feat(desktop): three-platform packaging and CI matrix (M3) (#177)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Yaowei Zheng
2026-08-04 18:32:13 +08:00
committed by GitHub
parent a4415cdb4b
commit 747077cabb
11 changed files with 2150 additions and 7 deletions
+82
View File
@@ -0,0 +1,82 @@
# Desktop packages (design § "桌面端原型 · 打包与更新", milestone M3).
#
# Reusable three-OS matrix: stage the pnpm-deploy app tree, run electron-builder, and
# upload the installers as workflow artifacts named desktop-<OS>. release.yml calls this
# BEFORE creating the Release — assets are immutable once published, so the desktop
# installers must exist at creation time. workflow_dispatch runs it standalone as a dry
# run on any branch.
#
# M3 ships unsigned artifacts; macOS signing/notarization, Windows code signing and
# electron-updater are milestone M4.
name: Desktop packages
on:
workflow_call: {}
workflow_dispatch: {}
env:
# Keep in sync with release.yml (its header comment is the source of truth; duplicated
# here because reusable workflows do not inherit the caller's env).
MINGIT_VERSION: 2.55.0.3
MINGIT_TAG: v2.55.0.windows.3
jobs:
build:
strategy:
fail-fast: false
matrix:
include:
- os: ubuntu-latest
args: --linux
- os: macos-latest
args: --mac
- os: windows-latest
args: --win
runs-on: ${{ matrix.os }}
permissions:
contents: read
steps:
- uses: actions/checkout@v5
# pnpm version comes from package.json's packageManager field.
- uses: pnpm/action-setup@v6
- uses: actions/setup-node@v5
with:
node-version: 24
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm -r build
- name: Stage the app directory
run: node packages/desktop/scripts/stage.mjs
# Windows carries MinGit under resources/git so the packaged agent shell has the
# same deterministic POSIX bash as the npm package (release.yml bundles the
# identical MinGit into the CLI win-x64 zip; the shell advertises it as
# PENGUIN_BUNDLED_SHELL).
- name: Bundle MinGit (Windows)
if: runner.os == 'Windows'
shell: bash
run: |
mingit="MinGit-$MINGIT_VERSION-64-bit.zip"
curl -fsSL -o "$mingit" \
"https://github.com/git-for-windows/git/releases/download/$MINGIT_TAG/$mingit"
unzip -q "$mingit" -d packages/desktop/stage/minigit
- name: Build packages
run: pnpm --dir packages/desktop exec electron-builder ${{ matrix.args }}
- name: Upload artifacts
uses: actions/upload-artifact@v4
with:
name: desktop-${{ runner.os }}
if-no-files-found: error
path: |
packages/desktop/stage/out/*.AppImage
packages/desktop/stage/out/*.deb
packages/desktop/stage/out/*.dmg
packages/desktop/stage/out/*-mac.zip
packages/desktop/stage/out/*.exe
+26 -1
View File
@@ -77,9 +77,17 @@ jobs:
echo "exists=false" >> "$GITHUB_OUTPUT"
fi
release:
# Desktop installers (Electron shell, three-OS matrix). Runs BEFORE the release job:
# Release assets are immutable once published, so the installers must exist when the
# Release is created. See design § "桌面端原型 · 打包与更新" (M3).
desktop:
needs: check-release
if: needs.check-release.outputs.exists != 'true'
uses: ./.github/workflows/desktop-build.yml
release:
needs: [check-release, desktop]
if: needs.check-release.outputs.exists != 'true'
runs-on: ubuntu-latest
permissions:
contents: write
@@ -284,6 +292,22 @@ jobs:
cd dist-artifacts
sha256sum -- *.tar.gz *.zip > SHA256SUMS
# Desktop installers built by the desktop job (three-OS matrix): collected here so
# they are part of the Release's initial (immutable) asset set. Their checksums go
# in a separate SHA256SUMS.desktop — the OSS mirror script's canonical file list
# stays untouched (desktop installers are not mirrored yet).
- name: Collect desktop artifacts
uses: actions/download-artifact@v4
with:
pattern: desktop-*
merge-multiple: true
path: desktop-artifacts
- name: Generate desktop checksums
run: |
cd desktop-artifacts
sha256sum -- * > SHA256SUMS.desktop
# Release notes come from changelog/<version>/RELEASE.md, written during release preparation and
# committed BEFORE the tag (the release job runs on the tag's checkout, so a file added afterwards
# is invisible here). Present and non-empty -> published verbatim as the body; absent -> GitHub
@@ -320,6 +344,7 @@ jobs:
dist-artifacts/*.zip
dist-artifacts/*.sha256
dist-artifacts/SHA256SUMS
desktop-artifacts/*
install.sh
install.ps1