[Feature] Release engineering for 0.1.0 #520
Labels
No labels
accepted
bug
declined
docs
duplicate
enhancement
good first issue
in-progress
needs-info
privacy
security
triage
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
LibreKAT/Ocideck#520
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The umbrella for actually shipping. Everything below was found in the release review; the code work is done, this is the last stretch.
pubspec.yamland hard-coded inlib/services/export_metadata.dart, which lands in the metadata of every exported PDF and PPTX. Add a test that compares the two, or derive one from the other — otherwise a bumped release ships files that announce the old version.SECURITY.mdasks reporters to state it.[Unreleased]; that becomes one dated version heading.com.exampleinwindows/runner/Runner.rcandlinux/CMakeLists.txt. Authenticode over a binary namingcom.exampleas publisher is indefensible, and a Flatpak with that app-id is not publishable.CODE_SIGN_IDENTITY = "-"), without hardened runtime, so a downloaded copy will not start on someone else's machine. Notarisation requires hardened runtime, so this is not a single flag.LICENSE.md, noTHIRD_PARTY_NOTICES.md, nosbom/, no checksums, no signature.The release checklist itself was written out during the review; the order matters, in particular that the artefact is tested from a download on a second machine with the quarantine flag intact. That step is what breaks most first releases.
Administrative half merged (#544): version derived from one constant with a test holding
export_metadata.dartto it, version shown in the About panel (translated across all 31 languages), andcom.examplegone from the Windows and Linux identity.[Unreleased]deliberately left alone — turning it into a dated heading is a release action and yours to take.Still open here, and none of it is a matter of effort:
CODE_SIGN_IDENTITY = "-") with no hardened runtime, so a downloaded copy will not start on someone else's machine — and notarisation requires hardened runtime, so this is not one flag.sbom/, checksums, signature). This follows from having a release process at all, which does not exist yet.The first two are the gate. Until a downloaded build starts on a machine that is not this one, there is no release to ship.
Scope decided 2026-07-22: 0.1.0 is web only. Desktop is build-from-source, stated plainly as such rather than as a lesser option.
What that settles, and it settles most of this issue:
[Unreleased]heading becomes a dated version, the artefacts travel alongside the bundle (LICENSE, THIRD_PARTY_NOTICES,sbom/, checksums), and there is a documented way to verify what you downloaded.The tag itself stays yours — that is the one irreversible, outward-facing step.
Next: I will prepare everything up to the tag, but only after the privacy and security queue from the pre-publication review, per the project's own ordering rule. Those are the findings that would be permanent the moment anything is published.
Opgepakt. Tak:
feat/release-artefacten. Reikwijdte:Makefile(build-web), een nieuwtool/-script voor de checksums,docs/BUILD.mdendocs/HOSTING.mdvoor de verificatieroute, plus een test die bewaakt dat de artefacten blijven meereizen. Buiten scope, en blijft van jou: de tag zelf.Klaar en op main in
908c9719(PR #665). Daarmee is alles wat zonder certificaat te bouwen was gedaan.Wat er landde
LICENSE.md,THIRD_PARTY_NOTICES.md,SOURCE.mden de SBOM reizen met de webbundel mee;SHA256SUMSsluit af, in het gewonesha256sum-formaat.docs/KNOWN_LIMITATIONS.mdin plaats van alleen hier.docs/BUILD.md, met de grenzen erbij: het is geen handtekening, en het vangt géén compromittering van onze eigen publicatieketen.Twee dingen die de bewakerreview opleverde en die het issue niet noemde
main.dart.jsis gecompileerd, en EUPL-1.2 artikel 5 vraagt bij distribueren of communiceren om de bron of een aanwijzing ernaartoe — artikel 1 rekent hosten daaronder. De repo-URL stond alleen in.well-known/security.txt, dat een herhoster door zijn eigen vervangt. VandaarSOURCE.md..last_build_idwerd mee verzegeld. De inhoud is een md5 over onder meer het absolute pad van de uitvoermap op de bouwmachine, dus wie zelf bouwt kreeg gegarandeerd een andere digest dan de aankondiging — bij byte-identieke bron. De enige controle die een zelf-bouwer een onafhankelijk oordeel geeft, stond structureel op rood.Niet gedraaid:
make check-secretsenmake sast— gitleaks, trufflehog en semgrep staan geen van drieën op deze machine. Deze wijziging voegt geen sleutel, netwerkpad of afhankelijkheid toe, maar de eis is daarmee niet gehaald.Wat overblijft is van jou: de tag zelf, en de
[Unreleased]/0.1.0 — unreleased-kop een datum geven. Dat is de onomkeerbare, naar buiten gerichte stap. Wil je dit issue als drager daarvan houden, dan heropen je hem met één klik.