# Releasing ForgeFlow ForgeFlow releases are built only from a clean, reviewed commit on Node 22 LTS. ## Quality gate ```powershell npm ci npm run quality npm audit --omit=dev --audit-level=high ``` ## Windows build — no paid services required ForgeFlow is a personal/internal tool. The supported release path therefore has no certificate, Azure or other paid-service dependency: ```powershell npm run dist:win ``` This produces the installer and portable executable, SHA-256 sidecars, a CycloneDX SBOM and provenance evidence. The in-app updater downloads only the matching Gitea release asset, checks its Windows executable format and verifies the published SHA-256 digest before staging it. The update helper verifies the digest again immediately before replacing the installed executable. Windows can display an `Unknown publisher` warning for an unsigned installer. That warning concerns public publisher reputation; it does not prevent ForgeFlow from installing or using its checksum-verified in-app updates. Authenticode can be added later as an optional distribution convenience, but is not required for correct operation. ## Atomic publication `npm run release:binary` keeps the Gitea release in draft state while uploading the installer, portable executable, two checksums, provenance and SBOM. It only publishes after all six assets are present. A failed upload leaves a draft rather than exposing an incomplete updater target. The optional signing acceptance fixture can still validate the complete local Authenticode chain without purchasing or retaining a certificate: ```powershell npm run test:signing ``` This disposable fixture signs installer, portable, update-helper and uninstaller stand-ins, requires an RFC 3161 timestamp, and proves rejection of a missing timestamp, wrong publisher and a modified binary. Its certificate is removed from the current-user certificate store after the test. The disposable test certificate is removed from the current-user certificate store after the test and is never used for a published build.