Release — F-Droid repo + Gitea/Codeberg release + Play / detect (push) Successful in 6s
Release — F-Droid repo + Gitea/Codeberg release + Play / release (push) Skipped
Release — F-Droid repo + Gitea/Codeberg release + Play / play (push) Skipped
Renovate / renovate (push) Successful in 1m30s
Beta — Codeberg pre-release / detect (push) Successful in 5s
Beta — Codeberg pre-release / beta (push) Skipped
### What this changes Adds beta releases, ported from Agendula (#38 and #40 there). Pushing a `release/*` branch whose `versionName` is `X.Y.Z-beta.N` runs the new `.gitea/workflows/beta.yaml`: unit tests, build + sign with the app key, then a **Codeberg pre-release** (APK + `.sha256`) and a Gitea pre-release (R8 mapping). F-Droid (self-hosted and official) and Play never get a beta; Obtainium only offers it with *Include prereleases* on. - **New versionCode scheme**, derived in one place by `scripts/version_info.sh`. 2.22.3 is the last legacy version (`X*10000 + Y*100 + Z`); from **2.22.4** on it is `X*1000000 + Y*10000 + Z*100 + N` for a beta (N = 1–98) and `+ 99` for stable, so `2.22.4` → `2220499`, `2.23.0-beta.1` → `2230001`. - **`scripts/release_gate.sh`** decides in both `detect` jobs whether the version still needs publishing. Tags are read by exact name via `git ls-remote`: Codeberg's `git/refs/tags/<name>` matches by prefix, so a beta tag would otherwise hide its stable release. A beta counts as done only once its Codeberg pre-release carries the APK (a failed publish is redone by the next push) and must be newer than the latest stable. - **Shared scripts** `publish_codeberg_release.sh`, `publish_gitea_release.sh`, `release_notes.sh`, `write_keystore.sh`, and a local composite action `.gitea/actions/android-env` for the toolchain setup, used by both `release.yaml` and `beta.yaml`. The stable path behaves as before (Codeberg step stays best-effort). - **Guards:** CI fails a PR whose `versionCode` doesn't match its `versionName`, or that brings a beta into `main`; `release.yaml` refuses a beta as a backstop; betas get no store What's New (`sync_changelog_to_fastlane.sh`, `check_changelog_lengths.sh`). - **Docs:** versionCode table and "Cutting a beta" in `docs/RELEASING.md`, the Obtainium note in the README, `build.gradle.kts` comment. - `gradle/gradle-daemon-jvm.properties` now points at JetBrains' own JBR 21.0.11 downloads instead of foojay, which dropped JetBrains 21 from its index (the pinned ids return 400, so a clean runner can't provision the daemon JVM). ### Why To ship test builds of an upcoming version to opted-in testers before the stable release, without them reaching F-Droid or Play users. Infra-only, so this targets `main` directly; no version bump. When cutting 2.22.4, its What's New file is `changelogs/2220499.txt`. ### Checklist - [x] Targeting `main` (infra change, noted above) - [x] No `values-*/strings.xml` touched - [x] `CHANGELOG.md` not updated: release infrastructure, not a user-visible change - [x] No planning or design documents committed Co-authored-by: Jean-Luc Makiola <business@jeanlucmakiola.de> Reviewed-on: https://codeberg.org/jlmakiola/calendula/pulls/369
204 lines
8.7 KiB
YAML
204 lines
8.7 KiB
YAML
name: CI
|
|
|
|
# One gate per pull request. Branch pushes no longer trigger CI on their own,
|
|
# so a change is built once on its PR (covering feature -> release/* and
|
|
# release/* -> main) instead of once per push and again on the merge to main.
|
|
# The merge itself is handled by release.yaml, which only does heavy work when
|
|
# the merge actually cuts a release.
|
|
on:
|
|
pull_request:
|
|
|
|
# Cancel superseded runs for the same PR.
|
|
concurrency:
|
|
group: ci-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
# Single job named `ci` so the required "CI" status check is always reported,
|
|
# even for docs-only PRs: those just skip the Android build and the job still
|
|
# succeeds (fast green check) instead of being filtered out and leaving the
|
|
# required check pending forever.
|
|
ci:
|
|
runs-on: docker
|
|
env:
|
|
ANDROID_HOME: /opt/android-sdk
|
|
ANDROID_SDK_ROOT: /opt/android-sdk
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
with:
|
|
# Full history so the base..HEAD diff below has a merge-base.
|
|
fetch-depth: 0
|
|
submodules: recursive
|
|
|
|
# Cheap, always-on guard: the release build must stay reproducible for the
|
|
# official F-Droid repo (no AGP VCS-info embedding). Runs regardless of
|
|
# change scope so a regression can't slip through on a "docs-only" PR.
|
|
- name: Reproducible-release invariant
|
|
run: bash scripts/check_reproducible_release.sh
|
|
|
|
# versionCode must match versionName (the official F-Droid repo builds the
|
|
# tag as committed), and a beta must never reach main.
|
|
- name: Committed version is well-formed
|
|
env:
|
|
BASE: ${{ github.base_ref }}
|
|
run: |
|
|
set -e
|
|
bash scripts/version_info.sh --check
|
|
if [ "${BASE#refs/heads/}" = "main" ] && [ "$(bash scripts/version_info.sh channel)" = "beta" ]; then
|
|
echo "ERROR: versionName $(bash scripts/version_info.sh version) is a beta." >&2
|
|
echo "Set the stable version (and its versionCode) before merging into main." >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Play rejects a "What's New" over 500 characters, which would fail the
|
|
# upload after the release had already shipped everywhere else. Cheap, so
|
|
# it runs on every PR rather than only on the release merge. A beta ships
|
|
# no What's New, so only the older files are checked for one.
|
|
- name: Changelog length invariant
|
|
run: bash scripts/check_changelog_lengths.sh
|
|
|
|
# The whole listing goes to Play with every release; a field over its cap
|
|
# or an image Play rejects would fail that upload.
|
|
- name: Store listing invariant
|
|
run: |
|
|
if ! command -v python3 >/dev/null 2>&1; then
|
|
if command -v apt-get >/dev/null 2>&1; then
|
|
apt-get update && apt-get install -y python3
|
|
elif command -v apk >/dev/null 2>&1; then
|
|
apk add --no-cache python3
|
|
fi
|
|
fi
|
|
python3 scripts/check_store_listing.py
|
|
|
|
# Decide whether anything that affects the app build changed. Docs, store
|
|
# metadata, licence texts and forge housekeeping don't, so those PRs skip
|
|
# the SDK + Gradle work below but still report a green `ci`.
|
|
- name: Classify change scope
|
|
id: scope
|
|
env:
|
|
# Deliberately a skip-list, not a build-list: a path nobody thought
|
|
# about defaults to building. Only paths the Gradle build provably
|
|
# never reads belong here — note that the workflows themselves, the
|
|
# `.gitmodules` submodule pointer and `scripts/` are *not* in it.
|
|
SKIP_RE: '(\.md$|^docs/|^fastlane/|^fdroid-metadata/|^licenses/|^\.planning/|^\.(forgejo|gitea)/ISSUE_TEMPLATE/|^\.editorconfig$|^\.gitattributes$|^\.gitignore$|^renovate\.json5$|^LICENSE$)'
|
|
run: |
|
|
set -e
|
|
BASE="${{ github.base_ref }}"
|
|
# Normally the bare branch name; tolerate a full ref, which would
|
|
# otherwise make the merge-base lookup fail and quietly degrade this
|
|
# guard into "always build".
|
|
BASE="${BASE#refs/heads/}"
|
|
if [ -z "$BASE" ]; then
|
|
echo "No base branch on this event — running the full build to be safe."
|
|
echo "code=true" >> "$GITHUB_OUTPUT"
|
|
exit 0
|
|
fi
|
|
# Full (not --depth=1) base fetch so the merge-base is present even when
|
|
# the PR branch forked several commits back; a shallow tip has no merge
|
|
# base with a divergent branch and `git diff base...HEAD` aborts.
|
|
git fetch --no-tags origin "$BASE"
|
|
MB=$(git merge-base "origin/$BASE" HEAD 2>/dev/null || true)
|
|
if [ -z "$MB" ]; then
|
|
# No common ancestor available — don't risk skipping the build.
|
|
echo "No merge base with origin/$BASE — running the full build to be safe."
|
|
echo "code=true" >> "$GITHUB_OUTPUT"
|
|
exit 0
|
|
fi
|
|
CHANGED=$(git diff --name-only "$MB" HEAD)
|
|
echo "Changed files:"; echo "$CHANGED"
|
|
RELEVANT=$(echo "$CHANGED" | grep -vE "$SKIP_RE" || true)
|
|
if [ -n "$RELEVANT" ]; then
|
|
# Naming them makes "why did my docs PR build for four minutes?"
|
|
# answerable from the log alone.
|
|
echo "Build-relevant changes:"; echo "$RELEVANT"
|
|
echo "code=true" >> "$GITHUB_OUTPUT"
|
|
else
|
|
echo "Docs/metadata-only change — skipping the Android build."
|
|
echo "code=false" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
- name: Setup Java
|
|
if: steps.scope.outputs.code == 'true'
|
|
uses: actions/setup-java@v4
|
|
with:
|
|
distribution: 'zulu'
|
|
java-version: '17'
|
|
|
|
# Fully qualified on purpose. Codeberg resolves bare `uses:` refs against
|
|
# data.forgejo.org, Forgejo's own action mirror — actions/checkout,
|
|
# setup-java and cache all exist there, but android-actions/setup-android
|
|
# does not, and the job dies with "repository not found". Gitea's instance
|
|
# defaults to GitHub, which is why this never surfaced before the split.
|
|
- name: Setup Android SDK
|
|
if: steps.scope.outputs.code == 'true'
|
|
uses: https://github.com/android-actions/setup-android@v3
|
|
with:
|
|
# Default ("tools platform-tools") drags in the Android Emulator
|
|
# (~300 MB) which the build never uses.
|
|
packages: ''
|
|
|
|
- name: Setup Android SDK cache
|
|
if: steps.scope.outputs.code == 'true'
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: /opt/android-sdk
|
|
key: ${{ runner.os }}-android-sdk-37-36.0.0
|
|
|
|
- name: Install Android SDK packages
|
|
if: steps.scope.outputs.code == 'true'
|
|
run: |
|
|
yes | sdkmanager --licenses >/dev/null || true
|
|
sdkmanager \
|
|
"platform-tools" \
|
|
"platforms;android-37.0" \
|
|
"build-tools;36.0.0"
|
|
|
|
- name: Setup Gradle cache
|
|
if: steps.scope.outputs.code == 'true'
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
~/.gradle/caches
|
|
~/.gradle/wrapper
|
|
key: ${{ runner.os }}-gradle-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties', 'gradle/libs.versions.toml') }}
|
|
restore-keys: |
|
|
${{ runner.os }}-gradle-
|
|
|
|
- name: Grant execute permission for gradlew
|
|
if: steps.scope.outputs.code == 'true'
|
|
run: chmod +x ./gradlew
|
|
|
|
# No --no-daemon: the daemon lives only as long as this job container
|
|
# and lets the following steps skip JVM startup + reconfiguration.
|
|
- name: Lint (debug variant only)
|
|
if: steps.scope.outputs.code == 'true'
|
|
run: ./gradlew lintDebug
|
|
|
|
- name: Unit tests
|
|
if: steps.scope.outputs.code == 'true'
|
|
run: ./gradlew testDebugUnitTest
|
|
|
|
- name: Assemble debug APK
|
|
if: steps.scope.outputs.code == 'true'
|
|
run: ./gradlew assembleDebug
|
|
|
|
- name: Trivy filesystem scan
|
|
if: steps.scope.outputs.code == 'true'
|
|
run: |
|
|
set -e
|
|
SUDO=""
|
|
if command -v sudo >/dev/null 2>&1; then
|
|
SUDO="sudo"
|
|
fi
|
|
if command -v apt-get >/dev/null 2>&1; then
|
|
$SUDO apt-get update
|
|
$SUDO apt-get install -y wget apt-transport-https gnupg lsb-release
|
|
wget -qO - https://aquasecurity.github.io/trivy-repo/deb/public.key | gpg --dearmor | $SUDO tee /usr/share/keyrings/trivy.gpg > /dev/null
|
|
echo "deb [signed-by=/usr/share/keyrings/trivy.gpg] https://aquasecurity.github.io/trivy-repo/deb generic main" | $SUDO tee /etc/apt/sources.list.d/trivy.list
|
|
$SUDO apt-get update
|
|
$SUDO apt-get install -y trivy
|
|
fi
|
|
trivy filesystem --severity HIGH,CRITICAL --exit-code 0 .
|
|
continue-on-error: true
|