[verified] Enforce a single release publisher
This commit is contained in:
parent
d0a46f511b
commit
004f01a842
3 changed files with 19 additions and 18 deletions
18
.github/workflows/windows-release.yml
vendored
18
.github/workflows/windows-release.yml
vendored
|
|
@ -1,10 +1,7 @@
|
||||||
name: Windows installer release
|
name: Windows installer packaging
|
||||||
|
|
||||||
on:
|
on:
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
push:
|
|
||||||
tags:
|
|
||||||
- 'v*'
|
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
|
|
@ -12,8 +9,6 @@ permissions:
|
||||||
jobs:
|
jobs:
|
||||||
package:
|
package:
|
||||||
runs-on: windows-latest
|
runs-on: windows-latest
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
env:
|
env:
|
||||||
SIGNING_CERTIFICATE_BASE64: ${{ secrets.WINDOWS_SIGNING_CERTIFICATE_BASE64 }}
|
SIGNING_CERTIFICATE_BASE64: ${{ secrets.WINDOWS_SIGNING_CERTIFICATE_BASE64 }}
|
||||||
SIGNING_CERTIFICATE_PASSWORD: ${{ secrets.WINDOWS_SIGNING_CERTIFICATE_PASSWORD }}
|
SIGNING_CERTIFICATE_PASSWORD: ${{ secrets.WINDOWS_SIGNING_CERTIFICATE_PASSWORD }}
|
||||||
|
|
@ -85,14 +80,3 @@ jobs:
|
||||||
artifacts/windows-installer/SHA256SUMS
|
artifacts/windows-installer/SHA256SUMS
|
||||||
server-monitor-manager-win-x64-sbom.json
|
server-monitor-manager-win-x64-sbom.json
|
||||||
if-no-files-found: error
|
if-no-files-found: error
|
||||||
|
|
||||||
- name: Attach installer to GitHub Release
|
|
||||||
if: startsWith(github.ref, 'refs/tags/')
|
|
||||||
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2
|
|
||||||
with:
|
|
||||||
prerelease: ${{ contains(github.ref_name, '-') }}
|
|
||||||
files: |
|
|
||||||
artifacts/windows-installer/ServerMonitorManager-win-x64.msix
|
|
||||||
artifacts/windows-installer/ServerMonitorManager-test-signing.cer
|
|
||||||
artifacts/windows-installer/SHA256SUMS
|
|
||||||
server-monitor-manager-win-x64-sbom.json
|
|
||||||
|
|
|
||||||
|
|
@ -4,6 +4,6 @@ Published tags and release assets are immutable.
|
||||||
|
|
||||||
A tag that has been published must never be moved, reused, deleted and recreated, or supplied with replacement assets under the same names. If a published build or installer is wrong, preserve the existing release and publish a new, higher version tag containing the correction.
|
A tag that has been published must never be moved, reused, deleted and recreated, or supplied with replacement assets under the same names. If a published build or installer is wrong, preserve the existing release and publish a new, higher version tag containing the correction.
|
||||||
|
|
||||||
Release artifacts are built from the commit named by the tag through the repository release workflows, including `.github/workflows/linux-release.yml` and `.github/workflows/windows-release.yml`. The tracked production source for the convenience installer is `deploy/smm-setup.sh`; the Linux release workflow copies that exact file to the release artifact set, records its SHA-256 in the signed manifest, and publishes its standalone checksum. The default release in that source must match the tag being produced.
|
`.github/workflows/linux-release.yml` is the sole GitHub Release publisher. On a version tag, it builds the Linux and Windows packages from the tagged commit, generates the signed manifest, and publishes the complete release asset set. `.github/workflows/windows-release.yml` is manual-only and may package and verify a Windows installer as a workflow artifact, but it never publishes or replaces GitHub Release assets. The tracked production source for the convenience installer is `deploy/smm-setup.sh`; the Linux release workflow copies that exact file to the release artifact set, records its SHA-256 in the signed manifest, and publishes its standalone checksum. The default release in that source must match the tag being produced.
|
||||||
|
|
||||||
For `v0.1.0-alpha.9`, this makes `smm-setup.sh`, `smm-setup.sh.sha256`, the bootstrap script, platform archives, SBOMs, and the signed manifest reproducible from the tagged tree. The installer fetches only same-tag assets and verifies the bootstrap checksum before execution. Corrections after publication require another tag; the `v0.1.0-alpha.9` tag and assets remain unchanged.
|
For `v0.1.0-alpha.9`, this makes `smm-setup.sh`, `smm-setup.sh.sha256`, the bootstrap script, platform archives, SBOMs, and the signed manifest reproducible from the tagged tree. The installer fetches only same-tag assets and verifies the bootstrap checksum before execution. Corrections after publication require another tag; the `v0.1.0-alpha.9` tag and assets remain unchanged.
|
||||||
|
|
|
||||||
|
|
@ -5,6 +5,7 @@ IFS=$'\n\t'
|
||||||
root="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")/../.." && pwd)"
|
root="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")/../.." && pwd)"
|
||||||
setup="$root/deploy/smm-setup.sh"
|
setup="$root/deploy/smm-setup.sh"
|
||||||
workflow="$root/.github/workflows/linux-release.yml"
|
workflow="$root/.github/workflows/linux-release.yml"
|
||||||
|
windows_workflow="$root/.github/workflows/windows-release.yml"
|
||||||
policy="$root/docs/release-policy.md"
|
policy="$root/docs/release-policy.md"
|
||||||
installer_contract="$root/docs/installer-contract.md"
|
installer_contract="$root/docs/installer-contract.md"
|
||||||
|
|
||||||
|
|
@ -22,6 +23,22 @@ fi
|
||||||
grep -Fq 'install -m 0755 deploy/smm-setup.sh "$DIST_DIR/smm-setup.sh"' "$workflow"
|
grep -Fq 'install -m 0755 deploy/smm-setup.sh "$DIST_DIR/smm-setup.sh"' "$workflow"
|
||||||
grep -Fq 'smm-setup.sh.sha256' "$workflow"
|
grep -Fq 'smm-setup.sh.sha256' "$workflow"
|
||||||
grep -Fq 'dist/smm-setup.sh' "$workflow"
|
grep -Fq 'dist/smm-setup.sh' "$workflow"
|
||||||
|
grep -Fq " - 'v*'" "$workflow"
|
||||||
|
grep -Fq 'contents: write' "$workflow"
|
||||||
|
grep -Fq 'softprops/action-gh-release@' "$workflow"
|
||||||
|
grep -Fq 'workflow_dispatch:' "$windows_workflow"
|
||||||
|
if grep -Eq '^[[:space:]]+tags:' "$windows_workflow"; then
|
||||||
|
printf '%s\n' 'Windows packaging workflow must not trigger on tags' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if grep -Fq 'softprops/action-gh-release@' "$windows_workflow"; then
|
||||||
|
printf '%s\n' 'Windows packaging workflow must not publish GitHub Release assets' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if grep -Eq 'contents:[[:space:]]*write' "$windows_workflow"; then
|
||||||
|
printf '%s\n' 'Windows packaging workflow must not have contents write permission' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
grep -Fq 'Published tags and release assets are immutable.' "$policy"
|
grep -Fq 'Published tags and release assets are immutable.' "$policy"
|
||||||
grep -Fq 'publish a new, higher version tag' "$policy"
|
grep -Fq 'publish a new, higher version tag' "$policy"
|
||||||
grep -Fq 'Published release tags and their assets are immutable.' "$installer_contract"
|
grep -Fq 'Published release tags and their assets are immutable.' "$installer_contract"
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue