Repository navigation
148 lines (131 loc) · 5.4 KB
/
Copy pathrelease.yml
File metadata and controls
148 lines (131 loc) · 5.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
name: Build and Release
on:
push:
tags:
- "v*.*.*"
permissions:
contents: write
jobs:
release:
runs-on: ${{ matrix.os }}
# Job-level so every build step bakes the DSN into both bundles, and so the
# `if:` below can test whether the upload is configured at all.
env:
NEXT_PUBLIC_SENTRY_DSN: ${{ secrets.SENTRY_DSN }}
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
SENTRY_ORG: ${{ secrets.SENTRY_ORG }}
SENTRY_PROJECT: ${{ secrets.SENTRY_PROJECT }}
strategy:
fail-fast: false
matrix:
os: [macos-latest, ubuntu-latest, windows-latest]
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
cache: npm
- name: Install dependencies
run: npm ci
- name: Typecheck
run: |
npx next typegen
npx tsc --noEmit
npm run typecheck:electron
# macOS: decode the App Store Connect API key used for notarization.
- name: Setup Apple API key
if: matrix.os == 'macos-latest'
run: |
mkdir -p "$RUNNER_TEMP/private_keys"
echo "${{ secrets.APPLE_API_KEY }}" | base64 --decode > "$RUNNER_TEMP/private_keys/AuthKey_${{ secrets.APPLE_API_KEY_ID }}.p8"
chmod 600 "$RUNNER_TEMP/private_keys/AuthKey_${{ secrets.APPLE_API_KEY_ID }}.p8"
# macOS: build, sign (Developer ID), notarize, and publish to GitHub Releases.
- name: Build, sign & publish (macOS)
if: matrix.os == 'macos-latest'
run: npm run release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
CSC_LINK: ${{ secrets.CSC_LINK }}
CSC_KEY_PASSWORD: ${{ secrets.CSC_KEY_PASSWORD }}
APPLE_API_KEY: ${{ runner.temp }}/private_keys/AuthKey_${{ secrets.APPLE_API_KEY_ID }}.p8
APPLE_API_KEY_ID: ${{ secrets.APPLE_API_KEY_ID }}
APPLE_API_ISSUER: ${{ secrets.APPLE_API_ISSUER }}
# Windows / Linux: build (unsigned) and publish to GitHub Releases.
- name: Build & publish (Windows/Linux)
if: matrix.os != 'macos-latest'
run: npm run release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# Desktop stack traces are otherwise unreadable: the renderer is served
# from app:// and the main process is a single esbuild bundle, so Sentry
# can't fetch either map the way it can for the web build. Uploaded from
# one OS only — the bundles are byte-identical across the matrix, and the
# Sentry release is keyed on version, not platform.
# Never block a release on this: the installers are already published by the
# step above, and Sentry being unreachable shouldn't hold back a shipped
# build. --strict still makes a misconfigured upload loud in the log rather
# than silently uploading nothing.
- name: Upload source maps to Sentry
if: matrix.os == 'ubuntu-latest' && env.SENTRY_AUTH_TOKEN != ''
continue-on-error: true
run: |
VERSION="${GITHUB_REF_NAME#v}"
# Pinned to the v3 line: `releases files ... upload-sourcemaps` was
# removed in v3 in favour of `sourcemaps upload`, and an unpinned npx
# silently follows the next major into the same kind of breakage.
CLI="npx --yes @sentry/cli@3"
$CLI releases new "$VERSION"
# Rewriting is the default in v3 (there is only --no-rewrite now).
$CLI sourcemaps upload --release "$VERSION" \
--url-prefix "app:///_next" --strict out/_next
$CLI sourcemaps upload --release "$VERSION" \
--url-prefix "app:///electron-dist" --strict electron-dist
$CLI releases finalize "$VERSION"
# Flip the draft to published only after every OS build succeeds, so a release
# never goes live (or reaches auto-update) with partial artifacts.
publish:
needs: release
runs-on: ubuntu-latest
env:
AI_GATEWAY_API_KEY: ${{ secrets.AI_GATEWAY_API_KEY }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
cache: npm
- name: Install dependencies
run: npm ci
- name: Resolve previous tag
id: tags
run: |
CURRENT="${{ github.ref_name }}"
PREVIOUS=$(git tag --sort=-v:refname | grep -E '^v[0-9]' | grep -v "^${CURRENT}$" | head -1 || true)
echo "current=$CURRENT" >> "$GITHUB_OUTPUT"
echo "previous=$PREVIOUS" >> "$GITHUB_OUTPUT"
- name: Generate release notes
if: env.AI_GATEWAY_API_KEY != ''
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
ARGS=("${{ steps.tags.outputs.current }}")
if [ -n "${{ steps.tags.outputs.previous }}" ]; then
ARGS+=("${{ steps.tags.outputs.previous }}")
fi
npx tsx scripts/generate-release-notes.ts "${ARGS[@]}" --out release-notes.md
gh release edit "${{ github.ref_name }}" \
--repo wassgha/rescript \
--notes-file release-notes.md
- name: Publish the draft release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
gh release edit "${{ github.ref_name }}" \
--repo wassgha/rescript \
--draft=false --latest