fix: 📝 point README artifact-key fetch at renamed cosign-signing-key-artifacts.pub #194

Merged
goern merged 0 commits from refs/pull/194/head into main 2026-06-02 13:52:13 +00:00
goern commented 2026-06-02 13:49:47 +00:00 (Migrated from codeberg.org)

What

The GitOps repo operate-first/op1st-emea-b4mad split its single cosign key into two:

  • cosign-signing-key-artifacts.pub — signs release blobs (checksums.txt.sig)
  • cosign-signing-key-images.pub — signs images + SBOM attestations

README §2 ("Fetch the public key", feeding §4 verify-blob) still fetched the old cosign-signing-key.pub, which now 404s on branch/main.

Changes (README §2 only)

  • Branch-tip fetch → cosign-signing-key-artifacts.pub.
  • Commit-pinned fetch → re-pinned to post-rename commit cd3715f with the new filename.
  • Prose now names the cosign-signing-key-artifacts Secret and states it is the artifact-signing key, distinct from the image key used in §5–§6.

Verification (all real)

URL result
branch/main …-artifacts.pub 200
commit cd3715f …-artifacts.pub 200, bytes == branch-tip
(sanity) cosign verify --key …-artifacts.pub release-tools:latest claims validated, tlog + sig verified

No stale cosign-signing-key.pub references remain (grep clean). §5/§6 images-key URLs already correct (200), untouched.

Context

Discovered during the signed-sbom-attestation archive (#193). The key split happened mid-work on 2026-06-02; this is the README-side cleanup.


Closes forgejo-mcp-0zl. Follows #193.

## What The GitOps repo `operate-first/op1st-emea-b4mad` split its single cosign key into two: - `cosign-signing-key-artifacts.pub` — signs release **blobs** (`checksums.txt.sig`) - `cosign-signing-key-images.pub` — signs **images** + SBOM attestations README §2 ("Fetch the public key", feeding §4 `verify-blob`) still fetched the old `cosign-signing-key.pub`, which now **404s** on `branch/main`. ## Changes (README §2 only) - **Branch-tip** fetch → `cosign-signing-key-artifacts.pub`. - **Commit-pinned** fetch → re-pinned to post-rename commit `cd3715f` with the new filename. - Prose now names the `cosign-signing-key-artifacts` Secret and states it is the artifact-signing key, distinct from the image key used in §5–§6. ## Verification (all real) | URL | result | |---|---| | branch/main `…-artifacts.pub` | **200** | | commit `cd3715f` `…-artifacts.pub` | **200**, bytes == branch-tip | | (sanity) `cosign verify --key …-artifacts.pub release-tools:latest` | claims validated, tlog + sig verified | No stale `cosign-signing-key.pub` references remain (`grep` clean). §5/§6 images-key URLs already correct (200), untouched. ## Context Discovered during the `signed-sbom-attestation` archive (#193). The key split happened mid-work on 2026-06-02; this is the README-side cleanup. --- Closes forgejo-mcp-0zl. Follows #193.
op1st-gitops commented 2026-06-02 13:49:55 +00:00 (Migrated from codeberg.org)

op1st Pipelines as Code/forgejo-mcp-code-scans-knpvt is running.

Starting Pipelinerun forgejo-mcp-code-scans-knpvt in namespace op1st-pipelines

You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:

tkn pr logs -n op1st-pipelines forgejo-mcp-code-scans-knpvt -f

op1st Pipelines as Code/forgejo-mcp-code-scans-knpvt is running. Starting Pipelinerun <b>[forgejo-mcp-code-scans-knpvt](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/forgejo-mcp-code-scans-knpvt)</b> in namespace <b>op1st-pipelines</b> You can monitor the execution using the [op1st Pipelines as Code](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/forgejo-mcp-code-scans-knpvt) PipelineRun viewer or through the command line by using the [tkn](https://tekton.dev/docs/cli/#installation) CLI with the following command: <code>tkn pr logs -n op1st-pipelines forgejo-mcp-code-scans-knpvt -f</code>
op1st-gitops commented 2026-06-02 13:49:55 +00:00 (Migrated from codeberg.org)

op1st Pipelines as Code/forgejo-mcp-on-pull-request-9d44g is running.

Starting Pipelinerun forgejo-mcp-on-pull-request-9d44g in namespace op1st-pipelines

You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:

tkn pr logs -n op1st-pipelines forgejo-mcp-on-pull-request-9d44g -f

op1st Pipelines as Code/forgejo-mcp-on-pull-request-9d44g is running. Starting Pipelinerun <b>[forgejo-mcp-on-pull-request-9d44g](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/forgejo-mcp-on-pull-request-9d44g)</b> in namespace <b>op1st-pipelines</b> You can monitor the execution using the [op1st Pipelines as Code](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/forgejo-mcp-on-pull-request-9d44g) PipelineRun viewer or through the command line by using the [tkn](https://tekton.dev/docs/cli/#installation) CLI with the following command: <code>tkn pr logs -n op1st-pipelines forgejo-mcp-on-pull-request-9d44g -f</code>
op1st-gitops commented 2026-06-02 13:50:20 +00:00 (Migrated from codeberg.org)

op1st Pipelines as Code/forgejo-mcp-code-scans-knpvt has successfully validated your commit.


Task Statuses:

StatusDurationName
Succeeded 13 seconds

fetch-source

Succeeded 9 seconds

gitleaks-version

Succeeded 11 seconds

gitleaks

op1st Pipelines as Code/forgejo-mcp-code-scans-knpvt has <b>successfully</b> validated your commit. <ul> <li><b>Namespace</b>: <a href="https://detailurl.setting.custom-console-url-namespace.is.not.configured">op1st-pipelines</a></li> <li><b>PipelineRun:</b> <a href="https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/forgejo-mcp-code-scans-knpvt">forgejo-mcp-code-scans-knpvt</a></li> </ul> <hr> <h4>Task Statuses:</h4> <table> <tr><th>Status</th><th>Duration</th><th>Name</th></tr> <tr> <td>Succeeded</td> <td>13 seconds</td><td> [fetch-source](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/forgejo-mcp-code-scans-knpvt/logs/fetch-source) </td></tr> <tr> <td>Succeeded</td> <td>9 seconds</td><td> [gitleaks-version](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/forgejo-mcp-code-scans-knpvt/logs/gitleaks-version) </td></tr> <tr> <td>Succeeded</td> <td>11 seconds</td><td> [gitleaks](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/forgejo-mcp-code-scans-knpvt/logs/gitleaks) </td></tr> </table>
op1st-gitops commented 2026-06-02 13:51:41 +00:00 (Migrated from codeberg.org)

op1st Pipelines as Code/forgejo-mcp-on-pull-request-9d44g has successfully validated your commit.


Task Statuses:

StatusDurationName
Succeeded 14 seconds

fetch-source

Succeeded 1 minute

build-and-test

Succeeded 16 seconds

commit-title-check

op1st Pipelines as Code/forgejo-mcp-on-pull-request-9d44g has <b>successfully</b> validated your commit. <ul> <li><b>Namespace</b>: <a href="https://detailurl.setting.custom-console-url-namespace.is.not.configured">op1st-pipelines</a></li> <li><b>PipelineRun:</b> <a href="https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/forgejo-mcp-on-pull-request-9d44g">forgejo-mcp-on-pull-request-9d44g</a></li> </ul> <hr> <h4>Task Statuses:</h4> <table> <tr><th>Status</th><th>Duration</th><th>Name</th></tr> <tr> <td>Succeeded</td> <td>14 seconds</td><td> [fetch-source](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/forgejo-mcp-on-pull-request-9d44g/logs/fetch-source) </td></tr> <tr> <td>Succeeded</td> <td>1 minute</td><td> [build-and-test](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/forgejo-mcp-on-pull-request-9d44g/logs/build-and-test) </td></tr> <tr> <td>Succeeded</td> <td>16 seconds</td><td> [commit-title-check](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/forgejo-mcp-on-pull-request-9d44g/logs/commit-title-check) </td></tr> </table>
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
agentic-forges/forgejo-mcp!194
No description provided.