From e4769bf1feed7ef7069cdb18406bbb9fc69c6855 Mon Sep 17 00:00:00 2001 From: Jeroen Knoops Date: Wed, 21 Sep 2022 21:52:00 +0100 Subject: [PATCH] Cosign now needs specific attestation types. --- container_digest.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/container_digest.sh b/container_digest.sh index d7ac790..132d0da 100755 --- a/container_digest.sh +++ b/container_digest.sh @@ -126,7 +126,7 @@ then { echo "SLSA Provenance file is attested. You can verify it with the following command." echo '```bash' - echo "cosign verify-attestation --key cosign.pub $registry_url_prefix/$imagename@${containerdigest} | jq '.payload |= @base64d | .payload | fromjson | select(.predicateType==\"https://slsa.dev/provenance/v0.2\" ) | .'" + echo "cosign verify-attestation --key cosign.pub --type slsaprovenance $registry_url_prefix/$imagename@${containerdigest} | jq '.payload |= @base64d | .payload | fromjson | select(.predicateType==\"https://slsa.dev/provenance/v0.2\" ) | .'" echo '```' } >> "$GITHUB_STEP_SUMMARY" fi @@ -160,7 +160,7 @@ then { echo "SBOM file is attested. You can verify it with the following command." echo '```bash' - echo "cosign verify-attestation --key cosign.pub $registry_url_prefix/$imagename@${containerdigest} | jq '.payload |= @base64d | .payload | fromjson | select( .predicateType==\"https://spdx.dev/Document\" ) | .predicate.Data | fromjson | .'" + echo "cosign verify-attestation --key cosign.pub --type spdx $registry_url_prefix/$imagename@${containerdigest} | jq '.payload |= @base64d | .payload | fromjson | select( .predicateType==\"https://spdx.dev/Document\" ) | .predicate.Data | fromjson | .'" echo '```' } >> "$GITHUB_STEP_SUMMARY"