前端: - 「我的构建」列表「查看详情/查看进度」按钮补充与其他按钮同风格的眼睛小图标 - 顶部导航增加 768px 以下移动端适配: 顶栏纵向排列, 导航单行横向滑动, 修复手机端错位 Gitea Actions 工作流 (仅 .gitea, 不动 .github): - 5 个生成器工作流全部补充 /updategh 终态状态回调 (成功/取消/失败均回调), 修复无回调导致构建 6 小时后被误判为超时的 P0 缺陷 - Windows 两个工作流 job 级默认 shell 设为 pwsh, 兼容 act 在 Windows 默认 bash - 修复 VCPKG_BINARY_SOURCES 中 \v 的 YAML 非法转义 (双引号改单引号) - Flutter 补丁路径改为 .rdgen-src/.github/patches/, run-on-arch 容器内用 /workspace 前缀 - run-on-arch githubToken 置空, 避免 Gitea token 拉 ghcr.io 失败 - runs-on 标签对齐现场 runner: ubuntu-22.04 改为 ubuntu-24.04 - run-vcpkg/setup-ndk 钉到 node20 运行时 SHA, 规避 node24 action 不兼容 - decrypt-secrets 的 pip 安装增加三级回退; cleanzip 请求增加超时重试 - 所有产物上传 curl 增加 --fail/超时/重试参数 - macOS 动态定位 *.app 不再硬编码 RustDesk.app, DMG 路径改用 GITHUB_WORKSPACE - 修复签名条件判断、PowerShell 变量空格等小问题 - setup.md 更新 runner 标签表及 Windows/macOS host 准备要求
53 lines
2.0 KiB
YAML
53 lines
2.0 KiB
YAML
name: 'Decrypt and Mask Secrets'
|
|
description: 'Decrypts a zip and masks the JSON contents as env vars'
|
|
inputs:
|
|
zip_password:
|
|
description: 'Password for the Zip'
|
|
required: true
|
|
zip_path:
|
|
description: 'Path to the encrypted zip'
|
|
required: false
|
|
default: 'secrets.zip'
|
|
|
|
runs:
|
|
using: "composite"
|
|
steps:
|
|
- name: install python deps
|
|
shell: bash
|
|
run: |
|
|
# Ubuntu 24.04 enforces PEP 668 (externally-managed-environment) and
|
|
# minimal macOS runners ship no pip by default: try the system installer
|
|
# first, then a --user install, finally bootstrap pip via ensurepip.
|
|
python3 -m pip install --break-system-packages -q pyzipper 2>/dev/null \
|
|
|| python3 -m pip install -q --user pyzipper 2>/dev/null \
|
|
|| { python3 -m ensurepip --user && python3 -m pip install -q --user pyzipper; }
|
|
- name: Decrypt and Mask
|
|
shell: python
|
|
env:
|
|
PYTHONUTF8: "1"
|
|
PYTHONIOENCODING: "utf-8"
|
|
run: |
|
|
import sys
|
|
import io
|
|
import pyzipper
|
|
import json
|
|
import os
|
|
|
|
# Force UTF-8 stdout/stderr so secrets with characters outside
|
|
# the runner codepage (CJK, emoji, etc.) do not crash this step
|
|
# on Windows runners (default cp1251) with UnicodeEncodeError
|
|
sys.stdout = io.TextIOWrapper(sys.stdout.buffer, encoding="utf-8", errors="replace")
|
|
sys.stderr = io.TextIOWrapper(sys.stderr.buffer, encoding="utf-8", errors="replace")
|
|
|
|
with pyzipper.AESZipFile('${{ inputs.zip_path }}') as zf:
|
|
zf.setpassword('${{ inputs.zip_password }}'.encode())
|
|
with zf.open('secrets.json') as f:
|
|
secrets = json.load(f)
|
|
|
|
with open(os.environ['GITHUB_ENV'], 'a', encoding='utf-8') as env_file:
|
|
for key, value in secrets.items():
|
|
if value:
|
|
print(f"::add-mask::{value}")
|
|
env_file.write(f"{key}={value}\n")
|
|
|
|
print(f"Successfully masked {len(secrets)} secrets.") |