Skip to content

chore(one): bump to 6.0.5 #12

chore(one): bump to 6.0.5

chore(one): bump to 6.0.5 #12

Workflow file for this run

name: one
on:
push:
tags:
- 'one-v*'
workflow_dispatch:
inputs:
release:
description: 'Create a draft GitHub release with the artifacts'
type: boolean
default: false
permissions:
contents: write
jobs:
build:
name: ${{ matrix.label }}
runs-on: ${{ matrix.os }}
timeout-minutes: 45
strategy:
fail-fast: false
matrix:
include:
- label: macOS (arm64)
os: macos-14
target: aarch64-apple-darwin
target-arch: arm64
bundle-dir: macos
- label: macOS (x64)
os: macos-14
target: x86_64-apple-darwin
target-arch: x64
bundle-dir: macos
- label: Windows (x64)
os: windows-2022
target: x86_64-pc-windows-msvc
target-arch: x64
bundle-dir: nsis
- label: Linux (x64)
os: ubuntu-22.04
target: x86_64-unknown-linux-gnu
target-arch: x64
bundle-dir: deb
steps:
- uses: actions/checkout@v4
- name: Linux build deps
if: runner.os == 'Linux'
run: |
sudo apt-get update
sudo apt-get install -y \
libwebkit2gtk-4.1-dev libssl-dev libayatana-appindicator3-dev \
librsvg2-dev patchelf libgtk-3-dev libsoup-3.0-dev
- uses: pnpm/action-setup@v4
with:
version: 10.28.2
- uses: actions/setup-node@v4
with:
node-version: 20
cache: pnpm
- uses: dtolnay/rust-toolchain@stable
with:
targets: ${{ matrix.target }}
- uses: Swatinem/rust-cache@v2
with:
workspaces: apps/objectos-one/src-tauri
- name: Install workspace deps
run: pnpm install --frozen-lockfile
- name: Stage Node runtime
env:
TARGET_ARCH: ${{ matrix.target-arch }}
run: pnpm --filter @objectos/one stage
- name: Import Apple signing certificate
if: runner.os == 'macOS'
env:
APPLE_CERTIFICATE: ${{ secrets.APPLE_CERTIFICATE }}
APPLE_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }}
run: |
set -euo pipefail
if [ -z "${APPLE_CERTIFICATE:-}" ]; then
echo "APPLE_CERTIFICATE not set — skipping (build will be unsigned)."
exit 0
fi
KEYCHAIN="$RUNNER_TEMP/build.keychain-db"
KEYCHAIN_PASSWORD="$(openssl rand -base64 24)"
CERT_PATH="$RUNNER_TEMP/cert.p12"
echo "$APPLE_CERTIFICATE" | base64 --decode > "$CERT_PATH"
security create-keychain -p "$KEYCHAIN_PASSWORD" "$KEYCHAIN"
security set-keychain-settings -lut 21600 "$KEYCHAIN"
security unlock-keychain -p "$KEYCHAIN_PASSWORD" "$KEYCHAIN"
security import "$CERT_PATH" -k "$KEYCHAIN" \
-P "$APPLE_CERTIFICATE_PASSWORD" \
-T /usr/bin/codesign -T /usr/bin/security -T /usr/bin/productbuild
security set-key-partition-list \
-S apple-tool:,apple:,codesign: \
-s -k "$KEYCHAIN_PASSWORD" "$KEYCHAIN" >/dev/null
# Put new keychain first in the search list (keep existing ones too).
security list-keychains -d user -s "$KEYCHAIN" $(security list-keychains -d user | tr -d '"')
echo "Available signing identities:"
security find-identity -v -p codesigning "$KEYCHAIN"
rm -f "$CERT_PATH"
- name: Debug Apple secret presence
if: runner.os == 'macOS'
env:
APPLE_SIGNING_IDENTITY: ${{ secrets.APPLE_SIGNING_IDENTITY }}
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
APPLE_ID: ${{ secrets.APPLE_ID }}
APPLE_PASSWORD: ${{ secrets.APPLE_PASSWORD }}
APPLE_CERTIFICATE: ${{ secrets.APPLE_CERTIFICATE }}
APPLE_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }}
run: |
# Print only the byte-length of each Apple secret so we can
# tell whether the value reached the runner without leaking it.
echo "APPLE_CERTIFICATE length=${#APPLE_CERTIFICATE}"
echo "APPLE_CERTIFICATE_PASSWORD length=${#APPLE_CERTIFICATE_PASSWORD}"
echo "APPLE_SIGNING_IDENTITY length=${#APPLE_SIGNING_IDENTITY}"
echo "APPLE_TEAM_ID length=${#APPLE_TEAM_ID}"
echo "APPLE_ID length=${#APPLE_ID}"
echo "APPLE_PASSWORD length=${#APPLE_PASSWORD}"
- name: Build Tauri bundle
env:
# AppImage tools need FUSE on Linux; ubuntu-22.04 dropped it.
# Setting this forces AppImage runtime to extract-and-run instead.
APPIMAGE_EXTRACT_AND_RUN: "1"
# Tauri updater key (no-password key generated via `signer generate --ci`).
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ""
# macOS code signing (only used if cert was imported above).
APPLE_SIGNING_IDENTITY: ${{ secrets.APPLE_SIGNING_IDENTITY }}
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
# macOS notarization (only triggered if APPLE_ID + APPLE_PASSWORD are set).
APPLE_ID: ${{ secrets.APPLE_ID }}
APPLE_PASSWORD: ${{ secrets.APPLE_PASSWORD }}
shell: bash
run: |
set -euo pipefail
# Tauri treats any defined APPLE_ID/APPLE_PASSWORD as a request to
# notarize; unset them when empty so we just sign without notarizing.
if [ -z "${APPLE_ID:-}" ] || [ -z "${APPLE_PASSWORD:-}" ]; then
unset APPLE_ID APPLE_PASSWORD
echo "APPLE_ID/APPLE_PASSWORD not set — will sign without notarization."
fi
pnpm --filter @objectos/one tauri build --target ${{ matrix.target }}
- name: Upload artifacts
uses: actions/upload-artifact@v4
with:
name: objectos-one-${{ matrix.target }}
path: |
apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*.dmg
apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*-setup.exe
apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*.msi
apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*.deb
apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*.app.tar.gz
apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*.nsis.zip
apps/objectos-one/src-tauri/target/${{ matrix.target }}/release/bundle/**/*.sig
if-no-files-found: warn
release:
name: Draft release
needs: build
if: startsWith(github.ref, 'refs/tags/one-v') || inputs.release
runs-on: ubuntu-22.04
steps:
- uses: actions/checkout@v4
- uses: actions/download-artifact@v4
with:
path: artifacts
- name: Generate latest.json (updater manifest)
env:
TAG: ${{ github.ref_name }}
run: node .github/scripts/build-update-manifest.mjs artifacts "$TAG" > artifacts/latest.json
- name: Create draft release
uses: softprops/action-gh-release@v2
with:
draft: true
generate_release_notes: true
name: ObjectOS One ${{ github.ref_name }}
files: |
artifacts/**/*.dmg
artifacts/**/*-setup.exe
artifacts/**/*.msi
artifacts/**/*.deb
artifacts/**/*.app.tar.gz
artifacts/**/*.nsis.zip
artifacts/**/*.sig
artifacts/latest.json