OpenSSF Scorecard / Scorecard analysis (push) Waiting to run
CI / Build & test (Node 20) (push) Canceled after 0s
CI / Build & test (Node 24) (push) Canceled after 0s
CI / Build & test (push) Canceled after 0s
CodeQL / Analyze (javascript-typescript) (push) Canceled after 0s
Security / Secret scan (gitleaks) (push) Canceled after 0s
Security / Dependency scan (OSV-Scanner) (push) Canceled after 0s
Security / IaC/config scan (Trivy) (push) Canceled after 0s
Security / License compliance scan (Trivy) (push) Canceled after 0s
The previous run went green and produced an installer with no system-audio capture in it — the exact silent failure this module exists to prevent. Two causes. electron-rebuild takes -w as one comma-separated list, not a repeated flag; passing it twice made argv.w an array and the CLI threw 'argv.w.split is not a function', which also broke uiohook-napi's rebuild that had been working. And pnpm 10 refuses to run a dependency's build script unless it is listed in onlyBuiltDependencies, so node-gyp never ran for it at all — the log said 'Ignored build scripts' and nothing else complained. Neither surfaced because desktop's postinstall ends in , which exists so contributors without build tools can install. That is reasonable locally and dangerous in CI, so the workflow now asserts a compiled .node exists and fails loudly when it does not, instead of trusting an exit code that was designed to lie.
98 lines
3.6 KiB
YAML
98 lines
3.6 KiB
YAML
# Caminho rápido: só Windows x64, disparado à mão.
|
|
#
|
|
# O `release.yml` continua sendo o release de verdade (todas as plataformas,
|
|
# publica release e alimenta o electron-updater). Este aqui existe para quando
|
|
# você só quer um .exe para testar, sem marcar versão.
|
|
#
|
|
# Arquivo separado de propósito: o release.yml veio do upstream e recebe merges;
|
|
# mexer nele criaria conflito a cada atualização.
|
|
name: Build Windows (rápido)
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
arch:
|
|
description: Arquitetura
|
|
required: false
|
|
default: x64
|
|
type: choice
|
|
options: [x64, arm64]
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build:
|
|
# windows-2022, não windows-latest: a imagem latest traz o Visual Studio 18,
|
|
# que o node-gyp embutido no electron-rebuild não detecta ao compilar os
|
|
# módulos nativos. Mesma razão documentada no release.yml.
|
|
runs-on: windows-2022
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
|
|
|
|
- name: Setup pnpm
|
|
uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5.0.0
|
|
with:
|
|
version: 10.34.3
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
|
|
with:
|
|
node-version: 20
|
|
cache: pnpm
|
|
|
|
# ~100MB de binários do Electron e das ferramentas do NSIS, baixados a
|
|
# cada execução sem isto. É o maior ganho depois de cortar o arm64.
|
|
- name: Cache Electron binaries
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
~\AppData\Local\electron\Cache
|
|
~\AppData\Local\electron-builder\Cache
|
|
key: electron-cache-${{ runner.os }}-${{ hashFiles('**/pnpm-lock.yaml') }}
|
|
restore-keys: electron-cache-${{ runner.os }}-
|
|
|
|
- name: Install dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
- name: Build shared package
|
|
run: pnpm --filter @backspace/shared build
|
|
|
|
# O postinstall termina em `|| console.warn` para que quem não tem
|
|
# ferramentas de build consiga instalar. No CI isso transforma falha em
|
|
# sucesso silencioso: o instalador sai sem o módulo nativo e o app
|
|
# compartilha tela sem som, sem erro nenhum. Então verifica-se o
|
|
# resultado em vez de confiar no código de saída.
|
|
- name: Verify native audio module compiled
|
|
shell: bash
|
|
run: |
|
|
found=$(find node_modules/.pnpm -path '*electron-native-screenshare*' -name '*.node' 2>/dev/null | head -5)
|
|
if [ -z "$found" ]; then
|
|
echo "::error::electron-native-screenshare has no compiled .node — the installer would ship without system-audio capture"
|
|
find node_modules/.pnpm -maxdepth 1 -name 'electron-native-screenshare*' -printf '%p\n' 2>/dev/null || true
|
|
exit 1
|
|
fi
|
|
echo "OK:"; echo "$found"
|
|
|
|
- name: Compile desktop TypeScript
|
|
working-directory: packages/desktop
|
|
run: pnpm exec tsc
|
|
|
|
# --publish never: sem release, sem precisar de tag nem bump de versão.
|
|
# O instalador sai como artefato desta execução.
|
|
- name: Build installer
|
|
working-directory: packages/desktop
|
|
run: pnpm exec electron-builder --win --${{ inputs.arch || 'x64' }} --publish never
|
|
env:
|
|
CSC_IDENTITY_AUTO_DISCOVERY: "false"
|
|
|
|
- name: Upload installer
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: backspace-windows-${{ inputs.arch || 'x64' }}
|
|
path: packages/desktop/dist-electron/*.exe
|
|
retention-days: 14
|
|
if-no-files-found: error
|