| Age | Commit message (Collapse) | Author |
|
🤖 Generated by [robots](https://vyos.io)
|
|
Match assets by filename instead of by position
|
|
|
|
T9075: Fix GitHub actions publishing step for rolling workflow
|
|
Updated asset indexing to correctly access ISO and signature files for nightly builds.
|
|
With async, the browser starts downloading Cookiebot in parallel and
immediately continues parsing, reaching GTM inline bootstrap before
Cookiebot executes. Removing async makes it render-blocking so consent
state is set before GTM fires.
Also clarifies the after + prepend_child ordering in the comment.
Generated by robots (https://vyos.io)
|
|
The amplify branch no longer exists in this repo; the trigger entry is
unreachable. main was already retargeted to development in #59 (rollout 1c).
This completes the trigger cleanup so the list matches real branches.
🤖 Generated by [robots](https://vyos.io)
|
|
follow-up) (#60)
Rollout 1c (IS-503) renamed vyos-cla-signatures' default branch to `production`,
but cla-check.yml still called the reusable at @current. The `current` branch of
vyos-cla-signatures has diverged from `production` and its copy of cla-reusable.yml
writes signatures to `branch: 'current'` — so CLA signatures from this repo's PRs
were landing on the stale `current` branch instead of `production`.
Flip the ref to @production (whose cla-reusable.yml writes to `branch: 'production'`).
Note: migrating/reconciling signatures already accumulated on
vyos-cla-signatures@current (and whether to delete that branch) is a separate
operator decision tracked in IS-504 / T8947.
🤖 Generated by [robots](https://vyos.io)
|
|
The default-branch reorg renamed main->development (production is now the
default). main.yml deploys by mirroring github.ref_name to an AWS Amplify
branch, so the dead main trigger is replaced with development. The Amplify
app has a matching development branch (operator-confirmed). amplify/production
trigger entries left unchanged.
Tracking: T8943
|
|
Production deploy: 1.5.0 status + Cookiebot direct loader + Mergify config
|
|
Add Mergify configuration
|
|
Enables @Mergifyio merge/rebase/update/backport commands.
No automated rules — all merges remain manual.
🤖 Generated by [robots](https://vyos.io)
|
|
Load Cookiebot uc.js directly before GTM
|
|
GTM container tag 163 was not firing the Cookiebot uc.js loader despite
correct rules in the container. Loading Cookiebot directly via soupault
is the architecturally correct approach anyway: consent state must be set
before GTM fires any tracking tags.
Widget runs after insert-google-tag-manager-head (same pattern as
insert-preconnect-hints) so the final <head> order is:
preconnect hints → Cookiebot uc.js → GTM snippet
🤖 Generated by [robots](https://vyos.io)
|
|
Add 1.5.0 to the release status data file
|
|
|
|
Promote main to production: Cookiebot + GTM-T5VQHRT consent migration
|
|
|
|
Substitute real Cookiebot CBID for vyos.net
|
|
Replaces the <CBID> placeholder in the insert-cookiebot-declaration
widget with the actual domain group ID (932cb8b9-5141-4dc9-9018-21fc31a0586f)
registered for vyos.net in the Cookiebot admin panel.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
|
Migrate to Cookiebot + GTM-T5VQHRT via metrics.vyos.io
|
|
Address Copilot review: preconnect order + staging-gate cookies-policy script
|
|
Two fixes flagged by the Copilot reviewer on #35:
1. Preconnect hints were appended to the end of <head> while the GTM
loader is prepended to the top, so GTM's async script creation
fired before the browser ever saw the preconnect tags — they
provided no benefit. Switches insert-preconnect-hints to
prepend_child and adds `after = "insert-google-tag-manager-head"`
so the widget runs after GTM and its prepend pushes GTM down to
position 1. Result: preconnects land at the top of <head>, ahead
of the GTM loader.
2. The Cookiebot cd.js script embedded directly in
site/legal/cookies-policy.md rendered on every profile, so a
staging visitor who hit /legal/cookies-policy/ would leak their
IP to consent.cookiebot.com. Replaces the inline <script> with a
<div id="cookie-declaration-placeholder"></div> and adds a new
insert-cookiebot-declaration widget (profile = "live", page =
"legal/cookies-policy.md") that replaces the placeholder with
the real script element only on live builds. Staging now emits
zero Cookiebot markup on the cookies-policy page.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
|
Ignore .soupault-cache/ build artifact directory (production)
|
|
Soupault 5.x writes incremental build caches under `.soupault-cache/`
in the repo root. The directory appears as untracked after any local
build and `gh pr create` warns about it. Add it to .gitignore
alongside `build/*` so clean checkouts stay clean.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
|
Ignore .soupault-cache/ build artifact directory
|
|
Soupault 5.x writes incremental build caches under `.soupault-cache/`
in the repo root. The directory appears as untracked after any local
build and `gh pr create` warns about it. Add it to .gitignore
alongside `build/*` so clean checkouts stay clean.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
|
Task 5 inserted the preconnect tags directly into templates/main.html,
which caused them to ship on every profile — defeating the staging
privacy posture (staging visitors' IPs would leak to Cookiebot and
metrics.vyos.io during TLS handshake). Moves them to a new
insert-preconnect-hints widget with profile = "live", matching the
pattern used for the two GTM widgets and Step 5.2's original
--profile live verification intent.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
|
Embeds Cookiebot's auto-generated cookie declaration table. The
declaration content is served by consent.cookiebot.com and rendered
at display time — this repo only holds the embed shim and intro copy.
The CBID is a <CBID> placeholder that MUST be substituted with the
real value before merging main into production. The PR body's
prerequisite checklist gates this.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
|
Sits next to the copyright line inside <div class="bottom">. Links to
the new /legal/cookies-policy/ page created in the next commit.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
|
Starts DNS/TCP/TLS handshake for the Cookiebot banner and GTM proxy
during initial HTML parse, shaving perceivable latency off the
first-visit banner paint.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
|
Deletes the hand-rolled "Allow Analytics" aside, its JavaScript, its
SCSS partial, and the unconditional gtag.js script. The replacement
consent UI (Cookiebot banner) is loaded by the new GTM-T5VQHRT
container; the custom banner is no longer needed and was also
ineffective (both GTM and gtag loaded before the user clicked anything).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
|
Migrates the site's GTM container to GTM-T5VQHRT (shared with vyos.io)
proxied through metrics.vyos.io, and gates both GTM widgets on
profile = "live" so they only render in production builds. The new
container handles Google Consent Mode v2 defaults, Cookiebot loading,
and consent-state updates internally, so no page-side consent plumbing
is needed.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
cosmetic bug: Fix image allign backport
|
|
(cherry picked from commit e8107f90846c7256184983a42a0fc8a3f5f36c66)
|
|
cosmetic bug: Fix image alignment
|
|
|
|
|
|
|
|
CI: T7579: fix of the run trigger for CLA
|