diff --git a/.github/workflows/ci-linux.yml b/.github/workflows/ci-linux.yml index d2fb70d4e0..68853ca122 100644 --- a/.github/workflows/ci-linux.yml +++ b/.github/workflows/ci-linux.yml @@ -24,7 +24,7 @@ jobs: name: Ubuntu arm64 runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: repository: ${{ inputs.repository || github.repository }} ref: ${{ inputs.ref }} @@ -36,7 +36,7 @@ jobs: - name: Check build artifacts for leaked secrets run: ./script/check-build-secrets.sh - name: Upload output artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: ubuntu-arm64-artifacts path: | @@ -50,7 +50,7 @@ jobs: name: Ubuntu arm runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: repository: ${{ inputs.repository || github.repository }} ref: ${{ inputs.ref }} @@ -62,7 +62,7 @@ jobs: - name: Check build artifacts for leaked secrets run: ./script/check-build-secrets.sh - name: Upload output artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: ubuntu-arm-artifacts path: | @@ -76,7 +76,7 @@ jobs: name: Ubuntu x64 runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: repository: ${{ inputs.repository || github.repository }} ref: ${{ inputs.ref }} @@ -88,7 +88,7 @@ jobs: - name: Check build artifacts for leaked secrets run: ./script/check-build-secrets.sh - name: Upload output artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: ubuntu-amd64-artifacts path: | @@ -109,16 +109,16 @@ jobs: id-token: write # mint the short-lived Sigstore identity attestations: write # record the provenance attestation steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Use Node.js 20.17.0 - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: 20.17.0 cache: yarn - name: Download all artifacts - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: path: './artifacts' @@ -165,7 +165,7 @@ jobs: echo "---" - name: Create Release - uses: softprops/action-gh-release@v2 + uses: softprops/action-gh-release@v3 with: name: GitHub Desktop for Linux ${{ env.RELEASE_TAG_WITHOUT_PREFIX }} body_path: script/release_notes.txt diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8614f4486b..f1c9e92ee1 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -56,12 +56,12 @@ jobs: env: RELEASE_CHANNEL: ${{ inputs.environment }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: repository: ${{ inputs.repository || github.repository }} ref: ${{ inputs.ref }} submodules: recursive - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version: ${{ env.NODE_VERSION }} cache: yarn @@ -91,16 +91,16 @@ jobs: env: RELEASE_CHANNEL: ${{ inputs.environment }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: repository: ${{ inputs.repository || github.repository }} ref: ${{ inputs.ref }} submodules: recursive - - uses: actions/setup-python@v5 + - uses: actions/setup-python@v7 with: python-version: '3.11' - name: Use Node.js ${{ env.NODE_VERSION }} - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: ${{ env.NODE_VERSION }} cache: yarn @@ -148,7 +148,7 @@ jobs: AZURE_CLIENT_ID: ${{ secrets.AZURE_CODE_SIGNING_CLIENT_ID }} AZURE_CLIENT_SECRET: ${{ secrets.AZURE_CODE_SIGNING_CLIENT_SECRET }} - name: Upload artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 if: ${{ inputs.upload-artifacts }} with: name: ${{matrix.friendlyName}}-${{matrix.arch}} diff --git a/.github/workflows/close-single-word-issues.yml b/.github/workflows/close-single-word-issues.yml index f2ef0dae8e..82eedb6a8e 100644 --- a/.github/workflows/close-single-word-issues.yml +++ b/.github/workflows/close-single-word-issues.yml @@ -14,7 +14,7 @@ jobs: steps: - name: Close Single-Word Issue - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: github-token: ${{ secrets.GITHUB_TOKEN }} script: | diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 0df88e9c02..d9e71e4dd9 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,7 +18,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL diff --git a/.github/workflows/create-draft-release.yml b/.github/workflows/create-draft-release.yml index 94c08b1a1f..a4cee2c5a1 100644 --- a/.github/workflows/create-draft-release.yml +++ b/.github/workflows/create-draft-release.yml @@ -22,7 +22,7 @@ jobs: name: Publish draft release steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: token: ${{ secrets.CREATE_RELEASE_AUTOMATION_TOKEN }} - name: Configure git diff --git a/.github/workflows/publish-apt.yml b/.github/workflows/publish-apt.yml index 2e83598b0a..445bf1460e 100644 --- a/.github/workflows/publish-apt.yml +++ b/.github/workflows/publish-apt.yml @@ -32,7 +32,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout (reprepro conf + public key) - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Install tooling run: | @@ -103,10 +103,31 @@ jobs: AWS_ACCESS_KEY_ID: ${{ secrets.R2_ACCESS_KEY_ID }} AWS_SECRET_ACCESS_KEY: ${{ secrets.R2_SECRET_ACCESS_KEY }} AWS_DEFAULT_REGION: auto + R2_ACCOUNT_ID: ${{ secrets.R2_ACCOUNT_ID }} run: | + set -euo pipefail mkdir -p repo - aws s3 sync "s3://$BUCKET/$PREFIX" repo \ - --endpoint-url "https://${{ secrets.R2_ACCOUNT_ID }}.r2.cloudflarestorage.com" || true + endpoint="https://${R2_ACCOUNT_ID}.r2.cloudflarestorage.com" + + # This step used to end in `|| true`. A failed pull therefore looked + # exactly like an empty repository: reprepro would add the one incoming + # package, export, and the sync would overwrite dists/ with a + # single-package index. Every previously published version silently + # stops being listed, and the run stays green. + # + # So: let a genuine failure fail, and separately catch the case where + # the remote has content but nothing arrived - which a zero exit code + # alone would not reveal. + remote=$(aws s3 ls "s3://$BUCKET/$PREFIX/" --recursive --endpoint-url "$endpoint" | wc -l) + aws s3 sync "s3://$BUCKET/$PREFIX" repo --endpoint-url "$endpoint" --no-progress + pulled=$(find repo -type f | wc -l) + echo "remote objects: $remote, pulled: $pulled" + + if [ "$remote" -gt 0 ] && [ "$pulled" -eq 0 ]; then + echo "::error::Remote holds $remote objects but none were pulled. Refusing to" + echo "::error::republish, which would drop every existing package from the index." + exit 1 + fi - name: Prepare reprepro config run: | diff --git a/.github/workflows/release-pr.yml b/.github/workflows/release-pr.yml index 8780960952..cb7d5d2fc5 100644 --- a/.github/workflows/release-pr.yml +++ b/.github/workflows/release-pr.yml @@ -9,7 +9,7 @@ jobs: permissions: pull-requests: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 if: | startsWith(github.ref, 'refs/heads/releases/') && !contains(github.ref, 'test') @@ -37,7 +37,7 @@ jobs: private_key: ${{ secrets.DESKTOP_RELEASES_APP_PRIVATE_KEY }} - name: Create Release Pull Request - uses: peter-evans/create-pull-request@v7.0.6 + uses: peter-evans/create-pull-request@v8.1.1 if: | startsWith(github.ref, 'refs/heads/releases/') && !contains(github.ref, 'test') with: diff --git a/.github/workflows/sync-with-upstream.yml b/.github/workflows/sync-with-upstream.yml index 36df18944a..2c3ddc26a7 100644 --- a/.github/workflows/sync-with-upstream.yml +++ b/.github/workflows/sync-with-upstream.yml @@ -11,7 +11,7 @@ jobs: name: Sync main branch with upstream steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: token: ${{ secrets.CREATE_RELEASE_AUTOMATION_TOKEN }} - name: Configure git