This commit is contained in:
@@ -1,63 +0,0 @@
|
||||
name: Build
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
push:
|
||||
branches: [main]
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
macos:
|
||||
runs-on: macos-15
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- name: Build Meetingnotes
|
||||
run: >-
|
||||
xcodebuild
|
||||
-project Meetingnotes.xcodeproj
|
||||
-scheme meetingnotes
|
||||
-configuration Release
|
||||
-destination 'generic/platform=macOS'
|
||||
-derivedDataPath "$RUNNER_TEMP/DerivedData"
|
||||
ARCHS="arm64 x86_64"
|
||||
ONLY_ACTIVE_ARCH=NO
|
||||
CODE_SIGNING_ALLOWED=NO
|
||||
build
|
||||
- name: Sign test build
|
||||
run: |
|
||||
app_path="$RUNNER_TEMP/DerivedData/Build/Products/Release/Meetingnotes.app"
|
||||
codesign --force --deep --sign - \
|
||||
--entitlements meetingnotes/meetingnotes.entitlements \
|
||||
"$app_path"
|
||||
codesign --verify --deep --strict "$app_path"
|
||||
codesign -d --entitlements :- "$app_path" 2>&1 \
|
||||
| grep -q 'com.apple.security.network.server'
|
||||
- name: Smoke test local API
|
||||
run: |
|
||||
defaults write net.jamesbone.meetingnotes muteDeckAPIEnabled -bool true
|
||||
defaults write net.jamesbone.meetingnotes muteDeckAPIPort -int 19880
|
||||
"$RUNNER_TEMP/DerivedData/Build/Products/Release/Meetingnotes.app/Contents/MacOS/Meetingnotes" >"$RUNNER_TEMP/meetingnotes.log" 2>&1 &
|
||||
app_pid=$!
|
||||
trap 'kill "$app_pid" 2>/dev/null || true' EXIT
|
||||
|
||||
for _ in {1..20}; do
|
||||
if curl -fsS http://127.0.0.1:19880/api/info >"$RUNNER_TEMP/api-info.json"; then
|
||||
break
|
||||
fi
|
||||
sleep 1
|
||||
done
|
||||
|
||||
grep -q '"name":"MeetingDebrief"' "$RUNNER_TEMP/api-info.json"
|
||||
test "$(curl -sS -o /dev/null -w '%{http_code}' http://127.0.0.1:19880/api/recording/status)" = "401"
|
||||
- name: Package test build
|
||||
run: |
|
||||
app_path="$RUNNER_TEMP/DerivedData/Build/Products/Release/Meetingnotes.app"
|
||||
ditto -c -k --sequesterRsrc --keepParent \
|
||||
"$app_path" "$RUNNER_TEMP/Meetingnotes-macOS.zip"
|
||||
- name: Upload test build
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: Meetingnotes-macOS-${{ github.sha }}
|
||||
path: ${{ runner.temp }}/Meetingnotes-macOS.zip
|
||||
retention-days: 30
|
||||
@@ -1,92 +0,0 @@
|
||||
name: Finalize Notarization (manual)
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
release_run_id:
|
||||
description: Release workflow run ID; leave blank to use the latest pending run
|
||||
required: false
|
||||
type: string
|
||||
|
||||
permissions:
|
||||
actions: read
|
||||
contents: write
|
||||
|
||||
concurrency:
|
||||
group: meetingnotes-finalize-release
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
finalize:
|
||||
if: github.event_name != 'workflow_run' || github.event.workflow_run.conclusion == 'success'
|
||||
runs-on: macos-15
|
||||
env:
|
||||
APPLE_ID: ${{ secrets.APPLE_ID }}
|
||||
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
|
||||
APPLE_APP_PASSWORD: ${{ secrets.APPLE_APP_PASSWORD }}
|
||||
SPARKLE_PRIVATE_KEY: ${{ secrets.SPARKLE_PRIVATE_KEY }}
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
steps:
|
||||
- uses: actions/checkout@v7
|
||||
|
||||
- name: Validate release secrets
|
||||
run: |
|
||||
for variable in APPLE_ID APPLE_TEAM_ID APPLE_APP_PASSWORD SPARKLE_PRIVATE_KEY; do
|
||||
if [[ -z "${!variable:-}" ]]; then
|
||||
echo "Missing GitHub Actions secret: $variable" >&2
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
- name: Download pending signed build
|
||||
id: submission
|
||||
env:
|
||||
MANUAL_RUN_ID: ${{ inputs.release_run_id }}
|
||||
COMPLETED_RUN_ID: ${{ github.event.workflow_run.id }}
|
||||
run: |
|
||||
PENDING_DIR="$RUNNER_TEMP/meetingnotes-pending"
|
||||
candidate_ids=()
|
||||
if [[ -n "${MANUAL_RUN_ID:-}" ]]; then
|
||||
candidate_ids+=("$MANUAL_RUN_ID")
|
||||
elif [[ -n "${COMPLETED_RUN_ID:-}" ]]; then
|
||||
candidate_ids+=("$COMPLETED_RUN_ID")
|
||||
else
|
||||
while IFS= read -r run_id; do
|
||||
candidate_ids+=("$run_id")
|
||||
done < <(gh run list --repo "$GITHUB_REPOSITORY" --workflow Release --status success --limit 20 --json databaseId --jq '.[].databaseId')
|
||||
fi
|
||||
|
||||
for run_id in "${candidate_ids[@]}"; do
|
||||
if [[ ! "$run_id" =~ ^[0-9]+$ ]]; then
|
||||
echo "Invalid release run ID: $run_id" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
artifact_name="meetingnotes-notarization-$run_id"
|
||||
artifact_count=$(gh api "repos/$GITHUB_REPOSITORY/actions/runs/$run_id/artifacts" \
|
||||
--jq "[.artifacts[] | select(.name == \"$artifact_name\" and .expired == false)] | length")
|
||||
if [[ "$artifact_count" == 0 ]]; then
|
||||
continue
|
||||
fi
|
||||
|
||||
rm -rf "$PENDING_DIR"
|
||||
mkdir -p "$PENDING_DIR"
|
||||
gh run download "$run_id" --repo "$GITHUB_REPOSITORY" --name "$artifact_name" --dir "$PENDING_DIR"
|
||||
|
||||
version=$(<"$PENDING_DIR/version")
|
||||
if gh release view "v$version" --repo "$GITHUB_REPOSITORY" >/dev/null 2>&1; then
|
||||
continue
|
||||
fi
|
||||
|
||||
echo "found=true" >> "$GITHUB_OUTPUT"
|
||||
echo "run_id=$run_id" >> "$GITHUB_OUTPUT"
|
||||
echo "Using release submission from workflow run $run_id"
|
||||
exit 0
|
||||
done
|
||||
|
||||
echo "found=false" >> "$GITHUB_OUTPUT"
|
||||
echo "No pending release submission was found"
|
||||
|
||||
- name: Check notarization and publish when accepted
|
||||
if: steps.submission.outputs.found == 'true'
|
||||
run: scripts/finalize_release.sh
|
||||
@@ -1,88 +0,0 @@
|
||||
name: Release
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
version:
|
||||
description: Version from MARKETING_VERSION, without the v prefix
|
||||
required: true
|
||||
type: string
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
|
||||
concurrency:
|
||||
group: meetingnotes-release
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
release:
|
||||
runs-on: macos-15
|
||||
env:
|
||||
VERSION: ${{ inputs.version }}
|
||||
APPLE_ID: ${{ secrets.APPLE_ID }}
|
||||
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
|
||||
APPLE_APP_PASSWORD: ${{ secrets.APPLE_APP_PASSWORD }}
|
||||
SPARKLE_PRIVATE_KEY: ${{ secrets.SPARKLE_PRIVATE_KEY }}
|
||||
steps:
|
||||
- uses: actions/checkout@v7
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Validate release secrets
|
||||
env:
|
||||
APPLE_CERTIFICATE_P12: ${{ secrets.APPLE_CERTIFICATE_P12 }}
|
||||
APPLE_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }}
|
||||
run: |
|
||||
for variable in APPLE_CERTIFICATE_P12 APPLE_CERTIFICATE_PASSWORD APPLE_ID APPLE_TEAM_ID APPLE_APP_PASSWORD SPARKLE_PRIVATE_KEY; do
|
||||
if [[ -z "${!variable:-}" ]]; then
|
||||
echo "Missing GitHub Actions secret: $variable" >&2
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
- name: Import Developer ID certificate
|
||||
uses: apple-actions/import-codesign-certs@v7
|
||||
with:
|
||||
p12-file-base64: ${{ secrets.APPLE_CERTIFICATE_P12 }}
|
||||
p12-password: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }}
|
||||
|
||||
- name: Locate Developer ID identity
|
||||
run: |
|
||||
signing_identity=$(security find-identity -v -p codesigning | awk -F '"' '/Developer ID Application/{print $2; exit}')
|
||||
if [[ -z "$signing_identity" ]]; then
|
||||
echo "The .p12 does not contain a Developer ID Application identity" >&2
|
||||
exit 1
|
||||
fi
|
||||
echo "SIGNING_IDENTITY=$signing_identity" >> "$GITHUB_ENV"
|
||||
|
||||
- name: Build, sign, and notarize release
|
||||
timeout-minutes: 30
|
||||
run: scripts/package_release.sh
|
||||
|
||||
- name: Preserve signed release artifacts
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: meetingnotes-signed-release-${{ github.run_id }}
|
||||
path: ${{ runner.temp }}/meetingnotes-release/release
|
||||
if-no-files-found: error
|
||||
retention-days: 30
|
||||
|
||||
- name: Publish signed GitHub release
|
||||
env:
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
run: |
|
||||
tag="v$VERSION"
|
||||
if gh release view "$tag" >/dev/null 2>&1; then
|
||||
gh release upload "$tag" \
|
||||
"$RUNNER_TEMP/meetingnotes-release/release/Meetingnotes-$VERSION.zip" \
|
||||
"$RUNNER_TEMP/meetingnotes-release/release/appcast.xml" \
|
||||
--clobber
|
||||
else
|
||||
gh release create "$tag" \
|
||||
"$RUNNER_TEMP/meetingnotes-release/release/Meetingnotes-$VERSION.zip" \
|
||||
"$RUNNER_TEMP/meetingnotes-release/release/appcast.xml" \
|
||||
--target "$GITHUB_SHA" \
|
||||
--title "Meetingnotes $VERSION" \
|
||||
--generate-notes
|
||||
fi
|
||||
Reference in New Issue
Block a user