diff --git a/.github/workflows/android-production-release.yml b/.github/workflows/android-production-release.yml index 58cc194..503eb3d 100644 --- a/.github/workflows/android-production-release.yml +++ b/.github/workflows/android-production-release.yml @@ -183,6 +183,7 @@ jobs: run: node scripts/verify-android-aab.mjs "${{ steps.aab.outputs.path }}" - name: Create draft GitHub Release + continue-on-error: true id: draft env: AAB_PATH: ${{ steps.aab.outputs.path }} @@ -223,6 +224,7 @@ jobs: run: bundle exec fastlane android production "version_code:${{ inputs.version_code }}" "release_status:${{ inputs.release_status }}" - name: Publish GitHub Release + if: ${{ steps.draft.outcome == 'success' }} env: GH_TOKEN: ${{ github.token }} run: | diff --git a/tests/contracts/android-release.test.ts b/tests/contracts/android-release.test.ts index 21e5069..d7440df 100644 --- a/tests/contracts/android-release.test.ts +++ b/tests/contracts/android-release.test.ts @@ -153,6 +153,15 @@ describe("Android release automation", () => { expect(productionWorkflow).toContain('release_status:${{ inputs.release_status }}'); }); + it("does not let GitHub release permissions block Google Play promotion", () => { + expect(productionWorkflow).toMatch( + /- name: Create draft GitHub Release\n\s+continue-on-error: true/, + ); + expect(productionWorkflow).toContain( + "if: ${{ steps.draft.outcome == 'success' }}", + ); + }); + it("verifies the exact signed bundle before archive, upload, and promotion", () => { expect(verifier).toContain("AAB_EXPECTED_CERT_SHA256"); expect(verifier).toContain("ANDROID_VERSION_CODE");