-
Notifications
You must be signed in to change notification settings - Fork 0
111 lines (106 loc) · 3.51 KB
/
Copy pathrelease.yml
File metadata and controls
111 lines (106 loc) · 3.51 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
name: Release
# PR / manual dispatch -> package on all 3 OSes WITHOUT publishing (QA dry-run).
# Pushing a v* tag -> build + publish artifacts to the matching GitHub Release.
on:
pull_request:
paths:
- 'package.json'
- 'package-lock.json'
- 'src/**'
- 'scripts/**'
- 'build/**'
- 'qa/**'
- '.github/workflows/ci.yml'
- '.github/workflows/release.yml'
workflow_dispatch:
push:
tags: ['v*']
permissions:
contents: write
jobs:
quality:
uses: ./.github/workflows/ci.yml
permissions:
contents: read
package:
needs: quality
name: package (${{ matrix.os }})
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
env:
PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1'
CSC_IDENTITY_AUTO_DISCOVERY: 'false' # no code-signing cert in CI (unsigned builds)
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- run: npm ci
- run: npm run build
- name: Verify tag matches the packaged version
if: startsWith(github.ref, 'refs/tags/')
shell: bash
run: test "${GITHUB_REF_NAME}" = "v$(node -p 'require("./package.json").version')"
- name: Build artifacts without publishing
run: npx --no-install electron-builder --publish never
- name: Exercise the packaged Windows app before publication
if: runner.os == 'Windows'
run: node qa/resilience.mjs
env:
DEVDECK_EXECUTABLE: release/win-unpacked/DevDeck.exe
- uses: actions/upload-artifact@v4
if: always() && runner.os == 'Windows'
with:
name: qa-packaged-windows
path: qa/shots/resilience/
- uses: actions/upload-artifact@v4
with:
name: release-${{ matrix.os }}
if-no-files-found: error
path: |
release/*.exe
release/*.blockmap
release/*.dmg
release/*.zip
release/*.AppImage
release/*.deb
release/latest*.yml
- name: List built artifacts
shell: bash
run: ls -la release || true
publish:
# A tag alone can no longer ship an untested or partially built release. All OS builds and
# the installed-layout Windows journeys must succeed before the draft becomes public.
needs: package
if: startsWith(github.ref, 'refs/tags/')
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/download-artifact@v4
with:
pattern: release-*
merge-multiple: true
path: release-assets
- name: Publish the complete validated release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
shell: bash
run: |
tag="$GITHUB_REF_NAME"
if gh release view "$tag" --json isDraft >/dev/null 2>&1; then
test "$(gh release view "$tag" --json isDraft --jq .isDraft)" = true
else
notes="docs/releases/${tag#v}.md"
if test -f "$notes"; then
gh release create "$tag" --verify-tag --draft --title "${tag#v}" --notes-file "$notes"
else
gh release create "$tag" --verify-tag --draft --title "${tag#v}" --generate-notes
fi
fi
gh release upload "$tag" release-assets/* --clobber
gh release edit "$tag" --draft=false --latest