Skip to content

fix: make release checksums verify beside jars - #13

Merged
remdui merged 1 commit into
mainfrom
fix/release-checksum-paths
Sep 25, 2026
Merged

remdui merged 1 commit into
mainfrom
fix/release-checksum-paths

Conversation

@remdui

@remdui remdui commented Sep 25, 2026

Copy link
Copy Markdown
Member

Release checksum files currently name target/<jar>, so sha256sum -c fails when users download the JAR and checksum into the same directory. Generate the checksum from inside target/ and check it before publishing; future release assets will verify side by side.

Validation: parsed the workflow, ran its checksum step against the published JAR, then verified the JAR and resulting checksum in a separate flat download directory. The version gate reports publish: False for this workflow-only change. Existing release assets remain unchanged.

@remdui
remdui merged commit e3011ac into main Sep 25, 2026
8 checks passed
@remdui
remdui deleted the fix/release-checksum-paths branch September 25, 2026 17:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant