Repository navigation
108 lines (97 loc) · 4.07 KB
/
Copy pathrelease.yml
File metadata and controls
108 lines (97 loc) · 4.07 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
name: Build standalone downloads
on:
workflow_dispatch:
inputs:
require_signing:
description: Require signed Windows and notarized macOS artifacts
type: boolean
required: true
default: false
# This workflow uploads CI artifacts only. It never publishes a release or site.
permissions:
contents: read
env:
COMETAPI_TEST_NATIVE_CREDENTIALS: '0'
jobs:
build:
strategy:
fail-fast: false
matrix:
include:
- runner: windows-2022
artifact: windows-x64
- runner: macos-14
artifact: macos-universal2
- runner: ubuntu-22.04
artifact: linux-x64
runs-on: ${{ matrix.runner }}
timeout-minutes: 45
env:
PYTHON_VERSION: '3.13.15'
PYTHON_MACOS_SHA256: '3b7eaf7f29825f796e8267024435540ddf1f17fc9a97ad58095daa7a75bfdcd3'
PYINSTALLER_VERSION: '6.22.2'
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
persist-credentials: false
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
with:
node-version: '22'
- name: Set up build Python (Windows and Linux only)
if: runner.os != 'macOS'
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
with:
python-version: ${{ env.PYTHON_VERSION }}
architecture: x64
- name: Install official universal2 build Python on macOS
if: runner.os == 'macOS'
shell: bash
run: |
package="$RUNNER_TEMP/python-universal2.pkg"
curl --fail --location --proto '=https' --tlsv1.2 \
"https://www.python.org/ftp/python/${PYTHON_VERSION}/python-${PYTHON_VERSION}-macos11.pkg" \
--output "$package"
printf '%s %s\n' "$PYTHON_MACOS_SHA256" "$package" | shasum -a 256 -c -
pkgutil --check-signature "$package" > "$RUNNER_TEMP/python-signature.txt"
grep -q 'Python Software Foundation' "$RUNNER_TEMP/python-signature.txt"
sudo installer -pkg "$package" -target /
/Library/Frameworks/Python.framework/Versions/3.13/bin/python3.13 -m venv .release-venv
echo "$GITHUB_WORKSPACE/.release-venv/bin" >> "$GITHUB_PATH"
lipo /Library/Frameworks/Python.framework/Versions/3.13/bin/python3.13 -verify_arch arm64 x86_64
- name: Install build dependencies
shell: bash
run: |
python -m pip install --upgrade pip
python -m pip install -r requirements.txt "pyinstaller==${PYINSTALLER_VERSION}" 'pytest>=8,<9'
python -m pip install --no-deps -e .
- name: Verify browser language matching
run: node tests/i18n.test.cjs
- name: Verify application tests
shell: bash
run: python -m pytest -q
- name: Build and verify bundled executable
shell: bash
env:
REQUIRE_SIGNING: ${{ inputs.require_signing }}
MACOS_CERTIFICATE_P12_BASE64: ${{ secrets.MACOS_CERTIFICATE_P12_BASE64 }}
MACOS_CERTIFICATE_PASSWORD: ${{ secrets.MACOS_CERTIFICATE_PASSWORD }}
MACOS_SIGNING_IDENTITY: ${{ secrets.MACOS_SIGNING_IDENTITY }}
MACOS_APPLE_ID: ${{ secrets.MACOS_APPLE_ID }}
MACOS_TEAM_ID: ${{ secrets.MACOS_TEAM_ID }}
MACOS_APP_PASSWORD: ${{ secrets.MACOS_APP_PASSWORD }}
WINDOWS_CERTIFICATE_PFX_BASE64: ${{ secrets.WINDOWS_CERTIFICATE_PFX_BASE64 }}
WINDOWS_CERTIFICATE_PASSWORD: ${{ secrets.WINDOWS_CERTIFICATE_PASSWORD }}
WINDOWS_TIMESTAMP_URL: ${{ vars.WINDOWS_TIMESTAMP_URL }}
run: |
if [ "$REQUIRE_SIGNING" = 'true' ]; then
python scripts/build_release.py --require-signing
else
python scripts/build_release.py
fi
- name: Upload standalone download, checksum, and build metadata
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: cometapi-connect-${{ matrix.artifact }}
path: dist/releases/*
if-no-files-found: error
retention-days: 14