Skip to content

First release prep: Quint spec review, test parity, and release pipeline validation #4

Description

@abienkowski

Summary

Tracking epic for all work required before publishing the first official release of docker-socket-policy. The repo currently has 6 draft releases (v0.2.1–v0.2.6) auto-created by release.yml on every push to main, none of which have been published.

Definition of Done

A tagged release is published with:

  • Go, Rust, and TypeScript binaries/archives attached
  • SPDX + CycloneDX SBOMs (syft) for all three Docker images
  • Cosign signatures on all three Docker images
  • Release notes generated and curated
  • Quint spec verified and matching all three implementations

Checklist

Which implementation(s) would this affect?

  • Go
  • Rust
  • TypeScript
  • Quint specification
  • All

Additional context

  • Release workflow: .github/workflows/release.yml (auto-bump patch on push to main, draft release, syft SBOM from Docker images, Cosign signing)
  • CI: .github/workflows/ci.yml (quint, go, rust, typescript, integration, reproducible-build)

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type: EpicAdded to issues to encompass many different types of issues together

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions