`cosign attach sbom` is deprecated (sigstore/cosign#2755) and pushes the SBOM UNSIGNED. Migrate the release-tools SBOM task to `cosign attest --predicate <sbom> --type cyclonedx --key`, signing the CycloneDX SBOM with the same cosign key the image-signing task uses. The signing key was already mounted in this task (previously unused by `attach`). - .tekton/release-tools/tasks/cosign-attach-sbom.yaml: attest instead of attach; refresh displayName/description/comments. - README.md: consumer block now verifies + extracts the signed attestation via `cosign verify-attestation --type cyclonedx`; `cosign download sbom` no longer applies. Closes forgejo-mcp-aa6. Follow-up forgejo-mcp-3y1 tracks the governed OpenSpec update (release-tools-image spec still cites `download sbom`). |
||
|---|---|---|
| .. | ||
| build-image.yaml | ||
| cosign-attach-sbom.yaml | ||
| cosign-sign-image-by-digest.yaml | ||
| promote-image-tag.yaml | ||
| push-image-by-digest.yaml | ||
| resolve-release-tools-tag.yaml | ||
| syft-scan-image.yaml | ||
| verify-image-tools.yaml | ||