-
Notifications
You must be signed in to change notification settings - Fork 0
154 lines (125 loc) · 5.7 KB
/
Copy pathrelease.yml
File metadata and controls
154 lines (125 loc) · 5.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
name: release
on:
push:
tags:
- "v*.*.*"
permissions:
contents: write
jobs:
windows-release:
runs-on: windows-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
submodules: false
- name: Setup Node.js (20 LTS)
uses: actions/setup-node@v4
with:
node-version: "20"
cache: npm
- name: Setup Python
uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Setup Rust (stable)
uses: dtolnay/rust-toolchain@stable
- name: Install frontend dependencies
run: npm ci
- name: Checkout tutor core (no submodule)
uses: actions/checkout@v4
with:
repository: aryanbarak/fiae-tutor-core
path: fiae-tutor-core
fetch-depth: 1
- name: Export-sync tutor resources
shell: pwsh
run: |
Set-StrictMode -Version Latest
$ErrorActionPreference = 'Stop'
python -m pip install -U pip
python -m pip install -e .\fiae-tutor-core
python -m fiae_tutor.export.tutor_static --out .\_build\tutor
if (Test-Path .\src-tauri\resources\tutor\*) {
Remove-Item -Recurse -Force .\src-tauri\resources\tutor\* -ErrorAction SilentlyContinue
}
New-Item -ItemType Directory -Force -Path .\src-tauri\resources\tutor | Out-Null
Copy-Item -Recurse .\_build\tutor\* .\src-tauri\resources\tutor\
if (!(Test-Path .\src-tauri\resources\tutor\topics)) {
throw 'Missing topics folder after export'
}
Push-Location .\src-tauri\resources\tutor
if (-not (Test-Path .\manifest.json)) { throw 'manifest.json missing after export-sync' }
if (-not (Test-Path .\index.json)) { throw 'index.json missing after export-sync' }
if (-not (Get-ChildItem .\topics -Directory | Select-Object -First 1)) {
throw 'topics/* missing after export-sync'
}
Pop-Location
- name: Build Tauri installers + updater metadata
env:
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }}
run: npm run tauri build
- name: Validate and collect release assets
shell: pwsh
run: |
Set-StrictMode -Version Latest
$ErrorActionPreference = 'Stop'
$tag = $env:GITHUB_REF_NAME
$version = $tag.TrimStart('v')
$bundleRoot = Join-Path $env:GITHUB_WORKSPACE 'src-tauri\target\release\bundle'
$nsis = Get-ChildItem (Join-Path $bundleRoot 'nsis') -Filter 'CodeZertifikat_*setup.exe' -File | Sort-Object LastWriteTime -Descending | Select-Object -First 1
$msi = Get-ChildItem (Join-Path $bundleRoot 'msi') -Filter 'CodeZertifikat_*.msi' -File | Sort-Object LastWriteTime -Descending | Select-Object -First 1
if (-not $nsis) { throw 'NSIS installer not found' }
if (-not $msi) { throw 'MSI installer not found' }
$latest = Get-ChildItem $bundleRoot -Recurse -Filter 'latest.json' -File | Select-Object -First 1
if (-not $latest) { throw 'latest.json not found. Ensure createUpdaterArtifacts and signing env are set.' }
$latestJson = Get-Content $latest.FullName -Raw
if ($latestJson -notmatch ('"version"\s*:\s*"' + [regex]::Escape($version) + '"')) {
throw "latest.json version mismatch. Expected: $version"
}
$sigFiles = Get-ChildItem $bundleRoot -Recurse -Filter '*.sig' -File
if (-not $sigFiles) { throw 'No .sig signature files found' }
$releaseDir = Join-Path $env:GITHUB_WORKSPACE 'release_assets'
if (Test-Path $releaseDir) { Remove-Item -Recurse -Force $releaseDir }
New-Item -ItemType Directory -Path $releaseDir | Out-Null
Copy-Item $nsis.FullName (Join-Path $releaseDir $nsis.Name) -Force
Copy-Item $msi.FullName (Join-Path $releaseDir $msi.Name) -Force
Copy-Item $latest.FullName (Join-Path $releaseDir 'latest.json') -Force
$sigOut = Join-Path $releaseDir 'signatures'
New-Item -ItemType Directory -Path $sigOut | Out-Null
foreach ($sig in $sigFiles) {
Copy-Item $sig.FullName (Join-Path $sigOut $sig.Name) -Force
}
$shaLines = @()
$hashTargets = @(
(Join-Path $releaseDir $nsis.Name),
(Join-Path $releaseDir $msi.Name),
(Join-Path $releaseDir 'latest.json')
) + (Get-ChildItem $sigOut -File | Select-Object -ExpandProperty FullName)
foreach ($f in $hashTargets) {
$h = (Get-FileHash $f -Algorithm SHA256).Hash
$name = [IO.Path]::GetFileName($f)
$shaLines += "$h $name"
}
Set-Content (Join-Path $releaseDir 'SHA256SUMS.txt') -Value $shaLines
Write-Host 'Release asset list:'
Get-ChildItem $releaseDir -Recurse -File | ForEach-Object { Write-Host $_.FullName }
- name: Upload release assets as workflow artifact
uses: actions/upload-artifact@v4
with:
name: release-assets
path: release_assets/**
if-no-files-found: error
- name: Create GitHub release and upload assets
uses: softprops/action-gh-release@v2
with:
files: |
release_assets/CodeZertifikat_*setup.exe
release_assets/CodeZertifikat_*.msi
release_assets/latest.json
release_assets/signatures/*.sig
release_assets/SHA256SUMS.txt
generate_release_notes: true
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}