feat(#330): pin Flutter and pass GIPHY_API_KEY in the signed build
Rebased onto dev after #331 landed. Brings the signing workflow in line with the rest of the matrix: - Pinned to Flutter 3.44.1, matching the bench and every other workflow. A release artifact in particular must not be built by whatever `stable` happens to point at that day, which was the whole argument for #331. - Generates dart_defines.json and passes --dart-define-from-file, so the signed release does not ship with a dead GIF picker. - Cleanup step now removes dart_defines.json alongside the keystore material, since it holds the Giphy key. Verified that a job pinned to an environment still receives repository secrets (precedence is org < repo < environment, environment winning on a name collision), so the repo-scoped GIPHY_API_KEY reaches this job while the keystore secrets stay environment-scoped behind the reviewer gate. Part of epic #312, plan #321 (Phase 5).pull/341/head
parent
1d1c887900
commit
3a44e944d3
Loading…
Reference in new issue