Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
77 commits
Select commit Hold shift + click to select a range
ed2b567
docs: replace release process with production flow
vitormattos Sep 21, 2026
cbddcea
docs: add release preparation guide
vitormattos Sep 21, 2026
e4366c2
docs: add release versioning guide
vitormattos Sep 21, 2026
3bf94e6
docs: add milestone and backport guide
vitormattos Sep 21, 2026
bdff1e5
docs: add release publication guide
vitormattos Sep 21, 2026
38e4117
docs: add manual release recovery guide
vitormattos Sep 21, 2026
58a75a6
docs: add release history navigation
vitormattos Sep 21, 2026
03c35c5
docs: link release history
vitormattos Sep 21, 2026
fb2c231
docs: add LibreSign 13.4.1 release history
vitormattos Sep 21, 2026
84fc0c1
docs: add LibreSign 13.4.0 release history
vitormattos Sep 21, 2026
35221c9
docs: add LibreSign 13.3.0 release history
vitormattos Sep 21, 2026
d1432c6
docs: add LibreSign 13.2.7 release history
vitormattos Sep 21, 2026
8728ff3
docs: add LibreSign 13.2.6 release history
vitormattos Sep 21, 2026
7f56e0f
docs: add LibreSign 13.2.5 release history
vitormattos Sep 21, 2026
4bd2398
docs: add LibreSign 13.2.4 release history
vitormattos Sep 21, 2026
4253f56
docs: add LibreSign 13.2.3 release history
vitormattos Sep 21, 2026
3b45bf1
docs: add LibreSign 13.2.2 release history
vitormattos Sep 21, 2026
e92e98b
docs: add LibreSign 13.2.1 release history
vitormattos Sep 21, 2026
8257d76
docs: add LibreSign 13.2.0 release history
vitormattos Sep 21, 2026
1bbb46d
docs: add LibreSign 13.1.3 release history
vitormattos Sep 21, 2026
5b22847
docs: add LibreSign 13.1.2 release history
vitormattos Sep 21, 2026
9019f29
docs: add LibreSign 13.1.1 release history
vitormattos Sep 21, 2026
67b1161
docs: add LibreSign 13.1.0 release history
vitormattos Sep 21, 2026
74c69c0
docs: add LibreSign 13.0.3 release history
vitormattos Sep 21, 2026
2272dc0
docs: add LibreSign 13.0.2 release history
vitormattos Sep 21, 2026
2f1b393
docs: add LibreSign 13.0.1 release history
vitormattos Sep 21, 2026
6ad99e8
docs: add LibreSign 13.0.0 release history
vitormattos Sep 21, 2026
221589a
docs: index LibreSign 13 releases
vitormattos Sep 21, 2026
bbd03c5
docs: add LibreSign 14.2.1 release history
vitormattos Sep 21, 2026
85a7d2f
docs: add LibreSign 14.2.0 release history
vitormattos Sep 21, 2026
1d6300e
docs: add LibreSign 14.1.0 release history
vitormattos Sep 21, 2026
e2cbb23
docs: add LibreSign 14.0.2 release history
vitormattos Sep 21, 2026
c0804f2
docs: add LibreSign 14.0.1 release history
vitormattos Sep 21, 2026
599d435
docs: add LibreSign 14.0.0 release history
vitormattos Sep 21, 2026
9ee1444
docs: index LibreSign 14 releases
vitormattos Sep 21, 2026
ba40b33
docs: add LibreSign 15.0.3 release history
vitormattos Sep 21, 2026
929e494
docs: add LibreSign 15.0.2 release history
vitormattos Sep 21, 2026
1d8b432
docs: add LibreSign 15.0.1 release history
vitormattos Sep 21, 2026
b5a4f3d
docs: add LibreSign 15.0.0 release history
vitormattos Sep 21, 2026
ff75b82
docs: index LibreSign 15 releases
vitormattos Sep 21, 2026
443fee0
docs: fix LibreSign 15.0.3 release history
vitormattos Sep 21, 2026
249f3b4
docs: fix LibreSign 15.0.2 release history
vitormattos Sep 21, 2026
16c5c27
docs: fix LibreSign 15.0.1 release history
vitormattos Sep 21, 2026
ec21cef
docs: fix LibreSign 15.0.0 release history
vitormattos Sep 21, 2026
71f4008
docs: fix LibreSign 14.2.1 release history
vitormattos Sep 21, 2026
ed29841
docs: fix LibreSign 14.2.0 release history
vitormattos Sep 21, 2026
1a77cbd
docs: fix LibreSign 14.1.0 release history
vitormattos Sep 21, 2026
e56d9d5
docs: fix LibreSign 14.0.2 release history
vitormattos Sep 21, 2026
c84df49
docs: fix LibreSign 14.0.1 release history
vitormattos Sep 21, 2026
f671398
docs: fix LibreSign 14.0.0 release history
vitormattos Sep 21, 2026
46422e7
docs: fix LibreSign 13.4.1 release history
vitormattos Sep 21, 2026
c653cd0
docs: fix LibreSign 13.4.0 release history
vitormattos Sep 21, 2026
3d08731
docs: fix LibreSign 13.3.0 release history
vitormattos Sep 21, 2026
5f5b70b
docs: fix LibreSign 13.2.7 release history
vitormattos Sep 21, 2026
a7b3d0b
docs: fix LibreSign 13.2.6 release history
vitormattos Sep 21, 2026
c8da170
docs: fix LibreSign 13.2.5 release history
vitormattos Sep 21, 2026
38289dd
docs: fix LibreSign 13.2.4 release history
vitormattos Sep 21, 2026
7dc0672
docs: fix LibreSign 13.2.3 release history
vitormattos Sep 21, 2026
cd30d59
docs: fix LibreSign 13.2.2 release history
vitormattos Sep 21, 2026
281c325
docs: fix LibreSign 13.2.1 release history
vitormattos Sep 21, 2026
ff352cb
docs: fix LibreSign 13.2.0 release history
vitormattos Sep 21, 2026
e34c4f7
docs: fix LibreSign 13.1.3 release history
vitormattos Sep 21, 2026
56200b6
docs: fix LibreSign 13.1.2 release history
vitormattos Sep 21, 2026
2ba805b
docs: fix LibreSign 13.1.1 release history
vitormattos Sep 21, 2026
a870e92
docs: fix LibreSign 13.1.0 release history
vitormattos Sep 21, 2026
35abc64
docs: fix LibreSign 13.0.3 release history
vitormattos Sep 21, 2026
4156822
docs: fix LibreSign 13.0.2 release history
vitormattos Sep 21, 2026
2f42d2d
docs: fix LibreSign 13.0.1 release history
vitormattos Sep 21, 2026
3899059
docs: fix LibreSign 13.0.0 release history
vitormattos Sep 21, 2026
5a199f8
ci: validate documentation pull requests
vitormattos Sep 21, 2026
e51bcec
ci: validate final documentation state
vitormattos Sep 21, 2026
1029770
ci: fail on developer documentation warnings
vitormattos Sep 21, 2026
493b4c3
docs: fix feature request image reference
vitormattos Sep 21, 2026
999b0e2
docs: include feature request guide in navigation
vitormattos Sep 21, 2026
0055724
docs: describe release tool configuration
vitormattos Sep 21, 2026
3832a34
docs: link release tool configuration
vitormattos Sep 21, 2026
7325cb4
docs: keep changelog only in LibreSign repository
vitormattos Sep 21, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 40 additions & 0 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors
# SPDX-License-Identifier: AGPL-3.0-or-later

name: Documentation

# Validate the complete documentation tree for pull requests.

on:
pull_request:

permissions:
contents: read

jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Set up Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: '3.12'
cache: pip

- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements.txt

- name: Build documentation
run: |
sphinx-build main _build/main
sphinx-build user_manual _build/user_manual
sphinx-build admin_manual _build/admin_manual
sphinx-build -W developer_manual _build/developer_manual
1 change: 1 addition & 0 deletions developer_manual/index.rst
Original file line number Diff line number Diff line change
Expand Up @@ -31,4 +31,5 @@ Here you will find all the documentation for developers.
getting-started/index
api/index
translation
requesting-features
release-process
391 changes: 26 additions & 365 deletions developer_manual/release-process.rst

Large diffs are not rendered by default.

69 changes: 69 additions & 0 deletions developer_manual/release-process/configuration.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
.. SPDX-FileCopyrightText: 2026 LibreCode coop and contributors
.. SPDX-License-Identifier: AGPL-3.0-or-later

Release tool and consumer configuration
=======================================

LibreSign release policy is executed by the versioned ``release-tool.phar`` distributed by ``LibreCodeCoop/release-tool``.
The reusable workflow pins an exact release-tool version and verifies its published SHA-256 checksum before execution. Do not replace that pin with a floating ``latest`` download.

Local installation
------------------

For diagnostics or manual recovery, download the same ``release-tool.phar`` and ``release-tool.phar.sha256`` release used by ``LibreCodeCoop/github-workflows``.
Verify the checksum before running the PHAR:

.. code-block:: bash

sha256sum --check release-tool.phar.sha256
php release-tool.phar --version

The reported version must match the version pinned by the reusable setup action.

Consumer configuration
----------------------

LibreSign keeps its release configuration in ``.nextcloud-release.yml``. The configuration is validated by the release tool before planning or mutation.

The main sections are:

``repository`` and ``app``
Repository identity, app id and main branch.

``branches``
Stable branch naming pattern and release-line mapping.

``version``
Authoritative version source, mirrors and Git tag prefix.

``history``
How the previous released baseline is selected.

``changelog``
Per-major source path and the package-root changelog destination.

``milestones``
Stable and prerelease milestone naming templates.

``authorization``
Minimum repository permissions required to start mutating preparation and to merge a generated release PR.

``package``
Package build command plus required and forbidden archive paths used by artifact validation.

``publication``
Existing publisher workflow, expected GitHub Release asset name and Nextcloud App Store API used by post-publication verification.

Validation
----------

Validate the configuration without changing repository state:

.. code-block:: bash

php release-tool.phar config:validate \
--config .nextcloud-release.yml \
--root . \
--json

Unknown keys and invalid values fail closed. Repository-specific behavior should be expressed through this configuration or a release-tool adapter, not copied into workflow YAML.
45 changes: 45 additions & 0 deletions developer_manual/release-process/manual.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
.. SPDX-FileCopyrightText: 2026 LibreCode coop and contributors
.. SPDX-License-Identifier: AGPL-3.0-or-later

Manual procedure and troubleshooting
====================================

The automated workflow is the normal path. Manual commands are useful for diagnostics and recovery, but they must follow the same policy.

Read-only planning
------------------

Download the verified ``release-tool.phar`` version used by ``LibreCodeCoop/github-workflows`` and its SHA-256 file, verify the checksum, then run:

.. code-block:: bash

php release-tool.phar config:validate --config .nextcloud-release.yml --root . --json
php release-tool.phar release:plan --config .nextcloud-release.yml --root . --branch stableXX --channel final --mode normal --json

The plan output should identify the previous reachable release tag, exact planning SHA, proposed version, target per-major changelog, milestone and blockers.

Manual equivalent
-----------------

1. Identify the previous reachable release tag from the selected branch.
2. Inspect release activity since that tag and apply the same patch/minor/channel policy.
3. Check open backport blockers for that stable line.
4. Update only the selected per-major changelog and configured version files.
5. Ensure the package build copies that per-major changelog to package-root ``CHANGELOG.md``.
6. Merge the release PR using an authorized maintainer.
7. Revalidate the merged SHA and release-file digests.
8. Rotate the milestone using the same configured policy.
9. Create a GitHub Release draft for the finalized SHA and released changelog section.
10. Publish it and let the existing publisher build/sign/upload the package.
11. Verify publisher success, artifact identity/content and App Store visibility.
12. Keep the released changelog in ``LibreSign/libresign`` as the canonical history; do not duplicate it in the documentation repository.

Recovery rules
--------------

* If planning is stale because the branch advanced, generate a new plan. Do not reuse the stale one.
* If the generated release PR contains files outside the allowed release set, stop and investigate.
* If the release branch advances after the release PR merge, do not create the draft from the old finalized state.
* If publication fails, fix the publisher problem and rerun verification. Do not reinterpret or regenerate release notes.
* If a tag/release points to the wrong commit, repair the GitHub Release/tag identity before publication verification can succeed.
* For security mode, never put advisory-private details in workflow inputs, changelog text, artifacts or public documentation.
15 changes: 15 additions & 0 deletions developer_manual/release-process/milestones.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
.. SPDX-FileCopyrightText: 2026 LibreCode coop and contributors
.. SPDX-License-Identifier: AGPL-3.0-or-later

Milestones and backports
========================

Stable releases use the configured ``Next Patch (<Nextcloud major>)`` milestone. Release candidates use the configured RC milestone policy.

Before preparation, the release plan checks matching open backport work. A blocker stops preparation unless the maintainer explicitly selected ``ignore_open_backport``.

After the release PR is merged, the workflow revalidates the merged state before any milestone mutation. It then renames/closes the released milestone, moves remaining open work when required, and optionally creates the next milestone.

The account that merged the generated release PR must satisfy ``authorization.merge_min_permission`` from ``.nextcloud-release.yml``. The triggering actor for preparation must satisfy ``authorization.prepare_min_permission``.

These permission checks happen before mutating stages. Mutations use short-lived GitHub App installation tokens scoped to the repository and stage.
45 changes: 45 additions & 0 deletions developer_manual/release-process/preparing.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
.. SPDX-FileCopyrightText: 2026 LibreCode coop and contributors
.. SPDX-License-Identifier: AGPL-3.0-or-later

Preparing a release
===================

Start the **Prepare release** workflow in ``LibreSign/libresign``.

The workflow builds a read-only release plan first. The plan identifies the previous reachable release tag, exact planning SHA, release activity, proposed version, changelog target, milestone state and open backport blockers.

Inputs
------

``branch``
Stable branch to release.

``ref``
Optional exact commit or ref for reproducing or recovering a known planning state.

``version``
Optional explicit version override. Branch/version consistency is still validated.

``channel``
``alpha``, ``beta``, ``rc`` or ``final``.

``ignore_open_backport``
Explicit override for a matching open backport blocker. It is never implied automatically.

``create_follow_up_milestone``
Whether a follow-up milestone should be created during the post-merge transition.

``mode``
``normal`` or ``security``.

``safe_public_text``
Public-safe wording for security mode. Advisory-private details must not be put in public release text.

Generated PR
------------

The preparation PR is deterministic and may change only the configured release files: the per-major changelog plus the version source and mirrors.

For LibreSign these are the per-major changelog, ``appinfo/info.xml``, ``package.json`` and ``package-lock.json``.

The selected stable branch is authoritative for the release. For a stable release, the exact released changelog section is synchronized back to the aggregate history on ``main`` without copying the stable version files into ``main``.
34 changes: 34 additions & 0 deletions developer_manual/release-process/publishing.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
.. SPDX-FileCopyrightText: 2026 LibreCode coop and contributors
.. SPDX-License-Identifier: AGPL-3.0-or-later

Publishing and verification
============================

After the generated release PR is merged, the workflow produces a finalized release contract from the merged SHA and creates or updates a GitHub Release draft.

Review the draft and use GitHub's **Publish release** action when it is correct. Publishing is the second and final semantic human gate.

Existing publisher
------------------

Publishing the GitHub Release triggers the existing LibreSign package/sign/App Store workflow. The release automation does not duplicate that publisher.

Publication verification
------------------------

After publication, the workflow waits for the existing publisher and validates:

* the GitHub Release is published and still points to the finalized tag/SHA;
* the configured publisher workflow completed successfully for that release;
* the expected release asset exists;
* artifact digest and package contents satisfy the configured package contract;
* the same version is visible in the Nextcloud App Store.

Verification is independently rerunnable. Bounded retries handle eventual consistency only; they do not replace release validation rules.

Changelog source
----------------

The released changelog remains in ``LibreSign/libresign`` under ``docs/changelogs/changelog-<major>.md``. This documentation repository does not copy or maintain a second release-history dataset.

For security releases, advisory-private text must never be added to the public changelog or documentation.
27 changes: 27 additions & 0 deletions developer_manual/release-process/versioning.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
.. SPDX-FileCopyrightText: 2026 LibreCode coop and contributors
.. SPDX-License-Identifier: AGPL-3.0-or-later

Versioning and prereleases
==========================

LibreSign versions follow ``MAJOR.MINOR.PATCH``. The app major tracks the supported Nextcloud major used by the corresponding stable line.

Normal version selection is derived from release activity since the previous reachable release tag. Feature-level activity advances the minor line; fixes and maintenance advance the patch line. Translation-only activity does not create a feature bump.

An explicit version override is supported for recovery or deliberate release decisions, but the release tool validates it against the selected branch and configured release files.

Prerelease channels
-------------------

``alpha`` and ``beta`` are prerelease channels for incomplete release lines. ``rc`` is a release candidate. ``final`` is the normal stable publication.

The selected channel is carried through the release contracts and determines whether the generated GitHub Release is marked as a prerelease.

Per-major changelogs
--------------------

Canonical release text lives in ``docs/changelogs/changelog-<major>.md`` in ``LibreSign/libresign``. Each major has its own file, avoiding conflicts between stable branches.

For packaging, the selected per-major file is copied to package-root ``CHANGELOG.md``. The package does not fetch this documentation repository.

GitHub Release notes are derived from the same released section. The changelog itself is maintained only in ``LibreSign/libresign``; this documentation repository does not duplicate it.
2 changes: 1 addition & 1 deletion developer_manual/requesting-features.rst
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ Follow these steps to request a feature:

2 - Go to the "Issues" tab.

.. figure:: images/issue_screen.png
.. figure:: images/choose_issue_screen.png
:alt: Main screen.

* 1 - Issue tab
Expand Down
Loading