Skip to content

Conversation

@dervoeti
Copy link
Member

@dervoeti dervoeti commented Sep 9, 2024

Fix for #827

Sorry, I hope this is the last fix: I built mergebom as a container image first but then switched to building a binary and forgot to adapt the signature check in the GitHub action, so that it matches the new workflow name.

Tested the change locally, works:

curl -L -o mergebom https://repo.stackable.tech/repository/packages/mergebom/stable-x86_64

curl -L -o mergebom.bundle https://repo.stackable.tech/repository/packages/mergebom/stable-x86_64_signature.bundle

cosign verify-blob --certificate-identity 'https://github.com/stackabletech/mergebom/.github/workflows/build_binary.yaml@refs/heads/main' --certificate-oidc-issuer https://token.actions.githubusercontent.com --bundle mergebom.bundle mergebom
Verified OK

@dervoeti dervoeti requested a review from lfrancke September 9, 2024 13:32
@dervoeti dervoeti added this pull request to the merge queue Sep 9, 2024
Merged via the queue into main with commit 4f57e94 Sep 9, 2024
1 check passed
@dervoeti dervoeti deleted the fix/mergebom-cosign-verification branch September 9, 2024 14:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants