From f31732b3d8898b7b480e9fb2f74777aaf4375901 Mon Sep 17 00:00:00 2001 From: kranurag7 <81210977+kranurag7@users.noreply.github.com> Date: Wed, 31 Jul 2024 11:17:13 +0530 Subject: [PATCH] fix cosign signing issue (#221) we don't need experimental anymore, we are using latest cosign here. Signed-off-by: kranurag7 <81210977+kranurag7@users.noreply.github.com> --- .github/workflows/publish.yml | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index c9d7eff..d764026 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -55,8 +55,6 @@ jobs: - uses: sigstore/cosign-installer@59acb6260d9c0ba8f4a2f9d9b48431a222b68e20 # v3.5.0 - name: Push chart to GHCR - env: - COSIGN_EXPERIMENTAL: 1 run: | shopt -s nullglob for pkg in .cr-release-packages/*; do @@ -64,7 +62,7 @@ jobs: break fi helm push "${pkg}" oci://ghcr.io/"${GITHUB_REPOSITORY_OWNER}"/charts |& tee .digest - cosign sign $(cat .digest | awk -F "[, ]+" '/Pushed/{print $NF}') + cosign sign --yes $(cat .digest | awk -F "[, ]+" '/Pushed/{print $NF}') done - uses: oras-project/setup-oras@ca28077386065e263c03428f4ae0c09024817c93 # v1 with: