Build each platform on its own native runner #3

Merged
jknapp merged 1 commits from ci/native-builders into main 2026-08-29 01:53:40 +00:00
Owner

Now that native Windows and macOS builders exist, nothing needs cross-building.

Workflow

Three build jobs (linux, windows, macos) feed a single publish job. Publishing is separate so parallel builds cannot race to create the release and fail on a duplicate tag.

Windows gets its icon back

signAndEditExecutable: false was suppressing rcedit, which is what embeds the icon and version resources into the exe — the v1.0.0 exe shipped with the stock Electron icon because of it. Building natively means that flag can go. Adds an NSIS installer alongside the portable zip.

macOS

Adds a dmg target, which cannot be produced off macOS. Builds both arch slices on the M-series machine.

Before tagging

All three runners must be registered — ubuntu-latest, windows-latest, macos-arm64. A job with no matching runner queues silently rather than failing. A RELEASE_TOKEN secret is also required.

Builds remain unsigned, so Gatekeeper and SmartScreen warnings persist until certificates exist.

🤖 Generated with Claude Code

Now that native Windows and macOS builders exist, nothing needs cross-building. ## Workflow Three build jobs (`linux`, `windows`, `macos`) feed a single `publish` job. Publishing is separate so parallel builds cannot race to create the release and fail on a duplicate tag. ## Windows gets its icon back `signAndEditExecutable: false` was suppressing `rcedit`, which is what embeds the icon and version resources into the exe — the v1.0.0 exe shipped with the stock Electron icon because of it. Building natively means that flag can go. Adds an NSIS installer alongside the portable zip. ## macOS Adds a `dmg` target, which cannot be produced off macOS. Builds both arch slices on the M-series machine. ## Before tagging All three runners must be registered — `ubuntu-latest`, `windows-latest`, `macos-arm64`. A job with no matching runner **queues silently** rather than failing. A `RELEASE_TOKEN` secret is also required. Builds remain unsigned, so Gatekeeper and SmartScreen warnings persist until certificates exist. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
jknapp added 1 commit 2026-08-29 01:53:36 +00:00
Splits the release workflow into linux, windows and macos jobs feeding a
single publish job. The publish step is separate so parallel builds cannot
race to create the release and fail on a duplicate tag.

Windows now builds natively, so signAndEditExecutable no longer has to be
disabled. That flag was suppressing rcedit, which is what embeds the icon
and version resources -- the v1.0.0 exe shipped with the stock Electron
icon as a result. Also adds an NSIS installer alongside the portable zip.

macOS gains a dmg target, which cannot be produced off macOS. Builds stay
unsigned pending a Developer ID, with CSC_IDENTITY_AUTO_DISCOVERY disabled
so electron-builder builds unsigned instead of failing on a real Mac.

Nothing cross-builds now; all three runners must be registered before
tagging, since a job with no matching runner queues silently.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
jknapp merged commit f8d10d3a24 into main 2026-08-29 01:53:40 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: streamer-tools/whats-that-music#3