Skip to content

Conversation

prabhu
Copy link
Collaborator

@prabhu prabhu commented May 14, 2025

Apparently, secrets aren't automatically passed to reusable workflows (in the name of security!). Plus, the base64-encoded approach is the only reliable way to get it working with GitHub, so I added a feature to create this file during generate-key-and-sign.

I don't know how people are using (or not using) BOM signing.

prabhu added 2 commits May 14, 2025 13:48
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
@prabhu prabhu merged commit 8a02b9e into master May 14, 2025
87 of 93 checks passed
@prabhu prabhu deleted the test/gh-sign-test branch May 14, 2025 13:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant