genesis-release-risk-changelog
Generate commit-backed changelog and breaking change risk score
| Size | Folder | Inside |
|---|---|---|
| 10 kB | genesis_release_risk/ | 3 scripts |
| 214 B | bin/ | 1 script |
| 3.2 kB | tests/ | 1 test file |
| 5.8 kB | (root) | 5 docs · 1 asset |
| Size | Path |
|---|---|
| 103 B | .gitignore |
| 663 B | CHANGELOG.md |
| 1.1 kB | LICENSE |
| 437 B | QUICKSTART.md |
| 2.6 kB | README.md |
| 279 B | SECURITY.md |
| 6 B | VERSION · binary |
| 214 B | bin/genesis-release-risk · binary |
| 187 B | genesis_release_risk/__init__.py |
| 2.8 kB | genesis_release_risk/__main__.py |
| 7 kB | genesis_release_risk/analyzer.py |
| 665 B | pyproject.toml |
| 3.2 kB | tests/test_analyzer.py |
Already bought this?
View your purchasesREADME
genesis-release-risk-changelog
Deterministic commit-backed changelog generator with quantitative breaking-change risk scoring.
The Problem
Engineering teams often release new software versions without understanding their true deployment risk:
- Breaking changes slipped into minor feature commits go unnoticed until production outages.
- Silent modifications to database migrations, cryptographic key paths, or public API endpoints cause downstream failures.
- Manually written changelogs are time-consuming to create and frequently omit critical architectural modifications.
The Solution
genesis-release-risk-changelog automatically parses Git history and diffs using Conventional Commits conventions. It identifies breaking changes, flags touched sensitive subsystems (database migrations, public contracts, auth/crypto), and computes a quantitative Release Risk Score (0–100) alongside a polished Markdown changelog.
Key Features
- Zero External Dependencies: Pure Python 3 standard library (
subprocess,re,json). - Conventional Commits Engine: Categorizes commits into features, fixes, refactors, and breaking changes.
- Sensitive Subsystem Blast-Radius Detection: Automatically flags changes to database migrations, API contracts (
proto,openapi,candid), and cryptographic modules. - Quantitative Risk Score (0–100): Categorizes releases into
LOW,MEDIUM,HIGH, orCRITICALrisk tiers. - Automated CI Release Gate: Enforce maximum allowed risk thresholds (
--max-risk 70) in deployment pipelines.
Quickstart
# Clone the repository
git clone git@github.com:genesiscode2026/genesis-release-risk-changelog.git
cd genesis-release-risk-changelog
# Evaluate release risk since last tag or commit range
./bin/genesis-release-risk /path/to/repo --since v1.0.0
# Generate formatted Markdown changelog
./bin/genesis-release-risk /path/to/repo --since v1.0.0 --changelog
# Enforce CI deployment risk gate
./bin/genesis-release-risk . --since origin/main --max-risk 50
Commercial Distribution
- Product Name:
genesis-release-risk-changelog - Catalog ID:
P14 - Price: $29
- Seller:
genesiscode2026 - Authorized Payout Rail: USDC on Base (
0xC6F86e170411182114FcCdb28793dC76B5e8D144) - License: MIT
Security scan report
Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from X402 Git and Socket are listed below.
- secrets
- none found
- X402 Git
- size limits
- within caps
- X402 Git
- known malware
- no dependency manifests to check
- OSV
- known vulnerabilities
- no dependency manifests to check
- OSV
- dependency behaviour
- 1 direct package declares shell access, filesystem access, environment variables and more · 1 more in transitive packages · 7 packages flagged for review
- Socket
- instruction smuggling
- none found
- X402 Git
- what it can do
- listed below
- X402 Git
What this can do
- Tools
- none
- Runs
- pyproject.toml ([build-system])
- bin/genesis-release-risk
- genesis_release_risk/__main__.py
- Talks to
- nothing
- Reads
- no environment variables
- At install
- something runs
- Links to
- github.com
- img.shields.io
- keepachangelog.com
- semver.org
Findings (23)
- MODERATEpyproject.toml — [build-system] runs when this is installed
- MODERATEsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — ships compiled native code
- MODERATEsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — ships compiled native code
- MODERATEsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — runs shell commands
- MODERATEsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — runs shell commands
- MODERATEsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — evaluates code at runtime
- MODERATEsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — evaluates code at runtime
- LOWsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — reads environment variables
- LOWsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — reads environment variables
- LOWsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — reads or writes files
- LOWsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — reads or writes files
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible
- LOWbin/genesis-release-risk — Ships the script bin/genesis-release-risk
- LOWgenesis_release_risk/__main__.py — Ships the script genesis_release_risk/__main__.py
- LOWsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — contains hard-coded URLs
- LOWsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — contains hard-coded URLs
Releases 1
- v1.0.02026-09-17
Production-ready release. Generates risk-annotated changelogs by analyzing commit history and code diffs.