ka2a documentation

Releasing

Developer preview. Not yet production ready. This page is rendered from docs/releasing.md of the ka2a repository at revision 96fb45e5e5f6693e779837998c3aa9581d6a37f2. It describes the behavior of that revision.

Contents

This procedure is for the repository owner. The tooling builds and checks the release artifacts. It publishes nothing: it creates no tag, no GitHub release and no upload, and it signs nothing (implementation decisions, section 24.3). Each publishing step below is a manual decision of the owner. No release of the R2 code exists yet.

Before the release

  1. Choose the version by the rules of Versioning, for example v0.2.0-alpha.1.
  2. Update CHANGELOG.md: move the entries of "Unreleased" to a new section with the version and the date. Name the breaking changes, the deprecations, the store schema, the wire profile and the a2a-go version.
  3. Update the release-candidate report under reports/qualification/. Its section "What was not executed" must list every open ledger row and task; make verify checks that.
  4. Commit these changes to main through the usual review.

Build and check

Run each step on a clean checkout of the release commit, with Go 1.27.0 (CGO_ENABLED=0 GOTOOLCHAIN=local). Keep the output of each step.

  1. make verify, make spec-check and make lint. Each must exit with 0.
  2. make test-integration (needs Docker). It must exit with 0.
  3. make vulncheck (needs govulncheck v1.8.0 and vuln.go.dev). When vuln.go.dev is not reachable, build an offline database with scripts/vulndb.sh DIR and run make vulncheck VULNDB=DIR. Keep the output with the database version. The scan covers Go code only.
  4. make release-check VERSION=vX.Y.Z RELEASE_CHECK_OUT=DIR. It builds the artifacts twice from git archive and fails when one file differs.
  5. make release-artifacts VERSION=vX.Y.Z. It writes dist/vX.Y.Z/: the binaries, the SBOMs, LICENSE, NOTICE, THIRD_PARTY_NOTICES.md, release-evidence.md and SHA256SUMS.
  6. Compare dist/vX.Y.Z/SHA256SUMS with the SHA256SUMS of step 4. They must be equal.
  7. Read dist/vX.Y.Z/release-evidence.md. Check the commit, the platform table and the section "Not executed".
  8. Run dist/vX.Y.Z/ka2a_vX.Y.Z_linux_amd64 version. It must print the version and the commit.

Publish (manual steps of the owner)

  1. Create an annotated tag on the release commit: git tag -a vX.Y.Z -m "ka2a vX.Y.Z". Sign it if you have a signing key for tags.
  2. Push the tag.
  3. Create the release page by hand. Attach the files of dist/vX.Y.Z/ and the output of make vulncheck. Paste the changelog section. Mark a version with a pre-release suffix as a pre-release.
  4. Check that go list -m github.com/k-a2a/ka2a@vX.Y.Z resolves through the Go module proxy.

After a security fix

Follow the security policy. Publish the fix and the advisory together. Name the fixed versions in the advisory and in the changelog.

All ka2a documents