Skip to content

Commit

Permalink
change version and rebuild
Browse files Browse the repository at this point in the history
  • Loading branch information
AEnguerrand committed Dec 2, 2024
1 parent b3127d1 commit c67dc17
Show file tree
Hide file tree
Showing 4 changed files with 15 additions and 15 deletions.
10 changes: 5 additions & 5 deletions .github/workflows/github-attest-predicate.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,15 +22,15 @@ jobs:
- uses: actions/attest@v1
id: attest
with:
subject-path: 'aenguerrand-examplepackage12-0.2.0.tgz'
subject-name: 'pkg:npm/%40aenguerrand/examplepackage12@0.2.0'
subject-path: 'aenguerrand-examplepackage12-0.3.0.tgz'
subject-name: 'pkg:npm/%40aenguerrand/examplepackage12@0.3.0'
predicate-type: 'https://slsa.dev/provenance/v0.2'
predicate: '{"builder":{"id":"https://github.com/slsa-framework/slsa-github-generator/.github/workflows/builder_nodejs_slsa3.yml@refs/tags/v2.0.0"}}'
- name: Upload artifact (build)
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3
with:
name: aenguerrand-examplepackage12-0.2.0.tgz
path: aenguerrand-examplepackage12-0.2.0.tgz
name: aenguerrand-examplepackage12-0.3.0.tgz
path: aenguerrand-examplepackage12-0.3.0.tgz
- name: Upload artifact (build)
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3
with:
Expand All @@ -39,4 +39,4 @@ jobs:
- name: Upload to npmjs.com
run: |
npm config set //registry.npmjs.org/:_authToken "${{ secrets.NPM_TOKEN }}"
npm publish aenguerrand-examplepackage12-0.2.0.tgz --access public --provenance-file ${{ steps.attest.outputs.bundle-path }} --access public
npm publish aenguerrand-examplepackage12-0.3.0.tgz --access public --provenance-file ${{ steps.attest.outputs.bundle-path }} --access public
10 changes: 5 additions & 5 deletions .github/workflows/github-attest.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,13 +22,13 @@ jobs:
- uses: actions/attest-build-provenance@v1
id: attest
with:
subject-path: 'aenguerrand-examplepackage12-0.2.0.tgz'
subject-name: 'pkg:npm/%40aenguerrand/examplepackage12@0.2.0'
subject-path: 'aenguerrand-examplepackage12-0.3.0.tgz'
subject-name: 'pkg:npm/%40aenguerrand/examplepackage12@0.3.0'
- name: Upload artifact (build)
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3
with:
name: aenguerrand-examplepackage12-0.2.0.tgz
path: aenguerrand-examplepackage12-0.2.0.tgz
name: aenguerrand-examplepackage12-0.3.0.tgz
path: aenguerrand-examplepackage12-0.3.0.tgz
- name: Upload artifact (build)
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3
with:
Expand All @@ -37,4 +37,4 @@ jobs:
- name: Upload to npmjs.com
run: |
npm config set //registry.npmjs.org/:_authToken "${{ secrets.NPM_TOKEN }}"
npm publish aenguerrand-examplepackage12-0.2.0.tgz --access public --provenance-file ${{ steps.attest.outputs.bundle-path }} --access public
npm publish aenguerrand-examplepackage12-0.3.0.tgz --access public --provenance-file ${{ steps.attest.outputs.bundle-path }} --access public
8 changes: 4 additions & 4 deletions .github/workflows/sigtstorejs.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ jobs:
- name: Generate dummy package
run: npm pack
- name: Generate provenance statement with package as attestation subject
run: npx @npmcli/provenance-cli generate aenguerrand-examplepackage12-0.2.0.tgz -o provenance-statement.json --subject-name="pkg:npm/%40aenguerrand/examplepackage12@0.2.0"
run: npx @npmcli/provenance-cli generate aenguerrand-examplepackage12-0.3.0.tgz -o provenance-statement.json --subject-name="pkg:npm/%40aenguerrand/examplepackage12@0.3.0"
- name: Sign provenance statement
run: npx @sigstore/cli attest ./provenance-statement.json -o provenance.sigstore.json
- name: "Verify provenance statement (TODO: Verify source identity)"
Expand All @@ -33,8 +33,8 @@ jobs:
- name: Upload artifact (build)
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3
with:
name: aenguerrand-examplepackage12-0.2.0.tgz
path: aenguerrand-examplepackage12-0.2.0.tgz
name: aenguerrand-examplepackage12-0.3.0.tgz
path: aenguerrand-examplepackage12-0.3.0.tgz
- name: Install Cosign
uses: sigstore/[email protected]
- name: debug
Expand All @@ -44,4 +44,4 @@ jobs:
- name: Upload to npmjs.com
run: |
npm config set //registry.npmjs.org/:_authToken "${{ secrets.NPM_TOKEN }}"
npm publish aenguerrand-examplepackage12-0.2.0.tgz --access public --provenance-file provenance.sigstore.json --access public
npm publish aenguerrand-examplepackage12-0.3.0.tgz --access public --provenance-file provenance.sigstore.json --access public
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@aenguerrand/examplepackage12",
"version": "0.2.0",
"version": "0.3.0",
"description": "An example npm package for demonstration purposes.",
"main": "index.js",
"scripts": {
Expand Down

0 comments on commit c67dc17

Please sign in to comment.