[codex] Fix desktop release workflow CI - #6

Merged
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci
Jun 8, 2026
Merged

[codex] Fix desktop release workflow CI#6
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci

Conversation

@DragonnZhang

Copy link
Copy Markdown
Member

What this PR does

Fixes the desktop release workflow so the cross-platform build jobs can rerun successfully after the initial 0.0.2 release attempt failed. The build matrix now uses bash consistently for shell expansion, signing secrets are only injected when a signing certificate is configured, generated release branches can be safely retried, and draft releases no longer open/auto-merge the version sync PR.

Why it's needed

The failed run showed two concrete CI issues: Windows ran bun run bump-desktop-version "$RELEASE_VERSION" under PowerShell, so the script received no version argument, and macOS unsigned builds still entered electron-builder's signing path because empty signing variables were present. The failed non-dry-run also left release/desktop-v0.0.2 behind, so rerunning the same release needs to update the generated branch instead of failing on branch creation.

Reviewer Test Plan

How to verify

Re-run the Desktop Release workflow for version 0.0.2. A dry run should build installers only. A non-dry-run from main should push or update release/desktop-v0.0.2, build macOS/Windows/Linux installers, publish the release assets, and only create the version sync PR when Draft is unchecked.

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 failed in Build Windows because Release version is required, and failed in Build macOS with electron-builder signing output ending in /Users/runner/work/openwork/openwork/apps/electron not a file.

After: Local workflow validation passed with actionlint, YAML parsing, git diff --check, and an isolated temp-worktree version bump/check for 0.0.2.

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

Local macOS shell in /Users/dragon/Documents/openwork; GitHub Actions logs inspected with gh.

Risk & Scope

  • Main risk or tradeoff: unsigned macOS CI builds now explicitly disable certificate auto-discovery unless CSC_LINK is configured, so signed releases depend on the signing secrets being present.
  • Not validated / out of scope: a full hosted rerun of the Desktop Release workflow has not completed yet from this PR branch.
  • Breaking changes / migration notes: Draft releases intentionally do not sync package versions back to main; run the workflow with Draft unchecked for the final public release.

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

中文说明

What this PR does

这个 PR 修复 desktop release workflow,让第一次 0.0.2 发版失败之后可以正常重跑。build matrix 现在统一用 bash 做 shell 展开,签名 secret 只有在配置了签名证书时才注入,自动生成的 release 分支可以安全重试更新,并且 draft release 不再创建或自动合并版本同步 PR。

Why it's needed

失败日志里有两个明确问题:Windows 在 PowerShell 下执行 bun run bump-desktop-version "$RELEASE_VERSION",导致脚本没有收到版本号;macOS unsigned build 因为空签名变量存在,仍然进入 electron-builder 的签名逻辑,最后报 /Users/runner/work/openwork/openwork/apps/electron not a file。这次非 dry-run 失败还留下了 release/desktop-v0.0.2 分支,所以同版本重跑需要更新这个生成分支,而不是卡在创建分支上。

Reviewer Test Plan

How to verify

重新运行 Desktop Release workflow,版本填 0.0.2。dry run 应该只构建安装包;从 main 执行非 dry-run 应该 push 或更新 release/desktop-v0.0.2,构建 macOS/Windows/Linux 安装包,发布 release assets,并且只有在 Draft 取消勾选时才创建版本同步 PR。

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 里 Build Windows 因为 Release version is required 失败,Build macOS 在 electron-builder 签名阶段输出 /Users/runner/work/openwork/openwork/apps/electron not a file 后失败。

After: 本地已通过 actionlint、YAML 解析、git diff --check,并在临时 git worktree 中验证了 0.0.2 的实际 bump 再 check 链路。

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

本地 macOS shell,目录 /Users/dragon/Documents/openwork;失败日志通过 gh 查看。

Risk & Scope

  • Main risk or tradeoff: macOS CI unsigned build 现在会在没有 CSC_LINK 时显式关闭证书自动发现,所以真正签名发版依赖签名 secrets 已配置完整。
  • Not validated / out of scope: 还没有从这个 PR 分支完整跑完一次托管 Desktop Release workflow。
  • Breaking changes / migration notes: Draft release 会刻意不把版本号同步回 main;最终公开发版时需要在 workflow 里取消勾选 Draft。

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

@DragonnZhang
DragonnZhang merged commit 9ae224a into mainJun 8, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@DragonnZhang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[codex] Fix desktop release workflow CI - #6

Merged
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci
Jun 8, 2026
Merged

[codex] Fix desktop release workflow CI#6
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci

Conversation

@DragonnZhang

Copy link
Copy Markdown
Member

What this PR does

Fixes the desktop release workflow so the cross-platform build jobs can rerun successfully after the initial 0.0.2 release attempt failed. The build matrix now uses bash consistently for shell expansion, signing secrets are only injected when a signing certificate is configured, generated release branches can be safely retried, and draft releases no longer open/auto-merge the version sync PR.

Why it's needed

The failed run showed two concrete CI issues: Windows ran bun run bump-desktop-version "$RELEASE_VERSION" under PowerShell, so the script received no version argument, and macOS unsigned builds still entered electron-builder's signing path because empty signing variables were present. The failed non-dry-run also left release/desktop-v0.0.2 behind, so rerunning the same release needs to update the generated branch instead of failing on branch creation.

Reviewer Test Plan

How to verify

Re-run the Desktop Release workflow for version 0.0.2. A dry run should build installers only. A non-dry-run from main should push or update release/desktop-v0.0.2, build macOS/Windows/Linux installers, publish the release assets, and only create the version sync PR when Draft is unchecked.

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 failed in Build Windows because Release version is required, and failed in Build macOS with electron-builder signing output ending in /Users/runner/work/openwork/openwork/apps/electron not a file.

After: Local workflow validation passed with actionlint, YAML parsing, git diff --check, and an isolated temp-worktree version bump/check for 0.0.2.

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

Local macOS shell in /Users/dragon/Documents/openwork; GitHub Actions logs inspected with gh.

Risk & Scope

  • Main risk or tradeoff: unsigned macOS CI builds now explicitly disable certificate auto-discovery unless CSC_LINK is configured, so signed releases depend on the signing secrets being present.
  • Not validated / out of scope: a full hosted rerun of the Desktop Release workflow has not completed yet from this PR branch.
  • Breaking changes / migration notes: Draft releases intentionally do not sync package versions back to main; run the workflow with Draft unchecked for the final public release.

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

中文说明

What this PR does

这个 PR 修复 desktop release workflow,让第一次 0.0.2 发版失败之后可以正常重跑。build matrix 现在统一用 bash 做 shell 展开,签名 secret 只有在配置了签名证书时才注入,自动生成的 release 分支可以安全重试更新,并且 draft release 不再创建或自动合并版本同步 PR。

Why it's needed

失败日志里有两个明确问题:Windows 在 PowerShell 下执行 bun run bump-desktop-version "$RELEASE_VERSION",导致脚本没有收到版本号;macOS unsigned build 因为空签名变量存在,仍然进入 electron-builder 的签名逻辑,最后报 /Users/runner/work/openwork/openwork/apps/electron not a file。这次非 dry-run 失败还留下了 release/desktop-v0.0.2 分支,所以同版本重跑需要更新这个生成分支,而不是卡在创建分支上。

Reviewer Test Plan

How to verify

重新运行 Desktop Release workflow,版本填 0.0.2。dry run 应该只构建安装包;从 main 执行非 dry-run 应该 push 或更新 release/desktop-v0.0.2,构建 macOS/Windows/Linux 安装包,发布 release assets,并且只有在 Draft 取消勾选时才创建版本同步 PR。

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 里 Build Windows 因为 Release version is required 失败,Build macOS 在 electron-builder 签名阶段输出 /Users/runner/work/openwork/openwork/apps/electron not a file 后失败。

After: 本地已通过 actionlint、YAML 解析、git diff --check,并在临时 git worktree 中验证了 0.0.2 的实际 bump 再 check 链路。

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

本地 macOS shell,目录 /Users/dragon/Documents/openwork;失败日志通过 gh 查看。

Risk & Scope

  • Main risk or tradeoff: macOS CI unsigned build 现在会在没有 CSC_LINK 时显式关闭证书自动发现,所以真正签名发版依赖签名 secrets 已配置完整。
  • Not validated / out of scope: 还没有从这个 PR 分支完整跑完一次托管 Desktop Release workflow。
  • Breaking changes / migration notes: Draft release 会刻意不把版本号同步回 main;最终公开发版时需要在 workflow 里取消勾选 Draft。

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

@DragonnZhang
DragonnZhang merged commit 9ae224a into mainJun 8, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@DragonnZhang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[codex] Fix desktop release workflow CI - #6

Merged
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci
Jun 8, 2026
Merged

[codex] Fix desktop release workflow CI#6
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci

Conversation

@DragonnZhang

Copy link
Copy Markdown
Member

What this PR does

Fixes the desktop release workflow so the cross-platform build jobs can rerun successfully after the initial 0.0.2 release attempt failed. The build matrix now uses bash consistently for shell expansion, signing secrets are only injected when a signing certificate is configured, generated release branches can be safely retried, and draft releases no longer open/auto-merge the version sync PR.

Why it's needed

The failed run showed two concrete CI issues: Windows ran bun run bump-desktop-version "$RELEASE_VERSION" under PowerShell, so the script received no version argument, and macOS unsigned builds still entered electron-builder's signing path because empty signing variables were present. The failed non-dry-run also left release/desktop-v0.0.2 behind, so rerunning the same release needs to update the generated branch instead of failing on branch creation.

Reviewer Test Plan

How to verify

Re-run the Desktop Release workflow for version 0.0.2. A dry run should build installers only. A non-dry-run from main should push or update release/desktop-v0.0.2, build macOS/Windows/Linux installers, publish the release assets, and only create the version sync PR when Draft is unchecked.

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 failed in Build Windows because Release version is required, and failed in Build macOS with electron-builder signing output ending in /Users/runner/work/openwork/openwork/apps/electron not a file.

After: Local workflow validation passed with actionlint, YAML parsing, git diff --check, and an isolated temp-worktree version bump/check for 0.0.2.

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

Local macOS shell in /Users/dragon/Documents/openwork; GitHub Actions logs inspected with gh.

Risk & Scope

  • Main risk or tradeoff: unsigned macOS CI builds now explicitly disable certificate auto-discovery unless CSC_LINK is configured, so signed releases depend on the signing secrets being present.
  • Not validated / out of scope: a full hosted rerun of the Desktop Release workflow has not completed yet from this PR branch.
  • Breaking changes / migration notes: Draft releases intentionally do not sync package versions back to main; run the workflow with Draft unchecked for the final public release.

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

中文说明

What this PR does

这个 PR 修复 desktop release workflow,让第一次 0.0.2 发版失败之后可以正常重跑。build matrix 现在统一用 bash 做 shell 展开,签名 secret 只有在配置了签名证书时才注入,自动生成的 release 分支可以安全重试更新,并且 draft release 不再创建或自动合并版本同步 PR。

Why it's needed

失败日志里有两个明确问题:Windows 在 PowerShell 下执行 bun run bump-desktop-version "$RELEASE_VERSION",导致脚本没有收到版本号;macOS unsigned build 因为空签名变量存在,仍然进入 electron-builder 的签名逻辑,最后报 /Users/runner/work/openwork/openwork/apps/electron not a file。这次非 dry-run 失败还留下了 release/desktop-v0.0.2 分支,所以同版本重跑需要更新这个生成分支,而不是卡在创建分支上。

Reviewer Test Plan

How to verify

重新运行 Desktop Release workflow,版本填 0.0.2。dry run 应该只构建安装包;从 main 执行非 dry-run 应该 push 或更新 release/desktop-v0.0.2,构建 macOS/Windows/Linux 安装包,发布 release assets,并且只有在 Draft 取消勾选时才创建版本同步 PR。

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 里 Build Windows 因为 Release version is required 失败,Build macOS 在 electron-builder 签名阶段输出 /Users/runner/work/openwork/openwork/apps/electron not a file 后失败。

After: 本地已通过 actionlint、YAML 解析、git diff --check,并在临时 git worktree 中验证了 0.0.2 的实际 bump 再 check 链路。

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

本地 macOS shell,目录 /Users/dragon/Documents/openwork;失败日志通过 gh 查看。

Risk & Scope

  • Main risk or tradeoff: macOS CI unsigned build 现在会在没有 CSC_LINK 时显式关闭证书自动发现,所以真正签名发版依赖签名 secrets 已配置完整。
  • Not validated / out of scope: 还没有从这个 PR 分支完整跑完一次托管 Desktop Release workflow。
  • Breaking changes / migration notes: Draft release 会刻意不把版本号同步回 main;最终公开发版时需要在 workflow 里取消勾选 Draft。

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

@DragonnZhang
DragonnZhang merged commit 9ae224a into mainJun 8, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@DragonnZhang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[codex] Fix desktop release workflow CI - #6

Merged
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci
Jun 8, 2026
Merged

[codex] Fix desktop release workflow CI#6
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci

Conversation

@DragonnZhang

Copy link
Copy Markdown
Member

What this PR does

Fixes the desktop release workflow so the cross-platform build jobs can rerun successfully after the initial 0.0.2 release attempt failed. The build matrix now uses bash consistently for shell expansion, signing secrets are only injected when a signing certificate is configured, generated release branches can be safely retried, and draft releases no longer open/auto-merge the version sync PR.

Why it's needed

The failed run showed two concrete CI issues: Windows ran bun run bump-desktop-version "$RELEASE_VERSION" under PowerShell, so the script received no version argument, and macOS unsigned builds still entered electron-builder's signing path because empty signing variables were present. The failed non-dry-run also left release/desktop-v0.0.2 behind, so rerunning the same release needs to update the generated branch instead of failing on branch creation.

Reviewer Test Plan

How to verify

Re-run the Desktop Release workflow for version 0.0.2. A dry run should build installers only. A non-dry-run from main should push or update release/desktop-v0.0.2, build macOS/Windows/Linux installers, publish the release assets, and only create the version sync PR when Draft is unchecked.

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 failed in Build Windows because Release version is required, and failed in Build macOS with electron-builder signing output ending in /Users/runner/work/openwork/openwork/apps/electron not a file.

After: Local workflow validation passed with actionlint, YAML parsing, git diff --check, and an isolated temp-worktree version bump/check for 0.0.2.

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

Local macOS shell in /Users/dragon/Documents/openwork; GitHub Actions logs inspected with gh.

Risk & Scope

  • Main risk or tradeoff: unsigned macOS CI builds now explicitly disable certificate auto-discovery unless CSC_LINK is configured, so signed releases depend on the signing secrets being present.
  • Not validated / out of scope: a full hosted rerun of the Desktop Release workflow has not completed yet from this PR branch.
  • Breaking changes / migration notes: Draft releases intentionally do not sync package versions back to main; run the workflow with Draft unchecked for the final public release.

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

中文说明

What this PR does

这个 PR 修复 desktop release workflow,让第一次 0.0.2 发版失败之后可以正常重跑。build matrix 现在统一用 bash 做 shell 展开,签名 secret 只有在配置了签名证书时才注入,自动生成的 release 分支可以安全重试更新,并且 draft release 不再创建或自动合并版本同步 PR。

Why it's needed

失败日志里有两个明确问题:Windows 在 PowerShell 下执行 bun run bump-desktop-version "$RELEASE_VERSION",导致脚本没有收到版本号;macOS unsigned build 因为空签名变量存在,仍然进入 electron-builder 的签名逻辑,最后报 /Users/runner/work/openwork/openwork/apps/electron not a file。这次非 dry-run 失败还留下了 release/desktop-v0.0.2 分支,所以同版本重跑需要更新这个生成分支,而不是卡在创建分支上。

Reviewer Test Plan

How to verify

重新运行 Desktop Release workflow,版本填 0.0.2。dry run 应该只构建安装包;从 main 执行非 dry-run 应该 push 或更新 release/desktop-v0.0.2,构建 macOS/Windows/Linux 安装包,发布 release assets,并且只有在 Draft 取消勾选时才创建版本同步 PR。

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 里 Build Windows 因为 Release version is required 失败,Build macOS 在 electron-builder 签名阶段输出 /Users/runner/work/openwork/openwork/apps/electron not a file 后失败。

After: 本地已通过 actionlint、YAML 解析、git diff --check,并在临时 git worktree 中验证了 0.0.2 的实际 bump 再 check 链路。

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

本地 macOS shell,目录 /Users/dragon/Documents/openwork;失败日志通过 gh 查看。

Risk & Scope

  • Main risk or tradeoff: macOS CI unsigned build 现在会在没有 CSC_LINK 时显式关闭证书自动发现,所以真正签名发版依赖签名 secrets 已配置完整。
  • Not validated / out of scope: 还没有从这个 PR 分支完整跑完一次托管 Desktop Release workflow。
  • Breaking changes / migration notes: Draft release 会刻意不把版本号同步回 main;最终公开发版时需要在 workflow 里取消勾选 Draft。

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

@DragonnZhang
DragonnZhang merged commit 9ae224a into mainJun 8, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@DragonnZhang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[codex] Fix desktop release workflow CI - #6

Merged
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci
Jun 8, 2026
Merged

[codex] Fix desktop release workflow CI#6
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci

Conversation

@DragonnZhang

Copy link
Copy Markdown
Member

What this PR does

Fixes the desktop release workflow so the cross-platform build jobs can rerun successfully after the initial 0.0.2 release attempt failed. The build matrix now uses bash consistently for shell expansion, signing secrets are only injected when a signing certificate is configured, generated release branches can be safely retried, and draft releases no longer open/auto-merge the version sync PR.

Why it's needed

The failed run showed two concrete CI issues: Windows ran bun run bump-desktop-version "$RELEASE_VERSION" under PowerShell, so the script received no version argument, and macOS unsigned builds still entered electron-builder's signing path because empty signing variables were present. The failed non-dry-run also left release/desktop-v0.0.2 behind, so rerunning the same release needs to update the generated branch instead of failing on branch creation.

Reviewer Test Plan

How to verify

Re-run the Desktop Release workflow for version 0.0.2. A dry run should build installers only. A non-dry-run from main should push or update release/desktop-v0.0.2, build macOS/Windows/Linux installers, publish the release assets, and only create the version sync PR when Draft is unchecked.

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 failed in Build Windows because Release version is required, and failed in Build macOS with electron-builder signing output ending in /Users/runner/work/openwork/openwork/apps/electron not a file.

After: Local workflow validation passed with actionlint, YAML parsing, git diff --check, and an isolated temp-worktree version bump/check for 0.0.2.

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

Local macOS shell in /Users/dragon/Documents/openwork; GitHub Actions logs inspected with gh.

Risk & Scope

  • Main risk or tradeoff: unsigned macOS CI builds now explicitly disable certificate auto-discovery unless CSC_LINK is configured, so signed releases depend on the signing secrets being present.
  • Not validated / out of scope: a full hosted rerun of the Desktop Release workflow has not completed yet from this PR branch.
  • Breaking changes / migration notes: Draft releases intentionally do not sync package versions back to main; run the workflow with Draft unchecked for the final public release.

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

中文说明

What this PR does

这个 PR 修复 desktop release workflow,让第一次 0.0.2 发版失败之后可以正常重跑。build matrix 现在统一用 bash 做 shell 展开,签名 secret 只有在配置了签名证书时才注入,自动生成的 release 分支可以安全重试更新,并且 draft release 不再创建或自动合并版本同步 PR。

Why it's needed

失败日志里有两个明确问题:Windows 在 PowerShell 下执行 bun run bump-desktop-version "$RELEASE_VERSION",导致脚本没有收到版本号;macOS unsigned build 因为空签名变量存在,仍然进入 electron-builder 的签名逻辑,最后报 /Users/runner/work/openwork/openwork/apps/electron not a file。这次非 dry-run 失败还留下了 release/desktop-v0.0.2 分支,所以同版本重跑需要更新这个生成分支,而不是卡在创建分支上。

Reviewer Test Plan

How to verify

重新运行 Desktop Release workflow,版本填 0.0.2。dry run 应该只构建安装包;从 main 执行非 dry-run 应该 push 或更新 release/desktop-v0.0.2,构建 macOS/Windows/Linux 安装包,发布 release assets,并且只有在 Draft 取消勾选时才创建版本同步 PR。

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 里 Build Windows 因为 Release version is required 失败,Build macOS 在 electron-builder 签名阶段输出 /Users/runner/work/openwork/openwork/apps/electron not a file 后失败。

After: 本地已通过 actionlint、YAML 解析、git diff --check,并在临时 git worktree 中验证了 0.0.2 的实际 bump 再 check 链路。

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

本地 macOS shell,目录 /Users/dragon/Documents/openwork;失败日志通过 gh 查看。

Risk & Scope

  • Main risk or tradeoff: macOS CI unsigned build 现在会在没有 CSC_LINK 时显式关闭证书自动发现,所以真正签名发版依赖签名 secrets 已配置完整。
  • Not validated / out of scope: 还没有从这个 PR 分支完整跑完一次托管 Desktop Release workflow。
  • Breaking changes / migration notes: Draft release 会刻意不把版本号同步回 main;最终公开发版时需要在 workflow 里取消勾选 Draft。

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

@DragonnZhang
DragonnZhang merged commit 9ae224a into mainJun 8, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@DragonnZhang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[codex] Fix desktop release workflow CI - #6

Merged
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci
Jun 8, 2026
Merged

[codex] Fix desktop release workflow CI#6
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci

Conversation

@DragonnZhang

Copy link
Copy Markdown
Member

What this PR does

Fixes the desktop release workflow so the cross-platform build jobs can rerun successfully after the initial 0.0.2 release attempt failed. The build matrix now uses bash consistently for shell expansion, signing secrets are only injected when a signing certificate is configured, generated release branches can be safely retried, and draft releases no longer open/auto-merge the version sync PR.

Why it's needed

The failed run showed two concrete CI issues: Windows ran bun run bump-desktop-version "$RELEASE_VERSION" under PowerShell, so the script received no version argument, and macOS unsigned builds still entered electron-builder's signing path because empty signing variables were present. The failed non-dry-run also left release/desktop-v0.0.2 behind, so rerunning the same release needs to update the generated branch instead of failing on branch creation.

Reviewer Test Plan

How to verify

Re-run the Desktop Release workflow for version 0.0.2. A dry run should build installers only. A non-dry-run from main should push or update release/desktop-v0.0.2, build macOS/Windows/Linux installers, publish the release assets, and only create the version sync PR when Draft is unchecked.

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 failed in Build Windows because Release version is required, and failed in Build macOS with electron-builder signing output ending in /Users/runner/work/openwork/openwork/apps/electron not a file.

After: Local workflow validation passed with actionlint, YAML parsing, git diff --check, and an isolated temp-worktree version bump/check for 0.0.2.

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

Local macOS shell in /Users/dragon/Documents/openwork; GitHub Actions logs inspected with gh.

Risk & Scope

  • Main risk or tradeoff: unsigned macOS CI builds now explicitly disable certificate auto-discovery unless CSC_LINK is configured, so signed releases depend on the signing secrets being present.
  • Not validated / out of scope: a full hosted rerun of the Desktop Release workflow has not completed yet from this PR branch.
  • Breaking changes / migration notes: Draft releases intentionally do not sync package versions back to main; run the workflow with Draft unchecked for the final public release.

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

中文说明

What this PR does

这个 PR 修复 desktop release workflow,让第一次 0.0.2 发版失败之后可以正常重跑。build matrix 现在统一用 bash 做 shell 展开,签名 secret 只有在配置了签名证书时才注入,自动生成的 release 分支可以安全重试更新,并且 draft release 不再创建或自动合并版本同步 PR。

Why it's needed

失败日志里有两个明确问题:Windows 在 PowerShell 下执行 bun run bump-desktop-version "$RELEASE_VERSION",导致脚本没有收到版本号;macOS unsigned build 因为空签名变量存在,仍然进入 electron-builder 的签名逻辑,最后报 /Users/runner/work/openwork/openwork/apps/electron not a file。这次非 dry-run 失败还留下了 release/desktop-v0.0.2 分支,所以同版本重跑需要更新这个生成分支,而不是卡在创建分支上。

Reviewer Test Plan

How to verify

重新运行 Desktop Release workflow,版本填 0.0.2。dry run 应该只构建安装包;从 main 执行非 dry-run 应该 push 或更新 release/desktop-v0.0.2,构建 macOS/Windows/Linux 安装包,发布 release assets,并且只有在 Draft 取消勾选时才创建版本同步 PR。

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 里 Build Windows 因为 Release version is required 失败,Build macOS 在 electron-builder 签名阶段输出 /Users/runner/work/openwork/openwork/apps/electron not a file 后失败。

After: 本地已通过 actionlint、YAML 解析、git diff --check,并在临时 git worktree 中验证了 0.0.2 的实际 bump 再 check 链路。

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

本地 macOS shell,目录 /Users/dragon/Documents/openwork;失败日志通过 gh 查看。

Risk & Scope

  • Main risk or tradeoff: macOS CI unsigned build 现在会在没有 CSC_LINK 时显式关闭证书自动发现,所以真正签名发版依赖签名 secrets 已配置完整。
  • Not validated / out of scope: 还没有从这个 PR 分支完整跑完一次托管 Desktop Release workflow。
  • Breaking changes / migration notes: Draft release 会刻意不把版本号同步回 main;最终公开发版时需要在 workflow 里取消勾选 Draft。

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

@DragonnZhang
DragonnZhang merged commit 9ae224a into mainJun 8, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@DragonnZhang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[codex] Fix desktop release workflow CI - #6

Merged
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci
Jun 8, 2026
Merged

[codex] Fix desktop release workflow CI#6
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci

Conversation

@DragonnZhang

Copy link
Copy Markdown
Member

What this PR does

Fixes the desktop release workflow so the cross-platform build jobs can rerun successfully after the initial 0.0.2 release attempt failed. The build matrix now uses bash consistently for shell expansion, signing secrets are only injected when a signing certificate is configured, generated release branches can be safely retried, and draft releases no longer open/auto-merge the version sync PR.

Why it's needed

The failed run showed two concrete CI issues: Windows ran bun run bump-desktop-version "$RELEASE_VERSION" under PowerShell, so the script received no version argument, and macOS unsigned builds still entered electron-builder's signing path because empty signing variables were present. The failed non-dry-run also left release/desktop-v0.0.2 behind, so rerunning the same release needs to update the generated branch instead of failing on branch creation.

Reviewer Test Plan

How to verify

Re-run the Desktop Release workflow for version 0.0.2. A dry run should build installers only. A non-dry-run from main should push or update release/desktop-v0.0.2, build macOS/Windows/Linux installers, publish the release assets, and only create the version sync PR when Draft is unchecked.

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 failed in Build Windows because Release version is required, and failed in Build macOS with electron-builder signing output ending in /Users/runner/work/openwork/openwork/apps/electron not a file.

After: Local workflow validation passed with actionlint, YAML parsing, git diff --check, and an isolated temp-worktree version bump/check for 0.0.2.

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

Local macOS shell in /Users/dragon/Documents/openwork; GitHub Actions logs inspected with gh.

Risk & Scope

  • Main risk or tradeoff: unsigned macOS CI builds now explicitly disable certificate auto-discovery unless CSC_LINK is configured, so signed releases depend on the signing secrets being present.
  • Not validated / out of scope: a full hosted rerun of the Desktop Release workflow has not completed yet from this PR branch.
  • Breaking changes / migration notes: Draft releases intentionally do not sync package versions back to main; run the workflow with Draft unchecked for the final public release.

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

中文说明

What this PR does

这个 PR 修复 desktop release workflow,让第一次 0.0.2 发版失败之后可以正常重跑。build matrix 现在统一用 bash 做 shell 展开,签名 secret 只有在配置了签名证书时才注入,自动生成的 release 分支可以安全重试更新,并且 draft release 不再创建或自动合并版本同步 PR。

Why it's needed

失败日志里有两个明确问题:Windows 在 PowerShell 下执行 bun run bump-desktop-version "$RELEASE_VERSION",导致脚本没有收到版本号;macOS unsigned build 因为空签名变量存在,仍然进入 electron-builder 的签名逻辑,最后报 /Users/runner/work/openwork/openwork/apps/electron not a file。这次非 dry-run 失败还留下了 release/desktop-v0.0.2 分支,所以同版本重跑需要更新这个生成分支,而不是卡在创建分支上。

Reviewer Test Plan

How to verify

重新运行 Desktop Release workflow,版本填 0.0.2。dry run 应该只构建安装包;从 main 执行非 dry-run 应该 push 或更新 release/desktop-v0.0.2,构建 macOS/Windows/Linux 安装包,发布 release assets,并且只有在 Draft 取消勾选时才创建版本同步 PR。

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 里 Build Windows 因为 Release version is required 失败,Build macOS 在 electron-builder 签名阶段输出 /Users/runner/work/openwork/openwork/apps/electron not a file 后失败。

After: 本地已通过 actionlint、YAML 解析、git diff --check,并在临时 git worktree 中验证了 0.0.2 的实际 bump 再 check 链路。

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

本地 macOS shell,目录 /Users/dragon/Documents/openwork;失败日志通过 gh 查看。

Risk & Scope

  • Main risk or tradeoff: macOS CI unsigned build 现在会在没有 CSC_LINK 时显式关闭证书自动发现,所以真正签名发版依赖签名 secrets 已配置完整。
  • Not validated / out of scope: 还没有从这个 PR 分支完整跑完一次托管 Desktop Release workflow。
  • Breaking changes / migration notes: Draft release 会刻意不把版本号同步回 main;最终公开发版时需要在 workflow 里取消勾选 Draft。

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

@DragonnZhang
DragonnZhang merged commit 9ae224a into mainJun 8, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@DragonnZhang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[codex] Fix desktop release workflow CI - #6

Merged
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci
Jun 8, 2026
Merged

[codex] Fix desktop release workflow CI#6
DragonnZhang merged 1 commit into
mainfrom
dragon/fix-desktop-release-ci

Conversation

@DragonnZhang

Copy link
Copy Markdown
Member

What this PR does

Fixes the desktop release workflow so the cross-platform build jobs can rerun successfully after the initial 0.0.2 release attempt failed. The build matrix now uses bash consistently for shell expansion, signing secrets are only injected when a signing certificate is configured, generated release branches can be safely retried, and draft releases no longer open/auto-merge the version sync PR.

Why it's needed

The failed run showed two concrete CI issues: Windows ran bun run bump-desktop-version "$RELEASE_VERSION" under PowerShell, so the script received no version argument, and macOS unsigned builds still entered electron-builder's signing path because empty signing variables were present. The failed non-dry-run also left release/desktop-v0.0.2 behind, so rerunning the same release needs to update the generated branch instead of failing on branch creation.

Reviewer Test Plan

How to verify

Re-run the Desktop Release workflow for version 0.0.2. A dry run should build installers only. A non-dry-run from main should push or update release/desktop-v0.0.2, build macOS/Windows/Linux installers, publish the release assets, and only create the version sync PR when Draft is unchecked.

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 failed in Build Windows because Release version is required, and failed in Build macOS with electron-builder signing output ending in /Users/runner/work/openwork/openwork/apps/electron not a file.

After: Local workflow validation passed with actionlint, YAML parsing, git diff --check, and an isolated temp-worktree version bump/check for 0.0.2.

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

Local macOS shell in /Users/dragon/Documents/openwork; GitHub Actions logs inspected with gh.

Risk & Scope

  • Main risk or tradeoff: unsigned macOS CI builds now explicitly disable certificate auto-discovery unless CSC_LINK is configured, so signed releases depend on the signing secrets being present.
  • Not validated / out of scope: a full hosted rerun of the Desktop Release workflow has not completed yet from this PR branch.
  • Breaking changes / migration notes: Draft releases intentionally do not sync package versions back to main; run the workflow with Draft unchecked for the final public release.

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

中文说明

What this PR does

这个 PR 修复 desktop release workflow,让第一次 0.0.2 发版失败之后可以正常重跑。build matrix 现在统一用 bash 做 shell 展开,签名 secret 只有在配置了签名证书时才注入,自动生成的 release 分支可以安全重试更新,并且 draft release 不再创建或自动合并版本同步 PR。

Why it's needed

失败日志里有两个明确问题:Windows 在 PowerShell 下执行 bun run bump-desktop-version "$RELEASE_VERSION",导致脚本没有收到版本号;macOS unsigned build 因为空签名变量存在,仍然进入 electron-builder 的签名逻辑,最后报 /Users/runner/work/openwork/openwork/apps/electron not a file。这次非 dry-run 失败还留下了 release/desktop-v0.0.2 分支,所以同版本重跑需要更新这个生成分支,而不是卡在创建分支上。

Reviewer Test Plan

How to verify

重新运行 Desktop Release workflow,版本填 0.0.2。dry run 应该只构建安装包;从 main 执行非 dry-run 应该 push 或更新 release/desktop-v0.0.2,构建 macOS/Windows/Linux 安装包,发布 release assets,并且只有在 Draft 取消勾选时才创建版本同步 PR。

Evidence (Before & After)

Before: GitHub Actions run https://github.com/modelstudioai/openwork/actions/runs/27129329184 里 Build Windows 因为 Release version is required 失败,Build macOS 在 electron-builder 签名阶段输出 /Users/runner/work/openwork/openwork/apps/electron not a file 后失败。

After: 本地已通过 actionlint、YAML 解析、git diff --check,并在临时 git worktree 中验证了 0.0.2 的实际 bump 再 check 链路。

Tested on

OSStatus
🍏 macOS✅ tested
🪟 Windows⚠️ not tested locally
🐧 Linux⚠️ not tested locally

Environment (optional)

本地 macOS shell,目录 /Users/dragon/Documents/openwork;失败日志通过 gh 查看。

Risk & Scope

  • Main risk or tradeoff: macOS CI unsigned build 现在会在没有 CSC_LINK 时显式关闭证书自动发现,所以真正签名发版依赖签名 secrets 已配置完整。
  • Not validated / out of scope: 还没有从这个 PR 分支完整跑完一次托管 Desktop Release workflow。
  • Breaking changes / migration notes: Draft release 会刻意不把版本号同步回 main;最终公开发版时需要在 workflow 里取消勾选 Draft。

Linked Issues

References https://github.com/modelstudioai/openwork/actions/runs/27129329184

@DragonnZhang
DragonnZhang merged commit 9ae224a into mainJun 8, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@DragonnZhang