fix: 📝 point README artifact-key fetch at renamed cosign-signing-key-artifacts.pub #194
No reviewers
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/OpenSpec
Kind/Security
Kind/Testing
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
RFC - Request For Comments
Reviewed/Confirmed
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Status/Abandoned
Status/Blocked
Status/Need More Info
hermes-attempted
hermes-needs-clarification
hermes-ready
hermes-review
hermes-wip
human-required
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
agentic-forges/forgejo-mcp!194
Loading…
Reference in a new issue
No description provided.
Delete branch "refs/pull/194/head"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
The GitOps repo
operate-first/op1st-emea-b4madsplit its single cosign key into two:cosign-signing-key-artifacts.pub— signs release blobs (checksums.txt.sig)cosign-signing-key-images.pub— signs images + SBOM attestationsREADME §2 ("Fetch the public key", feeding §4
verify-blob) still fetched the oldcosign-signing-key.pub, which now 404s onbranch/main.Changes (README §2 only)
cosign-signing-key-artifacts.pub.cd3715fwith the new filename.cosign-signing-key-artifactsSecret and states it is the artifact-signing key, distinct from the image key used in §5–§6.Verification (all real)
…-artifacts.pubcd3715f…-artifacts.pubcosign verify --key …-artifacts.pub release-tools:latestNo stale
cosign-signing-key.pubreferences remain (grepclean). §5/§6 images-key URLs already correct (200), untouched.Context
Discovered during the
signed-sbom-attestationarchive (#193). The key split happened mid-work on 2026-06-02; this is the README-side cleanup.Closes forgejo-mcp-0zl. Follows #193.
op1st Pipelines as Code/forgejo-mcp-code-scans-knpvt is running.
Starting Pipelinerun forgejo-mcp-code-scans-knpvt in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines forgejo-mcp-code-scans-knpvt -fop1st Pipelines as Code/forgejo-mcp-on-pull-request-9d44g is running.
Starting Pipelinerun forgejo-mcp-on-pull-request-9d44g in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines forgejo-mcp-on-pull-request-9d44g -fop1st Pipelines as Code/forgejo-mcp-code-scans-knpvt has successfully validated your commit.
Task Statuses:
fetch-source
gitleaks-version
gitleaks
op1st Pipelines as Code/forgejo-mcp-on-pull-request-9d44g has successfully validated your commit.
Task Statuses:
fetch-source
build-and-test
commit-title-check