chore(update): keep 2026-08-14 alive #1
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release signed desktop core | |
| on: | |
| push: | |
| tags: ["v*"] | |
| permissions: | |
| contents: write | |
| id-token: write | |
| attestations: write | |
| concurrency: | |
| group: core-release-${{ github.ref_name }} | |
| cancel-in-progress: false | |
| jobs: | |
| build: | |
| name: Build ${{ matrix.name }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - name: Linux x64 | |
| os: ubuntu-24.04 | |
| - name: Windows x64 | |
| os: windows-2025 | |
| - name: macOS Apple Silicon | |
| os: macos-15 | |
| - name: macOS Intel | |
| os: macos-15-intel | |
| runs-on: ${{ matrix.os }} | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Install Linux desktop dependencies | |
| if: runner.os == 'Linux' | |
| run: sudo apt-get update && sudo apt-get install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: Swatinem/rust-cache@v2 | |
| with: | |
| workspaces: src-tauri | |
| - uses: pnpm/action-setup@v6 | |
| with: | |
| version: 10.33.0 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 22.17.1 | |
| cache: pnpm | |
| - run: pnpm install --frozen-lockfile | |
| - run: pnpm version:check | |
| - uses: tauri-apps/tauri-action@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }} | |
| with: | |
| tagName: ${{ github.ref_name }} | |
| releaseName: "Updated Again ${{ github.ref_name }} · Developer Preview" | |
| releaseBody: | | |
| Signed cross-platform developer preview. Windows and macOS artifacts are not yet backed by commercial code-signing certificates, so the operating system may show a warning. | |
| prerelease: true | |
| releaseDraft: false | |
| generateReleaseNotes: true | |
| updaterJsonPreferNsis: true | |
| uploadUpdaterJson: true | |
| uploadUpdaterSignatures: true | |
| retryAttempts: 2 | |
| - uses: actions/attest-build-provenance@v4 | |
| with: | |
| subject-path: "src-tauri/target/release/bundle/**/*" | |
| publish-manifest: | |
| name: Publish updater manifest and archive the core release | |
| needs: build | |
| runs-on: ubuntu-24.04 | |
| concurrency: | |
| group: living-release-writer | |
| cancel-in-progress: false | |
| steps: | |
| - uses: actions/checkout@v7 | |
| with: | |
| ref: main | |
| fetch-depth: 0 | |
| - uses: pnpm/action-setup@v6 | |
| with: | |
| version: 10.33.0 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 22.17.1 | |
| cache: pnpm | |
| - run: pnpm install --frozen-lockfile | |
| - name: Download merged updater manifest | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| mkdir -p .release | |
| gh release download "${{ github.ref_name }}" --pattern latest.json --dir .release | |
| cp .release/latest.json public/feed/core-latest.json | |
| - name: Record the core update in the living ledger | |
| env: | |
| CORE_VERSION: ${{ github.ref_name }} | |
| CAPSULE_SIGNING_PRIVATE_KEY: ${{ secrets.CAPSULE_SIGNING_PRIVATE_KEY }} | |
| run: node scripts/record-core-release.mjs | |
| - run: pnpm update:validate | |
| - name: Commit the immutable public pointers | |
| run: | | |
| git config user.name "updated-again-bot" | |
| git config user.email "41898282+github-actions[bot]@users.noreply.github.com" | |
| git add public/feed/core-latest.json public/feed/index.json public/updates | |
| git commit -m "chore(release): archive ${{ github.ref_name }}" | |
| git push origin HEAD:main |