Commit a63f64b1 authored by Ivan Vandot's avatar Ivan Vandot Committed by GitHub

sign checksums.txt with gpg key (#1581)

parent 95a16dc9
......@@ -35,6 +35,12 @@ jobs:
uses: docker/setup-qemu-action@v1
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1
- name: Import GPG key
run: |
echo "$GPG_PRIVATE_KEY" | gpg --import --passphrase "$GPG_PASSPHRASE" --batch --allow-secret-key-import
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@v2
with:
......@@ -44,3 +50,5 @@ jobs:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
HOMEBREW_TAP_PAT: ${{ secrets.HOMEBREW_TAP_PAT }}
SCOOP_PAT: ${{ secrets.SCOOP_PAT }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
GPG_FINGERPRINT: ${{ secrets.GPG_FINGERPRINT }}
......@@ -53,6 +53,16 @@ builds:
snapshot:
name_template: "{{.Tag}}-snapshot"
signs:
- artifacts: checksum
args: [
"--pinentry-mode", "loopback",
"--passphrase", "{{ .Env.GPG_PASSPHRASE }}",
"-u", "{{ .Env.GPG_FINGERPRINT }}",
"--output", "${signature}",
"--detach-sign", "${artifact}",
]
archives:
-
id: scoop
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment