Skip to content

Commit f6a3e29

Browse files
authored
ci: sign & notarize macos binaries (#494)
signs and notarizes macos binaries on releases and nightlies
1 parent 597d932 commit f6a3e29

File tree

2 files changed

+12
-0
lines changed

2 files changed

+12
-0
lines changed

.github/workflows/goreleaser.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,5 @@
1+
# yaml-language-server: $schema=https://json.schemastore.org/github-workflow.json
2+
13
name: goreleaser
24

35
on:
@@ -21,6 +23,11 @@ jobs:
2123
fury_token: ${{ secrets.FURY_TOKEN }}
2224
nfpm_gpg_key: ${{ secrets.NFPM_GPG_KEY }}
2325
nfpm_passphrase: ${{ secrets.NFPM_PASSPHRASE }}
26+
macos_sign_p12: ${{ secrets.MACOS_SIGN_P12 }}
27+
macos_sign_password: ${{ secrets.MACOS_SIGN_PASSWORD }}
28+
macos_notary_issuer_id: ${{ secrets.MACOS_NOTARY_ISSUER_ID }}
29+
macos_notary_key_id: ${{ secrets.MACOS_NOTARY_KEY_ID }}
30+
macos_notary_key: ${{ secrets.MACOS_NOTARY_KEY }}
2431
homebrew:
2532
name: Bump Homebrew formula
2633
runs-on: ubuntu-latest

.github/workflows/nightly.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,3 +12,8 @@ jobs:
1212
docker_username: ${{ secrets.DOCKERHUB_USERNAME }}
1313
docker_token: ${{ secrets.DOCKERHUB_TOKEN }}
1414
goreleaser_key: ${{ secrets.GORELEASER_KEY }}
15+
macos_sign_p12: ${{ secrets.MACOS_SIGN_P12 }}
16+
macos_sign_password: ${{ secrets.MACOS_SIGN_PASSWORD }}
17+
macos_notary_issuer_id: ${{ secrets.MACOS_NOTARY_ISSUER_ID }}
18+
macos_notary_key_id: ${{ secrets.MACOS_NOTARY_KEY_ID }}
19+
macos_notary_key: ${{ secrets.MACOS_NOTARY_KEY }}

0 commit comments

Comments
 (0)