ci: rebuild release pipeline around OSS manifest protocol

Replace the broken yarn/Node 18 release workflow (wrong package manager,
missing build/ dir, archived actions) with a manifest-based distribution
flow modeled on yaklang/browser-binaries-mirror:

- scripts/package-release.mjs: package the four variants, emit
  release-entry.json and per-artifact sha256 checksums
- scripts/build-manifest.mjs: merge into a bounded public manifest
  (10 versions) with invariant validation
- scripts/publish-oss.mjs: immutable artifacts (forbid-overwrite,
  one-year cache) and mutable manifest (5-minute cache, checksum
  published second), idempotent via head + sha256 comparison
- scripts/verify-public.mjs: post-publish verification from the public
  endpoint (bytes, headers, zip layout)
- release.yml: pnpm + Node 22, full verify:production, OSS publish,
  GitHub Release, separate public verify job, publish concurrency group
- ci.yml: run verify:production on push/PR
- single-source the extension version in package.json (wxt.config reads)
- document the distribution protocol in README
This commit is contained in:
go0p
2026-08-18 14:40:36 +08:00
parent f8827cc4a4
commit 78b0c6befd
10 changed files with 1288 additions and 68 deletions
+7 -1
View File
@@ -1,5 +1,11 @@
import { readFileSync } from 'node:fs';
import { resolve } from 'node:path';
import { defineConfig } from 'wxt';
// package.json is the single source of truth for the version; release
// packaging asserts the built manifest matches it.
const { version } = JSON.parse(readFileSync(resolve(process.cwd(), 'package.json'), 'utf8'));
// See https://wxt.dev/api/config.html
export default defineConfig({
srcDir: 'src',
@@ -12,7 +18,7 @@ export default defineConfig({
manifest: ({ mode, browser }) => ({
name: 'Yakit Browser Agent',
description: 'Yakit 浏览器安全测试工具与 AI 上下文桥接',
version: '0.2.0',
version,
action: {
default_title: 'Yakit Browser Agent',
},