77 push :
88 branches :
99 - main
10+ - windowsSigning
1011
1112jobs :
1213 build-and-publish :
7071 if : matrix.platform == 'linux'
7172 env :
7273 GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
73- run : npm exec electron-builder -- --publish always --linux
74+ run : npm exec electron-builder -- --publish always --linux
75+
76+ - name : Get package version
77+ if : matrix.platform == 'win'
78+ id : get-version
79+ shell : bash
80+ run : |
81+ VERSION=$(node -p "require('./package.json').version")
82+ echo "version=$VERSION" >> $GITHUB_OUTPUT
83+ echo "artifact-name=Cobolt-Setup-$VERSION.exe" >> $GITHUB_OUTPUT
84+
85+ - name : Check if release already exists
86+ if : matrix.platform == 'win'
87+ id : check-release
88+ shell : bash
89+ run : |
90+ RELEASE_EXISTS=$(gh release view "v${{ steps.get-version.outputs.version }}" --json assets,draft --jq 'if .draft == false then .assets | map(select(.name == "${{ steps.get-version.outputs.artifact-name }}")) | length else 0 end' 2>/dev/null || echo "0")
91+ echo "release-exists=$RELEASE_EXISTS" >> $GITHUB_OUTPUT
92+ env :
93+ GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
94+
95+ - name : upload-unsigned-artifact
96+ id : upload-unsigned-artifact
97+ if : matrix.platform == 'win' && steps.check-release.outputs.release-exists == '0'
98+ uses : actions/upload-artifact@v4
99+ with :
100+ name : unsigned-intaller
101+ retention-days : 1
102+ path : CoboltSetup\output\CoboltSetup_${{ steps.get-version.outputs.version }}.exe
103+
104+ - name : Sign artifact
105+ if : matrix.platform == 'win' && steps.check-release.outputs.release-exists == '0'
106+ uses : signpath/github-action-submit-signing-request@v1.1
107+ with :
108+ api-token : ${{secrets.SIGNPATH_API_TOKEN}}
109+ organization-id : 3fe5dc9d-e6f6-4c25-83e5-70c5844441b9
110+ project-slug : cobolt
111+ signing-policy-slug : test-signing
112+ github-artifact-id : ${{steps.upload-unsigned-artifact.outputs.artifact-id}}
113+ wait-for-completion : true
0 commit comments