Release operations¶
CCB's experimental release workflow is triggered by relevant pushes to master and supports
manual dispatch. It creates timestamped prerelease metadata, release notes from Git history,
and a GitHub release, then coordinates platform/data artifacts such as translations, tilesets,
shaders, desktop packages, and Android bundles.
Authority and sequencing¶
.github/workflows/release.yml and .github/workflows/release-android-bundle.yaml define the
actual jobs, permissions, dependencies, artifact names, and triggers. doc/RELEASE_PROCESS.md
provides background. Always inspect the workflow at the release commit before operating it.
- Confirm the target commit and default-branch CI state.
- Confirm translations, shader/tiles generation, version metadata, and platform build inputs.
- Trigger only the intended workflow/event; do not rerun unrelated old commits.
- Monitor every dependent job and preserve the run URL/logs.
- Compare release target SHA, notes range, tags, checksums, artifact set, signatures, and smoke test results before announcing the release.
Failure handling¶
A created GitHub release does not prove every artifact succeeded. If a downstream job fails, state exactly which artifacts are absent or superseded; repair the workflow/input in a PR and rerun deliberately. Never upload a locally improvised replacement under a trusted release name.
Security and permissions¶
Release tokens/signing material stay in GitHub secrets or protected environments. Human review is required for workflow, permission, signing, and destination changes. Current broad permissions are a security-review target; documentation must not claim least privilege until settings and workflow scopes demonstrate it.
Records and rollback¶
Retain release commit, tag, run IDs, artifact checksums, toolchain/dependency revisions, signing identity, Responsible human, known issues, and supersession/rollback decision. Prefer publishing a corrected/superseding release to silently replacing artifacts.
Validation¶
Smoke-test each distributed platform from the published artifact and verify data, mods, Lua, translations, graphics/audio, save/load, and upgrade behavior. Archive matching symbols and the documentation/API snapshot needed to diagnose that exact release.