fix: 🔒️ restore fail-closed cosign signing, remove bootstrap SKIP_SIGN #158
No reviewers
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/OpenSpec
Kind/Security
Kind/Testing
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
RFC - Request For Comments
Reviewed/Confirmed
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Status/Abandoned
Status/Blocked
Status/Need More Info
hermes-attempted
hermes-needs-clarification
hermes-ready
hermes-review
hermes-wip
human-required
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
agentic-forges/forgejo-mcp!158
Loading…
Reference in a new issue
No description provided.
Delete branch "refs/pull/158/head"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
SKIP_SIGNparam (and itspipelineSpecdeclaration) that was a single-use bootstrap exception forrelease-tools/v1.0.0validate-skip-signguard task that enforced v1.0.0-only usagewhen:conditions oncosign-signandattach-sbom— both tasks now run unconditionally on every release-tools tag pushcosign-signrunAftersimplified to[push-by-digest]onlyRestores the A3 fail-closed posture from spec.md: if
cosign-signing-keySecret is absent,cosign-signfails andpromote-tagnever runs.Pre-merge requirement
Operator must verify
release-tools/v1.0.1(or later) published successfully with signing enabled andcosign verifypasses against the manifest before merging this PR. This PR is the code complement to that operational verification.Closes forgejo-mcp-00o
op1st Pipelines as Code/code-scans-zpxqr is running.
Starting Pipelinerun code-scans-zpxqr in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines code-scans-zpxqr -fop1st Pipelines as Code/on-pull-request-rkh6l is running.
Starting Pipelinerun on-pull-request-rkh6l in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines on-pull-request-rkh6l -fop1st Pipelines as Code/code-scans-zpxqr has successfully validated your commit.
Task Statuses:
fetch-source
gitleaks-version
gitleaks
op1st Pipelines as Code/on-pull-request-rkh6l has successfully validated your commit.
Task Statuses:
fetch-source
build-and-test