Skip to content

ci: align library release verification - #27

Merged
strider2038 merged 3 commits into
masterfrom
ci/align-library-releases
Oct 2, 2026
Merged

strider2038 merged 3 commits into
masterfrom
ci/align-library-releases

Conversation

@strider2038

@strider2038 strider2038 commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Changes

Share required verification between PR CI and maintainer-dispatched releases: existing quality gates, minimum-Go build/tests, and Security using govulncheck v1.8.0 with Go 1.26.6. Security fails on findings and scanner/setup errors and retains summaries and scanner output artifacts. There is no legacy security job in CI or releases; old-toolchain security audits can be performed manually when needed.

Validate the immutable release candidate and any changelog-only child before pushing; verify the published module from an external consumer. Preserve project-specific checks.

Release documentation explains the compatibility/security policy and identifies quality/minimum/Security as the required checks to configure in branch protection. Hosted rules currently have no required checks configured.

Validation

  • actionlint, shell syntax and git diff --check passed.
  • Scanner fixtures verify clean results, findings, operational errors, missing scanner and failed toolchain preflight; every nonzero scanner result fails.
  • Prior CI passed all library checks (Squirrel fuzz timed out once and passed on retry). CI reruns on this update.
  • No release or tag was created.

@strider2038 strider2038 changed the title ci: align verification and library release workflows ci: align library release verification Oct 2, 2026
@strider2038
strider2038 merged commit f7e69ec into master Oct 2, 2026
3 checks passed
@strider2038
strider2038 deleted the ci/align-library-releases branch October 2, 2026 11:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant