Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

README: prep 1.1.0 #43

Merged
merged 1 commit into from
Jan 31, 2023
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 23 additions & 23 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ jobs:
- uses: actions/checkout@v3
- name: install
run: python -m pip install .
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
```
Expand All @@ -53,15 +53,15 @@ provided.
To sign one or more files:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file0.txt file1.txt file2.txt
```

The `inputs` argument also supports file globbing:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: ./path/to/inputs/*.txt
```
Expand All @@ -74,7 +74,7 @@ The `identity-token` setting controls the OpenID Connect token provided to Fulci
workflow will use the credentials found in the GitHub Actions environment.

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
identity-token: ${{ IDENTITY_TOKEN }} # assigned elsewhere
Expand All @@ -90,7 +90,7 @@ Server during OAuth2.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
oidc-client-id: alternative-sigstore-id
Expand All @@ -106,7 +106,7 @@ Connect Server during OAuth2.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
oidc-client-secret: alternative-sigstore-secret
Expand All @@ -122,7 +122,7 @@ when signing multiple input files.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
signature: custom-signature-filename.sig
Expand All @@ -131,7 +131,7 @@ Example:
However, this example is invalid:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file0.txt file1.txt file2.txt
signature: custom-signature-filename.sig
Expand All @@ -147,7 +147,7 @@ work when signing multiple input files.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
certificate: custom-certificate-filename.crt
Expand All @@ -156,7 +156,7 @@ Example:
However, this example is invalid:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file0.txt file1.txt file2.txt
certificate: custom-certificate-filename.crt
Expand All @@ -172,7 +172,7 @@ when signing multiple input files.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
bundle: custom-bundle.sigstore
Expand All @@ -181,7 +181,7 @@ Example:
However, this example is invalid:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file0.txt file1.txt file2.txt
certificate: custom-bundle.sigstore
Expand All @@ -197,7 +197,7 @@ from. This setting cannot be used in combination with the `staging` setting.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
fulcio-url: https://fulcio.sigstage.dev
Expand All @@ -213,7 +213,7 @@ cannot be used in combination with the `staging` setting.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
rekor-url: https://rekor.sigstage.dev
Expand All @@ -229,7 +229,7 @@ in combination with the `staging` setting.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
ctfe: ./path/to/ctfe.pub
Expand All @@ -245,7 +245,7 @@ be used in combination with `staging` setting.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
ctfe: ./path/to/rekor.pub
Expand All @@ -261,7 +261,7 @@ instead of the default production instances.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
staging: true
Expand All @@ -284,7 +284,7 @@ and `verify-oidc-issuer` settings. Failing to pass these will produce an error.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
verify: true
Expand All @@ -307,7 +307,7 @@ This setting may only be used in conjunction with `verify-oidc-issuer`.
Supplying it without `verify-oidc-issuer` will produce an error.

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
verify: true
Expand All @@ -332,7 +332,7 @@ Supplying it without `verify-cert-identity` will produce an error.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
verify: true
Expand All @@ -354,7 +354,7 @@ workflow artifact retention period is used.
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
upload-signing-artifacts: true
Expand All @@ -379,7 +379,7 @@ permissions:

# ...

- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
release-signing-artifacts: true
Expand All @@ -406,7 +406,7 @@ permissions:
Example:

```yaml
- uses: sigstore/gh-action-sigstore-python@v1.0.0
- uses: sigstore/gh-action-sigstore-python@v1.1.0
with:
inputs: file.txt
internal-be-careful-debug: true
Expand Down