Skip to content

fix(pad): Softpedia-class Primary_Download_URL to public latest-x64.msi (3.0.96) - #83

Open
kantorcodes wants to merge 5 commits into
mainfrom
fix/pad-download-url-3.0.92
Open

kantorcodes wants to merge 5 commits into
mainfrom
fix/pad-download-url-3.0.92

Conversation

@kantorcodes

@kantorcodes kantorcodes commented Sep 20, 2026 •

Copy link
Copy Markdown
Member

Summary

Softpedia-class unlock: pin Guard PAD Primary_Download_URL to the public Windows MSI URL (path ends in .msi).

  • Primary_Download_URL: https://hol.org/guard/desktop/HOL-Guard-Desktop-latest-x64.msi
  • Version: 3.0.96
  • SHA256 (verified from /tmp/hol-guard-latest.msi): aab520ca456ebff610f1b8d01a3634433865579125782acd62b78d911749f88d
  • File: anonymous 302 → HOL-Guard-Desktop-3.0.96-x64.msi (38125568 bytes)
  • Application_XML_File_URL: https://raw.githubusercontent.com/hashgraph-online/hol-guard-plugin/main/pad/hol-guard.xml (canonical)

Softpedia-class note

Public .msi path unlocks validators that require Download_URL to end in .msi/.exe. Azure-signed Windows desktop. Maker HOL. Apache-2.0.

Guard labeling only (local-first runtime firewall).

Softpedia-class directories reject download URLs without .msi/.exe.
Pin Primary_Download_URL to the versioned hol.org desktop API for
HOL-Guard-Desktop-3.0.92-x64.msi (SHA256 verified). No public
anonymous GitHub releases/download/*.msi URL is available.
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Pin Guard PAD Windows download to MSI 3.0.92

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 5 minutes

Grey Divider

AI Description

• Pins the Windows PAD download API to Guard MSI 3.0.92.
• Synchronizes release date, file size, filename, and verified SHA-256 metadata.
• Replaces the inaccessible GitHub release fallback with the public installation page.
Diagram

graph TD
  A["PAD Metadata"] -->|primary URL| B["Windows API"] -->|version 3.0.92| C["MSI 3.0.92"]
  A -->|secondary URL| D["Install Page"]
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Publish a public static MSI URL
  • ➕ Satisfies validators requiring an .msi or .exe URL suffix
  • ➕ Provides a direct, anonymously accessible installer artifact
  • ➖ Requires additional public artifact hosting or release infrastructure
  • ➖ No suitable anonymous release asset currently exists

Recommendation: Use the version-pinned HOL download API for this release because it is the only currently available anonymous path to the verified MSI. Publishing a stable public .msi URL is the preferable follow-up for Softpedia-class directory compatibility.

Files changed (1) +9 / -9

Bug fix (1) +9 / -9
hol-guard.xmlPin PAD metadata and download links to Guard 3.0.92 +9/-9

Pin PAD metadata and download links to Guard 3.0.92

• Advances the advertised Windows release from 3.0.75 to 3.0.92 and synchronizes its release date, installer size, filename, and SHA-256 details. Pins the primary API URL to version 3.0.92 and replaces the inaccessible GitHub release fallback with the public installation page while documenting validator limitations.

pad/hol-guard.xml

@qodo-free-for-open-source-projects

qodo-free-for-open-source-projects Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0) 🎨 UX issues (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Directories reject the release feed ⊘ Outdated 🐞 Bug ≡ Correctness
Description
The new Program_Change_Info value exceeds the PAD 4.0 field's 300-character maximum. Validators
enforcing that limit reject or truncate the 3.0.92 record when software directories ingest this
updated feed.
Code

pad/hol-guard.xml[49]

+    <Program_Change_Info>Windows MSI desktop 3.0.92: HOL-Guard-Desktop-3.0.92-x64.msi via version-pinned hol.org download API (SHA256 ed8d1bd9bc287d6420776e7883c39e4b232dbf9ac4f3eb6e281be982c1e822f4); PAD Application_XML_File_URL self-hosted; Free Apache-2.0 + optional Guard Cloud. Note: Softpedia-class validators may reject API URLs without .msi/.exe extension; no public anonymous GitHub releases/download/*.msi URL exists (desktop release assets are not anonymously fetchable).</Program_Change_Info>
Evidence
The document declares PAD 4.0 and the newly expanded Program_Change_Info is longer than that
format's 300-character limit.

pad/hol-guard.xml[3-7]
pad/hol-guard.xml[49-49]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The new `Program_Change_Info` exceeds the PAD 4.0 maximum of 300 characters, causing conforming directory validators to reject or truncate the release record.
## Fix Focus Areas
- pad/hol-guard.xml[49-49]
## Recommended Fix
Shorten `Program_Change_Info` to no more than 300 ASCII characters. Retain the release version, installer name, and concise download change; move the checksum and detailed validator explanation outside this constrained field.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Tip of the day
💡 Did you know, you can turn on the rule miner and Qodo learns your standards from review history

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread pad/hol-guard.xml Outdated

Copy link
Copy Markdown
Member Author

r523 probe: Azure Authenticode confirmed; still no public *.msi URL

Evidence: /workspace/aeo-hunt/directory-submit/r523-signed-msi/

Binary (via hol.org API 302)

  • File: HOL-Guard-Desktop-3.0.92-x64.msi
  • Size: 38031360
  • SHA256: ed8d1bd9bc287d6420776e7883c39e4b232dbf9ac4f3eb6e281be982c1e822f4
  • ProductVersion: 3.0.92.0
  • ProductCode: {49381DE1-1594-4154-800A-6832955D84CC}
  • Authenticode: yes — Subject Moonscape Labs Inc, Issuer Microsoft ID Verified CS AOC CA 03 (Azure Trusted Signing / Microsoft Identity Verification), SHA256, timestamped 2026-09-18 04:14:06 UTC

Public *.msi / *.exe URLs

Candidate Anonymous
…/releases/download/desktop-v3.0.92/HOL-Guard-Desktop-3.0.92-x64.msi (path ends .msi) 404 (private hol-guard-desktop)
hol.org/api/guard/desktop/download?platform=windows&version=3.0.92 (PAD Primary) 302 → JWT Azure blob (works; path does not end .msi)
Static hol.org/.../*.msi / *.exe 404
.exe asset on release none

PAD action

No Primary_Download_URL change — GitHub *.msi path is not anonymously fetchable, so it is not better for Softpedia-class. Keep version-pinned API URL from this PR.

Softpedia-class

Retry Softpedia / Softpile / ham-software after eng publishes a stable public URL whose path ends in .msi (CDN or public release assets). No directory submits this turn. Do not touch Softonic/conda/SourceForge.

Install-page copy that says publisher signing is not on this build is stale vs the signed MSI.

@kantorcodes kantorcodes changed the title fix(pad): pin Guard Windows Download_URL to MSI 3.0.92 fix(pad): Softpedia-class Primary_Download_URL to public latest-x64.msi (3.0.96) Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant