Release Checklist¶
Use this checklist before and after cutting a release from main.
Before Tagging¶
Confirm
mainbranch protection matches the Rust-native required checks.make verify-branch-protectionRun the local merge-equivalent gates.
make ciExercise the checked-in release packaging path.
make smoke-release make release-emulate
Confirm the docs/download surface still builds and link-checks cleanly.
make docs-checkIf you are validating an already-published tag, verify the public release surface directly.
make verify-published-release TAG=paranoid-passwd-v3.5.2
After Publishing¶
Verify that the release workflow produced every expected archive plus
checksums.txt.Verify there are no stale browser-era or otherwise unexpected assets attached to the release.
Verify GitHub attestation for at least one downloaded archive.
Re-run installer validation against the published release surface if needed.
Confirm Homebrew, Scoop, and Chocolatey manifests were generated and published through their PR flow.
Canary Expectations¶
The first release after a pipeline change should be treated as a canary:
inspect the archive matrix
verify the checksums
verify provenance
verify
install.shconfirm the docs download links resolve
If any of those fail, treat the release pipeline as untrusted until the failure is fixed and the validation path passes again.