reverted config

This commit is contained in:
jon brookes 2026-01-25 18:45:59 +00:00
parent d088e76c51
commit 0d908a054b

View file

@ -35,31 +35,27 @@ steps:
- echo "Vulnerability Summary:" - echo "Vulnerability Summary:"
- trivy image --format table share-lt:test | tee trivy-vuln-summary.txt - trivy image --format table share-lt:test | tee trivy-vuln-summary.txt
publish: publish:
image: woodpeckerci/plugin-docker-buildx image: woodpeckerci/plugin-docker-buildx
settings: settings:
registry: quay.io registry: quay.io
repo: quay.io/marshyon/share-lt repo: quay.io/marshyon/share-lt
platforms: linux/amd64 platforms: linux/amd64
# Using the direct image name for local cache and escaped registry for remote tags:
cache_from: - v0.0.2
- "share-lt:test" - latest
- "type=registry,ref=quay.io/marshyon/share-lt:latest" username:
tags: from_secret: QUAY_USERNAME
- v0.0.2 password:
- latest from_secret: QUAY_PASSWORD
username:
from_secret: QUAY_USERNAME
password:
from_secret: QUAY_PASSWORD
upload-sbom: upload-sbom:
image: cgr.dev/chainguard/cosign:latest image: cgr.dev/chainguard/cosign:latest
volumes: volumes:
- /var/run/docker.sock:/var/run/docker.sock - /var/run/docker.sock:/var/run/docker.sock
environment: environment:
COSIGN_REGISTRY_USERNAME: COSIGN_REGISTRY_USERNAME:
from_secret: QUAY_USERNAME from_secret: QUAY_USERNAME
COSIGN_REGISTRY_PASSWORD: COSIGN_REGISTRY_PASSWORD:
from_secret: QUAY_PASSWORD from_secret: QUAY_PASSWORD
commands: commands:
- cosign attach sbom --sbom sbom.json quay.io/marshyon/share-lt:v0.0.2 || echo "SBOM attach failed" - cosign attach sbom --sbom sbom.json quay.io/marshyon/share-lt:v0.0.2 || echo "SBOM attach failed"
- echo "Done - trivy report saved to workspace for manual review" - echo "Done - trivy report saved to workspace for manual review"