app overrides; Tailwind theme uses --nowo-cc-* (no indigo/slate utilities) |
| 1.4.4 | 2026-07-30 | Composer locks: Symfony 7.4.15 / demo 8.1.2 |
| 1.4.3 | 2026-07-30 | Admin base.html.twig, Twig override docs in USAGE (REQ-TWIG-001), README docs links |
| 1.4.2 | 2026-07-29 | Compose V2/V1 Makefile fallback; optional monorepo includes; WSL Compose shell helper |
| 1.4.1 | 2026-07-28 | Coverage gate docs/tooling, Spec Kit inventory, deprecation CI gate, demo lock/migration fixes |
| 1.4.0 | 2026-07-27 | Admin web_ui / security, pagination, PSR Clock, PHPStan + demo-smoke CI |
| 1.3.6 | 2026-07-27 | Standards compliance: DOCS-016/017, MAKE-003/007, PHP coverage ≥99.95% |
| 1.3.5 | 2026-07-24 | PHPStan FrankenPHP (REQ-CS-005), empty baseline, DI/type hygiene |
| 1.3.4 | 2026-07-22 | Vite 8 / happy-dom 20, GHA bumps, demo FRANKENPHP_MODE |
| 1.3.3 | 2026-07-20 | REQ-GIT-001 hygiene, Code of Conduct, expanded PHPUnit coverage |
| 1.3.2 | 2026-07-13 | Asset package nowo_cookie_consent, AssetMapper-compatible script loading |
| 1.3.1 | 2026-07-09 | Spec Kit baseline, demo update-deps fix, dev lock sync |
| 1.3.0 | 2026-07-05 | Dashboard table names, doctrine.table_prefix, locale translations |
| 1.2.0 | 2026-06-15 | Page overlay, settings admin, bubble customization, modal position fix |
| 1.1.1 | 2026-06-15 | Standards compliance, SECURITY/docs, TS coverage gate |
| 1.1.0 | 2026-06-15 | Cookie inventory, granular selection, preferences bubble |
| 1.0.0 | 2026-06-15 | First stable release |
After creating the release commit and tag, run make check-no-cursor-coauthor again before git push (REQ-GIT-001). The release commit itself is not covered by an earlier release-check run.