-
Notifications
You must be signed in to change notification settings - Fork 2
189 lines (167 loc) · 7.41 KB
/
Copy pathrelease.yml
File metadata and controls
189 lines (167 loc) · 7.41 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
name: Build and Release
on:
push:
tags:
- 'v*'
workflow_dispatch:
inputs:
version:
description: 'Version tag (e.g., v2.0.0)'
required: true
default: 'v3.0.0'
permissions:
contents: write
jobs:
build:
name: Build (${{ matrix.arch_name }})
runs-on: windows-latest
strategy:
fail-fast: false
matrix:
include:
- rid: win-x64
platform: x64
arch_name: x64
- rid: win-arm64
platform: Arm64
arch_name: arm64
steps:
- name: Checkout Code
uses: actions/checkout@v4
- name: Setup .NET SDK
uses: actions/setup-dotnet@v4
with:
dotnet-version: '8.0.x'
- name: Sign Catalog Files (pinned-key catalog trust)
env:
CATALOG_SIGNING_KEY: ${{ secrets.CATALOG_SIGNING_KEY }}
shell: pwsh
run: |
if ([string]::IsNullOrWhiteSpace("$env:CATALOG_SIGNING_KEY")) {
Write-Host "CATALOG_SIGNING_KEY secret is not set. Catalog will ship unsigned - app versions fall back to the embedded catalog." -ForegroundColor Yellow
Write-Host "Generate a key with: openssl ecparam -name prime256v1 -genkey -noout -out catalog-signing-key.pem" -ForegroundColor Gray
exit 0
}
$keyPath = Join-Path $env:RUNNER_TEMP "catalog-signing-key.pem"
[IO.File]::WriteAllText($keyPath, "$env:CATALOG_SIGNING_KEY`n")
.\catalog\sign-catalog.ps1 -KeyPath $keyPath
Remove-Item $keyPath -Force
- name: Restore NuGet Packages
run: dotnet restore src/DevOpsToolsInstaller/DevOpsToolsInstaller.csproj -r ${{ matrix.rid }}
- name: Publish Single-File Executable
run: |
dotnet publish src/DevOpsToolsInstaller/DevOpsToolsInstaller.csproj -c Release -r ${{ matrix.rid }} --self-contained true -p:PublishSingleFile=true -p:IncludeNativeLibrariesForSelfExtract=true -p:WindowsAppSDKSelfContained=true -p:EnableCompressionInSingleFile=true -p:Platform=${{ matrix.platform }} -o publish_out
- name: Rename Executable
shell: pwsh
run: |
Copy-Item -Path "publish_out\DevOpsToolsInstaller.exe" -Destination "publish_out\DevOpsToolsInstaller_${{ matrix.arch_name }}.exe"
- name: Build Windows Setup Wizard (x64)
if: matrix.arch_name == 'x64'
shell: pwsh
run: |
$iscc = "C:\Program Files (x86)\Inno Setup 6\ISCC.exe"
if (-not (Test-Path $iscc)) {
$iscc = (Get-Command ISCC.exe -ErrorAction SilentlyContinue).Source
}
Write-Host "Compiling Inno Setup wizard with $iscc..."
$sourceDir = (Resolve-Path "publish_out").Path
if (-not (Test-Path "dist")) { New-Item -ItemType Directory -Path "dist" -Force | Out-Null }
$outDir = (Resolve-Path "dist").Path
& $iscc "/DSourceDir=$sourceDir" "/DOutputDir=$outDir" "/DOutputBaseFilename=DevOpsToolsInstaller_x64_Setup" "installer/setup.iss"
Move-Item -Path "dist\DevOpsToolsInstaller_x64_Setup.exe" -Destination "publish_out\" -Force
- name: Build Windows Installer (.msi) (x64)
if: matrix.arch_name == 'x64'
shell: pwsh
run: |
Write-Host "Installing WiX Toolset v5..."
dotnet tool install --global wix --version 5.0.2
wix extension add -g WixToolset.UI.wixext/5.0.2
$ver = "3.0.0"
if ($env:GITHUB_REF_NAME -match '^v?(\d+\.\d+\.\d+)') {
$ver = $Matches[1]
}
Write-Host "Compiling WiX .msi package (v$ver)..."
$sourceDir = (Resolve-Path "publish_out").Path
$assetsDir = (Resolve-Path "src/DevOpsToolsInstaller/Assets").Path
wix build "installer/setup.wxs" -ext WixToolset.UI.wixext -arch x64 -d "SourceDir=$sourceDir" -d "AssetsDir=$assetsDir" -d "AppVersion=$ver" -o "publish_out/DevOpsToolsInstaller_x64.msi"
- name: Sign Binaries, Setup Wizard & MSI (Authenticode)
shell: pwsh
env:
SIGNING_CERTIFICATE: ${{ secrets.SIGNING_CERTIFICATE }}
SIGNING_PASSWORD: ${{ secrets.SIGNING_PASSWORD }}
run: |
if (-not $env:SIGNING_CERTIFICATE) {
Write-Host "SIGNING_CERTIFICATE secret is not set. Binaries will not be code-signed." -ForegroundColor Yellow
Write-Host "To enable code signing, add base64-encoded PFX to repository secret 'SIGNING_CERTIFICATE'." -ForegroundColor Gray
} else {
$toSign = @("publish_out\DevOpsToolsInstaller_${{ matrix.arch_name }}.exe")
if (Test-Path "publish_out\DevOpsToolsInstaller_${{ matrix.arch_name }}_Setup.exe") {
$toSign += "publish_out\DevOpsToolsInstaller_${{ matrix.arch_name }}_Setup.exe"
}
if (Test-Path "publish_out\DevOpsToolsInstaller_${{ matrix.arch_name }}.msi") {
$toSign += "publish_out\DevOpsToolsInstaller_${{ matrix.arch_name }}.msi"
}
.\scripts\sign-binaries.ps1 -Files $toSign -Base64Cert "$env:SIGNING_CERTIFICATE" -Password "$env:SIGNING_PASSWORD"
}
- name: Upload Binary Artifact
uses: actions/upload-artifact@v4
with:
name: binary-${{ matrix.arch_name }}
path: publish_out/DevOpsToolsInstaller_${{ matrix.arch_name }}.exe
if-no-files-found: error
- name: Upload Setup Wizard Artifact
if: matrix.arch_name == 'x64'
uses: actions/upload-artifact@v4
with:
name: setup-${{ matrix.arch_name }}
path: publish_out/DevOpsToolsInstaller_${{ matrix.arch_name }}_Setup.exe
if-no-files-found: error
- name: Upload MSI Artifact
if: matrix.arch_name == 'x64'
uses: actions/upload-artifact@v4
with:
name: msi-${{ matrix.arch_name }}
path: publish_out/DevOpsToolsInstaller_${{ matrix.arch_name }}.msi
if-no-files-found: error
release:
name: Create GitHub Release
needs: build
runs-on: windows-latest
steps:
- name: Checkout Code
uses: actions/checkout@v4
- name: Determine Release Tag
id: get_tag
shell: bash
run: |
if [ "${{ github.event_name }}" = "workflow_dispatch" ]; then
echo "tag=${{ inputs.version }}" >> $GITHUB_OUTPUT
else
echo "tag=${{ github.ref_name }}" >> $GITHUB_OUTPUT
fi
- name: Download All Artifacts
uses: actions/download-artifact@v4
with:
path: release_assets
merge-multiple: true
- name: Generate Checksums and Release Notes
shell: pwsh
run: |
.\.github\workflows\generate-release-notes.ps1 -Tag "${{ steps.get_tag.outputs.tag }}" -AssetsDir "release_assets" -OutputFile "release_notes.md"
- name: Publish GitHub Release
uses: softprops/action-gh-release@v2
with:
tag_name: ${{ steps.get_tag.outputs.tag }}
name: Release ${{ steps.get_tag.outputs.tag }}
body_path: release_notes.md
files: |
release_assets/DevOpsToolsInstaller_x64_Setup.exe
release_assets/DevOpsToolsInstaller_x64.msi
release_assets/DevOpsToolsInstaller_x64.exe
release_assets/DevOpsToolsInstaller_arm64.exe
release_assets/SHA256SUMS.txt
draft: false
prerelease: false
generate_release_notes: true
env:
GITHUB_TOKEN: ${{ secrets.GH_TOKEN || secrets.GITHUB_TOKEN }}