Commit Graph
2 Commits
Author SHA1 Message Date
4grayandClaude Opus 5 319a0404aa ci(deps): bump checkout/upload-artifact/download-artifact majors
Supersedes the three individual Dependabot PRs (#1249, #1245, #1247) so the
pinned-SHA contract stays consistent in one commit.

actions/checkout v4 -> v7, actions/upload-artifact v4 -> v7 and
actions/download-artifact v4 -> v8 across every workflow. docker.yml moves
from checkout v6 to v7 with the rest.

publish-snap.yaml keeps full-commit pins, so the three new SHAs are updated
there and in the packaging policy tests that assert them
(snap-workflow-policy.test-helpers.mjs, publish-snap-workflow.test.mjs,
release-snap-assets.test.mjs). Each SHA was checked against the upstream tag
refs: checkout 3d3c42e5 = v7.0.1, upload-artifact 043fb46d = v7.0.1,
download-artifact 3e5f45b2 = v8.0.1. BUILD_ACTION_ALLOWLIST follows the
unpinned bumps in build-and-make.yaml.

download-artifact v8 changes two behaviours that matter for the Snap publish
path, both in our favour: an artifact digest mismatch now fails the run
instead of logging a warning, and the action only unzips responses whose
Content-Type says zip. The publish job downloads a normal upload-artifact
artifact by name, so decompression is unchanged, and it re-verifies the
receipt digest itself regardless.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 02:24:52 +02:00
4gray 8fdac824fd feat(packaging): ship Linux embedded MPV frame-copy runtime (#1200)
* docs: design Linux frame-copy packaging

* docs: plan Linux frame-copy packaging

* feat(packaging): define Linux frame-copy profiles

* fix(packaging): reject inherited profile names

* feat(embedded-mpv): validate staged Linux runtime

* fix(embedded-mpv): require Linux source packages

* fix(embedded-mpv): harden Linux runtime staging

* feat(embedded-mpv): build LGPL Linux runtime

* fix(embedded-mpv): pin Linux runtime inputs

* feat(embedded-mpv): build relocatable Linux helper

* fix(embedded-mpv): require bundled Linux runtime

* fix(embedded-mpv): make Linux runtime portable

* feat(packaging): ship Linux frame-copy artifacts

* fix(embedded-mpv): verify Linux helper linkage

* fix(packaging): enforce Linux frame-copy isolation

* fix(embedded-mpv): pin Linux display data

* docs(embedded-mpv): document Linux frame-copy packaging

* feat(embedded-mpv): probe Linux frame-copy runtime

* test(embedded-mpv): smoke packaged Linux frame-copy

* docs(embedded-mpv): clarify Linux system runtime baseline

* fix(embedded-mpv): harden Linux runtime capability gate

* ci: verify Linux frame-copy packages

* test(embedded-mpv): harden packaged Linux smoke

* test(embedded-mpv): preserve packaged GL mode

* test(packaging): harden Linux package probes

* fix(embedded-mpv): enable private Snap shared memory

* fix(embedded-mpv): sanitize Linux helper environment

* fix(packaging): enforce private Snap memory semantics

* fix(packaging): reject ambiguous Snap memory metadata

* fix(embedded-mpv): prioritize trusted Snap GL

* fix(packaging): reject advanced Snap YAML semantics

* fix(packaging): reject arbitrary Snap YAML aliases

* feat(packaging): ship Linux runtime license notices

* docs(embedded-mpv): document Linux runtime distribution

* fix(packaging): parse Snap trailing comments safely

* fix(release): gate Snap publish on public source release

* fix(packaging): strip VCS metadata from source bundle

* docs(packaging): clarify Linux source release gate

* test(embedded-mpv): smoke missing bundled libmpv

* style(embedded-mpv): format final validation inputs

* fix(e2e): satisfy fixture index signature typing

* fix(ci): declare fontconfig gperf generator

* fix(embedded-mpv): hash runtime cache identities

* fix(packaging): harden Linux frame-copy delivery

* fix(packaging): tighten runtime delivery gates

* fix(ci): decouple Linux runtime matrix

* fix(packaging): harden Linux frame-copy delivery

* fix(packaging): validate Linux frame-copy runtimes

* fix(packaging): scope Snap Electron library checks

* feat(packaging): ship Linux frame-copy runtimes

* fix(packaging): improve Linux runtime smoke diagnostics

* fix(packaging): expose bounded helper probe details

* test(packaging): trace Snap EGL probe failures

* fix(packaging): prefer core22 ABI in Snap helper

* fix(packaging): bound helper probe capture

* fix(packaging): harden Linux frame-copy releases

* fix(packaging): canonicalize libplacebo submodule identity

* fix(packaging): make source archive inspection portable

* fix(packaging): harden Snap release verification
2026-07-18 17:28:22 +02:00