Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 10 additions & 10 deletions .github/workflows/ci-linux.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ jobs:
name: Ubuntu arm64
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
repository: ${{ inputs.repository || github.repository }}
ref: ${{ inputs.ref }}
Expand All @@ -36,7 +36,7 @@ jobs:
- name: Check build artifacts for leaked secrets
run: ./script/check-build-secrets.sh
- name: Upload output artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: ubuntu-arm64-artifacts
path: |
Expand All @@ -50,7 +50,7 @@ jobs:
name: Ubuntu arm
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
repository: ${{ inputs.repository || github.repository }}
ref: ${{ inputs.ref }}
Expand All @@ -62,7 +62,7 @@ jobs:
- name: Check build artifacts for leaked secrets
run: ./script/check-build-secrets.sh
- name: Upload output artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: ubuntu-arm-artifacts
path: |
Expand All @@ -76,7 +76,7 @@ jobs:
name: Ubuntu x64
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
repository: ${{ inputs.repository || github.repository }}
ref: ${{ inputs.ref }}
Expand All @@ -88,7 +88,7 @@ jobs:
- name: Check build artifacts for leaked secrets
run: ./script/check-build-secrets.sh
- name: Upload output artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: ubuntu-amd64-artifacts
path: |
Expand All @@ -109,16 +109,16 @@ jobs:
id-token: write # mint the short-lived Sigstore identity
attestations: write # record the provenance attestation
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7

- name: Use Node.js 20.17.0
uses: actions/setup-node@v4
uses: actions/setup-node@v7
with:
node-version: 20.17.0
cache: yarn

- name: Download all artifacts
uses: actions/download-artifact@v4
uses: actions/download-artifact@v8
with:
path: './artifacts'

Expand Down Expand Up @@ -165,7 +165,7 @@ jobs:
echo "---"

- name: Create Release
uses: softprops/action-gh-release@v2
uses: softprops/action-gh-release@v3
with:
name: GitHub Desktop for Linux ${{ env.RELEASE_TAG_WITHOUT_PREFIX }}
body_path: script/release_notes.txt
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -56,12 +56,12 @@ jobs:
env:
RELEASE_CHANNEL: ${{ inputs.environment }}
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
repository: ${{ inputs.repository || github.repository }}
ref: ${{ inputs.ref }}
submodules: recursive
- uses: actions/setup-node@v4
- uses: actions/setup-node@v7
with:
node-version: ${{ env.NODE_VERSION }}
cache: yarn
Expand Down Expand Up @@ -91,16 +91,16 @@ jobs:
env:
RELEASE_CHANNEL: ${{ inputs.environment }}
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
repository: ${{ inputs.repository || github.repository }}
ref: ${{ inputs.ref }}
submodules: recursive
- uses: actions/setup-python@v5
- uses: actions/setup-python@v7
with:
python-version: '3.11'
- name: Use Node.js ${{ env.NODE_VERSION }}
uses: actions/setup-node@v4
uses: actions/setup-node@v7
with:
node-version: ${{ env.NODE_VERSION }}
cache: yarn
Expand Down Expand Up @@ -148,7 +148,7 @@ jobs:
AZURE_CLIENT_ID: ${{ secrets.AZURE_CODE_SIGNING_CLIENT_ID }}
AZURE_CLIENT_SECRET: ${{ secrets.AZURE_CODE_SIGNING_CLIENT_SECRET }}
- name: Upload artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
if: ${{ inputs.upload-artifacts }}
with:
name: ${{matrix.friendlyName}}-${{matrix.arch}}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/close-single-word-issues.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ jobs:

steps:
- name: Close Single-Word Issue
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
script: |
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v7

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/create-draft-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:
name: Publish draft release
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
token: ${{ secrets.CREATE_RELEASE_AUTOMATION_TOKEN }}
- name: Configure git
Expand Down
27 changes: 24 additions & 3 deletions .github/workflows/publish-apt.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout (reprepro conf + public key)
uses: actions/checkout@v4
uses: actions/checkout@v7

- name: Install tooling
run: |
Expand Down Expand Up @@ -103,10 +103,31 @@ jobs:
AWS_ACCESS_KEY_ID: ${{ secrets.R2_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.R2_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: auto
R2_ACCOUNT_ID: ${{ secrets.R2_ACCOUNT_ID }}
run: |
set -euo pipefail
mkdir -p repo
aws s3 sync "s3://$BUCKET/$PREFIX" repo \
--endpoint-url "https://${{ secrets.R2_ACCOUNT_ID }}.r2.cloudflarestorage.com" || true
endpoint="https://${R2_ACCOUNT_ID}.r2.cloudflarestorage.com"

# This step used to end in `|| true`. A failed pull therefore looked
# exactly like an empty repository: reprepro would add the one incoming
# package, export, and the sync would overwrite dists/ with a
# single-package index. Every previously published version silently
# stops being listed, and the run stays green.
#
# So: let a genuine failure fail, and separately catch the case where
# the remote has content but nothing arrived - which a zero exit code
# alone would not reveal.
remote=$(aws s3 ls "s3://$BUCKET/$PREFIX/" --recursive --endpoint-url "$endpoint" | wc -l)
aws s3 sync "s3://$BUCKET/$PREFIX" repo --endpoint-url "$endpoint" --no-progress
pulled=$(find repo -type f | wc -l)
echo "remote objects: $remote, pulled: $pulled"

if [ "$remote" -gt 0 ] && [ "$pulled" -eq 0 ]; then
echo "::error::Remote holds $remote objects but none were pulled. Refusing to"
echo "::error::republish, which would drop every existing package from the index."
exit 1
fi

- name: Prepare reprepro config
run: |
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/release-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ jobs:
permissions:
pull-requests: write
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
if: |
startsWith(github.ref, 'refs/heads/releases/') && !contains(github.ref, 'test')

Expand Down Expand Up @@ -37,7 +37,7 @@ jobs:
private_key: ${{ secrets.DESKTOP_RELEASES_APP_PRIVATE_KEY }}

- name: Create Release Pull Request
uses: peter-evans/create-pull-request@v7.0.6
uses: peter-evans/create-pull-request@v8.1.1
if: |
startsWith(github.ref, 'refs/heads/releases/') && !contains(github.ref, 'test')
with:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/sync-with-upstream.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ jobs:
name: Sync main branch with upstream
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
token: ${{ secrets.CREATE_RELEASE_AUTOMATION_TOKEN }}
- name: Configure git
Expand Down
Loading