# Attest an npm package on every release tag: npm pack of the COMMITTED tree, attestation, rebuild check from a clean # clone of the commit, optional hybrid signature, optional notarization on Aere Network (chain 2800). # # Repository secrets used (both optional): # AERE_POS_SIGNING_KEY the key file written by `node tools/proof-of-software/pos.mjs keygen --out keys.json` # (paste the JSON, or base64 of it). Keep keys.json itself off the repository. # AERE_API_KEY an Aere Cloud API key; without it the attestation is not notarized, and the summary says so. name: Attest npm package on: push: tags: ['v*'] permissions: contents: read jobs: attest: runs-on: ubuntu-latest steps: # the default fetch-depth (1) is enough: the rebuild needs only the attested commit - uses: actions/checkout@v4 # npm on PATH performs the pack; its version is recorded in the statement - uses: actions/setup-node@v4 with: node-version: 22 - id: pos # Reference this action by its directory in the repository that contains it, pinned to a full commit SHA. uses: //tools/proof-of-software/action@ with: source-path: packages/mylib signing-key: ${{ secrets.AERE_POS_SIGNING_KEY }} aere-api-key: ${{ secrets.AERE_API_KEY }} # verify-rebuild: true (default; the step fails if the artifact is not reproduced byte for byte) - uses: actions/upload-artifact@v4 with: name: proof-of-software path: | ${{ steps.pos.outputs.attestation-path }} ${{ steps.pos.outputs.artifact-path }} # Optional: publish the very file that was attested, never a new pack. # - run: npm publish "${{ steps.pos.outputs.artifact-path }}" # env: # NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - run: | echo "artifact sha256: ${{ steps.pos.outputs.artifact-sha256 }}" echo "git tree: ${{ steps.pos.outputs.tree }}" echo "statement hash: ${{ steps.pos.outputs.statement-hash }}" echo "notarized tx: ${{ steps.pos.outputs.notarized-tx }}"