Skip to content

chore(release): prepare verified Renderflow integration candidate - #437

Merged
szmyty merged 1 commit into
mainfrom
feat/renderflow-419-integration-release
Sep 28, 2026
Merged

szmyty merged 1 commit into
mainfrom
feat/renderflow-419-integration-release

Conversation

@szmyty

@szmyty szmyty commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Refs #419. Keep #419 open until the immutable prerelease and downloaded-asset verification are complete.

Candidate

  • Proposes v0.3.0-rc.1 without moving historical v0.2.1. Initial binary scope is Ubuntu 24.04 x86_64 GNU, glibc 2.39.
  • Replaces the version-bump and broad release workflow with an exact annotated-tag/manual-dispatch gate: reviewed main SHA, green CI/docs/manual fast+maximal conformance, latest scheduled maximal success within eight days, and enabled GitHub release immutability.
  • Stages one binary, SHA-256 files, SPDX workspace-lock inventory, dependency/license notices, an exact Flow provider-lock manifest, and GitHub provenance/SBOM attestations. The binary/tag have no separate maintainer signature.
  • Verifies draft assets after download, including a pinned installer, exact-provider PDF and native EPUB synthetic execution, independent inspections, refusal behavior, and an offline no-checkout Ubuntu 24.04 container smoke before publication. Other distribution channels are marked unpublished or unverified.
  • Aligns README, docs, site copy, roadmap, changelog, installer, and package templates with the observed release status.

Local evidence

  • Rust 1.94: cargo test --workspace --all-targets --locked --offline, strict Clippy, formatting, core crate package verification, Linux x86_64 release binary build, and fast artifact conformance passed.
  • Seven release receipt/refusal tests and JSON Schema validation passed. The built binary passed isolated EPUB and real img2pdf 0.6.3 PDF smoke, including independent inspection, source-byte preservation, stale-input refusal, and file:// installer verification.
  • Strict MkDocs, web typecheck/lint/format, web tests/build, workflow YAML/Bash parsing, and whitespace checks passed.
  • Local attestation bundles were synthetic contract fixtures. GitHub signatures, Docker no-checkout gate, hosted CI, release immutability setting, and final downloaded GitHub assets remain release-time gates; no tag or release was created.

After review and merge

Enable immutable releases; provision RELEASE_SETTINGS_READ_TOKEN with repository Administration read only; obtain exact-commit CI/docs and manually dispatched fast+maximal conformance plus fresh scheduled evidence. Create a new annotated tag at the reviewed main commit and dispatch release.yml on that tag with expected_commit. Verify the published immutable prerelease and record its URL/digest before closing #419 or pinning it in Flow #52.

Direct Git push was unavailable, so the branch was published via GitHub Git Data. Its remote tree 067492895bc7a8383bc964ec41b796ee9f7e2de3 matches the validated local tree exactly.

@szmyty
szmyty merged commit 8e866f9 into main Sep 28, 2026
18 of 20 checks passed
@szmyty
szmyty deleted the feat/renderflow-419-integration-release branch September 28, 2026 16:56
@devactivity-app

Copy link
Copy Markdown

Pull Request Summary by devActivity

Metrics

Cycle Time: 40m

Achievements

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant