@@ -77,22 +77,20 @@ builds:
7777
7878signs :
7979 - id : rekor
80- signature : " ${artifact}.sig "
80+ signature : " ${artifact}.sigstore.json "
8181 cmd : cosign
82- args : ["sign-blob", "--output-signature ", "${artifact}.sig ", "--key", "gcpkms://projects/{{ .Env.PROJECT_ID }}/locations/{{ .Env.KEY_LOCATION }}/keyRings/{{ .Env.KEY_RING }}/cryptoKeys/{{ .Env.KEY_NAME }}/versions/{{ .Env.KEY_VERSION }}", "${artifact}"]
82+ args : ["sign-blob", "--bundle ", "${signature} ", "--key", "gcpkms://projects/{{ .Env.PROJECT_ID }}/locations/{{ .Env.KEY_LOCATION }}/keyRings/{{ .Env.KEY_RING }}/cryptoKeys/{{ .Env.KEY_NAME }}/versions/{{ .Env.KEY_VERSION }}", "${artifact}"]
8383 artifacts : binary
8484 # Keyless
8585 - id : rekor-keyless
86- signature : " ${artifact}-keyless.sig"
87- certificate : " ${artifact}-keyless.pem"
86+ signature : " ${artifact}-keyless.sigstore.json"
8887 cmd : cosign
89- args : ["sign-blob", "--output-signature ", "${artifact}-keyless.sig", "--output-certificate", "${artifact}-keyless.pem ", "${artifact}"]
88+ args : ["sign-blob", "--bundle ", "${signature} ", "${artifact}"]
9089 artifacts : binary
9190 - id : checksum-keyless
92- signature : " ${artifact}-keyless.sig"
93- certificate : " ${artifact}-keyless.pem"
91+ signature : " ${artifact}-keyless.sigstore.json"
9492 cmd : cosign
95- args : ["sign-blob", "--output-signature ", "${artifact}-keyless.sig", "--output-certificate", "${artifact}-keyless.pem ", "${artifact}"]
93+ args : ["sign-blob", "--bundle ", "${signature} ", "${artifact}"]
9694 artifacts : checksum
9795
9896archives :
0 commit comments