From 9b671a3c4483cd194daa3239b874e5e0408b1120 Mon Sep 17 00:00:00 2001 From: Paul Isaris Date: Wed, 30 Sep 2026 12:01:28 +0300 Subject: [PATCH] Document the release tag ruleset --- README.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/README.md b/README.md index 4cd72a0..d6f24df 100644 --- a/README.md +++ b/README.md @@ -83,6 +83,12 @@ convention: When the workflows have run in real repositories for a while, `v1` becomes the first stable line. +The ruleset `protect-release-tags` blocks creating, moving and deleting `v*` +tags. Only organisation owners can bypass it, so Actions tokens, apps and +deploy keys cannot change a release. Callers reference workflows by tag, and +the organisation's SHA pinning policy does not cover reusable workflows, so +these tags decide what code runs in every caller. + To publish a fix release on the `v0.1` line: 1. Merge the fix to `main` and wait for a green Self-check.