Skip to content

Commit 9dbcadd

Browse files
committed
ci: switch to SSH signing everywhere
Signed-off-by: William Woodruff <[email protected]>
1 parent c9331b9 commit 9dbcadd

File tree

6 files changed

+12
-19
lines changed

6 files changed

+12
-19
lines changed

.github/workflows/autobump.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -47,15 +47,15 @@ jobs:
4747
- name: Set up commit signing
4848
uses: Homebrew/actions/setup-commit-signing@master
4949
with:
50-
signing_key: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY }}
50+
ssh: true
51+
signing_key: ${{ secrets.BREWTESTBOT_SSH_SIGNING_KEY }}
5152

5253
- name: Bump formulae
5354
env:
5455
HOMEBREW_TEST_BOT_AUTOBUMP: 1
5556
HOMEBREW_GITHUB_API_TOKEN: ${{ secrets.HOMEBREW_CORE_REPO_WORKFLOW_TOKEN }}
5657
HOMEBREW_GIT_COMMITTER_NAME: BrewTestBot
5758
HOMEBREW_GIT_COMMITTER_EMAIL: [email protected]
58-
HOMEBREW_GPG_PASSPHRASE: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
5959
FORMULAE: ${{ inputs.formulae }}
6060
run: |
6161
BREW_BUMP=(brew bump --no-fork --open-pr --formulae)

.github/workflows/create-replacement-pr.yml

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -152,14 +152,14 @@ jobs:
152152
- name: Set up commit signing
153153
uses: Homebrew/actions/setup-commit-signing@master
154154
with:
155-
signing_key: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY }}
155+
ssh: true
156+
signing_key: ${{ secrets.BREWTESTBOT_SSH_SIGNING_KEY }}
156157

157158
- name: Pull PR
158159
id: pr-pull
159160
working-directory: ${{ steps.set-up-homebrew.outputs.repository-path }}
160161
env:
161162
BREWTESTBOT_NAME_EMAIL: "BrewTestBot <[email protected]>"
162-
HOMEBREW_GPG_PASSPHRASE: ${{ inputs.autosquash && secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
163163
HOMEBREW_GITHUB_API_TOKEN: ${{ secrets.HOMEBREW_CORE_PUBLIC_REPO_EMAIL_TOKEN }}
164164
MESSAGE: ${{ inputs.message }}
165165
AUTOSQUASH_FLAG: ${{ inputs.autosquash && '--autosquash' || '' }}
@@ -193,7 +193,6 @@ jobs:
193193
working-directory: ${{steps.pr-pull.outputs.bottle_path}}
194194
env:
195195
BREWTESTBOT_NAME_EMAIL: "BrewTestBot <[email protected]>"
196-
HOMEBREW_GPG_PASSPHRASE: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
197196
HOMEBREW_GITHUB_PACKAGES_USER: brewtestbot
198197
HOMEBREW_GITHUB_PACKAGES_TOKEN: ${{secrets.HOMEBREW_CORE_GITHUB_PACKAGES_TOKEN}}
199198
WARN_ON_UPLOAD_FAILURE_FLAG: ${{inputs.warn_on_upload_failure && '--warn-on-upload-failure' || ''}}
@@ -216,7 +215,6 @@ jobs:
216215
env:
217216
GIT_COMMITTER_NAME: ${{ steps.git-user-config.outputs.name }}
218217
GIT_COMMITTER_EMAIL: ${{ steps.git-user-config.outputs.email }}
219-
HOMEBREW_GPG_PASSPHRASE: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
220218

221219
- name: Open replacement pull request
222220
id: create-pr

.github/workflows/dispatch-build-bottle.yml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -233,7 +233,8 @@ jobs:
233233
- name: Set up commit signing
234234
uses: Homebrew/actions/setup-commit-signing@master
235235
with:
236-
signing_key: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY }}
236+
ssh: true
237+
signing_key: ${{ secrets.BREWTESTBOT_SSH_SIGNING_KEY }}
237238

238239
- name: Generate build provenance
239240
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
@@ -249,7 +250,6 @@ jobs:
249250
env:
250251
HOMEBREW_GITHUB_PACKAGES_USER: brewtestbot
251252
HOMEBREW_GITHUB_PACKAGES_TOKEN: ${{secrets.HOMEBREW_CORE_GITHUB_PACKAGES_TOKEN}}
252-
HOMEBREW_GPG_PASSPHRASE: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
253253
BREWTESTBOT_NAME_EMAIL: "BrewTestBot <[email protected]>"
254254
HOMEBREW_CORE_PATH: ${{steps.set-up-homebrew.outputs.repository-path}}
255255
working-directory: ${{ env.BOTTLES_DIR }}
@@ -267,7 +267,6 @@ jobs:
267267
env:
268268
GIT_COMMITTER_NAME: BrewTestBot
269269
GIT_COMMITTER_EMAIL: [email protected]
270-
HOMEBREW_GPG_PASSPHRASE: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
271270

272271
- name: Open PR with bottle commit
273272
id: create-pr

.github/workflows/dispatch-rebottle.yml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -170,7 +170,8 @@ jobs:
170170
- name: Set up commit signing
171171
uses: Homebrew/actions/setup-commit-signing@master
172172
with:
173-
signing_key: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY }}
173+
ssh: true
174+
signing_key: ${{ secrets.BREWTESTBOT_SSH_SIGNING_KEY }}
174175

175176
- name: Generate build provenance
176177
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
@@ -186,7 +187,6 @@ jobs:
186187
env:
187188
HOMEBREW_GITHUB_PACKAGES_USER: brewtestbot
188189
HOMEBREW_GITHUB_PACKAGES_TOKEN: ${{secrets.HOMEBREW_CORE_GITHUB_PACKAGES_TOKEN}}
189-
HOMEBREW_GPG_PASSPHRASE: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
190190
BREWTESTBOT_NAME_EMAIL: "BrewTestBot <[email protected]>"
191191
HOMEBREW_CORE_PATH: ${{steps.set-up-homebrew.outputs.repository-path}}
192192
working-directory: ${{ env.BOTTLES_DIR }}
@@ -204,7 +204,6 @@ jobs:
204204
env:
205205
GIT_COMMITTER_NAME: BrewTestBot
206206
GIT_COMMITTER_EMAIL: [email protected]
207-
HOMEBREW_GPG_PASSPHRASE: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
208207

209208
- name: Open PR with bottle commit
210209
id: create-pr

.github/workflows/publish-commit-bottles.yml

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -299,7 +299,8 @@ jobs:
299299
- name: Set up commit signing
300300
uses: Homebrew/actions/setup-commit-signing@master
301301
with:
302-
signing_key: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY }}
302+
ssh: true
303+
signing_key: ${{ secrets.BREWTESTBOT_SSH_SIGNING_KEY }}
303304

304305
- name: Checkout PR branch
305306
working-directory: ${{steps.set-up-homebrew.outputs.repository-path}}
@@ -312,7 +313,6 @@ jobs:
312313
working-directory: ${{steps.set-up-homebrew.outputs.repository-path}}
313314
env:
314315
BREWTESTBOT_NAME_EMAIL: "BrewTestBot <[email protected]>"
315-
HOMEBREW_GPG_PASSPHRASE: ${{ inputs.autosquash && secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
316316
HOMEBREW_GITHUB_API_TOKEN: ${{secrets.HOMEBREW_CORE_PUBLIC_REPO_EMAIL_TOKEN}}
317317
EXPECTED_SHA: ${{needs.check.outputs.head_sha}}
318318
LARGE_RUNNER: ${{inputs.large_runner}}
@@ -363,7 +363,6 @@ jobs:
363363
working-directory: ${{steps.pr-pull.outputs.bottle_path}}
364364
env:
365365
BREWTESTBOT_NAME_EMAIL: "BrewTestBot <[email protected]>"
366-
HOMEBREW_GPG_PASSPHRASE: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
367366
HOMEBREW_GITHUB_PACKAGES_USER: brewtestbot
368367
HOMEBREW_GITHUB_PACKAGES_TOKEN: ${{secrets.HOMEBREW_CORE_GITHUB_PACKAGES_TOKEN}}
369368
REPO_PATH: ${{steps.set-up-homebrew.outputs.repository-path}}
@@ -391,7 +390,6 @@ jobs:
391390
env:
392391
GIT_COMMITTER_NAME: BrewTestBot
393392
GIT_COMMITTER_EMAIL: [email protected]
394-
HOMEBREW_GPG_PASSPHRASE: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
395393

396394
- name: Add CI-published-bottle-commits label
397395
run: gh pr edit --add-label CI-published-bottle-commits "$PR" --repo "$GITHUB_REPOSITORY"

.github/workflows/remove-disabled-packages.yml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,8 @@ jobs:
5252
- name: Set up commit signing
5353
uses: Homebrew/actions/setup-commit-signing@master
5454
with:
55-
signing_key: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY }}
55+
ssh: true
56+
signing_key: ${{ secrets.BREWTESTBOT_SSH_SIGNING_KEY }}
5657

5758
- name: Checkout removal branch
5859
run: git checkout -b "$REMOVAL_BRANCH" origin/master
@@ -62,7 +63,6 @@ jobs:
6263
id: remove_disabled
6364
uses: Homebrew/actions/remove-disabled-packages@master
6465
env:
65-
HOMEBREW_GPG_PASSPHRASE: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
6666
HOMEBREW_EVAL_ALL: 1
6767

6868
- name: Push commits
@@ -75,7 +75,6 @@ jobs:
7575
env:
7676
GIT_COMMITTER_NAME: ${{ steps.git-user-config.outputs.name }}
7777
GIT_COMMITTER_EMAIL: ${{ steps.git-user-config.outputs.email }}
78-
HOMEBREW_GPG_PASSPHRASE: ${{ secrets.BREWTESTBOT_GPG_SIGNING_SUBKEY_PASSPHRASE }}
7978

8079
- name: Create pull request
8180
if: fromJson(steps.remove_disabled.outputs.packages-removed)

0 commit comments

Comments
 (0)