Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
17 commits
Select commit Hold shift + click to select a range
df09792
test(release): remove configuration snapshot assertions
tisonkun Sep 29, 2026
fc5e50d
refactor(release): delegate dependency ordering to graphlib
tisonkun Sep 29, 2026
d5bdaad
refactor(release): trust the Cargo metadata schema
tisonkun Sep 29, 2026
539f5e6
refactor(release): keep the OIDC token lifecycle in one context
tisonkun Sep 29, 2026
df1a238
refactor(release): fail fast on bootstrap API errors
tisonkun Sep 29, 2026
21e0f08
refactor(release): assert bootstrap identity and publisher invariants
tisonkun Sep 29, 2026
7ad1df6
refactor(release): use bootstrap logs without a second report
tisonkun Sep 29, 2026
b922df6
refactor(release): fix helper entry points to this repository
tisonkun Sep 29, 2026
4bd0911
refactor(release): pass only the crate name to placeholder packaging
tisonkun Sep 29, 2026
b00cecc
refactor(release): consolidate bootstrap metadata propagation waits
tisonkun Sep 29, 2026
3a3bf63
refactor(release): reduce bootstrap to audit, reconcile, and audit
tisonkun Sep 29, 2026
0183a52
refactor(release): remove unused publish-plan representations
tisonkun Sep 29, 2026
85df013
ci(release): remove the redundant bootstrap discovery job
tisonkun Sep 29, 2026
c5f49d5
ci(release): rely on the existing formal-tag push filter
tisonkun Sep 29, 2026
db9b01e
refactor(release): use the workflow dispatch response run ID
tisonkun Sep 29, 2026
14475d2
refactor(release): express bootstrap preconditions directly
tisonkun Sep 29, 2026
c8e77d4
Add return_run_details parameter to workflow dispatch
tisonkun Oct 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 13 additions & 4 deletions .github/scripts/release_rust/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,8 @@ These scripts define and publish the crates.io package set for Apache Reqsign.
## Publish plan

`plan.py` reads `cargo metadata --no-deps`, selects workspace packages that can
publish to crates.io, and orders them by non-dev local dependencies.
publish to crates.io, and orders them by non-dev local dependencies using
Python's `TopologicalSorter`.

```bash
python3 .github/scripts/release_rust/plan.py
Expand Down Expand Up @@ -43,9 +44,8 @@ Trusted Publishing cannot create the first version of a crate.
ownership or the exact Trusted Publisher because those APIs require
authentication.

The protected `rust-bootstrap` workflow always runs the authenticated audit,
including when discovery finds no missing names. It never changes an
established crate. Existing crates must be migrated independently before the
The protected `rust-bootstrap` job audits the complete plan before any write,
including when no names are missing. It never changes an established crate. Existing crates must be migrated independently before the
workflow can succeed.

Published crate metadata may still reference the former repository URL or the
Expand All @@ -56,6 +56,15 @@ New placeholders and releases use the current project name and repository URL.
Version `0.0.0` is an irreversible namespace reservation. It is not an ASF
software release and contains no implementation.

The local dispatch helper uses GitHub REST API version `2026-03-10` to obtain
the exact workflow run ID, then checks its commit and waits for completion.

These are repository-specific scripts: run them with normal Python (without
`-O` or `PYTHONOPTIMIZE`, which disable assertions). Cargo and crates.io response
fields are used directly; unexpected package or publisher state fails an
assertion. Failed API requests stop the run; rerun after resolving the failure.
Only Cargo publish rate limits and public metadata propagation are retried.

## Tests

```bash
Expand Down
Loading
Loading