| 1 | name: Verify release |
| 2 | run-name: Verify v${{ inputs.version }} |
| 3 | |
| 4 | on: |
| 5 | workflow_dispatch: |
| 6 | inputs: |
| 7 | version: |
| 8 | description: "Official version without a tag prefix" |
| 9 | required: true |
| 10 | type: string |
| 11 | |
| 12 | permissions: |
| 13 | contents: read |
| 14 | |
| 15 | jobs: |
| 16 | verify: |
| 17 | name: verify immutable files and public pointers |
| 18 | runs-on: ubuntu-latest |
| 19 | steps: |
| 20 | - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 |
| 21 | with: |
| 22 | ref: ${{ github.sha }} |
| 23 | - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 |
| 24 | with: |
| 25 | node-version: "22" |
| 26 | - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7 |
| 27 | with: |
| 28 | go-version-file: go.mod |
| 29 | cache: false |
| 30 | - name: Verify public release |
| 31 | env: |
| 32 | GH_TOKEN: ${{ github.token }} |
| 33 | RELEASE_REPOSITORY: ${{ github.repository }} |
| 34 | RELEASE_VERSION: ${{ inputs.version }} |
| 35 | RELEASE_OPERATION: recover |
| 36 | CLI_TAG: v${{ inputs.version }} |
| 37 | DESKTOP_TAG: desktop-v${{ inputs.version }} |
| 38 | VERIFY_PUBLIC_POINTERS: "true" |
| 39 | CLI_PUBLISH_FROZEN: ${{ vars.CLI_PUBLISH_FROZEN == 'true' }} |
| 40 | run: bash scripts/verify-stable-release-artifacts.sh |
| 41 |