-
Notifications
You must be signed in to change notification settings - Fork 6
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix gittuf workflows #41
Conversation
Summary of changes: * Set key permission to 600 for SSH signing key * Use released version of gittuf via installer workflow * Use setup-gitsign workflow instead of installing from source Signed-off-by: Aditya Sirish <[email protected]>
e4b41be
to
1c05a55
Compare
Besides the version updates on the actions, are there any functionality changes introduced here? |
gittuf changed how ssh keys are used for signing, and this permission must be set on private keys. Basically, gittuf now uses ssh-keygen to sign, and ssh-keygen has this requirement. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Signed-off-by: Aditya Sirish <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the updates @adityasaky !
No description provided.