scorecard pipeline is failing in `master` branch
ytsarev opened this issue · comments
Yury Tsarev commented
It's happening for a while, example https://github.com/k8gb-io/k8gb/actions/runs/9150847377
Yury Tsarev commented
@jkremser as a supply chain master, do you see there some obvious fix? :)
Jirka Kremser commented
🤞 #1567
Yury Tsarev commented
@jkremser, thanks a ton for the quick attempt! https://github.com/k8gb-io/k8gb/actions/runs/9157536246/job/25174078930 unfortunately, it still fails
Yury Tsarev commented
breadcrumb ossf/scorecard-action#997
Yury Tsarev commented
2024/06/30 12:56:35 error signing scorecard json results: error signing payload: getting key from Fulcio: verifying SCT: updating local metadata and targets: error updating to TUF remote mirror: invalid key
which is matching the issue above