[2026-07-08T18:15:01,734611252+00:00] Upload SBOM INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' Using token for quay.io/redhat-appstudio-qe/build-e2e-sqoq/gl-test-custom-branch-buyflj Pushing sbom to registry [retry] executing: cosign attach sbom --sbom sbom.json --type spdx quay.io/redhat-appstudio-qe/build-e2e-sqoq/gl-test-custom-branch-buyflj:ffb67120b8d9ed7950fe68db55dbd792b4a44f18@sha256:6a18cb8059e79e9bf5ce42e27e61a8df2c368ce7c00c951eda4aea61c73de7d3 WARNING: SBOM attachments are deprecated and support will be removed in a Cosign release soon after 2024-02-22 (see https://github.com/sigstore/cosign/issues/2755). Instead, please use SBOM attestations. WARNING: Attaching SBOMs this way does not sign them. To sign them, use 'cosign attest --predicate sbom.json --key '. Uploading SBOM file for [quay.io/redhat-appstudio-qe/build-e2e-sqoq/gl-test-custom-branch-buyflj@sha256:6a18cb8059e79e9bf5ce42e27e61a8df2c368ce7c00c951eda4aea61c73de7d3] to [quay.io/redhat-appstudio-qe/build-e2e-sqoq/gl-test-custom-branch-buyflj:sha256-6a18cb8059e79e9bf5ce42e27e61a8df2c368ce7c00c951eda4aea61c73de7d3.sbom] with mediaType [text/spdx+json]. quay.io/redhat-appstudio-qe/build-e2e-sqoq/gl-test-custom-branch-buyflj@sha256:a1a8f1054e6ba00c111e810c69bf03300d09bacd745ce318fc3c7cd912635a96 [2026-07-08T18:15:25,103105213+00:00] End upload-sbom