ci(release): add tag-triggered signed-release and store-publish workflow #105

Merged
JMR-dev merged 3 commits from feat-release-workflow into main 2026-07-02 04:15:52 +00:00
3 Commits
Author SHA1 Message Date
Jason Ross 2474981c9e Merge branch 'main' into feat-release-workflow 2026-07-01 23:05:29 -05:00
Jason Ross 59e068e326 Merge branch 'main' into feat-release-workflow 2026-07-01 22:54:12 -05:00
JMR-devandClaude Fable 5 0b0f6b7018 ci(release): add tag-triggered signed-release and store-publish workflow
Rewrite the manual-dispatch release.yml into the issue-#19 pipeline:
v* tag push (or dispatch with dry-run/re-release inputs) runs the fast
CI gate, builds bundleRelease + assembleRelease signed from base64
keystore secrets (falling back to *-unsigned artifacts when unset),
generates a Conventional-Commit changelog and SHA-256 checksums, then
creates the GitHub release and fans out to secret-gated Google Play
publish (staged rollout supported), a documented Galaxy Store manual
stub, and an S3-compatible archive under releases/<tag>/. Every
credentialed stage skips with a clear notice while the store accounts
(#16/#17/#18) don't exist yet; no secret lives in the repo and
app/build.gradle.kts is unchanged. docs/release.md documents the
secrets, flows, and per-store manual fallbacks.

Part of #19

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-01 22:01:34 -05:00