Skip to content

Updating VMs for SimpleRisk 20260917-001 - #145

Merged
jsokol merged 1 commit into
updates.simplerisk.comfrom
vm-update-20260917
Sep 30, 2026
Merged

jsokol merged 1 commit into
updates.simplerisk.comfrom
vm-update-20260917

Conversation

@jsokol

@jsokol jsokol commented Sep 30, 2026

Copy link
Copy Markdown
Member

Records the appliance digests for SimpleRisk 20260917-001 in the prod feed. This is the VM-only subset of #144, landed on a topic branch off updates.simplerisk.com as #139 did.

Artifact Size MD5
simplerisk-20260917-001-virtualbox.zip 927,621,480 e11345d04d767d3a80af39345f81a64c
simplerisk-20260917-001-vmware.zip 1,139,475,453 577f957461e2b6b2d175dd7f776bd69b

Change

releases.xml only: the four virtualbox_* / vmware_* values for 20260917-001 go from false to the real digests. No other line changes.

Why not merge #144

#144 promotes the whole updates-test branch, which would also:

  • set bundle_sha256 to false for 20260909-001, 20260828-001, 20260820-001 and 20260519-001, erasing GA checksums that simplerisk/docker verifies against (fails closed);
  • add upgrade hops for 20260709-001, 20260811-001 and 20260908-001, testing RCs that never shipped GA. Their bundles 403 on prod, and Restore prod bundle hashes and upgrade path clobbered by the test-branch merge #141 removed two of them for that reason.

The test branch was never reconciled with prod after #141, so promotion by merge carries testing truth into the GA feed. I'll close #144 once this merges and reconcile updates-test separately.

Verification

scripts/validate_feed.py prod against this branch: PASSED (13 checks). All five served bundles hash to exactly what the feed claims, including 20260820-001 (3e279416…) and 20260519-001 (7d7fb242…).

🤖 Generated with Claude Code

Record the VirtualBox and VMware appliance digests for 20260917-001 in the
prod feed. Only the four virtual_machines values change; nothing else in the
feed is touched.

Landed on a topic branch off updates.simplerisk.com (as #139 did) rather than
by promoting updates-test, which would overwrite the GA bundle checksums with
testing-channel values and add upgrade hops through RCs that never shipped.

Verified: scripts/validate_feed.py prod PASSED (13 checks).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@jsokol
jsokol marked this pull request as ready for review September 30, 2026 20:19
@jsokol
jsokol merged commit 4a95d49 into updates.simplerisk.com Sep 30, 2026
1 check passed
@jsokol
jsokol deleted the vm-update-20260917 branch September 30, 2026 20:19
jsokol added a commit that referenced this pull request Sep 30, 2026
The two feed branches differ on purpose and prod has a single writer, so merging
updates-test into updates.simplerisk.com overwrites GA bundle checksums and adds
hops for RCs that never shipped (#140, attempted again in #144). Add a check that
fails a same-repo PR from updates-test into prod, and a README documenting the
topic-branch path for one-off prod changes (#139, #145).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant