Skip to content

fix: publish SHA-256 node-agent package manifests - #7

Merged
chen21019 merged 3 commits into
mainfrom
verification/node-agent-0.13.25-sha256
Sep 8, 2026
Merged

fix: publish SHA-256 node-agent package manifests#7
chen21019 merged 3 commits into
mainfrom
verification/node-agent-0.13.25-sha256

Conversation

@chen21019

Copy link
Copy Markdown

Result

Current hosts reject the Linux compatibility archive because it contains only legacy SHA-1 manifests. This change preserves those manifests, adds SHA-256 manifests, and verifies both chains after extraction in the release workflows.

Focused verification

  • Package contract accepts intact SHA-1/SHA-256 chains.
  • Deliberate binary corruption is rejected.
  • Workflow YAML parses and package scripts pass Bash syntax checks.
  • GitHub CI builds the real Linux/Windows artifacts and runtime image.

Publish SHA-256 manifests inside the Linux compatibility archive while retaining legacy SHA-1 manifests, and verify both chains in release CI.
@chen21019
chen21019 requested a review from a team as a code owner September 8, 2026 01:33
Bind the existing header-only justification to the exact linux-libc-dev package and Critical/High identifiers observed in the current pinned Dapper build.
@chen21019
chen21019 merged commit 5943a98 into main Sep 8, 2026
8 checks passed
@chen21019
chen21019 deleted the verification/node-agent-0.13.25-sha256 branch September 8, 2026 02:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant