Commit b1b861d 1 parent 704db21 commit b1b861d Copy full SHA for b1b861d
File tree 2 files changed +12
-4
lines changed
2 files changed +12
-4
lines changed Original file line number Diff line number Diff line change @@ -71,11 +71,15 @@ jobs:
71
71
- name : Install cosign
72
72
uses : sigstore/cosign-installer@9becc617647dfa20ae7b1151972e9b3a2c338a2b # v2.8.1
73
73
with :
74
- cosign-release : ' v1.13.0'
74
+ cosign-release : ' v1.13.1'
75
+
76
+ - name : Install crane to get digest of image
77
+ uses : imjasonh/setup-crane@e82f1b9a8007d399333baba4d75915558e9fb6a4
75
78
76
79
- name : Sign Argo CD latest image
77
80
run : |
78
- cosign sign --key env://COSIGN_PRIVATE_KEY quay.io/argoproj/argocd:latest
81
+ echo "IMAGE_DIGEST=$(crane digest quay.io/argoproj/argocd:latest)" >> $GITHUB_ENV
82
+ cosign sign --key env://COSIGN_PRIVATE_KEY quay.io/argoproj/argocd@${{ env.IMAGE_DIGEST }}
79
83
# Displays the public key to share.
80
84
cosign public-key --key env://COSIGN_PRIVATE_KEY
81
85
env :
Original file line number Diff line number Diff line change @@ -217,11 +217,15 @@ jobs:
217
217
- name : Install cosign
218
218
uses : sigstore/cosign-installer@9becc617647dfa20ae7b1151972e9b3a2c338a2b # v2.8.1
219
219
with :
220
- cosign-release : ' v1.13.0'
220
+ cosign-release : ' v1.13.1'
221
+
222
+ - name : Install crane to get digest of image
223
+ uses : imjasonh/setup-crane@e82f1b9a8007d399333baba4d75915558e9fb6a4
221
224
222
225
- name : Sign Argo CD container images and assets
223
226
run : |
224
- cosign sign --key env://COSIGN_PRIVATE_KEY ${IMAGE_NAMESPACE}/argocd:v${TARGET_VERSION}
227
+ echo "IMAGE_DIGEST=$(crane digest quay.io/argoproj/argocd:v${TARGET_VERSION})" >> $GITHUB_ENV
228
+ cosign sign --key env://COSIGN_PRIVATE_KEY ${IMAGE_NAMESPACE}/argocd@${{ env.IMAGE_DIGEST }}
225
229
cosign sign-blob --key env://COSIGN_PRIVATE_KEY ./dist/argocd-${TARGET_VERSION}-checksums.txt > ./dist/argocd-${TARGET_VERSION}-checksums.sig
226
230
# Retrieves the public key to release as an asset
227
231
cosign public-key --key env://COSIGN_PRIVATE_KEY > ./dist/argocd-cosign.pub
You can’t perform that action at this time.
0 commit comments