Skip to content

Commit f9a2252

Browse files
Verify cosign signatures after signing
Signed-off-by: Juan-Luis de Sousa-Valadas Castaño <[email protected]>
1 parent 63385a5 commit f9a2252

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

.github/workflows/release.yml

+4
Original file line numberDiff line numberDiff line change
@@ -105,6 +105,7 @@ jobs:
105105
chmod +x ./cosign
106106
COSIGN_KEY="$(printf %s "$COSIGN_KEY" | base64 -d)" ./cosign sign-blob --key env://COSIGN_KEY --tlog-upload=true --output-file=k0s.sig k0s
107107
cat k0s.sig
108+
COSIGN_KEY="$(printf %s "$COSIGN_KEY" | base64 -d)" ./cosign verify-blob --key env://COSIGN_KEY --signature k0s.sig k0s
108109
109110
- name: Upload Release Assets - Binary
110111
uses: shogo82148/[email protected]
@@ -197,6 +198,7 @@ jobs:
197198
chmod +x ./cosign
198199
COSIGN_KEY="$(printf %s "$COSIGN_KEY" | base64 -d)" ./cosign sign-blob --key env://COSIGN_KEY --tlog-upload=true --output-file=k0s.exe.sig k0s.exe
199200
cat k0s.exe.sig
201+
COSIGN_KEY="$(printf %s "$COSIGN_KEY" | base64 -d)" ./cosign verify-blob --key env://COSIGN_KEY --signature k0s.exe.sig k0s.exe
200202
201203
- name: Clean Docker
202204
run: |
@@ -265,6 +267,7 @@ jobs:
265267
chmod +x ./cosign
266268
COSIGN_KEY="$(printf %s "$COSIGN_KEY" | base64 -d)" ./cosign sign-blob --key env://COSIGN_KEY --tlog-upload=true --output-file=k0s.sig k0s
267269
cat k0s.sig
270+
COSIGN_KEY="$(printf %s "$COSIGN_KEY" | base64 -d)" ./cosign verify-blob --key env://COSIGN_KEY --signature k0s.sig k0s
268271
269272
- name: Set up Go for smoke tests
270273
uses: actions/setup-go@v3
@@ -352,6 +355,7 @@ jobs:
352355
chmod +x ./cosign
353356
COSIGN_KEY="$(printf %s "$COSIGN_KEY" | base64 -d)" ./cosign sign-blob --key env://COSIGN_KEY --tlog-upload=true --output-file=k0s.sig k0s
354357
cat k0s.sig
358+
COSIGN_KEY="$(printf %s "$COSIGN_KEY" | base64 -d)" ./cosign verify-blob --key env://COSIGN_KEY --signature k0s.sig k0s
355359
356360
- name: Set up Go for smoke tests
357361
uses: actions/setup-go@v3

0 commit comments

Comments
 (0)