name: Build Native Android on: push: tags: - 'native-v*' workflow_dispatch: inputs: tag: description: '要构建的 native 标签,例如 native-v0.1.0-beta.1' required: true type: string permissions: contents: write jobs: build-android: runs-on: ubuntu-latest defaults: run: working-directory: native steps: - name: Checkout repository uses: actions/checkout@v4 with: ref: ${{ github.event.inputs.tag && format('refs/tags/{0}', github.event.inputs.tag) || github.ref }} - name: Validate native tag shell: bash run: | TAG="${{ github.event.inputs.tag || github.ref_name }}" if [[ ! "$TAG" =~ ^native-v[0-9]+\.[0-9]+\.[0-9]+.*$ ]]; then echo "Invalid tag: $TAG" echo "Tag must look like native-v0.1.0 or native-v0.1.0-beta.1" exit 1 fi - name: Set up Java uses: actions/setup-java@v4 with: distribution: temurin java-version: '17' - name: Set up Flutter uses: subosito/flutter-action@v2 with: channel: stable cache: true - name: Flutter pub get run: flutter pub get - name: Flutter analyze run: flutter analyze - name: Restore Android signing files shell: bash env: ANDROID_KEYSTORE_BASE64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }} ANDROID_STORE_PASSWORD: ${{ secrets.ANDROID_STORE_PASSWORD }} ANDROID_KEY_PASSWORD: ${{ secrets.ANDROID_KEY_PASSWORD }} ANDROID_KEY_ALIAS: ${{ secrets.ANDROID_KEY_ALIAS }} run: | # 任一签名 Secret 为空就直接失败,避免 gradle 静默回退到 debug keystore for name in ANDROID_KEYSTORE_BASE64 ANDROID_STORE_PASSWORD ANDROID_KEY_PASSWORD ANDROID_KEY_ALIAS; do if [ -z "${!name}" ]; then echo "Missing required secret: $name" exit 1 fi done echo "$ANDROID_KEYSTORE_BASE64" | base64 --decode > android/easynode-release.jks cat > android/key.properties <