# Gate every pull request into `main` on lint + unit tests + a debug build, so a # broken build can't reach the deployable branch. Debug builds are auto-signed, # so this gate needs no secrets. The signed *release* APK + Gitea release come # later (release.yml, M6). See docs/android/PLAN.md ยง12. # # Enforcement (one-time, in the Gitea UI): # Repository Settings -> Branches -> Branch Protection (rule for `main`) # * Enable Status Check # * Status check patterns: PR Checks / * # # Runner: the org's self-hosted `ubuntu-latest`, on a bare `ubuntu:latest` # container that lacks git/curl/unzip (needed by checkout + sdkmanager) -- so the # first step installs them. (Faster later: switch to a prebuilt Android-SDK # container image so nothing installs per-run.) name: PR Checks on: pull_request: branches: [main] concurrency: group: pr-checks-${{ github.ref }} cancel-in-progress: true jobs: android-build: runs-on: ubuntu-latest steps: # Bare ubuntu:latest is missing the tools checkout + the SDK installer need. - name: Install base tools run: | apt-get update apt-get install -y git curl unzip - uses: actions/checkout@v4 - name: Set up JDK 17 uses: actions/setup-java@v4 with: distribution: temurin java-version: "17" - name: Set up Android SDK uses: android-actions/setup-android@v3 - name: Cache Gradle uses: actions/cache@v4 with: path: | ~/.gradle/caches ~/.gradle/wrapper key: gradle-${{ runner.os }}-${{ hashFiles('**/*.gradle.kts', 'gradle/libs.versions.toml', 'gradle/wrapper/gradle-wrapper.properties') }} restore-keys: | gradle-${{ runner.os }}- - name: Lint, test, assemble debug run: ./gradlew --no-daemon lint test assembleDebug