ReleaseFlow
An open-source application that turns merged pull requests into human-reviewed release notes that cannot change once published.
ReleaseFlow is an open-source web application (Apache-2.0) that helps a team write release notes from the changes it has actually merged. GitHub pull requests, GitLab merge requests, and completed Linear and Jira issues are recorded as changes, classified by explainable rules, summarised by AI if you enable it, and taken through a review before they become release notes. Once published, a note is locked in both the application and the database.
Highlights
-
Four change sources: signed webhooks for GitHub, GitLab, and Linear, polling for Jira Cloud, and a 90-day history import for GitHub and GitLab.
-
Rules first, AI second: OpenAI, Anthropic, or DeepSeek is asked exactly once per change, and can never clear a breaking flag the rules set.
-
A
DRAFT → IN_REVIEW → APPROVED → PUBLISHEDrelease lifecycle in which every change needs a reviewer’s decision. -
A separate note for each audience (operator, contributor, end user) through Mustache templates, in up to five languages via DeepL.
-
Automation that delivers a published note to GitHub Releases, Slack, email, Notion, Confluence, Microsoft Teams, Zendesk, and a public changelog with RSS.
-
Multi-tenant on one PostgreSQL schema, secrets encrypted with AES-256-GCM, and Prometheus metrics that never carry tenant information.
-
Try a release with nothing but Docker: every release ships
compose.yaml(the image pinned by digest) andquickstart.sh, which generates the secrets, so there is no repository to clone. The JAR and image come with an SBOM,SHA256SUMS, and a provenance attestation to verify them.
Screenshots
The full screenshot tour follows one release from an empty workspace to a note delivered by email, Slack, Notion, and a public changelog.
Technology
Java 21 · Spring Boot 4 · PostgreSQL · Flyway · Thymeleaf · Tailwind CSS · Alpine.js · Docker · Prometheus · Grafana
ReleaseFlow is a modular monolith: one Maven module and one JAR, with code packaged by product capability (change, release, audience, automation…). Background work runs from queue tables in PostgreSQL claimed with FOR UPDATE SKIP LOCKED, so several instances can run side by side without a message broker or leader election.
Current status
The first version, v0.1.0, was released on 23 September 2026 with every slice of the original plan. The latest is v0.2.1 (3 October 2026): v0.1.1 fixes what running one whole release on the demo stack turned up, v0.2.0 adds the quickstart bundle, and the repository now holds 31 ADRs recording the architectural decisions. Some things are still deliberately left out: changing roles or removing members, rotating secrets and tokens, paging and search in the Change Inbox, and correcting or withdrawing a published release note. The quickstart and the demo Docker Compose stack are both for one machine, not a production configuration.
Article series
-
Building ReleaseFlow: from merged pull requests to release notes — the problem, the modular-monolith architecture, and durable queues in PostgreSQL.
-
AI suggests, people decide — rules before AI, the review lifecycle, and immutable release notes.
-
Securing a multi-tenant app that takes webhooks from strangers — tenant isolation, signed webhooks, secret encryption, and observability.