Files
fips/.github/workflows
Johnathan Corgan efe77410a1 Version release-candidate Debian packages as X.Y.Z~rcN
A tag's -rcN suffix became the .deb version X.Y.Z-rcN, which dpkg reads
as a revision of X.Y.Z and sorts above the release, so the release never
upgraded a host that had installed the candidate. git does not allow '~'
in a tag, so the Linux package workflow now maps a pre-release suffix to
~ for the .deb Version only. The tarball, the workflow artifact and the
.deb file name keep the tag's form: GitHub renames a release asset whose
name has special characters, which would leave checksums-linux.txt
naming a file the release does not carry. Release and branch builds are
unchanged.

A new check runs the workflow's own derivation on a release tag, a
candidate tag and a branch, confirms with dpkg that the candidate sorts
below the release, and checks that the output is declared, passed to the
.deb build and that the file is renamed. Both local and GitHub CI run it.
2026-09-30 14:12:22 +00:00
..