Stackray uses release-please, checked-in semantic versions, and GitHub Releases as the public release source of truth.
package.jsonowns the package version..release-please-manifest.jsonstores the current release-please version state.lib/version.tsexposes the same version to the app UI and server update checks. Release-please updates it through thex-release-please-versionannotation.
Do not tag releases by hand for normal work. A tag without a GitHub Release is intentionally ignored by deployed apps.
- Normal feature and fix PRs merge to
main. .github/workflows/release-please.ymlruns on each push tomain.- release-please reads Conventional Commit messages since the last release.
- If there are releasable changes, it opens or updates a release PR with the version bump and generated release notes.
- As more releasable commits merge, release-please updates the same release PR.
- When maintainers are ready to release, merge the release PR.
- release-please creates the
vX.Y.Ztag and GitHub Release.
Normal feature, fix, scanner pin, and catalog PRs should not manually bump the Stackray version.
Stackray release commits should follow Conventional Commits. When PRs are squash-merged, use a Conventional Commit PR title:
fix: correct Railway update copycreates a patch release.feat: add CSV exportcreates a minor release.feat!: change scan result API shapeor aBREAKING CHANGE:footer creates a breaking release.
Because Stackray is still pre-1.0, release-please-config.json sets bump-minor-pre-major so breaking changes advance the minor version instead of jumping directly to 1.0.0.
The scheduled scanner pin workflow refreshes httpx, nuclei, subfinder, and nuclei-template pins without changing the Stackray app version. Its automation PR uses a fix(scanner): ... title so release-please can include the scanner update in the pending release PR, but the update is not published until maintainers merge that release PR.
This keeps self-hosted deployments from seeing update banners for every automated scanner dependency update before a structured Stackray release exists.
Admin users see an update banner when their deployed APP_VERSION is older than the latest GitHub Release from STACKRAY_RELEASE_REPOSITORY, which defaults to CarlosCommits/stackray.
STACKRAY_GITHUB_TOKEN is optional for public repositories. Set it for private release repositories or to increase GitHub API rate limits.