forgejo-mcp/.tekton/release-tools/tasks
Christoph Görn 560e375235
fix: 🔒️ sign SBOM via cosign attest (replace deprecated attach sbom)
`cosign attach sbom` is deprecated (sigstore/cosign#2755) and pushes the
SBOM UNSIGNED. Migrate the release-tools SBOM task to `cosign attest
--predicate <sbom> --type cyclonedx --key`, signing the CycloneDX SBOM
with the same cosign key the image-signing task uses. The signing key
was already mounted in this task (previously unused by `attach`).

- .tekton/release-tools/tasks/cosign-attach-sbom.yaml: attest instead of
  attach; refresh displayName/description/comments.
- README.md: consumer block now verifies + extracts the signed
  attestation via `cosign verify-attestation --type cyclonedx`;
  `cosign download sbom` no longer applies.

Closes forgejo-mcp-aa6. Follow-up forgejo-mcp-3y1 tracks the governed
OpenSpec update (release-tools-image spec still cites `download sbom`).
2026-06-02 08:00:08 +02:00
..
build-image.yaml fix: 🐛 avoid SIGPIPE (exit 141) capturing buildah image id 2026-06-01 11:15:09 +02:00
cosign-attach-sbom.yaml fix: 🔒️ sign SBOM via cosign attest (replace deprecated attach sbom) 2026-06-02 08:00:08 +02:00
cosign-sign-image-by-digest.yaml fix: 🔒️ resolve goern push token for cosign in image sign + SBOM tasks 2026-06-01 10:57:11 +02:00
promote-image-tag.yaml fix: 🔥 remove ephemeral :build-tmp tag after promotion 2026-06-01 11:32:01 +02:00
push-image-by-digest.yaml feat: ✨ enable Tekton Chains SLSA v1.0 provenance for release-tools image 2026-05-26 15:06:35 +02:00
resolve-release-tools-tag.yaml feat(ci): 🚀 add release-tools image build + publish Tekton pipelines (iteration 2) 2026-05-25 18:53:49 +02:00
syft-scan-image.yaml fix: 🔒️ address automated code review findings from PR #157 2026-05-25 23:11:33 +02:00
verify-image-tools.yaml feat(ci): 🚀 add release-tools image build + publish Tekton pipelines (iteration 2) 2026-05-25 18:53:49 +02:00