From 64ffe30f63df7545fae4cfa87d6bb4472a43dec9 Mon Sep 17 00:00:00 2001 From: Jonathon Anderson Date: Sat, 9 Dec 2023 17:06:03 -0700 Subject: [PATCH] Remove remnant of cosign key signing step Signed-off-by: Jonathon Anderson --- .github/workflows/container-publish.yml | 8 -------- 1 file changed, 8 deletions(-) diff --git a/.github/workflows/container-publish.yml b/.github/workflows/container-publish.yml index 8045ea3..e765137 100644 --- a/.github/workflows/container-publish.yml +++ b/.github/workflows/container-publish.yml @@ -136,14 +136,6 @@ jobs: cache-to: type=gha,mode=max # https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-an-intermediate-environment-variable - - name: Sign image with a key - if: github.event_name != 'pull_request' - run: | - cosign sign --yes "${TAGS}@${DIGEST}" - env: - TAGS: ${{ steps.docker_meta.outputs.tags }} - DIGEST: ${{ steps.build-and-push.outputs.digest }} - - name: Sign the images with GitHub OIDC Token if: github.event_name != 'pull_request' env: