We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent a290492 commit 7575729Copy full SHA for 7575729
1 file changed
.github/workflows/build-publish.yaml
@@ -4,8 +4,9 @@ on:
4
push:
5
6
permissions:
7
+ contents: read
8
+ id-token: write
9
packages: write
- contents: write
10
11
jobs:
12
build-and-push-docker-image:
@@ -26,6 +27,9 @@ jobs:
26
27
- name: Setup ko
28
uses: ko-build/setup-ko@v0.6
29
30
+ - name: Install Cosign
31
+ uses: sigstore/cosign-installer@ba7bc0a3fef59531c69a25acd34668d6d3fe6f22 # v4.1.0
32
+
33
- name: Login to Github Packages
34
uses: docker/login-action@v3
35
with:
@@ -37,6 +41,7 @@ jobs:
37
41
run: |
38
42
descr=$(git describe)
39
43
export version="${descr#v}"
40
- ko build --bare --sbom=none -t latest -t "$version" .
44
+ ko build --bare --sbom=none -t latest -t "$version" . \
45
+ | xargs cosign sign --yes --recursive
46
env:
47
KO_DOCKER_REPO: ghcr.io/syncthing/infra/roadmap-votes
0 commit comments