{"id":5805112,"name":"lando/code-sign-action","ecosystem":"actions","description":"A GitHub Action for code signing files. Particularly those generated with @yao-pkg/pkg.","homepage":"","licenses":"mit","normalized_licenses":["MIT"],"repository_url":"https://github.com/lando/code-sign-action","keywords_array":["actions","devops","github-actions","lando"],"namespace":"lando","versions_count":10,"first_release_published_at":"2022-04-13T20:48:24.000Z","latest_release_published_at":"2026-07-03T03:40:23.000Z","latest_release_number":"v3.1.0","last_synced_at":"2026-09-08T12:22:31.124Z","created_at":"2023-01-04T15:23:31.789Z","updated_at":"2026-09-17T03:51:29.630Z","registry_url":"https://github.com/lando/code-sign-action","install_command":null,"documentation_url":null,"metadata":{"name":"Code Sign Action","description":"A GitHub Action for code signing files. Particularly those generated with @yao-pkg/pkg.","branding":{"color":"purple","icon":"lock"},"inputs":{"file":{"description":"The file to sign","required":true},"certificate-data":{"description":"A `base64` encoded string of your `p12` or `pfx` cert contents. Note: if you use KeyLocker, this will be the base64 encoded client certificate (`SM_CLIENT_CERT_FILE`). Not required for Azure Artifact Signing.","required":false},"certificate-password":{"description":"The password to unlock the certificate-data. Not required for Azure Artifact Signing.","required":false},"apple-notary-password":{"description":"The Apple Developer account password to use in notarization","required":false},"apple-notary-user":{"description":"The Apple Developer account email to use in notarization","required":false},"apple-notary-tool":{"description":"The xcrun tool to use to notarize.","required":false,"default":"notarytool"},"apple-product-id":{"description":"The unique product ID to use for notarization","required":false},"apple-team-id":{"description":"The Apple Developer account Team ID","required":false},"certificate-id":{"description":"A string to identify the correct signing cert","required":false},"azure-client-id":{"description":"The Azure application client ID to use for Azure Artifact Signing","required":false},"azure-signing-account-name":{"description":"The Azure Artifact Signing account name","required":false},"azure-signing-endpoint":{"description":"The Azure Artifact Signing endpoint","required":false},"azure-subscription-id":{"description":"The Azure subscription ID to use for Azure Artifact Signing","required":false},"azure-tenant-id":{"description":"The Azure tenant ID to use for Azure Artifact Signing","required":false},"keylocker-api-key":{"description":"The API key to use for KeyLocker","required":false},"keylocker-cert-sha1-hash":{"description":"The SHA1 hash of the certificate to use for KeyLocker","required":false},"keylocker-host":{"description":"The host to use for KeyLocker","required":false},"keylocker-keypair-alias":{"description":"The alias of the keypair to use for KeyLocker","required":false},"options":{"description":"Extra options to pass to the codesigning tool","required":false},"signtool":{"description":"The signtool to use","required":false,"default":"auto"}},"outputs":{"file":{"description":"The path to the signed binary.","value":"${{ steps.code-sign-action.outputs.file }}"}},"runs":{"using":"composite","steps":[{"name":"Validate user inputs","shell":"bash","run":"echo \"::group::Ensure file is set\"\nif [ \"${{ inputs.file }}\" == \"\" ]; then\n  echo \"::error title=File is not set!::You must specify a file to sign!\"\n  exit 1\nfi\necho \"::endgroup::\"\n"},{"name":"Set generic internal inputs","id":"code-sign-action-generic-internal","shell":"bash","run":"# standardize os stuff\nif [ \"${{ runner.os }}\" == \"Linux\" ]; then\n  echo \"os=linux\" \u003e\u003e $GITHUB_OUTPUT\nelif [ \"${{ runner.os }}\" == \"macOS\" ]; then\n  echo \"os=macos\" \u003e\u003e $GITHUB_OUTPUT\nelif [ \"${{ runner.os }}\" == \"Windows\" ]; then\n  echo \"os=win\" \u003e\u003e $GITHUB_OUTPUT\nfi\n\n# cert id\nif [ \"${{ runner.os }}\" == \"macOS\" ] \u0026\u0026 [[ -n \"${{ inputs.apple-team-id }}\" ]]; then\n  echo \"signid=${{ inputs.apple-team-id }}\" \u003e\u003e $GITHUB_OUTPUT\nelse\n  echo \"signid=${{ inputs.certificate-id }}\" \u003e\u003e $GITHUB_OUTPUT\nfi\n\n# signtool discovery if needed\nif [ \"${{ inputs.signtool }}\" != \"auto\" ]; then\n  echo \"signtool=${{ inputs.signtool }}\" \u003e\u003e $GITHUB_OUTPUT\nelse\n  azure_inputs_set=false\n  if [[ -n \"${{ inputs.azure-client-id }}\" ]] \\\n    || [[ -n \"${{ inputs.azure-signing-account-name }}\" ]] \\\n    || [[ -n \"${{ inputs.azure-signing-endpoint }}\" ]] \\\n    || [[ -n \"${{ inputs.azure-subscription-id }}\" ]] \\\n    || [[ -n \"${{ inputs.azure-tenant-id }}\" ]]; then\n    azure_inputs_set=true\n  fi\n\n  # azure\n  if [ \"${{ runner.os }}\" == \"Windows\" ] \u0026\u0026 [ \"$azure_inputs_set\" == \"true\" ]; then\n    echo \"signtool=azure\" \u003e\u003e $GITHUB_OUTPUT\n\n  # keylocker\n  elif [ \"${{ runner.os }}\" != \"macOS\" ] \\\n    \u0026\u0026 [[ -n \"${{ inputs.keylocker-api-key }}\" ]] \\\n    \u0026\u0026 [[ -n \"${{ inputs.keylocker-cert-sha1-hash }}\" ]] \\\n    \u0026\u0026 [[ -n \"${{ inputs.keylocker-host }}\" ]] \\\n    \u0026\u0026 [[ -n \"${{ inputs.keylocker-keypair-alias }}\" ]]; then\n    echo \"signtool=keylocker\" \u003e\u003e $GITHUB_OUTPUT\n\n  # signtool\n  elif [ \"${{ runner.os }}\" == \"Windows\" ]; then\n    echo \"signtool=signtool\" \u003e\u003e $GITHUB_OUTPUT\n\n  # codesign\n  elif [ \"${{ runner.os }}\" == \"macOS\" ]; then\n    echo \"signtool=codesign\" \u003e\u003e $GITHUB_OUTPUT\n  fi\nfi\n\n# notarize logix\nif [ \"${{ runner.os }}\" == \"macOS\" ] \\\n  \u0026\u0026 [[ -n \"${{ inputs.apple-notary-password }}\" ]] \\\n  \u0026\u0026 [[ -n \"${{ inputs.apple-notary-user }}\" ]] \\\n  \u0026\u0026 [[ -n \"${{ inputs.apple-product-id }}\" ]]; then\n  echo \"notarize=true\" \u003e\u003e $GITHUB_OUTPUT\nfi\n"},{"name":"Set osy internal inputs","if":"runner.os == 'Windows'","id":"code-sign-action-win-internal","shell":"powershell","run":"# sign cert\n$certpath = \"$env:RUNNER_TEMP\\signcert.p12\"\nWrite-Output \"signcert=$certpath\" | Out-File -FilePath $env:GITHUB_OUTPUT -Append -Encoding utf8\n\n# input file\nif ((Split-Path -Path \"${{ inputs.file }}\" -IsAbsolute) -eq $true) {\n  $file=\"${{ inputs.file }}\"\n} else {\n  $file=\"$(Get-Location)/${{ inputs.file }}\"\n}\n\nWrite-Output \"file=$file\" | Out-File -FilePath $env:GITHUB_OUTPUT -Append -Encoding utf8\n\n# relative file path from GITHUB_WORKSPACE for keylocker things\nfunction Get-RelativePath {\n  param (\n      [string]$FromPath,\n      [string]$ToPath\n  )\n\n  # ensure paths are fully resolved\n  $resolvedFromPath = (Resolve-Path -LiteralPath $FromPath).Path\n  $resolvedToPath = (Resolve-Path -LiteralPath $ToPath).Path\n\n  # ensure $FromPath is treated as a directory (append a trailing slash if it's a directory and doesn't already have one)\n  if ((Test-Path -LiteralPath $resolvedFromPath -PathType Container) -and ($resolvedFromPath -notlike '*\\')) {\n    $resolvedFromPath += '\\'\n  }\n\n  # create URI objects\n  $fromUri = New-Object System.Uri -ArgumentList $resolvedFromPath\n  $toUri = New-Object System.Uri -ArgumentList $resolvedToPath\n\n  # compute the relative path\n  $relativeUri = $fromUri.MakeRelativeUri($toUri)\n  $relativePath = [System.Uri]::UnescapeDataString($relativeUri.ToString())\n\n  # convert URI-style paths to file system style paths (Windows-specific)\n  if ($relativePath -notlike \"*:*\") {\n    $relativePath = $relativePath -replace '/', '\\'\n  }\n\n  return $relativePath\n}\n\n$relativePath = Get-RelativePath -FromPath \"$env:GITHUB_WORKSPACE\" -ToPath \"$file\"\nWrite-Output \"ghwrfile=$relativePath\" | Out-File -FilePath $env:GITHUB_OUTPUT -Append -Encoding utf8\n"},{"name":"Set osy internal inputs","if":"runner.os != 'Windows'","id":"code-sign-action-posix-internal","shell":"bash","run":"# sign cert\ncertpath=\"$RUNNER_TEMP/signcert.p12\"\necho \"signcert=$certpath\" \u003e\u003e $GITHUB_OUTPUT\n\n# input file\nif [[ \"${{ inputs.file }}\" == /* ]]; then\n  echo \"file=${{ inputs.file }}\" \u003e\u003e $GITHUB_OUTPUT\nelse\n  echo \"file=$(pwd)/${{ inputs.file }}\" \u003e\u003e $GITHUB_OUTPUT\nfi\n"},{"name":"Set internal inputs","id":"code-sign-action-internal","shell":"bash","run":"# generics\necho \"notarize=${{ steps.code-sign-action-generic-internal.outputs.notarize }}\" \u003e\u003e $GITHUB_OUTPUT\necho \"os=${{ steps.code-sign-action-generic-internal.outputs.os }}\" \u003e\u003e $GITHUB_OUTPUT\necho \"signid=${{ steps.code-sign-action-generic-internal.outputs.signid }}\" \u003e\u003e $GITHUB_OUTPUT\necho \"signtool=${{ steps.code-sign-action-generic-internal.outputs.signtool }}\" \u003e\u003e $GITHUB_OUTPUT\n\n# osy\nif [ \"${{ runner.os }}\" == \"Windows\" ]; then\n  echo \"file=${{ steps.code-sign-action-win-internal.outputs.file }}\" \u003e\u003e $GITHUB_OUTPUT\n  echo \"ghwrfile=${{ steps.code-sign-action-win-internal.outputs.ghwrfile }}\" \u003e\u003e $GITHUB_OUTPUT\n  echo \"signcert=${{ steps.code-sign-action-win-internal.outputs.signcert }}\" \u003e\u003e $GITHUB_OUTPUT\nelse\n  echo \"file=${{ steps.code-sign-action-posix-internal.outputs.file }}\" \u003e\u003e $GITHUB_OUTPUT\n  echo \"signcert=${{ steps.code-sign-action-posix-internal.outputs.signcert }}\" \u003e\u003e $GITHUB_OUTPUT\nfi\n"},{"name":"Verify Outputs","shell":"bash","run":"echo \"::group::Internal output information\"\necho \"file=${{ steps.code-sign-action-internal.outputs.file }}\"\necho \"ghwrfile=${{ steps.code-sign-action-internal.outputs.ghwrfile }}\"\necho \"notarize=${{ steps.code-sign-action-internal.outputs.notarize }}\"\necho \"os=${{ steps.code-sign-action-internal.outputs.os }}\"\necho \"signcert=${{ steps.code-sign-action-internal.outputs.signcert }}\"\necho \"signid=${{ steps.code-sign-action-internal.outputs.signid }}\"\necho \"signtool=${{ steps.code-sign-action-internal.outputs.signtool }}\"\necho \"::endgroup::\"\n"},{"name":"Validate certificate inputs","if":"steps.code-sign-action-internal.outputs.os != 'linux' \u0026\u0026 steps.code-sign-action-internal.outputs.signtool != 'azure'","shell":"bash","run":"echo \"::group::Ensure cert data is set\"\nif [ \"${{ inputs.certificate-data }}\" == \"\" ]; then\n  echo \"::error title=Cert data is not set!::You must specify the cert you want to sign with!\"\n  exit 2\nfi\necho \"::endgroup::\"\n\necho \"::group::Ensure certificate password is set\"\nif [ \"${{ inputs.certificate-password }}\" == \"\" ]; then\n  echo \"::error title=Cert password is not set!::You must specify the password to unlock the cert with!\"\n  exit 2\nfi\necho \"::endgroup::\"\n"},{"name":"Validate linux specific inputs","if":"steps.code-sign-action-internal.outputs.os == 'linux'","shell":"bash","run":"echo \"::error::Codesigning is not available on Linux! FWIW its not usually necessary to sign binaries on Linux.\"\nexit 1\n"},{"name":"Validate macos specific inputs","if":"steps.code-sign-action-internal.outputs.os == 'macos'","shell":"bash","run":"# supported codesigner\nif [ \"${{ steps.code-sign-action-internal.outputs.signtool }}\" != \"codesign\" ]; then\n  echo \"::error::You must specify codesign as your signtool on macOS! You specified ${{ steps.code-sign-action-internal.outputs.signtool }}.\"\n  exit 1\nfi\n\n# team id\nif [ \"${{ steps.code-sign-action-internal.outputs.signid }}\" == \"\" ]; then\n  echo \"::error::You must specify a certificate-id or apple-team-id to sign!\"\n  exit 1\nfi\n"},{"name":"Validate windows specific inputs","if":"steps.code-sign-action-internal.outputs.os == 'win'","shell":"bash","run":"# supported codesigner\nif [ \"${{ steps.code-sign-action-internal.outputs.signtool }}\" != \"signtool\" ] \\\n  \u0026\u0026 [ \"${{ steps.code-sign-action-internal.outputs.signtool }}\" != \"keylocker\" ] \\\n  \u0026\u0026 [ \"${{ steps.code-sign-action-internal.outputs.signtool }}\" != \"smctl\" ] \\\n  \u0026\u0026 [ \"${{ steps.code-sign-action-internal.outputs.signtool }}\" != \"azure\" ]; then\n  echo \"::error::You must specify signtool, keylocker, smctl or azure as your signtool on Windows! You specified ${{ steps.code-sign-action-internal.outputs.signtool }}.\"\n  exit 1\nfi\n"},{"name":"Validate azure specific inputs","if":"steps.code-sign-action-internal.outputs.signtool == 'azure'","shell":"bash","run":"if [ \"${{ steps.code-sign-action-internal.outputs.os }}\" != \"win\" ]; then\n  echo \"::error::Azure Artifact Signing is only supported on Windows runners.\"\n  exit 1\nfi\n\nif [ \"${{ inputs.azure-client-id }}\" == \"\" ]; then\n  echo \"::error title=Azure client ID is not set!::You must specify azure-client-id to sign with Azure Artifact Signing.\"\n  exit 2\nfi\n\nif [ \"${{ inputs.azure-signing-account-name }}\" == \"\" ]; then\n  echo \"::error title=Azure signing account name is not set!::You must specify azure-signing-account-name to sign with Azure Artifact Signing.\"\n  exit 2\nfi\n\nif [ \"${{ inputs.azure-signing-endpoint }}\" == \"\" ]; then\n  echo \"::error title=Azure signing endpoint is not set!::You must specify azure-signing-endpoint to sign with Azure Artifact Signing.\"\n  exit 2\nfi\n\nif [ \"${{ inputs.azure-subscription-id }}\" == \"\" ]; then\n  echo \"::error title=Azure subscription ID is not set!::You must specify azure-subscription-id to sign with Azure Artifact Signing.\"\n  exit 2\nfi\n\nif [ \"${{ inputs.azure-tenant-id }}\" == \"\" ]; then\n  echo \"::error title=Azure tenant ID is not set!::You must specify azure-tenant-id to sign with Azure Artifact Signing.\"\n  exit 2\nfi\n\nif [ \"${{ steps.code-sign-action-internal.outputs.signid }}\" == \"\" ]; then\n  echo \"::error title=Azure certificate profile name is not set!::You must specify certificate-id to sign with Azure Artifact Signing.\"\n  exit 2\nfi\n"},{"name":"Dump certs","if":"steps.code-sign-action-internal.outputs.os == 'macos'","shell":"bash","run":"echo \"::group::Dumping inputs.certificate-data\"\necho \"Dumping cert to ${{ steps.code-sign-action-internal.outputs.signcert }}...\"\necho \"${{ inputs.certificate-data }}\" | base64 --decode \u003e \"${{ steps.code-sign-action-internal.outputs.signcert }}\"\necho \"::endgroup::\"\n"},{"name":"Dump certs","if":"steps.code-sign-action-internal.outputs.os == 'win' \u0026\u0026 steps.code-sign-action-internal.outputs.signtool != 'azure'","shell":"powershell","run":"echo \"::group::Dumping inputs.certificate-data\"\nWrite-Output \"Dumping cert to ${{ steps.code-sign-action-internal.outputs.signcert }}...\"\n$bytes = [Convert]::FromBase64String(\"${{ inputs.certificate-data }}\")\n[IO.File]::WriteAllBytes(\"${{ steps.code-sign-action-internal.outputs.signcert }}\", $bytes)\necho \"::endgroup::\"\n"},{"name":"Signing with ${{ steps.code-sign-action-internal.outputs.signtool }} (${{ steps.code-sign-action-internal.outputs.os }})","if":"steps.code-sign-action-internal.outputs.signtool == 'codesign'","shell":"bash","run":"echo \"::group::Signsetup\"\n# Throw error if file does not exist\nif [ ! -f \"${{ steps.code-sign-action-internal.outputs.file }}\" ]; then\n  echo \"${{ steps.code-sign-action-internal.outputs.file }} does not exist!\"\n  exit 5\nfi\n\nfunction import_cert() {\n  security import \"$1\" -k ~/Library/Keychains/macos-build.keychain -P \"$2\" -T /usr/bin/codesign -T /usr/bin/productsign\n}\n\n# Create keychain\nsecurity create-keychain -p actions macos-build.keychain\nsecurity default-keychain -s macos-build.keychain\nsecurity unlock-keychain -p actions macos-build.keychain\nsecurity set-keychain-settings -t 3600 -u macos-build.keychain\n\n# attempt to import p12 directly but fallback if it fails\nif ! import_cert \"${{ steps.code-sign-action-internal.outputs.signcert }}\" \"${{ inputs.certificate-password }}\"; then\n  openssl pkcs12 -in \"${{ steps.code-sign-action-internal.outputs.signcert }}\" -nocerts -out \"$RUNNER_TEMP/codesign.key\" -nodes -password pass:\"${{ inputs.certificate-password }}\"\n  openssl pkcs12 -in \"${{ steps.code-sign-action-internal.outputs.signcert }}\" -clcerts -nokeys -out \"$RUNNER_TEMP/codesign.crt\" -password pass:\"${{ inputs.certificate-password }}\"\n  import_cert \"$RUNNER_TEMP/codesign.key\" \"\"\n  import_cert \"$RUNNER_TEMP/codesign.crt\" \"\"\nfi\n\n# Key signing\nsecurity set-key-partition-list -S apple-tool:,apple: -s -k actions macos-build.keychain\necho \"::endgroup::\"\n\n# Scope out the keychain\nsecurity find-identity -v macos-build.keychain\n\n# Force the codesignature\ncodesign --force ${{ inputs.options }} -s \"${{ steps.code-sign-action-internal.outputs.signid }}\" \"${{ steps.code-sign-action-internal.outputs.file }}\"\n\n# Verify the code signature\ncodesign -v \"${{ steps.code-sign-action-internal.outputs.file }}\" --verbose\n"},{"name":"Signing with ${{ steps.code-sign-action-internal.outputs.signtool }} (${{ steps.code-sign-action-internal.outputs.os }})","if":"steps.code-sign-action-internal.outputs.signtool == 'signtool'","shell":"powershell","run":"$ErrorActionPreference = \"Stop\"\n\necho \"::group::Signsetup\"\n# get some things for cert opts\n$file = \"${{ steps.code-sign-action-internal.outputs.file }}\"\n$cert_secure_password = $null\n$signtool = Get-ChildItem \"${env:ProgramFiles(x86)}\\Windows Kits\\10\\bin\\*\\x64\\signtool.exe\" -ErrorAction SilentlyContinue |\n  Sort-Object { [version]$_.Directory.Parent.Name } -Descending |\n  Select-Object -First 1 -ExpandProperty FullName\n$signtoolFallbacks = @(\n  \"${env:ProgramFiles(x86)}\\Windows Kits\\10\\bin\\x64\\signtool.exe\",\n  \"${env:ProgramFiles(x86)}\\Windows Kits\\10\\bin\\10.0.17763.0\\x86\\signtool.exe\"\n)\n\n# throw error if file does not exist\nif (!(Test-Path \"${{ steps.code-sign-action-internal.outputs.file }}\"))\n{\n  throw \"${{ steps.code-sign-action-internal.outputs.file }} does not exist\"\n}\n\n# use a modern x64 signtool if available\nIf ([string]::IsNullOrEmpty($signtool)) {\n  $signtool = $signtoolFallbacks | Where-Object { Test-Path $_ } | Select-Object -First 1\n}\nIf ([string]::IsNullOrEmpty($signtool)) {\n  throw \"Could not find signtool.exe\"\n}\necho \"::endgroup::\"\n\n# verify the cert and password are good\nWrite-Output \"Verifying cert is good to go...\"\n$cert_secure_password = ConvertTo-SecureString \"${{ inputs.certificate-password }}\" -AsPlainText -Force\n$cert = Import-PfxCertificate -FilePath \"${{ steps.code-sign-action-internal.outputs.signcert }}\" -Password $cert_secure_password -CertStoreLocation \"Cert:\\LocalMachine\\My\"\n\n# sign and verify\nWrite-Output \"Trying to sign ${{ steps.code-sign-action-internal.outputs.file }} with $signtool...\"\n\u0026 $signtool sign -sha1 $cert.Thumbprint -sm -fd sha256 -tr \"http://timestamp.comodoca.com/?td=sha256\" -td sha256 ${{ inputs.options }} -as -v \"${{ steps.code-sign-action-internal.outputs.file }}\"\nWrite-Output \"Verifying $file has been signed with the signtool...\"\n\u0026 $signtool verify -pa -v \"${{ steps.code-sign-action-internal.outputs.file }}\"\n"},{"name":"Azure login","if":"steps.code-sign-action-internal.outputs.signtool == 'azure'","uses":"azure/login@v3","with":{"client-id":"${{ inputs.azure-client-id }}","tenant-id":"${{ inputs.azure-tenant-id }}","subscription-id":"${{ inputs.azure-subscription-id }}"}},{"name":"Signing with ${{ steps.code-sign-action-internal.outputs.signtool }} (${{ steps.code-sign-action-internal.outputs.os }})","if":"steps.code-sign-action-internal.outputs.signtool == 'azure'","uses":"azure/artifact-signing-action@v2","with":{"endpoint":"${{ inputs.azure-signing-endpoint }}","signing-account-name":"${{ inputs.azure-signing-account-name }}","certificate-profile-name":"${{ steps.code-sign-action-internal.outputs.signid }}","files":"${{ steps.code-sign-action-internal.outputs.file }}","file-digest":"SHA256","timestamp-rfc3161":"http://timestamp.acs.microsoft.com","timestamp-digest":"SHA256"}},{"name":"Verifying Azure signature","if":"steps.code-sign-action-internal.outputs.signtool == 'azure'","shell":"powershell","run":"$ErrorActionPreference = \"Stop\"\n\n$signtool = Get-ChildItem \"${env:ProgramFiles(x86)}\\Windows Kits\\10\\bin\\*\\x64\\signtool.exe\" -ErrorAction SilentlyContinue |\n  Sort-Object { [version]$_.Directory.Parent.Name } -Descending |\n  Select-Object -First 1 -ExpandProperty FullName\nif ([string]::IsNullOrEmpty($signtool)) {\n  throw \"Could not find signtool.exe\"\n}\n\n\u0026 $signtool verify -pa -v \"${{ steps.code-sign-action-internal.outputs.file }}\"\nif ($LASTEXITCODE -ne 0) {\n  throw \"signtool verify failed with exit code $LASTEXITCODE\"\n}\n"},{"name":"Signing with ${{ steps.code-sign-action-internal.outputs.signtool }} (${{ steps.code-sign-action-internal.outputs.os }})","if":"steps.code-sign-action-internal.outputs.signtool == 'keylocker' || steps.code-sign-action-internal.outputs.signtool == 'smctl'","uses":"cognitedata/code-sign-action@v3","with":{"path-to-binary":"${{ steps.code-sign-action-internal.outputs.ghwrfile }}"},"env":{"CERTIFICATE_HOST":"${{ inputs.keylocker-host }}","CERTIFICATE_HOST_API_KEY":"${{ inputs.keylocker-api-key }}","CERTIFICATE_SHA1_HASH":"${{ inputs.keylocker-cert-sha1-hash }}","CLIENT_CERTIFICATE":"${{ inputs.certificate-data }}","CLIENT_CERTIFICATE_PASSWORD":"${{ inputs.certificate-password }}","KEYPAIR_ALIAS":"${{ inputs.keylocker-keypair-alias }}"}},{"name":"Notarizing","if":"steps.code-sign-action-internal.outputs.notarize == 'true'","uses":"lando/notarize-action@v2","with":{"appstore-connect-username":"${{ inputs.apple-notary-user }}","appstore-connect-password":"${{ inputs.apple-notary-password }}","appstore-connect-team-id":"${{ steps.code-sign-action-internal.outputs.signid }}","primary-bundle-id":"${{ inputs.apple-product-id }}","product-path":"${{ steps.code-sign-action-internal.outputs.file }}","tool":"${{ inputs.apple-notary-tool }}","verbose":true}},{"name":"Verifying Notarization","if":"steps.code-sign-action-internal.outputs.notarize == 'true'","shell":"bash","run":"codesign -vvvv -R=\"notarized\" --check-notarization \"${{ steps.code-sign-action-internal.outputs.file }}\""},{"name":"Set outputs","id":"code-sign-action","shell":"bash","run":"echo \"::group::Setting outputs\"\necho \"file=${{ steps.code-sign-action-internal.outputs.file }}\" \u003e\u003e $GITHUB_OUTPUT\necho \"::endgroup::\"\n"}]},"default_branch":"main","path":null},"repo_metadata":{"id":42074812,"uuid":"481314397","full_name":"lando/code-sign-action","owner":"lando","description":"A GitHub action to code sign files","archived":false,"fork":false,"pushed_at":"2026-07-27T04:14:49.000Z","size":141,"stargazers_count":36,"open_issues_count":4,"forks_count":4,"subscribers_count":4,"default_branch":"main","last_synced_at":"2026-09-08T13:36:30.835Z","etag":null,"topics":["actions","devops","github-actions","lando"],"latest_commit_sha":null,"homepage":"","language":"PowerShell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/lando.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"claude":null,"gemini":null,"cursor":null,"copilot":null,"dco":null,"cla":null,"disclosure":null},"funding":{"github":["lando","pirog"],"patreon":"devwithlando","open_collective":"devwithlando","custom":"https://lando.dev/join"}},"created_at":"2022-04-13T17:37:12.000Z","updated_at":"2026-07-03T03:40:28.000Z","dependencies_parsed_at":"2023-01-11T17:22:10.640Z","dependency_job_id":"c9f00850-119c-460e-afd7-38d8e04b9097","html_url":"https://github.com/lando/code-sign-action","commit_stats":{"total_commits":27,"total_committers":4,"mean_commits":6.75,"dds":"0.14814814814814814","last_synced_commit":"0779d463b08142ea9cb9bc87dc755670a8675c30"},"previous_names":[],"tags_count":10,"template":false,"template_full_name":null,"purl":"pkg:github/lando/code-sign-action","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/lando","download_url":"https://codeload.github.com/lando/code-sign-action/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/sbom","scorecard":{"id":578365,"data":{"date":"2025-08-11","repo":{"name":"github.com/lando/code-sign-action","commit":"a2d97da1cd6f31537bf59de53943c8c1acbb1eac"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.8,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/24 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":3,"reason":"4 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 3","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/label-add-to-project.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/lando/code-sign-action/label-add-to-project.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/lando/code-sign-action/pr-tests.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/lando/code-sign-action/pr-tests.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:149: update your workflow using https://app.stepsecurity.io/secureworkflow/lando/code-sign-action/pr-tests.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/lando/code-sign-action/pr-tests.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/lando/code-sign-action/pr-tests.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/lando/code-sign-action/pr-tests.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/lando/code-sign-action/release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/lando/code-sign-action/release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/lando/code-sign-action/release.yml/main?enable=pin","Info:   0 out of   9 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   1 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/label-add-to-project.yml:1","Warn: no topLevel permission defined: .github/workflows/pr-tests.yml:1","Warn: no topLevel permission defined: .github/workflows/release.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 11 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":7,"reason":"3 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-pq67-2wwv-3xjx","Warn: Project is vulnerable to: GHSA-8cj5-5rvv-wf4v"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-20T18:27:58.132Z","repository_id":42074812,"created_at":"2025-08-20T18:27:58.132Z","updated_at":"2025-08-20T18:27:58.132Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":341189360,"owners_count":37351668,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-09-16T02:00:06.638Z","response_time":96,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"lando","name":"Lando","uuid":"31605584","kind":"organization","description":"Liberating developers since 2012","email":"lando@lando.dev","website":"https://lando.dev","location":"United States of America","twitter":"devwithlando","company":null,"icon_url":"https://avatars.githubusercontent.com/u/31605584?v=4","repositories_count":72,"last_synced_at":"2024-10-29T20:08:10.921Z","metadata":{"has_sponsors_listing":true},"html_url":"https://github.com/lando","funding_links":["https://github.com/sponsors/lando"],"total_stars":4416,"followers":149,"following":0,"created_at":"2022-11-07T20:45:29.911Z","updated_at":"2024-10-29T20:08:10.921Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/lando","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/lando/repositories"},"tags":[{"name":"v3.1.0","sha":"e4ff1308be14fade6516fd4f1ddd0509b7ea5223","kind":"commit","published_at":"2026-07-03T03:40:23.000Z","download_url":"https://codeload.github.com/lando/code-sign-action/tar.gz/v3.1.0","html_url":"https://github.com/lando/code-sign-action/releases/tag/v3.1.0","dependencies_parsed_at":"2026-08-08T10:43:22.321Z","dependency_job_id":null,"purl":"pkg:github/lando/code-sign-action@v3.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v3.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v3.1.0/manifests"},{"name":"v3","sha":"e4ff1308be14fade6516fd4f1ddd0509b7ea5223","kind":"commit","published_at":"2026-07-03T03:40:23.000Z","download_url":"https://codeload.github.com/lando/code-sign-action/tar.gz/v3","html_url":"https://github.com/lando/code-sign-action/releases/tag/v3","dependencies_parsed_at":null,"dependency_job_id":"7826d4e4-25fb-4a03-87b5-1e66962c592c","purl":"pkg:github/lando/code-sign-action@v3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v3/manifests"},{"name":"v3.0.0","sha":"a5703d3b5486ada6e8efd08912110f8756e873e8","kind":"commit","published_at":"2024-11-19T16:43:57.000Z","download_url":"https://codeload.github.com/lando/code-sign-action/tar.gz/v3.0.0","html_url":"https://github.com/lando/code-sign-action/releases/tag/v3.0.0","dependencies_parsed_at":"2024-11-29T09:20:26.715Z","dependency_job_id":null,"purl":"pkg:github/lando/code-sign-action@v3.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v3.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v3.0.0/manifests"},{"name":"v2.2.0","sha":"0779d463b08142ea9cb9bc87dc755670a8675c30","kind":"commit","published_at":"2024-05-03T18:10:57.000Z","download_url":"https://codeload.github.com/lando/code-sign-action/tar.gz/v2.2.0","html_url":"https://github.com/lando/code-sign-action/releases/tag/v2.2.0","dependencies_parsed_at":"2024-05-05T08:51:06.146Z","dependency_job_id":null,"purl":"pkg:github/lando/code-sign-action@v2.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2.2.0/manifests"},{"name":"v2","sha":"0779d463b08142ea9cb9bc87dc755670a8675c30","kind":"commit","published_at":"2024-05-03T18:10:57.000Z","download_url":"https://codeload.github.com/lando/code-sign-action/tar.gz/v2","html_url":"https://github.com/lando/code-sign-action/releases/tag/v2","dependencies_parsed_at":null,"dependency_job_id":"a1e5d606-e3c9-45b0-ab66-4ed27fab1fab","purl":"pkg:github/lando/code-sign-action@v2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2/manifests"},{"name":"v2.1.1","sha":"f8f2acea58ebc8b5847e7bc80e37e33bea37bc40","kind":"commit","published_at":"2023-06-17T15:48:21.000Z","download_url":"https://codeload.github.com/lando/code-sign-action/tar.gz/v2.1.1","html_url":"https://github.com/lando/code-sign-action/releases/tag/v2.1.1","dependencies_parsed_at":"2023-06-28T01:19:13.296Z","dependency_job_id":null,"purl":"pkg:github/lando/code-sign-action@v2.1.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2.1.1/manifests"},{"name":"v2.1.0","sha":"5d11a60ad48fe96af7564bf830b7515cfce4d63c","kind":"tag","published_at":"2023-04-27T19:10:28.000Z","download_url":"https://codeload.github.com/lando/code-sign-action/tar.gz/v2.1.0","html_url":"https://github.com/lando/code-sign-action/releases/tag/v2.1.0","dependencies_parsed_at":"2023-06-02T00:36:22.477Z","dependency_job_id":null,"purl":"pkg:github/lando/code-sign-action@v2.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2.1.0/manifests"},{"name":"v2.0.2","sha":"f81b3a45f755b9178483f9718607c938177d91b8","kind":"tag","published_at":"2023-04-27T19:09:25.000Z","download_url":"https://codeload.github.com/lando/code-sign-action/tar.gz/v2.0.2","html_url":"https://github.com/lando/code-sign-action/releases/tag/v2.0.2","dependencies_parsed_at":"2023-06-02T00:36:24.459Z","dependency_job_id":null,"purl":"pkg:github/lando/code-sign-action@v2.0.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2.0.2/manifests"},{"name":"v2.0.1","sha":"b3ffa1bde65ca53d3291ad7176e8ef881b7f992f","kind":"tag","published_at":"2022-04-13T20:54:43.000Z","download_url":"https://codeload.github.com/lando/code-sign-action/tar.gz/v2.0.1","html_url":"https://github.com/lando/code-sign-action/releases/tag/v2.0.1","dependencies_parsed_at":"2023-05-31T01:30:55.291Z","dependency_job_id":null,"purl":"pkg:github/lando/code-sign-action@v2.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2.0.1/manifests"},{"name":"v2.0.0","sha":"b4d0dc250d4e609e6319d89cc6960499af626ede","kind":"tag","published_at":"2022-04-13T20:48:24.000Z","download_url":"https://codeload.github.com/lando/code-sign-action/tar.gz/v2.0.0","html_url":"https://github.com/lando/code-sign-action/releases/tag/v2.0.0","dependencies_parsed_at":"2023-05-31T01:30:56.362Z","dependency_job_id":null,"purl":"pkg:github/lando/code-sign-action@v2.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/tags/v2.0.0/manifests"}]},"repo_metadata_updated_at":"2026-09-17T03:51:29.630Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":7,"rankings":{"downloads":null,"dependent_repos_count":13.69988908255427,"dependent_packages_count":0.0,"stargazers_count":17.53446363492315,"forks_count":35.113294248138175,"docker_downloads_count":null,"average":16.5869117414039},"purl":"pkg:githubactions/lando/code-sign-action","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/actions/lando/code-sign-action","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/actions/lando/code-sign-action","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/actions/lando/code-sign-action/dependencies","status":null,"funding_links":["https://github.com/sponsors/lando","https://github.com/sponsors/pirog","https://patreon.com/devwithlando","https://opencollective.com/devwithlando","https://lando.dev/join"],"critical":null,"issue_metadata":{"last_synced_at":"2026-09-16T04:50:37.865Z","issues_count":4,"pull_requests_count":19,"avg_time_to_close_issue":1774.5,"avg_time_to_close_pull_request":4955885.5625,"issues_closed_count":2,"pull_requests_closed_count":16,"pull_request_authors_count":3,"issue_authors_count":4,"avg_comments_per_issue":0.25,"avg_comments_per_pull_request":0.15789473684210525,"merged_pull_requests_count":11,"bot_issues_count":0,"bot_pull_requests_count":8,"past_year_issues_count":0,"past_year_pull_requests_count":2,"past_year_avg_time_to_close_issue":null,"past_year_avg_time_to_close_pull_request":39245.0,"past_year_issues_closed_count":0,"past_year_pull_requests_closed_count":1,"past_year_pull_request_authors_count":2,"past_year_issue_authors_count":0,"past_year_avg_comments_per_issue":null,"past_year_avg_comments_per_pull_request":0.0,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":1,"past_year_merged_pull_requests_count":1,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/lando%2Fcode-sign-action/issues","maintainers":[{"login":"pirog","count":9,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/pirog"},{"login":"reynoldsalec","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/reynoldsalec"}],"active_maintainers":[{"login":"pirog","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/pirog"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/lando%2Fcode-sign-action/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/lando%2Fcode-sign-action/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/lando%2Fcode-sign-action/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/lando%2Fcode-sign-action/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/lando%2Fcode-sign-action/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/lando%2Fcode-sign-action/codemeta","maintainers":[]}