mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
ci(release): rely on signed asset checksums
Motivation: NIP-82 asset events already bind release files to their SHA-256, while publishing a second platform-agnostic SHA256SUMS asset is redundant and rejected by catalogs that require an f tag. Approach: package and upload only the static archive, document the signed-checksum model in the manifest, and derive the release event timestamp from Git creatordate so annotated and lightweight tags both produce stable dates. Correctness: the archive remains deterministic and actions/upload-artifact retains the exact distributable; ngit signs its hash, size, MIME type, filename, URL, and Linux platform in the kind-3063 event. Excluded: the already-published 3.0.1 release is not replaced, and truly multi-platform release layouts remain unchanged. Validation: actionlint accepts the workflow; Git creatordate reproduces the v3.0.0 and v3.0.1 tag timestamps; ngit parses the manifest and reaches the expected publisher-author guard without signing or uploading.
This commit is contained in:
@@ -25,7 +25,7 @@ jobs:
|
||||
token: unused
|
||||
- name: Build static binary
|
||||
run: nix build .#static --out-link result-static
|
||||
- name: Package release assets
|
||||
- name: Package release asset
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
@@ -53,12 +53,11 @@ jobs:
|
||||
tar --sort=name --mtime="@${source_date_epoch}" \
|
||||
--owner=0 --group=0 --numeric-owner -C release-stage \
|
||||
-czf "dist/${archive}.tar.gz" "$archive"
|
||||
(cd dist && sha256sum ./*.tar.gz > SHA256SUMS)
|
||||
- name: Upload release assets
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: ngit-grasp-release-assets
|
||||
path: dist/*
|
||||
path: dist/*.tar.gz
|
||||
if-no-files-found: error
|
||||
- name: Publish NIP-82 release
|
||||
shell: bash
|
||||
@@ -75,10 +74,18 @@ jobs:
|
||||
printf '%s\n' "$NGIT_PUBLISHER_NBUNKSEC" > "$signer_file"
|
||||
|
||||
version="${GITHUB_REF_NAME#v}"
|
||||
released_at="$(git for-each-ref \
|
||||
--format='%(creatordate:unix)' \
|
||||
"refs/tags/$GITHUB_REF_NAME")"
|
||||
if [[ ! "$released_at" =~ ^[0-9]+$ ]]; then
|
||||
echo "could not derive release date from tag $GITHUB_REF_NAME" >&2
|
||||
exit 1
|
||||
fi
|
||||
ngit release publish "$version" \
|
||||
--repo nostr://npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/relay.ngit.dev/ngit-grasp \
|
||||
--manifest .ngit/release.yaml \
|
||||
--tag "$GITHUB_REF_NAME" \
|
||||
--released-at "$released_at" \
|
||||
--nbunksec-file "$signer_file" \
|
||||
--defaults \
|
||||
--repo-relay-only \
|
||||
|
||||
+3
-5
@@ -36,6 +36,9 @@ publication:
|
||||
zapstore_relay: true
|
||||
strict_metadata: true
|
||||
assets:
|
||||
# The signed kind-3063 event carries the archive's SHA-256. A separate
|
||||
# checksum asset would duplicate that trust record, and some catalogs require
|
||||
# every release asset to declare a target platform.
|
||||
- file: dist/ngit-grasp-{version}-x86_64-unknown-linux-musl.tar.gz
|
||||
filename: ngit-grasp-{version}-x86_64-unknown-linux-musl.tar.gz
|
||||
mime: application/gzip
|
||||
@@ -52,8 +55,3 @@ assets:
|
||||
- "77"
|
||||
- "98"
|
||||
variant: static-musl
|
||||
- file: dist/SHA256SUMS
|
||||
identifier: ngit-grasp-checksums
|
||||
filename: SHA256SUMS
|
||||
mime: text/plain
|
||||
platform_agnostic: true
|
||||
|
||||
Reference in New Issue
Block a user