Re-cut v3.8.0: Velopack upload hardening (#3521) to main - #3522
Conversation
…ader (#3520) (#3521) vpk upload github --merge dies mid-transfer on the large .nupkg (SslStream write, exhausts its own retries) and is not idempotent: once releases.<channel>.json exists on the release it hard-fails ("merging release files is not supported"), so a re-run cannot recover. vpk download+pack has already assembled the complete channel feed locally; gh transfers it robustly (it moved the 155MB Darling zip in the same job) and --clobber makes a retry idempotent. Per channel, upload the nupkgs -- including the downloaded prior full that the on-disk releases.<channel>.json references, since the index and every package it names must land on the release together -- plus Setup, Portable, and the channel index. Skip the inert assets.<channel>.json / RELEASES-<channel> the Velopack client never fetches. The tag comes from github.event.release.tag_name to match the proven plain-zip upload step. Claude-Session: https://claude.ai/code/session_01RzwoqcD62jKyp6tzsWpZLz Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
|
Reviewed. This is a clean, CI-only port of the already-fixed Velopack upload workflow change (#3521) from Checked the new PowerShell filter logic in both upload steps (nupkg / Non-blocking note: both new steps interpolate |
What
Bring the Velopack upload hardening (#3521) to
mainso it sits on the commit the re-cut v3.8.0 release build checks out.Context
v3.8.0's first release build failed at the Velopack upload step — vpk's Octokit uploader dies mid-transfer on the large
.nupkgand isn't idempotent, so the signed auto-update feed never published and that release was deleted. #3521 replacesvpk upload github --mergewithgh release upload(robust +--clobber-idempotent). This PR carries that fix to main; then thev3.8.0tag moves onto this merge and the release is re-published to re-fire the build with the working uploader.No version change. This is a re-cut of the same 3.8.0, not a new version —
Directory.Build.propsstays 3.8.0. The merge itself only runs build + tests; every sign/velopack/upload step is gated on therelease: publishedevent, so nothing releases on the merge.Field-validation delta
The 3.8.0 Azure/RDS field validation already ran; dev is one commit ahead of that sha, and the delta is exactly this CI-only
build.ymlchange. It touches no collector/runtime code, so it cannot affect cloud collector behavior — delta explicitly accepted.Single commit:
b4a89a3bUpload Velopack channel feeds with gh, not vpk's failing Octokit uploader (Release build: persist SIGNED Velopack artifacts so a failed vpk upload retries without re-signing #3520) (Upload Velopack channel feeds with gh, not vpk's failing Octokit uploader #3521)🤖 Generated with Claude Code
https://claude.ai/code/session_01RzwoqcD62jKyp6tzsWpZLz