Skip to content

Verify Pumpkin plugin ​v0.0.2

Verify Pumpkin plugin signatures with optional public-key pinning and metadata checks

This reference is generated from action.yml.

Inputs ​

InputRequiredDefaultDescription
wasm-fileNo—Path to one signed Pumpkin plugin .wasm file; use this or plugins-manifest
plugins-manifestNo—JSON manifest of plugin-name, version, and wasm-file entries to verify; use this or wasm-file
expected-public-keyNo—Expected 32-byte Ed25519 public key as 64 hexadecimal characters; pins the trusted signer
plugin-nameNo—Single-file mode; fail unless the signed metadata contains this exact plugin name
versionNo—Single-file mode; fail unless the signed metadata contains this exact version

Outputs ​

OutputDescription
verified-countNumber of files successfully verified
plugin-nameSingle-file mode; plugin name from the signed metadata
versionSingle-file mode; version from the signed metadata
developer-nameSingle-file mode; developer name from the signed metadata
public-keySingle-file mode; public key embedded in the signature
issued-atSingle-file mode; signing timestamp from the signed metadata

Implementation reference ​

Pumpkin Plugins documentation