feat: release/latest.json manifest and publish workflow - #655
Merged
Merged
Conversation
SafeDep Report SummaryNo dependency changes detected. Nothing to scan. This report is generated by SafeDep Github App |
Code Pathfinder Security ScanFindings
Powered by Code Pathfinder |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #655 +/- ##
=======================================
Coverage 84.91% 84.92%
=======================================
Files 172 172
Lines 24879 24879
=======================================
+ Hits 21126 21128 +2
+ Misses 2964 2963 -1
+ Partials 789 788 -1 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
This was referenced Apr 12, 2026
Owner
Author
This was referenced Apr 12, 2026
Owner
Author
Merge activity
|
shivasurya
changed the base branch from
feat/analytics-reach-measurement
to
graphite-base/655
April 12, 2026 14:29
Add the single publishing path for version update notices: - release/latest.json: bootstrap source-of-truth manifest (v2.0.2) - .github/workflows/publish-manifest.yml: schema-validate + R2 upload on push to main - CODEOWNERS: restrict release/latest.json edits to @shivasurya - .github/scripts/smoke-update-check.sh: manual end-to-end smoke test - Dockerfile / Dockerfile.mcp: add ENV PATHFINDER_NO_UPDATE_CHECK=1 - README.md: document the announcement push process Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
…d announcements Temporary: workflow now fires on pull_request to feat/publish-manifest so the CDN upload can be verified before merging to main. release/latest.json bumped to v2.0.3 with two test announcements: - test-generic-ann (info, no version_range) — visible to all versions - test-targeted-ann (warn, version_range <2.0.0) — visible only to old builds Test locally after the workflow publishes: cd sast-engine go build -ldflags="-X .../cmd.Version=0.0.1" -o /tmp/pf-stale . go build -ldflags="-X .../cmd.Version=2.0.2" -o /tmp/pf-current . /tmp/pf-stale version # -> upgrade notice + version-targeted ann /tmp/pf-current version # -> upgrade notice + generic ann Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
…-targeted announcements" This reverts commit 4df29bf.
shivasurya
force-pushed
the
feat/publish-manifest
branch
from
April 12, 2026 14:31
17a18be to
fb7ede6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.




Summary
PR-05 of the version-update-check stack. Adds the single publishing path so that
release/latest.jsononmainis the source of truth for update notices and announcements, and any merge that touches it publishes to the CDN within ~60 seconds.Stack: PR-01 (merged) → PR-02 (#652) → PR-03 (#653) → PR-04 (#654) → PR-05 (this)
Changes
release/latest.json— bootstrap manifest at v2.0.2, emptyannouncements: []; human-edited on each release.github/workflows/publish-manifest.yml—push/workflow_dispatchtrigger;jqschema gate → R2 upload (Cache-Control: public, max-age=300) → post-hoc CDN verifyCODEOWNERS— restricts/release/latest.jsonedits to@shivasurya; creates the file (didn't exist before).github/scripts/smoke-update-check.sh— manual end-to-end smoke: checks CDN version, builds stale binary, verifies upgrade banner, verifies current binary is silent. Not wired into CI.Dockerfile/Dockerfile.mcp— addENV PATHFINDER_NO_UPDATE_CHECK=1; Docker users upgrade by pulling a new tag, so an in-container nudge would be noiseREADME.md— adds "Pushing an in-product announcement" paragraph under ContributingNotes
R2_ACCOUNT_ID,R2_ACCESS_KEY_ID,R2_SECRET_ACCESS_KEY) already used bystdlib-r2-upload.yml— no new credentials.assets.codepathfinder.devalready fronts the bucket; no DNS changes needed.Test plan
jq -e '...'validation passes againstrelease/latest.jsonlocallyworkflow_dispatchsmoke run on the branch confirms R2 upload succeedscurl https://assets.codepathfinder.dev/pathfinder/latest.jsonreturns bootstrap JSON after merge🤖 Generated with Claude Code