File tree Expand file tree Collapse file tree 1 file changed +7
-7
lines changed Expand file tree Collapse file tree 1 file changed +7
-7
lines changed Original file line number Diff line number Diff line change @@ -81,20 +81,20 @@ jobs:
8181 env :
8282 GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
8383 GITHUB_SBOM_PATH : ./sbom.spdx.json
84- # parse metadata to the format required for image attestation
84+ # parse artifacts to the format required for image attestation
8585 - run : |
86- echo "digest=$(echo "$METADATA " | jq -r '.[]|select(.type=="Docker Manifest")|select(.name|test(":v"))|.extra.Digest')" >> "$GITHUB_OUTPUT"
87- echo "name=$(echo "$METADATA " | jq -r '.[]|select(.type=="Docker Manifest")|select(.name|test(":v"))|.name|split(":")[0]')" >> "$GITHUB_OUTPUT"
88- id: artifact_metadata
86+ echo "digest=$(echo "$ARTIFACTS " | jq -r '.[]|select(.type=="Docker Manifest")|select(.name|test(":v"))|.extra.Digest')" >> "$GITHUB_OUTPUT"
87+ echo "name=$(echo "$ARTIFACTS " | jq -r '.[]|select(.type=="Docker Manifest")|select(.name|test(":v"))|.name|split(":")[0]')" >> "$GITHUB_OUTPUT"
88+ id: image_metadata
8989 env:
90- METADATA : ${{steps.goreleaser.outputs.metadata }}
90+ ARTIFACTS : ${{steps.goreleaser.outputs.artifacts }}
9191 # attest archives
9292 - uses : actions/attest-build-provenance@173725a1209d09b31f9d30a3890cf2757ebbff0d # v1.1.2
9393 with :
9494 subject-path : " dist/*.tar.gz"
9595 # attest images
9696 - uses : actions/attest-build-provenance@173725a1209d09b31f9d30a3890cf2757ebbff0d # v1.1.2
9797 with :
98- subject-digest : ${{steps.artifact_metadata .outputs.digest}}
99- subject-name : ${{steps.artifact_metadata .outputs.name}}
98+ subject-digest : ${{steps.image_metadata .outputs.digest}}
99+ subject-name : ${{steps.image_metadata .outputs.name}}
100100 push-to-registry : true
You can’t perform that action at this time.
0 commit comments