Skip to content

docs(mobile): record that the build is now byte-reproducible #3

docs(mobile): record that the build is now byte-reproducible

docs(mobile): record that the build is now byte-reproducible #3

Workflow file for this run

# .github/workflows/release.yml
#
# Sidecoin Release Pipeline
#
# Triggers on version tags. Builds desktop binaries for all
# platforms and deploys web properties to Cloudflare Pages.
#
# ALL jobs depend on the guardian CI suite passing first.
# Nothing ships with failing tests.
name: Release Sidecoin
on:
push:
tags:
- 'v[0-9]+.[0-9]+.[0-9]+*'
jobs:
# ── Gate: Run full CI suite first ─────────────────────────
ci-gate:
strategy:
fail-fast: true
matrix:
platform: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.platform }}
env:
WEBVIEW2_LINK_STATIC: "1"
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup pnpm
uses: pnpm/action-setup@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
cache: "pnpm"
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
with:
components: clippy, rustfmt, llvm-tools-preview
- name: Install cargo-llvm-cov
uses: taiki-e/install-action@cargo-llvm-cov
- name: Rust Cache
uses: Swatinem/rust-cache@v2
with:
key: ${{ runner.os }}-v2
workspaces: "./apps/desktop/src-tauri -> target"
- name: Install Linux dependencies
if: matrix.platform == 'ubuntu-latest'
run: |
sudo apt-get update
sudo apt-get install -y \
libwebkit2gtk-4.1-dev \
libappindicator3-dev \
librsvg2-dev \
patchelf \
xvfb \
webkit2gtk-driver
cargo install tauri-driver
- name: Install Frontend dependencies
run: pnpm install --frozen-lockfile
- name: Type-check Shared
run: pnpm --filter @sidecoin/shared build
- name: Build Web
run: pnpm --filter @sidecoin/web build
- name: Build Wallet
run: pnpm --filter @sidecoin/wallet build
- name: Build Explorer
run: pnpm --filter @sidecoin/explorer build
- name: Test Wallet
run: pnpm --filter @sidecoin/wallet test
- name: Type-check Wallet
run: pnpm --filter @sidecoin/wallet type-check
- name: Test Explorer
run: pnpm --filter @sidecoin/explorer test
- name: Type-check Explorer
run: pnpm --filter @sidecoin/explorer type-check
- name: Check Rust Formatting
working-directory: apps/desktop/src-tauri
run: cargo fmt --all -- --check
- name: Clippy Lint
working-directory: apps/desktop/src-tauri
run: cargo clippy --all-features --lib -- -D warnings
- name: Create Placeholder Dist
shell: bash
run: mkdir -p apps/desktop/dist && touch apps/desktop/dist/index.html
- name: Generate Types (Specta)
shell: bash
working-directory: apps/desktop/src-tauri
run: |
cargo run --bin export_types
node -e "
const fs = require('fs');
const path = require('path');
const f = path.join('..', 'src', 'bindings.ts');
if (fs.existsSync(f)) {
const content = fs.readFileSync(f, 'utf8');
if (!content.startsWith('//@ts-nocheck')) {
fs.writeFileSync(f, '//@ts-nocheck\n' + content);
}
}
"
- name: Build Desktop Frontend
run: pnpm --filter @sidecoin/desktop exec vite build
- name: Build Tauri App
working-directory: apps/desktop/src-tauri
run: cargo build --locked
- name: Run Rust Unit Tests (with coverage)
if: matrix.platform != 'windows-latest'
working-directory: apps/desktop/src-tauri
shell: bash
run: cargo llvm-cov --all-features --lib --lcov --output-path lcov-rust.info
- name: Run Desktop Frontend Tests
run: pnpm --filter @sidecoin/desktop test
- name: Run Desktop Type Check
run: pnpm --filter @sidecoin/desktop exec vue-tsc --noEmit --skipLibCheck
- name: Run Mobile Tests
if: matrix.platform == 'ubuntu-latest'
run: pnpm --filter @sidecoin/mobile test
- name: Run E2E Tests
if: matrix.platform == 'ubuntu-latest'
continue-on-error: true
env:
CI: true
GDK_BACKEND: x11
WEBKIT_DISABLE_COMPOSITING_MODE: "1"
shell: bash
run: xvfb-run --auto-servernum pnpm --filter @sidecoin/desktop test:e2e
# ── GitHub Release ────────────────────────────────────────
create-release:
needs: ci-gate
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Create Release
uses: softprops/action-gh-release@v2
with:
tag_name: ${{ github.ref_name }}
draft: true
files: |
LICENSE.md
README.md
body_path: CHANGELOG.md
# ── Desktop Builds ───────────────────────────────────────
build-linux:
needs: create-release
runs-on: ubuntu-latest
container:
image: ubuntu:22.04
options: --privileged
defaults:
run:
shell: bash
steps:
- uses: actions/checkout@v4
- name: Setup Environment
run: |
export DEBIAN_FRONTEND=noninteractive
apt-get update
apt-get install -y --no-install-recommends tzdata
- name: Install Dependencies
run: |
apt-get install -y --no-install-recommends \
curl wget build-essential pkg-config ca-certificates \
libwebkit2gtk-4.1-dev libjavascriptcoregtk-4.1-dev \
libglib2.0-dev libgtk-3-dev libappindicator3-dev \
librsvg2-dev libssl-dev patchelf libcairo2-dev \
libpango1.0-dev libatk1.0-dev libgdk-pixbuf2.0-dev \
libsoup-3.0-dev xdg-utils file desktop-file-utils libfuse2
- name: Install Node.js 22
run: |
curl -fsSL https://deb.nodesource.com/setup_22.x | bash -
apt-get install -y nodejs
- name: Install Rust
run: |
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y
source "$HOME/.cargo/env"
rustup target add x86_64-unknown-linux-gnu
echo "PATH=$HOME/.cargo/bin:$PATH" >> $GITHUB_ENV
- name: Install pnpm
run: npm install -g pnpm@9
- name: Install frontend dependencies
run: pnpm install --frozen-lockfile
- name: Generate Rust Types (The Bridge)
run: pnpm --filter @sidecoin/desktop type:gen
- name: Build Tauri Application
working-directory: apps/desktop
run: pnpm tauri build --verbose
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }}
- name: Upload Linux Artifacts
uses: softprops/action-gh-release@v2
with:
tag_name: ${{ github.ref_name }}
files: |
apps/desktop/src-tauri/target/release/bundle/appimage/*.AppImage
apps/desktop/src-tauri/target/release/bundle/deb/*.deb
apps/desktop/src-tauri/target/release/bundle/rpm/*.rpm
build-macos:
needs: create-release
runs-on: macos-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 22
- name: Install Rust stable
uses: dtolnay/rust-toolchain@stable
with:
targets: x86_64-apple-darwin, aarch64-apple-darwin
- name: Install pnpm
uses: pnpm/action-setup@v4
- name: Install frontend dependencies
run: pnpm install --frozen-lockfile
- name: Generate Rust Types (The Bridge)
run: pnpm --filter @sidecoin/desktop type:gen
- name: Prepare Universal Binary for Helper Tools
working-directory: apps/desktop/src-tauri
run: |
cargo build --release --bin export_types --target x86_64-apple-darwin
cargo build --release --bin export_types --target aarch64-apple-darwin
mkdir -p target/universal-apple-darwin/release
lipo -create \
-output target/universal-apple-darwin/release/export_types \
target/x86_64-apple-darwin/release/export_types \
target/aarch64-apple-darwin/release/export_types
- name: Build Tauri Application
working-directory: apps/desktop
run: pnpm tauri build --target universal-apple-darwin --verbose
env:
NODE_OPTIONS: --max-old-space-size=4096
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }}
- name: Upload macOS Artifact
uses: softprops/action-gh-release@v2
with:
tag_name: ${{ github.ref_name }}
files: apps/desktop/src-tauri/target/universal-apple-darwin/release/bundle/dmg/*.dmg
build-windows:
needs: create-release
runs-on: windows-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 22
- name: Install Rust stable
uses: dtolnay/rust-toolchain@stable
- name: Install pnpm
uses: pnpm/action-setup@v4
- name: Install frontend dependencies
run: pnpm install --frozen-lockfile
- name: Generate Rust Types (The Bridge)
run: pnpm --filter @sidecoin/desktop type:gen
shell: bash
- name: Build Application
working-directory: apps/desktop
run: pnpm tauri build --verbose
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }}
- name: Upload Windows Artifacts
uses: softprops/action-gh-release@v2
with:
tag_name: ${{ github.ref_name }}
files: |
apps/desktop/src-tauri/target/release/bundle/msi/*.msi
apps/desktop/src-tauri/target/release/bundle/nsis/*.exe
# ── Cloudflare Pages — Landing Site ──────────────────────
deploy-web:
needs: ci-gate
runs-on: ubuntu-latest
environment:
name: production-web
url: https://sidecoin.app
steps:
- uses: actions/checkout@v4
- name: Setup pnpm
uses: pnpm/action-setup@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
cache: "pnpm"
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Build Shared
run: pnpm --filter @sidecoin/shared build
- name: Build Web
run: pnpm --filter @sidecoin/web build
- name: Deploy to Cloudflare Pages
run: npx wrangler pages deploy apps/web/dist --project-name=sidecoin --commit-dirty=true
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
# ── Cloudflare Pages — Wallet App ────────────────────────
deploy-wallet:
needs: ci-gate
runs-on: ubuntu-latest
environment:
name: production-wallet
url: https://wallet.sidecoin.app
steps:
- uses: actions/checkout@v4
- name: Setup pnpm
uses: pnpm/action-setup@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
cache: "pnpm"
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Build Shared
run: pnpm --filter @sidecoin/shared build
- name: Build Wallet
run: pnpm --filter @sidecoin/wallet build
- name: Deploy to Cloudflare Pages
run: npx wrangler pages deploy apps/wallet/dist --project-name=sidecoin-wallet --commit-dirty=true
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
# ── Cloudflare Pages — Explorer App ──────────────────────
deploy-explorer:
needs: ci-gate
runs-on: ubuntu-latest
environment:
name: production-explorer
url: https://explorer.sidecoin.app
steps:
- uses: actions/checkout@v4
- name: Setup pnpm
uses: pnpm/action-setup@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
cache: "pnpm"
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Build Shared
run: pnpm --filter @sidecoin/shared build
- name: Build Explorer
run: pnpm --filter @sidecoin/explorer build
- name: Deploy to Cloudflare Pages
run: npx wrangler pages deploy apps/explorer/dist --project-name=sidecoin-explorer --commit-dirty=true
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
# ── Publish GitHub Release ───────────────────────────────
publish-release:
runs-on: ubuntu-latest
needs: [build-linux, build-macos, build-windows, deploy-web, deploy-wallet, deploy-explorer]
steps:
- name: Publish Release
uses: softprops/action-gh-release@v2
with:
tag_name: ${{ github.ref_name }}
draft: false