ci(release): sign the image so podman can verify it #139

Merged
nalum merged 1 commit from ci/recursive-image-sign into main 2026-08-18 16:42:48 +00:00
Owner

Stacked on #138 (top of the #137 stack): the release image signing follow-up that was pushed without a PR. Two gaps, both found by pointing a podman sigstoreSigned policy at the image:

  1. cosign sign on the index digest alone leaves the platform manifests unsigned, and podman verifies the child it actually pulls — --recursive signs both.
  2. cosign v3 only writes the OCI referrers signature format, which podman does not read — the image job pins cosign v2.6.1, which writes the legacy tag scheme (sha256-<digest>.sig) podman consumes. Blob signing elsewhere stays v3.

🤖 Generated with Claude Code

Stacked on #138 (top of the #137 stack): the release image signing follow-up that was pushed without a PR. Two gaps, both found by pointing a podman sigstoreSigned policy at the image: 1. `cosign sign` on the index digest alone leaves the platform manifests unsigned, and podman verifies the child it actually pulls — `--recursive` signs both. 2. cosign v3 only writes the OCI referrers signature format, which podman does not read — the image job pins cosign v2.6.1, which writes the legacy tag scheme (`sha256-<digest>.sig`) podman consumes. Blob signing elsewhere stays v3. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
ci(release): sign the image so podman can verify it
Some checks failed
check / commits (pull_request) Successful in 9s
check / web (pull_request) Successful in 1m35s
check / go (pull_request) Successful in 2m32s
check / report (pull_request) Successful in 2s
check / report (push) Has been cancelled
check / web (push) Has been cancelled
tag / tag (push) Has been cancelled
check / go (push) Has been cancelled
check / commits (push) Has been cancelled
9a5f2bc7bf
Two gaps, both found by pointing a podman sigstoreSigned policy at the
image. cosign sign on the index digest alone leaves the platform
manifests unsigned, and podman verifies the child it actually pulls,
not the list — --recursive signs both. And cosign v3 can only write
the OCI referrers signature format, which podman does not read; the
image job pins cosign v2.6.1, which writes the legacy tag scheme
(sha256-<digest>.sig) podman consumes. Blob signing elsewhere stays
v3 — its bundle format is a published verify contract.

Test report

Suite Tests Result Skipped
Unit 1370 ✅ pass 1
Integration 85 ✅ pass —

Coverage: 28.2%

Updated by the check workflow · commit 9a5f2bc7bf

<!-- ci-test-report --> ## Test report | Suite | Tests | Result | Skipped | | --- | --: | --- | --: | | Unit | 1370 | ✅ pass | 1 | | Integration | 85 | ✅ pass | — | **Coverage:** 28.2% <sub>Updated by the check workflow · commit 9a5f2bc7bfb60a10d7de1b0f302546fff1afdd5c</sub>
nalum changed target branch from fix/sessions to main 2026-08-18 16:42:41 +00:00
nalum merged commit 9a5f2bc7bf into main 2026-08-18 16:42:48 +00:00
nalum deleted branch ci/recursive-image-sign 2026-08-18 16:42:48 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app!139
No description provided.