microsoft / BotFramework-WebChat

A highly-customizable web-based client for Azure Bot Services.
https://www.botframework.com/
MIT License
1.58k stars 1.53k forks source link

4.18.0 Release checklist #5239

Open compulim opened 1 month ago

compulim commented 1 month ago

Checklist

Build

  1. [x] ~Bump MockBot to latest Bot Framework SDK release~ (not needed for patch release)
  2. [x] ~Bump botframework-directlinejs to 0.15.5 in PR #XXX~
  3. [x] Update README.md with feature notes
  4. [x] Bump to 4.18.0
    • [x] Update CHANGELOG.md to mark specific changes in 4.18.0
    • [x] Run npm version --no-git-tag-version 4.18.0
    • [x] Merged into main, the PR number is #5240
    • Commit is 20f73e0
    • Do not merge any other unrelated changes after this PR. Any other PR merged, will need to be re-tested
  5. [x] Run official build pipeline manually, set "Generate_Prod_Version_Number" to true
    • (This will not push to NPM or CDN)
    • Pipeline name is BotFramework-WebChat-Official
    • The build number is 391743 and commit is 20f73e0
  6. [x] Run or wait for BotFramework-WebChat-Release-Testing pipeline to complete
  7. [x] Wait for WebChat-release-testing pipeline to complete
    • The release ID is 531
  8. [x] Check component governance and make sure there are no high/critical related to code under /packages/ folder
    • There could be some for projects under /samples/ folder, as they are pointing to previous version of Web Chat
  9. [x] Add manual tests to WebChat-release-testing as needed

Test

The test should run against the build artifacts from Azure Pipelines.

  1. [x] Manual testing on major browsers using webchat-release-testing
    • [x] Before starting testing, update all the browser version to latest
    • [x] Chrome 126.0.6478.127
    • [x] Edge 128.0.2703.0
    • [x] Firefox 127.0.2
    • [x] ~IE11 (Windows 11 22H2 23531.1001)~
    • [x] macOS Safari 17.5 (18618.2.12.111.5)
    • [x] iOS Safari 17.5.1 (21F90)
    • [x] iPadOS Safari 17.4.1 (21E236)
    • [x] Android Chrome 126.0.6478.122
  2. [x] ~Test specific fixes related to 4.18.0 and previous releases~

Note: when the bot is sending a long message (say, markdown) via Direct Line Speech, the service may kill the connection. This is an issue on Direct Line Speech service and is not an issue about Web Chat.

Release

  1. [x] Make sure you are on main ~or qfe~ branch, run git status to check
  2. [x] git pull -ff
  3. [x] Verify /package.json, /package-lock.json, and CHANGELOG.md has a version of 4.18.0
  4. [x] git log
    • Verify the latest commit is 20f73e0
  5. [x] git tag v4.18.0
  6. [x] git push -u upstream v4.18.0
    • You do not need to kick off a build again, use the previous build
  7. [x] Create a new GitHub release
    • [x] Copy entries from CHANGELOG.md
    • [x] Subresource Integrity can be generated by
      • From local: for file in $(ls *.js); do echo $file $(cat $file | openssl dgst -sha384 -binary | openssl base64 -A); done
      • From CDN: curl -H 'Accept-Encoding: gzip' https://cdn.botframework.com/botframework-webchat/4.18.0/webchat.js | gunzip - | openssl dgst -sha384 -binary | openssl base64 -A
    • [x] Attach assets including 3 JS files, stats.json and 6 tarballs
      • You can copy the artifacts from the BotFramework-WebChat-Official build
      • Tarballs download from npmjs
        curl -LO https://registry.npmjs.org/botframework-directlinespeech-sdk/-/botframework-directlinespeech-sdk-4.18.0.tgz
        curl -LO https://registry.npmjs.org/botframework-webchat/-/botframework-webchat-4.18.0.tgz
        curl -LO https://registry.npmjs.org/botframework-webchat-core/-/botframework-webchat-core-4.18.0.tgz
        curl -LO https://registry.npmjs.org/botframework-webchat-api/-/botframework-webchat-api-4.18.0.tgz
        curl -LO https://registry.npmjs.org/botframework-webchat-component/-/botframework-webchat-component-4.18.0.tgz
  8. [x] Kick off release to NPM
  9. [ ] Kick off release to CDN (cutoff at 10 PM PST, Sun-Wed only)
    1. [ ] Prepare the message for approval
    2. [ ] Send message to approvers
    3. [ ] Retain the build indefinitely

Post-release verification - complete within 30 minutes after release to NPM

Notification to interested parties


Post-release checklist

These are chores that we should do before starting the cycle to reduce ripple effects if we do it in mid-cycle.

Tips:

Applies to all releases

This list should be copied to versions in the future.

Applies to major/minor releases

Bump all dependencies to latest version

In PR #5174, we are bumping most dependencies to latest version.

After bumping, if a package broke compatibility, we should investigate:

  • Upgrade our code to use the latest package if possible, otherwise;
  • Add it to package.json/pinDependencies to prevent bumping deliberately
    • Pinning dependencies incur unpredictable technical debts, say, security issue found in the unsupported version, causing us slow to react
    • Every time we bump, we need to go through the whole pinDependencies list

Bump Docker image

The Docker image can be found at root docker-compose.yml and Dockerfile*.

dinowang commented 1 month ago

All 4.18 CDN scripts is not available.

<script
   crossorigin="anonymous"
   integrity="sha384-YCF4860lf811lnrrIBL4pfZ+UqiNit+8lXEhSY3R+dSc+C1rg6UnEQR5avdOTbj0"
   src="https://cdn.botframework.com/botframework-webchat/4.18.0/webchat.js"
></script>

<script
   crossorigin="anonymous"
   integrity="sha384-RuyQM7i2h9QDvJTm5quFymi0qfuWyIZocRdsgUaPIhlZnAM/Qz1/YnUxH55Dt9Rd"
   src="https://cdn.botframework.com/botframework-webchat/4.18.0/webchat-es5.js"
></script>

<script
   crossorigin="anonymous"
   integrity="sha384-YXzfTEuq6x+8VEBZcHmPE9rM+NpSTVfRQsU1X0v4drgjp3S4F8d8rnq/anR3WLpj"
   src="https://cdn.botframework.com/botframework-webchat/4.18.0/webchat-minimal.js"
></script>
image