Repository navigation
108 lines (96 loc) · 3.93 KB
/
Copy pathandroid-google-play.yml
File metadata and controls
108 lines (96 loc) · 3.93 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
name: Android Google Play
on:
workflow_call:
inputs:
track:
type: string
required: true
release_status:
type: string
required: true
permissions:
contents: read
concurrency:
group: google-play-${{ inputs.track }}
cancel-in-progress: false
jobs:
upload:
name: Build and upload the Android app
runs-on: ubuntu-24.04
environment: play-store
env:
ANDROID_KEYSTORE_BASE64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }}
ANDROID_KEYSTORE_PASSWORD: ${{ secrets.ANDROID_KEYSTORE_PASSWORD }}
ANDROID_KEY_ALIAS: ${{ secrets.ANDROID_KEY_ALIAS }}
ANDROID_KEY_PASSWORD: ${{ secrets.ANDROID_KEY_PASSWORD }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
persist-credentials: false
- uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4
with:
distribution: temurin
java-version: '17'
- uses: subosito/flutter-action@1a449444c387b1966244ae4d4f8c696479add0b2 # v2
with:
channel: stable
flutter-version: 3.38.9
cache: true
- name: Resolve dependencies
run: flutter pub get
# build.gradle.kts reads android/key.properties and falls back to debug
# keys when it is absent — which Play rejects, silently producing an
# unshippable artifact. Write it here, and fail loudly if any part of the
# key is missing rather than building something that cannot be uploaded.
- name: Install the upload key
run: |
set -euo pipefail
test -n "$ANDROID_KEYSTORE_BASE64"
test -n "$ANDROID_KEYSTORE_PASSWORD"
test -n "$ANDROID_KEY_ALIAS"
test -n "$ANDROID_KEY_PASSWORD"
KEYSTORE_PATH="$RUNNER_TEMP/labfox-upload.jks"
printf '%s' "$ANDROID_KEYSTORE_BASE64" | base64 --decode > "$KEYSTORE_PATH"
umask 077
cat > apps/labfox/android/key.properties <<PROPS
storeFile=$KEYSTORE_PATH
storePassword=$ANDROID_KEYSTORE_PASSWORD
keyAlias=$ANDROID_KEY_ALIAS
keyPassword=$ANDROID_KEY_PASSWORD
PROPS
- name: Build the signed app bundle
working-directory: apps/labfox
run: flutter build appbundle --release
# A debug-signed bundle builds successfully and is only rejected on
# upload, so check the certificate here rather than finding out from Play.
- name: Verify it is not signed with debug keys
run: |
set -euo pipefail
AAB=apps/labfox/build/app/outputs/bundle/release/app-release.aab
OWNER="$(keytool -printcert -jarfile "$AAB" | grep -m1 'Owner:')"
echo "$OWNER"
case "$OWNER" in
*"CN=Android Debug"*)
echo "::error::The bundle is signed with debug keys; the upload key was not applied."
exit 1
;;
esac
# The notes are written and reviewed in docs/store; carrying them here is
# what keeps the release page from saying nothing, or saying something
# nobody reviewed. A version with no notes fails the release rather than
# publishing an empty one.
- name: Collect the release notes
run: |
set -euo pipefail
VERSION="$(sed -n 's/^version: *\([^+]*\).*/\1/p' apps/labfox/pubspec.yaml | tr -d '[:space:]')"
python3 scripts/whatsnew.py --version "$VERSION" --out dist/whatsnew
ls -l dist/whatsnew
- name: Upload to Google Play
uses: r0adkll/upload-google-play@935ef9c68bb393a8e6116b1575626a7f5be3a7fb # v1.1.3
with:
serviceAccountJsonPlainText: ${{ secrets.GOOGLE_PLAY_SERVICE_ACCOUNT_JSON }}
packageName: com.sloki9637.labfox
releaseFiles: apps/labfox/build/app/outputs/bundle/release/app-release.aab
track: ${{ inputs.track }}
status: ${{ inputs.release_status }}
whatsNewDirectory: dist/whatsnew