Initial commit: FlatKontrol, a Kirigami Flatpak permissions manager
A KDE/Qt application to review and edit the permissions of installed Flatpak applications, editing the same override files as Flatpak itself. Covers shared subsystems, sockets, devices, features, filesystem access, persistent paths, environment variables, D-Bus policies and portals. Includes a Flatpak manifest and a CI workflow that publishes a bundle and a hosted Flatpak repository on tagged releases.
This commit is contained in:
@@ -0,0 +1,103 @@
|
||||
# SPDX-License-Identifier: GPL-3.0-or-later
|
||||
name: Build and Publish Flatpak
|
||||
|
||||
on:
|
||||
push:
|
||||
tags:
|
||||
- 'v*'
|
||||
workflow_dispatch: {}
|
||||
|
||||
permissions:
|
||||
contents: write # create releases / upload the bundle
|
||||
pages: write # deploy the hosted Flatpak repo
|
||||
id-token: write # required by actions/deploy-pages
|
||||
|
||||
concurrency:
|
||||
group: pages
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
build:
|
||||
name: Build Flatpak
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
# Ships the KDE Platform/Sdk + flatpak-builder. Bump the tag to match
|
||||
# runtime-version in the manifest.
|
||||
image: ghcr.io/flathub-infra/flatpak-github-actions:kde-6.10
|
||||
options: --privileged
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Build from the checked-out commit
|
||||
run: |
|
||||
python3 - <<'PY'
|
||||
import re
|
||||
p = "io.github.toservetheking.FlatKontrol.yml"
|
||||
s = open(p).read()
|
||||
s = re.sub(r" sources:.*\Z",
|
||||
" sources:\n - type: dir\n path: .\n",
|
||||
s, flags=re.S)
|
||||
open(p, "w").write(s)
|
||||
print(s)
|
||||
PY
|
||||
|
||||
- name: Build repo and bundle
|
||||
run: |
|
||||
flatpak-builder --user --disable-rofiles-fuse --force-clean \
|
||||
--default-branch=stable --repo=repo \
|
||||
builddir io.github.toservetheking.FlatKontrol.yml
|
||||
flatpak build-update-repo repo --generate-static-deltas
|
||||
flatpak build-bundle repo \
|
||||
io.github.toservetheking.FlatKontrol.flatpak \
|
||||
io.github.toservetheking.FlatKontrol stable
|
||||
|
||||
- name: Add repo landing page and .flatpakrepo
|
||||
run: |
|
||||
cat > repo/flatkontrol.flatpakrepo <<'EOF'
|
||||
[Flatpak Repo]
|
||||
Title=FlatKontrol
|
||||
Url=https://toservetheking.github.io/FlatKontrol/
|
||||
Homepage=https://github.com/toservetheking/FlatKontrol
|
||||
Description=Manage Flatpak permissions
|
||||
EOF
|
||||
cat > repo/index.html <<'EOF'
|
||||
<!doctype html>
|
||||
<meta charset="utf-8">
|
||||
<title>FlatKontrol Flatpak repository</title>
|
||||
<h1>FlatKontrol</h1>
|
||||
<p>Add the repository and install:</p>
|
||||
<pre>flatpak remote-add --if-not-exists --user flatkontrol https://toservetheking.github.io/FlatKontrol/flatkontrol.flatpakrepo
|
||||
flatpak install --user flatkontrol io.github.toservetheking.FlatKontrol</pre>
|
||||
<p>Or download the single-file bundle from the
|
||||
<a href="https://github.com/toservetheking/FlatKontrol/releases">Releases page</a>.</p>
|
||||
EOF
|
||||
|
||||
- name: Upload bundle artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: flatpak-bundle
|
||||
path: io.github.toservetheking.FlatKontrol.flatpak
|
||||
|
||||
- name: Attach bundle to release
|
||||
if: startsWith(github.ref, 'refs/tags/')
|
||||
uses: softprops/action-gh-release@v2
|
||||
with:
|
||||
files: io.github.toservetheking.FlatKontrol.flatpak
|
||||
|
||||
- name: Upload Pages artifact
|
||||
uses: actions/upload-pages-artifact@v3
|
||||
with:
|
||||
path: repo
|
||||
|
||||
deploy-pages:
|
||||
name: Deploy hosted repo to Pages
|
||||
needs: build
|
||||
runs-on: ubuntu-latest
|
||||
environment:
|
||||
name: github-pages
|
||||
url: ${{ steps.deployment.outputs.page_url }}
|
||||
steps:
|
||||
- name: Deploy
|
||||
id: deployment
|
||||
uses: actions/deploy-pages@v4
|
||||
Reference in New Issue
Block a user