Skip to content

Nightly Trusted Root Update Check #86

Nightly Trusted Root Update Check

Nightly Trusted Root Update Check #86

name: Nightly Trusted Root Update Check
on:
schedule:
- cron: "15 7 * * *" # Every day at 0715 UTC
workflow_dispatch:
concurrency:
group: nightly-trusted-root-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
check-trusted-root:
if: ${{ github.repository == 'zarf-dev/zarf' }}
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Download latest Zarf binary
run: |
set -euo pipefail
gh release download --repo zarf-dev/zarf --pattern "zarf_*_Linux_amd64" -O /tmp/zarf
chmod +x /tmp/zarf
env:
GH_TOKEN: ${{ github.token }}
- name: Fetch current Sigstore trusted root
run: |
/tmp/zarf tools trusted-root create --with-default-services --out /tmp/current_trusted_root.json
jq --indent 2 . /tmp/current_trusted_root.json > /tmp/current_trusted_root_formatted.json
- name: Diff against embedded trusted root
run: diff -u src/pkg/signing/embedded_trusted_root.json /tmp/current_trusted_root_formatted.json
- name: Notify Slack on change detected
if: failure()
uses: ./.github/actions/slack
with:
slack-webhook-url: ${{ secrets.SLACK_WEBHOOK_URL }}