Skip to content

Commit

Permalink
Merge pull request #169 from Kiln-AI/windows_signing
Browse files Browse the repository at this point in the history
Create signed windows builds via CI action
  • Loading branch information
scosman authored Feb 9, 2025
2 parents 48c6b3a + 0859b3b commit e02fc9b
Showing 1 changed file with 79 additions and 0 deletions.
79 changes: 79 additions & 0 deletions .github/workflows/windows_release_build.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
name: Build Signed Windows Release

on:
push:

jobs:
build:
runs-on: windows-latest

steps:
- uses: actions/checkout@v4

- name: Install uv
uses: astral-sh/setup-uv@v3
with:
enable-cache: true

# Use 3.12 - 3.13 not working yet (Numpy verion too old)
- uses: actions/setup-python@v5
with:
python-version: 3.12

# Use GH python version (includes TK/TCL)
- name: Set up Python using GH python version
run: uv venv --python 3.12 --python-preference only-system

- name: Install the project
run: uv sync

- name: Build Desktop App
run: uv run bash ./app/desktop/build_desktop_app.sh

- name: Sign internal files with Trusted Signing
uses: azure/[email protected]
with:
azure-tenant-id: ${{ secrets.AZURE_TENANT_ID }}
azure-client-id: ${{ secrets.AZURE_CLIENT_ID }}
azure-client-secret: ${{ secrets.AZURE_CLIENT_SECRET }}
endpoint: https://eus.codesigning.azure.net/
trusted-signing-account-name: Kiln-Steve-Signing
certificate-profile-name: Kiln-AI-Signing
files-folder: ${{ github.workspace }}/app/desktop/build/dist
files-folder-recurse: true
files-folder-filter: exe
# TODO: consider signing dlls as well. But for testing, we don't want to use all our quota.
# files-folder-filter: exe,dll
file-digest: SHA256
timestamp-rfc3161: http://timestamp.acs.microsoft.com
timestamp-digest: SHA256

- name: Build Windows Installer
uses: Minionguyjpro/[email protected]
with:
path: ./app/desktop/WinInnoSetup.iss

- name: Sign Windows Installer exe
uses: azure/[email protected]
with:
azure-tenant-id: ${{ secrets.AZURE_TENANT_ID }}
azure-client-id: ${{ secrets.AZURE_CLIENT_ID }}
azure-client-secret: ${{ secrets.AZURE_CLIENT_SECRET }}
endpoint: https://eus.codesigning.azure.net/
trusted-signing-account-name: Kiln-Steve-Signing
certificate-profile-name: Kiln-AI-Signing
files-folder: ${{ github.workspace }}/app/desktop/Output
files-folder-recurse: true
files-folder-filter: kilnsetup.exe
file-digest: SHA256
timestamp-rfc3161: http://timestamp.acs.microsoft.com
timestamp-digest: SHA256

- name: Copy Windows Installer
run: cp ./app/desktop/Output/kilnsetup.exe ./app/desktop/build/dist/Kiln.Windows.Installer.exe

- name: Upload Build
uses: actions/upload-artifact@v4
with:
name: kiln-desktop-windows-signed-installer
path: ./app/desktop/build/dist/*

0 comments on commit e02fc9b

Please sign in to comment.