From 98a2a233f4f71a2759f85ce87c7988b1b88b525f Mon Sep 17 00:00:00 2001 From: James Petersen Date: Tue, 21 Oct 2025 10:40:03 -0600 Subject: [PATCH 1/2] feat(build-and-sign-image): optional push or not Signed-off-by: James Petersen --- build-and-sign-image/action.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/build-and-sign-image/action.yml b/build-and-sign-image/action.yml index 1f4632d..7e38517 100644 --- a/build-and-sign-image/action.yml +++ b/build-and-sign-image/action.yml @@ -24,6 +24,9 @@ inputs: gcp_region: description: 'Google region to push images to' required: true + push: + description: 'To push or not' + default: 'true' runs: using: composite @@ -160,7 +163,7 @@ runs: file: ./images/Dockerfile.${{ inputs.component }} platforms: linux/amd64 tags: '${{ steps.meta.outputs.tags }}' - push: true + push: '${{ inputs.push }}' # TODO: Handle in-container script auth better build-args: | PROTECT_VERSION=${{ steps.version.outputs.protect_version }} From 262afe2c20bed7c1598b17e7a235d6a70e785dcb Mon Sep 17 00:00:00 2001 From: James Petersen Date: Tue, 21 Oct 2025 10:43:54 -0600 Subject: [PATCH 2/2] feat(build-and-sign-image): cosign if push is true Signed-off-by: James Petersen --- build-and-sign-image/action.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/build-and-sign-image/action.yml b/build-and-sign-image/action.yml index 7e38517..dc92e55 100644 --- a/build-and-sign-image/action.yml +++ b/build-and-sign-image/action.yml @@ -172,6 +172,7 @@ runs: registry_token=${{ steps.google-auth.outputs.access_token }} - name: 'Cosign sign all images' + if: '${{ inputs.push == true }}' shell: bash run: | for tag in $(echo '${{ steps.meta.outputs.tags }}'); do