ci(release): sign the image so podman can verify it #139
No reviewers
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app!139
Loading…
Reference in a new issue
No description provided.
Delete branch "ci/recursive-image-sign"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Stacked on #138 (top of the #137 stack): the release image signing follow-up that was pushed without a PR. Two gaps, both found by pointing a podman sigstoreSigned policy at the image:
cosign signon the index digest alone leaves the platform manifests unsigned, and podman verifies the child it actually pulls —--recursivesigns both.sha256-<digest>.sig) podman consumes. Blob signing elsewhere stays v3.🤖 Generated with Claude Code
Test report
Coverage: 28.2%
Updated by the check workflow · commit
9a5f2bc7bf