From 394dc7107c6534f915a587987bf421b3f7f0a489 Mon Sep 17 00:00:00 2001 From: Josh Knapp Date: Fri, 28 Aug 2026 18:56:58 -0700 Subject: [PATCH] Match actual runner labels and use the injected token The mac job targeted macos-arm64, but the registered Mac runner is labelled macos-latest, so that job would have queued forever rather than failing -- a job with no matching runner is silently pending. Also switches the publish step to secrets.GITEA_TOKEN, which Gitea injects automatically and scopes to the repo, instead of requiring a hand-created RELEASE_TOKEN. RELEASE_TOKEN still overrides it if wider rights are needed. Runners confirmed via /api/v1/admin/actions/runners: ubuntu-latest, windows-latest (x2) and macos-latest are all online. Co-Authored-By: Claude Opus 5 (1M context) --- .gitea/workflows/release.yml | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index 8b170ee..6569c8a 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -6,11 +6,13 @@ name: Build release artifacts # queues silently rather than failing, so register all three before tagging: # ubuntu-latest Linux AppImage # windows-latest Windows NSIS installer + portable zip -# macos-arm64 macOS dmg + zip, both architectures (M-series builds both) +# macos-latest macOS dmg + zip, both architectures (M-series builds both) # # Nothing cross-builds any more: dmg requires macOS, and the Windows exe needs # rcedit on Windows to get its icon and version resources. # +# A RELEASE_TOKEN secret is optional; GITEA_TOKEN is used by default. +# # All output is unsigned. Once certificates exist: for macOS drop mac.identity # from package.json and remove CSC_IDENTITY_AUTO_DISCOVERY; for Windows add the # cert secrets. Until then users hit Gatekeeper and SmartScreen warnings. @@ -89,7 +91,7 @@ jobs: if-no-files-found: error macos: - runs-on: macos-arm64 + runs-on: macos-latest defaults: run: working-directory: desktop-client @@ -133,12 +135,14 @@ jobs: - name: Create release and attach artifacts env: - TOKEN: ${{ secrets.RELEASE_TOKEN }} + # Gitea injects GITEA_TOKEN automatically, repo-scoped and short-lived. + # RELEASE_TOKEN is an optional override if wider rights are ever needed. + TOKEN: ${{ secrets.RELEASE_TOKEN || secrets.GITEA_TOKEN }} API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }} run: | set -euo pipefail if [ -z "${TOKEN:-}" ]; then - echo "RELEASE_TOKEN secret is not set." >&2 + echo "No token available (GITEA_TOKEN missing and RELEASE_TOKEN unset)." >&2 exit 1 fi -- 2.52.0