From 82348f6f3237d93b8de15bbc0e5d08f86fbebd1a Mon Sep 17 00:00:00 2001 From: Carlos Alexandro Becker Date: Wed, 24 Jul 2024 11:42:29 -0400 Subject: [PATCH] ci: sign & notarize macos binaries (#612) --- .github/workflows/goreleaser.yml | 7 +++++++ .github/workflows/nightly.yml | 5 +++++ 2 files changed, 12 insertions(+) diff --git a/.github/workflows/goreleaser.yml b/.github/workflows/goreleaser.yml index 1358069..7c988ab 100644 --- a/.github/workflows/goreleaser.yml +++ b/.github/workflows/goreleaser.yml @@ -1,3 +1,5 @@ +# yaml-language-server: $schema=https://json.schemastore.org/github-workflow.json + name: goreleaser on: @@ -20,3 +22,8 @@ jobs: fury_token: ${{ secrets.FURY_TOKEN }} nfpm_gpg_key: ${{ secrets.NFPM_GPG_KEY }} nfpm_passphrase: ${{ secrets.NFPM_PASSPHRASE }} + macos_sign_p12: ${{ secrets.MACOS_SIGN_P12 }} + macos_sign_password: ${{ secrets.MACOS_SIGN_PASSWORD }} + macos_notary_issuer_id: ${{ secrets.MACOS_NOTARY_ISSUER_ID }} + macos_notary_key_id: ${{ secrets.MACOS_NOTARY_KEY_ID }} + macos_notary_key: ${{ secrets.MACOS_NOTARY_KEY }} diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index 28f61f7..d86e6ab 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -12,3 +12,8 @@ jobs: docker_username: ${{ secrets.DOCKERHUB_USERNAME }} docker_token: ${{ secrets.DOCKERHUB_TOKEN }} goreleaser_key: ${{ secrets.GORELEASER_KEY }} + macos_sign_p12: ${{ secrets.MACOS_SIGN_P12 }} + macos_sign_password: ${{ secrets.MACOS_SIGN_PASSWORD }} + macos_notary_issuer_id: ${{ secrets.MACOS_NOTARY_ISSUER_ID }} + macos_notary_key_id: ${{ secrets.MACOS_NOTARY_KEY_ID }} + macos_notary_key: ${{ secrets.MACOS_NOTARY_KEY }}