🐛 fix(ci): pass version to release job via QUIRE_VERSION_FALLBACK #39
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: android-ci | |
| on: | |
| push: | |
| paths: | |
| - "app/**" | |
| - "auth/**" | |
| - "core/**" | |
| - "data/**" | |
| - "reader/**" | |
| - "build.gradle.kts" | |
| - "settings.gradle.kts" | |
| - "gradle.properties" | |
| - "gradle/**" | |
| - "gradlew" | |
| - ".github/workflows/android-ci.yaml" | |
| pull_request: | |
| paths: | |
| - "app/**" | |
| - "auth/**" | |
| - "core/**" | |
| - "data/**" | |
| - "reader/**" | |
| - "build.gradle.kts" | |
| - "settings.gradle.kts" | |
| - "gradle.properties" | |
| - "gradle/**" | |
| - "gradlew" | |
| - ".github/workflows/android-ci.yaml" | |
| # Cancel obsolete runs on PR / branch pushes. Never cancel runs on main — | |
| # we want a Release for every commit that lands. | |
| concurrency: | |
| group: android-ci-${{ github.ref }} | |
| cancel-in-progress: ${{ github.ref != 'refs/heads/main' }} | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| version: ${{ steps.version.outputs.version }} | |
| steps: | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| fetch-depth: 0 | |
| fetch-tags: true | |
| - uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 | |
| with: | |
| distribution: temurin | |
| java-version: "17" | |
| - uses: android-actions/setup-android@9fc6c4e9069bf8d3d10b2204b1fb8f6ef7065407 # v3 | |
| with: | |
| packages: "platform-tools platforms;android-34 build-tools;34.0.0" | |
| - uses: gradle/actions/setup-gradle@ed408507eac070d1f99cc633dbcf757c94c7933a # v4 | |
| - id: version | |
| name: Compute version | |
| run: | | |
| if [ "$GITHUB_REF" = "refs/heads/main" ]; then | |
| # On main: bump CalVer (date + CI run number) and tag the HEAD | |
| # locally so Gradle's git-describe finds an exact-match tag. | |
| # The release job pushes this tag when it creates the Release. | |
| BUILD_DATE=$(date -u +%Y-%m-%d) | |
| VERSION="${BUILD_DATE//-/.}.${GITHUB_RUN_NUMBER}" | |
| git tag "v$VERSION" | |
| else | |
| # On PRs / feature branches: derive from existing tag history. | |
| # Post-tag dev format is fine for non-release artifact names. | |
| if ! git describe --tags --match 'v*' --abbrev=0 >/dev/null 2>&1; then | |
| echo "::error::No matching v* tag in history. Build will fail." | |
| git tag -l 'v*' | head | |
| exit 1 | |
| fi | |
| VERSION=$(git describe --tags --match 'v*' --always | sed 's/^v//') | |
| fi | |
| echo "VERSION_NAME=$VERSION" >> "$GITHUB_ENV" | |
| echo "version=$VERSION" >> "$GITHUB_OUTPUT" | |
| echo "Building version $VERSION" | |
| - name: Assemble debug APK | |
| run: ./gradlew assembleDebug --stacktrace | |
| - name: Unit tests | |
| run: ./gradlew test --stacktrace | |
| - name: Lint | |
| run: ./gradlew lint --stacktrace | |
| - name: Upload debug APK | |
| if: github.ref == 'refs/heads/main' | |
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 | |
| with: | |
| name: app-debug-${{ env.VERSION_NAME }} | |
| path: app/build/outputs/apk/debug/*.apk | |
| if-no-files-found: error | |
| # On main only: build the signed release APK and publish a GitHub | |
| # Release. The release action creates the tag itself, so we don't push | |
| # tags from the workflow (workflow-pushed tags via GITHUB_TOKEN don't | |
| # trigger downstream runs anyway, which is why this used to be split). | |
| release: | |
| needs: build | |
| if: github.ref == 'refs/heads/main' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| steps: | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| fetch-depth: 0 | |
| fetch-tags: true | |
| - uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 | |
| with: | |
| distribution: temurin | |
| java-version: "17" | |
| - uses: android-actions/setup-android@9fc6c4e9069bf8d3d10b2204b1fb8f6ef7065407 # v3 | |
| with: | |
| packages: "platform-tools platforms;android-34 build-tools;34.0.0" | |
| - uses: gradle/actions/setup-gradle@ed408507eac070d1f99cc633dbcf757c94c7933a # v4 | |
| - name: Decode keystore | |
| if: env.KEYSTORE_B64 != '' | |
| run: echo "$KEYSTORE_B64" | base64 -d > "$RUNNER_TEMP/release.keystore" | |
| env: | |
| KEYSTORE_B64: ${{ secrets.QUIRE_RELEASE_KEYSTORE_B64 }} | |
| - name: Assemble release APK | |
| env: | |
| # The build job created the tag locally on its runner so Gradle's | |
| # git-describe found an exact match. Each release-job runner gets | |
| # a fresh checkout with no local tag, so feed the same CalVer in | |
| # via the parser's fallback path. | |
| QUIRE_VERSION_FALLBACK: ${{ needs.build.outputs.version }} | |
| QUIRE_RELEASE_KEYSTORE: ${{ secrets.QUIRE_RELEASE_KEYSTORE_B64 != '' && format('{0}/release.keystore', runner.temp) || '' }} | |
| QUIRE_RELEASE_KEYSTORE_PASSWORD: ${{ secrets.QUIRE_RELEASE_KEYSTORE_PASSWORD }} | |
| QUIRE_RELEASE_KEY_ALIAS: ${{ secrets.QUIRE_RELEASE_KEY_ALIAS }} | |
| QUIRE_RELEASE_KEY_PASSWORD: ${{ secrets.QUIRE_RELEASE_KEY_PASSWORD }} | |
| run: ./gradlew :app:assembleRelease --stacktrace | |
| - name: Create GitHub Release | |
| uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2 | |
| with: | |
| tag_name: v${{ needs.build.outputs.version }} | |
| files: app/build/outputs/apk/release/*.apk | |
| generate_release_notes: true |