Skip to content

fix(ci): hash Windows assets via stdin #23

fix(ci): hash Windows assets via stdin

fix(ci): hash Windows assets via stdin #23

Workflow file for this run

name: Release
env:
CEF_BACKEND_TAG: cef-150.0.11-laufey-0.5.0
DENO_VERSION: v2.9.2
on:
push:
tags:
- "v*"
jobs:
build:
name: Build ${{ matrix.name }}
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
include:
- name: linux-x64
os: ubuntu-latest
target: x86_64-unknown-linux-gnu
- name: linux-arm64
os: ubuntu-24.04-arm
target: aarch64-unknown-linux-gnu
- name: darwin-x64
os: macos-15-intel
target: x86_64-apple-darwin
- name: darwin-arm64
os: macos-14
target: aarch64-apple-darwin
- name: windows-x64
os: windows-latest
target: x86_64-pc-windows-msvc
steps:
- uses: actions/checkout@v7
- uses: denoland/setup-deno@v2.0.5
with:
deno-version: ${{ env.DENO_VERSION }}
- name: Download CEF 150 backend
shell: bash
env:
GH_TOKEN: ${{ github.token }}
run: |
case "${{ matrix.target }}" in
*windows*) asset="laufey-cef-${{ matrix.target }}.zip" ;;
*) asset="laufey-cef-${{ matrix.target }}.tar.gz" ;;
esac
download_dir="$RUNNER_TEMP/laufey-download"
backend_dir="$RUNNER_TEMP/laufey/cef/build/Release"
mkdir -p "$download_dir" "$backend_dir"
gh release download "$CEF_BACKEND_TAG" \
--pattern "$asset" \
--dir "$download_dir"
expected=$(gh release view "$CEF_BACKEND_TAG" \
--repo "$GITHUB_REPOSITORY" \
--json assets \
--jq ".assets[] | select(.name == \"$asset\") | .digest | ltrimstr(\"sha256:\")" \
| tr -d '\r')
if [[ -z "$expected" ]]; then
echo "::error::No checksum found for $asset"
exit 1
fi
if command -v sha256sum >/dev/null; then
checksum=$(sha256sum < "$download_dir/$asset")
else
checksum=$(shasum -a 256 < "$download_dir/$asset")
fi
actual=${checksum%% *}
if [[ "$actual" != "$expected" ]]; then
echo "::error::Checksum mismatch for $asset (expected $expected, got $actual)"
exit 1
fi
if [[ "$asset" == *.zip ]]; then
7z x -y "$download_dir/$asset" "-o$backend_dir"
else
tar xzf "$download_dir/$asset" -C "$backend_dir"
fi
echo "LAUFEY_DEV_DIR=$RUNNER_TEMP/laufey" >> "$GITHUB_ENV"
- name: Build CSS
run: deno task css:build
- name: Build desktop app
shell: bash
run: |
compress=""
if [[ "${{ matrix.name }}" != darwin-* ]]; then
compress="--compress=zstd"
fi
deno desktop -A \
--unstable-no-legacy-abort \
--conditions browser \
--include static \
$compress \
--target "${{ matrix.target }}" \
src/main.ts
- name: Package artifact
shell: bash
run: |
case "${{ matrix.name }}" in
linux-*) mv dist/linux/pi-ui.AppImage "dist/pi-ui-${{ matrix.name }}.AppImage" ;;
windows-*) mv dist/windows/pi-ui.msi "dist/pi-ui-${{ matrix.name }}.msi" ;;
darwin-*) ditto -c -k --keepParent dist/macos/pi-ui.app "dist/pi-ui-${{ matrix.name }}.zip" ;;
esac
- name: Upload artifact
uses: actions/upload-artifact@v7
with:
name: ${{ matrix.name }}
path: dist/pi-ui-${{ matrix.name }}.*
publish:
name: Publish release and packages
needs: [build]
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v7
- uses: actions/download-artifact@v8
with:
path: dist
- name: Flatten artifacts
run: |
find dist -mindepth 2 -type f -exec mv {} dist/ \;
find dist -mindepth 1 -type d -empty -delete
ls -lh dist
- name: GitHub release
uses: softprops/action-gh-release@v3
with:
files: dist/*
generate_release_notes: true
- name: Compute checksums
id: sha
run: |
echo "linux-x64=$(sha256sum dist/pi-ui-linux-x64.AppImage | cut -d' ' -f1)" >> "$GITHUB_OUTPUT"
echo "linux-arm64=$(sha256sum dist/pi-ui-linux-arm64.AppImage | cut -d' ' -f1)" >> "$GITHUB_OUTPUT"
echo "darwin-x64=$(sha256sum dist/pi-ui-darwin-x64.zip | cut -d' ' -f1)" >> "$GITHUB_OUTPUT"
echo "darwin-arm64=$(sha256sum dist/pi-ui-darwin-arm64.zip | cut -d' ' -f1)" >> "$GITHUB_OUTPUT"
- name: Generate Homebrew cask
run: |
V="${GITHUB_REF_NAME#v}"
sed -e "s/{{VERSION}}/$V/g" \
-e "s/{{SHA_DARWIN_X64}}/${{ steps.sha.outputs.darwin-x64 }}/g" \
-e "s/{{SHA_DARWIN_ARM64}}/${{ steps.sha.outputs.darwin-arm64 }}/g" \
packaging/homebrew/pi-ui.rb.in > /tmp/pi-ui.rb
- name: Push Homebrew cask
env:
GH_PAT: ${{ secrets.GH_PAT }}
run: |
git clone "https://x-access-token:${GH_PAT}@github.com/hyperpuncher/homebrew-tap.git" /tmp/homebrew-tap
mkdir -p /tmp/homebrew-tap/Casks
cp /tmp/pi-ui.rb /tmp/homebrew-tap/Casks/pi-ui.rb
cd /tmp/homebrew-tap
git config user.name "github-actions"
git config user.email "github-actions@github.com"
git add Casks/pi-ui.rb
git diff --staged --quiet || git commit -m "pi-ui ${GITHUB_REF_NAME}"
git push
- name: Generate AUR package
run: |
V="${GITHUB_REF_NAME#v}"
sed -e "s/{{VERSION}}/$V/g" \
-e "s/{{SHA_LINUX_X64}}/${{ steps.sha.outputs.linux-x64 }}/g" \
-e "s/{{SHA_LINUX_ARM64}}/${{ steps.sha.outputs.linux-arm64 }}/g" \
packaging/aur/PKGBUILD.in > /tmp/PKGBUILD
sed -e "s/{{VERSION}}/$V/g" \
-e "s/{{SHA_LINUX_X64}}/${{ steps.sha.outputs.linux-x64 }}/g" \
-e "s/{{SHA_LINUX_ARM64}}/${{ steps.sha.outputs.linux-arm64 }}/g" \
packaging/aur/.SRCINFO.in > /tmp/.SRCINFO
- name: Push AUR package
env:
AUR_KEY: ${{ secrets.AUR_KEY }}
run: |
mkdir -p ~/.ssh
echo "$AUR_KEY" > ~/.ssh/aur_key
chmod 600 ~/.ssh/aur_key
ssh-keyscan -t ed25519,rsa aur.archlinux.org >> ~/.ssh/known_hosts
export GIT_SSH_COMMAND="ssh -i ~/.ssh/aur_key"
git clone ssh://aur@aur.archlinux.org/pi-ui-bin.git /tmp/aur-repo
cp /tmp/PKGBUILD /tmp/aur-repo/PKGBUILD
cp /tmp/.SRCINFO /tmp/aur-repo/.SRCINFO
cp icons/pi-logo.svg /tmp/aur-repo/pi-logo.svg
cp packaging/aur/pi-ui.desktop /tmp/aur-repo/pi-ui.desktop
cp LICENSE /tmp/aur-repo/LICENSE
cd /tmp/aur-repo
git config user.name "hyperpuncher"
git config user.email "hyperpuncher@users.noreply.github.com"
git add PKGBUILD .SRCINFO pi-logo.svg pi-ui.desktop LICENSE
git diff --staged --quiet || git commit -m "upgpkg: pi-ui-bin ${GITHUB_REF_NAME#v}"
git push