ReleaseFlow

An open-source application that turns merged pull requests into human-reviewed release notes that cannot change once published.

ReleaseFlow illustration: pull requests pass through classification and a human reviewer, then become a locked release note.

ReleaseFlow is an open-source web application (Apache-2.0) that helps a team write release notes from the changes it has actually merged. GitHub pull requests, GitLab merge requests, and completed Linear and Jira issues are recorded as changes, classified by explainable rules, summarised by AI if you enable it, and taken through a review before they become release notes. Once published, a note is locked in both the application and the database.

Highlights

  • Four change sources: signed webhooks for GitHub, GitLab, and Linear, polling for Jira Cloud, and a 90-day history import for GitHub and GitLab.

  • Rules first, AI second: OpenAI, Anthropic, or DeepSeek is asked exactly once per change, and can never clear a breaking flag the rules set.

  • A DRAFT → IN_REVIEW → APPROVED → PUBLISHED release lifecycle in which every change needs a reviewer’s decision.

  • A separate note for each audience (operator, contributor, end user) through Mustache templates, in up to five languages via DeepL.

  • Automation that delivers a published note to GitHub Releases, Slack, email, Notion, Confluence, Microsoft Teams, Zendesk, and a public changelog with RSS.

  • Multi-tenant on one PostgreSQL schema, secrets encrypted with AES-256-GCM, and Prometheus metrics that never carry tenant information.

  • Try a release with nothing but Docker: every release ships compose.yaml (the image pinned by digest) and quickstart.sh, which generates the secrets, so there is no repository to clone. The JAR and image come with an SBOM, SHA256SUMS, and a provenance attestation to verify them.

Screenshots

ReleaseFlow’s Change Inbox with filters for project, category, status, and context, a Source sync panel for the acme/checkout-web repository, and change #109 labelled Feature and marked Needs review
Figure 1. Change Inbox: changes are classified by rules, and breaking or unrecognised changes wait for a reviewer
The published release 1.4.0 page, naming who approved and published it, with Contributor, End user, and Operator tabs and the note’s Markdown beside Copy and Download buttons
Figure 2. A published release: one note per audience, locked as an immutable snapshot

The full screenshot tour follows one release from an empty workspace to a note delivered by email, Slack, Notion, and a public changelog.

Technology

Java 21 · Spring Boot 4 · PostgreSQL · Flyway · Thymeleaf · Tailwind CSS · Alpine.js · Docker · Prometheus · Grafana

ReleaseFlow is a modular monolith: one Maven module and one JAR, with code packaged by product capability (change, release, audience, automation…​). Background work runs from queue tables in PostgreSQL claimed with FOR UPDATE SKIP LOCKED, so several instances can run side by side without a message broker or leader election.

Current status

The first version, v0.1.0, was released on 23 September 2026 with every slice of the original plan. The latest is v0.2.1 (3 October 2026): v0.1.1 fixes what running one whole release on the demo stack turned up, v0.2.0 adds the quickstart bundle, and the repository now holds 31 ADRs recording the architectural decisions. Some things are still deliberately left out: changing roles or removing members, rotating secrets and tokens, paging and search in the Change Inbox, and correcting or withdrawing a published release note. The quickstart and the demo Docker Compose stack are both for one machine, not a production configuration.

Article series

  1. Building ReleaseFlow: from merged pull requests to release notes — the problem, the modular-monolith architecture, and durable queues in PostgreSQL.

  2. AI suggests, people decide — rules before AI, the review lifecycle, and immutable release notes.

  3. Securing a multi-tenant app that takes webhooks from strangers — tenant isolation, signed webhooks, secret encryption, and observability.