-
-
Notifications
You must be signed in to change notification settings - Fork 3
release and support
github-actions[bot] edited this page Oct 3, 2026
·
2 revisions
Status: in progress. eepview has no release yet.
- eepview follows Semantic Versioning. Before 1.0, a minor version may break things. Each change is in
CHANGELOG.md. - A release is a git tag
vX.Y.Zonmain.
- Only the latest release is supported. It gets bug fixes and security fixes.
- An older release gets no fix. Upgrade to the latest release.
- Before the first release, nothing is supported. See SECURITY.md.
- Download the latest release for your system.
- Install it over the old version. Do not uninstall first.
- Your data stays. The bookmarks, history and settings live in the app config directory, not in the install folder.
- The stores have a
versionfield. It is there for future migrations.
- A tag starts
release.yml. The lint, security and test jobs must pass first. See Release pipeline. - The release holds installers for four targets, two CycloneDX SBOMs and a
SHA256SUMSfile. - A user checks a download with
sha256sum -c SHA256SUMS. - Each release file has a keyless Sigstore signature, made through GitHub Actions OIDC. The workflow also attests build provenance. The commands to check both are in Release pipeline. The attestation step runs only while the repository is public.
- A person reads the draft release and publishes it.
The maintainer signs each release tag with an SSH signing key. This is a practice, not a gate: release.yml does not check the tag signature. The release files carry their own Sigstore signatures, see Release pipeline.
One-time setup:
git config --global gpg.format ssh
git config --global user.signingkey ~/.ssh/id_ed25519.pubAdd the same public key on GitHub as a signing key (Settings, SSH and GPG keys). GitHub then marks the tag as Verified.
Cut the release from main:
git switch main && git pull --ff-only
git tag -s v0.1.0 -m "eepview v0.1.0"
git push origin v0.1.0Check a tag locally. git tag -v needs a file that lists the keys you trust:
echo "$(git config user.email) $(cat ~/.ssh/id_ed25519.pub)" > ~/.config/git/allowed_signers
git config --global gpg.ssh.allowedSignersFile ~/.config/git/allowed_signers
git tag -v v0.1.0- Windows installers and the macOS
.dmghave no platform code-signing certificate. The Sigstore signature does not replace one. - There is no in-app update. The user installs the new version by hand.
Generated from docs/wiki in the repository. Edit there, not here.