Skip to content

Manage releases through bake-gem-github - #45

Merged
samuel-williams-shopify merged 2 commits into
mainfrom
github-releases
Sep 27, 2026
Merged

samuel-williams-shopify merged 2 commits into
mainfrom
github-releases

Conversation

@samuel-williams-shopify

@samuel-williams-shopify samuel-williams-shopify commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Move releases from local publishing to release PRs prepared and validated by bake-gem-github. Merging a validated release PR publishes its signed gem through RubyGems Trusted Publishing, records attestations, and creates the version tag and GitHub release.

Preserve release-note and documentation generation, add copyright refresh, and remove the old GitHub-release hook now handled by the publishing workflow. The README documents the new release command. Replace the older personal signing certificate with the Socketry certificate already used by fiber-profiler and its organization signing key.

The generated policy requires two approvals and current CI for all PRs into main, allows explicit administrator bypass for reviews/checks, and protects main-branch history and release tags. It adds no separate publishing-review requirement. These rules are proposed files only; activate them after this PR merges and Release validation is available.

Validation:

  • All GitHub CI checks pass, including Release validation and the documentation/browser workflow.
  • 70 Ruby tests / 197 assertions pass; 1054/1054 measured lines covered (100%).
  • RuboCop and documentation coverage pass (96/96 public definitions).
  • Generated setup is idempotent; unsigned gem build and ordinary-PR validation pass.
  • A separate local release rehearsal generated a patch release and passed content/commit validation; nothing was published.

Publishing setup:

  • Created the rubygems environment restricted to the main branch.
  • Organization GEM_SIGNING_KEY is available to this repository; the public certificate matches the one used by successful fiber-profiler releases.
  • Registered the RubyGems Trusted Publisher through gem:github:setup:publisher for socketry/utopia-project, workflow release-publish.yaml, environment rubygems (registration 5198).
  • After merge, run bundle exec bake gem:github:setup:plan, review it, then bundle exec bake gem:github:setup:apply to activate the rules.

Signed-off-by: Samuel Williams <samuel.williams@shopify.com>
Signed-off-by: Samuel Williams <samuel.williams@shopify.com>
@samuel-williams-shopify
samuel-williams-shopify merged commit e3ad2d3 into main Sep 27, 2026
23 checks passed
@samuel-williams-shopify
samuel-williams-shopify deleted the github-releases branch September 27, 2026 22:17

This branch was successfully deployed

1 active deployment
github-pages-preview — 094db66c Deployed Sep 27, 2026 by samuel-williams-shopify via deploy #209
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant