ci: build on GitHub, publish updates from Gitea
OpenSSF Scorecard / Scorecard analysis (push) Waiting to run
CI / Build & test (Node 20) (push) Canceled after 0s
CI / Build & test (Node 24) (push) Canceled after 0s
CI / Build & test (push) Canceled after 0s
CodeQL / Analyze (javascript-typescript) (push) Canceled after 0s
Security / Secret scan (gitleaks) (push) Canceled after 0s
Security / Dependency scan (OSV-Scanner) (push) Canceled after 0s
Security / IaC/config scan (Trivy) (push) Canceled after 0s
Security / License compliance scan (Trivy) (push) Canceled after 0s
OpenSSF Scorecard / Scorecard analysis (push) Waiting to run
CI / Build & test (Node 20) (push) Canceled after 0s
CI / Build & test (Node 24) (push) Canceled after 0s
CI / Build & test (push) Canceled after 0s
CodeQL / Analyze (javascript-typescript) (push) Canceled after 0s
Security / Secret scan (gitleaks) (push) Canceled after 0s
Security / Dependency scan (OSV-Scanner) (push) Canceled after 0s
Security / IaC/config scan (Trivy) (push) Canceled after 0s
Security / License compliance scan (Trivy) (push) Canceled after 0s
GitHub stays the build machine — it has the Windows runners the native audio module needs — but the update feed moves to this fork's own Gitea. The GitHub repository is private, and electron-updater against a private GitHub repo needs a token inside the shipped app, which is a leaked token. Gitea serves release assets to anyone, so the installer carries no credential. The flow was verified end to end against the live instance before writing this: create release, upload asset, download anonymously. The release tag is fixed at 'latest' because electron-updater fetches latest.yml before it knows which version exists, so the URL cannot carry a version; CI replaces that release's assets each publish. electron-builder runs with --publish never since it cannot upload to Gitea, but still emits the latest.yml the updater reads. Needs a GITEA_TOKEN secret on the GitHub repository.
This commit is contained in:
@@ -22,11 +22,19 @@ asarUnpack:
|
||||
npmRebuild: false
|
||||
afterPack: ./scripts/afterPack.js
|
||||
publish:
|
||||
# Fork: releases (and therefore the electron-updater feed) come from this
|
||||
# repository, not upstream's.
|
||||
- provider: github
|
||||
owner: syncwrld
|
||||
repo: resenhacord
|
||||
# Updates are served from this fork's own Gitea, not from GitHub.
|
||||
#
|
||||
# GitHub is only the build machine — it has the Windows runners the native
|
||||
# audio module needs. Its repository is private, and electron-updater against
|
||||
# a private GitHub repo would need a token shipped inside the app, which is a
|
||||
# leaked token. Gitea serves release assets to anyone, so no credential ends
|
||||
# up in the installer.
|
||||
#
|
||||
# The tag is fixed at `latest` on purpose: electron-updater fetches
|
||||
# latest.yml before it knows which version exists, so the URL cannot contain
|
||||
# a version. CI replaces that release's assets on every publish.
|
||||
- provider: generic
|
||||
url: https://git.resenha.website/devsyncwrld/backspace/releases/download/latest/
|
||||
protocols:
|
||||
- name: Backspace
|
||||
schemes:
|
||||
|
||||
Reference in New Issue
Block a user