mirror of
https://github.com/J3vb/OwnCord.git
synced 2026-09-03 03:50:00 +03:00
feat(release): fold distribution back into the source repo
The separate J3vb/OwnCord-releases repo existed only because this repo was private: it carried the AGPL source snapshot and provided a publicly-readable update feed. Once this repo is public both roles collapse into its own Releases page, so the mirror is pure redundancy. - Server/config/config.go: github.repo default OwnCord-releases -> OwnCord. This one default drives both the server self-update and the client auto-update chain (tauri.conf.json updater.endpoints is empty, so the client resolves through the server). No test pinned the old value. - release.yml: drop the mirror step and its RELEASES_REPO_TOKEN guard, whose AGPL/private-repo premise no longer holds. The existing Create GitHub Release step is now the sole publish target. All 31 SHA pins verified intact. - Repoint the README badge/download link, both SECURITY.md links, the server-configuration table and sample, the system-overview diagram node and the CHANGELOG note. SECURITY.md's advisory link is the load-bearing one: left alone it would 404 once the mirror repo is deleted. - README: Go 1.25+ -> 1.26+ (badge and prerequisite) to match the toolchain actually required. Deleting the mirror repo loses nothing: both repos' v1.1.0-alpha.2 carry byte-identical asset sets, signatures and update manifest included. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
+4
-4
@@ -7,7 +7,7 @@ There are no backports.
|
||||
|
||||
| Version | Supported |
|
||||
| ------- | --------- |
|
||||
| Latest release (see [OwnCord-releases](https://github.com/J3vb/OwnCord-releases/releases)) | Yes |
|
||||
| Latest release (see [Releases](https://github.com/J3vb/OwnCord/releases)) | Yes |
|
||||
| Anything older | No |
|
||||
|
||||
## Reporting a vulnerability
|
||||
@@ -15,9 +15,9 @@ There are no backports.
|
||||
**Do not open a public issue for security bugs.**
|
||||
|
||||
Report vulnerabilities privately via GitHub Security Advisories on the
|
||||
[OwnCord-releases](https://github.com/J3vb/OwnCord-releases/security/advisories/new)
|
||||
repository ("Report a vulnerability"). This channel works even while the
|
||||
source repository is private.
|
||||
[OwnCord](https://github.com/J3vb/OwnCord/security/advisories/new)
|
||||
repository ("Report a vulnerability"). Advisories stay private until
|
||||
published, so this channel is safe even though the repository is public.
|
||||
|
||||
Please include:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user