diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 5432e6a3..3636bcfe 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -93,8 +93,8 @@ jobs: - name: Sign the images with GitHub OIDC Token if: ${{ (github.event_name != 'pull_request') && (github.repository == 'cowrie/cowrie') }} env: - DIGEST: ${{ steps.build.outputs.digest }} + DIGEST: ${{ steps.push.outputs.digest }} COSIGN_EXPERIMENTAL: 1 run: | - cosign sign cowrie/cowrie@${DIGEST} - cosign verify cowrie/cowrie@${DIGEST} + cosign sign -y cowrie/cowrie@${DIGEST} + cosign verify cowrie/cowrie@${DIGEST} --certificate-oidc-issuer-regexp '.*' --certificate-identity '.*' diff --git a/docker/Dockerfile b/docker/Dockerfile index 89335365..2ccba03b 100644 --- a/docker/Dockerfile +++ b/docker/Dockerfile @@ -102,7 +102,7 @@ COPY --from=builder --chown=0:0 /etc/group /etc/group COPY --from=builder --chown=${COWRIE_USER}:${COWRIE_GROUP} ${COWRIE_HOME} ${COWRIE_HOME} -RUN [ "python3", "-m", "compileall", "${COWRIE_HOME}", "/usr/lib/python3.11" ] +RUN [ "python3", "-m", "compileall", "-q", "/cowrie/cowrie-git/src", "/cowrie/cowrie-env/", "/usr/lib/python3.11"] VOLUME [ "/cowrie/cowrie-git/var", "/cowrie/cowrie-git/etc" ]