windows code-sign (follow electron-fiddle)

This commit is contained in:
Will Chen
2025-04-29 22:00:48 -07:00
parent 235c90e33e
commit 60b403e904
2 changed files with 10 additions and 3 deletions

View File

@@ -57,10 +57,15 @@ jobs:
- name: Code signing with Software Trust Manager - name: Code signing with Software Trust Manager
if: contains(matrix.os.name, 'windows') if: contains(matrix.os.name, 'windows')
uses: digicert/ssm-code-signing@v1.0.0 uses: digicert/ssm-code-signing@v1.0.0
# Publish (all platforms) - name: Sync certificate (Windows)
if: contains(matrix.os.name, 'windows')
run: |
smctl windows certsync --keypair-alias=${{ secrets.DIGICERT_KEYPAIR_ALIAS }}
shell: bash
# Publish (all platforms)
- name: Publish app - name: Publish app
env: env:
DIGICERT_KEYPAIR_ALIAS: ${{ secrets.DIGICERT_KEYPAIR_ALIAS }} SM_CODE_SIGNING_CERT_SHA1_HASH: ${{ secrets.SM_CODE_SIGNING_CERT_SHA1_HASH }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }} APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
APPLE_ID: ${{ secrets.APPLE_ID }} APPLE_ID: ${{ secrets.APPLE_ID }}

View File

@@ -68,7 +68,9 @@ const config: ForgeConfig = {
}, },
makers: [ makers: [
new MakerSquirrel({ new MakerSquirrel({
signWithParams: `/csp "DigiCert Signing Manager KSP" /kc ${process.env.DIGICERT_KEYPAIR_ALIAS} /f ${process.env.SM_CLIENT_CERT_FILE} /tr http://timestamp.digicert.com /td SHA256 /fd SHA256`, signWithParams: `/sha1 ${process.env.SM_CODE_SIGNING_CERT_SHA1_HASH} /tr http://timestamp.digicert.com /td SHA256 /fd SHA256`,
// signWithParams: `/csp "DigiCert Signing Manager KSP" /kc ${process.env.DIGICERT_KEYPAIR_ALIAS} /f ${process.env.SM_CLIENT_CERT_FILE} /tr http://timestamp.digicert.com /td SHA256 /fd SHA256`,
// windowsSign: { // windowsSign: {
// certificateFile: process.env.SM_CLIENT_CERT_FILE, // certificateFile: process.env.SM_CLIENT_CERT_FILE,