Publish curated ForgeFlow source from 63022ccf9a37242d573297c8ce7f15db61acc34e
ForgeFlow quality gate / secret-scan (push) Successful in 4s
ForgeFlow signed release / release (push) Failing after 18m45s
ForgeFlow quality gate / quality (push) Canceled after 0s

This commit is contained in:
Public Source Publisher committed 2026-09-30 21:27:28 +00:00
1 parent bdfcc1585d
commit 04cbfccbdb
19 files changed
+233 -77

No files matched your search

+11
View File
@@ -0,0 +1,11 @@
# ForgeFlow 0.10.16
## Signed releases from the public source repository
- Packaged updates follow the exact published release commit, so later documentation or source-only changes do not invalidate the signed executable.
- New installations check `Jens/ForgeFlow-Public` for Windows updates.
- Existing installations that still use the legacy `Jens/ForgeFlow` endpoint move to `ForgeFlow-Public` after installing this bridge release. An intentionally configured alternative update repository is preserved.
- A version change in the curated public source now starts the Windows quality, build, signing and release workflow. Source-only updates do not create another binary release.
- The publisher refuses to replace an already published version or attach assets built from a different commit. Release manifests continue to bind the executable checksums to the exact public source commit and the existing Ed25519 publisher key.
The legacy repository remains available for older installations until the bridge update has been verified in the field.
+2
View File
@@ -2,6 +2,8 @@
ForgeFlow releases are built only from a clean, reviewed commit on Node 22 LTS.
The private source repository publishes a curated snapshot to `Jens/ForgeFlow-Public`. A version change on its `main` branch triggers the Windows release workflow. The workflow checks the public-source manifest, runs the quality and browser gates, builds both Windows artifacts, signs the release manifest with the existing publisher key, and publishes the release after all required assets are present. A source-only change does not create another binary release. The legacy `Jens/ForgeFlow` repository remains available for the 0.10.16 updater bridge.
## Quality gate
```powershell
+5 -5
View File
@@ -14,13 +14,13 @@ Update a source checkout through Git instead:
4. run `npm ci --ignore-scripts` and review the dependency lifecycle allowlist;
5. run `npm run check` before starting ForgeFlow.
The in-app updater remains available for signed packaged Windows releases.
The in-app updater remains available for signed packaged Windows releases. Version 0.10.16 migrates the default endpoint from `Jens/ForgeFlow` to `Jens/ForgeFlow-Public` after a bridge release from the legacy repository. A separately configured update repository is preserved.
## Packaged Windows updates
ForgeFlow uses authenticated Gitea release assets when running from the installer or portable executable. The updater selects the artifact that matches the current installation mode and requires its `.sha256` sidecar. From version 0.10.13 onward it also requires an Ed25519-signed release manifest. The embedded public key verifies that manifest before ForgeFlow trusts the artifact name, byte length, exact source commit or SHA-256 digest. The digest is checked again immediately before applying the update.
`Publish-ForgeFlow-Release.ps1` treats source and binaries as one release transaction. It pushes the validated source, builds the exact published commit and uploads eight required assets:
A version bump in the curated `ForgeFlow-Public` source starts the Windows quality, build, signing and release workflow. It publishes eight required assets:
- `ForgeFlow-Setup-<version>-win-x64.exe`
- `ForgeFlow-Setup-<version>-win-x64.exe.sha256`
@@ -31,9 +31,9 @@ ForgeFlow uses authenticated Gitea release assets when running from the installe
- `ForgeFlow-<version>-release-manifest.json`
- `ForgeFlow-<version>-release-manifest.json.sig`
Run `npm run signing:setup` once on the release workstation. The private Ed25519 key stays outside the repository in ForgeFlow's user-data folder. This independent publisher signature is free; optional Authenticode can still be added later for Windows reputation.
The release workflow uses the same Ed25519 private key that signed the legacy releases, stored as a repository-scoped Gitea Actions secret. Only the public key is committed. `npm run signing:setup` remains available for a local recovery build; do not generate a replacement key for existing installations. Authenticode can still be added separately for Windows reputation.
Use `-SkipBinaryRelease` only when intentionally publishing source without enabling packaged auto-update.
The reviewed source sync runs for every merge to the private canonical repository. Source-only changes do not produce another Windows release. `workflow_dispatch` can retry a failed binary publication for the current public commit.
When the source was already pushed without a binary release, run the recovery publisher from Windows:
@@ -64,6 +64,6 @@ Set-ExecutionPolicy -Scope Process Bypass
.\Publish-ForgeFlow-Release.ps1
```
The script installs dependencies, runs the complete quality gate, clones `git@gitea.itworx.tech:Jens/ForgeFlow.git` into a temporary folder, mirrors the validated source without `.git`, `node_modules`, `dist` or release archives, commits it and pushes `main`. It then compares local `HEAD` with `git ls-remote`, builds the exact published checkout and uploads all binaries, checksums and signed release evidence to the matching Gitea release. Publication fails when either the source commit, publisher signature or any required asset cannot be verified.
The manual script is a recovery path for an extracted, reviewed `ForgeFlow-Public` source export. It installs dependencies, runs the quality gate, verifies the exact published source commit, builds the Windows artifacts and uploads the signed release evidence. Publication fails when the source commit, publisher signature or required assets cannot be verified. An already published version is immutable; use a new version for later source changes.
Keep the currently installed older ForgeFlow source folder untouched until the built-in updater test is complete.