Open castrojo opened 1 month ago
Something we could consider is to push the images to GHCR with a temporary tag (or no tag?), sign the images with cosign using the digest as the selector, then set the final tags via Skopeo. This would mean that the final "production" tags are only added onto the image after the image signing step was successful.
We got a few rando reports of image upgrade failures, p5 investigated and it was a temporary outage from sigstore:
Rebuilds fixed the issue: