Repository navigation
53 lines (46 loc) · 1.97 KB
/
Copy pathrelease.yml
File metadata and controls
53 lines (46 loc) · 1.97 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
name: Release
# NOTE: This produces an *unsigned* (ad-hoc) build, which hits Gatekeeper's
# hard "cannot verify developer" block on download. Real releases are cut
# locally and signed via `scripts/release.sh` (Apple Development identity +
# hardened runtime), so this no longer auto-runs on tag push -- it's kept
# for manual, on-demand unsigned builds only. Promote to Developer ID +
# notarization here if public friction-free distribution is ever needed.
on:
workflow_dispatch:
jobs:
build-and-release:
runs-on: macos-15
permissions:
contents: write
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Select Xcode
run: sudo xcode-select -s /Applications/Xcode.app/Contents/Developer
- name: Derive version from tag
id: version
run: echo "marketing_version=${GITHUB_REF_NAME#v}" >> "$GITHUB_OUTPUT"
- name: Build (Release, unsigned)
run: |
xcodebuild -project SoundCheck.xcodeproj \
-scheme SoundCheck \
-configuration Release \
-destination 'platform=macOS' \
-derivedDataPath build \
ARCHS="arm64 x86_64" ONLY_ACTIVE_ARCH=NO \
CODE_SIGNING_ALLOWED=NO \
MARKETING_VERSION=${{ steps.version.outputs.marketing_version }} \
CURRENT_PROJECT_VERSION=${{ github.run_number }} \
build
- name: Zip app bundle
run: |
cd build/Build/Products/Release
ditto -c -k --sequesterRsrc --keepParent SoundCheck.app "$GITHUB_WORKSPACE/SoundCheck-${{ github.ref_name }}.zip"
- name: Create GitHub release
uses: softprops/action-gh-release@v2
with:
files: SoundCheck-${{ github.ref_name }}.zip
generate_release_notes: true
body: |
Unsigned build — macOS will show a Gatekeeper warning on first launch.
To open: right-click `SoundCheck.app` > **Open** > **Open** (or run `xattr -cr SoundCheck.app` first).