Nothing verified that the commit being tagged for a release actually
carries the intended version. Tagging a release branch before the version
update PR is merged publishes images and manifests that reference the
previous release. Add build/release/validate-tag.sh to check that the tree
is clean and that deploy/examples/images.txt and the helm chart values
match the tag, run it from the release build workflow before any artifact
is published, and document it in the tagging steps. Alpha tags are exempt
as they only mark the creation of a release branch.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
(cherry picked from commit adda6b17d3)
# Conflicts:
# .github/workflows/push-build.yaml