# Reproducible release of the datekeys CLI (plan §8, spec §59). version: 2 project_name: datekeys before: hooks: - go mod verify builds: - id: datekeys main: ./cmd/datekeys binary: datekeys env: - CGO_ENABLED=0 flags: - -trimpath ldflags: - -s -w -buildid= mod_timestamp: "{{ .CommitTimestamp }}" goos: [linux, darwin, windows] goarch: [amd64, arm64] archives: - formats: [tar.gz] format_overrides: - goos: windows formats: [zip] files: - LICENSE - README.md - README.es.md - SECURITY.md - TRADEMARKS.md - CHANGELOG.md checksum: name_template: checksums.txt algorithm: sha256 sboms: - id: cyclonedx artifacts: binary cmd: cyclonedx-gomod documents: - "{{ .ArtifactName }}.cdx.json" args: ["bin", "-json", "-output", "$document", "$artifact"] signs: # Keyless signature of the checksum file with the workflow's OIDC identity. - cmd: cosign artifacts: checksum signature: "${artifact}.sig" certificate: "${artifact}.pem" args: - sign-blob - --output-signature=${signature} - --output-certificate=${certificate} - ${artifact} - --yes changelog: disable: true release: prerelease: auto