Skip to content

Update for for cosign v3, regularize inputs and outputs - #4

Merged
evankanderson merged 6 commits into
mindersec:mainfrom
evankanderson:cosign-v3
Jul 27, 2026
Merged

evankanderson merged 6 commits into
mindersec:mainfrom
evankanderson:cosign-v3

Conversation

@evankanderson

@evankanderson evankanderson commented Jul 21, 2026 •

Copy link
Copy Markdown
Member

A few changes:

  1. Updates for Cosign v3, to align with Update minder-client-installer for latest release with cosign v3 minder-client-installer#3 and Fix cosign invocation from goreleaser minder#6606
  2. Aligned input names between minder-action and minder-action/test where possible.
  3. Updated action and release references as follows:
    1. Targeted the upcoming minder-client-installer (after Update minder-client-installer for latest release with cosign v3 minder-client-installer#3) v1.1.0 actions release.
    2. Pinned the underlying minder release to a specific version (the current latest) by default, to assist people who are trying to not have their infrastructure move out from under them.
  4. Configured saving JUnit XML artifacts for minder-action/test, and outputting some data about where the test results exist.

@evankanderson

Copy link
Copy Markdown
Member Author

(Note that this won't work until mindersec/minder-client-installer#3 is merged, and v1.1.0, v1.1, and v1 tags are updated.)

@krrish175-byte

Copy link
Copy Markdown
Member

Renaming minder_version -> release, rules_directory -> rules-directory, and install_dir -> install-dir are breaking changes for existing users. Could we note this in the PR description and README, and consider whether a deprecation warning or alias is needed?

@krrish175-byte krrish175-byte left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Solid direction overall, but there are a few issues worth addressing.

Comment thread test/action.yml Outdated
value: ${{ steps.upload-results.outputs.artifact-url }}
junit-artifact-digest:
description: SHA-256 digest of the JUnit XML result.
value: ${{ steps.upload-results.outputs.artifact-url }}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This copies artifact-url again instead of artifact-digest. Should be: value: ${{ steps.upload-results.outputs.artifact-digest }}

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Too much autocomplete, thanks!

Comment thread test/action.yml Outdated
description: SHA-256 digest of the JUnit XML result.
value: ${{ steps.upload-results.outputs.artifact-url }}
junit-filename:
description: Filesystem path to the JUnixt XML result.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Typo: "JUnixt" -> "JUnit"

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done.

Comment thread test/action.yml
@evankanderson
evankanderson force-pushed the cosign-v3 branch 3 times, most recently from 01c97ce to fafc741 Compare July 27, 2026 21:55
@evankanderson
evankanderson merged commit f7ff63f into mindersec:main Jul 27, 2026
6 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants