From 8dc0673e8c76a3c0d789d26b88041f3691ed7d21 Mon Sep 17 00:00:00 2001 From: Stephen Webb Date: Fri, 14 Aug 2026 15:48:49 +1000 Subject: [PATCH 1/7] Improve the release-signing workflow --- .github/workflows/package_code.yml | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/.github/workflows/package_code.yml b/.github/workflows/package_code.yml index 73718e564..89acdd531 100644 --- a/.github/workflows/package_code.yml +++ b/.github/workflows/package_code.yml @@ -19,9 +19,9 @@ on: push: branches: - master -# pull_request: -# branches: -# - master + pull_request: + branches: + - master permissions: read-all @@ -70,6 +70,13 @@ jobs: sha256sum "apache-log4cxx-$VERSION.zip" > "apache-log4cxx-$VERSION.zip.sha256" gpg --armor --detach-sign --yes --pinentry-mode error "apache-log4cxx-$VERSION.zip" + - name: 'Clean up GPG keyring' + if: always() + run: | + # Wipe private/public key material + gpg --batch --yes --delete-secret-keys "LOGGING_GPG_KEY_ID" || true + gpg --batch --yes --delete-keys "LOGGING_GPG_KEY_ID" || true + - uses: actions/upload-artifact@v4 if: always() with: From 3f3714a23e2384ef3e04b3093ece8dc0063694f5 Mon Sep 17 00:00:00 2001 From: Stephen Webb Date: Fri, 14 Aug 2026 16:06:15 +1000 Subject: [PATCH 2/7] Extract the actual keys that need to be removed --- .github/workflows/package_code.yml | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/.github/workflows/package_code.yml b/.github/workflows/package_code.yml index 89acdd531..7e050faa8 100644 --- a/.github/workflows/package_code.yml +++ b/.github/workflows/package_code.yml @@ -73,9 +73,17 @@ jobs: - name: 'Clean up GPG keyring' if: always() run: | - # Wipe private/public key material - gpg --batch --yes --delete-secret-keys "LOGGING_GPG_KEY_ID" || true - gpg --batch --yes --delete-keys "LOGGING_GPG_KEY_ID" || true + # Extract secret key fingerprints dynamically from the keyring + FINGERPRINTS=$(gpg --list-secret-keys --with-colons | awk -F: '$1=="fpr" {print $10}') + if [ -z "$FINGERPRINTS" ]; then + echo "No secret keys found in keyring to delete." + else + for fpr in $FINGERPRINTS; do + echo "Deleting secret key: $fpr" + gpg --batch --yes --delete-secret-keys "$fpr" || true + gpg --batch --yes --delete-keys "$fpr" || true + done + fi - uses: actions/upload-artifact@v4 if: always() From e48b8d059d56acc47e5a8ec1abfc803420824bfa Mon Sep 17 00:00:00 2001 From: Stephen Webb Date: Fri, 14 Aug 2026 16:11:58 +1000 Subject: [PATCH 3/7] Only package release files pushed to master --- .github/workflows/package_code.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/package_code.yml b/.github/workflows/package_code.yml index 7e050faa8..af5f785e6 100644 --- a/.github/workflows/package_code.yml +++ b/.github/workflows/package_code.yml @@ -19,9 +19,9 @@ on: push: branches: - master - pull_request: - branches: - - master +# pull_request: +# branches: +# - master permissions: read-all From a52d24db2a4185b9e6275885261d801fa67da082 Mon Sep 17 00:00:00 2001 From: Stephen Webb Date: Fri, 14 Aug 2026 16:56:27 +1000 Subject: [PATCH 4/7] Update to latest upload-artifact action --- .github/workflows/package_code.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/package_code.yml b/.github/workflows/package_code.yml index af5f785e6..8443e45c9 100644 --- a/.github/workflows/package_code.yml +++ b/.github/workflows/package_code.yml @@ -85,7 +85,7 @@ jobs: done fi - - uses: actions/upload-artifact@v4 + - uses: actions/upload-artifact@v7 if: always() with: name: 'release_files' From 879c19952eb2b6163ca88bc8dd58f75cc46ca349 Mon Sep 17 00:00:00 2001 From: Stephen Webb Date: Fri, 14 Aug 2026 17:05:49 +1000 Subject: [PATCH 5/7] Update setup-java action --- .github/workflows/package_code.yml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/package_code.yml b/.github/workflows/package_code.yml index 8443e45c9..36cd85488 100644 --- a/.github/workflows/package_code.yml +++ b/.github/workflows/package_code.yml @@ -19,9 +19,9 @@ on: push: branches: - master -# pull_request: -# branches: -# - master + pull_request: + branches: + - master permissions: read-all @@ -31,14 +31,14 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: persist-credentials: false # do not persist auth token in the local git config path: clean-checkout # Using `setup-java` as temporary workaround, since `crazy-max` is not authorized - name: Setup GPG - uses: actions/setup-java@b36c23c0d998641eff861008f374ee103c25ac73 # 3.7.0 + uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0 with: distribution: temurin java-version: 17 From aaf012638f887d482ad67d7a7458e66d3355eb9f Mon Sep 17 00:00:00 2001 From: Stephen Webb Date: Fri, 14 Aug 2026 17:40:19 +1000 Subject: [PATCH 6/7] Use a shell step to import the secret key into gpg --- .github/workflows/package_code.yml | 10 +++------- 1 file changed, 3 insertions(+), 7 deletions(-) diff --git a/.github/workflows/package_code.yml b/.github/workflows/package_code.yml index 36cd85488..1662fd303 100644 --- a/.github/workflows/package_code.yml +++ b/.github/workflows/package_code.yml @@ -36,13 +36,9 @@ jobs: persist-credentials: false # do not persist auth token in the local git config path: clean-checkout - # Using `setup-java` as temporary workaround, since `crazy-max` is not authorized - - name: Setup GPG - uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0 - with: - distribution: temurin - java-version: 17 - gpg-private-key: ${{ secrets.LOGGING_GPG_SECRET_KEY }} + - name: Import GPG Key + run: | + echo "${{ secrets.LOGGING_GPG_SECRET_KEY }}" | gpg --batch --import # Consider using CPack when it supports a white-list for included files # - name: 'Install minimum dependencies' From 58a7e02bfdccabed16704eefed76002eb7cb98b2 Mon Sep 17 00:00:00 2001 From: Stephen Webb Date: Fri, 14 Aug 2026 17:55:56 +1000 Subject: [PATCH 7/7] Only package release files pushed to master --- .github/workflows/package_code.yml | 18 ++++-------------- 1 file changed, 4 insertions(+), 14 deletions(-) diff --git a/.github/workflows/package_code.yml b/.github/workflows/package_code.yml index 1662fd303..f512c29f8 100644 --- a/.github/workflows/package_code.yml +++ b/.github/workflows/package_code.yml @@ -19,9 +19,9 @@ on: push: branches: - master - pull_request: - branches: - - master +# pull_request: +# branches: +# - master permissions: read-all @@ -40,16 +40,6 @@ jobs: run: | echo "${{ secrets.LOGGING_GPG_SECRET_KEY }}" | gpg --batch --import -# Consider using CPack when it supports a white-list for included files -# - name: 'Install minimum dependencies' -# run: | -# sudo apt-get install -y libapr1-dev libaprutil1-dev -# -# - name: 'Create release files' -# run: | -# cmake -B package -S clean-checkout -DAPACHE_MAINTAINER=yes -DCPACK_PACKAGE_DIRECTORY=`pwd` -# cmake --build package --target dist -# - name: 'Create release files' run: | cd clean-checkout @@ -93,7 +83,7 @@ jobs: sudo apt-get update sudo apt-get install -y libapr1-dev libaprutil1-dev - - name: 'test archive' + - name: 'Test the archive' run: | VERSION=`ls apache-log4cxx-*.tar.gz | sed -Ee 's/.*apache-log4cxx-([0-9]*)\.([0-9]*)\.([0-9]*).*/\1.\2.\3/'` echo "Extracting files from apache-log4cxx-$VERSION.tar.gz..."