Development documentation

This is the in-progress lota-next branch. For the released version, see the stable documentation.

Release candidates and promotion

Release candidates

Tagging releases is a maintainer action. Contributors do not push tags.

For context, this is how a candidate is cut on lota-next:

  • The tag sits on a single commit that changes only VERSION.

  • That commit's description becomes the release notes. release.yml publishes the release page as the build line, then the body of the tagged commit, then the verification line.

  • release.yml builds reproducibly, signs SHA256SUMS with cosign keyless, and -- because the tag is 0.x or carries a - suffix -- marks the GitHub release as a pre-release.

  • Candidates iterate -rc1, -rc2, ... until one is stable.

Promotion to main

When a candidate is stable, the maintainer -- @szymonwilczek -- promotes lota-next to main through a pull request merged as a merge commit (no squash, no rebase), then tags the stable release (vX.Y.0) on main.

See ../../security/reproducible-builds for how a tag is built and signed and how to verify it yourself.