Skip to content

Merge pull request #659 from ComplianceAsCode/renovate/github.com-cen… #325

Merge pull request #659 from ComplianceAsCode/renovate/github.com-cen…

Merge pull request #659 from ComplianceAsCode/renovate/github.com-cen… #325

Triggered via push January 22, 2025 18:56
Status Success
Total duration 1h 53m 4s
Artifacts 5
bundle-container-push-latest  /  container
39s
bundle-container-push-latest / container
must-gather-latest  /  container
58s
must-gather-latest / container
openscap-container-push-latest  /  container
1m 47s
openscap-container-push-latest / container
operator-container-push-latest  /  container
1h 50m
operator-container-push-latest / container
bundle-container-push-latest  /  sign
7s
bundle-container-push-latest / sign
must-gather-latest  /  sign
6s
must-gather-latest / sign
openscap-container-push-latest  /  sign
10s
openscap-container-push-latest / sign
operator-container-push-latest  /  sign
6s
operator-container-push-latest / sign
catalog-container-push-pr  /  container
48s
catalog-container-push-pr / container
catalog-container-push-pr  /  sign
5s
catalog-container-push-pr / sign
Fit to window
Zoom out
Zoom in

Annotations

11 warnings and 15 notices
bundle-container-push-latest / container
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
bundle-container-push-latest / sign
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
must-gather-latest / container
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
JSON arguments recommended for ENTRYPOINT/CMD to prevent unintended behavior related to OS signals: images/must-gather/Dockerfile.ocp#L6
JSONArgsRecommended: JSON arguments recommended for ENTRYPOINT to prevent unintended behavior related to OS signals More info: https://docs.docker.com/go/dockerfile/rule/json-args-recommended/
must-gather-latest / sign
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
openscap-container-push-latest / container
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
openscap-container-push-latest / sign
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
operator-container-push-latest / container
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
operator-container-push-latest / sign
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
catalog-container-push-pr / container
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
catalog-container-push-pr / sign
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-bundle@sha256:6d1591796f6d1d3f9ed55cc37649b3b7e6c488667fb72bfe72eaeab5c1ea7d3b | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-bundle@sha256:6d1591796f6d1d3f9ed55cc37649b3b7e6c488667fb72bfe72eaeab5c1ea7d3b | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-bundle@sha256:6d1591796f6d1d3f9ed55cc37649b3b7e6c488667fb72bfe72eaeab5c1ea7d3b | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:01130cc76dd48d3a28b25482d1e27d43be665be347fca62cc003a34bc6de7542 | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:01130cc76dd48d3a28b25482d1e27d43be665be347fca62cc003a34bc6de7542 | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:01130cc76dd48d3a28b25482d1e27d43be665be347fca62cc003a34bc6de7542 | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/openscap-ocp@sha256:19379b7ad4fb41baa98e7aa3b4f692bf6aed2cdf86e490f4a8968244203bc53b | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/openscap-ocp@sha256:19379b7ad4fb41baa98e7aa3b4f692bf6aed2cdf86e490f4a8968244203bc53b | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/openscap-ocp@sha256:19379b7ad4fb41baa98e7aa3b4f692bf6aed2cdf86e490f4a8968244203bc53b | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator@sha256:12df3ab01ba77dd18a1cd0bb72aa57aae270ab98a6f3addfa11f5c6e95ebc12d | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator@sha256:12df3ab01ba77dd18a1cd0bb72aa57aae270ab98a6f3addfa11f5c6e95ebc12d | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator@sha256:12df3ab01ba77dd18a1cd0bb72aa57aae270ab98a6f3addfa11f5c6e95ebc12d | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-catalog@sha256:5422deb45eb492ea568e29279155afa1c95779467f3694794fb8a4726e9f7507 | jq '.[0]'
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-catalog@sha256:5422deb45eb492ea568e29279155afa1c95779467f3694794fb8a4726e9f7507 | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/compliance-operator-catalog@sha256:5422deb45eb492ea568e29279155afa1c95779467f3694794fb8a4726e9f7507 | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text

Artifacts

Produced during runtime
Name Size
ComplianceAsCode~compliance-operator~ER8CC3.dockerbuild
43.4 KB
ComplianceAsCode~compliance-operator~HFFZWN.dockerbuild
114 KB
ComplianceAsCode~compliance-operator~LKJF2J.dockerbuild
45.5 KB
ComplianceAsCode~compliance-operator~R1PJIV.dockerbuild
95.5 KB
ComplianceAsCode~compliance-operator~RJ46FY.dockerbuild
87.2 KB