Skip to content

feat: point the official entries at the re-signed detailLinks releases - #1

Merged
deveshk0 merged 1 commit into
mainfrom
feat/detail-links-releases
Sep 15, 2026
Merged

deveshk0 merged 1 commit into
mainfrom
feat/detail-links-releases

Conversation

@deveshk0

Copy link
Copy Markdown
Contributor

Points the official Argo CD and Flux entries at their re-signed releases, which rename rowActions to detailLinks (srelens#537, srelens/srelens#598).

What

Entry Version SHA-256
org.srelens.argocd 0.1.0 → 0.2.0 22e3578a76715a2611b557ab74c3a4002cd55ac1d1ff759668799a61076890db
org.srelens.flux 0.2.0 → 0.3.0 777c3afa8b036ffc2976dc3803f712f366f82549434c8d51219054567b7c2085
  • manifestUrl: each entry now points at the new release's manifest.json.
  • testedHost.revision: 5360059, the srelens commit both release workflows validated against (the head of #598 at the time).
  • catalog.json: regenerated with scripts/catalog.py.

Why now

  • Hosts with the rename (srelens#598) refuse the old releases with EXTENSION_UNKNOWN_FIELD. #598's "live catalog and signatures" check fails until this merges.
  • The publisher key was rotated. Both releases are signed with the new key, which the app repos' signing-public.pem and #598's srelens-apps.pub hold.
  • Hosts without #598 refuse the new manifests. Nothing is live, so there is no transition period.

Verification

  • sha256sum -c SHA256SUMS passes for both downloaded releases, and the entry hashes are taken from those same bytes.
  • Both manifest.json.sig files (64 bytes) verify against the new public key with Node's Ed25519 crypto.verify.
  • Both manifests have detailLinks and no rowActions.
  • python scripts/catalog.py --check and python -m unittest discover -s tests pass.

Once #598 merges, testedHost.revision can move to the merged commit.

Argo CD 0.2.0 and Flux 0.3.0 rename rowActions to detailLinks (srelens/srelens#537) and are signed with the rotated publisher key.
@deveshk0
deveshk0 merged commit f77c1fd into main Sep 15, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant