Skip to content

chore(ci): gate beta publish on full check suite - #47

Merged
0libote merged 5 commits into
mainfrom
feature/ci-gated-beta-publish
Sep 24, 2026
Merged

0libote merged 5 commits into
mainfrom
feature/ci-gated-beta-publish

Conversation

@0libote

@0libote 0libote commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Run macOS/Windows beta builders in parallel with CI checks and publish continuous only after security-gate succeeds, with stale-SHA skip and non-destructive asset upload.
  • Expand security-gate to require frontend, frontend-windows, rust-static, and native jobs in addition to review/security gates.
  • Trim native CI cache cost via CARGO_PROFILE_*_DEBUG=0 and CARGO_INCREMENTAL=0.
  • Add weekly dependency-health workflow for Bun outdated/audit plus Rust audit.
  • Bump Astryx to v0.6.3 and refresh frontend deps and lockfile.
  • Lazy-load Settings/Onboarding/Gallery windows with a suspense spinner fallback and replace App error retry with Astryx Button.
  • Honor useReducedMotion() in FlowBar animations and Writing Tools popup motion.
  • Update README provider copy from Gemini-only to Gemini/OpenCode Zen/Go/custom endpoints.
  • Publish signed updater archives and a platform-aware continuous.json for beta builds.
  • Install stable and rolling beta updates inside Kivo, including same-version beta builds with a new commit SHA; keep beta users on their channel when stable is already current.

Testing

  • bun run check passed.
  • bun test:ui passed (24 tests).
  • bun run build passed.
  • bun check:rust && cargo clippy --locked --all-targets -- -D warnings && cargo test --locked passed (121 Rust tests).

Release setup

The Tauri updater signing key and all three GitHub Actions secrets are now configured. A local encrypted key backup is stored outside the repository with owner-only permissions. Existing beta installs without an embedded public key will need one manual upgrade to a signed build; subsequent updates can install in-app. The signed macOS and Windows beta bundles will be validated by the next main-branch publish.

- Run beta builders alongside checks and publish only after security-gate passes
- Add stale-SHA skip, keep release available, and align continuous tag
- Lazy-load Settings/Gallery/Onboarding windows and honor reduced motion
- Bump Astryx and frontend deps, add weekly dependency audit
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Deploying kivo with  Cloudflare Pages  Cloudflare Pages

Latest commit: c700bcd
Status: ✅  Deploy successful!
Preview URL: https://4f7d0e69.kivo-28o.pages.dev
Branch Preview URL: https://feature-ci-gated-beta-publis.kivo-28o.pages.dev

View logs

@sonarqubecloud

Copy link
Copy Markdown

@0libote
0libote merged commit 0585e44 into main Sep 24, 2026
21 of 22 checks passed
@0libote
0libote deleted the feature/ci-gated-beta-publish branch September 24, 2026 09:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant