diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index a613a06d..be0e976d 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -59,6 +59,9 @@ jobs: run: | echo "IMAGE_DIGEST=${{ steps.docker_push.outputs.digest }}" >> $GITHUB_ENV + - name: Install Cosign + uses: sigstore/cosign-installer@v3.7.0 + - name: Sign Docker Image with Cosign env: COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }} @@ -70,7 +73,7 @@ jobs: - name: Verify Cosign Signature run: | cosign verify \ - usabilitydynamics/udx-worker@${IMAGE_DIGEST} + usabilitydynamics/udx-worker@${IMAGE_DIGEST} - name: Install Trivy run: |