Documentation
¶
Overview ¶
Command release signs and publishes Seaglass releases with the offline release key (internal/update/signature.go).
go run ./tools/release keygen make the key (once), print its public half
go run ./tools/release backup <file> write a password-protected copy for offline keeping
go run ./tools/release restore <file> put a backup on this PC
go run ./tools/release pubkey print the public key
go run ./tools/release publish <tag> sign the draft release <tag> and publish it
go run ./tools/release verify <tag> check a published release's signature
go run ./tools/release cut <tag> [--pr N] [--dry-run]
the whole release from main, checked step by step (cut.go)
The private key is stored encrypted with Windows DPAPI (this Windows account only) in %APPDATA%\Seaglass-release, outside the app's data folder so uninstalling Seaglass can't delete it. It never goes to GitHub. publish uses the GitHub CLI (gh), signed in as a maintainer.
Click to show internal directories.
Click to hide internal directories.