Repository navigation
Nightly release channel #2012
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Nightly release channel #2012
Changes from 10 commits
33f5299
71211b6
eb78ad3
e31527d
b3b32bb
aa4c156
97f90dd
65753f7
97efd80
31dce76
e4e0c90
3b8c3a8
87dd61f
9d5eac0
3fafa19
662b86c
79c032a
1666b94
5424cfb
5042785
2c825c0
b623a30
a1271cb
2aa826c
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,302 @@ | ||
| name: Nightly Desktop Release | ||
|
|
||
| on: | ||
| schedule: | ||
| - cron: "0 9 * * *" | ||
| workflow_dispatch: | ||
|
|
||
| concurrency: | ||
| group: nightly-release | ||
| cancel-in-progress: false | ||
|
|
||
| permissions: | ||
| contents: write | ||
| id-token: write | ||
|
|
||
| jobs: | ||
| preflight: | ||
| name: Preflight | ||
| runs-on: ubuntu-24.04 | ||
| timeout-minutes: 10 | ||
| outputs: | ||
| base_version: ${{ steps.release_meta.outputs.base_version }} | ||
| version: ${{ steps.release_meta.outputs.version }} | ||
| tag: ${{ steps.release_meta.outputs.tag }} | ||
| release_name: ${{ steps.release_meta.outputs.name }} | ||
| short_sha: ${{ steps.release_meta.outputs.short_sha }} | ||
| ref: ${{ github.sha }} | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v6 | ||
|
|
||
| - name: Setup Bun | ||
| uses: oven-sh/setup-bun@v2 | ||
| with: | ||
| bun-version-file: package.json | ||
|
|
||
| - name: Setup Node | ||
| uses: actions/setup-node@v6 | ||
| with: | ||
| node-version-file: package.json | ||
|
|
||
| - name: Install dependencies | ||
| run: bun install --frozen-lockfile | ||
|
|
||
| - id: release_meta | ||
| name: Resolve nightly release version | ||
| shell: bash | ||
| env: | ||
| NIGHTLY_DATE: ${{ github.run_started_at }} | ||
| NIGHTLY_SHA: ${{ github.sha }} | ||
| NIGHTLY_RUN_NUMBER: ${{ github.run_number }} | ||
| run: | | ||
| nightly_date="$(date -u -d "$NIGHTLY_DATE" +%Y%m%d)" | ||
|
|
||
| node scripts/resolve-nightly-release.ts \ | ||
| --date "$nightly_date" \ | ||
| --run-number "$NIGHTLY_RUN_NUMBER" \ | ||
| --sha "$NIGHTLY_SHA" \ | ||
| --github-output | ||
|
|
||
| - name: Lint | ||
| run: bun run lint | ||
|
|
||
| - name: Typecheck | ||
| run: bun run typecheck | ||
|
|
||
| - name: Test | ||
| run: bun run test | ||
|
|
||
| build: | ||
| name: Build ${{ matrix.label }} | ||
| needs: preflight | ||
| runs-on: ${{ matrix.runner }} | ||
| timeout-minutes: 30 | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| include: | ||
| - label: macOS arm64 | ||
| runner: macos-14 | ||
| platform: mac | ||
| target: dmg | ||
| arch: arm64 | ||
| - label: macOS x64 | ||
| runner: macos-15-intel | ||
| platform: mac | ||
| target: dmg | ||
| arch: x64 | ||
| - label: Linux x64 | ||
| runner: ubuntu-24.04 | ||
| platform: linux | ||
| target: AppImage | ||
| arch: x64 | ||
| - label: Windows x64 | ||
| runner: windows-2022 | ||
| platform: win | ||
| target: nsis | ||
| arch: x64 | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v6 | ||
| with: | ||
| ref: ${{ needs.preflight.outputs.ref }} | ||
| fetch-depth: 0 | ||
|
|
||
| - name: Setup Bun | ||
| uses: oven-sh/setup-bun@v2 | ||
| with: | ||
| bun-version-file: package.json | ||
|
|
||
| - name: Setup Node | ||
| uses: actions/setup-node@v6 | ||
| with: | ||
| node-version-file: package.json | ||
|
|
||
| - name: Install dependencies | ||
| run: bun install --frozen-lockfile | ||
|
|
||
| - name: Align package versions to nightly version | ||
| run: node scripts/update-release-package-versions.ts "${{ needs.preflight.outputs.version }}" | ||
|
|
||
| - name: Build desktop artifact | ||
| shell: bash | ||
| env: | ||
| CSC_LINK: ${{ secrets.CSC_LINK }} | ||
| CSC_KEY_PASSWORD: ${{ secrets.CSC_KEY_PASSWORD }} | ||
| APPLE_API_KEY: ${{ secrets.APPLE_API_KEY }} | ||
| APPLE_API_KEY_ID: ${{ secrets.APPLE_API_KEY_ID }} | ||
| APPLE_API_ISSUER: ${{ secrets.APPLE_API_ISSUER }} | ||
| AZURE_TENANT_ID: ${{ secrets.AZURE_TENANT_ID }} | ||
| AZURE_CLIENT_ID: ${{ secrets.AZURE_CLIENT_ID }} | ||
| AZURE_CLIENT_SECRET: ${{ secrets.AZURE_CLIENT_SECRET }} | ||
| AZURE_TRUSTED_SIGNING_ENDPOINT: ${{ secrets.AZURE_TRUSTED_SIGNING_ENDPOINT }} | ||
| AZURE_TRUSTED_SIGNING_ACCOUNT_NAME: ${{ secrets.AZURE_TRUSTED_SIGNING_ACCOUNT_NAME }} | ||
| AZURE_TRUSTED_SIGNING_CERTIFICATE_PROFILE_NAME: ${{ secrets.AZURE_TRUSTED_SIGNING_CERTIFICATE_PROFILE_NAME }} | ||
| AZURE_TRUSTED_SIGNING_PUBLISHER_NAME: ${{ secrets.AZURE_TRUSTED_SIGNING_PUBLISHER_NAME }} | ||
| run: | | ||
| args=( | ||
| --platform "${{ matrix.platform }}" | ||
| --target "${{ matrix.target }}" | ||
| --arch "${{ matrix.arch }}" | ||
| --build-version "${{ needs.preflight.outputs.version }}" | ||
| --verbose | ||
| ) | ||
|
|
||
| has_all() { | ||
| for value in "$@"; do | ||
| if [[ -z "$value" ]]; then | ||
| return 1 | ||
| fi | ||
| done | ||
| return 0 | ||
| } | ||
|
|
||
| if [[ "${{ matrix.platform }}" == "mac" ]]; then | ||
| if has_all "$CSC_LINK" "$CSC_KEY_PASSWORD" "$APPLE_API_KEY" "$APPLE_API_KEY_ID" "$APPLE_API_ISSUER"; then | ||
| key_path="$RUNNER_TEMP/AuthKey_${APPLE_API_KEY_ID}.p8" | ||
| printf '%s' "$APPLE_API_KEY" > "$key_path" | ||
| export APPLE_API_KEY="$key_path" | ||
| echo "macOS signing enabled." | ||
| args+=(--signed) | ||
| else | ||
| echo "macOS signing disabled (missing one or more Apple signing secrets)." | ||
| fi | ||
| elif [[ "${{ matrix.platform }}" == "win" ]]; then | ||
| if has_all \ | ||
| "$AZURE_TENANT_ID" \ | ||
| "$AZURE_CLIENT_ID" \ | ||
| "$AZURE_CLIENT_SECRET" \ | ||
| "$AZURE_TRUSTED_SIGNING_ENDPOINT" \ | ||
| "$AZURE_TRUSTED_SIGNING_ACCOUNT_NAME" \ | ||
| "$AZURE_TRUSTED_SIGNING_CERTIFICATE_PROFILE_NAME" \ | ||
| "$AZURE_TRUSTED_SIGNING_PUBLISHER_NAME"; then | ||
| echo "Windows signing enabled (Azure Trusted Signing)." | ||
| args+=(--signed) | ||
| else | ||
| echo "Windows signing disabled (missing one or more Azure Trusted Signing secrets)." | ||
| fi | ||
| else | ||
| echo "Signing disabled for ${{ matrix.platform }}." | ||
| fi | ||
|
|
||
| bun run dist:desktop:artifact -- "${args[@]}" | ||
|
|
||
| - name: Collect release assets | ||
| shell: bash | ||
| run: | | ||
| set -euo pipefail | ||
| mkdir -p release-publish | ||
|
|
||
| shopt -s nullglob | ||
| for pattern in \ | ||
| "release/*.dmg" \ | ||
| "release/*.zip" \ | ||
| "release/*.AppImage" \ | ||
| "release/*.exe" \ | ||
| "release/*.blockmap" \ | ||
| "release/*.yml"; do | ||
| for file in $pattern; do | ||
| cp "$file" release-publish/ | ||
| done | ||
| done | ||
|
|
||
| if [[ "${{ matrix.platform }}" == "mac" && "${{ matrix.arch }}" != "arm64" ]]; then | ||
| shopt -s nullglob | ||
| for manifest in release-publish/*-mac.yml; do | ||
| mv "$manifest" "${manifest%.yml}-${{ matrix.arch }}.yml" | ||
| done | ||
| fi | ||
|
|
||
| - name: Upload build artifacts | ||
| uses: actions/upload-artifact@v7 | ||
| with: | ||
| name: desktop-${{ matrix.platform }}-${{ matrix.arch }} | ||
| path: release-publish/* | ||
| if-no-files-found: error | ||
|
|
||
| publish_cli: | ||
| name: Publish CLI to npm (nightly) | ||
| needs: [preflight, build] | ||
| runs-on: ubuntu-24.04 | ||
| timeout-minutes: 10 | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v6 | ||
| with: | ||
| ref: ${{ needs.preflight.outputs.ref }} | ||
|
|
||
| - name: Setup Bun | ||
| uses: oven-sh/setup-bun@v2 | ||
| with: | ||
| bun-version-file: package.json | ||
|
|
||
| - name: Setup Node | ||
| uses: actions/setup-node@v6 | ||
| with: | ||
| node-version-file: package.json | ||
| registry-url: https://registry.npmjs.org | ||
|
|
||
| - name: Install dependencies | ||
| run: bun install --frozen-lockfile | ||
|
|
||
| - name: Align package versions to nightly version | ||
| run: node scripts/update-release-package-versions.ts "${{ needs.preflight.outputs.version }}" | ||
|
|
||
| - name: Build CLI package | ||
| run: bun run build --filter=@t3tools/web --filter=t3 | ||
|
|
||
| - name: Publish CLI package to npm nightly tag | ||
| run: node apps/server/scripts/cli.ts publish --tag nightly --app-version "${{ needs.preflight.outputs.version }}" --verbose | ||
|
|
||
| release: | ||
| name: Publish GitHub Release | ||
| needs: [preflight, build, publish_cli] | ||
| runs-on: ubuntu-24.04 | ||
| timeout-minutes: 10 | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v6 | ||
| with: | ||
| ref: ${{ needs.preflight.outputs.ref }} | ||
|
|
||
| - name: Setup Node | ||
| uses: actions/setup-node@v6 | ||
| with: | ||
| node-version-file: package.json | ||
|
|
||
| - name: Download all desktop artifacts | ||
| uses: actions/download-artifact@v8 | ||
| with: | ||
| pattern: desktop-* | ||
| merge-multiple: true | ||
| path: release-assets | ||
|
|
||
| - name: Merge macOS updater manifests | ||
| run: | | ||
| shopt -s nullglob | ||
| for x64_manifest in release-assets/*-mac-x64.yml; do | ||
| arm64_manifest="${x64_manifest%-x64.yml}.yml" | ||
| if [[ -f "$arm64_manifest" ]]; then | ||
| node scripts/merge-mac-update-manifests.ts "$arm64_manifest" "$x64_manifest" | ||
| rm -f "$x64_manifest" | ||
| fi | ||
| done | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Nightly release job missing dependency installation stepHigh Severity The Additional Locations (1)Reviewed by Cursor Bugbot for commit 31dce76. Configure here. |
||
|
|
||
| - name: Publish nightly prerelease | ||
| uses: softprops/action-gh-release@v2 | ||
| with: | ||
| tag_name: ${{ needs.preflight.outputs.tag }} | ||
| target_commitish: ${{ needs.preflight.outputs.ref }} | ||
| name: ${{ needs.preflight.outputs.release_name }} | ||
| generate_release_notes: true | ||
| prerelease: true | ||
| make_latest: false | ||
| files: | | ||
| release-assets/*.dmg | ||
| release-assets/*.zip | ||
| release-assets/*.AppImage | ||
| release-assets/*.exe | ||
| release-assets/*.blockmap | ||
| release-assets/*.yml | ||
| fail_on_unmatched_files: true | ||


Uh oh!
There was an error while loading. Please reload this page.