Skip to content

Commit

Permalink
cosign: update to release v1.3.0 (#30)
Browse files Browse the repository at this point in the history
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
  • Loading branch information
cpanato committed Nov 3, 2021
1 parent 57790db commit de5c6db
Show file tree
Hide file tree
Showing 3 changed files with 5 additions and 5 deletions.
2 changes: 1 addition & 1 deletion .github/workflows/test-action.yml
Expand Up @@ -49,7 +49,7 @@ jobs:
steps:
- uses: actions/checkout@v2
- name: Install Cosign
uses: sigstore/cosign-installer@v1.1.0
uses: sigstore/cosign-installer@v1.2.1
- name: Check install!
run: cosign version
- name: Check root directory
Expand Down
2 changes: 1 addition & 1 deletion README.md
Expand Up @@ -13,7 +13,7 @@ Add the following entry to your Github workflow YAML file:
```yaml
uses: sigstore/cosign-installer@main
with:
cosign-release: 'v1.2.1' # optional
cosign-release: 'v1.3.0' # optional
```

Example using a pinned version:
Expand Down
6 changes: 3 additions & 3 deletions action.yml
Expand Up @@ -9,7 +9,7 @@ inputs:
cosign-release:
description: 'Cosign release version to use in the actions.'
required: false
default: 'v1.2.1'
default: 'v1.3.0'
runs:
using: "composite"
steps:
Expand All @@ -20,8 +20,8 @@ runs:
mkdir -p $HOME/.cosign
pushd $HOME/.cosign
bootstrap_version='v1.2.1'
expected_bootstrap_version_digest='490cb1941aa317cd24a0bd9f2fe38932805dbaaba0ae89c12ec8138d15bdd8a0'
bootstrap_version='v1.3.0'
expected_bootstrap_version_digest='9604a5eb171748113f92a67495556007dde6f45804f0b38d3e55c3bc7e151774'
curl -L https://storage.googleapis.com/cosign-releases/${bootstrap_version}/cosign-linux-amd64 -o cosign
shaBootstrap=$(sha256sum cosign | cut -d' ' -f1);
if [[ $shaBootstrap != ${expected_bootstrap_version_digest} ]]; then exit 1; fi
Expand Down

0 comments on commit de5c6db

Please sign in to comment.