Every theauth-go release artifact is signed with cosign keyless signing via
Sigstore OIDC (GitHub Actions identity). The release workflow also generates a
CycloneDX SBOM and a SLSA provenance attestation.
Operational since v2.4.0.
Goreleaser, SBOM generation, cosign keyless signing, and SLSA provenance
attestation are all fully operational as of the v2.4.0 release (#57). The
workflow that drives this is
.github/workflows/release.yml.
Every tag push since v2.4.0 produces a signed, attested release.
Release process
See RELEASING.md in the repository for the full maintainer process. In brief:
- Update
CHANGELOG.md: move entries from [Unreleased] to a versioned section.
- Open and merge a PR for the changelog.
- Tag the release:
The tag push triggers .github/workflows/release.yml, which runs goreleaser, cosign, and the SLSA attestation step.
Verifying a release
Download assets
Verify the SBOM signature
Verify the source archive signature
Both commands should print Verified OK.
Verify SLSA provenance
Tags with -alpha, -beta, or -rc suffixes are published as pre-releases automatically (prerelease: auto in .goreleaser.yml). Follow the same tag procedure; GitHub marks the release as a pre-release.
Rollback
If a bad release is published:
- Delete the tag:
git push origin :refs/tags/vX.Y.Z
- Delete the GitHub Release:
gh release delete vX.Y.Z --repo glincker/theauth-go
- Fix the issue, cut a patch release (vX.Y.Z+1), and re-tag.
Do not reuse a version number after publishing it. Consumers may have cached the module at that version in their module proxy. Last modified on October 7, 2026