# Phase 1: build unsigned Windows installers on demand, upload as run artifacts. # # To graduate to Phase 2 (signed + published to GCS): # 1. Add GCP auth step (`google-github-actions/auth@v2` via WIF) + `setup-gcloud`. # Swap `yarn make:win` for a new `yarn release:win` script that runs # `electron-forge publish` per arch and a gsutil cache-control step. # 2. Add an Azure Trusted Signing setup step that downloads the # Microsoft.Trusted.Signing.Client dlib and writes a metadata JSON file, # then exports AZURE_DLIB_PATH + AZURE_METADATA_JSON_PATH. Set # AZURE_TENANT_ID / AZURE_CLIENT_ID / AZURE_CLIENT_SECRET from secrets. # The dormant `windowsSign` branch in js/forge.config.ts activates # automatically once AZURE_METADATA_JSON_PATH is set. name: Build Windows on: workflow_dispatch: jobs: build: runs-on: windows-latest defaults: run: working-directory: js env: APP_ENV: prod steps: - uses: actions/checkout@v4 - name: Enable corepack run: corepack enable shell: pwsh working-directory: . - uses: actions/setup-node@v4 with: node-version: 20 cache: yarn cache-dependency-path: js/yarn.lock - name: Install dependencies run: yarn install --frozen-lockfile --network-timeout 600000 - name: Build Windows installers (x64 + arm64, unsigned) run: yarn make:win - name: Upload installers uses: actions/upload-artifact@v4 with: name: flowy-llink-windows-unsigned path: js/out/make/**/* if-no-files-found: error