The verify step curl-fetched the public key anonymously from the dev repo's raw URL; since that repo went private the fetch 404s and every signed release died at verification. Embed the PUBLIC key verbatim (same pattern as the platform's sync-mirror.sh) so the workflow is self-contained. Keep in lockstep with infra/cosign/official.pub on key rotation. Signed-off-by: flemming-it <sf@flemming.it> |
||
|---|---|---|
| .. | ||
| ci.yml | ||
| sign.yml | ||