From f48efda87bb88efe7968bd6202b6c75e16d27eac Mon Sep 17 00:00:00 2001 From: Justin Marquis <34fathombelow@protonmail.com> Date: Thu, 19 Jan 2023 22:01:34 -0800 Subject: [PATCH] chore: disable docker sbom and attestations Signed-off-by: Justin Marquis <34fathombelow@protonmail.com> --- .github/workflows/docker-publish.yml | 8 ++++++-- .github/workflows/release.yaml | 8 ++++++-- 2 files changed, 12 insertions(+), 4 deletions(-) diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml index 2c7c565e2d..df0ad28776 100644 --- a/.github/workflows/docker-publish.yml +++ b/.github/workflows/docker-publish.yml @@ -82,19 +82,23 @@ jobs: echo "::set-output name=platform-matrix::$PLATFORM_MATRIX" - name: Build and push (controller-image) - uses: docker/build-push-action@v3 + uses: docker/build-push-action@37abcedcc1da61a57767b7588cb9d03eb57e28b3 # v3.3.0 with: platforms: ${{ steps.platform-matrix.outputs.platform-matrix }} push: ${{ github.event_name != 'pull_request' }} tags: ${{ steps.controller-meta.outputs.tags }} + provenance: false + sbom: false - name: Build and push (plugin-image) - uses: docker/build-push-action@v3 + uses: docker/build-push-action@37abcedcc1da61a57767b7588cb9d03eb57e28b3 # v3.3.0 with: target: kubectl-argo-rollouts platforms: ${{ steps.platform-matrix.outputs.platform-matrix }} push: ${{ github.event_name != 'pull_request' }} tags: ${{ steps.plugin-meta.outputs.tags }} + provenance: false + sbom: false - name: Install cosign uses: sigstore/cosign-installer@main diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 2b65ec1d26..8794e839d9 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -84,21 +84,25 @@ jobs: password: ${{ secrets.QUAY_ROBOT_TOKEN }} - name: Build and push (controller-image) - uses: docker/build-push-action@v3 + uses: docker/build-push-action@37abcedcc1da61a57767b7588cb9d03eb57e28b3 # v3.3.0 with: context: . platforms: linux/amd64,linux/arm64 push: true tags: ${{ steps.controller-meta.outputs.tags }} + provenance: false + sbom: false - name: Build and push (plugin-image) - uses: docker/build-push-action@v3 + uses: docker/build-push-action@37abcedcc1da61a57767b7588cb9d03eb57e28b3 # v3.3.0 with: context: . target: kubectl-argo-rollouts platforms: linux/amd64,linux/arm64 push: true tags: ${{ steps.plugin-meta.outputs.tags }} + provenance: false + sbom: false release-artifacts: