Commit graph

5 commits

Author SHA1 Message Date
Yun Chan
f505a03d34 fix(ci): point release-metadata checks at the relocated update and publish guards
Some checks are pending
ci / 정본·보안·린트·타입·테스트 (push) Waiting to run
ci / 워크스페이스 빌드 검증 (push) Blocked by required conditions
ci / 모바일 린트·타입·Jest (push) Waiting to run
ci / Supabase Edge Functions + Cloudflare Worker (push) Waiting to run
ci / .NET API 서버 테스트 (push) Waiting to run
deploy-site / deploy (push) Waiting to run
CI run 121 failed at "버전·계약 정본 대조": earlier refactors moved update
gating from UpdateService into update-policy.ts (evaluateUpdateOffer ties
decideUpdate + isWithinRollout), the differential-download switch into
update-adapters.ts, and the Forgejo re-release guard into
lib/immutable-package-guard.mjs (sha256 comparison, abort on conflict).
The checks still looked for the old markers in the old files. They now
verify the same guarantees where the code lives, and the self-test's
negative case targets assertNoImmutableConflicts.

Also clears the lint gate: a control-character regex in Keycap (range now
starts at U+0020) and unused helpers in two red-team tests.
2026-09-28 20:55:11 +09:00
Yun Chan
dc43884e3e ci: run CI only on Forgejo and delete the never-run GitHub workflows (WS-D)
The repository has Forgejo and GitLab remotes but no GitHub remote, so
nothing under .github/workflows ever ran - including the daily Payple
renewal job, which means Payple subscriptions were not being renewed.

- Port payple-renew (daily cron + manual dispatch) to Forgejo. Requires the
  Forgejo secrets SUPABASE_URL and CRON_SECRET.
- Port the CI checks (quality incl. version:check and contract:check, build,
  mobile quality, edge functions, API tests) to .forgejo/workflows/ci.yml.
  macOS and Android emulator jobs are dropped: no macOS runner here, and the
  signed Android release stays on GitLab mobile-production-release.
- Keep one site deploy workflow (Linux, Cloudflare Pages); remove the
  manual Windows duplicate. The mobile release boundary self-test runs there.
- Release verifiers read the Forgejo/GitLab workflows, fail if .github
  workflows come back, and check the rewritten site offers no mobile package.

Policy: docs/REFACTOR_POLICY.md Wave 3, W3-7 and W3-8.
2026-09-26 15:49:00 +09:00
Yun Chan
49a4c97923 fix(release): refuse to re-publish a version that already shipped
The feed publisher overwrote whatever version-specific assets it found, so a
re-run of an old release tag could quietly replace the installer that
customers already downloaded under that version number.

Publication now compares the bytes already in the version-specific registry
path and stops when they differ, while still allowing an identical re-run to
finish. The metadata verifier gained a negative case so the guard cannot be
removed unnoticed.
2026-09-16 23:49:37 +09:00
Yun Chan
7953706142 feat(release): publish desktop updates from a tag through one feed
Desktop clients had two competing update sources: the runtime pointed at a
legacy GitLab registry while the Forgejo packages were filled in by
hardcoded, version-pinned scripts. Operators could not tell which feed was
authoritative, and no release could be reproduced from a tag.

Auto-update now reads a single canonical Forgejo registry feed, updated by
a version-agnostic publisher that runs from the tag on Forgejo, GitLab, and
GitHub CI alike. Channel, minimum supported version, forced install,
full-versus-delta thresholds, staged rollout, and a remote kill switch come
from one policy file the client fetches alongside the feed. Tag creation is
gated on a clean tree, matching version surfaces, and a changelog section.
2026-09-16 23:23:00 +09:00
Yun Chan
5205dcdfa9 feat(release): prepare 1.1.0 candidate 2026-08-29 18:33:45 +09:00