# CI for Tane. Mirrors the local verification gate (analyze + test + # coverage) from docs/design/testing.md. Adapt to GitHub Actions if the # canonical remote changes; the commands are the same. # # Uses the official Flutter Docker image. Pin the version to match the # developer toolchain (Flutter 3.41.x / Dart 3.11.x). image: ghcr.io/cirruslabs/flutter:3.41.9 stages: - analyze - test - build - deploy variables: PUB_CACHE: "$CI_PROJECT_DIR/.pub-cache" cache: key: "$CI_COMMIT_REF_SLUG" paths: - .pub-cache/ before_script: # SQLCipher so the "no plaintext at rest" security test actually runs (it # skips where the library is absent). The -dev package ships the unversioned # libsqlcipher.so symlink, which package:sqlite3 loads reliably. - apt-get update -qq && apt-get install -y -qq libsqlcipher-dev - flutter --version - flutter pub get analyze: stage: analyze script: - dart format --output=none --set-exit-if-changed . - flutter analyze test:commons_core: stage: test script: - cd packages/commons_core - dart test # Windows desktop build. Needs a Windows runner: on gitlab.com the SaaS # `saas-windows-medium-amd64` shared runners (Windows Server 2022 with Visual # Studio 2022 Build Tools — the C++ workload Flutter requires). Manual + # allow_failure until the canonical remote actually has Windows runners. build:windows: stage: build tags: - saas-windows-medium-amd64 rules: - when: manual allow_failure: true # The global Linux image is ignored on Windows shell runners; override the # global before_script (apt-get) — this job runs in PowerShell. before_script: - git clone --depth 1 -b stable https://github.com/flutter/flutter.git "$env:CI_PROJECT_DIR\.flutter" - $env:PATH = "$env:CI_PROJECT_DIR\.flutter\bin;$env:PATH" - flutter --version - flutter pub get script: - cd apps\app_seeds - dart run slang - dart run build_runner build --delete-conflicting-outputs - flutter build windows --release artifacts: paths: - apps/app_seeds/build/windows/x64/runner/Release/ test:app_seeds: stage: test script: - cd apps/app_seeds # slang is generated via its CLI (disabled in build_runner); Drift via build_runner. - dart run slang - dart run build_runner build --delete-conflicting-outputs - flutter test --coverage coverage: '/lines\.*: \d+\.\d+\%/' artifacts: paths: - apps/app_seeds/coverage/lcov.info reports: coverage_report: coverage_format: cobertura path: apps/app_seeds/coverage/cobertura.xml # --------------------------------------------------------------------------- # Release automation. Runs ONLY on tags, so it never touches the per-push gate. # Password-free: signing + Play credentials come from masked+protected CI vars. # Required CI variables (Settings > CI/CD > Variables), set once: # TANE_KEYSTORE_BASE64 base64 of the dedicated Tane upload keystore (.jks) # TANE_KEYSTORE_PASSWORD store password # TANE_KEY_ALIAS key alias (tane-upload) # TANE_KEY_PASSWORD key password # SUPPLY_JSON_KEY_DATA Google Play service-account JSON (raw file contents) # Tag a commit (e.g. `git tag v0.1.0 && git push --tags`) to build + publish. # --------------------------------------------------------------------------- # Build the signed release artifacts (AAB for Play, APK for sideload/QA). build:android: stage: build rules: - if: '$CI_COMMIT_TAG' script: - cd apps/app_seeds - dart run slang - dart run build_runner build --delete-conflicting-outputs # Materialize the signing material from CI secrets (never in the repo). - echo "$TANE_KEYSTORE_BASE64" | base64 -d > "$CI_PROJECT_DIR/tane-upload.jks" - | cat > android/key.properties <