From 1306f10b90718ba4dc52d05ec49cbad90903c814 Mon Sep 17 00:00:00 2001 From: Jinsoo Heo Date: Sat, 22 Aug 2026 13:05:36 +0900 Subject: [PATCH] ci: check the legacy attestation layout in the VSA selfcheck [sc-19163] Mirrors chronicleprotocol/actions-workflows#41. Default cosign discovery prefers new-format bundles when any exist (SBOM and signature), so the selfcheck missed the legacy VSA. Pass --new-bundle-format=false to read the layout Kyverno reads. --- .github/workflows/promote-to-prod.yaml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/promote-to-prod.yaml b/.github/workflows/promote-to-prod.yaml index 26dadf7..c1e4c7c 100644 --- a/.github/workflows/promote-to-prod.yaml +++ b/.github/workflows/promote-to-prod.yaml @@ -309,7 +309,11 @@ jobs: IMAGE: ${{ inputs.image }}@${{ inputs.digest }} run: | set -euo pipefail + # --new-bundle-format=false: read the legacy .att layout the VSA above uses + # (default discovery prefers new-format bundles when any exist). Mirrors the + # canonical actions-workflows promote-to-prod.yaml. cosign verify-attestation \ + --new-bundle-format=false \ --type "https://slsa.dev/verification_summary/v1" \ --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \ --certificate-identity-regexp "^https://github\.com/chronicleprotocol/challenger/\.github/workflows/promote-to-prod\.yaml@refs/heads/main$" \