fix(ci): hash Windows assets via stdin #23
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| env: | |
| CEF_BACKEND_TAG: cef-150.0.11-laufey-0.5.0 | |
| DENO_VERSION: v2.9.2 | |
| on: | |
| push: | |
| tags: | |
| - "v*" | |
| jobs: | |
| build: | |
| name: Build ${{ matrix.name }} | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - name: linux-x64 | |
| os: ubuntu-latest | |
| target: x86_64-unknown-linux-gnu | |
| - name: linux-arm64 | |
| os: ubuntu-24.04-arm | |
| target: aarch64-unknown-linux-gnu | |
| - name: darwin-x64 | |
| os: macos-15-intel | |
| target: x86_64-apple-darwin | |
| - name: darwin-arm64 | |
| os: macos-14 | |
| target: aarch64-apple-darwin | |
| - name: windows-x64 | |
| os: windows-latest | |
| target: x86_64-pc-windows-msvc | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: denoland/setup-deno@v2.0.5 | |
| with: | |
| deno-version: ${{ env.DENO_VERSION }} | |
| - name: Download CEF 150 backend | |
| shell: bash | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| case "${{ matrix.target }}" in | |
| *windows*) asset="laufey-cef-${{ matrix.target }}.zip" ;; | |
| *) asset="laufey-cef-${{ matrix.target }}.tar.gz" ;; | |
| esac | |
| download_dir="$RUNNER_TEMP/laufey-download" | |
| backend_dir="$RUNNER_TEMP/laufey/cef/build/Release" | |
| mkdir -p "$download_dir" "$backend_dir" | |
| gh release download "$CEF_BACKEND_TAG" \ | |
| --pattern "$asset" \ | |
| --dir "$download_dir" | |
| expected=$(gh release view "$CEF_BACKEND_TAG" \ | |
| --repo "$GITHUB_REPOSITORY" \ | |
| --json assets \ | |
| --jq ".assets[] | select(.name == \"$asset\") | .digest | ltrimstr(\"sha256:\")" \ | |
| | tr -d '\r') | |
| if [[ -z "$expected" ]]; then | |
| echo "::error::No checksum found for $asset" | |
| exit 1 | |
| fi | |
| if command -v sha256sum >/dev/null; then | |
| checksum=$(sha256sum < "$download_dir/$asset") | |
| else | |
| checksum=$(shasum -a 256 < "$download_dir/$asset") | |
| fi | |
| actual=${checksum%% *} | |
| if [[ "$actual" != "$expected" ]]; then | |
| echo "::error::Checksum mismatch for $asset (expected $expected, got $actual)" | |
| exit 1 | |
| fi | |
| if [[ "$asset" == *.zip ]]; then | |
| 7z x -y "$download_dir/$asset" "-o$backend_dir" | |
| else | |
| tar xzf "$download_dir/$asset" -C "$backend_dir" | |
| fi | |
| echo "LAUFEY_DEV_DIR=$RUNNER_TEMP/laufey" >> "$GITHUB_ENV" | |
| - name: Build CSS | |
| run: deno task css:build | |
| - name: Build desktop app | |
| shell: bash | |
| run: | | |
| compress="" | |
| if [[ "${{ matrix.name }}" != darwin-* ]]; then | |
| compress="--compress=zstd" | |
| fi | |
| deno desktop -A \ | |
| --unstable-no-legacy-abort \ | |
| --conditions browser \ | |
| --include static \ | |
| $compress \ | |
| --target "${{ matrix.target }}" \ | |
| src/main.ts | |
| - name: Package artifact | |
| shell: bash | |
| run: | | |
| case "${{ matrix.name }}" in | |
| linux-*) mv dist/linux/pi-ui.AppImage "dist/pi-ui-${{ matrix.name }}.AppImage" ;; | |
| windows-*) mv dist/windows/pi-ui.msi "dist/pi-ui-${{ matrix.name }}.msi" ;; | |
| darwin-*) ditto -c -k --keepParent dist/macos/pi-ui.app "dist/pi-ui-${{ matrix.name }}.zip" ;; | |
| esac | |
| - name: Upload artifact | |
| uses: actions/upload-artifact@v7 | |
| with: | |
| name: ${{ matrix.name }} | |
| path: dist/pi-ui-${{ matrix.name }}.* | |
| publish: | |
| name: Publish release and packages | |
| needs: [build] | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: actions/download-artifact@v8 | |
| with: | |
| path: dist | |
| - name: Flatten artifacts | |
| run: | | |
| find dist -mindepth 2 -type f -exec mv {} dist/ \; | |
| find dist -mindepth 1 -type d -empty -delete | |
| ls -lh dist | |
| - name: GitHub release | |
| uses: softprops/action-gh-release@v3 | |
| with: | |
| files: dist/* | |
| generate_release_notes: true | |
| - name: Compute checksums | |
| id: sha | |
| run: | | |
| echo "linux-x64=$(sha256sum dist/pi-ui-linux-x64.AppImage | cut -d' ' -f1)" >> "$GITHUB_OUTPUT" | |
| echo "linux-arm64=$(sha256sum dist/pi-ui-linux-arm64.AppImage | cut -d' ' -f1)" >> "$GITHUB_OUTPUT" | |
| echo "darwin-x64=$(sha256sum dist/pi-ui-darwin-x64.zip | cut -d' ' -f1)" >> "$GITHUB_OUTPUT" | |
| echo "darwin-arm64=$(sha256sum dist/pi-ui-darwin-arm64.zip | cut -d' ' -f1)" >> "$GITHUB_OUTPUT" | |
| - name: Generate Homebrew cask | |
| run: | | |
| V="${GITHUB_REF_NAME#v}" | |
| sed -e "s/{{VERSION}}/$V/g" \ | |
| -e "s/{{SHA_DARWIN_X64}}/${{ steps.sha.outputs.darwin-x64 }}/g" \ | |
| -e "s/{{SHA_DARWIN_ARM64}}/${{ steps.sha.outputs.darwin-arm64 }}/g" \ | |
| packaging/homebrew/pi-ui.rb.in > /tmp/pi-ui.rb | |
| - name: Push Homebrew cask | |
| env: | |
| GH_PAT: ${{ secrets.GH_PAT }} | |
| run: | | |
| git clone "https://x-access-token:${GH_PAT}@github.com/hyperpuncher/homebrew-tap.git" /tmp/homebrew-tap | |
| mkdir -p /tmp/homebrew-tap/Casks | |
| cp /tmp/pi-ui.rb /tmp/homebrew-tap/Casks/pi-ui.rb | |
| cd /tmp/homebrew-tap | |
| git config user.name "github-actions" | |
| git config user.email "github-actions@github.com" | |
| git add Casks/pi-ui.rb | |
| git diff --staged --quiet || git commit -m "pi-ui ${GITHUB_REF_NAME}" | |
| git push | |
| - name: Generate AUR package | |
| run: | | |
| V="${GITHUB_REF_NAME#v}" | |
| sed -e "s/{{VERSION}}/$V/g" \ | |
| -e "s/{{SHA_LINUX_X64}}/${{ steps.sha.outputs.linux-x64 }}/g" \ | |
| -e "s/{{SHA_LINUX_ARM64}}/${{ steps.sha.outputs.linux-arm64 }}/g" \ | |
| packaging/aur/PKGBUILD.in > /tmp/PKGBUILD | |
| sed -e "s/{{VERSION}}/$V/g" \ | |
| -e "s/{{SHA_LINUX_X64}}/${{ steps.sha.outputs.linux-x64 }}/g" \ | |
| -e "s/{{SHA_LINUX_ARM64}}/${{ steps.sha.outputs.linux-arm64 }}/g" \ | |
| packaging/aur/.SRCINFO.in > /tmp/.SRCINFO | |
| - name: Push AUR package | |
| env: | |
| AUR_KEY: ${{ secrets.AUR_KEY }} | |
| run: | | |
| mkdir -p ~/.ssh | |
| echo "$AUR_KEY" > ~/.ssh/aur_key | |
| chmod 600 ~/.ssh/aur_key | |
| ssh-keyscan -t ed25519,rsa aur.archlinux.org >> ~/.ssh/known_hosts | |
| export GIT_SSH_COMMAND="ssh -i ~/.ssh/aur_key" | |
| git clone ssh://aur@aur.archlinux.org/pi-ui-bin.git /tmp/aur-repo | |
| cp /tmp/PKGBUILD /tmp/aur-repo/PKGBUILD | |
| cp /tmp/.SRCINFO /tmp/aur-repo/.SRCINFO | |
| cp icons/pi-logo.svg /tmp/aur-repo/pi-logo.svg | |
| cp packaging/aur/pi-ui.desktop /tmp/aur-repo/pi-ui.desktop | |
| cp LICENSE /tmp/aur-repo/LICENSE | |
| cd /tmp/aur-repo | |
| git config user.name "hyperpuncher" | |
| git config user.email "hyperpuncher@users.noreply.github.com" | |
| git add PKGBUILD .SRCINFO pi-logo.svg pi-ui.desktop LICENSE | |
| git diff --staged --quiet || git commit -m "upgpkg: pi-ui-bin ${GITHUB_REF_NAME#v}" | |
| git push |