Repository navigation
Prepare Configurator 2.0.3 with combined dependency updates - #74
Merged
Merged
Conversation
Combine the open Dependabot updates to Vite 8.3.2, Vitest 5.0.3, and Plotly 4.1.1 while retaining their locked transitive versions. Synchronize application and installer versions and document the release changes. Disable Plotly 4's new cloud-upload button in the app and standalone HTML exports to preserve the local flight-log workflow. Verified clean npm ci, 88 renderer tests, 68 native tests (11 opt-in tests skipped), lint, formatting, Clippy, audits, and release contracts. Production browser graphs and offline exports passed; the native app passed a dummy Vega check. Built the Windows installer and verified its updater signature, including rejection of modified bytes.
Keep release assets focused on installers, updater packages, and latest.json. Remove detached signature files after their contents have been embedded in the update manifest, while retaining them in CI build artifacts. Verified the exact workflow command against all four platform packages: latest.json and every embedded signature remain unchanged, all seven package assets remain, and no standalone signature files reach publication. Release-contract and Prettier checks passed. Removed the four redundant 2.0.2 public signature assets and verified all remaining asset identities and digests, unchanged public manifest bytes, valid signatures, and rejection of altered packages.
Replace the packaging fix already shipped in 2.0.2 with the signature-download cleanup included in the 2.0.3 branch. Describe the preserved signature verification through latest.json. Verified changelog and workflow formatting, application release contracts, the 2.0.3 version contract, and lockfile provenance against the unchanged three Dependabot PR heads.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prepare Configurator 2.0.3 by combining the open dependency updates to Vitest 5.0.3, Vite 8.3.2, and Plotly 4.1.1. Preserve their locked transitive versions and synchronize the application, installer, README, and changelog versions.
Closes #70
Closes #71
Closes #72
Disable Plotly 4's new cloud-upload button in the app and standalone HTML exports to preserve the local flight-log workflow.
Omit standalone
.sigdownloads from release assets after embedding their signatures inlatest.json. Retain the Mac.app.tar.gzarchives required for automatic updates.Validation:
.sigdownloads. Release-contract and formatting checks passed.The combined branch needs the PR's four-platform CI run before merging. The earlier green
mainrun validated 2.0.2, not these combined dependency updates.