Skip to content

Commit 297830a

Browse files
authored
Merge pull request #636 from saschagrunert/fix/cosign-bundle-format
Switch cosign signing to new bundle format
2 parents 1d37084 + 9246e00 commit 297830a

1 file changed

Lines changed: 5 additions & 3 deletions

File tree

.goreleaser.yml

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -52,10 +52,12 @@ archives:
5252
signs:
5353
# Keyless
5454
- id: bom-keyless
55-
signature: "${artifact}.sig"
56-
certificate: "${artifact}.pem"
55+
signature: "${artifact}.sigstore.json"
5756
cmd: cosign
58-
args: ["sign-blob", "--output-signature", "${artifact}.sig", "--output-certificate", "${artifact}.pem", "${artifact}"]
57+
args:
58+
- "sign-blob"
59+
- "--bundle=${signature}"
60+
- "${artifact}"
5961
artifacts: all
6062

6163
sboms:

0 commit comments

Comments
 (0)