Commit 6f853541d4
Verified · cmc
Layout: unified · split
RELEASING.org +14 −11
| @@ -3,10 +3,9 @@ | |||
| 3 | Read the content below for the release process. | 3 | Read the content below for the release process. |
| 4 | 4 | ||
| 5 | ** Before the first publish | 5 | ** Before the first publish |
| 6 | #+begin_src sh | 6 | Nothing to install and no token to store. The release workflow mints a short-lived |
| 7 | cargo login # a crates.io token, once per machine | 7 | crates.io token with OIDC, configured on crates.io against this repository, the |
| 8 | cargo publish --dry-run | 8 | =release.yml= workflow file and the =crates-io= environment that job runs in. |
| 9 | #+end_src | ||
| 10 | 9 | ||
| 11 | =repository= and =homepage= in =Cargo.toml= point at GitHub and at the documentation site | 10 | =repository= and =homepage= in =Cargo.toml= point at GitHub and at the documentation site |
| 12 | on Pages. | 11 | on Pages. |
| @@ -32,16 +31,20 @@ on Pages. | |||
| 32 | git push && git push --tags | 31 | git push && git push --tags |
| 33 | #+end_src | 32 | #+end_src |
| 34 | 33 | ||
| 35 | 5. Publish the crate. | 34 | 5. The tag push is the release. It builds binaries for macOS (arm64 and x86_64) and |
| 35 | Linux (gnu and musl), opens a /draft/ GitHub release with them attached, and runs | ||
| 36 | =cargo publish --locked= — there is nothing to publish by hand, and running | ||
| 37 | =cargo publish= locally now only fails on a version crates.io already has. | ||
| 36 | 38 | ||
| 37 | #+begin_src sh | 39 | Publishing is the one step that cannot be undone: a version can be yanked but never |
| 38 | cargo publish | 40 | replaced. The publish job runs in the =crates-io= environment so it can be held — |
| 39 | #+end_src | 41 | add a required reviewer to that environment in the repository settings and a tag |
| 42 | push waits for a human before it reaches crates.io. | ||
| 40 | 43 | ||
| 41 | This is irreversible: a published version can be yanked but never replaced. | 44 | A release that fails halfway is re-run from the Actions tab: the workflow takes the |
| 45 | tag to build as an input, so it does not need a second tag. | ||
| 42 | 46 | ||
| 43 | 6. Finish the GitHub release. Pushing the tag builds binaries for macOS (arm64 and | 47 | 6. Write the release notes and publish the draft. |
| 44 | x86_64) and Linux (gnu and musl) and opens a /draft/ release with them attached. | ||
| 45 | 48 | ||
| 46 | ** If a release goes wrong | 49 | ** If a release goes wrong |
| 47 | Yank rather than delete, and ship a fix as a new version: | 50 | Yank rather than delete, and ship a fix as a new version: |