diff --git a/.github/workflows/sign.yml b/.github/workflows/sign.yml index 97f1f7c35b..b243d99da7 100644 --- a/.github/workflows/sign.yml +++ b/.github/workflows/sign.yml @@ -32,46 +32,68 @@ on: # default: 'master' jobs: - download-and-sign: + find-setup-files: runs-on: ubuntu-latest permissions: actions: read contents: read + outputs: + setup_files: ${{ steps.get-files.output.setup_files }} + steps: + - name: Download Build Artifacts + uses: dawidd6/action-download-artifact@v6 + id: download + with: + workflow: build_viewer.yml + run_number: ${{ github.event.inputs.build_run_number }} + name: .*windows.* + name_is_regexp: true + path: artifacts + - name: Unzip All Artifacts + shell: bash + run: | + mkdir unzipped + for artifact in artifacts/*; do + unzip "$artifact" -d unzipped + done + - name: Get List of Setup.exe Files + id: get-files + shell: bash + run: | + files=$(find unzipped -type f -name '*Setup.exe') + files_json=$(printf '%s\n' "$files" | jq -R . | jq -s .) + echo "::set-output name=setup_files::$files_json" + + - name: Upload unsigned artifact + sign-and-upload: + name: Sign and Upload each Setup.exe + needs: find-setup-files + runs-on: ubuntu-latest + strategy: + matrix: + file: ${{ fromJson( needs.find-find-setup-files.outputs.setup_files) }} steps: - - - name: Download Build Artifacts - uses: dawidd6/action-download-artifact@v6 - id: download - with: - workflow: build_viewer.yml - run_number: ${{ github.event.inputs.build_run_number }} - name: .*windows.* - name_is_regexp: true - path: to_sign - - - name: Upload unsigned artifact - id: upload-unsigned-artifact - uses: actions/upload-artifact@v4 - with: - name: unsigned-artifact - path: ./to_sign + - name: Upload unsigned artifact + id: upload-unsigned-artifact + uses: actions/upload-artifact@v4 + with: + name: unsigned-artifact + path: ./to_sign + - name: sign + uses: signpath/github-action-submit-signing-request@v1 + env: + SIGNPATH_SIGNING_POLICY_SLUG: ${{ github.event.inputs.policy == 'Test' && vars.SIGNPATH_SIGNING_POLICY_SLUG_TEST || vars.SIGNPATH_SIGNING_POLICY_SLUG_RELEASE }} + with: + api-token: '${{ secrets.SIGNPATH_API_TOKEN }}' + organization-id: '${{ vars.SIGNPATH_ORGANIZATION_ID }}' + project-slug: '${{ vars.SIGNPATH_PROJECT_SLUG }}' + signing-policy-slug: '${{ env.SIGNPATH_SIGNING_POLICY_SLUG }}' + github-artifact-id: "${{steps.upload-unsigned-artifact.outputs.artifact-id}}" + wait-for-completion: true + output-artifact-directory: 'application-signed' - - name: sign - uses: signpath/github-action-submit-signing-request@v1 - env: - SIGNPATH_SIGNING_POLICY_SLUG: ${{ github.event.inputs.policy == 'Test' && vars.SIGNPATH_SIGNING_POLICY_SLUG_TEST || vars.SIGNPATH_SIGNING_POLICY_SLUG_RELEASE }} - - with: - api-token: '${{ secrets.SIGNPATH_API_TOKEN }}' - organization-id: '${{ vars.SIGNPATH_ORGANIZATION_ID }}' - project-slug: '${{ vars.SIGNPATH_PROJECT_SLUG }}' - signing-policy-slug: '${{ env.SIGNPATH_SIGNING_POLICY_SLUG }}' - github-artifact-id: "${{steps.upload-unsigned-artifact.outputs.artifact-id}}" - wait-for-completion: true - output-artifact-directory: 'application-signed' - - - name: Upload signed artifact - uses: actions/upload-artifact@v4 - with: - name: signed-artifact - path: ./application-signed \ No newline at end of file + - name: Upload signed artifact + uses: actions/upload-artifact@v4 + with: + name: signed-artifact + path: ./application-signed \ No newline at end of file