Skip to content

fix(release): retire obsolete 1.6.38 publishers and block SBOM overwrite - #377

Merged
masarray merged 7 commits into
mainfrom
fix/retire-legacy-release-publishers-v1640
Sep 24, 2026
Merged

masarray merged 7 commits into
mainfrom
fix/retire-legacy-release-publishers-v1640

Conversation

@masarray

Copy link
Copy Markdown
Owner

Root cause

Three one-off v1.6.38 workflow entrypoints remain runnable on current main; two can replace historical release assets and use --latest, bypassing the stable asset immutability guarantees introduced in #373. The manual supply-chain backfill can also overwrite an existing stable SBOM using --clobber.

Scope

  • Remove the three historical Actions YAML entrypoints from current tree only (Git history and exact recovery manifests/evidence remain intact).
  • Make manual SBOM backfill additive/fail-closed when the asset already exists, without overwriting published bytes.
  • Update release documentation to identify the canonical publisher and retained historical provenance.
  • Add regression tests for absent historical entrypoints, preserved evidence and immutable current publishers.

Non-regression boundary

No application runtime, Smart Discovery, SCL, DataSet, reporting, engine lock, version/tag, historical release, or website asset is changed. CI and the post-merge production authority must pass before merge.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2663dc8ba0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/WINDOWS_RELEASES.md
Comment on lines +92 to 93
.\scripts\publish-windows-portable.ps1 -Version 1.6.40
.\scripts\build-windows-installer.ps1 -Version 1.6.37 -Runtime win-x64

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Align the installer example with the current release version

When a user follows these adjacent local-packaging commands, the first publishes version 1.6.40 while build-windows-installer.ps1 derives its default input directory from version 1.6.37. The installer command therefore looks for dist/ARSAS-1.6.37-win-x64 instead of the newly published output, either failing with “Published application folder was not found” or packaging stale 1.6.37 files if that directory remains. Update the installer example to use the same current version.

Useful? React with 👍 / 👎.

@masarray
masarray merged commit 013aa61 into main Sep 24, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant