Skip to content

Commit

Permalink
update cosign to v1.4.1` (#39)
Browse files Browse the repository at this point in the history
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
  • Loading branch information
cpanato committed Dec 10, 2021
1 parent a1d32fe commit 116dc68
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 5 deletions.
4 changes: 2 additions & 2 deletions README.md
Expand Up @@ -13,7 +13,7 @@ Add the following entry to your Github workflow YAML file:
```yaml
uses: sigstore/cosign-installer@main
with:
cosign-release: 'v1.4.0' # optional
cosign-release: 'v1.4.1' # optional
```

Example using a pinned version:
Expand All @@ -40,7 +40,7 @@ jobs:
- name: Install Cosign
uses: sigstore/cosign-installer@main
with:
cosign-release: 'v1.4.0'
cosign-release: 'v1.4.1'
- name: Check install!
run: cosign version
```
Expand Down
6 changes: 3 additions & 3 deletions action.yml
Expand Up @@ -9,7 +9,7 @@ inputs:
cosign-release:
description: 'Cosign release version to use in the actions.'
required: false
default: 'v1.4.0'
default: 'v1.4.1'
runs:
using: "composite"
steps:
Expand All @@ -20,8 +20,8 @@ runs:
mkdir -p $HOME/.cosign
pushd $HOME/.cosign
bootstrap_version='v1.4.0'
expected_bootstrap_version_digest='bac6a2dee9100f5708226179466e0dad45e76291ef0d70b929ca52fe59a1ae0d'
bootstrap_version='v1.4.1'
expected_bootstrap_version_digest='08ba779a4e6ff827079abed1a6d1f0a0d9e48aea21f520ddeb42ff912f59d268'
curl -L https://storage.googleapis.com/cosign-releases/${bootstrap_version}/cosign-linux-amd64 -o cosign
shaBootstrap=$(sha256sum cosign | cut -d' ' -f1);
if [[ $shaBootstrap != ${expected_bootstrap_version_digest} ]]; then exit 1; fi
Expand Down

0 comments on commit 116dc68

Please sign in to comment.