OpenSSF Scorecard / Scorecard analysis (push) Waiting to run
CI / Build & test (Node 20) (push) Canceled after 0s
CI / Build & test (Node 24) (push) Canceled after 0s
CI / Build & test (push) Canceled after 0s
CodeQL / Analyze (javascript-typescript) (push) Canceled after 0s
Security / Secret scan (gitleaks) (push) Canceled after 0s
Security / Dependency scan (OSV-Scanner) (push) Canceled after 0s
Security / IaC/config scan (Trivy) (push) Canceled after 0s
Security / License compliance scan (Trivy) (push) Canceled after 0s
GitHub stays the build machine — it has the Windows runners the native audio module needs — but the update feed moves to this fork's own Gitea. The GitHub repository is private, and electron-updater against a private GitHub repo needs a token inside the shipped app, which is a leaked token. Gitea serves release assets to anyone, so the installer carries no credential. The flow was verified end to end against the live instance before writing this: create release, upload asset, download anonymously. The release tag is fixed at 'latest' because electron-updater fetches latest.yml before it knows which version exists, so the URL cannot carry a version; CI replaces that release's assets each publish. electron-builder runs with --publish never since it cannot upload to Gitea, but still emits the latest.yml the updater reads. Needs a GITEA_TOKEN secret on the GitHub repository.