File tree Expand file tree Collapse file tree 1 file changed +7
-6
lines changed Expand file tree Collapse file tree 1 file changed +7
-6
lines changed Original file line number Diff line number Diff line change @@ -36,6 +36,7 @@ permissions:
36
36
packages : write # push to ghcr.io via GITHUB_TOKEN
37
37
security-events : write # upload SARIF to “Code scanning”
38
38
actions : read # needed by upload-sarif in private repos
39
+ id-token : write # required for OIDC token generation
39
40
40
41
jobs :
41
42
build-scan-sign :
@@ -180,17 +181,17 @@ jobs:
180
181
181
182
- name : 🔏 Sign & attest images (latest + timestamp)
182
183
env :
183
- COSIGN_EXPERIMENTAL : " 1" # required for key-less flow
184
- OIDC_ISSUER : https://token.actions.githubusercontent.com
184
+ COSIGN_EXPERIMENTAL : " 1"
185
185
run : |
186
186
for REF in $IMAGE_NAME:latest $IMAGE_NAME:${{ env.TAG }}; do
187
187
echo "🔑 Signing $REF"
188
- cosign sign --yes --oidc-issuer "$OIDC_ISSUER" "$REF" # key-less sign
188
+ cosign sign --yes "$REF"
189
+
189
190
echo "📝 Attesting SBOM for $REF"
190
191
cosign attest --yes \
191
- --predicate sbom.spdx.json \
192
- --oidc-issuer "$OIDC_ISSUER" \
193
- "$REF" # SBOM attestation
192
+ --predicate sbom.spdx.json \
193
+ --type spdxjson \
194
+ "$REF"
194
195
done
195
196
196
197
# -------------------------------------------------------------
You can’t perform that action at this time.
0 commit comments