From 033efb21460725cc3eafd4e42f6a4665f4953afa Mon Sep 17 00:00:00 2001 From: Josh Holtz Date: Wed, 26 Aug 2026 13:03:59 -0500 Subject: [PATCH 1/4] ci: sign release checksums with keyless cosign Add a GoReleaser signs block that signs checksums.txt with keyless cosign (Sigstore/Fulcio), and install cosign in the release workflow. The checksum file covers every artifact, so one signature transitively covers all binaries. Uses the workflow's existing id-token: write for the OIDC identity; signature (.sig) and certificate (.pem) are published alongside the release assets. Verify with: cosign verify-blob --certificate checksums.txt.pem \ --signature checksums.txt.sig \ --certificate-identity-regexp 'https://github.com/RevenueCat/cli/.*' \ --certificate-oidc-issuer https://token.actions.githubusercontent.com \ checksums.txt Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/release.yml | 1 + .goreleaser.yaml | 15 +++++++++++++++ 2 files changed, 16 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 4ab1cdaf..fbc5c1de 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -19,6 +19,7 @@ jobs: - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 with: go-version-file: go.mod + - uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 - uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4.0 with: version: "~> v2" diff --git a/.goreleaser.yaml b/.goreleaser.yaml index e8f35345..271386d7 100644 --- a/.goreleaser.yaml +++ b/.goreleaser.yaml @@ -45,6 +45,21 @@ archives: checksum: name_template: "checksums.txt" +# Keyless (Sigstore/Fulcio) signature over the checksum file, which in turn +# covers every released artifact. Requires cosign on PATH and id-token: write. +signs: + - cmd: cosign + artifacts: checksum + output: true + signature: "${artifact}.sig" + certificate: "${artifact}.pem" + args: + - sign-blob + - "--yes" + - "--output-signature=${signature}" + - "--output-certificate=${certificate}" + - "${artifact}" + snapshot: version_template: "{{ incpatch .Version }}-next" From e02b68f272fdf620dd8b1913d6a6c6dda251186c Mon Sep 17 00:00:00 2001 From: Josh Holtz Date: Wed, 26 Aug 2026 13:21:34 -0500 Subject: [PATCH 2/4] fix(ci): pin cosign v2 so the sign-blob API matches the signs block cosign-installer v4.1.2 installs cosign v3 by default, which replaced the detached --output-signature/--output-certificate sign-blob flags with --bundle. Pin cosign-release v2.6.5 to keep the v2 API our GoReleaser signs block uses. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/release.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index fbc5c1de..5c1f9b94 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -20,6 +20,10 @@ jobs: with: go-version-file: go.mod - uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 + with: + # Pin cosign v2: v3 replaced the detached --output-signature/--output-certificate + # sign-blob API (used by the signs block below) with --bundle. + cosign-release: v2.6.5 - uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4.0 with: version: "~> v2" From 7bb663fa0d3180dda9ba4d5be6b9bef99c75cce5 Mon Sep 17 00:00:00 2001 From: Josh Holtz Date: Wed, 26 Aug 2026 17:25:08 -0500 Subject: [PATCH 3/4] docs: plain-English the cosign comments Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/release.yml | 3 +-- .goreleaser.yaml | 4 ++-- 2 files changed, 3 insertions(+), 4 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 5c1f9b94..019df868 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -21,8 +21,7 @@ jobs: go-version-file: go.mod - uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 with: - # Pin cosign v2: v3 replaced the detached --output-signature/--output-certificate - # sign-blob API (used by the signs block below) with --bundle. + # cosign v3 changed the sign-blob flags the signs block below uses; pin v2. cosign-release: v2.6.5 - uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4.0 with: diff --git a/.goreleaser.yaml b/.goreleaser.yaml index 271386d7..869eeaf9 100644 --- a/.goreleaser.yaml +++ b/.goreleaser.yaml @@ -45,8 +45,8 @@ archives: checksum: name_template: "checksums.txt" -# Keyless (Sigstore/Fulcio) signature over the checksum file, which in turn -# covers every released artifact. Requires cosign on PATH and id-token: write. +# Sign checksums.txt (it hashes every binary, so one signature covers the whole +# release) so downloads can be verified. Signing uses CI's GitHub identity, no keys. signs: - cmd: cosign artifacts: checksum From 37d8e89c999edd407bea5675cb91e9457136d779 Mon Sep 17 00:00:00 2001 From: Josh Holtz Date: Wed, 26 Aug 2026 17:28:20 -0500 Subject: [PATCH 4/4] ci: sign releases with cosign v3 bundle format Use cosign v3's single Sigstore bundle (checksums.txt.sigstore.json) instead of the separate .sig/.pem files, and pin the installer to cosign v3.1.3. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/release.yml | 3 +-- .goreleaser.yaml | 6 ++---- 2 files changed, 3 insertions(+), 6 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 019df868..9011d440 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -21,8 +21,7 @@ jobs: go-version-file: go.mod - uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 with: - # cosign v3 changed the sign-blob flags the signs block below uses; pin v2. - cosign-release: v2.6.5 + cosign-release: v3.1.3 - uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4.0 with: version: "~> v2" diff --git a/.goreleaser.yaml b/.goreleaser.yaml index 869eeaf9..376eeeea 100644 --- a/.goreleaser.yaml +++ b/.goreleaser.yaml @@ -51,13 +51,11 @@ signs: - cmd: cosign artifacts: checksum output: true - signature: "${artifact}.sig" - certificate: "${artifact}.pem" + signature: "${artifact}.sigstore.json" args: - sign-blob - "--yes" - - "--output-signature=${signature}" - - "--output-certificate=${certificate}" + - "--bundle=${signature}" - "${artifact}" snapshot: