Skip to content

Mirror moomux's Test/Deploy/Release pipeline - #77

Merged
afitzgerald merged 2 commits into
mainfrom
alan/release-pipeline
Sep 5, 2026
Merged

afitzgerald merged 2 commits into
mainfrom
alan/release-pipeline

Conversation

@afitzgerald

Copy link
Copy Markdown
Owner

Summary

Adopts the same three-workflow shape as erickgnclvs/moomux's release process:

  1. Test (renamed from build-dmg.yml) — now also runs yarn typecheck and yarn test, and runs on PRs too (previously push-to-main only). Still builds an unsigned DMG as a build-check artifact.
  2. Deploy — triggers on Test succeeding on main; computes the next vX.Y.Z tag from conventional-commit subjects since the last tag (scripts/next_version.sh, ported near-verbatim from moomux — type!:/BREAKING CHANGE → major, else patch), tags, pushes, and dispatches Release. Explicit dispatch because a GITHUB_TOKEN-authored tag push doesn't trigger other workflows (GitHub's anti-recursion rule).
  3. Release — builds, code-signs, notarizes, and publishes the DMG/zip to a GitHub Release for that tag, via electron-builder --publish always (added a publish: {provider: github} block to package.json).

build/afterSign.js gains a CI notarization path (APPLE_ID/APPLE_APP_PASSWORD/APPLE_TEAM_ID env vars) alongside the existing local keychain-profile path, so dev machines are unaffected.

Before Release can actually run, these repo secrets need to be added (Settings → Secrets and variables → Actions):

  • CSC_LINK / CSC_KEY_PASSWORD — base64-encoded Developer ID Application .p12 + its password
  • APPLE_ID / APPLE_APP_PASSWORD / APPLE_TEAM_ID — notarization credentials

I don't have a way to set these myself (no access to the certificate/passwords). Test and Deploy work without them; Release will fail at the signing step until they're added.

Test plan

  • YAML-validated all three workflow files
  • node -c build/afterSign.js, bash -n scripts/next_version.sh
  • yarn test passes
  • First real Release run (needs the secrets above)

…leases

Test (renamed from the old build-dmg workflow) now also runs typecheck
and the unit/integration suite, and runs on PRs too, not just pushes to
main. Deploy computes the next semver tag from conventional-commit
subjects (scripts/next_version.sh, ported near-verbatim from moomux) and
dispatches Release, which builds, code-signs, notarizes, and publishes
the DMG/zip to a GitHub Release.

afterSign.js gains a CI path: APPLE_ID/APPLE_APP_PASSWORD/APPLE_TEAM_ID
env vars (used by the Release workflow) alongside the existing local
keychain-profile path for dev machines.

Needs these repo secrets before Release can actually run: CSC_LINK,
CSC_KEY_PASSWORD, APPLE_ID, APPLE_APP_PASSWORD, APPLE_TEAM_ID.
Points afitzgerald/homebrew-diffier at the signed DMG electron-builder
just published, so `brew install --cask afitzgerald/diffier/diffier`
tracks releases automatically.
@afitzgerald
afitzgerald merged commit b37f605 into main Sep 5, 2026
1 check passed
@afitzgerald
afitzgerald deleted the alan/release-pipeline branch September 5, 2026 00:50
afitzgerald added a commit that referenced this pull request Sep 30, 2026
Mirror moomux's Test/Deploy/Release pipeline
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant