Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

release: create source tarball and sign all artifacts #538

Merged
merged 3 commits into from
Sep 13, 2023

Conversation

sauterp
Copy link
Member

@sauterp sauterp commented Sep 12, 2023

Description

We want to verify signatures of released packages before installing them with the install-latest.sh script and in makepkg. For the AUR source package we need a signature that includes the source of the go.mk submodule.

Checklist

  • Changelog updated (under Unreleased block)
  • Testing

Testing

goreleaser release --skip-docker --skip-publish --skip-announce --skip-validate --clean
  • starting release...
  • loading config file                              file=.goreleaser.yml
  • loading environment variables
  • getting and validating git state
    • building...                                    commit=7b144e8e5914e2e6cb6c3569bc5821b7cbfe4024 latest tag=v1.72.1
    • pipe skipped                                   reason=validation is disabled
  • parsing tag
  • setting defaults
      • DEPRECATED: `archives.rlcp` will be the default soon, check https://goreleaser.com/deprecations#archivesrlcp for more info
  • running before hooks
    • running                                        hook=make manpages completions
    • took: 3s
  • checking distribution directory
    • cleaning dist
  • loading go mod information
  • build prerequisites
  • writing effective config file
    • writing                                        config=dist/config.yaml
  • building binaries
    • building                                       binary=dist/exoscale-cli_linux_arm_6/exo
    • building                                       binary=dist/exoscale-cli_windows_arm_7/exo.exe
    • building                                       binary=dist/exoscale-cli_windows_arm_6/exo.exe
    • building                                       binary=dist/exoscale-cli_darwin_arm64/exo
    • building                                       binary=dist/exoscale-cli_windows_amd64_v1/exo.exe
    • building                                       binary=dist/exoscale-cli_windows_arm64/exo.exe
    • building                                       binary=dist/exoscale-cli_linux_amd64_v1/exo
    • building                                       binary=dist/exoscale-cli_darwin_amd64_v1/exo
    • building                                       binary=dist/exoscale-cli_linux_arm_7/exo
    • building                                       binary=dist/exoscale-cli_linux_arm64/exo
    • building                                       binary=dist/exoscale-cli_openbsd_amd64_v1/exo
    • took: 7s
  • universal binaries
    • creating from 2 binaries                       id=exoscale-cli binary=dist/exoscale-cli_darwin_all/exo
  • generating changelog
    • writing                                        changelog=dist/CHANGELOG.md
  • archives
    • creating                                       archive=dist/exoscale-cli_1.72.1_linux_armv6.tar.gz
    • creating                                       archive=dist/exoscale-cli_1.72.1_windows_amd64.zip
    • creating                                       archive=dist/exoscale-cli_1.72.1_darwin_all.tar.gz
    • creating                                       archive=dist/exoscale-cli_1.72.1_linux_amd64.tar.gz
    • creating                                       archive=dist/exoscale-cli_1.72.1_windows_arm64.zip
    • creating                                       archive=dist/exoscale-cli_1.72.1_openbsd_amd64.tar.gz
    • creating                                       archive=dist/exoscale-cli_1.72.1_linux_arm64.tar.gz
    • creating                                       archive=dist/exoscale-cli_1.72.1_linux_armv7.tar.gz
    • creating                                       archive=dist/exoscale-cli_1.72.1_windows_armv6.zip
    • creating                                       archive=dist/exoscale-cli_1.72.1_windows_armv7.zip
    • took: 12s
  • creating source archive
    • creating source archive                        file=exoscale-cli_1.72.1.tar.gz
    • took: 7s
  • linux packages
    • creating                                       package=exoscale-cli format=rpm arch=arm6 file=dist/exoscale-cli_1.72.1_linux_armv6.rpm
    • creating                                       package=exoscale-cli format=deb arch=arm64 file=dist/exoscale-cli_1.72.1_linux_arm64.deb
    • creating                                       package=exoscale-cli format=deb arch=amd64v1 file=dist/exoscale-cli_1.72.1_linux_amd64.deb
    • creating                                       package=exoscale-cli format=rpm arch=amd64v1 file=dist/exoscale-cli_1.72.1_linux_amd64.rpm
    • creating                                       package=exoscale-cli format=rpm arch=arm64 file=dist/exoscale-cli_1.72.1_linux_arm64.rpm
    • creating                                       package=exoscale-cli format=deb arch=arm7 file=dist/exoscale-cli_1.72.1_linux_armv7.deb
    • creating                                       package=exoscale-cli format=deb arch=arm6 file=dist/exoscale-cli_1.72.1_linux_armv6.deb
    • creating                                       package=exoscale-cli format=rpm arch=arm7 file=dist/exoscale-cli_1.72.1_linux_armv7.rpm
    • took: 2s
  • calculating checksums
  • signing artifacts
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_linux_armv6.tar.gz signature=dist/exoscale-cli_1.72.1_linux_armv6.tar.gz.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_linux_armv7.tar.gz signature=dist/exoscale-cli_1.72.1_linux_armv7.tar.gz.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_windows_arm64.zip signature=dist/exoscale-cli_1.72.1_windows_arm64.zip.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_linux_arm64.tar.gz signature=dist/exoscale-cli_1.72.1_linux_arm64.tar.gz.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_windows_amd64.zip signature=dist/exoscale-cli_1.72.1_windows_amd64.zip.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_openbsd_amd64.tar.gz signature=dist/exoscale-cli_1.72.1_openbsd_amd64.tar.gz.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_linux_amd64.tar.gz signature=dist/exoscale-cli_1.72.1_linux_amd64.tar.gz.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_windows_armv7.zip signature=dist/exoscale-cli_1.72.1_windows_armv7.zip.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_windows_armv6.zip signature=dist/exoscale-cli_1.72.1_windows_armv6.zip.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_darwin_all.tar.gz signature=dist/exoscale-cli_1.72.1_darwin_all.tar.gz.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1.tar.gz signature=dist/exoscale-cli_1.72.1.tar.gz.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_linux_arm64.deb signature=dist/exoscale-cli_1.72.1_linux_arm64.deb.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_linux_armv6.deb signature=dist/exoscale-cli_1.72.1_linux_armv6.deb.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_linux_amd64.deb signature=dist/exoscale-cli_1.72.1_linux_amd64.deb.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_linux_armv7.deb signature=dist/exoscale-cli_1.72.1_linux_armv7.deb.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_linux_arm64.rpm signature=dist/exoscale-cli_1.72.1_linux_arm64.rpm.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_linux_amd64.rpm signature=dist/exoscale-cli_1.72.1_linux_amd64.rpm.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_linux_armv7.rpm signature=dist/exoscale-cli_1.72.1_linux_armv7.rpm.sig
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_linux_armv6.rpm signature=dist/exoscale-cli_1.72.1_linux_armv6.rpm.sig
    • refreshing checksums                           file=exoscale-cli_1.72.1_checksums.txt
    • signing                                        cmd=gpg artifact=exoscale-cli_1.72.1_checksums.txt signature=dist/exoscale-cli_1.72.1_checksums.txt.sig
    • refreshing checksums                           file=exoscale-cli_1.72.1_checksums.txt
    • took: 7s
  • homebrew tap formula
    • writing                                        formula=dist/exoscale-cli.rb
  • storing release metadata
    • writing                                        file=dist/artifacts.json
    • writing                                        file=dist/metadata.json
  • you are using deprecated options, check the output above for details
  • release succeeded after 39s
  • thanks for using goreleaser!

@shortcut-integration
Copy link

This pull request has been linked to Shortcut Story #77213: cli: sign releases.

@sauterp sauterp marked this pull request as ready for review September 12, 2023 12:35
@sauterp sauterp merged commit 7af9765 into master Sep 13, 2023
1 check passed
@sauterp sauterp deleted the sauterp/sc-77213/sign-all-artifacts branch September 13, 2023 08:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants