Skip to content

Performance: make release runtime manifest-first and dependency-free - #43

Merged
masarray merged 1 commit into
mainfrom
perf/release-runtime-static-first
Sep 12, 2026
Merged

masarray merged 1 commit into
mainfrom
perf/release-runtime-static-first

Conversation

@masarray

Copy link
Copy Markdown
Owner

Goal

Finish the static-first landing optimization by making the reviewed same-origin release.json the browser runtime authority instead of calling the GitHub Releases API on each page load.

Changes

  • Replace the 21,994-byte release enrichment runtime with a 7,042-byte manifest-first runtime (~68% smaller raw source).
  • Fetch only same-origin release.json after the loader reaches browser idle time; remove the extra cross-origin GitHub API request.
  • Validate schema version, product version, required platforms, release URL, and every download asset URL before applying them.
  • Constrain all dynamic download targets to the exact https://github.com/masarray/vst-enhancer/releases/... path for the declared version.
  • Preserve the reviewed static HTML as the first-paint/failure fallback.
  • Preserve Windows/macOS direct downloads, checksums, release status/version labels, mobile navigation, and mobile download behavior.
  • Remove runtime-only release panel/schema mutation/hero-button insertion so the browser does less DOM work and the static HTML remains the SEO/source-of-truth surface.

Why

The repository contract already treats reviewed release metadata as authoritative. Loading the public GitHub API during normal page startup duplicated that source of truth, added a cross-origin request, and required significantly more JavaScript. This change reduces startup work, network dependency, privacy surface, and drift risk without changing product/release/legal semantics.

Performance impact

  • site-v6-core.js: 21,994 B -> 7,042 B (~68% smaller raw source).
  • Together with Performance: make ArSonKuPik landing static-first and Core Web Vitals friendly #42, the landing JavaScript moves from roughly 40.4 KB raw (site-v6.js + experience-v4.js + site-v6-core.js) to roughly 17.0 KB raw, about 58% less overall source JavaScript.
  • The larger release runtime remains off the immediate rendering path because site-v6.js loads it during browser idle.

Invariants preserved

  • ArSonKuPik site-name/canonical/hreflang/schema signals are unchanged.
  • Cloudflare Pages remains canonical and GitHub Pages remains the compatibility mirror.
  • Release manifest, release binaries, checksums, signing disclosures, privacy/legal text, and commercial terms are unchanged.
  • No third-party analytics, tracking, fonts, or marketing scripts are introduced.

Validation expected

Existing Pages CI should run release-boundary, SEO, discovery, rendered canonical artifact, and live host verification before merge.

@masarray
masarray merged commit 96d3678 into main Sep 12, 2026
4 checks passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3593fb9d00

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread site/site-v6-core.js
Comment on lines +61 to +65
vst3Url: asset('vst3Url'),
standaloneUrl: asset('standaloneUrl'),
macDmgUrl: asset('macDmgUrl'),
macVst3Url: asset('macVst3Url'),
macStandaloneUrl: asset('macStandaloneUrl'),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Gate all asset links on the pause state

When distributionEnabled is false or distributionStatus is paused, this object still exposes every non-installer asset URL; renderRelease then enables the VST3, standalone, macOS, and checksum links solely based on URL presence. An emergency distribution pause therefore disables only the installer CTAs while leaving direct binary downloads active. Omit these URLs for paused releases or gate every download link on state.type === 'enabled'.

AGENTS.md reference: AGENTS.md:L57-L59

Useful? React with 👍 / 👎.

Comment thread site/site-v6-core.js
Comment on lines +77 to 79
element.href = RELEASE_FALLBACK;
element.setAttribute('aria-disabled', 'true');
element.setAttribute('data-release-pending', 'true');

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep disabled links away from the moving latest release

When the manifest is unavailable, paused, or missing an optional asset, this branch marks the anchor disabled but gives it a live /releases/latest URL. aria-disabled does not prevent anchor activation, and the repository CSS only changes opacity, so users can still navigate through an apparently disabled download control to a moving release that may not match the reviewed manifest. Preserve a non-download target or explicitly suppress activation for disabled links.

AGENTS.md reference: AGENTS.md:L57-L59

Useful? React with 👍 / 👎.

Comment thread site/site-v6-core.js
Comment on lines +138 to +142
const response = await fetch(`${siteBase}/release.json`, {
cache: 'no-store',
credentials: 'same-origin',
signal: controller.signal
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update the release validators with the runtime

Replacing fetchJson and the GitHub API resolver without updating the repository's release regression checks makes the checked-in validation tooling fail on this commit: validate-latest-release.py still requires LATEST_API/parseGitHubRelease, while validate-trial-first-pages.py requires the removed fetchJson call. These checks can no longer validate the new manifest-first contract, so update them alongside this implementation.

AGENTS.md reference: AGENTS.md:L139-L145

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant