-
-
Notifications
You must be signed in to change notification settings - Fork 1.1k
258 lines (227 loc) · 8.85 KB
/
Copy pathrelease.yml
File metadata and controls
258 lines (227 loc) · 8.85 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
# You'll need to setup the follwing environment variables:
# secrets.REPO_TOKEN - A GitHub token with permissions to push and publish releases to the repo
name: Release builds (APK/EXE/DMG/DEB)
on:
workflow_dispatch:
inputs:
title:
description: 'Title to assign to the release'
required: true
type: string
tag:
description: 'Tag to assign to the release source code'
required: true
type: string
generate_release_notes:
description: 'Generate release notes?'
required: true
type: boolean
jobs:
desktop:
name: Tauri desktop build (${{ matrix.os }})
strategy:
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Setup Node
uses: actions/setup-node@v5
with:
node-version-file: '.nvmrc'
cache: 'yarn'
- name: Install dependencies
run: yarn install --frozen-lockfile
- name: Build desktop bundles (Tauri)
uses: tauri-apps/tauri-action@v0
with:
tauriScript: yarn tauri:build
- name: Upload desktop artifacts
uses: actions/upload-artifact@v4
with:
name: betaflight-desktop-${{ matrix.os }}
path: |
src-tauri/target/release/bundle/**/*.deb
src-tauri/target/release/bundle/**/*.AppImage
src-tauri/target/release/bundle/**/*.dmg
src-tauri/target/release/bundle/**/*.msi
src-tauri/target/release/bundle/**/*.exe
if-no-files-found: warn
retention-days: 30
android:
name: Android APK (Tauri)
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Setup Node
uses: actions/setup-node@v5
with:
node-version-file: '.nvmrc'
cache: 'yarn'
- name: Install dependencies
run: yarn install --frozen-lockfile
- name: Setup Android SDK
uses: android-actions/setup-android@v3
- name: Setup Java 21
uses: actions/setup-java@v5
with:
distribution: temurin
java-version: '21'
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@stable
with:
targets: aarch64-linux-android,armv7-linux-androideabi,i686-linux-android,x86_64-linux-android
- name: Setup Rust cache
uses: Swatinem/rust-cache@v2
with:
workspaces: src-tauri
- name: Cache Gradle
uses: actions/cache@v4
with:
path: |
~/.gradle/caches
~/.gradle/wrapper
key: ${{ runner.os }}-gradle-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
restore-keys: |
${{ runner.os }}-gradle-
- name: Ensure JitPack repository (for usb-serial-for-android)
shell: bash
run: |
set -euo pipefail
FILE="src-tauri/gen/android/build.gradle.kts"
if [ -f "$FILE" ]; then
echo "Ensuring JitPack repository is present in $FILE"
if ! grep -q 'jitpack.io' "$FILE"; then
printf '\nallprojects {\n repositories {\n maven(url = "https://jitpack.io")\n }\n}\n' >> "$FILE"
fi
grep -n "jitpack.io" "$FILE" || true
else
echo "Warning: $FILE not found (will be generated by Tauri on first build)."
fi
- name: Build Android release (unsigned)
run: |
yarn tauri:build:android
- name: Setup release keystore (if available)
if: ${{ secrets.ANDROID_KEYSTORE_BASE64 != '' }}
env:
ANDROID_KEYSTORE_BASE64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }}
ANDROID_KEYSTORE_PASSWORD: ${{ secrets.ANDROID_KEYSTORE_PASSWORD }}
ANDROID_KEY_ALIAS: ${{ secrets.ANDROID_KEY_ALIAS }}
ANDROID_KEY_PASSWORD: ${{ secrets.ANDROID_KEY_PASSWORD }}
shell: bash
run: |
set -euo pipefail
echo "Setting up release keystore from secrets"
echo "$ANDROID_KEYSTORE_BASE64" | base64 -d > release.keystore
echo "KEYSTORE_PATH=$(pwd)/release.keystore" >> $GITHUB_ENV
echo "KEYSTORE_PASSWORD=$ANDROID_KEYSTORE_PASSWORD" >> $GITHUB_ENV
echo "KEY_ALIAS=$ANDROID_KEY_ALIAS" >> $GITHUB_ENV
echo "KEY_PASSWORD=$ANDROID_KEY_PASSWORD" >> $GITHUB_ENV
- name: Sign APK/AAB (release or debug)
shell: bash
run: |
set -euo pipefail
# Determine signing configuration
if [ -f "release.keystore" ]; then
echo "Using release keystore for signing"
KEYSTORE="release.keystore"
STORE_PASS="${KEYSTORE_PASSWORD}"
KEY_ALIAS="${KEY_ALIAS}"
KEY_PASS="${KEY_PASSWORD}"
SUFFIX="release-signed"
else
echo "No release keystore found - using debug keystore"
mkdir -p "${HOME}/.android"
KEYSTORE="${HOME}/.android/debug.keystore"
if [ ! -f "$KEYSTORE" ]; then
echo "Generating debug keystore"
keytool -genkeypair -v \
-keystore "$KEYSTORE" \
-storepass android \
-alias androiddebugkey \
-keypass android \
-keyalg RSA \
-keysize 2048 \
-validity 10000 \
-dname "CN=Android Debug,O=Android,C=US"
fi
STORE_PASS="android"
KEY_ALIAS="androiddebugkey"
KEY_PASS="android"
SUFFIX="debug-signed"
fi
# Sign APK
UNSIGNED_APK=$(find src-tauri/gen/android/app/build/outputs/apk -name "*-unsigned.apk" | head -1)
if [ -n "$UNSIGNED_APK" ]; then
echo "Signing APK: $UNSIGNED_APK"
SIGNED_APK="${UNSIGNED_APK%-unsigned.apk}-${SUFFIX}.apk"
ALIGNED_APK="${UNSIGNED_APK%-unsigned.apk}-aligned.apk"
# First zipalign the unsigned APK
echo "Zipaligning APK..."
BUILD_TOOLS_VERSION=$(ls ${ANDROID_HOME}/build-tools | tail -1)
${ANDROID_HOME}/build-tools/${BUILD_TOOLS_VERSION}/zipalign -v -p 4 "$UNSIGNED_APK" "$ALIGNED_APK"
# Then sign the aligned APK with v2/v3 signatures using apksigner
echo "Signing aligned APK..."
${ANDROID_HOME}/build-tools/${BUILD_TOOLS_VERSION}/apksigner sign \
--ks "$KEYSTORE" \
--ks-key-alias "$KEY_ALIAS" \
--ks-pass pass:"$STORE_PASS" \
--key-pass pass:"$KEY_PASS" \
--v1-signing-enabled true \
--out "$SIGNED_APK" \
"$ALIGNED_APK"
echo "Signed APK created: $SIGNED_APK"
ls -lh "$SIGNED_APK"
# Verify the signature
${ANDROID_HOME}/build-tools/${BUILD_TOOLS_VERSION}/apksigner verify --verbose --print-certs "$SIGNED_APK"
else
echo "Warning: No unsigned APK found"
fi
# Sign AAB (if release keystore available)
if [ -f "release.keystore" ]; then
UNSIGNED_AAB=$(find src-tauri/gen/android/app/build/outputs/bundle -name "*.aab" | head -1)
if [ -n "$UNSIGNED_AAB" ]; then
echo "Signing AAB: $UNSIGNED_AAB"
SIGNED_AAB="${UNSIGNED_AAB%.aab}-signed.aab"
jarsigner -verbose -sigalg SHA256withRSA -digestalg SHA-256 \
-keystore "$KEYSTORE" \
-storepass "$STORE_PASS" \
-keypass "$KEY_PASS" \
"$UNSIGNED_AAB" \
"$KEY_ALIAS"
mv "$UNSIGNED_AAB" "$SIGNED_AAB"
echo "Signed AAB created: $SIGNED_AAB"
ls -lh "$SIGNED_AAB"
fi
fi
- name: Upload APK/AAB artifacts
uses: actions/upload-artifact@v4
with:
name: betaflight-android
path: |
src-tauri/gen/android/app/build/outputs/apk/universal/release/*-signed.apk
src-tauri/gen/android/app/build/outputs/bundle/universalRelease/*-signed.aab
if-no-files-found: warn
retention-days: 30
publish:
name: Create GitHub Release
needs: [desktop, android]
runs-on: ubuntu-latest
steps:
- name: Download all artifacts
uses: actions/download-artifact@v5
with:
path: release-assets/
- name: Release
uses: softprops/action-gh-release@v2
with:
token: ${{ secrets.GITHUB_TOKEN }}
name: ${{ github.event.inputs.title }}
tag_name: ${{ github.event.inputs.tag }}
generate_release_notes: ${{ github.event.inputs.generate_release_notes }}
files: release-assets/**
draft: true
prerelease: false
fail_on_unmatched_files: false