diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 99015c97..d102e52e 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -70,7 +70,7 @@ jobs: COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }} FULL_REFERENCE: ${{ env.FULL_REFERENCE }} run: | - cosign sign \ + cosign sign -y \ --key env://COSIGN_PRIVATE_KEY \ "${FULL_REFERENCE}" @@ -124,7 +124,7 @@ jobs: COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }} FULL_REFERENCE: ${{ env.FULL_REFERENCE }} run: | - cosign attest \ + cosign attest -y \ --key env://COSIGN_PRIVATE_KEY \ --predicate sbom.json \ --type https://spdx.dev/spdx-specification-2-2-pdf \