The Verify file signature with PGP action can be used to verify a file signature to ensure its authenticityarrow-up-right.
Verify file signature with PGP
GnuPG package must be installed in the runtime environment and encryption keys added to the runtime user keystore for this to function.
Action name
The name of the workflow action.
GPG location
The file path of the GnuPG executable (e.g. /usr/bin/gpg).
/usr/bin/gpg
Filename
The signed file path.
Use detached signature
Whether or not to use a detached signature.
Detached signature
Path to the detached signature file (only available when the Use detached signature above is checked)
Last updated 4 months ago