We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 1622612 commit d994934Copy full SHA for d994934
1 file changed
.github/workflows/ci.yml
@@ -198,6 +198,7 @@ jobs:
198
if: startsWith(github.ref, 'refs/tags/v')
199
permissions:
200
contents: write
201
+ id-token: write # required for keyless cosign signing via OIDC
202
steps:
203
- name: Checkout code
204
uses: actions/checkout@v4
@@ -209,8 +210,14 @@ jobs:
209
210
pattern: step-ca_*
211
merge-multiple: true
212
- - name: List artifacts
213
- run: ls -la dist/
+ - name: Install cosign
214
+ uses: sigstore/cosign-installer@v3
215
+
216
+ - name: Sign binaries
217
+ run: |
218
+ for bin in dist/step-ca_*; do
219
+ cosign sign-blob --yes --bundle="${bin}.bundle" "$bin"
220
+ done
221
222
- name: Get version
223
id: version
0 commit comments