Refactored GitHub workflow for artifact signing

Use a matrix to effectively iterate over the 4 possible windows artifacts.
extract the signable entity from the original composite artifact
upload it individually ready to be signed.
meow-7.2.2
Beq 2024-10-03 17:07:13 +01:00
parent 73a368b6bb
commit e49832c976
1 changed files with 59 additions and 37 deletions

View File

@ -32,46 +32,68 @@ on:
# default: 'master'
jobs:
download-and-sign:
find-setup-files:
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
outputs:
setup_files: ${{ steps.get-files.output.setup_files }}
steps:
- name: Download Build Artifacts
uses: dawidd6/action-download-artifact@v6
id: download
with:
workflow: build_viewer.yml
run_number: ${{ github.event.inputs.build_run_number }}
name: .*windows.*
name_is_regexp: true
path: artifacts
- name: Unzip All Artifacts
shell: bash
run: |
mkdir unzipped
for artifact in artifacts/*; do
unzip "$artifact" -d unzipped
done
- name: Get List of Setup.exe Files
id: get-files
shell: bash
run: |
files=$(find unzipped -type f -name '*Setup.exe')
files_json=$(printf '%s\n' "$files" | jq -R . | jq -s .)
echo "::set-output name=setup_files::$files_json"
- name: Upload unsigned artifact
sign-and-upload:
name: Sign and Upload each Setup.exe
needs: find-setup-files
runs-on: ubuntu-latest
strategy:
matrix:
file: ${{ fromJson( needs.find-find-setup-files.outputs.setup_files) }}
steps:
- name: Download Build Artifacts
uses: dawidd6/action-download-artifact@v6
id: download
with:
workflow: build_viewer.yml
run_number: ${{ github.event.inputs.build_run_number }}
name: .*windows.*
name_is_regexp: true
path: to_sign
- name: Upload unsigned artifact
id: upload-unsigned-artifact
uses: actions/upload-artifact@v4
with:
name: unsigned-artifact
path: ./to_sign
- name: Upload unsigned artifact
id: upload-unsigned-artifact
uses: actions/upload-artifact@v4
with:
name: unsigned-artifact
path: ./to_sign
- name: sign
uses: signpath/github-action-submit-signing-request@v1
env:
SIGNPATH_SIGNING_POLICY_SLUG: ${{ github.event.inputs.policy == 'Test' && vars.SIGNPATH_SIGNING_POLICY_SLUG_TEST || vars.SIGNPATH_SIGNING_POLICY_SLUG_RELEASE }}
with:
api-token: '${{ secrets.SIGNPATH_API_TOKEN }}'
organization-id: '${{ vars.SIGNPATH_ORGANIZATION_ID }}'
project-slug: '${{ vars.SIGNPATH_PROJECT_SLUG }}'
signing-policy-slug: '${{ env.SIGNPATH_SIGNING_POLICY_SLUG }}'
github-artifact-id: "${{steps.upload-unsigned-artifact.outputs.artifact-id}}"
wait-for-completion: true
output-artifact-directory: 'application-signed'
- name: sign
uses: signpath/github-action-submit-signing-request@v1
env:
SIGNPATH_SIGNING_POLICY_SLUG: ${{ github.event.inputs.policy == 'Test' && vars.SIGNPATH_SIGNING_POLICY_SLUG_TEST || vars.SIGNPATH_SIGNING_POLICY_SLUG_RELEASE }}
with:
api-token: '${{ secrets.SIGNPATH_API_TOKEN }}'
organization-id: '${{ vars.SIGNPATH_ORGANIZATION_ID }}'
project-slug: '${{ vars.SIGNPATH_PROJECT_SLUG }}'
signing-policy-slug: '${{ env.SIGNPATH_SIGNING_POLICY_SLUG }}'
github-artifact-id: "${{steps.upload-unsigned-artifact.outputs.artifact-id}}"
wait-for-completion: true
output-artifact-directory: 'application-signed'
- name: Upload signed artifact
uses: actions/upload-artifact@v4
with:
name: signed-artifact
path: ./application-signed
- name: Upload signed artifact
uses: actions/upload-artifact@v4
with:
name: signed-artifact
path: ./application-signed