Files
Amber/.github/workflows/unsigned-release.yml
T
Claude dacb9cc9aa ci: restrict GITHUB_TOKEN permissions to least privilege
Add explicit permissions blocks to all workflows to limit the scope
of the GITHUB_TOKEN rather than relying on the broad default permissions.

- build.yml: contents: read (checkout + artifacts)
- check-offline-permissions.yml: contents: read
- unsigned-release.yml: contents: read
- create-release.yml: contents: write (create release + upload assets)
- crowdin.yml: contents: write + pull-requests: write (push translations, open PRs)

https://claude.ai/code/session_012jEe5WfLkonuFPNZ7q7fKc
2026-03-27 10:38:39 +00:00

51 lines
1.1 KiB
YAML

name: Build All APKs
on:
push:
tags:
- 'v*'
permissions:
contents: read
jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Checkout source
uses: actions/checkout@v4
- name: Set up JDK 21
uses: actions/setup-java@v4
with:
distribution: 'temurin'
java-version: 21
- name: Cache Gradle
uses: actions/cache@v4
with:
path: |
~/.gradle/caches
~/.gradle/wrapper
key: ${{ runner.os }}-gradle-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
restore-keys: |
${{ runner.os }}-gradle-
- name: Grant execute permission to Gradle wrapper
run: chmod +x ./gradlew
- name: Clean project
run: ./gradlew clean
- name: Build AAB and APKs
run: |
./gradlew bundleRelease assembleRelease --stacktrace
- name: Upload all APKs as artifacts
uses: actions/upload-artifact@v4
with:
name: All-APKs-${{ github.ref_name }}
path: app/build/outputs/apk/**/release/*.apk
retention-days: 14