Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion developer_manual/release-process.rst
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ Release process

The normal LibreSign release path is driven from the **Prepare release** GitHub Actions workflow.

The reusable policy and contracts live in ``LibreCodeCoop/release-tool`` and orchestration lives in ``LibreCodeCoop/github-workflows``. ``LibreSign/libresign`` carries the consumer configuration and repository-specific packaging rules.
Release policy, contracts, the PHP runtime, and the three public lifecycle Actions live in ``LibreCodeCoop/release-tool``. LibreCode's managed workflow catalog and synchronization helper live in ``LibreCodeCoop/.github``. ``LibreSign/libresign`` carries the consumer configuration and repository-specific packaging rules.

Maintainer journey
------------------
Expand Down
6 changes: 3 additions & 3 deletions developer_manual/release-process/configuration.rst
Original file line number Diff line number Diff line change
Expand Up @@ -5,20 +5,20 @@ Release tool and consumer configuration
=======================================

LibreSign release policy is executed by the versioned ``release-tool.phar`` distributed by ``LibreCodeCoop/release-tool``.
The reusable workflow pins an exact release-tool version and verifies its published SHA-256 checksum before execution. Do not replace that pin with a floating ``latest`` download.
The LibreSign workflow pins the public Release Tool Actions to an immutable commit from a published release. Those Actions resolve the same repository ``VERSION`` and verify the published PHAR SHA-256 checksum before execution. Do not replace the immutable Action pin or verified PHAR with a floating ``latest`` reference.

Local installation
------------------

For diagnostics or manual recovery, download the same ``release-tool.phar`` and ``release-tool.phar.sha256`` release used by ``LibreCodeCoop/github-workflows``.
For diagnostics or manual recovery, download the same ``release-tool.phar`` and ``release-tool.phar.sha256`` release pinned by the LibreSign release workflow.
Verify the checksum before running the PHAR:

.. code-block:: bash

sha256sum --check release-tool.phar.sha256
php release-tool.phar --version

The reported version must match the version pinned by the reusable setup action.
The reported version must match the Release Tool version associated with the immutable Action commit used by the workflow.

Consumer configuration
----------------------
Expand Down
2 changes: 1 addition & 1 deletion developer_manual/release-process/manual.rst
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ The automated workflow is the normal path. Manual commands are useful for diagno
Read-only planning
------------------

Download the verified ``release-tool.phar`` version used by ``LibreCodeCoop/github-workflows`` and its SHA-256 file, verify the checksum, then run:
Download the verified ``release-tool.phar`` version published by ``LibreCodeCoop/release-tool`` and pinned by the LibreSign release workflow, together with its SHA-256 file. Verify the checksum, then run:

.. code-block:: bash

Expand Down
Loading