@@ -79,11 +79,11 @@ jobs:
7979 COSIGN_PRIVATE_KEY : ' ${{ secrets.COSIGN_PRIVATE_KEY }}'
8080 run : echo "${COSIGN_PRIVATE_KEY}" > cosign.key
8181 - name : ' sign images with sigstore key'
82+ env :
83+ COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
8284 run : |
8385 cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl-multi:$REL
8486 cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl-base-multi:$REL
85- env :
86- COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
8787 - name : ' verify image with public key'
8888 run : |
8989 cosign verify --key cosign.pub ghcr.io/curl/curl-container/curl-multi:$REL
@@ -95,13 +95,13 @@ jobs:
9595 buildah manifest push --format v2s2 --all localhost/curl-base-multi:$REL "docker://docker.io/curlimages/curl-base:${REL}"
9696 buildah manifest push --format v2s2 --all localhost/curl-base-multi:$REL "docker://docker.io/curlimages/curl-base:latest"
9797 - name : ' sign images with a sigstore key'
98+ env :
99+ COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
98100 run : |
99101 cosign sign -y --key cosign.key docker.io/curlimages/curl:$REL
100102 cosign sign -y --key cosign.key docker.io/curlimages/curl:latest
101103 cosign sign -y --key cosign.key docker.io/curlimages/curl-base:$REL
102104 cosign sign -y --key cosign.key docker.io/curlimages/curl-base:latest
103- env :
104- COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
105105 - name : ' verify image with public key'
106106 run : |
107107 cosign verify --key cosign.pub docker.io/curlimages/curl:$REL
@@ -115,13 +115,13 @@ jobs:
115115 buildah manifest push --format v2s2 --all localhost/curl-base-multi:$REL "docker://quay.io/curl/curl-base:${REL}"
116116 buildah manifest push --format v2s2 --all localhost/curl-base-multi:$REL "docker://quay.io/curl/curl-base:latest"
117117 - name : ' sign images with a sigstore key'
118+ env :
119+ COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
118120 run : |
119121 cosign sign -y --key cosign.key quay.io/curl/curl:$REL
120122 cosign sign -y --key cosign.key quay.io/curl/curl:latest
121123 cosign sign -y --key cosign.key quay.io/curl/curl-base:$REL
122124 cosign sign -y --key cosign.key quay.io/curl/curl-base:latest
123- env :
124- COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
125125 - name : ' verify image with public key'
126126 run : |
127127 cosign verify --key cosign.pub quay.io/curl/curl:$REL
0 commit comments