docs: 📝 archive signed-sbom-attestation + showboat demo (release-tools-image) #193
No reviewers
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/OpenSpec
Kind/Security
Kind/Testing
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
RFC - Request For Comments
Reviewed/Confirmed
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Status/Abandoned
Status/Blocked
Status/Need More Info
hermes-attempted
hermes-needs-clarification
hermes-ready
hermes-review
hermes-wip
human-required
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
agentic-forges/forgejo-mcp!193
Loading…
Reference in a new issue
No description provided.
Delete branch "refs/pull/193/head"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Completes the OpenSpec lifecycle for the change merged in #189. Runs
openspec archive signed-sbom-attestation(tasks.md step 3.2): syncs the liverelease-tools-imagespec and adds a reproducible showboat demo proving the signed-SBOM-attestation contract.This is the implementation/archive PR that follows #189. No code — the Tekton task + README already landed under
forgejo-mcp-aa6(commitb2619fc).Changes
openspec/specs/release-tools-image/spec.md, requirement "SBOM attached as registry artifact": now mandates a signedcosign attest --type cyclonedxand acosign verify-attestation --type cyclonedxretrieval contract, replacing the removed/unsignedcosign attach sbom/download sbompath. Two scenarios (signed attestation verifiable; deprecated attach path forbidden).openspec/specs/release-tools-image/signed-sbom-attestation.demo.md: real captured output of a fullsyft → cosign attest --type cyclonedx → cosign verify-attestationroundtrip (ephemeralttl.shregistry + throwaway key — the identical cosign/syft commands the pipeline runs), plus a real probe of the published image.openspec/changes/archive/2026-06-02-signed-sbom-attestation/.Demo evidence (all real, captured 2026-06-02)
verify-attestation --type cyclonedx→ claims validated, tlog verified, sig verified; predicatepredicateType: https://cyclonedx.org/bom,bomFormat: CycloneDXcosign attest --type=cyclonedx; no activecosign attach sbom(only historical comments)⚠️ Discovered during this work — key split (not fixed here)
The GitOps key was split mid-session into
cosign-signing-key-artifacts.pub(blob) +cosign-signing-key-images.pub(images). This makes the spec's--key cosign-images.pubcorrect going forward. Side effect: README §4 verify-blob still fetches the oldcosign-signing-key.pub(now 404). Filed as forgejo-mcp-0zl — separate follow-up, out of scope for this spec-archive PR.Validation
Published
release-tools:latestpredates the migration, so it carries no CycloneDX attestation yet — the demo documents that gap; the first post-aa6 tag reproduces the roundtrip againstcosign-signing-key-images.pub.Closes forgejo-mcp-3y1. Follows #189.
op1st Pipelines as Code/forgejo-mcp-code-scans-qds5g is running.
Starting Pipelinerun forgejo-mcp-code-scans-qds5g in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines forgejo-mcp-code-scans-qds5g -fop1st Pipelines as Code/forgejo-mcp-openspec-validate-pr-52pcz is running.
Starting Pipelinerun forgejo-mcp-openspec-validate-pr-52pcz in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines forgejo-mcp-openspec-validate-pr-52pcz -fop1st Pipelines as Code/forgejo-mcp-on-pull-request-b8zkh is running.
Starting Pipelinerun forgejo-mcp-on-pull-request-b8zkh in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines forgejo-mcp-on-pull-request-b8zkh -fop1st Pipelines as Code/forgejo-mcp-code-scans-qds5g has successfully validated your commit.
Task Statuses:
fetch-source
gitleaks-version
gitleaks
op1st Pipelines as Code/forgejo-mcp-openspec-validate-pr-52pcz has successfully validated your commit.
Task Statuses:
fetch-source
validate
op1st Pipelines as Code/forgejo-mcp-code-scans-6zrzj is running.
Starting Pipelinerun forgejo-mcp-code-scans-6zrzj in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines forgejo-mcp-code-scans-6zrzj -fop1st Pipelines as Code/forgejo-mcp-on-pull-request-8pg9w is running.
Starting Pipelinerun forgejo-mcp-on-pull-request-8pg9w in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines forgejo-mcp-on-pull-request-8pg9w -fop1st Pipelines as Code/forgejo-mcp-openspec-validate-pr- has failed.
There was an error creating the PipelineRun: forgejo-mcp-openspec-validate-pr-
cannot use the API on the provider platform to create a in_progress status:
op1st Pipelines as Code/forgejo-mcp-on-pull-request-b8zkh
Task Statuses:
fetch-source
build-and-test
commit-title-check
Failure snippet:
task build-and-test has the status "TaskRunCancelled":op1st Pipelines as Code/forgejo-mcp-code-scans-6zrzj has successfully validated your commit.
Task Statuses:
fetch-source
gitleaks-version
gitleaks
op1st Pipelines as Code/forgejo-mcp-on-pull-request-8pg9w has successfully validated your commit.
Task Statuses:
fetch-source
build-and-test
commit-title-check
/test forgejo-mcp-openspec-validate-pr
Re-running: the prior red status on this context was a PaC infrastructure error (
cannot use the API on the provider platform to create a in_progress status) from a duplicate PipelineRun during a rapid double-push — not a spec validation failure. The real run (-52pcz) validated successfully (openspec validate --all --strict→ 16/16,check-demos→ 0 errors), reproduced locally.op1st Pipelines as Code/forgejo-mcp-openspec-validate-pr-hh2gs is running.
Starting Pipelinerun forgejo-mcp-openspec-validate-pr-hh2gs in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines forgejo-mcp-openspec-validate-pr-hh2gs -fop1st Pipelines as Code/forgejo-mcp-openspec-validate-pr-hh2gs has successfully validated your commit.
Task Statuses:
fetch-source
validate