Makes Codeberg canonical for git, issues, PRs, tags and releases. The self-hosted Gitea instance stays build infrastructure: signing key, F-Droid publishing, release pipeline. **This PR is its own test.** It is the first PR opened on Codeberg, so a green `CI` check proves the new runner works *and* that the submodule resolves from its new home. ### 1 · floret-kit moved Mirrored to `jlmakiola/floret-kit` (6 branches, 3 tags, every SHA verified identical) and `.gitmodules` repointed. This is what actually unblocks contributors — a clone previously could not resolve its submodule without reaching the personal Gitea instance. The Gitea copy is **kept**: every existing tag records the old submodule URL, so rebuilds of past releases (including F-Droid reproducible rebuilds) still resolve. ### 2 · Workflows split by directory Forgejo's lookup is first-match-wins across `.forgejo/` → `.gitea/` → `.github/`, and Gitea cannot see `.forgejo/` at all. So each forge sees exactly one set, with no duplicated files and no expression to keep in sync: | Directory | Runs on | Contains | Secrets | | --- | --- | --- | --- | | `.forgejo/workflows/` | Codeberg | `ci.yaml`, `translations.yaml` | **none** | | `.gitea/workflows/` | Gitea | `release.yaml`, `renovate.yml` | all of them | The line is drawn at **secrets, not CI-vs-release** — that is what makes fork PRs safe. Renovate deliberately does *not* move despite opening PRs here; it keeps running where its token already lives and merely talks to Codeberg's API. ### 3 · Two release-pipeline safety changes - `release.yaml`'s `detect` gets an explicit `repository_owner` guard. The directory split only holds while `.forgejo/` is non-empty; empty it and Codeberg would fall back to `.gitea/` and start running the release pipeline on the contributor-facing runner, without secrets. - `detect` now reads tags from **Codeberg**, not from the Gitea instance it runs on. Push mirroring is `git push --mirror`, so a tag minted on Gitea is deleted by the next sync until the Codeberg tag push propagates back — asking Gitea inside that window reports "no tag" for an already-shipped release and would cut it twice. It also now fails on any status other than 200/404 rather than reading a transient error as "no tag": a failed job is recoverable, a duplicate release is not. ### 4 · Links repointed In-app Source/License links, README badge, both F-Droid metadata files. **`Repo:` in `docs/fdroid-official/` deliberately stays on Gitea** — it keeps receiving `main` and every tag, so it remains a complete build source, and leaving it alone means no fdroiddata MR and no reproducible-build risk. ### Not in this PR Renovate + Weblate repointing, and the Codeberg → Gitea push mirror (browser-side). Supersedes Gitea PR #104. Co-authored-by: Jean-Luc Makiola <business@jeanlucmakiola.de> Reviewed-on: https://codeberg.org/jlmakiola/calendula/pulls/86
77 lines
3.8 KiB
YAML
77 lines
3.8 KiB
YAML
# ---------------------------------------------------------------------------
|
|
# DRAFT fdroiddata metadata for the OFFICIAL F-Droid repository.
|
|
#
|
|
# This is NOT the self-hosted metadata (that lives in ../../fdroid-metadata/).
|
|
# When submitting, this file's contents go to fdroiddata on GitLab as
|
|
# metadata/de.jeanlucmakiola.calendula.yml
|
|
# See README.md in this folder for the verification status and submission steps.
|
|
#
|
|
# Publishing model: REPRODUCIBLE BUILD + developer-signed binary.
|
|
# F-Droid builds from source on its buildserver, then verifies the result is
|
|
# identical to our own signed APK (fetched via `Binaries`). If it matches,
|
|
# F-Droid publishes OUR binary signed with OUR key (`AllowedAPKSigningKeys`),
|
|
# so the official and self-hosted channels carry the SAME signature and users
|
|
# migrate between them with no reinstall / no data loss.
|
|
# ---------------------------------------------------------------------------
|
|
|
|
Categories:
|
|
- Calendar & Agenda
|
|
License: MIT
|
|
AuthorName: Jean-Luc Makiola
|
|
SourceCode: https://codeberg.org/jlmakiola/calendula
|
|
IssueTracker: https://codeberg.org/jlmakiola/calendula/issues
|
|
Changelog: https://codeberg.org/jlmakiola/calendula/src/branch/main/CHANGELOG.md
|
|
Donate: https://ko-fi.com/jeanlucmakiola
|
|
|
|
AutoName: Calendula
|
|
|
|
RepoType: git
|
|
Repo: https://gitea.jeanlucmakiola.de/makiolaj/calendula.git
|
|
|
|
# First build entry = v2.7.5, the first release that clears ALL three F-Droid
|
|
# blockers: (1) AGP VCS-info disabled (`vcsInfo { include = false }`, since
|
|
# v2.7.3); (2) the unused Gradle foojay toolchain-resolver plugin removed (since
|
|
# v2.7.4) — the offline build scanner rejects it as it can fetch a JDK; (3) AGP's
|
|
# dependency-metadata block no longer embedded (`dependenciesInfo { includeInApk
|
|
# = false }`) — the binary scanner rejects it as an "extra signing block". All
|
|
# three live outside the zip entries or are inert, so v2.7.5 is functionally
|
|
# identical to v2.7.3 and reproduces byte-for-byte from source. v2.7.4 and
|
|
# earlier trip one of these checks — do not target them. Subsequent versions are
|
|
# added automatically (AutoUpdateMode).
|
|
Builds:
|
|
- versionName: 2.7.5
|
|
versionCode: 20705
|
|
commit: v2.7.5
|
|
subdir: app
|
|
submodules: true
|
|
gradle:
|
|
- yes
|
|
# No NDK / no flavors. The release buildType applies a signingConfig only
|
|
# when key.properties exists; on the buildserver it does not, so this
|
|
# produces the unsigned APK F-Droid compares against our binary.
|
|
#
|
|
# submodules: true — REQUIRED from v2.11.0 onward, where the build pulls
|
|
# shared code from the `floret-kit` git submodule via a Gradle composite
|
|
# build (`includeBuild("floret-kit")`). Without it F-Droid checks out an
|
|
# empty floret-kit/ and the from-source build fails, stalling publishing.
|
|
# Inert for v2.7.5 (no submodule yet); kept here so AutoUpdateMode copies it
|
|
# onto every auto-generated future build entry. The kit is plain-Kotlin and
|
|
# carries no foojay toolchain resolver, so it clears the same reproducibility
|
|
# bar (enforced by scripts/check_reproducible_release.sh).
|
|
|
|
# SHA-256 of our app signing certificate (public; embedded in every published
|
|
# APK). Locks F-Droid to publish only binaries signed with our key.
|
|
AllowedAPKSigningKeys: 5cdaee8eb31cb0df9157c646ae3ec8b3dc43b5bb72624e088c9ddea0c4eb5ec1
|
|
|
|
# Our own developer-signed APK for reproducible-build verification. %v -> the
|
|
# versionName, so v2.7.5 resolves to calendula_v2.7.5.apk on the self-hosted repo.
|
|
Binaries: https://apps.dev.jeanlucmakiola.de/dev/fdroid/repo/calendula_v%v.apk
|
|
|
|
# After this one-time submission F-Droid auto-tracks new vX.Y.Z tags and creates
|
|
# build entries itself — no manual recipe edits per release. The tag regex keeps
|
|
# it to release tags only.
|
|
AutoUpdateMode: Version
|
|
UpdateCheckMode: Tags ^v[0-9.]+$
|
|
CurrentVersion: 2.7.5
|
|
CurrentVersionCode: 20705
|