You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The OpenSSF Best Practices Badge suggests signing release artifacts. Consider using OpenEXR's release-sign.yml workflow as a template. It's triggered on release creation and does these steps:
Runs get archive to generate a <release>.tar.gz artifact
Uploads the resulting sigstore signature file along with the tarball.
It looks like your release process already involves generating explicit tarballs, so your signing workflow won't need that step, but it will need to run sigstore on each of the artifacts.
The text was updated successfully, but these errors were encountered:
The OpenSSF Best Practices Badge suggests signing release artifacts. Consider using OpenEXR's release-sign.yml workflow as a template. It's triggered on release creation and does these steps:
get archive
to generate a<release>.tar.gz
artifact<release>.tar.gz
via sigstoreIt looks like your release process already involves generating explicit tarballs, so your signing workflow won't need that step, but it will need to run sigstore on each of the artifacts.
The text was updated successfully, but these errors were encountered: