fix: use Node.js 22 to match bundled runtime #118
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build and Release Tauri App | |
| on: | |
| push: | |
| branches: | |
| - main | |
| workflow_dispatch: | |
| inputs: | |
| tag: | |
| description: 'Version tag (e.g., v0.3.0)' | |
| required: false | |
| type: string | |
| env: | |
| NODE_VERSION: '22' | |
| RUST_VERSION: 'stable' | |
| ALLOOMI_REPO: 'melandlabs/alloomi' | |
| jobs: | |
| get-version: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| version: ${{ steps.version.outputs.version }} | |
| checkout_ref: ${{ steps.version.outputs.checkout_ref }} | |
| steps: | |
| - id: version | |
| run: | | |
| if [ "${{ github.event.inputs.tag }}" != "" ]; then | |
| echo "version=${{ github.event.inputs.tag }}" >> $GITHUB_OUTPUT | |
| echo "checkout_ref=refs/tags/${{ github.event.inputs.tag }}" >> $GITHUB_OUTPUT | |
| else | |
| echo "version=0.0.0-test" >> $GITHUB_OUTPUT | |
| echo "checkout_ref=refs/heads/main" >> $GITHUB_OUTPUT | |
| fi | |
| build-tauri-macos: | |
| needs: get-version | |
| if: needs.get-version.outputs.version != '' | |
| runs-on: macos-14 | |
| steps: | |
| - name: Checkout release repo | |
| uses: actions/checkout@v4 | |
| - name: Clone alloomi source code | |
| run: | | |
| git clone https://x-access-token:${{ secrets.LUMIS_TOKEN }}@github.com/${{ env.ALLOOMI_REPO }}.git alloomi | |
| cd alloomi | |
| git checkout ${{ needs.get-version.outputs.checkout_ref }} | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| - name: Install pnpm | |
| uses: pnpm/action-setup@v2 | |
| with: | |
| version: 9 | |
| - name: Add pnpm to PATH | |
| run: | | |
| echo "$HOME/.local/bin" >> $GITHUB_PATH | |
| echo "PNPM_HOME=$HOME/.local" >> $GITHUB_ENV | |
| - name: Setup Python | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: '3.12' | |
| - name: Setup Rust | |
| uses: dtolnay/rust-toolchain@stable | |
| with: | |
| toolchain: ${{ env.RUST_VERSION }} | |
| - name: Install Rust targets | |
| run: | | |
| rustup target add aarch64-apple-darwin | |
| rustup target add x86_64-apple-darwin | |
| - name: Get pnpm store directory | |
| run: | | |
| echo "STORE_PATH=$(pnpm store path --silent)" >> $GITHUB_ENV | |
| - name: Setup pnpm cache | |
| uses: actions/cache@v3 | |
| with: | |
| path: ${{ env.STORE_PATH }} | |
| key: ${{ runner.os }}-pnpm-store-${{ hashFiles('alloomi/**/pnpm-lock.yaml') }} | |
| restore-keys: | | |
| ${{ runner.os }}-pnpm-store- | |
| - name: Install dependencies | |
| working-directory: ./alloomi | |
| run: pnpm install --frozen-lockfile --ignore-scripts | |
| - name: Rebuild native modules for Tauri | |
| working-directory: ./alloomi | |
| run: | | |
| pnpm rebuild better-sqlite3 | |
| cd node_modules/@photon-ai/imessage-kit && pnpm rebuild | |
| - name: Create .env file | |
| working-directory: ./alloomi/apps/web | |
| run: | | |
| cat > .env << 'EOF' | |
| ENCRYPTION_KEY=${{ secrets.ENCRYPTION_KEY }} | |
| # Cloud API Configuration for Tauri Desktop App | |
| CLOUD_API_URL=https://app.alloomi.ai | |
| NEXT_PUBLIC_CLOUD_API_URL=https://app.alloomi.ai | |
| # Local development URL (for Tauri mode) | |
| NEXT_PUBLIC_APP_URL=http://localhost:3415 | |
| LLM_BASE_URL=https://openrouter.ai/api/v1 | |
| LLM_MODEL=google/gemini-3-flash-preview | |
| LLM_REASONING_MODEL=google/gemini-3-flash-preview | |
| LLM_VISION_LANGUAGE_MODEL=google/gemini-3-flash-preview | |
| LLM_IMAGE_MODEL=openai/gpt-5-image | |
| LLM_EMBEDDING_MODEL=qwen/qwen3-embedding-4b | |
| LLM_EMBEDDING_BASE_URL=https://openrouter.ai/api/v1 | |
| TELEGRAM_MODE=pooling | |
| # Telegram App Id and Hash. Reference: https://my.telegram.org/ | |
| TG_APP_ID=${{ secrets.TG_APP_ID }} | |
| TG_APP_HASH=${{ secrets.TG_APP_HASH }} | |
| # Roles | |
| ROLE_DETECTION_ENABLED=1 | |
| ROLE_OVERLAY_ANALYST_JOURNALIST=1 | |
| ROLE_OVERLAY_COMMUNITY_MANAGER=1 | |
| ROLE_OVERLAY_CUSTOMER_SUCCESS=1 | |
| ROLE_OVERLAY_EXECUTIVE=1 | |
| ROLE_OVERLAY_FREELANCER=1 | |
| ROLE_OVERLAY_INDIE_FOUNDER=1 | |
| ROLE_OVERLAY_INVESTOR_ADVISOR=1 | |
| ROLE_OVERLAY_REMOTE_WORKER=1 | |
| ROLE_OVERLAY_SALES_BIZDEV=1 | |
| CLAUDE_CODE_TMPDIR=$HOME/.cache/alloomi-tmp | |
| ANTHROPIC_BASE_URL=http://localhost:3415/api/ai | |
| API_TIMEOUT_MS=3000000 | |
| CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1 | |
| IS_TAURI=true | |
| # iMessage Backend Mode | |
| IMESSAGE_BACKEND_MODE=sdk | |
| NEXT_PUBLIC_IMESSAGE_BACKEND_MODE=sdk | |
| CLAUDE_DISABLE_URL_SAFETY_CHECK=true | |
| EOF | |
| - name: Import Apple Certificate and Intermediate Certificates | |
| env: | |
| APPLE_CERTIFICATE: "${{ secrets.APPLE_CERTIFICATE }}" | |
| APPLE_CERTIFICATE_PASSWORD: "${{ secrets.APPLE_CERTIFICATE_PASSWORD }}" | |
| run: | | |
| # Create a new keychain | |
| KEYCHAIN_PATH=$RUNNER_TEMP/app-signing.keychain-db | |
| security create-keychain -p "" $KEYCHAIN_PATH | |
| security set-keychain-settings -lut 21600 $KEYCHAIN_PATH | |
| security unlock-keychain -p "" $KEYCHAIN_PATH | |
| # Import Apple certificate | |
| echo "$APPLE_CERTIFICATE" | base64 --decode > cert.p12 | |
| security import cert.p12 -P "$APPLE_CERTIFICATE_PASSWORD" -A -k $KEYCHAIN_PATH | |
| rm cert.p12 | |
| # Download and import Apple intermediate certificates (not available in CI) | |
| curl -s -o /tmp/AppleWWDRCAG3.cer https://www.apple.com/certificateauthority/AppleWWDRCAG3.cer | |
| curl -s -o /tmp/DeveloperIDG2CA.cer https://www.apple.com/certificateauthority/DeveloperIDG2CA.cer | |
| security import /tmp/AppleWWDRCAG3.cer -A -k $KEYCHAIN_PATH | |
| security import /tmp/DeveloperIDG2CA.cer -A -k $KEYCHAIN_PATH | |
| # List keychains to ensure system can access certificates | |
| security list-keychain -d user -s $KEYCHAIN_PATH | |
| - name: Build Tauri app (Apple Silicon) | |
| working-directory: ./alloomi/apps/web | |
| run: pnpm tauri:build | |
| env: | |
| APPLE_CERTIFICATE: "${{ secrets.APPLE_CERTIFICATE }}" | |
| APPLE_CERTIFICATE_PASSWORD: "${{ secrets.APPLE_CERTIFICATE_PASSWORD }}" | |
| APPLE_SIGNING_IDENTITY: "${{ secrets.APPLE_SIGNING_IDENTITY }}" | |
| # Don't set APPLE_ID/APPLE_PASSWORD to prevent Tauri from auto-notarizing | |
| # Notarization will be done manually in a separate step | |
| SIGNING_IDENTITY: "${{ secrets.APPLE_SIGNING_IDENTITY }}" | |
| - name: Ensure all binaries are signed (fallback) | |
| env: | |
| APPLE_SIGNING_IDENTITY: "${{ secrets.APPLE_SIGNING_IDENTITY }}" | |
| run: | | |
| set -e | |
| SIGN_ID="${APPLE_SIGNING_IDENTITY}" | |
| APP_BUNDLE="./alloomi/apps/web/src-tauri/target/release/bundle/macos/Alloomi.app" | |
| echo "🔐 Fallback: Signing all binaries in $APP_BUNDLE" | |
| echo " Using SIGN_ID: $SIGN_ID" | |
| # Remove extended attributes from all binaries | |
| find "$APP_BUNDLE" -type f \( -name "*.node" -o -name "*.dylib" \) -print0 | xargs -0 xattr -cr 2>/dev/null || true | |
| # Sign all .node files with Developer ID, timestamp, and hardened runtime | |
| # But skip cli-bundle/node which is already signed by bundle-runtime.sh | |
| echo " Signing .node files..." | |
| find "$APP_BUNDLE" -type f -name "*.node" -not -path "*/cli-bundle/*" -print0 | xargs -0 codesign --force --sign "$SIGN_ID" --options runtime --timestamp || true | |
| # Sign all .dylib files with Developer ID, timestamp, and hardened runtime | |
| echo " Signing .dylib files..." | |
| find "$APP_BUNDLE" -type f -name "*.dylib" -print0 | xargs -0 codesign --force --sign "$SIGN_ID" --options runtime --timestamp || true | |
| # Sign specific problematic executables with Developer ID, timestamp, and hardened runtime | |
| # Skip cli-bundle/* as they are already signed by bundle-runtime.sh | |
| echo " Signing specific executables..." | |
| for exe in \ | |
| "$APP_BUNDLE/Contents/Resources/_up_/cli-bundle/vendor/ripgrep/arm64-darwin/rg" \ | |
| "$APP_BUNDLE/Contents/Resources/_up_/.next/standalone/apps/web/cli-bundle/vendor/ripgrep/arm64-darwin/rg" | |
| do | |
| if [ -f "$exe" ]; then | |
| echo " Signing: $exe" | |
| xattr -cr "$exe" 2>/dev/null || true | |
| codesign --force --sign "$SIGN_ID" --options runtime --timestamp "$exe" | |
| fi | |
| done | |
| # Verify signatures | |
| echo " Verifying signatures..." | |
| for file in \ | |
| "$APP_BUNDLE/Contents/Resources/_up_/.next/standalone/apps/web/cli-bundle/vendor/ripgrep/arm64-darwin/rg" | |
| do | |
| if [ -f "$file" ]; then | |
| echo " Verifying: $file" | |
| codesign -dv "$file" 2>&1 | head -10 | |
| fi | |
| done | |
| echo "✅ Fallback signing complete" | |
| - name: Sign app bundle with Developer ID (skip cli-bundle) | |
| env: | |
| APPLE_SIGNING_IDENTITY: "${{ secrets.APPLE_SIGNING_IDENTITY }}" | |
| run: | | |
| APP_BUNDLE="./alloomi/apps/web/src-tauri/target/release/bundle/macos/Alloomi.app" | |
| echo "Signing app bundle: $APP_BUNDLE" | |
| # Move cli-bundle out temporarily | |
| mv "$APP_BUNDLE/Contents/Resources/_up_/cli-bundle" /tmp/cli-bundle-backup || true | |
| # Deep sign the app bundle (without cli-bundle) | |
| codesign --deep --force --sign "$APPLE_SIGNING_IDENTITY" --options runtime --timestamp "$APP_BUNDLE" | |
| # Move cli-bundle back | |
| mv /tmp/cli-bundle-backup "$APP_BUNDLE/Contents/Resources/_up_/cli-bundle" || true | |
| # Sign Node.js with entitlements to allow execution | |
| # This is required for Developer ID signed Node.js to work | |
| cat > /tmp/node-entitlements.xml << 'EOF' | |
| <?xml version="1.0" encoding="UTF-8"?> | |
| <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> | |
| <plist version="1.0"> | |
| <dict> | |
| <key>com.apple.security.cs.allow-unsigned-executable-memory</key> | |
| <true/> | |
| <key>com.apple.security.cs.disable-library-validation</key> | |
| <true/> | |
| </dict> | |
| </plist> | |
| EOF | |
| codesign --force --sign "$APPLE_SIGNING_IDENTITY" --options runtime --entitlements /tmp/node-entitlements.xml "$APP_BUNDLE/Contents/Resources/_up_/cli-bundle/node" | |
| echo "✅ App bundle signed" | |
| - name: Notarize app bundle | |
| timeout-minutes: 60 | |
| run: | | |
| APP_BUNDLE="./alloomi/apps/web/src-tauri/target/release/bundle/macos/Alloomi.app" | |
| echo "Notarizing app bundle: $APP_BUNDLE" | |
| # Submit app bundle for notarization | |
| OUTPUT=$(xcrun notarytool submit "$APP_BUNDLE" \ | |
| --apple-id "${{ secrets.APPLE_ID }}" \ | |
| --password "${{ secrets.APPLE_PASSWORD }}" \ | |
| --team-id "${{ secrets.APPLE_TEAM_ID }}" 2>&1) | |
| echo "$OUTPUT" | |
| # Extract submission ID | |
| SUBMISSION_ID=$(echo "$OUTPUT" | grep "id:" | head -1 | awk '{print $2}') | |
| if [ -z "$SUBMISSION_ID" ]; then | |
| echo "❌ Failed to get submission ID" | |
| exit 1 | |
| fi | |
| echo "Submission ID: $SUBMISSION_ID" | |
| # Wait for notarization to complete | |
| echo "Waiting for notarization to complete..." | |
| if xcrun notarytool wait "$SUBMISSION_ID" \ | |
| --apple-id "${{ secrets.APPLE_ID }}" \ | |
| --password "${{ secrets.APPLE_PASSWORD }}" \ | |
| --team-id "${{ secrets.APPLE_TEAM_ID }}" 2>&1; then | |
| echo "✅ Notarization accepted!" | |
| else | |
| echo "❌ Notarization failed" | |
| exit 1 | |
| fi | |
| # Wait for ticket propagation | |
| echo "Waiting for ticket propagation..." | |
| sleep 60 | |
| - name: Create DMG manually from signed app bundle | |
| run: | | |
| # Remove old DMG | |
| rm -f ./alloomi/apps/web/src-tauri/target/release/bundle/dmg/Alloomi*.dmg | |
| # Get the app bundle path | |
| APP_BUNDLE="./alloomi/apps/web/src-tauri/target/release/bundle/macos/Alloomi.app" | |
| DMG_PATH="./alloomi/apps/web/src-tauri/target/release/bundle/dmg/Alloomi_0.3.0_aarch64.dmg" | |
| # Create a temporary directory for DMG contents | |
| TEMP_DMG_DIR=$(mktemp -d) | |
| cp -R "$APP_BUNDLE" "$TEMP_DMG_DIR/" | |
| # Create symlink to /Applications (shows as "Applications" folder in DMG) | |
| ln -s /Applications "$TEMP_DMG_DIR/Applications" | |
| # Create DMG from the temp directory with proper layout | |
| # This creates a DMG with the app on the left and Applications folder on the right | |
| hdiutil create -volname "Alloomi" \ | |
| -fs HFS+ \ | |
| -srcfolder "$TEMP_DMG_DIR" \ | |
| -format UDZO \ | |
| "$DMG_PATH" | |
| # Clean up temp directory | |
| rm -rf "$TEMP_DMG_DIR" | |
| echo "✅ DMG created from signed app bundle" | |
| - name: Sign DMG with Developer ID | |
| env: | |
| APPLE_SIGNING_IDENTITY: "${{ secrets.APPLE_SIGNING_IDENTITY }}" | |
| run: | | |
| DMG_PATH=$(ls ./alloomi/apps/web/src-tauri/target/release/bundle/dmg/Alloomi*.dmg) | |
| echo "Signing DMG with Developer ID: $DMG_PATH" | |
| # Re-sign the DMG with Developer ID certificate | |
| codesign --force --sign "$APPLE_SIGNING_IDENTITY" --options runtime --timestamp "$DMG_PATH" | |
| # Verify the signature | |
| codesign -dv "$DMG_PATH" 2>&1 | head -5 | |
| echo "✅ DMG re-signed" | |
| # Note: App bundle was notarized before DMG creation | |
| # This ensures the notarization ticket remains valid after signing | |
| - name: Staple DMG | |
| continue-on-error: true | |
| run: | | |
| DMG_PATH=$(ls ./alloomi/apps/web/src-tauri/target/release/bundle/dmg/Alloomi*.dmg) | |
| echo "Stapling: $DMG_PATH" | |
| # Retry stapling up to 10 times with longer delay | |
| for i in $(seq 1 10); do | |
| echo "Staple attempt $i..." | |
| if xcrun stapler staple "$DMG_PATH" 2>&1; then | |
| echo "✅ Staple succeeded on attempt $i" | |
| break | |
| else | |
| echo "Staple failed, waiting 30 seconds before retry..." | |
| sleep 30 | |
| fi | |
| done | |
| - name: Verify Staple | |
| continue-on-error: true | |
| run: | | |
| DMG_PATH=$(ls ./alloomi/apps/web/src-tauri/target/release/bundle/dmg/Alloomi*.dmg) | |
| xcrun stapler validate "$DMG_PATH" | |
| - name: Find and rename DMG file | |
| id: dmg | |
| working-directory: ./alloomi/apps/web/src-tauri/target/release/bundle/dmg | |
| run: | | |
| # Get original filename | |
| ORIGINAL=$(ls Alloomi*.dmg) | |
| # Extract version and arch, add macOS platform | |
| NEW=$(echo "$ORIGINAL" | sed 's/Alloomi_\(.*\)_aarch64\.dmg/Alloomi_\1_macOS_aarch64.dmg/') | |
| mv "$ORIGINAL" "$NEW" | |
| echo "path=$NEW" >> $GITHUB_OUTPUT | |
| echo "full_path=$(pwd)/$NEW" >> $GITHUB_OUTPUT | |
| - name: Upload Apple Silicon DMG | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: alloomi-dmg-arm64 | |
| path: ${{ steps.dmg.outputs.full_path }} | |
| build-tauri-linux: | |
| needs: get-version | |
| if: needs.get-version.outputs.version != '' | |
| runs-on: ubuntu-22.04 | |
| steps: | |
| - name: Checkout release repo | |
| uses: actions/checkout@v4 | |
| - name: Clone alloomi source code | |
| run: | | |
| git clone https://x-access-token:${{ secrets.LUMIS_TOKEN }}@github.com/${{ env.ALLOOMI_REPO }}.git alloomi | |
| cd alloomi | |
| git checkout ${{ needs.get-version.outputs.checkout_ref }} | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| - name: Install pnpm | |
| uses: pnpm/action-setup@v2 | |
| with: | |
| version: 9 | |
| - name: Add pnpm to PATH | |
| run: | | |
| echo "$HOME/.local/bin" >> $GITHUB_PATH | |
| echo "PNPM_HOME=$HOME/.local" >> $GITHUB_ENV | |
| - name: Setup Rust | |
| uses: dtolnay/rust-toolchain@stable | |
| with: | |
| toolchain: ${{ env.RUST_VERSION }} | |
| - name: Install Rust target | |
| run: | | |
| rustup target add x86_64-unknown-linux-gnu | |
| - name: Install dependencies | |
| working-directory: ./alloomi | |
| run: pnpm install --frozen-lockfile --ignore-scripts | |
| - name: Rebuild native modules for Tauri | |
| working-directory: ./alloomi | |
| run: | | |
| pnpm rebuild better-sqlite3 | |
| cd node_modules/@photon-ai/imessage-kit && pnpm rebuild | |
| - name: Create .env file | |
| working-directory: ./alloomi/apps/web | |
| run: | | |
| cat > .env << 'EOF' | |
| ENCRYPTION_KEY=${{ secrets.ENCRYPTION_KEY }} | |
| # Cloud API Configuration for Tauri Desktop App | |
| CLOUD_API_URL=https://app.alloomi.ai | |
| NEXT_PUBLIC_CLOUD_API_URL=https://app.alloomi.ai | |
| # Local development URL (for Tauri mode) | |
| NEXT_PUBLIC_APP_URL=http://localhost:3415 | |
| LLM_BASE_URL=https://openrouter.ai/api/v1 | |
| LLM_MODEL=google/gemini-3-flash-preview | |
| LLM_REASONING_MODEL=google/gemini-3-flash-preview | |
| LLM_VISION_LANGUAGE_MODEL=google/gemini-3-flash-preview | |
| LLM_IMAGE_MODEL=openai/gpt-5-image | |
| LLM_EMBEDDING_MODEL=qwen/qwen3-embedding-4b | |
| LLM_EMBEDDING_BASE_URL=https://openrouter.ai/api/v1 | |
| TELEGRAM_MODE=pooling | |
| # Telegram App Id and Hash. Reference: https://my.telegram.org/ | |
| TG_APP_ID=${{ secrets.TG_APP_ID }} | |
| TG_APP_HASH=${{ secrets.TG_APP_HASH }} | |
| # Roles | |
| ROLE_DETECTION_ENABLED=1 | |
| ROLE_OVERLAY_ANALYST_JOURNALIST=1 | |
| ROLE_OVERLAY_COMMUNITY_MANAGER=1 | |
| ROLE_OVERLAY_CUSTOMER_SUCCESS=1 | |
| ROLE_OVERLAY_EXECUTIVE=1 | |
| ROLE_OVERLAY_FREELANCER=1 | |
| ROLE_OVERLAY_INDIE_FOUNDER=1 | |
| ROLE_OVERLAY_INVESTOR_ADVISOR=1 | |
| ROLE_OVERLAY_REMOTE_WORKER=1 | |
| ROLE_OVERLAY_SALES_BIZDEV=1 | |
| CLAUDE_CODE_TMPDIR=$HOME/.cache/alloomi-tmp | |
| ANTHROPIC_BASE_URL=http://localhost:3415/api/ai | |
| API_TIMEOUT_MS=3000000 | |
| CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1 | |
| IS_TAURI=true | |
| # iMessage Backend Mode | |
| IMESSAGE_BACKEND_MODE=sdk | |
| NEXT_PUBLIC_IMESSAGE_BACKEND_MODE=sdk | |
| CLAUDE_DISABLE_URL_SAFETY_CHECK=true | |
| EOF | |
| - name: Install Linux build dependencies | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf | |
| - name: Build Tauri app (Linux) | |
| working-directory: ./alloomi/apps/web | |
| run: pnpm tauri:build | |
| env: | |
| # Try to build only deb to avoid AppImage issues | |
| TAURI_BUNDLE_TARGET: deb | |
| continue-on-error: true | |
| - name: Verify deb package exists | |
| run: | | |
| DEB_FILE=$(ls ./alloomi/apps/web/src-tauri/target/release/bundle/deb/*.deb 2>/dev/null || echo "") | |
| if [ -z "$DEB_FILE" ]; then | |
| echo "❌ Error: deb package not found!" | |
| ls -la ./alloomi/apps/web/src-tauri/target/release/bundle/ 2>/dev/null || true | |
| exit 1 | |
| fi | |
| echo "✅ deb package found: $DEB_FILE" | |
| - name: Find deb file | |
| id: deb | |
| working-directory: ./alloomi/apps/web/src-tauri/target/release/bundle/deb | |
| run: | | |
| ORIGINAL=$(ls *.deb) | |
| # Rename Alloomi_0.3.0_amd64.deb to Alloomi_0.3.0_linux_amd64.deb | |
| NEW=$(echo "$ORIGINAL" | sed 's/_amd64/_linux_amd64/') | |
| mv "$ORIGINAL" "$NEW" | |
| echo "path=$NEW" >> $GITHUB_OUTPUT | |
| - name: Upload Linux deb | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: alloomi-linux | |
| path: ./alloomi/apps/web/src-tauri/target/release/bundle/deb/${{ steps.deb.outputs.path }} | |
| release: | |
| needs: [get-version, build-tauri-macos, build-tauri-linux] | |
| if: needs.get-version.outputs.version != '' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Download Apple Silicon DMG | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: alloomi-dmg-arm64 | |
| - name: Download Linux deb | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: alloomi-linux | |
| - name: Create Release | |
| uses: softprops/action-gh-release@v1 | |
| with: | |
| tag_name: ${{ needs.get-version.outputs.version }} | |
| name: 'Alloomi ${{ needs.get-version.outputs.version }}' | |
| body: 'See assets to download this version and install.' | |
| draft: true | |
| files: | | |
| Alloomi*.dmg | |
| *.deb | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Update Homebrew Cask | |
| run: | | |
| # Find DMG file | |
| DMG_FILE=$(ls Alloomi*macOS*.dmg) | |
| # Extract version from filename (e.g., Alloomi_0.3.0_macOS_aarch64.dmg -> 0.3.0) | |
| VERSION=$(echo "$DMG_FILE" | sed -E 's/Alloomi_([0-9.]+)_macOS_aarch64.dmg/\1/') | |
| # Calculate SHA256 | |
| SHA256=$(sha256sum "$DMG_FILE" | awk '{print $1}') | |
| # Update cask file | |
| sed -i "s/version \"[^\"]*\"/version \"$VERSION\"/" Casks/alloomi.rb | |
| sed -i "s/sha256 \"[^\"]*\"/sha256 \"$SHA256\"/" Casks/alloomi.rb | |
| # Commit changes | |
| git config --local user.email "github-actions[bot]@users.noreply.github.com" | |
| git config --local user.name "github-actions[bot]" | |
| git add Casks/alloomi.rb | |
| git commit -m "chore: update Homebrew cask to v$VERSION" || echo "No changes to commit" | |
| - name: Push changes | |
| uses: ad-m/github-push-action@master | |
| with: | |
| github_token: ${{ secrets.GITHUB_TOKEN }} |