Skip to content

Commit

Permalink
test release
Browse files Browse the repository at this point in the history
  • Loading branch information
fqjony committed Nov 28, 2024
1 parent 03c397f commit 008cb05
Showing 1 changed file with 20 additions and 20 deletions.
40 changes: 20 additions & 20 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -122,26 +122,26 @@ jobs:
name: sbom
path: sbom.json

# - name: Install Cosign
# uses: sigstore/[email protected]

# - name: Sign Docker image with Cosign
# env:
# COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
# run: |
# cosign sign -y \
# --key env://COSIGN_PRIVATE_KEY \
# usabilitydynamics/udx-worker@${{ steps.build-push.outputs.digest }}

# - name: Sign SBOM with Cosign
# env:
# COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
# run: |
# cosign attest -y \
# --key env://COSIGN_PRIVATE_KEY \
# --predicate sbom.json \
# --type https://spdx.dev/spdx-specification-2-2-pdf \
# usabilitydynamics/udx-worker@${{ steps.build-push.outputs.digest }}
- name: Install Cosign
uses: sigstore/[email protected]

- name: Sign Docker image with Cosign
env:
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
run: |
cosign sign -y \
--key env://COSIGN_PRIVATE_KEY \
usabilitydynamics/udx-worker:${{ steps.gitversion.outputs.semVer }}
- name: Sign SBOM with Cosign
env:
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
run: |
cosign attest -y \
--key env://COSIGN_PRIVATE_KEY \
--predicate sbom.json \
--type https://spdx.dev/spdx-specification-2-2-pdf \
usabilitydynamics/udx-worker:${{ steps.gitversion.outputs.semVer }}
- name: Log out from Docker Hub
run: docker logout
Expand Down

0 comments on commit 008cb05

Please sign in to comment.