diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4ee4de5..764cd99 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -82,6 +82,13 @@ jobs: curl -LO https://github.com/sigstore/cosign/releases/download/v1.13.1/cosign-linux-amd64 chmod +x cosign-linux-amd64 sudo mv cosign-linux-amd64 /usr/local/bin/cosign + + - name: Write signing key to disk + run: | + echo $KEY > cosign.key + shell: bash + env: + KEY: ${{ secrets.COSIGN_PRIVATE_KEY }} - name: Sign Docker Image env: