From 6162dd41b7cbe53cc4c4b62b4078b1f56c2b05a7 Mon Sep 17 00:00:00 2001 From: DanConwayDev Date: Thu, 3 Sep 2026 12:42:22 +0000 Subject: [PATCH] ci(release): rely on signed asset checksums Motivation: NIP-82 asset events already bind release files to their SHA-256, while publishing a second platform-agnostic SHA256SUMS asset is redundant and rejected by catalogs that require an f tag. Approach: package and upload only the static archive, document the signed-checksum model in the manifest, and derive the release event timestamp from Git creatordate so annotated and lightweight tags both produce stable dates. Correctness: the archive remains deterministic and actions/upload-artifact retains the exact distributable; ngit signs its hash, size, MIME type, filename, URL, and Linux platform in the kind-3063 event. Excluded: the already-published 3.0.1 release is not replaced, and truly multi-platform release layouts remain unchanged. Validation: actionlint accepts the workflow; Git creatordate reproduces the v3.0.0 and v3.0.1 tag timestamps; ngit parses the manifest and reaches the expected publisher-author guard without signing or uploading. --- .ngit/act/workflows/release.yaml | 13 ++++++++++--- .ngit/release.yaml | 8 +++----- 2 files changed, 13 insertions(+), 8 deletions(-) diff --git a/.ngit/act/workflows/release.yaml b/.ngit/act/workflows/release.yaml index 6be363e..909d30a 100644 --- a/.ngit/act/workflows/release.yaml +++ b/.ngit/act/workflows/release.yaml @@ -25,7 +25,7 @@ jobs: token: unused - name: Build static binary run: nix build .#static --out-link result-static - - name: Package release assets + - name: Package release asset shell: bash run: | set -euo pipefail @@ -53,12 +53,11 @@ jobs: tar --sort=name --mtime="@${source_date_epoch}" \ --owner=0 --group=0 --numeric-owner -C release-stage \ -czf "dist/${archive}.tar.gz" "$archive" - (cd dist && sha256sum ./*.tar.gz > SHA256SUMS) - name: Upload release assets uses: actions/upload-artifact@v4 with: name: ngit-grasp-release-assets - path: dist/* + path: dist/*.tar.gz if-no-files-found: error - name: Publish NIP-82 release shell: bash @@ -75,10 +74,18 @@ jobs: printf '%s\n' "$NGIT_PUBLISHER_NBUNKSEC" > "$signer_file" version="${GITHUB_REF_NAME#v}" + released_at="$(git for-each-ref \ + --format='%(creatordate:unix)' \ + "refs/tags/$GITHUB_REF_NAME")" + if [[ ! "$released_at" =~ ^[0-9]+$ ]]; then + echo "could not derive release date from tag $GITHUB_REF_NAME" >&2 + exit 1 + fi ngit release publish "$version" \ --repo nostr://npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/relay.ngit.dev/ngit-grasp \ --manifest .ngit/release.yaml \ --tag "$GITHUB_REF_NAME" \ + --released-at "$released_at" \ --nbunksec-file "$signer_file" \ --defaults \ --repo-relay-only \ diff --git a/.ngit/release.yaml b/.ngit/release.yaml index 3227f83..f1832d4 100644 --- a/.ngit/release.yaml +++ b/.ngit/release.yaml @@ -36,6 +36,9 @@ publication: zapstore_relay: true strict_metadata: true assets: + # The signed kind-3063 event carries the archive's SHA-256. A separate + # checksum asset would duplicate that trust record, and some catalogs require + # every release asset to declare a target platform. - file: dist/ngit-grasp-{version}-x86_64-unknown-linux-musl.tar.gz filename: ngit-grasp-{version}-x86_64-unknown-linux-musl.tar.gz mime: application/gzip @@ -52,8 +55,3 @@ assets: - "77" - "98" variant: static-musl - - file: dist/SHA256SUMS - identifier: ngit-grasp-checksums - filename: SHA256SUMS - mime: text/plain - platform_agnostic: true