ci(release): build and publish the installer from CI - #27
Merged
Merged
Conversation
Push to main runs the gates, requires a new package.json version, builds the NSIS installer and publishes v<version> with generated notes plus a stable-named Filesmith-Setup-x64.exe. PRs touching the release machinery and manual dispatches run a dry run that uploads the installer instead. fetch-binaries --pinned stages every bundled tool from a pinned, SHA-256-checked download of the version the local build ships; verify-bundle fails the build if a tool is missing or does not run, before and after packing. Local builds are unchanged. Closes #26 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Owner
Author
|
Dry run 37227350075: green on the first run, Publish skipped as intended.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #26
What
.github/workflows/release.yml, modelled on Prism and Wind: push to main runs typecheck, lint, prettier and unit tests, requires a NEWpackage.jsonversion (refuses to overwrite an existing release), builds withelectron-builder --publish never, and publishesv<version>with--generate-notes --latestplus a stable-namedFilesmith-Setup-x64.exe(soreleases/latest/download/Filesmith-Setup-x64.exealways works). Docs, LICENSE and issue-template pushes are ignored.scripts/fetch-binaries.mjs --pinnedstages every tool from a pinned, SHA-256-checked official download of the exact version the local v0.5.0 bundle ships (scripts/pinned-tools.mjs). Without--pinned, local behaviour is unchanged.scripts/verify-bundle.mjs: fails the build if any bundled tool is missing or does not run (magick encodes and decodes a PNG through the bundled coder modules; ffmpeg, ffprobe, caesiumclt, mutool, 7z, Ghostscript and LibreOffice are smoke-run). It runs onresources/before packing and ondist/win-unpacked/resourcesafter, and writes file manifests.workflow_dispatchrun everything up to the verified installer and upload it (plus manifests) as a workflow artifact; publishing only happens on push to main.Pinned sources
Hashes agree with the GitHub release digests and the winget-pkgs manifests; mupdf, Real-ESRGAN and 7-Zip binaries were checked byte-identical to the local bundle.
Unsigned (no certificate configured).
🤖 Generated with Claude Code