Skip to content

Commit

Permalink
Sign releases with pgp
Browse files Browse the repository at this point in the history
Closes: #131
  • Loading branch information
sayanarijit committed Jun 5, 2021
1 parent 902f20a commit 992360d
Show file tree
Hide file tree
Showing 4 changed files with 41 additions and 16 deletions.
44 changes: 34 additions & 10 deletions .github/workflows/cd.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,6 @@ jobs:
os:
- macos-latest
- ubuntu-latest
# - windows-latest
rust: [stable]
include:
- os: macos-latest
Expand All @@ -26,10 +25,6 @@ jobs:
artifact_prefix: linux
target: x86_64-unknown-linux-gnu
binary_postfix: ""
# - os: windows-latest
# artifact_prefix: windows
# target: x86_64-pc-windows-msvc
# binary_postfix: ".exe"

steps:
- name: Installing Rust toolchain
Expand All @@ -54,6 +49,11 @@ jobs:
toolchain: ${{ matrix.rust }}
args: --locked --release --target ${{ matrix.target }}

- name: Install gpg secret key
run: |
cat <(echo -e "${{ secrets.GPG_SECRET }}") | gpg --batch --import
gpg --list-secret-keys --keyid-format LONG
- name: Packaging final binary
shell: bash
run: |
Expand All @@ -62,20 +62,44 @@ jobs:
strip $BINARY_NAME
RELEASE_NAME=xplr-${{ matrix.artifact_prefix }}
tar czvf $RELEASE_NAME.tar.gz $BINARY_NAME
if [[ ${{ runner.os }} == 'Windows' ]]; then
certutil -hashfile $RELEASE_NAME.tar.gz sha256 | grep -E [A-Fa-f0-9]{64} > $RELEASE_NAME.sha256
else
shasum -a 256 $RELEASE_NAME.tar.gz > $RELEASE_NAME.sha256
fi
shasum -a 256 $RELEASE_NAME.tar.gz > $RELEASE_NAME.sha256
cat <(echo "${{ secrets.GPG_PASS }}") | gpg --pinentry-mode loopback --passphrase-fd 0 --detach-sign --armor $RELEASE_NAME.tar.gz
- name: Releasing assets
uses: softprops/action-gh-release@v1
with:
files: |
target/${{ matrix.target }}/release/xplr-${{ matrix.artifact_prefix }}.tar.gz
target/${{ matrix.target }}/release/xplr-${{ matrix.artifact_prefix }}.sha256
target/${{ matrix.target }}/release/xplr-${{ matrix.artifact_prefix }}.tar.gz.asc
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

publish-gpg-signature:
name: Publishing GPG signature
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@master
- name: Install gpg secret key
run: |
cat <(echo -e "${{ secrets.GPG_SECRET }}") | gpg --batch --import
gpg --list-secret-keys --keyid-format LONG
- name: Signing archive with GPG
run: |
TAG=${GITHUB_REF##*/}
git archive -o xplr-${TAG:?}.tar.gz --format tar.gz --prefix "xplr-${TAG:?}/" "v${TAG}"
cat <(echo "${{ secrets.GPG_PASS }}") | gpg --detach-sign --armor "xplr-${TAG:?}.tar.gz"
- name: Releasing GPG signature
uses: softprops/action-gh-release@v1
with:
files: |
xplr-${GITHUB_REF##*/}.tar.gz.asc
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}


publish-cargo:
name: Publishing to Cargo
runs-on: ubuntu-latest
Expand Down
2 changes: 1 addition & 1 deletion Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "xplr"
version = "0.13.1" # Update lua.rs
version = "0.13.2" # Update lua.rs
authors = ["Arijit Basu <sayanarijit@gmail.com>"]
edition = "2018"
description = "A hackable, minimal, fast TUI file explorer"
Expand Down
9 changes: 5 additions & 4 deletions src/lua.rs
Original file line number Diff line number Diff line change
Expand Up @@ -133,10 +133,11 @@ mod test {
assert!(check_version(VERSION, "foo path").is_ok());
assert!(check_version("0.13.0", "foo path").is_ok());
assert!(check_version("0.13.1", "foo path").is_ok());
assert!(check_version("0.13.2", "foo path").is_ok());

assert!(check_version("0.13.2", "foo path").is_err());
assert!(check_version("0.14.1", "foo path").is_err());
assert!(check_version("0.11.1", "foo path").is_err());
assert!(check_version("1.13.1", "foo path").is_err());
assert!(check_version("0.13.3", "foo path").is_err());
assert!(check_version("0.14.2", "foo path").is_err());
assert!(check_version("0.11.2", "foo path").is_err());
assert!(check_version("1.13.2", "foo path").is_err());
}
}

0 comments on commit 992360d

Please sign in to comment.