diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 43d49ae..2acfe56 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -15,11 +15,20 @@ jobs: contents: write steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: fetch-depth: 0 persist-credentials: false + - name: Write RPM signing key + env: + RPM_SIGNING_KEY: ${{ secrets.RPM_SIGNING_KEY }} + run: | + set -euo pipefail + test -n "$RPM_SIGNING_KEY" + umask 077 + printf '%s\n' "$RPM_SIGNING_KEY" > "$RUNNER_TEMP/rpm-signing-key.asc" + - name: Set up Go uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 with: @@ -35,7 +44,9 @@ jobs: uses: goreleaser/goreleaser-action@5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89 # v7.2.2 with: distribution: goreleaser - version: '~> v2' + version: v2.16.0 args: release --clean env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GPG_KEY_PATH: ${{ runner.temp }}/rpm-signing-key.asc + NFPM_PASSPHRASE: ${{ secrets.NFPM_PASSPHRASE }} diff --git a/.github/workflows/test.yaml b/.github/workflows/test.yaml index 79b7467..2876bd6 100644 --- a/.github/workflows/test.yaml +++ b/.github/workflows/test.yaml @@ -33,7 +33,7 @@ jobs: - ubuntu-24.04-arm steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: persist-credentials: false diff --git a/.goreleaser.yaml b/.goreleaser.yaml index 325a3a2..08249d1 100644 --- a/.goreleaser.yaml +++ b/.goreleaser.yaml @@ -83,10 +83,11 @@ nfpms: - prec - precd description: |- - prec command execution logger (includes prec and precd) + prec is a Linux command execution observability tool maintainer: Jun Futagawa license: Apache-2.0 vendor: prec project + homepage: https://github.com/jfut/prec bindir: /usr/bin section: utils formats: @@ -95,6 +96,9 @@ nfpms: - rpm - termux.deb - archlinux + rpm: + signature: + key_file: '{{ with index .Env "GPG_KEY_PATH" }}{{ . }}{{ end }}' contents: - src: /usr/bin/precd dst: /usr/sbin/precd diff --git a/README.md b/README.md index 6fab2b1..3c25311 100644 --- a/README.md +++ b/README.md @@ -449,10 +449,13 @@ Generated files are stored in `dist/`: ## Release -1. Run `git tag -s vX.Y.Z -m vX.Y.Z` and wait for the Release to be created. -2. Edit the created Release. -3. Press the `Generate release notes` button and edit the release notes. -4. Press the `Update release` button. +GitHub Actions signs RPM artifacts with the GPG private key stored in `RPM_SIGNING_KEY`. If the key has a passphrase, store it in `NFPM_PASSPHRASE`. + +1. Run `git tag -s vX.Y.Z -m vX.Y.Z`. +2. Run `git push origin vX.Y.Z` and wait for the Release to be created. +3. Edit the created Release. +4. Press the `Generate release notes` button and edit the release notes. +5. Press the `Update release` button. ## License