Release process
The normal LibreSign release path is driven from the Prepare release GitHub Actions workflow.
Release policy, contracts, the PHP runtime, and the three public lifecycle Actions live in LibreCodeCoop/release-tool. LibreCode’s managed workflow catalog and synchronization helper live in LibreCodeCoop/.github. LibreSign/libresign carries the consumer configuration and repository-specific packaging rules.
Maintainer journey
Run Prepare release manually.
Select the stable branch to release.
Optionally select an exact ref, override the proposed version, choose a prerelease channel, or explicitly ignore a matching open backport blocker.
Review the generated release preparation PR.
Merge that PR using an account that satisfies the configured merge permission.
Review the generated GitHub Release draft.
Publish the draft.
The existing packaging/signing/App Store workflow runs.
Publication verification confirms release identity, publisher run, artifact and App Store visibility.
The released changelog remains in
LibreSign/libresignas the single canonical release-history source.
There are only two semantic human release gates: merging the generated release PR and publishing the generated GitHub Release draft.