From 5d901f8ac18dd9356a35d0afa04302270206ff8d Mon Sep 17 00:00:00 2001 From: jdx <216188+jdx@users.noreply.github.com> Date: Mon, 28 Sep 2026 08:49:35 -0500 Subject: [PATCH] ci: publish a signed packslip with each release (#2809) * ci: publish a signed packslip with each release Add a job after goreleaser that publishes a packslip.sigstore.json to tag releases: a manifest of the release archives, the helmfile executable in each, shell completions via `helmfile completion`, and the skills/helmfile agent skill at the release commit, signed keylessly with this workflow's OIDC identity and linked to build provenance. Co-Authored-By: Claude Opus 5.5 Signed-off-by: jdx <216188+jdx@users.noreply.github.com> * ci: include the 386 archives in the packslip packslip 1.4.0 reads goreleaser's 386 as i686 and leaves libc out for static Linux builds, so every archive can be listed. Co-Authored-By: Claude Opus 5.5 Signed-off-by: jdx <216188+jdx@users.noreply.github.com> --------- Signed-off-by: jdx <216188+jdx@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 --- .github/workflows/releaser.yaml | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/.github/workflows/releaser.yaml b/.github/workflows/releaser.yaml index 2cd17606..ac944547 100644 --- a/.github/workflows/releaser.yaml +++ b/.github/workflows/releaser.yaml @@ -45,3 +45,24 @@ jobs: with: version: latest args: release --clean ${{ env.SNAPSHOT }} + + # Publish a signed packslip (https://packslip.dev) listing each archive's + # digest, the helmfile executable inside it, its shell completions, and the + # skill in skills/helmfile, signed with this workflow's identity so + # installers can verify a download without a key this project must hold. + packslip: + needs: goreleaser + if: startsWith(github.ref, 'refs/tags/v') + runs-on: ubuntu-latest + permissions: + contents: write + id-token: write + attestations: write + steps: + - uses: jdx/packslip@v1 + with: + download: helmfile_*.tar.gz + bin: helmfile + resources: | + completion/bash,zsh,fish,powershell=exec:helmfile completion {shell} + skill/helmfile=repo:skills/helmfile