Skip to content

Commit c68052d

Browse files
committed
move sign to release
1 parent 14c775d commit c68052d

File tree

2 files changed

+6
-7
lines changed

2 files changed

+6
-7
lines changed

.github/workflows/release.yml

+6-3
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,7 @@ jobs:
3737
APPLE_DEVELOPER_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE_PASSWORD }}
3838
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
3939
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
40+
COSIGN_PUBLIC_KEY: ${{ secrets.COSIGN_PUBLIC_KEY }}
4041
steps:
4142
- name: Checkout
4243
uses: actions/checkout@1e31de5234b9f8995739874a8ce0492dc87873e2 #v4.0.0
@@ -127,9 +128,11 @@ jobs:
127128
SIGNING_REMOTE_SSH_HOST: ${{ secrets.SIGNING_REMOTE_SSH_HOST }}
128129
SIGNING_REMOTE_SSH_PRIVATE_KEY: ${{ secrets.SIGNING_REMOTE_SSH_PRIVATE_KEY }}
129130
SIGNING_HSM_CREDS: ${{ secrets.SIGNING_HSM_CREDS }}
130-
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
131-
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
132-
COSIGN_PUBLIC_KEY: ${{ secrets.COSIGN_PUBLIC_KEY }}
131+
132+
- name: Sign Docker Image with Cosign
133+
if: inputs.dev == false
134+
run: |
135+
cosign sign --key env://COSIGN_PRIVATE_KEY --passphrase env://COSIGN_PASSWORD ${{ inputs.docker_image }}:{{ inputs.tag }}
133136
134137
- name: Verify Docker image signature
135138
if: inputs.dev == false

.goreleaser.yml

-4
Original file line numberDiff line numberDiff line change
@@ -65,10 +65,6 @@ dockers:
6565
- "cxsdlc/ast-cli:{{ .Tag }}"
6666
- "checkmarx/ast-cli:latest"
6767
- "checkmarx/ast-cli:{{ .Tag }}"
68-
hooks:
69-
post:
70-
- cmd: cosign sign --key env://COSIGN_PRIVATE_KEY --passphrase env://COSIGN_PASSWORD {{ .ImageName }}
71-
output: true
7268

7369
archives:
7470
- id: cx

0 commit comments

Comments
 (0)