Updating VMs for SimpleRisk 20260917-001 - #145
Merged
Merged
Conversation
Record the VirtualBox and VMware appliance digests for 20260917-001 in the prod feed. Only the four virtual_machines values change; nothing else in the feed is touched. Landed on a topic branch off updates.simplerisk.com (as #139 did) rather than by promoting updates-test, which would overwrite the GA bundle checksums with testing-channel values and add upgrade hops through RCs that never shipped. Verified: scripts/validate_feed.py prod PASSED (13 checks). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
jsokol
marked this pull request as ready for review
September 30, 2026 20:19
This was referenced Sep 30, 2026
jsokol
added a commit
that referenced
this pull request
Sep 30, 2026
The two feed branches differ on purpose and prod has a single writer, so merging updates-test into updates.simplerisk.com overwrites GA bundle checksums and adds hops for RCs that never shipped (#140, attempted again in #144). Add a check that fails a same-repo PR from updates-test into prod, and a README documenting the topic-branch path for one-off prod changes (#139, #145). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Records the appliance digests for SimpleRisk 20260917-001 in the prod feed. This is the VM-only subset of #144, landed on a topic branch off
updates.simplerisk.comas #139 did.simplerisk-20260917-001-virtualbox.zipe11345d04d767d3a80af39345f81a64csimplerisk-20260917-001-vmware.zip577f957461e2b6b2d175dd7f776bd69bChange
releases.xmlonly: the fourvirtualbox_*/vmware_*values for 20260917-001 go fromfalseto the real digests. No other line changes.Why not merge #144
#144 promotes the whole
updates-testbranch, which would also:bundle_sha256tofalsefor 20260909-001, 20260828-001, 20260820-001 and 20260519-001, erasing GA checksums thatsimplerisk/dockerverifies against (fails closed);20260709-001,20260811-001and20260908-001, testing RCs that never shipped GA. Their bundles 403 on prod, and Restore prod bundle hashes and upgrade path clobbered by the test-branch merge #141 removed two of them for that reason.The test branch was never reconciled with prod after #141, so promotion by merge carries testing truth into the GA feed. I'll close #144 once this merges and reconcile
updates-testseparately.Verification
scripts/validate_feed.py prodagainst this branch: PASSED (13 checks). All five served bundles hash to exactly what the feed claims, including 20260820-001 (3e279416…) and 20260519-001 (7d7fb242…).🤖 Generated with Claude Code