Merge pull request #1166 from nupplaphil/feat/drone_sha512

Sign drone artifacts per GPG
pull/1167/head
Hypolite Petovan 2021-09-08 16:24:41 -04:00 committed by GitHub
commit 28e70485c5
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 26 additions and 2 deletions

View File

@ -126,9 +126,21 @@ steps:
- cd ./build - cd ./build
- sha256sum "$ARTIFACT" > "$ARTIFACT.sum256" - sha256sum "$ARTIFACT" > "$ARTIFACT.sum256"
- ls -lh - ls -lh
- # output the sha256 sum for checking purpose - # output the sha256 sum for checking
- cat "$ARTIFACT.sum256" - cat "$ARTIFACT.sum256"
- sha256sum "$ARTIFACT" - sha256sum "$ARTIFACT"
- name: Sign artifacts
image: plugins/gpgsign
settings:
key:
from_secret: gpg_key
passphrase:
from_secret: gpg_password
files:
- build/*
exclude:
- build/*.sum256
detach_sign: true
- name: Upload artifacts - name: Upload artifacts
image: alpine image: alpine
environment: environment:
@ -218,9 +230,21 @@ steps:
- cd ./build - cd ./build
- sha256sum "$ARTIFACT" > "$ARTIFACT.sum256" - sha256sum "$ARTIFACT" > "$ARTIFACT.sum256"
- ls -lh - ls -lh
- # output the sha256 sum for checking purpose - # output the sha256 sum for checking
- cat "$ARTIFACT.sum256" - cat "$ARTIFACT.sum256"
- sha256sum "$ARTIFACT" - sha256sum "$ARTIFACT"
- name: Sign artifacts
image: plugins/gpgsign
settings:
key:
from_secret: gpg_key
passphrase:
from_secret: gpg_password
files:
- build/*
exclude:
- build/*.sum256
detach_sign: true
- name: Upload artifacts - name: Upload artifacts
image: alpine image: alpine
environment: environment: