BC ModelVault follows Semantic Versioning using MAJOR.MINOR.PATCH.
- MAJOR: incompatible changes to configuration, behavior, or persistent data.
- MINOR: backward-compatible features.
- PATCH: backward-compatible fixes and security updates.
The canonical version must match across VERSION, bc_modelvault/__init__.py, pyproject.toml, version_info.txt, and CHANGELOG.md.
- Update the version and changelog.
- Run
python -m unittest discover -s tests -v. - Run
build-windows.ps1on Windows. - Verify startup and the
.exefile properties. - Verify the generated
dist/SHA256SUMS.txt. - Verify
pip-audit, third-party notices, anddist/sbom.cdx.json. - Create an annotated tag matching the release, for example
v1.0.1. - Publish a GitHub Release containing the executable, checksum, SBOM, Windows ZIP, changelog, and license/notice files.
The .github/workflows/release.yml workflow automates these steps for v* tags.
For Authenticode signing, configure WINDOWS_CERTIFICATE_BASE64 and
WINDOWS_CERTIFICATE_PASSWORD as GitHub Actions secrets. Without these secrets the
build remains unsigned, but tests, packaging, checksum generation, and artifact
publication still run.
Do not publish a release unless the source, executable, and checksum were produced from the same commit.