Skip to content

CI: sign Windows with ssign (drop the SimplySign container) - #14

Merged
Le-Syl21 merged 1 commit into
mainfrom
ci-sign-with-ssign
Jul 10, 2026
Merged

Le-Syl21 merged 1 commit into
mainfrom
ci-sign-with-ssign

Conversation

@Le-Syl21

Copy link
Copy Markdown
Owner

Remplace le workflow expérimental sign-windows.yml (conteneur SimplySign Desktop 2.9.10 + PKCS#11, ~143 lignes) par un job sign-windows gardé dans ci.yml :

  • le runner Linux installe ssign (crates.io) et signe pinready.exe via Certum — sans Windows, sans conteneur, sans stack proprio
  • gardé par l'environment signing (approbation propriétaire) ; le job release le met en needs: → un tag devient build → approbation → release signée
  • vérif osslsigncode incluse

À merger avant de builder la 0.17.2.

Note : les anciens secrets repo CERTUM_USERID / CERTUM_TOTP_SECRET (pour le conteneur) deviennent inutiles → à supprimer.

🤖 Generated with Claude Code

Replace the standalone SimplySign-Desktop-2.9.10 + PKCS#11 container workflow
with a gated `sign-windows` job in ci.yml: the Linux runner installs ssign and
Authenticode-signs pinready.exe via Certum (no Windows, no container). Gated by
the `signing` environment (owner approval); `release` now needs it, so a tag is
build → approve → signed release.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0138mtPxwfXPetBypyjp6KwU
@Le-Syl21
Le-Syl21 merged commit 88d339c into main Jul 10, 2026
5 checks passed
@Le-Syl21
Le-Syl21 deleted the ci-sign-with-ssign branch July 10, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant