Commit Graph
8 Commits
Author SHA1 Message Date
Jannis Braun 4758ca46fa ci(security): SHA-pin all actions and add harden-runner (audit) 2026-07-12 23:51:00 +02:00
TheZwiss 180228f2d1 ci: bump actions to Node 24 runtimes to clear deprecation warning (#8)
GitHub is deprecating the Node 20 runtime for JS actions; every run printed a
warning that actions/checkout@v4, actions/setup-node@v4 and pnpm/action-setup@v4
were being force-run on Node 24. Bump each to its first Node 24 major (v5) across
all workflows — the smallest jump that clears the warning, avoiding the extra
behavior changes in checkout v6/v7 (credential persistence, fork-PR blocking)
that don't apply here. Our checkout jobs use push/pull_request, not
pull_request_target/workflow_run, so none are affected regardless.

Also bump the GitHub Pages actions in deploy-pages.yml (configure-pages v5->v6,
upload-pages-artifact v3->v5, deploy-pages v4->v5), which were likewise on Node
20. Inputs are unchanged; pnpm still pinned to 10.34.3 via the version input and
the packageManager field.
2026-07-10 01:02:47 +02:00
Jannis Braun 9d3f72be75 chore: pin Node 20 (LTS) and pnpm 10.34.3
Unpinned `pnpm@latest` in the Dockerfile made fresh builds non-reproducible:
`latest` now resolves to pnpm 11, but the committed lockfile targets pnpm 10, so
`pnpm install --frozen-lockfile` fails with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH on
a clean host. Pin pnpm to 10.34.3 across the Dockerfile, the `packageManager`
field, and the release workflow; pin Node to 20 (LTS) via `.nvmrc` and `engines`
so Docker, CI, and from-source builds all use the same tested toolchain.

Also corrects the docs: the lockfile is v9.0 (requires pnpm 10, not "pnpm 8+"),
and "Node 20+" implied untested newer majors were supported.
2026-07-06 01:04:59 +02:00
Jannis Braun ef020601eb ci(release): build arm64 .deb with host-native fpm (USE_SYSTEM_FPM)
Release Desktop / build (--linux --arm64, ubuntu-24.04-arm) (push) Canceled after 0s
Release Desktop / build (--linux --x64, ubuntu-latest) (push) Canceled after 0s
Release Desktop / build (--mac --arm64 --x64, macos-latest) (push) Canceled after 0s
Release Desktop / build (--win --x64 --arm64, windows-2022) (push) Canceled after 0s
CI run 2: mac/win/linux-x64 green, but linux-arm64 failed packaging .deb —
electron-builder's bundled fpm is x86_64-only and can't execute on the arm64
runner (Exec format error). The arm64 AppImage built fine; only fpm/.deb broke.
Install fpm natively on the Linux runners and set USE_SYSTEM_FPM=true so both
arches package .deb with a host-native fpm. Preserves arm64 .deb (the reason
the arm64 runner was added — Raspberry Pi users).
2026-07-03 13:54:56 +02:00
Jannis Braun 9c293b9731 ci(release): fix native uiohook-napi build on Windows + Linux
First real CI run failed on 3 of 4 platforms in postinstall (electron-rebuild
of uiohook-napi):
- Linux (x64+arm64): missing X11 dev headers — 'Xrandr.h: No such file'. Add the
  full libuiohook header set (libxrandr-dev, libxinerama-dev, libx11-xcb-dev,
  libxkbfile-dev, libxkbcommon-x11-dev) derived from its #include list.
- Windows: node-gyp on the windows-latest image can't detect VS 18
  ('unknown version undefined'). Pin to windows-2022 (VS 2022 / v17).
macOS built cleanly and is unaffected.
2026-07-03 13:47:29 +02:00
Jannis Braun 70a648d209 ci(release): build Linux arm64 on native arm runner; pin unsigned mac builds 2026-07-03 13:17:13 +02:00
Jannis Braun cc30080ba8 chore: sync repo with deployed state — clean up old specs/plans, desktop tweaks 2026-03-24 04:33:23 +01:00
Jannis Braun 568b049b22 ci: add GitHub Actions workflow for desktop release builds
Triggers on v* tag push, builds for Windows, macOS (arm64), and Linux.
Uses electron-builder --publish to upload artifacts to GitHub Releases.
2026-03-21 02:32:43 +01:00