Maintainers
Operational docs for releasing and packaging llmenv.
- Release process — cutting a version: changelog,
Cargo.tomlbump, tagging, and the release workflow. Read this before touching the version number,CHANGELOG-<major>.md, or a release. - Homebrew tap setup — configuring and publishing the Homebrew tap.
Branch strategy​
Feature development happens on main. Each major version gets a
release/X.x long-lived branch for bug fixes and small enhancements. Fix in the oldest applicable
branch first, then merge forward — the forward-merge-release workflow carries the fix and its CHANGELOG entry
up to main. See release.md for the full policy
and patch-release workflow.
Versioning invariant​
A version exists only once it has been git-tagged. Until then, every change goes
under ## [Unreleased] in
the CHANGELOG-<major>.md file for the line you are on (see changelog). git tag -l
is the source of truth — no tag means no version section and no Cargo.toml bump. Full
details in release.md.
Design docs​
- Engine capabilities
— the two-layer
(neutral + per-engine
native) capability model.
Continuous integration​
The workflows are in .github/workflows/.
ciruns on each pull request. Thetestjob runscargo fmt --check,cargo clippy -D warnings, andcargo nextest run --profile ci. Thedenyandhawkjobs runcargo denyandscripts/hawk-check.sh.test,deny, andhawkare required checks, and each job skips itself when its files did not change.coveragerunscargo llvm-covon a pull request that changes Rust, test, script, or changelog files. It fails when total line coverage is below 64%. Raise the floor when the coverage rises; never lower it.mutantsrunscargo mutantson a pull request that touchescrates/llmenv-config,src/merge, orsrc/hook_run. It tests only the mutants on the changed lines, and the job fails when one survives. A full sweep runs every Monday at 04:00 UTC and only reports.codeqlscans Python, JavaScript and TypeScript, Rust, and the workflows. A pull request scans only the languages whose files changed, and uploads an empty result for the others. A push tomainorrelease/**and the weekly run (Monday 05:00 UTC) scan every language, so an unchanged language never closes its open alerts.forward-merge-releasemerges eachrelease/X.xpush into the next branch up tomain. See Forward-merge workflow.releaseruns when av*tag is pushed. See Release process.docsbuilds the website, and deploys it whenmainchangeswebsite/.
Developer tooling​
scripts/hawk-check.sh(the CIhawkjob and thecargo-hawkpre-push hook) builds intotarget/hawk, socargo cleanremoves the hawk build. Before this, hawk built into$TMPDIR/cargo-hawk-target/, which nothing cleaned. Remove old directories once withtrash "${TMPDIR:-/tmp}/cargo-hawk-target". A--target-dirargument orCARGO_TARGET_DIRoverrides the default..config/nextest.tomlsets a 2 sleak-timeout, because the 100 ms default flags file-I/O tests under full parallel load. CI runscargo nextest run --profile ci, where a leaked handle fails the run.