fix: cosign sign-blob use --bundle format (new cosign default) (#103)

cosign deprecated --output-signature/--output-certificate in new
bundle format, causing open: no such file or directory error.
This commit is contained in:
2026-04-06 01:52:55 +03:00
committed by GitHub
parent 7766a2f02c
commit 3fd92278c3

View File

@@ -267,7 +267,7 @@ jobs:
uses: sigstore/cosign-installer@cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003 # v3
- name: Sign binary with cosign (keyless Sigstore)
run: cosign sign-blob --yes --output-signature nora-linux-amd64.sig --output-certificate nora-linux-amd64.pem ./nora-linux-amd64
run: cosign sign-blob --yes --bundle nora-linux-amd64.bundle ./nora-linux-amd64
- name: Create Release
uses: softprops/action-gh-release@153bb8e04406b158c6c84fc1615b65b24149a1fe # v2
@@ -276,8 +276,7 @@ jobs:
files: |
nora-linux-amd64
nora-linux-amd64.sha256
nora-linux-amd64.sig
nora-linux-amd64.pem
nora-linux-amd64.bundle
nora-${{ github.ref_name }}.sbom.spdx.json
nora-${{ github.ref_name }}.sbom.cdx.json
nora-${{ github.ref_name }}.provenance.json