Repository navigation
109 lines (96 loc) · 3.85 KB
/
Copy pathandroid.yml
File metadata and controls
109 lines (96 loc) · 3.85 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
name: Android CI
# Docs-only changes don't build. Store texts (fastlane/) are NOT ignored: StoreMetadataTest
# checks them. A change that also touches anything else runs CI as usual.
on:
push:
branches: [ main ]
paths-ignore:
- '**.md'
- 'docs/**'
- 'LICENSE'
- '.github/ISSUE_TEMPLATE/**'
pull_request:
paths-ignore:
- '**.md'
- 'docs/**'
- 'LICENSE'
- '.github/ISSUE_TEMPLATE/**'
workflow_dispatch:
# Only the newest run per branch / PR matters; cancel superseded ones.
concurrency:
group: ci-${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
build:
# Dependabot bumps (build(deps) / ci(deps)) don't run CI on their own PR: they are merged in
# batches and checked on the branch that takes them, or on main after the merge.
if: github.actor != 'dependabot[bot]'
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
contents: read
pull-requests: write # only for the coverage comment
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Validate Gradle wrapper
uses: gradle/actions/wrapper-validation@748248ddd2a24f49513d8f472f81c3a07d4d50e1 # v4.4.4
- name: Set up JDK 21
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
with:
distribution: temurin
java-version: '21'
- name: Set up Gradle
uses: gradle/actions/setup-gradle@748248ddd2a24f49513d8f472f81c3a07d4d50e1 # v4.4.4
- name: Grant execute permission for gradlew
run: chmod +x ./gradlew
# One Gradle invocation, fdroid flavor only, to keep Actions minutes low. The play flavor
# differs only in store flags and is built by the release workflow; instrumented tests
# (Room migrations, SQLCipher) run locally on an emulator: see CONTRIBUTING.md.
- name: Format, unit tests, detekt, release build
run: >-
./gradlew spotlessCheck
:app:testFdroidDebugUnitTest
:app:koverXmlReportFdroidDebug
:app:koverVerifyFdroidDebug
:app:detekt
:app:assembleFdroidRelease
# Separate invocation: lint running alongside Hilt code generation for another variant has
# raced on generated sources; after the build it reads finished outputs.
- name: Lint (release)
run: ./gradlew :app:lintFdroidRelease
- name: Check merged manifest has no INTERNET permission
run: |
set -euo pipefail
found=0
for m in $(find app/build/intermediates/merged_manifests -name AndroidManifest.xml -path '*elease*'); do
if grep -q 'android.permission.INTERNET' "$m"; then
echo "::error file=$m::INTERNET permission found in merged release manifest"
found=1
fi
done
exit $found
# For information only: posts (and keeps updating) one PR comment with the core/security
# coverage. It never fails the build.
- name: Coverage comment
if: github.event_name == 'pull_request'
continue-on-error: true
uses: madrapps/jacoco-report@e51ce1f46f7f8b5331593f935e59cbaf44b84920 # v1.8.0
with:
paths: app/build/reports/kover/reportFdroidDebug.xml
token: ${{ secrets.GITHUB_TOKEN }}
title: 'Coverage (core/security)'
update-comment: true
min-coverage-overall: 0
min-coverage-changed-files: 0
- name: Upload reports on failure
if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: reports
path: |
app/build/reports/
app/build/test-results/
retention-days: 7
if-no-files-found: ignore