-
Notifications
You must be signed in to change notification settings - Fork 145
100 lines (81 loc) · 3.81 KB
/
release-verify-signatures.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
name: Reproducible binary
# This workflow waits for release signatures to appear on Maven Central,
# then rebuilds the artifacts and verifies them against those signatures,
# and finally uploads the signatures to the GitHub release.
on:
release:
types: [published]
jobs:
download:
name: Download keys and signatures
runs-on: ubuntu-latest
steps:
- name: Fetch keys
run: gpg --no-default-keyring --keyring ./yubico.keyring --keyserver hkps://keys.openpgp.org --recv-keys 57A9DEED4C6D962A923BB691816F3ED99921835E
- name: Download signatures from Maven Central
timeout-minutes: 60
run: |
until wget https://repo1.maven.org/maven2/com/yubico/webauthn-server-attestation/${{ github.ref_name }}/webauthn-server-attestation-${{ github.ref_name }}.jar.asc; do sleep 180; done
until wget https://repo1.maven.org/maven2/com/yubico/webauthn-server-core/${{ github.ref_name }}/webauthn-server-core-${{ github.ref_name }}.jar.asc; do sleep 180; done
- name: Store keyring and signatures as artifact
uses: actions/upload-artifact@v4
with:
name: keyring-and-signatures
retention-days: 1
path: |
yubico.keyring
*.jar.asc
verify:
name: Verify signatures (JDK ${{ matrix.java }} ${{ matrix.distribution }})
needs: download
runs-on: ubuntu-latest
strategy:
matrix:
java: ["17.0.10"]
distribution: [temurin, zulu, microsoft]
steps:
- name: check out code
uses: actions/checkout@v4
with:
ref: ${{ github.ref_name }}
- name: Set up JDK
uses: actions/setup-java@v4
with:
java-version: ${{ matrix.java }}
distribution: ${{ matrix.distribution }}
- name: Build jars
run: |
java --version
./gradlew jar
- name: Print checksums
run: |
for sumprog in md5sum sha1sum sha256sum; do
echo $sumprog
$sumprog webauthn-server-attestation/build/libs/webauthn-server-attestation-${{ github.ref_name }}.jar
$sumprog webauthn-server-core/build/libs/webauthn-server-core-${{ github.ref_name }}.jar
done
- name: Retrieve keyring and signatures
uses: actions/download-artifact@v4
with:
name: keyring-and-signatures
- name: Verify signatures from Maven Central
run: |
gpg --no-default-keyring --keyring ./yubico.keyring --verify webauthn-server-attestation-${{ github.ref_name }}.jar.asc webauthn-server-attestation/build/libs/webauthn-server-attestation-${{ github.ref_name }}.jar
gpg --no-default-keyring --keyring ./yubico.keyring --verify webauthn-server-core-${{ github.ref_name }}.jar.asc webauthn-server-core/build/libs/webauthn-server-core-${{ github.ref_name }}.jar
upload:
name: Upload signatures to GitHub
needs: verify
runs-on: ubuntu-latest
permissions:
contents: write # Allow uploading release artifacts
steps:
- name: Retrieve signatures
uses: actions/download-artifact@v4
with:
name: keyring-and-signatures
- name: Upload signatures to GitHub
run: |
RELEASE_DATA=$(curl -H "Authorization: Bearer ${{ github.token }}" ${{ github.api_url }}/repos/${{ github.repository }}/releases/tags/${{ github.ref_name }})
UPLOAD_URL=$(jq -r .upload_url <<<"${RELEASE_DATA}" | sed 's/{?name,label}//')
curl -X POST -H "Authorization: Bearer ${{ github.token }}" -H 'Content-Type: text/plain' --data-binary @webauthn-server-attestation-${{ github.ref_name }}.jar.asc "${UPLOAD_URL}?name=webauthn-server-attestation-${{ github.ref_name }}.jar.asc"
curl -X POST -H "Authorization: Bearer ${{ github.token }}" -H 'Content-Type: text/plain' --data-binary @webauthn-server-core-${{ github.ref_name }}.jar.asc "${UPLOAD_URL}?name=webauthn-server-core-${{ github.ref_name }}.jar.asc"