Commit graph

2 commits

Author SHA1 Message Date
574a8183d4 ci: auto-derive versionCode from commit count (never reuse a code)
Some checks failed
build-apk / build-and-publish (push) Successful in 8m58s
gitleaks / scan (push) Failing after 1s
Releases were silently no-op'ing on fdroid: versionCode was a hand-maintained
constant, so a commit that didn't bump it rebuilt the same debug_<vc>.apk, the
publish receiver's anti-downgrade guard refused the duplicate (exit 3 =
"nothing to do"), and the CI went green having shipped nothing. build.yml now
patches ProjectConfig's versionCode from `git rev-list --count HEAD` (minus an
offset keeping it continuous with the manual era, last=91) before assembling,
so every main commit auto-produces a new monotonic code. The ProjectConfig
literal is now just the local-dev default.
2026-07-29 07:23:23 -07:00
e34fbd457b ci: restore Forgejo build+publish + gitleaks workflows (infra-clean)
Some checks failed
build-apk / build-and-publish (push) Successful in 8m20s
gitleaks / scan (push) Failing after 1s
The OSS public-scrub removed .forgejo/workflows/ wholesale — it only needed
to parameterize the two infra literals in the publish step. Restored both
workflows; the publish target (root@host) and its SSH host-key now come from
Forgejo repo secrets (STRAW_PUBLISH_TARGET / STRAW_LUCY_HOSTKEY) instead of
literals, so the public workflow carries zero infra topology. Everything else
was already clean: signing keystore + deploy key are secrets, the actual
publish is a forced-command on the host (not in this YAML), and the runner
label / build image / signer fingerprint are non-sensitive.

Restores push-triggered CI: build assembleDebug in the straw-build image,
verify signer bb9ca96b, publish to fdroid. This push also builds vc=91.
2026-07-04 12:29:06 -07:00