You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ci(release): verify published artifact integrity before release
The build job's "Verify AppImage integrity" step runs before
upload-artifact, so it validates good bytes but never sees the bytes
that are actually published. v0.7.26 shipped a linux-x64 bundle whose
AppImage, .deb AND .rpm were all corrupt (valid headers, unreadable
compressed payloads) despite that gate passing -- the corruption was
introduced in the upload-artifact -> download-artifact round-trip.
Add a "Verify artifact integrity" step to the release job, after
download-artifact and before Create Release, that fully extracts every
AppImage (squashfs), .deb, .rpm and .zip and fails the release if any
is corrupt. This guards the exact bytes that reach users; a transient
transport corruption now blocks publish instead of shipping.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
0 commit comments