Repository navigation
Releases: theQRL/actions-mldsa-sign
Release list
v2.0.0 — signed release manifests
Adds a signed release manifest binding each artifact's digest to its filename,
product and tag, so verifiers can establish which release a file is — not just
that it was signed.
Breaking: manifests are on by default. A context that does not end in
-release-signatures now fails unless product is set. Set manifest: '' for
v1 behaviour.
New inputs: product, tag, manifest, manifest-context.
backfill-manifest.sh signs a manifest for a release published before v2.
v1.0.0 — ML-DSA-87 post-quantum signing
actions-mldsa-sign
Initial public release of actions-mldsa-sign — a GitHub Action that signs build artifacts with ML-DSA-87 (FIPS 204) post-quantum signatures.
It supersedes actions-dilithium-sign, which is deprecated.
Usage
- uses: theQRL/actions-mldsa-sign@v1
with:
patterns: |
dist/*.zip
hexseed: ${{ secrets.MLDSA_HEXSEED }}
context: my-app-releases
output: signatures.txtInputs
| Input | Required | Default | Description |
|---|---|---|---|
hexseed |
Yes | – | ML-DSA hexseed used for signing — store it as a repository secret |
context |
Yes | – | Context string for FIPS 204 domain separation (0–255 bytes) |
patterns |
Yes | – | Glob patterns for files to sign, one per line |
output |
No | signatures.txt |
Path of the generated signatures file |
Output
One line per signed file, signature first:
<signature_hex> dist/artifact.zip
Before your first signed release
contextis effectively permanent. A signature only verifies under the exact context string that produced it, so choose a stable, application-specific value (e.g.myapp-release-signatures) before you publish anything signed.- Generate a fresh ML-DSA hexseed with qrlft:
qrlft new -a mldsa --context="my-app-releases" mykey. - Publish the matching public key (
mykey.pub) wherever your users can reach it, and verify your first signed release before announcing it.
Verifying
qrlft verify -a mldsa --context="my-app-releases" \
--signature=<sig_hex> --pkfile=mykey.pub artifact.zipExit code 0 and Signature is valid means the artifact is byte-for-byte what was signed. Note that --sigfile expects a file containing only a signature, so extract the relevant line from the signatures file first.
Notes
- Runs as a Docker action from
ghcr.io/theqrl/actions-mldsa-sign:v1.0.0, which bundles qrlft v4.0.0. - For supply-chain hardening, pin by commit SHA rather than by tag:
uses: theQRL/actions-mldsa-sign@97a05abefff417d595c28c7b5d9d886ebe2fe9d0 # v1.0.0
Migration guidance from actions-dilithium-sign is in the README.
Full Changelog: https://github.com/theQRL/actions-mldsa-sign/commits/v1.0.0