File tree Expand file tree Collapse file tree 1 file changed +6
-14
lines changed
Expand file tree Collapse file tree 1 file changed +6
-14
lines changed Original file line number Diff line number Diff line change 11name : " Release Build"
2+
23on :
3- release :
4- types : [published]
4+ push :
5+ branches :
6+ - main
7+
58env :
69 CONTAINER_REGISTRY : ghcr.io/securecodebox
710jobs :
@@ -11,22 +14,17 @@ jobs:
1114 permissions :
1215 contents : read
1316 packages : write
14- id-token : write # needed for signing the images with GitHub OIDC Token
1517 steps :
1618 - name : Checkout
1719 uses : actions/checkout@v4
1820
19- - name : Install Cosign
20- uses : sigstore/cosign-installer@v3
21-
2221 - id : image-metadata
2322 name : Container Image Metadata
2423 uses : docker/metadata-action@v5
2524 with :
2625 images : ${{ env.CONTAINER_REGISTRY }}/scan-deduplicator/scan-deduplicator
2726 tags : |
28- type=semver,pattern={{raw}}
29-
27+ latest
3028 - name : Set up QEMU
3129 uses : docker/setup-qemu-action@v3
3230 - name : Set up Docker Buildx
4846 push : true
4947 tags : ${{ steps.image-metadata.outputs.tags }}
5048 labels : ${{ steps.image-metadata.outputs.labels }}
51-
52- - name : Sign the images with GitHub OIDC Token
53- env :
54- DIGEST : ${{ steps.build-and-push.outputs.digest }}
55- TAGS : ${{ steps.image-metadata.outputs.tags }}
56- run : echo "${TAGS}" | xargs -I {} cosign sign --yes {}@${DIGEST}
You can’t perform that action at this time.
0 commit comments