Merge pull request #10546 from cli/kw-wm-af/base64-decode-gpg-passphrase-in-deployment-workflow

Base64 decode GPG passphrase in deployment workflow
This commit is contained in:
Kynan Ware 2025-03-05 12:44:33 -07:00 committed by GitHub
commit a92528a158
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -301,7 +301,7 @@ jobs:
base64 -d <<<"$GPG_KEY" | gpg --import --no-tty --batch --yes
echo "allow-preset-passphrase" > ~/.gnupg/gpg-agent.conf
gpg-connect-agent RELOADAGENT /bye
/usr/lib/gnupg2/gpg-preset-passphrase --preset "$GPG_KEYGRIP" <<<"$GPG_PASSPHRASE"
base64 -d <<<"$GPG_PASSPHRASE" | /usr/lib/gnupg2/gpg-preset-passphrase --preset "$GPG_KEYGRIP"
- name: Sign RPMs
if: inputs.environment == 'production'
run: |