ci(release): pin legacy update feeds to the 0.2.20 notice manifests - #3157
Merged
Merged
Conversation
Every stable release re-downloaded latest.json and linux-binaries.json from the v0.2.19 tag, which silently erased the 0.2.20 upgrade notice after each new 1.x tag. Copy the pinned manifests from scripts/fixtures/legacy-update-feeds/ instead and validate them inline (desktop feed = 0.2.20 with non-empty notes, CLI feed = 0.2.19). The publication step byte-compares the uploaded feeds against the fixtures so a drifting fixture or stale upload fails the run. The step no longer shells out to curl or jq, and the verify step is unrolled per manifest so it runs on any bash environment without relying on loop-variable expansion.
kev1n77
force-pushed
the
fmy/updater
branch
from
September 20, 2026 11:43
8ac55b9 to
bb92758
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Every stable release re-downloaded
latest.jsonandlinux-binaries.jsonfrom thev0.2.19tag, which silently erased the 0.2.20 upgrade notice after each new 1.x tag. This PR copies the pinned legacy manifests fromscripts/fixtures/legacy-update-feeds/instead and validates them inline, so the notice survives every future stable release without manual re-upload.Type and Areas
Type: CI (release workflow) + test + docs
Areas: GitHub Actions release pipeline, release guard tests, release docs
Motivation / Impact
platformsblock still resolves to the final 0.2.19 artifacts, so the notice never installs 1.x into a 0.2.x client. The CLI feed stays byte-for-byte on 0.2.19 (no note field exists there).curl/jqfor the copy, and the verify step is unrolled per manifest.No direct user-facing change in 1.x clients; 1.x keeps reading the versioned
latest-v1.json/linux-binaries-v1.jsonfeeds.Verification
node --test --test-name-pattern "legacy updater" scripts/check-github-config.test.mjs— pass. The test mirrors the CI working tree in a sandbox, executes the real step script via bash, and asserts the copied feeds are byte-identical to the pinned fixtures whilelatest-v1.jsonstays untouched.pnpm --dir src/web-ui exec node ../../scripts/check-github-config.mjs— pass (15 YAML files parsed).node --test scripts/check-github-config.test.mjs: 24/26 pass on Windows; the 2 failures (Relay image rebuild...,release publication omits target...) reproduce on the base commit via stash comparison and stem from the local WSL bash stripping$variables inspawnSyncargs — CI (ubuntu bash) is unaffected.latest.json= version 0.2.20 with non-empty notes;linux-binaries.json= version 0.2.19.Reviewer Notes
.gitattributespins the fixtures totext eol=lfbecause the publication step usescmpbyte comparison; newlines must survive any checkout platform unchanged.Checklist