Repository navigation
Expand file tree
/
Copy pathelectron-builder.yml
More file actions
213 lines (199 loc) · 8.38 KB
/
Copy pathelectron-builder.yml
File metadata and controls
213 lines (199 loc) · 8.38 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
appId: com.openmausbot.app
productName: OpenMausBot
artifactName: OpenMausBot-${version}-${arch}.${ext}
protocols:
- name: OpenMausBot package install
schemes: [openmausbot]
# In-app auto-update reads latest-mac.yml + the .zip (macOS) or latest.yml +
# the NSIS .exe (Windows) from the PUBLIC releases in this source repo.
# Public → no token on users' machines. Baked into
# app-update.yml; both metadata files are emitted here even with
# --publish never, and must be uploaded to the GitHub release alongside the
# artifacts — a release missing latest.yml leaves every Windows install
# stranded on its installed version.
publish:
- provider: github
owner: milind-soni
repo: OpenMausBot
directories:
buildResources: build
output: release
# electron-builder makes copied directories group-writable by default. The
# Linux CUA trust boundary requires root-owned package ancestors to be 0755.
afterPack: ./scripts/after-pack.mjs
# The app is three self-contained pieces, none needing node_modules at
# runtime: the Electron main/preload (plain .mjs/.cjs), the built UI
# (Vite → ui/), and the compiled harness server (tsc → server/), both
# shipped in Resources and run on Electron's own Node via
# ELECTRON_RUN_AS_NODE (the agentcal-hq pattern).
files:
- electron/**
- "!electron/**/*.test.*"
- "!electron/resources/speech-helper"
- "!electron/resources/speech-helper.swift"
- "!electron/resources/speech-helper-Info.plist"
- "!electron/resources/OpenMausBot Speech.app/**"
# The Teach a skill recorder is gone, but a machine that once ran
# `pnpm build:recorder` may still hold its helper build; never ship it.
- "!electron/resources/recorder-helper"
- "!electron/resources/recorder-helper.swift"
- "!electron/resources/recorder-helper-Info.plist"
- "!electron/resources/OpenMausBot Recorder.app/**"
- "!**/node_modules/**"
- package.json
asar: true
extraResources:
# Ship the app's own license terms in every desktop distribution.
- from: LICENSE
to: licenses/OpenMausBot-LICENSE.txt
- from: NOTICE
to: licenses/OpenMausBot-NOTICE.txt
# cloudflared is distributed under Apache-2.0 as a separate executable.
# OpenMausBot itself uses the same full license text; ship another named
# copy so the third-party executable's terms remain unambiguous.
- from: LICENSE
to: licenses/cloudflared-LICENSE.txt
- from: third_party/cloudflared/README.md
to: licenses/cloudflared-README.md
- from: third_party/hpke-js/core-LICENSE.txt
to: licenses/hpke-core-LICENSE.txt
- from: third_party/hpke-js/common-LICENSE.txt
to: licenses/hpke-common-LICENSE.txt
- from: dist
to: ui
- from: dist-server
to: server
# the companion sidecar — a separate process because it is the only part
# of the app that listens off this machine, and it stays off until asked
- from: dist-companion
to: companion
- from: skills
to: skills
- from: dist-native/android-platform-tools
to: android-platform-tools
mac:
# Two single-arch artifacts rather than one universal binary: the app is
# architecture-specific, and universal would make users download both halves.
# electron-updater picks by filename (arm64-marked files on Apple silicon,
# unmarked ones on Intel), so latest-mac.yml must list all four files.
target:
- target: dmg
arch: [arm64, x64]
- target: zip
arch: [arm64, x64]
icon: build/icon.icns
category: public.app-category.productivity
hardenedRuntime: true
gatekeeperAssess: false
entitlements: build/entitlements.mac.plist
entitlementsInherit: build/entitlements.mac.plist
# the dictation helper is a signed background app — Windows and Linux never see it
extraResources:
- from: electron/resources/OpenMausBot Speech.app
to: OpenMausBot Speech.app
# CUA must live outside ASAR. prepare-cua stages the signed executable and
# a self-contained JS/native SDK bundle selected for macOS arm64.
# ${arch} resolves per built arch — each bundle carries its own natives
- from: dist-native/${arch}/cua-driver
to: cua-driver
- from: dist-native/${arch}/cua-sdk
to: cua-sdk
- from: dist-native/cloudflared/darwin-${arch}/cloudflared
to: cloudflared/cloudflared
- from: dist-native/browser/darwin-${arch}
to: browser-engine
extendInfo:
NSMicrophoneUsageDescription: OpenMausBot uses the microphone for voice dictation into the composer.
NSSpeechRecognitionUsageDescription: OpenMausBot transcribes your voice on-device to type messages for you.
NSAccessibilityUsageDescription: OpenMausBot uses Accessibility when you let a bot control this Mac.
NSScreenCaptureUsageDescription: OpenMausBot uses Screen Recording so bots can see this Mac before acting.
# Notarization runs manually after the build (notarytool + staple),
# mirroring the BlueyLite ship_release.sh flow.
notarize: false
dmg:
sign: true
# ${arch} is load-bearing: without it the x64 dmg silently overwrites
# the arm64 one when both arches build (this section overrides both the
# top-level and mac-level artifactName, so it must carry the arch itself)
artifactName: OpenMausBot-${version}-${arch}.dmg
win:
target:
- target: nsis
arch: x64
- target: zip
arch: x64
icon: build/icon.ico
extraResources:
- from: dist-native/cloudflared/win32-x64/cloudflared.exe
to: cloudflared/cloudflared.exe
- from: dist-native/browser/win32-x64
to: browser-engine
# CUA driver and SDK for Windows — must live outside ASAR for native modules
- from: dist-native/cua-win32-x64/cua-driver.exe
to: cua-driver.exe
- from: dist-native/cua-win32-x64/cua-driver-background.exe
to: cua-driver-background.exe
- from: dist-native/cua-win32-x64/cua-sdk
to: cua-sdk
# No signing config yet (would go under win.signtoolOptions or
# win.azureSignOptions — eb 26 nests it, there is no top-level
# win.certificateFile). The installer is unsigned, so SmartScreen shows
# "unknown publisher" on first run (README says so). verifyUpdateCodeSignature
# defaults true, but electron-updater skips the check when app-update.yml
# carries no publisherName — so auto-update still works today. Do NOT set
# publisherName without actually signing, or every update is rejected as
# untrusted; and once signed, keep the cert subject stable (or list both old
# and new in publisherName) or you strand already-installed users.
nsis:
oneClick: true
perMachine: false
shortcutName: OpenMausBot
# Versioned, like the .dmg. The README's /latest/download/ button needs a
# STABLE filename, so ship a second copy named OpenMausBot-setup.exe on the
# release — the same trick as OpenMausBot.dmg beside OpenMausBot-${version}.dmg.
artifactName: OpenMausBot-${version}-setup.${ext}
linux:
target:
- target: AppImage
arch: x64
- target: deb
arch: x64
# Keep the vector source in the freedesktop scalable icon hierarchy. A
# lone 1024px PNG is not indexed by GNOME's hicolor theme on Ubuntu 24.04.
icon: build/icon.svg
category: Utility
executableName: openmausbot
synopsis: Your own team of AI bots, in a chat app
description: A local-first chat app for running a team of AI agents.
maintainer: Milind Soni <46266943+milind-soni@users.noreply.github.com>
vendor: OpenMausBot
syncDesktopName: true
# The reviewed x64 CLI runtime is staged before packaging and remains
# outside ASAR so executable modes and adjacent sidecars are preserved.
extraResources:
- from: dist-native/cua-linux-x64
to: cua-linux-x64
- from: dist-native/cloudflared/linux-x64/cloudflared
to: cloudflared/cloudflared
- from: dist-native/browser/linux-x64
to: browser-engine
- from: build/linux-openmausbot-browser.apparmor
to: openmausbot-browser.apparmor
desktop:
entry:
Name: OpenMausBot
Comment: Your own team of AI bots, in a chat app
Keywords: AI;Agents;Chat;Productivity;
deb:
packageCategory: utils
priority: optional
# Add the narrow browser policy's parser without replacing Electron's
# default shared-library dependencies.
fpm: ["--depends", "apparmor"]
# dpkg can preserve legacy directory modes during an upgrade. This
# idempotent hook repairs only the exact package-owned CUA path.
afterInstall: build/linux-after-install.sh
afterRemove: build/linux-after-remove.sh
# Static AppImage runtime: Ubuntu 24.04 can launch it without legacy FUSE 2.
toolsets:
appimage: "1.0.3"