ci: setup windows with signing and gcs publish
This commit is contained in:
+115
-121
@@ -1,121 +1,115 @@
|
||||
import type { ForgeConfig } from '@electron-forge/shared-types';
|
||||
import { MakerSquirrel } from '@electron-forge/maker-squirrel';
|
||||
import { MakerZIP } from '@electron-forge/maker-zip';
|
||||
import { MakerDeb } from '@electron-forge/maker-deb';
|
||||
import { MakerRpm } from '@electron-forge/maker-rpm';
|
||||
import { VitePlugin } from '@electron-forge/plugin-vite';
|
||||
import { FusesPlugin } from '@electron-forge/plugin-fuses';
|
||||
import { FuseV1Options, FuseVersion } from '@electron/fuses';
|
||||
|
||||
const config: ForgeConfig = {
|
||||
packagerConfig: {
|
||||
asar: true,
|
||||
icon: './assets/flowy',
|
||||
appBundleId: 'live.flowy.llink',
|
||||
protocols: [
|
||||
{ name: 'llink', schemes: ['llink'] },
|
||||
],
|
||||
extendInfo: {
|
||||
NSMicrophoneUsageDescription: 'llink needs microphone access to record audio messages.',
|
||||
NSCameraUsageDescription: 'llink needs camera access to record video messages.',
|
||||
},
|
||||
osxSign: {},
|
||||
osxNotarize: {
|
||||
keychainProfile: 'default',
|
||||
}
|
||||
},
|
||||
publishers: [
|
||||
{
|
||||
name: '@electron-forge/publisher-gcs',
|
||||
config: {
|
||||
storageOptions: {
|
||||
projectId: 'flowy-prod-440017'
|
||||
},
|
||||
bucket: 'flowy-releases',
|
||||
folder: 'llink',
|
||||
// NOTE: commented out because we do not want to apply per object ACL which conflicts with uniform bucket-level access that's already public
|
||||
// public: true
|
||||
}
|
||||
}
|
||||
],
|
||||
rebuildConfig: {},
|
||||
makers: [
|
||||
new MakerSquirrel((arch) => ({
|
||||
// `remoteReleases` is only useful when producing delta packages against a
|
||||
// previously-published build. During a plain `make` (no publish), Squirrel
|
||||
// fetches this URL and fails with a 404 if nothing has been uploaded yet.
|
||||
// Gate it on SQUIRREL_REMOTE_RELEASES=1 which the publish workflow sets.
|
||||
...(process.env.SQUIRREL_REMOTE_RELEASES === '1' ? {
|
||||
remoteReleases: `https://storage.googleapis.com/flowy-releases/llink/win32/${arch}`,
|
||||
} : {}),
|
||||
// Windows code signing via Azure Trusted Signing. Dormant unless the workflow
|
||||
// provisions the dlib + metadata file and exports these env vars, so local
|
||||
// `yarn make` and unsigned CI builds both work unchanged.
|
||||
windowsSign: process.env.AZURE_METADATA_JSON_PATH ? {
|
||||
signWithParams: [
|
||||
'/v',
|
||||
'/fd', 'SHA256',
|
||||
'/tr', 'http://timestamp.acs.microsoft.com',
|
||||
'/td', 'SHA256',
|
||||
'/dlib', process.env.AZURE_DLIB_PATH,
|
||||
'/dmdf', process.env.AZURE_METADATA_JSON_PATH,
|
||||
].join(' '),
|
||||
} : undefined,
|
||||
})),
|
||||
new MakerZIP((arch) => ({
|
||||
macUpdateManifestBaseUrl: `https://storage.googleapis.com/flowy-releases/llink/darwin/${arch}`
|
||||
}), ['darwin']),
|
||||
new MakerRpm({}),
|
||||
new MakerDeb({}),
|
||||
],
|
||||
plugins: [
|
||||
new VitePlugin({
|
||||
// `build` can specify multiple entry builds, which can be Main process, Preload scripts, Worker process, etc.
|
||||
// If you are familiar with Vite configuration, it will look really familiar.
|
||||
build: [
|
||||
{
|
||||
// `entry` is just an alias for `build.lib.entry` in the corresponding file of `config`.
|
||||
entry: 'src/main.ts',
|
||||
config: 'vite.main.config.ts',
|
||||
target: 'main',
|
||||
},
|
||||
{
|
||||
entry: 'src/preload.ts',
|
||||
config: 'vite.preload.config.ts',
|
||||
target: 'preload',
|
||||
},
|
||||
],
|
||||
renderer: [
|
||||
{
|
||||
name: 'main_window',
|
||||
config: 'vite.renderer.config.mts',
|
||||
},
|
||||
{
|
||||
name: 'autoplay_window',
|
||||
config: 'vite.autoplay.config.mts',
|
||||
},
|
||||
{
|
||||
name: 'huddle_window',
|
||||
config: 'vite.huddle.config.mts',
|
||||
},
|
||||
{
|
||||
name: 'screen_record_window',
|
||||
config: 'vite.screen-record.config.mts',
|
||||
},
|
||||
],
|
||||
}),
|
||||
// Fuses are used to enable/disable various Electron functionality
|
||||
// at package time, before code signing the application
|
||||
new FusesPlugin({
|
||||
version: FuseVersion.V1,
|
||||
[FuseV1Options.RunAsNode]: false,
|
||||
[FuseV1Options.EnableCookieEncryption]: true,
|
||||
[FuseV1Options.EnableNodeOptionsEnvironmentVariable]: false,
|
||||
[FuseV1Options.EnableNodeCliInspectArguments]: false,
|
||||
[FuseV1Options.EnableEmbeddedAsarIntegrityValidation]: true,
|
||||
[FuseV1Options.OnlyLoadAppFromAsar]: true,
|
||||
}),
|
||||
],
|
||||
};
|
||||
|
||||
export default config;
|
||||
import type { ForgeConfig } from '@electron-forge/shared-types';
|
||||
import { MakerSquirrel } from '@electron-forge/maker-squirrel';
|
||||
import { MakerZIP } from '@electron-forge/maker-zip';
|
||||
import { MakerDeb } from '@electron-forge/maker-deb';
|
||||
import { MakerRpm } from '@electron-forge/maker-rpm';
|
||||
import { VitePlugin } from '@electron-forge/plugin-vite';
|
||||
import { FusesPlugin } from '@electron-forge/plugin-fuses';
|
||||
import { FuseV1Options, FuseVersion } from '@electron/fuses';
|
||||
|
||||
const config: ForgeConfig = {
|
||||
packagerConfig: {
|
||||
asar: true,
|
||||
icon: './assets/flowy',
|
||||
appBundleId: 'live.flowy.llink',
|
||||
protocols: [
|
||||
{ name: 'llink', schemes: ['llink'] },
|
||||
],
|
||||
extendInfo: {
|
||||
NSMicrophoneUsageDescription: 'llink needs microphone access to record audio messages.',
|
||||
NSCameraUsageDescription: 'llink needs camera access to record video messages.',
|
||||
},
|
||||
osxSign: {},
|
||||
osxNotarize: {
|
||||
keychainProfile: 'default',
|
||||
}
|
||||
},
|
||||
publishers: [
|
||||
{
|
||||
name: '@electron-forge/publisher-gcs',
|
||||
config: {
|
||||
storageOptions: {
|
||||
projectId: 'flowy-prod-440017'
|
||||
},
|
||||
bucket: 'flowy-releases',
|
||||
folder: 'llink',
|
||||
// NOTE: commented out because we do not want to apply per object ACL which conflicts with uniform bucket-level access that's already public
|
||||
// public: true
|
||||
}
|
||||
}
|
||||
],
|
||||
rebuildConfig: {},
|
||||
makers: [
|
||||
new MakerSquirrel((arch) => ({
|
||||
remoteReleases: `https://storage.googleapis.com/flowy-releases/llink/win32/${arch}`,
|
||||
// Windows code signing via Azure Trusted Signing. Dormant unless the workflow
|
||||
// provisions the dlib + metadata file and exports these env vars, so local
|
||||
// `yarn make` and unsigned CI builds both work unchanged.
|
||||
windowsSign: process.env.AZURE_METADATA_JSON_PATH ? {
|
||||
signWithParams: [
|
||||
'/v',
|
||||
'/fd', 'SHA256',
|
||||
'/tr', 'http://timestamp.acs.microsoft.com',
|
||||
'/td', 'SHA256',
|
||||
'/dlib', process.env.AZURE_DLIB_PATH,
|
||||
'/dmdf', process.env.AZURE_METADATA_JSON_PATH,
|
||||
].join(' '),
|
||||
} : undefined,
|
||||
})),
|
||||
new MakerZIP((arch) => ({
|
||||
macUpdateManifestBaseUrl: `https://storage.googleapis.com/flowy-releases/llink/darwin/${arch}`
|
||||
}), ['darwin']),
|
||||
new MakerRpm({}),
|
||||
new MakerDeb({}),
|
||||
],
|
||||
plugins: [
|
||||
new VitePlugin({
|
||||
// `build` can specify multiple entry builds, which can be Main process, Preload scripts, Worker process, etc.
|
||||
// If you are familiar with Vite configuration, it will look really familiar.
|
||||
build: [
|
||||
{
|
||||
// `entry` is just an alias for `build.lib.entry` in the corresponding file of `config`.
|
||||
entry: 'src/main.ts',
|
||||
config: 'vite.main.config.ts',
|
||||
target: 'main',
|
||||
},
|
||||
{
|
||||
entry: 'src/preload.ts',
|
||||
config: 'vite.preload.config.ts',
|
||||
target: 'preload',
|
||||
},
|
||||
],
|
||||
renderer: [
|
||||
{
|
||||
name: 'main_window',
|
||||
config: 'vite.renderer.config.mts',
|
||||
},
|
||||
{
|
||||
name: 'autoplay_window',
|
||||
config: 'vite.autoplay.config.mts',
|
||||
},
|
||||
{
|
||||
name: 'huddle_window',
|
||||
config: 'vite.huddle.config.mts',
|
||||
},
|
||||
{
|
||||
name: 'screen_record_window',
|
||||
config: 'vite.screen-record.config.mts',
|
||||
},
|
||||
],
|
||||
}),
|
||||
// Fuses are used to enable/disable various Electron functionality
|
||||
// at package time, before code signing the application
|
||||
new FusesPlugin({
|
||||
version: FuseVersion.V1,
|
||||
[FuseV1Options.RunAsNode]: false,
|
||||
[FuseV1Options.EnableCookieEncryption]: true,
|
||||
[FuseV1Options.EnableNodeOptionsEnvironmentVariable]: false,
|
||||
[FuseV1Options.EnableNodeCliInspectArguments]: false,
|
||||
[FuseV1Options.EnableEmbeddedAsarIntegrityValidation]: true,
|
||||
[FuseV1Options.OnlyLoadAppFromAsar]: true,
|
||||
}),
|
||||
],
|
||||
};
|
||||
|
||||
export default config;
|
||||
|
||||
Reference in New Issue
Block a user