name: TallyNote release on: push: tags: - "v*.*.*" # A tag is the immutable input to a release. Publishing is kept in one job so # SHA256SUMS covers every archive exactly once and the Gitea Release API never # receives duplicate checksum assets from parallel architecture jobs. permissions: contents: write jobs: linux-x64: runs-on: ubuntu-latest steps: - name: Checkout tag uses: actions/checkout@v4 with: # Release notes are derived from the previous version tag. A shallow # checkout would leave only the synthetic release commit available. fetch-depth: 0 - name: Set up Node.js uses: actions/setup-node@v4 with: node-version: 24 - name: Enable pnpm run: corepack enable && corepack prepare pnpm@9.0.6 --activate - name: Verify tag and test gate run: | set -euo pipefail target_version="${GITHUB_REF_NAME#v}" package_version="$(node -p 'require("./package.json").version')" test "$package_version" = "$target_version" previous_tag="$(git tag --list 'v*.*.*' --sort=-version:refname | grep -Fxv "$GITHUB_REF_NAME" | head -n 1 || true)" if [[ -n "$previous_tag" ]]; then node - "$target_version" "${previous_tag#v}" <<'NODE' const [target, previous] = process.argv.slice(2).map((value) => value.split(/[.+-]/, 1)[0].split('.').map(Number)); if (target.length !== 3 || previous.length !== 3 || target.some((n) => !Number.isSafeInteger(n)) || previous.some((n) => !Number.isSafeInteger(n))) process.exit(2); const newer = target[0] > previous[0] || (target[0] === previous[0] && (target[1] > previous[1] || (target[1] === previous[1] && target[2] > previous[2]))); if (!newer) { console.error(`release ${process.argv[2]} must be newer than ${process.argv[3]}`); process.exit(1); } NODE fi pnpm install --frozen-lockfile pnpm check # better-sqlite3 is a native addon; a single Vitest worker avoids a # Node cleanup race observed on the hosted runner while preserving # the complete test suite. pnpm test -- --pool=threads --poolOptions.threads.singleThread=true pnpm test:installer - name: Build Linux release run: pnpm release:build "${GITHUB_REF_NAME#v}" ./release - name: Create and publish Gitea Release env: GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} run: ./scripts/publish-gitea-release.sh "$GITHUB_REF_NAME" ./release # Linux x86 (i386/i686) is intentionally not published: Node.js 24 and the # better-sqlite3/argon2/sharp native modules have no maintained 32-bit build. # Add an ARM64 job only on a runner with native ARM64 support, then let the # publisher aggregate all archives before signing one SHA256SUMS file.