Skip to content

Merge pull request #605 from ComplianceAsCode/renovate/github.com-ope… #315

Merge pull request #605 from ComplianceAsCode/renovate/github.com-ope…

Merge pull request #605 from ComplianceAsCode/renovate/github.com-ope… #315

Triggered via push January 15, 2025 21:25
Status Success
Total duration 1h 52m 50s
Artifacts 5
bundle-container-push-latest  /  container
35s
bundle-container-push-latest / container
must-gather-latest  /  container
1m 0s
must-gather-latest / container
openscap-container-push-latest  /  container
1m 33s
openscap-container-push-latest / container
operator-container-push-latest  /  container
1h 51m
operator-container-push-latest / container
bundle-container-push-latest  /  sign
6s
bundle-container-push-latest / sign
must-gather-latest  /  sign
6s
must-gather-latest / sign
openscap-container-push-latest  /  sign
4s
openscap-container-push-latest / sign
operator-container-push-latest  /  sign
5s
operator-container-push-latest / sign
catalog-container-push-pr  /  container
1m 0s
catalog-container-push-pr / container
catalog-container-push-pr  /  sign
5s
catalog-container-push-pr / sign
Fit to window
Zoom out
Zoom in

Annotations

11 warnings and 15 notices
bundle-container-push-latest / container
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
bundle-container-push-latest / sign
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
must-gather-latest / container
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
JSON arguments recommended for ENTRYPOINT/CMD to prevent unintended behavior related to OS signals: images/must-gather/Dockerfile.ocp#L6
JSONArgsRecommended: JSON arguments recommended for ENTRYPOINT to prevent unintended behavior related to OS signals More info: https://docs.docker.com/go/dockerfile/rule/json-args-recommended/
must-gather-latest / sign
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
openscap-container-push-latest / container
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
openscap-container-push-latest / sign
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
operator-container-push-latest / container
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
operator-container-push-latest / sign
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
catalog-container-push-pr / container
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
catalog-container-push-pr / sign
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-bundle@sha256:a5a14136456a9fd2986ababce3b2d36e7ea73db2b595ee505df3080c6c580b6b | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-bundle@sha256:a5a14136456a9fd2986ababce3b2d36e7ea73db2b595ee505df3080c6c580b6b | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-bundle@sha256:a5a14136456a9fd2986ababce3b2d36e7ea73db2b595ee505df3080c6c580b6b | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:31ee0ac91d3edd3dd87bcc3b088220d621557ada73f4aa582f708ebfea545cea | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:31ee0ac91d3edd3dd87bcc3b088220d621557ada73f4aa582f708ebfea545cea | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:31ee0ac91d3edd3dd87bcc3b088220d621557ada73f4aa582f708ebfea545cea | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/openscap-ocp@sha256:3886336d43793c3aae23792bc53969bea6e3b95cac0b87b8cc736a6ad11e8821 | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/openscap-ocp@sha256:3886336d43793c3aae23792bc53969bea6e3b95cac0b87b8cc736a6ad11e8821 | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/openscap-ocp@sha256:3886336d43793c3aae23792bc53969bea6e3b95cac0b87b8cc736a6ad11e8821 | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator@sha256:cbee8b273650c2c42cc0f251252c6e03d05a29f0b878a67c0bb723d3baca6338 | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator@sha256:cbee8b273650c2c42cc0f251252c6e03d05a29f0b878a67c0bb723d3baca6338 | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator@sha256:cbee8b273650c2c42cc0f251252c6e03d05a29f0b878a67c0bb723d3baca6338 | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-catalog@sha256:7da832792165fd6a73f9643686506f4ad1d0813cae09e9c1f548a0e838965b56 | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-catalog@sha256:7da832792165fd6a73f9643686506f4ad1d0813cae09e9c1f548a0e838965b56 | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-catalog@sha256:7da832792165fd6a73f9643686506f4ad1d0813cae09e9c1f548a0e838965b56 | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text

Artifacts

Produced during runtime
Name Size
ComplianceAsCode~compliance-operator~0MGFUT.dockerbuild
43.3 KB
ComplianceAsCode~compliance-operator~AK6ZWX.dockerbuild
113 KB
ComplianceAsCode~compliance-operator~PWWIJQ.dockerbuild
41 KB
ComplianceAsCode~compliance-operator~TZQ6QY.dockerbuild
86.8 KB
ComplianceAsCode~compliance-operator~XIAOU4.dockerbuild
97.8 KB