Build and sign releases in CI, and install locally with one command

Ported from margin's pipeline, with the platform list this app actually
claims. Release is manual: it bumps tauri.conf.json, package.json and
Cargo.toml together, tags, and then builds the tag rather than whatever main
has drifted to by the time the runners pick it up.

Nothing publishes until every platform lands. The last job downloads
latest.json and refuses to take the release out of draft unless
darwin-aarch64, darwin-x86_64 and linux-x86_64 are all present, because a
half-populated manifest is worse than no release at all: the updater would
offer an update to the platforms that made it and error on the ones that did
not.

Linux builds on Ubuntu 22.04 rather than latest. The bundle will not run on
anything older than the glibc it was linked against, and 22.04 is the
baseline docs/setup.md commits to. Windows is not built, matching the bundle
targets and the README; adding it is a matrix entry, msi and nsis in the
targets, and windows-x86_64 in the publish gate.

The updater had a plugin, a capability and a menu item but no keypair and no
endpoint, so releases would have produced artifacts nothing could verify.
The public half is now in tauri.release.conf.json and the private half is a
repository secret, alongside the Google OAuth client that build.rs embeds.
Without that secret the build falls back to the example credentials and warns
rather than failing, which yields an app that runs and then says Google
Calendar is not set up.

CI enforces the gate setup.md already names, the two test suites, and nothing
more. cargo fmt --check and cargo clippy -D warnings both fail on the tree as
it stands, and adopting either is a cleanup pass to decide on rather than
something to bolt onto a new pipeline.

justfile is the local equivalent of all this. `just install` builds for the
machine it is run on and installs it, and is the same command whether or not
the app is already there, so it doubles as the update. On macOS it asks a
running copy to quit first, because replacing a bundle under a live process
leaves it half old and half new.
This commit is contained in:
pj committed 2026-08-12 20:16:29 +05:30
1 parent d4c3a304b5
commit 590506eb92
6 files changed
+458 -5

No files matched your search

+6 -5
View File
@@ -6,8 +6,9 @@ fits without scrolling, and on a desktop the whole thing is drivable from the ke
It is a sibling to [margin](https://github.com/priyanshujain/margin) and shares its stack and its
visual language.
Setup and the Google OAuth client it needs are in [docs/setup.md](docs/setup.md), and the extra
clients a phone build needs are in [docs/mobile.md](docs/mobile.md). The product decisions are in
[docs/design.md](docs/design.md), how it is built is in
[docs/architecture.md](docs/architecture.md), and the conventions it follows are in
[docs/conventions.md](docs/conventions.md).
`just install` builds it and installs it on the machine you are on. Setup and the Google OAuth
client it needs are in [docs/setup.md](docs/setup.md), and the extra clients a phone build needs
are in [docs/mobile.md](docs/mobile.md). How releases are cut is in
[docs/release.md](docs/release.md). The product decisions are in [docs/design.md](docs/design.md),
how it is built is in [docs/architecture.md](docs/architecture.md), and the conventions it follows
are in [docs/conventions.md](docs/conventions.md).