Skip to content
This repository was archived by the owner on Nov 24, 2025. It is now read-only.

Commit e4769bf

Browse files
authored
Cosign now needs specific attestation types.
1 parent 4bd11de commit e4769bf

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

container_digest.sh

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -126,7 +126,7 @@ then
126126
{
127127
echo "SLSA Provenance file is attested. You can verify it with the following command."
128128
echo '```bash'
129-
echo "cosign verify-attestation --key cosign.pub $registry_url_prefix/$imagename@${containerdigest} | jq '.payload |= @base64d | .payload | fromjson | select(.predicateType==\"https://slsa.dev/provenance/v0.2\" ) | .'"
129+
echo "cosign verify-attestation --key cosign.pub --type slsaprovenance $registry_url_prefix/$imagename@${containerdigest} | jq '.payload |= @base64d | .payload | fromjson | select(.predicateType==\"https://slsa.dev/provenance/v0.2\" ) | .'"
130130
echo '```'
131131
} >> "$GITHUB_STEP_SUMMARY"
132132
fi
@@ -160,7 +160,7 @@ then
160160
{
161161
echo "SBOM file is attested. You can verify it with the following command."
162162
echo '```bash'
163-
echo "cosign verify-attestation --key cosign.pub $registry_url_prefix/$imagename@${containerdigest} | jq '.payload |= @base64d | .payload | fromjson | select( .predicateType==\"https://spdx.dev/Document\" ) | .predicate.Data | fromjson | .'"
163+
echo "cosign verify-attestation --key cosign.pub --type spdx $registry_url_prefix/$imagename@${containerdigest} | jq '.payload |= @base64d | .payload | fromjson | select( .predicateType==\"https://spdx.dev/Document\" ) | .predicate.Data | fromjson | .'"
164164
echo '```'
165165
} >> "$GITHUB_STEP_SUMMARY"
166166

0 commit comments

Comments
 (0)