Skip to content

ci: drop GCP login and GCP KMS / GlobalSign secrets - #112

Open
mike-ainsel wants to merge 1 commit into
mainfrom
chore/drop-gcp-signing
Open

mike-ainsel wants to merge 1 commit into
mainfrom
chore/drop-gcp-signing

Conversation

@mike-ainsel

@mike-ainsel mike-ainsel commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Removes the GCP / GlobalSign settings from the build. Nothing in this repo uses them any more.

Changes

  • Remove gcp-login-enable: true (where set).
  • Remove the WIN_SIGN_CERT and GCP_KMS_* secrets passed to the reusable workflow.

The reusable workflows still declare these inputs and secrets, so this PR and the shared CI can merge in any order. Merging triggers a build on main; with an unchanged version, publishing is skipped as before.

RetriggerConfidence Score: 5/5

The PR appears safe to merge, with no actionable issue established.

Summary

Removes the Windows certificate and five GCP KMS secrets passed by .github/workflows/build.yaml to the shared build workflow.

  • Keeps the shared workflow reference, build settings, npm credentials, and macOS signing secrets unchanged.
  • No actionable issues were established.

Important touched terms; no code types changed:

  • WIN_SIGN_CERT: The Windows signing certificate supplied to the shared workflow. Its mapping from WIN_CODE_SIGN_CHAIN is removed.
  • GCP_KMS_WORKLOAD_IDENTITY_PROVIDER: The provider used to obtain Google Cloud credentials through workload identity. Its secret mapping is removed.
  • GCP_KMS_SERVICE_ACCOUNT: The Google Cloud account used for KMS access. Its secret mapping is removed.
  • GCP_KMS_LOCATION: The location containing the KMS key ring. Its secret mapping is removed.
  • GCP_KMS_KEYRING: The KMS key ring containing the signing key. Its mapping from GCP_SOFTWARE_KMS_KEYRING is removed.
  • GCP_KMS_KEY_NAME: The name of the KMS signing key. Its mapping from GCP_SOFTWARE_KMS_KEY_NAME is removed.

Reviews (1) · Last reviewed commit: "ci: drop GCP login and GCP KMS / GlobalS..." · Reviewed by Greptile

Windows binaries are signed with Azure Trusted Signing in milaboratory/github-ci
windows-sign, and this repo publishes with plain npm publish, so nothing uses
the GCP login or the GCP KMS / GlobalSign secrets any more.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant