Peter Steinberger
295d63c331
ci: record package proof in release evidence
2026-04-27 22:00:03 +01:00
Vincent Koc
bd51f82efa
fix(security): harden CodeQL secret ref validation
...
Remediate current-profile CodeQL findings for file SecretRef id validation and release workflow job permissions. Includes changelog credit. Thanks @vincentkoc.
2026-04-27 13:53:27 -07:00
Vincent Koc
36b5e34fc0
fix(ci): add macOS CodeQL security shard
...
Add a manual macOS CodeQL security shard scoped to app sources. Verified with profile=macos-security on Blacksmith in 16m55s.
2026-04-27 13:40:34 -07:00
Peter Steinberger
cdf88bcad4
test: harden release qa live gates
2026-04-27 21:16:48 +01:00
Vincent Koc
74eccd42d8
fix(ci): add android CodeQL security shard
...
Add a manual Android CodeQL security shard scoped to app production sources. Verified with profile=android-security on Blacksmith in 4m22s.
2026-04-27 12:32:55 -07:00
Peter Steinberger
54e13d4910
ci: split release validation slow shards
2026-04-27 20:30:17 +01:00
dependabot[bot]
48f433479d
chore(deps): bump github/codeql-action
...
Bump github/codeql-action from b25d0ebf40e5b63ee81e1bd6e5d2a12b7c2aeb61 to 95e58e9a2cdfd71adc6e0353d5c52f41a045d225.
2026-04-27 12:01:27 -07:00
Vincent Koc
282af9c50a
fix(ci): run CodeQL on small Blacksmith runners ( #72988 )
2026-04-27 11:56:48 -07:00
Vincent Koc
e864fd39cc
fix(ci): narrow CodeQL critical scan ( #72982 )
2026-04-27 11:42:42 -07:00
Peter Steinberger
c41126dbbb
ci: capture dispatched full validation runs
2026-04-27 15:51:03 +01:00
Peter Steinberger
2243a68a1d
ci: shard release live validation
2026-04-27 14:24:10 +01:00
Peter Steinberger
9ca4049861
ci: match package Telegram harness to release ref
2026-04-27 14:06:05 +01:00
Peter Steinberger
1b1916053f
ci: inline Docker release planning for old refs
2026-04-27 14:03:17 +01:00
Peter Steinberger
fd4b59a906
ci: keep release checks compatible with stable refs
2026-04-27 13:59:49 +01:00
Peter Steinberger
0931a1f11e
ci: fix release validation dispatch and protocol drift
2026-04-27 13:32:03 +01:00
Peter Steinberger
98b441edb1
ci: split release docker integration chunks
2026-04-27 13:24:30 +01:00
Peter Steinberger
cff1bdb491
ci: trim duplicate release package lanes
2026-04-27 13:15:10 +01:00
Peter Steinberger
e9986aa787
fix(ci): make full validation rerun-aware
2026-04-27 13:00:09 +01:00
Peter Steinberger
c4fe72b8d6
ci: pin full release validation child refs
2026-04-27 11:16:16 +01:00
Peter Steinberger
5757d1bb69
ci: harden live release validation lane
2026-04-27 10:59:25 +01:00
Peter Steinberger
1b581b4c71
fix(ci): stabilize live release validation
2026-04-27 10:56:35 +01:00
Peter Steinberger
57092a1794
ci: harden cross-os release harness on Windows
2026-04-27 10:03:38 +01:00
Peter Steinberger
ca44ab65e6
ci(release): allow live E2E actions reads
2026-04-27 07:26:33 +01:00
Peter Steinberger
93ac2cefaa
ci(docker): resolve short refs before checkout
2026-04-27 07:18:57 +01:00
Peter Steinberger
a3fcb8db79
ci(docker): split bundled release lanes
2026-04-27 07:17:14 +01:00
Peter Steinberger
ac5a1d1622
ci: forward package acceptance live secrets
2026-04-27 07:00:11 +01:00
Peter Steinberger
45bdfb5f72
ci(docker): keep release path at three chunks
2026-04-27 06:39:46 +01:00
Peter Steinberger
5e9a96fafb
ci(docker): reuse cached e2e images for reruns
2026-04-27 06:29:09 +01:00
Peter Steinberger
679e476183
ci: always shard full Matrix QA
2026-04-27 06:28:35 +01:00
Peter Steinberger
32b1f0ce74
ci: narrow package acceptance to artifact lanes
2026-04-27 06:17:05 +01:00
Peter Steinberger
86da88c120
ci: request release evidence after full validation
2026-04-27 06:01:06 +01:00
Peter Steinberger
748daa4857
ci: make package acceptance legacy-safe
2026-04-27 05:46:06 +01:00
Peter Steinberger
6987132aed
ci: add Matrix QA profiles
2026-04-27 05:43:14 +01:00
Peter Steinberger
02455c0c52
ci: include telegram in release package acceptance
2026-04-27 05:14:19 +01:00
Peter Steinberger
09107e0b7f
ci: let telegram e2e use package artifacts
2026-04-27 05:09:16 +01:00
Vincent Koc
a33a2c97a3
ci(testbox): save build artifact cache before wait
2026-04-26 21:07:02 -07:00
Vincent Koc
9626ef274a
ci(testbox): add build artifact cache warmup
2026-04-26 20:58:14 -07:00
Peter Steinberger
5f9506f7fd
ci: avoid inherited package acceptance secrets
2026-04-27 04:44:29 +01:00
Peter Steinberger
02d266c6c4
ci: split package acceptance refs
2026-04-27 04:39:19 +01:00
Peter Steinberger
6a05b9eec5
ci: fix package acceptance permissions
2026-04-27 04:27:45 +01:00
Peter Steinberger
76de167ca1
ci: add package acceptance workflow
2026-04-27 04:25:31 +01:00
Peter Steinberger
6c1cffa7f8
ci: fix targeted live model provider run
2026-04-27 04:08:16 +01:00
Peter Steinberger
e0141946b2
ci: allow targeted live model providers
2026-04-27 04:04:38 +01:00
Peter Steinberger
d8c1140235
ci: fix full release validation gh repo context
2026-04-27 02:36:20 +01:00
Shadow
3f59cd0a09
Adjust message for stale workflow
2026-04-26 20:31:00 -05:00
Peter Steinberger
658240de74
ci: add full release validation workflow
2026-04-27 02:02:34 +01:00
Peter Steinberger
b109c1f99c
ci: limit node 22 compatibility to manual ci
2026-04-27 01:39:32 +01:00
Peter Steinberger
92c1924d27
ci: remove duplicate extension fast lane
2026-04-27 01:36:45 +01:00
Peter Steinberger
11e17793e1
ci: include node22 compat in manual full ci
2026-04-27 01:27:27 +01:00
Peter Steinberger
fa0729e145
test: auto-discover vitest suites
2026-04-27 00:55:06 +01:00