Skip to content

Merge pull request #601 from rhmdnd/update-bundle #275

Merge pull request #601 from rhmdnd/update-bundle

Merge pull request #601 from rhmdnd/update-bundle #275

Triggered via push August 20, 2024 19:42
Status Success
Total duration 1h 34m 23s
Artifacts 5
bundle-container-push-latest  /  container
30s
bundle-container-push-latest / container
must-gather-latest  /  container
52s
must-gather-latest / container
openscap-container-push-latest  /  container
1m 37s
openscap-container-push-latest / container
operator-container-push-latest  /  container
1h 32m
operator-container-push-latest / container
bundle-container-push-latest  /  sign
7s
bundle-container-push-latest / sign
must-gather-latest  /  sign
10s
must-gather-latest / sign
openscap-container-push-latest  /  sign
10s
openscap-container-push-latest / sign
operator-container-push-latest  /  sign
9s
operator-container-push-latest / sign
catalog-container-push-pr  /  container
53s
catalog-container-push-pr / container
catalog-container-push-pr  /  sign
7s
catalog-container-push-pr / sign
Fit to window
Zoom out
Zoom in

Annotations

1 warning and 15 notices
JSON arguments recommended for ENTRYPOINT/CMD to prevent unintended behavior related to OS signals: images/must-gather/Dockerfile.ocp#L6
JSONArgsRecommended: JSON arguments recommended for ENTRYPOINT to prevent unintended behavior related to OS signals More info: https://docs.docker.com/go/dockerfile/rule/json-args-recommended/
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-bundle@sha256:8e35dacce9ff429df872dd01c2a4852048715e09370612d1d60023e38d1af7c8 | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-bundle@sha256:8e35dacce9ff429df872dd01c2a4852048715e09370612d1d60023e38d1af7c8 | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-bundle@sha256:8e35dacce9ff429df872dd01c2a4852048715e09370612d1d60023e38d1af7c8 | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:c17ac0699f55020d5680cfd977c6ba17736ecfa9b61136d54b441dfdb4e3d9b4 | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:c17ac0699f55020d5680cfd977c6ba17736ecfa9b61136d54b441dfdb4e3d9b4 | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:c17ac0699f55020d5680cfd977c6ba17736ecfa9b61136d54b441dfdb4e3d9b4 | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/openscap-ocp@sha256:f5b17780696acdacf0f458a7bd683c3bec885086f910a6707b001ce983a0c285 | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/openscap-ocp@sha256:f5b17780696acdacf0f458a7bd683c3bec885086f910a6707b001ce983a0c285 | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/openscap-ocp@sha256:f5b17780696acdacf0f458a7bd683c3bec885086f910a6707b001ce983a0c285 | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator@sha256:5ca6256a25b75e4cfb884763160fd8d5e994715b46e194b3706f38e9f940c875 | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator@sha256:5ca6256a25b75e4cfb884763160fd8d5e994715b46e194b3706f38e9f940c875 | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator@sha256:5ca6256a25b75e4cfb884763160fd8d5e994715b46e194b3706f38e9f940c875 | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-catalog@sha256:eee8553484e1c30af55d8b8791cab5f4e4d394dc746c2ae8f7d1bfedbd639e79 | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-catalog@sha256:eee8553484e1c30af55d8b8791cab5f4e4d394dc746c2ae8f7d1bfedbd639e79 | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-catalog@sha256:eee8553484e1c30af55d8b8791cab5f4e4d394dc746c2ae8f7d1bfedbd639e79 | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text

Artifacts

Produced during runtime
Name Size
ComplianceAsCode~compliance-operator~MIZ9SS.dockerbuild
39 KB
ComplianceAsCode~compliance-operator~OHYZLT.dockerbuild
16.4 KB
ComplianceAsCode~compliance-operator~RSO8ZE.dockerbuild
37.8 KB
ComplianceAsCode~compliance-operator~UQMI17.dockerbuild
14.5 KB
ComplianceAsCode~compliance-operator~WV264N.dockerbuild
11.3 KB