fix: auto-sync landing pages with stable release - #278
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 91d537db43
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| fallback_highlights = [ | ||
| f"The verified Windows installer is published as the stable ARSAS {version} package.", | ||
| "The portable single EXE is published from the same verified stable release.", | ||
| "SHA-256 checksums, SPDX SBOM and release provenance are published alongside the Windows binaries.", |
There was a problem hiding this comment.
Verify supply-chain assets before advertising them
When a release body yields zero or one parsed change, this fallback publishes a release-note claim that an SPDX SBOM and provenance are available, but the workflow's normalized-evidence step requires only the installer, portable binary, and checksum file. A stable release missing either supply-chain asset therefore passes synchronization and is publicly described as containing files that do not exist; either validate both assets before generating this text or omit the claim.
Useful? React with 👍 / 👎.
Root cause
The stable release evidence had already advanced to ARSAS 1.6.35, but
landing/release-notes.jsonwas still 1.6.33. The Pages workflow intentionally requires both identities to match, so deployment failed withRelease notes and stable evidence versions differand the public landing site remained behind the published release.Fix
scripts/sync-landing-release.pyauthority that updates landing release notes from verified stable release evidence + the exact GitHub Release metadatalanding/latest.jsonandlanding/release-notes.jsonin the same release-documentation workflowpages.ymlafter synchronization so a GitHub Actions token commit cannot leave Pages behind the stable releasereleases/latest/download/ARSAS-Windows-x64-Setup.exe, while the Download Center remains the no-JavaScript/options fallbackExpected future release flow
stable release published -> verified release evidence -> landing latest + release notes synchronized -> Pages explicitly dispatched -> public Download CTA resolves newest stable installerNo ARSAS runtime, IEC 61850 protocol, ARIEC61850 engine pin, FAT behavior, or Windows release binary is changed by this PR.