mirror of
https://github.com/helmfile/helmfile.git
synced 2026-10-03 03:25:05 +02:00
ci: publish a signed packslip with each release (#2809)
* ci: publish a signed packslip with each release Add a job after goreleaser that publishes a packslip.sigstore.json to tag releases: a manifest of the release archives, the helmfile executable in each, shell completions via `helmfile completion`, and the skills/helmfile agent skill at the release commit, signed keylessly with this workflow's OIDC identity and linked to build provenance. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: jdx <216188+jdx@users.noreply.github.com> * ci: include the 386 archives in the packslip packslip 1.4.0 reads goreleaser's 386 as i686 and leaves libc out for static Linux builds, so every archive can be listed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: jdx <216188+jdx@users.noreply.github.com> --------- Signed-off-by: jdx <216188+jdx@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -45,3 +45,24 @@ jobs:
|
||||
with:
|
||||
version: latest
|
||||
args: release --clean ${{ env.SNAPSHOT }}
|
||||
|
||||
# Publish a signed packslip (https://packslip.dev) listing each archive's
|
||||
# digest, the helmfile executable inside it, its shell completions, and the
|
||||
# skill in skills/helmfile, signed with this workflow's identity so
|
||||
# installers can verify a download without a key this project must hold.
|
||||
packslip:
|
||||
needs: goreleaser
|
||||
if: startsWith(github.ref, 'refs/tags/v')
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write
|
||||
id-token: write
|
||||
attestations: write
|
||||
steps:
|
||||
- uses: jdx/packslip@v1
|
||||
with:
|
||||
download: helmfile_*.tar.gz
|
||||
bin: helmfile
|
||||
resources: |
|
||||
completion/bash,zsh,fish,powershell=exec:helmfile completion {shell}
|
||||
skill/helmfile=repo:skills/helmfile
|
||||
|
||||
Reference in New Issue
Block a user