Repository navigation
Automate verified tag release publishing - #6
Merged
Merged
Conversation
Signed-off-by: Juan Antonio Osorio <ozz@stacklok.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Verification
Offline tests, race tests, vet, both fuzz smoke targets, actionlint, and independent DevOps/security/QA review passed. Regression tests execute the actual inline workflow scripts with isolated environments and mocked git/gh; no network publication is used.
Before the first release
An administrator must configure and verify v* tag rules restricting creation and preventing updates/deletion. The repository currently has no such ruleset; this PR deliberately does not change repository settings. The final SHA recheck cannot make tag lookup and release creation atomic.
Pushing a public Go module tag can expose that version before this workflow completes. Pre-tag review and CI remain mandatory. Module-proxy verification remains a manual post-publication step because indexing is eventually consistent.
No release, tag, workflow dispatch, SDK API change, or live inference call was performed.