-
Notifications
You must be signed in to change notification settings - Fork 163
Expand file tree
/
Copy path.goreleaser.yml
More file actions
127 lines (126 loc) · 2.74 KB
/
Copy path.goreleaser.yml
File metadata and controls
127 lines (126 loc) · 2.74 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
version: 2
before:
hooks:
- go mod download
builds:
- env:
- CGO_ENABLED=0
id: k8gb
main: ./main.go
binary: bin/k8gb
goos:
- linux
goarch:
- amd64
- arm64
flags:
- -trimpath
ldflags:
- -s -w -X main.version={{ .Tag }} -X main.commit={{ .Commit }}
archives:
- id: binary
formats: ["binary"]
name_template: >-
{{ .ProjectName }}_
{{- if eq .Os "darwin" }}macOS
{{- else }}{{ .Os }}{{ end }}-{{ .Arch }}
- id: archive
formats: ["tar.gz"]
files:
- LICENSE*
- README*
- cosign.pub
- dist/*.sig
format_overrides:
- goos: windows
formats: ["zip"]
dockers_v2:
- images:
- ghcr.io/k8gb-io/k8gb
tags:
- "v{{.Version}}"
platforms:
- linux/amd64
- linux/arm64
ids:
- k8gb
labels:
"org.opencontainers.image.title": "k8gb"
"org.opencontainers.image.description": "A cloud native Kubernetes Global Balancer"
"org.opencontainers.image.revision": "{{ .FullCommit }}"
"org.opencontainers.image.version": "{{ .Version }}"
sboms:
- id: archive-sbom
cmd: syft
args: ["${artifact}", "--file", "${artifact}.sbom.json", "--output", "spdx-json"]
documents:
- "${artifact}.sbom.json"
artifacts: archive
signs:
- id: checksums
cmd: cosign
stdin: '{{ .Env.COSIGN_PASSWORD }}'
output: true
artifacts: checksum
args:
- sign-blob
- --key
- cosign.key
- '--output-certificate=${certificate}'
- '--output-signature=${signature}'
- '${artifact}'
- id: binaries
cmd: cosign
stdin: '{{ .Env.COSIGN_PASSWORD }}'
output: true
artifacts: binary
args:
- sign-blob
- --key
- cosign.key
- '--output-certificate=${certificate}'
- '--output-signature=${signature}'
- '${artifact}'
- id: archives
cmd: cosign
stdin: '{{ .Env.COSIGN_PASSWORD }}'
output: true
artifacts: archive
args:
- sign-blob
- --key
- cosign.key
- '--output-certificate=${certificate}'
- '--output-signature=${signature}'
- '${artifact}'
- id: sboms
cmd: cosign
stdin: '{{ .Env.COSIGN_PASSWORD }}'
output: true
artifacts: sbom
args:
- sign-blob
- --key
- cosign.key
- '--output-certificate=${certificate}'
- '--output-signature=${signature}'
- '${artifact}'
docker_signs:
- cmd: cosign
artifacts: all
output: true
args:
- 'sign'
- --key
- cosign.key
- '${artifact}'
checksum:
name_template: 'checksums.txt'
snapshot:
version_template: "{{ .Version }}-{{ .ShortCommit }}"
release:
draft: true
extra_files:
- glob: "./cosign.pub"
footer: |
:rocket: