Skip to content

Commit 06f4497

Browse files
committed
Switching to correct tool
1 parent 51178b4 commit 06f4497

File tree

1 file changed

+17
-12
lines changed

1 file changed

+17
-12
lines changed

.github/workflows/ci.yml

Lines changed: 17 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -58,21 +58,26 @@ jobs:
5858
8.0.x
5959
9.0.x
6060
10.0.x
61-
- name: Install AzureSignTool
62-
run: dotnet tool install --global AzureSignTool
61+
- name: Install NuGetKeyVaultSignTool
62+
run: dotnet tool install --global NuGetKeyVaultSignTool
6363
- name: Build and Test
6464
run: ./Build.ps1
6565
shell: pwsh
66-
- name: Sign package
67-
run: |
68-
AzureSignTool sign `
69-
--azure-key-vault-url ${{ secrets.AZURE_KEYVAULT_URI }} `
70-
--azure-key-vault-client-id ${{ secrets.AZURE_CLIENT_ID }} `
71-
--azure-key-vault-tenant-id ${{ secrets.AZURE_TENANT_ID }} `
72-
--azure-key-vault-certificate ${{ secrets.CODESIGN_CERT_NAME }} `
73-
--description "AutoMapper" `
74-
--timestamp-url http://timestamp.digicert.com `
75-
./artifacts/*.nupkg
66+
- name: Sign packages
67+
if: github.event == 'push'
68+
run: |-
69+
for file in artifacts/*.nupkg; do
70+
dotnet NuGetKeyVaultSignTool sign "$file" --file-digest sha256 --timestamp-rfc3161 http://timestamp.digicert.com --azure-key-vault-managed-identity --azure-key-vault-url ${{ secrets.AZURE_KEYVAULT_URI }} --azure-key-vault-certificate ${{ secrets.CODESIGN_CERT_NAME }}
71+
done
72+
# - name: Sign package
73+
# run: |
74+
# NuGetKeyVaultSignTool sign `
75+
# --azure-key-vault-managed-identity `
76+
# --azure-key-vault-url ${{ secrets.AZURE_KEYVAULT_URI }} `
77+
# --azure-key-vault-certificate ${{ secrets.CODESIGN_CERT_NAME }} `
78+
# --description "AutoMapper" `
79+
# --timestamp-url http://timestamp.digicert.com `
80+
# ./artifacts/*.nupkg
7681
- name: Push to MyGet
7782
if: github.ref == 'refs/heads/main'
7883
env:

0 commit comments

Comments
 (0)