Compare commits

..

No commits in common. "39bc8b065c4a4ab5c59e7f2e2f34f1da021c4822" and "d53fdbc5364bf2ee6b65dd69c0e6f43728e0f03f" have entirely different histories.

11 changed files with 84 additions and 422 deletions

View File

@ -6,14 +6,12 @@ on:
workflow_dispatch: workflow_dispatch:
permissions: permissions:
contents: read
jobs:
ci:
permissions:
contents: write contents: write
id-token: write id-token: write
attestations: write attestations: write
jobs:
ci:
name: "${{ matrix.target }}" name: "${{ matrix.target }}"
strategy: strategy:
matrix: matrix:
@ -53,6 +51,12 @@ jobs:
with: with:
name: "3proxy-${{ env.RELEASE }}-arm64.rpm" name: "3proxy-${{ env.RELEASE }}-arm64.rpm"
path: "*.rpm" path: "*.rpm"
- name: Upload rpm to release
if: github.event_name == 'release'
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" 3proxy-${{ env.RELEASE }}.arm64.rpm
- name: debbuild - name: debbuild
run: | run: |
ret=`pwd` ret=`pwd`
@ -73,68 +77,12 @@ jobs:
with: with:
name: "3proxy-${{ env.RELEASE }}-arm64.deb" name: "3proxy-${{ env.RELEASE }}-arm64.deb"
path: "*.deb" path: "*.deb"
- name: Import signing key - name: Upload deb to release
if: github.event_name == 'release' if: github.event_name == 'release'
env: env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} GH_TOKEN: ${{ github.token }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} TAG: ${{ github.event.release.tag_name }}
run: | run: gh release upload "$TAG" 3proxy-${{ env.RELEASE }}.arm64.deb
if [ -z "$GPG_PRIVATE_KEY" ]; then echo "GPG_PRIVATE_KEY is not set"; exit 1; fi
mkdir -p ~/.gnupg && chmod 700 ~/.gnupg
printf 'allow-loopback-pinentry\ndefault-cache-ttl 7200\nmax-cache-ttl 7200\n' > ~/.gnupg/gpg-agent.conf
gpgconf --kill gpg-agent || true
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
KEYID=$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/{print $5; exit}')
echo "GPG_KEYID=$KEYID" >> $GITHUB_ENV
echo prime > /tmp/prime.txt
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
-u "$KEYID" --detach-sign -o /dev/null /tmp/prime.txt
rm -f /tmp/prime.txt
- name: Sign rpm
if: github.event_name == 'release'
env:
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
GPGBIN=$(command -v gpg)
if [ -z "$GPGBIN" ]; then echo "gpg not found"; exit 1; fi
umask 077
printf '%s' "$GPG_PASSPHRASE" > /tmp/gpgpass
echo test > /tmp/signtest
gpg --batch --yes --pinentry-mode loopback --passphrase-file /tmp/gpgpass \
-u "$GPG_KEYID" --detach-sign -o /tmp/signtest.sig /tmp/signtest
echo "key can sign"
{ echo "%_gpg_name $GPG_KEYID"
echo "%__gpg $GPGBIN"
echo '%__gpg_sign_cmd %{__gpg} gpg --batch --no-armor --pinentry-mode loopback --passphrase-file /tmp/gpgpass --no-secmem-warning --digest-algo sha256 -u "%{_gpg_name}" -sbo %{__signature_filename} %{__plaintext_filename}'
} > ~/.rpmmacros
rpm --addsign *.rpm
rm -f /tmp/gpgpass /tmp/signtest /tmp/signtest.sig
for f in *.rpm; do
sig=$(rpm -qp --qf '%{RSAHEADER:pgpsig}' "$f" 2>/dev/null)
case "$sig" in ""|"(none)")
sig=$(rpm -qp --qf '%{DSAHEADER:pgpsig}' "$f" 2>/dev/null) ;;
esac
case "$sig" in ""|"(none)")
echo "$f is not signed"
echo "--- rpm version ---"; rpm --version
echo "--- sign cmd ---"; rpm --eval '%{__gpg_sign_cmd}'
echo "--- secret keys ---"; gpg --list-secret-keys --with-colons | grep -E '^(sec|ssb):' || true
exit 1 ;;
esac
echo "$f: $sig"
done
- name: Checksums and detached signatures
if: github.event_name == 'release'
env:
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
sha256sum *.rpm *.deb > SHA256SUMS-arm64
for f in *.deb SHA256SUMS-arm64; do
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
-u "$GPG_KEYID" --armor --detach-sign "$f"
done
sha256sum -c SHA256SUMS-arm64
gpg --verify SHA256SUMS-arm64.asc SHA256SUMS-arm64
- name: Attest build provenance - name: Attest build provenance
if: github.event_name == 'release' if: github.event_name == 'release'
uses: actions/attest-build-provenance@v2 uses: actions/attest-build-provenance@v2
@ -142,9 +90,3 @@ jobs:
subject-path: | subject-path: |
*.rpm *.rpm
*.deb *.deb
- name: Upload to release
if: github.event_name == 'release'
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" *.rpm *.deb *.deb.asc SHA256SUMS-arm64 SHA256SUMS-arm64.asc

View File

@ -6,14 +6,12 @@ on:
workflow_dispatch: workflow_dispatch:
permissions: permissions:
contents: read
jobs:
ci:
permissions:
contents: write contents: write
id-token: write id-token: write
attestations: write attestations: write
jobs:
ci:
name: "${{ matrix.target }}" name: "${{ matrix.target }}"
strategy: strategy:
matrix: matrix:
@ -80,6 +78,12 @@ jobs:
with: with:
name: "3proxy-${{ env.RELEASE }}-arm.rpm" name: "3proxy-${{ env.RELEASE }}-arm.rpm"
path: "*.rpm" path: "*.rpm"
- name: Upload rpm to release
if: github.event_name == 'release'
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" 3proxy-${{ env.RELEASE }}.arm.rpm
- name: debbuild - name: debbuild
run: | run: |
ret=`pwd` ret=`pwd`
@ -106,68 +110,12 @@ jobs:
with: with:
name: "3proxy-${{ env.RELEASE }}-arm.deb" name: "3proxy-${{ env.RELEASE }}-arm.deb"
path: "*.deb" path: "*.deb"
- name: Import signing key - name: Upload deb to release
if: github.event_name == 'release' if: github.event_name == 'release'
env: env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} GH_TOKEN: ${{ github.token }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} TAG: ${{ github.event.release.tag_name }}
run: | run: gh release upload "$TAG" 3proxy-${{ env.RELEASE }}.arm.deb
if [ -z "$GPG_PRIVATE_KEY" ]; then echo "GPG_PRIVATE_KEY is not set"; exit 1; fi
mkdir -p ~/.gnupg && chmod 700 ~/.gnupg
printf 'allow-loopback-pinentry\ndefault-cache-ttl 7200\nmax-cache-ttl 7200\n' > ~/.gnupg/gpg-agent.conf
gpgconf --kill gpg-agent || true
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
KEYID=$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/{print $5; exit}')
echo "GPG_KEYID=$KEYID" >> $GITHUB_ENV
echo prime > /tmp/prime.txt
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
-u "$KEYID" --detach-sign -o /dev/null /tmp/prime.txt
rm -f /tmp/prime.txt
- name: Sign rpm
if: github.event_name == 'release'
env:
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
GPGBIN=$(command -v gpg)
if [ -z "$GPGBIN" ]; then echo "gpg not found"; exit 1; fi
umask 077
printf '%s' "$GPG_PASSPHRASE" > /tmp/gpgpass
echo test > /tmp/signtest
gpg --batch --yes --pinentry-mode loopback --passphrase-file /tmp/gpgpass \
-u "$GPG_KEYID" --detach-sign -o /tmp/signtest.sig /tmp/signtest
echo "key can sign"
{ echo "%_gpg_name $GPG_KEYID"
echo "%__gpg $GPGBIN"
echo '%__gpg_sign_cmd %{__gpg} gpg --batch --no-armor --pinentry-mode loopback --passphrase-file /tmp/gpgpass --no-secmem-warning --digest-algo sha256 -u "%{_gpg_name}" -sbo %{__signature_filename} %{__plaintext_filename}'
} > ~/.rpmmacros
rpm --addsign *.rpm
rm -f /tmp/gpgpass /tmp/signtest /tmp/signtest.sig
for f in *.rpm; do
sig=$(rpm -qp --qf '%{RSAHEADER:pgpsig}' "$f" 2>/dev/null)
case "$sig" in ""|"(none)")
sig=$(rpm -qp --qf '%{DSAHEADER:pgpsig}' "$f" 2>/dev/null) ;;
esac
case "$sig" in ""|"(none)")
echo "$f is not signed"
echo "--- rpm version ---"; rpm --version
echo "--- sign cmd ---"; rpm --eval '%{__gpg_sign_cmd}'
echo "--- secret keys ---"; gpg --list-secret-keys --with-colons | grep -E '^(sec|ssb):' || true
exit 1 ;;
esac
echo "$f: $sig"
done
- name: Checksums and detached signatures
if: github.event_name == 'release'
env:
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
sha256sum *.rpm *.deb > SHA256SUMS-arm
for f in *.deb SHA256SUMS-arm; do
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
-u "$GPG_KEYID" --armor --detach-sign "$f"
done
sha256sum -c SHA256SUMS-arm
gpg --verify SHA256SUMS-arm.asc SHA256SUMS-arm
- name: Attest build provenance - name: Attest build provenance
if: github.event_name == 'release' if: github.event_name == 'release'
uses: actions/attest-build-provenance@v2 uses: actions/attest-build-provenance@v2
@ -175,9 +123,3 @@ jobs:
subject-path: | subject-path: |
*.rpm *.rpm
*.deb *.deb
- name: Upload to release
if: github.event_name == 'release'
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" *.rpm *.deb *.deb.asc SHA256SUMS-arm SHA256SUMS-arm.asc

View File

@ -6,14 +6,12 @@ on:
workflow_dispatch: workflow_dispatch:
permissions: permissions:
contents: read
jobs:
ci:
permissions:
contents: write contents: write
id-token: write id-token: write
attestations: write attestations: write
jobs:
ci:
name: "${{ matrix.target }}" name: "${{ matrix.target }}"
strategy: strategy:
matrix: matrix:
@ -53,6 +51,12 @@ jobs:
with: with:
name: "3proxy-${{ env.RELEASE }}-x86_64.rpm" name: "3proxy-${{ env.RELEASE }}-x86_64.rpm"
path: "*.rpm" path: "*.rpm"
- name: Upload rpm to release
if: github.event_name == 'release'
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" 3proxy-${{ env.RELEASE }}.x86_64.rpm
- name: debbuild - name: debbuild
run: | run: |
ret=`pwd` ret=`pwd`
@ -73,69 +77,13 @@ jobs:
with: with:
name: "3proxy-${{ env.RELEASE }}-x86_64.deb" name: "3proxy-${{ env.RELEASE }}-x86_64.deb"
path: "*.deb" path: "*.deb"
- name: Upload deb to release
if: github.event_name == 'release'
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" 3proxy-${{ env.RELEASE }}.x86_64.deb
- name: Import signing key
if: github.event_name == 'release'
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
if [ -z "$GPG_PRIVATE_KEY" ]; then echo "GPG_PRIVATE_KEY is not set"; exit 1; fi
mkdir -p ~/.gnupg && chmod 700 ~/.gnupg
printf 'allow-loopback-pinentry\ndefault-cache-ttl 7200\nmax-cache-ttl 7200\n' > ~/.gnupg/gpg-agent.conf
gpgconf --kill gpg-agent || true
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
KEYID=$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/{print $5; exit}')
echo "GPG_KEYID=$KEYID" >> $GITHUB_ENV
echo prime > /tmp/prime.txt
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
-u "$KEYID" --detach-sign -o /dev/null /tmp/prime.txt
rm -f /tmp/prime.txt
- name: Sign rpm
if: github.event_name == 'release'
env:
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
GPGBIN=$(command -v gpg)
if [ -z "$GPGBIN" ]; then echo "gpg not found"; exit 1; fi
umask 077
printf '%s' "$GPG_PASSPHRASE" > /tmp/gpgpass
echo test > /tmp/signtest
gpg --batch --yes --pinentry-mode loopback --passphrase-file /tmp/gpgpass \
-u "$GPG_KEYID" --detach-sign -o /tmp/signtest.sig /tmp/signtest
echo "key can sign"
{ echo "%_gpg_name $GPG_KEYID"
echo "%__gpg $GPGBIN"
echo '%__gpg_sign_cmd %{__gpg} gpg --batch --no-armor --pinentry-mode loopback --passphrase-file /tmp/gpgpass --no-secmem-warning --digest-algo sha256 -u "%{_gpg_name}" -sbo %{__signature_filename} %{__plaintext_filename}'
} > ~/.rpmmacros
rpm --addsign *.rpm
rm -f /tmp/gpgpass /tmp/signtest /tmp/signtest.sig
for f in *.rpm; do
sig=$(rpm -qp --qf '%{RSAHEADER:pgpsig}' "$f" 2>/dev/null)
case "$sig" in ""|"(none)")
sig=$(rpm -qp --qf '%{DSAHEADER:pgpsig}' "$f" 2>/dev/null) ;;
esac
case "$sig" in ""|"(none)")
echo "$f is not signed"
echo "--- rpm version ---"; rpm --version
echo "--- sign cmd ---"; rpm --eval '%{__gpg_sign_cmd}'
echo "--- secret keys ---"; gpg --list-secret-keys --with-colons | grep -E '^(sec|ssb):' || true
exit 1 ;;
esac
echo "$f: $sig"
done
- name: Checksums and detached signatures
if: github.event_name == 'release'
env:
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
sha256sum *.rpm *.deb > SHA256SUMS-x86_64
for f in *.deb SHA256SUMS-x86_64; do
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
-u "$GPG_KEYID" --armor --detach-sign "$f"
done
sha256sum -c SHA256SUMS-x86_64
gpg --verify SHA256SUMS-x86_64.asc SHA256SUMS-x86_64
- name: Attest build provenance - name: Attest build provenance
if: github.event_name == 'release' if: github.event_name == 'release'
uses: actions/attest-build-provenance@v2 uses: actions/attest-build-provenance@v2
@ -143,9 +91,3 @@ jobs:
subject-path: | subject-path: |
*.rpm *.rpm
*.deb *.deb
- name: Upload to release
if: github.event_name == 'release'
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" *.rpm *.deb *.deb.asc SHA256SUMS-x86_64 SHA256SUMS-x86_64.asc

View File

@ -6,14 +6,12 @@ on:
workflow_dispatch: workflow_dispatch:
permissions: permissions:
contents: read
jobs:
ci:
permissions:
contents: write contents: write
id-token: write id-token: write
attestations: write attestations: write
jobs:
ci:
name: "${{ matrix.target }}" name: "${{ matrix.target }}"
strategy: strategy:
matrix: matrix:
@ -90,30 +88,16 @@ jobs:
if: github.event_name == 'release' if: github.event_name == 'release'
shell: pwsh shell: pwsh
run: Compress-Archive -Path dist/* -DestinationPath 3proxy-${{ env.RELEASE }}-lite.zip run: Compress-Archive -Path dist/* -DestinationPath 3proxy-${{ env.RELEASE }}-lite.zip
- name: Checksums and detached signature
if: github.event_name == 'release'
shell: bash
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
if [ -z "$GPG_PRIVATE_KEY" ]; then echo "GPG_PRIVATE_KEY is not set"; exit 1; fi
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
KEYID=$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/{print $5; exit}')
sha256sum *.zip > SHA256SUMS-win-lite
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
-u "$KEYID" --armor --detach-sign SHA256SUMS-win-lite
sha256sum -c SHA256SUMS-win-lite
- name: Attest build provenance
if: github.event_name == 'release'
uses: actions/attest-build-provenance@v2
with:
subject-path: |
*.zip
- name: Upload to release - name: Upload to release
if: github.event_name == 'release' if: github.event_name == 'release'
shell: bash shell: bash
env: env:
GH_TOKEN: ${{ github.token }} GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }} TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" *.zip SHA256SUMS-win-lite SHA256SUMS-win-lite.asc run: gh release upload "$TAG" 3proxy-${{ env.RELEASE }}-lite.zip
- name: Attest build provenance
if: github.event_name == 'release'
uses: actions/attest-build-provenance@v2
with:
subject-path: |
*.zip

View File

@ -6,14 +6,12 @@ on:
workflow_dispatch: workflow_dispatch:
permissions: permissions:
contents: read
jobs:
ci:
permissions:
contents: write contents: write
id-token: write id-token: write
attestations: write attestations: write
jobs:
ci:
name: "${{ matrix.target }}" name: "${{ matrix.target }}"
strategy: strategy:
matrix: matrix:
@ -105,30 +103,16 @@ jobs:
if: github.event_name == 'release' if: github.event_name == 'release'
shell: pwsh shell: pwsh
run: Compress-Archive -Path dist/* -DestinationPath 3proxy-${{ env.RELEASE }}-x86.zip run: Compress-Archive -Path dist/* -DestinationPath 3proxy-${{ env.RELEASE }}-x86.zip
- name: Checksums and detached signature
if: github.event_name == 'release'
shell: bash
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
if [ -z "$GPG_PRIVATE_KEY" ]; then echo "GPG_PRIVATE_KEY is not set"; exit 1; fi
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
KEYID=$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/{print $5; exit}')
sha256sum *.zip > SHA256SUMS-win-x86
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
-u "$KEYID" --armor --detach-sign SHA256SUMS-win-x86
sha256sum -c SHA256SUMS-win-x86
- name: Attest build provenance
if: github.event_name == 'release'
uses: actions/attest-build-provenance@v2
with:
subject-path: |
*.zip
- name: Upload to release - name: Upload to release
if: github.event_name == 'release' if: github.event_name == 'release'
shell: bash shell: bash
env: env:
GH_TOKEN: ${{ github.token }} GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }} TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" *.zip SHA256SUMS-win-x86 SHA256SUMS-win-x86.asc run: gh release upload "$TAG" 3proxy-${{ env.RELEASE }}-x86.zip
- name: Attest build provenance
if: github.event_name == 'release'
uses: actions/attest-build-provenance@v2
with:
subject-path: |
*.zip

View File

@ -6,14 +6,12 @@ on:
workflow_dispatch: workflow_dispatch:
permissions: permissions:
contents: read
jobs:
ci:
permissions:
contents: write contents: write
id-token: write id-token: write
attestations: write attestations: write
jobs:
ci:
name: "${{ matrix.target }}" name: "${{ matrix.target }}"
strategy: strategy:
matrix: matrix:
@ -106,30 +104,16 @@ jobs:
if: github.event_name == 'release' if: github.event_name == 'release'
shell: pwsh shell: pwsh
run: Compress-Archive -Path dist/* -DestinationPath 3proxy-${{ env.RELEASE }}-x64.zip run: Compress-Archive -Path dist/* -DestinationPath 3proxy-${{ env.RELEASE }}-x64.zip
- name: Checksums and detached signature
if: github.event_name == 'release'
shell: bash
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
if [ -z "$GPG_PRIVATE_KEY" ]; then echo "GPG_PRIVATE_KEY is not set"; exit 1; fi
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
KEYID=$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/{print $5; exit}')
sha256sum *.zip > SHA256SUMS-win-x64
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
-u "$KEYID" --armor --detach-sign SHA256SUMS-win-x64
sha256sum -c SHA256SUMS-win-x64
- name: Attest build provenance
if: github.event_name == 'release'
uses: actions/attest-build-provenance@v2
with:
subject-path: |
*.zip
- name: Upload to release - name: Upload to release
if: github.event_name == 'release' if: github.event_name == 'release'
shell: bash shell: bash
env: env:
GH_TOKEN: ${{ github.token }} GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }} TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" *.zip SHA256SUMS-win-x64 SHA256SUMS-win-x64.asc run: gh release upload "$TAG" 3proxy-${{ env.RELEASE }}-x64.zip
- name: Attest build provenance
if: github.event_name == 'release'
uses: actions/attest-build-provenance@v2
with:
subject-path: |
*.zip

View File

@ -6,14 +6,12 @@ on:
workflow_dispatch: workflow_dispatch:
permissions: permissions:
contents: read
jobs:
ci:
permissions:
contents: write contents: write
id-token: write id-token: write
attestations: write attestations: write
jobs:
ci:
name: "${{ matrix.target }}" name: "${{ matrix.target }}"
strategy: strategy:
matrix: matrix:
@ -105,30 +103,16 @@ jobs:
if: github.event_name == 'release' if: github.event_name == 'release'
shell: pwsh shell: pwsh
run: Compress-Archive -Path dist/* -DestinationPath 3proxy-${{ env.RELEASE }}-arm64.zip run: Compress-Archive -Path dist/* -DestinationPath 3proxy-${{ env.RELEASE }}-arm64.zip
- name: Checksums and detached signature
if: github.event_name == 'release'
shell: bash
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
if [ -z "$GPG_PRIVATE_KEY" ]; then echo "GPG_PRIVATE_KEY is not set"; exit 1; fi
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
KEYID=$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/{print $5; exit}')
sha256sum *.zip > SHA256SUMS-win-arm64
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
-u "$KEYID" --armor --detach-sign SHA256SUMS-win-arm64
sha256sum -c SHA256SUMS-win-arm64
- name: Attest build provenance
if: github.event_name == 'release'
uses: actions/attest-build-provenance@v2
with:
subject-path: |
*.zip
- name: Upload to release - name: Upload to release
if: github.event_name == 'release' if: github.event_name == 'release'
shell: bash shell: bash
env: env:
GH_TOKEN: ${{ github.token }} GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }} TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" *.zip SHA256SUMS-win-arm64 SHA256SUMS-win-arm64.asc run: gh release upload "$TAG" 3proxy-${{ env.RELEASE }}-arm64.zip
- name: Attest build provenance
if: github.event_name == 'release'
uses: actions/attest-build-provenance@v2
with:
subject-path: |
*.zip

View File

@ -7,6 +7,9 @@ on:
permissions: permissions:
contents: read contents: read
packages: write
id-token: write
attestations: write
env: env:
DOCKERHUB_IMAGE: docker.io/3proxy/3proxy DOCKERHUB_IMAGE: docker.io/3proxy/3proxy
@ -15,9 +18,6 @@ env:
jobs: jobs:
build: build:
name: ${{ matrix.image }} ${{ matrix.platform }} name: ${{ matrix.image }} ${{ matrix.platform }}
permissions:
contents: read
packages: write
runs-on: ${{ matrix.runner }} runs-on: ${{ matrix.runner }}
strategy: strategy:
fail-fast: false fail-fast: false
@ -81,11 +81,6 @@ jobs:
publish: publish:
name: Publish ${{ matrix.image }} name: Publish ${{ matrix.image }}
permissions:
contents: read
packages: write
id-token: write
attestations: write
runs-on: ubuntu-latest runs-on: ubuntu-latest
needs: build needs: build
strategy: strategy:

View File

@ -1,10 +0,0 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----
mDMEaogJthYJKwYBBAHaRw8BAQdA8rZ4l90kTOSrlosP0yyeX6jFGfiFFizawjS0
vyQnmu60KjNwcm94eSByZWxlYXNlIHNpZ25pbmcgPDNwcm94eUAzcHJveHkub3Jn
PoivBBMWCgBXFiEEvHxfo3tIuOfF5ScUw2JYsMbAg6oFAmqICbYbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMCwzAhsDBQsJCAcCAiICBhUKCQgLAgQWAgMBAh4HAheA
AAoJEMNiWLDGwIOqBHIA/iRus5VEqL+v6nYQ+GDLDUZJzMfFcnDBI+BOOhiESnTp
AP4s3uvhigRcdutxkYwSXBlJ+7wE1yZeuUmjPoJXvgNaDw==
=Ngp2
-----END PGP PUBLIC KEY BLOCK-----

View File

@ -1,29 +0,0 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBGqIZCIBEADF3zxdMo2dvUGAlQm3aIcQiqmpLMHucvLfSK3fHtwagO8f03CO
bEx9EfIK/U6BzLwEJ0CxyClzfvgo9COVpi5EjES9sI2LXzcgc4hGaYO0Q4Unj//0
W/G8aarDaLF2NRKMLf07eaYGBRJjqHnmeHgOHdr+SnN0JtMSadWMHoliB8esnabz
5CO4JabTrhwoez3DMLSgJNIod7wL6PJJv/2BeRahwNr2CjaXmzZKr/j7fc1MKLij
bsvJ5OmLmngZr6CHDa9cBhVhiH+7RgWLCsRlEGxEv7w0afp/T0xDwNAPkGzk5ObC
BrdXvypTAbNyUoVT8qSVJwkneZ4S0Ts4rRRNfNpaus4tsCmgyGKzsrbxvbiBOTPW
jB/fjkgr6X9M/AQ3yGpXrwXRJrM/nSfjUyOEHXttTC9HpGt41NH/mpC4mDWa1Kxi
FMxuo1+dw2kpDKl0Bp78IGdCo5akHwftFr8aHgmfZoGXAGJRHPAWbJGjC2ARy8yp
QOpxba0S3VlCU6bs8MDKl6cpWItnlXcl/GD/Qc55bjLXjFv1pbn2RUSYZS+n9wDX
64syZf3dZ/N5U4ydmybWfiLFUXqKQLtdO8QAWQGt4TSwKptTmI581/MMCTQ8qWZL
zgFj6C/8K0SZ4lMOv+5zfc2+QOoWw7E2Ws3stEKTyWjOMm/QMJAGumqvqwARAQAB
tCozcHJveHkgcmVsZWFzZSBzaWduaW5nIDwzcHJveHlAM3Byb3h5Lm9yZz6JAm0E
EwEIAFcWIQT8EiFEmfzHuhz/bNwDEjhOOnOUCwUCaohkIhsUgAAAAAAEAA5tYW51
MiwyLjUrMS4xMiwwLDMCGwMFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQ
AxI4TjpzlAsCwRAAtH3OO42yCd2B8Od4yS1yBDkaIFwEm8hF68eou6uaSDkKG8YZ
C3DUH7qk0nXEMQu/5J6RWZKlW1C8D3AkUR9A1g54o6mUg4IL5196XsrQRdVu64YF
nLCk17Piku1lMk+Re6bZ6uJv5UlSv8d0dvxmAYzjusyPyBC2VXy7B0CoDif6AmXt
aw2/V6m0dRrfFo4W9mJKUqTAJcdBOKzEiQb7qLnzuwy4CB5qsvnEQTqymoCXFXzg
VDCSKRLXnbDPbIs0TvsCmthn/w1hCgftPq4W0s7EUJBOhbrjF59+AuTb+U1wIXNR
1+DPF+V+5RlwWjOWMlsOVGk2jaxjVY8wuaD3rE6ISJkt1pRv/WVdY984rT7Eu94J
ZHnxPjFrb2ohFKjoBCt60kbgZbuQ6yvEma5lAF9K63gwMNNyGZvq6QWl58iouzuS
3B9t7EwGwFstJfaXVhn/rnIHoExgxVZMbbsmXiGJyE2KcfVmlZcEi0MIyqEeBSDD
gjpE4yVO6StBtJKfXra8rMwtsbWBw9MptPhcLvdWtN6TG0CxDyTHhdL1pSLNcwX1
CTVpwi6+WmGogcv0WFNn5caQUpu9le/v/5qLRK08KWOH8inMJmTfpJg/9869YJuF
vDKdzJd6jug5YQRfV/7YVC2hdSOBLvBuDpRINePrj9CKJ34qG+jRSJ5xwYk=
=IS3Y
-----END PGP PUBLIC KEY BLOCK-----

View File

@ -12,59 +12,3 @@
Report to 3proxy@3proxy.org or via [GitHub security reporting](https://github.com/3proxy/3proxy/security) Report to 3proxy@3proxy.org or via [GitHub security reporting](https://github.com/3proxy/3proxy/security)
For High/Critical patched version is released within 2 weeks For High/Critical patched version is released within 2 weeks
## Verifying downloads
Release binaries are published with SHA256 checksums, an OpenPGP signature and
a GitHub build provenance attestation.
The release signing key is `3proxy-release-key.asc` in the root of this
repository, an RSA-4096 key:
```
pub rsa4096 2026-08-21 [SC]
FC12 2144 99FC C7BA 1CFF 6CDC 0312 384E 3A73 940B
uid 3proxy release signing <3proxy@3proxy.org>
```
Import it once:
```
gpg --import 3proxy-release-key.asc
```
Releases up to and including 0.9.9 were signed with an Ed25519 key, kept as
`3proxy-release-key-ed25519.asc` for verifying those older files. Note that
rpm 4.14 and earlier (RHEL/CentOS 8 and older) cannot import an Ed25519 key
and will report `SIGNATURES NOT OK`; use the RSA key and 0.9.9.1 or later on
those systems.
Checksums and the checksum file signature:
```
gpg --verify SHA256SUMS-x86_64.asc SHA256SUMS-x86_64
sha256sum -c SHA256SUMS-x86_64
```
RPM packages are signed, the signature is checked by rpm itself:
```
sudo rpm --import 3proxy-release-key.asc
rpm -K 3proxy-0.9.9.x86_64.rpm
```
DEB packages are published with a detached signature:
```
gpg --verify 3proxy-0.9.9.x86_64.deb.asc 3proxy-0.9.9.x86_64.deb
```
Build provenance (which workflow, commit and runner produced the file) is
verified with the GitHub CLI:
```
gh attestation verify 3proxy-0.9.9.x86_64.rpm --owner 3proxy
gh attestation verify oci://docker.io/3proxy/3proxy:lts --owner 3proxy
```
Windows binaries are Authenticode signed in addition to the above.