added missing cosign.key (#427)

SBOM generation was failing because it missed a step to generate the private key needed for SBOM signing from Github secret.
This commit is contained in:
John Murphy
2021-09-23 10:46:30 -05:00
committed by GitHub
parent 880c7dc3ea
commit a2b5edb551

View File

@@ -118,9 +118,15 @@ jobs:
with:
cosign-release: "v1.2.1"
- name: Get Cosign Key
run: |
echo $COSIGN_KEY | base64 -d > ./cosign.key
env:
COSIGN_KEY: ${{secrets.COSIGN_KEY}}
- name: Generate SBOM
run: |
COSIGN_PASSWORD=$COSIGNPASSWORD COSIGN_KEY=$COSIGN_KEY make sbom
make sbom
env:
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
COSIGN_KEY: ${{ secrets.COSIGN_KEY }}