Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trim unsigned #58

Open
wants to merge 4 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,11 @@ Then copy the contents of the `.txt` file to your GH secrets

**Optional:** The private key password for your signing keystore

### `trimUnsigned`

**Optional:** Set to `true` to trim trailing `-unsigned` from the APK name before signing,
to avoid `...-unsigned-signed.apk`.

## ENV: `BUILD_TOOLS_VERSION`

**Optional:** You can manually specify a version of build-tools to use. We use `29.0.3` by default.
Expand Down
3 changes: 3 additions & 0 deletions action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,9 @@ inputs:
keyPassword:
description: 'The password for the key'
required: false
trimUnsigned:
description: 'Whether a trailing -unsigned should be trimmed from APK names - set to "true" to enable'
required: false
outputs:
signedReleaseFile:
description: 'The signed release APK or AAB file, if single'
Expand Down
28 changes: 22 additions & 6 deletions lib/main.js
Original file line number Diff line number Diff line change
Expand Up @@ -48,20 +48,24 @@ function run() {
const alias = core.getInput('alias');
const keyStorePassword = core.getInput('keyStorePassword');
const keyPassword = core.getInput('keyPassword');
console.log(`Preparing to sign key @ ${releaseDir} with signing key`);
const trimUnsignedStr = core.getInput('trimUnsigned');
const trimUnsigned = trimUnsignedStr !== null && trimUnsignedStr === "true";
console.log(`Preparing to sign file(s) @ ${releaseDir} with signing key`);
// 1. Find release files
const releaseFiles = io.findReleaseFiles(releaseDir);
if (releaseFiles !== undefined) {
if (releaseFiles !== undefined && releaseFiles.length !== 0) {
// 3. Now that we have a release files, decode and save the signing key
const signingKey = path_1.default.join(releaseDir, 'signingKey.jks');
fs_1.default.writeFileSync(signingKey, signingKeyBase64, 'base64');
// 4. Now zipalign and sign each one of the the release files
let signedReleaseFiles = [];
let index = 0;
for (let releaseFile of releaseFiles) {
core.debug(`Found release to sign: ${releaseFile.name}`);
const releaseFilePath = path_1.default.join(releaseDir, releaseFile.name);
let signedReleaseFile = '';
if (releaseFile.name.endsWith('.apk')) {
signedReleaseFile = yield signing_1.signApkFile(releaseFilePath, signingKey, alias, keyStorePassword, keyPassword);
signedReleaseFile = yield signing_1.signApkFile(releaseFilePath, trimUnsigned, signingKey, alias, keyStorePassword, keyPassword);
}
else if (releaseFile.name.endsWith('.aab')) {
signedReleaseFile = yield signing_1.signAabFile(releaseFilePath, signingKey, alias, keyStorePassword, keyPassword);
Expand All @@ -70,9 +74,21 @@ function run() {
core.error('No valid release file to sign, abort.');
core.setFailed('No valid release file to sign.');
}
core.debug('Release signed! Setting outputs.');
core.exportVariable("SIGNED_RELEASE_FILE", signedReleaseFile);
core.setOutput('signedReleaseFile', signedReleaseFile);
// Each signed release file is stored in a separate variable + output.
core.exportVariable(`SIGNED_RELEASE_FILE_${index}`, signedReleaseFile);
core.setOutput(`signedReleaseFile${index}`, signedReleaseFile);
signedReleaseFiles.push(signedReleaseFile);
++index;
}
// All signed release files are stored in a merged variable + output.
core.exportVariable(`SIGNED_RELEASE_FILES`, signedReleaseFiles.join(":"));
core.setOutput('signedReleaseFiles', signedReleaseFiles.join(":"));
core.exportVariable(`NOF_SIGNED_RELEASE_FILES`, `${signedReleaseFiles.length}`);
core.setOutput(`nofSignedReleaseFiles`, `${signedReleaseFiles.length}`);
// When there is one and only one signed release file, store it in a specific variable + output.
if (signedReleaseFiles.length == 1) {
core.exportVariable(`SIGNED_RELEASE_FILE`, signedReleaseFiles[0]);
core.setOutput('signedReleaseFile', signedReleaseFiles[0]);
}
console.log('Releases signed!');
}
Expand Down
4 changes: 2 additions & 2 deletions lib/signing.js
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ const core = __importStar(require("@actions/core"));
const io = __importStar(require("@actions/io"));
const path = __importStar(require("path"));
const fs = __importStar(require("fs"));
function signApkFile(apkFile, signingKeyFile, alias, keyStorePassword, keyPassword) {
function signApkFile(apkFile, trimUnsigned, signingKeyFile, alias, keyStorePassword, keyPassword) {
return __awaiter(this, void 0, void 0, function* () {
core.debug("Zipaligning APK file");
// Find zipalign executable
Expand Down Expand Up @@ -62,7 +62,7 @@ function signApkFile(apkFile, signingKeyFile, alias, keyStorePassword, keyPasswo
const apkSigner = path.join(buildTools, 'apksigner');
core.debug(`Found 'apksigner' @ ${apkSigner}`);
// apksigner sign --ks my-release-key.jks --out my-app-release.apk my-app-unsigned-aligned.apk
const signedApkFile = apkFile.replace('.apk', '-signed.apk');
const signedApkFile = (trimUnsigned ? apkFile.replace('-unsigned.apk', '.apk') : apkFile).replace('.apk', '-signed.apk');
const args = [
'sign',
'--ks', signingKeyFile,
Expand Down
8 changes: 5 additions & 3 deletions src/main.ts
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,10 @@ async function run() {
const alias = core.getInput('alias');
const keyStorePassword = core.getInput('keyStorePassword');
const keyPassword = core.getInput('keyPassword');
const trimUnsignedStr = core.getInput('trimUnsigned');
const trimUnsigned = trimUnsignedStr !== null && trimUnsignedStr === "true";

console.log(`Preparing to sign key @ ${releaseDir} with signing key`);
console.log(`Preparing to sign file(s) @ ${releaseDir} with signing key`);

// 1. Find release files
const releaseFiles = io.findReleaseFiles(releaseDir);
Expand All @@ -34,7 +36,7 @@ async function run() {
const releaseFilePath = path.join(releaseDir, releaseFile.name);
let signedReleaseFile = '';
if (releaseFile.name.endsWith('.apk')) {
signedReleaseFile = await signApkFile(releaseFilePath, signingKey, alias, keyStorePassword, keyPassword);
signedReleaseFile = await signApkFile(releaseFilePath, trimUnsigned, signingKey, alias, keyStorePassword, keyPassword);
} else if (releaseFile.name.endsWith('.aab')) {
signedReleaseFile = await signAabFile(releaseFilePath, signingKey, alias, keyStorePassword, keyPassword);
} else {
Expand All @@ -55,7 +57,7 @@ async function run() {
core.exportVariable(`NOF_SIGNED_RELEASE_FILES`, `${signedReleaseFiles.length}`);
core.setOutput(`nofSignedReleaseFiles`, `${signedReleaseFiles.length}`);

// When there is one and only one signed release file, stoire it in a specific variable + output.
// When there is one and only one signed release file, store it in a specific variable + output.
if (signedReleaseFiles.length == 1) {
core.exportVariable(`SIGNED_RELEASE_FILE`, signedReleaseFiles[0]);
core.setOutput('signedReleaseFile', signedReleaseFiles[0]);
Expand Down
7 changes: 4 additions & 3 deletions src/signing.ts
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,11 @@ import * as fs from "fs";

export async function signApkFile(
apkFile: string,
trimUnsigned: boolean,
signingKeyFile: string,
alias: string,
keyStorePassword: string,
keyPassword?: string
keyPassword?: string,
): Promise<string> {

core.debug("Zipaligning APK file");
Expand All @@ -32,7 +33,7 @@ export async function signApkFile(
'-v', '4',
apkFile
]);

await exec.exec(`"cp"`, [
apkFile,
alignedApkFile
Expand All @@ -45,7 +46,7 @@ export async function signApkFile(
core.debug(`Found 'apksigner' @ ${apkSigner}`);

// apksigner sign --ks my-release-key.jks --out my-app-release.apk my-app-unsigned-aligned.apk
const signedApkFile = apkFile.replace('.apk', '-signed.apk');
const signedApkFile = (trimUnsigned ? apkFile.replace('-unsigned.apk', '.apk') : apkFile).replace('.apk', '-signed.apk');
const args = [
'sign',
'--ks', signingKeyFile,
Expand Down