ochenstarik-ui
0f1908cf35
ci: test latest published release before cut
2026-08-18 12:00:23 +07:00
ochenstarik-ui
6285f1e3ac
release: prepare v0.1.0-alpha.20
2026-08-18 11:54:11 +07:00
Ochenstarik
c9cedd0552
ci(windows): separate offline and live release desktop security test steps
2026-08-18 01:11:28 +07:00
ochenstarik-ui
6bd58abe2f
fix: provision cosign for verified installs
2026-08-15 23:29:49 +07:00
Ochenstarik
e1359b1b5f
fix(release): publish keyless signing certificate
...
Close the producer/consumer certificate contract and advance the immutable correction release to alpha.14.
2026-08-13 14:29:16 +07:00
ochenstarik-ui
56a29e2b33
fix(release): normalize Windows checksum asset ( #39 )
...
Validate SHA256SUMS with GNU sha256sum before publishing and advance the immutable correction release to alpha.13.
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-08-13 13:53:16 +07:00
ochenstarik-ui
7b322a69d3
Add release-verification workflow to main
2026-08-11 01:30:09 +07:00
Ochenstarik
004f01a842
[verified] Enforce a single release publisher
2026-08-10 17:43:18 +07:00
Ochenstarik
12dfaf71e8
[verified] Fix monitor snapshot contract and release compatibility
2026-08-10 17:24:07 +07:00
ochenstarik-ui
ad180e9a7e
fix(ci): fix casing in windows artifacts download
2026-08-10 15:42:17 +07:00
ochenstarik-ui
fda9c6dce8
Merge PR #28 : repair CycloneDX release jobs
2026-08-10 14:54:29 +07:00
ochenstarik-ui
a17efa0e5c
fix(ci): update CycloneDX release invocation ( #27 )
...
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-08-10 14:52:29 +07:00
ochenstarik-ui
04eab57ef1
Merge branch 'antigravity/signed-delivery-queue-a'
2026-08-10 14:34:57 +07:00
ochenstarik-ui
dfab4f4a33
feat: Set PROGRAM_VERSION in dotnet publish and msix
2026-08-10 13:34:38 +07:00
ochenstarik-ui
03e3683074
Add SQLite backward compatibility test (Hermes Task 1)
2026-08-10 13:26:21 +07:00
ochenstarik-ui
32ee96c039
fix: keep 5 workflows
2026-08-10 12:11:31 +07:00
ochenstarik-ui
79a5e8c071
feat: Manifest v2 and keyless signing
2026-08-10 12:06:53 +07:00
dependabot[bot]
3f338840c6
Bump actions/checkout from 6.1.0 to 7.0.1 ( #21 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.1.0 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](d23441a48e...3d3c42e5aa )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 00:34:14 +07:00
dependabot[bot]
04a57f047b
Bump actions/upload-artifact from 6.0.0 to 7.0.1 ( #20 )
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 6.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](b7c566a772...043fb46d1a )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 00:34:05 +07:00
dependabot[bot]
bcc79124c1
Bump actions/setup-dotnet from 5.4.0 to 6.0.0 ( #19 )
...
Bumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet ) from 5.4.0 to 6.0.0.
- [Release notes](https://github.com/actions/setup-dotnet/releases )
- [Commits](26b0ec14cb...a98b56852c )
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: 6.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 00:33:48 +07:00
dependabot[bot]
a25f04e24b
Bump softprops/action-gh-release from 2.6.2 to 3.0.2 ( #18 )
...
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release ) from 2.6.2 to 3.0.2.
- [Release notes](https://github.com/softprops/action-gh-release/releases )
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md )
- [Commits](3bb12739c2...3d0d9888cb )
---
updated-dependencies:
- dependency-name: softprops/action-gh-release
dependency-version: 3.0.2
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 00:33:35 +07:00
ochenstarik-ui
80b4797f2a
fix(enrollment): repair node enrollment path ( #24 )
...
* fix(enrollment): repair node enrollment path
Make trimmed Agent configuration fail closed, harden Control URL validation, add device-code and bootstrap delivery, and make alpha.7 Control updates migration- and recovery-safe.
* fix(enrollment): allow agent token cleanup
---------
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-08-09 22:32:53 +07:00
ochenstarik-ui
1b798e7ee8
Merge pull request #15 from ochenstarik-ui/antigravity/reproducible-builds
...
feat: reproducible builds — central package versions and lock files
2026-08-09 19:08:08 +07:00
ochenstarik-ui
ec78537656
feat: reproducible builds — central package versions and lock files
2026-08-09 18:13:34 +07:00
ochenstarik-ui
2745ee55a5
fix: move permissions to job level, fix SBOM attachment
...
- permissions: contents: write moved from step to job level in
linux-release.yml (both 'bootstrap' and 'publish' jobs) and
windows-release.yml ('package' job); step-level permissions key
is not valid in GitHub Actions schema
- Remove redundant SBOM generation from 'bootstrap' job (no .NET
setup there; 'publish' job already covers the full solution)
- Remove '|| true' from SBOM steps — failures are now visible
- Add SBOM JSON to upload-artifact path and release files in
linux-release.yml (publish job) and windows-release.yml
Verified with actionlint 1.7.7 — 0 errors on all 5 workflow files
2026-08-07 12:03:50 +07:00
ochenstarik-ui
4cc873883c
chore: repo hygiene — pin actions, dependabot, SBOM, docs
...
- Pin all 23 GitHub Actions uses to 40-char commit SHA with tag comments:
actions/checkout@v6 -> d23441a48e516b6c34aea4fa41551a30e30af803 (v6.1.0)
actions/setup-dotnet@v5 -> 26b0ec14cb23fa6904739307f278c14f94c95bf1 (v5.4.0)
actions/upload-artifact@v6 -> b7c566a772e6b6bfb58ed0dc250532a479d7789f (v6.0.0)
actions/download-artifact@v8 -> 3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c (v8.0.1)
softprops/action-gh-release@v2 -> 3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 (v2.6.2)
SHAs verified via gh api repos/<owner>/<action>/git/ref/tags/<tag>
- Move contents:write from workflow level to release steps only
- Add dotnet CycloneDX SBOM generation to linux-release and windows-release
- Add .github/dependabot.yml (github-actions + nuget, weekly, limit 5 PRs)
- Add SECURITY.md with private advisory channel, 72h SLA, threat model
- Add CHANGELOG.md from real git history (Keep a Changelog format)
- Add CONTRIBUTING.md with build/test instructions and Linux test note
- Add CODEOWNERS
- Add .github/ISSUE_TEMPLATE/{bug_report,feature_request}.md
- Add .github/PULL_REQUEST_TEMPLATE.md with mandatory verification checklist
2026-08-07 11:40:34 +07:00
ochenstarik-ui
c13501e529
fix(security): pin SSH trust and protect session keys ( #8 )
...
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-07-31 02:36:52 +07:00
ochenstarik-ui
93e0f8ddbd
fix(security): harden enrollment and provisioning helper ( #7 )
...
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-07-31 02:32:47 +07:00
ochenstarik-ui
3851d87534
Add standalone Linux bootstrap foundation ( #5 )
...
* Add standalone Linux bootstrap foundation
* Record bootstrap foundation progress
* Add single-code Node enrollment
* Validate bootstrap release payloads
* Add managed WireGuard mesh bootstrap
* Exercise repeated systemd installation in CI
* Expose systemd smoke failure diagnostics
* Fix bootstrap os-release variable collision
* Create policy helper directory during install
* Capture systemd smoke healthcheck errors
* Report Control listener diagnostics in CI
* Capture stalled Control process diagnostics
* Set service working directories
* Run protected CA healthcheck as root
* Add local Mesh emergency recovery
* Add multi-architecture Linux system matrix
* Add provisioning job control plane
* Stabilize Debian systemd smoke files
* Add node-scoped provisioning job channel
* Add provisioning progress state machine
* Reconcile expired provisioning jobs
* Add provisioning rollback workflow
* Add redacted provisioning event history
* Add restricted provisioning preflight helper
* Persist typed provisioning preflight facts
* Add preflight desired state drift detection
* Define strict base install schema catalog
* Add safe base install plan generation
* Add pre-confirmation base install plans
* Test base install plan API flow
* Authorize confirmed provisioning execution
---------
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-07-30 21:18:39 +07:00
ochenstarik-ui
266900115c
Harden Link lifecycle and Control operations
...
* Harden link lifecycle and control operations
* Complete three-server acceptance lifecycle
---------
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-07-19 12:25:10 +07:00
Ochenstarik
497f197069
Normalize Windows workflow script indentation
2026-07-17 09:49:50 +07:00
Ochenstarik
2c31a10216
Fix clean runner MSIX publishing
2026-07-17 09:49:10 +07:00
Ochenstarik
5c383ec9e2
Add signed Windows MSIX release pipeline
2026-07-17 09:19:09 +07:00
Ochenstarik
3b28ff4462
Mark alpha artifacts as prerelease
2026-07-16 20:46:57 +07:00
Ochenstarik
46a1c393c7
Add persistent mTLS control layer
2026-07-16 20:35:05 +07:00
Ochenstarik
0f6dd31646
Restore ReadyToRun pack in CI
2026-07-16 18:52:48 +07:00
Ochenstarik
4fc5263c8d
Restore explicit Windows runtime in CI
2026-07-16 18:48:00 +07:00
Ochenstarik
4015e3e777
Add Windows build verification
2026-07-16 18:18:03 +07:00