Bundles cosign v3.1.3.
A simple wrapper around the cosign executable for use as a step in GitHub
Actions. The container image is prebuilt and pulled from
GitHub Container Registry
rather than built on every action run.
| Input | Required | Default | Description |
|---|---|---|---|
args |
yes | version |
Arguments passed to cosign |
each |
no | — | Newline-separated list of values. Each line is substituted for {} in args and cosign is called once per line. args must contain {} when each is set. |
registry |
no | ghcr.io |
Container registry hostname to authenticate to. Required when registry-token is set. |
registry-username |
no | GITHUB_REPOSITORY_OWNER |
Username for registry authentication. Defaults to the repository owner via the GITHUB_REPOSITORY_OWNER environment variable provided by GitHub Actions. |
registry-token |
no | — | Token for authenticating to the container registry. If set, runs cosign login before the main command. |
- name: Verify image
uses: samhclark/cosign-exec-action@v1
with:
args: >-
verify
--certificate-identity=https://github.com/org/repo/.github/workflows/release.yml@refs/heads/main
--certificate-oidc-issuer=https://token.actions.githubusercontent.com
docker.io/org/image@sha256:<digest>Sign with Sigstore's keyless flow using GitHub OIDC. Requires id-token: write
and packages: write permissions.
- name: Sign image
uses: samhclark/cosign-exec-action@v1
with:
args: 'sign ghcr.io/org/image@sha256:<digest> --yes'
registry-token: ${{ secrets.GITHUB_TOKEN }}Use each to call cosign once per image, substituting {} in args:
- name: Verify images
uses: samhclark/cosign-exec-action@v1
with:
args: >-
verify
--certificate-identity=https://github.com/org/repo/.github/workflows/release.yml@refs/heads/main
--certificate-oidc-issuer=https://token.actions.githubusercontent.com
{}
each: |
docker.io/org/image1@sha256:<digest1>
docker.io/org/image2@sha256:<digest2>podman build -t cosign-exec-action .
# Simple mode
podman run --env INPUT_ARGS=version --rm cosign-exec-action
# Each mode
podman run \
--env INPUT_ARGS="{}" \
--env INPUT_EACH=version \
--rm cosign-exec-actionThe cd.yml workflow publishes a new container
image, signs it with cosign (keyless via Sigstore), and creates a GitHub release
whenever a pull request is merged into main. To release a new version, bump the image tag in
action.yml as part of your pull request. The
version-check.yml workflow will
block merging if the version has not been incremented.