Traceary changelog

A site that keeps other people’s release notes should keep its own. This page is built from the same components as every product page in the archive, so it is also the shortest description of what those pages do.

0.x4 releases

0.4.0

The notes become searchable, and Kubernetes gets its advisories

added3

  • Search inside the notes themselves. Text matching covered the product, the version and a 150 character summary, so "oauth" found 10 records while the notes hold 105. The whole archive is 12.9 MB of prose, 52,625 words and 407,818 postings; as one file the index is 634 kB even packed, so it is split by first letter into 27 files averaging 24 kB and a search fetches only the one or two its words begin with. A kept word is answered by prefix when the exact word is not there, and several kept words narrow each other. Measured: oauth 10 to 105, browser 42 to 218, memory 39 to 287, deprecat 34 to 309.
  • Kubernetes advisories, 91 of them, from the CVE feed the project publishes itself. Advisories had come only from a repository’s own GitHub filings and Kubernetes files nowhere near them, so the product most likely to be audited showed none. Severity is taken only where the publisher wrote it beside the score, which is 24 times out of 91 and in six different notations; the rest stay unrated rather than computed from a CVSS vector, and fixed versions stay empty because this feed states them as ranges and the field they would fill names an exact release.
  • A line naming the newest products above the index. Whatever later decides what that block shows will be built from what readers already reach, and a rule like that feeds itself: what is shown gets read, what is read stays shown, and a product added this week never gets in. The line is the place kept for the newest, and the date it uses is derived from the day the archive first held the product rather than maintained by hand.

fixed4

  • The privacy page, which said no client side code on this site makes a network request at all. The filter and the palette had been fetching a file of rows for some time, and searching the notes now fetches one index file chosen by the first letter of the word. That is the one place where what a reader types affects what is requested, and the page now says so, along with what it would have cost to hide even the letter.
  • The advisory identifier, which was the React key on three pages and is empty for anything filed outside GitHub. Ninety one Kubernetes rows would have shared one blank key.
  • Thirty four addresses on this site that were 404s. A release its publisher shipped with no notes is held, counted and listed, but gets no page of its own, and nine places built a link out of its id anyway. Found by walking all 73,359 internal links across 3,358 pages, which had never been done. Every one of them now goes through one function that sends the reader to the product when there is no release page, and the version is still named either way.
  • A link a publisher wrote as "/docs/sandbox", which on this domain pointed at us rather than at them. Relative addresses inside collected notes are now resolved against the address the note came from, which is not editing what they wrote but spelling out the address they meant.
Tagged v0.4.0
0.3.0

The archive stops treating a build stamp as a release

fixed4

  • The line between a record existing and a record saying something, which was drawn nowhere. The home page, the site feed and the command palette ranked a CVE announcement and a nightly build stamp the same way, because time was the only criterion and time cannot tell them apart. 492 of 3,111 records describe no change at all: a build stamp, a note pointing at another document, a subpackage matching its dependency, or one tag republished forever. They stay in the archive and on their product page, and they no longer take a place in a list that crosses products.
  • Three products that looked like they published no notes. Kubernetes, Vue and Vite write a sentence naming their CHANGELOG and the notes are in it, so the collector was reading the wrong document. 169 records went from "see the CHANGELOG" to the publisher’s own text, and Kubernetes records carry change labels for the first time, 11 of them marked security.
  • The count beside each day on the home page, which counted the rows shown rather than the day. With a selection under it that read "1 release" on a day that carried 36. It now reads the day, and the rest of the day is one link away.
  • The order inside a day, which came from the order of the index and so put the product that publishes every day at the top of every day. Inside a day the product that publishes least often comes first: a release from something that ships monthly is an event, one from something that ships nightly is a Tuesday. The home page went from 16 products across 48 rows to 28.

added4

  • /stack, the archive read down one reader’s own list. Every other page here is filed by product, because publishers are, and a developer is not. The list lives in the address and in that browser, with no account, no server and no cookie, and Subscribe hands a feed reader all of it at once as an OPML file written in the browser.
  • A block on the home page for the three things the archive does that a release feed does not: advisories joined to the release that fixes them, the releases a publisher marked breaking, and the filter across every product. All three already existed and each was one word in the navigation. Every figure is counted at build time and the coverage is stated next to it.
  • Command K opens the palette, alongside the slash it already answered to.
  • A build guard against a product whose slug matches a page address. The failure would have been silent: the build succeeds, the fixed route answers, and that product’s whole history is never published.

changed1

  • The index of products on the home page, from a second copy of the catalogue into an index. It repeated every product’s summary and latest version, 5,743 characters saying what /catalog already says. One alphabetical order in aligned columns, every one of the 48 links kept, and the page’s own text down from 19,183 characters to 16,950.
Tagged v0.3.0
0.2.0

The archive becomes readable by machines, and stops forgetting

added7

  • A machine layer, so the archive can be read without parsing a page. /llms.txt says what is here and what it does not know, /catalog.json lists every tracked product, /[product]/releases.json returns one product’s history, and /status.json carries the collection record. None of the four existed at 0.1.0.
  • /[product]/advisories, which gives every published advisory its own row: 777 of them across 27 products. The security page had been saying it listed every advisory while showing 300, which left 348 reachable from nowhere.
  • The two pages only an archive can write. /[product]/breaking collects the releases a publisher marked as breaking, 9 pages, and /[product]/compare/[range] reads one major line against the next, 20 pages. Both are built from what was already collected rather than from anything new.
  • A context block on every release page, which says what happened after that version: how long it stood, what came next, and which advisories closed against it.
  • The legal pages, /terms, /privacy, /copyright and /imprint, and a removal register behind them. A withheld entry is filtered from the stored side as well as the incoming one, so a takedown holds even after the entry falls out of the publisher’s own window.
  • A sentinel that asks all 45 sources every five minutes whether anything moved, and wakes the collection job when something has, under a daily ceiling on how many builds it may ask for. The four hourly schedule is now the floor rather than the clock.
  • An outage log on the status page, along with the measured cadence of each source.

fixed2

  • The collector, which was a mirror calling itself an archive. Each run wrote the newest entries a source listed and dropped everything older, so a single day took 16 published pages off the site. Runs are merged into what is already held, and the 127 pages that had been dropped came back.
  • The day an entry is filed under. A publisher that stamps a release in the future was folding into today and reordering the history around it. Entries are now filed under the day they appeared, and marked when their own date runs ahead.

changed2

  • What the run log keeps, from four months to a year, because a source that fails once a quarter looked healthy in a window shorter than its own period. A year is also the default view now.
  • The archive itself grew from 36 products to 45 and from 2,034 releases to 2,752 across the same period. Products are added by hand at two or three a day, each one measured against the weakest product already published before it is accepted.
Tagged v0.2.0
0.1.0

First working version

added8

  • Collects release notes for 36 developer, infrastructure and AI products through the GitHub Releases API and public RSS or Atom changelogs. Nothing is scraped and no browser is driven.
  • Every release with notes gets its own page and its own address, 1,991 of them at this version, plus a per product RSS feed and a feed covering everything.
  • Conditional requests mean a source that has published nothing costs one 304 response, and a day on which nothing changed produces no commit, no build and no deployment.
  • Tags are split into the package they belong to and the version, so Astro shows 7.2.7 rather than astro@7.2.7 and PostHog shows desktop 0.61.35 rather than an unlabelled 0.61.35.
  • Version history bands by major release line rather than by publication order, which keeps products such as Node.js readable while they maintain several lines at once.
  • A copy guard runs before every build and rejects the writing patterns that mark machine written English. A layout guard checks the page gutter, rejects colours written outside the palette, and measures every text tone against its own background.
  • The build measures its own output against the 20,000 file ceiling the static host enforces, and fails before a deployment can be refused.
  • A status page reports the collection job, day by day, and names a source only when that source is failing. How current any one product is sits on that product’s own page, under its facts, next to the releases it affects.
Tagged v0.1.0

Traceary follows semantic versioning, and the number that matters most is the one on the collected data. A change to the shape of a release address is a breaking change, because every link anyone has made to a version page depends on it.