-
Notifications
You must be signed in to change notification settings - Fork 12
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Signed-off-by: Alex Cameron <[email protected]>
- Loading branch information
1 parent
f802438
commit e323e1b
Showing
1 changed file
with
24 additions
and
24 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -29,7 +29,7 @@ jobs: | |
- uses: actions/checkout@v3 | ||
- name: install | ||
run: python -m pip install . | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
``` | ||
|
@@ -53,15 +53,15 @@ provided. | |
To sign one or more files: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file0.txt file1.txt file2.txt | ||
``` | ||
|
||
The `inputs` argument also supports file globbing: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: ./path/to/inputs/*.txt | ||
``` | ||
|
@@ -74,7 +74,7 @@ The `identity-token` setting controls the OpenID Connect token provided to Fulci | |
workflow will use the credentials found in the GitHub Actions environment. | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
identity-token: ${{ IDENTITY_TOKEN }} # assigned elsewhere | ||
|
@@ -90,7 +90,7 @@ Server during OAuth2. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
oidc-client-id: alternative-sigstore-id | ||
|
@@ -106,7 +106,7 @@ Connect Server during OAuth2. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
oidc-client-secret: alternative-sigstore-secret | ||
|
@@ -122,7 +122,7 @@ when signing multiple input files. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
signature: custom-signature-filename.sig | ||
|
@@ -131,7 +131,7 @@ Example: | |
However, this example is invalid: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file0.txt file1.txt file2.txt | ||
signature: custom-signature-filename.sig | ||
|
@@ -147,7 +147,7 @@ work when signing multiple input files. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
certificate: custom-certificate-filename.crt | ||
|
@@ -156,7 +156,7 @@ Example: | |
However, this example is invalid: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file0.txt file1.txt file2.txt | ||
certificate: custom-certificate-filename.crt | ||
|
@@ -172,7 +172,7 @@ when signing multiple input files. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
bundle: custom-bundle.sigstore | ||
|
@@ -181,7 +181,7 @@ Example: | |
However, this example is invalid: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file0.txt file1.txt file2.txt | ||
certificate: custom-bundle.sigstore | ||
|
@@ -197,7 +197,7 @@ from. This setting cannot be used in combination with the `staging` setting. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
fulcio-url: https://fulcio.sigstage.dev | ||
|
@@ -213,7 +213,7 @@ cannot be used in combination with the `staging` setting. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
rekor-url: https://rekor.sigstage.dev | ||
|
@@ -229,7 +229,7 @@ in combination with the `staging` setting. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
ctfe: ./path/to/ctfe.pub | ||
|
@@ -245,7 +245,7 @@ be used in combination with `staging` setting. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
ctfe: ./path/to/rekor.pub | ||
|
@@ -261,7 +261,7 @@ instead of the default production instances. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
staging: true | ||
|
@@ -284,7 +284,7 @@ and `verify-oidc-issuer` settings. Failing to pass these will produce an error. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
verify: true | ||
|
@@ -307,7 +307,7 @@ This setting may only be used in conjunction with `verify-oidc-issuer`. | |
Supplying it without `verify-oidc-issuer` will produce an error. | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
verify: true | ||
|
@@ -332,7 +332,7 @@ Supplying it without `verify-cert-identity` will produce an error. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
verify: true | ||
|
@@ -354,7 +354,7 @@ workflow artifact retention period is used. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
upload-signing-artifacts: true | ||
|
@@ -382,7 +382,7 @@ permissions: | |
# ... | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
release-signing-artifacts: true | ||
|
@@ -404,7 +404,7 @@ signing artifact is uploaded. | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
upload-signing-artifacts: true | ||
|
@@ -432,7 +432,7 @@ Example: | |
Example: | ||
|
||
```yaml | ||
- uses: sigstore/[email protected].2 | ||
- uses: sigstore/[email protected].3 | ||
with: | ||
inputs: file.txt | ||
internal-be-careful-debug: true | ||
|