Skip to content

Re-cut v3.8.0: Velopack upload hardening (#3521) to main - #3522

Merged
erikdarlingdata merged 1 commit into
mainfrom
dev
Sep 18, 2026
Merged

erikdarlingdata merged 1 commit into
mainfrom
dev

Conversation

@erikdarlingdata

Copy link
Copy Markdown
Owner

What

Bring the Velopack upload hardening (#3521) to main so it sits on the commit the re-cut v3.8.0 release build checks out.

Context

v3.8.0's first release build failed at the Velopack upload step — vpk's Octokit uploader dies mid-transfer on the large .nupkg and isn't idempotent, so the signed auto-update feed never published and that release was deleted. #3521 replaces vpk upload github --merge with gh release upload (robust + --clobber-idempotent). This PR carries that fix to main; then the v3.8.0 tag moves onto this merge and the release is re-published to re-fire the build with the working uploader.

No version change. This is a re-cut of the same 3.8.0, not a new version — Directory.Build.props stays 3.8.0. The merge itself only runs build + tests; every sign/velopack/upload step is gated on the release: published event, so nothing releases on the merge.

Field-validation delta

The 3.8.0 Azure/RDS field validation already ran; dev is one commit ahead of that sha, and the delta is exactly this CI-only build.yml change. It touches no collector/runtime code, so it cannot affect cloud collector behavior — delta explicitly accepted.

Single commit:

🤖 Generated with Claude Code

https://claude.ai/code/session_01RzwoqcD62jKyp6tzsWpZLz

…ader (#3520) (#3521)

vpk upload github --merge dies mid-transfer on the large .nupkg (SslStream
write, exhausts its own retries) and is not idempotent: once
releases.<channel>.json exists on the release it hard-fails ("merging release
files is not supported"), so a re-run cannot recover. vpk download+pack has
already assembled the complete channel feed locally; gh transfers it robustly
(it moved the 155MB Darling zip in the same job) and --clobber makes a retry
idempotent.

Per channel, upload the nupkgs -- including the downloaded prior full that the
on-disk releases.<channel>.json references, since the index and every package
it names must land on the release together -- plus Setup, Portable, and the
channel index. Skip the inert assets.<channel>.json / RELEASES-<channel> the
Velopack client never fetches. The tag comes from github.event.release.tag_name
to match the proven plain-zip upload step.


Claude-Session: https://claude.ai/code/session_01RzwoqcD62jKyp6tzsWpZLz

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
@claude

claude Bot commented Sep 17, 2026

Copy link
Copy Markdown

Reviewed. This is a clean, CI-only port of the already-fixed Velopack upload workflow change (#3521) from dev to main ahead of the v3.8.0 re-cut. No T-SQL or collector code is touched, so Lite/Darling parity isn't at risk here — and both Velopack channels (Lite, Darling Viewer) get identical treatment in this diff.

Checked the new PowerShell filter logic in both upload steps (nupkg / -Setup.exe / -Portable.zip / releases.<channel>.json) — it correctly selects the artifacts described in the comments and correctly excludes the inert assets.<channel>.json/RELEASES-<channel> files.

Non-blocking note: both new steps interpolate ${{ github.event.release.tag_name }} directly into the run: script (a value controlled by whoever creates the GitHub release). This is a known GitHub Actions script-injection footgun in general, but it's not new risk from this PR — the same pattern already exists at lines 743 and 1105 of this file, and release creation is already gated to users with write access. Just flagging for awareness in case a future cleanup wants to route it through an env: var instead.

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — reviewed the CI-only Velopack upload fix port to main; correct filter logic, both channels handled identically, no Lite/Darling parity or T-SQL surface touched.

@erikdarlingdata
erikdarlingdata merged commit b342229 into main Sep 18, 2026
12 of 13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant