Repository navigation
Merge channels/google-play #7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # The redoubtbrowser.org website (docs/android/WEBSITE.md), published as a | |
| # GitHub Page from site/. | |
| # | |
| # GitHub-hosted runner, not the self-hosted Android runner: this job needs only | |
| # python3 and the Pages actions, and the self-hosted machine stays free for | |
| # builds. android-test.yaml ignores pushes that touch only site/**, this file | |
| # and the site checker, so a site edit does not start the hour-long build. | |
| # | |
| # What it publishes is site/ verbatim, including site/update/** (the signed | |
| # update-check endpoint, docs/android/DISTRIBUTION.md), which this workflow | |
| # neither generates nor rewrites. site/CNAME sets the custom domain. | |
| # | |
| # Plus the F-Droid repository's APKs (LW-M6-03, docs/android/FDROID.md). Only | |
| # the signed index is committed (site/fdroid/repo/). scripts/fdroid-pages.py | |
| # assemble copies site/ to _site/, verifies the index signature against the | |
| # pinned repository fingerprint (assets/fdroid/repo-fingerprint), fetches every | |
| # APK the signed index names from its GitHub release (site/fdroid/sources.json), | |
| # and fails the deploy on any sha256/size mismatch with the signed index, a | |
| # missing file, an APK not signed by the release key (apksigner from the | |
| # runner's Android SDK), or a site over 1 GB (GitHub Pages' published-site | |
| # limit). Without site/fdroid/repo/ it only copies site/. Pull requests run the | |
| # offline index check and download nothing. | |
| # | |
| # Before anything is uploaded, scripts/site-check.py must pass: well-formed HTML, | |
| # no script and nothing loaded from another origin, every internal link and | |
| # anchor resolves, external links only to the project's GitHub repository, | |
| # librewolf.net and mozilla.org, and the signing fingerprint identical to | |
| # README.md's. Pull requests run the check only and deploy nothing. | |
| # | |
| # It references no secrets. The deploy authenticates with the job's OIDC token | |
| # (id-token: write), which is what actions/deploy-pages requires. | |
| name: Website | |
| on: | |
| push: | |
| branches: | |
| - main | |
| paths: | |
| - site/** | |
| - .github/workflows/pages.yaml | |
| - scripts/site-check.py | |
| # The checker compares the site's fingerprint against README.md. | |
| - README.md | |
| # The F-Droid repository: its pinned fingerprint and the assembler. | |
| - assets/fdroid/repo-fingerprint | |
| - scripts/fdroid-pages.py | |
| - scripts/tests/test-fdroid-pages.py | |
| pull_request: | |
| paths: | |
| - site/** | |
| - .github/workflows/pages.yaml | |
| - scripts/site-check.py | |
| - README.md | |
| - assets/fdroid/repo-fingerprint | |
| - scripts/fdroid-pages.py | |
| - scripts/tests/test-fdroid-pages.py | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| # One deploy at a time; never cancel one half-way through. | |
| group: pages | |
| cancel-in-progress: false | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| persist-credentials: false | |
| - name: Check the site | |
| run: python3 scripts/site-check.py site | |
| - name: Test the F-Droid assembler (throwaway keys, offline) | |
| run: python3 scripts/tests/test-fdroid-pages.py | |
| - name: Check the F-Droid index (offline) | |
| run: python3 scripts/fdroid-pages.py check --site site | |
| - name: Assemble the site with the F-Droid APKs | |
| if: github.event_name != 'pull_request' | |
| # apksigner comes from the runner image's Android SDK ($ANDROID_HOME). | |
| run: python3 scripts/fdroid-pages.py assemble --site site --out _site | |
| - name: Configure Pages | |
| if: github.event_name != 'pull_request' | |
| uses: actions/configure-pages@v5 | |
| - name: Upload the site | |
| if: github.event_name != 'pull_request' | |
| uses: actions/upload-pages-artifact@v3 | |
| with: | |
| path: _site | |
| deploy: | |
| if: github.event_name != 'pull_request' | |
| needs: build | |
| runs-on: ubuntu-latest | |
| permissions: | |
| pages: write | |
| id-token: write | |
| environment: | |
| name: github-pages | |
| url: ${{ steps.deployment.outputs.page_url }} | |
| steps: | |
| - name: Deploy to GitHub Pages | |
| id: deployment | |
| uses: actions/deploy-pages@v4 |