Skip to content

Decide Mars release secrets and GoReleaser policy #7

Description

@luccahuguet

Mars still carries inherited Rio release automation, including GoReleaser Pro and optional Apple signing/notarization paths. The project needs an explicit policy before treating release workflows as public packaging support.

Internal tracking: Bead yzt-c2d.

Context:

  • The release workflow is intentionally limited to v*.*.* tags and manual dispatch.
  • GORELEASER_KEY is required for GoReleaser Pro release execution.
  • Apple signing/notarization should only run when the required secrets are present and intentionally configured.

Acceptance:

  • Decide which inherited Rio release tools Mars should keep, disable, or defer.
  • Document required GitHub secrets, owners, rotation expectations, and failure behavior.
  • Decide whether unsigned/manual builds are enough for Mars in the near term.
  • If GoReleaser remains, ordinary CI pushes must not fail due to release-only secret policy.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions