diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml index f40d821..cfac85d 100644 --- a/.github/workflows/docker-publish.yml +++ b/.github/workflows/docker-publish.yml @@ -16,17 +16,11 @@ jobs: permissions: contents: read packages: write - id-token: write steps: - name: Checkout repository uses: actions/checkout@v3 - - name: Setup Docker and cosign - run: | - sudo apt-get update - sudo apt-get install -y buildx cosign - - name: Log into registry uses: docker/login-action@v2 with: @@ -34,25 +28,9 @@ jobs: username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - - name: Extract Docker metadata - id: meta - uses: docker/metadata-action@v4 - with: - images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} - - name: Build and push Docker image - id: build-and-push uses: docker/build-push-action@v4 with: context: . push: true - tags: ${{ steps.meta.outputs.tags }} - labels: ${{ steps.meta.outputs.labels }} - cache-from: type=gha - cache-to: type=gha,mode=max - - - name: Sign the published Docker image - env: - TAGS: ${{ steps.meta.outputs.tags }} - DIGEST: ${{ steps.build-and-push.outputs.digest }} - run: echo "${TAGS}" | xargs -I {} cosign sign --yes {}@${DIGEST} + tags: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest \ No newline at end of file