From 9dac310c7aa98b1329d7593d30650ad3ad503d30 Mon Sep 17 00:00:00 2001 From: "Beau Beauchamp, WebTigers" Date: Fri, 9 Oct 2026 07:01:04 -0400 Subject: [PATCH] =?UTF-8?q?chore(release):=20v1.20.1=20=E2=80=94=20private?= =?UTF-8?q?-repo=20install=20fix?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_01ASauLLscjqdsNqBNsx2Typ --- CHANGELOG.md | 11 +++++++++++ library/Tiger/Version.php | 2 +- 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 6ec9825..8ae88b9 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,17 @@ All notable changes to **Tiger Core** (`webtigers/tiger-core`). Format follows ## [Unreleased] +## [1.20.1] — 2026-10-09 + +### Fixed + +- **Private module repos now install, not just detect.** `Tiger_Module_Github::tarballUrl()` returned + GitHub's web archive URL (`github.com///archive/.tar.gz`), which 404s for a PRIVATE + repo even with a valid bearer token — so an authenticated module source could *detect* an update but + fail to *apply* it. It now uses the API tarball endpoint (`api.github.com/repos///tarball/`), + which honours the token and redirects to a signed codeload URL, and works for public repos too. The + licensed/authority install path is unaffected (it mints its own signed URL). + ## [1.20.0] — 2026-10-08 ### Added diff --git a/library/Tiger/Version.php b/library/Tiger/Version.php index 8240876..1fe94d1 100644 --- a/library/Tiger/Version.php +++ b/library/Tiger/Version.php @@ -9,5 +9,5 @@ class Tiger_Version { /** Current Tiger Core version. Keep in lockstep with the git tag cut for a release. */ - const VERSION = '1.20.0'; + const VERSION = '1.20.1'; }