mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 10:33:12 +00:00
The workflow-templates catalog offered starter workflows for only 7 of the 12 reusable workflows in .github/workflows, so ci-python-app, ci-typescript-frontend, ci-static, ci-dotnet and cd-mobile-ios were invisible in the org's Actions > New workflow UI and had to be wired by hand. Add a template + properties.json pair for each. Each caller CI job is keyed `ci` so the check context resolves to the `ci / ci` required by the org ruleset, and every reusable ref is pinned to the same 40-char SHA the existing templates use. node-version: "24" is passed on the three reusables that declare the input (ci-typescript-frontend, ci-static, cd-mobile-ios); ci-python-app and ci-dotnet do not declare it, so it is omitted there.
21 lines
892 B
YAML
21 lines
892 B
YAML
name: Deploy (iOS / TestFlight)
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
jobs:
|
|
deploy:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@555d07c3a240689a81668026787eba089df4c975 # main
|
|
with:
|
|
# Pinned explicitly (handbook): local dev is Node 24 / npm 11, which
|
|
# generates lockfileVersion 3. Being explicit avoids lockfile drift.
|
|
node-version: "24"
|
|
secrets:
|
|
# All five are required. deploy-role-arn is the repo's OIDC role, used
|
|
# here to read the fastlane match certificate store from S3; the four
|
|
# asc-*/match-* values come from App Store Connect and the match repo.
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
|
match-password: ${{ secrets.MATCH_PASSWORD }}
|
|
asc-key-id: ${{ secrets.ASC_KEY_ID }}
|
|
asc-issuer-id: ${{ secrets.ASC_ISSUER_ID }}
|
|
asc-key-content: ${{ secrets.ASC_KEY_CONTENT }}
|