{"repo":"crazy-max/ghaction-import-gpg","free":true,"listed":false,"github":"https://github.com/crazy-max/ghaction-import-gpg","clone":"git clone https://github.com/crazy-max/ghaction-import-gpg.git","description":"GitHub Action to import a GPG key","language":"TypeScript","stars":383,"topics":["github-actions","gnupg","gnupg2","openpgp","signing","git","actions"],"license":"MIT","category":"workflow-automation","readme_excerpt":"About GitHub Action to easily import a GPG key. Features Prerequisites Usage Workflow Sign commits Use a subkey Set key's trust level Customizing inputs outputs Contributing License Features Works on Linux, macOS and Windows virtual environments Allow seeding the internal cache of gpg-agent with provided passphrase Signing-only subkeys support Purge imported GPG key, cache information and kill agent from runner (Git) Enable signing for Git commits, tags and pushes (Git) Configure and check committer info against GPG key Prerequisites First, generate a GPG key and export the GPG private key as an ASCII armored version to your clipboard: Paste your clipboard as a secret named GPG PRIVATE KEY for example. Create another secret with the PASSPHRASE if applicable. Usage Workflow Sign commits Use a subkey With the input fingerprint , you can specify which one of the subkeys in a GPG key you want to use for signing. For example, given this GPG key with a signing subkey: You can use the subkey with signing capability whose fingerprint is C17D11ADF199F12A30A0910F1F80449BE0B08CB8 . Set key's trust level With the trust level input, you can specify the trust level of the GPG key. Valid values are: 1 : unknown 2 : never 3 : marginal 4 : full 5 : ultimate Customizing inputs The following inputs can be used as step.with keys: Name Type Description ----------------------- -------- -------------------------------------------------------------------------------------------- gpg private key Stri","default_branch":null,"files":null,"tree":[],"storefront":"/r/crazy-max","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/crazy-max/ghaction-import-gpg/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}