Skip to content

ci: publish releases and pages, add weekly health check - #4

Merged
datlechin merged 1 commit into
mainfrom
ci/publish-and-health
Oct 10, 2026
Merged

datlechin merged 1 commit into
mainfrom
ci/publish-and-health

Conversation

@datlechin

Copy link
Copy Markdown
Member
  • scripts/build.py: validates the registry, then writes a flat directory: index.json (checked against schema/index.schema.json), each icon at 512 and 128 and each screenshot as <slug>-<name>-<sha12>.png, and SHA256SUMS over index.json and every PNG. No tarball. Images are re-encoded: RGB profiles converted to sRGB, metadata dropped, alpha removed when opaque. generatedAt is the commit time, so two builds are byte-identical.
  • publish.yml, workflow_dispatch only, main only:
    • build (contents: read) builds and compares contentSha256 with the latest release. Same data means no release.
    • release (contents: write) runs gh release create with every file as its own asset. gh uploads to a draft and then publishes, so with immutable releases on the tag and assets lock and GitHub attests the release. No attest-build-provenance.
    • pages (pages: write, id-token: write, environment github-pages) deploys v1/ (the same files as the latest release) and schema/v1/, so each schema $id resolves.
  • Tag: v1.<YYYYMMDD>.<run number> (UTC), the pattern index.schema.json already allows. Notes: Registry data built from <sha>.
  • scripts/health.py: for each active entry, checks the source by numeric repo ID (gone, moved, archived, private, path, license, no push in 18 months), the install target and every link (reported only after failing twice), grace ending or ended, lastVerifiedAt older than a year, and homepage domain age through RDAP. Also checks built-in client drift against IntegrationClient.swift and runs the private-file scan. Reuses the registry.py and validate.py checks. Never writes to an entry.
  • health.yml: Mondays 06:23 UTC and on dispatch. check (contents: read) runs the script. issue (issues: write, no checkout) then updates the one open health issue opened by github-actions, creates it if missing, or closes it when nothing is found. Findings go in code spans, so a third-party path cannot mention anyone.
  • 24 tests in test_build.py and test_health.py. validate.yml now runs every test file.
  • README layout row.

Owner steps:

  1. DNS: CNAME integrations to tableproapp.github.io, DNS only.
  2. Once the certificate is issued: gh api -X PUT repos/TableProApp/integrations/pages -F https_enforced=true.
  3. Run Publish: gh workflow run publish.yml --repo TableProApp/integrations --ref main.
  4. Check it: gh release verify <tag> --repo TableProApp/integrations and gh release verify-asset <tag> <file> --repo TableProApp/integrations for each asset, then open https://integrations.tablepro.app/v1/index.json.
  5. Once HTTPS is on, add a push trigger on main (data paths) or a schedule to publish.yml if you want automatic releases.
  6. Optional: run Health with gh workflow run health.yml --repo TableProApp/integrations. With no entries yet, it reports the four Connect a Client cases as missing.

@datlechin
datlechin requested a review from a team as a code owner October 10, 2026 09:52
@github-actions github-actions Bot added the tooling Changes scripts, schemas or workflows label Oct 10, 2026
@datlechin
datlechin merged commit 83b5a7d into main Oct 10, 2026
5 checks passed
@datlechin
datlechin deleted the ci/publish-and-health branch October 10, 2026 10:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tooling Changes scripts, schemas or workflows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant