diff --git a/MAINTENANCE.md b/MAINTENANCE.md index ca0fcbf..c40a4f4 100644 --- a/MAINTENANCE.md +++ b/MAINTENANCE.md @@ -29,7 +29,8 @@ the proposed starting size.)_ ## Maintainer Responsibilities This recipe commits to the following, which is tighter than the floor set by -Resolution 025 (stable-recipe category): +Resolution 025 (stable-recipe category). However, these timelines are +best-effort, so we aim for them as good as possible: - Respond to PRs / issues within 3 working days - Apply security patches within 1 week of disclosure @@ -51,16 +52,24 @@ our own. In practice this means: - **Patch releases (e.g. `32.0.x`)**: published to this recipe shortly after upstream, ideally within 1 week. `chore(deps)` opens the PRs; a maintainer - reviews, deploys against a test instance, and tags. -- **Minor releases**: same flow as patch releases. + reviews the release notes and Nextcloud's issue tracker, and merges the PR + if it is OK. +- **Minor releases**: same flow as patch releases, but one of the maintainer + tests it on their own instance before merging. - **Major releases (e.g. `32 → 33`)**: not adopted on day one. We wait for the first one or two upstream patch releases of the new major to land (typically 1–2 months) before promoting it here, to avoid passing the early-adopter cost to operators. Major bumps get their own PR with release notes and an upgrade-path check. - - If people have the time it would be nice to create specially tagged versions - which reflect that this is 'bleeding edge'. + Before adding a major release, the following needs to be done: + - at least two maintainers update one of their production instances to the + new version + - the previous release gets a last update pointing to the docker image + versions nextcloud:xx-fpm, so that users can auto-update if they wish so + - the new release is added to this repo +- If people have the time it would be nice to create specially tagged versions + for major releases, which reflect that this is 'bleeding edge' and has not + been thoroughly tested. - **Co-installed components** (Talk HPB, OnlyOffice, Whiteboard, etc.) are bumped alongside or shortly after the matching Nextcloud release.