Commit eeb829b
authored
release: switch signing sidecars to sigstore bundles (#358)
## Summary
- switch shared release signing from legacy `.sig` / `.pem` sidecars to
Sigstore bundle sidecars
- update direct installers to verify `*.sigstore.json` bundles with
`cosign verify-blob --bundle`
- align release contracts and public docs with the new bundle-only
direct install flow
## Evidence
- fixes the `release-nodeup` failure in GitHub Actions where `cosign
v3.0.5` rejected the old `sign-blob` invocation
- local smoke test with `cosign v3.0.5` now produces `SHA256SUMS` plus
`*.sigstore.json` and verifies successfully
## Current Gap
- release automation still emitted legacy sidecars that are incompatible
with the current `cosign` behavior
- direct installer scripts and docs still referenced `.sig` / `.pem`
artifacts
## Proposed Scope
- update `scripts/release/generate-checksums.sh` to emit bundle sidecars
only
- update shell and PowerShell direct installers for `nodeup`, `derun`,
and `dexdex`
- update docs and public docs pages to document bundle-only direct
installs
## Acceptance Criteria
- release workflows publish `SHA256SUMS` and `*.sigstore.json` sidecars
without legacy `.sig` / `.pem` files
- direct installers verify bundle sidecars successfully
- docs and public docs match the new release artifact contract
## Test Scenarios
- `bash -n scripts/release/generate-checksums.sh
scripts/install/nodeup.sh scripts/install/derun.sh
scripts/install/dexdex-stack.sh`
- local `cosign v3.0.5` smoke test for bundle generation and
`verify-blob --bundle`
- `pnpm --filter public-docs test`
## Out of Scope
- republishing `nodeup@v0.1.10`
- legacy installer fallback for historical `.sig` / `.pem`-only releases1 parent 5bb2074 commit eeb829b
File tree
19 files changed
+145
-58
lines changed- apps/public-docs
- docs
- scripts
- install
- release
19 files changed
+145
-58
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
| 46 | + | |
| 47 | + | |
46 | 48 | | |
47 | 49 | | |
48 | 50 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
| 47 | + | |
| 48 | + | |
47 | 49 | | |
48 | 50 | | |
49 | 51 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
42 | 42 | | |
43 | 43 | | |
44 | 44 | | |
| 45 | + | |
| 46 | + | |
45 | 47 | | |
46 | 48 | | |
47 | 49 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
| 22 | + | |
22 | 23 | | |
23 | 24 | | |
24 | 25 | | |
| 26 | + | |
25 | 27 | | |
26 | 28 | | |
27 | 29 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
| 69 | + | |
69 | 70 | | |
70 | 71 | | |
71 | 72 | | |
72 | 73 | | |
73 | | - | |
| 74 | + | |
74 | 75 | | |
75 | 76 | | |
76 | 77 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
21 | 22 | | |
22 | 23 | | |
23 | 24 | | |
| |||
53 | 54 | | |
54 | 55 | | |
55 | 56 | | |
| 57 | + | |
56 | 58 | | |
57 | 59 | | |
58 | 60 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| 24 | + | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
21 | 22 | | |
22 | 23 | | |
23 | 24 | | |
24 | 25 | | |
25 | 26 | | |
26 | 27 | | |
| 28 | + | |
27 | 29 | | |
28 | 30 | | |
29 | 31 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
139 | 139 | | |
140 | 140 | | |
141 | 141 | | |
142 | | - | |
| 142 | + | |
| 143 | + | |
143 | 144 | | |
144 | 145 | | |
145 | 146 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
21 | | - | |
| 21 | + | |
| 22 | + | |
22 | 23 | | |
23 | 24 | | |
24 | 25 | | |
| |||
0 commit comments