From f0bb1aba48b9126fa85d0cee99c5d9fabbbd5022 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:13:53 -0300 Subject: [PATCH 1/3] docs: reflect release-tool ownership --- developer_manual/release-process.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/developer_manual/release-process.rst b/developer_manual/release-process.rst index 6e245d7..f7ea330 100644 --- a/developer_manual/release-process.rst +++ b/developer_manual/release-process.rst @@ -6,7 +6,7 @@ Release process The normal LibreSign release path is driven from the **Prepare release** GitHub Actions workflow. -The reusable policy and contracts live in ``LibreCodeCoop/release-tool`` and orchestration lives in ``LibreCodeCoop/github-workflows``. ``LibreSign/libresign`` carries the consumer configuration and repository-specific packaging rules. +Release policy, contracts, the PHP runtime, and the three public lifecycle Actions live in ``LibreCodeCoop/release-tool``. LibreCode's managed workflow catalog and synchronization helper live in ``LibreCodeCoop/.github``. ``LibreSign/libresign`` carries the consumer configuration and repository-specific packaging rules. Maintainer journey ------------------ From 5d49cfe2541adc66e35ac0bb41f5eab15ebf646e Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:13:57 -0300 Subject: [PATCH 2/3] docs: reflect release-tool ownership --- developer_manual/release-process/manual.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/developer_manual/release-process/manual.rst b/developer_manual/release-process/manual.rst index 25d3838..c186e11 100644 --- a/developer_manual/release-process/manual.rst +++ b/developer_manual/release-process/manual.rst @@ -9,7 +9,7 @@ The automated workflow is the normal path. Manual commands are useful for diagno Read-only planning ------------------ -Download the verified ``release-tool.phar`` version used by ``LibreCodeCoop/github-workflows`` and its SHA-256 file, verify the checksum, then run: +Download the verified ``release-tool.phar`` version published by ``LibreCodeCoop/release-tool`` and pinned by the LibreSign release workflow, together with its SHA-256 file. Verify the checksum, then run: .. code-block:: bash From acd357400bd4823fc0fd4304b48b0a15b938f065 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:14:00 -0300 Subject: [PATCH 3/3] docs: reflect release-tool ownership --- developer_manual/release-process/configuration.rst | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/developer_manual/release-process/configuration.rst b/developer_manual/release-process/configuration.rst index 73b84b6..6404c8d 100644 --- a/developer_manual/release-process/configuration.rst +++ b/developer_manual/release-process/configuration.rst @@ -5,12 +5,12 @@ Release tool and consumer configuration ======================================= LibreSign release policy is executed by the versioned ``release-tool.phar`` distributed by ``LibreCodeCoop/release-tool``. -The reusable workflow pins an exact release-tool version and verifies its published SHA-256 checksum before execution. Do not replace that pin with a floating ``latest`` download. +The LibreSign workflow pins the public Release Tool Actions to an immutable commit from a published release. Those Actions resolve the same repository ``VERSION`` and verify the published PHAR SHA-256 checksum before execution. Do not replace the immutable Action pin or verified PHAR with a floating ``latest`` reference. Local installation ------------------ -For diagnostics or manual recovery, download the same ``release-tool.phar`` and ``release-tool.phar.sha256`` release used by ``LibreCodeCoop/github-workflows``. +For diagnostics or manual recovery, download the same ``release-tool.phar`` and ``release-tool.phar.sha256`` release pinned by the LibreSign release workflow. Verify the checksum before running the PHAR: .. code-block:: bash @@ -18,7 +18,7 @@ Verify the checksum before running the PHAR: sha256sum --check release-tool.phar.sha256 php release-tool.phar --version -The reported version must match the version pinned by the reusable setup action. +The reported version must match the Release Tool version associated with the immutable Action commit used by the workflow. Consumer configuration ----------------------