nvidia.just on all images, but the profile shell script only includes it if you are running ublue nvidia derivative imagesostree-unverified-image anywhere in the org (new github code search rocks btw), so I'm wondering how this can be cropping upostree-unverified-registry:quay.io/exampleos/custom:latest - this will pull from a remote registry, and no signature will be required. In practice, this is just a shorthand for ostree-unverified-image:docker://quay.io/exampleos/custom:latest.
main's "release-please" workflow is what builds an ISOisogeneratordocker: anywhere in isogenerator code (local git checkout grep) and only one not-related occurance in mainimgurlimageurl=ghcr.io/{{ GITHUB_REPOSITORY_OWNER }}/{{ flavor_menu.label }}:{{ RELEASE }}ostreecontainer --url=mount -o loop $theisogrub.cfg sample kinoite linelinux /images/pxeboot/vmlinuz inst.stage2=hd:LABEL=Fedora-E-dvd-x86_64-38 nomodeset rd.live.check quiet inst.ks=hd:LABEL=Fedora-E-dvd-x86_64-38:/kickstart/ublue-os-nvidia.ks imageurl=ghcr.io/ublue-os/kinoite-nvidia:38pre-install.shostreecontainer --url="${URL}" --no-signature-verificationnvidia.justostree-unverified-imageisogeneratordocker:imgurlimageurl=ghcr.io/{{ GITHUB_REPOSITORY_OWNER }}/{{ flavor_menu.label }}:{{ RELEASE }}ostreecontainer --url=mount -o loop $theisogrub.cfglinux /images/pxeboot/vmlinuz inst.stage2=hd:LABEL=Fedora-E-dvd-x86_64-38 nomodeset rd.live.check quiet inst.ks=hd:LABEL=Fedora-E-dvd-x86_64-38:/kickstart/ublue-os-nvidia.ks imageurl=ghcr.io/ublue-os/kinoite-nvidia:38pre-install.shostreecontainer --url="${URL}" --no-signature-verification