Skip to content

Sign Pumpkin plugin ​v0.0.3

Add Pumpkin's Ed25519 signature and release metadata to one or more existing plugin .wasm files. This action signs files in place; it does not build the plugins.

See the action guide and API reference on the documentation site.

yaml
steps:
  - uses: filiphsps/pumpkin-plugins/actions/sign-pumpkin-plugin@sign-pumpkin-plugin-v0.0.3
    with:
      plugin-name: MyPlugin
      version: 1.2.3
      wasm-file: dist/my-plugin.wasm
      developer-name: My Name
      signing-key: ${{ secrets.PLUGIN_SIGNING_KEY }}

The version reference above is this action's Release Please tag. Action releases are independent from plugin releases and other actions, and Release Please creates a versioned tag when this action changes.

The action uses the repository's tested @pumpkin-plugins/signing implementation and verifies its output before writing it. Existing signing sections are replaced. If a sibling <wasm-file>.sha256 checksum file exists, the action updates it to match the signed bytes. Its .mjs entrypoint loads the shared TypeScript signer with Node 24's built-in type stripping, so it does not need a separate build or bundle step.

For CI jobs that need to sign multiple plugins, provide a JSON array manifest instead of the three single-plugin inputs:

json
[
  { "plugin-name": "MyPlugin", "version": "1.2.3", "wasm-file": "dist/my-plugin.wasm" }
]

The action signs each entry and refreshes any adjacent checksums. developer-name and signing-key still apply to every entry.

Inputs ​

InputRequiredDefaultDescription
plugin-nameNoSingle-file mode; exact plugin name embedded in the signature metadata
versionNoSingle-file mode; plugin version embedded without a leading v
wasm-fileNoSingle-file mode; path to the plugin .wasm file to sign
plugins-manifestNoBatch mode; JSON array of plugin-name, version, and wasm-file entries instead of single-file inputs
developer-nameYesDeveloper name embedded in signed metadata; required in either mode
signing-keyNo32-byte Ed25519 secret seed as 64 hexadecimal characters; required unless warn is true
warnNofalseWarn and leave the file unchanged when signing-key is empty instead of failing

Outputs ​

This action has no outputs.

An empty key can be skipped with warn: true, which is useful for forks and repositories that release unsigned plugins. A malformed key, missing file, or failed signature verification always fails. The action runs on GitHub's Node 24 runtime and needs no extra runner setup.

Pumpkin Plugins documentation