Skip to content

Fix compressed marketplace download verification - #13

Merged
DavidBakerEffendi merged 1 commit into
mainfrom
dave/marketplace-http-decoding
Oct 9, 2026
Merged

DavidBakerEffendi merged 1 commit into
mainfrom
dave/marketplace-http-decoding

Conversation

@DavidBakerEffendi

Copy link
Copy Markdown
Contributor

Marketplace now returns the extension package with HTTP gzip encoding. The release smoke saved the encoded response as a VSIX, so unzip failed even though the decoded package matches the qualified artifact.

Key Changes:

  • Ask curl to negotiate and decode HTTP compression for registry metadata, packages, and checksum responses. Keep ZIP integrity and exact SHA-256 checks intact.
  • Verified both published 0.12.0 marketplace downloads against the attested VSIX (770ad7725834c673e84b4844098ffdaa990bdbe5a22771babbb2530512b31b9a); bash syntax and diff checks pass.

Touch Points:

  • scripts/smoke-vscode-marketplaces.sh

@DavidBakerEffendi
DavidBakerEffendi merged commit d1a4eb0 into main Oct 9, 2026
9 checks passed
@DavidBakerEffendi
DavidBakerEffendi deleted the dave/marketplace-http-decoding branch October 9, 2026 07:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant