mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 04:43:12 +00:00
Replace mutable v1 tag references with immutable commit SHAs so a compromised or force-moved tag cannot inject code into reusable workflows. Each pin keeps a # v1 comment for readability. - claude-code-action in compliance-audit.yaml - ruby/setup-ruby in cd-mobile-ios.yaml (v1 branch)
94 lines
2.7 KiB
YAML
94 lines
2.7 KiB
YAML
name: CD — Mobile iOS (TestFlight)
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
node-version:
|
|
description: "Node.js version to use"
|
|
type: string
|
|
default: "24"
|
|
ruby-version:
|
|
description: "Ruby version for Fastlane"
|
|
type: string
|
|
default: "3.3"
|
|
working-directory:
|
|
description: "Directory containing the mobile project"
|
|
type: string
|
|
default: "."
|
|
cache-dependency-path:
|
|
description: "Path to package-lock.json for npm cache"
|
|
type: string
|
|
default: "package-lock.json"
|
|
fastlane-lane:
|
|
description: "Fastlane lane to run"
|
|
type: string
|
|
default: "ios beta"
|
|
region:
|
|
description: "AWS region (for match S3 storage)"
|
|
type: string
|
|
default: "us-east-1"
|
|
timeout-minutes:
|
|
description: "Job timeout in minutes"
|
|
type: number
|
|
default: 45
|
|
secrets:
|
|
deploy-role-arn:
|
|
description: "OIDC deploy role ARN (for match S3 access)"
|
|
required: true
|
|
match-password:
|
|
description: "Encryption passphrase for match certificates"
|
|
required: true
|
|
asc-key-id:
|
|
description: "App Store Connect API key ID"
|
|
required: true
|
|
asc-issuer-id:
|
|
description: "App Store Connect API issuer ID"
|
|
required: true
|
|
asc-key-content:
|
|
description: "Base64-encoded App Store Connect API key (.p8)"
|
|
required: true
|
|
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
|
|
jobs:
|
|
deploy-ios:
|
|
runs-on: macos-26
|
|
timeout-minutes: ${{ inputs.timeout-minutes }}
|
|
defaults:
|
|
run:
|
|
working-directory: ${{ inputs.working-directory }}
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
|
|
- uses: aws-actions/configure-aws-credentials@v6
|
|
with:
|
|
role-to-assume: ${{ secrets.deploy-role-arn }}
|
|
aws-region: ${{ inputs.region }}
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: ${{ inputs.node-version }}
|
|
cache: npm
|
|
cache-dependency-path: ${{ inputs.cache-dependency-path }}
|
|
|
|
- uses: ruby/setup-ruby@afeafc3d1ab54a631816aba4c914a0081c12ff2f # v1
|
|
with:
|
|
ruby-version: ${{ inputs.ruby-version }}
|
|
bundler-cache: true
|
|
working-directory: ${{ inputs.working-directory }}
|
|
|
|
- name: Install JS dependencies
|
|
run: npm ci
|
|
|
|
- name: Install CocoaPods
|
|
run: bundle exec pod install --project-directory=ios
|
|
|
|
- name: Build and upload
|
|
run: bundle exec fastlane ${{ inputs.fastlane-lane }}
|
|
env:
|
|
MATCH_PASSWORD: ${{ secrets.match-password }}
|
|
ASC_KEY_ID: ${{ secrets.asc-key-id }}
|
|
ASC_ISSUER_ID: ${{ secrets.asc-issuer-id }}
|
|
ASC_KEY_CONTENT: ${{ secrets.asc-key-content }}
|