fix(release): per-artifact checksums so a release can span hosts
build_artifacts wrote a single dist/SHA256SUMS covering whatever that host happened to build. But a release is assembled from more than one machine — the Linux runner cannot produce the darwin-arm64 toolchain — and forgejo_upload_assets deliberately skips an asset whose name is already attached. So the first host to publish wrote SHA256SUMS, and every artifact added later was silently left uncovered by it. Emit one <artifact>.sha256 per tarball instead. The names are unique, so each host's contribution stands on its own and nothing goes stale. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
f81ca5c3c1
commit
80da7e6275
4 changed files with 41 additions and 6 deletions
9
changes/per-artifact-checksums.md
Normal file
9
changes/per-artifact-checksums.md
Normal file
|
|
@ -0,0 +1,9 @@
|
|||
bump: patch
|
||||
type: fix
|
||||
Release checksums are one `.sha256` file per artifact instead of a single
|
||||
`SHA256SUMS`. A release is assembled from more than one host — a Linux runner
|
||||
cannot build the macOS toolchain — and `x publish` never overwrites an asset that
|
||||
is already attached, so a shared `SHA256SUMS` was written by whichever host
|
||||
published first and then never covered anything added afterwards. Per-artifact
|
||||
names compose across hosts. Verify one with
|
||||
`shasum -a 256 -c ludic-X.Y.Z-src.tar.gz.sha256`.
|
||||
Loading…
Add table
Add a link
Reference in a new issue