ka2a documentation
Releasing
Developer preview. Not yet production ready. This page is rendered from docs/releasing.md of the ka2a repository at revision 96fb45e5e5f6693e779837998c3aa9581d6a37f2. It describes the behavior of that revision.
Contents
This procedure is for the repository owner. The tooling builds and checks the release artifacts. It publishes nothing: it creates no tag, no GitHub release and no upload, and it signs nothing (implementation decisions, section 24.3). Each publishing step below is a manual decision of the owner. No release of the R2 code exists yet.
Before the release
- Choose the version by the rules of Versioning, for example
v0.2.0-alpha.1. - Update CHANGELOG.md: move the entries of "Unreleased" to a new section with the version and the date. Name the breaking changes, the deprecations, the store schema, the wire profile and the a2a-go version.
- Update the release-candidate report under
reports/qualification/. Its section "What was not executed" must list every open ledger row and task;make verifychecks that. - Commit these changes to
mainthrough the usual review.
Build and check
Run each step on a clean checkout of the release commit, with Go 1.27.0
(CGO_ENABLED=0 GOTOOLCHAIN=local). Keep the output of each step.
make verify,make spec-checkandmake lint. Each must exit with 0.make test-integration(needs Docker). It must exit with 0.make vulncheck(needsgovulncheckv1.8.0 andvuln.go.dev). Whenvuln.go.devis not reachable, build an offline database withscripts/vulndb.sh DIRand runmake vulncheck VULNDB=DIR. Keep the output with the database version. The scan covers Go code only.make release-check VERSION=vX.Y.Z RELEASE_CHECK_OUT=DIR. It builds the artifacts twice fromgit archiveand fails when one file differs.make release-artifacts VERSION=vX.Y.Z. It writesdist/vX.Y.Z/: the binaries, the SBOMs, LICENSE, NOTICE, THIRD_PARTY_NOTICES.md,release-evidence.mdandSHA256SUMS.- Compare
dist/vX.Y.Z/SHA256SUMSwith theSHA256SUMSof step 4. They must be equal. - Read
dist/vX.Y.Z/release-evidence.md. Check the commit, the platform table and the section "Not executed". - Run
dist/vX.Y.Z/ka2a_vX.Y.Z_linux_amd64 version. It must print the version and the commit.
Publish (manual steps of the owner)
- Create an annotated tag on the release commit:
git tag -a vX.Y.Z -m "ka2a vX.Y.Z". Sign it if you have a signing key for tags. - Push the tag.
- Create the release page by hand. Attach the files of
dist/vX.Y.Z/and the output ofmake vulncheck. Paste the changelog section. Mark a version with a pre-release suffix as a pre-release. - Check that
go list -m github.com/k-a2a/ka2a@vX.Y.Zresolves through the Go module proxy.
After a security fix
Follow the security policy. Publish the fix and the advisory together. Name the fixed versions in the advisory and in the changelog.