fix(forgejo-distribute): mirror cosign's accessories, not just the image #56
No reviewers
Labels
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/workflows!56
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/sign-the-forgejo-mirror"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The GHCR mirror was publishing an unsigned copy of a signed image. v1.11.0 fixed that and left the Forgejo mirror with the identical defect — both take the same
imagetools createpath.imagetoolscopies the manifest list, so BuildKit's SLSA provenance and SBOM ride along inside the index for free. cosign's signature and CycloneDX attestation live as separate.sig/.atttags and are left behind.Same shape as
github-distribute:cosign copy --only=sig,att,sbomafter the image copy, so the image is not pushed twice. Gated on an input defaulting to off, so existing callers are untouched. Fail-soft on a missing signature — an unsigned source is legitimate (the signing job is independent) and failing the mirror over it would make the image unavailable rather than merely unverifiable.The installer is referenced by absolute github.com URL. A bare
owner/actionresolves against the Forgejo instance, which does not mirror this one, and the clone 404s the job before any step runs — the mistake that cost ploeg run 209, not repeated here.With this, all three registries carry the same signature rather than Harbor alone, which is what "the image is signed" has generally been taken to mean.