Compare commits
@@ -6,6 +6,9 @@ name: Mirror version tag
|
||||
# pointing to the same object, so both forms exist.
|
||||
# No retrigger loop: the tag filter never matches a "v"-prefixed tag, and
|
||||
# refs created with GITHUB_TOKEN do not fire workflows anyway.
|
||||
# The job mirrors first and then fails when the pushed tag is lightweight,
|
||||
# which is what the release form produces: that tag can never carry a
|
||||
# signature, so the failure has to be loud.
|
||||
|
||||
on:
|
||||
push:
|
||||
@@ -26,19 +29,39 @@ jobs:
|
||||
REPO: ${{ github.repository }}
|
||||
TAG: ${{ github.ref_name }}
|
||||
run: |
|
||||
if gh api "repos/$REPO/git/ref/tags/v$TAG" >/dev/null 2>&1; then
|
||||
echo "Tag v$TAG already exists, nothing to do."
|
||||
exit 0
|
||||
fi
|
||||
# Mirror the object the pushed tag actually points at: the commit
|
||||
# for a lightweight tag, the tag object itself for an annotated or
|
||||
# signed one. Pointing the mirror at the commit would strip the
|
||||
# signature, so "git verify-tag v3.1.3" would fail while
|
||||
# "git verify-tag 3.1.3" succeeds.
|
||||
sha="$(gh api "repos/$REPO/git/ref/tags/$TAG" --jq .object.sha)"
|
||||
_ref="$(gh api "repos/$REPO/git/ref/tags/$TAG" --jq '.object.sha + " " + .object.type')"
|
||||
sha="${_ref%% *}"
|
||||
objtype="${_ref##* }"
|
||||
if [ -z "$sha" ] || [ "$sha" = "null" ]; then
|
||||
echo "Could not resolve refs/tags/$TAG"
|
||||
exit 1
|
||||
fi
|
||||
gh api "repos/$REPO/git/refs" -f ref="refs/tags/v$TAG" -f sha="$sha"
|
||||
echo "Created tag v$TAG -> $sha"
|
||||
if gh api "repos/$REPO/git/ref/tags/v$TAG" >/dev/null 2>&1; then
|
||||
echo "Tag v$TAG already exists, nothing to do."
|
||||
else
|
||||
gh api "repos/$REPO/git/refs" -f ref="refs/tags/v$TAG" -f sha="$sha"
|
||||
echo "Created tag v$TAG -> $sha"
|
||||
fi
|
||||
|
||||
- name: Check that the tag is signable
|
||||
env:
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
REPO: ${{ github.repository }}
|
||||
TAG: ${{ github.ref_name }}
|
||||
run: |
|
||||
# A release published from the GitHub UI creates the tag server-side
|
||||
# as a lightweight ref, which points straight at a commit and can
|
||||
# never carry a signature (3.1.5 shipped that way, see issue 7273).
|
||||
# The tag has to be created locally with "git tag -s" and pushed
|
||||
# BEFORE the release is published, then selected on the release form.
|
||||
objtype="$(gh api "repos/$REPO/git/ref/tags/$TAG" --jq .object.type)"
|
||||
if [ "$objtype" != "tag" ]; then
|
||||
echo "::error::refs/tags/$TAG points at a $objtype, not a tag object. It is a lightweight tag and carries no signature. Recreate it locally with 'git tag -s $TAG' and push it before publishing the release."
|
||||
exit 1
|
||||
fi
|
||||
echo "refs/tags/$TAG is a tag object."
|
||||
|
||||
@@ -233,7 +233,7 @@ acme.sh -h
|
||||
|
||||
#### 🔏 Verify a Release
|
||||
|
||||
Release tags from `3.1.5` on are signed with the maintainer's SSH key. The
|
||||
Release tags from `3.1.6` on are signed with the maintainer's SSH key. The
|
||||
signing happens on the maintainer's machine, so the private key is never
|
||||
available to CI. The public half is [`allowed_signers`](allowed_signers) in
|
||||
this repository. From a clone:
|
||||
@@ -243,7 +243,7 @@ git config gpg.ssh.allowedSignersFile allowed_signers
|
||||
```
|
||||
|
||||
```bash
|
||||
git verify-tag 3.1.5
|
||||
git verify-tag 3.1.6
|
||||
```
|
||||
|
||||
The signature covers the tag object, which pins the commit and therefore the
|
||||
@@ -251,10 +251,10 @@ whole tree, so a good signature verifies every file at that release and no
|
||||
separate tarball checksum is needed. Build a tarball from the verified tag:
|
||||
|
||||
```bash
|
||||
git archive --format=tar.gz --prefix=acme.sh-3.1.5/ 3.1.5 > acme.sh-3.1.5.tar.gz
|
||||
git archive --format=tar.gz --prefix=acme.sh-3.1.6/ 3.1.6 > acme.sh-3.1.6.tar.gz
|
||||
```
|
||||
|
||||
> ⚠️ Tags up to `3.1.4` predate the signing key and are unsigned.
|
||||
> ⚠️ Tags up to `3.1.5` are unsigned.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/env sh
|
||||
|
||||
VER=3.1.5
|
||||
VER=3.1.6
|
||||
|
||||
PROJECT_NAME="acme.sh"
|
||||
|
||||
|
||||
+4
-2
@@ -4,17 +4,19 @@
|
||||
# maintainer and is never available to CI, so a compromise of the build
|
||||
# pipeline cannot produce a tag that verifies against this file.
|
||||
#
|
||||
# Signing starts at 3.1.6; tags up to 3.1.5 are unsigned.
|
||||
#
|
||||
# Fingerprint: SHA256:M60qVafm/NUywQHXAkoQcj2v6KgkfrdSXv6mPejUUeE
|
||||
#
|
||||
# To verify a release tag, from a clone of this repository:
|
||||
#
|
||||
# git config gpg.ssh.allowedSignersFile allowed_signers
|
||||
# git verify-tag 3.1.5
|
||||
# git verify-tag 3.1.6
|
||||
#
|
||||
# A good signature covers the tag object, which pins the commit, which pins
|
||||
# the whole tree -- so verifying the tag verifies every file at that
|
||||
# release. Build a tarball from the verified tag with:
|
||||
#
|
||||
# git archive --format=tar.gz --prefix=acme.sh-3.1.5/ 3.1.5 > acme.sh-3.1.5.tar.gz
|
||||
# git archive --format=tar.gz --prefix=acme.sh-3.1.6/ 3.1.6 > acme.sh-3.1.6.tar.gz
|
||||
#
|
||||
github@neilpang.com namespaces="git" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBTjI0HBJn3uhfT2DsNcFybfAZi3ADbIacMpz1BItKdB
|
||||
|
||||
Reference in New Issue
Block a user