Skip to content

fix(release): compile the SLSA generator from source - #55

Merged
emir-hasanbegovic merged 1 commit into
mainfrom
fix/slsa-compile-generator
Aug 23, 2026
Merged

fix(release): compile the SLSA generator from source#55
emir-hasanbegovic merged 1 commit into
mainfrom
fix/slsa-compile-generator

Conversation

@emir-hasanbegovic

Copy link
Copy Markdown
Contributor

dish-linux's first tag surfaced this in the shared provenance shape: a SHA-pinned call to the generic generator cannot resolve which prebuilt builder release to download, so the binary never arrives and the generator dies at exit 127. compile-generator: true builds it from source, the way satellite's shipped 1.0.0 already did. Same one-line fix as dish-linux #41.

Same 127 dish-linux hit on its first tag: a SHA-pinned generator call
cannot resolve the prebuilt builder release.

(cherry picked from commit c46a2ab)
@emir-hasanbegovic
emir-hasanbegovic enabled auto-merge (squash) August 23, 2026 15:52
@emir-hasanbegovic
emir-hasanbegovic merged commit 288add5 into main Aug 23, 2026
8 checks passed
@emir-hasanbegovic
emir-hasanbegovic deleted the fix/slsa-compile-generator branch August 23, 2026 16:21
@emir-hasanbegovic emir-hasanbegovic mentioned this pull request Aug 24, 2026
emir-hasanbegovic added a commit that referenced this pull request Aug 24, 2026
Version bump for the pending work on main:

- **Added**: configurable keep-awake (Power settings)
- **Fixed**: zero-width overflow menus, cross-transport twin dedup,
pinned Configure-binding action bar
- **Changed**: app-mark iconography; release pipeline moved to the
shared harden workflow with advisory Authenticode signing (#54) and a
from-source SLSA generator (#55)

CHANGELOG heading dated, and all three version mirrors
(`CMakeLists.txt`, `packaging/dish.rc`, `vcpkg.json`) move together so
`version-consistency.yml` and the tag-build asserts pass. Tagging
`1.1.0` after merge publishes it.

No changes to the stable asset names (`dish-setup.exe`,
`dish-windows.zip`, `latest.json`) — this repo is already the model the
other product repos just adopted.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant