HeaderProof uses Semantic Versioning for the scanner package. Evidence-schema versions are independent compatibility contracts and do not automatically track the package version.
- Release changes must already be on
main. - Required CI checks on the release commit must be green.
CHANGELOG.mdmust describe the user-visible change.docs/releases/vX.Y.Z.mdmust exist and followdocs/releases/TEMPLATE.md.- Package and runtime versions must match the intended tag.
- Accepted external contributions shipping for the first time must be credited.
- No controlled-fixture result may be rewritten as an internet-wide accuracy claim.
Run locally:
python -m compileall -q header_active_scan.py src/headerproof
python -m ruff check header_active_scan.py src/headerproof tests
python -m mypy
python -m pytest -q
python -m buildCreate the annotated release tag only from the verified main commit. The
release workflow builds native binaries and Python distributions from that tag,
creates checksums, signs the checksum manifest with Sigstore/Cosign, creates
GitHub provenance attestations, publishes the GitHub Release, and publishes and
signs the multi-architecture GHCR image.
PyPI publishing is a separate Trusted Publishing workflow and remains gated by
the PyPI publisher configuration documented in docs/PYPI.md.
- Download the public release artifacts and verify checksums.
- Verify the Cosign checksum bundle against the release workflow identity.
- Verify GitHub provenance with
gh attestation verify. - Run
--versionand--helpfrom the downloaded native binary. - Confirm the GHCR image signature and provenance.
- Confirm release notes credit every accepted external contribution included.
- Confirm GitHub marks the release immutable and
gh release verifysucceeds. - Never replace published assets; issue a patch release for corrections.
See docs/VERIFYING_RELEASES.md for consumer verification commands.