Repository navigation
chore(one): bump to 6.0.5 #12
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: one | |
| on: | |
| push: | |
| tags: | |
| - 'one-v*' | |
| workflow_dispatch: | |
| inputs: | |
| release: | |
| description: 'Create a draft GitHub release with the artifacts' | |
| type: boolean | |
| default: false | |
| permissions: | |
| contents: write | |
| jobs: | |
| build: | |
| name: ${{ matrix.label }} | |
| runs-on: ${{ matrix.os }} | |
| timeout-minutes: 45 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - label: macOS (arm64) | |
| os: macos-14 | |
| target: aarch64-apple-darwin | |
| target-arch: arm64 | |
| bundle-dir: macos | |
| - label: macOS (x64) | |
| os: macos-14 | |
| target: x86_64-apple-darwin | |
| target-arch: x64 | |
| bundle-dir: macos | |
| - label: Windows (x64) | |
| os: windows-2022 | |
| target: x86_64-pc-windows-msvc | |
| target-arch: x64 | |
| bundle-dir: nsis | |
| - label: Linux (x64) | |
| os: ubuntu-22.04 | |
| target: x86_64-unknown-linux-gnu | |
| target-arch: x64 | |
| bundle-dir: deb | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Linux build deps | |
| if: runner.os == 'Linux' | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y \ | |
| libwebkit2gtk-4.1-dev libssl-dev libayatana-appindicator3-dev \ | |
| librsvg2-dev patchelf libgtk-3-dev libsoup-3.0-dev | |
| - uses: pnpm/action-setup@v4 | |
| with: | |
| version: 10.28.2 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 20 | |
| cache: pnpm | |
| - uses: dtolnay/rust-toolchain@stable | |
| with: | |
| targets: ${{ matrix.target }} | |
| - uses: Swatinem/rust-cache@v2 | |
| with: | |
| workspaces: apps/objectos-one/src-tauri | |
| - name: Install workspace deps | |
| run: pnpm install --frozen-lockfile | |
| - name: Stage Node runtime | |
| env: | |
| TARGET_ARCH: ${{ matrix.target-arch }} | |
| run: pnpm --filter @objectos/one stage | |
| - name: Import Apple signing certificate | |
| if: runner.os == 'macOS' | |
| env: | |
| APPLE_CERTIFICATE: ${{ secrets.APPLE_CERTIFICATE }} | |
| APPLE_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }} | |
| run: | | |
| set -euo pipefail | |
| if [ -z "${APPLE_CERTIFICATE:-}" ]; then | |
| echo "APPLE_CERTIFICATE not set — skipping (build will be unsigned)." | |
| exit 0 | |
| fi | |
| KEYCHAIN="$RUNNER_TEMP/build.keychain-db" | |
| KEYCHAIN_PASSWORD="$(openssl rand -base64 24)" | |
| CERT_PATH="$RUNNER_TEMP/cert.p12" | |
| echo "$APPLE_CERTIFICATE" | base64 --decode > "$CERT_PATH" | |
| security create-keychain -p "$KEYCHAIN_PASSWORD" "$KEYCHAIN" | |
| security set-keychain-settings -lut 21600 "$KEYCHAIN" | |
| security unlock-keychain -p "$KEYCHAIN_PASSWORD" "$KEYCHAIN" | |
| security import "$CERT_PATH" -k "$KEYCHAIN" \ | |
| -P "$APPLE_CERTIFICATE_PASSWORD" \ | |
| -T /usr/bin/codesign -T /usr/bin/security -T /usr/bin/productbuild | |
| security set-key-partition-list \ | |
| -S apple-tool:,apple:,codesign: \ | |
| -s -k "$KEYCHAIN_PASSWORD" "$KEYCHAIN" >/dev/null | |
| # Put new keychain first in the search list (keep existing ones too). | |
| security list-keychains -d user -s "$KEYCHAIN" $(security list-keychains -d user | tr -d '"') | |
| echo "Available signing identities:" | |
| security find-identity -v -p codesigning "$KEYCHAIN" | |
| rm -f "$CERT_PATH" | |
| - name: Debug Apple secret presence | |
| if: runner.os == 'macOS' | |
| env: | |
| APPLE_SIGNING_IDENTITY: ${{ secrets.APPLE_SIGNING_IDENTITY }} | |
| APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }} | |
| APPLE_ID: ${{ secrets.APPLE_ID }} | |
| APPLE_PASSWORD: ${{ secrets.APPLE_PASSWORD }} | |
| APPLE_CERTIFICATE: ${{ secrets.APPLE_CERTIFICATE }} | |
| APPLE_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }} | |
| run: | | |
| # Print only the byte-length of each Apple secret so we can | |
| # tell whether the value reached the runner without leaking it. | |
| echo "APPLE_CERTIFICATE length=${#APPLE_CERTIFICATE}" | |
| echo "APPLE_CERTIFICATE_PASSWORD length=${#APPLE_CERTIFICATE_PASSWORD}" | |
| echo "APPLE_SIGNING_IDENTITY length=${#APPLE_SIGNING_IDENTITY}" | |
| echo "APPLE_TEAM_ID length=${#APPLE_TEAM_ID}" | |
| echo "APPLE_ID length=${#APPLE_ID}" | |
| echo "APPLE_PASSWORD length=${#APPLE_PASSWORD}" | |
| - name: Build Tauri bundle | |
| env: | |
| # AppImage tools need FUSE on Linux; ubuntu-22.04 dropped it. | |
| # Setting this forces AppImage runtime to extract-and-run instead. | |
| APPIMAGE_EXTRACT_AND_RUN: "1" | |
| # Tauri updater key (no-password key generated via `signer generate --ci`). | |
| TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }} | |
| TAURI_SIGNING_PRIVATE_KEY_PASSWORD: "" | |
| # macOS code signing (only used if cert was imported above). | |
| APPLE_SIGNING_IDENTITY: ${{ secrets.APPLE_SIGNING_IDENTITY }} | |
| APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }} | |
| # macOS notarization (only triggered if APPLE_ID + APPLE_PASSWORD are set). | |
| APPLE_ID: ${{ secrets.APPLE_ID }} | |
| APPLE_PASSWORD: ${{ secrets.APPLE_PASSWORD }} | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| # Tauri treats any defined APPLE_ID/APPLE_PASSWORD as a request to | |
| # notarize; unset them when empty so we just sign without notarizing. | |
| if [ -z "${APPLE_ID:-}" ] || [ -z "${APPLE_PASSWORD:-}" ]; then | |
| unset APPLE_ID APPLE_PASSWORD | |
| echo "APPLE_ID/APPLE_PASSWORD not set — will sign without notarization." | |
| fi | |
| pnpm --filter @objectos/one tauri build --target ${{ matrix.target }} | |
| - name: Upload artifacts | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: objectos-one-${{ matrix.target }} | |
| path: | | |
| apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*.dmg | |
| apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*-setup.exe | |
| apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*.msi | |
| apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*.deb | |
| apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*.app.tar.gz | |
| apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*.nsis.zip | |
| apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*.sig | |
| if-no-files-found: warn | |
| release: | |
| name: Draft release | |
| needs: build | |
| if: startsWith(github.ref, 'refs/tags/one-v') || inputs.release | |
| runs-on: ubuntu-22.04 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/download-artifact@v4 | |
| with: | |
| path: artifacts | |
| - name: Generate latest.json (updater manifest) | |
| env: | |
| TAG: ${{ github.ref_name }} | |
| run: node .github/scripts/build-update-manifest.mjs artifacts "$TAG" > artifacts/latest.json | |
| - name: Create draft release | |
| uses: softprops/action-gh-release@v2 | |
| with: | |
| draft: true | |
| generate_release_notes: true | |
| name: ObjectOS One ${{ github.ref_name }} | |
| files: | | |
| artifacts/**/*.dmg | |
| artifacts/**/*-setup.exe | |
| artifacts/**/*.msi | |
| artifacts/**/*.deb | |
| artifacts/**/*.app.tar.gz | |
| artifacts/**/*.nsis.zip | |
| artifacts/**/*.sig | |
| artifacts/latest.json |