Repository navigation
ci: add Azure desktop packaging pipeline - #284
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
Release-tag and version-rewrite logic is duplicated across four CI paths, creating avoidable drift risk.
1 open finding
What changed in this PR
Adds Azure DevOps packaging for Windows and signed/notarized macOS desktop artifacts while preserving the existing release configuration.
Changes:
- Adds tag-triggered and manual Azure packaging jobs.
- Validates and publishes complete platform artifacts.
- Documents setup, secrets, ESRP integration, and validation.
| File | Description |
|---|---|
azure-pipelines.yml |
Defines Windows and macOS packaging jobs. |
docs/architecture/desktop-auto-update.md |
Documents Azure packaging and onboarding. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
Comment on lines
+44
to
+48
| @' | ||
| const fs = require('node:fs'); | ||
| const path = 'apps/desktop/package.json'; | ||
| const ref = process.env.BUILD_SOURCEBRANCH ?? ''; | ||
| const tag = ref.startsWith('refs/tags/') ? ref.slice('refs/tags/'.length) : (process.env.RELEASE_TAG ?? ''); |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Add an Azure DevOps pipeline that packages the Huabu desktop app on independent Microsoft-hosted Windows and macOS jobs, reusing the existing GitHub Actions release commands and electron-builder configuration.
.nvmrcand pass it toUseNode@1; use Corepack with the integrity-pinned pnpmpackageManager.releaseTagparameter without committing generated version changes.huabu-windowsandhuabu-macos, retaining auto-update metadata and blockmaps.Existing package scripts, electron-builder configuration, and GitHub Actions release publishing are unchanged. This PR does not publish GitHub Releases or configure ESRP.
Validation
pnpm install --frozen-lockfilecompleted in an isolated worktree based on currentmain.pnpm typecheckpassed.pnpm formatandpnpm lint:fixcompleted; lint reported 0 errors and 350 existing warnings. Only the pipeline and its architecture documentation are included..nvmrc(currently 24.16.0).Post-merge cloud validation required
The current governed Azure DevOps creation flow only reads YAML from the repository's default branch, so actual hosted Windows/macOS packaging and Apple signing/notarization have NOT been run yet. Compatibility with any organization-required governed templates must also be confirmed during onboarding.
/azure-pipelines.ymlfrom the default branch.CSC_LINK(base64 Developer ID .p12),CSC_KEY_PASSWORD,APPLE_ID,APPLE_APP_SPECIFIC_PASSWORD, andAPPLE_TEAM_ID.releaseTag; do not push a real version tag for this test, since that also triggers the existing GitHub Actions release workflow.Windows build -> ESRP Sign -> Publish artifact. If signing changes installer bytes, regenerate matching update metadata and blockmaps before publishing.