Skip to content

[ci] verify native release artifacts before publishing (STAR-104) - #36

Merged
vt128 merged 1 commit into
masterfrom
codex/artifact-validation
Sep 19, 2026
Merged

vt128 merged 1 commit into
masterfrom
codex/artifact-validation

Conversation

@vt128

@vt128 vt128 commented Sep 19, 2026

Copy link
Copy Markdown
Member

Release archives were published immediately after cross-compilation. No native installation gate proved that the archives could be installed, exercised, upgraded, and rolled back, and local snapshots used a floating GoReleaser version.

Build once without publishing, validate the full six-target checksum/archive/member contract, and test those exact binaries on native Linux, macOS, and Windows runners for both amd64 and arm64. The existing end-to-end suite accepts an explicit installed binary, so the artifact check cannot silently rebuild source instead. Installation rehearsals use a path with spaces, upgrade from the real v0.1.2 release, and restore the previous binary byte-for-byte.

For an approved annotated tag, only the tested archives are uploaded after all native gates pass. Release title and notes come from the annotation; artifact attestations bind the distributed bytes to this workflow. Retries do not overwrite an existing release. PR/master snapshots have read-only repository permissions and never publish. Pin local make snapshot to the same GoReleaser 2.18.2 as CI.

References STAR-104. Packaging and workflow preparation do not publish the still-pending dependency releases or claim support for untrusted multi-tenant scripts.

Validation:

  • Actual six-target GoReleaser snapshot build; native macOS arm64 checksum/install/upgrade/full end-to-end/rollback run passed, including the real downloaded v0.1.2 baseline.
  • Negative checks reject missing archives, missing or duplicate manifest entries, incorrect hashes and unexpected distribution files.
  • Full build, race tests twice, vet, formatting, actionlint and Go 1.26.8 Docker build/race passed. CI additionally runs the artifact rehearsal on every target.
  • The tag-only attestation/publication path is deliberately not executed before maintainer release approval.

@codecov

codecov Bot commented Sep 19, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.34%. Comparing base (7edf857) to head (e1e59c4).

Additional details and impacted files
@@           Coverage Diff           @@
##           master      #36   +/-   ##
=======================================
  Coverage   86.34%   86.34%           
=======================================
  Files          23       23           
  Lines        1128     1128           
=======================================
  Hits          974      974           
  Misses        117      117           
  Partials       37       37           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@vt128
vt128 merged commit 760b2d2 into master Sep 19, 2026
18 checks passed
@vt128
vt128 deleted the codex/artifact-validation branch September 19, 2026 23:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant