diff --git a/.github/workflows/sign.yml b/.github/workflows/sign.yml index b3ea7d23d7..9d300f8c13 100644 --- a/.github/workflows/sign.yml +++ b/.github/workflows/sign.yml @@ -38,7 +38,7 @@ jobs: actions: read contents: read outputs: - setup_files: ${{ steps.get-files.output.setup_files }} + setup_files: ${{ steps.get-files.outputs.setup_files }} steps: - name: Download Build Artifacts uses: dawidd6/action-download-artifact@v6 @@ -53,24 +53,54 @@ jobs: id: get-files shell: bash run: | + mkdir -p setup_exe_files files=$(find artifacts -type f -name '*Setup.exe') - files_json=$(printf '%s\n' "$files" | jq -R . | jq -s -c .) + for file in $files; do + basename=$(basename "$file") + cp "$file" "setup_exe_files/$basename" + done + files_json=$(ls setup_exe_files | jq -R . | jq -s -c .) echo "setup_files=$files_json" >> $GITHUB_OUTPUT + - name: Upload Setup.exe Files + uses: actions/upload-artifact@v4 + with: + name: setup-exe-files + path: setup_exe_files/ sign-and-upload: name: Sign and Upload each Setup.exe needs: find-setup-files runs-on: ubuntu-latest strategy: matrix: - file: ${{ fromJson( needs.find-find-setup-files.outputs.setup_files) }} + file: ${{ fromJson( needs.find-setup-files.outputs.setup_files) }} + permissions: + actions: read + contents: read steps: + - name: List Available Artifacts + run: | + echo "Available artifacts:" + curl -H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \ + -H "Accept: application/vnd.github.v3+json" \ + https://api.github.com/repos/${{ github.repository }}/actions/runs/${{ github.run_id }}/artifacts + + - name: Download Setup.exe Files Artifact + uses: actions/download-artifact@v4 + with: + name: setup-exe-files + path: setup_exe_files + - name: Prepare File for Signing + run: | + mkdir -p to_sign + cp "setup_exe_files/${{ matrix.file }}" to_sign/ - name: Upload unsigned artifact id: upload-unsigned-artifact uses: actions/upload-artifact@v4 with: - name: unsigned-artifact - path: ./to_sign - - name: sign + name: unsigned-artifact-${{ matrix.file }} + path: to_sign/ + + - name: sign the file uses: signpath/github-action-submit-signing-request@v1 env: SIGNPATH_SIGNING_POLICY_SLUG: ${{ github.event.inputs.policy == 'Test' && vars.SIGNPATH_SIGNING_POLICY_SLUG_TEST || vars.SIGNPATH_SIGNING_POLICY_SLUG_RELEASE }} @@ -86,5 +116,5 @@ jobs: - name: Upload signed artifact uses: actions/upload-artifact@v4 with: - name: signed-artifact + name: signed-artifact-${{ matrix.file }} path: ./application-signed \ No newline at end of file