feat(desktop): three-platform packaging and CI matrix (M3) (#177)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,82 @@
|
||||
# Desktop packages (design § "桌面端原型 · 打包与更新", milestone M3).
|
||||
#
|
||||
# Reusable three-OS matrix: stage the pnpm-deploy app tree, run electron-builder, and
|
||||
# upload the installers as workflow artifacts named desktop-<OS>. release.yml calls this
|
||||
# BEFORE creating the Release — assets are immutable once published, so the desktop
|
||||
# installers must exist at creation time. workflow_dispatch runs it standalone as a dry
|
||||
# run on any branch.
|
||||
#
|
||||
# M3 ships unsigned artifacts; macOS signing/notarization, Windows code signing and
|
||||
# electron-updater are milestone M4.
|
||||
name: Desktop packages
|
||||
|
||||
on:
|
||||
workflow_call: {}
|
||||
workflow_dispatch: {}
|
||||
|
||||
env:
|
||||
# Keep in sync with release.yml (its header comment is the source of truth; duplicated
|
||||
# here because reusable workflows do not inherit the caller's env).
|
||||
MINGIT_VERSION: 2.55.0.3
|
||||
MINGIT_TAG: v2.55.0.windows.3
|
||||
|
||||
jobs:
|
||||
build:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- os: ubuntu-latest
|
||||
args: --linux
|
||||
- os: macos-latest
|
||||
args: --mac
|
||||
- os: windows-latest
|
||||
args: --win
|
||||
runs-on: ${{ matrix.os }}
|
||||
permissions:
|
||||
contents: read
|
||||
steps:
|
||||
- uses: actions/checkout@v5
|
||||
|
||||
# pnpm version comes from package.json's packageManager field.
|
||||
- uses: pnpm/action-setup@v6
|
||||
|
||||
- uses: actions/setup-node@v5
|
||||
with:
|
||||
node-version: 24
|
||||
cache: pnpm
|
||||
|
||||
- run: pnpm install --frozen-lockfile
|
||||
|
||||
- run: pnpm -r build
|
||||
|
||||
- name: Stage the app directory
|
||||
run: node packages/desktop/scripts/stage.mjs
|
||||
|
||||
# Windows carries MinGit under resources/git so the packaged agent shell has the
|
||||
# same deterministic POSIX bash as the npm package (release.yml bundles the
|
||||
# identical MinGit into the CLI win-x64 zip; the shell advertises it as
|
||||
# PENGUIN_BUNDLED_SHELL).
|
||||
- name: Bundle MinGit (Windows)
|
||||
if: runner.os == 'Windows'
|
||||
shell: bash
|
||||
run: |
|
||||
mingit="MinGit-$MINGIT_VERSION-64-bit.zip"
|
||||
curl -fsSL -o "$mingit" \
|
||||
"https://github.com/git-for-windows/git/releases/download/$MINGIT_TAG/$mingit"
|
||||
unzip -q "$mingit" -d packages/desktop/stage/minigit
|
||||
|
||||
- name: Build packages
|
||||
run: pnpm --dir packages/desktop exec electron-builder ${{ matrix.args }}
|
||||
|
||||
- name: Upload artifacts
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: desktop-${{ runner.os }}
|
||||
if-no-files-found: error
|
||||
path: |
|
||||
packages/desktop/stage/out/*.AppImage
|
||||
packages/desktop/stage/out/*.deb
|
||||
packages/desktop/stage/out/*.dmg
|
||||
packages/desktop/stage/out/*-mac.zip
|
||||
packages/desktop/stage/out/*.exe
|
||||
@@ -77,9 +77,17 @@ jobs:
|
||||
echo "exists=false" >> "$GITHUB_OUTPUT"
|
||||
fi
|
||||
|
||||
release:
|
||||
# Desktop installers (Electron shell, three-OS matrix). Runs BEFORE the release job:
|
||||
# Release assets are immutable once published, so the installers must exist when the
|
||||
# Release is created. See design § "桌面端原型 · 打包与更新" (M3).
|
||||
desktop:
|
||||
needs: check-release
|
||||
if: needs.check-release.outputs.exists != 'true'
|
||||
uses: ./.github/workflows/desktop-build.yml
|
||||
|
||||
release:
|
||||
needs: [check-release, desktop]
|
||||
if: needs.check-release.outputs.exists != 'true'
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write
|
||||
@@ -284,6 +292,22 @@ jobs:
|
||||
cd dist-artifacts
|
||||
sha256sum -- *.tar.gz *.zip > SHA256SUMS
|
||||
|
||||
# Desktop installers built by the desktop job (three-OS matrix): collected here so
|
||||
# they are part of the Release's initial (immutable) asset set. Their checksums go
|
||||
# in a separate SHA256SUMS.desktop — the OSS mirror script's canonical file list
|
||||
# stays untouched (desktop installers are not mirrored yet).
|
||||
- name: Collect desktop artifacts
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
pattern: desktop-*
|
||||
merge-multiple: true
|
||||
path: desktop-artifacts
|
||||
|
||||
- name: Generate desktop checksums
|
||||
run: |
|
||||
cd desktop-artifacts
|
||||
sha256sum -- * > SHA256SUMS.desktop
|
||||
|
||||
# Release notes come from changelog/<version>/RELEASE.md, written during release preparation and
|
||||
# committed BEFORE the tag (the release job runs on the tag's checkout, so a file added afterwards
|
||||
# is invisible here). Present and non-empty -> published verbatim as the body; absent -> GitHub
|
||||
@@ -320,6 +344,7 @@ jobs:
|
||||
dist-artifacts/*.zip
|
||||
dist-artifacts/*.sha256
|
||||
dist-artifacts/SHA256SUMS
|
||||
desktop-artifacts/*
|
||||
install.sh
|
||||
install.ps1
|
||||
|
||||
|
||||
Reference in New Issue
Block a user