krz/orgo

Lightning fast org-mode static site generator. fast go org-mode static-site-generator

Commit 6f853541d4

6f853541d48be3675d1e8358d56c6eb704f9c800

parent: 8d5e263d21

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-21 20:15 UTC

Describe the release CI actually runs

Step 5 still said to run `cargo publish` by hand and step 6 still described the
draft release as the only thing a tag push produces. Publishing has come from CI
since the OIDC workflow landed, so following the old step now just fails on a
version crates.io already has — which is how the 0.22.0 release found it.

The `cargo login` in the first-publish section went with it: there is no token
to store on a machine any more.

Layout: unified · split

RELEASING.org +14 −11
@@ -3,10 +3,9 @@
33Read the content below for the release process.
44
55** Before the first publish
6#+begin_src sh
7cargo login # a crates.io token, once per machine
8cargo publish --dry-run
9#+end_src
6Nothing to install and no token to store. The release workflow mints a short-lived
7crates.io token with OIDC, configured on crates.io against this repository, the
8=release.yml= workflow file and the =crates-io= environment that job runs in.
109
1110=repository= and =homepage= in =Cargo.toml= point at GitHub and at the documentation site
1211on Pages.
@@ -32,16 +31,20 @@ on Pages.
3231 git push && git push --tags
3332 #+end_src
3433
355. Publish the crate.
345. The tag push is the release. It builds binaries for macOS (arm64 and x86_64) and
35 Linux (gnu and musl), opens a /draft/ GitHub release with them attached, and runs
36 =cargo publish --locked= — there is nothing to publish by hand, and running
37 =cargo publish= locally now only fails on a version crates.io already has.
3638
37 #+begin_src sh
38 cargo publish
39 #+end_src
39 Publishing is the one step that cannot be undone: a version can be yanked but never
40 replaced. The publish job runs in the =crates-io= environment so it can be held —
41 add a required reviewer to that environment in the repository settings and a tag
42 push waits for a human before it reaches crates.io.
4043
41 This is irreversible: a published version can be yanked but never replaced.
44 A release that fails halfway is re-run from the Actions tab: the workflow takes the
45 tag to build as an input, so it does not need a second tag.
4246
436. Finish the GitHub release. Pushing the tag builds binaries for macOS (arm64 and
44 x86_64) and Linux (gnu and musl) and opens a /draft/ release with them attached.
476. Write the release notes and publish the draft.
4548
4649** If a release goes wrong
4750Yank rather than delete, and ship a fix as a new version: