Skip to content

fix: sign container images by digest in release workflows - #6

Merged
eksrha merged 1 commit into
mainfrom
fix/sign-container-images
Oct 1, 2026
Merged

eksrha merged 1 commit into
mainfrom
fix/sign-container-images

Conversation

@eksrha

@eksrha eksrha commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Closes #5

The release workflows pushed images without signing them. This adds keyless cosign signing (GitHub OIDC, id-token: write) of each pushed image by digest in release.yml (router, TEI base and runtime) and release-models.yml (model init images, whisper), via a small scripts/sign-image.sh, and documents cosign verify with the exact workflow identity.

Verification happens after merge: a release build must produce an image whose digest passes cosign verify.

https://claude.ai/code/session_01F31tj4MqKr67gzt3awyM4m

Sign the pushed images with keyless cosign (GitHub OIDC) after push, and document how to verify them.

Closes #5

Claude-Session: https://claude.ai/code/session_01F31tj4MqKr67gzt3awyM4m
@eksrha
eksrha merged commit d6388d9 into main Oct 1, 2026
2 checks passed
@eksrha
eksrha deleted the fix/sign-container-images branch October 1, 2026 12:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sign container images in the release workflows

1 participant