Skip to content

🐛 fix(build): disable VCS info embedding for reproducible builds #41

🐛 fix(build): disable VCS info embedding for reproducible builds

🐛 fix(build): disable VCS info embedding for reproducible builds #41

Workflow file for this run

name: android-ci
on:
push:
paths:
- "app/**"
- "auth/**"
- "core/**"
- "data/**"
- "reader/**"
- "build.gradle.kts"
- "settings.gradle.kts"
- "gradle.properties"
- "gradle/**"
- "gradlew"
- ".github/workflows/android-ci.yaml"
pull_request:
paths:
- "app/**"
- "auth/**"
- "core/**"
- "data/**"
- "reader/**"
- "build.gradle.kts"
- "settings.gradle.kts"
- "gradle.properties"
- "gradle/**"
- "gradlew"
- ".github/workflows/android-ci.yaml"
# Cancel obsolete runs on PR / branch pushes. Never cancel runs on main —
# we want a Release for every commit that lands.
concurrency:
group: android-ci-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
jobs:
build:
runs-on: ubuntu-latest
outputs:
version: ${{ steps.version.outputs.version }}
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
fetch-depth: 0
fetch-tags: true
- uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4
with:
distribution: temurin
java-version: "21"
- uses: android-actions/setup-android@9fc6c4e9069bf8d3d10b2204b1fb8f6ef7065407 # v3
with:
packages: "platform-tools platforms;android-34 build-tools;34.0.0"
- uses: gradle/actions/setup-gradle@ed408507eac070d1f99cc633dbcf757c94c7933a # v4
- id: version
name: Compute version
run: |
if [ "$GITHUB_REF" = "refs/heads/main" ]; then
# On main: bump CalVer (date + CI run number) and tag the HEAD
# locally so Gradle's git-describe finds an exact-match tag.
# The release job pushes this tag when it creates the Release.
BUILD_DATE=$(date -u +%Y-%m-%d)
VERSION="${BUILD_DATE//-/.}.${GITHUB_RUN_NUMBER}"
git tag "v$VERSION"
else
# On PRs / feature branches: derive from existing tag history.
# Post-tag dev format is fine for non-release artifact names.
if ! git describe --tags --match 'v*' --abbrev=0 >/dev/null 2>&1; then
echo "::error::No matching v* tag in history. Build will fail."
git tag -l 'v*' | head
exit 1
fi
VERSION=$(git describe --tags --match 'v*' --always | sed 's/^v//')
fi
echo "VERSION_NAME=$VERSION" >> "$GITHUB_ENV"
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
echo "Building version $VERSION"
- name: Assemble debug APK
run: ./gradlew assembleDebug --stacktrace
- name: Unit tests
run: ./gradlew test --stacktrace
- name: Lint
run: ./gradlew lint --stacktrace
- name: Upload debug APK
if: github.ref == 'refs/heads/main'
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: app-debug-${{ env.VERSION_NAME }}
path: app/build/outputs/apk/debug/*.apk
if-no-files-found: error
# On main only: build the signed release APK and publish a GitHub
# Release. The release action creates the tag itself, so we don't push
# tags from the workflow (workflow-pushed tags via GITHUB_TOKEN don't
# trigger downstream runs anyway, which is why this used to be split).
release:
needs: build
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
fetch-depth: 0
fetch-tags: true
- uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4
with:
distribution: temurin
java-version: "21"
- uses: android-actions/setup-android@9fc6c4e9069bf8d3d10b2204b1fb8f6ef7065407 # v3
with:
packages: "platform-tools platforms;android-34 build-tools;34.0.0"
- uses: gradle/actions/setup-gradle@ed408507eac070d1f99cc633dbcf757c94c7933a # v4
- name: Decode keystore
if: env.KEYSTORE_B64 != ''
run: echo "$KEYSTORE_B64" | base64 -d > "$RUNNER_TEMP/release.keystore"
env:
KEYSTORE_B64: ${{ secrets.QUIRE_RELEASE_KEYSTORE_B64 }}
- name: Assemble release APK
env:
# The build job created the tag locally on its runner so Gradle's
# git-describe found an exact match. Each release-job runner gets
# a fresh checkout with no local tag, so feed the same CalVer in
# via the parser's fallback path.
QUIRE_VERSION_FALLBACK: ${{ needs.build.outputs.version }}
QUIRE_RELEASE_KEYSTORE: ${{ secrets.QUIRE_RELEASE_KEYSTORE_B64 != '' && format('{0}/release.keystore', runner.temp) || '' }}
QUIRE_RELEASE_KEYSTORE_PASSWORD: ${{ secrets.QUIRE_RELEASE_KEYSTORE_PASSWORD }}
QUIRE_RELEASE_KEY_ALIAS: ${{ secrets.QUIRE_RELEASE_KEY_ALIAS }}
QUIRE_RELEASE_KEY_PASSWORD: ${{ secrets.QUIRE_RELEASE_KEY_PASSWORD }}
run: ./gradlew :app:assembleRelease --stacktrace
- name: Create GitHub Release
uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2
with:
tag_name: v${{ needs.build.outputs.version }}
files: app/build/outputs/apk/release/*.apk
generate_release_notes: true