Skip to content

Conversation

@calebbrown
Copy link
Contributor

Introduces goreleaser to automate the creation of binary artifacts when a new release tag is created.

Additionally uses cosign to automatically sign releases.

oliverchang
oliverchang previously approved these changes Feb 23, 2023
Copy link
Contributor

@oliverchang oliverchang left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, but maybe also take a look at https://github.com/google/osv-scanner/blob/main/.github/workflows/goreleaser.yml

to see if there's any things that can be simplified there by using slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml

@calebbrown
Copy link
Contributor Author

PTAL - I switched over to the SLSA generator

Copy link
Contributor

@oliverchang oliverchang left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice!

@calebbrown calebbrown merged commit 972deec into main Feb 23, 2023
@calebbrown calebbrown deleted the binaryrelease branch February 23, 2023 06:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants