Skip to content

chore(update): keep 2026-08-14 alive #1

chore(update): keep 2026-08-14 alive

chore(update): keep 2026-08-14 alive #1

Workflow file for this run

name: Release signed desktop core
on:
push:
tags: ["v*"]
permissions:
contents: write
id-token: write
attestations: write
concurrency:
group: core-release-${{ github.ref_name }}
cancel-in-progress: false
jobs:
build:
name: Build ${{ matrix.name }}
strategy:
fail-fast: false
matrix:
include:
- name: Linux x64
os: ubuntu-24.04
- name: Windows x64
os: windows-2025
- name: macOS Apple Silicon
os: macos-15
- name: macOS Intel
os: macos-15-intel
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v7
- name: Install Linux desktop dependencies
if: runner.os == 'Linux'
run: sudo apt-get update && sudo apt-get install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
with:
workspaces: src-tauri
- uses: pnpm/action-setup@v6
with:
version: 10.33.0
- uses: actions/setup-node@v4
with:
node-version: 22.17.1
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm version:check
- uses: tauri-apps/tauri-action@v1
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
with:
tagName: ${{ github.ref_name }}
releaseName: "Updated Again ${{ github.ref_name }} · Developer Preview"
releaseBody: |
Signed cross-platform developer preview. Windows and macOS artifacts are not yet backed by commercial code-signing certificates, so the operating system may show a warning.
prerelease: true
releaseDraft: false
generateReleaseNotes: true
updaterJsonPreferNsis: true
uploadUpdaterJson: true
uploadUpdaterSignatures: true
retryAttempts: 2
- uses: actions/attest-build-provenance@v4
with:
subject-path: "src-tauri/target/release/bundle/**/*"
publish-manifest:
name: Publish updater manifest and archive the core release
needs: build
runs-on: ubuntu-24.04
concurrency:
group: living-release-writer
cancel-in-progress: false
steps:
- uses: actions/checkout@v7
with:
ref: main
fetch-depth: 0
- uses: pnpm/action-setup@v6
with:
version: 10.33.0
- uses: actions/setup-node@v4
with:
node-version: 22.17.1
cache: pnpm
- run: pnpm install --frozen-lockfile
- name: Download merged updater manifest
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
mkdir -p .release
gh release download "${{ github.ref_name }}" --pattern latest.json --dir .release
cp .release/latest.json public/feed/core-latest.json
- name: Record the core update in the living ledger
env:
CORE_VERSION: ${{ github.ref_name }}
CAPSULE_SIGNING_PRIVATE_KEY: ${{ secrets.CAPSULE_SIGNING_PRIVATE_KEY }}
run: node scripts/record-core-release.mjs
- run: pnpm update:validate
- name: Commit the immutable public pointers
run: |
git config user.name "updated-again-bot"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add public/feed/core-latest.json public/feed/index.json public/updates
git commit -m "chore(release): archive ${{ github.ref_name }}"
git push origin HEAD:main