name: Release # Tag pushes mirrored from Gitea (git.jezz.wtf) trigger this on the GitHub # mirror. Builds the NSIS installer and attaches it to a DRAFT GitHub Release — # review and publish manually. on: push: tags: - 'v*' workflow_dispatch: jobs: release: permissions: contents: write runs-on: windows-latest steps: - uses: actions/checkout@v4 - uses: pnpm/action-setup@v4 with: version: 11 - uses: actions/setup-node@v4 with: node-version: 22 cache: pnpm - name: Install Rust stable uses: dtolnay/rust-toolchain@stable - uses: Swatinem/rust-cache@v2 with: workspaces: src-tauri - name: Install frontend dependencies run: pnpm install --frozen-lockfile - name: Build and create draft release uses: tauri-apps/tauri-action@v1 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Updater artifact signing (Phase 3) — set these repo secrets once # the updater keypair exists; empty values are ignored until then. TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }} TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }} with: tagName: ${{ github.ref_name }} releaseName: 'Phokus v__VERSION__' releaseBody: 'See the assets below to download and install this version.' releaseDraft: true prerelease: false uploadUpdaterJson: true updaterJsonPreferNsis: true # Cargo args after `--`: ship the CPU/DirectML build — default # features enable candle-cuda, which runners (and most users) lack. args: '-- --no-default-features'