mirror of
https://github.com/openclaw/openclaw.git
synced 2026-09-28 14:12:28 +08:00
* chore(deps): refresh dependencies with a seven-day cutoff * fix(deps): preserve Teams and jsdom integration contracts Use the Teams SDK public token and processing APIs while keeping SSO sender checks ahead of native token operations. Remove obsolete ambient declarations and route workarounds, and cover the SDK routing with real processing tests. Adapt the test environment to jsdom private-field bindings, preserve file bytes and registry cleanup, and preload it through native Node and Bun workers. * fix(test): preserve jsdom window and fixture contracts * fix(ci): keep typecheck cache reuse within matching inputs
105 lines
4.2 KiB
YAML
105 lines
4.2 KiB
YAML
name: macOS Release
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
tag:
|
|
description: Existing release tag to validate for macOS release handoff (for example v2026.3.22, v2026.3.22-alpha.1, or v2026.3.22-beta.1)
|
|
required: true
|
|
type: string
|
|
preflight_only:
|
|
description: Retained for operator compatibility; this public workflow is validation-only
|
|
required: true
|
|
default: true
|
|
type: boolean
|
|
public_release_branch:
|
|
description: Public branch that contains the release tag commit, usually main or release/YYYY.M.PATCH
|
|
required: false
|
|
default: main
|
|
type: string
|
|
|
|
concurrency:
|
|
group: macos-release-${{ inputs.tag }}
|
|
cancel-in-progress: false
|
|
|
|
env:
|
|
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
|
|
NODE_VERSION: "24.21.0"
|
|
|
|
jobs:
|
|
validate_macos_release_request:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Validate tag input format
|
|
env:
|
|
RELEASE_TAG: ${{ inputs.tag }}
|
|
run: |
|
|
set -euo pipefail
|
|
if [[ ! "${RELEASE_TAG}" =~ ^v[0-9]{4}\.[1-9][0-9]*\.[1-9][0-9]*((-(alpha|beta)\.[1-9][0-9]*)|(-[1-9][0-9]*))?$ ]]; then
|
|
echo "Invalid release tag format: ${RELEASE_TAG}"
|
|
exit 1
|
|
fi
|
|
|
|
- name: Prepare Git owner
|
|
uses: openclaw/openclaw/.github/actions/git-owner@dd4528b6393e7d00063067a080ca7241b48ce475
|
|
|
|
- name: Checkout selected tag
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
ref: refs/tags/${{ inputs.tag }}
|
|
fetch-depth: 0
|
|
|
|
- name: Setup Node environment
|
|
uses: ./.github/actions/setup-node-env
|
|
with:
|
|
cache-mode: restore
|
|
node-version: ${{ env.NODE_VERSION }}
|
|
install-bun: "false"
|
|
build-all-cache-scope: full
|
|
|
|
- name: Build
|
|
run: pnpm build
|
|
|
|
- name: Build Control UI
|
|
env:
|
|
OPENCLAW_CONTROL_UI_RELEASE_BUILD: "1"
|
|
run: pnpm ui:build
|
|
|
|
- name: Validate release tag and package metadata
|
|
env:
|
|
RELEASE_TAG: ${{ inputs.tag }}
|
|
PUBLIC_RELEASE_BRANCH: ${{ inputs.public_release_branch }}
|
|
run: |
|
|
set -euo pipefail
|
|
if [[ "${PUBLIC_RELEASE_BRANCH}" != "main" && ! "${PUBLIC_RELEASE_BRANCH}" =~ ^release/[0-9]{4}\.[1-9][0-9]*\.[1-9][0-9]*$ ]]; then
|
|
echo "public_release_branch must be main or release/YYYY.M.PATCH, got ${PUBLIC_RELEASE_BRANCH}." >&2
|
|
exit 1
|
|
fi
|
|
RELEASE_SHA="$(
|
|
python3 -I -S "$CI_GIT_OWNER" --git 0 rev-parse HEAD
|
|
)"
|
|
RELEASE_MAIN_REF="refs/remotes/origin/${PUBLIC_RELEASE_BRANCH}"
|
|
export RELEASE_SHA RELEASE_TAG RELEASE_MAIN_REF
|
|
python3 -I -S "$CI_GIT_OWNER" --checkout-git 120 fetch --no-tags origin \
|
|
"+refs/heads/${PUBLIC_RELEASE_BRANCH}:refs/remotes/origin/${PUBLIC_RELEASE_BRANCH}"
|
|
pnpm release:openclaw:npm:check
|
|
|
|
- name: Summarize next step
|
|
env:
|
|
RELEASE_TAG: ${{ inputs.tag }}
|
|
run: |
|
|
{
|
|
echo "## Public macOS validation only"
|
|
echo
|
|
echo "This workflow validates the public release handoff and still builds JS artifacts needed for release checks."
|
|
echo "It does not sign, notarize, or upload macOS assets."
|
|
echo
|
|
echo "Next step:"
|
|
echo "- Run \`openclaw/releases/.github/workflows/openclaw-macos-validate.yml\` with tag \`${RELEASE_TAG}\` and wait for the macOS validation lane to pass."
|
|
echo "- Run \`openclaw/releases/.github/workflows/openclaw-macos-publish.yml\` with tag \`${RELEASE_TAG}\` and \`preflight_only=true\` for the full macOS preflight."
|
|
echo "- For the real publish path, run the same macOS publish workflow from \`main\` with the successful preflight \`preflight_run_id\` so it promotes the prepared artifacts instead of rebuilding them."
|
|
echo "- For stable releases, the publish workflow uploads universal, arm64, and x86_64 assets and publishes their signed Sparkle appcasts to public \`main\`, or opens an appcast PR if direct push is blocked."
|
|
} >> "$GITHUB_STEP_SUMMARY"
|