Skip to main content

Metadata

Configure project metadata and control metadata.json output

The metadata section sets project-level information used by publishers and made available as template variables.

Minimal config

metadata:
  description: "A fast CLI tool for data processing"
  homepage: "https://example.com/myapp"
  license: MIT

Metadata config fields

FieldTypeDefaultDescription
descriptionstringnoneProject description
documentationstringCargo [package].documentationProject documentation URL. Drives the OCI org.opencontainers.image.documentation label and {{ Metadata.Documentation }}. Derived from Cargo.toml when unset.
homepagestringnoneProject homepage URL
licensestringCargo [package].licenseSPDX license identifier or expression (e.g., MIT, Apache-2.0, MIT OR Apache-2.0). Drives {{ Metadata.License }}. Derived from Cargo.toml when unset.
maintainerslistnoneList of maintainer names/emails
mod_timestampstringnoneTemplate or Unix timestamp applied as mtime to metadata.json and artifacts.json

Template variables

All metadata fields are available as template variables:

VariableDescription
{{ Metadata.Description }}Project description
{{ Metadata.Documentation }}Documentation URL
{{ Metadata.Homepage }}Homepage URL
{{ Metadata.License }}SPDX license identifier
{{ Metadata.Maintainers }}Maintainer list
{{ Metadata.ModTimestamp }}Rendered mod_timestamp value

Reproducible timestamps

Use mod_timestamp to set a deterministic modification time on the generated metadata files:

metadata:
  mod_timestamp: "{{ CommitTimestamp }}"

This renders the template at the end of the pipeline and applies the resulting Unix timestamp as the file mtime to both metadata.json and artifacts.json.

Generated files

Anodizer always writes two JSON files to the dist directory:

  • metadata.json — project metadata: project_name, tag, previous_tag, version, commit, date, and runtime info (goos, goarch)
  • artifacts.json — full list of all artifacts produced during the release (see Artifacts)

Uploading metadata files

To attach metadata.json to the release:

release:
  include_meta: true

include_meta attaches only metadata.json. artifacts.json is the dist directory's local manifest — anodizer reads it back for release --continue, merge, and the determinism harness — and is never uploaded as a release asset. It records absolute dist paths and internal artifact bookkeeping that carry no meaning outside the machine that produced them.

The same rule holds everywhere include_meta / meta appears: the blob, Artifactory, and generic upload publishers each ship metadata.json alone.

Full example

metadata:
  description: "A fast CLI tool for data processing"
  homepage: "https://example.com/myapp"
  license: Apache-2.0
  maintainers:
    - "Alice <alice@example.com>"
    - "Bob <bob@example.com>"
  mod_timestamp: "{{ CommitTimestamp }}"