ci: rebuild release pipeline around OSS manifest protocol

Replace the broken yarn/Node 18 release workflow (wrong package manager,
missing build/ dir, archived actions) with a manifest-based distribution
flow modeled on yaklang/browser-binaries-mirror:

- scripts/package-release.mjs: package the four variants, emit
  release-entry.json and per-artifact sha256 checksums
- scripts/build-manifest.mjs: merge into a bounded public manifest
  (10 versions) with invariant validation
- scripts/publish-oss.mjs: immutable artifacts (forbid-overwrite,
  one-year cache) and mutable manifest (5-minute cache, checksum
  published second), idempotent via head + sha256 comparison
- scripts/verify-public.mjs: post-publish verification from the public
  endpoint (bytes, headers, zip layout)
- release.yml: pnpm + Node 22, full verify:production, OSS publish,
  GitHub Release, separate public verify job, publish concurrency group
- ci.yml: run verify:production on push/PR
- single-source the extension version in package.json (wxt.config reads)
- document the distribution protocol in README
This commit is contained in:
go0p
2026-08-18 14:40:36 +08:00
parent f8827cc4a4
commit 78b0c6befd
10 changed files with 1288 additions and 68 deletions
+25
View File
@@ -328,6 +328,31 @@ Native Host 的构建与注册方式见 [native-host/README.md](./native-host/RE
Chrome Store 构建声明 Chrome 138+。用户需要在扩展详情页开启“允许用户脚本”,页面主世界能力才能正常工作;未开启时扩展会明确报告原因,不会静默降级为直接 Eval。
### 发布与下载
发布由 GitHub Actions 的 **Build and Release** workflow(手动触发)完成:执行 `verify:production` 全量校验后,将四个变体打包为不可变的版本化产物上传到 OSS,再发布机器可读的 manifest,并从公网侧回读验证。CI 在每次 push / PR 时运行同一套构建与审计。
**下载入口**(不要硬编码版本号):
```
https://aliyun-oss.yaklang.com/chrome-extension/manifest.json
```
manifest 的 `latest` 指向最新版本,`versions[0]` 为完整记录,最多保留 10 个历史版本。每个版本按 `variant``chrome-store` / `chrome-enterprise` / `firefox` / `firefox-amo`)匹配 artifact,字段包括 `url``filename``sha256``size``checksum_url`manifest 自身的 SHA-256 在同目录的 `manifest.json.sha256.txt`
推荐的消费流程:
1. 拉取 `manifest.json`(缓存 5 分钟),按需选择版本与变体;
2. 下载 artifact(版本化 URL 永不变更,缓存一年)到临时文件;
3. 校验 `size``sha256`(或对比 `checksum_url` 内容)后,解压并安装;
4. 变体用途见上表“构建差异”。
**发布契约**
- 版本化产物不可变:URL 形如 `…/chrome-extension/<version>/<variant>-<version>.zip`,重复发布同版本时内容一致则跳过、不一致则流水线报错拒绝覆盖;
- `manifest.json` 可变、缓存 5 分钟,先发布 manifest 再发布其校验文件,消费方可用校验文件识别中间态;
- 发布 job 结束前有独立的 verify job 从公网下载全部产物,复核 sha256、缓存头与 zip 内 `manifest.json` 版本。
## 权限与数据边界
扩展声明 `tabs``scripting``cookies``proxy``webRequest``webNavigation``debugger` 等权限,是为了在用户主动选择的目标页面上提供对应安全测试能力。`nativeMessaging` 是可选权限,仅在用户选择 Native 模式时请求。