Skip to content

Commit 24bec48

Browse files
committed
GHA: yaml: move env: before run: where not there
1 parent 5d40de3 commit 24bec48

File tree

4 files changed

+14
-14
lines changed

4 files changed

+14
-14
lines changed

.github/workflows/build_latest_release_multi.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -79,11 +79,11 @@ jobs:
7979
COSIGN_PRIVATE_KEY: '${{ secrets.COSIGN_PRIVATE_KEY }}'
8080
run: echo "${COSIGN_PRIVATE_KEY}" > cosign.key
8181
- name: 'sign images with sigstore key'
82+
env:
83+
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
8284
run: |
8385
cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl-multi:$REL
8486
cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl-base-multi:$REL
85-
env:
86-
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
8787
- name: 'verify image with public key'
8888
run: |
8989
cosign verify --key cosign.pub ghcr.io/curl/curl-container/curl-multi:$REL
@@ -95,13 +95,13 @@ jobs:
9595
buildah manifest push --format v2s2 --all localhost/curl-base-multi:$REL "docker://docker.io/curlimages/curl-base:${REL}"
9696
buildah manifest push --format v2s2 --all localhost/curl-base-multi:$REL "docker://docker.io/curlimages/curl-base:latest"
9797
- name: 'sign images with a sigstore key'
98+
env:
99+
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
98100
run: |
99101
cosign sign -y --key cosign.key docker.io/curlimages/curl:$REL
100102
cosign sign -y --key cosign.key docker.io/curlimages/curl:latest
101103
cosign sign -y --key cosign.key docker.io/curlimages/curl-base:$REL
102104
cosign sign -y --key cosign.key docker.io/curlimages/curl-base:latest
103-
env:
104-
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
105105
- name: 'verify image with public key'
106106
run: |
107107
cosign verify --key cosign.pub docker.io/curlimages/curl:$REL
@@ -115,13 +115,13 @@ jobs:
115115
buildah manifest push --format v2s2 --all localhost/curl-base-multi:$REL "docker://quay.io/curl/curl-base:${REL}"
116116
buildah manifest push --format v2s2 --all localhost/curl-base-multi:$REL "docker://quay.io/curl/curl-base:latest"
117117
- name: 'sign images with a sigstore key'
118+
env:
119+
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
118120
run: |
119121
cosign sign -y --key cosign.key quay.io/curl/curl:$REL
120122
cosign sign -y --key cosign.key quay.io/curl/curl:latest
121123
cosign sign -y --key cosign.key quay.io/curl/curl-base:$REL
122124
cosign sign -y --key cosign.key quay.io/curl/curl-base:latest
123-
env:
124-
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
125125
- name: 'verify image with public key'
126126
run: |
127127
cosign verify --key cosign.pub quay.io/curl/curl:$REL

.github/workflows/build_master.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -74,12 +74,12 @@ jobs:
7474
COSIGN_PRIVATE_KEY: '${{ secrets.COSIGN_PRIVATE_KEY }}'
7575
run: echo "${COSIGN_PRIVATE_KEY}" > cosign.key
7676
- name: 'sign image with a key'
77+
env:
78+
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
7779
run: |
7880
cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl-dev:master
7981
cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl-base:master
8082
cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl:master
81-
env:
82-
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
8383
- name: 'verify image with public key'
8484
run: |
8585
cosign verify --key cosign.pub ghcr.io/curl/curl-container/curl-dev:master

.github/workflows/build_master_dev.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -71,10 +71,10 @@ jobs:
7171
COSIGN_PRIVATE_KEY: '${{ secrets.COSIGN_PRIVATE_KEY }}'
7272
run: echo "${COSIGN_PRIVATE_KEY}" > cosign.key
7373
- name: 'sign image with a key'
74-
run: |
75-
cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl-dev-debian:master
7674
env:
7775
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
76+
run: |
77+
cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl-dev-debian:master
7878
- name: 'verify image with public key'
7979
run: |
8080
cosign verify --key cosign.pub ghcr.io/curl/curl-container/curl-dev-debian:master
@@ -88,10 +88,10 @@ jobs:
8888
run: |
8989
buildah push curl-dev-fedora:master "docker://ghcr.io/curl/curl-container/curl-dev-fedora:master"
9090
- name: 'sign image with a key'
91-
run: |
92-
cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl-dev-fedora:master
9391
env:
9492
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
93+
run: |
94+
cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl-dev-fedora:master
9595
- name: 'verify image with public key'
9696
run: |
9797
cosign verify --key cosign.pub ghcr.io/curl/curl-container/curl-dev-fedora:master

.github/workflows/build_master_multi.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -73,11 +73,11 @@ jobs:
7373
COSIGN_PRIVATE_KEY: '${{ secrets.COSIGN_PRIVATE_KEY }}'
7474
run: echo "${COSIGN_PRIVATE_KEY}" > cosign.key
7575
- name: 'sign image with a key'
76+
env:
77+
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
7678
run: |
7779
cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl-multi:master
7880
cosign sign -y --key cosign.key ghcr.io/curl/curl-container/curl-base-multi:master
79-
env:
80-
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
8181
- name: 'verify image with public key'
8282
run: |
8383
cosign verify --key cosign.pub ghcr.io/curl/curl-container/curl-multi:master

0 commit comments

Comments
 (0)