INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' Using token for quay.io/redhat-appstudio-qe/build-e2e-oci-archive/component-oci-archive [2026-08-18T04:39:26,522573970+00:00] Upload SBOM Pushing sbom to registry [retry] executing: cosign attach sbom --sbom sbom.json --type spdx quay.io/redhat-appstudio-qe/build-e2e-oci-archive/component-oci-archive:on-pr-3d689542737e2ced2507dfc1fd5df92039315af9@sha256:ad3a6dba7c6e739089d8c9f182d1cbe7d3e32431e6c537c4a5fcc2311c606687 WARNING: SBOM attachments are deprecated and support will be removed in a Cosign release soon after 2024-02-22 (see https://github.com/sigstore/cosign/issues/2755). Instead, please use SBOM attestations. WARNING: Attaching SBOMs this way does not sign them. To sign them, use 'cosign attest --predicate sbom.json --key '. Uploading SBOM file for [quay.io/redhat-appstudio-qe/build-e2e-oci-archive/component-oci-archive@sha256:ad3a6dba7c6e739089d8c9f182d1cbe7d3e32431e6c537c4a5fcc2311c606687] to [quay.io/redhat-appstudio-qe/build-e2e-oci-archive/component-oci-archive:sha256-ad3a6dba7c6e739089d8c9f182d1cbe7d3e32431e6c537c4a5fcc2311c606687.sbom] with mediaType [text/spdx+json]. quay.io/redhat-appstudio-qe/build-e2e-oci-archive/component-oci-archive@sha256:d7400d005bb1e420e0ef3356786b77c3dd9c2e8e9ebe76579cf10f6b4b4f0784 [2026-08-18T04:39:29,230453111+00:00] Handle keyless signing if enabled [retry] executing: kubectl get configmap cluster-config -n konflux-info -o json Keyless signing is disabled (none of rekorInternalUrl, fulcioInternalUrl, defaultOIDCIssuer, tufInternalUrl are configured in the konflux-info/cluster-config configmap) [2026-08-18T04:39:30,223282345+00:00] End upload-sbom