Skip to content

Conversation

guitarrapc
Copy link
Owner

No description provided.

@Copilot Copilot AI review requested due to automatic review settings April 21, 2025 16:08
Copy link
Contributor

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces artifact signing with Cosign and updates the documentation to guide Windows users in configuring security settings for symbolic link creation and binary verification.

  • Updated Japanese and English README files with instructions on Windows security and signature verification.
  • Modified .goreleaser.yml to add Cosign signing and improve build reproducibility.
  • Enhanced GitHub workflows to install Cosign, set up Cosign keys, and ensure proper cleanup of sensitive files.

Reviewed Changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.

Show a summary per file
File Description
README_ja.md Added a section detailing Windows security settings and binary integrity verification.
README.md Added a corresponding Windows security section for binary verification and Cosign usage.
.goreleaser.yml Integrated Cosign signing configuration and added build reproducibility flags/envs.
.github/workflows/release.yaml Updated the release workflow to include Cosign and SBOM installation, key setup, and cleanup.
.github/workflows/build.yaml Updated build workflow to skip signing as part of snapshot builds.

@guitarrapc guitarrapc merged commit 07a6b71 into main Apr 21, 2025
11 checks passed
@guitarrapc guitarrapc deleted the ci branch April 21, 2025 16:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant