Gitea has no /releases/latest/download/ redirect and release URLs always
include the tag, so updaters that poll a constant URL (Shelly) cannot use
them. After publishing a vX.Y.Z release, replace the asset on a rolling
pre-release tagged "latest":
.../releases/download/latest/WhatsThatMusic-latest-linux-x86_64.AppImage
Replacing the asset changes its ETag and Last-Modified, which Shelly
compares. The pre-release flag keeps Gitea's own "latest release" on the
newest vX.Y.Z. The logic lives in .gitea/scripts/update-latest.sh so it can
be run against the API outside CI. The publish job now checks out first,
since checkout cleans the workspace and would delete downloaded artifacts.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The publish job has never run successfully. When it failed on the v1.0.0
tag it reported "SyntaxError: Unexpected end of JSON input" from piping an
empty curl body into JSON.parse, which said nothing about the actual cause
(an unset token). An opaque failure there costs a full three-platform build.
Routes every call through a helper that captures the HTTP status and prints
the response body on 4xx/5xx. Also switches artifact iteration to while-read
so filenames with spaces cannot split, and dumps the artifact tree when
nothing matches.
Helper verified against the live API: existing tag resolves to its release
id, a missing tag reports HTTP 404 with the body and yields an empty id so
the create path runs.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The mac job targeted macos-arm64, but the registered Mac runner is
labelled macos-latest, so that job would have queued forever rather than
failing -- a job with no matching runner is silently pending.
Also switches the publish step to secrets.GITEA_TOKEN, which Gitea injects
automatically and scopes to the repo, instead of requiring a hand-created
RELEASE_TOKEN. RELEASE_TOKEN still overrides it if wider rights are needed.
Runners confirmed via /api/v1/admin/actions/runners: ubuntu-latest,
windows-latest (x2) and macos-latest are all online.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Splits the release workflow into linux, windows and macos jobs feeding a
single publish job. The publish step is separate so parallel builds cannot
race to create the release and fail on a duplicate tag.
Windows now builds natively, so signAndEditExecutable no longer has to be
disabled. That flag was suppressing rcedit, which is what embeds the icon
and version resources -- the v1.0.0 exe shipped with the stock Electron
icon as a result. Also adds an NSIS installer alongside the portable zip.
macOS gains a dmg target, which cannot be produced off macOS. Builds stay
unsigned pending a Developer ID, with CSC_IDENTITY_AUTO_DISCOVERY disabled
so electron-builder builds unsigned instead of failing on a real Mac.
Nothing cross-builds now; all three runners must be registered before
tagging, since a job with no matching runner queues silently.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Builds the Linux AppImage on a v* tag, runs the test suite first, and
attaches the artifact to a Gitea release via the API (no third-party
action, so nothing needs to be fetched from github.com at runtime).
Guards that the tag matches package.json version: electron-builder names
the artifact from package.json, so tagging v1.0.1 without bumping the
manifest would otherwise publish an AppImage named 1.0.0.
Requires a RELEASE_TOKEN secret and a registered act_runner; neither is
set up yet, so this is inert until both exist.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>