# Reproducible release of the datekeys CLI (plan §8, spec §59). version: 2 project_name: datekeys before: hooks: - go mod verify builds: - id: datekeys main: ./cmd/datekeys binary: datekeys env: - CGO_ENABLED=0 flags: - -trimpath ldflags: - -s -w -buildid= mod_timestamp: "{{ .CommitTimestamp }}" goos: [linux, darwin, windows] goarch: [amd64, arm64] archives: - formats: [tar.gz] format_overrides: - goos: windows formats: [zip] files: - LICENSE - README.md - README.es.md - SECURITY.md - TRADEMARKS.md - CHANGELOG.md checksum: name_template: checksums.txt algorithm: sha256 sboms: - id: cyclonedx artifacts: binary cmd: cyclonedx-gomod documents: - "{{ .ArtifactName }}.cdx.json" args: ["bin", "-json", "-output", "$document", "$artifact"] signs: # Signature of the checksum file with the project's cosign key, supplied at # release time through COSIGN_PRIVATE_KEY and COSIGN_PASSWORD. - cmd: cosign artifacts: checksum signature: "${artifact}.sig" args: - sign-blob - --key=env://COSIGN_PRIVATE_KEY - --output-signature=${signature} - ${artifact} - --yes changelog: disable: true # Releases are published on the project's Gitea server. gitea_urls: api: https://g.activething.com/api/v1 download: https://g.activething.com # The server presents a certificate Go and goreleaser do not trust by # default. Remove this when a trusted certificate is installed. skip_tls_verify: true release: prerelease: auto