ci(desktop): release prod snaps to the Snap Store stable channel

Every Gauzy app snap (desktop, desktop-timer, server, api-server, agent,
mcp-server; amd64 and arm64) went to the Snap Store 'edge' channel only,
from both the stage lane (stage-apps) and the prod lane (apps). The
electron-builder snap target publishes with its own snapStore config.
When the build config has no snapStore entry, that config has no
channels, and the Snap Store publisher then defaults to 'edge'.

Prod builds now release to 'stable' and stage builds to 'edge'. Each
Linux build step appends
-c.snap.publish.provider=snapStore -c.snap.publish.channels=<channel>
to its yarn command. yarn adds extra arguments to the end of the script,
which is the electron-builder call. The override is in the workflows
because the root build scripts are shared by both lanes. Only
snap.publish is overridden: a -c.publish override would be merged into
the GitHub publish entry. GitHub releases, update channels and every
other target are unchanged. Stage names 'edge' explicitly so each
prod/stage pair still differs only in the channel.

The generated snaps already use grade stable and strict confinement,
and they need no store-approved plugs, so the store accepts them on
stable.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Ruslan Konviser
2026-09-26 01:10:55 +02:00
co-authored by Claude Opus 5.5
parent f32a4488bd
commit cec254cd35
12 changed files with 96 additions and 24 deletions
+8 -2
View File
@@ -213,7 +213,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Agent
run: 'yarn build:agent:linux:release:gh:x64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:agent:linux:release:gh:x64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=stable'
env:
USE_HARD_LINKS: false
GH_TOKEN: ${{ secrets.GH_TOKEN }}
@@ -476,7 +479,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Agent
run: 'yarn build:agent:linux:release:gh:arm64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:agent:linux:release:gh:arm64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=stable'
env:
USE_HARD_LINKS: false
USE_SYSTEM_FPM: true
+8 -2
View File
@@ -217,7 +217,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Agent
run: 'yarn build:agent:linux:release:gh:x64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:agent:linux:release:gh:x64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=edge'
env:
USE_HARD_LINKS: false
GH_TOKEN: ${{ secrets.GH_TOKEN }}
@@ -480,7 +483,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Agent
run: 'yarn build:agent:linux:release:gh:arm64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:agent:linux:release:gh:arm64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=edge'
env:
USE_HARD_LINKS: false
USE_SYSTEM_FPM: true
+8 -2
View File
@@ -213,7 +213,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Desktop App
run: 'yarn build:desktop:linux:release:gh:x64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:desktop:linux:release:gh:x64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=stable'
env:
USE_HARD_LINKS: false
GH_TOKEN: ${{ secrets.GH_TOKEN }}
@@ -476,7 +479,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Desktop App
run: 'yarn build:desktop:linux:release:gh:arm64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:desktop:linux:release:gh:arm64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=stable'
env:
USE_HARD_LINKS: false
USE_SYSTEM_FPM: true
+8 -2
View File
@@ -218,7 +218,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Desktop App
run: 'yarn build:desktop:linux:release:gh:x64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:desktop:linux:release:gh:x64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=edge'
env:
USE_HARD_LINKS: false
GH_TOKEN: ${{ secrets.GH_TOKEN }}
@@ -481,7 +484,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Desktop App
run: 'yarn build:desktop:linux:release:gh:arm64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:desktop:linux:release:gh:arm64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=edge'
env:
USE_HARD_LINKS: false
USE_SYSTEM_FPM: true
+8 -2
View File
@@ -213,7 +213,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Desktop Timer App
run: 'yarn build:desktop-timer:linux:release:gh:x64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:desktop-timer:linux:release:gh:x64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=stable'
env:
USE_HARD_LINKS: false
GH_TOKEN: ${{ secrets.GH_TOKEN }}
@@ -476,7 +479,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Desktop Timer App
run: 'yarn build:desktop-timer:linux:release:gh:arm64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:desktop-timer:linux:release:gh:arm64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=stable'
env:
USE_HARD_LINKS: false
USE_SYSTEM_FPM: true
@@ -217,7 +217,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Desktop Timer App
run: 'yarn build:desktop-timer:linux:release:gh:x64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:desktop-timer:linux:release:gh:x64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=edge'
env:
USE_HARD_LINKS: false
GH_TOKEN: ${{ secrets.GH_TOKEN }}
@@ -480,7 +483,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Desktop Timer App
run: 'yarn build:desktop-timer:linux:release:gh:arm64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:desktop-timer:linux:release:gh:arm64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=edge'
env:
USE_HARD_LINKS: false
USE_SYSTEM_FPM: true
+8 -2
View File
@@ -213,7 +213,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Server
run: 'yarn build:gauzy-api-server:linux:release:gh:x64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:gauzy-api-server:linux:release:gh:x64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=stable'
env:
USE_HARD_LINKS: false
GH_TOKEN: ${{ secrets.GH_TOKEN }}
@@ -476,7 +479,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Server API
run: 'yarn build:gauzy-api-server:linux:release:gh:arm64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:gauzy-api-server:linux:release:gh:arm64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=stable'
env:
USE_HARD_LINKS: false
USE_SYSTEM_FPM: true
+8 -2
View File
@@ -218,7 +218,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Server
run: 'yarn build:gauzy-api-server:linux:release:gh:x64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:gauzy-api-server:linux:release:gh:x64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=edge'
env:
USE_HARD_LINKS: false
GH_TOKEN: ${{ secrets.GH_TOKEN }}
@@ -481,7 +484,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Server API
run: 'yarn build:gauzy-api-server:linux:release:gh:arm64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:gauzy-api-server:linux:release:gh:arm64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=edge'
env:
USE_HARD_LINKS: false
USE_SYSTEM_FPM: true
+8 -2
View File
@@ -204,7 +204,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Server
run: 'yarn build:gauzy-mcp-server:linux:release:gh:x64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:gauzy-mcp-server:linux:release:gh:x64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=stable'
env:
USE_HARD_LINKS: false
GH_TOKEN: ${{ secrets.GH_TOKEN }}
@@ -458,7 +461,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Server MCP
run: 'yarn build:gauzy-mcp-server:linux:release:gh:arm64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:gauzy-mcp-server:linux:release:gh:arm64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=stable'
env:
USE_HARD_LINKS: false
USE_SYSTEM_FPM: true
+8 -2
View File
@@ -209,7 +209,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Server
run: 'yarn build:gauzy-mcp-server:linux:release:gh:x64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:gauzy-mcp-server:linux:release:gh:x64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=edge'
env:
USE_HARD_LINKS: false
GH_TOKEN: ${{ secrets.GH_TOKEN }}
@@ -463,7 +466,10 @@ jobs:
run: mkdir -p dist/packages
- name: Build Server MCP
run: 'yarn build:gauzy-mcp-server:linux:release:gh:arm64'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:gauzy-mcp-server:linux:release:gh:arm64 -c.snap.publish.provider=snapStore -c.snap.publish.channels=edge'
env:
USE_HARD_LINKS: false
USE_SYSTEM_FPM: true
+8 -2
View File
@@ -245,7 +245,10 @@ jobs:
NX_DAEMON: false
- name: Build Server App
run: 'yarn build:gauzy-server:linux:release:gh:x64:isolated'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:gauzy-server:linux:release:gh:x64:isolated -c.snap.publish.provider=snapStore -c.snap.publish.channels=stable'
env:
USE_HARD_LINKS: false
GH_TOKEN: ${{ secrets.GH_TOKEN }}
@@ -542,7 +545,10 @@ jobs:
NX_DAEMON: false
- name: Build Server App
run: 'yarn build:gauzy-server:linux:release:gh:arm64:isolated'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:gauzy-server:linux:release:gh:arm64:isolated -c.snap.publish.provider=snapStore -c.snap.publish.channels=stable'
env:
USE_HARD_LINKS: false
USE_SYSTEM_FPM: true
+8 -2
View File
@@ -249,7 +249,10 @@ jobs:
NX_DAEMON: false
- name: Build Server App
run: 'yarn build:gauzy-server:linux:release:gh:x64:isolated'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:gauzy-server:linux:release:gh:x64:isolated -c.snap.publish.provider=snapStore -c.snap.publish.channels=edge'
env:
USE_HARD_LINKS: false
GH_TOKEN: ${{ secrets.GH_TOKEN }}
@@ -546,7 +549,10 @@ jobs:
NX_DAEMON: false
- name: Build Server App
run: 'yarn build:gauzy-server:linux:release:gh:arm64:isolated'
# Snap Store channel: prod ('apps') releases to 'stable', stage ('stage-apps') to 'edge' (the
# electron-builder default). yarn appends these flags to the script's last command, the
# electron-builder call. Override snap.publish only: a -c.publish override lands in the GitHub entry.
run: 'yarn build:gauzy-server:linux:release:gh:arm64:isolated -c.snap.publish.provider=snapStore -c.snap.publish.channels=edge'
env:
USE_HARD_LINKS: false
USE_SYSTEM_FPM: true