--- name: Bundle and Deploy EAS Update on: push: branches: - main workflow_dispatch: inputs: channel: type: choice description: Deployment channel to use options: - testflight - production runtimeVersion: type: string description: Runtime version (in x.x.x format) that this update is for required: true jobs: bundleDeploy: if: github.repository == 'bluesky-social/social-app' name: Bundle and Deploy EAS Update runs-on: ubuntu-latest concurrency: group: ${{ github.workflow }}-${{ github.event_name }}-${{ github.ref }}-deploy cancel-in-progress: true outputs: changes-detected: ${{ steps.fingerprint.outputs.includes-changes }} steps: - name: Check for EXPO_TOKEN run: > if [ -z "${{ secrets.EXPO_TOKEN }}" ]; then echo "You must provide an EXPO_TOKEN secret linked to this project's Expo account in this repo's secrets. Learn more: https://docs.expo.dev/eas-update/github-actions" exit 1 fi # Validate the version if one is supplied. This should generally happen if the update is for a production client - name: 🧐 Validate version env: RUNTIME_VERSION: ${{ inputs.runtimeVersion }} if: ${{ inputs.runtimeVersion }} run: | if [ -z "$RUNTIME_VERSION" ]; then [[ "$RUNTIME_VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]] && echo "Version is valid" || exit 1 fi - name: ⬇️ Checkout uses: actions/checkout@v5 with: fetch-depth: 0 - name: ⬇️ Fetch commits from base branch if: ${{ github.ref != 'refs/heads/main' }} run: git fetch origin main:main --depth 100 - uses: pnpm/action-setup@v6 - name: 🔧 Setup Node uses: actions/setup-node@v6 with: node-version-file: .nvmrc cache: pnpm - name: 📷 Check fingerprint and install dependencies id: fingerprint uses: bluesky-social/github-actions/fingerprint-native@main with: profile: ${{ inputs.channel || 'testflight' }} previous-commit-tag: ${{ inputs.runtimeVersion }} - name: Lint check run: pnpm lint - name: Prettier check run: pnpm prettier --check . - name: 🔤 Compile translations run: pnpm intl:build 2>&1 | tee i18n.log - name: Check for i18n compilation errors run: if grep -q "invalid syntax" "i18n.log"; then echo "\n\nFound compilation errors!\n\n" && exit 1; else echo "\n\nNo compilation errors!\n\n"; fi - name: Type check run: pnpm typecheck - name: 🔨 Setup EAS uses: expo/expo-github-action@main if: ${{ !steps.fingerprint.outputs.includes-changes }} with: expo-version: latest eas-version: latest packager: pnpm token: ${{ secrets.EXPO_TOKEN }} - name: ⛏️ Setup Expo if: ${{ !steps.fingerprint.outputs.includes-changes }} run: pnpm add -g eas-cli-local-build-plugin - name: 🪛 Setup jq if: ${{ !steps.fingerprint.outputs.includes-changes }} uses: dcarbone/install-jq-action@v2 # eas.json not used here, set EXPO_PUBLIC_ENV - name: Env env: CHANNEL: ${{ inputs.channel || 'testflight' }} GITHUB_SHA: ${{ github.sha }} id: env if: ${{ !steps.fingerprint.outputs.includes-changes }} run: | export json='${{ secrets.GOOGLE_SERVICES_TOKEN }}' echo "${{ secrets.ENV_TOKEN }}" > .env echo "EXPO_PUBLIC_ENV=$CHANNEL" >> .env echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> .env echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> $GITHUB_OUTPUT echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> .env echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> $GITHUB_OUTPUT echo "EXPO_PUBLIC_BUNDLE_DATE=$(date -u +"%y%m%d%H")" >> .env echo "EXPO_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN }}" >> .env echo "EXPO_PUBLIC_BITDRIFT_API_KEY=${{ secrets.BITDRIFT_API_KEY }}" >> .env echo "EXPO_PUBLIC_GCP_PROJECT_ID=${{ secrets.EXPO_PUBLIC_GCP_PROJECT_ID }}" >> .env echo "$json" > google-services.json - name: 🏗️ Create Bundle if: ${{ !steps.fingerprint.outputs.includes-changes }} run: > SENTRY_AUTH_TOKEN=${{ secrets.SENTRY_AUTH_TOKEN }} SENTRY_RELEASE=${{ steps.env.outputs.EXPO_PUBLIC_RELEASE_VERSION }} SENTRY_DIST=${{ steps.env.outputs.EXPO_PUBLIC_BUNDLE_IDENTIFIER }} pnpm export - name: 📦 Package Bundle and 🚀 Deploy if: ${{ !steps.fingerprint.outputs.includes-changes }} run: pnpm use-build-number bash scripts/bundleUpdate.sh env: DENIS_API_KEY: ${{ secrets.DENIS_API_KEY }} RUNTIME_VERSION: ${{ inputs.runtimeVersion }} CHANNEL_NAME: ${{ inputs.channel || 'testflight' }} - name: ⬇️ Restore Cache id: get-base-commit uses: actions/cache@v5 if: ${{ !steps.fingerprint.outputs.includes-changes }} with: path: most-recent-testflight-commit.txt key: most-recent-testflight-commit - name: ✏️ Write commit hash to cache if: ${{ !steps.fingerprint.outputs.includes-changes }} run: echo $GITHUB_SHA > most-recent-testflight-commit.txt # GitHub actions are horrible so let's just copy paste this in buildIfNecessaryIOS: name: Build and Submit iOS runs-on: macos-26 concurrency: group: ios-build cancel-in-progress: false needs: [bundleDeploy] # Gotta check if its NOT '[]' because any md5 hash in the outputs is detected as a possible secret and won't be # available here if: ${{ inputs.channel != 'production' && needs.bundleDeploy.outputs.changes-detected && github.repository == 'bluesky-social/social-app' }} steps: - name: Check for EXPO_TOKEN run: > if [ -z "${{ secrets.EXPO_TOKEN }}" ]; then echo "You must provide an EXPO_TOKEN secret linked to this project's Expo account in this repo's secrets. Learn more: https://docs.expo.dev/eas-update/github-actions" exit 1 fi - name: ⬇️ Checkout uses: actions/checkout@v5 with: fetch-depth: 5 - uses: pnpm/action-setup@v6 - name: 🔧 Setup Node uses: actions/setup-node@v6 with: node-version-file: .nvmrc cache: pnpm - name: 🔨 Setup EAS uses: expo/expo-github-action@main with: expo-version: latest eas-version: latest packager: pnpm token: ${{ secrets.EXPO_TOKEN }} - name: ⛏️ Setup EAS local builds run: pnpm add -g eas-cli-local-build-plugin - name: ⚙️ Install dependencies run: pnpm install --frozen-lockfile - uses: maxim-lobanov/setup-xcode@v1 with: xcode-version: "26.4" - name: ☕️ Setup Cocoapods uses: maxim-lobanov/setup-cocoapods@v1 with: version: 1.16.2 - name: 💾 Cache Pods uses: actions/cache@v5 id: pods-cache with: path: ./ios/Pods # We'll use the pnpm-lock.yaml for our hash since we don't yet have a Podfile.lock. Pod versions will not # change unless the pnpm version changes as well. key: ${{ runner.os }}-pods-${{ hashFiles('pnpm-lock.yaml') }} - name: 🔤 Compile translations run: pnpm intl:build # EXPO_PUBLIC_ENV is handled in eas.json - name: Env id: env run: | echo "${{ secrets.ENV_TOKEN }}" > .env echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> .env echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> $GITHUB_OUTPUT echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> .env echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> $GITHUB_OUTPUT echo "EXPO_PUBLIC_BUNDLE_DATE=$(date -u +"%y%m%d%H")" >> .env echo "EXPO_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN }}" >> .env echo "EXPO_PUBLIC_BITDRIFT_API_KEY=${{ secrets.BITDRIFT_API_KEY }}" >> .env echo "EXPO_PUBLIC_GCP_PROJECT_ID=${{ secrets.EXPO_PUBLIC_GCP_PROJECT_ID }}" >> .env echo "${{ secrets.GOOGLE_SERVICES_TOKEN }}" > google-services.json - name: 🏗️ EAS Build run: > SENTRY_AUTH_TOKEN=${{ secrets.SENTRY_AUTH_TOKEN }} SENTRY_RELEASE=${{ steps.env.outputs.EXPO_PUBLIC_RELEASE_VERSION }} SENTRY_DIST=${{ steps.env.outputs.EXPO_PUBLIC_BUNDLE_IDENTIFIER }} pnpm use-build-number-with-bump eas build -p ios --profile testflight --local --output build.tar.gz --non-interactive - name: 📂 Extract build artifact run: | if [ -f "build.tar.gz" ]; then echo "Extracting build.tar.gz..." rm -rf ios-build mkdir -p ios-build tar -xzf build.tar.gz -C ios-build echo "Extraction completed successfully" echo "" echo "Top-level extracted files:" find ios-build -maxdepth 3 -print echo "" echo "Searching for IPA..." IPA_PATH="$(find ios-build -type f -name '*.ipa' -print -quit)" if [ -z "$IPA_PATH" ]; then echo "ERROR: No .ipa found anywhere under ios-build." echo "Archive contents:" tar -tzf build.tar.gz | sed -n '1,200p' exit 1 fi BUILD_DIR="$(dirname "$IPA_PATH")" echo "Found IPA at: $IPA_PATH" echo "Build dir: $BUILD_DIR" echo "" echo "Build dir contents:" ls -la "$BUILD_DIR" echo "BUILD_DIR=$BUILD_DIR" >> $GITHUB_ENV else echo "Archive file not found!" exit 1 fi - name: 🚀 Deploy run: eas submit -p ios --non-interactive --path "$BUILD_DIR/Bluesky.ipa" - name: 🪲 Upload dSYM to Sentry run: > SENTRY_ORG=blueskyweb SENTRY_PROJECT=app SENTRY_AUTH_TOKEN=${{ secrets.SENTRY_AUTH_TOKEN }} pnpm sentry-cli debug-files upload "$BUILD_DIR/Bluesky.app.dSYM.zip" --include-sources - name: ⬇️ Restore Cache id: get-base-commit uses: actions/cache@v5 if: ${{ inputs.channel == 'testflight' }} with: path: most-recent-testflight-commit.txt key: most-recent-testflight-commit - name: ✏️ Write commit hash to cache if: ${{ inputs.channel == 'testflight' }} env: GITHUB_SHA: ${{ github.sha }} run: echo $GITHUB_SHA > most-recent-testflight-commit.txt buildIfNecessaryAndroid: name: Build and Submit Android runs-on: ubuntu-latest concurrency: group: android-build cancel-in-progress: false needs: [bundleDeploy] # Gotta check if its NOT '[]' because any md5 hash in the outputs is detected as a possible secret and won't be # available here if: ${{ inputs.channel != 'production' && needs.bundleDeploy.outputs.changes-detected && github.repository == 'bluesky-social/social-app'}} steps: - name: Check for EXPO_TOKEN run: > if [ -z "${{ secrets.EXPO_TOKEN }}" ]; then echo "You must provide an EXPO_TOKEN secret linked to this project's Expo account in this repo's secrets. Learn more: https://docs.expo.dev/eas-update/github-actions" exit 1 fi - name: ⬇️ Checkout uses: actions/checkout@v5 with: fetch-depth: 5 - uses: pnpm/action-setup@v6 - name: 🔧 Setup Node uses: actions/setup-node@v6 with: node-version-file: .nvmrc cache: pnpm - name: 🔨 Setup EAS uses: expo/expo-github-action@main with: expo-version: latest eas-version: latest packager: pnpm token: ${{ secrets.EXPO_TOKEN }} - name: ⛏️ Setup EAS local builds run: pnpm add -g eas-cli-local-build-plugin - uses: actions/setup-java@v5 with: distribution: "temurin" java-version: "17" - name: ⚙️ Install dependencies run: pnpm install --frozen-lockfile - name: 🔤 Compile translations run: pnpm intl:build # EXPO_PUBLIC_ENV is handled in eas.json - name: Env id: env run: | export json='${{ secrets.GOOGLE_SERVICES_TOKEN }}' echo "${{ secrets.ENV_TOKEN }}" > .env echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> .env echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> $GITHUB_OUTPUT echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> .env echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> $GITHUB_OUTPUT echo "EXPO_PUBLIC_BUNDLE_DATE=$(date -u +"%y%m%d%H")" >> .env echo "EXPO_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN }}" >> .env echo "EXPO_PUBLIC_BITDRIFT_API_KEY=${{ secrets.BITDRIFT_API_KEY }}" >> .env echo "EXPO_PUBLIC_GCP_PROJECT_ID=${{ secrets.EXPO_PUBLIC_GCP_PROJECT_ID }}" >> .env echo "$json" > google-services.json - name: 🏗️ EAS Build run: > SENTRY_AUTH_TOKEN=${{ secrets.SENTRY_AUTH_TOKEN }} SENTRY_RELEASE=${{ steps.env.outputs.EXPO_PUBLIC_RELEASE_VERSION }} SENTRY_DIST=${{ steps.env.outputs.EXPO_PUBLIC_BUNDLE_IDENTIFIER }} pnpm use-build-number-with-bump eas build -p android --profile testflight-android --local --output build.apk --non-interactive - name: ⏰ Get a timestamp id: timestamp uses: nanzm/get-time-action@master with: format: "MM-DD-HH-mm-ss" - name: 🚀 Upload Artifact id: upload-artifact uses: actions/upload-artifact@v7 with: retention-days: 30 compression-level: 0 name: build-${{ steps.timestamp.outputs.time }}.apk path: build.apk - name: 🔔 Notify Slack uses: slackapi/slack-github-action@v2.1.1 with: webhook: ${{ secrets.SLACK_CLIENT_ALERT_WEBHOOK }} webhook-type: incoming-webhook payload-templated: true payload: | text: Android build is ready for testing. Download the artifact here: ${{ steps.upload-artifact.outputs.artifact-url }} - name: ⬇️ Restore Cache id: get-base-commit uses: actions/cache@v5 if: ${{ inputs.channel != 'testflight' && inputs.channel != 'production' }} with: path: most-recent-testflight-commit.txt key: most-recent-testflight-commit - name: ✏️ Write commit hash to cache env: GITHUB_SHA: ${{ github.sha }} if: ${{ inputs.channel != 'testflight' && inputs.channel != 'production' }} run: echo $GITHUB_SHA > most-recent-testflight-commit.txt