Skip to content

docs: bake CI hardening into a 2.2.1 release#30

Merged
cohenrobinson merged 1 commit into
mainfrom
chore/release-2-2-1
May 10, 2026
Merged

docs: bake CI hardening into a 2.2.1 release#30
cohenrobinson merged 1 commit into
mainfrom
chore/release-2-2-1

Conversation

@cohenrobinson
Copy link
Copy Markdown
Contributor

Why

Cuts a 2.2.1 patch so the in-toto provenance file (PR #28) and the SHA-pinned OSS-Fuzz base image (PR #29) ship in a tagged GitHub Release. Both were `ci:` commits that release-please skipped.

Practical effect: Scorecard's Signed-Releases check will see the provenance bundle in v2.2.1's release assets and lift from 8/10 → 10/10. No source/behaviour change versus v2.2.0 — wheel and sdist bytes are identical apart from version metadata.

The visible body change is a small extension to the release-pipeline diagram in CONTRIBUTING.md to mention the new provenance asset. `Release-As: 2.2.1` in the squash message forces release-please to cut the patch.

🤖 Generated with Claude Code

Cuts a 2.2.1 patch so the in-toto provenance file (PR #28) and the
SHA-pinned OSS-Fuzz base image (PR #29) ship in a tagged GitHub
Release. Both were ``ci:`` commits that release-please skipped.

Practical effect: Scorecard's Signed-Releases check will see the
provenance bundle in v2.2.1's release assets and lift from 8/10 to
10/10. No source/behaviour change versus v2.2.0 — the wheel and
sdist bytes are identical apart from version metadata.

Body change: extend the release-pipeline diagram in CONTRIBUTING.md
to mention the new provenance asset.

Release-As: 2.2.1

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@cohenrobinson cohenrobinson merged commit 7798a08 into main May 10, 2026
10 checks passed
@cohenrobinson cohenrobinson deleted the chore/release-2-2-1 branch May 10, 2026 14:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant