diff --git a/.github/workflows/build-xpi.yml b/.github/workflows/build-xpi.yml index e7183b0..96708ac 100644 --- a/.github/workflows/build-xpi.yml +++ b/.github/workflows/build-xpi.yml @@ -1,147 +1,148 @@ -name: Build & Sign XPI - -on: - push: - branches: - - main - - "feat/**" - - "fix/**" - paths: - - "src/**" - -jobs: - build: - name: Package, sign and release - runs-on: ubuntu-latest - - permissions: - contents: write # nécessaire pour créer la release GitHub - - steps: - # --------------------------------------------------------------- - # 1. Récupérer le code - # --------------------------------------------------------------- - - name: Checkout - uses: actions/checkout@v4 - - # --------------------------------------------------------------- - # 2. Installer Node.js + web-ext (outil officiel Mozilla) - # --------------------------------------------------------------- - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: "20" - - - name: Install web-ext - run: npm install -g web-ext - - # --------------------------------------------------------------- - # 3. Lire la version depuis manifest.json - # --------------------------------------------------------------- - - name: Read version - id: version - run: | - VERSION=$(jq -r '.version' src/manifest.json) - echo "version=${VERSION}" >> "$GITHUB_OUTPUT" - echo "unsigned_xpi=ytptube-extension-${VERSION}.xpi" >> "$GITHUB_OUTPUT" - echo "signed_xpi=ytptube-extension-${VERSION}-signed.xpi" >> "$GITHUB_OUTPUT" - - # --------------------------------------------------------------- - # 4. Construire le XPI non signé (lint + zip) - # --------------------------------------------------------------- - - name: Lint extension - run: web-ext lint --source-dir src/ - - - name: Build unsigned XPI - run: | - web-ext build \ - --source-dir src/ \ - --artifacts-dir dist/ \ - --filename "${{ steps.version.outputs.unsigned_xpi }}" \ - --overwrite-dest - echo "Contenu du XPI :" - unzip -l "dist/${{ steps.version.outputs.unsigned_xpi }}" - - # --------------------------------------------------------------- - # 5. Uploader le XPI non signé comme artefact CI - # (toutes branches, utile pour debug) - # --------------------------------------------------------------- - - name: Upload unsigned artifact - uses: actions/upload-artifact@v4 - with: - name: ${{ steps.version.outputs.unsigned_xpi }} - path: dist/${{ steps.version.outputs.unsigned_xpi }} - retention-days: 30 - - # --------------------------------------------------------------- - # 6. Signer via l'API Mozilla AMO (uniquement sur main) - # Requiert les secrets AMO_JWT_ISSUER et AMO_JWT_SECRET - # --------------------------------------------------------------- - - name: Sign XPI with Mozilla - if: github.ref == 'refs/heads/main' - id: sign - env: - AMO_JWT_ISSUER: ${{ secrets.AMO_JWT_ISSUER }} - AMO_JWT_SECRET: ${{ secrets.AMO_JWT_SECRET }} - run: | - web-ext sign \ - --source-dir src/ \ - --artifacts-dir dist/ \ - --api-key "$AMO_JWT_ISSUER" \ - --api-secret "$AMO_JWT_SECRET" \ - --channel unlisted - - # web-ext sign produit un fichier signé dans dist/ — on le retrouve - SIGNED=$(find dist/ -name "*.xpi" ! -name "${{ steps.version.outputs.unsigned_xpi }}" | head -1) - if [ -z "$SIGNED" ]; then - echo "Aucun XPI signé trouvé, on utilise l'unsigned en fallback" - SIGNED="dist/${{ steps.version.outputs.unsigned_xpi }}" - fi - cp "$SIGNED" "dist/${{ steps.version.outputs.signed_xpi }}" - echo "signed_path=dist/${{ steps.version.outputs.signed_xpi }}" >> "$GITHUB_OUTPUT" - - # --------------------------------------------------------------- - # 7. Uploader le XPI signé comme artefact CI - # --------------------------------------------------------------- - - name: Upload signed artifact - if: github.ref == 'refs/heads/main' - uses: actions/upload-artifact@v3 - with: - name: ${{ steps.version.outputs.signed_xpi }} - path: ${{ steps.sign.outputs.signed_path }} - retention-days: 90 - - # --------------------------------------------------------------- - # 8. Créer ou mettre à jour la pre-release "latest-dev" sur main - # avec le XPI signé en pièce jointe - # --------------------------------------------------------------- - - name: Create or update dev release - if: github.ref == 'refs/heads/main' - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: | - TAG="latest-dev" - XPI="${{ steps.sign.outputs.signed_path }}" - SHORT_SHA="${GITHUB_SHA::7}" - VERSION="${{ steps.version.outputs.version }}" - TITLE="Dev build v${VERSION} (${SHORT_SHA})" - - # Supprimer l'ancienne release/tag si elle existe - gh release delete "$TAG" --yes 2>/dev/null || true - git push --delete origin "$TAG" 2>/dev/null || true - - # Recréer la release pre-release avec le XPI signé - gh release create "$TAG" "$XPI" \ - --title "$TITLE" \ - --notes "$(cat <> "$GITHUB_OUTPUT" + echo "unsigned_xpi=ytptube-extension-${VERSION}.xpi" >> "$GITHUB_OUTPUT" + echo "signed_xpi=ytptube-extension-${VERSION}-signed.xpi" >> "$GITHUB_OUTPUT" + + # --------------------------------------------------------------- + # 4. Construire le XPI non signé (lint + zip) + # --------------------------------------------------------------- + - name: Lint extension + run: web-ext lint --source-dir src/ + + - name: Build unsigned XPI + run: | + web-ext build \ + --source-dir src/ \ + --artifacts-dir dist/ \ + --filename "${{ steps.version.outputs.unsigned_xpi }}" \ + --overwrite-dest + echo "Contenu du XPI :" + unzip -l "dist/${{ steps.version.outputs.unsigned_xpi }}" + + # --------------------------------------------------------------- + # 5. Uploader le XPI non signé comme artefact CI + # (toutes branches, utile pour debug) + # --------------------------------------------------------------- + - name: Upload unsigned artifact + uses: actions/upload-artifact@v4 + with: + name: ${{ steps.version.outputs.unsigned_xpi }} + path: dist/${{ steps.version.outputs.unsigned_xpi }} + retention-days: 30 + + # --------------------------------------------------------------- + # 6. Signer via l'API Mozilla AMO (uniquement sur main) + # Requiert les secrets AMO_JWT_ISSUER et AMO_JWT_SECRET + # --------------------------------------------------------------- + - name: Sign XPI with Mozilla + if: github.ref == 'refs/heads/main' + id: sign + env: + AMO_JWT_ISSUER: ${{ secrets.AMO_JWT_ISSUER }} + AMO_JWT_SECRET: ${{ secrets.AMO_JWT_SECRET }} + run: | + web-ext sign \ + --source-dir src/ \ + --artifacts-dir dist/ \ + --api-key "$AMO_JWT_ISSUER" \ + --api-secret "$AMO_JWT_SECRET" \ + --channel unlisted + + # web-ext sign produit un fichier signé dans dist/ — on le retrouve + SIGNED=$(find dist/ -name "*.xpi" ! -name "${{ steps.version.outputs.unsigned_xpi }}" | head -1) + if [ -z "$SIGNED" ]; then + echo "Aucun XPI signé trouvé, on utilise l'unsigned en fallback" + SIGNED="dist/${{ steps.version.outputs.unsigned_xpi }}" + fi + cp "$SIGNED" "dist/${{ steps.version.outputs.signed_xpi }}" + echo "signed_path=dist/${{ steps.version.outputs.signed_xpi }}" >> "$GITHUB_OUTPUT" + + # --------------------------------------------------------------- + # 7. Uploader le XPI signé comme artefact CI + # --------------------------------------------------------------- + - name: Upload signed artifact + if: github.ref == 'refs/heads/main' + uses: actions/upload-artifact@v3 + with: + name: ${{ steps.version.outputs.signed_xpi }} + path: ${{ steps.sign.outputs.signed_path }} + retention-days: 90 + + # --------------------------------------------------------------- + # 8. Créer ou mettre à jour la pre-release "latest-dev" sur main + # avec le XPI signé en pièce jointe + # --------------------------------------------------------------- + - name: Create or update dev release + if: github.ref == 'refs/heads/main' + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + TAG="latest-dev" + XPI="${{ steps.sign.outputs.signed_path }}" + SHORT_SHA="${GITHUB_SHA::7}" + VERSION="${{ steps.version.outputs.version }}" + TITLE="Dev build v${VERSION} (${SHORT_SHA})" + + # Supprimer l'ancienne release/tag si elle existe + gh release delete "$TAG" --yes 2>/dev/null || true + git push --delete origin "$TAG" 2>/dev/null || true + + # Recréer la release pre-release avec le XPI signé + gh release create "$TAG" "$XPI" \ + --title "$TITLE" \ + --notes "$(cat <