Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions .github/workflows/build+test+deploy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,11 @@ jobs:

runs-on: android-large-runner

outputs:
version: ${{ steps.version.outputs.prop }}
released: ${{ steps.release.outcome == 'success' }}
prerelease: ${{ steps.prerelease.outputs.status }}

steps:
- uses: actions/checkout@v3
with:
Expand Down Expand Up @@ -174,3 +179,14 @@ jobs:
env:
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK }}
SLACK_WEBHOOK_TYPE: INCOMING_WEBHOOK

# Lets Flutter, Expo and KMP open a bump PR for this version. Called directly
# because the release above is created with GITHUB_TOKEN, which never fires
# `release` events for other workflows.
notify_wrappers:
needs: build
if: needs.build.outputs.released == 'true' && needs.build.outputs.prerelease == 'false'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This if: has no status function, so GitHub implicitly adds success(). If anything after Create GitHub release fails (today that is slack-send), build goes red and the job is skipped. The next push then sees release-exists=true, so released is never true again for that version, and the wrappers are never notified unless someone runs it by hand. Using !cancelled() gates the job on the release itself rather than on the Slack ping.

Suggested change
if: needs.build.outputs.released == 'true' && needs.build.outputs.prerelease == 'false'
if: ${{ !cancelled() && needs.build.outputs.released == 'true' && needs.build.outputs.prerelease == 'false' }}

uses: ./.github/workflows/notify-wrappers.yml
with:
version: ${{ needs.build.outputs.version }}
secrets: inherit

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

secrets: inherit forwards every repo secret (AWS keys, Maven Central credentials, GPG signing key) into a job that only needs WRAPPER_DISPATCH_TOKEN. Passing just that one secret keeps the called workflow least-privilege. It also needs a matching secrets: WRAPPER_DISPATCH_TOKEN: { required: false } declaration under workflow_call in notify-wrappers.yml.

Suggested change
secrets: inherit
secrets:
WRAPPER_DISPATCH_TOKEN: ${{ secrets.WRAPPER_DISPATCH_TOKEN }}

69 changes: 69 additions & 0 deletions .github/workflows/notify-wrappers.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
# Tells the cross-platform wrappers (Flutter, Expo, KMP) that a new native SDK
# release exists. Each wrapper's native-sdk-bump.yml picks the event up, bumps
# its pinned native version, and opens a PR (with any integration work done by
# an agent on top).
#
# Android releases are created by build+test+deploy.yml with GITHUB_TOKEN, and
# GitHub never fires `release` events for GITHUB_TOKEN-created releases — so that
# workflow calls this one directly (workflow_call). `release: published` only
# covers releases made by hand; a duplicate dispatch is harmless, the wrappers
# skip versions they already have a PR for.
#
# Requires the WRAPPER_DISPATCH_TOKEN secret: a fine-grained PAT (or GitHub App
# token) with "Contents: read & write" on every repo in WRAPPER_REPOS — that is
# the permission the repository_dispatch API checks. GITHUB_TOKEN cannot
# dispatch into other repositories.
name: Notify wrapper SDKs

on:
release:
types: [published]
workflow_call:
inputs:
version:
required: true
type: string
workflow_dispatch:
inputs:
version:
description: Released version to announce (e.g. 2.8.5)
required: true
type: string

permissions:
contents: read

env:
PLATFORM: android
WRAPPER_REPOS: superwall/Superwall-Flutter superwall/expo-superwall superwall/Superwall-KMP

jobs:
dispatch:
runs-on: ubuntu-latest
# Wrappers only ship stable native versions.
if: github.event_name != 'release' || !github.event.release.prerelease
steps:
- name: Dispatch native-sdk-release
env:
GH_TOKEN: ${{ secrets.WRAPPER_DISPATCH_TOKEN }}
VERSION: ${{ inputs.version || github.event.release.tag_name }}
run: |
VERSION="${VERSION#v}"
if ! [[ "$VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
echo "::notice::'$VERSION' is not a stable x.y.z version, not notifying wrappers."
exit 0
fi
failed=0
for repo in $WRAPPER_REPOS; do
# One wrapper being unreachable must not stop the others.
if gh api "repos/$repo/dispatches" \
-f event_type=native-sdk-release \
-f "client_payload[platform]=$PLATFORM" \
-f "client_payload[version]=$VERSION"; then
echo "Notified $repo of $PLATFORM $VERSION"
else
echo "::error::Could not dispatch to $repo"
failed=1
fi
done
exit $failed
Loading