Releasing
This page consolidates the stable release and publishing procedure for the workspace.
Published Crates
The workspace publishes three crates:
detritus-protocoldetritus-serverdetritus-client
All three stay version-synchronized during 0.x.
Release Order
The release workflow publishes in topological dependency order:
detritus-protocoldetritus-serverdetritus-client
After publishing detritus-protocol and detritus-server, the release workflow waits for the new version to become visible on the crates.io sparse index before continuing.
CI Contract
On every push to trunk and every pull request, CI runs:
cargo fmt --all --checkcargo clippy --workspace --all-features --all-targets -- -D warningscargo check --workspace --all-featurescargo test --workspace --all-featurescargo doc --workspace --no-deps --all-features- an MSRV check on Rust
1.88 cargo audit --deny warningscargo deny --all-features check
CI dry-runs only detritus-protocol:
cargo publish --dry-run -p detritus-protocol --allow-dirty
The dependent crates cannot be dry-run published on arbitrary push and PR commits because their versioned sibling dependencies are resolved against the live crates.io index.
docs.rs Contract
Each published crate carries:
[package.metadata.docs.rs]
all-features = true
rustdoc-args = ["--cfg", "docsrs"]
That keeps docs.rs builds aligned with the feature-complete public API.
Manual Release Procedure
- Bump every published crate version together.
- Bump the
version = "X.Y.Z"qualifiers on internal path dependencies. - Move the
CHANGELOG.mdunreleased entries under a dated release heading. - Commit the release bump.
- Push the commit to
trunkand wait for CI to go green. - Create and push the
vX.Y.Ztag. - Wait for the release workflow to publish the crates in order.
- Verify the published versions on crates.io and then verify the docs.rs builds.
First Release Checklist
Before the first publish of a crate name:
- verify the crate name is free on crates.io
- publish with the tag-driven workflow
- add any intended co-owners after the first successful publish
Supply-Chain Checks
The repository keeps deny.toml at the root and enforces both cargo-audit and cargo-deny in CI. Treat advisory or licensing failures as release blockers.