Skip to content

Add validated, human-approved Git source releases - #8

Merged
first-assist merged 1 commit into
mainfrom
build/upstream-release-automation-20260915
Sep 14, 2026
Merged

first-assist merged 1 commit into
mainfrom
build/upstream-release-automation-20260915

Conversation

@first-assist

Copy link
Copy Markdown
Collaborator

agql-auth has no repeatable GitHub release workflow. This adds CI and a manual release workflow that validates the selected current-main commit, requires the designated human reviewer on the release environment, and publishes an annotated version tag with attested source-manifest and checksum assets.

The library remains 0.19.0 with no source or public API changes. A tracked lockfile fixes the Rust 1.90.0 validation inputs. Release policy checks and eight disposable-repository tests cover version changes, registry-publication rejection, new feature lanes, and manifest integrity. Documentation updated: the README links the release process and uses the actual Git-only dependency source.

Validation:

  • Rustfmt and actionlint pass.
  • Default and no-default-features lanes each pass warnings-denied Clippy, all 184 tests, and warnings-denied rustdoc.
  • cargo-semver-checks 0.46.0 accepts the 0.13.0 → 0.19.0 version increase (pre-1.0 major compatibility boundary).
  • Release metadata/policy checks and all eight Python tests pass; deterministic manifest preview generated from the committed tree.

Before publication, a repository administrator must configure the release environment with Dastari as a required reviewer, restrict it to main, and enable immutable releases. There is currently no release environment. The workflow fails closed if the designated reviewer is absent. Once merged and main CI passes, Toby dispatches version 0.19.0 at the merged main SHA and approves the environment; this PR does not publish a release.

@first-assist
first-assist merged commit 51f33bf into main Sep 14, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant