Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 21 additions & 19 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,8 @@ jobs:
steps:
- uses: actions/checkout@v4
with:
# Preserve annotated tag objects instead of an event-synthesized tag.
ref: main
fetch-depth: 0
- name: Validate immutable tag on main
id: metadata
Expand All @@ -59,8 +61,8 @@ jobs:
}
}
NODE
- uses: actions/setup-node@v4
with:
- uses: actions/setup-node@v4
with:
node-version: '22'
cache: npm
- run: npm ci
Expand All @@ -73,16 +75,16 @@ jobs:
test -n "$TAURI_SIGNING_PRIVATE_KEY"
sudo apt-get update
sudo apt-get install -y minisign
printf 'VibeShell updater signing preflight\n' > "$RUNNER_TEMP/signing-probe.txt"
npx --no-install tauri signer sign --private-key "$TAURI_SIGNING_PRIVATE_KEY" --password "$TAURI_SIGNING_PRIVATE_KEY_PASSWORD" "$RUNNER_TEMP/signing-probe.txt"
printf 'VibeShell updater signing preflight\n' > "$RUNNER_TEMP/signing-probe.txt"
npx --no-install tauri signer sign --private-key "$TAURI_SIGNING_PRIVATE_KEY" --password "$TAURI_SIGNING_PRIVATE_KEY_PASSWORD" "$RUNNER_TEMP/signing-probe.txt"
python3 scripts/verify-updater.py "$RUNNER_TEMP/signing-probe.txt"
- name: Create or resume draft only
run: |
set -euo pipefail
if gh release view "$TAG" --json isDraft > "$RUNNER_TEMP/release.json" 2>/dev/null; then
node -e 'if (!JSON.parse(require("node:fs").readFileSync(process.argv[1])).isDraft) throw new Error("Refusing to overwrite a published release")' "$RUNNER_TEMP/release.json"
else
gh release create "$TAG" --draft --verify-tag --title "VibeShell ${TAG#v}" --notes-file CHANGELOG.md
gh release create "$TAG" --draft --verify-tag --target main --title "VibeShell ${TAG#v}" --notes-file CHANGELOG.md
fi

build:
Expand All @@ -98,8 +100,8 @@ jobs:
- os: macos-latest
target: aarch64-apple-darwin
bundles: app,dmg
- os: macos-latest
target: x86_64-apple-darwin
- os: macos-latest
target: x86_64-apple-darwin
bundles: app,dmg
- os: ubuntu-22.04
target: x86_64-unknown-linux-gnu
Expand All @@ -109,18 +111,18 @@ jobs:
TARGET: ${{ matrix.target }}
BUNDLES: ${{ matrix.bundles }}
MACOSX_DEPLOYMENT_TARGET: '11.0'
steps:
- uses: actions/checkout@v4
with:
ref: ${{ needs.prepare.outputs.sha }}
steps:
- uses: actions/checkout@v4
with:
ref: ${{ needs.prepare.outputs.sha }}
- name: Linux prerequisites
if: runner.os == 'Linux'
run: |
sudo apt-get update
sudo apt-get install -y build-essential curl wget file libwebkit2gtk-4.1-dev libgtk-3-dev libayatana-appindicator3-dev librsvg2-dev patchelf libssl-dev libxdo-dev
- uses: actions/setup-node@v4
- uses: actions/setup-node@v4
with:
node-version: '22'
node-version: '22'
cache: npm
- uses: actions/setup-python@v5
with:
Expand Down Expand Up @@ -222,8 +224,8 @@ jobs:
HAS_APPLE_SIGNING: ${{ secrets.APPLE_CERTIFICATE != '' || secrets.APPLE_SIGNING_IDENTITY != '' }}
HAS_APPLE_NOTARIZATION: ${{ secrets.APPLE_ID != '' && secrets.APPLE_PASSWORD != '' && secrets.APPLE_TEAM_ID != '' }}
steps:
- uses: actions/checkout@v4
with:
- uses: actions/checkout@v4
with:
ref: ${{ needs.prepare.outputs.sha }}
- uses: actions/setup-node@v4
with:
Expand All @@ -245,11 +247,11 @@ jobs:
cp licenses/legacy-MIT.txt assets/legacy-MIT.txt
(cd assets && sha256sum ./* > SHA256SUMS.txt)
- name: Publish only after all required jobs succeed
run: |
set -euo pipefail
run: |
set -euo pipefail
gh release view "$TAG" --json isDraft > "$RUNNER_TEMP/release.json"
node -e 'if (!JSON.parse(require("node:fs").readFileSync(process.argv[1])).isDraft) throw new Error("Release is no longer a draft")' "$RUNNER_TEMP/release.json"
cp CHANGELOG.md "$RUNNER_TEMP/notes.md"
node -e 'if (!JSON.parse(require("node:fs").readFileSync(process.argv[1])).isDraft) throw new Error("Release is no longer a draft")' "$RUNNER_TEMP/release.json"
cp CHANGELOG.md "$RUNNER_TEMP/notes.md"
printf '\n## Downloads and source\n\nDesktop and native CLI assets are accompanied by VibeShell-Source-%s.tar.gz and SHA256SUMS.txt. The source bundle contains the exact tagged tree, vendored Rust dependencies, locked npm archives, build scripts and license notices.\n' "$VERSION" >> "$RUNNER_TEMP/notes.md"
if [[ "$HAS_APPLE_SIGNING" != 'true' ]]; then
printf '\nmacOS builds use ad-hoc signatures, not Developer ID signatures or Apple notarization.\n' >> "$RUNNER_TEMP/notes.md"
Expand Down
Loading