@@ -108,23 +108,24 @@ jobs:
108108
109109 - name : Sign artifacts with Sigstore
110110 run : |
111- for artifact in \
112- "${{ steps.binaries.outputs.darwin }}" \
113- "${{ steps.binaries.outputs.win_amd64 }}" \
114- "${{ steps.binaries.outputs.win_arm64 }}" \
115- stepsecurity-dev-machine-guard.sh; do
116- cosign sign-blob "$artifact" --bundle "${artifact}.bundle" --yes
117- done
111+ cosign sign-blob "${{ steps.binaries.outputs.darwin }}" \
112+ --bundle dist/stepsecurity-dev-machine-guard-darwin_unnotarized.bundle --yes
113+ cosign sign-blob "${{ steps.binaries.outputs.win_amd64 }}" \
114+ --bundle dist/stepsecurity-dev-machine-guard-windows_amd64.exe.bundle --yes
115+ cosign sign-blob "${{ steps.binaries.outputs.win_arm64 }}" \
116+ --bundle dist/stepsecurity-dev-machine-guard-windows_arm64.exe.bundle --yes
117+ cosign sign-blob stepsecurity-dev-machine-guard.sh \
118+ --bundle dist/stepsecurity-dev-machine-guard.sh.bundle --yes
118119
119120 - name : Upload cosign bundles
120121 env :
121122 GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
122123 run : |
123124 gh release upload "${{ steps.release.outputs.tag }}" \
124- "${{ steps.binaries.outputs.darwin }}. bundle" \
125- "${{ steps.binaries.outputs.win_amd64 }}. bundle" \
126- "${{ steps.binaries.outputs.win_arm64 }}. bundle" \
127- stepsecurity-dev-machine-guard.sh.bundle \
125+ dist/stepsecurity-dev-machine-guard-darwin_unnotarized. bundle \
126+ dist/stepsecurity-dev-machine-guard-windows_amd64.exe. bundle \
127+ dist/stepsecurity-dev-machine-guard-windows_arm64.exe. bundle \
128+ dist/ stepsecurity-dev-machine-guard.sh.bundle \
128129 --clobber
129130
130131 - name : Attest build provenance
0 commit comments