You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Given that they can change, the correct thing for us to do here is probably to download the asset as it appears, sign for it, and then re-upload it to the release as a new asset: this will freeze it, meaning that the signature will remain correct.
The text was updated successfully, but these errors were encountered:
By default, GitHub Actions produces
{tag}.tar.gz
and{tag}.zip
assets for each release.These artifacts are generated on the fly, meaning that they can (and have) changed their contents (and thus digests) over time. This recently caused some significant breakage due to incorrect assumptions around that: https://github.blog/changelog/2023-01-30-git-archive-checksums-may-change/
Given that they can change, the correct thing for us to do here is probably to download the asset as it appears, sign for it, and then re-upload it to the release as a new asset: this will freeze it, meaning that the signature will remain correct.
The text was updated successfully, but these errors were encountered: