INFO: Using mounted CA bundle: /tekton-custom-certs/ca-bundle.crt '/tekton-custom-certs/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' Initializing TUF root... WARNING: Fetching initial root from URL without providing its checksum is deprecated and will be disallowed in a future Cosign release. Please provide the initial root checksum via the --root-checksum argument. Root status: { "local": "/root/.sigstore/root", "remote": "https://tuf-tssc-tas.apps.rosa.kx-4d53a051e4.hbvr.p3.openshiftapps.com", "metadata": { "root.json": { "version": 1, "len": 4128, "expiration": "04 Feb 27 14:28 UTC", "error": "" }, "snapshot.json": { "version": 1, "len": 994, "expiration": "04 Feb 27 14:28 UTC", "error": "" }, "targets.json": { "version": 1, "len": 2071, "expiration": "04 Feb 27 14:28 UTC", "error": "" }, "timestamp.json": { "version": 1, "len": 995, "expiration": "04 Feb 27 14:28 UTC", "error": "" } }, "targets": [ "fulcio_v1.crt.pem", "trusted_root.json", "ctfe.pub", "rekor.pub" ] } Getting attestation for quay.io/rhtap_qe/backend-tests-go-wzxjpjqg:39202ed73a7bfba8a70b20c147ac9dea19be832b@sha256:b7634e829f2e694abb9ee0ea643ee507a8150caf3f036d26bde691e0a75e97e1 Verification for quay.io/rhtap_qe/backend-tests-go-wzxjpjqg:39202ed73a7bfba8a70b20c147ac9dea19be832b@sha256:b7634e829f2e694abb9ee0ea643ee507a8150caf3f036d26bde691e0a75e97e1 -- The following checks were performed on each of these signatures: - The cosign claims were validated - Existence of the claims in the transparency log was verified offline - The signatures were verified against the specified public key