Skip to content

Commit 82f4abc

Browse files
committed
Sign before upload
[skip ci]
1 parent 823cbf3 commit 82f4abc

File tree

1 file changed

+18
-16
lines changed

1 file changed

+18
-16
lines changed

.github/workflows/release-gradle.yml

Lines changed: 18 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -153,13 +153,29 @@ jobs:
153153
ORG_GRADLE_PROJECT_compose.desktop.mac.notarization.password: ${{ secrets.PROCESSING_APP_PASSWORD }}
154154
ORG_GRADLE_PROJECT_compose.desktop.mac.notarization.teamID: ${{ secrets.PROCESSING_TEAM_ID }}
155155
ORG_GRADLE_PROJECT_snapname: ${{ vars.SNAP_NAME }}
156+
157+
- name: Sign files with Trusted Signing
158+
if: runner.os == 'Windows'
159+
uses: azure/trusted-signing-action@v0
160+
with:
161+
azure-tenant-id: ${{ secrets.AZURE_TENANT_ID }}
162+
azure-client-id: ${{ secrets.AZURE_CLIENT_ID }}
163+
azure-client-secret: ${{ secrets.AZURE_CLIENT_SECRET }}
164+
endpoint: https://eus.codesigning.azure.net/
165+
trusted-signing-account-name: ${{ secrets.AZURE_SIGNING_ACCOUNT_NAME }}
166+
certificate-profile-name: ${{ secrets.AZURE_CERTIFICATE_PROFILE_NAME }}
167+
files-folder: app/build/compose/binaries/main/msi
168+
files-folder-filter: msi
169+
file-digest: SHA256
170+
timestamp-rfc3161: http://timestamp.acs.microsoft.com
171+
timestamp-digest: SHA256
156172

157173
- name: Upload portables to release
158174
uses: svenstaro/upload-release-action@v2
159175
with:
160176
repo_token: ${{ secrets.GITHUB_TOKEN }}
161177
asset_name: processing-${{ needs.version.outputs.version }}-${{ matrix.os_prefix }}-${{ matrix.arch }}-portable.zip
162-
file: app/build/compose/binaries/main/Processing-${{ needs.version.outputs.version }}.zip
178+
file: app/build/compose/binaries/main/app
163179

164180
- name: Upload installers to release
165181
uses: svenstaro/upload-release-action@v2
@@ -174,18 +190,4 @@ jobs:
174190
env:
175191
SNAPCRAFT_STORE_CREDENTIALS: ${{ secrets.PROCESSING_SNAPCRAFT_TOKEN }}
176192

177-
- name: Sign files with Trusted Signing
178-
if: runner.os == 'Windows'
179-
uses: azure/trusted-signing-action@v0
180-
with:
181-
azure-tenant-id: ${{ secrets.AZURE_TENANT_ID }}
182-
azure-client-id: ${{ secrets.AZURE_CLIENT_ID }}
183-
azure-client-secret: ${{ secrets.AZURE_CLIENT_SECRET }}
184-
endpoint: https://eus.codesigning.azure.net/
185-
trusted-signing-account-name: ${{ secrets.AZURE_SIGNING_ACCOUNT_NAME }}
186-
certificate-profile-name: ${{ secrets.AZURE_CERTIFICATE_PROFILE_NAME }}
187-
files-folder: app/build/compose/binaries/main/msi
188-
files-folder-filter: msi
189-
file-digest: SHA256
190-
timestamp-rfc3161: http://timestamp.acs.microsoft.com
191-
timestamp-digest: SHA256
193+

0 commit comments

Comments
 (0)