diff --git a/.gitea/workflows/docker-builder.yml b/.gitea/workflows/docker-builder.yml index 3539613..99e41c0 100644 --- a/.gitea/workflows/docker-builder.yml +++ b/.gitea/workflows/docker-builder.yml @@ -231,8 +231,16 @@ jobs: with: name: sbom path: sbom.spdx.json - + + - name: Install cosign + run: | + curl -sSfL https://github.com/sigstore/cosign/releases/latest/download/cosign-linux-amd64 \ + -o /usr/local/bin/cosign + chmod +x /usr/local/bin/cosign - name: Sign image - run: cosign sign --key ${{ secrets.COSIGN_KEY }} ${IMAGE_NAME}:v${VERSION} + if: env.IS_TAG == 'true' + run: | + cosign sign --key ${{ secrets.COSIGN_KEY }} ${IMAGE_NAME}:${VERSION} +