diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index 8b170ee..6569c8a 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -6,11 +6,13 @@ name: Build release artifacts # queues silently rather than failing, so register all three before tagging: # ubuntu-latest Linux AppImage # windows-latest Windows NSIS installer + portable zip -# macos-arm64 macOS dmg + zip, both architectures (M-series builds both) +# macos-latest macOS dmg + zip, both architectures (M-series builds both) # # Nothing cross-builds any more: dmg requires macOS, and the Windows exe needs # rcedit on Windows to get its icon and version resources. # +# A RELEASE_TOKEN secret is optional; GITEA_TOKEN is used by default. +# # All output is unsigned. Once certificates exist: for macOS drop mac.identity # from package.json and remove CSC_IDENTITY_AUTO_DISCOVERY; for Windows add the # cert secrets. Until then users hit Gatekeeper and SmartScreen warnings. @@ -89,7 +91,7 @@ jobs: if-no-files-found: error macos: - runs-on: macos-arm64 + runs-on: macos-latest defaults: run: working-directory: desktop-client @@ -133,12 +135,14 @@ jobs: - name: Create release and attach artifacts env: - TOKEN: ${{ secrets.RELEASE_TOKEN }} + # Gitea injects GITEA_TOKEN automatically, repo-scoped and short-lived. + # RELEASE_TOKEN is an optional override if wider rights are ever needed. + TOKEN: ${{ secrets.RELEASE_TOKEN || secrets.GITEA_TOKEN }} API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }} run: | set -euo pipefail if [ -z "${TOKEN:-}" ]; then - echo "RELEASE_TOKEN secret is not set." >&2 + echo "No token available (GITEA_TOKEN missing and RELEASE_TOKEN unset)." >&2 exit 1 fi