`cosign attach sbom` is deprecated (sigstore/cosign#2755) and pushes the SBOM UNSIGNED. Migrate the release-tools SBOM task to `cosign attest --predicate <sbom> --type cyclonedx --key`, signing the CycloneDX SBOM with the same cosign key the image-signing task uses. The signing key was already mounted in this task (previously unused by `attach`). - .tekton/release-tools/tasks/cosign-attach-sbom.yaml: attest instead of attach; refresh displayName/description/comments. - README.md: consumer block now verifies + extracts the signed attestation via `cosign verify-attestation --type cyclonedx`; `cosign download sbom` no longer applies. Closes forgejo-mcp-aa6. Follow-up forgejo-mcp-3y1 tracks the governed OpenSpec update (release-tools-image spec still cites `download sbom`). |
||
|---|---|---|
| .. | ||
| release-tools/tasks | ||
| tasks | ||
| code-scans.yaml | ||
| on-pull-request.yaml | ||
| on-push-to-main.yaml | ||
| on-tag-push-release.yaml | ||
| openspec-validate-pr.yaml | ||
| openspec-validate-push.yaml | ||
| release-tools-on-pull-request-build.yaml | ||
| release-tools-on-tag-publish.yaml | ||
| repository.yaml | ||