Skip to content

Merge pull request #596 from ComplianceAsCode/renovate/github.com-ope… #279

Merge pull request #596 from ComplianceAsCode/renovate/github.com-ope…

Merge pull request #596 from ComplianceAsCode/renovate/github.com-ope… #279

Triggered via push August 21, 2024 22:58
Status Success
Total duration 1h 37m 21s
Artifacts 5
bundle-container-push-latest  /  container
29s
bundle-container-push-latest / container
must-gather-latest  /  container
50s
must-gather-latest / container
openscap-container-push-latest  /  container
1m 50s
openscap-container-push-latest / container
operator-container-push-latest  /  container
1h 35m
operator-container-push-latest / container
bundle-container-push-latest  /  sign
12s
bundle-container-push-latest / sign
must-gather-latest  /  sign
5s
must-gather-latest / sign
openscap-container-push-latest  /  sign
6s
openscap-container-push-latest / sign
operator-container-push-latest  /  sign
6s
operator-container-push-latest / sign
catalog-container-push-pr  /  container
1m 7s
catalog-container-push-pr / container
catalog-container-push-pr  /  sign
6s
catalog-container-push-pr / sign
Fit to window
Zoom out
Zoom in

Annotations

1 warning and 15 notices
JSON arguments recommended for ENTRYPOINT/CMD to prevent unintended behavior related to OS signals: images/must-gather/Dockerfile.ocp#L6
JSONArgsRecommended: JSON arguments recommended for ENTRYPOINT to prevent unintended behavior related to OS signals More info: https://docs.docker.com/go/dockerfile/rule/json-args-recommended/
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-bundle@sha256:cc6744686a6d59370a47d2da25b8ce2edd68f0bc66e04e9203581b394ff77d65 | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-bundle@sha256:cc6744686a6d59370a47d2da25b8ce2edd68f0bc66e04e9203581b394ff77d65 | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-bundle@sha256:cc6744686a6d59370a47d2da25b8ce2edd68f0bc66e04e9203581b394ff77d65 | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:6611deeed1a899a2ffb9ce99032b04faaafda2ebbf4bde04564c0c4bbc99a98e | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:6611deeed1a899a2ffb9ce99032b04faaafda2ebbf4bde04564c0c4bbc99a98e | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:6611deeed1a899a2ffb9ce99032b04faaafda2ebbf4bde04564c0c4bbc99a98e | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/openscap-ocp@sha256:3234f85f48a5a45b779315c33f6dd2c536e3f1af6aae9a6f97b70e08148f2ebe | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/openscap-ocp@sha256:3234f85f48a5a45b779315c33f6dd2c536e3f1af6aae9a6f97b70e08148f2ebe | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/openscap-ocp@sha256:3234f85f48a5a45b779315c33f6dd2c536e3f1af6aae9a6f97b70e08148f2ebe | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator@sha256:6c75720411cfe3e3b6c18054c8331796c711326c1053a316488cc1b61c06370a | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator@sha256:6c75720411cfe3e3b6c18054c8331796c711326c1053a316488cc1b61c06370a | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator@sha256:6c75720411cfe3e3b6c18054c8331796c711326c1053a316488cc1b61c06370a | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-catalog@sha256:0192beae6e76c9972c17ef0f787c0cdb715e5238c5c910ac59b09cad40564e3a | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-catalog@sha256:0192beae6e76c9972c17ef0f787c0cdb715e5238c5c910ac59b09cad40564e3a | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-catalog@sha256:0192beae6e76c9972c17ef0f787c0cdb715e5238c5c910ac59b09cad40564e3a | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text

Artifacts

Produced during runtime
Name Size
ComplianceAsCode~compliance-operator~0OJ1VE.dockerbuild
15.2 KB
ComplianceAsCode~compliance-operator~D7A0NM.dockerbuild
38.5 KB
ComplianceAsCode~compliance-operator~RU5EKZ.dockerbuild
24.4 KB
ComplianceAsCode~compliance-operator~T8AY00.dockerbuild
11 KB
ComplianceAsCode~compliance-operator~U1WJTX.dockerbuild
39.6 KB