Releases

How a release is cut

Latest Go release: v2.7.0, published 2026-10-05. TypeScript core: 0.5.0. The process is documented below. No release cadence is promised.

Sources and review date

SourceLast reviewed 2026-10-06
Last reviewed
2026-10-06. Summaries on this page are written by hand and checked against the linked documents on that date. The documents themselves are the record.
Latest versions
Go v2.7.0 (2026-10-05), TypeScript @glinr/theauth 0.5.0. Data as of 2026-10-06.

Go

From changelog to signed release

Steps as RELEASING.md describes them.

  • 1. ChangelogMove entries into a dated section with upgrade notes first, through a pull request.
  • 2. TagCreate a signed, annotated tag on the merged default branch and push it. That triggers the release workflow.
  • 3. WorkflowRuns go mod tidy and the tests as a gate, builds a source archive, generates a CycloneDX SBOM, signs artifacts with cosign keyless signing, creates the GitHub Release and generates a SLSA provenance attestation.
  • 4. VerifyThe document shows how to check signatures with cosign verify-blob and the attestation with gh attestation verify.
  • 5. Sub-modulesstorage/sqlite, mcpresource and audit/sinks/otlp are tagged with a directory prefix, after the root is available through the Go module proxy.
  • Module pathThe root module is github.com/glincker/theauth-go/v2. Tags v2.0.0 to v2.5.0 were never resolvable by the Go toolchain; the first resolvable tag is v2.6.0.
  • Pre-releasesTags with an alpha, beta or rc suffix are published as pre-releases automatically.
  • RollbackDelete the tag and the GitHub Release, fix the issue and cut a new patch release. A published version number is never reused.
  • ScheduleNone. The Go governance file says the project does not publish a release schedule.

Rules

Module path, pre-releases, rollback

TypeScript

Changesets, per package

TypeScript packages are versioned independently with Changesets. The maintainer checklist checks changeset status and bump classes, runs build, typecheck and tests, generates versions, reviews the output, publishes through CI or pnpm release per policy, and verifies npm metadata and installability.

That checklist does not list signing or SBOM steps. The ones above are documented for the Go module. Version lines and what they mean for stability are on the stability page. Per-release notes: GitHub Releases.

What we do not claim

  • No release cadence. Releases ship when they are ready, not on a calendar.
  • No signing claims for TypeScript. Only the Go release process documents signatures, an SBOM and provenance.

Get started

Give your first agent an identity.

Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.

  • npm install @glinr/theauth
  • go get github.com/glincker/theauth-go
Or skip hosting with theAuth Cloud