Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

docs/release-guide: move to checklist ticket template #176

Open
lucab opened this issue Mar 14, 2019 · 4 comments

Comments

@lucab
Copy link
Member

commented Mar 14, 2019

On each release we publish a .crate file to crates.io, which is then used by distribution to package coreos-metadata. Its SHA256 is recorded at publish time in the index, eg
rust-lang/crates.io-index@e0bc5cf.

In order to improve the integrity chain and to make manual checks easier, we should also record the SHA256 of the .crate file on local filesystem (before upload) and publish it in the release notes.

As per discussion with @ashcrow.

@lucab

This comment has been minimized.

Copy link
Member Author

commented Mar 28, 2019

@lucab

This comment has been minimized.

Copy link
Member Author

commented Apr 23, 2019

Self-note: local digests come from

sha256sum target/package/afterburn-${RELEASE_VER}.crate
sha256sum target/afterburn-${RELEASE_VER}-vendor.tar.gz 
@ashcrow

This comment has been minimized.

@lucab lucab changed the title docs/release-guide: record local SHA256 docs/release-guide: move to checklist ticket template Sep 13, 2019

@lucab

This comment has been minimized.

Copy link
Member Author

commented Sep 13, 2019

I'm keeping this ticket open till the guide is actually converted into a checklist ticket template.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
2 participants
You can’t perform that action at this time.