Repository navigation
feat(msix): publish Store assets on every release - #1453
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: blocked before merge. Reviewed September 20, 2026, 2:21 PM ET / 18:21 UTC (Revision 3). ClawSweeper reviewWhat this changesPublish validated unsigned Microsoft Store packages, their multi-architecture bundle, and metadata on stable, correction, and prerelease GitHub releases. Merge readiness⛔ Blocked before merge - 1 item remains Still useful: current main limits Store release attachments to alpha tags. No blocking correctness or security defect was found in this focused extension. Priority: P2 Review scores
Verification
How this fits togetherThe release pipeline builds Windows packages, validates their reserved versions and provenance, and stages them for GitHub Releases. These unsigned assets support manual Partner Center submission; they are not end-user installers. flowchart LR
A[Official release tag] --> B[Reserved package version]
B --> C[x64 and ARM64 packages]
C --> D[Multi-architecture bundle]
C --> E[Provenance and hash validation]
D --> E
E --> F[GitHub release attachments]
F --> G[Manual Partner Center submission]
Before merge
Agent review detailsSecurityNone. Review metricsNone. Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Use the existing validated staging path for every official tag while preserving unsigned-submission labeling and the separate Store-distribution rollout gates. Do we have a high-confidence way to reproduce the issue? Not applicable as a bug reproduction: this extends an intentional alpha-only publication policy visible on current main. Is this the best way to solve the issue? Yes. Reusing the existing stager avoids a competing publication path and retains the established package validation contract. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 67f6aa5882db. LabelsLabel justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
History |
|
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. Re-review progress:
|
Summary
Required proof pools
none: this is packaging-only GitHub Actions publication. It does not change installed runtime behavior, UI, architecture-specific payload composition, signing policy, or Store submission behavior, so no capacity-dependent custom Windows pool applies.Validation
Passed on PR head
e1270d3d5b94c95900ac6442eee9064fc633e88a:pwsh -NoLogo -NoProfile -File scripts/test-msix-alpha-release.ps1pwsh -NoLogo -NoProfile -File scripts/test-ci-workflow-contract.ps1dotnet test tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --filter FullyQualifiedName~ReleaseSigningWorkflowTests(4 passed, 0 failed)Host-limited on macOS:
pwsh -NoLogo -NoProfile -File ./build.ps1stops at the repository Windows prerequisite.scripts/validate-docs.ps1treats existing Windows backslash proof-pool entry points as literal macOS paths.Real Behavior Proof
e1270d3d5b94c95900ac6442eee9064fc633e88aSecurity Impact