Using token for quay.io/redhat-appstudio-qe/build-e2e-oci-archive/component-oci-archive WARNING: SBOM attachments are deprecated and support will be removed in a Cosign release soon after 2024-02-22 (see https://github.com/sigstore/cosign/issues/2755). Instead, please use SBOM attestations. WARNING: Downloading SBOMs this way does not ensure its authenticity. If you want to ensure a tamper-proof SBOM, download it using 'cosign download attestation '. Found SBOM of media type: text/spdx+json Detected base images from amd64 SBOM: registry.access.redhat.com/ubi9/ubi Images to be checked: registry.access.redhat.com/ubi9/ubi Querying Red Hat Catalog for registry.access.redhat.com/ubi9/ubi. Running conftest using /project/repository/ policy, required_checks namespace. [ { "filename": "/tmp/ubi9/ubi/repository_data.json", "namespace": "required_checks", "successes": 1 } ] [SUCCESS] Image registry.access.redhat.com/ubi9/ubi is valid {"result":"SUCCESS","timestamp":"2026-08-18T04:41:24+00:00","note":"Task deprecated-image-check completed: Check result for task result.","namespace":"required_checks","successes":1,"failures":0,"warnings":0} {"image": {"pullspec": "quay.io/redhat-appstudio-qe/build-e2e-oci-archive/component-oci-archive:on-pr-3d689542737e2ced2507dfc1fd5df92039315af9", "digests": ["sha256:ad3a6dba7c6e739089d8c9f182d1cbe7d3e32431e6c537c4a5fcc2311c606687"]}}