Skip to content

Conversation

@zvonkok
Copy link
Collaborator

@zvonkok zvonkok commented Jan 15, 2026

release: Fix new sigstore format and update VERIFY.md

Signed-off-by: Zvonko Kaiser <zkaiser@nvidia.com>
@zvonkok zvonkok marked this pull request as ready for review January 15, 2026 00:28
Copilot AI review requested due to automatic review settings January 15, 2026 00:28
@zvonkok zvonkok merged commit a3244ec into NVIDIA:main Jan 15, 2026
23 checks passed
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR simplifies the release documentation and workflow by removing support for the two-flavor build system (NVRC and NVRC-confidential variants) and updating to the new sigstore bundle format for verifying the Rekor CLI.

Changes:

  • Removed all references to the two-flavor build system (NVRC vs NVRC-confidential) from VERIFY.md
  • Updated workflow to use new .sigstore.json bundle format instead of separate .pem and .sig files
  • Improved documentation formatting with multi-line commands and corrected workflow filename reference

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
VERIFY.md Removed BIN variable and two-flavor references, hardcoded NVRC binary name, improved command formatting, and corrected workflow filename from .yml to .yaml
.github/workflows/release.yaml Updated Rekor CLI verification to use new .sigstore.json bundle format, removed conditional logic for old/new formats, and updated step name to reflect actual installation

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant