Skip to content

Commit 5f78337

Browse files
authored
chore: Changes signing app for NuGet (#325)
1 parent f1fafb5 commit 5f78337

File tree

1 file changed

+12
-7
lines changed

1 file changed

+12
-7
lines changed

.github/workflows/release.yml

Lines changed: 12 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -216,13 +216,18 @@ jobs:
216216
password: ${{ secrets.ARTIFACTORY_PASSWORD }}
217217
- name: Sign NuGet package
218218
run: |
219-
docker run \
220-
-e GRS_CONFIG_USER1_USERNAME="${{ secrets.ARTIFACTORY_SIGN_USER }}" \
221-
-e GRS_CONFIG_USER1_PASSWORD="${{ secrets.ARTIFACTORY_SIGN_PASSWORD }}" \
222-
--rm -v "$(pwd)":"$(pwd)" -w "$(pwd)" \
223-
"${{ secrets.ARTIFACTORY_REGISTRY }}/${{ secrets.ARTIFACTORY_SIGN_TOOL }}" \
224-
/bin/bash -c "jsign --tsaurl http://timestamp.digicert.com -a mongo-authenticode-2021 \
225-
./dist/dotnet/MongoDB.AWSCDKResourcesMongoDBAtlas.${{ steps.extract-version.outputs.VERSION }}.nupkg"
219+
docker run --platform="linux/amd64" --rm -v "$(pwd)":/workdir -w /workdir \
220+
artifactory.corp.mongodb.com/release-tools-container-registry-local/azure-keyvault-nuget \
221+
NuGetKeyVaultSignTool sign "dist/dotnet/MongoDB.AWSCDKResourcesMongoDBAtlas.${{ steps.extract-version.outputs.VERSION }}.nupkg" \
222+
--force \
223+
--file-digest=sha256 \
224+
--timestamp-rfc3161=http://timestamp.digicert.com \
225+
--timestamp-digest=sha256 \
226+
--azure-key-vault-url=https://mdb-authenticode.vault.azure.net \
227+
--azure-key-vault-tenant-id="${{ secrets.AZURE_NUGET_SIGN_TENANT_ID }}" \
228+
--azure-key-vault-client-secret="${{ secrets.AZURE_NUGET_SIGN_CLIENT_SECRET }}" \
229+
--azure-key-vault-client-id="${{ secrets.AZURE_NUGET_SIGN_CLIENT_ID }}" \
230+
--azure-key-vault-certificate=authenticode-2021
226231
- name: Release
227232
env:
228233
NUGET_API_KEY: ${{ secrets.NUGET_API_KEY }}

0 commit comments

Comments
 (0)