@@ -168,7 +168,7 @@ jobs:
168168 if : runner.os == 'Windows'
169169 shell : pwsh
170170 run : |
171- Copy-Item "build/Release/sine-win-$env:ARCH.exe" -Destination "unsigned/sine-installer .exe"
171+ Copy-Item "build/Release/sine-win-$env:ARCH.exe" -Destination "unsigned/sine-win-$env:ARCH-unsigned .exe"
172172 env :
173173 ARCH : ${{ matrix.arch }}
174174
@@ -178,49 +178,85 @@ jobs:
178178 uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
179179 with :
180180 name : sine-win-${{ matrix.arch }}-unsigned
181- path : unsigned/sine-installer .exe
181+ path : unsigned/sine-win-${{ matrix.arch }}-unsigned .exe
182182
183- - name : Submit signing request
184- if : matrix.os == 'windows '
185- uses : signpath/github-action-submit-signing-request@b9d91eadd323de506c0c81cf0c7fe7438f3360fd # v2.2
183+ - name : Upload Linux executable
184+ if : matrix.os == 'linux '
185+ uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
186186 with :
187- api-token : " ${{ secrets.SIGNPATH_API_TOKEN }}"
188- organization-id : " 1324b51a-cb3d-4d1e-aab7-27b1169bd402"
189- project-slug : " Sine"
190- signing-policy-slug : " release-signing"
191- github-artifact-id : " ${{ steps.upload-unsigned-artifact.outputs.artifact-id }}"
192- wait-for-completion : true
193- output-artifact-directory : " artifacts"
187+ name : sine-linux-${{ matrix.arch }}
188+ path : artifacts/sine-linux-${{ matrix.arch }}
194189
195- - name : Rename Windows signed artifact
196- if : matrix.os == 'windows'
197- shell : bash
198- run : mv "artifacts/sine-installer.exe" "artifacts/sine-win-${ARCH}.exe"
190+ - name : Upload macOS executable
191+ if : matrix.os == 'macos'
192+ uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
193+ with :
194+ name : sine-osx-${{ matrix.arch }}
195+ path : artifacts/sine-osx-${{ matrix.arch }}
196+
197+ post-build :
198+ runs-on : ubuntu-latest
199+ name : Handle post-build steps
200+ steps :
201+ - name : Check signing requirements
202+ id : status
199203 env :
200- ARCH : ${{ matrix.arch }}
204+ REF_NAME : ${{ github.ref_name }}
205+ run : |
206+ if [[ "$REF_NAME" == "main" ]]; then
207+ echo "should-sign=yes" >> $GITHUB_OUTPUT
208+ else
209+ echo "should-sign=no" >> $GITHUB_OUTPUT
210+ fi
211+
212+ - name : Download all artifacts
213+ if : steps.status.outputs.should-sign == 'yes'
214+ uses : actions/download-artifact@v8
201215
202216 - name : Attest artifacts
203217 uses : actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
204218 with :
205219 subject-path : artifacts/*
206220
207- - name : Upload Windows executable
208- if : matrix.os == 'windows'
209- uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
221+ - name : Attest unsigned executables
222+ uses : actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
210223 with :
211- name : sine-win-${{ matrix.arch }}
212- path : artifacts/sine-win-${{ matrix.arch }}.exe
224+ subject-path : unsigned/*
213225
214- - name : Upload Linux executable
215- if : matrix.os == 'linux'
226+ - name : Upload Windows artifacts (for code signing)
227+ if : steps.status.outputs.should-sign == 'yes'
228+ id : upload-unsigned-zip
216229 uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
217230 with :
218- name : sine-linux-${{ matrix.arch }}
219- path : artifacts/sine-linux-${{ matrix.arch }}
231+ name : sine-package-for-signing
232+ path : ./unsigned
220233
221- - name : Upload macOS executable
222- if : matrix.os == 'macos'
234+ - name : Submit signing request
235+ if : steps.status.outputs.should-sign == 'yes'
236+ id : signpath-code-signing
237+ uses : signpath/github-action-submit-signing-request@b9d91eadd323de506c0c81cf0c7fe7438f3360fd # v2.2
238+ with :
239+ api-token : " ${{ secrets.SIGNPATH_API_TOKEN }}"
240+ organization-id : " 1324b51a-cb3d-4d1e-aab7-27b1169bd402"
241+ project-slug : " Sine"
242+ signing-policy-slug : " release-signing"
243+ github-artifact-id : " ${{ steps.upload-unsigned-zip.outputs.artifact-id }}"
244+ wait-for-completion : false
245+
246+ - name : Save code signing info
247+ if : steps.status.outputs.should-sign == 'yes'
248+ run : |
249+ mkdir -p artifacts/info
250+ cp repo-info/* artifacts/info
251+
252+ echo "${{ steps.signpath-code-signing.outputs.signing-request-id }}" \
253+ | tee artifacts/info/signing-request-id.txt
254+ echo "${{ steps.signpath-code-signing.outputs.signing-request-web-url }}" \
255+ | tee artifacts/info/signing-request-web-url.txt
256+
257+ - name : Upload Artifact (signing info)
258+ if : steps.status.outputs.should-sign == 'yes'
223259 uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
224260 with :
225- name : sine-osx-${{ matrix.arch }}
226- path : artifacts/sine-osx-${{ matrix.arch }}
261+ name : info
262+ path : ./ artifacts/info
0 commit comments