Releasing
Versions have four parts, major.minor.patch.release (for example 0.7.1.1).
Checklist
- Bump the version in
api/package.json,web/package.json,plugins/host/package.json,plugins/tools/package.jsonand their lock files,agent/main.go(version) and.env.example(APP_VERSION). Bundled plugin manifests carry their own versions andminPanelVersion. - Write the release notes in
docs/releases/vX.Y.Z.N.md: highlights, added, changed, fixed, verified (what was really tested and what was not), known limits and upgrade steps. - Make sure CI is green,
npm auditis clean in every package, and Dependabot and code-scanning alerts are resolved. - Tag
vX.Y.Z.N. The workflow Release Linux node agent then:- builds the agent for
amd64andarm64and writesSHA256SUMSandVERSION, - packages the bundled plugins (signed when
PLUGIN_SIGNING_KEYis configured), - collects SBOMs from an unprivileged job,
- signs
SHA256SUMSwith cosign and attests build provenance (best effort), - creates the GitHub release with all assets.
- builds the agent for
- Update nodes: the panel offers the new agent once the release exists.
Plugin registry
If you maintain a registry, rebuild and sign its index with plugins/tools/pack.mjs index after releasing new plugin versions.
Documentation
The docs site is built and published to GitHub Pages by a workflow on pushes to main that touch docs-site/, the API, the plugin host, the schema or the agent, and on release tags.
