Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Sign releaser artifacts, not only container manifests
The current goreleaser configuration leverages cosign to sign the goreleaser container manifests using public sigstore infrastructure. This is great! This PR also signs the rest of the releaser artifacts (binaries, sbom file, etc), so we can verify them using the aforementioned public infrastructure. This is very useful for folks consuming the binaries from the public GitHub releases. Note that this assumes that the OIDC issuer is GitHub, and thus ties this signature to be triggered a GitHub action. Signed-off-by: Juan Antonio Osorio <juan.osoriorobles@eu.equinix.com>
- Loading branch information