name: Build App Bundle # Deliberately not "on every push" - only when a real release tag (Release-1.0.0, # Release-1.2.3, ...) is pushed. Tag the commit you want built: # git tag Release-1.0.0 && git push origin Release-1.0.0 # Unlike the RC* flow (build.yml), this builds the .aab Play Console wants, # not a sideloadable .apk. on: push: tags: - "Release-*" jobs: build: runs-on: ubuntu-latest steps: - name: Check out code uses: actions/checkout@v4 - name: Set up JDK 17 uses: actions/setup-java@v4 with: distribution: temurin java-version: "17" - name: Set up Flutter uses: subosito/flutter-action@v2 with: channel: stable - name: Set up Android SDK uses: android-actions/setup-android@v3 with: # Google removed the legacy standalone "tools" package from the # SDK repository (~Sep 2026); the action's own default packages # list ("tools platform-tools") now makes its internal sdkmanager # call fail for everyone. platform-tools is all this step needs # to install itself - flutter build fetches whatever # platform/build-tools versions it actually needs on its own. packages: "platform-tools" - name: Check tag matches pubspec version # Play rejects a repeated versionCode and a mismatched tag would # publish the wrong version name, so fail fast before building. run: | VERSION=$(grep '^version:' pubspec.yaml | sed 's/version: //' | cut -d'+' -f1) if [ "${GITHUB_REF_NAME}" != "Release-${VERSION}" ]; then echo "Tag ${GITHUB_REF_NAME} does not match pubspec version ${VERSION}" >&2 exit 1 fi - name: Install dependencies run: flutter pub get - name: Analyze run: flutter analyze - name: Decode release keystore # Same key as the RC* APK builds, so a Play Store upload's signature # matches anything sideloaded from a release build. See # android/app/build.gradle.kts. run: echo "$RELEASE_KEYSTORE_BASE64" | base64 -d > "${{ runner.temp }}/release-keystore.jks" env: RELEASE_KEYSTORE_BASE64: ${{ secrets.RELEASE_KEYSTORE_BASE64 }} - name: Build release App Bundle run: flutter build appbundle --release env: RELEASE_KEYSTORE_PATH: ${{ runner.temp }}/release-keystore.jks RELEASE_KEYSTORE_PASSWORD: ${{ secrets.RELEASE_KEYSTORE_PASSWORD }} RELEASE_KEY_ALIAS: ${{ secrets.RELEASE_KEY_ALIAS }} RELEASE_KEY_PASSWORD: ${{ secrets.RELEASE_KEY_PASSWORD }} - name: Rename bundle to Noo-.aab run: | VERSION=$(grep '^version:' pubspec.yaml | sed 's/version: //' | cut -d'+' -f1) mkdir -p release cp build/app/outputs/bundle/release/app-release.aab "release/Noo-${VERSION}.aab" echo "AAB_PATH=release/Noo-${VERSION}.aab" >> "$GITHUB_ENV" echo "VERSION=${VERSION}" >> "$GITHUB_ENV" - name: Publish Gitea release with App Bundle attached # Gitea-native release action (not GitHub's) - authenticates and # talks to this same Gitea instance automatically via the # `github.token`/`github.server_url` context Gitea Actions # provides for compatibility. Release is named/tagged after # whatever tag triggered this run (e.g. "Release-1.0.0"). uses: akkuman/gitea-release-action@v1 with: files: ${{ env.AAB_PATH }} - name: Upload to Google Play (internal track, auto-publish) # Rolls the build out to internal testers automatically # (`status: completed`); promote it to other tracks in Play Console. # Needs the PLAY_SERVICE_ACCOUNT_JSON repo secret, and the app's # first release must already have been uploaded by hand. uses: r0adkll/upload-google-play@v1 with: serviceAccountJsonPlainText: ${{ secrets.PLAY_SERVICE_ACCOUNT_JSON }} packageName: dev.ayushya.noo releaseFiles: ${{ env.AAB_PATH }} releaseName: ${{ env.VERSION }} track: internal status: completed whatsNewDirectory: distribution/whatsnew