Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/workflows/portable-native-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ on:
- "scripts/platform-storage-probe.ts"
- "scripts/windows-credential-probe.ts"
- "scripts/windows-icon.ts"
- "scripts/windows-installed-qualification.ts"
- "scripts/windows-package-probe.ts"
- "forge.config.ts"
- "src/**"
Expand Down Expand Up @@ -84,3 +85,6 @@ jobs:
if ($signature.Status -ne "NotSigned") {
throw "Local package unexpectedly has status $($signature.Status)"
}
- name: Qualify the installed Windows package
if: runner.os == 'Windows'
run: pnpm test:windows-installed
65 changes: 65 additions & 0 deletions .github/workflows/windows-signed-qualification.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
# Build and exercise a signed package without uploading or publishing it.
name: Windows signed qualification

on:
workflow_dispatch:

permissions:
contents: read

jobs:
qualify:
runs-on: windows-2025
timeout-minutes: 45
environment: windows-release
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- uses: pnpm/action-setup@d15e628ca66d93ee5f352c71671a7bc6a97af5c9 # v6.0.8
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: "24"
cache: pnpm
- uses: ilammy/msvc-dev-cmd@a102174a2b586eec2ea151a69e6fd14404a8ce7c # v1.13.0
with:
arch: x64
- name: Install the pinned Rust toolchain
run: rustup toolchain install
- run: pnpm install --frozen-lockfile
- name: Materialize the temporary signing certificate
shell: pwsh
env:
WINDOWS_SIGNING_PFX_BASE64: ${{ secrets.WINDOWS_SIGNING_PFX_BASE64 }}
run: |
if (-not $env:WINDOWS_SIGNING_PFX_BASE64) {
throw "WINDOWS_SIGNING_PFX_BASE64 is required"
}
$certificate = Join-Path $env:RUNNER_TEMP "gwonmac-windows-signing.pfx"
[IO.File]::WriteAllBytes(
$certificate,
[Convert]::FromBase64String($env:WINDOWS_SIGNING_PFX_BASE64)
)
"WINDOWS_CERTIFICATE_FILE=$certificate" | Out-File $env:GITHUB_ENV -Append
- name: Build the signed package
env:
GW_PACKAGE_INTENT: release
WINDOWS_CERTIFICATE_PASSWORD: ${{ secrets.WINDOWS_SIGNING_PASSWORD }}
run: pnpm make -- --platform=win32 --arch=x64
- name: Verify the signed installer
shell: pwsh
run: |
$setup = Get-ChildItem "out/make/squirrel.windows/x64/*Setup.exe"
if ($setup.Count -ne 1) { throw "Expected one Setup executable" }
$signature = Get-AuthenticodeSignature $setup.FullName
if ($signature.Status -ne "Valid") {
throw "Signed Setup has status $($signature.Status)"
}
- name: Qualify signed install, replacement, and credentials
env:
GW_WINDOWS_SIGNED_QUALIFICATION: "1"
run: pnpm test:windows-installed
- name: Remove the temporary signing certificate
if: always()
shell: pwsh
run: Remove-Item "$env:RUNNER_TEMP/gwonmac-windows-signing.pfx" -Force -ErrorAction SilentlyContinue
1 change: 1 addition & 0 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,7 @@
"launcher:fixture": "pnpm build && node --import ./scripts/ts-hook.mjs scripts/launcher-fixture.ts",
"storage:probe": "node --import ./scripts/ts-hook.mjs scripts/platform-storage-probe.ts",
"test:windows-credentials": "node --import ./scripts/ts-hook.mjs scripts/windows-credential-probe.ts",
"test:windows-installed": "node --import ./scripts/ts-hook.mjs scripts/windows-installed-qualification.ts",
"test:windows-package": "node --import ./scripts/ts-hook.mjs scripts/windows-package-probe.ts",
"test:signed-dev": "node --import ./scripts/ts-hook.mjs scripts/run-signed-dev.ts --test-keychain",
"tools:dev": "pnpm --filter @gwonmac/tools-ui dev",
Expand Down
Loading
Loading