Skip to content

Commit 7ba2f80

Browse files
authored
Updating the cosign library for Github Actions (#5603)
1 parent 2942ebf commit 7ba2f80

File tree

2 files changed

+8
-5
lines changed

2 files changed

+8
-5
lines changed

.github/workflows/deploy-prod.yaml

+1-3
Original file line numberDiff line numberDiff line change
@@ -271,9 +271,7 @@ jobs:
271271
env:
272272
COSIGN_KEY: ${{secrets.COSIGN_KEY}}
273273

274-
- uses: sigstore/cosign-installer@main
275-
with:
276-
cosign-release: 'v1.2.1'
274+
- uses: sigstore/[email protected]
277275

278276
- name: Generate SBOM
279277
run: |

Makefile

+7-2
Original file line numberDiff line numberDiff line change
@@ -696,8 +696,13 @@ sbom/assets/kurl-sbom.tgz: generate-sbom
696696
tar -czf sbom/assets/kurl-sbom.tgz sbom/spdx/*.spdx
697697

698698
sbom: sbom/assets/kurl-sbom.tgz
699-
cosign sign-blob -key ./cosign.key sbom/assets/kurl-sbom.tgz > ./sbom/assets/kurl-sbom.tgz.sig
700-
cosign public-key -key ./cosign.key -outfile ./sbom/assets/key.pub
699+
cosign sign-blob \
700+
--key ./cosign.key \
701+
--tlog-upload \
702+
--yes \
703+
--rekor-url=https://rekor.sigstore.dev \
704+
sbom/assets/kurl-sbom.tgz > ./sbom/assets/kurl-sbom.tgz.sig
705+
cosign public-key --key ./cosign.key --outfile ./sbom/assets/key.pub
701706

702707
.PHONY: tag-and-release
703708
tag-and-release: ## Create tags and release

0 commit comments

Comments
 (0)