ci: adopt the modern calendula pipeline + Codeberg mirror
Port Calendula's current CI/release pipeline: - ci.yaml: pull_request-triggered, change-scope classification (docs/metadata-only PRs skip the Android build but still report a green CI), and a reproducible-release invariant guard. - release.yaml: the committed versionName is the source of truth — a bump reaching main triggers the release, which builds, signs, publishes to the F-Droid repo, then mints the vX.Y.Z tag + Gitea release and mirrors it to Codeberg with the signed APK + SHA-256 checksum. workflow_dispatch runs the re-sign-only recovery path. - Gitea releases are flagged as pre-releases while MAJOR is 0. - build.gradle.kts: reproducible-release invariants (vcsInfo, dependenciesInfo) + a releaseTest variant for the on-device gate. - fastlane/ becomes the single source of truth for store metadata; the localized F-Droid layout is generated from it at release time. - Port scripts/, .gitea/ISSUE_TEMPLATE/, and rewrite docs/RELEASING.md for the versionName-in-main model; fix stale references elsewhere. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -23,11 +23,12 @@ android {
|
||||
applicationId = "de.jeanlucmakiola.agendula"
|
||||
minSdk = 29
|
||||
targetSdk = 36
|
||||
// The git tag is the single source of truth for released builds: at
|
||||
// release time .gitea/workflows/release.yaml derives both fields from
|
||||
// the tag, with versionCode = MAJOR*10000 + MINOR*100 + PATCH
|
||||
// (e.g. v2.0.0 -> 20000). These committed values are the dev/local
|
||||
// default; keep them matching the latest released tag. See docs/RELEASING.md.
|
||||
// These committed values ARE the source of truth for a release: merging
|
||||
// a bumped versionName into main triggers .gitea/workflows/release.yaml,
|
||||
// which builds this version and then creates the matching vX.Y.Z tag +
|
||||
// release itself (versionCode is pinned to MAJOR*10000 + MINOR*100 +
|
||||
// PATCH from versionName, e.g. 0.2.0 -> 200). The Gitea release is marked
|
||||
// as a pre-release while MAJOR is 0. See docs/RELEASING.md.
|
||||
versionCode = 200
|
||||
versionName = "0.2.0"
|
||||
|
||||
@@ -47,6 +48,11 @@ android {
|
||||
|
||||
buildTypes {
|
||||
release {
|
||||
// Keep release builds reproducible for F-Droid: don't let AGP embed
|
||||
// build-environment git metadata (META-INF/version-control-info.textproto),
|
||||
// whose `revision`/path content varies by build machine and is the only
|
||||
// thing that otherwise differs from a clean from-source rebuild.
|
||||
vcsInfo { include = false }
|
||||
isMinifyEnabled = true
|
||||
isShrinkResources = true
|
||||
proguardFiles(
|
||||
@@ -61,6 +67,22 @@ android {
|
||||
applicationIdSuffix = ".debug"
|
||||
isMinifyEnabled = false
|
||||
}
|
||||
// A locally-installable twin of `release`: same R8 shrinking + obfuscation
|
||||
// and resource shrinking, but debug-signed and given its own applicationId
|
||||
// suffix so it installs alongside both the production app (signed with the
|
||||
// real key) and the debug build. Used to smoke-test a release candidate on
|
||||
// a real device before merging to main — R8-only breakage and first-run/
|
||||
// permission states don't surface in the unminified debug build, nor on a
|
||||
// device that already holds the permission. Never published. See
|
||||
// docs/RELEASING.md.
|
||||
create("releaseTest") {
|
||||
initWith(getByName("release"))
|
||||
applicationIdSuffix = ".releasetest"
|
||||
signingConfig = signingConfigs.getByName("debug")
|
||||
isMinifyEnabled = true
|
||||
isShrinkResources = true
|
||||
matchingFallbacks += "release"
|
||||
}
|
||||
}
|
||||
|
||||
compileOptions {
|
||||
@@ -73,6 +95,16 @@ android {
|
||||
buildConfig = true
|
||||
}
|
||||
|
||||
// Don't embed AGP's dependency-metadata block in the APK signing block. It's
|
||||
// a Play-oriented blob, and F-Droid's reproducible-build scanner rejects any
|
||||
// "extra signing block" — so leaving it in blocks publishing to the official
|
||||
// repo. It lives in the signing block, not the zip entries, so disabling it
|
||||
// doesn't change the build output (reproducibility is unaffected).
|
||||
dependenciesInfo {
|
||||
includeInApk = false
|
||||
includeInBundle = false
|
||||
}
|
||||
|
||||
packaging {
|
||||
resources {
|
||||
excludes += "/META-INF/{AL2.0,LGPL2.1}"
|
||||
|
||||
Reference in New Issue
Block a user