Skip to content

release: SignPath Foundation and catalog key / SignPath и ключ каталога #8

Description

@OneDeadMachine-Dev

RU

Внешние шаги перед подписанным stable release:

  • Владелец проекта подаёт заявку SignPath Foundation.
  • После одобрения добавить repository variables: SIGNPATH_ORGANIZATION_ID, SIGNPATH_PROJECT_SLUG, SIGNPATH_SIGNING_POLICY_SLUG, SIGNPATH_ARTIFACT_CONFIGURATION_SLUG.
  • Добавить SIGNPATH_API_TOKEN только в Environment secret release.
  • На доверенном ПК выполнить bootstrap из CODE_SIGNING_POLICY.md: записать KNOWN_ISSUES_PRIVATE_KEY_PEM в GitHub Secret, закоммитить только новый public key.
  • Проверить ручное approval окружения release, Authenticode status и timestamp.
  • Проверить SHA256SUMS и подпись known-issues catalog.

Закрытые ключи, токены и содержимое credentials в Issue не публиковать.

EN

External steps before a signed stable release:

  • Project owner submits the SignPath Foundation application.
  • After approval, configure the four SignPath repository variables.
  • Store SIGNPATH_API_TOKEN only in the release Environment secret.
  • On a trusted PC, follow CODE_SIGNING_POLICY.md to store KNOWN_ISSUES_PRIVATE_KEY_PEM; commit only the public key.
  • Verify manual release approval, Authenticode status, and timestamp.
  • Verify SHA256SUMS and the known-issues catalog signature.

Never publish private keys, tokens, or credentials in this issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions