Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
99 changes: 42 additions & 57 deletions .github/workflows/pages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,40 @@ jobs:
with:
python-version: "3.12"

- name: Prepare verified stable release evidence
env:
GH_TOKEN: ${{ github.token }}
shell: bash
run: |
set -euo pipefail
if [ "$GITHUB_EVENT_NAME" = "pull_request" ]; then
cp landing/latest.json /tmp/arsas-published.json
else
gh api "repos/$GITHUB_REPOSITORY/contents/published.json?ref=release-evidence" --jq .content | base64 -d > /tmp/arsas-published.json
fi
python - <<'PY'
import json
import re
from pathlib import Path

evidence = json.loads(Path('/tmp/arsas-published.json').read_text())
notes = json.loads(Path('landing/release-notes.json').read_text())
if evidence.get('product') not in (None, 'ARSAS'):
raise SystemExit('Stable release evidence is for another product')
if evidence.get('channel') != 'stable':
raise SystemExit('Only stable release evidence may be deployed')
if evidence.get('version') != notes.get('version'):
raise SystemExit('Release notes and stable evidence versions differ')
if not re.fullmatch(r'\d+\.\d+\.\d+', str(evidence.get('version', ''))):
raise SystemExit('Stable release version is invalid')
for name in ('installer', 'portable'):
package = evidence.get(name, {})
if not re.fullmatch(r'[0-9a-fA-F]{64}', str(package.get('sha256', ''))):
raise SystemExit(f'{name} SHA-256 is invalid')
if int(package.get('sizeBytes', 0)) < 1_000_000:
raise SystemExit(f'{name} size is invalid')
PY

- name: Validate product source, templates and SEO contract
id: source_validation
continue-on-error: true
Expand All @@ -67,66 +101,11 @@ jobs:
exit 1

- name: Build deterministic product website
run: python scripts/build-product-site.py --output _site
run: python scripts/build-product-site.py --output _site --release-evidence /tmp/arsas-published.json

- name: Validate IndexNow payload without network submission
run: python scripts/submit-indexnow.py --sitemap _site/sitemap.xml --dry-run

- name: Sync verified stable updater manifest
if: github.event_name != 'pull_request'
env:
GH_TOKEN: ${{ github.token }}
shell: bash
run: |
set -euo pipefail
gh api "repos/$GITHUB_REPOSITORY/contents/published.json?ref=release-evidence" --jq .content | base64 -d > /tmp/arsas-published.json
python - <<'PY'
import json
from pathlib import Path

evidence = json.loads(Path('/tmp/arsas-published.json').read_text())
installer = evidence['installer']
manifest = {
'schemaVersion': 1,
'product': 'ARSAS',
'version': evidence['version'],
'channel': evidence['channel'],
'publishedAtUtc': evidence['publishedAtUtc'],
'installer': {
'name': installer['name'],
'url': installer['url'],
'sha256': installer['sha256'],
'sizeBytes': installer['sizeBytes'],
},
}
Path('_site/latest.json').write_text(json.dumps(manifest, indent=2) + '\n')
PY

- name: Add PR validation manifest
if: github.event_name == 'pull_request'
shell: bash
run: |
python - <<'PY'
import json
from pathlib import Path

build = json.loads(Path('_site/build-info.json').read_text())
manifest = {
'schemaVersion': 1,
'product': 'ARSAS',
'version': build['version'],
'channel': 'stable',
'publishedAtUtc': '1970-01-01T00:00:00Z',
'installer': {
'name': 'ARSAS-Windows-x64-Setup.exe',
'url': 'https://github.com/masarray/arsas/releases/latest/download/ARSAS-Windows-x64-Setup.exe',
'sha256': '0' * 64,
'sizeBytes': 1000000,
},
}
Path('_site/latest.json').write_text(json.dumps(manifest, indent=2) + '\n')
PY

- name: Validate rendered product website
id: build_validation
continue-on-error: true
Expand Down Expand Up @@ -195,8 +174,14 @@ jobs:
with:
python-version: "3.12"

- name: Prepare stable release evidence
env:
GH_TOKEN: ${{ github.token }}
shell: bash
run: gh api "repos/$GITHUB_REPOSITORY/contents/published.json?ref=release-evidence" --jq .content | base64 -d > /tmp/arsas-published.json

- name: Build current sitemap
run: python scripts/build-product-site.py --output _site
run: python scripts/build-product-site.py --output _site --release-evidence /tmp/arsas-published.json

- name: Submit deployed URLs through IndexNow
id: indexnow
Expand Down
98 changes: 80 additions & 18 deletions .github/workflows/publish-verified-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,12 @@ on:
branches: [ main ]
paths:
- ".release/publish-verified.json"
- "landing/release-notes.json"
- ".github/workflows/publish-verified-release.yml"
push:
branches: [ main ]
paths:
- ".release/publish-verified.json"
- ".github/workflows/publish-verified-release.yml"
workflow_dispatch:

permissions:
Expand All @@ -26,30 +26,40 @@ jobs:
- name: Checkout
uses: actions/checkout@v4

- name: Read verified publication request
- name: Read verified publication request and release notes
id: request
shell: bash
run: |
set -euo pipefail
python - <<'PY' >> "$GITHUB_OUTPUT"
import json
import re
from pathlib import Path

request = json.loads(Path('.release/publish-verified.json').read_text())
notes = json.loads(Path('landing/release-notes.json').read_text())
required = (
'version', 'installerArtifactId', 'installerSha256',
'portableArtifactId', 'portableSha256'
)
missing = [key for key in required if not request.get(key)]
if missing:
raise SystemExit('Missing publication request fields: ' + ', '.join(missing))
if not re.fullmatch(r'\d+\.\d+\.\d+', str(request['version'])):
raise SystemExit('Publication request version is invalid')
if notes.get('version') != request['version']:
raise SystemExit('Release notes version does not match publication request')
signing = notes.get('codeSigning', {})
if signing.get('status') not in ('signed', 'unsigned'):
raise SystemExit('Release notes must declare code-signing status')

print(f"version={request['version']}")
print(f"tag=v{request['version']}")
print(f"installer_artifact_id={request['installerArtifactId']}")
print(f"installer_sha256={request['installerSha256'].lower()}")
print(f"portable_artifact_id={request['portableArtifactId']}")
print(f"portable_sha256={request['portableSha256'].lower()}")
print(f"signing_status={signing['status']}")
PY

- name: Download tested workflow artifacts
Expand Down Expand Up @@ -92,6 +102,51 @@ jobs:
sha256sum verified/ARSAS-Windows-x64-Portable.zip | sed 's#verified/##'
} > verified/ARSAS-Windows-x64-SHA256SUMS.txt

- name: Build public release notes from reviewed metadata
env:
VERSION: ${{ steps.request.outputs.version }}
shell: bash
run: |
python - <<'PY'
import json
import os
from pathlib import Path

notes = json.loads(Path('landing/release-notes.json').read_text())
version = os.environ['VERSION']
lines = [
f"# ARSAS {version}",
"",
notes['summary'],
"",
"## What's new",
"",
*[f"- {item}" for item in notes['highlights']],
"",
"## Reliability improvements",
"",
*[f"- {item}" for item in notes['improvements']],
"",
"## Known limitations",
"",
*[f"- {item}" for item in notes['knownLimitations']],
"",
"## Code-signing status",
"",
f"**{notes['codeSigning']['label']}.** {notes['codeSigning']['detail']}",
"",
"## Included assets",
"",
"- Windows x64 installer",
"- Portable Windows x64 ZIP",
"- SHA-256 checksums",
"",
"Verify the SHA-256 value before use and report reproducible problems through the project issue tracker.",
"",
]
Path('verified/release-notes.md').write_text('\n'.join(lines), encoding='utf-8')
PY

- name: Publish or update stable GitHub release
if: github.event_name != 'pull_request'
env:
Expand All @@ -101,19 +156,6 @@ jobs:
shell: bash
run: |
set -euo pipefail
cat > verified/release-notes.md <<EOF
# ARSAS $VERSION

Stable Windows x64 release of the ARSAS IEC 61850 engineering workstation.

Public users should access ARSAS through the product website. The release assets are used only as the direct-download backend for the landing page and the in-app verified updater.

Included assets:
- Windows installer
- Portable Windows ZIP
- SHA-256 checksums
EOF

assets=(
verified/ARSAS-Windows-x64-Setup.exe
verified/ARSAS-Windows-x64-Portable.zip
Expand Down Expand Up @@ -172,17 +214,32 @@ jobs:
portable_sha="$(sha256sum verified/ARSAS-Windows-x64-Portable.zip | awk '{print $1}')"
installer_size="$(stat -c %s verified/ARSAS-Windows-x64-Setup.exe)"
portable_size="$(stat -c %s verified/ARSAS-Windows-x64-Portable.zip)"
if ! gh api "repos/$GITHUB_REPOSITORY/contents/published.json?ref=release-evidence" --jq .content | base64 -d > verified/existing-published.json; then
printf '{}\n' > verified/existing-published.json
fi

python - <<PY > verified/published.json
import json
from datetime import datetime, timezone
from pathlib import Path

notes = json.loads(Path('landing/release-notes.json').read_text())
try:
existing = json.loads(Path('verified/existing-published.json').read_text())
except (json.JSONDecodeError, OSError):
existing = {}
same_version = existing.get('version') == '$VERSION'
published_at = existing.get('publishedAtUtc') if same_version else datetime.now(timezone.utc).isoformat()
source_commit = existing.get('sourceCommit') if same_version else '$GITHUB_SHA'
print(json.dumps({
'schemaVersion': 1,
'product': 'ARSAS',
'version': '$VERSION',
'tag': '$TAG',
'channel': 'stable',
'publishedAtUtc': datetime.now(timezone.utc).isoformat(),
'sourceCommit': '$GITHUB_SHA',
'publishedAtUtc': published_at,
'sourceCommit': source_commit,
'releaseUrl': 'https://github.com/$GITHUB_REPOSITORY/releases/tag/$TAG',
'installer': {
'name': 'ARSAS-Windows-x64-Setup.exe',
'url': 'https://github.com/$GITHUB_REPOSITORY/releases/latest/download/ARSAS-Windows-x64-Setup.exe',
Expand All @@ -199,6 +256,11 @@ jobs:
'name': 'ARSAS-Windows-x64-SHA256SUMS.txt',
'url': 'https://github.com/$GITHUB_REPOSITORY/releases/latest/download/ARSAS-Windows-x64-SHA256SUMS.txt',
},
'codeSigning': {
'status': notes['codeSigning']['status'],
'platform': 'Authenticode',
'detail': notes['codeSigning']['detail'],
},
}, indent=2))
PY

Expand All @@ -215,7 +277,7 @@ jobs:
if [ -n "$existing_sha" ]; then args+=(-f sha="$existing_sha"); fi
gh api --method PUT "$api_path" "${args[@]}" >/dev/null

- name: Refresh product website updater manifest
- name: Refresh product website release metadata
if: github.event_name != 'pull_request'
env:
GH_TOKEN: ${{ github.token }}
Expand Down
23 changes: 23 additions & 0 deletions landing/app.js
Original file line number Diff line number Diff line change
Expand Up @@ -44,4 +44,27 @@
document.querySelectorAll('[data-year]').forEach(node => {
node.textContent = String(new Date().getFullYear());
});

document.querySelectorAll('[data-copy-value]').forEach(button => {
if (!(button instanceof HTMLButtonElement)) return;
const original = button.textContent || '';
const copiedLabel = document.documentElement.lang === 'id' ? 'Tersalin' : 'Copied';
const failedLabel = document.documentElement.lang === 'id' ? 'Salin manual' : 'Copy manually';
let restoreTimer;

button.addEventListener('click', async () => {
const value = button.dataset.copyValue || '';
if (!value) return;
window.clearTimeout(restoreTimer);
try {
await navigator.clipboard.writeText(value);
button.textContent = copiedLabel;
} catch {
button.textContent = failedLabel;
}
restoreTimer = window.setTimeout(() => {
button.textContent = original;
}, 2200);
});
});
})();
2 changes: 1 addition & 1 deletion landing/download.css

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading
Loading