From 64d22a3b37827187e27ecea5b8ccd5e80be6aa52 Mon Sep 17 00:00:00 2001 From: Rick <6553213+veithly@users.noreply.github.com> Date: Fri, 18 Sep 2026 13:18:18 +0800 Subject: [PATCH 1/2] fix: preserve annotated tags in release checkout --- .github/workflows/release.yml | 38 ++++++++++++++++++----------------- 1 file changed, 20 insertions(+), 18 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 9bd7792..0cc0267 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -34,6 +34,8 @@ jobs: steps: - uses: actions/checkout@v4 with: + # Preserve annotated tag objects instead of an event-synthesized tag. + ref: main fetch-depth: 0 - name: Validate immutable tag on main id: metadata @@ -59,8 +61,8 @@ jobs: } } NODE - - uses: actions/setup-node@v4 - with: + - uses: actions/setup-node@v4 + with: node-version: '22' cache: npm - run: npm ci @@ -73,8 +75,8 @@ jobs: test -n "$TAURI_SIGNING_PRIVATE_KEY" sudo apt-get update sudo apt-get install -y minisign - printf 'VibeShell updater signing preflight\n' > "$RUNNER_TEMP/signing-probe.txt" - npx --no-install tauri signer sign --private-key "$TAURI_SIGNING_PRIVATE_KEY" --password "$TAURI_SIGNING_PRIVATE_KEY_PASSWORD" "$RUNNER_TEMP/signing-probe.txt" + printf 'VibeShell updater signing preflight\n' > "$RUNNER_TEMP/signing-probe.txt" + npx --no-install tauri signer sign --private-key "$TAURI_SIGNING_PRIVATE_KEY" --password "$TAURI_SIGNING_PRIVATE_KEY_PASSWORD" "$RUNNER_TEMP/signing-probe.txt" python3 scripts/verify-updater.py "$RUNNER_TEMP/signing-probe.txt" - name: Create or resume draft only run: | @@ -98,8 +100,8 @@ jobs: - os: macos-latest target: aarch64-apple-darwin bundles: app,dmg - - os: macos-latest - target: x86_64-apple-darwin + - os: macos-latest + target: x86_64-apple-darwin bundles: app,dmg - os: ubuntu-22.04 target: x86_64-unknown-linux-gnu @@ -109,18 +111,18 @@ jobs: TARGET: ${{ matrix.target }} BUNDLES: ${{ matrix.bundles }} MACOSX_DEPLOYMENT_TARGET: '11.0' - steps: - - uses: actions/checkout@v4 - with: - ref: ${{ needs.prepare.outputs.sha }} + steps: + - uses: actions/checkout@v4 + with: + ref: ${{ needs.prepare.outputs.sha }} - name: Linux prerequisites if: runner.os == 'Linux' run: | sudo apt-get update sudo apt-get install -y build-essential curl wget file libwebkit2gtk-4.1-dev libgtk-3-dev libayatana-appindicator3-dev librsvg2-dev patchelf libssl-dev libxdo-dev - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v4 with: - node-version: '22' + node-version: '22' cache: npm - uses: actions/setup-python@v5 with: @@ -222,8 +224,8 @@ jobs: HAS_APPLE_SIGNING: ${{ secrets.APPLE_CERTIFICATE != '' || secrets.APPLE_SIGNING_IDENTITY != '' }} HAS_APPLE_NOTARIZATION: ${{ secrets.APPLE_ID != '' && secrets.APPLE_PASSWORD != '' && secrets.APPLE_TEAM_ID != '' }} steps: - - uses: actions/checkout@v4 - with: + - uses: actions/checkout@v4 + with: ref: ${{ needs.prepare.outputs.sha }} - uses: actions/setup-node@v4 with: @@ -245,11 +247,11 @@ jobs: cp licenses/legacy-MIT.txt assets/legacy-MIT.txt (cd assets && sha256sum ./* > SHA256SUMS.txt) - name: Publish only after all required jobs succeed - run: | - set -euo pipefail + run: | + set -euo pipefail gh release view "$TAG" --json isDraft > "$RUNNER_TEMP/release.json" - node -e 'if (!JSON.parse(require("node:fs").readFileSync(process.argv[1])).isDraft) throw new Error("Release is no longer a draft")' "$RUNNER_TEMP/release.json" - cp CHANGELOG.md "$RUNNER_TEMP/notes.md" + node -e 'if (!JSON.parse(require("node:fs").readFileSync(process.argv[1])).isDraft) throw new Error("Release is no longer a draft")' "$RUNNER_TEMP/release.json" + cp CHANGELOG.md "$RUNNER_TEMP/notes.md" printf '\n## Downloads and source\n\nDesktop and native CLI assets are accompanied by VibeShell-Source-%s.tar.gz and SHA256SUMS.txt. The source bundle contains the exact tagged tree, vendored Rust dependencies, locked npm archives, build scripts and license notices.\n' "$VERSION" >> "$RUNNER_TEMP/notes.md" if [[ "$HAS_APPLE_SIGNING" != 'true' ]]; then printf '\nmacOS builds use ad-hoc signatures, not Developer ID signatures or Apple notarization.\n' >> "$RUNNER_TEMP/notes.md" From b1628a09c8a0542db1d11968a57e8ef7e582b40e Mon Sep 17 00:00:00 2001 From: Rick <6553213+veithly@users.noreply.github.com> Date: Fri, 18 Sep 2026 13:20:16 +0800 Subject: [PATCH 2/2] fix: target stable main in release metadata --- .github/workflows/release.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 0cc0267..5970dc0 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -84,7 +84,7 @@ jobs: if gh release view "$TAG" --json isDraft > "$RUNNER_TEMP/release.json" 2>/dev/null; then node -e 'if (!JSON.parse(require("node:fs").readFileSync(process.argv[1])).isDraft) throw new Error("Refusing to overwrite a published release")' "$RUNNER_TEMP/release.json" else - gh release create "$TAG" --draft --verify-tag --title "VibeShell ${TAG#v}" --notes-file CHANGELOG.md + gh release create "$TAG" --draft --verify-tag --target main --title "VibeShell ${TAG#v}" --notes-file CHANGELOG.md fi build: