diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index de5913e..4b15c3a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -267,7 +267,7 @@ jobs: uses: sigstore/cosign-installer@cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003 # v3 - name: Sign binary with cosign (keyless Sigstore) - run: cosign sign-blob --yes --output-signature nora-linux-amd64.sig --output-certificate nora-linux-amd64.pem ./nora-linux-amd64 + run: cosign sign-blob --yes --bundle nora-linux-amd64.bundle ./nora-linux-amd64 - name: Create Release uses: softprops/action-gh-release@153bb8e04406b158c6c84fc1615b65b24149a1fe # v2 @@ -276,8 +276,7 @@ jobs: files: | nora-linux-amd64 nora-linux-amd64.sha256 - nora-linux-amd64.sig - nora-linux-amd64.pem + nora-linux-amd64.bundle nora-${{ github.ref_name }}.sbom.spdx.json nora-${{ github.ref_name }}.sbom.cdx.json nora-${{ github.ref_name }}.provenance.json