diff --git a/.github/workflows/nightly-build.yml b/.github/workflows/nightly-build.yml index bf9cc2cf0..5b2886a0f 100644 --- a/.github/workflows/nightly-build.yml +++ b/.github/workflows/nightly-build.yml @@ -15,6 +15,10 @@ default: false type: boolean description: If a Pull Request has triggered it. + is_trusted_pr: + default: false + type: boolean + description: If a Pull Request is from the same repository, and not a forked one. PR_NUMBER: required: true type: number @@ -24,6 +28,13 @@ default: true type: boolean description: Skips Tagging & releases, since workflow_call isn't available for github.event_name, default is true + secrets: + KEYSTORE_CONTENT: + required: true + description: Base64 encoded keystore file content + BUILD_JSON_CONTENT: + required: true + description: Base64 encoded build.json file content outputs: job_result: description: "Build job result" @@ -59,7 +70,6 @@ permissions: # contents write is needed to create Nightly Releases. contents: write -# issues: write pull-requests: write outputs: @@ -118,6 +128,7 @@ cache: ${{ (!(inputs.is_PR && inputs.PR_NUMBER) && github.ref == 'refs/heads/main' && 'npm') || '' }} - name: Add keystore and build.json from secrets + if: ${{ !inputs.is_PR || inputs.is_trusted_pr }} run: | echo "${{ secrets.KEYSTORE_CONTENT }}" | base64 -d > ${{ env.STORE_FILE_PATH }} echo "${{ secrets.BUILD_JSON_CONTENT }}" | base64 -d > ${{ env.BUILD_JSON_PATH }} @@ -200,6 +211,7 @@ path: ${{ env.FDROID_APK_PATH }} - name: remove keystore and build.json + if: ${{ !inputs.is_PR || inputs.is_trusted_pr }} run: | rm $STORE_FILE_PATH $BUILD_JSON_PATH echo "Keystore and build.json removed successfully." @@ -265,18 +277,6 @@ [Compare Changes](https://github.com/${{ github.repository }}/compare/${{ env.TAG_COMMIT }}...${{ github.sha }}) ${{ env.RELEASE_NOTES }} - - - name: Update Last Comment by bot (If ran in PR) - if: inputs.is_PR - uses: marocchino/sticky-pull-request-comment@v3 - with: - hide_and_recreate: true - hide_classify: "OUTDATED" - header: on-demand-build-status - message: | - Preview Release for this, has been built. - - [Click here to view that github actions build](https://github.com/${{ github.repository}}/actions/runs/${{ github.run_id }}) community-release-notifier: diff --git a/.github/workflows/on-demand-preview-releases-PR.yml b/.github/workflows/on-demand-preview-releases-PR.yml index 29c86d8d8..a4e577020 100644 --- a/.github/workflows/on-demand-preview-releases-PR.yml +++ b/.github/workflows/on-demand-preview-releases-PR.yml @@ -9,7 +9,7 @@ on: # defined at workflow-level as the workflow, Requires these permissions to function. permissions: - contents: write + contents: read pull-requests: write # All Pull Requests are issues, but not all issues are Pull Requests (like GitHub says 🙃) issues: write @@ -39,8 +39,6 @@ jobs: clean: false fetch-depth: 0 persist-credentials: false - # Checkout pull request HEAD commit instead of merge commit - ref: ${{ github.event.pull_request.head.sha }} - name: Remove Manually added PR Label if: | @@ -73,25 +71,36 @@ jobs: trigger_builder: needs: job_trigger - secrets: inherit + secrets: + KEYSTORE_CONTENT: ${{ secrets.KEYSTORE_CONTENT }} + BUILD_JSON_CONTENT: ${{ secrets.BUILD_JSON_CONTENT }} uses: Acode-Foundation/acode/.github/workflows/nightly-build.yml@main with: is_PR: true PR_NUMBER: ${{ github.event.pull_request.number }} + is_trusted_pr: ${{ github.event.pull_request.head.repo.full_name == github.repository }} skip_tagging_and_releases: true update_Last_Comment: needs: [job_trigger,trigger_builder] runs-on: ubuntu-latest - if: ${{ github.repository_owner == 'Acode-Foundation' && always() && contains(fromJSON('["failure","cancelled"]'), needs.trigger_builder.result) }} + if: ${{ github.repository_owner == 'Acode-Foundation' && always() && contains(fromJSON('["failure","cancelled", "success"]'), needs.trigger_builder.result) }} steps: -# - name: Checkout code -# uses: actions/checkout@v4 -# with: -# clean: false -# fetch-depth: 0 + + - name: Update Last Comment by bot (If Workflow Triggering succeeded) + if: ${{ needs.trigger_builder.result == 'success' && github.event.pull_request.number }} + uses: marocchino/sticky-pull-request-comment@v3 + with: + hide_and_recreate: true + hide_classify: "OUTDATED" + header: on-demand-build-status + message: | + Preview Release for this, has been built. + + [Click here to view that github actions build](https://github.com/${{ github.repository}}/actions/runs/${{ github.run_id }}) - name: Update Last Comment by bot (if Workflow Triggering failed) + if: ${{ needs.trigger_builder.result != 'success' && github.event.pull_request.number }} uses: marocchino/sticky-pull-request-comment@v3 with: hide_and_recreate: true @@ -102,4 +111,4 @@ jobs: status: **${{ needs.trigger_builder.result || 'failure'}}** --- - For Owners: Please [Click here to view that github actions](https://github.com/${{ github.repository}}/actions/runs/${{ github.run_id }}) + Please [Click here to view that github actions](https://github.com/${{ github.repository}}/actions/runs/${{ github.run_id }})