Release Process¶
Creating a Release¶
Releases are automated via the release.yml workflow:
# 1. Update version in pyproject.toml, src/__init__.py, CITATION.cff
# 2. Commit and push
git add -A && git commit -m "chore: bump version to v2.x.x"
git push origin main
# 3. Create and push tag
git tag -a v2.x.x -m "Release v2.x.x"
git push origin v2.x.x
# 4. GitHub Actions handles the rest:
# - Build sdist + wheel
# - Run full test suite
# - Sign with sigstore
# - Create GitHub Release
# - Upload artifacts + signatures
Sigstore Signing¶
Each release artifact is signed using sigstore, providing verifiable proof of origin:
# Verify a release artifact
pip install sigstore
sigstore verify \
--certificate-identity=aslan08_05@mail.ru \
--certificate-oidc-issuer=https://github.com/login/oauth \
choptyuk-spinor-2.0.0.tar.gz \
--signature choptyuk-spinor-2.0.0.tar.gz.sig \
--certificate choptyuk-spinor-2.0.0.tar.gz.cert
Zenodo DOI¶
When a GitHub Release is created, Zenodo automatically:
- Archives a snapshot of the repository
- Mints a versioned DOI
- Updates the badge in README.md
Changelog¶
The changelog is maintained in CHANGELOG.md following Keep a Changelog format.