Try keyless signing for blobs

This commit is contained in:
Matthew Kilgore
2025-08-23 17:51:55 -04:00
parent 62ed3fabc2
commit b7369b00ee

View File

@@ -43,11 +43,14 @@ signs:
stdin: "{{ .Env.COSIGN_PWD }}"
args:
- "sign-blob"
- "--key=cosign.key"
- "--output-certificate=${certificate}"
- "--output-signature=${signature}"
- "${artifact}"
- "--yes" # needed on cosign 2.0.0+
artifacts: all
output:
signature: "${artifact}.sig"
certificate: "${artifact}.pem"
archives:
- formats: [ 'tar.gz' ]