|
5 | 5 | tags: ["v*"] |
6 | 6 |
|
7 | 7 | # Release assets are published only after all supported platforms produce a |
8 | | -# minisign-signed updater package. This detached updater signature is separate |
9 | | -# from macOS code signing. It is safe to rerun a failed release: uploads replace |
10 | | -# an existing asset with the same name. |
| 8 | +# minisign-signed updater package. The signature is embedded in latest.json and |
| 9 | +# is separate from macOS code signing. It is safe to rerun a failed release: |
| 10 | +# uploads replace an existing asset with the same name. |
11 | 11 | permissions: |
12 | 12 | contents: write |
13 | 13 |
|
|
29 | 29 | fail-fast: false |
30 | 30 | matrix: |
31 | 31 | include: |
32 | | - - os: macos-26-intel |
33 | | - formats: app,dmg |
34 | | - platform: macos-x86_64 |
35 | | - updater_format: app |
36 | | - updater_glob: '*.app.tar.gz' |
37 | | - updater_asset: Siffra-macos-x86_64.app.tar.gz |
38 | | - installer_glob: '*.dmg' |
39 | 32 | - os: macos-15 |
40 | 33 | formats: app,dmg |
41 | 34 | platform: macos-aarch64 |
@@ -124,18 +117,20 @@ jobs: |
124 | 117 | test -n "$updater" |
125 | 118 | test -n "$installer" |
126 | 119 | test -f "$updater.sig" |
127 | | - test -f "$installer.sig" |
128 | 120 | cp "$updater" "release/${{ matrix.updater_asset }}" |
129 | | - cp "$updater.sig" "release/${{ matrix.updater_asset }}.sig" |
130 | 121 | cp "$installer" "release/$(basename "$installer")" |
131 | | - cp "$installer.sig" "release/$(basename "$installer").sig" |
132 | | - printf '{"platform":"%s","asset":"%s","format":"%s"}\n' \ |
133 | | - '${{ matrix.platform }}' '${{ matrix.updater_asset }}' '${{ matrix.updater_format }}' \ |
| 122 | + signature="$(<"$updater.sig")" |
| 123 | + jq -n \ |
| 124 | + --arg platform '${{ matrix.platform }}' \ |
| 125 | + --arg asset '${{ matrix.updater_asset }}' \ |
| 126 | + --arg format '${{ matrix.updater_format }}' \ |
| 127 | + --arg signature "$signature" \ |
| 128 | + '{platform: $platform, asset: $asset, format: $format, signature: $signature}' \ |
134 | 129 | > release/updater.json |
135 | 130 |
|
136 | 131 | # Keep the artifact contract narrow: one updater package, one native |
137 | | - # installer, their detached signatures, and internal manifest data. |
138 | | - test "$(find release -maxdepth 1 -type f | wc -l | tr -d ' ')" -eq 5 |
| 132 | + # installer, and internal manifest data containing the signature. |
| 133 | + test "$(find release -maxdepth 1 -type f | wc -l | tr -d ' ')" -eq 3 |
139 | 134 |
|
140 | 135 | - uses: actions/upload-artifact@v4 |
141 | 136 | with: |
@@ -187,18 +182,18 @@ jobs: |
187 | 182 | while IFS= read -r -d '' asset; do |
188 | 183 | assets+=("$asset") |
189 | 184 | done < <(find release-assets -type f \( \ |
190 | | - -name '*.AppImage' -o -name '*.AppImage.sig' -o \ |
191 | | - -name '*.app.tar.gz' -o -name '*.app.tar.gz.sig' -o \ |
192 | | - -name '*-setup.exe' -o -name '*-setup.exe.sig' -o \ |
193 | | - -name '*.dmg' -o -name '*.dmg.sig' -o \ |
194 | | - -name '*.msi' -o -name '*.msi.sig' -o \ |
195 | | - -name '*.deb' -o -name '*.deb.sig' -o \ |
| 185 | + -name '*.AppImage' -o \ |
| 186 | + -name '*.app.tar.gz' -o \ |
| 187 | + -name '*-setup.exe' -o \ |
| 188 | + -name '*.dmg' -o \ |
| 189 | + -name '*.msi' -o \ |
| 190 | + -name '*.deb' -o \ |
196 | 191 | -name latest.json \ |
197 | 192 | \) -print0) |
198 | 193 |
|
199 | | - # Four platforms contribute four public artifacts each, followed by |
| 194 | + # Three platforms contribute two public artifacts each, followed by |
200 | 195 | # the updater manifest. Refuse to publish anything else. |
201 | | - test "${#assets[@]}" -eq 17 |
| 196 | + test "${#assets[@]}" -eq 7 |
202 | 197 | for asset in "${assets[@]}"; do |
203 | 198 | gh release upload "$GITHUB_REF_NAME" "$asset" --clobber |
204 | 199 | done |
|
0 commit comments