fix(forgejo-distribute): mirror cosign's accessories, not just the image #56

Merged
ryangr0 merged 1 commit from feat/sign-the-forgejo-mirror into main 2026-08-26 10:18:07 +00:00
Owner

The GHCR mirror was publishing an unsigned copy of a signed image. v1.11.0 fixed that and left the Forgejo mirror with the identical defect — both take the same imagetools create path.

imagetools copies the manifest list, so BuildKit's SLSA provenance and SBOM ride along inside the index for free. cosign's signature and CycloneDX attestation live as separate .sig/.att tags and are left behind.

Same shape as github-distribute: cosign copy --only=sig,att,sbom after the image copy, so the image is not pushed twice. Gated on an input defaulting to off, so existing callers are untouched. Fail-soft on a missing signature — an unsigned source is legitimate (the signing job is independent) and failing the mirror over it would make the image unavailable rather than merely unverifiable.

The installer is referenced by absolute github.com URL. A bare owner/action resolves against the Forgejo instance, which does not mirror this one, and the clone 404s the job before any step runs — the mistake that cost ploeg run 209, not repeated here.

With this, all three registries carry the same signature rather than Harbor alone, which is what "the image is signed" has generally been taken to mean.

The GHCR mirror was publishing an unsigned copy of a signed image. v1.11.0 fixed that and **left the Forgejo mirror with the identical defect** — both take the same `imagetools create` path. `imagetools` copies the manifest list, so BuildKit's SLSA provenance and SBOM ride along inside the index for free. cosign's signature and CycloneDX attestation live as separate `.sig`/`.att` tags and are left behind. Same shape as `github-distribute`: `cosign copy --only=sig,att,sbom` after the image copy, so the image is not pushed twice. Gated on an input defaulting to **off**, so existing callers are untouched. Fail-soft on a missing signature — an unsigned source is legitimate (the signing job is independent) and failing the mirror over it would make the image *unavailable* rather than merely unverifiable. The installer is referenced by **absolute** github.com URL. A bare `owner/action` resolves against the Forgejo instance, which does not mirror this one, and the clone 404s the job before any step runs — the mistake that cost ploeg run 209, not repeated here. With this, all three registries carry the same signature rather than Harbor alone, which is what "the image is signed" has generally been taken to mean.
fix(forgejo-distribute): mirror cosign's accessories, not just the image
Some checks failed
docker-build-and-push-registry.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
docker-build-and-push.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
forgejo-distribute.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
github-distribute.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
github-issue-create-by-prompt.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
github-issues-create-by-prompt.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
helm-chart-deploy.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
helm-chart-push.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
helm-charts-deploy.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
helm-charts-push.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
laravel-quality.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
php-application-static-analysis.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
rust-semantic-release.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
semantic-release-monorepo.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
semantic-release.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
setup-repository-bootstrap.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
setup-repository-copilot-files.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
setup-repository-create-from-template.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
spa-preview.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
static-analysis.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
sync-template-files.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
techdocs-deploy-backstage-s3.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
techdocs-deploy-codeberg.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
techdocs-deploy-docs-site.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
techdocs-deploy-gh-pages.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
tests.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
update_mkdocs.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
update_techdocs.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
wordpress-plugin-release-distribute.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
wordpress-plugin-release.yml / Merge pull request 'fix(forgejo-distribute): mirror cosign's accessories, not just the image' (#56) from feat/sign-the-forgejo-mirror into main (pull_request) Failing after 0s
79b12042dd
The GHCR mirror was publishing an unsigned copy of a signed image; v1.11.0 fixed
that and left the Forgejo mirror with the identical defect, because both take
the same `imagetools create` path. imagetools copies the manifest list, so
BuildKit's SLSA provenance and SBOM ride along inside the index for free, while
cosign's signature and CycloneDX attestation — separate .sig/.att tags — are
left behind.

Same shape as github-distribute: `cosign copy --only=sig,att,sbom` after the
image copy, so the image is not pushed twice, gated on an input that defaults to
off so existing callers are untouched. Fail-soft on a missing signature, since
an unsigned source is legitimate and failing the mirror over it would make the
image unavailable rather than merely unverifiable.

The installer is referenced by absolute github.com URL. A bare `owner/action`
resolves against the Forgejo instance, which does not mirror this one, and the
clone 404s the job before any step runs — the mistake that cost ploeg run 209.

With this, all three registries carry the same signature rather than Harbor
alone, which is what "the image is signed" has been taken to mean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
webgrip-ci referenced this pull request from a commit 2026-08-26 10:18:56 +00:00
Sign in to join this conversation.
No reviewers
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/workflows!56
No description provided.