diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml index 1d9f3b8..5bf2013 100644 --- a/.github/workflows/docker-publish.yml +++ b/.github/workflows/docker-publish.yml @@ -31,7 +31,7 @@ jobs: outputs: image: ${{ steps.image.outputs.image }} digest: ${{ steps.build-and-push.outputs.digest }} - runs-on: ubuntu-latest + runs-on: mahamed-runner permissions: contents: read packages: write @@ -135,4 +135,4 @@ jobs: IMAGE_DIGEST: ${{ needs.build.outputs.digest }} run: | COSIGN_EXPERIMENTAL=1 cosign verify-attestation --certificate-identity-regexp=".*" --certificate-oidc-issuer-regexp=".*" --type slsaprovenance "${IMAGE_NAME}@${IMAGE_DIGEST}" - # TODO(github.com/slsa-framework/slsa-verifier/issues/92): Add step to verify using slsa-verifier \ No newline at end of file + # TODO(github.com/slsa-framework/slsa-verifier/issues/92): Add step to verify using slsa-verifier