diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index e5cce62..3bfbfb4 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -124,6 +124,8 @@ jobs: chmod 600 cosign.key - name: Attest Docker image + env: + COSIGN_PASSWORD: "" run: | IMAGE_NAME="ghcr.io/${{ github.repository_owner }}/cpp-cli" V_TAG="${IMAGE_NAME}:v${{ needs.semantic-release.outputs.next-version }}" @@ -132,6 +134,7 @@ jobs: - name: Verify attestation env: COSIGN_PUBLIC_KEY: ${{ vars.COSIGN_PUBLIC_KEY }} + COSIGN_PASSWORD: "" run: | echo "$COSIGN_PUBLIC_KEY" > cosign.pub IMAGE_NAME="ghcr.io/${{ github.repository_owner }}/cpp-cli"