Skip to content

Commit

Permalink
Update signing.yml
Browse files Browse the repository at this point in the history
  • Loading branch information
arcanis authored May 24, 2024
1 parent 4969908 commit 2e76969
Showing 1 changed file with 12 additions and 2 deletions.
14 changes: 12 additions & 2 deletions .github/workflows/signing.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,10 +23,16 @@ jobs:
passphrase: ${{ secrets.GPG_PASSPHRASE }}

- name: Downloading the release
run: wget https://github.com/yarnpkg/yarn/releases/download/v${{ inputs.version }}/yarn-v${{ inputs.version }}.tar.gz
run: |
wget https://github.com/yarnpkg/yarn/releases/download/v${{ inputs.version }}/yarn-v${{ inputs.version }}.tar.gz
wget https://github.com/yarnpkg/yarn/releases/download/v${{ inputs.version }}/yarn-${{ inputs.version }}.js
wget https://github.com/yarnpkg/yarn/releases/download/v${{ inputs.version }}/yarn-legacy-${{ inputs.version }}.js
- name: GPG sign file
run: gpg -u ${{ vars.GPG_RELEASE_KEY_ID }} --armor --output yarn-v${{ inputs.version }}.tar.gz.asc --detach-sign yarn-v${{ inputs.version }}.tar.gz
run: |
gpg -u ${{ vars.GPG_RELEASE_KEY_ID }} --armor --output yarn-v${{ inputs.version }}.tar.gz.asc --detach-sign yarn-v${{ inputs.version }}.tar.gz
gpg -u ${{ vars.GPG_RELEASE_KEY_ID }} --armor --output yarn-${{ inputs.version }}.js.asc --detach-sign yarn-${{ inputs.version }}.js
gpg -u ${{ vars.GPG_RELEASE_KEY_ID }} --armor --output yarn-legacy-${{ inputs.version }}.js.asc --detach-sign yarn-legacy-${{ inputs.version }}.js
- name: Store signature as artifact
uses: actions/upload-artifact@v3
Expand All @@ -35,3 +41,7 @@ jobs:
path: |
yarn-v${{ inputs.version }}.tar.gz
yarn-v${{ inputs.version }}.tar.gz.asc
yarn-v${{ inputs.version }}.js
yarn-v${{ inputs.version }}.js.asc
yarn-legacy-${{ inputs.version }}.js
yarn-legacy-${{ inputs.version }}.js.asc

1 comment on commit 2e76969

@rzr
Copy link

@rzr rzr commented on 2e76969 Jan 18, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why can't it done without download files insecurely ?
I would use gh release download instead of wget

FYI: softprops/action-gh-release#580

Please sign in to comment.