Repository navigation
release: full-history changelog and an uploaded signing certificate - #6
Merged
Merged
Conversation
v0.3.0 shipped with an empty changelog (the release checkout was shallow, so goreleaser couldn't see v0.2.0) and with checksums.txt.sig but no certificate, so the documented cosign verify-blob couldn't succeed. - release workflow checks out full history - goreleaser uploads checksums.txt.pem next to the signature - new 'Sign release' workflow re-signs an existing tag's checksums and uploads signature + certificate (fixes v0.3.0 without re-cutting it) - release header describes the current cometcli; INSTALL.md verifies with the certificate; RELEASE.md checklist covers both Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes two problems with the v0.3.0 release pipeline:
actions/checkoutwas shallow, so goreleaser couldn't see the commits sincev0.2.0. The release workflow now usesfetch-depth: 0.checksums.txt.pembut never uploaded it, and keylesscosign verify-blobneeds that certificate..goreleaser.yamlnow declaressignatureandcertificateso both are uploaded.Also in this PR:
workflow_dispatch, input: tag). It re-signs a publishedchecksums.txt, verifies the result and uploads.sigand.pem. Running it on v0.3.0 makes that release verifiable without re-cutting it.docs/INSTALL.mdverification uses the certificate, and its examples point at v0.3.0.docs/RELEASE.mdchecks for the.pemand the changelog.goreleaser checkpasses. I've already filled in the v0.3.0 release notes by hand.🤖 Generated with Claude Code