Continuous Delivery Scripts: task guides
Use these guides to choose a command for a delivery task. All commands read
the shared project delivery definition from [ProjectConfig] in
pyproject.toml, regardless of language or CI system. Language plugins select
the ecosystem tools used for project-specific steps. The tools run in a Git
checkout with a Python environment; they are not tied to one CI provider.
The API reference covers
the implementation, while these pages focus on inputs, outputs and examples.
For language-specific packaging, credentials and metadata support, consult
the plugin guides.
Dependency licences and OpenChain workflows
- Assess dependency licence risks: Review directional, explainable licence screening and optional project policy overrides.
- Check licence compliance: Gate a project without generating SPDX files; optionally write reports.
- Generate an SPDX SBOM: Produce project and dependency SPDX tag-value documents.
- Generate a third-party IP / TPIP report: Review dependency licences and compliance summaries.
- Manage licence headers: Apply copyright and SPDX headers to source files.
Versioning and releases
- Create a news fragment: Describe one change before a release.
- Check news fragments: Require a valid fragment on a branch.
- Preview a version: Calculate a proposed project version.
- Generate a changelog: Build release notes from news fragments.
- Automate releases: Tag and publish with a language plugin.
Other project checks
- Generate code documentation: Build the API reference.
- Read project configuration: Reuse values in scripts and CI.
- Record accepted secret findings: Maintain the detect-secrets baseline.
- Check for new secrets: Scan Git-tracked files in CI.