File tree 2 files changed +6
-7
lines changed
2 files changed +6
-7
lines changed Original file line number Diff line number Diff line change 37
37
APPLE_DEVELOPER_CERTIFICATE_PASSWORD : ${{ secrets.APPLE_DEVELOPER_CERTIFICATE_PASSWORD }}
38
38
COSIGN_PRIVATE_KEY : ${{ secrets.COSIGN_PRIVATE_KEY }}
39
39
COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
40
+ COSIGN_PUBLIC_KEY : ${{ secrets.COSIGN_PUBLIC_KEY }}
40
41
steps :
41
42
- name : Checkout
42
43
uses : actions/checkout@1e31de5234b9f8995739874a8ce0492dc87873e2 # v4.0.0
@@ -127,9 +128,11 @@ jobs:
127
128
SIGNING_REMOTE_SSH_HOST : ${{ secrets.SIGNING_REMOTE_SSH_HOST }}
128
129
SIGNING_REMOTE_SSH_PRIVATE_KEY : ${{ secrets.SIGNING_REMOTE_SSH_PRIVATE_KEY }}
129
130
SIGNING_HSM_CREDS : ${{ secrets.SIGNING_HSM_CREDS }}
130
- COSIGN_PRIVATE_KEY : ${{ secrets.COSIGN_PRIVATE_KEY }}
131
- COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
132
- COSIGN_PUBLIC_KEY : ${{ secrets.COSIGN_PUBLIC_KEY }}
131
+
132
+ - name : Sign Docker Image with Cosign
133
+ if : inputs.dev == false
134
+ run : |
135
+ cosign sign --key env://COSIGN_PRIVATE_KEY --passphrase env://COSIGN_PASSWORD ${{ inputs.docker_image }}:{{ inputs.tag }}
133
136
134
137
- name : Verify Docker image signature
135
138
if : inputs.dev == false
Original file line number Diff line number Diff line change @@ -65,10 +65,6 @@ dockers:
65
65
- " cxsdlc/ast-cli:{{ .Tag }}"
66
66
- " checkmarx/ast-cli:latest"
67
67
- " checkmarx/ast-cli:{{ .Tag }}"
68
- hooks :
69
- post :
70
- - cmd : cosign sign --key env://COSIGN_PRIVATE_KEY --passphrase env://COSIGN_PASSWORD {{ .ImageName }}
71
- output : true
72
68
73
69
archives :
74
70
- id : cx
You can’t perform that action at this time.
0 commit comments