Skip to content

Commit e3facc5

Browse files
committed
release: use custom Sign.Cli tool for signing
Use our customised version of the dotnet/sign tool for Trusted Signing, including export of the certificate.
1 parent c724c8d commit e3facc5

File tree

1 file changed

+12
-26
lines changed

1 file changed

+12
-26
lines changed

.github/workflows/release.yml

Lines changed: 12 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -353,27 +353,20 @@ jobs:
353353
env:
354354
AST: ${{ secrets.AZURE_STORAGE_ACCOUNT }}
355355
ASC: ${{ secrets.AZURE_STORAGE_CONTAINER }}
356-
SCT: ${{ secrets.SIGN_CLI_TOOL }}
356+
SCT: 'Sign.Cli-alpha.zip'
357357
run: |
358358
az storage blob download --file sign-cli.zip --auth-mode login `
359359
--account-name $env:AST --container-name $env:ASC --name $env:SCT
360360
Expand-Archive -Path sign-cli.zip -DestinationPath .\sign-cli
361361
362362
- name: Sign payload
363-
env:
364-
ACST: ${{ secrets.AZURE_TENANT_ID }}
365-
ACSI: ${{ secrets.AZURE_CLIENT_ID }}
366-
ACSS: ${{ secrets.AZURE_CLIENT_SECRET }}
367363
run: |
368-
./sign-cli/sign.exe code azcodesign payload/* `
369-
-acsu https://wus2.codesigning.azure.net/ `
370-
-acsa git-fundamentals-signing `
371-
-acscp git-fundamentals-windows-signing `
364+
./sign-cli/sign.exe code trusted-signing payload/* `
365+
-tse https://wus2.codesigning.azure.net/ `
366+
-tsa git-fundamentals-signing `
367+
-tscp git-fundamentals-windows-signing `
372368
-d "Git Fundamentals Windows Signing Certificate" `
373-
-u "https://github.com/git-ecosystem/git-credential-manager" `
374-
-acst $env:ACST `
375-
-acsi $env:ACSI `
376-
-acss $env:ACSS
369+
-u "https://github.com/git-ecosystem/git-credential-manager"
377370
378371
- name: Lay out signed payload, images, and symbols
379372
shell: bash
@@ -444,28 +437,21 @@ jobs:
444437
env:
445438
AST: ${{ secrets.AZURE_STORAGE_ACCOUNT }}
446439
ASC: ${{ secrets.AZURE_STORAGE_CONTAINER }}
447-
SCT: ${{ secrets.SIGN_CLI_TOOL }}
440+
SCT: 'Sign.Cli-alpha.zip'
448441
run: |
449442
az storage blob download --file sign-cli.zip --auth-mode login `
450443
--account-name $env:AST --container-name $env:ASC --name $env:SCT
451444
Expand-Archive -Path sign-cli.zip -DestinationPath .\sign-cli
452445
453446
- name: Sign package
454-
env:
455-
ACST: ${{ secrets.AZURE_TENANT_ID }}
456-
ACSI: ${{ secrets.AZURE_CLIENT_ID }}
457-
ACSS: ${{ secrets.AZURE_CLIENT_SECRET }}
458447
run: |
459-
./sign-cli/sign.exe code azcodesign nupkg/* `
460-
-acsu https://wus2.codesigning.azure.net/ `
461-
-acsa git-fundamentals-signing `
462-
-acscp git-fundamentals-windows-signing `
448+
./sign-cli/sign.exe code trusted-signing nupkg/* `
449+
-tse https://wus2.codesigning.azure.net/ `
450+
-tsa git-fundamentals-signing `
451+
-tscp git-fundamentals-windows-signing `
463452
-d "Git Fundamentals Windows Signing Certificate" `
464453
-u "https://github.com/git-ecosystem/git-credential-manager" `
465-
-acst $env:ACST `
466-
-acsi $env:ACSI `
467-
-acss $env:ACSS `
468-
-acsc nuget-signing-certificate.cer
454+
-co nuget-signing-certificate.cer
469455
470456
mv nupkg/* .
471457

0 commit comments

Comments
 (0)