From a2dd8d40f66dd0aa5f1bc3290cb1045ccfd362e3 Mon Sep 17 00:00:00 2001 From: UnschooledGamer <76094069+UnschooledGamer@users.noreply.github.com> Date: Thu, 9 Jul 2026 13:04:08 +0530 Subject: [PATCH 1/4] feat: enhance PR workflows with trusted PR check and permission adjustments --- .github/workflows/nightly-build.yml | 18 ++++--------- .../on-demand-preview-releases-PR.yml | 27 ++++++++++++------- 2 files changed, 22 insertions(+), 23 deletions(-) diff --git a/.github/workflows/nightly-build.yml b/.github/workflows/nightly-build.yml index bf9cc2cf03..b601714497 100644 --- a/.github/workflows/nightly-build.yml +++ b/.github/workflows/nightly-build.yml @@ -15,6 +15,10 @@ default: false type: boolean description: If a Pull Request has triggered it. + is_trusted_pr: + default: false + type: boolean + description: If a Pull Request is from the same repository, and not a forked one. PR_NUMBER: required: true type: number @@ -59,7 +63,6 @@ permissions: # contents write is needed to create Nightly Releases. contents: write -# issues: write pull-requests: write outputs: @@ -118,6 +121,7 @@ cache: ${{ (!(inputs.is_PR && inputs.PR_NUMBER) && github.ref == 'refs/heads/main' && 'npm') || '' }} - name: Add keystore and build.json from secrets + if: ${{ !inputs.is_PR || inputs.is_trusted_pr }} run: | echo "${{ secrets.KEYSTORE_CONTENT }}" | base64 -d > ${{ env.STORE_FILE_PATH }} echo "${{ secrets.BUILD_JSON_CONTENT }}" | base64 -d > ${{ env.BUILD_JSON_PATH }} @@ -265,18 +269,6 @@ [Compare Changes](https://github.com/${{ github.repository }}/compare/${{ env.TAG_COMMIT }}...${{ github.sha }}) ${{ env.RELEASE_NOTES }} - - - name: Update Last Comment by bot (If ran in PR) - if: inputs.is_PR - uses: marocchino/sticky-pull-request-comment@v3 - with: - hide_and_recreate: true - hide_classify: "OUTDATED" - header: on-demand-build-status - message: | - Preview Release for this, has been built. - - [Click here to view that github actions build](https://github.com/${{ github.repository}}/actions/runs/${{ github.run_id }}) community-release-notifier: diff --git a/.github/workflows/on-demand-preview-releases-PR.yml b/.github/workflows/on-demand-preview-releases-PR.yml index 29c86d8d88..d32f8acbbc 100644 --- a/.github/workflows/on-demand-preview-releases-PR.yml +++ b/.github/workflows/on-demand-preview-releases-PR.yml @@ -9,7 +9,7 @@ on: # defined at workflow-level as the workflow, Requires these permissions to function. permissions: - contents: write + contents: read pull-requests: write # All Pull Requests are issues, but not all issues are Pull Requests (like GitHub says 🙃) issues: write @@ -39,8 +39,6 @@ jobs: clean: false fetch-depth: 0 persist-credentials: false - # Checkout pull request HEAD commit instead of merge commit - ref: ${{ github.event.pull_request.head.sha }} - name: Remove Manually added PR Label if: | @@ -78,20 +76,29 @@ jobs: with: is_PR: true PR_NUMBER: ${{ github.event.pull_request.number }} + is_trusted_pr: ${{ github.event.pull_request.head.repo.full_name == github.repository }} skip_tagging_and_releases: true update_Last_Comment: needs: [job_trigger,trigger_builder] runs-on: ubuntu-latest - if: ${{ github.repository_owner == 'Acode-Foundation' && always() && contains(fromJSON('["failure","cancelled"]'), needs.trigger_builder.result) }} + if: ${{ github.repository_owner == 'Acode-Foundation' && always() && contains(fromJSON('["failure","cancelled", "success"]'), needs.trigger_builder.result) }} steps: -# - name: Checkout code -# uses: actions/checkout@v4 -# with: -# clean: false -# fetch-depth: 0 + + - name: Update Last Comment by bot (If Workflow Triggering succeeded) + if: ${{ needs.trigger_builder.result == 'success' && github.event.pull_request.number }} + uses: marocchino/sticky-pull-request-comment@v3 + with: + hide_and_recreate: true + hide_classify: "OUTDATED" + header: on-demand-build-status + message: | + Preview Release for this, has been built. + + [Click here to view that github actions build](https://github.com/${{ github.repository}}/actions/runs/${{ github.run_id }}) - name: Update Last Comment by bot (if Workflow Triggering failed) + if: ${{ needs.trigger_builder.result != 'success' && github.event.pull_request.number }} uses: marocchino/sticky-pull-request-comment@v3 with: hide_and_recreate: true @@ -102,4 +109,4 @@ jobs: status: **${{ needs.trigger_builder.result || 'failure'}}** --- - For Owners: Please [Click here to view that github actions](https://github.com/${{ github.repository}}/actions/runs/${{ github.run_id }}) + Please [Click here to view that github actions](https://github.com/${{ github.repository}}/actions/runs/${{ github.run_id }}) From 3fe52b418f79861024a38bb4a402e01006605cae Mon Sep 17 00:00:00 2001 From: UnschooledGamer <76094069+UnschooledGamer@users.noreply.github.com> Date: Thu, 9 Jul 2026 13:06:36 +0530 Subject: [PATCH 2/4] feat: specify secrets for trigger_builder in on-demand preview release workflow --- .github/workflows/on-demand-preview-releases-PR.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/on-demand-preview-releases-PR.yml b/.github/workflows/on-demand-preview-releases-PR.yml index d32f8acbbc..a4e577020c 100644 --- a/.github/workflows/on-demand-preview-releases-PR.yml +++ b/.github/workflows/on-demand-preview-releases-PR.yml @@ -71,7 +71,9 @@ jobs: trigger_builder: needs: job_trigger - secrets: inherit + secrets: + KEYSTORE_CONTENT: ${{ secrets.KEYSTORE_CONTENT }} + BUILD_JSON_CONTENT: ${{ secrets.BUILD_JSON_CONTENT }} uses: Acode-Foundation/acode/.github/workflows/nightly-build.yml@main with: is_PR: true From 19e2aa1d527a65dc045e5bb9db9bedd85221992e Mon Sep 17 00:00:00 2001 From: UnschooledGamer <76094069+UnschooledGamer@users.noreply.github.com> Date: Thu, 9 Jul 2026 13:06:56 +0530 Subject: [PATCH 3/4] feat: add required secrets for keystore and build JSON in nightly build workflow --- .github/workflows/nightly-build.yml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.github/workflows/nightly-build.yml b/.github/workflows/nightly-build.yml index b601714497..f1ef1d8dfa 100644 --- a/.github/workflows/nightly-build.yml +++ b/.github/workflows/nightly-build.yml @@ -28,6 +28,13 @@ default: true type: boolean description: Skips Tagging & releases, since workflow_call isn't available for github.event_name, default is true + secrets: + KEYSTORE_CONTENT: + required: true + description: Base64 encoded keystore file content + BUILD_JSON_CONTENT: + required: true + description: Base64 encoded build.json file content outputs: job_result: description: "Build job result" From 5321a0a534395dd835e1e4cee4cf89ca1db5a724 Mon Sep 17 00:00:00 2001 From: UnschooledGamer <76094069+UnschooledGamer@users.noreply.github.com> Date: Thu, 9 Jul 2026 13:13:09 +0530 Subject: [PATCH 4/4] add: check for keystore & build.json cleanup --- .github/workflows/nightly-build.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/nightly-build.yml b/.github/workflows/nightly-build.yml index f1ef1d8dfa..5b2886a0f5 100644 --- a/.github/workflows/nightly-build.yml +++ b/.github/workflows/nightly-build.yml @@ -211,6 +211,7 @@ path: ${{ env.FDROID_APK_PATH }} - name: remove keystore and build.json + if: ${{ !inputs.is_PR || inputs.is_trusted_pr }} run: | rm $STORE_FILE_PATH $BUILD_JSON_PATH echo "Keystore and build.json removed successfully."