diff --git a/.github/workflows/buildReporting.yml b/.github/workflows/buildReporting.yml index a7958484..ce04265e 100644 --- a/.github/workflows/buildReporting.yml +++ b/.github/workflows/buildReporting.yml @@ -151,9 +151,7 @@ jobs: env: KEY: ${{ secrets.COSIGN_PRIVATE_KEY }} - - name: Sign image with private key - run: | - cosign sign --key cosign.key docker.io/anhefti/seb-server:${{ env.TAG_NAME }} - env: - COSIGN_PRIVATE_KEY: ${{secrets.COSIGN_PRIVATE_KEY}} - COSIGN_PASSWORD: ${{secrets.COSIGN_PASSWORD}} + name: Sign the published Docker image + env: + COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }} + run: cosign sign --key cosign.key docker.io/anhefti/seb-server:${{ env.TAG_NAME }}