From d24cb90ed2f599c5df4afb18a8dc6af1e434c24b Mon Sep 17 00:00:00 2001 From: Yun Chan Date: Wed, 6 May 2026 23:13:03 +0900 Subject: [PATCH] =?UTF-8?q?ci:=20build.yml=20+=20release.yml=20=EB=B3=B4?= =?UTF-8?q?=EA=B0=95=20(=EC=84=9C=EB=AA=85=20=EC=98=B5=EC=85=98=20+=20work?= =?UTF-8?q?flow=5Fdispatch)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - build.yml 추가: PR/push 시 솔루션 빌드 + MSIX 산출 검증, 14일 보관 - release.yml: PFX_BASE64 / PFX_PASSWORD secrets 있으면 자동 서명, 없으면 unsigned. workflow_dispatch로 수동 트리거도 가능. - 릴리즈 본문에 인증서 등록 + 사이드로드 가이드 inline 포함. Co-Authored-By: Claude Opus 4.7 (1M context) --- .github/workflows/build.yml | 43 ++++++++++++++++++++++++ .github/workflows/release.yml | 63 +++++++++++++++++++++++++++++------ 2 files changed, 96 insertions(+), 10 deletions(-) create mode 100644 .github/workflows/build.yml diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml new file mode 100644 index 0000000..899fe66 --- /dev/null +++ b/.github/workflows/build.yml @@ -0,0 +1,43 @@ +name: Build + +on: + push: + branches: [master, main] + pull_request: + branches: [master, main] + +permissions: + contents: read + +jobs: + build: + runs-on: windows-latest + + steps: + - uses: actions/checkout@v4 + + - name: Setup .NET + uses: actions/setup-dotnet@v4 + with: + dotnet-version: 9.0.x + + - name: Setup MSBuild + uses: microsoft/setup-msbuild@v2 + + - name: Restore + Build solution + shell: pwsh + run: | + dotnet build EverythingToJpeg.slnx -c Release --nologo + + - name: Build MSIX + shell: pwsh + run: | + ./packaging/GenerateAssets.ps1 + ./packaging/BuildMsix.ps1 -Configuration Release -Platform x64 + + - name: Upload MSIX artifact + uses: actions/upload-artifact@v4 + with: + name: EverythingToJpeg-x64-msix-${{ github.sha }} + path: packaging/dist/EverythingToJpeg-x64.msix + retention-days: 14 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 82f0554..3066cb1 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -5,6 +5,10 @@ on: tags: - 'v*' workflow_dispatch: + inputs: + tag: + description: '릴리즈 태그 (예: v0.1.0)' + required: true permissions: contents: write @@ -24,11 +28,38 @@ jobs: - name: Setup MSBuild uses: microsoft/setup-msbuild@v2 - - name: Build MSIX (unsigned) + - name: Generate placeholder logos shell: pwsh + run: ./packaging/GenerateAssets.ps1 + + - name: Decode PFX (if secret provided) + id: pfx + shell: pwsh + env: + PFX_BASE64: ${{ secrets.PFX_BASE64 }} run: | - ./packaging/GenerateAssets.ps1 - ./packaging/BuildMsix.ps1 -Configuration Release -Platform x64 + if ($env:PFX_BASE64) { + $bytes = [Convert]::FromBase64String($env:PFX_BASE64) + $path = Join-Path $env:RUNNER_TEMP 'cert.pfx' + [IO.File]::WriteAllBytes($path, $bytes) + "pfx_path=$path" >> $env:GITHUB_OUTPUT + Write-Host '✅ PFX 디코딩 완료 — 서명 모드로 빌드' + } else { + Write-Host 'ℹ PFX_BASE64 secret 없음 — unsigned 모드로 빌드' + } + + - name: Build MSIX (signed if PFX, else unsigned) + shell: pwsh + env: + PFX_PASSWORD: ${{ secrets.PFX_PASSWORD }} + run: | + $pfx = '${{ steps.pfx.outputs.pfx_path }}' + if ($pfx) { + $sec = ConvertTo-SecureString -String $env:PFX_PASSWORD -AsPlainText -Force + ./packaging/BuildMsix.ps1 -Configuration Release -Platform x64 -Sign -PfxPath $pfx -PfxPassword $sec + } else { + ./packaging/BuildMsix.ps1 -Configuration Release -Platform x64 + } - name: Upload artifact uses: actions/upload-artifact@v4 @@ -37,19 +68,31 @@ jobs: path: packaging/dist/EverythingToJpeg-x64.msix - name: Create GitHub Release - if: startsWith(github.ref, 'refs/tags/v') + if: startsWith(github.ref, 'refs/tags/v') || github.event_name == 'workflow_dispatch' uses: softprops/action-gh-release@v2 with: + tag_name: ${{ github.event.inputs.tag || github.ref_name }} files: packaging/dist/EverythingToJpeg-x64.msix generate_release_notes: true body: | - ## 설치 방법 + ## EverythingToJpeg - 1. 본 릴리즈에서 `EverythingToJpeg-x64.msix` 와 함께 배포된 PFX 인증서를 받습니다. + 모든 파일을 우클릭 한 번으로 JPEG 로 변환합니다. + + ### 설치 방법 + 1. 아래 `EverythingToJpeg-x64.msix` 다운로드. 2. 관리자 PowerShell: ```powershell - .\Install-EverythingToJpeg.ps1 -PfxPath .\EverythingToJpeg-DevCert.pfx -MsixPath .\EverythingToJpeg-x64.msix - ``` - 3. PNG/HEIC/PDF 등 파일을 우클릭 → "JPEG로 빠른 변환" 또는 "JPEG로 변환…" + # 자체 서명 인증서를 신뢰 저장소에 등록 (PFX 별도 보유 필요) + Import-PfxCertificate -CertStoreLocation Cert:\LocalMachine\TrustedPeople ` + -FilePath .\EverythingToJpeg-DevCert.pfx ` + -Password (ConvertTo-SecureString 'EverythingToJpegDev' -AsPlainText -Force) - > 이 패키지는 자체 서명입니다. 인증서를 `LocalMachine\TrustedPeople`에 신뢰 등록해야 설치됩니다. + # MSIX 사이드로드 + Add-AppxPackage -Path .\EverythingToJpeg-x64.msix -ForceApplicationShutdown + ``` + 3. PNG/HEIC/PDF 등 파일 우클릭 → "JPEG로 빠른 변환" 또는 "JPEG로 변환…" + + > 이 패키지는 자체 서명입니다. 첫 PC 1회만 인증서 등록이 필요합니다. + + ### 변경사항