go test ./...go vet ./...pnpm --dir web lint && pnpm --dir web builddist/, bin/, *.sbom.json, coverage.out,
web/dist/, web/node_modules/)goreleaser release --snapshot --clean --skip=docker,sbom,signgolangci-lint run ./...CHANGELOG.md updated with all changes since last releasemain commitRELEASE_TAG=<tag> RELEASE_MAIN_REF=main bash scripts/verify-release-tag.sh passes before pushv* tag pushed once; an existing release tag is never moved, reused, or deletedtask release:verifyversion and appVersion match the release tag without the leading vdocker logout ghcr.io, VERIFY_REMOTE_IMAGES=1 scripts/verify-chart-images.sh <version> passes for all three public GHCR manifestsghcr.io/oaslananka/ and multi-arch manifests createddocker run --rm ghcr.io/oaslananka/draforge-server:v0.x.x version
docker run --rm ghcr.io/oaslananka/draforge-server:v0.x.x doctor --help
docs/release.md readme reflects any process changestask demo:up tested in a clean namespacescripts/verify-sim-driver-cdi.sh passes for non-root demo and fail-closed host-integrated node modestask demo:down tears down its billable resourcesos/exec or shell injection vectors in changed code* in production)go tool govulncheck ./...)This section applies only when maintainers use the optional DigitalOcean showcase.
task demo:downinfra/terraform/*/terraform.tfstate*
covered by .gitignore)scripts/audit-cloud-resources.sh run after any infrastructure changegit status --short checked before committing.gitignore entries confirmed active for:
dist/bin/*.sbom.jsoncoverage.outweb/dist/web/node_modules/.env or credential files staged