Skip to content

fix: auto-sync landing pages with stable release - #278

Merged
masarray merged 4 commits into
mainfrom
fix/landing-release-auto-sync
Sep 8, 2026
Merged

masarray merged 4 commits into
mainfrom
fix/landing-release-auto-sync

Conversation

@masarray

@masarray masarray commented Sep 8, 2026

Copy link
Copy Markdown
Owner

Root cause

The stable release evidence had already advanced to ARSAS 1.6.35, but landing/release-notes.json was still 1.6.33. The Pages workflow intentionally requires both identities to match, so deployment failed with Release notes and stable evidence versions differ and the public landing site remained behind the published release.

Fix

  • add a deterministic scripts/sync-landing-release.py authority that updates landing release notes from verified stable release evidence + the exact GitHub Release metadata
  • preserve curated release copy when it already matches the current version; otherwise generate conservative bilingual notes from the published release changes and verified package evidence
  • synchronize landing/latest.json and landing/release-notes.json in the same release-documentation workflow
  • explicitly dispatch pages.yml after synchronization so a GitHub Actions token commit cannot leave Pages behind the stable release
  • keep the existing strict version-equality gate; stale release metadata remains a deployment failure instead of being silently ignored
  • route prominent landing-page Download CTAs directly to releases/latest/download/ARSAS-Windows-x64-Setup.exe, while the Download Center remains the no-JavaScript/options fallback
  • synchronize the current landing notes to ARSAS 1.6.35

Expected future release flow

stable release published -> verified release evidence -> landing latest + release notes synchronized -> Pages explicitly dispatched -> public Download CTA resolves newest stable installer

No ARSAS runtime, IEC 61850 protocol, ARIEC61850 engine pin, FAT behavior, or Windows release binary is changed by this PR.

@masarray
masarray merged commit a3ff26c into main Sep 8, 2026
10 checks passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 91d537db43

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

fallback_highlights = [
f"The verified Windows installer is published as the stable ARSAS {version} package.",
"The portable single EXE is published from the same verified stable release.",
"SHA-256 checksums, SPDX SBOM and release provenance are published alongside the Windows binaries.",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Verify supply-chain assets before advertising them

When a release body yields zero or one parsed change, this fallback publishes a release-note claim that an SPDX SBOM and provenance are available, but the workflow's normalized-evidence step requires only the installer, portable binary, and checksum file. A stable release missing either supply-chain asset therefore passes synchronization and is publicly described as containing files that do not exist; either validate both assets before generating this text or omit the claim.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant