Skip to content

Commit 1175d22

Browse files
authored
Merge pull request #760 from sigstore/update-post11
Update post 0.11.0 release
2 parents d2da726 + cc1c65d commit 1175d22

File tree

4 files changed

+26
-11
lines changed

4 files changed

+26
-11
lines changed

build-logic/publishing/build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,6 @@ dependencies {
1010
implementation(project(":basics"))
1111
implementation(project(":jvm"))
1212
implementation("dev.sigstore.build-logic:gradle-plugin")
13-
implementation("dev.sigstore:sigstore-gradle-sign-plugin:0.10.0")
13+
implementation("dev.sigstore:sigstore-gradle-sign-plugin:0.11.0")
1414
implementation("com.gradle.plugin-publish:com.gradle.plugin-publish.gradle.plugin:1.2.1")
1515
}

gradle.properties

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,4 +7,4 @@ group=dev.sigstore
77
# remember to also update version in
88
# - SigstoreSignExtension.kt
99
# - build-logic/publishing/build.gradle.kts
10-
version=0.11.0
10+
version=0.12.0

sigstore-gradle/sigstore-gradle-sign-base-plugin/src/main/kotlin/dev/sigstore/sign/SigstoreSignExtension.kt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ abstract class SigstoreSignExtension(private val project: Project) {
4444
abstract val sigstoreJavaVersion : Property<String>
4545

4646
init {
47-
sigstoreJavaVersion.convention("0.11.0")
47+
sigstoreJavaVersion.convention("0.12.0")
4848
(this as ExtensionAware).extensions.create<OidcClientExtension>(
4949
"oidcClient",
5050
project.objects,

sigstore-maven-plugin/README.md

Lines changed: 23 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,19 +1,21 @@
1-
sigstore-maven-plugin
2-
=====================
1+
# sigstore-maven-plugin
32

43
[![Maven Central](https://img.shields.io/maven-central/v/dev.sigstore/sigstore-maven-plugin.svg?label=Maven%20Central)](https://central.sonatype.com/artifact/dev.sigstore/sigstore-maven-plugin)
54

6-
This is a Maven plugin that can be used to use the "keyless" signing paradigm supported by Sigstore.
7-
This plugin is still in early phases, then has known limitations described below.
5+
A Maven plugin for signing artifacts with Sigstore
86

9-
sign
10-
----
7+
8+
## Requirements
9+
10+
* Java 11 (https://github.com/sigstore/sigstore-java requires Java 11)
11+
12+
## Minimal usage
1113

1214
```xml
1315
<plugin>
1416
<groupId>dev.sigstore</groupId>
1517
<artifactId>sigstore-maven-plugin</artifactId>
16-
<version>0.4.0</version>
18+
<version>0.11.0</version>
1719
<executions>
1820
<execution>
1921
<id>sign</id>
@@ -25,9 +27,22 @@ sign
2527
</plugin>
2628
```
2729

30+
### GitHub Actions OIDC support
31+
32+
In order for the required environment variables to be available, the workflow requires the following permissions:
33+
34+
```yaml
35+
permissions:
36+
id-token: write
37+
contents: read
38+
```
39+
40+
See [GitHub documentation](https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-cloud-providers#adding-permissions-settings) for details.
41+
42+
2843
Notes:
2944
30-
- GPG: Maven Central publication rules require GPG signing each files: to avoid GPG signing of `.sigstore.json` files, just use version 3.1.0 minimum of [maven-gpg-plugin](https://maven.apache.org/plugins/maven-gpg-plugin/).
45+
<!-- TBD: (uncomment when gpg adding exclusion from .sigstore.java - GPG: Maven Central publication rules require GPG signing each files: to avoid GPG signing of `.sigstore.json` files, just use version 3.X.X minimum of [maven-gpg-plugin](https://maven.apache.org/plugins/maven-gpg-plugin/). -->
3146
- `.md5`/`.sha1`: to avoid unneeded checksum files for `.sigstore.java` files, use Maven 3.9.2 minimum or create `.mvn/maven.config` file containing `-Daether.checksums.omitChecksumsForExtensions=.asc,.sigstore.java`
3247

3348
Known limitations:

0 commit comments

Comments
 (0)