Open
Conversation
0f7d199 to
05fafb7
Compare
Add detached GPG signatures (.sig) to the macOS packaging pipeline, reusing the same key infrastructure as RPM and linux tarball signing. Extract inline zip/upload steps into build-zip-pkg.sh script.
05fafb7 to
a0f5e32
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why this should be merged
macOS binary zips are uploaded to S3 unsigned. This adds detached GPG signatures (
.zip.sig), matching the linux tarball and RPM signing pipelines.Closes #5161
Note: When
RPM_GPG_PRIVATE_KEYis unset or empty, unsigned zips are silently published to S3. This matches linux tarball behavior.How this works
build-zip-pkg.sh: GPG setup, zip creation, signing, S3 upload. No-op when no key is provided.build-macos-release.yml: GPG key import, script call,.sigin artifacts.How this was tested
.sigfiles produced,gpg --verifypassesNeed to be documented in RELEASES.md?
No