# Local verification of the first release, from a Windows machine outside GitHub Actions
# 2026-09-30T01:59:41Z — cosign v3.1.3

## 1. This repository's release workflow (must pass)
$ cosign verify ghcr.io/santorest/lab-04-secure-cicd-dotnet:388e61eea3509965b519639f747f094423ad0762 --certificate-identity https://github.com/santorest/lab-04-secure-cicd-dotnet/.github/workflows/release.yml@refs/heads/main --certificate-oidc-issuer https://token.actions.githubusercontent.com
Verification for ghcr.io/santorest/lab-04-secure-cicd-dotnet:388e61eea3509965b519639f747f094423ad0762 --
The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - Existence of the claims in the transparency log was verified offline
  - The code-signing certificate was verified using trusted certificate authority certificates
exit code: 0

## 2. Another repository's workflow (must fail)
$ cosign verify ghcr.io/santorest/lab-04-secure-cicd-dotnet:388e61eea3509965b519639f747f094423ad0762 --certificate-identity https://github.com/santorest/some-other-repo/.github/workflows/release.yml@refs/heads/main --certificate-oidc-issuer https://token.actions.githubusercontent.com
failed to verify certificate identity: no matching CertificateIdentity found, last error: expected SAN value "https://github.com/santorest/some-other-repo/.github/workflows/release.yml@refs/heads/main", got "https://github.com/san
exit code: 1
