Release Checklist¶
Before tagging a release or merging to main, ALL of the following
items must be verified. This list matches the actually-installed CI
pipeline (see Git & CI/CD) one-to-one — it is not a
generic template.
Git¶
- [ ]
git status --shortis clean, or every change is accounted for - [ ] no files containing real secrets (
.env,.env.local, etc.) show up ingit status(gitignored) - [ ] newly added files contain no real secret/password/token (see the "Security" item below)
- [ ]
node_modules/,dist/,coverage/, raw k6 JSON output are not tracked by Git
Frontend (dashboard/, pnpm)¶
- [ ]
pnpm run typecheck— 0 errors - [ ]
pnpm run lint— 0 errors - [ ]
pnpm run prettier— 0 diffs - [ ]
pnpm test— all tests PASS - [ ]
pnpm run test:coverage— coverage report generated - [ ]
pnpm run build— production build completes successfully
Backend (backend/, npm)¶
- [ ]
npm run typecheck— 0 errors - [ ]
npm run lint— 0 errors - [ ]
npm run prettier— 0 diffs - [ ]
npm test— all tests PASS (auth, authz, dictionary, personnel, resilience) - [ ]
npm run test:coverage— coverage report generated - [ ]
npm run build—dist/builds successfully - [ ]
/healthreturns 200 against the in-memory test server
Security¶
- [ ] auth/authorization/self-privilege-escalation regression tests PASS (see Testing)
- [ ] deep secret scan: no real JWT secret/Mongo URI (with
credentials)/password/token/API key anywhere in
.env, config, Docker, source, test, docs, README, or script files - [ ]
.env.examplefiles are up to date (real variable NAMES, no real VALUES)
Docker¶
- [ ]
docker build ./backendsucceeds - [ ]
docker build ./dashboardsucceeds - [ ]
docker compose configis valid (no syntax/merge errors) - [ ] no image contains an embedded secret
k6¶
- [ ] smoke tests (
k6-smokejob) PASS - [ ] (only when needed, manual) load/stress tests were run and results reviewed — never run against production
MkDocs¶
- [ ]
mkdocs build --strictcompletes without errors - [ ] new pages appear in
mkdocs.yml'snav
Deployment (scripts/, docker-compose.prod.yml)¶
- [ ] the
VERSIONfile was updated for this release (the single source of truth logged by install/update scripts as "Current version"/"Target version" — see Installation / Update / Uninstall) - [ ]
bash -n scripts/linux/*.sh— no syntax errors - [ ] PowerShell parser validation (CI's
scripts-lintjob, or locally viapwsh:[System.Management.Automation.Language.Parser]::ParseFile(...)) passes forscripts/windows/*.ps1/*.psm1 - [ ]
docker compose -f docker-compose.prod.yml configis valid - [ ]
docker build -f backend/Dockerfile.prod ./backendsucceeds - [ ]
docker build -f dashboard/Dockerfile.prod ./dashboardsucceeds - [ ]
docker-compose.yml(development) is UNTOUCHED/unbroken — still hot-reloads viadocker compose up -d
Test data cleanup¶
- [ ]
K6_-prefixed data left over from k6/test runs was cleaned up automatically since it's in-memory only (no separate cleanup step NEEDED) — if a manual test was run against a real DB, itsK6_/test data must be cleaned up by hand