create-release-tag
Create a Release Tag
Require an explicit stable version in exact <major>.<minor>.<patch> form. Do
not infer it from metadata or a branch name, and do not edit package metadata
while tagging. The matching release/<major>.<minor> branch must exist on
upstream; Relay stable tags are raw SemVer, for example 0.9.0, without v.
Before the destructive tag push, require explicit approval. Preserve user
changes: do not stash, discard, or switch away from a dirty checkout. Fetch the
release branch and tags, require HEAD to equal the upstream release branch,
and require the workspace version to equal the requested version. Verify both
local and remote tags are absent, create a signed annotated tag, verify it with
git tag -v, and push only refs/tags/<tag>. Stop on any failed check; never
force-update, replace, or delete tags.