INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-gomod/component-prefetch-gomod [2026-08-18T04:50:23,817959519+00:00] Upload SBOM Pushing sbom to registry [retry] executing: cosign attach sbom --sbom sbom.json --type spdx quay.io/redhat-appstudio-qe/build-e2e-prefetch-gomod/component-prefetch-gomod:on-pr-da5fe4bb86eb5a3c891f15efd65553f23d29594a@sha256:e1a3fd0ba9c64dc9aaab2886336a8b02605ace57992a1af7c02778cf8e5a86a3 WARNING: SBOM attachments are deprecated and support will be removed in a Cosign release soon after 2024-02-22 (see https://github.com/sigstore/cosign/issues/2755). Instead, please use SBOM attestations. WARNING: Attaching SBOMs this way does not sign them. To sign them, use 'cosign attest --predicate sbom.json --key '. Uploading SBOM file for [quay.io/redhat-appstudio-qe/build-e2e-prefetch-gomod/component-prefetch-gomod@sha256:e1a3fd0ba9c64dc9aaab2886336a8b02605ace57992a1af7c02778cf8e5a86a3] to [quay.io/redhat-appstudio-qe/build-e2e-prefetch-gomod/component-prefetch-gomod:sha256-e1a3fd0ba9c64dc9aaab2886336a8b02605ace57992a1af7c02778cf8e5a86a3.sbom] with mediaType [text/spdx+json]. quay.io/redhat-appstudio-qe/build-e2e-prefetch-gomod/component-prefetch-gomod@sha256:3f560f7a6052218ff3568d77fe8f783fac339fe7412d34e200136448314becb0 [2026-08-18T04:50:26,621987576+00:00] Handle keyless signing if enabled [retry] executing: kubectl get configmap cluster-config -n konflux-info -o json Keyless signing is disabled (none of rekorInternalUrl, fulcioInternalUrl, defaultOIDCIssuer, tufInternalUrl are configured in the konflux-info/cluster-config configmap) [2026-08-18T04:50:27,321215524+00:00] End upload-sbom