diff --git a/templates/gitlab-ci-docker.yml b/templates/gitlab-ci-docker.yml index 5e9d030293e7b9b7700ca08acfde1c7ecda78358..eb5e8520302fb0dd79f377d2ce81d1af56ac1b65 100644 --- a/templates/gitlab-ci-docker.yml +++ b/templates/gitlab-ci-docker.yml @@ -1320,7 +1320,7 @@ docker-sbom: log_info "Attaching attested SBOM to ${DOCKER_SNAPSHOT_IMAGE}..." install_cosign configure_cosign_private_key - $docker_cosign attest --key ${docker_cosign_private_key} ${DOCKER_COSIGN_OPTS} --predicate reports/docker-sbom-${basename}.cyclonedx.json ${docker_image_digest} + $docker_cosign attest --key ${docker_cosign_private_key} ${DOCKER_COSIGN_OPTS} --predicate reports/docker-sbom-${basename}.cyclonedx.json ${DOCKER_SNAPSHOT_IMAGE} fi artifacts: name: "SBOM for docker from $CI_PROJECT_NAME on $CI_COMMIT_REF_SLUG"