Skip to content

Automate verified tag release publishing - #6

Merged
JAORMX merged 1 commit into
mainfrom
ci/automated-releases
Sep 21, 2026
Merged

JAORMX merged 1 commit into
mainfrom
ci/automated-releases

Conversation

@JAORMX

@JAORMX JAORMX commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Publish a GitHub release with generated notes when an authorized releaser creates a stable v0/v1 tag.
  • Verify the exact event/tag/checkout SHA, main ancestry, module path and SemVer before running fresh release checks with read-only permissions.
  • Isolate contents:write in a no-checkout publisher; recheck the fully qualified tag before gh release create --verify-tag.
  • Reject tag-update events, invalid versions, missing/moved tags, and existing releases without overwriting them.
  • Pin actions, disable caches, and keep live inference tests off.

Verification

Offline tests, race tests, vet, both fuzz smoke targets, actionlint, and independent DevOps/security/QA review passed. Regression tests execute the actual inline workflow scripts with isolated environments and mocked git/gh; no network publication is used.

Before the first release

An administrator must configure and verify v* tag rules restricting creation and preventing updates/deletion. The repository currently has no such ruleset; this PR deliberately does not change repository settings. The final SHA recheck cannot make tag lookup and release creation atomic.

Pushing a public Go module tag can expose that version before this workflow completes. Pre-tag review and CI remain mandatory. Module-proxy verification remains a manual post-publication step because indexing is eventually consistent.

No release, tag, workflow dispatch, SDK API change, or live inference call was performed.

Signed-off-by: Juan Antonio Osorio <ozz@stacklok.com>
@JAORMX
JAORMX merged commit 10b7302 into main Sep 21, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant