mirror of
https://github.com/sabnzbd/sabnzbd.git
synced 2026-09-23 19:35:42 -04:00
223 lines
9.0 KiB
YAML
223 lines
9.0 KiB
YAML
name: Build binaries and source distribution
|
|
|
|
on: [push, pull_request]
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
env:
|
|
# Setting PYTHONNODEBUGRANGES reduces binary size
|
|
PYTHONNODEBUGRANGES: 1
|
|
# For macOS we download the official Python, because the GitHub one only support newer macOS 11+ versions
|
|
# We also use the specific pin for Windows release, so Renovate can update it all at once
|
|
PYTHON_VERSION: "3.14.7"
|
|
|
|
jobs:
|
|
build_windows:
|
|
name: Build Windows binary (${{ matrix.architecture }})
|
|
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- architecture: x64
|
|
runs-on: windows-2022
|
|
- architecture: arm64
|
|
runs-on: windows-11-arm
|
|
|
|
runs-on: ${{ matrix.runs-on }}
|
|
timeout-minutes: 15
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- name: Set up Python
|
|
uses: actions/setup-python@v7
|
|
with:
|
|
python-version: ${{ env.PYTHON_VERSION }}
|
|
architecture: ${{ matrix.architecture }}
|
|
cache: pip
|
|
cache-dependency-path: "**/requirements.txt"
|
|
- name: Install Python dependencies
|
|
# Without dependencies to make sure everything is covered in the requirements.txt
|
|
# Special settings:
|
|
# cryptography see https://github.com/pyca/cryptography/pull/14216
|
|
run: |
|
|
python --version
|
|
python -m pip install --upgrade pip wheel
|
|
pip install -r requirements.txt --no-dependencies --only-binary=cryptography
|
|
pip install -r builder/requirements.txt --no-dependencies
|
|
- name: Build Windows standalone binary
|
|
id: windows_binary
|
|
run: python builder/package.py binary
|
|
- name: Upload Windows standalone binary (unsigned)
|
|
# When releasing, SignPath consumes this artifact directly and requires the
|
|
# zip-in-zip layout because they don't support the archive-flag
|
|
uses: actions/upload-artifact@v7
|
|
id: upload-unsigned-binary
|
|
with:
|
|
archive: ${{ contains(github.ref, 'refs/tags/') }}
|
|
path: "*-win*-bin.zip"
|
|
name: Windows standalone binary (${{ matrix.architecture }})
|
|
- name: Sign Windows standalone binary
|
|
uses: signpath/github-action-submit-signing-request@v2
|
|
if: contains(github.ref, 'refs/tags/')
|
|
with:
|
|
api-token: ${{ secrets.SIGNPATH_API_TOKEN }}
|
|
organization-id: ${{ secrets.SIGNPATH_ORG_ID }}
|
|
project-slug: "sabnzbd"
|
|
artifact-configuration-slug: "sabnzbd-binary"
|
|
signing-policy-slug: "release-signing"
|
|
github-artifact-id: ${{ steps.upload-unsigned-binary.outputs.artifact-id }}
|
|
wait-for-completion: true
|
|
output-artifact-directory: "signed"
|
|
- name: Upload Windows standalone binary (signed)
|
|
# The release file is a .zip, which download-artifact would extract if
|
|
# uploaded raw, so keep it archived and let the release job unpack it
|
|
uses: actions/upload-artifact@v7
|
|
if: contains(github.ref, 'refs/tags/')
|
|
with:
|
|
name: Windows standalone binary (${{ matrix.architecture }}, signed)
|
|
path: "signed/*-win*-bin.zip"
|
|
- name: Build Windows installer
|
|
if: matrix.architecture == 'x64'
|
|
run: python builder/package.py installer
|
|
- name: Upload Windows installer
|
|
if: matrix.architecture == 'x64'
|
|
uses: actions/upload-artifact@v7
|
|
id: upload-unsigned-installer
|
|
with:
|
|
archive: ${{ contains(github.ref, 'refs/tags/') }}
|
|
path: "*-win-setup.exe"
|
|
name: Windows installer (${{ matrix.architecture }})
|
|
- name: Sign Windows installer
|
|
if: matrix.architecture == 'x64' && contains(github.ref, 'refs/tags/')
|
|
uses: signpath/github-action-submit-signing-request@v2
|
|
with:
|
|
api-token: ${{ secrets.SIGNPATH_API_TOKEN }}
|
|
organization-id: ${{ secrets.SIGNPATH_ORG_ID }}
|
|
project-slug: "sabnzbd"
|
|
artifact-configuration-slug: "sabnzbd-installer"
|
|
signing-policy-slug: "release-signing"
|
|
github-artifact-id: ${{ steps.upload-unsigned-installer.outputs.artifact-id }}
|
|
wait-for-completion: true
|
|
output-artifact-directory: "signed"
|
|
- name: Upload Windows installer (signed)
|
|
if: matrix.architecture == 'x64' && contains(github.ref, 'refs/tags/')
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
archive: false
|
|
path: "signed/*-win-setup.exe"
|
|
|
|
build_macos:
|
|
name: Build macOS binary
|
|
runs-on: macos-14
|
|
timeout-minutes: 15
|
|
env:
|
|
# The deployment target is picked up by the Python build tools automatically
|
|
# If updated, make sure to also set LSMinimumSystemVersion in SABnzbd.spec
|
|
MACOSX_DEPLOYMENT_TARGET: "10.15"
|
|
# We need to force compile for universal2 support
|
|
CFLAGS: -arch x86_64 -arch arm64
|
|
ARCHFLAGS: -arch x86_64 -arch arm64
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- name: Set up Python
|
|
# Only use this for the caching of pip packages!
|
|
uses: actions/setup-python@v7
|
|
with:
|
|
python-version: "3.14"
|
|
cache: pip
|
|
cache-dependency-path: "**/requirements.txt"
|
|
- name: Cache Python download
|
|
id: cache-python-download
|
|
uses: actions/cache@v6
|
|
with:
|
|
path: ~/python.pkg
|
|
key: cache-macOS-Python-${{ env.PYTHON_VERSION }}
|
|
- name: Get Python from python.org
|
|
if: steps.cache-python-download.outputs.cache-hit != 'true'
|
|
run: curl https://www.python.org/ftp/python/${PYTHON_VERSION}/python-${PYTHON_VERSION}-macos11.pkg -o ~/python.pkg
|
|
- name: Install Python
|
|
run: sudo installer -pkg ~/python.pkg -target /
|
|
- name: Install Python dependencies
|
|
# We have to manually compile some modules as they don't automatically fetch universal2 binaries
|
|
run: |
|
|
python3 --version
|
|
pip3 install --upgrade pip wheel
|
|
pip3 install -r requirements.txt --no-binary cffi,CT3,PyYAML,httptools --no-dependencies
|
|
pip3 install -r builder/requirements.txt --no-dependencies
|
|
- name: Import macOS codesign certificates
|
|
# Taken from https://github.com/Apple-Actions/import-codesign-certs/pull/27 (comments)
|
|
env:
|
|
CERTIFICATES_P12: ${{ secrets.CERTIFICATES_P12 }}
|
|
CERTIFICATES_P12_PASSWORD: ${{ secrets.CERTIFICATES_P12_PASSWORD }}
|
|
MACOS_KEYCHAIN_TEMP_PASSWORD: ${{ secrets.MACOS_KEYCHAIN_TEMP_PASSWORD }}
|
|
if: env.CERTIFICATES_P12
|
|
run: |
|
|
echo $CERTIFICATES_P12 | base64 --decode > certificate.p12
|
|
security create-keychain -p "$MACOS_KEYCHAIN_TEMP_PASSWORD" build.keychain
|
|
security default-keychain -s build.keychain
|
|
security unlock-keychain -p "$MACOS_KEYCHAIN_TEMP_PASSWORD" build.keychain
|
|
security set-keychain-settings -lut 21600 build.keychain
|
|
security import certificate.p12 -k build.keychain -P "$CERTIFICATES_P12_PASSWORD" -T /usr/bin/codesign -T /usr/bin/productsign -T /usr/bin/xcrun
|
|
security set-key-partition-list -S apple-tool:,apple:,codesign: -s -k "$MACOS_KEYCHAIN_TEMP_PASSWORD" build.keychain
|
|
- name: Build source distribution
|
|
# Run this on macOS so the line endings are correct by default
|
|
run: python builder/package.py source
|
|
- name: Upload source distribution
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
archive: false
|
|
path: "*-src.tar.gz"
|
|
- name: Build macOS binary
|
|
env:
|
|
SIGNING_AUTH: ${{ secrets.SIGNING_AUTH }}
|
|
NOTARIZATION_USER: ${{ secrets.NOTARIZATION_USER }}
|
|
NOTARIZATION_PASS: ${{ secrets.NOTARIZATION_PASS }}
|
|
run: |
|
|
python3 builder/package.py app dmg
|
|
- name: Upload macOS binary
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
archive: false
|
|
path: "*-macos.dmg"
|
|
|
|
release:
|
|
name: Prepare Release
|
|
runs-on: ubuntu-latest
|
|
needs: [build_windows, build_macos]
|
|
if: contains(github.ref, 'refs/tags/')
|
|
environment: release
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- name: Set up Python
|
|
uses: actions/setup-python@v7
|
|
with:
|
|
python-version: "3.14"
|
|
cache: pip
|
|
cache-dependency-path: "builder/release-requirements.txt"
|
|
- name: Download release artifacts
|
|
# The installer, source and macOS builds are uploaded with archive: false,
|
|
# so their artifact name is the release filename
|
|
uses: actions/download-artifact@v8
|
|
with:
|
|
pattern: "SABnzbd-*"
|
|
merge-multiple: true
|
|
- name: Download signed Windows binaries
|
|
# These stay archived (.zip release files), so download-artifact unpacks
|
|
# them back into the release .zip
|
|
uses: actions/download-artifact@v8
|
|
with:
|
|
pattern: "*signed*"
|
|
merge-multiple: true
|
|
- name: Prepare official release
|
|
env:
|
|
AUTOMATION_GITHUB_TOKEN: ${{ secrets.AUTOMATION_GITHUB_TOKEN }}
|
|
REDDIT_TOKEN: ${{ secrets.REDDIT_TOKEN }}
|
|
LINUXSERVER_WEBHOOK_TOKEN: ${{ secrets.LINUXSERVER_WEBHOOK_TOKEN }}
|
|
DISCORD_WEBHOOK_TESTING: ${{ secrets.DISCORD_WEBHOOK_TESTING }}
|
|
DISCORD_WEBHOOK_STABLE: ${{ secrets.DISCORD_WEBHOOK_STABLE }}
|
|
run: |
|
|
pip3 install -r builder/release-requirements.txt --no-dependencies
|
|
python3 builder/release.py
|