Skip to content

docs: say what CI and the release workflow really do - #32

Merged
MotherSphere merged 6 commits into
mainfrom
docs/ci-and-release-reality
Oct 8, 2026
Merged

MotherSphere merged 6 commits into
mainfrom
docs/ci-and-release-reality

Conversation

@MotherSphere

Copy link
Copy Markdown
Member

What changed

Docs only. Several pages still described the repository as it was before ci.yml existed and before the release moved to the shared signing workflow (#31).

  • docs/internals/contributing.md: no longer says there is no CI or that Windows and macOS are only compile-verified. It now says what ci.yml runs (build and cargo test on Linux, Windows and macOS, a build at Rust 1.90, the colony.json check) and what it still does not (rustfmt and clippy, for the reasons in the header of ci.yml). Also drops a broken sentence fragment claiming the startup failure message in src/main.rs is French; it is English.
  • docs/internals/packaging.md: the release build is no longer described as the only check Windows and macOS get. Adds a paragraph saying scripts/sign-release.sh is a manual fallback no workflow uses.
  • docs/project/roadmap.md: "Run the tests in CI" moves to Done; Next now lists the part that is really missing, gating rustfmt and clippy. The signed-releases entry describes the shared sign-and-publish workflow and the pending SignPath Authenticode.
  • scripts/sign-release.sh (comment only): its header said to use it in CI; it now says releases do not use it and it is the manual fallback. It also pointed at a src/signing.rs that is Colony's, not Grape's.
  • scripts/README.md: "Strict mode (as in CI)" for clippy was wrong; CI does not run clippy.
  • README.md, docs/guide/install.md: each binary ships with .sig, .meta and .meta.sig (as the v0.4.1 release does), not just .sig.
  • Test counts in contributing.md, architecture.md, roadmap.md and one comment in ci.yml said 50 tests in src/ and 19 of 23 player tests ignored; it is 65 (2 ignored) and 20 of 25. The ci.yml change is that comment only.
  • SECURITY.md: replaces GitHub's unfilled template (versions 4.0 to 5.1 that never existed) with a real policy: only the latest release is supported, report privately through GitHub's private vulnerability reporting, which is enabled on this repository.

Proven locally

  • Every new claim was checked against .github/workflows/ci.yml, .github/workflows/release.yml and the pinned sign-and-publish.yml of Project-Colony-Resources (619460f), including that sign-release.sh writes the same .meta format.
  • gh api repos/Project-Colony/Grape/private-vulnerability-reporting returns {"enabled":true}.
  • The v0.4.1 release assets are the four binaries plus .sig, .meta and .meta.sig each.
  • cargo fmt --check and cargo clippy --all-targets -- -D warnings both fail on main as well (rustfmt.toml uses nightly-only options; clippy reports 385 errors in the lib), which is exactly what ci.yml and the updated docs say. This PR touches no Rust code.
  • cargo test passes on Linux: 63 + 2 ignored in src/, 20 cache, 20 Last.fm, 5 + 20 ignored player tests. Those counts are what the docs now say.
  • bash -n scripts/sign-release.sh passes, ci.yml still parses as YAML, and no added line has an em or en dash.

What only CI or a release can prove

@MotherSphere
MotherSphere merged commit f51c383 into main Oct 8, 2026
8 checks passed
@MotherSphere
MotherSphere deleted the docs/ci-and-release-reality branch October 8, 2026 12:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant