Repository navigation
Merge pull request #220 from NoRiskClient/@feat/website-things #960
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build and Release | |
| on: | |
| push: | |
| branches: | |
| - '**' # Build on push to v3 branch | |
| tags: | |
| - "v*" # Release on v* tags | |
| workflow_dispatch: {} # Allow manual dispatch | |
| jobs: | |
| # --- JOB 1: Build & Rename --- | |
| build: | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - platform: 'macos-latest' | |
| target: aarch64-apple-darwin | |
| output_path: ./src-tauri/target/aarch64-apple-darwin/release/bundle | |
| asset_name_base: NoRiskClient-MacOS-arm64 | |
| - platform: 'macos-latest' | |
| target: x86_64-apple-darwin | |
| output_path: ./src-tauri/target/x86_64-apple-darwin/release/bundle | |
| asset_name_base: NoRiskClient-MacOS-x86_64 | |
| - platform: 'ubuntu-22.04' | |
| target: '' # Kein explizites Target für Linux x86_64 | |
| output_path: ./src-tauri/target/release/bundle | |
| asset_name_base: NoRiskClient-Linux | |
| - platform: 'windows-latest' | |
| target: '' # Kein explizites Target für Windows x86_64 | |
| output_path: ./src-tauri/target/release/bundle | |
| asset_name_base: NoRiskClient-Windows-setup | |
| runs-on: ${{ matrix.platform }} | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: install dependencies (ubuntu only) | |
| if: matrix.platform == 'ubuntu-22.04' | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y libwebkit2gtk-4.1-dev libayatana-appindicator3-dev librsvg2-dev patchelf | |
| - name: setup node | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: lts/* | |
| cache: 'yarn' # Switch cache to yarn | |
| - name: install Rust stable | |
| uses: dtolnay/rust-toolchain@stable | |
| with: | |
| targets: ${{ matrix.target }} | |
| - name: Clean workspace (including node_modules) | |
| run: git clean -fdx | |
| - name: Rust cache | |
| uses: swatinem/rust-cache@v2 | |
| with: | |
| workspaces: './src-tauri -> target' | |
| - name: install frontend dependencies | |
| # If you don't have `beforeBuildCommand` configured you may want to build your frontend here too. | |
| run: yarn install --frozen-lockfile # Use yarn install | |
| # Tauri Action now handles build and sign | |
| - name: Build and Sign Tauri App | |
| uses: tauri-apps/tauri-action@v0 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Wird evtl. intern von Tauri benötigt | |
| TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_PRIVATE_KEY }} | |
| TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_KEY_PASSWORD }} | |
| RUSTFLAGS: ${{ matrix.platform == 'ubuntu-22.04' && '-C link-arg=-Wl,--no-as-needed -C link-arg=-layatana-appindicator3 -C link-arg=-Wl,--as-needed' || '' }} | |
| with: | |
| # Revert to using packageManager and args | |
| args: --verbose ${{ matrix.target != '' && format('--target {0}', matrix.target) || '' }} # Füge --target hinzu, wenn es gesetzt ist | |
| packageManager: yarn # Set packageManager to yarn | |
| - name: Fix AppImage (Remove Wayland libs & Resign) | |
| if: matrix.platform == 'ubuntu-22.04' | |
| env: | |
| # Pass the secrets directly to the environment | |
| TAURI_PRIVATE_KEY: ${{ secrets.TAURI_PRIVATE_KEY }} | |
| TAURI_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_KEY_PASSWORD }} | |
| run: | | |
| echo "--- Fix AppImage Started ---" | |
| BUNDLE_DIR="$(pwd)/${{ matrix.output_path }}/appimage" | |
| cd "$BUNDLE_DIR" | |
| APPIMAGE=$(ls *.AppImage | head -n 1) | |
| echo "Target: $APPIMAGE" | |
| chmod +x "$APPIMAGE" | |
| ./"$APPIMAGE" --appimage-extract > /dev/null | |
| echo "Removing conflicting libraries..." | |
| find squashfs-root -name "*wayland*" -delete | |
| wget -q https://github.com/AppImage/appimagetool/releases/download/continuous/appimagetool-x86_64.AppImage | |
| chmod +x appimagetool-x86_64.AppImage | |
| export ARCH=x86_64 | |
| ./appimagetool-x86_64.AppImage squashfs-root/ "$APPIMAGE" | |
| echo "Re-signing..." | |
| cd - > /dev/null | |
| yarn tauri signer sign "$BUNDLE_DIR/$APPIMAGE" | |
| cd "$BUNDLE_DIR" | |
| rm -rf squashfs-root appimagetool-x86_64.AppImage | |
| echo "--- Fix Complete ---" | |
| # --- EV Code Signing (Windows) --- | |
| - name: Find Windows EXE for Signing | |
| if: matrix.platform == 'windows-latest' && startsWith(github.ref, 'refs/tags/') | |
| id: find_exe | |
| run: | | |
| $NsisDir = "${{ github.workspace }}\src-tauri\target\release\bundle\nsis" | |
| $ExeFile = Get-ChildItem -Path $NsisDir -Filter "*.exe" | Where-Object { $_.Name -notlike "*.sig" } | Select-Object -First 1 | |
| echo "EXE_PATH=$($ExeFile.FullName)" >> $env:GITHUB_OUTPUT | |
| echo "NSIS_DIR=$NsisDir" >> $env:GITHUB_OUTPUT | |
| echo "Found EXE: $($ExeFile.FullName)" | |
| shell: pwsh | |
| - name: Sign Windows EXE with SSL.com EV Certificate | |
| if: matrix.platform == 'windows-latest' && startsWith(github.ref, 'refs/tags/') && !contains(github.ref_name, '-beta') | |
| uses: sslcom/esigner-codesign@develop | |
| with: | |
| command: sign | |
| username: ${{ secrets.ES_USERNAME }} | |
| password: ${{ secrets.ES_PASSWORD }} | |
| credential_id: ${{ secrets.CREDENTIAL_ID }} | |
| totp_secret: ${{ secrets.ES_TOTP_SECRET }} | |
| file_path: ${{ steps.find_exe.outputs.EXE_PATH }} | |
| environment_name: PROD | |
| malware_block: false | |
| override: true | |
| - name: Re-sign Windows EXE for Tauri Updater | |
| if: matrix.platform == 'windows-latest' && startsWith(github.ref, 'refs/tags/') && !contains(github.ref_name, '-beta') | |
| env: | |
| TAURI_PRIVATE_KEY: ${{ secrets.TAURI_PRIVATE_KEY }} | |
| TAURI_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_KEY_PASSWORD }} | |
| run: | | |
| echo "Re-signing EXE for Tauri updater after EV code signing..." | |
| yarn tauri signer sign "${{ steps.find_exe.outputs.EXE_PATH }}" | |
| echo "Re-signing complete." | |
| shell: bash | |
| # --- Umbenennen und Artefakte vorbereiten --- | |
| - name: Rename Linux Artifacts | |
| if: matrix.platform == 'ubuntu-22.04' | |
| run: | | |
| echo "--- Listing content BEFORE rename ---" | |
| echo "Output path: ${{ matrix.output_path }}" | |
| ls -R "${{ matrix.output_path }}" || true | |
| echo "-----------------------------------" | |
| APP_BASE_NAME="NoRisk Launcher" # Dein productName | |
| APPIMAGE_DIR=${{ matrix.output_path }}/appimage | |
| DEB_DIR=${{ matrix.output_path }}/deb | |
| echo "Listing content of $APPIMAGE_DIR and $DEB_DIR" | |
| ls -R "$APPIMAGE_DIR" || true | |
| ls -R "$DEB_DIR" || true | |
| # Verschiebe und benenne AppImage um (verwende einfachen Wildcard) | |
| mv "$APPIMAGE_DIR"/*.AppImage "$APPIMAGE_DIR"/${{ matrix.asset_name_base }}.AppImage | |
| # Verschiebe und benenne AppImage Signatur um (verwende einfachen Wildcard) | |
| mv "$APPIMAGE_DIR"/*.AppImage.sig "$APPIMAGE_DIR"/${{ matrix.asset_name_base }}.AppImage.sig | |
| # Verschiebe und benenne Deb Paket um | |
| mv "$DEB_DIR"/*.deb "$APPIMAGE_DIR"/${{ matrix.asset_name_base }}.deb | |
| # Verschiebe und benenne Deb Signatur um | |
| mv "$DEB_DIR"/*.deb.sig "$APPIMAGE_DIR"/${{ matrix.asset_name_base }}.deb.sig | |
| echo "Final content of $APPIMAGE_DIR after moves" | |
| ls -R "$APPIMAGE_DIR" || true | |
| echo "--- Listing content AFTER rename ---" | |
| echo "Output path: ${{ matrix.output_path }}" | |
| ls -R "${{ matrix.output_path }}" || true | |
| echo "-----------------------------------" | |
| shell: bash | |
| - name: Rename Windows Artifacts | |
| if: matrix.platform == 'windows-latest' | |
| run: | | |
| echo "--- Listing content BEFORE rename ---" | |
| echo "Output path: ${{ matrix.output_path }}" | |
| Get-ChildItem -Path "${{ matrix.output_path }}\release\bundle" -Recurse -ErrorAction SilentlyContinue | |
| echo "-----------------------------------" | |
| $ARTIFACT_DIR = "${{ matrix.output_path }}\nsis" | |
| echo "Listing content of $ARTIFACT_DIR" | |
| Get-ChildItem -Path $ARTIFACT_DIR -Recurse | |
| # Finde die Originalnamen (angenommen nur eine .exe und eine .exe.sig) | |
| $ExeFile = Get-ChildItem -Path $ARTIFACT_DIR -Filter *.exe | |
| $SigFile = Get-ChildItem -Path $ARTIFACT_DIR -Filter *.exe.sig | |
| # Benenne .exe um | |
| Move-Item -Path $ExeFile.FullName -Destination "$ARTIFACT_DIR\${{ matrix.asset_name_base }}.exe" | |
| # Benenne .exe.sig um | |
| Move-Item -Path $SigFile.FullName -Destination "$ARTIFACT_DIR\${{ matrix.asset_name_base }}.exe.sig" | |
| echo "Final content of $ARTIFACT_DIR after move" | |
| Get-ChildItem -Path $ARTIFACT_DIR -Recurse | |
| echo "--- Listing content AFTER rename ---" | |
| echo "Output path: ${{ matrix.output_path }}" | |
| Get-ChildItem -Path "${{ matrix.output_path }}" -Recurse -ErrorAction SilentlyContinue | |
| echo "-----------------------------------" | |
| shell: pwsh | |
| - name: Rename macOS Artifacts | |
| if: matrix.platform == 'macos-latest' | |
| run: | | |
| echo "--- Listing content BEFORE rename ---" | |
| echo "Output path: ${{ matrix.output_path }}" | |
| ls -R "${{ matrix.output_path }}" || true | |
| echo "-----------------------------------" | |
| APP_BASE_NAME="NoRisk Launcher" # Dein productName | |
| ARTIFACT_DIR_DMG=${{ matrix.output_path }}/dmg | |
| ARTIFACT_DIR_APP=${{ matrix.output_path }}/macos | |
| RENAMED_DIR="$ARTIFACT_DIR_APP/renamed" | |
| echo "Listing content of $ARTIFACT_DIR_DMG and $ARTIFACT_DIR_APP" | |
| ls -R "$ARTIFACT_DIR_DMG" || true | |
| ls -R "$ARTIFACT_DIR_APP" || true | |
| mkdir -p "$RENAMED_DIR" | |
| # Verschiebe DMG (Wildcard sollte ok sein) | |
| mv "$ARTIFACT_DIR_DMG"/*.dmg "$RENAMED_DIR"/${{ matrix.asset_name_base }}.dmg | |
| # Verschiebe App Tarball (expliziter Name) | |
| mv "$ARTIFACT_DIR_APP/${APP_BASE_NAME}.app.tar.gz" "$RENAMED_DIR"/${{ matrix.asset_name_base }}.app.tar.gz | |
| # Verschiebe App Tarball Signatur (expliziter Name, ignoriere Fehler) | |
| mv "$ARTIFACT_DIR_APP/${APP_BASE_NAME}.app.tar.gz.sig" "$RENAMED_DIR"/${{ matrix.asset_name_base }}.app.tar.gz.sig | |
| echo "Final content of $RENAMED_DIR after move" | |
| ls -R "$RENAMED_DIR" || true | |
| echo "--- Listing content AFTER rename ---" | |
| echo "Output path: ${{ matrix.output_path }}" | |
| ls -R "${{ matrix.output_path }}" || true | |
| echo "-----------------------------------" | |
| shell: bash | |
| # --- Artefakte hochladen --- | |
| - name: Upload Linux Artifact | |
| uses: actions/upload-artifact@v4 | |
| if: matrix.platform == 'ubuntu-22.04' | |
| with: | |
| name: artifact-${{ matrix.platform }} | |
| path: ${{ matrix.output_path }}/appimage/${{ matrix.asset_name_base }}.* | |
| if-no-files-found: error | |
| - name: Upload Windows Artifact | |
| uses: actions/upload-artifact@v4 | |
| if: matrix.platform == 'windows-latest' | |
| with: | |
| name: artifact-${{ matrix.platform }} | |
| path: ${{ matrix.output_path }}\nsis\${{ matrix.asset_name_base }}.* | |
| if-no-files-found: error | |
| - name: Upload macOS Artifact | |
| uses: actions/upload-artifact@v4 | |
| if: matrix.platform == 'macos-latest' | |
| with: | |
| name: artifact-${{ matrix.platform }}-${{ matrix.target }} | |
| path: ${{ matrix.output_path }}/macos/renamed/${{ matrix.asset_name_base }}.* | |
| if-no-files-found: error | |
| # --- JOB 2: Create Release --- | |
| release: | |
| if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') | |
| needs: build # Abhängigkeit vom Build-Job | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write # Benötigt für Release-Erstellung | |
| steps: | |
| - name: Checkout repository (needed for release notes maybe) | |
| uses: actions/checkout@v4 | |
| - name: Download all artifacts | |
| uses: actions/download-artifact@v4 | |
| with: | |
| path: artifacts # Alle Artefakte in ein Unterverzeichnis herunterladen | |
| # Kein expliziter Name, lädt alle hochgeladenen Artefakte herunter | |
| - name: List downloaded artifacts | |
| run: ls -R artifacts | |
| - name: Create GitHub Release | |
| uses: softprops/action-gh-release@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| tag_name: ${{ github.ref_name }} # Verwendet den Tag, der den Workflow ausgelöst hat | |
| name: Release ${{ github.ref_name }} # Name des Releases | |
| body: | # Optional: Release Notes | |
| Automated release for tag ${{ github.ref_name }} | |
| See assets below. | |
| draft: false | |
| # Setze auf true, wenn der Tag '-alpha', '-beta' oder '-rc' enthält | |
| prerelease: ${{ contains(github.ref_name, '-alpha') || contains(github.ref_name, '-beta') || contains(github.ref_name, '-rc') }} | |
| files: artifacts/**/* # Lädt alle heruntergeladenen Artefakte hoch | |
| # --- Schritt: Produktions-Backend benachrichtigen --- | |
| - name: Notify Production Backend | |
| if: success() # Nur wenn Release-Erstellung erfolgreich war | |
| run: | | |
| echo "Sending notification to PRODUCTION backend for tag ${{ github.ref_name }}" | |
| curl -X POST \ | |
| -H "Content-Type: application/json" \ | |
| -H "Authorization: Bearer ${{ secrets.BACKEND_API_KEY }}" \ | |
| https://api.norisk.gg/api/v1/launcher/releases/update | |
| shell: bash | |
| # --- JOB 3: Staging-Backend benachrichtigen --- | |
| notify_staging: # Neuer Job für Staging/Manual | |
| # Läuft bei Push zu staging ODER bei manuellem Start | |
| if: (github.event_name == 'push' && github.ref == 'refs/heads/staging') || (github.event_name == 'workflow_dispatch') | |
| runs-on: ubuntu-latest | |
| needs: build # Stellt sicher, dass Builds abgeschlossen sind (oder fehlgeschlagen sind) | |
| steps: | |
| - name: Notify Staging Backend | |
| run: | | |
| echo "Sending notification to STAGING backend for ref ${{ github.ref_name }}" | |
| curl -X POST \ | |
| -H "Content-Type: application/json" \ | |
| -H "Authorization: Bearer ${{ secrets.BACKEND_API_KEY }}" \ | |
| https://api-staging.norisk.gg/api/v1/launcher/releases/update | |
| shell: bash |