Skip to content

fix(ci): pin cosign to v2.6.3#39

Merged
aksOps merged 1 commit intomainfrom
fix-cosign-v2
Apr 23, 2026
Merged

fix(ci): pin cosign to v2.6.3#39
aksOps merged 1 commit intomainfrom
fix-cosign-v2

Conversation

@aksOps
Copy link
Copy Markdown
Contributor

@aksOps aksOps commented Apr 23, 2026

v3 changed sign-blob defaults to emit a Sigstore bundle; our explicit flags aren't compatible and the empty-bundle-path caused release.yml to fail with: create bundle file: open : no such file or directory. Pinning v2.6.3 which matches the CLI we wrote for. Revisit v3 as a follow-up.

cosign v3 now emits a Sigstore bundle by default; our explicit
--output-signature + --output-certificate flags aren't compatible and
the empty-bundle-path caused: 'create bundle file: open : no such
file or directory'. v2.6.3 keeps the CLI we wrote for. Revisit v3
once we're ready to move to bundle-based attestations.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@aksOps aksOps enabled auto-merge (squash) April 23, 2026 03:30
@aksOps aksOps merged commit 5abd428 into main Apr 23, 2026
12 checks passed
@aksOps aksOps deleted the fix-cosign-v2 branch April 23, 2026 03:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant