name: 'HSM Signing' description: 'Signs APKs and makes detached signatures of files, with a key held in an HSM' author: 'lobo' inputs: files: description: 'Files to make detached signatures of (a glob in one directory, or dir/** for all files under dir). Signatures are written beside them as FILE.sig' required: false apk: description: 'An unsigned, zipaligned APK to sign (signature schemes v2 and v3). Signed before files, so files can include apk_output' required: false apk_output: description: 'Where to write the signed APK. Required with apk' required: false pin: description: 'User pin for HSM on build server' required: true key_id: description: 'CKA_ID of the key, in hex' required: true default: '03' slot_index: description: 'PKCS#11 slot, by position in the slot list' required: true default: '0' key_alias: description: 'APK only: the key alias, when the token holds more than one key with a certificate' required: false default: '' apk_cert_sha256: description: 'APK only: SHA-256 of the certificate the APK must be signed with (the app identity). Signing with any other certificate fails the step. Recommended once the certificate is chosen' required: false default: '' public_key: description: 'URL to PEM format public key. Specify only if uploading detached signatures to sigstore' required: false uhub_control: description: 'If HSM is attached to software controlled power hub, setting this to "true" will power cycle the HSM before signing and power it off afterwards. The runner needs UHUB_PORT set (see README)' required: true default: "false" runs: using: 'docker' image: 'Dockerfile'