423 lines
15 KiB
YAML
423 lines
15 KiB
YAML
---
|
|
name: Bundle and Deploy EAS Update
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
workflow_dispatch:
|
|
inputs:
|
|
channel:
|
|
type: choice
|
|
description: Deployment channel to use
|
|
options:
|
|
- testflight
|
|
- production
|
|
runtimeVersion:
|
|
type: string
|
|
description: Runtime version (in x.x.x format) that this update is for
|
|
required: true
|
|
|
|
jobs:
|
|
bundleDeploy:
|
|
if: github.repository == 'bluesky-social/social-app'
|
|
name: Bundle and Deploy EAS Update
|
|
runs-on: ubuntu-latest
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.event_name }}-${{ github.ref }}-deploy
|
|
cancel-in-progress: true
|
|
outputs:
|
|
changes-detected: ${{ steps.fingerprint.outputs.includes-changes }}
|
|
|
|
steps:
|
|
- name: Check for EXPO_TOKEN
|
|
run: >
|
|
if [ -z "${{ secrets.EXPO_TOKEN }}" ]; then
|
|
echo "You must provide an EXPO_TOKEN secret linked to this project's Expo account in this repo's secrets. Learn more: https://docs.expo.dev/eas-update/github-actions"
|
|
exit 1
|
|
fi
|
|
|
|
# Validate the version if one is supplied. This should generally happen if the update is for a production client
|
|
- name: 🧐 Validate version
|
|
env:
|
|
RUNTIME_VERSION: ${{ inputs.runtimeVersion }}
|
|
if: ${{ inputs.runtimeVersion }}
|
|
run: |
|
|
if [ -z "$RUNTIME_VERSION" ]; then
|
|
[[ "$RUNTIME_VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]] && echo "Version is valid" || exit 1
|
|
fi
|
|
|
|
- name: ⬇️ Checkout
|
|
uses: actions/checkout@v5
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: ⬇️ Fetch commits from base branch
|
|
if: ${{ github.ref != 'refs/heads/main' }}
|
|
run: git fetch origin main:main --depth 100
|
|
|
|
- uses: pnpm/action-setup@v6
|
|
|
|
- name: 🔧 Setup Node
|
|
uses: actions/setup-node@v6
|
|
with:
|
|
node-version-file: .nvmrc
|
|
cache: pnpm
|
|
|
|
- name: 📷 Check fingerprint and install dependencies
|
|
id: fingerprint
|
|
uses: bluesky-social/github-actions/fingerprint-native@main
|
|
with:
|
|
profile: ${{ inputs.channel || 'testflight' }}
|
|
previous-commit-tag: ${{ inputs.runtimeVersion }}
|
|
|
|
- name: Lint check
|
|
run: pnpm lint
|
|
|
|
- name: Prettier check
|
|
run: pnpm prettier --check .
|
|
|
|
- name: 🔤 Compile translations
|
|
run: pnpm intl:build 2>&1 | tee i18n.log
|
|
|
|
- name: Check for i18n compilation errors
|
|
run: if grep -q "invalid syntax" "i18n.log"; then echo "\n\nFound compilation errors!\n\n" && exit 1; else echo "\n\nNo compilation errors!\n\n"; fi
|
|
|
|
- name: Type check
|
|
run: pnpm typecheck
|
|
|
|
- name: 🔨 Setup EAS
|
|
uses: expo/expo-github-action@main
|
|
if: ${{ !steps.fingerprint.outputs.includes-changes }}
|
|
with:
|
|
expo-version: latest
|
|
eas-version: latest
|
|
packager: pnpm
|
|
token: ${{ secrets.EXPO_TOKEN }}
|
|
|
|
- name: ⛏️ Setup Expo
|
|
if: ${{ !steps.fingerprint.outputs.includes-changes }}
|
|
run: pnpm add -g eas-cli-local-build-plugin
|
|
|
|
- name: 🪛 Setup jq
|
|
if: ${{ !steps.fingerprint.outputs.includes-changes }}
|
|
uses: dcarbone/install-jq-action@v2
|
|
|
|
# eas.json not used here, set EXPO_PUBLIC_ENV
|
|
- name: Env
|
|
env:
|
|
CHANNEL: ${{ inputs.channel || 'testflight' }}
|
|
GITHUB_SHA: ${{ github.sha }}
|
|
id: env
|
|
if: ${{ !steps.fingerprint.outputs.includes-changes }}
|
|
run: |
|
|
export json='${{ secrets.GOOGLE_SERVICES_TOKEN }}'
|
|
echo "${{ secrets.ENV_TOKEN }}" > .env
|
|
echo "EXPO_PUBLIC_ENV=$CHANNEL" >> .env
|
|
echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> .env
|
|
echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> $GITHUB_OUTPUT
|
|
echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> .env
|
|
echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> $GITHUB_OUTPUT
|
|
echo "EXPO_PUBLIC_BUNDLE_DATE=$(date -u +"%y%m%d%H")" >> .env
|
|
echo "EXPO_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN }}" >> .env
|
|
echo "EXPO_PUBLIC_BITDRIFT_API_KEY=${{ secrets.BITDRIFT_API_KEY }}" >> .env
|
|
echo "EXPO_PUBLIC_GCP_PROJECT_ID=${{ secrets.EXPO_PUBLIC_GCP_PROJECT_ID }}" >> .env
|
|
echo "$json" > google-services.json
|
|
|
|
- name: 🏗️ Create Bundle
|
|
if: ${{ !steps.fingerprint.outputs.includes-changes }}
|
|
run: >
|
|
SENTRY_AUTH_TOKEN=${{ secrets.SENTRY_AUTH_TOKEN }}
|
|
SENTRY_RELEASE=${{ steps.env.outputs.EXPO_PUBLIC_RELEASE_VERSION }}
|
|
SENTRY_DIST=${{ steps.env.outputs.EXPO_PUBLIC_BUNDLE_IDENTIFIER }}
|
|
pnpm export
|
|
|
|
- name: 📦 Package Bundle and 🚀 Deploy
|
|
if: ${{ !steps.fingerprint.outputs.includes-changes }}
|
|
run: pnpm use-build-number bash scripts/bundleUpdate.sh
|
|
env:
|
|
DENIS_API_KEY: ${{ secrets.DENIS_API_KEY }}
|
|
RUNTIME_VERSION: ${{ inputs.runtimeVersion }}
|
|
CHANNEL_NAME: ${{ inputs.channel || 'testflight' }}
|
|
|
|
- name: ⬇️ Restore Cache
|
|
id: get-base-commit
|
|
uses: actions/cache@v5
|
|
if: ${{ !steps.fingerprint.outputs.includes-changes }}
|
|
with:
|
|
path: most-recent-testflight-commit.txt
|
|
key: most-recent-testflight-commit
|
|
|
|
- name: ✏️ Write commit hash to cache
|
|
if: ${{ !steps.fingerprint.outputs.includes-changes }}
|
|
run: echo $GITHUB_SHA > most-recent-testflight-commit.txt
|
|
|
|
# GitHub actions are horrible so let's just copy paste this in
|
|
buildIfNecessaryIOS:
|
|
name: Build and Submit iOS
|
|
runs-on: macos-26
|
|
concurrency:
|
|
group: ios-build
|
|
cancel-in-progress: false
|
|
needs: [bundleDeploy]
|
|
# Gotta check if its NOT '[]' because any md5 hash in the outputs is detected as a possible secret and won't be
|
|
# available here
|
|
if: ${{ inputs.channel != 'production' && needs.bundleDeploy.outputs.changes-detected && github.repository == 'bluesky-social/social-app' }}
|
|
steps:
|
|
- name: Check for EXPO_TOKEN
|
|
run: >
|
|
if [ -z "${{ secrets.EXPO_TOKEN }}" ]; then
|
|
echo "You must provide an EXPO_TOKEN secret linked to this project's Expo account in this repo's secrets. Learn more: https://docs.expo.dev/eas-update/github-actions"
|
|
exit 1
|
|
fi
|
|
|
|
- name: ⬇️ Checkout
|
|
uses: actions/checkout@v5
|
|
with:
|
|
fetch-depth: 5
|
|
|
|
- uses: pnpm/action-setup@v6
|
|
|
|
- name: 🔧 Setup Node
|
|
uses: actions/setup-node@v6
|
|
with:
|
|
node-version-file: .nvmrc
|
|
cache: pnpm
|
|
|
|
- name: 🔨 Setup EAS
|
|
uses: expo/expo-github-action@main
|
|
with:
|
|
expo-version: latest
|
|
eas-version: latest
|
|
packager: pnpm
|
|
token: ${{ secrets.EXPO_TOKEN }}
|
|
|
|
- name: ⛏️ Setup EAS local builds
|
|
run: pnpm add -g eas-cli-local-build-plugin
|
|
|
|
- name: ⚙️ Install dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
- uses: maxim-lobanov/setup-xcode@v1
|
|
with:
|
|
xcode-version: "26.4"
|
|
|
|
- name: ☕️ Setup Cocoapods
|
|
uses: maxim-lobanov/setup-cocoapods@v1
|
|
with:
|
|
version: 1.16.2
|
|
|
|
- name: 💾 Cache Pods
|
|
uses: actions/cache@v5
|
|
id: pods-cache
|
|
with:
|
|
path: ./ios/Pods
|
|
# We'll use the pnpm-lock.yaml for our hash since we don't yet have a Podfile.lock. Pod versions will not
|
|
# change unless the pnpm version changes as well.
|
|
key: ${{ runner.os }}-pods-${{ hashFiles('pnpm-lock.yaml') }}
|
|
|
|
- name: 🔤 Compile translations
|
|
run: pnpm intl:build
|
|
|
|
# EXPO_PUBLIC_ENV is handled in eas.json
|
|
- name: Env
|
|
id: env
|
|
run: |
|
|
echo "${{ secrets.ENV_TOKEN }}" > .env
|
|
echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> .env
|
|
echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> $GITHUB_OUTPUT
|
|
echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> .env
|
|
echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> $GITHUB_OUTPUT
|
|
echo "EXPO_PUBLIC_BUNDLE_DATE=$(date -u +"%y%m%d%H")" >> .env
|
|
echo "EXPO_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN }}" >> .env
|
|
echo "EXPO_PUBLIC_BITDRIFT_API_KEY=${{ secrets.BITDRIFT_API_KEY }}" >> .env
|
|
echo "EXPO_PUBLIC_GCP_PROJECT_ID=${{ secrets.EXPO_PUBLIC_GCP_PROJECT_ID }}" >> .env
|
|
echo "${{ secrets.GOOGLE_SERVICES_TOKEN }}" > google-services.json
|
|
|
|
- name: 🏗️ EAS Build
|
|
run: >
|
|
SENTRY_AUTH_TOKEN=${{ secrets.SENTRY_AUTH_TOKEN }}
|
|
SENTRY_RELEASE=${{ steps.env.outputs.EXPO_PUBLIC_RELEASE_VERSION }}
|
|
SENTRY_DIST=${{ steps.env.outputs.EXPO_PUBLIC_BUNDLE_IDENTIFIER }}
|
|
pnpm use-build-number-with-bump
|
|
eas build -p ios
|
|
--profile testflight
|
|
--local --output build.tar.gz --non-interactive
|
|
|
|
- name: 📂 Extract build artifact
|
|
run: |
|
|
if [ -f "build.tar.gz" ]; then
|
|
echo "Extracting build.tar.gz..."
|
|
rm -rf ios-build
|
|
mkdir -p ios-build
|
|
tar -xzf build.tar.gz -C ios-build
|
|
echo "Extraction completed successfully"
|
|
|
|
echo ""
|
|
echo "Top-level extracted files:"
|
|
find ios-build -maxdepth 3 -print
|
|
|
|
echo ""
|
|
echo "Searching for IPA..."
|
|
IPA_PATH="$(find ios-build -type f -name '*.ipa' -print -quit)"
|
|
if [ -z "$IPA_PATH" ]; then
|
|
echo "ERROR: No .ipa found anywhere under ios-build."
|
|
echo "Archive contents:"
|
|
tar -tzf build.tar.gz | sed -n '1,200p'
|
|
exit 1
|
|
fi
|
|
|
|
BUILD_DIR="$(dirname "$IPA_PATH")"
|
|
echo "Found IPA at: $IPA_PATH"
|
|
echo "Build dir: $BUILD_DIR"
|
|
echo ""
|
|
echo "Build dir contents:"
|
|
ls -la "$BUILD_DIR"
|
|
echo "BUILD_DIR=$BUILD_DIR" >> $GITHUB_ENV
|
|
else
|
|
echo "Archive file not found!"
|
|
exit 1
|
|
fi
|
|
|
|
- name: 🚀 Deploy
|
|
run: eas submit -p ios --non-interactive --path "$BUILD_DIR/Bluesky.ipa"
|
|
|
|
- name: 🪲 Upload dSYM to Sentry
|
|
run: >
|
|
SENTRY_ORG=blueskyweb
|
|
SENTRY_PROJECT=app
|
|
SENTRY_AUTH_TOKEN=${{ secrets.SENTRY_AUTH_TOKEN }}
|
|
pnpm sentry-cli debug-files upload "$BUILD_DIR/Bluesky.app.dSYM.zip" --include-sources
|
|
|
|
- name: ⬇️ Restore Cache
|
|
id: get-base-commit
|
|
uses: actions/cache@v5
|
|
if: ${{ inputs.channel == 'testflight' }}
|
|
with:
|
|
path: most-recent-testflight-commit.txt
|
|
key: most-recent-testflight-commit
|
|
|
|
- name: ✏️ Write commit hash to cache
|
|
if: ${{ inputs.channel == 'testflight' }}
|
|
env:
|
|
GITHUB_SHA: ${{ github.sha }}
|
|
run: echo $GITHUB_SHA > most-recent-testflight-commit.txt
|
|
|
|
buildIfNecessaryAndroid:
|
|
name: Build and Submit Android
|
|
runs-on: ubuntu-latest
|
|
concurrency:
|
|
group: android-build
|
|
cancel-in-progress: false
|
|
needs: [bundleDeploy]
|
|
# Gotta check if its NOT '[]' because any md5 hash in the outputs is detected as a possible secret and won't be
|
|
# available here
|
|
if: ${{ inputs.channel != 'production' && needs.bundleDeploy.outputs.changes-detected && github.repository == 'bluesky-social/social-app'}}
|
|
|
|
steps:
|
|
- name: Check for EXPO_TOKEN
|
|
run: >
|
|
if [ -z "${{ secrets.EXPO_TOKEN }}" ]; then
|
|
echo "You must provide an EXPO_TOKEN secret linked to this project's Expo account in this repo's secrets. Learn more: https://docs.expo.dev/eas-update/github-actions"
|
|
exit 1
|
|
fi
|
|
|
|
- name: ⬇️ Checkout
|
|
uses: actions/checkout@v5
|
|
with:
|
|
fetch-depth: 5
|
|
|
|
- uses: pnpm/action-setup@v6
|
|
|
|
- name: 🔧 Setup Node
|
|
uses: actions/setup-node@v6
|
|
with:
|
|
node-version-file: .nvmrc
|
|
cache: pnpm
|
|
|
|
- name: 🔨 Setup EAS
|
|
uses: expo/expo-github-action@main
|
|
with:
|
|
expo-version: latest
|
|
eas-version: latest
|
|
packager: pnpm
|
|
token: ${{ secrets.EXPO_TOKEN }}
|
|
|
|
- name: ⛏️ Setup EAS local builds
|
|
run: pnpm add -g eas-cli-local-build-plugin
|
|
|
|
- uses: actions/setup-java@v5
|
|
with:
|
|
distribution: "temurin"
|
|
java-version: "17"
|
|
|
|
- name: ⚙️ Install dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
- name: 🔤 Compile translations
|
|
run: pnpm intl:build
|
|
|
|
# EXPO_PUBLIC_ENV is handled in eas.json
|
|
- name: Env
|
|
id: env
|
|
run: |
|
|
export json='${{ secrets.GOOGLE_SERVICES_TOKEN }}'
|
|
echo "${{ secrets.ENV_TOKEN }}" > .env
|
|
echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> .env
|
|
echo "EXPO_PUBLIC_RELEASE_VERSION=$(jq -r '.version' package.json)" >> $GITHUB_OUTPUT
|
|
echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> .env
|
|
echo "EXPO_PUBLIC_BUNDLE_IDENTIFIER=$(git rev-parse HEAD)" >> $GITHUB_OUTPUT
|
|
echo "EXPO_PUBLIC_BUNDLE_DATE=$(date -u +"%y%m%d%H")" >> .env
|
|
echo "EXPO_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN }}" >> .env
|
|
echo "EXPO_PUBLIC_BITDRIFT_API_KEY=${{ secrets.BITDRIFT_API_KEY }}" >> .env
|
|
echo "EXPO_PUBLIC_GCP_PROJECT_ID=${{ secrets.EXPO_PUBLIC_GCP_PROJECT_ID }}" >> .env
|
|
echo "$json" > google-services.json
|
|
|
|
- name: 🏗️ EAS Build
|
|
run: >
|
|
SENTRY_AUTH_TOKEN=${{ secrets.SENTRY_AUTH_TOKEN }}
|
|
SENTRY_RELEASE=${{ steps.env.outputs.EXPO_PUBLIC_RELEASE_VERSION }}
|
|
SENTRY_DIST=${{ steps.env.outputs.EXPO_PUBLIC_BUNDLE_IDENTIFIER }}
|
|
pnpm use-build-number-with-bump
|
|
eas build -p android
|
|
--profile testflight-android
|
|
--local --output build.apk --non-interactive
|
|
|
|
- name: ⏰ Get a timestamp
|
|
id: timestamp
|
|
uses: nanzm/get-time-action@master
|
|
with:
|
|
format: "MM-DD-HH-mm-ss"
|
|
|
|
- name: 🚀 Upload Artifact
|
|
id: upload-artifact
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
retention-days: 30
|
|
compression-level: 0
|
|
name: build-${{ steps.timestamp.outputs.time }}.apk
|
|
path: build.apk
|
|
|
|
- name: 🔔 Notify Slack
|
|
uses: slackapi/slack-github-action@v2.1.1
|
|
with:
|
|
webhook: ${{ secrets.SLACK_CLIENT_ALERT_WEBHOOK }}
|
|
webhook-type: incoming-webhook
|
|
payload-templated: true
|
|
payload: |
|
|
text: Android build is ready for testing. Download the artifact here: ${{ steps.upload-artifact.outputs.artifact-url }}
|
|
|
|
- name: ⬇️ Restore Cache
|
|
id: get-base-commit
|
|
uses: actions/cache@v5
|
|
if: ${{ inputs.channel != 'testflight' && inputs.channel != 'production' }}
|
|
with:
|
|
path: most-recent-testflight-commit.txt
|
|
key: most-recent-testflight-commit
|
|
|
|
- name: ✏️ Write commit hash to cache
|
|
env:
|
|
GITHUB_SHA: ${{ github.sha }}
|
|
if: ${{ inputs.channel != 'testflight' && inputs.channel != 'production' }}
|
|
run: echo $GITHUB_SHA > most-recent-testflight-commit.txt
|