--------- Co-authored-by-agent: Codex <267193182+codex@users.noreply.github.com> Co-authored-by-agent: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: RainbowBird <rbxin2003@outlook.com> Co-authored-by: Neko <neko@ayaka.moe>
544 lines
29 KiB
YAML
544 lines
29 KiB
YAML
name: Release Tamagotchi
|
|
|
|
permissions:
|
|
contents: write
|
|
actions: read
|
|
|
|
env:
|
|
BUNDLE_NAME: ''
|
|
DEB_BUNDLE_NAME: ''
|
|
RPM_BUNDLE_NAME: ''
|
|
FLATPAK_BUNDLE_NAME: ''
|
|
PRODUCT_NAME: 'AIRI'
|
|
VERSION: ''
|
|
|
|
on:
|
|
release:
|
|
types:
|
|
- prereleased
|
|
workflow_dispatch:
|
|
inputs:
|
|
build_only:
|
|
description: Build only
|
|
required: false
|
|
default: false
|
|
type: boolean
|
|
artifacts_only:
|
|
description: Build and upload artifacts only
|
|
required: false
|
|
default: false
|
|
type: boolean
|
|
tag:
|
|
description: Specific tag/commit for the release (leave empty to auto-detect latest tag)
|
|
required: false
|
|
type: string
|
|
platform:
|
|
description: Platform
|
|
type: choice
|
|
options:
|
|
- all
|
|
- windows
|
|
- macos
|
|
- linux
|
|
schedule:
|
|
- cron: '0 0 * * *'
|
|
|
|
jobs:
|
|
build:
|
|
name: Build
|
|
continue-on-error: ${{ matrix.skip }} # WORKAROUND: Skipping subsequent steps without failing the whole workflow
|
|
env:
|
|
VITE_ENABLE_POSTHOG: ${{ ((github.event_name == 'release') || (github.event_name == 'workflow_dispatch' && !inputs.build_only)) && 'true' || 'false' }}
|
|
strategy:
|
|
matrix:
|
|
include:
|
|
|
|
- os: macos-15-intel
|
|
artifact: darwin-x64
|
|
target: x86_64-apple-darwin
|
|
arch: x64
|
|
builder-args: --macos --x64
|
|
skip: ${{ inputs.platform != '' && inputs.platform != 'all' && inputs.platform != 'macos' }}
|
|
|
|
- os: macos-26
|
|
artifact: darwin-arm64
|
|
target: aarch64-apple-darwin
|
|
builder-args: --macos --arm64
|
|
arch: arm64
|
|
skip: ${{ inputs.platform != '' && inputs.platform != 'all' && inputs.platform != 'macos' }}
|
|
|
|
- os: ubuntu-latest
|
|
artifact: linux-x64
|
|
target: x86_64-unknown-linux-gnu
|
|
builder-args: --linux --x64
|
|
arch: x64
|
|
skip: ${{ inputs.platform != '' && inputs.platform != 'all' && inputs.platform != 'linux' }}
|
|
|
|
- os: ubuntu-24.04-arm
|
|
artifact: linux-arm64
|
|
target: aarch64-unknown-linux-gnu
|
|
builder-args: --linux --arm64
|
|
arch: arm64
|
|
skip: ${{ inputs.platform != '' && inputs.platform != 'all' && inputs.platform != 'linux' }}
|
|
|
|
- os: windows-latest
|
|
artifact: windows-x64-setup
|
|
target: x86_64-pc-windows-msvc
|
|
builder-args: --windows --x64
|
|
arch: x64
|
|
skip: ${{ inputs.platform != '' && inputs.platform != 'all' && inputs.platform != 'windows' }}
|
|
|
|
runs-on: ${{ matrix.os }}
|
|
steps:
|
|
- name: Skip the build (fail fast)
|
|
run: |
|
|
echo "Skipping build for ${{ matrix.os }}..."
|
|
echo "This will fail the job, but don't panic—this is expected when not building for all."
|
|
echo "This will be improved in the future."
|
|
exit ${{ matrix.skip && '1' || '0' }}
|
|
|
|
# Why?
|
|
#
|
|
# failed to build archive at `/home/runner/work/airi/airi/target/x86_64-unknown-linux-gnu/release/deps/libapp_lib.rlib`:
|
|
# No space left on device (os error 28)
|
|
- name: Free Disk Space
|
|
if: matrix.os == 'ubuntu-latest' || matrix.os == 'ubuntu-24.04-arm'
|
|
uses: jlumbroso/free-disk-space@main
|
|
|
|
- uses: actions/checkout@v6
|
|
|
|
- name: macOS Select Xcode 26.2
|
|
if: matrix.os == 'macos-15-intel' || matrix.os == 'macos-26'
|
|
run: |
|
|
sudo xcode-select -s /Applications/Xcode_26.2.app
|
|
xcodebuild -version
|
|
|
|
- name: macOS Show Toolchain
|
|
if: matrix.os == 'macos-15-intel' || matrix.os == 'macos-26'
|
|
run: |
|
|
xcodebuild -version
|
|
actool --version
|
|
|
|
- uses: pnpm/action-setup@v4
|
|
with:
|
|
run_install: false
|
|
- uses: actions/setup-node@v6
|
|
with:
|
|
node-version: lts/*
|
|
cache: pnpm
|
|
- run: pnpm install --frozen-lockfile
|
|
|
|
# ---------
|
|
# Build
|
|
# ---------
|
|
|
|
- run: pnpm run build:packages
|
|
|
|
- name: Build (Windows Only) # Windows
|
|
if: matrix.os == 'windows-latest'
|
|
run: pnpm run -F @proj-airi/stage-tamagotchi build && pnpm -F @proj-airi/stage-tamagotchi exec electron-builder build ${{ matrix.builder-args }} --publish=${{ (inputs.build_only || inputs.artifacts_only) && 'never' || 'onTagOrDraft' }}
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Build (macOS Only) # macOS
|
|
if: matrix.os == 'macos-15-intel' || matrix.os == 'macos-26'
|
|
run: |
|
|
echo "$CSC_CONTENT" | base64 --decode > apps/stage-tamagotchi/apple-developer-code-signing.p12
|
|
export CSC_LINK="./apple-developer-code-signing.p12"
|
|
pnpm run -F @proj-airi/stage-tamagotchi build && pnpm -F @proj-airi/stage-tamagotchi exec electron-builder build ${{ matrix.builder-args }} --publish=${{ (inputs.build_only || inputs.artifacts_only) && 'never' || 'onTagOrDraft' }}
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
CSC_CONTENT: ${{ secrets.CSC_CONTENT }}
|
|
CSC_KEY_PASSWORD: ${{ secrets.CSC_KEY_PASSWORD }}
|
|
APPLE_ID: ${{ secrets.APPLE_DEVELOPER_APPLE_ID }}
|
|
APPLE_APP_SPECIFIC_PASSWORD: ${{ secrets.APPLE_DEVELOPER_APPLE_APP_SPECIFIC_PASSWORD }}
|
|
APPLE_TEAM_ID: ${{ secrets.APPLE_DEVELOPER_TEAM_ID }}
|
|
|
|
- name: Build (Linux Only) # Linux
|
|
if: matrix.os == 'ubuntu-latest' || matrix.os == 'ubuntu-24.04-arm'
|
|
run: pnpm run -F @proj-airi/stage-tamagotchi build && pnpm -F @proj-airi/stage-tamagotchi exec electron-builder build ${{ matrix.builder-args }} --publish=${{ (inputs.build_only || inputs.artifacts_only) && 'never' || 'onTagOrDraft' }}
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Setup Flatpak (Linux Only)
|
|
if: ${{ matrix.os == 'ubuntu-latest' || matrix.os == 'ubuntu-24.04-arm' }}
|
|
run: |
|
|
sudo apt update
|
|
sudo apt install -y flatpak flatpak-builder elfutils
|
|
flatpak --version
|
|
flatpak --user remote-add --if-not-exists flathub https://dl.flathub.org/repo/flathub.flatpakrepo
|
|
|
|
- name: Build Flatpak (Linux Only) # Flatpak
|
|
if: ${{ matrix.os == 'ubuntu-latest' || matrix.os == 'ubuntu-24.04-arm' }}
|
|
working-directory: ./apps/stage-tamagotchi
|
|
run: |
|
|
mkdir -p dist
|
|
# Auto-install required SDK/Platform/BaseApp from Flathub in user scope
|
|
flatpak-builder --user --install-deps-from=flathub ./flatpak ai.moeru.airi.flatpak.yml --force-clean
|
|
flatpak build-export ./flatpak-repo ./flatpak
|
|
export FLATPAK_OUTPUT_NAME=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-output-filename flatpak)
|
|
flatpak build-bundle ./flatpak-repo dist/${FLATPAK_OUTPUT_NAME} ai.moeru.airi
|
|
|
|
# ---------
|
|
# Nightly (schedule) builds only
|
|
# ---------
|
|
|
|
- name: Get Artifacts Envs (Nightly + Windows Only)
|
|
if: ${{ github.event_name == 'schedule' && matrix.os == 'windows-latest' }}
|
|
working-directory: ./apps/stage-tamagotchi
|
|
run: |
|
|
echo "BUNDLE_NAME=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-bundle-name)" >> $env:GITHUB_ENV
|
|
echo "VERSION=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-version)" >> $env:GITHUB_ENV
|
|
|
|
- name: Get Artifacts Envs (Nightly + Non-Windows)
|
|
if: ${{ github.event_name == 'schedule' && matrix.os != 'windows-latest' }}
|
|
working-directory: ./apps/stage-tamagotchi
|
|
run: |
|
|
echo "VERSION=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-version)" >> $GITHUB_ENV
|
|
|
|
- name: Get Artifacts Envs (Nightly + macOS Only)
|
|
if: ${{ github.event_name == 'schedule' && (matrix.os == 'macos-26' || matrix.os == 'macos-15-intel') }}
|
|
working-directory: ./apps/stage-tamagotchi
|
|
run: |
|
|
echo "BUNDLE_NAME=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-bundle-name)" >> $GITHUB_ENV
|
|
|
|
- name: Rename Artifacts (Nightly)
|
|
if: ${{ github.event_name == 'schedule' }}
|
|
run:
|
|
pnpm run -F @proj-airi/stage-tamagotchi rename-artifacts ${{ matrix.target }}
|
|
|
|
- name: Get Linux Artifact Names (Nightly + Linux Only)
|
|
if: ${{ github.event_name == 'schedule' && (matrix.os == 'ubuntu-latest' || matrix.os == 'ubuntu-24.04-arm') }}
|
|
working-directory: ./apps/stage-tamagotchi
|
|
run: |
|
|
echo "DEB_BUNDLE_NAME=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-filename deb)" >> $GITHUB_ENV
|
|
echo "RPM_BUNDLE_NAME=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-filename rpm)" >> $GITHUB_ENV
|
|
echo "FLATPAK_BUNDLE_NAME=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-filename flatpak)" >> $GITHUB_ENV
|
|
|
|
- name: Upload Artifacts (Nightly + Non-Linux)
|
|
if: ${{ github.event_name == 'schedule' && (matrix.os != 'ubuntu-latest' && matrix.os != 'ubuntu-24.04-arm') }}
|
|
id: unsigned-artifacts-nightly
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: ${{ env.BUNDLE_NAME }}
|
|
path: apps/stage-tamagotchi/bundle/${{ env.BUNDLE_NAME }}
|
|
|
|
- name: Upload Artifacts (Nightly + Linux deb)
|
|
if: ${{ github.event_name == 'schedule' && (matrix.os == 'ubuntu-latest' || matrix.os == 'ubuntu-24.04-arm') }}
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: ${{ env.DEB_BUNDLE_NAME }}
|
|
path: apps/stage-tamagotchi/bundle/${{ env.DEB_BUNDLE_NAME }}
|
|
|
|
- name: Upload Artifacts (Nightly + Linux rpm)
|
|
if: ${{ github.event_name == 'schedule' && (matrix.os == 'ubuntu-latest' || matrix.os == 'ubuntu-24.04-arm') }}
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: ${{ env.RPM_BUNDLE_NAME }}
|
|
path: apps/stage-tamagotchi/bundle/${{ env.RPM_BUNDLE_NAME }}
|
|
|
|
- name: Upload Flatpak Artifact (Nightly + Linux Only)
|
|
if: ${{ github.event_name == 'schedule' && (matrix.os == 'ubuntu-latest' || matrix.os == 'ubuntu-24.04-arm') }}
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: ${{ env.FLATPAK_BUNDLE_NAME }}
|
|
path: apps/stage-tamagotchi/bundle/${{ env.FLATPAK_BUNDLE_NAME }}
|
|
|
|
- name: Sign Windows Artifacts with SignPath (Nightly + Windows Only)
|
|
uses: signpath/github-action-submit-signing-request@v2
|
|
if: ${{ github.event_name == 'schedule' && (matrix.os == 'windows-latest' && github.repository == 'moeru-ai/airi') }}
|
|
with:
|
|
api-token: '${{ secrets.SIGNPATH_API_TOKEN }}'
|
|
organization-id: '${{ secrets.SIGNPATH_ORGANIZATION_ID }}'
|
|
project-slug: 'airi'
|
|
signing-policy-slug: 'test-signing'
|
|
artifact-configuration-slug: ci-github-actions-artifacts-windows
|
|
github-artifact-id: '${{ steps.unsigned-artifacts-nightly.outputs.artifact-id }}'
|
|
wait-for-completion: true
|
|
wait-for-completion-timeout-in-seconds: 900 # 15 minutes
|
|
download-signed-artifact-timeout-in-seconds: 900 # 15 minutes
|
|
output-artifact-directory: apps/stage-tamagotchi/bundle/signed/windows/
|
|
|
|
- name: Upload Signed Artifacts (Nightly + Non-Linux)
|
|
if: ${{ github.event_name == 'schedule' && (matrix.os == 'windows-latest') }}
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: ${{ env.BUNDLE_NAME }}
|
|
path: apps/stage-tamagotchi/bundle/signed/windows/${{ env.BUNDLE_NAME }}
|
|
overwrite: true
|
|
|
|
# NOTICE: Electron Builder generates latest.yml during the build step, before this workflow
|
|
# submits the Windows installer to SignPath. SignPath re-signs the .exe and changes its bytes,
|
|
# which changes the updater hashes too. Regenerating latest.yml from the signed installer keeps
|
|
# the published Windows update metadata aligned with the final released artifact.
|
|
- name: Regenerate Windows latest.yml (Nightly + Windows Only)
|
|
if: ${{ github.event_name == 'schedule' && matrix.os == 'windows-latest' }}
|
|
run: |
|
|
pnpm -F @proj-airi/stage-tamagotchi run regenerate-windows-latest --input apps/stage-tamagotchi/bundle/signed/windows/${{ env.BUNDLE_NAME }} --output apps/stage-tamagotchi/bundle/latest.yml --version ${{ env.VERSION }}
|
|
|
|
# ---------
|
|
# Workflow Dispatch only
|
|
# ---------
|
|
|
|
- name: Get Artifacts Envs (Manual + Windows Only)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && matrix.os == 'windows-latest' }}
|
|
working-directory: ./apps/stage-tamagotchi
|
|
run: |
|
|
echo "BUNDLE_NAME=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-bundle-name --release ${{ !inputs.build_only && !inputs.artifacts_only }} --tag ${{ inputs.tag }} --auto-tag ${{ !inputs.build_only }})" >> $env:GITHUB_ENV
|
|
echo "VERSION=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-version --release ${{ !inputs.build_only && !inputs.artifacts_only }} --tag ${{ inputs.tag }} --auto-tag ${{ !inputs.build_only }})" >> $env:GITHUB_ENV
|
|
|
|
- name: Get Artifacts Envs (Manual + Non-Windows)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && matrix.os != 'windows-latest' }}
|
|
working-directory: ./apps/stage-tamagotchi
|
|
run: |
|
|
echo "VERSION=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-version --release ${{ !inputs.build_only && !inputs.artifacts_only }} --tag ${{ inputs.tag }} --auto-tag ${{ !inputs.build_only }})" > $GITHUB_ENV
|
|
|
|
- name: Get Artifacts Envs (Manual + macOS Only)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && (matrix.os == 'macos-26' || matrix.os == 'macos-15-intel') }}
|
|
working-directory: ./apps/stage-tamagotchi
|
|
run: |
|
|
echo "BUNDLE_NAME=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-bundle-name --release ${{ !inputs.build_only && !inputs.artifacts_only }} --tag ${{ inputs.tag }} --auto-tag ${{ !inputs.build_only }})" > $GITHUB_ENV
|
|
|
|
- name: Rename Artifacts (Manual)
|
|
if: ${{ github.event_name == 'workflow_dispatch' }}
|
|
run: |
|
|
pnpm run -F @proj-airi/stage-tamagotchi rename-artifacts ${{ matrix.target }} --release ${{ !inputs.build_only && !inputs.artifacts_only }} --tag ${{ inputs.tag }} --auto-tag ${{ !inputs.build_only }}
|
|
|
|
# NOTICE: electron-builder emits `latest-mac.yml` per macOS architecture, but GitHub Releases can only keep one asset with that exact name.
|
|
# NOTICE: publishing both matrix outputs under the generic name causes the last upload to win, which can leave auto-update metadata pinned to a single architecture instead of the merged manifest.
|
|
# NOTICE: rename the per-arch manifests before upload so the follow-up merge job can publish the only generic `latest-mac.yml`, whose `files` list contains both arm64 and x64 ZIPs for electron-updater to choose from.
|
|
- name: Rename macOS update info (Manual + Release + macOS Only)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && !inputs.build_only && !inputs.artifacts_only && (matrix.os == 'macos-26' || matrix.os == 'macos-15-intel') }}
|
|
run: |
|
|
mv apps/stage-tamagotchi/bundle/latest-mac.yml apps/stage-tamagotchi/bundle/latest-mac-${{ matrix.arch }}.yml
|
|
|
|
- name: Upload macOS update info (Manual + Release + macOS Only)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && !inputs.build_only && !inputs.artifacts_only && (matrix.os == 'macos-26' || matrix.os == 'macos-15-intel') }}
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: latest-mac-yml-${{ matrix.arch }}
|
|
path: apps/stage-tamagotchi/bundle/latest-mac-${{ matrix.arch }}.yml
|
|
if-no-files-found: error
|
|
|
|
- name: Get Linux Artifact Names (Manual + Non-Release + Linux Only)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && !inputs.build_only && inputs.artifacts_only && (matrix.os == 'ubuntu-latest' || matrix.os == 'ubuntu-24.04-arm') }}
|
|
working-directory: ./apps/stage-tamagotchi
|
|
run: |
|
|
echo "DEB_BUNDLE_NAME=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-filename deb --release ${{ !inputs.build_only && !inputs.artifacts_only }} --tag ${{ inputs.tag }} --auto-tag ${{ !inputs.build_only }})" >> $GITHUB_ENV
|
|
echo "RPM_BUNDLE_NAME=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-filename rpm --release ${{ !inputs.build_only && !inputs.artifacts_only }} --tag ${{ inputs.tag }} --auto-tag ${{ !inputs.build_only }})" >> $GITHUB_ENV
|
|
echo "FLATPAK_BUNDLE_NAME=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-filename flatpak --release ${{ !inputs.build_only && !inputs.artifacts_only }} --tag ${{ inputs.tag }} --auto-tag ${{ !inputs.build_only }})" >> $GITHUB_ENV
|
|
|
|
- name: Upload Artifacts (Manual + Non-Release + Non-Linux)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && !inputs.build_only && inputs.artifacts_only && (matrix.os != 'ubuntu-latest' && matrix.os != 'ubuntu-24.04-arm') }}
|
|
id: unsigned-artifacts-workflow-dispatch
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: ${{ env.BUNDLE_NAME }}
|
|
path: apps/stage-tamagotchi/bundle/${{ env.BUNDLE_NAME }}
|
|
|
|
- name: Upload Artifacts (Manual + Non-Release + Linux deb)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && !inputs.build_only && inputs.artifacts_only && (matrix.os == 'ubuntu-latest' || matrix.os == 'ubuntu-24.04-arm') }}
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: ${{ env.DEB_BUNDLE_NAME }}
|
|
path: apps/stage-tamagotchi/bundle/${{ env.DEB_BUNDLE_NAME }}
|
|
|
|
- name: Upload Artifacts (Manual + Non-Release + Linux rpm)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && !inputs.build_only && inputs.artifacts_only && (matrix.os == 'ubuntu-latest' || matrix.os == 'ubuntu-24.04-arm') }}
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: ${{ env.RPM_BUNDLE_NAME }}
|
|
path: apps/stage-tamagotchi/bundle/${{ env.RPM_BUNDLE_NAME }}
|
|
|
|
- name: Upload Flatpak Artifact (Manual + Non-Release + Linux)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && !inputs.build_only && inputs.artifacts_only && (matrix.os == 'ubuntu-latest' || matrix.os == 'ubuntu-24.04-arm') }}
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: ${{ env.FLATPAK_BUNDLE_NAME }}
|
|
path: apps/stage-tamagotchi/bundle/${{ env.FLATPAK_BUNDLE_NAME }}
|
|
|
|
- name: Sign Windows Artifacts with SignPath (Manual + Windows Only)
|
|
uses: signpath/github-action-submit-signing-request@v2
|
|
if: ${{ github.event_name == 'workflow_dispatch' && !inputs.build_only && inputs.artifacts_only && (matrix.os == 'windows-latest' && github.repository == 'moeru-ai/airi') }}
|
|
with:
|
|
api-token: '${{ secrets.SIGNPATH_API_TOKEN }}'
|
|
organization-id: '${{ secrets.SIGNPATH_ORGANIZATION_ID }}'
|
|
project-slug: 'airi'
|
|
signing-policy-slug: 'test-signing'
|
|
artifact-configuration-slug: ci-github-actions-artifacts-windows
|
|
github-artifact-id: '${{ steps.unsigned-artifacts-workflow-dispatch.outputs.artifact-id }}'
|
|
wait-for-completion: true
|
|
wait-for-completion-timeout-in-seconds: 900 # 15 minutes
|
|
download-signed-artifact-timeout-in-seconds: 900 # 15 minutes
|
|
output-artifact-directory: apps/stage-tamagotchi/bundle/signed/windows/
|
|
|
|
- name: Move Signed Artifacts (Manual + Release + Windows Only)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && !inputs.build_only && inputs.artifacts_only && matrix.os == 'windows-latest' }}
|
|
run: |
|
|
Move-Item -Force apps/stage-tamagotchi/bundle/signed/windows/${{ env.BUNDLE_NAME }} apps/stage-tamagotchi/bundle/${{ env.BUNDLE_NAME }}
|
|
|
|
- name: Upload Signed Artifacts (Manual + Windows Only)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && !inputs.build_only && inputs.artifacts_only && (matrix.os == 'windows-latest') }}
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: ${{ env.BUNDLE_NAME }}
|
|
path: apps/stage-tamagotchi/bundle/${{ env.BUNDLE_NAME }}
|
|
overwrite: true
|
|
|
|
# NOTICE: Electron Builder already wrote latest.yml before SignPath signed the installer.
|
|
# After the signed .exe replaces the unsigned one, we must rebuild latest.yml so its hashes
|
|
# describe the final Windows artifact that users will actually download.
|
|
- name: Regenerate Windows latest.yml (Manual + Windows Only)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && !inputs.build_only && inputs.artifacts_only && matrix.os == 'windows-latest' }}
|
|
run: |
|
|
pnpm -F @proj-airi/stage-tamagotchi run regenerate-windows-latest --input apps/stage-tamagotchi/bundle/${{ env.BUNDLE_NAME }} --output apps/stage-tamagotchi/bundle/latest.yml --version ${{ env.VERSION }}
|
|
|
|
- name: Upload To GitHub Releases (Manual + Release + Overwrite Release)
|
|
if: ${{ github.event_name == 'workflow_dispatch' && !inputs.build_only && !inputs.artifacts_only }}
|
|
uses: softprops/action-gh-release@v2
|
|
with:
|
|
files: |
|
|
apps/stage-tamagotchi/bundle/${{ env.PRODUCT_NAME }}-*.exe
|
|
apps/stage-tamagotchi/bundle/${{ env.PRODUCT_NAME }}-*.zip
|
|
apps/stage-tamagotchi/bundle/${{ env.PRODUCT_NAME }}-*.dmg
|
|
apps/stage-tamagotchi/bundle/${{ env.PRODUCT_NAME }}-*.deb
|
|
apps/stage-tamagotchi/bundle/${{ env.PRODUCT_NAME }}-*.rpm
|
|
apps/stage-tamagotchi/bundle/${{ env.PRODUCT_NAME }}-*.flatpak
|
|
apps/stage-tamagotchi/bundle/latest.yml
|
|
apps/stage-tamagotchi/bundle/latest-linux*.yml
|
|
apps/stage-tamagotchi/bundle/latest-mac-*.yml
|
|
append_body: true
|
|
tag_name: ${{ inputs.tag }}
|
|
|
|
# ---------
|
|
# Version push
|
|
# ---------
|
|
|
|
- name: Rename Artifacts (Automatic)
|
|
if: ${{ github.event_name == 'release' }}
|
|
run: |
|
|
pnpm run -F @proj-airi/stage-tamagotchi rename-artifacts ${{ matrix.target }} --release --auto-tag
|
|
|
|
# NOTICE: electron-builder emits `latest-mac.yml` per macOS architecture, but GitHub Releases can only keep one asset with that exact name.
|
|
# NOTICE: publishing both matrix outputs under the generic name causes the last upload to win, which can leave auto-update metadata pinned to a single architecture instead of the merged manifest.
|
|
# NOTICE: rename the per-arch manifests before upload so the follow-up merge job can publish the only generic `latest-mac.yml`, whose `files` list contains both arm64 and x64 ZIPs for electron-updater to choose from.
|
|
- name: Rename macOS update info (Automatic + macOS Only)
|
|
if: ${{ github.event_name == 'release' && (matrix.os == 'macos-26' || matrix.os == 'macos-15-intel') }}
|
|
run: |
|
|
mv apps/stage-tamagotchi/bundle/latest-mac.yml apps/stage-tamagotchi/bundle/latest-mac-${{ matrix.arch }}.yml
|
|
|
|
- name: Upload macOS update info (Automatic + macOS Only)
|
|
if: ${{ github.event_name == 'release' && (matrix.os == 'macos-26' || matrix.os == 'macos-15-intel') }}
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: latest-mac-yml-${{ matrix.arch }}
|
|
path: apps/stage-tamagotchi/bundle/latest-mac-${{ matrix.arch }}.yml
|
|
if-no-files-found: error
|
|
|
|
- name: Get Artifacts Envs (Automatic + Windows Only)
|
|
if: ${{ github.event_name == 'release' && matrix.os == 'windows-latest' }}
|
|
working-directory: ./apps/stage-tamagotchi
|
|
run: |
|
|
echo "BUNDLE_NAME=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-bundle-name --release ${{ !inputs.build_only && !inputs.artifacts_only }} --tag ${{ inputs.tag }} --auto-tag ${{ !inputs.build_only }})" >> $env:GITHUB_ENV
|
|
echo "VERSION=$(pnpm exec tsx scripts/artifacts-metadata.ts ${{ matrix.target }} --get-version --release ${{ !inputs.build_only && !inputs.artifacts_only }} --tag ${{ inputs.tag }} --auto-tag ${{ !inputs.build_only }})" >> $env:GITHUB_ENV
|
|
|
|
- name: Upload Artifacts (Automatic + Windows Only)
|
|
if: ${{ github.event_name == 'release' && matrix.os == 'windows-latest' }}
|
|
id: unsigned-artifacts-release
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: ${{ env.BUNDLE_NAME }}
|
|
path: apps/stage-tamagotchi/bundle/${{ env.BUNDLE_NAME }}
|
|
|
|
- name: Sign Windows Artifacts with SignPath (Nightly + Windows Only)
|
|
uses: signpath/github-action-submit-signing-request@v2
|
|
if: ${{ github.event_name == 'release' && (matrix.os == 'windows-latest' && github.repository == 'moeru-ai/airi') }}
|
|
with:
|
|
api-token: '${{ secrets.SIGNPATH_API_TOKEN }}'
|
|
organization-id: '${{ secrets.SIGNPATH_ORGANIZATION_ID }}'
|
|
project-slug: 'airi'
|
|
signing-policy-slug: 'test-signing'
|
|
artifact-configuration-slug: ci-github-actions-artifacts-windows
|
|
github-artifact-id: '${{ steps.unsigned-artifacts-release.outputs.artifact-id }}'
|
|
wait-for-completion: true
|
|
wait-for-completion-timeout-in-seconds: 900 # 15 minutes
|
|
download-signed-artifact-timeout-in-seconds: 900 # 15 minutes
|
|
output-artifact-directory: apps/stage-tamagotchi/bundle/signed/windows/
|
|
|
|
- name: Move Signed Artifacts (Automatic + Windows Only)
|
|
if: ${{ github.event_name == 'release' && matrix.os == 'windows-latest' }}
|
|
run: |
|
|
Move-Item -Force apps/stage-tamagotchi/bundle/signed/windows/${{ env.BUNDLE_NAME }} apps/stage-tamagotchi/bundle/${{ env.BUNDLE_NAME }}
|
|
|
|
# NOTICE: The root cause here is the build/signing order: latest.yml is produced by Electron
|
|
# Builder before SignPath re-signs the installer. That post-build signing step mutates the .exe,
|
|
# so the updater metadata becomes stale. Recomputing latest.yml after the signed file is moved
|
|
# into its final bundle path makes the release upload self-consistent again.
|
|
- name: Regenerate Windows latest.yml (Automatic + Windows Only)
|
|
if: ${{ github.event_name == 'release' && matrix.os == 'windows-latest' }}
|
|
run: |
|
|
pnpm -F @proj-airi/stage-tamagotchi run regenerate-windows-latest --input apps/stage-tamagotchi/bundle/${{ env.BUNDLE_NAME }} --output apps/stage-tamagotchi/bundle/latest.yml --version ${{ env.VERSION }}
|
|
|
|
- name: Upload To GitHub Releases (Automatic)
|
|
if: ${{ github.event_name == 'release' }}
|
|
uses: softprops/action-gh-release@v2
|
|
with:
|
|
# Possible auto updater files:
|
|
# Windows: latest.yml
|
|
# macOS: latest-mac-arm64.yml, latest-mac-x64.yml, latest-mac.yml (merged in follow-up job)
|
|
# Linux: latest-linux-arm64.yml (arm64), latest-linux.yml (x64)
|
|
files: |
|
|
apps/stage-tamagotchi/bundle/${{ env.PRODUCT_NAME }}-*.exe
|
|
apps/stage-tamagotchi/bundle/${{ env.PRODUCT_NAME }}-*.zip
|
|
apps/stage-tamagotchi/bundle/${{ env.PRODUCT_NAME }}-*.dmg
|
|
apps/stage-tamagotchi/bundle/${{ env.PRODUCT_NAME }}-*.deb
|
|
apps/stage-tamagotchi/bundle/${{ env.PRODUCT_NAME }}-*.rpm
|
|
apps/stage-tamagotchi/bundle/${{ env.PRODUCT_NAME }}-*.flatpak
|
|
apps/stage-tamagotchi/bundle/latest.yml
|
|
apps/stage-tamagotchi/bundle/latest-linux*.yml
|
|
apps/stage-tamagotchi/bundle/latest-mac-*.yml
|
|
append_body: true
|
|
|
|
merge-mac-latest:
|
|
name: Merge macOS latest-mac.yml
|
|
if: ${{ github.event_name == 'release' || (github.event_name == 'workflow_dispatch' && !inputs.build_only && !inputs.artifacts_only) }}
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
|
|
- uses: pnpm/action-setup@v4
|
|
with:
|
|
run_install: false
|
|
- uses: actions/setup-node@v6
|
|
with:
|
|
node-version: lts/*
|
|
cache: pnpm
|
|
- run: pnpm install --frozen-lockfile
|
|
|
|
- name: Download latest-mac.yml (x64)
|
|
uses: actions/download-artifact@v8
|
|
with:
|
|
name: latest-mac-yml-x64
|
|
path: artifacts/x64
|
|
|
|
- name: Download latest-mac.yml (arm64)
|
|
uses: actions/download-artifact@v8
|
|
with:
|
|
name: latest-mac-yml-arm64
|
|
path: artifacts/arm64
|
|
|
|
# NOTICE: the merged `latest-mac.yml` must be the only generic macOS update manifest published to the release.
|
|
# NOTICE: electron-updater resolves the correct macOS ZIP from the merged `files` list; if we skip this merge or publish a single-arch file as `latest-mac.yml`, Apple Silicon users can be routed to the wrong build.
|
|
- name: Merge latest-mac.yml
|
|
run: |
|
|
pnpm -F @proj-airi/stage-tamagotchi exec tsx scripts/merge-latest-mac.ts \
|
|
--dir artifacts \
|
|
--output apps/stage-tamagotchi/bundle/latest-mac.yml
|
|
|
|
- name: Upload merged latest-mac.yml
|
|
uses: softprops/action-gh-release@v2
|
|
with:
|
|
files: apps/stage-tamagotchi/bundle/latest-mac.yml
|
|
tag_name: ${{ github.event_name == 'release' && github.event.release.tag_name || inputs.tag }}
|