[2026-07-09T18:30:00,816813688+00:00] Upload SBOM INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' Using token for quay.io/redhat-appstudio-qe/build-e2e-xzub/fj-test-custom-branch-mugmtg Pushing sbom to registry [retry] executing: cosign attach sbom --sbom sbom.json --type spdx quay.io/redhat-appstudio-qe/build-e2e-xzub/fj-test-custom-branch-mugmtg:3c804d8c3ee30ed7517f53387a5b00117627e732@sha256:3b5198a49979893f53d9386ae6d02557226642626759182643f0e638f899ac35 WARNING: SBOM attachments are deprecated and support will be removed in a Cosign release soon after 2024-02-22 (see https://github.com/sigstore/cosign/issues/2755). Instead, please use SBOM attestations. WARNING: Attaching SBOMs this way does not sign them. To sign them, use 'cosign attest --predicate sbom.json --key '. Uploading SBOM file for [quay.io/redhat-appstudio-qe/build-e2e-xzub/fj-test-custom-branch-mugmtg@sha256:3b5198a49979893f53d9386ae6d02557226642626759182643f0e638f899ac35] to [quay.io/redhat-appstudio-qe/build-e2e-xzub/fj-test-custom-branch-mugmtg:sha256-3b5198a49979893f53d9386ae6d02557226642626759182643f0e638f899ac35.sbom] with mediaType [text/spdx+json]. quay.io/redhat-appstudio-qe/build-e2e-xzub/fj-test-custom-branch-mugmtg@sha256:49950a8820f5221d0e5c95c49d86ce019edcecef8fcdb78411eb6a1dd786fc03 [2026-07-09T18:30:18,883899580+00:00] End upload-sbom