feat(updater): nightly builds and a stable/nightly update channel

Every master push publishes its artifacts as a prerelease of
4gray/iptvnator-nightly instead of the rolling test-master draft, with a
version of <next patch>-nightly.<commit date>.<run number> applied in
every build job. Settings → About gains an Update channel switch;
AppUpdateService re-points electron-updater per check (feed repository,
allowPrerelease, channel name, allowDowngrade reset) and reads release
notes from the repository the requested version belongs to. Channel
switches are forward-only: a nightly build stays until a newer stable
release exists.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
4grayandClaude Fable 5.1 committed 2026-09-15 10:16:39 +02:00
1 parent 7f724494b9
commit c9272f5635
53 files changed
+2024 -223

No files matched your search

+227 -9
View File
@@ -13,6 +13,14 @@ name: Build and Make Electron App
# cleanup-pr-draft.yml deletes the draft when the PR closes, so the stale
# window is visible and bounded; refreshing drafts on skipped runs is not
# worth a separate workflow.
#
# Master pushes are the nightly channel: every build job rewrites the
# package.json version to <next patch>-nightly.<date>.<run number>
# (tools/release/nightly-version.mjs) so electron-updater treats the build
# as newer than the released version, and the release job publishes the
# artifacts as a prerelease of 4gray/iptvnator-nightly instead of the
# rolling test-master draft. Contract: docs/architecture/release-pipeline.md
# ("Nightly channel").
on:
push:
branches:
@@ -445,6 +453,16 @@ jobs:
BUILD_COMMIT: ${{ github.event.pull_request.head.sha || github.sha }}
run: node tools/build/inject-build-commit.mjs
- name: Apply nightly version
# Master merges feed the nightly update channel. The version
# must be greater than the released one for electron-updater to
# offer it, and it must be in package.json before the frontend
# and backend builds and electron-builder read it. Every job of
# this run derives the same value from the commit date and the
# run number, so nothing has to be handed between jobs.
if: github.event_name == 'push' && github.ref == 'refs/heads/master' && github.repository == '4gray/iptvnator'
run: node tools/release/nightly-version.mjs --apply
- name: Build frontend
run: pnpm nx build web --skip-nx-cache
@@ -1188,6 +1206,7 @@ jobs:
dist/executables/**/*.dmg
dist/executables/**/*.zip
dist/executables/**/latest-mac.yml
dist/executables/**/nightly-mac.yml
dist/executables/**/*.blockmap
retention-days: 7
@@ -1212,6 +1231,7 @@ jobs:
dist/executables/*.AppImage
dist/executables/*.snap
dist/executables/**/latest-linux*.yml
dist/executables/**/nightly-linux*.yml
dist/executables/**/*.blockmap
retention-days: 7
@@ -1234,6 +1254,7 @@ jobs:
dist/executables/**/*.msi
dist/executables/**/*.zip
dist/executables/**/latest.yml
dist/executables/**/nightly.yml
dist/executables/**/*.blockmap
retention-days: 7
@@ -1285,6 +1306,12 @@ jobs:
cancel-in-progress: false
permissions:
contents: write
env:
# Master pushes publish to the nightly repository (steps at the
# end of this job) instead of the rolling draft.
NIGHTLY: ${{ github.event_name == 'push' && github.ref == 'refs/heads/master' && github.repository == '4gray/iptvnator' }}
NIGHTLY_REPOSITORY: 4gray/iptvnator-nightly
NIGHTLY_KEEP_RELEASES: '20'
steps:
- name: Checkout code
@@ -1306,10 +1333,20 @@ jobs:
node <<'NODE'
const fs = require('fs');
const candidates = [
'artifacts/macos-x64-artifacts/latest-mac.yml',
'artifacts/macos-arm64-artifacts/latest-mac.yml',
].filter((filePath) => fs.existsSync(filePath));
// electron-builder names the updater metadata after the
// channel: latest-mac.yml for releases, nightly-mac.yml for
// the prerelease versions master builds carry.
const channelFile = ['latest-mac.yml', 'nightly-mac.yml'].find(
(name) =>
fs.existsSync(`artifacts/macos-x64-artifacts/${name}`) ||
fs.existsSync(`artifacts/macos-arm64-artifacts/${name}`)
);
const candidates = channelFile
? [
`artifacts/macos-x64-artifacts/${channelFile}`,
`artifacts/macos-arm64-artifacts/${channelFile}`,
].filter((filePath) => fs.existsSync(filePath))
: [];
if (candidates.length === 0) {
console.log('No macOS update metadata found; skipping merge.');
@@ -1407,8 +1444,8 @@ jobs:
mergedEntries
);
fs.writeFileSync('artifacts/latest-mac.yml', merged);
console.log(`Merged ${candidates.length} macOS update metadata files.`);
fs.writeFileSync(`artifacts/${channelFile}`, merged);
console.log(`Merged ${candidates.length} macOS update metadata files into ${channelFile}.`);
NODE
- name: Get version from package.json
@@ -1422,6 +1459,7 @@ jobs:
# for every push. PR builds must not use github.sha here: that is the
# ephemeral merge-commit SHA, which resolves to nothing in the repo.
- name: Compose release metadata
if: env.NIGHTLY != 'true'
id: release-meta
shell: bash
env:
@@ -1499,7 +1537,7 @@ jobs:
# full current set right after. Only drafts are pruned; published
# releases are never touched.
- name: Prune stale draft assets
if: github.event_name != 'pull_request' || steps.pr-state.outputs.state == 'open'
if: env.NIGHTLY != 'true' && (github.event_name != 'pull_request' || steps.pr-state.outputs.state == 'open')
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
RELEASE_TAG: ${{ steps.release-meta.outputs.tag }}
@@ -1522,7 +1560,7 @@ jobs:
- name: Create Draft Release
id: draft-release
if: github.event_name != 'pull_request' || steps.pr-state.outputs.state == 'open'
if: env.NIGHTLY != 'true' && (github.event_name != 'pull_request' || steps.pr-state.outputs.state == 'open')
uses: softprops/action-gh-release@v3
with:
draft: true
@@ -1569,7 +1607,7 @@ jobs:
# body is left as the action set it and only title/commitish are
# re-asserted.
- name: Ensure draft metadata is current
if: steps.draft-release.outputs.id != ''
if: env.NIGHTLY != 'true' && steps.draft-release.outputs.id != ''
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
RELEASE_ID: ${{ steps.draft-release.outputs.id }}
@@ -1612,3 +1650,183 @@ jobs:
--arg body "${FULL_BODY}" \
'{tag_name: $tag, name: $name, target_commitish: $commitish, body: ($body | .[0:120000])}' |
gh api -X PATCH "repos/${GITHUB_REPOSITORY}/releases/${RELEASE_ID}" --input - > /dev/null
# ── Nightly channel ──────────────────────────────────────────
# Drafts are invisible to anyone without write access and to
# electron-updater, so master builds are published as prereleases
# of the nightly repository, which the desktop app's Nightly update
# channel follows. The repository needs one commit on its default
# branch (gh creates the release tag there) and a fine-grained PAT
# with Contents: read/write on it, stored as NIGHTLY_RELEASE_TOKEN.
# Without the token the build still succeeds and only warns.
- name: Resolve nightly release metadata
if: env.NIGHTLY == 'true'
id: nightly-meta
shell: bash
env:
NIGHTLY_RELEASE_TOKEN: ${{ secrets.NIGHTLY_RELEASE_TOKEN }}
run: |
set -euo pipefail
VERSION="$(node tools/release/nightly-version.mjs)"
{
echo "version=${VERSION}"
echo "tag=v${VERSION}"
} >> "${GITHUB_OUTPUT}"
if [ -z "${NIGHTLY_RELEASE_TOKEN}" ]; then
echo "::warning::NIGHTLY_RELEASE_TOKEN is not configured; the nightly release for ${VERSION} is skipped."
echo "publish=false" >> "${GITHUB_OUTPUT}"
else
echo "publish=true" >> "${GITHUB_OUTPUT}"
fi
# The notes list the master commits since the previous nightly.
# That nightly's source commit is read back from the marker its
# own notes carry, because the nightly repository has no copy of
# the app history to compare against. The main-repository compare
# uses GITHUB_TOKEN; only the nightly repository is read with the
# PAT.
- name: Compose nightly release notes
if: steps.nightly-meta.outputs.publish == 'true'
id: nightly-notes
shell: bash
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NIGHTLY_RELEASE_TOKEN: ${{ secrets.NIGHTLY_RELEASE_TOKEN }}
VERSION: ${{ steps.nightly-meta.outputs.version }}
HEAD_SHA: ${{ github.sha }}
REPO_URL: ${{ github.server_url }}/${{ github.repository }}
RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
run: |
set -euo pipefail
SHORT_SHA="${HEAD_SHA:0:7}"
NOTES_FILE="${RUNNER_TEMP}/nightly-notes.md"
PREVIOUS_TAG="$(GH_TOKEN="${NIGHTLY_RELEASE_TOKEN}" gh release list \
--repo "${NIGHTLY_REPOSITORY}" --exclude-drafts --limit 1 \
--json tagName --jq '.[0].tagName // ""')"
PREVIOUS_SHA=""
if [ -n "${PREVIOUS_TAG}" ]; then
PREVIOUS_SHA="$(GH_TOKEN="${NIGHTLY_RELEASE_TOKEN}" gh release view "${PREVIOUS_TAG}" \
--repo "${NIGHTLY_REPOSITORY}" --json body --jq '.body // ""' |
sed -n 's/.*<!-- iptvnator-commit: \([0-9a-f]\{40\}\) -->.*/\1/p' | head -n 1)"
fi
COMMITS=""
if [ -n "${PREVIOUS_SHA}" ] && [ "${PREVIOUS_SHA}" != "${HEAD_SHA}" ]; then
# A rewritten history makes the compare fail; the notes
# then just omit the list rather than failing the release.
COMMITS="$(gh api "repos/${GITHUB_REPOSITORY}/compare/${PREVIOUS_SHA}...${HEAD_SHA}" \
--jq '.commits[] | "- [`\(.sha[0:7])`](\(.html_url)) \(.commit.message | split("\n")[0])"' || true)"
fi
{
printf '🌙 Nightly build from `master` — commit [`%s`](%s/commit/%s) · [workflow run](%s)\n\n' \
"${SHORT_SHA}" "${REPO_URL}" "${HEAD_SHA}" "${RUN_URL}"
printf 'Untested snapshot of master for the desktop app'"'"'s **Nightly** update channel (Settings → About → Update channel). Nightly builds may break, and their database changes are permanent: switching back to Stable keeps this build installed until the next stable release is newer. Back up your playlists first.\n\n'
if [ -n "${COMMITS}" ]; then
printf '## Changes since %s\n\n%s\n\n' "${PREVIOUS_TAG}" "${COMMITS}"
else
printf 'See the [commit history](%s/commits/master) for what changed.\n\n' "${REPO_URL}"
fi
printf '<!-- iptvnator-commit: %s -->\n' "${HEAD_SHA}"
} > "${NOTES_FILE}"
echo "notes-file=${NOTES_FILE}" >> "${GITHUB_OUTPUT}"
# Created as a draft, assets uploaded, then published in one edit,
# so electron-updater never sees a release whose channel file is
# still missing. The release job is serialized per ref but two
# master runs can still finish out of order, so a nightly that is
# older than the newest published one is dropped instead of
# becoming the feed's newest entry.
- name: Publish nightly release
if: steps.nightly-meta.outputs.publish == 'true'
shell: bash
env:
GH_TOKEN: ${{ secrets.NIGHTLY_RELEASE_TOKEN }}
TAG: ${{ steps.nightly-meta.outputs.tag }}
VERSION: ${{ steps.nightly-meta.outputs.version }}
HEAD_SHA: ${{ github.sha }}
NOTES_FILE: ${{ steps.nightly-notes.outputs.notes-file }}
run: |
set -euo pipefail
shopt -s nullglob
NEWEST_PUBLISHED="$(gh release list --repo "${NIGHTLY_REPOSITORY}" --exclude-drafts --limit 200 \
--json tagName --jq '.[].tagName | select(test("^v[0-9]+\\.[0-9]+\\.[0-9]+-nightly\\."))' |
sort -V | tail -n 1)"
if [ -n "${NEWEST_PUBLISHED}" ] && [ "${NEWEST_PUBLISHED}" != "${TAG}" ] &&
[ "$(printf '%s\n%s\n' "${NEWEST_PUBLISHED}" "${TAG}" | sort -V | tail -n 1)" != "${TAG}" ]; then
echo "::notice::${NEWEST_PUBLISHED} is already published and newer than ${TAG}; not publishing this superseded build."
exit 0
fi
for required in \
artifacts/nightly-mac.yml \
artifacts/windows-artifacts/nightly.yml \
artifacts/linux-portable-artifacts/nightly-linux.yml; do
if [ ! -f "${required}" ]; then
echo "::error::Missing updater metadata ${required}; the nightly channel would be unable to install this build."
exit 1
fi
done
assets=(
artifacts/macos-x64-artifacts/*-x64.dmg
artifacts/macos-x64-artifacts/*-x64.zip
artifacts/macos-x64-artifacts/*.blockmap
artifacts/macos-arm64-artifacts/*-arm64.dmg
artifacts/macos-arm64-artifacts/*-arm64.zip
artifacts/macos-arm64-artifacts/*.blockmap
artifacts/nightly-mac.yml
artifacts/linux-system-artifacts/*.deb
artifacts/linux-system-artifacts/*.rpm
artifacts/linux-system-artifacts/*.pacman
artifacts/linux-system-artifacts/*.pkg.tar.*
artifacts/linux-portable-artifacts/*.AppImage
artifacts/linux-portable-artifacts/*.snap
artifacts/linux-portable-artifacts/nightly-linux*.yml
artifacts/linux-portable-artifacts/*.blockmap
artifacts/linux-flatpak-artifacts/*.flatpak
artifacts/linux-frame-copy-runtime-sources/linux-frame-copy-runtime-sources.tar.xz
artifacts/windows-artifacts/*-setup.exe
artifacts/windows-artifacts/*.msi
artifacts/windows-artifacts/*.zip
artifacts/windows-artifacts/nightly.yml
artifacts/windows-artifacts/*.blockmap
)
if gh release view "${TAG}" --repo "${NIGHTLY_REPOSITORY}" > /dev/null 2>&1; then
echo "Release ${TAG} already exists (re-run); replacing it."
gh release delete "${TAG}" --repo "${NIGHTLY_REPOSITORY}" --cleanup-tag --yes
fi
gh release create "${TAG}" "${assets[@]}" \
--repo "${NIGHTLY_REPOSITORY}" \
--draft \
--prerelease \
--title "Nightly ${VERSION} (${HEAD_SHA:0:7})" \
--notes-file "${NOTES_FILE}"
gh release edit "${TAG}" --repo "${NIGHTLY_REPOSITORY}" --draft=false --prerelease
echo "Published ${TAG} to ${NIGHTLY_REPOSITORY} with ${#assets[@]} assets."
- name: Prune old nightly releases
if: steps.nightly-meta.outputs.publish == 'true'
shell: bash
env:
GH_TOKEN: ${{ secrets.NIGHTLY_RELEASE_TOKEN }}
run: |
set -euo pipefail
gh release list --repo "${NIGHTLY_REPOSITORY}" --exclude-drafts --limit 200 \
--json tagName --jq '.[].tagName | select(test("^v[0-9]+\\.[0-9]+\\.[0-9]+-nightly\\."))' |
sort -V -r | tail -n "+$((NIGHTLY_KEEP_RELEASES + 1))" |
while read -r tag; do
[ -n "${tag}" ] || continue
echo "Deleting nightly ${tag} (keeping the newest ${NIGHTLY_KEEP_RELEASES})."
gh release delete "${tag}" --repo "${NIGHTLY_REPOSITORY}" --cleanup-tag --yes
done