ci: publish a signed packslip with each release (#2809)

* ci: publish a signed packslip with each release

Add a job after goreleaser that publishes a packslip.sigstore.json to
tag releases: a manifest of the release archives, the helmfile
executable in each, shell completions via `helmfile completion`, and
the skills/helmfile agent skill at the release commit, signed keylessly
with this workflow's OIDC identity and linked to build provenance.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: jdx <216188+jdx@users.noreply.github.com>

* ci: include the 386 archives in the packslip

packslip 1.4.0 reads goreleaser's 386 as i686 and leaves libc out for
static Linux builds, so every archive can be listed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: jdx <216188+jdx@users.noreply.github.com>

---------

Signed-off-by: jdx <216188+jdx@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
jdx
2026-09-28 21:49:35 +08:00
committed by GitHub
co-authored by Claude Opus 5.5
parent c36d150a3a
commit 5d901f8ac1
+21
View File
@@ -45,3 +45,24 @@ jobs:
with:
version: latest
args: release --clean ${{ env.SNAPSHOT }}
# Publish a signed packslip (https://packslip.dev) listing each archive's
# digest, the helmfile executable inside it, its shell completions, and the
# skill in skills/helmfile, signed with this workflow's identity so
# installers can verify a download without a key this project must hold.
packslip:
needs: goreleaser
if: startsWith(github.ref, 'refs/tags/v')
runs-on: ubuntu-latest
permissions:
contents: write
id-token: write
attestations: write
steps:
- uses: jdx/packslip@v1
with:
download: helmfile_*.tar.gz
bin: helmfile
resources: |
completion/bash,zsh,fish,powershell=exec:helmfile completion {shell}
skill/helmfile=repo:skills/helmfile