mirror of
https://github.com/ko-build/ko.git
synced 2026-06-18 20:14:08 +02:00
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.5.2 to 3.5.3. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/8e5e7e5ab8b370d6c329ec480221332ada57f0ab...c85c95e3d7251135ab7dc9ce3241c5835cc595a9) --- updated-dependencies: - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
145 lines
4.6 KiB
YAML
145 lines
4.6 KiB
YAML
name: goreleaser
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- '*'
|
|
|
|
jobs:
|
|
goreleaser:
|
|
outputs:
|
|
hashes: ${{ steps.hash.outputs.hashes }}
|
|
tag_name: ${{ steps.tag.outputs.tag_name }}
|
|
|
|
permissions:
|
|
packages: write
|
|
id-token: write
|
|
contents: write
|
|
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
|
|
|
|
- run: git fetch --prune --unshallow
|
|
|
|
- uses: actions/setup-go@fac708d6674e30b6ba41289acaab6d4b75aa0753 # v4.0.1
|
|
with:
|
|
go-version: '1.20'
|
|
check-latest: true
|
|
|
|
# This installs the current latest release.
|
|
- uses: ko-build/setup-ko@ace48d793556083a76f1e3e6068850c1f4a369aa # v0.6
|
|
|
|
- uses: imjasonh/setup-crane@00c9e93efa4e1138c9a7a5c594acd6c75a2fbf0c # v0.3
|
|
|
|
- uses: sigstore/cosign-installer@dd6b2e2b610a11fd73dd187a43d57cc1394e35f9 # v3.0.5
|
|
|
|
- name: Set tag output
|
|
id: tag
|
|
run: echo "tag_name=${GITHUB_REF#refs/*/}" >> "$GITHUB_OUTPUT"
|
|
|
|
- uses: goreleaser/goreleaser-action@f82d6c1c344bcacabba2c841718984797f664a6b # v4.2.0
|
|
id: run-goreleaser
|
|
with:
|
|
version: latest
|
|
args: release --clean
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: sign ko-image
|
|
run: |
|
|
digest=$(crane digest "${REGISTRY}":"${GIT_TAG}")
|
|
cosign sign --yes \
|
|
-a GIT_HASH="${GIT_HASH}" \
|
|
-a GIT_TAG="${GIT_TAG}" \
|
|
-a RUN_ID="${RUN_ID}" \
|
|
-a RUN_ATTEMPT="${RUN_ATTEMPT}" \
|
|
"${REGISTRY}@${digest}"
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
GIT_HASH: ${{ github.sha }}
|
|
GIT_TAG: ${{ steps.tag.outputs.tag_name }}
|
|
RUN_ATTEMPT: ${{ github.run_attempt }}
|
|
RUN_ID: ${{ github.run_id }}
|
|
REGISTRY: "ghcr.io/${{ github.repository }}"
|
|
|
|
- name: Generate subject
|
|
id: hash
|
|
env:
|
|
ARTIFACTS: "${{ steps.run-goreleaser.outputs.artifacts }}"
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
checksum_file=$(echo "$ARTIFACTS" | jq -r '.[] | select (.type=="Checksum") | .path')
|
|
echo "hashes=$(cat $checksum_file | base64 -w0)" >> "$GITHUB_OUTPUT"
|
|
|
|
provenance:
|
|
needs:
|
|
- goreleaser
|
|
|
|
permissions:
|
|
actions: read # To read the workflow path.
|
|
id-token: write # To sign the provenance.
|
|
contents: write # To add assets to a release.
|
|
|
|
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v1.6.0
|
|
with:
|
|
base64-subjects: "${{ needs.goreleaser.outputs.hashes }}"
|
|
upload-assets: true
|
|
upload-tag-name: "${{ needs.release.outputs.tag_name }}"
|
|
|
|
verification:
|
|
needs:
|
|
- goreleaser
|
|
- provenance
|
|
|
|
runs-on: ubuntu-latest
|
|
permissions: read-all
|
|
|
|
steps:
|
|
# Note: this will be replaced with the GHA in the future.
|
|
- name: Install the verifier
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
gh -R slsa-framework/slsa-verifier release download v1.3.2 -p "slsa-verifier-linux-amd64"
|
|
chmod ug+x slsa-verifier-linux-amd64
|
|
# Note: see https://github.com/slsa-framework/slsa-verifier/blob/main/SHA256SUM.md
|
|
COMPUTED_HASH=$(sha256sum slsa-verifier-linux-amd64 | cut -d ' ' -f1)
|
|
EXPECTED_HASH="b1d6c9bbce6274e253f0be33158cacd7fb894c5ebd643f14a911bfe55574f4c0"
|
|
if [[ "$EXPECTED_HASH" != "$COMPUTED_HASH" ]];then
|
|
echo "error: expected $EXPECTED_HASH, computed $COMPUTED_HASH"
|
|
exit 1
|
|
fi
|
|
|
|
- name: Download assets
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
PROVENANCE: "${{ needs.provenance.outputs.provenance-name }}"
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
gh -R "$GITHUB_REPOSITORY" release download "$GITHUB_REF_NAME" -p "*.tar.gz"
|
|
gh -R "$GITHUB_REPOSITORY" release download "$GITHUB_REF_NAME" -p "$PROVENANCE"
|
|
|
|
- name: Verify assets
|
|
env:
|
|
CHECKSUMS: ${{ needs.goreleaser.outputs.hashes }}
|
|
PROVENANCE: "${{ needs.provenance.outputs.provenance-name }}"
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
checksums=$(echo "$CHECKSUMS" | base64 -d)
|
|
while read -r line; do
|
|
fn=$(echo $line | cut -d ' ' -f2)
|
|
|
|
echo "Verifying $fn"
|
|
./slsa-verifier-linux-amd64 -artifact-path "$fn" \
|
|
-provenance "$PROVENANCE" \
|
|
-source "github.com/$GITHUB_REPOSITORY" \
|
|
-tag "$GITHUB_REF_NAME"
|
|
|
|
done <<<"$checksums"
|