Skip to content

Commit 7490186

Browse files
authored
Fix permissions and verify sigantures (#2723)
Signed-off-by: jose.vazquez <[email protected]>
1 parent 7698fcf commit 7490186

File tree

1 file changed

+13
-0
lines changed

1 file changed

+13
-0
lines changed

.github/workflows/release-image.yml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@ on:
2626
permissions:
2727
contents: write
2828
pull-requests: write
29+
workflows: write
2930

3031
jobs:
3132
# Image2commit: Creates a mapping between the image_sha given as input and the actual git commit
@@ -246,6 +247,18 @@ jobs:
246247
PKCS11_URI: ${{ secrets.PKCS11_URI }}
247248
GRS_USERNAME: ${{ secrets.GRS_USERNAME }}
248249
GRS_PASSWORD: ${{ secrets.GRS_PASSWORD }}
250+
251+
- name: Self-verify released image signatures
252+
run: |
253+
devbox run -- make verify IMG="${{ env.DOCKER_IMAGE_URL }}" SIGNATURE_REPO="${{ env.DOCKER_RELEASE_REPO }}"
254+
devbox run -- make verify IMG="${{ env.QUAY_IMAGE_URL }}" SIGNATURE_REPO="${{ env.QUAY_RELEASE_REPO }}"
255+
devbox run -- make verify IMG="${{ env.DOCKER_IMAGE_URL }}" SIGNATURE_REPO="${{ env.DOCKER_SIGNATURE_REPO }}"
256+
devbox run -- make verify IMG="${{ env.QUAY_CERTIFIED_IMAGE_URL }}" SIGNATURE_REPO="${{ env.QUAY_RELEASE_REPO }}"
257+
devbox run -- make verify IMG="${{ env.QUAY_CERTIFIED_IMAGE_URL }}" SIGNATURE_REPO="${{ env.DOCKER_SIGNATURE_REPO }}"
258+
env:
259+
PKCS11_URI: ${{ secrets.PKCS11_URI }}
260+
GRS_USERNAME: ${{ secrets.GRS_USERNAME }}
261+
GRS_PASSWORD: ${{ secrets.GRS_PASSWORD }}
249262

250263
- name: Generate SBOMs
251264
run: devbox run -- make generate-sboms RELEASED_OPERATOR_IMAGE="${{ env.DOCKER_RELEASE_REPO }}"

0 commit comments

Comments
 (0)