fix(release): honor --publish never, guard Windows signing, fix desktop spawn
Second pass after the cache/arch fix unblocked `pnpm build` and surfaced later-stage failures: - Desktop packaging called `pnpm --filter @fusion/desktop dist:mac -- <args>`, but pnpm leaks the `--` separator into the script args. electron-builder stops parsing at `--`, so `--publish never` was ignored — it auto-published to api.github.com/repos/gsxdsm/fusion/releases and 404'd. The same leak dropped Linux's `--x64 --arm64`. Switch all four desktop packaging steps to `pnpm --filter @fusion/desktop exec electron-builder ...`, which forwards args cleanly (verified locally). - Windows CLI signing now skips when WINDOWS_CERTIFICATE_BASE64 is absent, mirroring the macOS guard (was hard-failing the bun-windows-x64 job). - Desktop build spawns workspace .cmd bins with shell:true on Windows; Node rejects .cmd/.bat spawns without a shell (EINVAL) since CVE-2024-27980, which broke `@fusion/desktop build` on the Windows runner. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -23,6 +23,10 @@ export function runWorkspaceBin(command: string, args: string[], cwd: string): P
|
||||
cwd,
|
||||
stdio: "inherit",
|
||||
env: process.env,
|
||||
// On Windows the resolved bin is a .cmd shim; Node refuses to spawn
|
||||
// .cmd/.bat without a shell (EINVAL) since CVE-2024-27980. resolveBin
|
||||
// produces an absolute, space-free path, so shell quoting is safe here.
|
||||
shell: process.platform === "win32",
|
||||
});
|
||||
|
||||
child.on("error", rejectPromise);
|
||||
|
||||
Reference in New Issue
Block a user