Skip to content

build: enforce minimal release archives - #34

Merged
zongqichen merged 1 commit into
mainfrom
build/minimal-release-archives-33
Sep 24, 2026
Merged

zongqichen merged 1 commit into
mainfrom
build/minimal-release-archives-33

Conversation

@zongqichen

Copy link
Copy Markdown
Owner

Summary

  • keep an explicit five-file allowlist for every binary archive
  • normalize archive ownership, permissions, and timestamps
  • verify all four platform archives and their SHA-256 entries
  • run the same package audit in pull-request CI and before release publication
  • document the difference between minimal binary archives and GitHub-generated source archives

Closes #33

Validation

  • make check
  • make release-check
  • make security
  • GoReleaser v2.18.2 snapshot build
  • make package-check
  • repeated snapshot builds produced identical archive SHA-256 values
  • negative test rejected an archive containing an unexpected file
  • released v0.3.1 assets audited separately; all published checksums are valid

Checklist

  • Archive contents are limited to cfs, README.md, LICENSE, NOTICE, and CHANGELOG.md.
  • No credentials, tokens, CF configuration, or sensitive logs are included.
  • The change is focused and does not publish a release.

@zongqichen
zongqichen merged commit a5031eb into main Sep 24, 2026
10 checks passed
@zongqichen
zongqichen deleted the build/minimal-release-archives-33 branch September 24, 2026 13:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

build: enforce minimal release archive contents

1 participant