Skip to content

docs(release): guide signed tags for verified releases - #96

Merged
lsiddiquee merged 1 commit into
mainfrom
docs/signed-release-tag-guidance
Sep 30, 2026
Merged

lsiddiquee merged 1 commit into
mainfrom
docs/signed-release-tag-guidance

Conversation

@lsiddiquee

Copy link
Copy Markdown
Owner

Why

The existing v1.0.0 tag is annotated but unsigned (verification.reason=unsigned), although the merge commit it points to is Verified. The release instructions still suggested an unsigned git tag, which would repeat this for v1.1.0.

Change

Update release CLI output, workflow guidance and roadmap to instruct a signed tag from a GitHub-registered signing key. Document the distinction between a verified commit and a verified release tag; leave the published v1.0.0 tag untouched.

Validation

node --check scripts/release.mjs; focused pre-commit checks of the edited files passed.

Clarify that v1.0.0 has an unsigned annotated tag despite its verified commit and guide maintainers to sign future tags.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@lsiddiquee
lsiddiquee merged commit dc5b4b6 into main Sep 30, 2026
7 checks passed
@lsiddiquee
lsiddiquee deleted the docs/signed-release-tag-guidance branch September 30, 2026 17:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant