A reusable workflow signs artifacts successfully and verification fails
The signature exists, yet downstream verification computes a different digest because one timestamp component is serialized differently on one runner class.
CI/CDAdvanced
A release provenance check fails only on one registry
Community-field CI/CD problem inspired by provenance and registry discussions where annotation order rewrites broke naive verification.
CI/CDAdvanced
A GitOps promotion pipeline signs manifests correctly and the admission...
Community-field CI/CD problem inspired by GitOps and supply-chain threads where signing and verification used different manifest canonicalization.
CI/CDIntermediate
A GitHub release workflow signs artifacts and still fails attestations
The pipeline runs, but one alias still points at the pre-signing artifact from the build fan-out stage.