Verify Pumpkin plugin v0.0.2
Verify Pumpkin plugin signatures with optional public-key pinning and metadata checks
This reference is generated from action.yml.
Inputs
| Input | Required | Default | Description |
|---|---|---|---|
wasm-file | No | — | Path to one signed Pumpkin plugin .wasm file; use this or plugins-manifest |
plugins-manifest | No | — | JSON manifest of plugin-name, version, and wasm-file entries to verify; use this or wasm-file |
expected-public-key | No | — | Expected 32-byte Ed25519 public key as 64 hexadecimal characters; pins the trusted signer |
plugin-name | No | — | Single-file mode; fail unless the signed metadata contains this exact plugin name |
version | No | — | Single-file mode; fail unless the signed metadata contains this exact version |
Outputs
| Output | Description |
|---|---|
verified-count | Number of files successfully verified |
plugin-name | Single-file mode; plugin name from the signed metadata |
version | Single-file mode; version from the signed metadata |
developer-name | Single-file mode; developer name from the signed metadata |
public-key | Single-file mode; public key embedded in the signature |
issued-at | Single-file mode; signing timestamp from the signed metadata |