fix(github): reference cosign-installer by absolute URL #54
No reviewers
Labels
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/workflows!54
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/cosign-installer-absolute-url"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
My bug in #53, caught by the first release that used it.
A bare
uses: sigstore/cosign-installer@...resolves against the Forgejo instance first. Forgejo mirrorsactions/*anddocker/*— both other bare refs in this file clone fine — but not this one, so the clone 404s and the job dies before any step runs. ploeg run 209:That took
Distribute image (GHCR)and its flattened caller down with it, on the first release that was supposed to publish a signed mirror.cosign-sign-attestalready had this right, and says why: Forgejo's default action host is an incomplete mirror, so these are pinned to the canonical source. Now using the identical pin and version comment, so the two cosign paths cannot drift to different majors.Audited the rest of the file:
actions/checkout@v4anddocker/setup-buildx-action@v3both cloned successfully from Forgejo in that same run, so they are genuinely mirrored and stay bare.The rest of #53 worked — the Harbor job went green through the new index-annotation gate, which is the first time that gate has meant anything.
A bare `uses: sigstore/cosign-installer@...` resolves against the Forgejo instance first. Forgejo mirrors actions/* and docker/* — both bare refs in this file clone fine — but not this one, so the clone 404s and the job dies before any step runs. ploeg run 209: unable to clone '.../sigstore/cosign-installer': remote: Not found. which took `Distribute image (GHCR)` and its flattened caller down with it, on the first release that was supposed to publish a signed mirror. cosign-sign-attest already had this right and says why: Forgejo's default action host is an incomplete mirror, so these are pinned to the canonical source. Same pin, same version comment, so the two cosign paths cannot drift apart. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>