diff --git a/developer_manual/release-process.rst b/developer_manual/release-process.rst index 6e245d7..f7ea330 100644 --- a/developer_manual/release-process.rst +++ b/developer_manual/release-process.rst @@ -6,7 +6,7 @@ Release process The normal LibreSign release path is driven from the **Prepare release** GitHub Actions workflow. -The reusable policy and contracts live in ``LibreCodeCoop/release-tool`` and orchestration lives in ``LibreCodeCoop/github-workflows``. ``LibreSign/libresign`` carries the consumer configuration and repository-specific packaging rules. +Release policy, contracts, the PHP runtime, and the three public lifecycle Actions live in ``LibreCodeCoop/release-tool``. LibreCode's managed workflow catalog and synchronization helper live in ``LibreCodeCoop/.github``. ``LibreSign/libresign`` carries the consumer configuration and repository-specific packaging rules. Maintainer journey ------------------ diff --git a/developer_manual/release-process/configuration.rst b/developer_manual/release-process/configuration.rst index 73b84b6..6404c8d 100644 --- a/developer_manual/release-process/configuration.rst +++ b/developer_manual/release-process/configuration.rst @@ -5,12 +5,12 @@ Release tool and consumer configuration ======================================= LibreSign release policy is executed by the versioned ``release-tool.phar`` distributed by ``LibreCodeCoop/release-tool``. -The reusable workflow pins an exact release-tool version and verifies its published SHA-256 checksum before execution. Do not replace that pin with a floating ``latest`` download. +The LibreSign workflow pins the public Release Tool Actions to an immutable commit from a published release. Those Actions resolve the same repository ``VERSION`` and verify the published PHAR SHA-256 checksum before execution. Do not replace the immutable Action pin or verified PHAR with a floating ``latest`` reference. Local installation ------------------ -For diagnostics or manual recovery, download the same ``release-tool.phar`` and ``release-tool.phar.sha256`` release used by ``LibreCodeCoop/github-workflows``. +For diagnostics or manual recovery, download the same ``release-tool.phar`` and ``release-tool.phar.sha256`` release pinned by the LibreSign release workflow. Verify the checksum before running the PHAR: .. code-block:: bash @@ -18,7 +18,7 @@ Verify the checksum before running the PHAR: sha256sum --check release-tool.phar.sha256 php release-tool.phar --version -The reported version must match the version pinned by the reusable setup action. +The reported version must match the Release Tool version associated with the immutable Action commit used by the workflow. Consumer configuration ---------------------- diff --git a/developer_manual/release-process/manual.rst b/developer_manual/release-process/manual.rst index 25d3838..c186e11 100644 --- a/developer_manual/release-process/manual.rst +++ b/developer_manual/release-process/manual.rst @@ -9,7 +9,7 @@ The automated workflow is the normal path. Manual commands are useful for diagno Read-only planning ------------------ -Download the verified ``release-tool.phar`` version used by ``LibreCodeCoop/github-workflows`` and its SHA-256 file, verify the checksum, then run: +Download the verified ``release-tool.phar`` version published by ``LibreCodeCoop/release-tool`` and pinned by the LibreSign release workflow, together with its SHA-256 file. Verify the checksum, then run: .. code-block:: bash