Release candidates and promotion
Release candidates
Tagging releases is a maintainer action. Contributors do not push tags.
For context, this is how a candidate is cut on lota-next:
The tag sits on a single commit that changes only
VERSION.That commit's description becomes the release notes.
release.ymlpublishes the release page as the build line, then the body of the tagged commit, then the verification line.release.ymlbuilds reproducibly, signsSHA256SUMSwith cosign keyless, and -- because the tag is0.xor carries a-suffix -- marks the GitHub release as a pre-release.Candidates iterate
-rc1,-rc2, ... until one is stable.
Promotion to main
When a candidate is stable, the maintainer -- @szymonwilczek -- promotes
lota-next to main through a pull request merged as a merge commit
(no squash, no rebase), then tags the stable release (vX.Y.0) on main.
See ../../security/reproducible-builds for how a tag is built and signed and how to verify it yourself.