Skip to content

fix(release): cosign v4 bundle format (#136) #146

fix(release): cosign v4 bundle format (#136)

fix(release): cosign v4 bundle format (#136) #146

Triggered via push May 13, 2026 05:42
Status Success
Total duration 27s
Artifacts 1

security.yml

on: push
OSV-Scanner (SCA)
5s
OSV-Scanner (SCA)
Trivy (filesystem + container scan)
10s
Trivy (filesystem + container scan)
Semgrep (SAST)
23s
Semgrep (SAST)
Gitleaks (secret scan)
13s
Gitleaks (secret scan)
jscpd (duplication < 3% on touched code)
12s
jscpd (duplication < 3% on touched code)
SBOM (SPDX + CycloneDX)
18s
SBOM (SPDX + CycloneDX)
Fit to window
Zoom out
Zoom in

Artifacts

Produced during runtime
Name Size Digest
sbom
12.4 KB
sha256:ffb16dd10ef7b6ea0849f449f2f5480299255051ef24ef7f0802bc2ebca26bb2