Try keyless signing for blobs

This commit is contained in:
Matthew Kilgore
2025-08-23 17:51:55 -04:00
parent 62ed3fabc2
commit b7369b00ee

View File

@@ -43,11 +43,14 @@ signs:
stdin: "{{ .Env.COSIGN_PWD }}" stdin: "{{ .Env.COSIGN_PWD }}"
args: args:
- "sign-blob" - "sign-blob"
- "--key=cosign.key" - "--output-certificate=${certificate}"
- "--output-signature=${signature}" - "--output-signature=${signature}"
- "${artifact}" - "${artifact}"
- "--yes" # needed on cosign 2.0.0+ - "--yes" # needed on cosign 2.0.0+
artifacts: all artifacts: all
output:
signature: "${artifact}.sig"
certificate: "${artifact}.pem"
archives: archives:
- formats: [ 'tar.gz' ] - formats: [ 'tar.gz' ]