fix(github): reference cosign-installer by absolute URL #54

Merged
ryangr0 merged 1 commit from fix/cosign-installer-absolute-url into main 2026-08-26 09:32:13 +00:00
Owner

My bug in #53, caught by the first release that used it.

A bare uses: sigstore/cosign-installer@... resolves against the Forgejo instance first. Forgejo mirrors actions/* and docker/* — both other bare refs in this file clone fine — but not this one, so the clone 404s and the job dies before any step runs. ploeg run 209:

unable to clone '.../sigstore/cosign-installer': remote: Not found.

That took Distribute image (GHCR) and its flattened caller down with it, on the first release that was supposed to publish a signed mirror.

cosign-sign-attest already had this right, and says why: Forgejo's default action host is an incomplete mirror, so these are pinned to the canonical source. Now using the identical pin and version comment, so the two cosign paths cannot drift to different majors.

Audited the rest of the file: actions/checkout@v4 and docker/setup-buildx-action@v3 both cloned successfully from Forgejo in that same run, so they are genuinely mirrored and stay bare.

The rest of #53 worked — the Harbor job went green through the new index-annotation gate, which is the first time that gate has meant anything.

My bug in #53, caught by the first release that used it. A bare `uses: sigstore/cosign-installer@...` resolves against the **Forgejo instance first**. Forgejo mirrors `actions/*` and `docker/*` — both other bare refs in this file clone fine — but not this one, so the clone 404s and the job dies before any step runs. ploeg run 209: ``` unable to clone '.../sigstore/cosign-installer': remote: Not found. ``` That took `Distribute image (GHCR)` and its flattened caller down with it, on the first release that was supposed to publish a signed mirror. `cosign-sign-attest` already had this right, and says why: Forgejo's default action host is an incomplete mirror, so these are pinned to the canonical source. Now using the identical pin and version comment, so the two cosign paths cannot drift to different majors. Audited the rest of the file: `actions/checkout@v4` and `docker/setup-buildx-action@v3` both cloned successfully from Forgejo in that same run, so they are genuinely mirrored and stay bare. The rest of #53 worked — the Harbor job went green **through** the new index-annotation gate, which is the first time that gate has meant anything.
fix(github): reference cosign-installer by absolute URL
Some checks failed
docker-build-and-push-registry.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
docker-build-and-push.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
forgejo-distribute.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
github-distribute.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
github-issue-create-by-prompt.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
github-issues-create-by-prompt.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
helm-chart-deploy.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
helm-chart-push.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
helm-charts-deploy.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
helm-charts-push.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
laravel-quality.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
php-application-static-analysis.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
rust-semantic-release.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
semantic-release-monorepo.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
semantic-release.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
setup-repository-bootstrap.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
setup-repository-copilot-files.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
setup-repository-create-from-template.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
spa-preview.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
static-analysis.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
sync-template-files.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
techdocs-deploy-backstage-s3.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
techdocs-deploy-codeberg.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
techdocs-deploy-docs-site.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
techdocs-deploy-gh-pages.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
tests.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
update_mkdocs.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
update_techdocs.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
wordpress-plugin-release-distribute.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
wordpress-plugin-release.yml / Merge pull request 'fix(github): reference cosign-installer by absolute URL' (#54) from fix/cosign-installer-absolute-url into main (pull_request) Failing after 0s
d546935e80
A bare `uses: sigstore/cosign-installer@...` resolves against the Forgejo
instance first. Forgejo mirrors actions/* and docker/* — both bare refs in this
file clone fine — but not this one, so the clone 404s and the job dies before
any step runs. ploeg run 209:

    unable to clone '.../sigstore/cosign-installer': remote: Not found.

which took `Distribute image (GHCR)` and its flattened caller down with it, on
the first release that was supposed to publish a signed mirror.

cosign-sign-attest already had this right and says why: Forgejo's default action
host is an incomplete mirror, so these are pinned to the canonical source. Same
pin, same version comment, so the two cosign paths cannot drift apart.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
webgrip-ci referenced this pull request from a commit 2026-08-26 09:33:20 +00:00
Sign in to join this conversation.
No reviewers
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/workflows!54
No description provided.