Update docker-publish.yml

This commit is contained in:
hexeth 2022-10-07 14:54:05 -07:00 committed by GitHub
parent 34eedfbc65
commit a84bdc16de
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -84,10 +84,10 @@ jobs:
# repository is public to avoid leaking data. If you would like to publish # repository is public to avoid leaking data. If you would like to publish
# transparency data even for private images, pass --force to cosign below. # transparency data even for private images, pass --force to cosign below.
# https://github.com/sigstore/cosign # https://github.com/sigstore/cosign
- name: Sign the published Docker image #- name: Sign the published Docker image
if: ${{ github.event_name != 'pull_request' }} # if: ${{ github.event_name != 'pull_request' }}
env: # env:
COSIGN_EXPERIMENTAL: "true" # COSIGN_EXPERIMENTAL: "true"
# This step uses the identity token to provision an ephemeral certificate # This step uses the identity token to provision an ephemeral certificate
# against the sigstore community Fulcio instance. # against the sigstore community Fulcio instance.
run: cosign sign ${{ steps.meta.outputs.tags }}@${{ steps.build-and-push.outputs.digest }} # run: cosign sign ${{ steps.meta.outputs.tags }}@${{ steps.build-and-push.outputs.digest }}