Skip to content

Commit a276777

Browse files
ci(.github)[SEC-1084]: fix image digest for provenance
1 parent f061d8e commit a276777

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

.github/workflows/release.yaml

+2-2
Original file line numberDiff line numberDiff line change
@@ -149,7 +149,7 @@ jobs:
149149
IMAGE_TAGS: ${{ needs.build-images.outputs.image_tags }}
150150
outputs:
151151
image_name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
152-
image_manifest_sha: ${{ steps.image_manifest_metadata.outputs.image_manifest_sha }}
152+
image_manifest_sha: ${{ steps.image_manifest_metadata.outputs.sha }}
153153
notary_repository: ${{ env.NOTARY_REPOSITORY }}
154154
steps:
155155

@@ -221,9 +221,9 @@ jobs:
221221
with:
222222
image: ${{ needs.release-images.outputs.image_name }} # Image repository without tag. Eg: kong/insomnia-mockbins
223223
digest: ${{ needs.release-images.outputs.image_manifest_sha }} # Image manifest digest for the published docker image/TAR
224+
registry-username: ${{ github.actor }}
224225
#provenance-repository: ${{ needs.release-images.outputs.notary_repository }}
225226
secrets:
226-
registry-username: ${{ github.actor }}
227227
registry-password: ${{ secrets.GITHUB_TOKEN }}
228228
# provenance-registry-username: ${{ secrets.GHA_DOCKERHUB_PUSH_USER }}
229229
# provenance-registry-password: ${{ secrets.GHA_KONG_ORG_DOCKERHUB_PUSH_TOKEN }}

0 commit comments

Comments
 (0)