Files
rdgen/.gitea/actions/decrypt-secrets/action.yml
T
naeeo 73ca96fa67 完善 Gitea 工作流并修复移动端导航与列表按钮图标
前端:
- 「我的构建」列表「查看详情/查看进度」按钮补充与其他按钮同风格的眼睛小图标
- 顶部导航增加 768px 以下移动端适配: 顶栏纵向排列, 导航单行横向滑动, 修复手机端错位

Gitea Actions 工作流 (仅 .gitea, 不动 .github):
- 5 个生成器工作流全部补充 /updategh 终态状态回调 (成功/取消/失败均回调),
  修复无回调导致构建 6 小时后被误判为超时的 P0 缺陷
- Windows 两个工作流 job 级默认 shell 设为 pwsh, 兼容 act 在 Windows 默认 bash
- 修复 VCPKG_BINARY_SOURCES 中 \v 的 YAML 非法转义 (双引号改单引号)
- Flutter 补丁路径改为 .rdgen-src/.github/patches/, run-on-arch 容器内用 /workspace 前缀
- run-on-arch githubToken 置空, 避免 Gitea token 拉 ghcr.io 失败
- runs-on 标签对齐现场 runner: ubuntu-22.04 改为 ubuntu-24.04
- run-vcpkg/setup-ndk 钉到 node20 运行时 SHA, 规避 node24 action 不兼容
- decrypt-secrets 的 pip 安装增加三级回退; cleanzip 请求增加超时重试
- 所有产物上传 curl 增加 --fail/超时/重试参数
- macOS 动态定位 *.app 不再硬编码 RustDesk.app, DMG 路径改用 GITHUB_WORKSPACE
- 修复签名条件判断、PowerShell 变量空格等小问题
- setup.md 更新 runner 标签表及 Windows/macOS host 准备要求
2026-09-30 11:40:33 +08:00

53 lines
2.0 KiB
YAML

name: 'Decrypt and Mask Secrets'
description: 'Decrypts a zip and masks the JSON contents as env vars'
inputs:
zip_password:
description: 'Password for the Zip'
required: true
zip_path:
description: 'Path to the encrypted zip'
required: false
default: 'secrets.zip'
runs:
using: "composite"
steps:
- name: install python deps
shell: bash
run: |
# Ubuntu 24.04 enforces PEP 668 (externally-managed-environment) and
# minimal macOS runners ship no pip by default: try the system installer
# first, then a --user install, finally bootstrap pip via ensurepip.
python3 -m pip install --break-system-packages -q pyzipper 2>/dev/null \
|| python3 -m pip install -q --user pyzipper 2>/dev/null \
|| { python3 -m ensurepip --user && python3 -m pip install -q --user pyzipper; }
- name: Decrypt and Mask
shell: python
env:
PYTHONUTF8: "1"
PYTHONIOENCODING: "utf-8"
run: |
import sys
import io
import pyzipper
import json
import os
# Force UTF-8 stdout/stderr so secrets with characters outside
# the runner codepage (CJK, emoji, etc.) do not crash this step
# on Windows runners (default cp1251) with UnicodeEncodeError
sys.stdout = io.TextIOWrapper(sys.stdout.buffer, encoding="utf-8", errors="replace")
sys.stderr = io.TextIOWrapper(sys.stderr.buffer, encoding="utf-8", errors="replace")
with pyzipper.AESZipFile('${{ inputs.zip_path }}') as zf:
zf.setpassword('${{ inputs.zip_password }}'.encode())
with zf.open('secrets.json') as f:
secrets = json.load(f)
with open(os.environ['GITHUB_ENV'], 'a', encoding='utf-8') as env_file:
for key, value in secrets.items():
if value:
print(f"::add-mask::{value}")
env_file.write(f"{key}={value}\n")
print(f"Successfully masked {len(secrets)} secrets.")