docs(release): require verified Windows asset links

This commit is contained in:
Peter Steinberger
2026-06-03 22:42:53 +01:00
parent bf368e7609
commit ed283490b5
2 changed files with 9 additions and 6 deletions
@@ -150,10 +150,11 @@ Use this skill for release and publish-time workflow. Load `$release-private` if
`openclaw/openclaw` GitHub Release. Use the public `Windows Node Release`
workflow after the matching `openclaw/openclaw-windows-node` release exists;
it verifies Authenticode signatures on Windows before uploading assets.
- Website Windows Hub download links should target the canonical
`openclaw/openclaw/releases/latest/download/...` assets so the installable
signed Windows artifact is visible from both the GitHub release page and
openclaw.ai.
- Website Windows Hub download links should target exact canonical
`openclaw/openclaw/releases/download/vYYYY.M.D/...` assets for the current
stable release, or `releases/latest/download/...` only after verifying the
redirect resolves to that same tag, so the installable signed Windows artifact
is visible from both the GitHub release page and openclaw.ai.
## Build changelog-backed release notes
+4 -2
View File
@@ -243,8 +243,10 @@ vYYYY.M.D-beta.N` from the matching `release/YYYY.M.D` branch. The helper runs
signed Windows Hub installers from the companion repo, verifies their
Authenticode signatures on a Windows runner, writes a SHA-256 manifest, and
uploads the installers plus manifest onto the canonical OpenClaw GitHub
release. Website download links should target the OpenClaw release assets, not
only the companion repo release page.
release. Website download links should target exact OpenClaw release asset
URLs for the current stable release, or `releases/latest/download/...` only
after verifying GitHub's latest redirect points at that same release; do not
link only to the companion repo release page.
- Release checks now run in a separate manual workflow:
`OpenClaw Release Checks`
- `OpenClaw Release Checks` also runs the QA Lab mock parity lane plus the fast