[2026-07-08T18:10:31,512605097+00:00] Upload SBOM INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' Using token for quay.io/redhat-appstudio-qe/build-e2e-sqoq/gl-test-custom-branch-buyflj Pushing sbom to registry [retry] executing: cosign attach sbom --sbom sbom.json --type spdx quay.io/redhat-appstudio-qe/build-e2e-sqoq/gl-test-custom-branch-buyflj:on-pr-329a656552fe95e5629018fe487e1dcfbaae5e88@sha256:4b5074e38517481ed89ac2aa0e75ffcf4733c4ee8680dee81f5d12e2cd41ca28 WARNING: SBOM attachments are deprecated and support will be removed in a Cosign release soon after 2024-02-22 (see https://github.com/sigstore/cosign/issues/2755). Instead, please use SBOM attestations. WARNING: Attaching SBOMs this way does not sign them. To sign them, use 'cosign attest --predicate sbom.json --key '. Uploading SBOM file for [quay.io/redhat-appstudio-qe/build-e2e-sqoq/gl-test-custom-branch-buyflj@sha256:4b5074e38517481ed89ac2aa0e75ffcf4733c4ee8680dee81f5d12e2cd41ca28] to [quay.io/redhat-appstudio-qe/build-e2e-sqoq/gl-test-custom-branch-buyflj:sha256-4b5074e38517481ed89ac2aa0e75ffcf4733c4ee8680dee81f5d12e2cd41ca28.sbom] with mediaType [text/spdx+json]. quay.io/redhat-appstudio-qe/build-e2e-sqoq/gl-test-custom-branch-buyflj@sha256:3d189243417e293583668d56dab204c534a4ae075e27ab06d55902927a817623 [2026-07-08T18:10:54,484641954+00:00] End upload-sbom