mirror of
https://github.com/getnora-io/nora.git
synced 2026-04-12 10:20:32 +00:00
fix: cosign sign-blob use --bundle format (new cosign default) (#103)
cosign deprecated --output-signature/--output-certificate in new bundle format, causing open: no such file or directory error.
This commit is contained in:
5
.github/workflows/release.yml
vendored
5
.github/workflows/release.yml
vendored
@@ -267,7 +267,7 @@ jobs:
|
|||||||
uses: sigstore/cosign-installer@cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003 # v3
|
uses: sigstore/cosign-installer@cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003 # v3
|
||||||
|
|
||||||
- name: Sign binary with cosign (keyless Sigstore)
|
- name: Sign binary with cosign (keyless Sigstore)
|
||||||
run: cosign sign-blob --yes --output-signature nora-linux-amd64.sig --output-certificate nora-linux-amd64.pem ./nora-linux-amd64
|
run: cosign sign-blob --yes --bundle nora-linux-amd64.bundle ./nora-linux-amd64
|
||||||
|
|
||||||
- name: Create Release
|
- name: Create Release
|
||||||
uses: softprops/action-gh-release@153bb8e04406b158c6c84fc1615b65b24149a1fe # v2
|
uses: softprops/action-gh-release@153bb8e04406b158c6c84fc1615b65b24149a1fe # v2
|
||||||
@@ -276,8 +276,7 @@ jobs:
|
|||||||
files: |
|
files: |
|
||||||
nora-linux-amd64
|
nora-linux-amd64
|
||||||
nora-linux-amd64.sha256
|
nora-linux-amd64.sha256
|
||||||
nora-linux-amd64.sig
|
nora-linux-amd64.bundle
|
||||||
nora-linux-amd64.pem
|
|
||||||
nora-${{ github.ref_name }}.sbom.spdx.json
|
nora-${{ github.ref_name }}.sbom.spdx.json
|
||||||
nora-${{ github.ref_name }}.sbom.cdx.json
|
nora-${{ github.ref_name }}.sbom.cdx.json
|
||||||
nora-${{ github.ref_name }}.provenance.json
|
nora-${{ github.ref_name }}.provenance.json
|
||||||
|
|||||||
Reference in New Issue
Block a user