-
Notifications
You must be signed in to change notification settings - Fork 258
ci: run checks and builds on GitHub Actions, with release-intent automation #87
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
13 commits
Select commit
Hold shift + click to select a range
175569d
ci: add GitHub Actions checks and unsigned installer builds
Noah-Tervalon-Nvidia f862287
docs: add public changelog seeded from the published releases
Noah-Tervalon-Nvidia 033b394
refactor: rename versions.json product to services, drop installer
Noah-Tervalon-Nvidia 59cb542
ci: add release-intent automation
Noah-Tervalon-Nvidia a4ab54e
ci: declare toolchain versions once in a composite action
Noah-Tervalon-Nvidia 77ac75f
ci: point setup-go at the module lockfiles
Noah-Tervalon-Nvidia 161cda0
ci: assert staged binaries match versions.json, not a count
Noah-Tervalon-Nvidia 9156995
docs: regenerate services-api.md after the versions rename
Noah-Tervalon-Nvidia fd2c35a
ci: make the staged-binary check immune to line endings
Noah-Tervalon-Nvidia b0c3815
ci: fix release-intent triggers and the installer path filter
Noah-Tervalon-Nvidia 2d87948
fix: rebuild cli-bin when only the services version changes
Noah-Tervalon-Nvidia e035658
docs: point contributors at develop and the intent block
Noah-Tervalon-Nvidia aad7cd1
Merge origin/develop into ci/hosted-runner-workflows
Noah-Tervalon-Nvidia File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,70 @@ | ||
| # SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. | ||
| # SPDX-License-Identifier: Apache-2.0 | ||
|
|
||
| # The single place the Node and Go versions are declared. | ||
| # | ||
| # GitHub Actions has no shared constants file: `env:` is per-workflow and one | ||
| # workflow cannot read another. Four workflows exist because each needs a | ||
| # distinct `on:` block, so without this they would each carry their own copy of | ||
| # the versions, and bumping one while forgetting another would have pull request | ||
| # checks and release builds running different toolchains. | ||
| # | ||
| # The caller must check out the repository first — a local action cannot exist | ||
| # until its own repo is on disk, so checkout stays in the workflow. | ||
| # | ||
| # On a fork pull request this file comes from the fork, like every other script | ||
| # those jobs run. That adds no exposure: those jobs already execute the pull | ||
| # request's `npm ci` and `go test`, hold no secret, and run on hosted runners. | ||
| name: Set up toolchains | ||
| description: Installs the pinned Node and Go toolchains used across all workflows. | ||
|
|
||
| inputs: | ||
| node: | ||
| description: Install Node. | ||
| default: 'true' | ||
| go: | ||
| description: Install Go. | ||
| default: 'false' | ||
| npm-cache: | ||
| description: Cache the npm download cache. Pointless without an npm install. | ||
| default: 'true' | ||
|
|
||
| runs: | ||
| using: composite | ||
| steps: | ||
| # desktop/package.json engines requires >=25.5.0. Pinned to a major | ||
| # rather than read from that range, which would drift to whatever Node | ||
| # is newest. | ||
| - if: inputs.node == 'true' | ||
| uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5 | ||
| with: | ||
| node-version: '25' | ||
| cache: ${{ inputs.npm-cache == 'true' && 'npm' || '' }} | ||
| cache-dependency-path: desktop/package-lock.json | ||
|
|
||
| # Forbids the surprise toolchain download, so the version below is the | ||
| # one that actually builds. Set before setup-go because setup-go reads | ||
| # GOTOOLCHAIN when resolving a version file. | ||
| - if: inputs.go == 'true' | ||
| shell: bash | ||
| run: echo 'GOTOOLCHAIN=local' >> "$GITHUB_ENV" | ||
|
|
||
| # Must be >= the highest `go` directive across services/*/go.mod, which | ||
| # GOTOOLCHAIN=local would otherwise refuse to satisfy. | ||
| # | ||
| # cache-dependency-path is required, not an optimization. setup-go | ||
| # caches by default and looks for the dependency file at the repository | ||
| # root, where there is none — every Go module lives under services/. | ||
| # Left unset it reports "Dependencies file is not found" on every run. | ||
| # Naming the path also pins the cache key: older versions hash go.sum, | ||
| # newer ones hash go.mod. | ||
| # | ||
| # scripts/ matches nothing today; it is listed so a Go dependency added | ||
| # to the support tooling joins the key instead of silently missing it. | ||
| - if: inputs.go == 'true' | ||
| uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6 | ||
| with: | ||
| go-version: '1.26.7' | ||
| cache-dependency-path: | | ||
| services/**/go.sum | ||
| scripts/**/go.sum |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,109 @@ | ||
| # SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. | ||
| # SPDX-License-Identifier: Apache-2.0 | ||
|
|
||
| # Unsigned installer builds on GitHub-hosted runners. | ||
| # | ||
| # These are verification and pull-request artifacts, never releases: every | ||
| # target ends in `electron-builder --publish never`, and this workflow holds no | ||
| # signing or publishing credentials. Signed releases are produced separately | ||
| # from a tag, and are rebuilt from source rather than signing anything this | ||
| # workflow produced. | ||
| name: Build | ||
|
|
||
| on: | ||
| workflow_dispatch: | ||
| push: | ||
| branches: [main, develop] | ||
| pull_request: | ||
| branches: [main, develop] | ||
| paths: | ||
| - '.github/workflows/**' | ||
| # The composite action pins the Node and Go versions. Without this | ||
| # a toolchain bump would run ci.yml and skip the installer matrix, | ||
| # which is the cross-workflow drift the action exists to prevent. | ||
| - '.github/actions/**' | ||
| - 'scripts/**' | ||
| - 'services/**' | ||
| - 'desktop/package.json' | ||
| - 'desktop/package-lock.json' | ||
| - 'desktop/src/**' | ||
| - 'desktop/scripts/**' | ||
| - 'desktop/native/**' | ||
| - 'desktop/resources/**' | ||
| - 'desktop/tsconfig*.json' | ||
| - 'desktop/vite.*.config.ts' | ||
| - 'desktop/electron.vite.config.ts' | ||
| - 'desktop/electron-builder.config.ts' | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| concurrency: | ||
| group: build-${{ github.ref }} | ||
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | ||
|
|
||
| # Toolchain versions are declared once, in .github/actions/setup. | ||
|
|
||
| jobs: | ||
| build: | ||
| name: ${{ matrix.name }} | ||
| runs-on: ${{ matrix.os }} | ||
| timeout-minutes: 60 | ||
| strategy: | ||
| # One platform failing should not hide the state of the other five. | ||
| fail-fast: false | ||
| matrix: | ||
| include: | ||
| - name: linux-x64 | ||
| os: ubuntu-latest | ||
| script: build:linux:x64 | ||
| - name: linux-arm64 | ||
| os: ubuntu-latest | ||
| script: build:linux:arm64 | ||
| - name: win-x64 | ||
| os: windows-latest | ||
| script: build:win:x64 | ||
| - name: win-arm64 | ||
| os: windows-latest | ||
| script: build:win:arm64 | ||
| - name: mac-arm64 | ||
| os: macos-latest | ||
| script: build:mac:arm64 | ||
| - name: mac-x64 | ||
| os: macos-15-intel | ||
| script: build:mac:x64 | ||
| steps: | ||
| - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 | ||
|
|
||
| # Recorded so a failure can be read against the machine it ran on. | ||
| - name: Report runner capacity | ||
| shell: bash | ||
| run: | | ||
| echo "label: ${{ matrix.os }}" | ||
| echo "kernel: $(uname -s) $(uname -m)" | ||
| echo "cpus: $(nproc 2>/dev/null || sysctl -n hw.ncpu 2>/dev/null || echo unknown)" | ||
| free -h 2>/dev/null || sysctl -n hw.memsize 2>/dev/null || echo "mem: unknown" | ||
| df -h . | tail -1 | ||
|
|
||
| - uses: ./.github/actions/setup | ||
| with: | ||
| go: 'true' | ||
|
|
||
| # electron-builder needs fakeroot and rpm to stage Linux packages; | ||
| # ubuntu-latest ships neither. | ||
| - name: Install Linux packaging tools | ||
| if: runner.os == 'Linux' | ||
| run: sudo apt-get update -qq && sudo apt-get install -y -qq fakeroot rpm | ||
|
|
||
| - run: npm --prefix desktop ci --prefer-offline | ||
|
|
||
| - name: Build ${{ matrix.name }} | ||
| run: npm --prefix desktop run ${{ matrix.script }} | ||
|
|
||
| - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 | ||
| if: always() | ||
| with: | ||
| name: unsigned-${{ matrix.name }} | ||
| path: desktop/release/** | ||
| retention-days: 7 | ||
| if-no-files-found: warn | ||
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.