Introduction
Logmarq is a self-hosted release ledger. It keeps the record of each release you ship: exactly which code and artifacts a version was, what changed since the version before it, the notes that explain it, where it is reported running, and the security decisions made about it.
Your pipeline still tags, builds, and ships. Logmarq records what the pipeline made and does the paperwork afterward. Switch it off and your releases are unaffected.
What Logmarq does
- Records each version. The commit a version's tag points at, every declared artifact pinned to a digest, and the pull requests, commits, and tracker issues since the version before. Release records
- Writes the notes. Internal notes drafted from the changes, and customer notes that are a checked subset of them. Release notes
- Remembers where it runs. Which release each environment reports running, with who or what reported it and when. Environments
- Supports older versions. Release lines for the versions you keep fixing after a newer one ships. Release lines
- Keeps the security record with the release. Bills of materials, vulnerability scans, and VEX decisions for every artifact. Bills of materials
- Answers customers. Which customers run a version, and reviewed packages that answer their security questions. Customers
What Logmarq does not do
- Build, tag, deploy, or roll back software. Your CI/CD pipeline remains the release actor.
- Create or edit tickets, or stand in for your issue tracker or git host. It reads them.
- Manage QA test cases. A release has a status and validation notes, not a test plan.
- Claim that a recorded deployment is what is running now. It keeps what was reported, with its source and age.
Logmarq makes two optional writes to your git host, and only after you grant the permission for each: publishing notes as the body of a release, and freezing a release branch while a version is validated. Everything else it does with the host is reading.
The objects you will work with
| Object | What it is |
|---|---|
| Project | One thing you release: its repositories, tracker, artifacts, and environments |
| Release record | One version: its pinned source, artifacts, changes, status, and history |
| Notes | A release's internal and customer notes, versioned on every save |
| Environment | A place a release runs, such as production, and the releases reported there |
| Release line | A series of versions you keep supporting, such as 1.5.x beside 2.0 |
| Bill of materials | The components and versions inside an artifact, stored against its digest |
| VEX decision | Your recorded answer to whether a vulnerability affects a release |
| Customer | An organization whose environments only the people you grant can see |
| Response package | A reviewed bundle of notes, artifacts, bills of materials, and decisions you send one audience |
A project can span several repositories, such as an application and its deployment configuration, released together as one version.
Integrations and storage
Logmarq reads from GitHub, GitLab, Gitea and Forgejo, Bitbucket Cloud, and Azure DevOps, and links issues from Linear, Jira, GitHub Issues, YouTrack, Shortcut, and Azure Boards. The quickstart follows GitHub. The other hosts and trackers are implemented against their documented interfaces, and live acceptance varies by provider.
It runs as one container. Its database is one SQLite file on a volume by default, or a PostgreSQL server you operate. Drafting notes with a model is optional and uses a model endpoint you configure; without one, a template drafts them.
Development status
Logmarq is in development. The capabilities these pages describe are implemented for controlled evaluation; this documentation does not establish production qualification or a supported public release. Where a capability has not yet been used by a team outside Dekglas, its page says so.
Where to go next
- Quickstart: from the image to a recorded release in a few minutes.
- Release records: what a record pins and where versions come from.
- Glossary: every term these pages use.