Skip to content

chore: release v0.8.4 - #64

Merged
tobyhede merged 1 commit into
mainfrom
release-plz-2026-09-23T01-05-33Z
Sep 29, 2026
Merged

tobyhede merged 1 commit into
mainfrom
release-plz-2026-09-23T01-05-33Z

Conversation

@cipherstash-envelopers-release-plz

@cipherstash-envelopers-release-plz cipherstash-envelopers-release-plz Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

🤖 New release

  • envelopers: 0.8.3 -> 0.8.4 (✓ API compatible changes)
Changelog

0.8.4 - 2026-09-28

Other

  • Merge pull request chore: enable release-plz trusted publishing #65 from cipherstash/chore/cip-4135-enable-trusted-publishing
  • publish only when a release PR merges
  • check release workflow structurally and drop publish job write token
  • use app client-id and check release environment binding
  • harden release workflow invariants
  • (cip-4135) enable trusted publishing
  • record envelopers 0.8.3 release
  • (cip-4132) add release-plz observation workflow


This PR was generated with release-plz.

@freshtonic freshtonic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review of the first release-plz PR (observation phase, CIP-4132).

Summary: The generated output is correct and consistent. The version changes from 0.8.3 to 0.8.4 in Cargo.toml and Cargo.lock. The semver check reports API-compatible changes. The PR triggered test.yml through the GitHub App token, and all four checks pass. The new changelog section is below ## Unreleased, and that agrees with the Keep a Changelog format of the file. For step 4 of docs/research/release-plz.md, this PR is good evidence that the release-PR job operates correctly.

Recommendation: do not merge this PR yet.

  1. No publish job exists. .github/workflows/release-plz.yml has only the release-pr job. If you merge this PR now, main will declare 0.8.4, but nothing publishes 0.8.4 to crates.io and nothing creates a 0.8.4 tag. That is the same "declared but not released" condition that CIP-4131 had to reconcile for 0.8.3. Also, with release_always = false, the release job publishes only on a commit that merges a release PR. If you add the release job after this merge, it will possibly not publish 0.8.4 without a manual step. Keep this PR open (release-plz updates it on each push to main), or close it. Merge a release PR only after the Trusted Publishing release job is in place (rollout step 5).

  2. The release has no crate-facing change. Both changelog entries are internal (a CI workflow and a research document). See the inline comment.

  3. Compare link. The new heading links to compare/0.8.3...0.8.4. This link operates only if a 0.8.3 tag is on origin. My local clone has no 0.8.3 tag (the latest local tag is 0.8.2). Make sure that the tag exists before the first automated release. If it does not exist, the link and the release-plz tag history will be incorrect.

There are no blocking problems in the diff itself.

Comment thread CHANGELOG.md

@freshtonic freshtonic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated re-review of head 5c7daaa. The earlier review was on 31aa542.

Changes since the earlier review: release-plz rebased the PR on main after #68. The diff now has a third changelog entry, "(agents) track issues in GitHub instead of Linear". That commit (e90a5b0) changes only AGENTS.md, docs/agents/*, and docs/research/release-plz.md. It does not change the published crate. The version change (0.8.3 to 0.8.4 in Cargo.toml and Cargo.lock) is correct, and all four checks pass on this head.

The earlier findings are still applicable:

  1. No publish job. .github/workflows/release-plz.yml on main still has only the release-pr job. Do not merge this PR until the Trusted Publishing release job is in place (rollout step 5). If you merge it now, main declares 0.8.4, but nothing publishes it or tags it.
  2. Internal-only release. All three entries are docs or CI changes. The open inline thread on CHANGELOG.md gives possible release-plz.toml settings to skip these commits.
  3. The 0.8.3 tag is not on GitHub. I examined the remote this time, not only a local clone. The GitHub tags API shows 0.8.2 as the latest tag, and git/ref/tags/0.8.3 returns 404. Thus the compare/0.8.3...0.8.4 link in the new heading does not operate. Also, release-plz uses tags to find the previous release. Push a 0.8.3 tag on the 0.8.3 release commit before you enable the release job.

There are no blocking problems in the diff itself.

@freshtonic freshtonic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated re-review of head 18cf294. The earlier review was on 5c7daaa.

Recommendation: approve. The earlier blockers are fixed:

  1. Publish job: fixed. On main (5476aa3, #65), .github/workflows/release-plz.yml has a release-gate job and a release job. The release job runs only when the push merges a release PR from cipherstash-envelopers-release-plz[bot] on a release-plz-* branch. It uses Trusted Publishing (id-token: write) and the release environment. The release environment has required_reviewers and branch_policy protection rules. Thus a merge of this PR starts a publish of 0.8.4, and a reviewer must approve the deployment first.
  2. 0.8.3 tag: fixed. refs/tags/0.8.3 is on GitHub. It is an annotated tag on 60a9151, which agrees with the .cargo_vcs_info.json sha of the published crate. The compare/0.8.3...0.8.4 link now operates.
  3. Internal-only release: accepted. This release is the verification run for the release job. The commit filter is a follow-up item. I resolved the thread.

The diff: The version changes from 0.8.3 to 0.8.4 in Cargo.toml and Cargo.lock, and there are no other manifest changes. The semver check reports API-compatible changes. The new section is below ## Unreleased. All four checks pass on this head.

Non-blocking note: The changelog does not include e90a5b0 ("docs(agents): track issues in GitHub instead of Linear") or the merge of #68. The earlier head included them. The two commits change only agent docs, so this has no effect on users of the crate. If you want a complete changelog, add the line manually before merge.

After the merge, make sure that the release job publishes 0.8.4 to crates.io and pushes a 0.8.4 tag and GitHub release.

@tobyhede
tobyhede merged commit 6975c44 into main Sep 29, 2026
4 checks passed
@tobyhede
tobyhede deleted the release-plz-2026-09-23T01-05-33Z branch September 29, 2026 00:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants