Repository navigation
90 lines (79 loc) · 3.28 KB
/
Copy pathrelease.yml
File metadata and controls
90 lines (79 loc) · 3.28 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
name: Release
# Tagging is the release: `git tag v1.2.0 && git push --tags` builds the app and
# publishes it. Also runnable by hand to rehearse a build without tagging.
on:
push:
tags: ["v*"]
workflow_dispatch:
permissions:
contents: write
jobs:
build:
runs-on: macos-latest
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0 # build.sh reads tags and the commit count
- name: Build
run: ./build.sh
# Two assets: a DMG for people who just want to drag it to Applications,
# and a zip for scripted installs. `ditto` rather than `zip` for the
# latter — it preserves the bundle's symlinks and resource forks.
- name: Package
run: |
VERSION="${GITHUB_REF_NAME#v}"
[ "$GITHUB_REF_TYPE" = tag ] || VERSION="dev-${GITHUB_SHA::7}"
ditto -c -k --keepParent build/ScreenBox.app "ScreenBox-$VERSION.zip"
./scripts/make-dmg.sh "$VERSION"
mv "build/ScreenBox-$VERSION.dmg" .
echo "DMG=ScreenBox-$VERSION.dmg" >> "$GITHUB_ENV"
echo "ZIP=ScreenBox-$VERSION.zip" >> "$GITHUB_ENV"
- name: Upload build artifacts
uses: actions/upload-artifact@v7
with:
name: ScreenBox
path: |
${{ env.DMG }}
${{ env.ZIP }}
# The app is only ad-hoc signed, so Gatekeeper quarantines it on download.
# The release notes have to say how to get past that.
- name: Publish release
if: github.ref_type == 'tag'
env:
GH_TOKEN: ${{ github.token }}
run: |
# Re-running a tag build shouldn't fail the job just because the
# release already exists — replace the asset instead.
if gh release view "$GITHUB_REF_NAME" >/dev/null 2>&1; then
gh release upload "$GITHUB_REF_NAME" "$DMG" "$ZIP" --clobber
else
gh release create "$GITHUB_REF_NAME" "$DMG" "$ZIP" \
--title "$GITHUB_REF_NAME" \
--notes-file .github/install-notes.md \
--generate-notes
fi
# Homebrew installs come from Orva-Studio/homebrew-tap, which pins the
# version and the zip's checksum. Point it at the release we just made.
# TAP_TOKEN is a PAT with contents:write on that repo — github.token is
# scoped to this one and can't push there.
- name: Update the Homebrew cask
if: github.ref_type == 'tag'
env:
GH_TOKEN: ${{ secrets.TAP_TOKEN }}
run: |
VERSION="${GITHUB_REF_NAME#v}"
SHA=$(shasum -a 256 "$ZIP" | cut -d' ' -f1)
git clone --depth 1 \
"https://x-access-token:$GH_TOKEN@github.com/Orva-Studio/homebrew-tap.git" tap
CASK=tap/Casks/screenbox.rb
# Only the two pinned lines change; the rest of the cask is hand-kept.
sed -i '' \
-e "s|^ version \".*\"| version \"$VERSION\"|" \
-e "s|^ sha256 \".*\"| sha256 \"$SHA\"|" \
"$CASK"
cd tap
git diff --quiet && { echo "Cask already at $VERSION"; exit 0; }
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git commit -qam "Update ScreenBox to $VERSION"
git push -q