name: Mobile Release on: push: tags: - 'mobile-v*' workflow_dispatch: jobs: android-build: runs-on: ubuntu-latest # Why: the "Create GitHub Release" step below uses the default GITHUB_TOKEN # to call `gh release create`, which requires contents:write. Without this, # the job builds the APK fine but fails at release time with # "HTTP 403: Resource not accessible by integration". permissions: contents: write defaults: run: working-directory: mobile steps: - name: Checkout uses: actions/checkout@v6 - name: Setup Node.js uses: actions/setup-node@v6 with: node-version: 24 - name: Setup pnpm uses: pnpm/action-setup@v6 with: run_install: false - name: Install dependencies run: pnpm install --frozen-lockfile - name: Setup JDK 17 uses: actions/setup-java@v5 with: distribution: temurin java-version: 17 - name: Expo prebuild run: npx expo prebuild --platform android --no-install - name: Build Android release APK run: cd android && ./gradlew assembleRelease - name: Upload APK artifact uses: actions/upload-artifact@v7 with: name: orca-mobile-apk path: mobile/android/app/build/outputs/apk/release/*.apk - name: Create GitHub Release if: startsWith(github.ref, 'refs/tags/mobile-v') env: GH_TOKEN: ${{ github.token }} run: | tag="${GITHUB_REF#refs/tags/}" gh release create "$tag" \ --repo "$GITHUB_REPOSITORY" \ --title "Orca Mobile $tag" \ --prerelease \ --latest=false \ --generate-notes \ android/app/build/outputs/apk/release/*.apk