name: Build APK # Deliberately not "on every push" - only when a release-candidate tag # (RC1, RC2, RC2026.1, ...) is pushed. Tag the commit you want built: # git tag RC1 && git push origin RC1 on: push: tags: - "RC*" jobs: build: runs-on: ubuntu-latest steps: - name: Check out code uses: actions/checkout@v4 - name: Set up JDK 17 uses: actions/setup-java@v4 with: distribution: temurin java-version: "17" - name: Set up Flutter uses: subosito/flutter-action@v2 with: channel: stable - name: Set up Android SDK uses: android-actions/setup-android@v3 with: # Google removed the legacy standalone "tools" package from the # SDK repository (~Sep 2026); the action's own default packages # list ("tools platform-tools") now makes its internal sdkmanager # call fail for everyone. platform-tools is all this step needs # to install itself - flutter build fetches whatever # platform/build-tools versions it actually needs on its own. packages: "platform-tools" - name: Install dependencies run: flutter pub get - name: Analyze run: flutter analyze - name: Decode release keystore # Keeps every release build - regardless of which runner built it - # signed with the same key, so downloaded updates install cleanly # over a previous release instead of failing with "App not # installed" (mismatched signature). See android/app/build.gradle.kts. run: echo "$RELEASE_KEYSTORE_BASE64" | base64 -d > "${{ runner.temp }}/release-keystore.jks" env: RELEASE_KEYSTORE_BASE64: ${{ secrets.RELEASE_KEYSTORE_BASE64 }} - name: Build release APK run: flutter build apk --release env: RELEASE_KEYSTORE_PATH: ${{ runner.temp }}/release-keystore.jks RELEASE_KEYSTORE_PASSWORD: ${{ secrets.RELEASE_KEYSTORE_PASSWORD }} RELEASE_KEY_ALIAS: ${{ secrets.RELEASE_KEY_ALIAS }} RELEASE_KEY_PASSWORD: ${{ secrets.RELEASE_KEY_PASSWORD }} - name: Rename APK to Noo-.apk run: | VERSION=$(grep '^version:' pubspec.yaml | sed 's/version: //' | cut -d'+' -f1) mkdir -p release cp build/app/outputs/flutter-apk/app-release.apk "release/Noo-${VERSION}.apk" echo "APK_PATH=release/Noo-${VERSION}.apk" >> "$GITHUB_ENV" - name: Publish Gitea release with APK attached # Gitea-native release action (not GitHub's) - authenticates and # talks to this same Gitea instance automatically via the # `github.token`/`github.server_url` context Gitea Actions # provides for compatibility. Release is named/tagged after # whatever tag triggered this run (e.g. "RC1"). uses: akkuman/gitea-release-action@v1 with: files: ${{ env.APK_PATH }}