Refactored GitHub workflow for artifact signing
Use a matrix to effectively iterate over the 4 possible windows artifacts. extract the signable entity from the original composite artifact upload it individually ready to be signed.meow-7.2.2
parent
73a368b6bb
commit
e49832c976
|
|
@ -32,46 +32,68 @@ on:
|
|||
# default: 'master'
|
||||
|
||||
jobs:
|
||||
download-and-sign:
|
||||
find-setup-files:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
actions: read
|
||||
contents: read
|
||||
outputs:
|
||||
setup_files: ${{ steps.get-files.output.setup_files }}
|
||||
steps:
|
||||
- name: Download Build Artifacts
|
||||
uses: dawidd6/action-download-artifact@v6
|
||||
id: download
|
||||
with:
|
||||
workflow: build_viewer.yml
|
||||
run_number: ${{ github.event.inputs.build_run_number }}
|
||||
name: .*windows.*
|
||||
name_is_regexp: true
|
||||
path: artifacts
|
||||
- name: Unzip All Artifacts
|
||||
shell: bash
|
||||
run: |
|
||||
mkdir unzipped
|
||||
for artifact in artifacts/*; do
|
||||
unzip "$artifact" -d unzipped
|
||||
done
|
||||
- name: Get List of Setup.exe Files
|
||||
id: get-files
|
||||
shell: bash
|
||||
run: |
|
||||
files=$(find unzipped -type f -name '*Setup.exe')
|
||||
files_json=$(printf '%s\n' "$files" | jq -R . | jq -s .)
|
||||
echo "::set-output name=setup_files::$files_json"
|
||||
|
||||
- name: Upload unsigned artifact
|
||||
sign-and-upload:
|
||||
name: Sign and Upload each Setup.exe
|
||||
needs: find-setup-files
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
file: ${{ fromJson( needs.find-find-setup-files.outputs.setup_files) }}
|
||||
steps:
|
||||
|
||||
- name: Download Build Artifacts
|
||||
uses: dawidd6/action-download-artifact@v6
|
||||
id: download
|
||||
with:
|
||||
workflow: build_viewer.yml
|
||||
run_number: ${{ github.event.inputs.build_run_number }}
|
||||
name: .*windows.*
|
||||
name_is_regexp: true
|
||||
path: to_sign
|
||||
|
||||
- name: Upload unsigned artifact
|
||||
id: upload-unsigned-artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: unsigned-artifact
|
||||
path: ./to_sign
|
||||
- name: Upload unsigned artifact
|
||||
id: upload-unsigned-artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: unsigned-artifact
|
||||
path: ./to_sign
|
||||
- name: sign
|
||||
uses: signpath/github-action-submit-signing-request@v1
|
||||
env:
|
||||
SIGNPATH_SIGNING_POLICY_SLUG: ${{ github.event.inputs.policy == 'Test' && vars.SIGNPATH_SIGNING_POLICY_SLUG_TEST || vars.SIGNPATH_SIGNING_POLICY_SLUG_RELEASE }}
|
||||
with:
|
||||
api-token: '${{ secrets.SIGNPATH_API_TOKEN }}'
|
||||
organization-id: '${{ vars.SIGNPATH_ORGANIZATION_ID }}'
|
||||
project-slug: '${{ vars.SIGNPATH_PROJECT_SLUG }}'
|
||||
signing-policy-slug: '${{ env.SIGNPATH_SIGNING_POLICY_SLUG }}'
|
||||
github-artifact-id: "${{steps.upload-unsigned-artifact.outputs.artifact-id}}"
|
||||
wait-for-completion: true
|
||||
output-artifact-directory: 'application-signed'
|
||||
|
||||
- name: sign
|
||||
uses: signpath/github-action-submit-signing-request@v1
|
||||
env:
|
||||
SIGNPATH_SIGNING_POLICY_SLUG: ${{ github.event.inputs.policy == 'Test' && vars.SIGNPATH_SIGNING_POLICY_SLUG_TEST || vars.SIGNPATH_SIGNING_POLICY_SLUG_RELEASE }}
|
||||
|
||||
with:
|
||||
api-token: '${{ secrets.SIGNPATH_API_TOKEN }}'
|
||||
organization-id: '${{ vars.SIGNPATH_ORGANIZATION_ID }}'
|
||||
project-slug: '${{ vars.SIGNPATH_PROJECT_SLUG }}'
|
||||
signing-policy-slug: '${{ env.SIGNPATH_SIGNING_POLICY_SLUG }}'
|
||||
github-artifact-id: "${{steps.upload-unsigned-artifact.outputs.artifact-id}}"
|
||||
wait-for-completion: true
|
||||
output-artifact-directory: 'application-signed'
|
||||
|
||||
- name: Upload signed artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: signed-artifact
|
||||
path: ./application-signed
|
||||
- name: Upload signed artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: signed-artifact
|
||||
path: ./application-signed
|
||||
Loading…
Reference in New Issue