Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
54 changes: 44 additions & 10 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
name: Release Artifacts
name: Release APK and Windows MSIX

on:
release:
Expand Down Expand Up @@ -80,23 +80,57 @@ jobs:
- name: Build release Windows app
run: flutter build windows --release

- name: Build MSIX installer
- name: Import MSIX signing certificate
id: import-msix-certificate
shell: pwsh
env:
MSIX_CERT_PFX_BASE64: ${{ secrets.MSIX_CERT_PFX_BASE64 }}
run: |
if ([string]::IsNullOrWhiteSpace($env:MSIX_CERT_PFX_BASE64)) {
throw 'Missing required secret: MSIX_CERT_PFX_BASE64'
}
$certPath = Join-Path $env:RUNNER_TEMP 'msix-signing.pfx'
$cerPath = Join-Path $env:RUNNER_TEMP 'msix-signing.cer'
[System.IO.File]::WriteAllBytes($certPath, [System.Convert]::FromBase64String($env:MSIX_CERT_PFX_BASE64))
$certPassword = ConvertTo-SecureString -String "${{ secrets.MSIX_CERT_PASSWORD }}" -AsPlainText -Force
$importedCert = Import-PfxCertificate -FilePath $certPath -Password $certPassword -CertStoreLocation 'Cert:\CurrentUser\My'
Export-Certificate -Cert $importedCert -FilePath $cerPath | Out-Null
"cert_path=$certPath" >> $env:GITHUB_OUTPUT
"cer_path=$cerPath" >> $env:GITHUB_OUTPUT

- name: Create MSIX installer
shell: pwsh
env:
MSIX_CERT_PASSWORD: ${{ secrets.MSIX_CERT_PASSWORD }}
run: |
if ([string]::IsNullOrWhiteSpace($env:MSIX_CERT_PASSWORD)) {
throw 'Missing required secret: MSIX_CERT_PASSWORD'
}
dart run msix:create --build-windows false --install-certificate false --certificate-path "${{ steps.import-msix-certificate.outputs.cert_path }}" --certificate-password "$env:MSIX_CERT_PASSWORD"

- name: Prepare versioned Windows MSIX filename
id: msix
shell: pwsh
env:
VERSION: ${{ github.event.release.tag_name || github.ref_name }}
run: |
$version = $env:VERSION.TrimStart('v')
$outputDir = 'build/windows/msix'
New-Item -ItemType Directory -Path $outputDir -Force | Out-Null
dart run msix:create --build-windows false --install-certificate false --output-path $outputDir --output-name "simplications-$version-windows-installer"
$msixPath = (Get-ChildItem -Path $outputDir -Filter '*.msix' | Select-Object -First 1).FullName
if (-not $msixPath) {
throw 'MSIX output was not created.'
$msixSrc = Get-ChildItem -Path 'build' -Filter '*.msix' -Recurse | Select-Object -First 1
if (-not $msixSrc) {
throw 'MSIX package not found under build/'
}
"msix_path=$msixPath" >> $env:GITHUB_OUTPUT
$msixTarget = "build/simplications-$version-windows-release.msix"
Copy-Item -Path $msixSrc.FullName -Destination $msixTarget -Force
"msix_path=$msixTarget" >> $env:GITHUB_OUTPUT

- name: Attach MSIX to release
uses: softprops/action-gh-release@v2
with:
files: ${{ steps.msix.outputs.msix_path }}
files: |
${{ steps.msix.outputs.msix_path }}
${{ steps.import-msix-certificate.outputs.cer_path }}
append_body: true
body: |
## Internal Testing: Trust Install for Windows MSIX
If SmartScreen or certificate trust blocks install, follow the tester guide:
https://github.com/${{ github.repository }}/blob/main/docs/msix-trust-install.md
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,8 @@ The app targets Android, iOS, Web, Windows, macOS, and Linux.

All developer setup, architecture notes, code standards, and contribution workflow are documented in [CONTRIBUTING.md](CONTRIBUTING.md).

Internal Windows MSIX trust-install instructions for testing are documented in [docs/msix-trust-install.md](docs/msix-trust-install.md).

### Localization workflow (contributors)

1. Add the new key in `lib/l10n/app_en.arb`.
Expand Down
33 changes: 33 additions & 0 deletions docs/msix-trust-install.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
# Windows MSIX Trust Install (Internal Testing)

This guide is for internal testers using releases signed with the project self-signed certificate.

## When to use this

Use these steps if Windows blocks the installer with a trust or SmartScreen warning.

## Steps (GUI)

1. Download both release assets:
- `simplications-<version>-windows-release.msix`
- `msix-signing.cer`
2. Open `msix-signing.cer`.
3. Select Install Certificate.
4. Choose Current User (or Local Machine if required by your policy).
5. Choose Place all certificates in the following store.
6. Browse and select Trusted People.
7. Complete the wizard.
8. Run the `.msix` installer again.

## Optional PowerShell import

Run PowerShell as your user:

```powershell
Import-Certificate -FilePath .\msix-signing.cer -CertStoreLocation Cert:\CurrentUser\TrustedPeople
```

## Notes

- This process is only for internal testing.
- For public releases without trust prompts, use a certificate issued by a trusted code-signing CA.
8 changes: 4 additions & 4 deletions pubspec.lock
Original file line number Diff line number Diff line change
Expand Up @@ -321,10 +321,10 @@ packages:
dependency: transitive
description:
name: meta
sha256: "23f08335362185a5ea2ad3a4e597f1375e78bce8a040df5c600c8d3552ef2394"
sha256: "1741988757a65eb6b36abe716829688cf01910bbf91c34354ff7ec1c3de2b349"
url: "https://pub.dev"
source: hosted
version: "1.17.0"
version: "1.18.0"
mime:
dependency: transitive
description:
Expand Down Expand Up @@ -606,10 +606,10 @@ packages:
dependency: transitive
description:
name: test_api
sha256: "8161c84903fd860b26bfdefb7963b3f0b68fee7adea0f59ef805ecca346f0c7a"
sha256: "949a932224383300f01be9221c39180316445ecb8e7547f70a41a35bf421fb9e"
url: "https://pub.dev"
source: hosted
version: "0.7.10"
version: "0.7.11"
typed_data:
dependency: transitive
description:
Expand Down
Loading
Loading