From 05f3ca80f9f1f0e9d662303fae85966d792d2d0e Mon Sep 17 00:00:00 2001 From: Sascha Grunert Date: Thu, 23 Jun 2022 14:50:50 +0200 Subject: [PATCH] Pin cosign-installer to `v2` (#824) We now have tags available in the cosign-installer, which allows us to pin the latest release via `v2`. Signed-off-by: Sascha Grunert --- .github/workflows/release.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 84cd45c..3b8812a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -10,7 +10,7 @@ jobs: GO111MODULE: on ACTIONS_ALLOW_UNSECURE_COMMANDS: true steps: - - name: Checkout Source + - name: Checkout Source uses: actions/checkout@v3 - name: Unshallow run: git fetch --prune --unshallow @@ -19,7 +19,7 @@ jobs: with: go-version: 1.18 - name: Install Cosign - uses: sigstore/cosign-installer@main + uses: sigstore/cosign-installer@v2 with: cosign-release: 'v1.6.0' - name: Store Cosign private key in a file