Commit 79f875b
authored
changes for cosign v3 compatibility (#2877)
### Problem
Cosign v3.0.2 removed support for `--output-signature` and
`--output-certificate` flags in favor of bundle format. Workflows were
failing with:
```
Error: must provide --bundle with --signing-config or
--use-signing-config
```
### Solution
Updated all `cosign sign-blob` commands to use bundle format:
```bash
cosign sign-blob <file> --yes --bundle=<file>.bundle
```
### Files Changed
**compile-docs.yml:**
- Simplified 3 cosign commands to use --bundle only
- Created placeholder .sig/.crt files for backward compatibility
- Updated tar archive to include .bundle files
- Updated release artifacts to use .bundle
- Updated verification instructions for bundle format
**compile-public-docs.yml:**
- Simplified 2 cosign commands to use --bundle only
- Created placeholder .sig/.crt files for backward compatibility
- Updated release to include .bundle files
### Why Placeholder Files?
The Dockerfile and some verification scripts still expect .sig/.crt
files.
Created empty placeholders to maintain compatibility during transition.
The
real verification data is in the .bundle files.
### Backward Compatibility
- Tar archives include both .bundle files (real) and .sig/.crt
(placeholders)
- GitHub releases include .bundle files
- Verification instructions updated to use bundle format
- Dockerfile continues to work (copies placeholder files)
Signed-off-by: ltagliaferri <[email protected]>1 parent bfeb2ba commit 79f875b
2 files changed
+32
-33
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
143 | 143 | | |
144 | 144 | | |
145 | 145 | | |
146 | | - | |
| 146 | + | |
147 | 147 | | |
148 | 148 | | |
149 | | - | |
150 | | - | |
151 | | - | |
| 149 | + | |
152 | 150 | | |
153 | | - | |
| 151 | + | |
154 | 152 | | |
155 | 153 | | |
156 | | - | |
157 | | - | |
158 | | - | |
159 | | - | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
160 | 161 | | |
161 | 162 | | |
162 | 163 | | |
163 | 164 | | |
164 | 165 | | |
165 | 166 | | |
| 167 | + | |
166 | 168 | | |
167 | 169 | | |
168 | 170 | | |
| 171 | + | |
169 | 172 | | |
170 | 173 | | |
171 | 174 | | |
172 | 175 | | |
173 | | - | |
| 176 | + | |
174 | 177 | | |
175 | 178 | | |
176 | | - | |
177 | | - | |
178 | | - | |
| 179 | + | |
179 | 180 | | |
180 | 181 | | |
181 | 182 | | |
| |||
276 | 277 | | |
277 | 278 | | |
278 | 279 | | |
279 | | - | |
| 280 | + | |
280 | 281 | | |
281 | | - | |
282 | 282 | | |
283 | 283 | | |
284 | | - | |
285 | | - | |
286 | | - | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
287 | 287 | | |
| 288 | + | |
288 | 289 | | |
289 | 290 | | |
290 | | - | |
291 | 291 | | |
292 | | - | |
| 292 | + | |
293 | 293 | | |
294 | 294 | | |
295 | 295 | | |
| |||
308 | 308 | | |
309 | 309 | | |
310 | 310 | | |
311 | | - | |
312 | | - | |
313 | 311 | | |
314 | 312 | | |
315 | 313 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
114 | 114 | | |
115 | 115 | | |
116 | 116 | | |
117 | | - | |
| 117 | + | |
118 | 118 | | |
119 | 119 | | |
120 | | - | |
121 | | - | |
122 | | - | |
| 120 | + | |
123 | 121 | | |
124 | | - | |
| 122 | + | |
125 | 123 | | |
126 | 124 | | |
127 | | - | |
128 | | - | |
129 | | - | |
130 | | - | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
131 | 132 | | |
132 | 133 | | |
133 | 134 | | |
| |||
213 | 214 | | |
214 | 215 | | |
215 | 216 | | |
216 | | - | |
217 | | - | |
| 217 | + | |
| 218 | + | |
218 | 219 | | |
219 | 220 | | |
220 | 221 | | |
| |||
0 commit comments