Skip to content

Android release 157.0-3: H.264/AAC video hotfix #9

Android release 157.0-3: H.264/AAC video hotfix

Android release 157.0-3: H.264/AAC video hotfix #9

Workflow file for this run

# The redoubtbrowser.org website (docs/android/WEBSITE.md), published as a
# GitHub Page from site/.
#
# GitHub-hosted runner, not the self-hosted Android runner: this job needs only
# python3 and the Pages actions, and the self-hosted machine stays free for
# builds. android-test.yaml ignores pushes that touch only site/**, this file
# and the site checker, so a site edit does not start the hour-long build.
#
# What it publishes is site/ verbatim, including site/update/** (the signed
# update-check endpoint, docs/android/DISTRIBUTION.md), which this workflow
# neither generates nor rewrites. site/CNAME sets the custom domain.
#
# The F-Droid repository (LW-M6-03, docs/android/FDROID.md) is NOT published
# here. Its index and APKs live in the owner's Hetzner Object Storage bucket,
# uploaded by `scripts/fdroid-repo.sh deploy` from the owner's machine; this
# workflow downloads no APK. Only the human page site/fdroid.html and its QR
# code are part of this site. (Until 2026-10-05 this workflow fetched the APKs
# from the GitHub release into the Pages artifact; GitHub Pages' 1 GB site limit
# allowed only one to three releases, so the repository moved to the bucket.)
#
# Before anything is uploaded, scripts/site-check.py must pass: well-formed HTML,
# no script and nothing loaded from another origin, every internal link and
# anchor resolves, external links only to the project's GitHub repository,
# librewolf.net, mozilla.org, f-droid.org and (from fdroid.html only) the
# F-Droid bucket named in assets/fdroid/deploy.conf, the signing fingerprint
# identical to README.md's, and no APK or site/fdroid/ directory committed.
# Pull requests run the check only and deploy nothing.
#
# It references no secrets. The deploy authenticates with the job's OIDC token
# (id-token: write), which is what actions/deploy-pages requires.
name: Website
on:
push:
branches:
- main
paths:
- site/**
- .github/workflows/pages.yaml
- scripts/site-check.py
# The checker compares the site's fingerprint against README.md.
- README.md
# The F-Droid page's inputs to the checker: the pinned repository
# fingerprint and the bucket it may link to, and the checker's tests.
- assets/fdroid/repo-fingerprint
- assets/fdroid/deploy.conf
- scripts/tests/test-site-check-fdroid.py
pull_request:
paths:
- site/**
- .github/workflows/pages.yaml
- scripts/site-check.py
- README.md
- assets/fdroid/repo-fingerprint
- assets/fdroid/deploy.conf
- scripts/tests/test-site-check-fdroid.py
workflow_dispatch:
permissions:
contents: read
concurrency:
# One deploy at a time; never cancel one half-way through.
group: pages
cancel-in-progress: false
jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
persist-credentials: false
- name: Check the site
run: python3 scripts/site-check.py site
- name: Test the checker's F-Droid rules (hermetic)
run: python3 scripts/tests/test-site-check-fdroid.py
- name: Configure Pages
if: github.event_name != 'pull_request'
uses: actions/configure-pages@v5
- name: Upload the site
if: github.event_name != 'pull_request'
uses: actions/upload-pages-artifact@v3
with:
path: site
deploy:
if: github.event_name != 'pull_request'
needs: build
runs-on: ubuntu-latest
permissions:
pages: write
id-token: write
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
steps:
- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@v4