You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Point the update feed at GitHub Releases
The release pipeline was proven against a loopback feed because no host
existed. Distribution now goes through github.com/williamwue/codexbar-plus,
which is not a static file feed — assets hang off the releases API — so the
updater picks its Velopack source from the feed URL's host. Static feeds
still work, and are what keeps install/upgrade/rollback verifiable locally
without publishing anything.
No access token is compiled in. The repository is public, and a token baked
into a shipped binary would hand the author's GitHub credentials to everyone
who installs the app; unauthenticated release lookups are rate limited to
60/hr per IP, far above what one desktop app needs.
`package-windows.ps1 -Publish` uploads to GitHub Releases, taking the token
from GITHUB_TOKEN or gh's own store so it never lands in shell history.
Uploads are drafts unless -NoDraft is passed, since a draft is invisible to
the updater and cannot reach installed apps by accident.
Also adds the root LICENSE the manifest has always claimed, recording both
this port's copyright and upstream's over the verbatim plugin files, plus a
README, now that the repository is about to be public.
cargo test --workspace: 216 passed, 1 ignored by design, zero warnings.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>