actionhippie/actionhippie-gpgsign

Sign artifacts or any file with GnuPG

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jul 14, 2026
License
Apache 2.0

Pinned Snippet

workflow.ymlSHA-pinned
uses: actionhippie/gpgsign@3dd7077a5b772de330fa7307ce06c8132c71b954 # v1.8.1

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
private_keyPrivate GPG key used for signing yes
passphrasePassphrase for the GPG key no
armorCreate ASCII armored output, defaults to `true` notrue
detach_signMake a detached signature no
clear_signMake a clear text signature no
filesList of files to create a signature yes
excludesList of files to exclude from signing no

no outputs