Files
nextcloud-workflow-deck-aut…/.gitea/workflows/build-main.yml
T
Patrick Niebeling 9a8e4e47f0
Build package / package (push) Successful in 59s
Lint info.xml / xml-lint (push) Successful in 13s
Lint PHP / php-lint (8.2) (push) Successful in 43s
Lint PHP / php-lint (8.3) (push) Successful in 36s
Lint PHP / php-lint (8.4) (push) Successful in 34s
PHPUnit / unit-tests (push) Successful in 40s
Use the built-in GITEA_TOKEN instead of a hand-made RELEASE_TOKEN secret
Gitea injects a token into every Actions job as secrets.GITEA_TOKEN, so the
manually created PAT was never necessary. Declare permissions: contents:
write on the job, which Gitea maps to Code: write (deleting the latest-main
tag) and Releases: write (creating the release, uploading the asset) - the
full set the publish step needs.

Removes a secret that had to be created by hand, could expire, and was a
single point of failure the workflow had no fallback for.
2026-08-13 13:54:38 +02:00

86 lines
3.0 KiB
YAML

name: Build package
on:
push:
branches:
- main
tags:
- 'v*'
jobs:
package:
runs-on: gitea-runner-server03
# contents: write maps to Code: write (deleting the latest-main tag) plus
# Releases: write (creating releases and uploading the asset) - everything
# the publish step below needs, so it runs on the built-in GITEA_TOKEN.
permissions:
contents: write
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: '24'
- name: Install JS dependencies
run: npm install
- name: Build frontend
run: npm run build
- name: Package appstore artifact
run: make appstore
- name: Publish release
env:
GITEA_API: ${{ gitea.server_url }}/api/v1
REPO: ${{ gitea.repository }}
TOKEN: ${{ secrets.GITEA_TOKEN }}
SHA: ${{ gitea.sha }}
REF: ${{ gitea.ref }}
run: |
set -e
ASSET="build/artifacts/appstore/workflow_deck_automation.tar.gz"
case "$REF" in
refs/tags/*)
TAG="${REF#refs/tags/}"
RECREATE_TAG=false
PRERELEASE=false
TITLE="$TAG"
BODY="Release $TAG"
;;
*)
TAG="latest-main"
RECREATE_TAG=true
PRERELEASE=true
TITLE="Latest main build"
BODY="Automatisch aus $SHA gebaut - nur zum schnellen Testen/Deployen, kein offizielles Release."
;;
esac
api() { curl -sS -H "Authorization: token $TOKEN" "$@"; }
# Always drop an existing release for this tag first: the rolling tag is
# rebuilt on every push, and a moved version tag has to publish the new
# build instead of failing on a duplicate asset name.
api "$GITEA_API/repos/$REPO/releases/tags/$TAG" -o /tmp/old_release.json
OLD_ID=$(node -e "try{const j=require('/tmp/old_release.json');console.log(j.id||'')}catch(e){console.log('')}")
if [ -n "$OLD_ID" ]; then
api -X DELETE "$GITEA_API/repos/$REPO/releases/$OLD_ID"
fi
# Only latest-main gets its tag recreated - a version tag was just pushed
# and must survive, otherwise this job would delete what triggered it.
if [ "$RECREATE_TAG" = true ]; then
api -X DELETE "$GITEA_API/repos/$REPO/tags/$TAG" > /dev/null || true
fi
api -X POST -H "Content-Type: application/json" \
-d "{\"tag_name\":\"$TAG\",\"target_commitish\":\"$SHA\",\"name\":\"$TITLE\",\"body\":\"$BODY\",\"prerelease\":$PRERELEASE}" \
"$GITEA_API/repos/$REPO/releases" -o /tmp/new_release.json
NEW_ID=$(node -e "console.log(require('/tmp/new_release.json').id)")
api -X POST -F "attachment=@$ASSET" \
"$GITEA_API/repos/$REPO/releases/$NEW_ID/assets?name=workflow_deck_automation.tar.gz"