Publishing is only ever done by GitHub Actions (.github/workflows/release.yml), triggered by
a vX.Y.Z tag whose commit is reachable from develop. Tags on any other branch are rejected by
the workflow before anything is built. No one needs local publishing credentials — the workflow
authenticates to RubyGems.org via OIDC trusted publishing.
The v prefix is required: the workflow triggers on v*, and it is the tag rake release
creates. RubyGems.org strips it, so v3.6.3 publishes version 3.6.3 — which is why the
versions listed on rubygems.org never carry the prefix.
-
Bump
MAJOR/MINOR/PATCHinlib/patches/version.rb. -
Replace
unreleasedin the## [X.Y.Z] - unreleasedheading at the top ofCHANGELOG.mdwith today's date. A release branch carriesunreleasedwhile it waits for review, so the date is always the day it ships - 3.7.0 shipped a week after its entry was drafted and claimed the drafting date until someone noticed. -
Commit both changes and get them onto
develop(PR + merge, as normal). -
From an up-to-date
develop, tag the commit and push the tag:git tag vX.Y.Z git push origin vX.Y.Z
-
Watch the "Release" workflow run in the Actions tab.
-
Confirm the new version shows up on rubygems.org.
Do not run bundle exec rake release from a workstation. It would push the gem under your own
credentials and push the tag, and the workflow's own rake release would then fail because the
version already exists.
- RubyGems.org: an existing owner of the
patchesgem must add a Trusted Publisher forrdytech/patches, workflowrelease.yml(no environment). See Trusted Publishing: adding a publisher. Until this is done, the release will fail while configuring credentials. The gem currently lists a single owner, handlejr.