|
1 | 1 | # Fork workflow: build the desktop binaries for every platform this repo already |
2 | | -# supports, on every push to `main`. |
| 2 | +# supports, on every push to `main`, and publish them as a development-build |
| 3 | +# prerelease (`desktop-dev-<run number>`), pruning older dev releases so only |
| 4 | +# the current one plus two remain. |
3 | 5 | # |
4 | 6 | # Upstream produces these from `release.yml`, which also reads the production |
5 | 7 | # T3 Connect relay config, signs, publishes to npm, and cuts a GitHub Release — |
|
8 | 10 | # fork can actually run. |
9 | 11 | # |
10 | 12 | # Constraints this file deliberately respects: |
11 | | -# - no secrets beyond the automatic GITHUB_TOKEN (which it never uses) |
| 13 | +# - no secrets beyond the automatic GITHUB_TOKEN (only the release job uses |
| 14 | +# it, with job-scoped contents: write, to publish and prune dev releases) |
12 | 15 | # - standard GitHub-hosted runners only (upstream's `blacksmith-*` labels do |
13 | 16 | # not resolve here, so those jobs sat queued for 24h and were cancelled) |
14 | 17 | # - builds are unsigned: passing `--signed` is what pulls in signing |
@@ -226,3 +229,94 @@ jobs: |
226 | 229 | path: release/* |
227 | 230 | if-no-files-found: error |
228 | 231 | retention-days: 14 |
| 232 | + |
| 233 | + release: |
| 234 | + name: Publish dev release |
| 235 | + # Publish whatever platforms built — a development build with one platform |
| 236 | + # missing is still useful, and the build job is what turns the run red. |
| 237 | + # The publish step fails only when no platform produced anything at all. |
| 238 | + needs: [build] |
| 239 | + if: ${{ !cancelled() }} |
| 240 | + runs-on: ubuntu-24.04 |
| 241 | + timeout-minutes: 30 |
| 242 | + permissions: |
| 243 | + contents: write |
| 244 | + env: |
| 245 | + GH_TOKEN: ${{ github.token }} |
| 246 | + TAG_PREFIX: desktop-dev- |
| 247 | + KEEP_RELEASES: "3" |
| 248 | + steps: |
| 249 | + - name: Download desktop artifacts |
| 250 | + uses: actions/download-artifact@v8 |
| 251 | + with: |
| 252 | + pattern: desktop-* |
| 253 | + path: assets |
| 254 | + |
| 255 | + # Each artifact lands in its own directory; flatten them for upload. The |
| 256 | + # installer names carry the arch (T3-Code-<version>-<arch>.<ext>), but |
| 257 | + # electron-builder's update metadata does not — both macOS legs emit a |
| 258 | + # latest-mac.yml — so a colliding name gets its artifact name prefixed. |
| 259 | + - name: Collect release assets |
| 260 | + shell: bash |
| 261 | + run: | |
| 262 | + set -euo pipefail |
| 263 | + shopt -s nullglob |
| 264 | + mkdir -p dist |
| 265 | + for dir in assets/*/; do |
| 266 | + artifact="$(basename "$dir")" |
| 267 | + for file in "$dir"*; do |
| 268 | + base="$(basename "$file")" |
| 269 | + if [[ -e "dist/$base" ]]; then |
| 270 | + base="${artifact}-${base}" |
| 271 | + fi |
| 272 | + mv "$file" "dist/$base" |
| 273 | + done |
| 274 | + done |
| 275 | + ls -lh dist |
| 276 | +
|
| 277 | + - name: Create development release |
| 278 | + shell: bash |
| 279 | + run: | |
| 280 | + set -euo pipefail |
| 281 | + shopt -s nullglob |
| 282 | + files=(dist/*) |
| 283 | + if (( ${#files[@]} == 0 )); then |
| 284 | + echo "::error::No desktop artifacts were produced; nothing to release." |
| 285 | + exit 1 |
| 286 | + fi |
| 287 | +
|
| 288 | + tag="${TAG_PREFIX}${GITHUB_RUN_NUMBER}" |
| 289 | + # A re-run reuses the run number, so drop any release this same run |
| 290 | + # already published before recreating it. |
| 291 | + gh release delete "$tag" --repo "$GITHUB_REPOSITORY" --yes --cleanup-tag || true |
| 292 | +
|
| 293 | + { |
| 294 | + echo "Unsigned development build from \`${GITHUB_SHA}\`." |
| 295 | + echo |
| 296 | + echo "Published automatically by the Desktop Artifacts workflow" |
| 297 | + echo "([run ${GITHUB_RUN_NUMBER}](${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/actions/runs/${GITHUB_RUN_ID}))." |
| 298 | + echo "Older development releases are pruned; only the newest ${KEEP_RELEASES} are kept." |
| 299 | + } > notes.md |
| 300 | +
|
| 301 | + gh release create "$tag" "${files[@]}" \ |
| 302 | + --repo "$GITHUB_REPOSITORY" \ |
| 303 | + --target "$GITHUB_SHA" \ |
| 304 | + --title "Desktop dev build ${GITHUB_SHA::7}" \ |
| 305 | + --prerelease \ |
| 306 | + --notes-file notes.md |
| 307 | +
|
| 308 | + - name: Prune older development releases |
| 309 | + shell: bash |
| 310 | + run: | |
| 311 | + set -euo pipefail |
| 312 | + current="${TAG_PREFIX}${GITHUB_RUN_NUMBER}" |
| 313 | + gh api "repos/${GITHUB_REPOSITORY}/releases" --paginate \ |
| 314 | + --jq ".[] | select(.tag_name | startswith(\"${TAG_PREFIX}\")) | [.created_at, .tag_name] | @tsv" | |
| 315 | + sort -r | tail -n +"$((KEEP_RELEASES + 1))" | cut -f2 | |
| 316 | + while IFS= read -r tag; do |
| 317 | + if [[ "$tag" == "$current" ]]; then |
| 318 | + continue |
| 319 | + fi |
| 320 | + echo "Pruning $tag" |
| 321 | + gh release delete "$tag" --repo "$GITHUB_REPOSITORY" --yes --cleanup-tag |
| 322 | + done |
0 commit comments