vX.Y.Z on main in midplaneai/midplane. Its workflow
(.github/workflows/release.yml) runs CI, then packs the gateway once with
its whole dependency tree pinned in npm-shrinkwrap.json, runs the package
smoke test on that tarball and an image built from it, and only then, in a
separate job that runs none of its code or dependencies on the runner,
publishes that same tarball:
- the npm package
midplane, with provenance: a Sigstore-signed statement that this tarball was built by that workflow, from that commit, in this public repository; - the image
ghcr.io/midplaneai/midplane:X.Y.Z(amd64 and arm64), with an SBOM and build provenance attached, signed keyless with cosign by the same workflow’s identity.:latestmoves to each release; deploy a version tag or, better, the digest.
midplane versions on
npm are an older, unrelated product).
The npm package
In a project that installed it:midplane should be listed
as verified with provenance. The package’s page on npmjs.com links its
provenance to the workflow run and the commit.
The image
What is tested before a release
Every change runs the package job in CI: the packed tarball is installed with npm and runs the local quickstart,midplane enroll and linked mode, and the
image built from it runs the quickstart as a non-root user. A release runs the
same test on the exact tarball it publishes. Installing it runs no dependency
install scripts (--ignore-scripts), in the test and in the image. Publishing,
signing and the attestations happen only on a tag; the commands above are how
to check what a tag produced.