Skip to content

feat: release/latest.json manifest and publish workflow - #655

Merged
shivasurya merged 3 commits into
mainfrom
feat/publish-manifest
Apr 12, 2026
Merged

shivasurya merged 3 commits into
mainfrom
feat/publish-manifest

Conversation

@shivasurya

Copy link
Copy Markdown
Owner

Summary

PR-05 of the version-update-check stack. Adds the single publishing path so that release/latest.json on main is the source of truth for update notices and announcements, and any merge that touches it publishes to the CDN within ~60 seconds.

Stack: PR-01 (merged) → PR-02 (#652) → PR-03 (#653) → PR-04 (#654) → PR-05 (this)

Changes

  • release/latest.json — bootstrap manifest at v2.0.2, empty announcements: []; human-edited on each release
  • .github/workflows/publish-manifest.yml — push/workflow_dispatch trigger; jq schema gate → R2 upload (Cache-Control: public, max-age=300) → post-hoc CDN verify
  • CODEOWNERS — restricts /release/latest.json edits to @shivasurya; creates the file (didn't exist before)
  • .github/scripts/smoke-update-check.sh — manual end-to-end smoke: checks CDN version, builds stale binary, verifies upgrade banner, verifies current binary is silent. Not wired into CI.
  • Dockerfile / Dockerfile.mcp — add ENV PATHFINDER_NO_UPDATE_CHECK=1; Docker users upgrade by pulling a new tag, so an in-container nudge would be noise
  • README.md — adds "Pushing an in-product announcement" paragraph under Contributing

Notes

  • First-merge chicken-and-egg is intentional: GitHub evaluates the workflow from the commit being pushed, so the first run is the bootstrap publish.
  • Reuses existing R2 secrets (R2_ACCOUNT_ID, R2_ACCESS_KEY_ID, R2_SECRET_ACCESS_KEY) already used by stdlib-r2-upload.yml — no new credentials.
  • assets.codepathfinder.dev already fronts the bucket; no DNS changes needed.

Test plan

  • jq -e '...' validation passes against release/latest.json locally
  • workflow_dispatch smoke run on the branch confirms R2 upload succeeds
  • curl https://assets.codepathfinder.dev/pathfinder/latest.json returns bootstrap JSON after merge

🤖 Generated with Claude Code

@shivasurya shivasurya added documentation Improvements or additions to documentation enhancement New feature or request github_actions Pull requests that update GitHub Actions code docker Docker/Dockerfile related changes labels Apr 12, 2026
@shivasurya shivasurya self-assigned this Apr 12, 2026
@shivasurya shivasurya added documentation Improvements or additions to documentation enhancement New feature or request github_actions Pull requests that update GitHub Actions code docker Docker/Dockerfile related changes labels Apr 12, 2026
@safedep

safedep Bot commented Apr 12, 2026 •

Copy link
Copy Markdown

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

No dependency changes detected. Nothing to scan.

View complete scan results →

This report is generated by SafeDep Github App

@github-actions

github-actions Bot commented Apr 12, 2026 •

Copy link
Copy Markdown

Code Pathfinder Security Scan

Issues Found Critical High Medium Low Info

Findings

Severity File Line Issue
🟠 High Dockerfile 1 Missing Image Version 🔗
🟠 High Dockerfile 21 Missing Image Version 🔗
🟠 High Dockerfile 1 Missing Image Version 🔗
🟠 High Dockerfile 21 Missing Image Version 🔗
🟠 High Dockerfile 1 Container Running as Root - Missing USER 🔗
🟡 Medium Dockerfile.mcp 25 Missing pipefail in Shell Commands 🔗
🟡 Medium Dockerfile.mcp 49 Multiple ENTRYPOINT Instructions 🔗
🟡 Medium Dockerfile.mcp 15 Sudo Usage in Dockerfile 🔗
🟡 Medium Dockerfile.mcp 22 Sudo Usage in Dockerfile 🔗
🟡 Medium Dockerfile.mcp 25 Sudo Usage in Dockerfile 🔗
🟡 Medium Dockerfile.mcp 30 Sudo Usage in Dockerfile 🔗
🟡 Medium Dockerfile.mcp 33 Sudo Usage in Dockerfile 🔗
🟡 Medium Dockerfile 1 Base Image Uses :latest Tag 🔗
🟡 Medium Dockerfile 21 Base Image Uses :latest Tag 🔗
🟡 Medium Dockerfile 49 Multiple ENTRYPOINT Instructions 🔗
🟡 Medium Dockerfile 15 Sudo Usage in Dockerfile 🔗
🟡 Medium Dockerfile 17 Sudo Usage in Dockerfile 🔗
🟡 Medium Dockerfile 19 Sudo Usage in Dockerfile 🔗
🟡 Medium Dockerfile 26 Sudo Usage in Dockerfile 🔗
🟡 Medium Dockerfile 31 Sudo Usage in Dockerfile 🔗
🟡 Medium Dockerfile 38 Sudo Usage in Dockerfile 🔗
🟡 Medium Dockerfile 40 Sudo Usage in Dockerfile 🔗
🔵 Low Dockerfile.mcp 15 apt-get Without --no-install-recommends 🔗
🔵 Low Dockerfile.mcp 15 Remove apt Package Lists 🔗
🔵 Low Dockerfile.mcp 49 Prefer JSON Notation for CMD/ENTRYPOINT 🔗
🔵 Low Dockerfile.mcp 12 Use Absolute Path in WORKDIR 🔗
🔵 Low Dockerfile.mcp 15 Missing -y flag for apt-get 🔗
🔵 Low Dockerfile.mcp 15 Prefer apt-get over apt 🔗
🔵 Low Dockerfile.mcp 22 Prefer apt-get over apt 🔗
🔵 Low Dockerfile.mcp 25 Prefer apt-get over apt 🔗
🔵 Low Dockerfile.mcp 30 Prefer apt-get over apt 🔗
🔵 Low Dockerfile.mcp 33 Prefer apt-get over apt 🔗
🔵 Low Dockerfile.mcp 15 Nonsensical Command 🔗
🔵 Low Dockerfile.mcp 22 Nonsensical Command 🔗
🔵 Low Dockerfile.mcp 25 Nonsensical Command 🔗
🔵 Low Dockerfile.mcp 30 Nonsensical Command 🔗
🔵 Low Dockerfile.mcp 33 Nonsensical Command 🔗
🔵 Low Dockerfile.mcp 15 Nonsensical Command 🔗
🔵 Low Dockerfile.mcp 22 Nonsensical Command 🔗
🔵 Low Dockerfile.mcp 25 Nonsensical Command 🔗
🔵 Low Dockerfile.mcp 30 Nonsensical Command 🔗
🔵 Low Dockerfile.mcp 33 Nonsensical Command 🔗
🔵 Low Dockerfile.mcp 22 pip install Without --no-cache-dir 🔗
🔵 Low Dockerfile 1 Dockerfile Source Not Pinned 🔗
🔵 Low Dockerfile 21 Dockerfile Source Not Pinned 🔗
🔵 Low Dockerfile 49 Prefer JSON Notation for CMD/ENTRYPOINT 🔗
🔵 Low Dockerfile 3 Use Absolute Path in WORKDIR 🔗
🔵 Low Dockerfile 23 Use Absolute Path in WORKDIR 🔗
🔵 Low Dockerfile 1 Missing HEALTHCHECK Instruction 🔗
🔵 Low Dockerfile 15 Prefer apt-get over apt 🔗
🔵 Low Dockerfile 17 Prefer apt-get over apt 🔗
🔵 Low Dockerfile 19 Prefer apt-get over apt 🔗
🔵 Low Dockerfile 26 Prefer apt-get over apt 🔗
🔵 Low Dockerfile 31 Prefer apt-get over apt 🔗
🔵 Low Dockerfile 38 Prefer apt-get over apt 🔗
🔵 Low Dockerfile 40 Prefer apt-get over apt 🔗
🔵 Low Dockerfile 15 Nonsensical Command 🔗
🔵 Low Dockerfile 17 Nonsensical Command 🔗
🔵 Low Dockerfile 19 Nonsensical Command 🔗
🔵 Low Dockerfile 26 Nonsensical Command 🔗
🔵 Low Dockerfile 31 Nonsensical Command 🔗
🔵 Low Dockerfile 38 Nonsensical Command 🔗
🔵 Low Dockerfile 40 Nonsensical Command 🔗
🔵 Low Dockerfile 15 Nonsensical Command 🔗
🔵 Low Dockerfile 17 Nonsensical Command 🔗
🔵 Low Dockerfile 19 Nonsensical Command 🔗
🔵 Low Dockerfile 26 Nonsensical Command 🔗
🔵 Low Dockerfile 31 Nonsensical Command 🔗
🔵 Low Dockerfile 38 Nonsensical Command 🔗
🔵 Low Dockerfile 40 Nonsensical Command 🔗
🔵 Low Dockerfile 26 apk add Without --no-cache 🔗
🔵 Low Dockerfile 31 pip install Without --no-cache-dir 🔗
Metric Value
Files Scanned 7
Rules 205

Powered by Code Pathfinder

@codecov

codecov Bot commented Apr 12, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 84.92%. Comparing base (dbc4a34) to head (fb7ede6).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #655   +/-   ##
=======================================
  Coverage   84.91%   84.92%           
=======================================
  Files         172      172           
  Lines       24879    24879           
=======================================
+ Hits        21126    21128    +2     
+ Misses       2964     2963    -1     
+ Partials      789      788    -1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

shivasurya commented Apr 12, 2026 •

Copy link
Copy Markdown
Owner Author

shivasurya commented Apr 12, 2026 •

Copy link
Copy Markdown
Owner Author

Merge activity

  • Apr 12, 2:24 PM UTC: A user started a stack merge that includes this pull request via Graphite.
  • Apr 12, 2:31 PM UTC: Graphite rebased this pull request as part of a merge.
  • Apr 12, 2:32 PM UTC: @shivasurya merged this pull request with Graphite.

@shivasurya
shivasurya changed the base branch from feat/analytics-reach-measurement to graphite-base/655 April 12, 2026 14:29
@shivasurya
shivasurya changed the base branch from graphite-base/655 to main April 12, 2026 14:30
shivasurya and others added 3 commits April 12, 2026 14:31
Add the single publishing path for version update notices:
- release/latest.json: bootstrap source-of-truth manifest (v2.0.2)
- .github/workflows/publish-manifest.yml: schema-validate + R2 upload on push to main
- CODEOWNERS: restrict release/latest.json edits to @shivasurya
- .github/scripts/smoke-update-check.sh: manual end-to-end smoke test
- Dockerfile / Dockerfile.mcp: add ENV PATHFINDER_NO_UPDATE_CHECK=1
- README.md: document the announcement push process

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
…d announcements

Temporary: workflow now fires on pull_request to feat/publish-manifest so the
CDN upload can be verified before merging to main.

release/latest.json bumped to v2.0.3 with two test announcements:
  - test-generic-ann (info, no version_range) — visible to all versions
  - test-targeted-ann (warn, version_range <2.0.0) — visible only to old builds

Test locally after the workflow publishes:
  cd sast-engine
  go build -ldflags="-X .../cmd.Version=0.0.1" -o /tmp/pf-stale .
  go build -ldflags="-X .../cmd.Version=2.0.2" -o /tmp/pf-current .
  /tmp/pf-stale version      # -> upgrade notice + version-targeted ann
  /tmp/pf-current version    # -> upgrade notice + generic ann

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@shivasurya
shivasurya force-pushed the feat/publish-manifest branch from 17a18be to fb7ede6 Compare April 12, 2026 14:31
@shivasurya
shivasurya merged commit c8de7ed into main Apr 12, 2026
6 checks passed
@shivasurya
shivasurya deleted the feat/publish-manifest branch April 12, 2026 14:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docker Docker/Dockerfile related changes documentation Improvements or additions to documentation enhancement New feature or request github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant