2.0 KiB
Releasing ForgeFlow
ForgeFlow releases are built only from a clean, reviewed commit on Node 22 LTS.
Quality gate
npm ci
npm run quality
npm audit --omit=dev --audit-level=high
Windows build — no paid services required
ForgeFlow is a personal/internal tool. The supported release path therefore has no certificate, Azure or other paid-service dependency:
npm run dist:win
This produces the installer and portable executable, SHA-256 sidecars, a CycloneDX SBOM and provenance evidence. The in-app updater downloads only the matching Gitea release asset, checks its Windows executable format and verifies the published SHA-256 digest before staging it. The update helper verifies the digest again immediately before replacing the installed executable.
Windows can display an Unknown publisher warning for an unsigned installer.
That warning concerns public publisher reputation; it does not prevent ForgeFlow
from installing or using its checksum-verified in-app updates. Authenticode can
be added later as an optional distribution convenience, but is not required for
correct operation.
Atomic publication
npm run release:binary keeps the Gitea release in draft state while uploading
the installer, portable executable, two checksums, provenance and SBOM. It only
publishes after all six assets are present. A failed upload leaves a draft rather
than exposing an incomplete updater target.
The optional signing acceptance fixture can still validate the complete local Authenticode chain without purchasing or retaining a certificate:
npm run test:signing
This disposable fixture signs installer, portable, update-helper and uninstaller stand-ins, requires an RFC 3161 timestamp, and proves rejection of a missing timestamp, wrong publisher and a modified binary. Its certificate is removed from the current-user certificate store after the test.
The disposable test certificate is removed from the current-user certificate store after the test and is never used for a published build.