Don't need to verify distroless when using alpine

This commit is contained in:
Morten Lied Johansen 2024-10-02 20:27:12 +02:00
parent b7f3fd0ca2
commit 36d28ead20
No known key found for this signature in database
GPG key ID: 8DC6DECB15005221

View file

@ -31,12 +31,6 @@ jobs:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Install cosign
uses: sigstore/cosign-installer@4959ce089c160fddf62f7b42464195ba1a56d382 # ratchet:sigstore/cosign-installer@main
with:
cosign-release: 'v2.2.3'
- name: Verify runner image
run: cosign verify --certificate-identity keyless@distroless.iam.gserviceaccount.com --certificate-oidc-issuer https://accounts.google.com gcr.io/distroless/static-debian11
- name: "Docker metadata"
id: "metadata"
uses: docker/metadata-action@v5