Commit a63f64b1 authored by Ivan Vandot's avatar Ivan Vandot Committed by GitHub

sign checksums.txt with gpg key (#1581)

parent 95a16dc9
...@@ -35,6 +35,12 @@ jobs: ...@@ -35,6 +35,12 @@ jobs:
uses: docker/setup-qemu-action@v1 uses: docker/setup-qemu-action@v1
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1 uses: docker/setup-buildx-action@v1
- name: Import GPG key
run: |
echo "$GPG_PRIVATE_KEY" | gpg --import --passphrase "$GPG_PASSPHRASE" --batch --allow-secret-key-import
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
- name: Run GoReleaser - name: Run GoReleaser
uses: goreleaser/goreleaser-action@v2 uses: goreleaser/goreleaser-action@v2
with: with:
...@@ -44,3 +50,5 @@ jobs: ...@@ -44,3 +50,5 @@ jobs:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
HOMEBREW_TAP_PAT: ${{ secrets.HOMEBREW_TAP_PAT }} HOMEBREW_TAP_PAT: ${{ secrets.HOMEBREW_TAP_PAT }}
SCOOP_PAT: ${{ secrets.SCOOP_PAT }} SCOOP_PAT: ${{ secrets.SCOOP_PAT }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
GPG_FINGERPRINT: ${{ secrets.GPG_FINGERPRINT }}
...@@ -53,6 +53,16 @@ builds: ...@@ -53,6 +53,16 @@ builds:
snapshot: snapshot:
name_template: "{{.Tag}}-snapshot" name_template: "{{.Tag}}-snapshot"
signs:
- artifacts: checksum
args: [
"--pinentry-mode", "loopback",
"--passphrase", "{{ .Env.GPG_PASSPHRASE }}",
"-u", "{{ .Env.GPG_FINGERPRINT }}",
"--output", "${signature}",
"--detach-sign", "${artifact}",
]
archives: archives:
- -
id: scoop id: scoop
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment