Claude Transcripts docs GitHub
Work in progressUnder active development — not tested as ready for use. Breaking changes land without notice, stored data may need to be discarded between revisions, and there is no auth or security model.

12. GitHub Actions + GHCR for releases

Date: 2026-06-07

Status

Accepted. Pins the CI system + registry for the tag-driven release model of ADR 0005 (which is unchanged). Amended 2026-09-30 — see Amendment.

Context

The release model (ADR 0005) is tag-driven: pushing a vX.Y.Z tag builds and publishes the single combined image (webapi + prebuilt webui SPA). This record pins which CI system and registry carry that out.

The project ships as a public GitHub repository, so its CI and registry are the ones GitHub provides — nothing external to provision, and images live next to the source.

Decision

Consequences

Amendment: five workflows, and main publishes

2026-09-30.

The two workflows above are now five; publish-image.yml also runs on main (why):

workflowruns ondoes
ci.ymlpush + PR to mainlint/typecheck/test/build, generated-file and contract checks, the Bun-floor check, browser tests
publish-image.ymlv*.*.* tag, push to main, dispatchthe combined image (tags); grype/trivy before push
release-cli.ymlv*.*.* tag, dispatchcross-compiled CLI binaries on the GitHub Release, and the npm package
mirror-images.ymlv*.*.* tag, dispatchmirrors the backing-service images (ADR 0024)
pages.ymlpush to main (site/docs paths), dispatchthe project site and rendered docs on GitHub Pages

release-cli.yml needs one optional secret, NPM_TOKEN; without it the npm step is skipped with a warning.