Repository navigation
Expand file tree
/
Copy pathelectron-builder.yml
More file actions
126 lines (126 loc) · 6.04 KB
/
Copy pathelectron-builder.yml
File metadata and controls
126 lines (126 loc) · 6.04 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
appId: com.knownote.app
productName: KnowNote
directories:
buildResources: build
files:
- '!**/.vscode/*'
- '!src/*'
- '!electron.vite.config.{js,ts,mjs,cjs}'
- '!{.eslintcache,eslint.config.mjs,.prettierignore,.prettierrc.yaml,dev-app-update.yml,CHANGELOG.md,README.md}'
- '!{.env,.env.*,.npmrc,package-lock.json}'
- '!{tsconfig.json,tsconfig.node.json,tsconfig.web.json}'
# Dev-only: test fixtures and build scripts are not part of the shipped app.
- '!{test,scripts}/*'
# PDF.js treats CMaps, standard fonts and the wasm image decoders as *external*
# assets fetched by filename. They ship as real files under
# `resources/pdfjs/`, outside app.asar, because both consumers need them there:
# the main-process loader reads them with `fs` (pdfjs resolves its own optional
# native peer that way), and the renderer reads them through the
# `knownote-asset://` protocol. Chromium cannot read inside app.asar, so these
# cannot ride along in the bundle. See `src/main/pdfjsAssetPaths.ts`.
extraResources:
- from: node_modules/pdfjs-dist/cmaps
to: pdfjs/cmaps
- from: node_modules/pdfjs-dist/standard_fonts
to: pdfjs/standard_fonts
- from: node_modules/pdfjs-dist/wasm
to: pdfjs/wasm
# Native modules must live outside the asar so they can be loaded by dlopen()
# AND so electron-builder signs them individually. Keep these patterns explicit:
# if a native module stays inside app.asar it cannot be signed or loaded.
asarUnpack:
- resources/**
- '**/*.node'
- '**/*.dylib'
- node_modules/better-sqlite3/**
- node_modules/sqlite-vec/**
- node_modules/sqlite-vec-*/**
# @huggingface/transformers pulls native onnxruntime-node (libonnxruntime.so/.dll/.dylib
# next to the .node binding) and sharp (@img/sharp-* platform packages with libvips
# binaries). Neither can be dlopen()ed from inside app.asar, so keep them on disk.
- node_modules/onnxruntime-node/**
- node_modules/sharp/**
- node_modules/@img/**
win:
executableName: knownote
nsis:
artifactName: ${name}-${version}-setup.${ext}
shortcutName: ${productName}
uninstallDisplayName: ${productName}
oneClick: false
allowToChangeInstallationDirectory: true
createDesktopShortcut: always
createStartMenuShortcut: true
deleteAppDataOnUninstall: false
mac:
# Applied to the main binary; entitlementsInherit propagates the same set to
# the Helper (GPU/Renderer/Plugin) processes. Both must point at the same
# file, otherwise a helper can reject a library the main process accepted.
entitlements: build/entitlements.mac.plist
entitlementsInherit: build/entitlements.mac.plist
hardenedRuntime: true
# Do not let electron-builder run spctl during the build: an ad-hoc signed
# build always fails that assessment and would abort packaging.
gatekeeperAssess: false
extendInfo:
- NSCameraUsageDescription: Application requests access to the device's camera.
- NSMicrophoneUsageDescription: Application requests access to the device's microphone.
- NSDocumentsFolderUsageDescription: Application requests access to the user's Documents folder.
- NSDownloadsFolderUsageDescription: Application requests access to the user's Downloads folder.
# Notarization requires an Apple Developer ID (MACOS_CERTIFICATE +
# APPLE_ID/APPLE_APP_SPECIFIC_PASSWORD/APPLE_TEAM_ID secrets). Left off so
# unsigned/community builds still ship; see .github/workflows/release.yml.
notarize: false
dmg:
# ${arch} is required: without it an arm64 and an x64 build both produce
# `knownote-<version>.dmg` and silently clobber each other on the release.
artifactName: ${name}-${version}-${arch}.${ext}
linux:
target:
- AppImage
- snap
- deb
maintainer: electronjs.org
category: Utility
appImage:
artifactName: ${name}-${version}.${ext}
# Fail the build when the dependency collector cannot resolve a production
# dependency, instead of only logging a warning (which is the v26 default).
# A missed dependency is invisible at build time and only surfaces as
# MODULE_NOT_FOUND on a user's machine - exactly how v1.2.1 broke. Requires
# electron-builder >= 26.16.0. Missing *optional* dependencies (e.g. fsevents on
# Linux/Windows) are still allowed and never fail the build.
allowMissingDependencies: false
# Every native dependency here is N-API, so electron-builder has nothing to
# rebuild: `better-sqlite3` (>= 13) ships a prebuild per platform/arch inside its
# own npm package, `onnxruntime-node` ships `bin/napi-v6/<platform>/<arch>`, and
# `sharp` / `@napi-rs/canvas` ship platform packages. N-API binaries are stable
# across Node and Electron versions, so rebuilding cannot improve them and can
# only replace a correct prebuild with a locally compiled one.
#
# Leaving this at the default (true) is what broke `npm install` on a plain
# Windows machine once the runtime moved to Electron 44 (ABI 149): published
# better-sqlite3 12.x prebuilds stop at ABI 146, so @electron/rebuild fell back
# to `node-gyp rebuild --build-from-source` and demanded Python + MSVC.
#
# Cross-arch still works because the prebuilds are shipped for every supported
# target: `better-sqlite3` carries darwin/linux/win32 prebuilds for x64 and
# arm64, and `onnxruntime-node` carries every platform in one package. The
# release matrix builds each artifact on its own architecture.
#
# `postinstall` no longer runs `electron-builder install-app-deps`: that command
# ignores this flag and always rebuilds, which would reintroduce the toolchain
# requirement for `npm install` even though nothing needs compiling.
npmRebuild: false
# Published as a DRAFT: electron-builder uploads the artifacts, but the release
# only becomes public after every platform built and the macOS artifact passed
# the verification step in .github/workflows/release.yml.
publish:
provider: github
owner: MrSibe
repo: KnowNote
releaseType: draft
# NOTE: no electronDownload.mirror on purpose. Pulling the Electron runtime
# from a third-party mirror makes the shipped signature non-reproducible and
# can mix differently-signed Electron binaries into the bundle. Developers who
# need a mirror should set ELECTRON_MIRROR in their own environment instead.