mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-11 02:46:16 -08:00
CodeQL: the pacman rule built a regex from the interpolated version and escaped only dots. It now compares plain strings, so the exported requiredAssetRules() carries no escaping trap; only the literal compression suffix stays a regex. verify-draft-release: - Never exits 0 once the release is published. The asset report still prints (auditing after the fact is useful), but a pre-publication gate must not report success for a boundary already crossed. - Polls for the tag run before concluding it does not exist: `gh run list` reports what is indexed right now, and a run pushed seconds ago routinely is not. Adds injectable progress/sleep io, so runVerification is async. - The live sleep timer is deliberately not unref'd — a pending promise does not hold the event loop open, and an empty loop exits 0, which would turn a mid-poll exit into a silent false success. - `--repo` is shape-checked so a typo fails with the usage line. Announcements: an internal-only release now returns null instead of throwing a misleading "even a single entry exceeds the limit" error. The CLI explains it on stderr, leaves stdout empty and exits 0 — the shape extract-changelog-section.mjs --public already uses for the same case. Highlight cards: card filenames derive from the note filename, never the screenshot slug. Two highlights may legitimately share one manifest shot, which previously made the second card overwrite the first. Tests: the CLI harness moved to spawnSync — execFileSync discards stderr on success, hiding exactly the messages these paths emit. Adds regressions for each finding above (165 passing). Docs: CLAUDE.md and AGENTS.md release sections (mirrored, verified identical) now document the highlight field, the announcement/card commands, and the draft verifier; .changes/README.md records the internal-only announcement behavior. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>